← Files Rohas Legal AI: PrivacyARCHIVED FILE
skills/cross-border-transfer-analyst/SKILL.md
3.11 KB · Oct 5, 2026 · 18:30 UTC
--- name: cross-border-transfer-analyst description: >- Analyse cross-border personal-data transfers, remote access, hosting, support, disclosures, and onward transfers. Use when identifying applicable transfer restrictions, roles, localisation rules, mechanisms, destination risks, supplementary safeguards, notices, approvals, and operational controls. --- # Cross-Border Transfer Analyst Analyse the concrete transfer, not merely the vendor's headquarters. Include remote access, support, backups, telemetry, subprocessors, government requests, and onward transfers. ## Intake Obtain exporters, importers, affiliates, controllers and processors, origin and destination countries, data subjects and categories, sensitivity, purpose, frequency, systems, storage and access locations, vendors and subprocessors, retention, legal bases, sector rules, existing mechanisms, contracts, technical controls, and government-access experience. ## Analysis method 1. Draw the end-to-end transfer map and separate collection, disclosure, remote access, transit, storage, onward transfer, repatriation, and deletion. 2. Identify each law's territorial scope and the parties' legal roles. Distinguish a regulated transfer from processing already directly subject to that law. 3. Verify whether localisation, approved-country, adequacy, government approval, registration, sector, secrecy, employment, health, financial, or public-record restrictions apply. 4. Select and verify an available mechanism: adequacy, standard clauses, binding corporate rules, certification, code, consent or another narrow derogation, statutory permission, or local contract. Do not combine incompatible tools. 5. Complete required annexes with specific parties, data, purposes, frequency, retention, security, onward transfers, authority, governing law, and modules. 6. Assess destination law and practice, government-access powers, remedies, transparency, importer experience, data sensitivity, access likelihood, and whether the mechanism can operate in practice. 7. Identify supplementary technical, contractual, and organisational measures, including strong encryption, key control, pseudonymisation, minimisation, split processing, access limits, challenge and notice duties, and audit evidence. 8. Test onward transfers, subprocessor change, merger, remote support, disaster recovery, law-enforcement requests, and termination. 9. Align records, notices, DPA, SCC or equivalent, DPIA, security, retention, procurement, and data-subject response processes. 10. Set approval, implementation, reassessment, suspension, and escalation triggers. ## Output Provide the transfer map, law and role matrix, mechanism analysis, transfer-risk assessment, supplementary-measures plan, contract and notice changes, approval record, and reassessment calendar. ## Guardrails Do not treat a contract as sufficient without operational safeguards, use consent as a routine substitute where invalid, or assume cloud location equals all access locations. Verify current adequacy, clause versions, localisation, regulator guidance, and destination law with qualified counsel.
SHA-256: 0ed83e0a0c98553c76f06d99d92b03e379b92f7c03fe238c46db71b6a6122f04