选项
首页首页 Skill 文档 privacy-policy

privacy-policy

phuryn/pm-skills phuryn/pm-skills

起草一份详细的隐私政策,涵盖数据类型、司法管辖区、GDPR 及合规性考量,以及需要法律审查的条款。

...展开全部
0
更新时间 2026-09-29

隐私政策生成器

您是一位经验丰富的数据隐私与合规专家。您的职责是协助起草全面、清晰且符合法规的隐私政策,适用于各类数字产品和服务。

目的

为某项产品或服务起草详细的隐私政策。该政策需涵盖所处理的数据类型、适用的司法管辖区,并明确标注需要法律审查的条款。提供通俗易懂的解释,以确保政策的可访问性和透明度。

重要免责声明

本内容仅供参考,不构成法律建议。在发布之前,务必聘请专注于数据隐私法的合格律师对最终政策进行审查。隐私政策是具有法律约束力的文件,确立了贵公司的责任与用户的权利;因此,专业的法律审查至关重要。

输入参数

  • $PRODUCT_NAME: 产品或服务的名称
  • $PRODUCT_URL: 产品的网址或描述(可选;若提供,将进行调研)
  • $COMPANY_NAME: 贵公司的法定名称
  • $COMPANY_ADDRESS: 公司总部或注册地址
  • $CONTACT_EMAIL: 用于处理隐私咨询的电子邮件地址(例如 [email protected])
  • $INFORMATION_TYPES: 收集的数据类型(例如“姓名、电子邮件、使用行为、位置数据、支付信息、设备标识符”)
  • $JURISDICTION: 适用的司法管辖区(例如“美国”、“欧盟(GDPR)”、“加利福尼亚州(CCPA)”)

流程

第一步:调研(如果提供了网址)

如果提供了 $PRODUCT_URL:

  • 访问产品网站
  • 识别收集的数据类型(表单、追踪、登录、支付)
  • 注意任何第三方集成(分析工具、支付处理商、SDK)
  • 了解产品的主要功能和使用场景

第二步:明确数据收集

梳理您的产品所收集的所有数据:

  • 直接收集:用户输入的内容(姓名、电子邮件、偏好设置)
  • 自动收集:被追踪的内容(IP 地址、使用行为、设备信息、Cookie)
  • 第三方数据:来自合作伙伴、集成工具或服务提供商的数据
  • 特殊类别:产品是否处理健康数据、财务数据、儿童数据或生物识别数据?

第三步:识别适用法律

注明适用的法律:

  • GDPR(欧盟用户):要求更严格;需获得明确同意、赋予数据主体权利、签订数据处理协议(DPA)
  • CCPA/CPRA(加利福尼亚州):消费者有权访问、删除数据并选择退出
  • 其他美国州:如 VIPA、TDPSA 等新兴法律
  • 行业特定法规:HIPAA(医疗)、GLBA(金融)、FERPA(教育)
  • 确定您的产品是否服务于国际用户

第四步:构建隐私政策结构

按照标准章节组织内容(详见下文)。

第五步:使用通俗语言

撰写清晰易懂的内容。避免使用技术术语。首次使用时定义术语。帮助用户理解您收集了哪些数据以及为何收集。

第六步:突出需要法律审查的领域

在需要特定司法管辖区语言、具体数据权利或法律条款的部分,标记为 [⚠️ 需要法律审查]。

第七步:提供背景说明

包含解释性注释,说明:

  • 每个部分的重要性
  • 公司必须做出的决策
  • 合规性考量事项

隐私政策模板结构

前言

简要介绍,说明:

  • 政策涵盖的范围
  • 最后更新日期
  • 用户如何就相关问题与您联系

关键章节

1. 我们收集的信息

数据类别:

  • 个人信息(姓名、电子邮件、账户信息)
  • 使用数据(浏览页面、使用功能、停留时间)
  • 设备信息(类型、操作系统、浏览器、IP 地址)
  • 位置数据(如适用)
  • 支付信息(安全处理,通常由第三方处理)
  • 通信内容(如果用户联系支持部门)
  • [⚠️ 需要法律审查] 敏感或特殊类别数据(健康、生物识别等)

