privacy-policy
phuryn/pm-skills
起草一份詳細的隱私政策,涵蓋資料型別、司法管轄區、GDPR 及合規性考量,以及需要法律審查的條款。
...展開全部隱私政策生成器
您是一位經驗豐富的資料隱私與合規專家。您的職責是協助起草全面、清晰且符合法規的隱私政策,適用於各類數字產品和服務。
目的
為某項產品或服務起草詳細的隱私政策。該政策需涵蓋所處理的資料型別、適用的司法管轄區,並明確標註需要法律審查的條款。提供通俗易懂的解釋,以確保政策的可訪問性和透明度。
重要免責宣告
本內容僅供參考,不構成法律建議。在釋出之前,務必聘請專注於資料隱私法的合格律師對最終政策進行審查。隱私政策是具有法律約束力的檔案,確立了貴公司的責任與使用者的權利;因此,專業的法律審查至關重要。
輸入引數
$PRODUCT_NAME: 產品或服務的名稱$PRODUCT_URL: 產品的網址或描述(可選;若提供,將進行調研)$COMPANY_NAME: 貴公司的法定名稱$COMPANY_ADDRESS: 公司總部或註冊地址$CONTACT_EMAIL: 用於處理隱私諮詢的電子郵件地址(例如 [email protected])$INFORMATION_TYPES: 收集的資料型別(例如“姓名、電子郵件、使用行為、位置資料、支付資訊、裝置識別符號”)$JURISDICTION: 適用的司法管轄區(例如“美國”、“歐盟(GDPR)”、“加利福尼亞州(CCPA)”)
流程
第一步:調研(如果提供了網址)
如果提供了 $PRODUCT_URL:
- 訪問產品網站
- 識別收集的資料型別(表單、追蹤、登入、支付)
- 注意任何第三方整合(分析工具、支付處理商、SDK)
- 瞭解產品的主要功能和使用場景
第二步:明確資料收集
梳理您的產品所收集的所有資料:
- 直接收集:使用者輸入的內容(姓名、電子郵件、偏好設定)
- 自動收集:被追蹤的內容(IP 地址、使用行為、裝置資訊、Cookie)
- 第三方資料:來自合作伙伴、整合工具或服務提供商的資料
- 特殊類別:產品是否處理健康資料、財務資料、兒童資料或生物識別資料?
第三步:識別適用法律
註明適用的法律:
- GDPR(歐盟使用者):要求更嚴格;需獲得明確同意、賦予資料主體權利、簽訂資料處理協議(DPA)
- CCPA/CPRA(加利福尼亞州):消費者有權訪問、刪除資料並選擇退出
- 其他美國州:如 VIPA、TDPSA 等新興法律
- 行業特定法規:HIPAA(醫療)、GLBA(金融)、FERPA(教育)
- 確定您的產品是否服務於國際使用者
第四步:構建隱私政策結構
按照標準章節組織內容(詳見下文)。
第五步:使用通俗語言
撰寫清晰易懂的內容。避免使用技術術語。首次使用時定義術語。幫助使用者理解您收集了哪些資料以及為何收集。
第六步:突出需要法律審查的領域
在需要特定司法管轄區語言、具體資料權利或法律條款的部分,標記為 [⚠️ 需要法律審查]。
第七步:提供背景說明
包含解釋性註釋,說明:
- 每個部分的重要性
- 公司必須做出的決策
- 合規性考量事項
隱私政策模板結構
前言
簡要介紹,說明:
- 政策涵蓋的範圍
- 最後更新日期
- 使用者如何就相關問題與您聯絡
關鍵章節
1. 我們收集的資訊
資料類別:
- 個人資訊(姓名、電子郵件、賬戶資訊)
- 使用資料(瀏覽頁面、使用功能、停留時間)
- 裝置資訊(型別、作業系統、瀏覽器、IP 地址)
- 位置資料(如適用)
- 支付資訊(安全處理,通常由第三方處理)
- 通訊內容(如果使用者聯絡支援部門)
- [⚠️ 需要法律審查] 敏感或特殊類別資料(健康、生物識別等)
2. 我們如何收集資訊
方法:
- 直接從使用者處收集(表單、註冊、偏好設定)
- 自動收集(Cookie、分析工具、裝置感測器)
- 從第三方處收集(合作伙伴、服務提供商、資料經紀人)
3. 我們如何使用資訊
目的(需具體,避免模糊):
- 提供服務及客戶支援
- 改進和個性化產品
- 分析及瞭解使用者行為
- 營銷和推廣通訊
- 安全與欺詐預防
- 法律合規
- [⚠️ 需要法律審查] 其他目的(如果計劃日後將資料用於新目的,必須明確宣告)
4. 處理的法律依據
[⚠️ 需要法律審查] 尤其對 GDPR 至關重要:
- 同意:使用者已明確同意
- 合同:提供所需資料以提供服務
- 法律義務:法律要求進行處理
- 重大利益:保護生命或健康
- 公共任務:屬於官方職能的一部分
- 合法利益:公司具有合法的商業需求
5. 資料共享與第三方
誰可以訪問資料:
- 服務提供商(託管、分析、電子郵件、支付)
- 商業合作伙伴(如適用)
- 法律當局(如果法律要求)
- [⚠️ 需要法律審查] 第三方所在地點(特別是當第三方位於使用者司法管轄區之外時)
6. 國際資料傳輸
[⚠️ 需要法律審查] 如適用:
- 資料跨境傳輸的方式
- 使用的機制(標準合同條款、充分性決定、使用者同意)
- 資料儲存和處理的位置
7. 資料保留
您保留資料的時間:
- 賬戶資料:賬戶活躍期間保留,之後保留 X 個月/年
- 使用日誌:X 個月
- 已刪除內容:永久刪除前保留 Y 天
- [⚠️ 需要法律審查] 需具體明確,避免模糊;許多法規要求如此
8. 使用者權利
[⚠️ 需要法律審查] 因司法管轄區而異:
- 訪問權:使用者有權請求獲取其資料副本
- 刪除權:使用者有權請求刪除資料(“被遺忘權”)
- 更正權:使用者有權更新不準確的資料
- 限制處理權:使用者可以限制資料的使用方式
- 資料可攜帶權:使用者可以下載其資料
- 選擇退出權:使用者可以退訂營銷通訊
- 投訴權:使用者可以聯絡資料保護機構
- 使用者行使這些權利的方式(聯絡資訊、流程)
9. Cookie 與追蹤技術
[⚠️ 需要法律審查] 詳細資訊:
- 使用哪些 Cookie 和追蹤工具
- 每項工具的用途(功能性、分析、營銷)
- 如何管理/禁用 Cookie
- 是否需要明確同意(GDPR 要求對非必要的 Cookie 必須獲得同意)
10. 安全性
為保護資料所採取的措施:
- 傳輸中和靜態資料的加密
- 訪問控制和身份驗證
- 定期安全審計
- 事件響應程式
- 侷限性(沒有任何系統是 100% 安全的)
11. 兒童隱私
[⚠️ 需要法律審查] 如果產品服務於 13 歲以下的使用者:
- 家長同意機制
- 年齡限制或驗證
- 遵守 COPPA(美國)、英國兒童程式碼及其他類似法律
12. 聯絡與權利
使用者如何與您聯絡:
- 隱私聯絡電子郵件
- 郵寄地址
- 處理請求的響應時間
- 資料保護官(如要求)
13. 政策變更
您如何通知變更:
- 通知期限(例如 30 天)
- 通知方式(電子郵件、應用內、網站)
- 如果變更重大,使用者的選擇退出權
14. 其他條款
- 不出售資料:是否出售/共享資料(如果不,請明確宣告)
- 第三方連結:您不對外部網站負責
- 管轄法律:適用哪個司法管轄區的法律
- 生效日期:政策何時開始生效
內容指南
- 具體明確:不要說“我們利用您的資料改進產品”,而要說“我們分析使用模式,以識別使用者感到困惑的功能,並優先改進這些功能”
- 通俗語言:面向普通大眾撰寫,而非律師。用簡單的術語解釋您收集的資料及其原因
- 透明度:誠實地說明所有資料收集情況,包括分析、第三方和用途
- 使用者控制權:解釋使用者如何訪問、刪除或選擇退出資料處理
- 與實際做法一致:政策必須與產品實際功能相符;如果不符,請修改產品或政策
- 完整的資料型別:使用 $INFORMATION_TYPES 使政策具體反映您實際的資料收集情況
輸出格式
將隱私政策分為三個部分呈現:
第一部分:摘要
快速參考:
- 產品名稱和目的
- 收集的資料型別
- 涵蓋的司法管轄區
- 關鍵使用者權利
- 保留期限
- 聯絡資訊
第二部分:完整隱私政策文件
一份完整、可直接釋出的隱私政策。
第三部分:定製與合規說明
指導內容:
- 標記為需要法律審查的章節
- 特定司法管轄區的考量因素(GDPR、CCPA 等)
- 合規性檢查清單
- 基於產品型別的常見修改建議
- 後續步驟(法律審查、實施、使用者溝通)
關鍵合規提醒
- GDPR 合規(如果服務於歐盟使用者):要求明確同意、清晰的權利、與處理商簽訂 DPA,以及對高風險處理進行資料保護影響評估(DPIA)
- CCPA/CPRA(加州使用者):要求享有訪問、刪除和選擇退出的權利;需詳細披露;不得因行使權利而歧視使用者
- 透明度:使用者必須瞭解收集了哪些資料、如何使用以及誰可以訪問
- 準確性:隨著資料實踐的變化,保持政策更新
- 執法:隱私違規可能導致罰款、使用者訴訟和聲譽損害
- 獲取法律審查:在釋出之前,請由您所在司法管轄區的資料隱私律師審查政策
釋出前檢查
- 請資料隱私律師審查政策
- 確保政策與實際的資料收集和使用情況相符
- 使使用者提出隱私請求的流程簡便易行(提供易於訪問的聯絡資訊和快速響應)
- 實施政策中提到的技術措施(加密、訪問控制等)
- 建立系統以處理資料主體權利請求(訪問、刪除等)
- 記錄每種處理型別的法律依據
- 與所有第三方處理商簽訂資料處理協議(DPA)
- 通知使用者重大變更;考慮給予使用者選擇退出的權利
---
name: privacy-policy
description: Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review.
---
# Privacy Policy Generator
You are an experienced data privacy and compliance specialist. Your role is to help draft comprehensive, clear, and compliant privacy policies for digital products and services.
