By mukul975
Provides 282+ skills for privacy and data protection compliance across GDPR, CCPA, HIPAA, LGPD, PIPL, and 15+ other regulations. Covers DPIAs, breach notifications, consent management, data subject requests, vendor audits, AI/ML privacy, and multi-jurisdiction gap analysis.
Implements 42 CFR Part 2 protections for substance use disorder patient records. Covers written consent requirements stricter than HIPAA, re-disclosure prohibition, court order procedures, qualified service organization agreements, and 2024 amendments aligning Part 2 with HIPAA. Keywords: 42 CFR Part 2, substance use disorder, SUD records, re-disclosure, consent, Part 2 amendments.
Guides assessment of third-country adequacy decisions under GDPR Article 45 for international data transfers. Covers the current EC adequacy decisions list, adequacy assessment criteria, partial adequacy handling, and monitoring of adequacy decision reviews. Keywords: adequacy decision, Article 45, third country, adequate protection, EC adequacy list.
Implements age-gating mechanisms for online services to restrict access based on user age. Covers hard gates versus soft gates, neutral age prompts, re-verification triggers, circumvention prevention, and regulatory requirements under GDPR, COPPA, UK Online Safety Act, and DSA. Keywords: age gate, age restriction, neutral prompt, children, online services, access control.
Evaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
Preparing EU AI Act compliance documentation for high-risk AI systems. Covers Annex III classification, technical documentation under Art. 11, conformity assessment, risk management systems, and CE marking requirements. Keywords: EU AI Act, high-risk AI, Annex III, conformity assessment, CE marking.
npx claudepluginhub mukul975/privacy-data-protection-skills --plugin privacy-skills-completeBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
The first structured, machine-readable privacy skills database for AI agents. 282+ open-source privacy compliance procedures covering GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, and India's DPDP Act — following the agentskills.io open standard. Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI, and 26+ AI platforms.
git clone https://github.com/mukul975/Privacy-Data-Protection-Skills.git
cd Privacy-Data-Protection-Skills/skills/privacy/conducting-gdpr-dpia
cat SKILL.md
Or install via Claude Code Plugin Marketplace:
/plugin marketplace add mukul975/Privacy-Data-Protection-Skills
/plugin install privacy-skills-complete@privacy-data-protection-skills
| Jurisdiction | Regulation | Skills | Status |
|---|---|---|---|
| EU | GDPR (Regulation 2016/679) | 50+ | Full |
| EU | EU AI Act (Regulation 2024/1689) | 15+ | Full |
| EU | ePrivacy Directive | 12+ | Full |
| US | CCPA/CPRA | 13+ | Full |
| US | HIPAA Privacy and Security Rules | 11+ | Full |
| US | 13 State Privacy Laws | 13+ | Full |
| Brazil | LGPD | 3+ | Yes |
| China | PIPL | 3+ | Yes |
| India | DPDP Act 2023 | 3+ | Yes |
| Japan | APPI | 3+ | Yes |
| South Korea | PIPA | 3+ | Yes |
| Singapore | PDPA | 3+ | Yes |
| Thailand | PDPA | 3+ | Yes |
| South Africa | POPIA | 3+ | Yes |
| Australia | Privacy Act 1988 | 3+ | Yes |
| Canada | PIPEDA | 3+ | Yes |
| Cross-border | APEC CBPR, SCCs, BCRs, EU-US DPF | 12+ | Full |
AI agents are increasingly used for privacy compliance tasks but operate with zero structured knowledge of privacy regulations, leading to:
Each skill provides structured, verified regulatory knowledge that AI agents load on demand, replacing hallucination with precision.
Real-world use cases:
Disclaimer: These skills are educational reference materials, not legal advice. Consult qualified legal counsel for compliance decisions.
| Category | Skills | Example |
|---|---|---|
| GDPR Compliance | 18 | gdpr-compliance-audit |
| Privacy Impact Assessment | 18 | conducting-gdpr-dpia |
| Data Subject Rights | 15 | dsar-processing |
| AI Privacy Governance | 15 | ai-dpia |
| Consent Management | 14 | gdpr-valid-consent |
| Privacy Engineering | 14 | differential-privacy-prod |
| Privacy by Design | 13 | implementing-homomorphic-encryption |
| Data Breach Response | 13 | breach-72h-notification |
| US State Privacy Laws | 13 | ccpa-cpra-compliance |
| Cross-Border Transfers | 12 | scc-implementation |
| Cookie and Consent | 12 | tcf-v2-implementation |
| Data Classification | 12 | pii-detection-pipeline |
| Data Retention | 12 | retention-schedule |
| Global Regulations | 12 | china-pipl |
| Vendor Management | 11 | vendor-risk-scoring |
| Healthcare Privacy | 11 | hipaa-risk-analysis |
| Employee Privacy | 11 | employee-monitoring-dpia |
| Privacy Audit | 11 | iso-27701-pims |
| Records of Processing | 10 | controller-ropa-creation |
| Children's Privacy | 10 | coppa-compliance |
Every skill follows the agentskills.io open standard:
817 cybersecurity skills covering web security, pentesting, DFIR, threat intelligence, cloud security, malware analysis, and more.
11 healthcare privacy skills: HIPAA Privacy/Security Rules, risk analysis, BAA management, de-identification, telehealth
13 US state privacy law skills: CCPA/CPRA, VCDPA, CPA, CTDPA, TDPSA, multi-state compliance, universal opt-out
14 consent management skills: valid consent, consent withdrawal, preference centers, consent for research, children, mobile apps
13 breach response skills: 72h notification, forensics, remediation, simulation, multi-jurisdiction, credit monitoring
18 GDPR compliance skills: audit, gap analysis, accountability, DPO, certification, DPA drafting, supervisory authority cooperation
GDPR compliance assistant — code and system audits, privacy notice drafting, DPAs, DPIAs, data flow reviews, and authoritative article-cited Q&A.
Conjunto modular e orquestrado de skills para Claude que cobre, ponta-a-ponta, conformidade com a LGPD (Lei 13.709/2018), resoluções da ANPD aplicáveis e o ECA Digital (Lei 15.211/2025). Inclui 1 skill maestro (lgpd-audit) que orquestra 18 sub-skills especializadas: base legal, mapeamento de dados, ROPA, RIPD, consentimento, DSAR, resposta a incidentes, encarregado, criptografia, retenção, DPA, transferência internacional e proteção de menores.
Implement GDPR-compliant data handling with consent management, data subject rights, and privacy by design. Use when building systems that process EU personal data, implementing privacy controls, or conducting GDPR compliance reviews.
Regulatory compliance verification for GDPR, SOC2, and HIPAA
Use this agent when you need to implement data privacy engineering, GDPR compliance, data protection frameworks, and privacy-by-design principles for B2B applications. This agent specializes in privacy engineering, data minimization, consent management, and global privacy regulation compliance for enterprise platforms. Examples: