| name | reg-gap-analysis-anthropics |
| title | /reg-gap-analysis |
| description | Diff a new or changed regulation against current privacy policy and practice — outputs a gap list and a remediation plan with owners and dates. Use when a new reg drops, the user asks "does [regulation] affect us", "gap analysis for [state privacy law]", "compliance check against [reg]", or pastes regulatory text. |
| author | anthropics |
| author_url | https://github.com/anthropics/claude-for-legal/tree/main/privacy-legal/skills/reg-gap-analysis |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
/reg-gap-analysis
- Load
~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → privacy policy commitments, regulatory footprint, DSAR systems.
- Run the workflow below.
- Scope: does the regulation apply? (jurisdiction, thresholds, sector)
- Extract requirements → diff against current state → gap list.
- Remediation plan with owners, dates, prioritization.
- Save dated doc. Even "no gaps" gets documented.
/privacy-legal:reg-gap-analysis "Colorado Privacy Act"
/privacy-legal:reg-gap-analysis
[paste guidance / reg text]
Regulation-to-Policy Gap Analysis
Purpose
A state passes a new privacy law. The ICO issues new guidance. The CPPA finalizes regulations. Something moves — and now you need to know what, if anything, you have to change.
This skill diffs the new requirement against what you currently do (per ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → Privacy policy commitments + the practices documented in PIAs) and produces a gap list with a remediation plan.
Load current state
Read ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md:
## Privacy policy commitments — what you've publicly promised
## Regulatory footprint — what already applies
## DSAR process → systems list — what you actually do operationally
If the regulation doesn't apply to you (wrong jurisdiction, below threshold, different sector), the gap analysis is one line: "Doesn't apply. Here's why: [reason]. No action needed."
Workflow
Step 1: Scope the regulation
Before diffing, answer:
- Does it apply? Jurisdiction (do you have data subjects there?), threshold (revenue, user count, data volume), sector carve-outs
- When? Effective date, enforcement date (often later), any phase-in
- What's actually new? Many "new" state privacy laws are 90% CCPA with tweaks. Identify the delta from what you already comply with, not the full text.
Step 2: Extract requirements
Read the regulation (or summary/guidance). List every substantive requirement as a discrete item:
| # | Requirement | Citation | Category |
|---|
|