Data Residency By Country skills for AI agents
8 practitioner-grade data residency by country skills, each a focused Markdown document your agent loads into context on demand. Search them from Claude Desktop, Cursor or any MCP client, or pull one with the CLI.
All 8 skills
- Cross-Border Transfer Mechanisms
Activate this skill when the user needs to move personal data lawfully between countries and must choose and document the mechanism: Standard Contractual Clauses, Binding Corporate Rules, certifications, adequacy decisions, transfer impact assessments or China's standard contract, or when a data residency programme must decide which flows can leave a region under GDPR, PDPA, PIPL or DPDP and which data localization rule stops them. Triggers when the user mentions "cross-border transfer," "international data transfer," "SCCs," "Standard Contractual Clauses," "BCRs," "Binding Corporate Rules," "adequacy decision," "Data Privacy Framework," "transfer impact assessment," "TIA," "supplementary measures," "IDTA," "UK Addendum," "China standard contract," "CAC security assessment," "APEC CBPR," "ASEAN MCCs," or "transfer decision tree." Covers each mechanism, how to run a TIA, the China standard contract and filing, the Singapore and India routes, and a decision tree for picking the mechanism per flow.
169 lines - Data Residency Architecture
Activate this skill when the user is designing or auditing the technical architecture that keeps a tenant's data inside a country or region, whether the driver is a data localization law such as PIPL or the RBI's payment rules, a data residency commitment in an enterprise contract, or a transfer restriction under GDPR, PDPA or DPDP. Triggers when the user mentions "data residency," "region pinning," "tenant sharding," "cell-based architecture," "per-region keys," "KMS," "BYOK," "HYOK," "cross-region replication," "backup residency," "log leakage," "telemetry leakage," "CDN and edge," "edge caching of personal data," "support access," "customer lockbox," "data sovereignty," "CLOUD Act," "org policy," "SCP," or "proving residency to auditors." Covers region pinning, tenant-to-region mapping, per-region key management, backups and disaster recovery, the leakage paths in logs, telemetry, CDNs and support tooling, and the evidence pack that satisfies auditors.
190 lines - DPDP (India)
Activate this skill when the user is preparing a product or organisation for India's Digital Personal Data Protection Act 2023 and its Rules, is integrating with a consent manager, or is deciding how India fits into a data residency or data localization design next to GDPR, PDPA and PIPL obligations. Triggers when the user mentions "DPDP," "DPDP Act," "DPDP Rules," "Data Fiduciary," "Data Principal," "Significant Data Fiduciary," "Consent Manager," "Data Protection Board," "MeitY," "CERT-In," "RBI data localisation," "SPDI Rules," "verifiable parental consent," "DigiLocker," "Aadhaar," or "India privacy readiness." Covers the Act's structure and phased commencement, consent and legitimate uses, fiduciary duties including breach notification and erasure, the consent manager model, cross-border allowances and sectoral overlays, and a readiness plan.
170 lines - GDPR (EU) with National Differences
Activate this skill when the user is designing, launching or auditing a product for the European Union and needs the General Data Protection Regulation applied correctly, including the places where Germany, the Netherlands and Ireland diverge in practice, or is comparing GDPR with PDPA, PIPL or DPDP inside a data residency programme and needs to know that the GDPR restricts transfers rather than imposing data localization. Triggers when the user mentions "GDPR," "DSGVO," "AVG," "lead supervisory authority," "one-stop-shop," "DPC," "Data Protection Commission," "BDSG," "Datenschutzbeauftragter," "DSB," "TTDSG," "TDDDG," "UAVG," "Autoriteit Persoonsgegevens," "Standard Contractual Clauses," "SCCs," "transfer impact assessment," "TIA," "adequacy decision," "Data Privacy Framework," "Schrems II," "DPIA," or "Article 30 records." Covers core GDPR obligations, the German DPO thresholds and telemedia consent rules, Dutch national identifier and enforcement specifics, the Irish DPC's lead-authority role, and transfers via adequacy, SCCs and TIAs.
168 lines - PDPA (Singapore)
Activate this skill when the user is building, operating or auditing a product that handles personal data of individuals in Singapore and needs to meet the Personal Data Protection Act, or is weighing Singapore's rules against GDPR, PIPL or DPDP in a data residency or data localization decision. Triggers when the user mentions "PDPA," "PDPC," "Singapore privacy," "data protection officer," "DPO registration," "transfer limitation," "notifiable data breach," "NRIC," "Singpass," "Myinfo," "Do Not Call Registry," "data intermediary," "deemed consent," or "PDPA checklist for SaaS." Covers the obligations, the lawful routes for moving data out of Singapore, breach assessment and notification timelines, the accountability and DPO requirements, and a practical compliance checklist for a SaaS serving Singapore customers.
169 lines - PIPL (China)
Activate this skill when the user is launching, re-architecting or auditing a product that processes personal information of people in mainland China under the Personal Information Protection Law, or is deciding how China's data localization rules fit into a global data residency design alongside GDPR, PDPA or DPDP programmes. Triggers when the user mentions "PIPL," "CAC," "Cyberspace Administration," "separate consent," "sensitive personal information," "cross-border data transfer," "security assessment," "China standard contract," "PIPIA," "CIIO," "critical information infrastructure," "MLPS," "Multi-Level Protection Scheme," "ICP filing," "Data Security Law," "important data," or "China stack." Covers the processing principles and lawful bases, when separate consent is required, the three cross-border transfer paths and their thresholds, localization duties for CIIOs and large handlers, MLPS grading, and the architecture consequences of running a China deployment.
183 lines - Privacy by Design for Multi-Region Products
Activate this skill when the user is building one product for several jurisdictions and needs consent experiences, retention schedules, data subject request handling, breach playbooks and records of processing that satisfy GDPR, PDPA, PIPL, DPDP and the US state laws at once, or is turning a data residency or data localization architecture into day-to-day operating procedures. Triggers when the user mentions "privacy by design," "consent banner," "cookie consent," "consent UX," "retention schedule," "DSAR," "data subject access request," "rights request across regions," "breach playbook," "72 hours," "notification deadlines," "records of processing," "RoPA," "data inventory," "data minimisation," "purpose limitation," or "privacy operating model." Covers consent design by jurisdiction, a retention matrix, cross-region DSAR routing, breach response with per-country deadlines, and a records-of-processing schema that doubles as the residency data map.
187 lines - US State Privacy Laws
Activate this skill when the user must comply with the California Consumer Privacy Act as amended by the CPRA and the growing set of US state comprehensive privacy laws, needs to layer sector rules such as HIPAA, GLBA and COPPA on top, or is placing the US inside a data residency programme that also covers GDPR, PDPA, PIPL or DPDP and wants a design that works across many states. Triggers when the user mentions "CCPA," "CPRA," "CPPA," "state privacy laws," "Global Privacy Control," "GPC," "Do Not Sell or Share," "opt-out preference signal," "universal opt-out mechanism," "sensitive personal information," "data protection assessment," "HIPAA," "GLBA," "COPPA," "BIPA," "My Health My Data," "data broker registration," or "data localization in the US." Covers CCPA/CPRA and the state patchwork in principle, sector overlays, opt-out signals, and how to design once for many states.
167 lines