Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By mukul975
Execute structured data breach responses including 72-hour GDPR notifications, risk assessments via CIA triad, digital forensics with chain of custody, remediation to prevent recurrence, tabletop simulations, credit monitoring enrollment, and compliance across EU GDPR, HIPAA, California laws, and multi-jurisdictions.
npx claudepluginhub mukul975/privacy-data-protection-skills --plugin data-breach-response-skillsManages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notification laws (varying timelines from 30 to 90 days), and other international regimes. Covers conflict resolution when notification timelines differ, lead supervisory authority determination, and parallel notification execution. Keywords: multi-jurisdiction, cross-border breach, notification coordination, GDPR, US state laws, international breach notification.
Conducts structured post-breach remediation using a lessons learned framework covering root cause remediation, control gap closure, policy updates, training modifications, monitoring enhancements, and regulatory follow-up. Provides a systematic approach to preventing breach recurrence and demonstrating accountability to supervisory authorities. Keywords: post-breach, remediation, lessons learned, root cause, control gap, policy update, training.
Builds a comprehensive breach response team playbook defining CSIRT and privacy team structure with named roles (incident commander, legal counsel, communications, IT forensics, DPO), escalation matrices, communication templates, pre-negotiated vendor contacts, and regulatory authority contacts organized by jurisdiction. Keywords: breach response playbook, CSIRT, incident response team, escalation matrix, communication templates, vendor contacts.
Determines whether a personal data breach triggers notification obligations under GDPR Articles 33 and 34 using structured risk assessment methodology. Covers breach type classification (CIA triad), data sensitivity scoring, volume assessment, identifiability analysis, and consequence severity evaluation. References EDPB Guidelines 01/2021 with 18 breach scenarios. Keywords: breach risk assessment, GDPR, Article 33, Article 34, EDPB, notification threshold.
Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities. Covers scenario creation with realistic inject timelines, participant role assignment, communication testing across internal and external channels, decision-point evaluation, and after-action report generation. Keywords: tabletop exercise, breach simulation, incident response testing, scenario design, after-action report.
Share bugs, ideas, or general feedback.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Complete collection of 282+ privacy and data protection skills covering GDPR, CCPA, HIPAA, LGPD, PIPL, and 15+ regulations
GDPR compliance assistant — code and system audits, privacy notice drafting, DPAs, DPIAs, data flow reviews, and authoritative article-cited Q&A.
Conjunto modular e orquestrado de skills para Claude que cobre, ponta-a-ponta, conformidade com a LGPD (Lei 13.709/2018), resoluções da ANPD aplicáveis e o ECA Digital (Lei 15.211/2025). Inclui 1 skill maestro (lgpd-audit) que orquestra 18 sub-skills especializadas: base legal, mapeamento de dados, ROPA, RIPD, consentimento, DSAR, resposta a incidentes, encarregado, criptografia, retenção, DPA, transferência internacional e proteção de menores.
GDPR Plugin - EU General Data Protection Regulation with DPIA, data subject rights, and 72-hour breach notification
Ultra-compressed communication mode. Cuts ~75% of tokens while keeping full technical accuracy by speaking like a caveman.
Frontend design skill for UI/UX implementation
753 cybersecurity skills covering web security, pentesting, DFIR, threat intelligence, cloud security, malware analysis, and more.
12 data retention and deletion skills: retention schedules, auto-deletion, backup erasure, secure destruction, litigation holds
14 privacy engineering skills: differential privacy, PII detection, NIST Privacy Framework, privacy APIs, data sharing, metrics
12 data classification skills: auto-discovery, PII detection, data inventory, labeling, lineage tracking, special category data
11 privacy audit and certification skills: ISO 27701, APEC CBPR, SOC 2, maturity model, continuous compliance, DPA inspection
The first structured, machine-readable privacy skills database for AI agents. 282+ open-source privacy compliance procedures covering GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, and India's DPDP Act — following the agentskills.io open standard. Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI, and 26+ AI platforms.
git clone https://github.com/mukul975/Privacy-Data-Protection-Skills.git
cd Privacy-Data-Protection-Skills/skills/privacy/conducting-gdpr-dpia
cat SKILL.md
Or install via Claude Code Plugin Marketplace:
/plugin marketplace add mukul975/Privacy-Data-Protection-Skills
/plugin install privacy-skills-complete@privacy-data-protection-skills
| Jurisdiction | Regulation | Skills | Status |
|---|---|---|---|
| EU | GDPR (Regulation 2016/679) | 50+ | Full |
| EU | EU AI Act (Regulation 2024/1689) | 15+ | Full |
| EU | ePrivacy Directive | 12+ | Full |
| US | CCPA/CPRA | 13+ | Full |
| US | HIPAA Privacy and Security Rules | 11+ | Full |
| US | 13 State Privacy Laws | 13+ | Full |
| Brazil | LGPD | 3+ | Yes |
| China | PIPL | 3+ | Yes |
| India | DPDP Act 2023 | 3+ | Yes |
| Japan | APPI | 3+ | Yes |
| South Korea | PIPA | 3+ | Yes |
| Singapore | PDPA | 3+ | Yes |
| Thailand | PDPA | 3+ | Yes |
| South Africa | POPIA | 3+ | Yes |
| Australia | Privacy Act 1988 | 3+ | Yes |
| Canada | PIPEDA | 3+ | Yes |
| Cross-border | APEC CBPR, SCCs, BCRs, EU-US DPF | 12+ | Full |
AI agents are increasingly used for privacy compliance tasks but operate with zero structured knowledge of privacy regulations, leading to:
Each skill provides structured, verified regulatory knowledge that AI agents load on demand, replacing hallucination with precision.
Real-world use cases:
Disclaimer: These skills are educational reference materials, not legal advice. Consult qualified legal counsel for compliance decisions.
| Category | Skills | Example |
|---|---|---|
| GDPR Compliance | 18 | gdpr-compliance-audit |
| Privacy Impact Assessment | 18 | conducting-gdpr-dpia |
| Data Subject Rights | 15 | dsar-processing |
| AI Privacy Governance | 15 | ai-dpia |
| Consent Management | 14 | gdpr-valid-consent |
| Privacy Engineering | 14 | differential-privacy-prod |
| Privacy by Design | 13 | implementing-homomorphic-encryption |
| Data Breach Response | 13 | breach-72h-notification |
| US State Privacy Laws | 13 | ccpa-cpra-compliance |
| Cross-Border Transfers | 12 | scc-implementation |
| Cookie and Consent | 12 | tcf-v2-implementation |
| Data Classification | 12 | pii-detection-pipeline |
| Data Retention | 12 | retention-schedule |
| Global Regulations | 12 | china-pipl |
| Vendor Management | 11 | vendor-risk-scoring |
| Healthcare Privacy | 11 | hipaa-risk-analysis |
| Employee Privacy | 11 | employee-monitoring-dpia |
| Privacy Audit | 11 | iso-27701-pims |
| Records of Processing | 10 | controller-ropa-creation |
| Children's Privacy | 10 | coppa-compliance |
Every skill follows the agentskills.io open standard: