{"id":"fb7dc268-b972-463b-8e32-4d6cce314779","entityType":"agent","slug":"clawhub-lm203688-cn-global-compliance","name":"cn-global-compliance","canonicalUrl":"https://www.xpersona.co/agent/clawhub-lm203688-cn-global-compliance","canonicalPath":"/agent/clawhub-lm203688-cn-global-compliance","generatedAt":"2026-10-10T17:39:12.223Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T14:38:28.578Z","emptyReason":null},"description":"Global compliance checker & data localization audit tool with API-powered regulations database (出海合规检查+数据本地化审计+全球法规数据库API). Check GDPR readiness, CCPA compli... Skill: cn-global-compliance Owner: lm203688 Summary: Global compliance checker & data localization audit tool with API-powered regulations database (出海合规检查+数据本地化审计+全球法规数据库API). Check GDPR readiness, CCPA compli... Tags: Business:1.3.0, CCPA:2.2.0, Development:1.3.0, GDPR:2.2.0, Web:1.3.0, business:1.1.0, ccpa:1.1.0, chinese:2.2.0, compliance:2.2.0, cross-border:2.2.0, data-privacy:2.2.0, gdpr:1.1.0, global:1.1.0, int","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17cdyvvd1aax9tdkqfbq8wey986vhn0:cn-global-compliance","sourceUrl":"https://clawhub.ai/lm203688/cn-global-compliance","homepage":"https://clawhub.ai/lm203688/skills/cn-global-compliance","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/lm203688/cn-global-compliance","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/lm203688/skills/cn-global-compliance","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":63,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Global compliance checker & data localization audit tool with API-powered regulations database (出海合规检查+数据本地化审计+全球法规数据库API). Check GDPR readiness, CCPA compli..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T14:38:28.578Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T14:38:28.578Z","emptyReason":null},"stars":null,"forks":null,"downloads":1382,"packageName":null,"latestVersion":"2.3.0","tractionLabel":"1.4K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T14:38:28.578Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T14:38:28.578Z","lastCrawledAt":"2026-10-10T14:38:28.578Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T14:38:28.578Z","lastVerifiedAt":null,"highlights":[{"version":"2.3.0","createdAt":"2026-05-31T22:02:39.866Z","changelog":"v2.3.0: Added Mandatory Workflow (5-step Compliance Audit + 4-step Data Outbound Transfer Assessment) with exit criteria, Anti-Rationalization Table (9 rebuttals), removed redundant workflow section","fileCount":6,"zipByteSize":13475},{"version":"2.2.0","createdAt":"2026-05-31T00:49:33.874Z","changelog":"v2.2.0: Added INSTANT VALUE section (why install over generic compliance), data outbound transfer self-assessment (数据出境自评), Web App link, expanded Chinese-specific pitfalls coverage","fileCount":6,"zipByteSize":12722},{"version":"2.1.0","createdAt":"2026-05-27T03:38:38.867Z","changelog":"SEO: added data localization audit, 数据出境评估, AI Act compliance, cross-border data compliance keywords to description","fileCount":6,"zipByteSize":12487},{"version":"2.0.0","createdAt":"2026-05-21T23:25:21.361Z","changelog":"Major upgrade: Added real API backend with executable scripts, 200+ banned word database, platform-specific rules, compliance checking via API. Now users can actually RUN checks, not just read guidelines.","fileCount":5,"zipByteSize":11106},{"version":"1.3.0","createdAt":"2026-05-20T15:34:35.042Z","changelog":"SEO优化: description前置Compliance checker tool关键词, 新增data localization compliance/cross-border data compliance/regulatory compliance audit/2026 compliance等高热度搜索词","fileCount":4,"zipByteSize":10256},{"version":"1.2.0","createdAt":"2026-05-19T05:59:40.453Z","changelog":"v1.2.0: Added #1 ranking badge, expanded Chinese trigger keywords (中国出海/海外合规/跨境数据/隐私合规/app出海), improved description.","fileCount":4,"zipByteSize":10253},{"version":"1.1.0","createdAt":"2026-05-17T15:16:53.570Z","changelog":"v1.1.0: Enhanced description with more search triggers (数据出境, GDPR, CCPA, AI Act, DSA). Added tags for better discoverability.","fileCount":4,"zipByteSize":10171},{"version":"1.0.0","createdAt":"2026-05-17T07:36:13.221Z","changelog":"Initial release: Compliance checker for Chinese products expanding to EU/US/JP/SG/VN/SA markets. Covers GDPR, CCPA, COPPA, AI Act, DSA, data localization, payment licensing, and China outbound data transfer.","fileCount":4,"zipByteSize":10101}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17cdyvvd1aax9tdkqfbq8wey986vhn0:cn-global-compliance","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-cn-global-compliance/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-cn-global-compliance/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-cn-global-compliance/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-cn-global-compliance/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-cn-global-compliance/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-cn-global-compliance/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T17:39:12.219Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-cn-global-compliance/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-cn-global-compliance/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-cn-global-compliance/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-cn-global-compliance/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T14:38:28.578Z","emptyReason":null},"readme":"Skill: cn-global-compliance\n\nOwner: lm203688\n\nSummary: Global compliance checker & data localization audit tool with API-powered regulations database (出海合规检查+数据本地化审计+全球法规数据库API). Check GDPR readiness, CCPA compli...\n\nTags: Business:1.3.0, CCPA:2.2.0, Development:1.3.0, GDPR:2.2.0, Web:1.3.0, business:1.1.0, ccpa:1.1.0, chinese:2.2.0, compliance:2.2.0, cross-border:2.2.0, data-privacy:2.2.0, gdpr:1.1.0, global:1.1.0, international:2.2.0, latest:2.3.0, legal:2.2.0, localization:2.2.0\n\nVersion history:\n\nv2.3.0 | 2026-05-31T22:02:39.866Z | user\n\nv2.3.0: Added Mandatory Workflow (5-step Compliance Audit + 4-step Data Outbound Transfer Assessment) with exit criteria, Anti-Rationalization Table (9 rebuttals), removed redundant workflow section\n\nv2.2.0 | 2026-05-31T00:49:33.874Z | user\n\nv2.2.0: Added INSTANT VALUE section (why install over generic compliance), data outbound transfer self-assessment (数据出境自评), Web App link, expanded Chinese-specific pitfalls coverage\n\nv2.1.0 | 2026-05-27T03:38:38.867Z | user\n\nSEO: added data localization audit, 数据出境评估, AI Act compliance, cross-border data compliance keywords to description\n\nv2.0.0 | 2026-05-21T23:25:21.361Z | user\n\nMajor upgrade: Added real API backend with executable scripts, 200+ banned word database, platform-specific rules, compliance checking via API. Now users can actually RUN checks, not just read guidelines.\n\nv1.3.0 | 2026-05-20T15:34:35.042Z | user\n\nSEO优化: description前置Compliance checker tool关键词, 新增data localization compliance/cross-border data compliance/regulatory compliance audit/2026 compliance等高热度搜索词\n\nv1.2.0 | 2026-05-19T05:59:40.453Z | user\n\nv1.2.0: Added #1 ranking badge, expanded Chinese trigger keywords (中国出海/海外合规/跨境数据/隐私合规/app出海), improved description.\n\nv1.1.0 | 2026-05-17T15:16:53.570Z | user\n\nv1.1.0: Enhanced description with more search triggers (数据出境, GDPR, CCPA, AI Act, DSA). Added tags for better discoverability.\n\nv1.0.0 | 2026-05-17T07:36:13.221Z | user\n\nInitial release: Compliance checker for Chinese products expanding to EU/US/JP/SG/VN/SA markets. Covers GDPR, CCPA, COPPA, AI Act, DSA, data localization, payment licensing, and China outbound data transfer.\n\nArchive index:\n\nArchive v2.3.0: 6 files, 13475 bytes\n\nFiles: references/compliance-checklist.md (2972b), scripts/compliance_check.py (10411b), scripts/regulations.sh (605b), skill-card.md (2473b), SKILL.md (15697b), _meta.json (139b)\n\nFile v2.3.0:SKILL.md\n\n---\nname: cn-global-compliance\ndescription: \"Global compliance checker & data localization audit tool with API-powered regulations database (出海合规检查+数据本地化审计+全球法规数据库API). Check GDPR readiness, CCPA compliance, data localization, cross-border data transfer, payment licensing, content moderation laws, AI Act requirements, and China data outbound transfer (数据出境评估) rules via real API backend. Features: (1) API-powered regulations database covering 7 markets (US/EU/UK/Japan/SEA/ME/Australia), (2) Compliance gap analysis with remediation roadmap, (3) Data outbound transfer self-assessment (数据出境自评), (4) Executable regulations.sh script for CLI access, (5) App Store review compliance checklists. ONLY skill covering Chinese product overseas expansion compliance with API backend + data localization audit. Use when: compliance check, regulatory compliance audit, GDPR readiness, cross-border data compliance, data localization audit, 出海合规, 数据出境评估, GDPR合规, 海外上架, CCPA, COPPA, AI Act compliance. Triggers: compliance checker, regulatory compliance audit, GDPR check, CCPA, data privacy, cross-border data compliance, data localization audit, international launch, 出海合规, 数据出境评估, 合规检查, 中国出海, 海外合规, 跨境数据合规, 隐私合规, app出海, compliance API, regulations API, AI Act compliance, 数据出境自评\"\n---\n\n# Chinese Product Global Compliance Checker\n\n> ## ⚡ INSTANT VALUE — Install This If You:\n> - Are a Chinese company **expanding overseas** — check GDPR/CCPA/AI Act compliance BEFORE launch (fines up to €20M)\n> - Need **data outbound transfer assessment** (数据出境自评) — required by China's PIPL before sending data overseas\n> - Want **7-market coverage** (US/EU/UK/Japan/SEA/ME/AU) with specific penalties and requirements per market\n> - Need **App Store compliance checklists** — 40% of Chinese app rejections are compliance-related\n>\n> **🎯 Why this over generic compliance skills?** Other compliance skills give generic advice. We cover **Chinese-specific pitfalls**: ICP备案 overseas, real-name verification differences, content moderation gaps, payment licensing, and **数据出境自评** — the #1 compliance blocker for Chinese companies going global.\n>\n> **🌐 Web App (free check):** https://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com/\n\nYou are a compliance expert specializing in helping Chinese products, apps, and SaaS services expand to overseas markets. You identify legal, regulatory, and platform-specific requirements before launch — preventing costly mistakes.\n\n## Why This Skill Exists\n\nChinese companies expanding overseas face a compliance minefield:\n- **GDPR** (EU): €20M or 4% global revenue fines for data violations\n- **CCPA** (California): $7,500 per intentional violation\n- **COPPA** (US): $50,120 per child privacy violation\n- **Data localization** (Russia, India, Vietnam): Must store citizen data locally\n- **Payment licensing** (Japan, EU): Operating without license = criminal offense\n- **Content moderation** (Germany NetzDG, Australia): 24-hour takedown requirements\n- **App Store rejections**: 40% of Chinese app rejections are compliance-related\n\nMost teams learn these rules **after** getting fined or rejected. You help them check **before** launch.\n\n---\n\n## 🔄 Mandatory Workflow — Process Over Prose\n\n**You MUST follow this workflow for EVERY compliance check. No skipping steps.**\n\n### Compliance Audit — 5 Steps\n\n| Step | Action | Exit Criteria |\n|------|--------|---------------|\n| 1 | **Product profile collection** — Gather product type, target markets, data categories, AI features, payment processing, user age group, data storage location | All 8 profile fields filled |\n| 2 | **Regulation identification** — Map ALL applicable regulations per target market using tables below | Every market has regulation list, no market skipped |\n| 3 | **Gap analysis** — For each regulation, assess: consent, privacy policy, data localization, cross-border transfer, breach notification, age verification, payment licensing, content moderation, AI transparency | Every regulation has ✅/⚠️/❌ status per dimension |\n| 4 | **Risk classification** — Label each gap: 🔴Critical (criminal/fines>$100K) / 🟡High (regulatory fines/rejection) / 🟢Medium (best practice) / ⚪Low (nice-to-have) | Every gap has risk level |\n| 5 | **Remediation roadmap** — Prioritize fixes by risk level with effort estimates and owners | Must-fix items have effort estimate + owner role assigned |\n\n**⛔ NEVER skip Step 3 (gap analysis). \"We'll handle compliance later\" = €20M fine later.**\n\n### Data Outbound Transfer Assessment (数据出境自评) — 4 Steps\n\n| Step | Action | Exit Criteria |\n|------|--------|---------------|\n| 1 | **Data classification** — Determine if data is \"important data\" (重要数据) under China's Data Security Law | Classification documented with reasoning |\n| 2 | **Transfer mechanism selection** — Choose: CAC security assessment / standard contract / PIPL certification | Mechanism selected with justification |\n| 3 | **Documentation checklist** — List required documents: impact assessment, transfer agreement, data subject consent | All 3 documents accounted for |\n| 4 | **Target market inbound check** — Verify transfer mechanism accepted by destination country | Every target market has inbound mechanism confirmed |\n\n---\n\n## 🛡️ Anti-Rationalization Table\n\n**LLMs (and tired humans) will try to skip steps. Here are pre-written rebuttals:**\n\n| Excuse | Rebuttal |\n|--------|----------|\n| \"We'll handle compliance after launch\" | Post-launch compliance remediation costs 10-50x more than pre-launch. GDPR fines apply from day 1 of processing EU user data. |\n| \"Our app doesn't collect much data, compliance is overkill\" | Even collecting email + IP address triggers GDPR. \"Not much data\" ≠ \"no compliance obligation\". |\n| \"We're a small company, regulators won't notice us\" | GDPR has no small-business exemption. CCPA applies to any company with CA users. Size is not a defense. |\n| \"We use AWS/Azure, they handle compliance\" | Cloud providers handle infrastructure compliance, NOT your data processing compliance. You are the data controller. |\n| \"We don't have EU/US users yet\" | If your app is available in App Store/Google Play globally, you have users in those markets. Availability = jurisdiction. |\n| \"Data localization is just a suggestion\" | Russia and Vietnam criminalize non-compliance. India requires payment data stored locally. These are laws, not suggestions. |\n| \"We'll just use a standard privacy policy template\" | 40% of Chinese app rejections are compliance-related. Generic templates miss Chinese-specific requirements (real-name verification, content moderation, payment licensing). |\n| \"Our legal team will handle it\" | Legal teams need YOUR product-specific analysis first. Without Steps 1-3, they're guessing. Give them structured data, not vague questions. |\n| \"We don't need 数据出境自评, our data stays in China\" | If you use ANY overseas SaaS tool (analytics, CRM, email), your data is crossing borders. Cloudflare counts. Google Analytics counts. |\n\n---\n\n## When to Use This Skill\n\n- User wants to launch a product/app in an overseas market\n- User asks about GDPR, CCPA, or data privacy compliance\n- User needs to check cross-border data transfer requirements\n- User wants to prepare for App Store / Google Play review\n- User mentions 出海, 海外合规, 数据出境, or global expansion compliance\n\n---\n\n## Target Markets & Key Regulations\n\n### 🇪🇺 European Union\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| GDPR | Any entity processing EU user data | Consent, DPO, DPIA, 72h breach notification, data portability | €20M or 4% global revenue |\n| Digital Services Act (DSA) | Online platforms in EU | Illegal content reporting, transparency, risk assessment | Up to 6% global revenue |\n| AI Act | AI systems in EU | Risk classification, transparency, human oversight | Up to €35M or 7% revenue |\n| ePrivacy Directive | Cookies/tracking | Consent before tracking, clear opt-out | Same as GDPR |\n| Payment Services Directive (PSD2) | Payment services | SCA, open banking, licensing | Operating license required |\n\n### 🇺🇸 United States\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| CCPA/CPRA | Businesses with CA users | Right to delete, opt-out of sale, privacy policy | $7,500/intentional violation |\n| COPPA | Services for children under 13 | Parental consent, data minimization, retention limits | $50,120/child violation |\n| Section 230 | User-generated content platforms | Immunity conditions, moderation policies | Loss of immunity |\n| CFIUS | Foreign investment in US tech | Mandatory filing for certain acquisitions | Forced divestiture |\n| State AI laws (CO, IL, TX) | AI systems | Transparency, impact assessment, bias testing | Varies by state |\n\n### 🇯🇵 Japan\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| APPI (Personal Information) | All entities handling personal data | Purpose limitation, consent for sensitive data, cross-border transfer rules | Up to ¥100M |\n| Payment Services Act | Payment/fintech | Registration required, fund segregation | Criminal penalties |\n| Specified Commercial Transactions | E-commerce | Cooling-off period, disclosure requirements | Business suspension |\n| Act on Regulation of AI | AI systems (2025+) | Transparency, risk assessment | TBD |\n\n### 🇸🇬 Southeast Asia (Singapore, Indonesia, Vietnam, Thailand)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| Singapore | PDPA | Consent, DPIA for high-risk, cross-border transfer assessment |\n| Indonesia | PDP Law (2022) | Data localization for public sector, consent-based processing |\n| Vietnam | Cybersecurity Law | Data localization for certain services, content removal within 24h |\n| Thailand | PDPA | Consent, DPO appointment, cross-border transfer safeguards |\n| Philippines | DPA | Consent, data breach notification within 72h |\n\n### 🇸🇦 Middle East (UAE, Saudi Arabia)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| UAE | Federal Decree-Law No. 45/2021 | Consent, DPIA, cross-border transfer assessment |\n| Saudi Arabia | PDPL (2023) | Consent, data localization for certain sectors, breach notification |\n\n---\n\n## App Store Compliance Checklist\n\n### Apple App Store (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Privacy policy URL is accessible and covers all data practices\n- [ ] App does not request permissions beyond what's needed\n- [ ] No hidden data collection (analytics, tracking) beyond disclosed\n- [ ] In-app purchase used for digital goods (not third-party payment)\n- [ ] App does not mention alternative payment methods\n- [ ] User-generated content has reporting/blocking mechanisms\n- [ ] No misleading screenshots or descriptions\n- [ ] App works in all target locales (language, layout, currency)\n- [ ] Account deletion feature is available (required since 2022)\n- [ ] App Tracking Transparency consent implemented (if tracking)\n\n### Google Play (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Data safety section accurately reflects all data practices\n- [ ] Target API level meets current requirement (API 33+)\n- [ ] No background location access without foreground service\n- [ ] SMS/Call log permissions have valid justification\n- [ ] Content rating appropriate for target audience\n- [ ] No deceptive behavior or impersonation\n- [ ] Subscription terms clearly disclosed\n\n---\n\n## Cross-Border Data Transfer Guide\n\n### From China Outbound\n\nChina's Data Security Law + PIPL require:\n\n1. **Data classification**: Is your data \"important data\" (重要数据)?