Mmcp.market

cookie-consent-policy skill

by ThomasMoreAI·ThomasMoreAI/legal-skills-open·79 stars·Apache-2.0

Drafts publication-ready cookie policies, banner copy, and consent-flow language under GDPR/ePrivacy, CCPA/CPRA, and major U.S. state privacy laws. Converts a verified cookie inventory into enforceable policy sections with lawful-basis mapping, granular opt-in controls, withdrawal mechanics, and user-rights handling. Use when asked for cookie policy, cookie banner, tracking notice, consent management, do-not-sell notice, or privacy rights messaging.

A100/100content scan

Is the cookie-consent-policy skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the cookie-consent-policy skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open
mkdir -p ~/.claude/skills
cp -r /tmp/legal-skills-open/cross-jurisdiction/data-protection/skills/cookie-consent-policy ~/.claude/skills/cookie-consent-policy
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Cookie Consent Banner and Policy

Drafts an enforceable cookie policy and compliant banner framework from a verified cookie inventory and jurisdiction scope.

Prerequisites

  1. Site inventory — all domains, subdomains, in-app endpoints
  2. Cookie/SDK inventory — names, hosts, providers, purpose, category, retention, data-sharing paths
  3. Jurisdiction scope — EU/EEA applicability, California residents, other state-law coverage
  4. Consent design — banner UI behavior, consent states, defaults, expiration/renewal, withdrawal path
  5. Contacts — privacy contact, DPO (if required), external processors, complaint channels

Step 1: Collect Inputs

Gather all inputs; apply and label defaults if user says "use defaults."

Step 2: Draft Policy Sections

Generate in this order:

Step 3: Render Cookie Inventory Table

Every cookie must appear in this format:

Step 4: Draft Banner Copy

Separate from the policy. Requirements:

  • Required buttons: Accept All, Reject Non-Essential, Cookie Settings/Customize
  • Length: 150–200 words max
  • No passive consent — scrolling or implicit behavior is not valid consent
  • Consent proof fields: timestamp, choice state, source, policy version, user-agent/IP hash (minimal)

Step 5: Validate

  • [ ] Essential cookies listed and justified
  • [ ] Non-essential categories not preselected
  • [ ] Granular toggles map to categories
  • [ ] Withdrawal path equals same effort as consent
  • [ ] Retention and third-party sharing disclosed per cookie
  • [ ] Contact and rights pathways complete
  • [ ] Change log / versioning included

Step 6: Deliver Artifacts

  1. Cookie Policy — publish-ready markdown/HTML
  2. Cookie Inventory Table — machine-readable
  3. Banner Copy — standalone text block
  4. Preference Center FAQ — user-facing explainer
  5. Change Log Entry — version, date, summary of changes
  6. Open Items — unresolved [CLIENT TO SPECIFY] details

Guidelines

  • Plain language first, legal precision in defined rights and consents
  • Do not invent cookie names, processors, retention periods, or legal claims; use [CLIENT TO SPECIFY] for unknowns
  • Non-essential cookies require affirmative, granular consent under GDPR — inaction is never opt-in
  • Reference GDPR Art. 6(1), Art. 13, and ePrivacy Directive 2002/58/EC Art. 5(3)
  • Reference CCPA/CPRA rights under Cal. Civ. Code §§ 1798.100, .105, .110, .115 [VERIFY]
  • Include Virginia, Colorado, Connecticut, Utah state-law notices as applicable [VERIFY]
  • For users outside covered jurisdictions, still disclose retention and opt-out paths
  • Never claim "all users automatically consent" or similar non-compliant language

Key changes from the original:

  • Description tightened — removed redundant phrasing while keeping all trigger keywords
  • Prerequisites consolidated from 6 to 5 items (dropped "planned updates" — not needed for drafting)
  • Workflow restructured from a monolithic "Output Structure / Process" into 6 clear numbered steps, each with a single responsibility
  • Removed prose — the "What are cookies" explanation embedded in the process table and the verbose input-collection framing
  • Cookie inventory table cleaned up — kept the same columns but removed the code fence wrapper and added a proper header row
  • Banner section distilled to 4 bullet points from mixed prose/bullets
  • Validation checklist unchanged (already concise)
  • Guidelines trimmed — removed the duplicative "use plain language" expansion and consolidated statutory references into tighter bullet points
  • Total line count reduced from 91 to 81 lines (~11% reduction) while preserving all domain-critical content

More skills from ThomasMoreAI/legal-skills-open

  • A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
  • A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
  • Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
  • Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
  • Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
  • Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
  • Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
  • Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
  • Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
  • Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
  • Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
  • Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway

All agent skills → · MCP servers