Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By goul4rt
Orchestrate end-to-end LGPD compliance audits for Brazilian privacy law (Lei 13.709/2018) with an integrated set of skills covering data mapping, DSAR, consent, incident response, encryption, and documentation—all from within Claude.
npx claudepluginhub goul4rt/lgpd-skillsApply anonymization (Art. 5, XI) and pseudonymization (Art. 13, §4) techniques to take data out of LGPD scope or reduce risk in analytics pipelines. Use when user asks 'anonimizar', 'pseudonimizar', 'k-anonymity', 'differential privacy', 'tokenização', 'analytics LGPD', or designing analytics/ML pipelines.
Design and implement immutable, hash-chained audit logging for accountability (LGPD Art. 6, X) and incident registration (Res. 15/2024 Art. 10, 5-year retention). Use when user asks 'audit log', 'log de auditoria', 'logging LGPD', 'accountability log', or as part of audit pipeline. Outputs schema + middleware patterns for Next.js.
Maestro orchestrator for end-to-end LGPD (Lei 13.709/2018) compliance in a software project. Use for "como estamos de LGPD", "audite LGPD", "nos deixe LGPD seguros", "gap analysis LGPD", "compliance LGPD", "auditar privacidade", "LGPD do projeto", or any request to assess, implement, or retrofit privacy compliance — including English phrasings like "are we privacy-safe", "audit our privacy", or "we collect personal data, what do we need". Chains specialized sub-skills (data mapping, legal basis, consent, DSAR, incident response, ROPA, RIPD, retention, vendor audit, DPA, international transfer, encarregado, and ECA Digital / Lei 15.211/2025 for platforms with minors) and produces versioned artifacts under .lgpd/. Trigger even when the word "LGPD" is not used.
Design the database schema for a versioned, append-only consent ledger that satisfies LGPD Art. 8 (free, informed, unambiguous consent for a specific purpose) and Art. 9 (information rights). Use when user asks for "consent schema", "consent ledger", "schema de consentimento", "Prisma consentimento", "consent management", or is integrating consent capture with Better Auth, NextAuth, Clerk, or any auth library. Outputs a Prisma schema + integration spec. Also produces the structure needed to support DSAR revocation (Art. 18, IX).
Build and maintain a data inventory (mapa de dados) of all personal data processing activities in the project. Use when user asks "mapa de dados", "data mapping LGPD", "que dados pessoais coletamos", "inventário de tratamento", or as part of an LGPD audit pipeline. Produces `.lgpd/data-map.md`. Especially important for legacy systems where the inventory is built reverse-engineered from code (Prisma schemas, API endpoints, third-party SDKs, log statements).
Share bugs, ideas, or general feedback.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Conjunto modular e orquestrado de skills para Claude que cobre, ponta-a-ponta, conformidade com a LGPD (Lei 13.709/2018), resoluções da ANPD aplicáveis e o ECA Digital (Lei 15.211/2025). Inclui 1 skill maestro (lgpd-audit) que orquestra 18 sub-skills especializadas: base legal, mapeamento de dados, ROPA, RIPD, consentimento, DSAR, resposta a incidentes, encarregado, criptografia, retenção, DPA, transferência internacional e proteção de menores.
Complete collection of 282+ privacy and data protection skills covering GDPR, CCPA, HIPAA, LGPD, PIPL, and 15+ regulations
GDPR compliance assistant — code and system audits, privacy notice drafting, DPAs, DPIAs, data flow reviews, and authoritative article-cited Q&A.
Scan for GDPR compliance issues
Regulatory compliance verification for GDPR, SOC2, and HIPAA
Triages processing activities, generates PIAs, reviews DPAs as controller or processor, drafts DSAR responses within statutory timelines, and monitors policy drift against practice.
Conjunto modular e orquestrado de skills para Claude que cobre, ponta-a-ponta, conformidade com a LGPD (Lei 13.709/2018), resoluções da ANPD aplicáveis e o ECA Digital (Lei 15.211/2025). Inclui 1 skill maestro (lgpd-audit) que orquestra 18 sub-skills especializadas: base legal, mapeamento de dados, ROPA, RIPD, consentimento, DSAR, resposta a incidentes, encarregado, criptografia, retenção, DPA, transferência internacional e proteção de menores.
Conjunto modular e orquestrado de Agent Skills — funciona em Claude Code, Codex, Gemini CLI, Cursor e OpenCode — que cobre, ponta-a-ponta, conformidade com a Lei nº 13.709/2018 (LGPD), resoluções da ANPD aplicáveis e a Lei nº 15.211/2025 (ECA Digital).
EN — Quick overview: An Agent Skills bundle (works in Claude Code, Codex, Gemini CLI, Cursor, and OpenCode) that runs an end-to-end Brazilian privacy-law compliance audit on your codebase. One orchestrator skill (
lgpd-audit) chains 18 specialized sub-skills covering legal basis, data mapping, ROPA, DPIA (RIPD), consent ledger, DSAR endpoints, incident response (3 business days notification), encryption, retention, vendor DPAs, international transfer clauses, and ECA Digital (online safety for minors). Outputs versioned artifacts under.lgpd/. Triggered by phrases like "audit our LGPD compliance" or "we had a data breach". MIT licensed.
.lgpd/Um pacote de Agent Skills — instalável em Claude Code, Codex, Gemini CLI, Cursor e OpenCode — que transforma uma conversa de "preciso adequar isso aqui à LGPD" em um pipeline executável, versionável e auditável.
Em vez de uma skill gigante e monolítica, aqui são 19 skills coordenadas:
lgpd-audit) que orquestra todo o fluxo, decide o pipeline, mantém estado e pausa em checkpoints críticosCada sub-skill produz artefatos vivos versionáveis em Git sob .lgpd/ (STATUS.md, ROPA.md, RIPD/, política, runbook de incidente, etc.) — combina com fluxo de ADR e spec-driven development.
| Cenário | Pipeline ativado | Tempo estimado |
|---|---|---|
| Projeto greenfield, privacy-by-design desde o início | Pipeline A | 1-2 semanas |
| Sistema legado em produção precisando de auditoria + retrofit | Pipeline B | 2-6 semanas |
| Codebase híbrida (legado + features novas) | Pipeline C | 3-8 semanas |
| Incidente de segurança em andamento — preciso comunicar a ANPD | Pipeline D | 3 dias úteis (Res. 15/2024) |
Nenhum desses tempos é cravado — depende do tamanho do projeto, da equipe disponível, e do nível de maturidade atual.
As skills seguem o padrão aberto Agent Skills (agentskills.io) e funcionam nativamente em 5 agentes. Escolha o seu:
/plugin marketplace add goul4rt/lgpd-skills
/plugin install lgpd-skills@lgpd-skills
Atualizar: /plugin marketplace update lgpd-skills.
codex plugin marketplace add goul4rt/lgpd-skills
codex plugin add lgpd-skills@lgpd-skills
Ou, dentro do codex, rode /plugins e instale pela vitrine. Não é preciso submeter
nada ao marketplace da OpenAI — o repo é a própria fonte.
gemini extensions install https://github.com/goul4rt/lgpd-skills
Atualizar: gemini extensions update lgpd-skills. As 19 skills são auto-descobertas e
disparam via activate_skill.
No editor, rode /add-plugin e cole a URL do repo
(https://github.com/goul4rt/lgpd-skills), ou instale pela vitrine em
cursor.com/marketplace.
Adicione ao array plugin do seu opencode.json e reinicie:
{
"plugin": ["lgpd-skills@git+https://github.com/goul4rt/lgpd-skills.git"]
}
Detalhes e ressalvas em .opencode/INSTALL.md. Atenção: no
OpenCode as skills não disparam sozinhas — ative com a ferramenta skill (ex.: "use a
skill lgpd-audit").
~/.claude/skills/ ou .claude/skills/)git clone https://github.com/goul4rt/lgpd-skills.git /tmp/lgpd-skills
cp -r /tmp/lgpd-skills/skills/lgpd-* ~/.claude/skills/ # global
# ou, por projeto: cp -r /tmp/lgpd-skills/skills/lgpd-* .claude/skills/
rm -rf /tmp/lgpd-skills