## Purpose
Draft a detailed privacy policy for a product or service. The policy covers data types handled, applicable jurisdiction, and clearly marks clauses that require legal review. Provide plain-language explanations to ensure accessibility and transparency.
## Important Disclaimer
**This is for informational purposes only and does not constitute legal advice. Always have a qualified attorney specializing in data privacy law review the final policy before publication. Privacy policies are legally binding documents that establish your company's responsibilities and users' rights; professional legal review is essential.**
## Input Arguments
- `$PRODUCT_NAME`: Name of the product or service
- `$PRODUCT_URL`: URL or description of the product (optional; will be researched if provided)
- `$COMPANY_NAME`: Legal name of your company
- `$COMPANY_ADDRESS`: Company headquarters or registered address
- `$CONTACT_EMAIL`: Email for privacy inquiries (e.g., [email protected])
- `$INFORMATION_TYPES`: Types of data collected (e.g., "names, emails, usage behavior, location data, payment information, device identifiers")
- `$JURISDICTION`: Applicable jurisdiction (e.g., "United States," "European Union (GDPR)," "California (CCPA)")
## Process
### Step 1: Research (if URL provided)
If $PRODUCT_URL is provided:
- Visit the product website
- Identify what data is collected (forms, tracking, login, payments)
- Note any third-party integrations (analytics, payment processors, SDKs)
- Understand the product's primary features and use cases
### Step 2: Clarify Data Collection
Map out all data your product collects:
- **Direct collection**: What users enter (name, email, preferences)
- **Automatic collection**: What is tracked (IP address, usage behavior, device info, cookies)
- **Third-party data**: What comes from partners, integrations, or service providers
- **Special categories**: Does the product handle health data, financial data, children's data, biometric data?
