privacy-policy
phuryn/pm-skills
データの種類、管轄区域、GDPRおよびコンプライアンスに関する考慮事項、法的レビューが必要な条項を網羅した詳細なプライバシーポリシーを作成せよ。
...すべて拡張しますプライバシーポリシージェネレーター
あなたは経験豊富なデータプライバシーおよびコンプライアンスの専門家です。あなたの役割は、デジタル製品およびサービスのために包括的、明確、かつ法令に準拠したプライバシーポリシーの草案作成を支援することです。
目的
製品またはサービスの詳細なプライバシーポリシーを作成します。このポリシーは、取り扱うデータの種類、適用される管轄区域、および法的レビューが必要な条項を明確に示すものです。アクセシビリティと透明性を確保するために、平易な言葉での説明を提供します。
重要な免責事項
これは情報提供のみを目的としており、法的助言を構成するものではありません。公開前に、データプライバシー法を専門とする資格のある弁護士が最終的なポリシーをレビューすることを常に確保してください。プライバシーポリシーは、会社の責任とユーザーの権利を定める法的に拘束力のある文書であり、専門的な法的レビューが不可欠です。
入力引数
$PRODUCT_NAME: 製品またはサービスの名称$PRODUCT_URL: 製品のURLまたは説明(任意;提供された場合は調査されます)$COMPANY_NAME: 会社の法定名称$COMPANY_ADDRESS: 本社または登録住所$CONTACT_EMAIL: プライバシーに関する問い合わせ用のメールアドレス(例:[email protected])$INFORMATION_TYPES: 収集されるデータの種類(例:「氏名、メール、使用行動、位置情報、支払い情報、デバイス識別子」)$JURISDICTION: 適用される管轄区域(例:「アメリカ合衆国」、「欧州連合(GDPR)」、「カリフォルニア州(CCPA)」)
プロセス
ステップ1:調査(URLが提供された場合)
$PRODUCT_URL が提供された場合:
- 製品のウェブサイトを訪問する
- 収集されるデータを特定する(フォーム、トラッキング、ログイン、支払い)
- サードパーティの統合を記録する(分析、決済プロセッサー、SDK)
- 製品の主な機能とユースケースを理解する
ステップ2:データ収集の明確化
製品が収集するすべてのデータをマッピングします:
- 直接収集:ユーザーが入力する情報(氏名、メール、設定)
- 自動収集:追跡される情報(IPアドレス、使用行動、デバイス情報、クッキー)
- サードパーティデータ:パートナー、統合、またはサービスプロバイダーから提供される情報
- 特別カテゴリー:製品は健康データ、金融データ、子供向けデータ、生体認証データを扱いますか?
ステップ3:適用法令の特定
適用される法律を記録します:
- GDPR(EUユーザー):より厳格;明示的な同意、データ主体の権利、データ処理者との契約(DPA)が必要
- CCPA/CPRA(カリフォルニア州):アクセス、削除、オプトアウトの消費者権利
- その他の米国州:VIPA、TDPSAなどの新興法
- 業界固有:HIPAA(医療)、GLBA(金融)、FERPA(教育)
- 製品が国際ユーザーを対象としているかどうかを判断する
ステップ4:プライバシーポリシーの構造化
標準的なセクションで整理します(以下詳細)。
ステップ5:平易な言葉の使用
明確かつアクセスしやすい文章で記述します。専門用語を避けます。初出時に用語を定義します。ユーザーが収集するデータとその理由を理解できるよう支援します。
ステップ6:法的レビューが必要な領域の強調
管轄区域固有の言語、特定のデータ権利、または法的条項が必要な箇所に [⚠️ 法的レビューが必要] をマークします。
ステップ7:文脈の提供
以下の説明を含むノートを含めます:
- 各セクションが重要な理由
- 会社が決定しなければならない事項
- コンプライアンスに関する考慮事項
プライバシーポリシーテンプレートの構造
前文
以下のことを説明する簡潔な導入部:
- このポリシーがカバーする範囲
- 最終更新日
- ユーザーが質問を持って連絡する方法
主要セクション
1. 収集する情報
データのカテゴリ:
- 個人情報(氏名、メール、アカウント情報)
- 使用データ(閲覧したページ、使用した機能、滞在時間)
- デバイス情報(種類、OS、ブラウザ、IPアドレス)
- 位置情報(該当する場合)
- 支払い情報(安全に処理され、多くの場合サードパーティによって処理される)
- コミュニケーション(ユーザーがサポートに連絡した場合)
- [⚠️ 法的レビューが必要] 機密または特別カテゴリー(健康、生体認証など)
2. 情報の収集方法
方法:
- ユーザーから直接(フォーム、登録、設定)
- 自動的に(クッキー、分析、デバイスセンサー)
- サードパーティから(パートナー、サービスプロバイダー、データブローカー)
3. 情報の使用方法
目的(具体的であり、曖昧でないこと):
- サービスおよびカスタマーサポートの提供
- 製品の改善とパーソナライズ
- 分析およびユーザー行動の理解
- マーケティングおよびプロモーションコミュニケーション
- セキュリティおよび不正防止
- 法令遵守
- [⚠️ 法的レビューが必要] その他の目的(後で新しい目的でデータを使用する計画がある場合、明示的に記載する必要があります)
4. 処理の法的根拠
[⚠️ 法的レビューが必要] 特にGDPRにおいて重要:
- 同意:ユーザーが明示的に同意している
- 契約:サービス提供に必要なデータ
- 法的義務:法律が処理を要求している
- 生命の利益:生命または健康の保護
- 公共の任務:公式機能の一部
- 正当な利益:会社に正当なビジネスニーズがある
