From singapore-pdpa
Singapore - Personal Data Protection Ac (PDPA) (2012) expert. Reference-depth framework plugin with assessment, scope determination, and evidence checklist — backed by the SCF crosswalk. Level up to Full by adding framework-specific workflow commands.
npx claudepluginhub rifh2000/claude-grc-engineering. --plugin singapore-pdpaThis skill is limited to using the following tools:
Reference-depth expertise for **Singapore - Personal Data Protection Ac (PDPA) (2012)**. This plugin bundles the SCF crosswalk (30 SCF controls → 14 framework controls) with framework-specific context.
Creates isolated Git worktrees for feature branches with prioritized directory selection, gitignore safety checks, auto project setup for Node/Python/Rust/Go, and baseline verification.
Executes implementation plans in current session by dispatching fresh subagents per independent task, with two-stage reviews: spec compliance then code quality.
Dispatches parallel agents to independently tackle 2+ tasks like separate test failures or subsystems without shared state or dependencies.
Reference-depth expertise for Singapore - Personal Data Protection Ac (PDPA) (2012). This plugin bundles the SCF crosswalk (30 SCF controls → 14 framework controls) with framework-specific context.
apac-sgp-pdpa-2012TODO: add the following when filling in expertise. Reference depth expects all of these to have at least two-sentence answers.
TODO: one-paragraph summary of what Singapore - Personal Data Protection Ac (PDPA) (2012) exists to do and who it affects. Avoid verbatim regulation text — paraphrase and cite articles/sections by number.
TODO: who must comply, where operations must be happening, what the carve-outs are.
TODO: the named documents or registers the framework requires (e.g. GDPR's ROPA/DPIA, PCI DSS's ROC/SAQ, ISO 27001's Statement of Applicability). Stub if uncertain; a Full-depth PR can add commands to generate each.
TODO: notification windows (e.g. GDPR 72 hours), assessment frequency, recertification cycles.
TODO: who enforces, how penalties are calculated, recent enforcement patterns worth knowing.
TODO: overlaps with GDPR / ISO / NIST / sectoral rules. Reference the cross-framework analyzer outputs when useful.
TODO: at least 2–3 community-level misunderstandings this plugin should correct. Example: "ITAR only affects munitions" (it covers technical data too).
/singapore-pdpa:scope — determine applicability/singapore-pdpa:assess — run a gap assessment/singapore-pdpa:evidence-checklist — enumerate evidence requirementsAll three delegate to /grc-engineer:gap-assessment with SCF framework ID apac-sgp-pdpa-2012 for the control-by-control mechanics, and wrap the results in Singapore - Personal Data Protection Ac (PDPA) (2012)-specific terminology.
Full-depth plugins add framework-specific workflow commands tied to the audit ritual. Candidates for this framework:
TODO: propose 2–4 framework-specific commands. Examples from existing Full-depth plugins:
soc2: /soc2:service-auditor-prep, /soc2:trust-service-matrixfedramp-rev5: /fedramp-rev5:poam-review, /fedramp-rev5:ssp-outlinepci-dss: /pci-dss:roc-walkthrough, /pci-dss:saq-routecmmc: /cmmc:c3pao-readiness