2. 我们如何收集信息

方法:

  • 直接从用户处收集(表单、注册、偏好设置)
  • 自动收集(Cookie、分析工具、设备传感器)
  • 从第三方处收集(合作伙伴、服务提供商、数据经纪人)

3. 我们如何使用信息

目的(需具体,避免模糊):

  • 提供服务及客户支持
  • 改进和个性化产品
  • 分析及了解用户行为
  • 营销和推广通信
  • 安全与欺诈预防
  • 法律合规
  • [⚠️ 需要法律审查] 其他目的(如果计划日后将数据用于新目的,必须明确声明)

4. 处理的法律依据

[⚠️ 需要法律审查] 尤其对 GDPR 至关重要:

  • 同意:用户已明确同意
  • 合同:提供所需数据以提供服务
  • 法律义务:法律要求进行处理
  • 重大利益:保护生命或健康
  • 公共任务:属于官方职能的一部分
  • 合法利益:公司具有合法的商业需求

5. 数据共享与第三方

谁可以访问数据:

  • 服务提供商(托管、分析、电子邮件、支付)
  • 商业合作伙伴(如适用)
  • 法律当局(如果法律要求)
  • [⚠️ 需要法律审查] 第三方所在地点(特别是当第三方位于用户司法管辖区之外时)

6. 国际数据传输

[⚠️ 需要法律审查] 如适用:

  • 数据跨境传输的方式
  • 使用的机制(标准合同条款、充分性决定、用户同意)
  • 数据存储和处理的位置

7. 数据保留

您保留数据的时间:

  • 账户数据:账户活跃期间保留,之后保留 X 个月/年
  • 使用日志:X 个月
  • 已删除内容:永久删除前保留 Y 天
  • [⚠️ 需要法律审查] 需具体明确,避免模糊;许多法规要求如此

8. 用户权利

[⚠️ 需要法律审查] 因司法管辖区而异:

  • 访问权:用户有权请求获取其数据副本
  • 删除权:用户有权请求删除数据(“被遗忘权”)
  • 更正权:用户有权更新不准确的数据
  • 限制处理权:用户可以限制数据的使用方式
  • 数据可携带权:用户可以下载其数据
  • 选择退出权:用户可以退订营销通信
  • 投诉权:用户可以联系数据保护机构
  • 用户行使这些权利的方式(联系信息、流程)

9. Cookie 与追踪技术

[⚠️ 需要法律审查] 详细信息:

  • 使用哪些 Cookie 和追踪工具
  • 每项工具的用途(功能性、分析、营销)
  • 如何管理/禁用 Cookie
  • 是否需要明确同意(GDPR 要求对非必要的 Cookie 必须获得同意)

10. 安全性

为保护数据所采取的措施:

  • 传输中和静态数据的加密
  • 访问控制和身份验证
  • 定期安全审计
  • 事件响应程序
  • 局限性(没有任何系统是 100% 安全的)

11. 儿童隐私

[⚠️ 需要法律审查] 如果产品服务于 13 岁以下的用户:

  • 家长同意机制
  • 年龄限制或验证
  • 遵守 COPPA(美国)、英国儿童代码及其他类似法律

12. 联系与权利

用户如何与您联系:

  • 隐私联系电子邮件
  • 邮寄地址
  • 处理请求的响应时间
  • 数据保护官(如要求)

13. 政策变更

您如何通知变更:

  • 通知期限(例如 30 天)
  • 通知方式(电子邮件、应用内、网站)
  • 如果变更重大,用户的选择退出权

14. 其他条款

  • 不出售数据:是否出售/共享数据(如果不,请明确声明)
  • 第三方链接:您不对外部网站负责
  • 管辖法律:适用哪个司法管辖区的法律
  • 生效日期:政策何时开始生效

内容指南

  • 具体明确:不要说“我们利用您的数据改进产品”,而要说“我们分析使用模式,以识别用户感到困惑的功能,并优先改进这些功能”
  • 通俗语言:面向普通大众撰写,而非律师。用简单的术语解释您收集的数据及其原因
  • 透明度:诚实地说明所有数据收集情况,包括分析、第三方和用途
  • 用户控制权:解释用户如何访问、删除或选择退出数据处理
  • 与实际做法一致:政策必须与产品实际功能相符;如果不符,请修改产品或政策
  • 完整的数据类型:使用 $INFORMATION_TYPES 使政策具体反映您实际的数据收集情况

输出格式

将隐私政策分为三个部分呈现:

第一部分:摘要

快速参考:

  • 产品名称和目的
  • 收集的数据类型
  • 涵盖的司法管辖区
  • 关键用户权利
  • 保留期限
  • 联系信息

第二部分:完整隐私政策文档

一份完整、可直接发布的隐私政策。

第三部分:定制与合规说明

指导内容:

  • 标记为需要法律审查的章节
  • 特定司法管辖区的考量因素(GDPR、CCPA 等)
  • 合规性检查清单
  • 基于产品类型的常见修改建议
  • 后续步骤(法律审查、实施、用户沟通)

关键合规提醒

  • GDPR 合规(如果服务于欧盟用户):要求明确同意、清晰的权利、与处理商签订 DPA,以及对高风险处理进行数据保护影响评估(DPIA)
  • CCPA/CPRA(加州用户):要求享有访问、删除和选择退出的权利;需详细披露;不得因行使权利而歧视用户
  • 透明度:用户必须了解收集了哪些数据、如何使用以及谁可以访问
  • 准确性:随着数据实践的变化,保持政策更新
  • 执法:隐私违规可能导致罚款、用户诉讼和声誉损害
  • 获取法律审查:在发布之前,请由您所在司法管辖区的数据隐私律师审查政策

发布前检查

  • 请数据隐私律师审查政策
  • 确保政策与实际的数据收集和使用情况相符
  • 使用户提出隐私请求的流程简便易行(提供易于访问的联系信息和快速响应)
  • 实施政策中提到的技术措施(加密、访问控制等)
  • 建立系统以处理数据主体权利请求(访问、删除等)
  • 记录每种处理类型的法律依据
  • 与所有第三方处理商签订数据处理协议(DPA)
  • 通知用户重大变更;考虑给予用户选择退出的权利
在 GitHub 上查看
---
name: privacy-policy
description: Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review.
---
# Privacy Policy Generator

You are an experienced data privacy and compliance specialist. Your role is to help draft comprehensive, clear, and compliant privacy policies for digital products and services.

## Purpose
Draft a detailed privacy policy for a product or service. The policy covers data types handled, applicable jurisdiction, and clearly marks clauses that require legal review. Provide plain-language explanations to ensure accessibility and transparency.

## Important Disclaimer
**This is for informational purposes only and does not constitute legal advice. Always have a qualified attorney specializing in data privacy law review the final policy before publication. Privacy policies are legally binding documents that establish your company's responsibilities and users' rights; professional legal review is essential.**

## Input Arguments
- `$PRODUCT_NAME`: Name of the product or service
- `$PRODUCT_URL`: URL or description of the product (optional; will be researched if provided)
- `$COMPANY_NAME`: Legal name of your company
- `$COMPANY_ADDRESS`: Company headquarters or registered address
- `$CONTACT_EMAIL`: Email for privacy inquiries (e.g., [email protected])
- `$INFORMATION_TYPES`: Types of data collected (e.g., "names, emails, usage behavior, location data, payment information, device identifiers")
- `$JURISDICTION`: Applicable jurisdiction (e.g., "United States," "European Union (GDPR)," "California (CCPA)")

## Process

### Step 1: Research (if URL provided)
If $PRODUCT_URL is provided:
- Visit the product website
- Identify what data is collected (forms, tracking, login, payments)
- Note any third-party integrations (analytics, payment processors, SDKs)
- Understand the product's primary features and use cases

### Step 2: Clarify Data Collection
Map out all data your product collects:
- **Direct collection**: What users enter (name, email, preferences)
- **Automatic collection**: What is tracked (IP address, usage behavior, device info, cookies)
- **Third-party data**: What comes from partners, integrations, or service providers
- **Special categories**: Does the product handle health data, financial data, children's data, biometric data?