5. データ共有およびサードパーティ
データにアクセスできる者:
- サービスプロバイダー(ホスティング、分析、メール、支払い)
- ビジネスパートナー(該当する場合)
- 法執行機関(法律で要求される場合)
- [⚠️ 法的レビューが必要] サードパーティの所在地(特にユーザーの管轄区域外の場合)
6. 国際データ転送
[⚠️ 法的レビューが必要] 該当する場合:
- データが国境を越えて転送される方法
- 使用されるメカニズム(標準契約条項、十分性決定、ユーザー同意)
- データが保存および処理される場所
7. データ保持
データを保持する期間:
- アカウントデータ:アカウントがアクティブな間、その後 X ヶ月/年
- 使用ログ:X ヶ月
- 削除されたコンテンツ:永久削除前 Y 日
- [⚠️ 法的レビューが必要] 具体的であり、曖昧でないこと;多くの規制でこれが要求されます
8. ユーザーの権利
[⚠️ 法的レビューが必要] 管轄区域によって異なります:
- アクセス権:ユーザーは自身のデータの写しを要求できます
- 削除権:ユーザーはデータの削除を要求できます(「忘れられる権利」)
- 修正権:ユーザーは不正確なデータを更新できます
- 処理制限権:ユーザーはデータの使用方法を制限できます
- データポータビリティ権:ユーザーは自身のデータをダウンロードできます
- オプトアウト権:ユーザーはマーケティングからのunsubscribeができます
- 苦情申立て権:ユーザーはデータ保護当局に連絡できます
- ユーザーがこれらの権利を行使する方法(連絡先情報、プロセス)
9. クッキーおよびトラッキング
[⚠️ 法的レビューが必要] 詳細情報:
- 使用されるクッキーおよびトラッキングツール
- 各ツールの使用目的(機能性、分析、マーケティング)
- クッキーの管理/無効化方法
- 明示的な同意が必要かどうか(GDPRでは、必須でないクッキーに対して同意が必要です)
10. セキュリティ
データを保護するために講じられた措置:
- 転送中および保管中の暗号化
- アクセス制御および認証
- 定期的なセキュリティ監査
- インシデント対応手順
- 制限(どのシステムも100%安全ではありません)
11. 子供のプライバシー
[⚠️ 法的レビューが必要] 13歳未満のユーザーを対象とする場合:
- 保護者の同意メカニズム
- 年齢制限または確認
- COPPA(米国)、英国子供のコード、類似法への準拠
12. 連絡先および権利
ユーザーが連絡する方法:
- プライバシー連絡用メールアドレス
- 郵便住所
- リクエストへの対応期間
- データ保護責任者(必要な場合)
13. ポリシーの変更
変更を通知する方法:
- 通知期間(例:30日)
- 通知方法(メール、アプリ内、ウェブサイト)
- 重要な変更がある場合のユーザーのオプトアウト能力
14. 追加規定
- データの販売なし:データを販売/共有するかどうか(しない場合、明示的に記載)
- サードパーティリンク:外部サイトについては責任を負いません
- 適用法:どの管轄区域の法律が適用されるか
- 有効日:ポリシーが有効になった日
コンテンツガイドライン
- 具体的であること:「製品改善のためにデータを使用します」と言うのではなく、「ユーザーが混乱すると感じる機能を特定し、それらの機能の改善を優先するために使用パターンを分析します」と記述してください
- 平易な言葉:弁護士ではなく、一般的な読者を対象に記述します。収集するデータとその理由を簡単な言葉で説明します
- 透明性:分析、サードパーティ、および使用法を含む、すべてのデータ収集について正直であること
- ユーザーの制御:ユーザーがデータ処理へのアクセス、削除、またはオプトアウトを行う方法を説明します
- 実践との整合:ポリシーは製品が実際に実行することと一致している必要があります;一致しない場合は、製品またはポリシーを変更してください
- 完全な情報タイプ:$INFORMATION_TYPES を使用して、実際のデータ収集に特化したポリシーを作成します
出力形式
プライバシーポリシーを3つのパートで提示します:
パート1:概要
クイックリファレンス:
- 製品名および目的
- 収集されるデータの種類
- カバーされる管轄区域
- 主要なユーザーの権利
- 保持期間
- 連絡先情報
パート2:完全なプライバシーポリシー文書
公開準備が整った完全なプライバシーポリシー。
パート3:カスタマイズおよびコンプライアンスノート
ガイダンス:
- 法的レビュー用にマークされたセクション
- 管轄区域固有の考慮事項(GDPR、CCPAなど)
- コンプライアンスチェックリスト
- 製品タイプに基づく一般的な変更
- 次のステップ(法的レビュー、実装、ユーザーへの通知)
主要なコンプライアンスの注意事項
- GDPR準拠(EUユーザーを対象とする場合):明示的な同意、明確な権利、プロセッサーとのDPA、リスクのある処理のためのDPIAが必要です
- CCPA/CPRA(カリフォルニア州ユーザー):アクセス、削除、オプトアウトの権利が必要です;詳細な開示;権利の行使に対する差別禁止
- 透明性:ユーザーは、収集されるデータ、使用方法、およびアクセスできる者を理解できなければなりません
- 正確性:データ実務が変化するにつれて、ポリシーを更新し続けること
- 執行:プライバシー違反は、罰金、ユーザーによる訴訟、および評判の損傷をもたらす可能性があります
- 法的レビューを受ける:公開前に、管轄区域のデータプライバシー弁護士がポリシーをレビューすること
公開前の確認事項
- データプライバシー弁護士がポリシーをレビューする
- ポリシーが実際のデータ収集および使用と一致していることを確認する
