← Files Rohas Legal AI: PrivacyARCHIVED FILE

skills/cross-border-transfer-analyst/SKILL.md

3.11 KB · Oct 4, 2026 · 12:29 UTC

↓ Download file

---
name: cross-border-transfer-analyst
description: >-
  Analyse cross-border personal-data transfers, remote access, hosting, support,
  disclosures, and onward transfers. Use when identifying applicable transfer
  restrictions, roles, localisation rules, mechanisms, destination risks,
  supplementary safeguards, notices, approvals, and operational controls.
---

# Cross-Border Transfer Analyst

Analyse the concrete transfer, not merely the vendor's headquarters. Include
remote access, support, backups, telemetry, subprocessors, government requests,
and onward transfers.

## Intake

Obtain exporters, importers, affiliates, controllers and processors, origin and
destination countries, data subjects and categories, sensitivity, purpose,
frequency, systems, storage and access locations, vendors and subprocessors,
retention, legal bases, sector rules, existing mechanisms, contracts, technical
controls, and government-access experience.

## Analysis method

1. Draw the end-to-end transfer map and separate collection, disclosure, remote
   access, transit, storage, onward transfer, repatriation, and deletion.
2. Identify each law's territorial scope and the parties' legal roles. Distinguish
   a regulated transfer from processing already directly subject to that law.
3. Verify whether localisation, approved-country, adequacy, government approval,
   registration, sector, secrecy, employment, health, financial, or public-record
   restrictions apply.
4. Select and verify an available mechanism: adequacy, standard clauses, binding
   corporate rules, certification, code, consent or another narrow derogation,
   statutory permission, or local contract. Do not combine incompatible tools.
5. Complete required annexes with specific parties, data, purposes, frequency,
   retention, security, onward transfers, authority, governing law, and modules.
6. Assess destination law and practice, government-access powers, remedies,
   transparency, importer experience, data sensitivity, access likelihood, and
   whether the mechanism can operate in practice.
7. Identify supplementary technical, contractual, and organisational measures,
   including strong encryption, key control, pseudonymisation, minimisation,
   split processing, access limits, challenge and notice duties, and audit evidence.
8. Test onward transfers, subprocessor change, merger, remote support, disaster
   recovery, law-enforcement requests, and termination.
9. Align records, notices, DPA, SCC or equivalent, DPIA, security, retention,
   procurement, and data-subject response processes.
10. Set approval, implementation, reassessment, suspension, and escalation triggers.

## Output

Provide the transfer map, law and role matrix, mechanism analysis, transfer-risk
assessment, supplementary-measures plan, contract and notice changes, approval
record, and reassessment calendar.

## Guardrails

Do not treat a contract as sufficient without operational safeguards, use consent
as a routine substitute where invalid, or assume cloud location equals all access
locations. Verify current adequacy, clause versions, localisation, regulator
guidance, and destination law with qualified counsel.

SHA-256: 0ed83e0a0c98553c76f06d99d92b03e379b92f7c03fe238c46db71b6a6122f04