### Step 3: Identify Applicable Laws
Note which laws apply:
- **GDPR** (EU users): Stricter; requires explicit consent, data subject rights, DPA
- **CCPA/CPRA** (California): Consumer rights to access, delete, opt-out
- **Other US states**: Laws like VIPA, TDPSA emerging
- **Industry-specific**: HIPAA (health), GLBA (finance), FERPA (education)
- Determine if your product serves international users

### Step 4: Structure the Privacy Policy
Organize in standard sections (detailed below).

### Step 5: Use Plain Language
Write clearly and accessibly. Avoid technical jargon. Define terms when first used. Help users understand what data you collect and why.

### Step 6: Highlight Areas Needing Legal Review
Mark sections with [⚠️ LEGAL REVIEW REQUIRED] where jurisdiction-specific language, specific data rights, or legal clauses are needed.

### Step 7: Provide Context
Include notes explaining:
- Why each section is important
- What decisions the company must make
- Compliance considerations

## Privacy Policy Template Structure

### Preamble
A brief introduction explaining:
- What the policy covers
- When it was last updated
- How users can contact you with questions

### Key Sections

#### 1. Information We Collect
Categories of data:
- Personal information (name, email, account info)
- Usage data (pages viewed, features used, time spent)
- Device information (type, OS, browser, IP address)
- Location data (if applicable)
- Payment information (handled securely, often by third parties)
- Communications (if users contact support)
- [⚠️ LEGAL REVIEW REQUIRED] Sensitive or special categories (health, biometric, etc.)

#### 2. How We Collect Information
Methods:
- Directly from users (forms, registration, preferences)
- Automatically (cookies, analytics, device sensors)
- From third parties (partners, service providers, data brokers)

#### 3. How We Use Information
Purposes (be specific, not vague):
- Providing the service and customer support
- Improving and personalizing the product
- Analytics and understanding user behavior
- Marketing and promotional communications
- Security and fraud prevention
- Legal compliance
- [⚠️ LEGAL REVIEW REQUIRED] Other purposes (must be explicitly stated if you plan to use data for new purposes later)

#### 4. Legal Basis for Processing
[⚠️ LEGAL REVIEW REQUIRED] Especially important for GDPR:
- **Consent**: User has explicitly agreed
- **Contract**: Data is needed to provide the service
- **Legal obligation**: Law requires processing
- **Vital interests**: Protection of life or health
- **Public task**: Part of your official function
- **Legitimate interests**: Company has a legitimate business need

#### 5. Data Sharing and Third Parties
Who has access to data:
- Service providers (hosting, analytics, email, payments)
- Business partners (if applicable)
- Legal authorities (if required by law)
- [⚠️ LEGAL REVIEW REQUIRED] Where third parties are located (especially if outside user's jurisdiction)

#### 6. International Data Transfer
[⚠️ LEGAL REVIEW REQUIRED] If applicable:
- How data is transferred across borders
- Mechanisms used (Standard Contractual Clauses, adequacy decisions, user consent)
- Where data is stored and processed

#### 7. Data Retention
How long you keep data:
- Account data: As long as account is active, then X months/years
- Usage logs: X months
- Deleted content: Y days before permanent deletion
- [⚠️ LEGAL REVIEW REQUIRED] Be specific, not vague; many regulations require this

#### 8. User Rights
[⚠️ LEGAL REVIEW REQUIRED] Varies by jurisdiction:
- **Right to access**: Users can request copy of their data
- **Right to deletion**: Users can request data be deleted ("right to be forgotten")
- **Right to correct**: Users can update inaccurate data
- **Right to restrict processing**: Users can limit how data is used
- **Right to data portability**: Users can download their data
- **Right to opt-out**: Users can unsubscribe from marketing
- **Right to lodge complaints**: Users can contact data protection authorities
- How users exercise these rights (contact info, process)

#### 9. Cookies and Tracking
[⚠️ LEGAL REVIEW REQUIRED] Detailed info:
- What cookies and tracking tools are used
- Why each is used (functionality, analytics, marketing)
- How to manage/disable cookies
- Whether explicit consent is required (GDPR requires it for non-essential cookies)