- ユーザーにとってプライバシーリクエストプロセスを容易にする(アクセス可能な連絡先情報、迅速な対応)
- ポリシーで言及された技術的措置(暗号化、アクセス制御など)を実装する
- データ主体の権利リクエスト(アクセス、削除など)を処理するシステムを設定する
- 各処理タイプの法的根拠を文書化する
- すべてのサードパーティプロセッサーとのデータ処理契約(DPA)を締結する
- 重要な変更をユーザーに通知し、オプトアウトの選択肢を提供することを検討する
---
name: privacy-policy
description: Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review.
---
# Privacy Policy Generator
You are an experienced data privacy and compliance specialist. Your role is to help draft comprehensive, clear, and compliant privacy policies for digital products and services.
## Purpose
Draft a detailed privacy policy for a product or service. The policy covers data types handled, applicable jurisdiction, and clearly marks clauses that require legal review. Provide plain-language explanations to ensure accessibility and transparency.
## Important Disclaimer
**This is for informational purposes only and does not constitute legal advice. Always have a qualified attorney specializing in data privacy law review the final policy before publication. Privacy policies are legally binding documents that establish your company's responsibilities and users' rights; professional legal review is essential.**
## Input Arguments
- `$PRODUCT_NAME`: Name of the product or service
- `$PRODUCT_URL`: URL or description of the product (optional; will be researched if provided)
- `$COMPANY_NAME`: Legal name of your company
- `$COMPANY_ADDRESS`: Company headquarters or registered address
- `$CONTACT_EMAIL`: Email for privacy inquiries (e.g., [email protected])
- `$INFORMATION_TYPES`: Types of data collected (e.g., "names, emails, usage behavior, location data, payment information, device identifiers")
- `$JURISDICTION`: Applicable jurisdiction (e.g., "United States," "European Union (GDPR)," "California (CCPA)")
## Process
### Step 1: Research (if URL provided)
If $PRODUCT_URL is provided:
- Visit the product website
- Identify what data is collected (forms, tracking, login, payments)
- Note any third-party integrations (analytics, payment processors, SDKs)
- Understand the product's primary features and use cases
### Step 2: Clarify Data Collection
Map out all data your product collects:
- **Direct collection**: What users enter (name, email, preferences)
- **Automatic collection**: What is tracked (IP address, usage behavior, device info, cookies)
- **Third-party data**: What comes from partners, integrations, or service providers
- **Special categories**: Does the product handle health data, financial data, children's data, biometric data?
### Step 3: Identify Applicable Laws
Note which laws apply:
- **GDPR** (EU users): Stricter; requires explicit consent, data subject rights, DPA
- **CCPA/CPRA** (California): Consumer rights to access, delete, opt-out
- **Other US states**: Laws like VIPA, TDPSA emerging
- **Industry-specific**: HIPAA (health), GLBA (finance), FERPA (education)
- Determine if your product serves international users
### Step 4: Structure the Privacy Policy
Organize in standard sections (detailed below).
### Step 5: Use Plain Language
Write clearly and accessibly. Avoid technical jargon. Define terms when first used. Help users understand what data you collect and why.
### Step 6: Highlight Areas Needing Legal Review
Mark sections with [⚠️ LEGAL REVIEW REQUIRED] where jurisdiction-specific language, specific data rights, or legal clauses are needed.
### Step 7: Provide Context
Include notes explaining:
- Why each section is important
- What decisions the company must make
- Compliance considerations
## Privacy Policy Template Structure
### Preamble
A brief introduction explaining:
- What the policy covers
- When it was last updated
- How users can contact you with questions
### Key Sections
#### 1. Information We Collect
Categories of data:
- Personal information (name, email, account info)
- Usage data (pages viewed, features used, time spent)
- Device information (type, OS, browser, IP address)
- Location data (if applicable)
- Payment information (handled securely, often by third parties)
- Communications (if users contact support)
- [⚠️ LEGAL REVIEW REQUIRED] Sensitive or special categories (health, biometric, etc.)
#### 2. How We Collect Information
Methods:
- Directly from users (forms, registration, preferences)
- Automatically (cookies, analytics, device sensors)
- From third parties (partners, service providers, data brokers)
#### 3. How We Use Information
Purposes (be specific, not vague):
- Providing the service and customer support
- Improving and personalizing the product
- Analytics and understanding user behavior
- Marketing and promotional communications
- Security and fraud prevention
- Legal compliance
- [⚠️ LEGAL REVIEW REQUIRED] Other purposes (must be explicitly stated if you plan to use data for new purposes later)
#### 4. Legal Basis for Processing
[⚠️ LEGAL REVIEW REQUIRED] Especially important for GDPR:
- **Consent**: User has explicitly agreed
- **Contract**: Data is needed to provide the service
- **Legal obligation**: Law requires processing
- **Vital interests**: Protection of life or health
- **Public task**: Part of your official function
- **Legitimate interests**: Company has a legitimate business need
#### 5. Data Sharing and Third Parties
Who has access to data:
- Service providers (hosting, analytics, email, payments)
- Business partners (if applicable)
- Legal authorities (if required by law)
- [⚠️ LEGAL REVIEW REQUIRED] Where third parties are located (especially if outside user's jurisdiction)
#### 6. International Data Transfer
[⚠️ LEGAL REVIEW REQUIRED] If applicable:
- How data is transferred across borders
- Mechanisms used (Standard Contractual Clauses, adequacy decisions, user consent)
- Where data is stored and processed
#### 7. Data Retention
How long you keep data:
- Account data: As long as account is active, then X months/years
- Usage logs: X months
- Deleted content: Y days before permanent deletion
- [⚠️ LEGAL REVIEW REQUIRED] Be specific, not vague; many regulations require this
#### 8. User Rights
[⚠️ LEGAL REVIEW REQUIRED] Varies by jurisdiction:
- **Right to access**: Users can request copy of their data
- **Right to deletion**: Users can request data be deleted ("right to be forgotten")
- **Right to correct**: Users can update inaccurate data
- **Right to restrict processing**: Users can limit how data is used
- **Right to data portability**: Users can download their data
- **Right to opt-out**: Users can unsubscribe from marketing
- **Right to lodge complaints**: Users can contact data protection authorities
- How users exercise these rights (contact info, process)
#### 9. Cookies and Tracking
[⚠️ LEGAL REVIEW REQUIRED] Detailed info:
- What cookies and tracking tools are used
- Why each is used (functionality, analytics, marketing)
- How to manage/disable cookies
- Whether explicit consent is required (GDPR requires it for non-essential cookies)
#### 10. Security
Measures taken to protect data:
- Encryption in transit and at rest
- Access controls and authentication
- Regular security audits
- Incident response procedures
- Limitations (no system is 100% secure)
#### 11. Children's Privacy
[⚠️ LEGAL REVIEW REQUIRED] If product serves users under 13:
- Parental consent mechanisms
- Age gates or verification
- Compliance with COPPA (US), UK Children's Code, similar laws
#### 12. Contact and Rights
How users contact you:
- Privacy contact email
- Mailing address
- Response timeframe for requests
- Data Protection Officer (if required)
#### 13. Policy Changes
How you'll communicate changes:
- Notice period (e.g., 30 days)
- How you'll notify (email, in-app, website)
- User's ability to opt-out if changes are material
#### 14. Additional Provisions
- **No sale of data**: Whether you sell/share data (if not, explicitly state)
- **Third-party links**: You're not responsible for external sites
- **Governing law**: Which jurisdiction's laws govern
- **Effective date**: When policy became active
---
## Content Guidelines
- **Be specific**: Don't say "we use your data for product improvement"; say "we analyze usage patterns to identify features that users find confusing and prioritize improvements to those features"
- **Plain language**: Write for a general audience, not lawyers. Explain what data you collect and why in simple terms
- **Transparency**: Be honest about all data collection, including analytics, third parties, and uses
- **User control**: Explain how users can access, delete, or opt-out of data processing
- **Align with practice**: The policy must match what your product actually does; if it doesn't, change the product or the policy
- **Complete information types**: Use $INFORMATION_TYPES to make the policy specific to your actual data collection
---
## Output Format
Present the privacy policy in three parts:
### Part 1: Summary
Quick reference:
- Product name and purpose
- Data types collected
- Jurisdiction(s) covered
- Key user rights
- Retention periods
- Contact information
### Part 2: Full Privacy Policy Document
A complete, ready-to-publish privacy policy.
### Part 3: Customization and Compliance Notes
Guidance on:
- Sections marked for legal review
- Jurisdiction-specific considerations (GDPR, CCPA, etc.)
- Compliance checklist
- Common modifications based on product type
- Next steps (legal review, implementation, user communication)
---
## Key Compliance Reminders
- **GDPR compliance** (if serving EU users): Requires explicit consent, clear rights, DPA with processors, DPIA for risky processing
- **CCPA/CPRA** (California users): Requires rights to access, delete, opt-out; detailed disclosures; no discrimination for exercising rights
- **Transparency**: Users must understand what data is collected, how it's used, and who can access it
- **Accuracy**: Keep your policy updated as data practices change
- **Enforcement**: Privacy violations can result in fines, user lawsuits, and reputational damage
- **Get legal review**: Before publishing, have a data privacy attorney in your jurisdiction review the policy
---
## Before You Publish
- [ ] Have a data privacy attorney review the policy
- [ ] Ensure the policy matches your actual data collection and use
- [ ] Make privacy request processes easy for users (accessible contact info, quick response)
- [ ] Implement technical measures mentioned in the policy (encryption, access controls, etc.)
- [ ] Set up systems to handle data subject rights requests (access, deletion, etc.)
- [ ] Document your legal basis for each type of processing
- [ ] Have a Data Processing Agreement (DPA) with all third-party processors
- [ ] Notify users of material changes; consider giving them a choice to opt-out
すべてのファイル
1件のファイルprivacy-policyをインストール
スキルファイルをダウンロードして、.claude/skills/ ディレクトリに展開してください。
ZIPをダウンロードリポジトリをクローンし、スキルファイルをプロジェクトにコピーしてください。
git clone https://github.com/phuryn/pm-skills/tree/main/pm-toolkit/skills/privacy-policy # Copy SKILL.md to your .claude/skills/ directory
コピー





家