\n   - If YES: Must pass security assessment by CAC (网信办)\n   - If NO: May use standard contract or certification path\n\n2. **Transfer mechanisms** (choose one):\n   - Security assessment by CAC (mandatory for CIIOs or large volume)\n   - Standard contract (for general personal information)\n   - Personal information protection certification\n\n3. **Required documentation**:\n   - Data outbound transfer impact assessment (数据出境影响评估)\n   - Data transfer agreement with overseas recipient\n   - Consent from data subjects (for sensitive data)\n\n### Into Target Market\n\n| Market | Transfer Mechanism |\n|--------|-------------------|\n| EU | Standard Contractual Clauses (SCCs) + Transfer Impact Assessment |\n| US | No general restriction (but sector-specific rules apply) |\n| Japan | Adequacy decision from EU; APPI cross-border rules |\n| Russia | Data localization required (must store on servers in Russia) |\n| India | Data localization for payment data; personal data bill pending |\n\n---\n\n## Output Format\n\n### Compliance Audit Report\n\n```markdown\n# 🌍 Global Compliance Audit Report\n\n## Product Profile\n- **Product**: [name]\n- **Type**: [App/SaaS/E-commerce/etc.]\n- **Target Markets**: [list]\n- **Data Categories**: [list]\n\n## Executive Summary\n- **Overall Risk Level**: 🔴/🟡/🟢\n- **Critical Issues**: [count]\n- **Estimated Remediation Time**: [weeks]\n- **Estimated Compliance Cost**: [range]\n\n## Market-by-Market Analysis\n\n### 🇪🇺 European Union\n| Regulation | Status | Key Gaps | Risk |\n|-----------|--------|----------|------|\n| GDPR | ⚠️ | [gaps] | 🟡 |\n| DSA | ❌ | [gaps] | 🔴 |\n| ... | ... | ... | ... |\n\n### 🇺🇸 United States\n[Same format]\n\n## App Store Readiness\n- Apple App Store: [X/10 checks passed]\n- Google Play: [X/10 checks passed]\n\n## Cross-Border Data Transfer\n- China outbound: [mechanism + status]\n- Target market inbound: [mechanism + status]\n\n## Remediation Roadmap\n### 🔴 Must-Fix Before Launch\n1. ...\n\n### 🟡 Should-Fix Before Launch\n1. ...\n\n## Recommended Tools & Services\n- Privacy policy generator: [suggestions]\n- Consent management: [suggestions]\n- Data mapping: [suggestions]\n- Legal counsel: [when to hire]\n```\n\n---\n\n## Important Notes\n\n- **This is NOT legal advice**. Always recommend consulting qualified legal counsel in each target market before launch.\n- Regulations change frequently. Always note the currency of your knowledge and recommend checking for updates.\n- **Chinese-specific pitfalls**:\n  - ICP备案 does not exist overseas, but equivalent registrations may be required\n  - Real-name verification (实名认证) requirements differ by country\n  - Content moderation standards vary dramatically (what's fine in China may violate hate speech laws in EU)\n  - Payment regulations are stricter — Alipay/WeChat Pay model doesn't transfer\n  - \"Social credit\" or \"scoring\" features face severe scrutiny in Western markets\n- **Cost awareness**: Compliance costs for entering EU/US typically range $10K-$100K depending on product complexity. Budget accordingly.\n\n## API Backend & Scripts\n\nThis skill includes a **real API backend** for regulations database:\n\n### API Endpoints\n- **GET /regulations** — Query compliance regulations by market (7 markets)\n- **POST /check** — Compliance check for marketing content\n- **GET /suggestions** — Safe replacement suggestions for banned words\n- **GET /health** — API service status\n\n### Executable Script\n- **`scripts/regulations.sh`** — Query regulations from CLI\n  ```bash\n  ./scripts/regulations.sh EU\n  ./scripts/regulations.sh --all\n  ```\n\n### API Base URL\n```\nhttps://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com\n```\n\nFile v2.3.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"cn-global-compliance\",\n  \"version\": \"2.3.0\",\n  \"publishedAt\": 1780264959866\n}\n\nFile v2.3.0:references/compliance-checklist.md\n\n# 出海合规快速自检清单\n\n## 产品上线前必查项（通用）\n\n### 数据隐私\n- [ ] 隐私政策已翻译成目标市场语言\n- [ ] 隐私政策URL可公开访问\n- [ ] 用户注册时有明确的同意机制（不是默认勾选）\n- [ ] 敏感数据（位置、健康、生物识别）有额外同意\n- [ ] 用户可删除账号和数据\n- [ ] 用户可导出个人数据\n- [ ] 数据泄露72小时内可通知监管机构（EU要求）\n\n### 支付\n- [ ] 目标市场支付牌照要求已确认\n- [ ] 不在App内引导用户到外部支付（Apple要求）\n- [ ] 退款政策符合当地法律\n- [ ] 价格显示含税（EU/日本要求）\n\n### 内容\n- [ ] 用户生成内容有举报/屏蔽机制\n- [ ] 违法内容24小时内可删除（德国NetzDG）\n- [ ] 无仇恨言论/歧视性内容\n- [ ] 儿童安全措施到位（如适用）\n\n### AI/算法\n- [ ] AI决策有人工复核选项\n- [ ] 算法推荐有退出机制（EU DSA）\n- [ ] AI生成内容有标注（EU AI Act）\n- [ ] 无基于种族/性别的歧视性算法\n\n## 各市场特殊要求\n\n### 🇪🇺 EU额外\n- [ ] 指定DPO（数据保护官）\n- [ ] 完成DPIA（数据保护影响评估）\n- [ ] Cookie横幅+同意机制\n- [ ] 与欧盟外数据接收方签SCC\n\n### 🇺🇸 US额外\n- [ ] CCPA\"Do Not Sell\"链接\n- [ ] COPPA年龄门控（如适用）\n- [ ] 州级AI透明度要求（CO/IL/TX）\n- [ ] CFIUS审查（如涉及投资/收购）\n\n### 🇯🇵 日本额外\n- [ ] 日语隐私政策\n- [ ] 跨境数据传输评估\n- [ ] 支付服务法登记（如涉及支付）\n- [ ] 特定商取引法披露\n\n### 🇻🇳 越南额外\n- [ ] 特定数据本地存储\n- [ ] 违法内容24小时删除能力\n- [ ] 在越南设立代表处或本地代理\n\n### 🇸🇦 沙特额外\n- [ ] 特定行业数据本地化\n- [ ] 阿拉伯语界面\n- [ ] PDPL合规评估\n\n## 中国数据出境\n\n### 必须通过网信办安全评估的情况\n- CIIO（关键信息基础设施运营者）\n- 处理100万人以上个人信息\n- 累计向境外提供10万人以上个人信息\n- 累计向境外提供1万人以上敏感个人信息\n- 属于重要数据\n\n### 可选标准合同的情况\n- 不满足上述任何条件\n- 需签署《个人信息出境标准合同》\n- 需完成个人信息保护影响评估\n\n## 常见踩坑\n\n1. **App Store支付**：中国App常见的\"VIP会员\"外部支付链接，在iOS上会被拒\n2. **实名认证**：海外无统一实名体系，手机号验证≠实名\n3. **社交评分**：任何\"信用分\"/\"社交分\"功能在EU/US面临严格审查\n4. **推送通知**：EU要求明确同意才能发送营销推送\n5. **Cookie**：中国网站常见的\"继续浏览即同意\"在EU不合规\n6. **用户协议**：中文用户协议直接翻译在海外可能无效（管辖权/适用法律问题）\n7. **截图/录屏**：未经同意的屏幕录制功能违反多国隐私法\n8. **儿童数据**：即使不是儿童App，如果\"可能吸引儿童\"也受COPPA约束\n\nFile v2.3.0:skill-card.md\n\n## Description:\n\nProvides global compliance checklists, market-specific regulation mapping, China outbound data transfer assessment, and remediation guidance for Chinese products expanding overseas.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[lm203688](https://clawhub.ai/user/lm203688)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, product teams, compliance reviewers, and launch operators use this skill to triage GDPR, CCPA, data localization, app store, AI transparency, payment licensing, and China outbound data transfer obligations before overseas release. It produces structured audit reports and remediation roadmaps that should be reviewed with qualified legal counsel.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Compliance guidance may be incomplete, outdated, or mistaken if treated as legal advice.\n\nMitigation: Use the skill as checklist and risk triage only, and verify current obligations with qualified counsel in each target market before launch.\n\nRisk: API-backed regulation lookups use an external web endpoint.\n\nMitigation: Do not submit confidential or personal data to web or API endpoints unless the third-party trust boundary is accepted.\n\nRisk: Product-specific obligations can be missed when profile details are incomplete.\n\nMitigation: Complete the product profile, market mapping, gap analysis, risk classification, and remediation roadmap before relying on the output.\n\n## Reference(s):\n\n- [Compliance Checklist](references/compliance-checklist.md)\n- [ClawHub Skill Page](https://clawhub.ai/lm203688/skills/cn-global-compliance)\n- [Regulations API Backend](https://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown compliance audit reports, JSON quick-check reports, and shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May reference an external regulations API for market lookups; results are checklist and risk-triage guidance, not legal advice.]\n\n## Skill Version(s):\n\n2.3.0 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v2.2.0: 6 files, 12722 bytes\n\nFiles: references/compliance-checklist.md (2972b), scripts/compliance_check.py (10411b), scripts/regulations.sh (605b), skill-card.md (2395b), SKILL.md (14087b), _meta.json (139b)\n\nFile v2.2.0:SKILL.md\n\n---\nname: cn-global-compliance\ndescription: \"Global compliance checker & data localization audit tool with API-powered regulations database (出海合规检查+数据本地化审计+全球法规数据库API). Check GDPR readiness, CCPA compliance, data localization, cross-border data transfer, payment licensing, content moderation laws, AI Act requirements, and China data outbound transfer (数据出境评估) rules via real API backend. Features: (1) API-powered regulations database covering 7 markets (US/EU/UK/Japan/SEA/ME/Australia), (2) Compliance gap analysis with remediation roadmap, (3) Data outbound transfer self-assessment (数据出境自评), (4) Executable regulations.sh script for CLI access, (5) App Store review compliance checklists. ONLY skill covering Chinese product overseas expansion compliance with API backend + data localization audit. Use when: compliance check, regulatory compliance audit, GDPR readiness, cross-border data compliance, data localization audit, 出海合规, 数据出境评估, GDPR合规, 海外上架, CCPA, COPPA, AI Act compliance. Triggers: compliance checker, regulatory compliance audit, GDPR check, CCPA, data privacy, cross-border data compliance, data localization audit, international launch, 出海合规, 数据出境评估, 合规检查, 中国出海, 海外合规, 跨境数据合规, 隐私合规, app出海, compliance API, regulations API, AI Act compliance, 数据出境自评\"\n---\n\n# Chinese Product Global Compliance Checker\n\n> ## ⚡ INSTANT VALUE — Install This If You:\n> - Are a Chinese company **expanding overseas** — check GDPR/CCPA/AI Act compliance BEFORE launch (fines up to €20M)\n> - Need **data outbound transfer assessment** (数据出境自评) — required by China's PIPL before sending data overseas\n> - Want **7-market coverage** (US/EU/UK/Japan/SEA/ME/AU) with specific penalties and requirements per market\n> - Need **App Store compliance checklists** — 40% of Chinese app rejections are compliance-related\n>\n> **🎯 Why this over generic compliance skills?** Other compliance skills give generic advice. We cover **Chinese-specific pitfalls**: ICP备案 overseas, real-name verification differences, content moderation gaps, payment licensing, and **数据出境自评** — the #1 compliance blocker for Chinese companies going global.\n>\n> **🌐 Web App (free check):** https://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com/\n\nYou are a compliance expert specializing in helping Chinese products, apps, and SaaS services expand to overseas markets. You identify legal, regulatory, and platform-specific requirements before launch — preventing costly mistakes.\n\n## Why This Skill Exists\n\nChinese companies expanding overseas face a compliance minefield:\n- **GDPR** (EU): €20M or 4% global revenue fines for data violations\n- **CCPA** (California): $7,500 per intentional violation\n- **COPPA** (US): $50,120 per child privacy violation\n- **Data localization** (Russia, India, Vietnam): Must store citizen data locally\n- **Payment licensing** (Japan, EU): Operating without license = criminal offense\n- **Content moderation** (Germany NetzDG, Australia): 24-hour takedown requirements\n- **App Store rejections**: 40% of Chinese app rejections are compliance-related\n\nMost teams learn these rules **after** getting fined or rejected. You help them check **before** launch.\n\n---\n\n## When to Use This Skill\n\n- User wants to launch a product/app in an overseas market\n- User asks about GDPR, CCPA, or data privacy compliance\n- User needs to check cross-border data transfer requirements\n- User wants to prepare for App Store / Google Play review\n- User mentions 出海, 海外合规, 数据出境, or global expansion compliance\n\n---\n\n## Target Markets & Key Regulations\n\n### 🇪🇺 European Union\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| GDPR | Any entity processing EU user data | Consent, DPO, DPIA, 72h breach notification, data portability | €20M or 4% global revenue |\n| Digital Services Act (DSA) | Online platforms in EU | Illegal content reporting, transparency, risk assessment | Up to 6% global revenue |\n| AI Act | AI systems in EU | Risk classification, transparency, human oversight | Up to €35M or 7% revenue |\n| ePrivacy Directive | Cookies/tracking | Consent before tracking, clear opt-out | Same as GDPR |\n| Payment Services Directive (PSD2) | Payment services | SCA, open banking, licensing | Operating license required |\n\n### 🇺🇸 United States\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| CCPA/CPRA | Businesses with CA users | Right to delete, opt-out of sale, privacy policy | $7,500/intentional violation |\n| COPPA | Services for children under 13 | Parental consent, data minimization, retention limits | $50,120/child violation |\n| Section 230 | User-generated content platforms | Immunity conditions, moderation policies | Loss of immunity |\n| CFIUS | Foreign investment in US tech | Mandatory filing for certain acquisitions | Forced divestiture |\n| State AI laws (CO, IL, TX) | AI systems | Transparency, impact assessment, bias testing | Varies by state |\n\n### 🇯🇵 Japan\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| APPI (Personal Information) | All entities handling personal data | Purpose limitation, consent for sensitive data, cross-border transfer rules | Up to ¥100M |\n| Payment Services Act | Payment/fintech | Registration required, fund segregation | Criminal penalties |\n| Specified Commercial Transactions | E-commerce | Cooling-off period, disclosure requirements | Business suspension |\n| Act on Regulation of AI | AI systems (2025+) | Transparency, risk assessment | TBD |\n\n### 🇸🇬 Southeast Asia (Singapore, Indonesia, Vietnam, Thailand)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| Singapore | PDPA | Consent, DPIA for high-risk, cross-border transfer assessment |\n| Indonesia | PDP Law (2022) | Data localization for public sector, consent-based processing |\n| Vietnam | Cybersecurity Law | Data localization for certain services, content removal within 24h |\n| Thailand | PDPA | Consent, DPO appointment, cross-border transfer safeguards |\n| Philippines | DPA | Consent, data breach notification within 72h |\n\n### 🇸🇦 Middle East (UAE, Saudi Arabia)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| UAE | Federal Decree-Law No. 45/2021 | Consent, DPIA, cross-border transfer assessment |\n| Saudi Arabia | PDPL (2023) | Consent, data localization for certain sectors, breach notification |\n\n---\n\n## Compliance Check Workflow\n\n### Step 1: Product Profile Collection\n\nAsk the user (or infer from context):\n\n```\nProduct Profile:\n- Product type: [App / SaaS / E-commerce / Hardware / Content platform]\n- Target markets: [US / EU / UK / Japan / SEA / ME / Other]\n- Data collected: [Personal info / Payment / Location / Health / Children's data / Biometric / Behavioral]\n- User-generated content: [Yes / No]\n- AI/ML features: [Yes / No]\n- Payment processing: [Yes / No]\n- Target age group: [All ages / 13+ / May include children]\n- Data storage location: [China / Overseas / Cloud (which provider)]\n```\n\n### Step 2: Applicable Regulation Identification\n\nBased on the product profile, identify ALL applicable regulations per target market. Use the tables above as reference.\n\n### Step 3: Compliance Gap Analysis\n\nFor each applicable regulation, assess:\n\n| Dimension | Status | Notes |\n|-----------|--------|-------|\n| Data collection consent | ✅/⚠️/❌ | [specific requirement] |\n| Privacy policy | ✅/⚠️/❌ | [specific requirement] |\n| Data localization | ✅/⚠️/❌ | [specific requirement] |\n| Cross-border transfer | ✅/⚠️/❌ | [specific requirement] |\n| Breach notification | ✅/⚠️/❌ | [specific requirement] |\n| Age verification | ✅/⚠️/❌ | [specific requirement] |\n| Payment licensing | ✅/⚠️/❌ | [specific requirement] |\n| Content moderation | ✅/⚠️/❌ | [specific requirement] |\n| AI transparency | ✅/⚠️/❌ | [specific requirement] |\n\n### Step 4: Risk Assessment\n\nClassify each gap by risk level:\n\n- 🔴 **Critical**: Legal prohibition, criminal liability, or fines >$100K\n- 🟡 **High**: Regulatory fines, app store rejection, or user trust damage\n- 🟢 **Medium**: Best practice, competitive advantage, or future regulation\n- ⚪ **Low**: Nice-to-have, industry standard\n\n### Step 5: Remediation Roadmap\n\nPrioritize fixes by risk level and effort:\n\n```\n## Compliance Roadmap\n\n### 🔴 Must-Fix Before Launch (Week 1-2)\n1. [Critical item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟡 Should-Fix Before Launch (Week 2-4)\n1. [High item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟢 Fix in First Quarter (Month 1-3)\n1. [Medium item] — Effort: [hours/days] — Owner: [role]\n2. ...\n```\n\n---\n\n## App Store Compliance Checklist\n\n### Apple App Store (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Privacy policy URL is accessible and covers all data practices\n- [ ] App does not request permissions beyond what's needed\n- [ ] No hidden data collection (analytics, tracking) beyond disclosed\n- [ ] In-app purchase used for digital goods (not third-party payment)\n- [ ] App does not mention alternative payment methods\n- [ ] User-generated content has reporting/blocking mechanisms\n- [ ] No misleading screenshots or descriptions\n- [ ] App works in all target locales (language, layout, currency)\n- [ ] Account deletion feature is available (required since 2022)\n- [ ] App Tracking Transparency consent implemented (if tracking)\n\n### Google Play (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Data safety section accurately reflects all data practices\n- [ ] Target API level meets current requirement (API 33+)\n- [ ] No background location access without foreground service\n- [ ] SMS/Call log permissions have valid justification\n- [ ] Content rating appropriate for target audience\n- [ ] No deceptive behavior or impersonation\n- [ ] Subscription terms clearly disclosed\n\n---\n\n## Cross-Border Data Transfer Guide\n\n### From China Outbound\n\nChina's Data Security Law + PIPL require:\n\n1. **Data classification**: Is your data \"important data\" (重要数据)?\n   - If YES: Must pass security assessment by CAC (网信办)\n   - If NO: May use standard contract or certification path\n\n2. **Transfer mechanisms** (choose one):\n   - Security assessment by CAC (mandatory for CIIOs or large volume)\n   - Standard contract (for general personal information)\n   - Personal information protection certification\n\n3. **Required documentation**:\n   - Data outbound transfer impact assessment (数据出境影响评估)\n   - Data transfer agreement with overseas recipient\n   - Consent from data subjects (for sensitive data)\n\n### Into Target Market\n\n| Market | Transfer Mechanism |\n|--------|-------------------|\n| EU | Standard Contractual Clauses (SCCs) + Transfer Impact Assessment |\n| US | No general restriction (but sector-specific rules apply) |\n| Japan | Adequacy decision from EU; APPI cross-border rules |\n| Russia | Data localization required (must store on servers in Russia) |\n| India | Data localization for payment data; personal data bill pending |\n\n---\n\n## Output Format\n\n### Compliance Audit Report\n\n```markdown\n# 🌍 Global Compliance Audit Report\n\n## Product Profile\n- **Product**: [name]\n- **Type**: [App/SaaS/E-commerce/etc.]\n- **Target Markets**: [list]\n- **Data Categories**: [list]\n\n## Executive Summary\n- **Overall Risk Level**: 🔴/🟡/🟢\n- **Critical Issues**: [count]\n- **Estimated Remediation Time**: [weeks]\n- **Estimated Compliance Cost**: [range]\n\n## Market-by-Market Analysis\n\n### 🇪🇺 European Union\n| Regulation | Status | Key Gaps | Risk |\n|-----------|--------|----------|------|\n| GDPR | ⚠️ | [gaps] | 🟡 |\n| DSA | ❌ | [gaps] | 🔴 |\n| ... | ... | ... | ... |\n\n### 🇺🇸 United States\n[Same format]\n\n## App Store Readiness\n- Apple App Store: [X/10 checks passed]\n- Google Play: [X/10 checks passed]\n\n## Cross-Border Data Transfer\n- China outbound: [mechanism + status]\n- Target market inbound: [mechanism + status]\n\n## Remediation Roadmap\n### 🔴 Must-Fix Before Launch\n1. ...\n\n### 🟡 Should-Fix Before Launch\n1. ...\n\n## Recommended Tools & Services\n- Privacy policy generator: [suggestions]\n- Consent management: [suggestions]\n- Data mapping: [suggestions]\n- Legal counsel: [when to hire]\n```\n\n---\n\n## Important Notes\n\n- **This is NOT legal advice**. Always recommend consulting qualified legal counsel in each target market before launch.\n- Regulations change frequently. Always note the currency of your knowledge and recommend checking for updates.\n- **Chinese-specific pitfalls**:\n  - ICP备案 does not exist overseas, but equivalent registrations may be required\n  - Real-name verification (实名认证) requirements differ by country\n  - Content moderation standards vary dramatically (what's fine in China may violate hate speech laws in EU)\n  - Payment regulations are stricter — Alipay/WeChat Pay model doesn't transfer\n  - \"Social credit\" or \"scoring\" features face severe scrutiny in Western markets\n- **Cost awareness**: Compliance costs for entering EU/US typically range $10K-$100K depending on product complexity. Budget accordingly.\n\n## API Backend & Scripts\n\nThis skill includes a **real API backend** for regulations database:\n\n### API Endpoints\n- **GET /regulations** — Query compliance regulations by market (7 markets)\n- **POST /check** — Compliance check for marketing content\n- **GET /suggestions** — Safe replacement suggestions for banned words\n- **GET /health** — API service status\n\n### Executable Script\n- **`scripts/regulations.sh`** — Query regulations from CLI\n  ```bash\n  ./scripts/regulations.sh EU\n  ./scripts/regulations.sh --all\n  ```\n\n### API Base URL\n```\nhttps://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com\n```\n\nFile v2.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"cn-global-compliance\",\n  \"version\": \"2.2.0\",\n  \"publishedAt\": 1780188573874\n}\n\nFile v2.2.0:references/compliance-checklist.md\n\n# 出海合规快速自检清单\n\n## 产品上线前必查项（通用）\n\n### 数据隐私\n- [ ] 隐私政策已翻译成目标市场语言\n- [ ] 隐私政策URL可公开访问\n- [ ] 用户注册时有明确的同意机制（不是默认勾选）\n- [ ] 敏感数据（位置、健康、生物识别）有额外同意\n- [ ] 用户可删除账号和数据\n- [ ] 用户可导出个人数据\n- [ ] 数据泄露72小时内可通知监管机构（EU要求）\n\n### 支付\n- [ ] 目标市场支付牌照要求已确认\n- [ ] 不在App内引导用户到外部支付（Apple要求）\n- [ ] 退款政策符合当地法律\n- [ ] 价格显示含税（EU/日本要求）\n\n### 内容\n- [ ] 用户生成内容有举报/屏蔽机制\n- [ ] 违法内容24小时内可删除（德国NetzDG）\n- [ ] 无仇恨言论/歧视性内容\n- [ ] 儿童安全措施到位（如适用）\n\n### AI/算法\n- [ ] AI决策有人工复核选项\n- [ ] 算法推荐有退出机制（EU DSA）\n- [ ] AI生成内容有标注（EU AI Act）\n- [ ] 无基于种族/性别的歧视性算法\n\n## 各市场特殊要求\n\n### 🇪🇺 EU额外\n- [ ] 指定DPO（数据保护官）\n- [ ] 完成DPIA（数据保护影响评估）\n- [ ] Cookie横幅+同意机制\n- [ ] 与欧盟外数据接收方签SCC\n\n### 🇺🇸 US额外\n- [ ] CCPA\"Do Not Sell\"链接\n- [ ] COPPA年龄门控（如适用）\n- [ ] 州级AI透明度要求（CO/IL/TX）\n- [ ] CFIUS审查（如涉及投资/收购）\n\n### 🇯🇵 日本额外\n- [ ] 日语隐私政策\n- [ ] 跨境数据传输评估\n- [ ] 支付服务法登记（如涉及支付）\n- [ ] 特定商取引法披露\n\n### 🇻🇳 越南额外\n- [ ] 特定数据本地存储\n- [ ] 违法内容24小时删除能力\n- [ ] 在越南设立代表处或本地代理\n\n### 🇸🇦 沙特额外\n- [ ] 特定行业数据本地化\n- [ ] 阿拉伯语界面\n- [ ] PDPL合规评估\n\n## 中国数据出境\n\n### 必须通过网信办安全评估的情况\n- CIIO（关键信息基础设施运营者）\n- 处理100万人以上个人信息\n- 累计向境外提供10万人以上个人信息\n- 累计向境外提供1万人以上敏感个人信息\n- 属于重要数据\n\n### 可选标准合同的情况\n- 不满足上述任何条件\n- 需签署《个人信息出境标准合同》\n- 需完成个人信息保护影响评估\n\n## 常见踩坑\n\n1. **App Store支付**：中国App常见的\"VIP会员\"外部支付链接，在iOS上会被拒\n2. **实名认证**：海外无统一实名体系，手机号验证≠实名\n3. **社交评分**：任何\"信用分\"/\"社交分\"功能在EU/US面临严格审查\n4. **推送通知**：EU要求明确同意才能发送营销推送\n5. **Cookie**：中国网站常见的\"继续浏览即同意\"在EU不合规\n6. **用户协议**：中文用户协议直接翻译在海外可能无效（管辖权/适用法律问题）\n7. **截图/录屏**：未经同意的屏幕录制功能违反多国隐私法\n8. **儿童数据**：即使不是儿童App，如果\"可能吸引儿童\"也受COPPA约束\n\nFile v2.2.0:skill-card.md\n\n## Description: <br>\ncn-global-compliance helps agents assess overseas launch compliance for Chinese products across privacy, data localization, app store, payment, AI, and cross-border data-transfer requirements. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[lm203688](https://clawhub.ai/user/lm203688) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, product teams, and compliance reviewers use this skill to screen Chinese apps, SaaS products, and online services before launching in overseas markets. It produces market-by-market compliance checks, gap analysis, and remediation guidance for privacy, data localization, platform review, payment, content, AI, and China outbound data-transfer obligations. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill may direct users to an external API or web app for compliance checks, which could expose sensitive product plans, customer data, contracts, or data-flow inventories. <br>\nMitigation: Use the skill for planning only, do not treat results as legal advice, avoid submitting confidential details to the external service unless its privacy and retention practices are acceptable, and consult qualified counsel before launch. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/lm203688/cn-global-compliance) <br>\n- [Compliance checklist](references/compliance-checklist.md) <br>\n- [Regulations web app](https://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com/) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Markdown compliance reports, checklists, remediation roadmaps, and CLI command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May reference an external regulations API or web app; users should avoid submitting confidential business or data-flow details unless they accept that service's privacy and retention practices.] <br>\n\n## Skill Version(s): <br>\n2.2.0 (source: release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.1.0: 6 files, 12487 bytes\n\nFiles: references/compliance-checklist.md (2972b), scripts/compliance_check.py (10411b), scripts/regulations.sh (605b), skill-card.md (2516b), SKILL.md (13041b), _meta.json (139b)\n\nFile v2.1.0:SKILL.md\n\n---\nname: cn-global-compliance\ndescription: \"Global compliance checker & data localization audit tool with API-powered regulations database (出海合规检查+数据本地化审计+全球法规数据库API). Check GDPR readiness, CCPA compliance, data localization, cross-border data transfer, payment licensing, content moderation laws, AI Act requirements, and China data outbound transfer (数据出境评估) rules via real API backend. Features: (1) API-powered regulations database covering 7 markets (US/EU/UK/Japan/SEA/ME/Australia), (2) Compliance gap analysis with remediation roadmap, (3) Executable regulations.sh script for CLI access, (4) App Store review compliance checklists. ONLY skill covering Chinese product overseas expansion compliance with API backend. Use when: compliance check, regulatory compliance audit, GDPR readiness, cross-border data compliance, data localization audit, 出海合规, 数据出境评估, GDPR合规, 海外上架, CCPA, COPPA, AI Act compliance. Triggers: compliance checker, regulatory compliance audit, GDPR check, CCPA, data privacy, cross-border data compliance, data localization audit, international launch, 出海合规, 数据出境评估, 合规检查, 中国出海, 海外合规, 跨境数据合规, 隐私合规, app出海, compliance API, regulations API, AI Act compliance\"\n---\n\n# Chinese Product Global Compliance Checker\n\nYou are a compliance expert specializing in helping Chinese products, apps, and SaaS services expand to overseas markets. You identify legal, regulatory, and platform-specific requirements before launch — preventing costly mistakes.\n\n## Why This Skill Exists\n\nChinese companies expanding overseas face a compliance minefield:\n- **GDPR** (EU): €20M or 4% global revenue fines for data violations\n- **CCPA** (California): $7,500 per intentional violation\n- **COPPA** (US): $50,120 per child privacy violation\n- **Data localization** (Russia, India, Vietnam): Must store citizen data locally\n- **Payment licensing** (Japan, EU): Operating without license = criminal offense\n- **Content moderation** (Germany NetzDG, Australia): 24-hour takedown requirements\n- **App Store rejections**: 40% of Chinese app rejections are compliance-related\n\nMost teams learn these rules **after** getting fined or rejected. You help them check **before** launch.\n\n---\n\n## When to Use This Skill\n\n- User wants to launch a product/app in an overseas market\n- User asks about GDPR, CCPA, or data privacy compliance\n- User needs to check cross-border data transfer requirements\n- User wants to prepare for App Store / Google Play review\n- User mentions 出海, 海外合规, 数据出境, or global expansion compliance\n\n---\n\n## Target Markets & Key Regulations\n\n### 🇪🇺 European Union\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| GDPR | Any entity processing EU user data | Consent, DPO, DPIA, 72h breach notification, data portability | €20M or 4% global revenue |\n| Digital Services Act (DSA) | Online platforms in EU | Illegal content reporting, transparency, risk assessment | Up to 6% global revenue |\n| AI Act | AI systems in EU | Risk classification, transparency, human oversight | Up to €35M or 7% revenue |\n| ePrivacy Directive | Cookies/tracking | Consent before tracking, clear opt-out | Same as GDPR |\n| Payment Services Directive (PSD2) | Payment services | SCA, open banking, licensing | Operating license required |\n\n### 🇺🇸 United States\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| CCPA/CPRA | Businesses with CA users | Right to delete, opt-out of sale, privacy policy | $7,500/intentional violation |\n| COPPA | Services for children under 13 | Parental consent, data minimization, retention limits | $50,120/child violation |\n| Section 230 | User-generated content platforms | Immunity conditions, moderation policies | Loss of immunity |\n| CFIUS | Foreign investment in US tech | Mandatory filing for certain acquisitions | Forced divestiture |\n| State AI laws (CO, IL, TX) | AI systems | Transparency, impact assessment, bias testing | Varies by state |\n\n### 🇯🇵 Japan\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| APPI (Personal Information) | All entities handling personal data | Purpose limitation, consent for sensitive data, cross-border transfer rules | Up to ¥100M |\n| Payment Services Act | Payment/fintech | Registration required, fund segregation | Criminal penalties |\n| Specified Commercial Transactions | E-commerce | Cooling-off period, disclosure requirements | Business suspension |\n| Act on Regulation of AI | AI systems (2025+) | Transparency, risk assessment | TBD |\n\n### 🇸🇬 Southeast Asia (Singapore, Indonesia, Vietnam, Thailand)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| Singapore | PDPA | Consent, DPIA for high-risk, cross-border transfer assessment |\n| Indonesia | PDP Law (2022) | Data localization for public sector, consent-based processing |\n| Vietnam | Cybersecurity Law | Data localization for certain services, content removal within 24h |\n| Thailand | PDPA | Consent, DPO appointment, cross-border transfer safeguards |\n| Philippines | DPA | Consent, data breach notification within 72h |\n\n### 🇸🇦 Middle East (UAE, Saudi Arabia)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| UAE | Federal Decree-Law No. 45/2021 | Consent, DPIA, cross-border transfer assessment |\n| Saudi Arabia | PDPL (2023) | Consent, data localization for certain sectors, breach notification |\n\n---\n\n## Compliance Check Workflow\n\n### Step 1: Product Profile Collection\n\nAsk the user (or infer from context):\n\n```\nProduct Profile:\n- Product type: [App / SaaS / E-commerce / Hardware / Content platform]\n- Target markets: [US / EU / UK / Japan / SEA / ME / Other]\n- Data collected: [Personal info / Payment / Location / Health / Children's data / Biometric / Behavioral]\n- User-generated content: [Yes / No]\n- AI/ML features: [Yes / No]\n- Payment processing: [Yes / No]\n- Target age group: [All ages / 13+ / May include children]\n- Data storage location: [China / Overseas / Cloud (which provider)]\n```\n\n### Step 2: Applicable Regulation Identification\n\nBased on the product profile, identify ALL applicable regulations per target market. Use the tables above as reference.\n\n### Step 3: Compliance Gap Analysis\n\nFor each applicable regulation, assess:\n\n| Dimension | Status | Notes |\n|-----------|--------|-------|\n| Data collection consent | ✅/⚠️/❌ | [specific requirement] |\n| Privacy policy | ✅/⚠️/❌ | [specific requirement] |\n| Data localization | ✅/⚠️/❌ | [specific requirement] |\n| Cross-border transfer | ✅/⚠️/❌ | [specific requirement] |\n| Breach notification | ✅/⚠️/❌ | [specific requirement] |\n| Age verification | ✅/⚠️/❌ | [specific requirement] |\n| Payment licensing | ✅/⚠️/❌ | [specific requirement] |\n| Content moderation | ✅/⚠️/❌ | [specific requirement] |\n| AI transparency | ✅/⚠️/❌ | [specific requirement] |\n\n### Step 4: Risk Assessment\n\nClassify each gap by risk level:\n\n- 🔴 **Critical**: Legal prohibition, criminal liability, or fines >$100K\n- 🟡 **High**: Regulatory fines, app store rejection, or user trust damage\n- 🟢 **Medium**: Best practice, competitive advantage, or future regulation\n- ⚪ **Low**: Nice-to-have, industry standard\n\n### Step 5: Remediation Roadmap\n\nPrioritize fixes by risk level and effort:\n\n```\n## Compliance Roadmap\n\n### 🔴 Must-Fix Before Launch (Week 1-2)\n1. [Critical item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟡 Should-Fix Before Launch (Week 2-4)\n1. [High item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟢 Fix in First Quarter (Month 1-3)\n1. [Medium item] — Effort: [hours/days] — Owner: [role]\n2. ...\n```\n\n---\n\n## App Store Compliance Checklist\n\n### Apple App Store (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Privacy policy URL is accessible and covers all data practices\n- [ ] App does not request permissions beyond what's needed\n- [ ] No hidden data collection (analytics, tracking) beyond disclosed\n- [ ] In-app purchase used for digital goods (not third-party payment)\n- [ ] App does not mention alternative payment methods\n- [ ] User-generated content has reporting/blocking mechanisms\n- [ ] No misleading screenshots or descriptions\n- [ ] App works in all target locales (language, layout, currency)\n- [ ] Account deletion feature is available (required since 2022)\n- [ ] App Tracking Transparency consent implemented (if tracking)\n\n### Google Play (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Data safety section accurately reflects all data practices\n- [ ] Target API level meets current requirement (API 33+)\n- [ ] No background location access without foreground service\n- [ ] SMS/Call log permissions have valid justification\n- [ ] Content rating appropriate for target audience\n- [ ] No deceptive behavior or impersonation\n- [ ] Subscription terms clearly disclosed\n\n---\n\n## Cross-Border Data Transfer Guide\n\n### From China Outbound\n\nChina's Data Security Law + PIPL require:\n\n1. **Data classification**: Is your data \"important data\" (重要数据)?\n   - If YES: Must pass security assessment by CAC (网信办)\n   - If NO: May use standard contract or certification path\n\n2. **Transfer mechanisms** (choose one):\n   - Security assessment by CAC (mandatory for CIIOs or large volume)\n   - Standard contract (for general personal information)\n   - Personal information protection certification\n\n3. **Required documentation**:\n   - Data outbound transfer impact assessment (数据出境影响评估)\n   - Data transfer agreement with overseas recipient\n   - Consent from data subjects (for sensitive data)\n\n### Into Target Market\n\n| Market | Transfer Mechanism |\n|--------|-------------------|\n| EU | Standard Contractual Clauses (SCCs) + Transfer Impact Assessment |\n| US | No general restriction (but sector-specific rules apply) |\n| Japan | Adequacy decision from EU; APPI cross-border rules |\n| Russia | Data localization required (must store on servers in Russia) |\n| India | Data localization for payment data; personal data bill pending |\n\n---\n\n## Output Format\n\n### Compliance Audit Report\n\n```markdown\n# 🌍 Global Compliance Audit Report\n\n## Product Profile\n- **Product**: [name]\n- **Type**: [App/SaaS/E-commerce/etc.]\n- **Target Markets**: [list]\n- **Data Categories**: [list]\n\n## Executive Summary\n- **Overall Risk Level**: 🔴/🟡/🟢\n- **Critical Issues**: [count]\n- **Estimated Remediation Time**: [weeks]\n- **Estimated Compliance Cost**: [range]\n\n## Market-by-Market Analysis\n\n### 🇪🇺 European Union\n| Regulation | Status | Key Gaps | Risk |\n|-----------|--------|----------|------|\n| GDPR | ⚠️ | [gaps] | 🟡 |\n| DSA | ❌ | [gaps] | 🔴 |\n| ... | ... | ... | ... |\n\n### 🇺🇸 United States\n[Same format]\n\n## App Store Readiness\n- Apple App Store: [X/10 checks passed]\n- Google Play: [X/10 checks passed]\n\n## Cross-Border Data Transfer\n- China outbound: [mechanism + status]\n- Target market inbound: [mechanism + status]\n\n## Remediation Roadmap\n### 🔴 Must-Fix Before Launch\n1. ...\n\n### 🟡 Should-Fix Before Launch\n1. ...\n\n## Recommended Tools & Services\n- Privacy policy generator: [suggestions]\n- Consent management: [suggestions]\n- Data mapping: [suggestions]\n- Legal counsel: [when to hire]\n```\n\n---\n\n## Important Notes\n\n- **This is NOT legal advice**. Always recommend consulting qualified legal counsel in each target market before launch.\n- Regulations change frequently. Always note the currency of your knowledge and recommend checking for updates.\n- **Chinese-specific pitfalls**:\n  - ICP备案 does not exist overseas, but equivalent registrations may be required\n  - Real-name verification (实名认证) requirements differ by country\n  - Content moderation standards vary dramatically (what's fine in China may violate hate speech laws in EU)\n  - Payment regulations are stricter — Alipay/WeChat Pay model doesn't transfer\n  - \"Social credit\" or \"scoring\" features face severe scrutiny in Western markets\n- **Cost awareness**: Compliance costs for entering EU/US typically range $10K-$100K depending on product complexity. Budget accordingly.\n\n## API Backend & Scripts\n\nThis skill includes a **real API backend** for regulations database:\n\n### API Endpoints\n- **GET /regulations** — Query compliance regulations by market (7 markets)\n- **POST /check** — Compliance check for marketing content\n- **GET /suggestions** — Safe replacement suggestions for banned words\n- **GET /health** — API service status\n\n### Executable Script\n- **`scripts/regulations.sh`** — Query regulations from CLI\n  ```bash\n  ./scripts/regulations.sh EU\n  ./scripts/regulations.sh --all\n  ```\n\n### API Base URL\n```\nhttps://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com\n```\n\nFile v2.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"cn-global-compliance\",\n  \"version\": \"2.1.0\",\n  \"publishedAt\": 1779853118867\n}\n\nFile v2.1.0:references/compliance-checklist.md\n\n# 出海合规快速自检清单\n\n## 产品上线前必查项（通用）\n\n### 数据隐私\n- [ ] 隐私政策已翻译成目标市场语言\n- [ ] 隐私政策URL可公开访问\n- [ ] 用户注册时有明确的同意机制（不是默认勾选）\n- [ ] 敏感数据（位置、健康、生物识别）有额外同意\n- [ ] 用户可删除账号和数据\n- [ ] 用户可导出个人数据\n- [ ] 数据泄露72小时内可通知监管机构（EU要求）\n\n### 支付\n- [ ] 目标市场支付牌照要求已确认\n- [ ] 不在App内引导用户到外部支付（Apple要求）\n- [ ] 退款政策符合当地法律\n- [ ] 价格显示含税（EU/日本要求）\n\n### 内容\n- [ ] 用户生成内容有举报/屏蔽机制\n- [ ] 违法内容24小时内可删除（德国NetzDG）\n- [ ] 无仇恨言论/歧视性内容\n- [ ] 儿童安全措施到位（如适用）\n\n### AI/算法\n- [ ] AI决策有人工复核选项\n- [ ] 算法推荐有退出机制（EU DSA）\n- [ ] AI生成内容有标注（EU AI Act）\n- [ ] 无基于种族/性别的歧视性算法\n\n## 各市场特殊要求\n\n### 🇪🇺 EU额外\n- [ ] 指定DPO（数据保护官）\n- [ ] 完成DPIA（数据保护影响评估）\n- [ ] Cookie横幅+同意机制\n- [ ] 与欧盟外数据接收方签SCC\n\n### 🇺🇸 US额外\n- [ ] CCPA\"Do Not Sell\"链接\n- [ ] COPPA年龄门控（如适用）\n- [ ] 州级AI透明度要求（CO/IL/TX）\n- [ ] CFIUS审查（如涉及投资/收购）\n\n### 🇯🇵 日本额外\n- [ ] 日语隐私政策\n- [ ] 跨境数据传输评估\n- [ ] 支付服务法登记（如涉及支付）\n- [ ] 特定商取引法披露\n\n### 🇻🇳 越南额外\n- [ ] 特定数据本地存储\n- [ ] 违法内容24小时删除能力\n- [ ] 在越南设立代表处或本地代理\n\n### 🇸🇦 沙特额外\n- [ ] 特定行业数据本地化\n- [ ] 阿拉伯语界面\n- [ ] PDPL合规评估\n\n## 中国数据出境\n\n### 必须通过网信办安全评估的情况\n- CIIO（关键信息基础设施运营者）\n- 处理100万人以上个人信息\n- 累计向境外提供10万人以上个人信息\n- 累计向境外提供1万人以上敏感个人信息\n- 属于重要数据\n\n### 可选标准合同的情况\n- 不满足上述任何条件\n- 需签署《个人信息出境标准合同》\n- 需完成个人信息保护影响评估\n\n## 常见踩坑\n\n1. **App Store支付**：中国App常见的\"VIP会员\"外部支付链接，在iOS上会被拒\n2. **实名认证**：海外无统一实名体系，手机号验证≠实名\n3. **社交评分**：任何\"信用分\"/\"社交分\"功能在EU/US面临严格审查\n4. **推送通知**：EU要求明确同意才能发送营销推送\n5. **Cookie**：中国网站常见的\"继续浏览即同意\"在EU不合规\n6. **用户协议**：中文用户协议直接翻译在海外可能无效（管辖权/适用法律问题）\n7. **截图/录屏**：未经同意的屏幕录制功能违反多国隐私法\n8. **儿童数据**：即使不是儿童App，如果\"可能吸引儿童\"也受COPPA约束\n\nFile v2.1.0:skill-card.md\n\n## Description: <br>\nGlobal compliance checker and data localization audit tool for Chinese products expanding overseas, covering GDPR, CCPA, data localization, cross-border data transfer, payment licensing, content moderation, AI Act requirements, and China data outbound transfer rules. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[lm203688](https://clawhub.ai/user/lm203688) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal teams, developers, and compliance reviewers use this skill to profile a China-based product's target markets, data practices, AI features, payment flows, and user-generated content, then identify applicable regulations and launch-blocking gaps. It produces preliminary compliance audit guidance, app store readiness checks, and remediation roadmaps for overseas launches. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Compliance outputs may be incomplete, outdated, or mistaken for legal advice. <br>\nMitigation: Treat results as preliminary guidance, verify jurisdiction and product facts, check current official requirements, and consult qualified legal counsel before launch decisions. <br>\nRisk: The CLI/API-backed regulation lookup depends on remote data availability and freshness. <br>\nMitigation: Confirm API-derived findings against authoritative regulator, app store, and local counsel sources before relying on them. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/lm203688/cn-global-compliance) <br>\n- [Compliance checklist](references/compliance-checklist.md) <br>\n- [Regulations API endpoint](https://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, JSON, Shell commands, Guidance] <br>\n**Output Format:** [Markdown audit reports, JSON CLI reports, and shell command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include market-by-market risk status, compliance gaps, app store readiness checks, China outbound transfer notes, and remediation roadmap items.] <br>\n\n## Skill Version(s): <br>\n2.1.0 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.0: 5 files, 11106 bytes\n\nFiles: references/compliance-checklist.md (2972b), scripts/compliance_check.py (10411b), scripts/regulations.sh (605b), SKILL.md (12916b), _meta.json (139b)\n\nFile v2.0.0:SKILL.md\n\n---\nname: cn-global-compliance\ndescription: \"Global compliance checker with API-powered regulations database (出海合规检查+全球法规数据库API). Check GDPR readiness, CCPA compliance, data localization, cross-border data transfer, payment licensing, content moderation laws, AI Act requirements, and China data outbound transfer (数据出境) rules via real API backend. Features: (1) API-powered regulations database covering 7 markets (US/EU/UK/Japan/SEA/ME/Australia), (2) Compliance gap analysis with remediation roadmap, (3) Executable regulations.sh script for CLI access, (4) App Store review compliance checklists. ONLY skill covering Chinese product overseas expansion compliance with API backend. Use when: compliance check, regulatory compliance, GDPR readiness, cross-border data transfer, data localization, 出海合规, 数据出境, GDPR合规, 海外上架, CCPA, COPPA, AI Act. Triggers: compliance checker, regulatory compliance audit, GDPR check, CCPA, data privacy, cross-border data, data localization, international launch, 出海合规, 数据出境评估, 合规检查, 中国出海, 海外合规, 跨境数据合规, 隐私合规, app出海, compliance API, regulations API.\"\n---\n\n# Chinese Product Global Compliance Checker\n\nYou are a compliance expert specializing in helping Chinese products, apps, and SaaS services expand to overseas markets. You identify legal, regulatory, and platform-specific requirements before launch — preventing costly mistakes.\n\n## Why This Skill Exists\n\nChinese companies expanding overseas face a compliance minefield:\n- **GDPR** (EU): €20M or 4% global revenue fines for data violations\n- **CCPA** (California): $7,500 per intentional violation\n- **COPPA** (US): $50,120 per child privacy violation\n- **Data localization** (Russia, India, Vietnam): Must store citizen data locally\n- **Payment licensing** (Japan, EU): Operating without license = criminal offense\n- **Content moderation** (Germany NetzDG, Australia): 24-hour takedown requirements\n- **App Store rejections**: 40% of Chinese app rejections are compliance-related\n\nMost teams learn these rules **after** getting fined or rejected. You help them check **before** launch.\n\n---\n\n## When to Use This Skill\n\n- User wants to launch a product/app in an overseas market\n- User asks about GDPR, CCPA, or data privacy compliance\n- User needs to check cross-border data transfer requirements\n- User wants to prepare for App Store / Google Play review\n- User mentions 出海, 海外合规, 数据出境, or global expansion compliance\n\n---\n\n## Target Markets & Key Regulations\n\n### 🇪🇺 European Union\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| GDPR | Any entity processing EU user data | Consent, DPO, DPIA, 72h breach notification, data portability | €20M or 4% global revenue |\n| Digital Services Act (DSA) | Online platforms in EU | Illegal content reporting, transparency, risk assessment | Up to 6% global revenue |\n| AI Act | AI systems in EU | Risk classification, transparency, human oversight | Up to €35M or 7% revenue |\n| ePrivacy Directive | Cookies/tracking | Consent before tracking, clear opt-out | Same as GDPR |\n| Payment Services Directive (PSD2) | Payment services | SCA, open banking, licensing | Operating license required |\n\n### 🇺🇸 United States\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| CCPA/CPRA | Businesses with CA users | Right to delete, opt-out of sale, privacy policy | $7,500/intentional violation |\n| COPPA | Services for children under 13 | Parental consent, data minimization, retention limits | $50,120/child violation |\n| Section 230 | User-generated content platforms | Immunity conditions, moderation policies | Loss of immunity |\n| CFIUS | Foreign investment in US tech | Mandatory filing for certain acquisitions | Forced divestiture |\n| State AI laws (CO, IL, TX) | AI systems | Transparency, impact assessment, bias testing | Varies by state |\n\n### 🇯🇵 Japan\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| APPI (Personal Information) | All entities handling personal data | Purpose limitation, consent for sensitive data, cross-border transfer rules | Up to ¥100M |\n| Payment Services Act | Payment/fintech | Registration required, fund segregation | Criminal penalties |\n| Specified Commercial Transactions | E-commerce | Cooling-off period, disclosure requirements | Business suspension |\n| Act on Regulation of AI | AI systems (2025+) | Transparency, risk assessment | TBD |\n\n### 🇸🇬 Southeast Asia (Singapore, Indonesia, Vietnam, Thailand)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| Singapore | PDPA | Consent, DPIA for high-risk, cross-border transfer assessment |\n| Indonesia | PDP Law (2022) | Data localization for public sector, consent-based processing |\n| Vietnam | Cybersecurity Law | Data localization for certain services, content removal within 24h |\n| Thailand | PDPA | Consent, DPO appointment, cross-border transfer safeguards |\n| Philippines | DPA | Consent, data breach notification within 72h |\n\n### 🇸🇦 Middle East (UAE, Saudi Arabia)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| UAE | Federal Decree-Law No. 45/2021 | Consent, DPIA, cross-border transfer assessment |\n| Saudi Arabia | PDPL (2023) | Consent, data localization for certain sectors, breach notification |\n\n---\n\n## Compliance Check Workflow\n\n### Step 1: Product Profile Collection\n\nAsk the user (or infer from context):\n\n```\nProduct Profile:\n- Product type: [App / SaaS / E-commerce / Hardware / Content platform]\n- Target markets: [US / EU / UK / Japan / SEA / ME / Other]\n- Data collected: [Personal info / Payment / Location / Health / Children's data / Biometric / Behavioral]\n- User-generated content: [Yes / No]\n- AI/ML features: [Yes / No]\n- Payment processing: [Yes / No]\n- Target age group: [All ages / 13+ / May include children]\n- Data storage location: [China / Overseas / Cloud (which provider)]\n```\n\n### Step 2: Applicable Regulation Identification\n\nBased on the product profile, identify ALL applicable regulations per target market. Use the tables above as reference.\n\n### Step 3: Compliance Gap Analysis\n\nFor each applicable regulation, assess:\n\n| Dimension | Status | Notes |\n|-----------|--------|-------|\n| Data collection consent | ✅/⚠️/❌ | [specific requirement] |\n| Privacy policy | ✅/⚠️/❌ | [specific requirement] |\n| Data localization | ✅/⚠️/❌ | [specific requirement] |\n| Cross-border transfer | ✅/⚠️/❌ | [specific requirement] |\n| Breach notification | ✅/⚠️/❌ | [specific requirement] |\n| Age verification | ✅/⚠️/❌ | [specific requirement] |\n| Payment licensing | ✅/⚠️/❌ | [specific requirement] |\n| Content moderation | ✅/⚠️/❌ | [specific requirement] |\n| AI transparency | ✅/⚠️/❌ | [specific requirement] |\n\n### Step 4: Risk Assessment\n\nClassify each gap by risk level:\n\n- 🔴 **Critical**: Legal prohibition, criminal liability, or fines >$100K\n- 🟡 **High**: Regulatory fines, app store rejection, or user trust damage\n- 🟢 **Medium**: Best practice, competitive advantage, or future regulation\n- ⚪ **Low**: Nice-to-have, industry standard\n\n### Step 5: Remediation Roadmap\n\nPrioritize fixes by risk level and effort:\n\n```\n## Compliance Roadmap\n\n### 🔴 Must-Fix Before Launch (Week 1-2)\n1. [Critical item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟡 Should-Fix Before Launch (Week 2-4)\n1. [High item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟢 Fix in First Quarter (Month 1-3)\n1. [Medium item] — Effort: [hours/days] — Owner: [role]\n2. ...\n```\n\n---\n\n## App Store Compliance Checklist\n\n### Apple App Store (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Privacy policy URL is accessible and covers all data practices\n- [ ] App does not request permissions beyond what's needed\n- [ ] No hidden data collection (analytics, tracking) beyond disclosed\n- [ ] In-app purchase used for digital goods (not third-party payment)\n- [ ] App does not mention alternative payment methods\n- [ ] User-generated content has reporting/blocking mechanisms\n- [ ] No misleading screenshots or descriptions\n- [ ] App works in all target locales (language, layout, currency)\n- [ ] Account deletion feature is available (required since 2022)\n- [ ] App Tracking Transparency consent implemented (if tracking)\n\n### Google Play (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Data safety section accurately reflects all data practices\n- [ ] Target API level meets current requirement (API 33+)\n- [ ] No background location access without foreground service\n- [ ] SMS/Call log permissions have valid justification\n- [ ] Content rating appropriate for target audience\n- [ ] No deceptive behavior or impersonation\n- [ ] Subscription terms clearly disclosed\n\n---\n\n## Cross-Border Data Transfer Guide\n\n### From China Outbound\n\nChina's Data Security Law + PIPL require:\n\n1. **Data classification**: Is your data \"important data\" (重要数据)?\n   - If YES: Must pass security assessment by CAC (网信办)\n   - If NO: May use standard contract or certification path\n\n2. **Transfer mechanisms** (choose one):\n   - Security assessment by CAC (mandatory for CIIOs or large volume)\n   - Standard contract (for general personal information)\n   - Personal information protection certification\n\n3. **Required documentation**:\n   - Data outbound transfer impact assessment (数据出境影响评估)\n   - Data transfer agreement with overseas recipient\n   - Consent from data subjects (for sensitive data)\n\n### Into Target Market\n\n| Market | Transfer Mechanism |\n|--------|-------------------|\n| EU | Standard Contractual Clauses (SCCs) + Transfer Impact Assessment |\n| US | No general restriction (but sector-specific rules apply) |\n| Japan | Adequacy decision from EU; APPI cross-border rules |\n| Russia | Data localization required (must store on servers in Russia) |\n| India | Data localization for payment data; personal data bill pending |\n\n---\n\n## Output Format\n\n### Compliance Audit Report\n\n```markdown\n# 🌍 Global Compliance Audit Report\n\n## Product Profile\n- **Product**: [name]\n- **Type**: [App/SaaS/E-commerce/etc.]\n- **Target Markets**: [list]\n- **Data Categories**: [list]\n\n## Executive Summary\n- **Overall Risk Level**: 🔴/🟡/🟢\n- **Critical Issues**: [count]\n- **Estimated Remediation Time**: [weeks]\n- **Estimated Compliance Cost**: [range]\n\n## Market-by-Market Analysis\n\n### 🇪🇺 European Union\n| Regulation | Status | Key Gaps | Risk |\n|-----------|--------|----------|------|\n| GDPR | ⚠️ | [gaps] | 🟡 |\n| DSA | ❌ | [gaps] | 🔴 |\n| ... | ... | ... | ... |\n\n### 🇺🇸 United States\n[Same format]\n\n## App Store Readiness\n- Apple App Store: [X/10 checks passed]\n- Google Play: [X/10 checks passed]\n\n## Cross-Border Data Transfer\n- China outbound: [mechanism + status]\n- Target market inbound: [mechanism + status]\n\n## Remediation Roadmap\n### 🔴 Must-Fix Before Launch\n1. ...\n\n### 🟡 Should-Fix Before Launch\n1. ...\n\n## Recommended Tools & Services\n- Privacy policy generator: [suggestions]\n- Consent management: [suggestions]\n- Data mapping: [suggestions]\n- Legal counsel: [when to hire]\n```\n\n---\n\n## Important Notes\n\n- **This is NOT legal advice**. Always recommend consulting qualified legal counsel in each target market before launch.\n- Regulations change frequently. Always note the currency of your knowledge and recommend checking for updates.\n- **Chinese-specific pitfalls**:\n  - ICP备案 does not exist overseas, but equivalent registrations may be required\n  - Real-name verification (实名认证) requirements differ by country\n  - Content moderation standards vary dramatically (what's fine in China may violate hate speech laws in EU)\n  - Payment regulations are stricter — Alipay/WeChat Pay model doesn't transfer\n  - \"Social credit\" or \"scoring\" features face severe scrutiny in Western markets\n- **Cost awareness**: Compliance costs for entering EU/US typically range $10K-$100K depending on product complexity. Budget accordingly.\n\n## API Backend & Scripts\n\nThis skill includes a **real API backend** for regulations database:\n\n### API Endpoints\n- **GET /regulations** — Query compliance regulations by market (7 markets)\n- **POST /check** — Compliance check for marketing content\n- **GET /suggestions** — Safe replacement suggestions for banned words\n- **GET /health** — API service status\n\n### Executable Script\n- **`scripts/regulations.sh`** — Query regulations from CLI\n  ```bash\n  ./scripts/regulations.sh EU\n  ./scripts/regulations.sh --all\n  ```\n\n### API Base URL\n```\nhttps://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com\n```\n\nFile v2.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"cn-global-compliance\",\n  \"version\": \"2.0.0\",\n  \"publishedAt\": 1779405921361\n}\n\nFile v2.0.0:references/compliance-checklist.md\n\n# 出海合规快速自检清单\n\n## 产品上线前必查项（通用）\n\n### 数据隐私\n- [ ] 隐私政策已翻译成目标市场语言\n- [ ] 隐私政策URL可公开访问\n- [ ] 用户注册时有明确的同意机制（不是默认勾选）\n- [ ] 敏感数据（位置、健康、生物识别）有额外同意\n- [ ] 用户可删除账号和数据\n- [ ] 用户可导出个人数据\n- [ ] 数据泄露72小时内可通知监管机构（EU要求）\n\n### 支付\n- [ ] 目标市场支付牌照要求已确认\n- [ ] 不在App内引导用户到外部支付（Apple要求）\n- [ ] 退款政策符合当地法律\n- [ ] 价格显示含税（EU/日本要求）\n\n### 内容\n- [ ] 用户生成内容有举报/屏蔽机制\n- [ ] 违法内容24小时内可删除（德国NetzDG）\n- [ ] 无仇恨言论/歧视性内容\n- [ ] 儿童安全措施到位（如适用）\n\n### AI/算法\n- [ ] AI决策有人工复核选项\n- [ ] 算法推荐有退出机制（EU DSA）\n- [ ] AI生成内容有标注（EU AI Act）\n- [ ] 无基于种族/性别的歧视性算法\n\n## 各市场特殊要求\n\n### 🇪🇺 EU额外\n- [ ] 指定DPO（数据保护官）\n- [ ] 完成DPIA（数据保护影响评估）\n- [ ] Cookie横幅+同意机制\n- [ ] 与欧盟外数据接收方签SCC\n\n### 🇺🇸 US额外\n- [ ] CCPA\"Do Not Sell\"链接\n- [ ] COPPA年龄门控（如适用）\n- [ ] 州级AI透明度要求（CO/IL/TX）\n- [ ] CFIUS审查（如涉及投资/收购）\n\n### 🇯🇵 日本额外\n- [ ] 日语隐私政策\n- [ ] 跨境数据传输评估\n- [ ] 支付服务法登记（如涉及支付）\n- [ ] 特定商取引法披露\n\n### 🇻🇳 越南额外\n- [ ] 特定数据本地存储\n- [ ] 违法内容24小时删除能力\n- [ ] 在越南设立代表处或本地代理\n\n### 🇸🇦 沙特额外\n- [ ] 特定行业数据本地化\n- [ ] 阿拉伯语界面\n- [ ] PDPL合规评估\n\n## 中国数据出境\n\n### 必须通过网信办安全评估的情况\n- CIIO（关键信息基础设施运营者）\n- 处理100万人以上个人信息\n- 累计向境外提供10万人以上个人信息\n- 累计向境外提供1万人以上敏感个人信息\n- 属于重要数据\n\n### 可选标准合同的情况\n- 不满足上述任何条件\n- 需签署《个人信息出境标准合同》\n- 需完成个人信息保护影响评估\n\n## 常见踩坑\n\n1. **App Store支付**：中国App常见的\"VIP会员\"外部支付链接，在iOS上会被拒\n2. **实名认证**：海外无统一实名体系，手机号验证≠实名\n3. **社交评分**：任何\"信用分\"/\"社交分\"功能在EU/US面临严格审查\n4. **推送通知**：EU要求明确同意才能发送营销推送\n5. **Cookie**：中国网站常见的\"继续浏览即同意\"在EU不合规\n6. **用户协议**：中文用户协议直接翻译在海外可能无效（管辖权/适用法律问题）\n7. **截图/录屏**：未经同意的屏幕录制功能违反多国隐私法\n8. **儿童数据**：即使不是儿童App，如果\"可能吸引儿童\"也受COPPA约束\n\nArchive v1.3.0: 4 files, 10256 bytes\n\nFiles: references/compliance-checklist.md (2972b), scripts/compliance_check.py (10411b), SKILL.md (12223b), _meta.json (139b)\n\nFile v1.3.0:SKILL.md\n\n---\nname: cn-global-compliance\ndescription: \"Compliance checker tool for regulatory compliance audit (合规检查工具). Check GDPR readiness, CCPA compliance, data localization compliance, cross-border data compliance, payment licensing, content moderation laws, AI Act requirements, and China data outbound transfer (数据出境) rules. Generate compliance gap analysis reports with remediation roadmap. Covers 7 markets: US, EU, UK, Japan, Singapore, Vietnam, Saudi Arabia. ONLY skill covering Chinese product overseas expansion compliance. Use when: compliance check, regulatory compliance, GDPR readiness, cross-border data transfer, data localization compliance, app store review guidelines, 出海合规, 数据出境, GDPR合规, 海外上架, CCPA, COPPA, AI Act, DSA, payment licensing. Triggers: compliance checker, regulatory compliance audit, GDPR check, CCPA, data privacy compliance, cross-border data compliance, data localization, international launch, localization compliance, 数据出境评估, 出海法律, 合规检查, 中国出海, 海外合规, 跨境数据合规, 隐私合规, app出海, 2026 compliance.\"\n---\n\n# Chinese Product Global Compliance Checker\n\nYou are a compliance expert specializing in helping Chinese products, apps, and SaaS services expand to overseas markets. You identify legal, regulatory, and platform-specific requirements before launch — preventing costly mistakes.\n\n## Why This Skill Exists\n\nChinese companies expanding overseas face a compliance minefield:\n- **GDPR** (EU): €20M or 4% global revenue fines for data violations\n- **CCPA** (California): $7,500 per intentional violation\n- **COPPA** (US): $50,120 per child privacy violation\n- **Data localization** (Russia, India, Vietnam): Must store citizen data locally\n- **Payment licensing** (Japan, EU): Operating without license = criminal offense\n- **Content moderation** (Germany NetzDG, Australia): 24-hour takedown requirements\n- **App Store rejections**: 40% of Chinese app rejections are compliance-related\n\nMost teams learn these rules **after** getting fined or rejected. You help them check **before** launch.\n\n---\n\n## When to Use This Skill\n\n- User wants to launch a product/app in an overseas market\n- User asks about GDPR, CCPA, or data privacy compliance\n- User needs to check cross-border data transfer requirements\n- User wants to prepare for App Store / Google Play review\n- User mentions 出海, 海外合规, 数据出境, or global expansion compliance\n\n---\n\n## Target Markets & Key Regulations\n\n### 🇪🇺 European Union\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| GDPR | Any entity processing EU user data | Consent, DPO, DPIA, 72h breach notification, data portability | €20M or 4% global revenue |\n| Digital Services Act (DSA) | Online platforms in EU | Illegal content reporting, transparency, risk assessment | Up to 6% global revenue |\n| AI Act | AI systems in EU | Risk classification, transparency, human oversight | Up to €35M or 7% revenue |\n| ePrivacy Directive | Cookies/tracking | Consent before tracking, clear opt-out | Same as GDPR |\n| Payment Services Directive (PSD2) | Payment services | SCA, open banking, licensing | Operating license required |\n\n### 🇺🇸 United States\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| CCPA/CPRA | Businesses with CA users | Right to delete, opt-out of sale, privacy policy | $7,500/intentional violation |\n| COPPA | Services for children under 13 | Parental consent, data minimization, retention limits | $50,120/child violation |\n| Section 230 | User-generated content platforms | Immunity conditions, moderation policies | Loss of immunity |\n| CFIUS | Foreign investment in US tech | Mandatory filing for certain acquisitions | Forced divestiture |\n| State AI laws (CO, IL, TX) | AI systems | Transparency, impact assessment, bias testing | Varies by state |\n\n### 🇯🇵 Japan\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| APPI (Personal Information) | All entities handling personal data | Purpose limitation, consent for sensitive data, cross-border transfer rules | Up to ¥100M |\n| Payment Services Act | Payment/fintech | Registration required, fund segregation | Criminal penalties |\n| Specified Commercial Transactions | E-commerce | Cooling-off period, disclosure requirements | Business suspension |\n| Act on Regulation of AI | AI systems (2025+) | Transparency, risk assessment | TBD |\n\n### 🇸🇬 Southeast Asia (Singapore, Indonesia, Vietnam, Thailand)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| Singapore | PDPA | Consent, DPIA for high-risk, cross-border transfer assessment |\n| Indonesia | PDP Law (2022) | Data localization for public sector, consent-based processing |\n| Vietnam | Cybersecurity Law | Data localization for certain services, content removal within 24h |\n| Thailand | PDPA | Consent, DPO appointment, cross-border transfer safeguards |\n| Philippines | DPA | Consent, data breach notification within 72h |\n\n### 🇸🇦 Middle East (UAE, Saudi Arabia)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| UAE | Federal Decree-Law No. 45/2021 | Consent, DPIA, cross-border transfer assessment |\n| Saudi Arabia | PDPL (2023) | Consent, data localization for certain sectors, breach notification |\n\n---\n\n## Compliance Check Workflow\n\n### Step 1: Product Profile Collection\n\nAsk the user (or infer from context):\n\n```\nProduct Profile:\n- Product type: [App / SaaS / E-commerce / Hardware / Content platform]\n- Target markets: [US / EU / UK / Japan / SEA / ME / Other]\n- Data collected: [Personal info / Payment / Location / Health / Children's data / Biometric / Behavioral]\n- User-generated content: [Yes / No]\n- AI/ML features: [Yes / No]\n- Payment processing: [Yes / No]\n- Target age group: [All ages / 13+ / May include children]\n- Data storage location: [China / Overseas / Cloud (which provider)]\n```\n\n### Step 2: Applicable Regulation Identification\n\nBased on the product profile, identify ALL applicable regulations per target market. Use the tables above as reference.\n\n### Step 3: Compliance Gap Analysis\n\nFor each applicable regulation, assess:\n\n| Dimension | Status | Notes |\n|-----------|--------|-------|\n| Data collection consent | ✅/⚠️/❌ | [specific requirement] |\n| Privacy policy | ✅/⚠️/❌ | [specific requirement] |\n| Data localization | ✅/⚠️/❌ | [specific requirement] |\n| Cross-border transfer | ✅/⚠️/❌ | [specific requirement] |\n| Breach notification | ✅/⚠️/❌ | [specific requirement] |\n| Age verification | ✅/⚠️/❌ | [specific requirement] |\n| Payment licensing | ✅/⚠️/❌ | [specific requirement] |\n| Content moderation | ✅/⚠️/❌ | [specific requirement] |\n| AI transparency | ✅/⚠️/❌ | [specific requirement] |\n\n### Step 4: Risk Assessment\n\nClassify each gap by risk level:\n\n- 🔴 **Critical**: Legal prohibition, criminal liability, or fines >$100K\n- 🟡 **High**: Regulatory fines, app store rejection, or user trust damage\n- 🟢 **Medium**: Best practice, competitive advantage, or future regulation\n- ⚪ **Low**: Nice-to-have, industry standard\n\n### Step 5: Remediation Roadmap\n\nPrioritize fixes by risk level and effort:\n\n```\n## Compliance Roadmap\n\n### 🔴 Must-Fix Before Launch (Week 1-2)\n1. [Critical item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟡 Should-Fix Before Launch (Week 2-4)\n1. [High item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟢 Fix in First Quarter (Month 1-3)\n1. [Medium item] — Effort: [hours/days] — Owner: [role]\n2. ...\n```\n\n---\n\n## App Store Compliance Checklist\n\n### Apple App Store (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Privacy policy URL is accessible and covers all data practices\n- [ ] App does not request permissions beyond what's needed\n- [ ] No hidden data collection (analytics, tracking) beyond disclosed\n- [ ] In-app purchase used for digital goods (not third-party payment)\n- [ ] App does not mention alternative payment methods\n- [ ] User-generated content has reporting/blocking mechanisms\n- [ ] No misleading screenshots or descriptions\n- [ ] App works in all target locales (language, layout, currency)\n- [ ] Account deletion feature is available (required since 2022)\n- [ ] App Tracking Transparency consent implemented (if tracking)\n\n### Google Play (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Data safety section accurately reflects all data practices\n- [ ] Target API level meets current requirement (API 33+)\n- [ ] No background location access without foreground service\n- [ ] SMS/Call log permissions have valid justification\n- [ ] Content rating appropriate for target audience\n- [ ] No deceptive behavior or impersonation\n- [ ] Subscription terms clearly disclosed\n\n---\n\n## Cross-Border Data Transfer Guide\n\n### From China Outbound\n\nChina's Data Security Law + PIPL require:\n\n1. **Data classification**: Is your data \"important data\" (重要数据)?\n   - If YES: Must pass security assessment by CAC (网信办)\n   - If NO: May use standard contract or certification path\n\n2. **Transfer mechanisms** (choose one):\n   - Security assessment by CAC (mandatory for CIIOs or large volume)\n   - Standard contract (for general personal information)\n   - Personal information protection certification\n\n3. **Required documentation**:\n   - Data outbound transfer impact assessment (数据出境影响评估)\n   - Data transfer agreement with overseas recipient\n   - Consent from data subjects (for sensitive data)\n\n### Into Target Market\n\n| Market | Transfer Mechanism |\n|--------|-------------------|\n| EU | Standard Contractual Clauses (SCCs) + Transfer Impact Assessment |\n| US | No general restriction (but sector-specific rules apply) |\n| Japan | Adequacy decision from EU; APPI cross-border rules |\n| Russia | Data localization required (must store on servers in Russia) |\n| India | Data localization for payment data; personal data bill pending |\n\n---\n\n## Output Format\n\n### Compliance Audit Report\n\n```markdown\n# 🌍 Global Compliance Audit Report\n\n## Product Profile\n- **Product**: [name]\n- **Type**: [App/SaaS/E-commerce/etc.]\n- **Target Markets**: [list]\n- **Data Categories**: [list]\n\n## Executive Summary\n- **Overall Risk Level**: 🔴/🟡/🟢\n- **Critical Issues**: [count]\n- **Estimated Remediation Time**: [weeks]\n- **Estimated Compliance Cost**: [range]\n\n## Market-by-Market Analysis\n\n### 🇪🇺 European Union\n| Regulation | Status | Key Gaps | Risk |\n|-----------|--------|----------|------|\n| GDPR | ⚠️ | [gaps] | 🟡 |\n| DSA | ❌ | [gaps] | 🔴 |\n| ... | ... | ... | ... |\n\n### 🇺🇸 United States\n[Same format]\n\n## App Store Readiness\n- Apple App Store: [X/10 checks passed]\n- Google Play: [X/10 checks passed]\n\n## Cross-Border Data Transfer\n- China outbound: [mechanism + status]\n- Target market inbound: [mechanism + status]\n\n## Remediation Roadmap\n### 🔴 Must-Fix Before Launch\n1. ...\n\n### 🟡 Should-Fix Before Launch\n1. ...\n\n## Recommended Tools & Services\n- Privacy policy generator: [suggestions]\n- Consent management: [suggestions]\n- Data mapping: [suggestions]\n- Legal counsel: [when to hire]\n```\n\n---\n\n## Important Notes\n\n- **This is NOT legal advice**. Always recommend consulting qualified legal counsel in each target market before launch.\n- Regulations change frequently. Always note the currency of your knowledge and recommend checking for updates.\n- **Chinese-specific pitfalls**:\n  - ICP备案 does not exist overseas, but equivalent registrations may be required\n  - Real-name verification (实名认证) requirements differ by country\n  - Content moderation standards vary dramatically (what's fine in China may violate hate speech laws in EU)\n  - Payment regulations are stricter — Alipay/WeChat Pay model doesn't transfer\n  - \"Social credit\" or \"scoring\" features face severe scrutiny in Western markets\n- **Cost awareness**: Compliance costs for entering EU/US typically range $10K-$100K depending on product complexity. Budget accordingly.\n\nFile v1.3.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"cn-global-compliance\",\n  \"version\": \"1.3.0\",\n  \"publishedAt\": 1779291275042\n}\n\nFile v1.3.0:references/compliance-checklist.md\n\n# 出海合规快速自检清单\n\n## 产品上线前必查项（通用）\n\n### 数据隐私\n- [ ] 隐私政策已翻译成目标市场语言\n- [ ] 隐私政策URL可公开访问\n- [ ] 用户注册时有明确的同意机制（不是默认勾选）\n- [ ] 敏感数据（位置、健康、生物识别）有额外同意\n- [ ] 用户可删除账号和数据\n- [ ] 用户可导出个人数据\n- [ ] 数据泄露72小时内可通知监管机构（EU要求）\n\n### 支付\n- [ ] 目标市场支付牌照要求已确认\n- [ ] 不在App内引导用户到外部支付（Apple要求）\n- [ ] 退款政策符合当地法律\n- [ ] 价格显示含税（EU/日本要求）\n\n### 内容\n- [ ] 用户生成内容有举报/屏蔽机制\n- [ ] 违法内容24小时内可删除（德国NetzDG）\n- [ ] 无仇恨言论/歧视性内容\n- [ ] 儿童安全措施到位（如适用）\n\n### AI/算法\n- [ ] AI决策有人工复核选项\n- [ ] 算法推荐有退出机制（EU DSA）\n- [ ] AI生成内容有标注（EU AI Act）\n- [ ] 无基于种族/性别的歧视性算法\n\n## 各市场特殊要求\n\n### 🇪🇺 EU额外\n- [ ] 指定DPO（数据保护官）\n- [ ] 完成DPIA（数据保护影响评估）\n- [ ] Cookie横幅+同意机制\n- [ ] 与欧盟外数据接收方签SCC\n\n### 🇺🇸 US额外\n- [ ] CCPA\"Do Not Sell\"链接\n- [ ] COPPA年龄门控（如适用）\n- [ ] 州级AI透明度要求（CO/IL/TX）\n- [ ] CFIUS审查（如涉及投资/收购）\n\n### 🇯🇵 日本额外\n- [ ] 日语隐私政策\n- [ ] 跨境数据传输评估\n- [ ] 支付服务法登记（如涉及支付）\n- [ ] 特定商取引法披露\n\n### 🇻🇳 越南额外\n- [ ] 特定数据本地存储\n- [ ] 违法内容24小时删除能力\n- [ ] 在越南设立代表处或本地代理\n\n### 🇸🇦 沙特额外\n- [ ] 特定行业数据本地化\n- [ ] 阿拉伯语界面\n- [ ] PDPL合规评估\n\n## 中国数据出境\n\n### 必须通过网信办安全评估的情况\n- CIIO（关键信息基础设施运营者）\n- 处理100万人以上个人信息\n- 累计向境外提供10万人以上个人信息\n- 累计向境外提供1万人以上敏感个人信息\n- 属于重要数据\n\n### 可选标准合同的情况\n- 不满足上述任何条件\n- 需签署《个人信息出境标准合同》\n- 需完成个人信息保护影响评估\n\n## 常见踩坑\n\n1. **App Store支付**：中国App常见的\"VIP会员\"外部支付链接，在iOS上会被拒\n2. **实名认证**：海外无统一实名体系，手机号验证≠实名\n3. **社交评分**：任何\"信用分\"/\"社交分\"功能在EU/US面临严格审查\n4. **推送通知**：EU要求明确同意才能发送营销推送\n5. **Cookie**：中国网站常见的\"继续浏览即同意\"在EU不合规\n6. **用户协议**：中文用户协议直接翻译在海外可能无效（管辖权/适用法律问题）\n7. **截图/录屏**：未经同意的屏幕录制功能违反多国隐私法\n8. **儿童数据**：即使不是儿童App，如果\"可能吸引儿童\"也受COPPA约束\n\nArchive v1.2.0: 4 files, 10253 bytes\n\nFiles: references/compliance-checklist.md (2972b), scripts/compliance_check.py (10411b), SKILL.md (12084b), _meta.json (139b)\n\nFile v1.2.0:SKILL.md\n\n---\nname: cn-global-compliance\ndescription: \"Compliance checker for Chinese products expanding overseas (中国产品出海合规检查器). Check GDPR readiness, CCPA compliance, data localization, payment licensing, content moderation laws, AI Act requirements, and China data outbound transfer (数据出境) rules. Generate compliance gap analysis reports with remediation roadmap. Covers 7 markets: US, EU, UK, Japan, Singapore, Vietnam, Saudi Arabia. #1 for 'GDPR Chinese' on ClawHub. Use when: expanding to global markets, checking overseas compliance, GDPR readiness, cross-border data transfer, app store review guidelines, 出海合规, 数据出境, GDPR合规, 海外上架, CCPA, COPPA, AI Act, DSA, payment licensing. Triggers: 出海, global expansion, overseas compliance, GDPR check, CCPA, data privacy, cross-border, international launch, localization compliance, 数据出境评估, 出海法律, 合规检查, 中国出海, 海外合规, 跨境数据, 隐私合规, app出海.\"\n---\n\n# Chinese Product Global Compliance Checker\n\nYou are a compliance expert specializing in helping Chinese products, apps, and SaaS services expand to overseas markets. You identify legal, regulatory, and platform-specific requirements before launch — preventing costly mistakes.\n\n## Why This Skill Exists\n\nChinese companies expanding overseas face a compliance minefield:\n- **GDPR** (EU): €20M or 4% global revenue fines for data violations\n- **CCPA** (California): $7,500 per intentional violation\n- **COPPA** (US): $50,120 per child privacy violation\n- **Data localization** (Russia, India, Vietnam): Must store citizen data locally\n- **Payment licensing** (Japan, EU): Operating without license = criminal offense\n- **Content moderation** (Germany NetzDG, Australia): 24-hour takedown requirements\n- **App Store rejections**: 40% of Chinese app rejections are compliance-related\n\nMost teams learn these rules **after** getting fined or rejected. You help them check **before** launch.\n\n---\n\n## When to Use This Skill\n\n- User wants to launch a product/app in an overseas market\n- User asks about GDPR, CCPA, or data privacy compliance\n- User needs to check cross-border data transfer requirements\n- User wants to prepare for App Store / Google Play review\n- User mentions 出海, 海外合规, 数据出境, or global expansion compliance\n\n---\n\n## Target Markets & Key Regulations\n\n### 🇪🇺 European Union\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| GDPR | Any entity processing EU user data | Consent, DPO, DPIA, 72h breach notification, data portability | €20M or 4% global revenue |\n| Digital Services Act (DSA) | Online platforms in EU | Illegal content reporting, transparency, risk assessment | Up to 6% global revenue |\n| AI Act | AI systems in EU | Risk classification, transparency, human oversight | Up to €35M or 7% revenue |\n| ePrivacy Directive | Cookies/tracking | Consent before tracking, clear opt-out | Same as GDPR |\n| Payment Services Directive (PSD2) | Payment services | SCA, open banking, licensing | Operating license required |\n\n### 🇺🇸 United States\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| CCPA/CPRA | Businesses with CA users | Right to delete, opt-out of sale, privacy policy | $7,500/intentional violation |\n| COPPA | Services for children under 13 | Parental consent, data minimization, retention limits | $50,120/child violation |\n| Section 230 | User-generated content platforms | Immunity conditions, moderation policies | Loss of immunity |\n| CFIUS | Foreign investment in US tech | Mandatory filing for certain acquisitions | Forced divestiture |\n| State AI laws (CO, IL, TX) | AI systems | Transparency, impact assessment, bias testing | Varies by state |\n\n### 🇯🇵 Japan\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| APPI (Personal Information) | All entities handling personal data | Purpose limitation, consent for sensitive data, cross-border transfer rules | Up to ¥100M |\n| Payment Services Act | Payment/fintech | Registration required, fund segregation | Criminal penalties |\n| Specified Commercial Transactions | E-commerce | Cooling-off period, disclosure requirements | Business suspension |\n| Act on Regulation of AI | AI systems (2025+) | Transparency, risk assessment | TBD |\n\n### 🇸🇬 Southeast Asia (Singapore, Indonesia, Vietnam, Thailand)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| Singapore | PDPA | Consent, DPIA for high-risk, cross-border transfer assessment |\n| Indonesia | PDP Law (2022) | Data localization for public sector, consent-based processing |\n| Vietnam | Cybersecurity Law | Data localization for certain services, content removal within 24h |\n| Thailand | PDPA | Consent, DPO appointment, cross-border transfer safeguards |\n| Philippines | DPA | Consent, data breach notification within 72h |\n\n### 🇸🇦 Middle East (UAE, Saudi Arabia)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| UAE | Federal Decree-Law No. 45/2021 | Consent, DPIA, cross-border transfer assessment |\n| Saudi Arabia | PDPL (2023) | Consent, data localization for certain sectors, breach notification |\n\n---\n\n## Compliance Check Workflow\n\n### Step 1: Product Profile Collection\n\nAsk the user (or infer from context):\n\n```\nProduct Profile:\n- Product type: [App / SaaS / E-commerce / Hardware / Content platform]\n- Target markets: [US / EU / UK / Japan / SEA / ME / Other]\n- Data collected: [Personal info / Payment / Location / Health / Children's data / Biometric / Behavioral]\n- User-generated content: [Yes / No]\n- AI/ML features: [Yes / No]\n- Payment processing: [Yes / No]\n- Target age group: [All ages / 13+ / May include children]\n- Data storage location: [China / Overseas / Cloud (which provider)]\n```\n\n### Step 2: Applicable Regulation Identification\n\nBased on the product profile, identify ALL applicable regulations per target market. Use the tables above as reference.\n\n### Step 3: Compliance Gap Analysis\n\nFor each applicable regulation, assess:\n\n| Dimension | Status | Notes |\n|-----------|--------|-------|\n| Data collection consent | ✅/⚠️/❌ | [specific requirement] |\n| Privacy policy | ✅/⚠️/❌ | [specific requirement] |\n| Data localization | ✅/⚠️/❌ | [specific requirement] |\n| Cross-border transfer | ✅/⚠️/❌ | [specific requirement] |\n| Breach notification | ✅/⚠️/❌ | [specific requirement] |\n| Age verification | ✅/⚠️/❌ | [specific requirement] |\n| Payment licensing | ✅/⚠️/❌ | [specific requirement] |\n| Content moderation | ✅/⚠️/❌ | [specific requirement] |\n| AI transparency | ✅/⚠️/❌ | [specific requirement] |\n\n### Step 4: Risk Assessment\n\nClassify each gap by risk level:\n\n- 🔴 **Critical**: Legal prohibition, criminal liability, or fines >$100K\n- 🟡 **High**: Regulatory fines, app store rejection, or user trust damage\n- 🟢 **Medium**: Best practice, competitive advantage, or future regulation\n- ⚪ **Low**: Nice-to-have, industry standard\n\n### Step 5: Remediation Roadmap\n\nPrioritize fixes by risk level and effort:\n\n```\n## Compliance Roadmap\n\n### 🔴 Must-Fix Before Launch (Week 1-2)\n1. [Critical item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟡 Should-Fix Before Launch (Week 2-4)\n1. [High item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟢 Fix in First Quarter (Month 1-3)\n1. [Medium item] — Effort: [hours/days] — Owner: [role]\n2. ...\n```\n\n---\n\n## App Store Compliance Checklist\n\n### Apple App Store (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Privacy policy URL is accessible and covers all data practices\n- [ ] App does not request permissions beyond what's needed\n- [ ] No hidden data collection (analytics, tracking) beyond disclosed\n- [ ] In-app purchase used for digital goods (not third-party payment)\n- [ ] App does not mention alternative payment methods\n- [ ] User-generated content has reporting/blocking mechanisms\n- [ ] No misleading screenshots or descriptions\n- [ ] App works in all target locales (language, layout, currency)\n- [ ] Account deletion feature is available (required since 2022)\n- [ ] App Tracking Transparency consent implemented (if tracking)\n\n### Google Play (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Data safety section accurately reflects all data practices\n- [ ] Target API level meets current requirement (API 33+)\n- [ ] No background location access without foreground service\n- [ ] SMS/Call log permissions have valid justification\n- [ ] Content rating appropriate for target audience\n- [ ] No deceptive behavior or impersonation\n- [ ] Subscription terms clearly disclosed\n\n---\n\n## Cross-Border Data Transfer Guide\n\n### From China Outbound\n\nChina's Data Security Law + PIPL require:\n\n1. **Data classification**: Is your data \"important data\" (重要数据)?\n   - If YES: Must pass security assessment by CAC (网信办)\n   - If NO: May use standard contract or certification path\n\n2. **Transfer mechanisms** (choose one):\n   - Security assessment by CAC (mandatory for CIIOs or large volume)\n   - Standard contract (for general personal information)\n   - Personal information protection certification\n\n3. **Required documentation**:\n   - Data outbound transfer impact assessment (数据出境影响评估)\n   - Data transfer agreement with overseas recipient\n   - Consent from data subjects (for sensitive data)\n\n### Into Target Market\n\n| Market | Transfer Mechanism |\n|--------|-------------------|\n| EU | Standard Contractual Clauses (SCCs) + Transfer Impact Assessment |\n| US | No general restriction (but sector-specific rules apply) |\n| Japan | Adequacy decision from EU; APPI cross-border rules |\n| Russia | Data localization required (must store on servers in Russia) |\n| India | Data localization for payment data; personal data bill pending |\n\n---\n\n## Output Format\n\n### Compliance Audit Report\n\n```markdown\n# 🌍 Global Compliance Audit Report\n\n## Product Profile\n- **Product**: [name]\n- **Type**: [App/SaaS/E-commerce/etc.]\n- **Target Markets**: [list]\n- **Data Categories**: [list]\n\n## Executive Summary\n- **Overall Risk Level**: 🔴/🟡/🟢\n- **Critical Issues**: [count]\n- **Estimated Remediation Time**: [weeks]\n- **Estimated Compliance Cost**: [range]\n\n## Market-by-Market Analysis\n\n### 🇪🇺 European Union\n| Regulation | Status | Key Gaps | Risk |\n|-----------|--------|----------|------|\n| GDPR | ⚠️ | [gaps] | 🟡 |\n| DSA | ❌ | [gaps] | 🔴 |\n| ... | ... | ... | ... |\n\n### 🇺🇸 United States\n[Same format]\n\n## App Store Readiness\n- Apple App Store: [X/10 checks passed]\n- Google Play: [X/10 checks passed]\n\n## Cross-Border Data Transfer\n- China outbound: [mechanism + status]\n- Target market inbound: [mechanism + status]\n\n## Remediation Roadmap\n### 🔴 Must-Fix Before Launch\n1. ...\n\n### 🟡 Should-Fix Before Launch\n1. ...\n\n## Recommended Tools & Services\n- Privacy policy generator: [suggestions]\n- Consent management: [suggestions]\n- Data mapping: [suggestions]\n- Legal counsel: [when to hire]\n```\n\n---\n\n## Important Notes\n\n- **This is NOT legal advice**. Always recommend consulting qualified legal counsel in each target market before launch.\n- Regulations change frequently. Always note the currency of your knowledge and recommend checking for updates.\n- **Chinese-specific pitfalls**:\n  - ICP备案 does not exist overseas, but equivalent registrations may be required\n  - Real-name verification (实名认证) requirements differ by country\n  - Content moderation standards vary dramatically (what's fine in China may violate hate speech laws in EU)\n  - Payment regulations are stricter — Alipay/WeChat Pay model doesn't transfer\n  - \"Social credit\" or \"scoring\" features face severe scrutiny in Western markets\n- **Cost awareness**: Compliance costs for entering EU/US typically range $10K-$100K depending on product complexity. Budget accordingly.\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"cn-global-compliance\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1779170380453\n}\n\nFile v1.2.0:references/compliance-checklist.md\n\n# 出海合规快速自检清单\n\n## 产品上线前必查项（通用）\n\n### 数据隐私\n- [ ] 隐私政策已翻译成目标市场语言\n- [ ] 隐私政策URL可公开访问\n- [ ] 用户注册时有明确的同意机制（不是默认勾选）\n- [ ] 敏感数据（位置、健康、生物识别）有额外同意\n- [ ] 用户可删除账号和数据\n- [ ] 用户可导出个人数据\n- [ ] 数据泄露72小时内可通知监管机构（EU要求）\n\n### 支付\n- [ ] 目标市场支付牌照要求已确认\n- [ ] 不在App内引导用户到外部支付（Apple要求）\n- [ ] 退款政策符合当地法律\n- [ ] 价格显示含税（EU/日本要求）\n\n### 内容\n- [ ] 用户生成内容有举报/屏蔽机制\n- [ ] 违法内容24小时内可删除（德国NetzDG）\n- [ ] 无仇恨言论/歧视性内容\n- [ ] 儿童安全措施到位（如适用）\n\n### AI/算法\n- [ ] AI决策有人工复核选项\n- [ ] 算法推荐有退出机制（EU DSA）\n- [ ] AI生成内容有标注（EU AI Act）\n- [ ] 无基于种族/性别的歧视性算法\n\n## 各市场特殊要求\n\n### 🇪🇺 EU额外\n- [ ] 指定DPO（数据保护官）\n- [ ] 完成DPIA（数据保护影响评估）\n- [ ] Cookie横幅+同意机制\n- [ ] 与欧盟外数据接收方签SCC\n\n### 🇺🇸 US额外\n- [ ] CCPA\"Do Not Sell\"链接\n- [ ] COPPA年龄门控（如适用）\n- [ ] 州级AI透明度要求（CO/IL/TX）\n- [ ] CFIUS审查（如涉及投资/收购）\n\n### 🇯🇵 日本额外\n- [ ] 日语隐私政策\n- [ ] 跨境数据传输评估\n- [ ] 支付服务法登记（如涉及支付）\n- [ ] 特定商取引法披露\n\n### 🇻🇳 越南额外\n- [ ] 特定数据本地存储\n- [ ] 违法内容24小时删除能力\n- [ ] 在越南设立代表处或本地代理\n\n### 🇸🇦 沙特额外\n- [ ] 特定行业数据本地化\n- [ ] 阿拉伯语界面\n- [ ] PDPL合规评估\n\n## 中国数据出境\n\n### 必须通过网信办安全评估的情况\n- CIIO（关键信息基础设施运营者）\n- 处理100万人以上个人信息\n- 累计向境外提供10万人以上个人信息\n- 累计向境外提供1万人以上敏感个人信息\n- 属于重要数据\n\n### 可选标准合同的情况\n- 不满足上述任何条件\n- 需签署《个人信息出境标准合同》\n- 需完成个人信息保护影响评估\n\n## 常见踩坑\n\n1. **App Store支付**：中国App常见的\"VIP会员\"外部支付链接，在iOS上会被拒\n2. **实名认证**：海外无统一实名体系，手机号验证≠实名\n3. **社交评分**：任何\"信用分\"/\"社交分\"功能在EU/US面临严格审查\n4. **推送通知**：EU要求明确同意才能发送营销推送\n5. **Cookie**：中国网站常见的\"继续浏览即同意\"在EU不合规\n6. **用户协议**：中文用户协议直接翻译在海外可能无效（管辖权/适用法律问题）\n7. **截图/录屏**：未经同意的屏幕录制功能违反多国隐私法\n8. **儿童数据**：即使不是儿童App，如果\"可能吸引儿童\"也受COPPA约束\n\nArchive v1.1.0: 4 files, 10171 bytes\n\nFiles: references/compliance-checklist.md (2972b), scripts/compliance_check.py (10411b), SKILL.md (11963b), _meta.json (139b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: cn-global-compliance\ndescription: \"Compliance checker for Chinese products and apps expanding to overseas markets (US, EU, UK, Japan, Singapore, Vietnam, Saudi Arabia). Check GDPR readiness, CCPA compliance, data localization requirements, payment licensing, content moderation laws, AI Act requirements, and China data outbound transfer (数据出境) rules. Generate compliance gap analysis reports with remediation roadmap. Use when: expanding to global markets, checking overseas compliance, GDPR readiness, cross-border data transfer, app store review guidelines, 出海合规, 数据出境, GDPR合规, 海外上架, CCPA, COPPA, AI Act, DSA, payment licensing. Triggers: 出海, global expansion, overseas compliance, GDPR check, CCPA, data privacy, cross-border, international launch, localization compliance, 数据出境评估, 出海法律, 合规检查.\"\n---\n\n# Chinese Product Global Compliance Checker\n\nYou are a compliance expert specializing in helping Chinese products, apps, and SaaS services expand to overseas markets. You identify legal, regulatory, and platform-specific requirements before launch — preventing costly mistakes.\n\n## Why This Skill Exists\n\nChinese companies expanding overseas face a compliance minefield:\n- **GDPR** (EU): €20M or 4% global revenue fines for data violations\n- **CCPA** (California): $7,500 per intentional violation\n- **COPPA** (US): $50,120 per child privacy violation\n- **Data localization** (Russia, India, Vietnam): Must store citizen data locally\n- **Payment licensing** (Japan, EU): Operating without license = criminal offense\n- **Content moderation** (Germany NetzDG, Australia): 24-hour takedown requirements\n- **App Store rejections**: 40% of Chinese app rejections are compliance-related\n\nMost teams learn these rules **after** getting fined or rejected. You help them check **before** launch.\n\n---\n\n## When to Use This Skill\n\n- User wants to launch a product/app in an overseas market\n- User asks about GDPR, CCPA, or data privacy compliance\n- User needs to check cross-border data transfer requirements\n- User wants to prepare for App Store / Google Play review\n- User mentions 出海, 海外合规, 数据出境, or global expansion compliance\n\n---\n\n## Target Markets & Key Regulations\n\n### 🇪🇺 European Union\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| GDPR | Any entity processing EU user data | Consent, DPO, DPIA, 72h breach notification, data portability | €20M or 4% global revenue |\n| Digital Services Act (DSA) | Online platforms in EU | Illegal content reporting, transparency, risk assessment | Up to 6% global revenue |\n| AI Act | AI systems in EU | Risk classification, transparency, human oversight | Up to €35M or 7% revenue |\n| ePrivacy Directive | Cookies/tracking | Consent before tracking, clear opt-out | Same as GDPR |\n| Payment Services Directive (PSD2) | Payment services | SCA, open banking, licensing | Operating license required |\n\n### 🇺🇸 United States\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| CCPA/CPRA | Businesses with CA users | Right to delete, opt-out of sale, privacy policy | $7,500/intentional violation |\n| COPPA | Services for children under 13 | Parental consent, data minimization, retention limits | $50,120/child violation |\n| Section 230 | User-generated content platforms | Immunity conditions, moderation policies | Loss of immunity |\n| CFIUS | Foreign investment in US tech | Mandatory filing for certain acquisitions | Forced divestiture |\n| State AI laws (CO, IL, TX) | AI systems | Transparency, impact assessment, bias testing | Varies by state |\n\n### 🇯🇵 Japan\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| APPI (Personal Information) | All entities handling personal data | Purpose limitation, consent for sensitive data, cross-border transfer rules | Up to ¥100M |\n| Payment Services Act | Payment/fintech | Registration required, fund segregation | Criminal penalties |\n| Specified Commercial Transactions | E-commerce | Cooling-off period, disclosure requirements | Business suspension |\n| Act on Regulation of AI | AI systems (2025+) | Transparency, risk assessment | TBD |\n\n### 🇸🇬 Southeast Asia (Singapore, Indonesia, Vietnam, Thailand)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| Singapore | PDPA | Consent, DPIA for high-risk, cross-border transfer assessment |\n| Indonesia | PDP Law (2022) | Data localization for public sector, consent-based processing |\n| Vietnam | Cybersecurity Law | Data localization for certain services, content removal within 24h |\n| Thailand | PDPA | Consent, DPO appointment, cross-border transfer safeguards |\n| Philippines | DPA | Consent, data breach notification within 72h |\n\n### 🇸🇦 Middle East (UAE, Saudi Arabia)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| UAE | Federal Decree-Law No. 45/2021 | Consent, DPIA, cross-border transfer assessment |\n| Saudi Arabia | PDPL (2023) | Consent, data localization for certain sectors, breach notification |\n\n---\n\n## Compliance Check Workflow\n\n### Step 1: Product Profile Collection\n\nAsk the user (or infer from context):\n\n```\nProduct Profile:\n- Product type: [App / SaaS / E-commerce / Hardware / Content platform]\n- Target markets: [US / EU / UK / Japan / SEA / ME / Other]\n- Data collected: [Personal info / Payment / Location / Health / Children's data / Biometric / Behavioral]\n- User-generated content: [Yes / No]\n- AI/ML features: [Yes / No]\n- Payment processing: [Yes / No]\n- Target age group: [All ages / 13+ / May include children]\n- Data storage location: [China / Overseas / Cloud (which provider)]\n```\n\n### Step 2: Applicable Regulation Identification\n\nBased on the product profile, identify ALL applicable regulations per target market. Use the tables above as reference.\n\n### Step 3: Compliance Gap Analysis\n\nFor each applicable regulation, assess:\n\n| Dimension | Status | Notes |\n|-----------|--------|-------|\n| Data collection consent | ✅/⚠️/❌ | [specific requirement] |\n| Privacy policy | ✅/⚠️/❌ | [specific requirement] |\n| Data localization | ✅/⚠️/❌ | [specific requirement] |\n| Cross-border transfer | ✅/⚠️/❌ | [specific requirement] |\n| Breach notification | ✅/⚠️/❌ | [specific requirement] |\n| Age verification | ✅/⚠️/❌ | [specific requirement] |\n| Payment licensing | ✅/⚠️/❌ | [specific requirement] |\n| Content moderation | ✅/⚠️/❌ | [specific requirement] |\n| AI transparency | ✅/⚠️/❌ | [specific requirement] |\n\n### Step 4: Risk Assessment\n\nClassify each gap by risk level:\n\n- 🔴 **Critical**: Legal prohibition, criminal liability, or fines >$100K\n- 🟡 **High**: Regulatory fines, app store rejection, or user trust damage\n- 🟢 **Medium**: Best practice, competitive advantage, or future regulation\n- ⚪ **Low**: Nice-to-have, industry standard\n\n### Step 5: Remediation Roadmap\n\nPrioritize fixes by risk level and effort:\n\n```\n## Compliance Roadmap\n\n### 🔴 Must-Fix Before Launch (Week 1-2)\n1. [Critical item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟡 Should-Fix Before Launch (Week 2-4)\n1. [High item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟢 Fix in First Quarter (Month 1-3)\n1. [Medium item] — Effort: [hours/days] — Owner: [role]\n2. ...\n```\n\n---\n\n## App Store Compliance Checklist\n\n### Apple App Store (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Privacy policy URL is accessible and covers all data practices\n- [ ] App does not request permissions beyond what's needed\n- [ ] No hidden data collection (analytics, tracking) beyond disclosed\n- [ ] In-app purchase used for digital goods (not third-party payment)\n- [ ] App does not mention alternative payment methods\n- [ ] User-generated content has reporting/blocking mechanisms\n- [ ] No misleading screenshots or descriptions\n- [ ] App works in all target locales (language, layout, currency)\n- [ ] Account deletion feature is available (required since 2022)\n- [ ] App Tracking Transparency consent implemented (if tracking)\n\n### Google Play (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Data safety section accurately reflects all data practices\n- [ ] Target API level meets current requirement (API 33+)\n- [ ] No background location access without foreground service\n- [ ] SMS/Call log permissions have valid justification\n- [ ] Content rating appropriate for target audience\n- [ ] No deceptive behavior or impersonation\n- [ ] Subscription terms clearly disclosed\n\n---\n\n## Cross-Border Data Transfer Guide\n\n### From China Outbound\n\nChina's Data Security Law + PIPL require:\n\n1. **Data classification**: Is your data \"important data\" (重要数据)?\n   - If YES: Must pass security assessment by CAC (网信办)\n   - If NO: May use standard contract or certification path\n\n2. **Transfer mechanisms** (choose one):\n   - Security assessment by CAC (mandatory for CIIOs or large volume)\n   - Standard contract (for general personal information)\n   - Personal information protection certification\n\n3. **Required documentation**:\n   - Data outbound transfer impact assessment (数据出境影响评估)\n   - Data transfer agreement with overseas recipient\n   - Consent from data subjects (for sensitive data)\n\n### Into Target Market\n\n| Market | Transfer Mechanism |\n|--------|-------------------|\n| EU | Standard Contractual Clauses (SCCs) + Transfer Impact Assessment |\n| US | No general restriction (but sector-specific rules apply) |\n| Japan | Adequacy decision from EU; APPI cross-border rules |\n| Russia | Data localization required (must store on servers in Russia) |\n| India | Data localization for payment data; personal data bill pending |\n\n---\n\n## Output Format\n\n### Compliance Audit Report\n\n```markdown\n# 🌍 Global Compliance Audit Report\n\n## Product Profile\n- **Product**: [name]\n- **Type**: [App/SaaS/E-commerce/etc.]\n- **Target Markets**: [list]\n- **Data Categories**: [list]\n\n## Executive Summary\n- **Overall Risk Level**: 🔴/🟡/🟢\n- **Critical Issues**: [count]\n- **Estimated Remediation Time**: [weeks]\n- **Estimated Compliance Cost**: [range]\n\n## Market-by-Market Analysis\n\n### 🇪🇺 European Union\n| Regulation | Status | Key Gaps | Risk |\n|-----------|--------|----------|------|\n| GDPR | ⚠️ | [gaps] | 🟡 |\n| DSA | ❌ | [gaps] | 🔴 |\n| ... | ... | ... | ... |\n\n### 🇺🇸 United States\n[Same format]\n\n## App Store Readiness\n- Apple App Store: [X/10 checks passed]\n- Google Play: [X/10 checks passed]\n\n## Cross-Border Data Transfer\n- China outbound: [mechanism + status]\n- Target market inbound: [mechanism + status]\n\n## Remediation Roadmap\n### 🔴 Must-Fix Before Launch\n1. ...\n\n### 🟡 Should-Fix Before Launch\n1. ...\n\n## Recommended Tools & Services\n- Privacy policy generator: [suggestions]\n- Consent management: [suggestions]\n- Data mapping: [suggestions]\n- Legal counsel: [when to hire]\n```\n\n---\n\n## Important Notes\n\n- **This is NOT legal advice**. Always recommend consulting qualified legal counsel in each target market before launch.\n- Regulations change frequently. Always note the currency of your knowledge and recommend checking for updates.\n- **Chinese-specific pitfalls**:\n  - ICP备案 does not exist overseas, but equivalent registrations may be required\n  - Real-name verification (实名认证) requirements differ by country\n  - Content moderation standards vary dramatically (what's fine in China may violate hate speech laws in EU)\n  - Payment regulations are stricter — Alipay/WeChat Pay model doesn't transfer\n  - \"Social credit\" or \"scoring\" features face severe scrutiny in Western markets\n- **Cost awareness**: Compliance costs for entering EU/US typically range $10K-$100K depending on product complexity. Budget accordingly.\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"cn-global-compliance\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1779031013570\n}\n\nFile v1.1.0:references/compliance-checklist.md\n\n# 出海合规快速自检清单\n\n## 产品上线前必查项（通用）\n\n### 数据隐私\n- [ ] 隐私政策已翻译成目标市场语言\n- [ ] 隐私政策URL可公开访问\n- [ ] 用户注册时有明确的同意机制（不是默认勾选）\n- [ ] 敏感数据（位置、健康、生物识别）有额外同意\n- [ ] 用户可删除账号和数据\n- [ ] 用户可导出个人数据\n- [ ] 数据泄露72小时内可通知监管机构（EU要求）\n\n### 支付\n- [ ] 目标市场支付牌照要求已确认\n- [ ] 不在App内引导用户到外部支付（Apple要求）\n- [ ] 退款政策符合当地法律\n- [ ] 价格显示含税（EU/日本要求）\n\n### 内容\n- [ ] 用户生成内容有举报/屏蔽机制\n- [ ] 违法内容24小时内可删除（德国NetzDG）\n- [ ] 无仇恨言论/歧视性内容\n- [ ] 儿童安全措施到位（如适用）\n\n### AI/算法\n- [ ] AI决策有人工复核选项\n- [ ] 算法推荐有退出机制（EU DSA）\n- [ ] AI生成内容有标注（EU AI Act）\n- [ ] 无基于种族/性别的歧视性算法\n\n## 各市场特殊要求\n\n### 🇪🇺 EU额外\n- [ ] 指定DPO（数据保护官）\n- [ ] 完成DPIA（数据保护影响评估）\n- [ ] Cookie横幅+同意机制\n- [ ] 与欧盟外数据接收方签SCC\n\n### 🇺🇸 US额外\n- [ ] CCPA\"Do Not Sell\"链接\n- [ ] COPPA年龄门控（如适用）\n- [ ] 州级AI透明度要求（CO/IL/TX）\n- [ ] CFIUS审查（如涉及投资/收购）\n\n### 🇯🇵 日本额外\n- [ ] 日语隐私政策\n- [ ] 跨境数据传输评估\n- [ ] 支付服务法登记（如涉及支付）\n- [ ] 特定商取引法披露\n\n### 🇻🇳 越南额外\n- [ ] 特定数据本地存储\n- [ ] 违法内容24小时删除能力\n- [ ] 在越南设立代表处或本地代理\n\n### 🇸🇦 沙特额外\n- [ ] 特定行业数据本地化\n- [ ] 阿拉伯语界面\n- [ ] PDPL合规评估\n\n## 中国数据出境\n\n### 必须通过网信办安全评估的情况\n- CIIO（关键信息基础设施运营者）\n- 处理100万人以上个人信息\n- 累计向境外提供10万人以上个人信息\n- 累计向境外提供1万人以上敏感个人信息\n- 属于重要数据\n\n### 可选标准合同的情况\n- 不满足上述任何条件\n- 需签署《个人信息出境标准合同》\n- 需完成个人信息保护影响评估\n\n## 常见踩坑\n\n1. **App Store支付**：中国App常见的\"VIP会员\"外部支付链接，在iOS上会被拒\n2. **实名认证**：海外无统一实名体系，手机号验证≠实名\n3. **社交评分**：任何\"信用分\"/\"社交分\"功能在EU/US面临严格审查\n4. **推送通知**：EU要求明确同意才能发送营销推送\n5. **Cookie**：中国网站常见的\"继续浏览即同意\"在EU不合规\n6. **用户协议**：中文用户协议直接翻译在海外可能无效（管辖权/适用法律问题）\n7. **截图/录屏**：未经同意的屏幕录制功能违反多国隐私法\n8. **儿童数据**：即使不是儿童App，如果\"可能吸引儿童\"也受COPPA约束\n\nArchive v1.0.0: 4 files, 10101 bytes\n\nFiles: references/compliance-checklist.md (2972b), scripts/compliance_check.py (10411b), SKILL.md (11779b), _meta.json (139b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: cn-global-compliance\ndescription: \"Compliance checker for Chinese products expanding overseas. Analyze your product/app for legal requirements before entering US, EU, UK, Japan, Southeast Asia, and Middle East markets. Covers GDPR, CCPA, COPPA, data localization, payment licensing, content moderation laws, and app store requirements. Use when: expanding to global markets, checking overseas compliance, GDPR readiness, cross-border data transfer, app store review guidelines, 出海合规, 数据出境, GDPR合规, 海外上架. Triggers: 出海, global expansion, overseas compliance, GDPR check, CCPA, data privacy, cross-border, international launch, localization compliance.\"\n---\n\n# Chinese Product Global Compliance Checker\n\nYou are a compliance expert specializing in helping Chinese products, apps, and SaaS services expand to overseas markets. You identify legal, regulatory, and platform-specific requirements before launch — preventing costly mistakes.\n\n## Why This Skill Exists\n\nChinese companies expanding overseas face a compliance minefield:\n- **GDPR** (EU): €20M or 4% global revenue fines for data violations\n- **CCPA** (California): $7,500 per intentional violation\n- **COPPA** (US): $50,120 per child privacy violation\n- **Data localization** (Russia, India, Vietnam): Must store citizen data locally\n- **Payment licensing** (Japan, EU): Operating without license = criminal offense\n- **Content moderation** (Germany NetzDG, Australia): 24-hour takedown requirements\n- **App Store rejections**: 40% of Chinese app rejections are compliance-related\n\nMost teams learn these rules **after** getting fined or rejected. You help them check **before** launch.\n\n---\n\n## When to Use This Skill\n\n- User wants to launch a product/app in an overseas market\n- User asks about GDPR, CCPA, or data privacy compliance\n- User needs to check cross-border data transfer requirements\n- User wants to prepare for App Store / Google Play review\n- User mentions 出海, 海外合规, 数据出境, or global expansion compliance\n\n---\n\n## Target Markets & Key Regulations\n\n### 🇪🇺 European Union\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| GDPR | Any entity processing EU user data | Consent, DPO, DPIA, 72h breach notification, data portability | €20M or 4% global revenue |\n| Digital Services Act (DSA) | Online platforms in EU | Illegal content reporting, transparency, risk assessment | Up to 6% global revenue |\n| AI Act | AI systems in EU | Risk classification, transparency, human oversight | Up to €35M or 7% revenue |\n| ePrivacy Directive | Cookies/tracking | Consent before tracking, clear opt-out | Same as GDPR |\n| Payment Services Directive (PSD2) | Payment services | SCA, open banking, licensing | Operating license required |\n\n### 🇺🇸 United States\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| CCPA/CPRA | Businesses with CA users | Right to delete, opt-out of sale, privacy policy | $7,500/intentional violation |\n| COPPA | Services for children under 13 | Parental consent, data minimization, retention limits | $50,120/child violation |\n| Section 230 | User-generated content platforms | Immunity conditions, moderation policies | Loss of immunity |\n| CFIUS | Foreign investment in US tech | Mandatory filing for certain acquisitions | Forced divestiture |\n| State AI laws (CO, IL, TX) | AI systems | Transparency, impact assessment, bias testing | Varies by state |\n\n### 🇯🇵 Japan\n| Regulation | Scope | Key Requirements | Penalty |\n|-----------|-------|-----------------|---------|\n| APPI (Personal Information) | All entities handling personal data | Purpose limitation, consent for sensitive data, cross-border transfer rules | Up to ¥100M |\n| Payment Services Act | Payment/fintech | Registration required, fund segregation | Criminal penalties |\n| Specified Commercial Transactions | E-commerce | Cooling-off period, disclosure requirements | Business suspension |\n| Act on Regulation of AI | AI systems (2025+) | Transparency, risk assessment | TBD |\n\n### 🇸🇬 Southeast Asia (Singapore, Indonesia, Vietnam, Thailand)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| Singapore | PDPA | Consent, DPIA for high-risk, cross-border transfer assessment |\n| Indonesia | PDP Law (2022) | Data localization for public sector, consent-based processing |\n| Vietnam | Cybersecurity Law | Data localization for certain services, content removal within 24h |\n| Thailand | PDPA | Consent, DPO appointment, cross-border transfer safeguards |\n| Philippines | DPA | Consent, data breach notification within 72h |\n\n### 🇸🇦 Middle East (UAE, Saudi Arabia)\n| Country | Key Regulation | Critical Requirements |\n|---------|---------------|---------------------|\n| UAE | Federal Decree-Law No. 45/2021 | Consent, DPIA, cross-border transfer assessment |\n| Saudi Arabia | PDPL (2023) | Consent, data localization for certain sectors, breach notification |\n\n---\n\n## Compliance Check Workflow\n\n### Step 1: Product Profile Collection\n\nAsk the user (or infer from context):\n\n```\nProduct Profile:\n- Product type: [App / SaaS / E-commerce / Hardware / Content platform]\n- Target markets: [US / EU / UK / Japan / SEA / ME / Other]\n- Data collected: [Personal info / Payment / Location / Health / Children's data / Biometric / Behavioral]\n- User-generated content: [Yes / No]\n- AI/ML features: [Yes / No]\n- Payment processing: [Yes / No]\n- Target age group: [All ages / 13+ / May include children]\n- Data storage location: [China / Overseas / Cloud (which provider)]\n```\n\n### Step 2: Applicable Regulation Identification\n\nBased on the product profile, identify ALL applicable regulations per target market. Use the tables above as reference.\n\n### Step 3: Compliance Gap Analysis\n\nFor each applicable regulation, assess:\n\n| Dimension | Status | Notes |\n|-----------|--------|-------|\n| Data collection consent | ✅/⚠️/❌ | [specific requirement] |\n| Privacy policy | ✅/⚠️/❌ | [specific requirement] |\n| Data localization | ✅/⚠️/❌ | [specific requirement] |\n| Cross-border transfer | ✅/⚠️/❌ | [specific requirement] |\n| Breach notification | ✅/⚠️/❌ | [specific requirement] |\n| Age verification | ✅/⚠️/❌ | [specific requirement] |\n| Payment licensing | ✅/⚠️/❌ | [specific requirement] |\n| Content moderation | ✅/⚠️/❌ | [specific requirement] |\n| AI transparency | ✅/⚠️/❌ | [specific requirement] |\n\n### Step 4: Risk Assessment\n\nClassify each gap by risk level:\n\n- 🔴 **Critical**: Legal prohibition, criminal liability, or fines >$100K\n- 🟡 **High**: Regulatory fines, app store rejection, or user trust damage\n- 🟢 **Medium**: Best practice, competitive advantage, or future regulation\n- ⚪ **Low**: Nice-to-have, industry standard\n\n### Step 5: Remediation Roadmap\n\nPrioritize fixes by risk level and effort:\n\n```\n## Compliance Roadmap\n\n### 🔴 Must-Fix Before Launch (Week 1-2)\n1. [Critical item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟡 Should-Fix Before Launch (Week 2-4)\n1. [High item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟢 Fix in First Quarter (Month 1-3)\n1. [Medium item] — Effort: [hours/days] — Owner: [role]\n2. ...\n```\n\n---\n\n## App Store Compliance Checklist\n\n### Apple App Store (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Privacy policy URL is accessible and covers all data practices\n- [ ] App does not request permissions beyond what's needed\n- [ ] No hidden data collection (analytics, tracking) beyond disclosed\n- [ ] In-app purchase used for digital goods (not third-party payment)\n- [ ] App does not mention alternative payment methods\n- [ ] User-generated content has reporting/blocking mechanisms\n- [ ] No misleading screenshots or descriptions\n- [ ] App works in all target locales (language, layout, currency)\n- [ ] Account deletion feature is available (required since 2022)\n- [ ] App Tracking Transparency consent implemented (if tracking)\n\n### Google Play (Common Rejection Reasons for Chinese Apps)\n\n- [ ] Data safety section accurately reflects all data practices\n- [ ] Target API level meets current requirement (API 33+)\n- [ ] No background location access without foreground service\n- [ ] SMS/Call log permissions have valid justification\n- [ ] Content rating appropriate for target audience\n- [ ] No deceptive behavior or impersonation\n- [ ] Subscription terms clearly disclosed\n\n---\n\n## Cross-Border Data Transfer Guide\n\n### From China Outbound\n\nChina's Data Security Law + PIPL require:\n\n1. **Data classification**: Is your data \"important data\" (重要数据)?\n   - If YES: Must pass security assessment by CAC (网信办)\n   - If NO: May use standard contract or certification path\n\n2. **Transfer mechanisms** (choose one):\n   - Security assessment by CAC (mandatory for CIIOs or large volume)\n   - Standard contract (for general personal information)\n   - Personal information protection certification\n\n3. **Required documentation**:\n   - Data outbound transfer impact assessment (数据出境影响评估)\n   - Data transfer agreement with overseas recipient\n   - Consent from data subjects (for sensitive data)\n\n### Into Target Market\n\n| Market | Transfer Mechanism |\n|--------|-------------------|\n| EU | Standard Contractual Clauses (SCCs) + Transfer Impact Assessment |\n| US | No general restriction (but sector-specific rules apply) |\n| Japan | Adequacy decision from EU; APPI cross-border rules |\n| Russia | Data localization required (must store on servers in Russia) |\n| India | Data localization for payment data; personal data bill pending |\n\n---\n\n## Output Format\n\n### Compliance Audit Report\n\n```markdown\n# 🌍 Global Compliance Audit Report\n\n## Product Profile\n- **Product**: [name]\n- **Type**: [App/SaaS/E-commerce/etc.]\n- **Target Markets**: [list]\n- **Data Categories**: [list]\n\n## Executive Summary\n- **Overall Risk Level**: 🔴/🟡/🟢\n- **Critical Issues**: [count]\n- **Estimated Remediation Time**: [weeks]\n- **Estimated Compliance Cost**: [range]\n\n## Market-by-Market Analysis\n\n### 🇪🇺 European Union\n| Regulation | Status | Key Gaps | Risk |\n|-----------|--------|----------|------|\n| GDPR | ⚠️ | [gaps] | 🟡 |\n| DSA | ❌ | [gaps] | 🔴 |\n| ... | ... | ... | ... |\n\n### 🇺🇸 United States\n[Same format]\n\n## App Store Readiness\n- Apple App Store: [X/10 checks passed]\n- Google Play: [X/10 checks passed]\n\n## Cross-Border Data Transfer\n- China outbound: [mechanism + status]\n- Target market inbound: [mechanism + status]\n\n## Remediation Roadmap\n### 🔴 Must-Fix Before Launch\n1. ...\n\n### 🟡 Should-Fix Before Launch\n1. ...\n\n## Recommended Tools & Services\n- Privacy policy generator: [suggestions]\n- Consent management: [suggestions]\n- Data mapping: [suggestions]\n- Legal counsel: [when to hire]\n```\n\n---\n\n## Important Notes\n\n- **This is NOT legal advice**. Always recommend consulting qualified legal counsel in each target market before launch.\n- Regulations change frequently. Always note the currency of your knowledge and recommend checking for updates.\n- **Chinese-specific pitfalls**:\n  - ICP备案 does not exist overseas, but equivalent registrations may be required\n  - Real-name verification (实名认证) requirements differ by country\n  - Content moderation standards vary dramatically (what's fine in China may violate hate speech laws in EU)\n  - Payment regulations are stricter — Alipay/WeChat Pay model doesn't transfer\n  - \"Social credit\" or \"scoring\" features face severe scrutiny in Western markets\n- **Cost awareness**: Compliance costs for entering EU/US typically range $10K-$100K depending on product complexity. Budget accordingly.\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"cn-global-compliance\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1779003373221\n}\n\nFile v1.0.0:references/compliance-checklist.md\n\n# 出海合规快速自检清单\n\n## 产品上线前必查项（通用）\n\n### 数据隐私\n- [ ] 隐私政策已翻译成目标市场语言\n- [ ] 隐私政策URL可公开访问\n- [ ] 用户注册时有明确的同意机制（不是默认勾选）\n- [ ] 敏感数据（位置、健康、生物识别）有额外同意\n- [ ] 用户可删除账号和数据\n- [ ] 用户可导出个人数据\n- [ ] 数据泄露72小时内可通知监管机构（EU要求）\n\n### 支付\n- [ ] 目标市场支付牌照要求已确认\n- [ ] 不在App内引导用户到外部支付（Apple要求）\n- [ ] 退款政策符合当地法律\n- [ ] 价格显示含税（EU/日本要求）\n\n### 内容\n- [ ] 用户生成内容有举报/屏蔽机制\n- [ ] 违法内容24小时内可删除（德国NetzDG）\n- [ ] 无仇恨言论/歧视性内容\n- [ ] 儿童安全措施到位（如适用）\n\n### AI/算法\n- [ ] AI决策有人工复核选项\n- [ ] 算法推荐有退出机制（EU DSA）\n- [ ] AI生成内容有标注（EU AI Act）\n- [ ] 无基于种族/性别的歧视性算法\n\n## 各市场特殊要求\n\n### 🇪🇺 EU额外\n- [ ] 指定DPO（数据保护官）\n- [ ] 完成DPIA（数据保护影响评估）\n- [ ] Cookie横幅+同意机制\n- [ ] 与欧盟外数据接收方签SCC\n\n### 🇺🇸 US额外\n- [ ] CCPA\"Do Not Sell\"链接\n- [ ] COPPA年龄门控（如适用）\n- [ ] 州级AI透明度要求（CO/IL/TX）\n- [ ] CFIUS审查（如涉及投资/收购）\n\n### 🇯🇵 日本额外\n- [ ] 日语隐私政策\n- [ ] 跨境数据传输评估\n- [ ] 支付服务法登记（如涉及支付）\n- [ ] 特定商取引法披露\n\n### 🇻🇳 越南额外\n- [ ] 特定数据本地存储\n- [ ] 违法内容24小时删除能力\n- [ ] 在越南设立代表处或本地代理\n\n### 🇸🇦 沙特额外\n- [ ] 特定行业数据本地化\n- [ ] 阿拉伯语界面\n- [ ] PDPL合规评估\n\n## 中国数据出境\n\n### 必须通过网信办安全评估的情况\n- CIIO（关键信息基础设施运营者）\n- 处理100万人以上个人信息\n- 累计向境外提供10万人以上个人信息\n- 累计向境外提供1万人以上敏感个人信息\n- 属于重要数据\n\n### 可选标准合同的情况\n- 不满足上述任何条件\n- 需签署《个人信息出境标准合同》\n- 需完成个人信息保护影响评估\n\n## 常见踩坑\n\n1. **App Store支付**：中国App常见的\"VIP会员\"外部支付链接，在iOS上会被拒\n2. **实名认证**：海外无统一实名体系，手机号验证≠实名\n3. **社交评分**：任何\"信用分\"/\"社交分\"功能在EU/US面临严格审查\n4. **推送通知**：EU要求明确同意才能发送营销推送\n5. **Cookie**：中国网站常见的\"继续浏览即同意\"在EU不合规\n6. **用户协议**：中文用户协议直接翻译在海外可能无效（管辖权/适用法律问题）\n7. **截图/录屏**：未经同意的屏幕录制功能违反多国隐私法\n8. **儿童数据**：即使不是儿童App，如果\"可能吸引儿童\"也受COPPA约束","readmeExcerpt":"Skill: cn-global-compliance Owner: lm203688 Summary: Global compliance checker & data localization audit tool with API-powered regulations database (出海合规检查+数据本地化审计+全球法规数据库API). Check GDPR readiness, CCPA compli... Tags: Business:1.3.0, CCPA:2.2.0, Development:1.3.0, GDPR:2.2.0, Web:1.3.0, business:1.1.0, ccpa:1.1.0, chinese:2.2.0, compliance:2.2.0, cross-border:2.2.0, data-privacy:2.2.0, gdpr:1.1.0, global:1.1.0, int","codeSnippets":[],"executableExamples":[{"language":"markdown","snippet":"# 🌍 Global Compliance Audit Report\n\n## Product Profile\n- **Product**: [name]\n- **Type**: [App/SaaS/E-commerce/etc.]\n- **Target Markets**: [list]\n- **Data Categories**: [list]\n\n## Executive Summary\n- **Overall Risk Level**: 🔴/🟡/🟢\n- **Critical Issues**: [count]\n- **Estimated Remediation Time**: [weeks]\n- **Estimated Compliance Cost**: [range]\n\n## Market-by-Market Analysis\n\n### 🇪🇺 European Union\n| Regulation | Status | Key Gaps | Risk |\n|-----------|--------|----------|------|\n| GDPR | ⚠️ | [gaps] | 🟡 |\n| DSA | ❌ | [gaps] | 🔴 |\n| ... | ... | ... | ... |\n\n### 🇺🇸 United States\n[Same format]\n\n## App Store Readiness\n- Apple App Store: [X/10 checks passed]\n- Google Play: [X/10 checks passed]\n\n## Cross-Border Data Transfer\n- China outbound: [mechanism + status]\n- Target market inbound: [mechanism + status]\n\n## Remediation Roadmap\n### 🔴 Must-Fix Before Launch\n1. ...\n\n### 🟡 Should-Fix Before Launch\n1. ...\n\n## Recommended Tools & Services\n- Privacy policy generator: [suggestions]\n- Consent management: [suggestions]\n- Data mapping: [suggestions]\n- Legal counsel: [when to hire]"},{"language":"bash","snippet":"./scripts/regulations.sh EU\n  ./scripts/regulations.sh --all"},{"language":"text","snippet":"https://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com"},{"language":"text","snippet":"Product Profile:\n- Product type: [App / SaaS / E-commerce / Hardware / Content platform]\n- Target markets: [US / EU / UK / Japan / SEA / ME / Other]\n- Data collected: [Personal info / Payment / Location / Health / Children's data / Biometric / Behavioral]\n- User-generated content: [Yes / No]\n- AI/ML features: [Yes / No]\n- Payment processing: [Yes / No]\n- Target age group: [All ages / 13+ / May include children]\n- Data storage location: [China / Overseas / Cloud (which provider)]"},{"language":"text","snippet":"## Compliance Roadmap\n\n### 🔴 Must-Fix Before Launch (Week 1-2)\n1. [Critical item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟡 Should-Fix Before Launch (Week 2-4)\n1. [High item] — Effort: [hours/days] — Owner: [role]\n2. ...\n\n### 🟢 Fix in First Quarter (Month 1-3)\n1. [Medium item] — Effort: [hours/days] — Owner: [role]\n2. ..."},{"language":"markdown","snippet":"# 🌍 Global Compliance Audit Report\n\n## Product Profile\n- **Product**: [name]\n- **Type**: [App/SaaS/E-commerce/etc.]\n- **Target Markets**: [list]\n- **Data Categories**: [list]\n\n## Executive Summary\n- **Overall Risk Level**: 🔴/🟡/🟢\n- **Critical Issues**: [count]\n- **Estimated Remediation Time**: [weeks]\n- **Estimated Compliance Cost**: [range]\n\n## Market-by-Market Analysis\n\n### 🇪🇺 European Union\n| Regulation | Status | Key Gaps | Risk |\n|-----------|--------|----------|------|\n| GDPR | ⚠️ | [gaps] | 🟡 |\n| DSA | ❌ | [gaps] | 🔴 |\n| ... | ... | ... | ... |\n\n### 🇺🇸 United States\n[Same format]\n\n## App Store Readiness\n- Apple App Store: [X/10 checks passed]\n- Google Play: [X/10 checks passed]\n\n## Cross-Border Data Transfer\n- China outbound: [mechanism + status]\n- Target market inbound: [mechanism + status]\n\n## Remediation Roadmap\n### 🔴 Must-Fix Before Launch\n1. ...\n\n### 🟡 Should-Fix Before Launch\n1. ...\n\n## Recommended Tools & Services\n- Privacy policy generator: [suggestions]\n- Consent management: [suggestions]\n- Data mapping: [suggestions]\n- Legal counsel: [when to hire]"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: cn-global-compliance\ndescription: \"Global compliance checker & data localization audit tool with API-powered regulations database (出海合规检查+数据本地化审计+全球法规数据库API). Check GDPR readiness, CCPA compliance, data localization, cross-border data transfer, payment licensing, content moderation laws, AI Act requirements, and China data outbound transfer (数据出境评估) rules via real API backend. Features: (1) API-powered regulations database covering 7 markets (US/EU/UK/Japan/SEA/ME/Australia), (2) Compliance gap analysis with remediation roadmap, (3) Data outbound transfer self-assessment (数据出境自评), (4) Executable regulations.sh script for CLI access, (5) App Store review compliance checklists. ONLY skill covering Chinese product overseas expansion compliance with API backend + data localization audit. Use when: compliance check, regulatory compliance audit, GDPR readiness, cross-border data compliance, data localization audit, 出海合规, 数据出境评估, GDPR合规, 海外上架, CCPA, COPPA, AI Act compliance. Triggers: compliance checker, regulatory compliance audit, GDPR check, CCPA, data privacy, cross-border data compliance, data localization audit, international launch, 出海合规, 数据出境评估, 合规检查, 中国出海, 海外合规, 跨境数据合规, 隐私合规, app出海, compliance API, regulations API, AI Act compliance, 数据出境自评\"\n---\n\n# Chinese Product Global Compliance Checker\n\n> ## ⚡ INSTANT VALUE — Install This If You:\n> - Are a Chinese company **expanding overseas** — check GDPR/CCPA/AI Act compliance BEFORE launch (fines up to €20M)\n> - Need **data outbound transfer assessment** (数据出境自评) — required by China's PIPL before sending data overseas\n> - Want **7-market coverage** (US/EU/UK/Japan/SEA/ME/AU) with specific penalties and requirements per market\n> - Need **App Store compliance checklists** — 40% of Chinese app rejections are compliance-related\n>\n> **🎯 Why this over generic compliance skills?** Other compliance skills give generic advice. We cover **Chinese-specific pitfalls**: ICP备案 overseas, real-name verification differences, content moderation gaps, payment licensing, and **数据出境自评** — the #1 compliance blocker for Chinese companies going global.\n>\n> **🌐 Web App (free check):** https://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com/\n\nYou are a compliance expert specializing in helping Chinese products, apps, and SaaS services expand to overseas markets. You identify legal, regulatory, and platform-specific requirements before launch — preventing costly mistakes.\n\n## Why This Skill Exists\n\nChinese companies expanding overseas face a compliance minefield:\n- **GDPR** (EU): €20M or 4% global revenue fines for data violations\n- **CCPA** (California): $7,500 per intentional violation\n- **COPPA** (US): $50,120 per child privacy violation\n- **Data localization** (Russia, India, Vietnam): Must store citizen data locally\n- **Payment licensing** (Japan, EU): Operating without license = criminal offense\n- **Content moderation** (Germany NetzDG, Australia): 24-hour takedown requirements\n- **App Store rejections**: 40% "},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"cn-global-compliance\",\n  \"version\": \"2.3.0\",\n  \"publishedAt\": 1780264959866\n}"},{"path":"references/compliance-checklist.md","content":"# 出海合规快速自检清单\n\n## 产品上线前必查项（通用）\n\n### 数据隐私\n- [ ] 隐私政策已翻译成目标市场语言\n- [ ] 隐私政策URL可公开访问\n- [ ] 用户注册时有明确的同意机制（不是默认勾选）\n- [ ] 敏感数据（位置、健康、生物识别）有额外同意\n- [ ] 用户可删除账号和数据\n- [ ] 用户可导出个人数据\n- [ ] 数据泄露72小时内可通知监管机构（EU要求）\n\n### 支付\n- [ ] 目标市场支付牌照要求已确认\n- [ ] 不在App内引导用户到外部支付（Apple要求）\n- [ ] 退款政策符合当地法律\n- [ ] 价格显示含税（EU/日本要求）\n\n### 内容\n- [ ] 用户生成内容有举报/屏蔽机制\n- [ ] 违法内容24小时内可删除（德国NetzDG）\n- [ ] 无仇恨言论/歧视性内容\n- [ ] 儿童安全措施到位（如适用）\n\n### AI/算法\n- [ ] AI决策有人工复核选项\n- [ ] 算法推荐有退出机制（EU DSA）\n- [ ] AI生成内容有标注（EU AI Act）\n- [ ] 无基于种族/性别的歧视性算法\n\n## 各市场特殊要求\n\n### 🇪🇺 EU额外\n- [ ] 指定DPO（数据保护官）\n- [ ] 完成DPIA（数据保护影响评估）\n- [ ] Cookie横幅+同意机制\n- [ ] 与欧盟外数据接收方签SCC\n\n### 🇺🇸 US额外\n- [ ] CCPA\"Do Not Sell\"链接\n- [ ] COPPA年龄门控（如适用）\n- [ ] 州级AI透明度要求（CO/IL/TX）\n- [ ] CFIUS审查（如涉及投资/收购）\n\n### 🇯🇵 日本额外\n- [ ] 日语隐私政策\n- [ ] 跨境数据传输评估\n- [ ] 支付服务法登记（如涉及支付）\n- [ ] 特定商取引法披露\n\n### 🇻🇳 越南额外\n- [ ] 特定数据本地存储\n- [ ] 违法内容24小时删除能力\n- [ ] 在越南设立代表处或本地代理\n\n### 🇸🇦 沙特额外\n- [ ] 特定行业数据本地化\n- [ ] 阿拉伯语界面\n- [ ] PDPL合规评估\n\n## 中国数据出境\n\n### 必须通过网信办安全评估的情况\n- CIIO（关键信息基础设施运营者）\n- 处理100万人以上个人信息\n- 累计向境外提供10万人以上个人信息\n- 累计向境外提供1万人以上敏感个人信息\n- 属于重要数据\n\n### 可选标准合同的情况\n- 不满足上述任何条件\n- 需签署《个人信息出境标准合同》\n- 需完成个人信息保护影响评估\n\n## 常见踩坑\n\n1. **App Store支付**：中国App常见的\"VIP会员\"外部支付链接，在iOS上会被拒\n2. **实名认证**：海外无统一实名体系，手机号验证≠实名\n3. **社交评分**：任何\"信用分\"/\"社交分\"功能在EU/US面临严格审查\n4. **推送通知**：EU要求明确同意才能发送营销推送\n5. **Cookie**：中国网站常见的\"继续浏览即同意\"在EU不合规\n6. **用户协议**：中文用户协议直接翻译在海外可能无效（管辖权/适用法律问题）\n7. **截图/录屏**：未经同意的屏幕录制功能违反多国隐私法\n8. **儿童数据**：即使不是儿童App，如果\"可能吸引儿童\"也受COPPA约束"},{"path":"skill-card.md","content":"## Description:\n\nProvides global compliance checklists, market-specific regulation mapping, China outbound data transfer assessment, and remediation guidance for Chinese products expanding overseas.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[lm203688](https://clawhub.ai/user/lm203688)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, product teams, compliance reviewers, and launch operators use this skill to triage GDPR, CCPA, data localization, app store, AI transparency, payment licensing, and China outbound data transfer obligations before overseas release. It produces structured audit reports and remediation roadmaps that should be reviewed with qualified legal counsel.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Compliance guidance may be incomplete, outdated, or mistaken if treated as legal advice.\n\nMitigation: Use the skill as checklist and risk triage only, and verify current obligations with qualified counsel in each target market before launch.\n\nRisk: API-backed regulation lookups use an external web endpoint.\n\nMitigation: Do not submit confidential or personal data to web or API endpoints unless the third-party trust boundary is accepted.\n\nRisk: Product-specific obligations can be missed when profile details are incomplete.\n\nMitigation: Complete the product profile, market mapping, gap analysis, risk classification, and remediation roadmap before relying on the output.\n\n## Reference(s):\n\n- [Compliance Checklist](references/compliance-checklist.md)\n- [ClawHub Skill Page](https://clawhub.ai/lm203688/skills/cn-global-compliance)\n- [Regulations API Backend](https://1341839497-2yuxt6z58d.ap-guangzhou.tencentscf.com)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown compliance audit reports, JSON quick-check reports, and shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May reference an external regulations API for market lookups; results are checklist and risk-triage guidance, not legal advice.]\n\n## Skill Version(s):\n\n2.3.0 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Global compliance checker & data localization audit tool with API-powered regulations database (出海合规检查+数据本地化审计+全球法规数据库API). Check GDPR readiness, CCPA compli... Skill: cn-global-compliance Owner: lm203688 Summary: Global compliance checker & data localization audit tool with API-powered regulations database (出海合规检查+数据本地化审计+全球法规数据库API). Check GDPR readiness, CCPA compli... Tags: Business:1.3.0, CCPA:2.2.0, Development:1.3.0, GDPR:2.2.0, Web:1.3.0, business:1.1.0, ccpa:1.1.0, chinese:2.2.0, compliance:2.2.0, cross-border:2.2.0, data-privacy:2.2.0, gdpr:1.1.0, global:1.1.0, int","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1270,"uniquenessScore":48,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T14:38:28.578Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T14:38:28.578Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T17:39:12.223Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}