← ClaudeAtlas

data-protection-checklisted

Focused Personal Data Protection Act 2026 compliance review — processing inventory, lawful basis, data classification, localisation, cross-border transfers, breach and registration duties. Use for "PDPA check", "can we send this data abroad", "privacy review", "data protection compliance", DPA/data-clause reviews, or breach response.
Zerif007/Claude_Legal-Bangladesh_Edition · ★ 0 · Data & Documents · score 68
Install: claude install-skill Zerif007/Claude_Legal-Bangladesh_Edition
# Data Protection Check — PDPA 2026 Config gate (regulatory footprint: data classes held) + currency check: the regime is brand-new — PDP Ordinance 2025 (promulgated 6 Nov 2025) → Amendment Ordinance (Feb 2026) → **Personal Data Protection Act 2026 (Act 63 of 2026, deemed effective 6 Nov 2025)**, with some sections (CDO appointment, administrative-penalty machinery) commencing on later notification. **Open every output by stating which instrument/version the analysis uses and what remains un-commenced `[verify]`.** ## Review sequence 1. **Role & scope:** fiduciary vs processor per the Act's definitions; extraterritorial hook (processing outside Bangladesh connected to offering products/services to, or monitoring, data subjects in Bangladesh). 2. **Processing inventory:** data classes mapped to the Act's four-tier classification (public/open, internal, confidential, restricted) — classification drives everything downstream; where the schedule criteria are still opaque, say so and take the conservative tier. 3. **Lawful basis & consent:** consent-centric regime; consent quality (informed, specific, withdrawable); sensitive-data subcategories (financial, biometric, genetic, health, identifiers); children's data — profiling/targeted ads prohibited. 4. **Data subject rights machinery:** access, correction, erasure, portability, opt-out of automated decision-making — intake channel, clocks, verification procedure. 5. **Localisation & transfers:** restrict