45% OFF Launch Sale. Learn AI for your job with 332+ courses. Certificates included. Ends . Enroll now →

Lessons 1-2 Free Intermediate

Claude Privacy-Legal Plugin

Run Anthropic's privacy-legal plugin: 7 skills for DPA review (bi-directional), DSAR response, PIA generation, use-case triage, regulation gap analysis, and policy drift monitoring. GDPR + CCPA + state law coverage. 8 lessons + certificate.

8 lessons
2.5 hours
Certificate Included

Anthropic shipped a privacy counsel plugin on May 12, 2026 — and it knows controller vs processor out of the box

The privacy-legal plugin covers in-house privacy counsel workflows: DPA review (bi-directional — customer-side defends operational flex, vendor-side protects data), DSAR response drafting under GDPR + CCPA + state laws, PIA generation in house format, use-case triage for new processing activities, regulation gap analysis when new privacy laws emerge, and policy drift monitoring against actual practice.

The plugin learns from your seed documents: your privacy policy URL, your standard DPA template, and one reference PIA you’re happy with. From these, it captures your actual positions and house style. Subsequent skills apply your positions automatically — DPA reviews flag where the counterparty’s terms deviate from your playbook; PIA generation produces output in your house format; use-case triage applies your firm’s risk thresholds.

This course walks the 7 skills: cold-start-interview, use-case-triage, dpa-review, dsar-response, pia-generation, reg-gap-analysis, policy-monitor. You’ll learn GDPR’s Article 35 DPIA criteria, CCPA’s DSAR identity verification requirements, the controller-vs-processor flip across DPAs, Schrems II and SCC (Standard Contractual Clauses) compliance, state law variations (CCPA / CPRA / VA / CO / CT / UT / NJ / KY / NE / TX), and the policy-monitor drift detection that catches when your practice has diverged from your stated policy.

You’ll come out with a CLAUDE.md profile at ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md, a sample DSAR response file demonstrating GDPR + CCPA workflow, sample PIA in your house format, and a credential (PRIV-XXXXXX) documenting the work. The plugin costs nothing beyond your Claude Pro subscription. The operating discipline this course teaches is the difference between AI that helps with privacy work and AI that you’d actually deploy on a regulator inquiry.

What You'll Learn

  • Install and cold-start the privacy-legal plugin with your privacy policy + DPA template + reference PIA as seed documents
  • Run `dpa-review` bi-directionally (customer DPA vs vendor DPA) and produce playbook-aligned redlines
  • Operate `dsar-response` workflow (verify identity → walk systems → apply exemptions → draft response) under GDPR + CCPA + state law
  • Generate PIAs via `pia-generation` with house format + policy consistency check; classify PIA vs DPIA requirements
  • Apply `use-case-triage` for PROCEED / PIA REQUIRED / DPIA MANDATORY / STOP decisions on new processing activities

After This Course, You Can

Run DPA reviews bi-directionally — customer DPAs (defend operational flex) and vendor DPAs (protect data) — in 15-20 minutes each
Handle DSAR requests under GDPR and CCPA with structured workflow (identity verify → system walk → exemptions → draft) that survives audit
Generate PIAs in your house format from intake questions, with automatic policy consistency check against your current privacy policy
Triage new processing activities (new feature, new vendor, new data type) with PROCEED / PIA REQUIRED / DPIA MANDATORY / STOP decisions in under 10 minutes
Run regulation gap analysis when a new privacy law is enacted (NJ, KY, NE, etc.) and produce a remediation plan against your current state

What You'll Build

Your Firm's Privacy CLAUDE.md Profile
Practice profile capturing controller/processor status, applicable regulations, DPA playbook positions, and house style — built from your privacy policy + DPA template + reference PIA.
Sample DSAR Response File
End-to-end DSAR walkthrough demonstrating identity verification, system walk, exemption application, and response draft for GDPR/CCPA.
Claude Privacy-Legal Plugin Certificate
Verifiable credential proving you can run all 7 skills bi-directionally (DPA), execute DSAR workflow, generate PIAs in house format, triage new use cases, and operate the policy-monitor drift detection.

Course Syllabus

Prerequisites

  • Active privacy counsel or program manager role
  • Recommended: The Hallucination Defense Playbook (HDP) for verification rail
  • Claude Cowork or Claude Code installed; ability to install plugins from the Anthropic marketplace

Who Is This For?

  • Privacy counsel (in-house + outside)
  • Privacy program managers handling DPAs, DSARs, vendor reviews
  • Product counsel for PIA on new features and launches
  • Support / CS leads handling DSAR first-line response
  • DPOs (EU + UK)
  • Compliance officers tracking multi-jurisdiction privacy regulation
The research says
56%
higher wages for professionals with AI skills
PwC 2025 AI Jobs Barometer
83%
of growing businesses have adopted AI
Salesforce SMB Survey
$3.50
return for every $1 invested in AI
Vena Solutions / Industry data
We deliver
250+
Courses
Teachers, nurses, accountants, and more
2
free lessons per course to try before you commit
Free account to start
9
languages with verifiable certificates
EN, DE, ES, FR, JA, KO, PT, VI, IT
Start Learning Now

Frequently Asked Questions

Does the plugin replace OneTrust, TrustArc, BigID, or similar privacy platforms?

Partially. The plugin's strength is the lawyer-facing analysis: DPA review, DSAR drafting, PIA generation, use-case triage. Platform vendors provide the operational layer (system inventory, automated DSAR routing, consent management). They complement: the plugin produces lawyer-quality analysis; the platforms automate the rest of the workflow.

Controller vs processor — how does the plugin handle the role flip?

Cold-start captures whether you're typically controller (you decide purposes and means), processor (you process for someone else), or both depending on activity. DPA review auto-detects direction (customer DPA = you defending operational flex as processor for them; vendor DPA = you protecting data as controller engaging them as processor).

How does the plugin handle multi-jurisdiction DSARs (e.g., a request from someone covered by both GDPR and CCPA)?

The dsar-response workflow handles the most-protective standard — typically GDPR if EU resident; CCPA if CA resident; both apply if data was collected before residence changes. The skill walks each applicable framework's identity verification, exemption analysis, and response requirements separately, then composes the response.

PIA vs DPIA — when does each apply?

PIA is your internal process for any new processing activity. DPIA is the GDPR Article 35 requirement for high-risk processing (large-scale special category data, systematic monitoring, etc.). The use-case-triage skill classifies — PIA REQUIRED for moderate-risk activities; DPIA MANDATORY when GDPR Article 35 criteria apply.

How does this work with other practice-area plugins?

Privacy-legal pairs with: Commercial-Legal (DPAs are commercial contracts), Employment-Legal (employee data privacy), Corporate-Legal (M&A privacy diligence), and HDP for the verification rail. Many firms run all of these as the practice-area plugin stack.

Related Skill Templates

2 Lessons Free