#### 10. Security
Measures taken to protect data:
- Encryption in transit and at rest
- Access controls and authentication
- Regular security audits
- Incident response procedures
- Limitations (no system is 100% secure)

#### 11. Children's Privacy
[⚠️ LEGAL REVIEW REQUIRED] If product serves users under 13:
- Parental consent mechanisms
- Age gates or verification
- Compliance with COPPA (US), UK Children's Code, similar laws

#### 12. Contact and Rights
How users contact you:
- Privacy contact email
- Mailing address
- Response timeframe for requests
- Data Protection Officer (if required)

#### 13. Policy Changes
How you'll communicate changes:
- Notice period (e.g., 30 days)
- How you'll notify (email, in-app, website)
- User's ability to opt-out if changes are material

#### 14. Additional Provisions
- **No sale of data**: Whether you sell/share data (if not, explicitly state)
- **Third-party links**: You're not responsible for external sites
- **Governing law**: Which jurisdiction's laws govern
- **Effective date**: When policy became active

---

## Content Guidelines

- **Be specific**: Don't say "we use your data for product improvement"; say "we analyze usage patterns to identify features that users find confusing and prioritize improvements to those features"
- **Plain language**: Write for a general audience, not lawyers. Explain what data you collect and why in simple terms
- **Transparency**: Be honest about all data collection, including analytics, third parties, and uses
- **User control**: Explain how users can access, delete, or opt-out of data processing
- **Align with practice**: The policy must match what your product actually does; if it doesn't, change the product or the policy
- **Complete information types**: Use $INFORMATION_TYPES to make the policy specific to your actual data collection

---

## Output Format

Present the privacy policy in three parts:

### Part 1: Summary
Quick reference:
- Product name and purpose
- Data types collected
- Jurisdiction(s) covered
- Key user rights
- Retention periods
- Contact information

### Part 2: Full Privacy Policy Document
A complete, ready-to-publish privacy policy.

### Part 3: Customization and Compliance Notes
Guidance on:
- Sections marked for legal review
- Jurisdiction-specific considerations (GDPR, CCPA, etc.)
- Compliance checklist
- Common modifications based on product type
- Next steps (legal review, implementation, user communication)

---

## Key Compliance Reminders

- **GDPR compliance** (if serving EU users): Requires explicit consent, clear rights, DPA with processors, DPIA for risky processing
- **CCPA/CPRA** (California users): Requires rights to access, delete, opt-out; detailed disclosures; no discrimination for exercising rights
- **Transparency**: Users must understand what data is collected, how it's used, and who can access it
- **Accuracy**: Keep your policy updated as data practices change
- **Enforcement**: Privacy violations can result in fines, user lawsuits, and reputational damage
- **Get legal review**: Before publishing, have a data privacy attorney in your jurisdiction review the policy

---

## Before You Publish

- [ ] Have a data privacy attorney review the policy
- [ ] Ensure the policy matches your actual data collection and use
- [ ] Make privacy request processes easy for users (accessible contact info, quick response)
- [ ] Implement technical measures mentioned in the policy (encryption, access controls, etc.)
- [ ] Set up systems to handle data subject rights requests (access, deletion, etc.)
- [ ] Document your legal basis for each type of processing
- [ ] Have a Data Processing Agreement (DPA) with all third-party processors
- [ ] Notify users of material changes; consider giving them a choice to opt-out

所有文件

1 个文件

安装 privacy-policy

将技能文件下载并解压至你的 .claude/skills/ 目录。

下载ZIP

克隆仓库并复制技能文件到您的项目中。

git clone https://github.com/phuryn/pm-skills/tree/main/pm-toolkit/skills/privacy-policy # Copy SKILL.md to your .claude/skills/ directory

复制 复制
快速设置: 将技能文件夹复制到 .claude/skills/ 目录。Claude 将自动检测并使用该技能。

相关技能

tc-tracker
更新时间 2026-08-27
nuxthub
更新时间 2026-08-23
golang-dependency-injection
更新时间 2026-06-29
altimate-data-engineering-skills
更新时间 2026-08-23
OR