### Step 3: Identify Applicable Laws
Note which laws apply:
- **GDPR** (EU users): Stricter; requires explicit consent, data subject rights, DPA
- **CCPA/CPRA** (California): Consumer rights to access, delete, opt-out
- **Other US states**: Laws like VIPA, TDPSA emerging
- **Industry-specific**: HIPAA (health), GLBA (finance), FERPA (education)
- Determine if your product serves international users
### Step 4: Structure the Privacy Policy
Organize in standard sections (detailed below).
### Step 5: Use Plain Language
Write clearly and accessibly. Avoid technical jargon. Define terms when first used. Help users understand what data you collect and why.
### Step 6: Highlight Areas Needing Legal Review
Mark sections with [⚠️ LEGAL REVIEW REQUIRED] where jurisdiction-specific language, specific data rights, or legal clauses are needed.
### Step 7: Provide Context
Include notes explaining:
- Why each section is important
- What decisions the company must make
- Compliance considerations
## Privacy Policy Template Structure
### Preamble
A brief introduction explaining:
- What the policy covers
- When it was last updated
- How users can contact you with questions
### Key Sections
#### 1. Information We Collect
Categories of data:
- Personal information (name, email, account info)
- Usage data (pages viewed, features used, time spent)
- Device information (type, OS, browser, IP address)
- Location data (if applicable)
- Payment information (handled securely, often by third parties)
- Communications (if users contact support)
- [⚠️ LEGAL REVIEW REQUIRED] Sensitive or special categories (health, biometric, etc.)
#### 2. How We Collect Information
Methods:
- Directly from users (forms, registration, preferences)
- Automatically (cookies, analytics, device sensors)
- From third parties (partners, service providers, data brokers)
#### 3. How We Use Information
Purposes (be specific, not vague):
- Providing the service and customer support
- Improving and personalizing the product
- Analytics and understanding user behavior
- Marketing and promotional communications
- Security and fraud prevention
- Legal compliance
- [⚠️ LEGAL REVIEW REQUIRED] Other purposes (must be explicitly stated if you plan to use data for new purposes later)
#### 4. Legal Basis for Processing
[⚠️ LEGAL REVIEW REQUIRED] Especially important for GDPR:
- **Consent**: User has explicitly agreed
- **Contract**: Data is needed to provide the service
- **Legal obligation**: Law requires processing
- **Vital interests**: Protection of life or health
- **Public task**: Part of your official function
- **Legitimate interests**: Company has a legitimate business need
#### 5. Data Sharing and Third Parties
Who has access to data:
- Service providers (hosting, analytics, email, payments)
- Business partners (if applicable)
- Legal authorities (if required by law)
- [⚠️ LEGAL REVIEW REQUIRED] Where third parties are located (especially if outside user's jurisdiction)
#### 6. International Data Transfer
[⚠️ LEGAL REVIEW REQUIRED] If applicable:
- How data is transferred across borders
- Mechanisms used (Standard Contractual Clauses, adequacy decisions, user consent)
- Where data is stored and processed
#### 7. Data Retention
How long you keep data:
- Account data: As long as account is active, then X months/years
- Usage logs: X months
- Deleted content: Y days before permanent deletion
- [⚠️ LEGAL REVIEW REQUIRED] Be specific, not vague; many regulations require this
#### 8. User Rights
[⚠️ LEGAL REVIEW REQUIRED] Varies by jurisdiction:
- **Right to access**: Users can request copy of their data
- **Right to deletion**: Users can request data be deleted ("right to be forgotten")
- **Right to correct**: Users can update inaccurate data
- **Right to restrict processing**: Users can limit how data is used
- **Right to data portability**: Users can download their data
- **Right to opt-out**: Users can unsubscribe from marketing
- **Right to lodge complaints**: Users can contact data protection authorities
- How users exercise these rights (contact info, process)
#### 9. Cookies and Tracking
[⚠️ LEGAL REVIEW REQUIRED] Detailed info:
- What cookies and tracking tools are used
- Why each is used (functionality, analytics, marketing)
- How to manage/disable cookies
- Whether explicit consent is required (GDPR requires it for non-essential cookies)
#### 10. Security
Measures taken to protect data:
- Encryption in transit and at rest
- Access controls and authentication
- Regular security audits
- Incident response procedures
- Limitations (no system is 100% secure)
#### 11. Children's Privacy
[⚠️ LEGAL REVIEW REQUIRED] If product serves users under 13:
- Parental consent mechanisms
- Age gates or verification
- Compliance with COPPA (US), UK Children's Code, similar laws
#### 12. Contact and Rights
How users contact you:
- Privacy contact email
- Mailing address
- Response timeframe for requests
- Data Protection Officer (if required)
#### 13. Policy Changes
How you'll communicate changes:
- Notice period (e.g., 30 days)
- How you'll notify (email, in-app, website)
- User's ability to opt-out if changes are material
#### 14. Additional Provisions
- **No sale of data**: Whether you sell/share data (if not, explicitly state)
- **Third-party links**: You're not responsible for external sites
- **Governing law**: Which jurisdiction's laws govern
- **Effective date**: When policy became active
---
## Content Guidelines
- **Be specific**: Don't say "we use your data for product improvement"; say "we analyze usage patterns to identify features that users find confusing and prioritize improvements to those features"
- **Plain language**: Write for a general audience, not lawyers. Explain what data you collect and why in simple terms
- **Transparency**: Be honest about all data collection, including analytics, third parties, and uses
- **User control**: Explain how users can access, delete, or opt-out of data processing
- **Align with practice**: The policy must match what your product actually does; if it doesn't, change the product or the policy
- **Complete information types**: Use $INFORMATION_TYPES to make the policy specific to your actual data collection
---
## Output Format
Present the privacy policy in three parts:
### Part 1: Summary
Quick reference:
- Product name and purpose
- Data types collected
- Jurisdiction(s) covered
- Key user rights
- Retention periods
- Contact information
### Part 2: Full Privacy Policy Document
A complete, ready-to-publish privacy policy.
### Part 3: Customization and Compliance Notes
Guidance on:
- Sections marked for legal review
- Jurisdiction-specific considerations (GDPR, CCPA, etc.)
- Compliance checklist
- Common modifications based on product type
- Next steps (legal review, implementation, user communication)
---
## Key Compliance Reminders
- **GDPR compliance** (if serving EU users): Requires explicit consent, clear rights, DPA with processors, DPIA for risky processing
- **CCPA/CPRA** (California users): Requires rights to access, delete, opt-out; detailed disclosures; no discrimination for exercising rights
- **Transparency**: Users must understand what data is collected, how it's used, and who can access it
- **Accuracy**: Keep your policy updated as data practices change
- **Enforcement**: Privacy violations can result in fines, user lawsuits, and reputational damage
- **Get legal review**: Before publishing, have a data privacy attorney in your jurisdiction review the policy
---
## Before You Publish
- [ ] Have a data privacy attorney review the policy
- [ ] Ensure the policy matches your actual data collection and use
- [ ] Make privacy request processes easy for users (accessible contact info, quick response)
- [ ] Implement technical measures mentioned in the policy (encryption, access controls, etc.)
- [ ] Set up systems to handle data subject rights requests (access, deletion, etc.)
- [ ] Document your legal basis for each type of processing
- [ ] Have a Data Processing Agreement (DPA) with all third-party processors
- [ ] Notify users of material changes; consider giving them a choice to opt-out
所有檔案
1 個檔案安裝 privacy-policy
將技能檔案下載並解壓至你的 .claude/skills/ 目錄。
下載 ZIP複製儲存庫並將技能檔案複製到您的專案中。
git clone https://github.com/phuryn/pm-skills/tree/main/pm-toolkit/skills/privacy-policy # Copy SKILL.md to your .claude/skills/ directory
複製





首頁
