Comprehensive data privacy compliance assessment across 20 control areas and 63 individual controls. Covers data governance, mapping, policies, consent, security, retention, access control, privacy by design, training, incident response, vendor management, data subject rights, cross-border transfers, and more. Returns area-by-area scores with prioritized findings.
Built by a CISSP/CISM certified security professional at ToolWeb.in
TOOLWEB_API_KEY — Get your API key from portal.toolweb.incurl must be available on the systemPOST https://portal.toolweb.in/apis/compliance/data-privacy-checklist
| Area Key | Area Name | Controls | IDs |
|---|---|---|---|
| data_governance | Data Governance | 4 | dg.1, dg.2, dg.3, dg.4 |
| data_mapping | Data Mapping and Inventory | 3 | dm.1, dm.2, dm.3 |
| privacy_policies | Privacy Policies and Notices | 4 | pp.1, pp.2, pp.3, pp.4 |
| consent_management | Consent Management | 3 | cm.1, cm.2, cm.3 |
| data_minimization | Data Minimization | 3 | dmin.1, dmin.2, dmin.3 |
| data_security | Data Security | 4 | ds.1, ds.2, ds.3, ds.4 |
| data_retention | Data Retention and Disposal | 3 | dr.1, dr.2, dr.3 |
| access_control | Access Control | 3 | ac.1, ac.2, ac.3 |
| privacy_by_design | Privacy by Design | 3 | pbd.1, pbd.2, pbd.3 |
| employee_training | Employee Training | 3 | et.1, et.2, et.3 |
| incident_response | Incident Response and Breach Notification | 3 | ir.1, ir.2, ir.3 |
| vendor_management | Vendor Management | 3 | vm.1, vm.2, vm.3 |
| data_subject_rights | Data Subject Rights | 3 | dsr.1, dsr.2, dsr.3 |
| cross_border | Cross-Border Data Transfers | 3 | cb.1, cb.2, cb.3 |
| record_keeping | Record Keeping | 3 | rk.1, rk.2, rk.3 |
| privacy_audits | Privacy Audits and Assessments | 3 | pa.1, pa.2, pa.3 |
| breach_simulation | Data Breach Simulation | 3 | bs.1, bs.2, bs.3 |
| compliance_monitoring | Privacy Compliance Monitoring | 3 | cmon.1, cmon.2, cmon.3 |
| data_localization | Data Localization | 3 | dl.1, dl.2, dl.3 |
| privacy_communication | Privacy Communication | 3 | pc.1, pc.2, pc.3 |
Gather inputs from the user. For each control area, ask if they are compliant (yes/no). You can go area by area or ask about all areas at once.
Conversational approach: Ask the user about each area naturally:
Map their yes/no answers to the control IDs for each area.
Build the controls object from user responses:
{
"data_governance": [
{"controlId": "dg.1", "compliant": true, "notes": ""},
{"controlId": "dg.2", "compliant": false, "notes": "No formal DPO appointed"},
{"controlId": "dg.3", "compliant": true, "notes": ""},
{"controlId": "dg.4", "compliant": false, "notes": ""}
],
"consent_management": [
{"controlId": "cm.1", "compliant": true, "notes": ""},
{"controlId": "cm.2", "compliant": false, "notes": ""},
{"controlId": "cm.3", "compliant": false, "notes": ""}
]
}
curl -s -X POST "https://portal.toolweb.in/apis/compliance/data-privacy-checklist" \
-H "Content-Type: application/json" \
-H "X-API-Key: $TOOLWEB_API_KEY" \
-d '{
"tier": "standard",
"controls": {
"data_governance": [
{"controlId": "dg.1", "compliant": true},
{"controlId": "dg.2", "compliant": false},
{"controlId": "dg.3", "compliant": true},
{"controlId": "dg.4", "compliant": false}
],
"data_mapping": [
{"controlId": "dm.1", "compliant": true},
{"controlId": "dm.2", "compliant": false},
{"controlId": "dm.3", "compliant": false}
]
},
"sessionId": "<unique-id>"
}'
Tip: You don't need to include all 20 areas — the API will score missing areas as 0% compliant. Include only the areas the user has provided answers for, or include all with best-effort mapping.
✅ Data Privacy Checklist Assessment
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Overall Compliance: [XX]%
Total Controls: 63 | Compliant: [X] | Non-Compliant: [X]
📊 Area Scores:
✅ Data Governance: [X]% (X/4)
✅ Data Mapping: [X]% (X/3)
✅ Privacy Policies: [X]% (X/4)
⚠️ Consent Management: [X]% (X/3)
❌ Incident Response: [X]% (X/3)
... [all 20 areas]
🚨 Critical Findings:
[List top non-compliant controls with highest risk]
📋 Priority Actions:
1. [Most urgent remediation]
2. [Next priority]
3. [Next priority]
📎 Full report powered by ToolWeb.in
发现更多技能插件,请访问7w4.net。
TOOLWEB_API_KEY is not set: Tell the user to get an API key from https://portal.toolweb.incontrolId and compliantUser: "Run a data privacy checklist for our company"
Agent flow:
Created by ToolWeb.in — a security-focused MicroSaaS platform with 200+ security APIs, built by a CISSP & CISM certified professional. Trusted by security teams in USA, UK, and Europe and we have platforms for "Pay-per-run", "API Gateway", "MCP Server", "OpenClaw", "RapidAPI" for execution and YouTube channel for demos.
这个 Skill 质量不错,能有效引导用户完成隐私合规评估。它把复杂的 63 项检查点组织得清晰易懂,对话流程设计合理,错误提示也很完善。不过它依赖外部付费 API 服务才能工作,没有免费本地评估的能力,而且文档有些地方重复、末尾内容不完整。整体适合需要专业隐私评估的用户,但不适合寻求免费离线工具的场景。