---
name: compliance-desk
description: Build, send and track legally-deadlined requests through takeitdown.agentexchange.work (Compliance Desk) - TAKE IT DOWN Act removal of intimate images posted without consent (48-hour deadline), DMCA takedown notices, CCPA/GDPR privacy requests (access, deletion, correction, opt-out of sale) and TCPA/CAN-SPAM do-not-call or unsubscribe requests. Also checks whether a website publishes the notices and request mechanisms it is legally required to have, and sets up a hosted, logged request desk for a site the user operates. Use when a user wants content removed, a takedown or privacy request written, unwanted calls, texts or emails stopped, a site's compliance notices checked, or a takedown, DSA, privacy, accessibility or opt-out intake for their own site.
license: MIT
compatibility: Needs outbound HTTPS. Free during launch, no key. Requests are HTML forms (application/x-www-form-urlencoded) and answers are HTML pages, except /check.json and /health which return JSON.
metadata:
  author: agentexchange
  version: "1.0.0"
  homepage: https://takeitdown.agentexchange.work
  source: https://skills.agentexchange.work/skills/compliance-desk/SKILL.md
---

# Compliance Desk (takeitdown.agentexchange.work)

Two sides of one service:

- **Requester tools** (free): build a legally sufficient request letter, get a tracking id and the recipient's legal deadline. The service does not send the letter; the requester sends it (email or the platform's report form), unless the target platform runs a hosted desk here, in which case the request is filed directly and gets a ticket.
- **Hosted desks** (for site operators): a public request page, tickets with deadlines, status pages, a private dashboard, a webhook, a badge and an embed. Five desk kinds: `takedown` (TAKE IT DOWN Act and DMCA, 48 hours), `dsa` (EU Digital Services Act Art. 16/17 notice-and-action, 7 days), `privacy` (CCPA/CPRA and GDPR, 45 days), `accessibility` (European Accessibility Act, ADA Title II feedback), `optout` (TCPA and CAN-SPAM, 10 business days). Free while the service launches; the home page states the price once billing opens (planned $29 per month per desk).

## Ground rules for an agent

1. The good-faith checkbox and the typed signature are legal attestations by the requester. Never tick or sign on a user's behalf until the user has confirmed every factual statement: who they are, exactly where the content or data is, and that the claim is true. Show the generated letter to the user before it is sent anywhere.
2. Never submit a test or hypothetical request. Every submission is recorded (platform host, request type, deadline) and counts on the public platform page.
3. If anyone depicted is under 18, also point the user to NCMEC's Take It Down (takeitdown.ncmec.org). Adults can use StopNCII.org to block re-uploads on participating platforms.
4. Do not create desks for sites the user does not operate.

## 1. Build a request (requester side)

| kind | Use it for | Legal basis | Recipient's deadline |
| --- | --- | --- | --- |
| `takedown` | An intimate image or video of the requester (or their minor child, or a client they represent) published without consent, including AI-generated imagery | TAKE IT DOWN Act, Section 3 (in force since May 19, 2026; enforced by the FTC) | 48 hours |
| `dmca` | The requester's copyrighted work reproduced without permission | 17 U.S.C. 512(c) | "expeditiously"; tracked at 72 hours |
| `privacy` | Access, delete or correct personal data, or stop its sale or sharing | CCPA/CPRA and other US state privacy laws; GDPR | 45 days (CCPA); one month (GDPR) |
| `optout` | Stop marketing calls, texts or emails | TCPA, 47 CFR 64.1200(d)(3); CAN-SPAM | 10 business days; tracked at 14 days |

Flow:

1. `GET https://takeitdown.agentexchange.work/request/<kind>` (optionally `?platform=<url>` to prefill) shows the human form. You do not need to render it; you can POST directly.
2. `POST https://takeitdown.agentexchange.work/request/<kind>` with `content-type: application/x-www-form-urlencoded` and these fields:
   - `platform` (required): a URL on the platform or company that holds the content or data, for example `https://example.com/post/123`. Only the host is stored.
   - `locations` (required, up to 3,000 characters): exact URLs, one per line (`takedown`, `dmca`); the account, email or identifiers the company knows the requester by (`privacy`); the phone number or email to stop contacting (`optout`).
   - `contact` (required, email): where the recipient should answer. It appears only in the letter.
   - `signature` (required): the requester's full name, typed.
   - `good_faith=1` (required): the good-faith attestation.
   - `relationship`: `takedown`: `self` | `parent` | `representative`. `privacy`: `access` | `deletion` | `correction` | `opt out of sale or sharing` | `access and deletion`. `optout`: `all marketing (calls, texts, email)` | `calls` | `texts` | `emails`. Not used for `dmca`.
   - `description` (optional, up to 2,000 characters): details that help identify the content; for `dmca`, describe the original work and where it was first published.
   - `minor=1` (`takedown` only): the depicted person is a minor.
   Rate limit: 20 requests per hour per IP (HTTP 429, JSON body).
3. The answer is an HTML page (HTTP 200) titled `Request RQ-XXXXX-XX is ready`. Extract:
   - the ticket id, pattern `RQ-[0-9A-Z]{5}-[0-9A-Z]{2}`;
   - the letter, inside `<pre class="small">...</pre>` (HTML-escaped: decode `&amp;` `&lt;` `&gt;` `&quot;`);
   - the deadline (UTC) after `Deadline:`;
   - a `mailto:` link with subject and body prefilled, and suggested addresses to try (`abuse@`, `legal@`, `privacy@`, `support@` the host);
   - the escalation text for that kind.
   If the platform runs a hosted desk here, the page instead offers `Submit to <host>` linking to `/r/<siteId>`; use section 2.
   HTTP 400 means a required field is missing (`Incomplete request`) or `platform` is not a URL (`Check the address`).
4. Send the letter yourself: from the user's email, or through the platform's own report form. `https://takeitdown.agentexchange.work/remove/<platform>` gives the official reporting path, stated response time and hash-program membership for 44 platforms. Quote the `RQ-` id in every follow-up.
5. Track: `GET /platform/<host>` shows how many requests that host has received through the service and whether it runs a desk (404 until a request exists).
6. After the deadline, escalate: `takedown` to the FTC (reportfraud.ftc.gov); `dmca`: a host that ignores a valid notice risks its safe harbor, find its designated agent at dmca.copyright.gov/osp; `privacy`: California Privacy Protection Agency (cppa.ca.gov) or the state Attorney General, EU residents to their data protection authority; `optout`: FCC (consumercomplaints.fcc.gov), and in many states statutory damages.

## 2. File with a site that runs a hosted desk

`GET https://takeitdown.agentexchange.work/r/<siteId>` shows that site's public request form. `POST /r/<siteId>` (form-urlencoded) with `requester_contact` (required), `locations` (required, up to 4,000 characters), `signature` (required), `good_faith=1` (required), and optionally `requester_name`, `relationship`, `description`, `minor=1`. Rate limit 20 per hour per IP.

The answer is an HTML page `Request <ticket> received` with the ticket number, the site's deadline (UTC) and the status URL `https://takeitdown.agentexchange.work/s/<siteId>/<ticket>`. The status page shows status (`received`, `in review`, `actioned`, `declined`), received time, deadline with hours remaining and last update; it never shows the content of the request. Public statistics for the site: `/status/<siteId>`.

## 3. Check a site's legal notices (free JSON)

`GET https://takeitdown.agentexchange.work/check.json?url=<site>` returns `{site, checked_at, pages_fetched[], pages_tried, score, max: 12, results}` where `results` has one entry per desk kind (`takedown`, `dmca`, `dsa`, `privacy`, `accessibility`, `optout`), each `{label, notice, mechanism, evidence, mechanism_evidence, fix, score}`: `notice` is true when the site states the policy, `mechanism` when there is a usable way to submit a request without an account, `score` is 0-2. Human page: `/check?url=<site>`. This is the check behind area 5 of the Agent-Readiness Grade.

## 4. Set up a hosted desk for a site the user operates

`POST https://takeitdown.agentexchange.work/api/sites` (form-urlencoded): `kind` (`takedown` | `dsa` | `privacy` | `accessibility` | `optout`), `name` (site or business name, up to 120 characters), `url` (`https://...`), `contact` (email), `webhook` (optional https URL). Rate limit 10 desks per hour per IP. The answer is an HTML page `<name>: desk created` containing:

- the private dashboard link `/admin/<id>?token=<token>`: shown once, it is the only credential. Hand it to the user or store it in their secret store; never log it or repeat it in chat.
- the public request page `/r/<id>` to link from the site's notice; the notice text generator at `/desk/<kind>`; embed code at `/embed/<id>`; a trust badge at `/badge/<id>.svg`; public status at `/status/<id>`.

Each new request triggers the webhook, if set: `POST` JSON `{event: "request.received", desk, site, ticket, deadline_at, status_url, dashboard}` with user-agent `compliance-desk/1.0`. From the dashboard the operator moves tickets `received` -> `in review` -> `actioned` or `declined` and exports tickets as JSON or CSV for the records these laws require (CCPA 24 months, TCPA 5 years).

## Reference pages

`/llms.txt` (guide for LLMs), `/health` (JSON: `ok`, `desks[]`), `/regulations`, `/desk/<kind>` (law facts and notice generator), `/remove` and `/remove/<platform>` (official reporting paths), `/state` and `/state.json` (nonconsensual-intimate-image laws by US state, CC BY 4.0), `/define/<term>`, `/templates`, `/generators`, `/compare`, `/for/<platform>` (setup per website platform).
