Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By mukul975
Conduct GDPR DPIA/PIA for high-risk personal data processing in AI systems, biometrics, cloud migrations, health data, employee surveillance, marketing analytics, and emerging tech. Perform threshold screening, risk scoring with likelihood-severity matrices, mitigation planning, stakeholder consultations, periodic reviews, and prior supervisory authority consultations.
npx claudepluginhub mukul975/privacy-data-protection-skills --plugin privacy-impact-assessment-skillsGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
Guides DPIA for biometric processing systems including facial recognition, fingerprint, voice, iris, and gait analysis. Covers Art. 9 special category requirements, Art. 35(3)(b) mandatory DPIA triggers for large-scale biometric processing, and EDPB Guidelines 3/2019 on video surveillance. Keywords: biometric, facial recognition, fingerprint, DPIA, Art. 9, special category, EDPB Guidelines 3/2019.
Guides DPIA for migrating personal data to cloud infrastructure covering controller-processor analysis under Art. 28, international transfer assessment, encryption requirements, and shared responsibility model evaluation. Activate for cloud adoption, SaaS procurement, or data centre migration projects. Keywords: cloud migration, DPIA, Art. 28, processor, encryption, shared responsibility, SaaS, IaaS, PaaS.
Compares PIA/DPIA methodologies: CNIL PIA tool, ICO DPIA template, NIST Privacy Framework, and ISO 29134. Provides methodology selection criteria based on regulatory jurisdiction, organisation maturity, processing complexity, and resource availability. Covers regulatory acceptance, tool features, and cross-methodology mapping. Keywords: PIA methodology, CNIL, ICO, NIST Privacy Framework, ISO 29134, DPIA comparison, assessment.
Guides the end-to-end GDPR Data Protection Impact Assessment process under Article 35, including mandatory trigger identification per Art. 35(3), DPIA content requirements per Art. 35(7), and EDPB WP248rev.01 methodology. Activate for systematic profiling, large-scale special category processing, or large-scale public monitoring. Keywords: DPIA, Article 35, impact assessment, WP248, data protection, risk assessment.
Share bugs, ideas, or general feedback.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
18 GDPR compliance skills: audit, gap analysis, accountability, DPO, certification, DPA drafting, supervisory authority cooperation
GDPR compliance assistant — code and system audits, privacy notice drafting, DPAs, DPIAs, data flow reviews, and authoritative article-cited Q&A.
Conjunto modular e orquestrado de skills para Claude que cobre, ponta-a-ponta, conformidade com a LGPD (Lei 13.709/2018), resoluções da ANPD aplicáveis e o ECA Digital (Lei 15.211/2025). Inclui 1 skill maestro (lgpd-audit) que orquestra 18 sub-skills especializadas: base legal, mapeamento de dados, ROPA, RIPD, consentimento, DSAR, resposta a incidentes, encarregado, criptografia, retenção, DPA, transferência internacional e proteção de menores.
GDPR Plugin - EU General Data Protection Regulation with DPIA, data subject rights, and 72-hour breach notification
Ultra-compressed communication mode. Cuts ~75% of tokens while keeping full technical accuracy by speaking like a caveman.
Frontend design skill for UI/UX implementation
753 cybersecurity skills covering web security, pentesting, DFIR, threat intelligence, cloud security, malware analysis, and more.
12 data retention and deletion skills: retention schedules, auto-deletion, backup erasure, secure destruction, litigation holds
14 privacy engineering skills: differential privacy, PII detection, NIST Privacy Framework, privacy APIs, data sharing, metrics
12 data classification skills: auto-discovery, PII detection, data inventory, labeling, lineage tracking, special category data
11 privacy audit and certification skills: ISO 27701, APEC CBPR, SOC 2, maturity model, continuous compliance, DPA inspection
The first structured, machine-readable privacy skills database for AI agents. 282+ open-source privacy compliance procedures covering GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, and India's DPDP Act — following the agentskills.io open standard. Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI, and 26+ AI platforms.
git clone https://github.com/mukul975/Privacy-Data-Protection-Skills.git
cd Privacy-Data-Protection-Skills/skills/privacy/conducting-gdpr-dpia
cat SKILL.md
Or install via Claude Code Plugin Marketplace:
/plugin marketplace add mukul975/Privacy-Data-Protection-Skills
/plugin install privacy-skills-complete@privacy-data-protection-skills
| Jurisdiction | Regulation | Skills | Status |
|---|---|---|---|
| EU | GDPR (Regulation 2016/679) | 50+ | Full |
| EU | EU AI Act (Regulation 2024/1689) | 15+ | Full |
| EU | ePrivacy Directive | 12+ | Full |
| US | CCPA/CPRA | 13+ | Full |
| US | HIPAA Privacy and Security Rules | 11+ | Full |
| US | 13 State Privacy Laws | 13+ | Full |
| Brazil | LGPD | 3+ | Yes |
| China | PIPL | 3+ | Yes |
| India | DPDP Act 2023 | 3+ | Yes |
| Japan | APPI | 3+ | Yes |
| South Korea | PIPA | 3+ | Yes |
| Singapore | PDPA | 3+ | Yes |
| Thailand | PDPA | 3+ | Yes |
| South Africa | POPIA | 3+ | Yes |
| Australia | Privacy Act 1988 | 3+ | Yes |
| Canada | PIPEDA | 3+ | Yes |
| Cross-border | APEC CBPR, SCCs, BCRs, EU-US DPF | 12+ | Full |
AI agents are increasingly used for privacy compliance tasks but operate with zero structured knowledge of privacy regulations, leading to:
Each skill provides structured, verified regulatory knowledge that AI agents load on demand, replacing hallucination with precision.
Real-world use cases:
Disclaimer: These skills are educational reference materials, not legal advice. Consult qualified legal counsel for compliance decisions.
| Category | Skills | Example |
|---|---|---|
| GDPR Compliance | 18 | gdpr-compliance-audit |
| Privacy Impact Assessment | 18 | conducting-gdpr-dpia |
| Data Subject Rights | 15 | dsar-processing |
| AI Privacy Governance | 15 | ai-dpia |
| Consent Management | 14 | gdpr-valid-consent |
| Privacy Engineering | 14 | differential-privacy-prod |
| Privacy by Design | 13 | implementing-homomorphic-encryption |
| Data Breach Response | 13 | breach-72h-notification |
| US State Privacy Laws | 13 | ccpa-cpra-compliance |
| Cross-Border Transfers | 12 | scc-implementation |
| Cookie and Consent | 12 | tcf-v2-implementation |
| Data Classification | 12 | pii-detection-pipeline |
| Data Retention | 12 | retention-schedule |
| Global Regulations | 12 | china-pipl |
| Vendor Management | 11 | vendor-risk-scoring |
| Healthcare Privacy | 11 | hipaa-risk-analysis |
| Employee Privacy | 11 | employee-monitoring-dpia |
| Privacy Audit | 11 | iso-27701-pims |
| Records of Processing | 10 | controller-ropa-creation |
| Children's Privacy | 10 | coppa-compliance |
Every skill follows the agentskills.io open standard: