Mmcp.market

conflicting-laws-mgmt skill

by ThomasMoreAI·ThomasMoreAI/legal-skills-open·79 stars·Apache-2.0

Guides managing conflicting privacy requirements across jurisdictions. Covers data localisation vs transfer freedom, consent standards variation, age thresholds, breach timelines, and resolution frameworks for incompatible obligations. Keywords: conflicting laws, data localisation, consent variation, age thresholds, resolution framework.

A100/100content scan

Is the conflicting-laws-mgmt skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the conflicting-laws-mgmt skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open
mkdir -p ~/.claude/skills
cp -r /tmp/legal-skills-open/cross-jurisdiction/data-protection/skills/conflicting-laws-mgmt ~/.claude/skills/conflicting-laws-mgmt
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Managing Conflicting Privacy Requirements

Overview

Organisations operating across multiple jurisdictions inevitably encounter situations where privacy requirements in different countries conflict, are incompatible, or create compliance tensions. These conflicts arise because privacy laws reflect different legal traditions, cultural values, and policy priorities. A structured resolution framework enables organisations to navigate these conflicts while maintaining defensible compliance positions in all jurisdictions.

Categories of Conflict

Category 1: Data Localisation vs Transfer Freedom

Resolution Framework for Zenith Global Enterprises:

Category 2: Consent Standards Variation

Conflict examples:

  • GDPR allows legitimate interest without consent; PIPL requires consent as default with no legitimate interest basis
  • LGPD separates consent from contract clauses; some jurisdictions permit integrated consent
  • Korea prescribes font size and display; other jurisdictions are principle-based

Resolution: Apply the most restrictive consent standard globally (separate, explicit, purpose-specific consent with clear display) as the harmonised baseline. Where a jurisdiction permits processing without consent (e.g., GDPR legitimate interest), document the jurisdiction-specific basis but maintain the consent infrastructure as a fallback.

Category 3: Age Thresholds for Children

Conflict: Different age thresholds create operational complexity for global platforms.

Resolution: Apply the highest global threshold (18, from India DPDP) as the harmonised standard for all markets. This ensures compliance everywhere at the cost of stricter treatment in jurisdictions with lower thresholds. Where the highest threshold creates significant business impact, implement jurisdiction-specific age logic in the consent management platform.

Category 4: Breach Notification Timelines

Conflict: The 72-hour clock (EU/Korea/India) conflicts with the 30-day assessment window (Singapore/Australia).

Resolution: Implement a two-track notification process:

  1. Global fast track: Begin assessment immediately upon awareness; prepare notification within 72 hours for jurisdictions requiring it
  2. Assessment track: Continue assessment for up to 30 days for jurisdictions permitting it, but issue preliminary notification at 72 hours to the fast-track jurisdictions
  3. Content: Preliminary 72-hour notification may be updated as assessment continues

Category 5: Legitimate Interest Availability

Conflict: An organisation relying on legitimate interest in the EU cannot use the same basis in China, India, or Singapore.

Resolution: For processing activities that rely on legitimate interest in some jurisdictions, maintain consent collection infrastructure as a parallel mechanism. In jurisdictions without legitimate interest, obtain consent or identify an applicable alternative basis. Document both bases in the processing register with jurisdiction-specific applicability.

Category 6: DPO Independence vs Organisational Structure

Resolution: Appoint regional DPOs with local employment protections consistent with national law, reporting to a global Chief Privacy Officer. Each regional DPO holds the statutory DPO role for their jurisdiction while the global CPO provides strategic coordination.

Resolution Framework

Decision Tree for Conflicting Requirements

START: Identify the conflict
  |
  ├── Can a single harmonised standard satisfy all jurisdictions?
  |     |
  |     ├── YES → Apply the most stringent standard globally
  |     |
  |     └── NO → Are the requirements truly incompatible?
  |           |
  |           ├── YES → Implement jurisdiction-specific controls
  |           |     |
  |           |     └── Document: (a) the conflict, (b) the resolution,
  |           |         (c) the risk accepted in each jurisdiction
  |           |
  |           └── NO (tension but not incompatible) → Apply layered approach:
  |                 global baseline + jurisdiction-specific supplements
  |
  └── Record the resolution in the conflict register

Conflict Register Template

Governance

More skills from ThomasMoreAI/legal-skills-open

  • A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
  • A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
  • Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
  • Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
  • Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
  • Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
  • Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
  • Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
  • Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
  • Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
  • Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
  • Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway

All agent skills → · MCP servers