Privacy and website compliance specialist
cg-web-privacy
Its job is not to produce a generic template. It writes the privacy policy, and checks the technical implementation behind it, from the website that is actually running.
1
Current law first, from primary sources
Before any legal statement, Claude searches the web and checks the current state: EUR-Lex and gesetze-im-internet.de, the German data protection authorities and the DSK, the EDPB, relevant case law, and the official documentation of each provider in use. Blog posts and policy generators are not primary sources, and the result carries its research date and sources.
Never use an outdated legal position just because an earlier template contains it.
cg-web-privacy · SKILL.md · translated from German2
The website before the text
Claude inventories what the site really does: pages, forms, cookies, local and session storage, fonts, embeds, maps, videos, analytics, pixels, captchas, consent management, hosting, CDN, email and AI services. It checks the code too — dependencies, script tags, API routes, middleware, server actions — and records each processing with purpose, legal basis, recipients, transfers, retention and a status. Only verified or confirmed facts go into the final policy.
For a Next.js website in particular, check whether a third party receives data not in the visible frontend but server-side via API routes or Server Components.
cg-web-privacy · SKILL.md · translated from German5
§ 25 TDDDG and the GDPR, kept apart
Storing or reading information on the device is one question; the processing of personal data that follows is another. Claude checks both, including local storage, SDKs, pixels and fingerprinting, not just classic cookies. Where consent is required, nothing that needs it loads before it, no category is pre-ticked, and withdrawing consent is as easy as giving it.
Do not add a cookie banner just because “cookies exist”.
cg-web-privacy · SKILL.md · translated from German12
Policy, banner and code in sync
When a consent management system exists, provider, purpose, category, legal basis, storage mechanism, recipient and third country have to match everywhere. Claude checks all four directions: does the policy claim something the code doesn't do, does the code do something the policy leaves out, does the banner really block, and does the banner say the same as the policy?
Are scripts that require consent really blocked before consent?
cg-web-privacy · SKILL.md · translated from GermanWhat it never does
Whatever it cannot find in the site, the code, the configuration or a reliable current source, the skill asks for — the controller, a data protection officer, the hosting provider, retention periods — in a compact table. Until then, the policy is not presented as finished:
Never guess. Never present placeholders as finished facts. Never invent a legal basis or a retention period.
cg-web-privacy · SKILL.md · translated from GermanHow it works when you just say “write the privacy policy”
The skill's default workflow. The text comes sixth: before it, the site is examined, the law researched, the processing inventoried and the gaps asked for; after it, the banner is checked against it and the final text is checked against the law again.
- Examine the website/project
- Research the current law
- Inventory the processing
- Research unclear providers/features
- Ask for missing information
- Write the privacy policy
- Check the consent banner against it
- Name technical privacy problems
- Re-check against the current law
Try asking Claude
- Write the privacy policy for this website.
- Check our privacy policy against what the site actually loads.
- Does our cookie banner match the privacy policy? Are scripts blocked before consent?
- We added Google Maps and a newsletter. Update the privacy policy.
$ npx cg-web-skills@latest install cg-web-privacy