Agent skill

Privacy Compliance

by aAAaqwq in aAAaqwq/AGI-Super-Team

Multi-regulation privacy compliance navigator. An agent skill from aAAaqwq/AGI-Super-Team.

MITAuto-check passedLegal & Compliance

Install Privacy Compliance

skills CLI
$ npx skills add aAAaqwq/AGI-Super-Team --skill privacy-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aAAaqwq/AGI-Super-Team privacy-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy-compliance .claude/skills/privacy-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
privacy-compliance
GitHub stars
105
Used in
1 other repo
Token cost
~3.6k tokens
SKILL.md length
1,096 words
Files
1
Skills in repo
167
Repo updated
First seen
Licence
MIT

At a glance

Multi-regulation privacy compliance navigator. An agent skill from aAAaqwq/AGI-Super-Team.

  • UK GDPR compliance assessments
  • SKILL.md covers Table of Contents, Tools, Reference Guides and Workflows, plus 5 more sections
  • Calls python
  • Data subject request management

What it does

Privacy Compliance is an agent skill from aAAaqwq/AGI-Super-Team. Multi-regulation privacy compliance navigator. Use for GDPR, CCPA, LGPD, POPIA, PIPEDA, PDPA, Privacy Act, PIPL, UK GDPR compliance assessments, DPA reviews, and data subject request management.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: An installable, cross-framework AI organization: C-suite agents, expert subagents, curated skills, independent review, and one-command setup across 18 AI client/runtime adapters. The licence is MIT.

When your agent uses it

  • UK GDPR compliance assessments
  • Data subject request management

Example prompts

  • “/privacy-compliance”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 7cefd81. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Privacy Compliance loads about 3.6k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 1,096 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aAAaqwq/AGI-Super-Team at commit 7cefd81, republished under its MIT licence (© aAAaqwq). 1,096 words, ~3,612 tokens.

Download SKILL.mdSave it as .claude/skills/privacy-compliance/SKILL.md (or your agent's skills folder).
name
privacy-compliance
description
Multi-regulation privacy compliance navigator. Use for GDPR, CCPA, LGPD, POPIA, PIPEDA, PDPA, Privacy Act, PIPL, UK GDPR compliance assessments, DPA reviews, and data subject request management.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
The Glass Room
metadata.category
legal
metadata.domain
privacy-compliance
metadata.updated
2026-04-10
metadata.tags
privacy, gdpr, ccpa, data-protection, compliance

⚠️ EXPERIMENTAL — This skill is provided for educational and informational purposes only. It does NOT constitute legal advice. All responsibility for usage rests with the user. Consult qualified legal professionals before acting on any output.

Privacy Compliance Navigator

Tools and guidance for multi-regulation privacy compliance across 9 major global privacy frameworks, DPA review, and data subject request lifecycle management.


Table of Contents


Tools

Privacy Regulation Checker

Determines which privacy regulations apply to an organization based on its location, data subjects, data types, and processing activities. Generates a compliance obligations matrix and flags gaps.

bash
# Basic check — organization in Germany processing EU and US data
python scripts/privacy_regulation_checker.py \
  --org-location DE \
  --data-subjects EU,US \
  --data-types personal,sensitive,financial \
  --processing-activities marketing,analytics,hr

# JSON output for integration
python scripts/privacy_regulation_checker.py \
  --org-location SG \
  --data-subjects SG,AU,CN \
  --data-types personal,health \
  --processing-activities healthcare,research \
  --json

# Include gap analysis against current practices
python scripts/privacy_regulation_checker.py \
  --org-location US-CA \
  --data-subjects EU,US,BR \
  --data-types personal,biometric \
  --processing-activities ecommerce,profiling \
  --current-practices consent_mechanism,breach_process,retention_policy

Determines:

  • Which of 9 regulations apply based on territorial scope rules
  • Key obligations per applicable regulation
  • Data subject rights required per regulation
  • Response timelines per regulation
  • Gap analysis when current practices are provided

Output:

  • Applicable regulations list with confidence level
  • Per-regulation obligations matrix
  • Gap analysis with risk ratings
  • Recommended priority actions

DSR Tracker

Manages Data Subject Request lifecycle across multiple regulations with deadline calculation, status tracking, and overdue alerts.

bash
# Add a new GDPR access request
python scripts/dsr_tracker.py add \
  --type access --regulation gdpr \
  --subject "Jane Smith" --email "jane@example.com"

# Add CCPA deletion request
python scripts/dsr_tracker.py add \
  --type deletion --regulation ccpa \
  --subject "John Doe" --email "john@example.com"

# List all open requests
python scripts/dsr_tracker.py list

# List overdue requests only
python scripts/dsr_tracker.py list --overdue

# Update request status
python scripts/dsr_tracker.py update --id DSR-0001 --status verified

# Dashboard view with time remaining
python scripts/dsr_tracker.py dashboard

# Export as JSON
python scripts/dsr_tracker.py dashboard --json

Supported Request Types:

TypeGDPR Art.CCPA SectionLGPD Art.
AccessArt. 15§1798.100Art. 18
Deletion/ErasureArt. 17§1798.105Art. 18(VI)
Correction/RectificationArt. 16§1798.106Art. 18(III)
PortabilityArt. 20§1798.130Art. 18(V)
RestrictionArt. 18—Art. 18(IV)
ObjectionArt. 21§1798.120Art. 18(IV)
Automated Decision Opt-OutArt. 22§1798.185Art. 20
Withdraw ConsentArt. 7(3)—Art. 18(IX)

Deadline Calculation:

RegulationInitial DeadlineExtensionExtension Deadline
GDPR30 calendar days+60 days (complex)90 calendar days
CCPA10 business days (ack) + 45 calendar days+45 days90 calendar days
LGPD15 calendar days——
POPIA30 calendar days——
PIPEDA30 calendar days+30 days60 calendar days
PDPA (SG)30 calendar days——
Privacy Act (AU)30 calendar days+30 days60 calendar days
PIPL15 calendar days+15 days30 calendar days
UK GDPR30 calendar days+60 days90 calendar days

Statuses: received → verified → processing → completed | denied | extended


Reference Guides

Global Privacy Regulations

references/global_privacy_regulations.md

Comprehensive comparison of 9 major privacy regulations covering:

  • Territorial scope and applicability criteria
  • Legal bases for processing
  • Data subject rights comparison matrix
  • Breach notification requirements and timelines
  • Cross-border transfer mechanisms
  • DPO requirements
  • Penalty structures
DPA Review Checklist

references/dpa_review_checklist.md

Complete Data Processing Agreement review guide:

  • Art. 28 GDPR required elements
  • 10 processor obligations with analysis points
  • International transfer mechanisms (SCCs June 2021, module selection)
  • Transfer impact assessment requirements
  • Common DPA issues with risk levels
  • Practical negotiation considerations
DSR Handling Guide

references/dsr_handling_guide.md

Data Subject Request handling reference:

  • 8 request types with intake procedures
  • Identity verification methods
  • Response timelines per regulation
  • Exemptions by regulation
  • 6-step response process
  • Regulatory monitoring approach

Workflows

Workflow 1: Regulation Applicability Assessment
Step 1: Identify organization parameters
        → Location, data subjects, data types, processing activities

Step 2: Run regulation checker
        → python scripts/privacy_regulation_checker.py --org-location [LOC] ...

Step 3: Review applicable regulations and obligations
        → Prioritize by risk (penalties, data volume, enforcement activity)

Step 4: Gap analysis against current practices
        → Re-run with --current-practices flag

Step 5: Build remediation roadmap
        → Address critical gaps first (missing legal basis, no breach process)
Workflow 2: Data Subject Request Handling
Step 1: Receive and log request
        → python scripts/dsr_tracker.py add --type [type] --regulation [reg] ...

Step 2: Verify identity (proportionate to sensitivity)
        → See references/dsr_handling_guide.md for methods
        → python scripts/dsr_tracker.py update --id [ID] --status verified

Step 3: Gather data from all systems
        → python scripts/dsr_tracker.py update --id [ID] --status processing

Step 4: Apply exemptions if applicable
        → Check references/dsr_handling_guide.md exemptions table

Step 5: Prepare and send response within deadline
        → python scripts/dsr_tracker.py update --id [ID] --status completed

Step 6: Monitor dashboard for overdue requests
        → python scripts/dsr_tracker.py dashboard
Workflow 3: DPA Review
Step 1: Check DPA against Art. 28 required elements
        → Use references/dpa_review_checklist.md

Step 2: Verify processor obligations (10 items)
        → Sub-processing, deletion, audit rights, etc.

Step 3: Assess international transfer provisions
        → SCC module selection (C2P, C2C, P2P, P2C)
        → Transfer impact assessment
        → Supplementary measures

Step 4: Review practical considerations
        → Liability caps, insurance, termination, data locations

Step 5: Document findings and negotiate amendments
Workflow 4: Multi-Regulation Compliance Program
Step 1: Run regulation checker for full scope
        → python scripts/privacy_regulation_checker.py [params]

Step 2: Map overlapping obligations across regulations
        → Use references/global_privacy_regulations.md comparison matrix

Step 3: Build unified controls (satisfy strictest requirement)
        → GDPR-first approach covers most other regulations

Step 4: Layer regulation-specific requirements
        → CCPA opt-out mechanisms, LGPD DPO, PIPL localization

Step 5: Monitor regulatory changes
        → See references/dsr_handling_guide.md monitoring approach

Troubleshooting

ProblemPossible CauseResolution
Regulation checker flags unexpected regulationData subjects in jurisdiction not consideredReview data flow maps; even indirect data collection (analytics, cookies) can trigger territorial scope
DSR deadline missedRequest not logged promptly or status not updatedImplement intake SLA (log within 24 hours); use dashboard daily for overdue alerts
DPA missing Art. 28 elementsTemplate from processor is incompleteUse DPA review checklist to identify gaps; require amendments before signing
Cross-border transfer mechanism unclearMultiple transfer layers (controller → processor → sub-processor)Map full data flow chain; each transfer leg needs its own mechanism
Conflicting obligations across regulationsRetention vs. deletion requirements differDocument conflicts; apply strictest obligation unless local law mandates otherwise; seek legal counsel
Identity verification proportionality unclearOver-verification deters legitimate requestsMatch verification to risk: low-risk data = email confirmation; high-risk = ID verification

Success Criteria

  • All applicable regulations identified and mapped — regulation checker confirms coverage with zero unaddressed jurisdictions where data subjects reside
  • 100% of DSRs responded within statutory deadlines — dashboard shows zero overdue requests; extension documented where used
  • DPAs reviewed against Art. 28 checklist before signing — all 10 processor obligations addressed; international transfer mechanisms validated
  • Compliance matrix maintained and current — quarterly review of obligations per regulation with change log
  • Regulatory monitoring active — escalation criteria defined; new regulation applicability assessed within 30 days of enactment

Show full SKILL.md (415 more words)Show less

Scope & Limitations

In Scope:

  • Applicability assessment for 9 major privacy regulations
  • Data subject request tracking with multi-regulation deadline calculation
  • DPA review against Art. 28 GDPR requirements
  • Cross-regulation obligation mapping
  • Gap analysis against current practices
  • International transfer mechanism assessment

Out of Scope:

  • Legal advice on specific legal basis selection — consult qualified privacy counsel
  • Supervisory authority filings or breach notifications
  • Cookie consent implementation or consent management platform configuration
  • Binding Corporate Rules (BCR) application process
  • Sector-specific regulations (HIPAA, FERPA, GLBA) beyond the 9 covered frameworks
  • Data Protection Impact Assessments (see dpia-assessment skill)

Anti-Patterns

Anti-PatternWhy It FailsBetter Approach
GDPR-only complianceOrganizations assume GDPR covers all obligations; miss CCPA opt-out requirements, LGPD DPO mandate, PIPL data localizationRun regulation checker against all jurisdictions where data subjects reside; layer regulation-specific controls
One-size-fits-all DSR processApplying GDPR 30-day timeline to all regulations misses CCPA 10-business-day acknowledgment or PIPL 15-day deadlineConfigure per-regulation deadlines; use DSR tracker with regulation parameter for accurate deadline calculation
Ignoring sub-processor chains in DPA reviewDPA covers direct processor but sub-processors transfer data to third countries without TIAMap full processing chain in DPA review; require Art. 28(2) sub-processor obligations; validate each transfer leg
Treating privacy as a one-time projectRegulations evolve; new laws enacted; enforcement priorities shiftImplement regulatory monitoring with escalation criteria; quarterly compliance reviews

Tool Reference

privacy_regulation_checker.py

Determines applicable privacy regulations and maps obligations based on organization parameters.

FlagRequiredDescription
--org-location <code>YesOrganization headquarters (ISO country code, e.g., DE, US-CA, SG)
--data-subjects <list>YesComma-separated locations of data subjects (EU, US, BR, ZA, CA, SG, AU, CN, UK)
--data-types <list>YesComma-separated data types (personal, sensitive, financial, health, biometric, children)
--processing-activities <list>YesComma-separated activities (marketing, analytics, hr, ecommerce, profiling, healthcare, research)
--current-practices <list>NoComma-separated current practices for gap analysis
--jsonNoOutput in JSON format
dsr_tracker.py

Tracks Data Subject Request lifecycle with multi-regulation deadline calculation.

SubcommandDescription
addAdd new DSR (--type, --regulation, --subject, --email required)
listList all requests (--overdue for overdue only)
updateUpdate request status (--id, --status required)
dashboardShow dashboard with time remaining and alerts
FlagDescription
--type <type>Request type: access, deletion, correction, portability, restriction, objection, automated_decision, withdraw_consent
--regulation <reg>Regulation: gdpr, ccpa, lgpd, popia, pipeda, pdpa, privacy_act_au, pipl, uk_gdpr
--subject <name>Data subject name
--email <email>Data subject email
--id <id>Request ID (e.g., DSR-0001)
--status <status>Status: received, verified, processing, completed, denied, extended
--overdueFilter to overdue requests only
--jsonOutput in JSON format
--data-file <path>Custom data file path (default: dsr_requests.json)

© aAAaqwq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/privacy-compliance of aAAaqwq/AGI-Super-Team.

Open the folder on GitHubat commit 7cefd81

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in aAAaqwq/AGI-Super-Team, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Privacy Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Privacy Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Privacy Compliance this skillaAAaqwq/AGI-Super-Team1051 repos~3.6kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from aAAaqwq/AGI-Super-Team

All 167 skills in this repo
  • Content Creator

    aAAaqwq/AGI-Super-Team

    Create SEO-optimized marketing content with consistent brand voice.

    105 GitHub starsUsed in 3 repos~1.9k tokens
    Auto-check passed
  • Financial Calculator

    aAAaqwq/AGI-Super-Team

    Advanced financial calculator with future value tables, present value, discount calculations, markup pricing, and compound interest.

    105 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Bankr Signals

    aAAaqwq/AGI-Super-Team

    Transaction-verified trading signals on Base blockchain. An agent skill from aAAaqwq/AGI-Super-Team.

    105 GitHub starsUsed in 2 repos~3.3k tokens
    Auto-check passed
  • Erc 8004

    aAAaqwq/AGI-Super-Team

    Register AI agents on Ethereum mainnet using ERC-8004 (Trustless Agents).

    105 GitHub starsUsed in 2 repos~1.2k tokens
    Auto-check passed
  • Frontend Design Ultimate

    aAAaqwq/AGI-Super-Team

    Create distinctive, production-grade static sites with React, Tailwind CSS, and shadcn/ui — no mockups needed.

    105 GitHub starsUsed in 2 repos~2.7k tokens
    Auto-check passed
  • Zsxq Smart Publish

    aAAaqwq/AGI-Super-Team

    Publish and manage content on 知识星球 (zsxq.com). An agent skill from aAAaqwq/AGI-Super-Team.

    105 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed

Questions about Privacy Compliance

What does Privacy Compliance do?

Multi-regulation privacy compliance navigator. An agent skill from aAAaqwq/AGI-Super-Team. Privacy Compliance is an agent skill from aAAaqwq/AGI-Super-Team. Multi-regulation privacy compliance navigator.

When should I use Privacy Compliance?

Privacy Compliance fits situations like: UK GDPR compliance assessments; data subject request management.

How do I install Privacy Compliance in Claude Code?

Run `npx skills add aAAaqwq/AGI-Super-Team --skill privacy-compliance -a claude-code`. Or copy the skill folder (skills/privacy-compliance in aAAaqwq/AGI-Super-Team) into .claude/skills/privacy-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Privacy Compliance in Codex?

Run `npx skills add aAAaqwq/AGI-Super-Team --skill privacy-compliance -a codex`. Or copy the skill folder (skills/privacy-compliance in aAAaqwq/AGI-Super-Team) into .agents/skills/privacy-compliance in your project. Codex loads it when a task matches its description.

Can I use Privacy Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aAAaqwq/AGI-Super-Team --skill privacy-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-compliance, .gemini/skills/privacy-compliance, .github/skills/privacy-compliance and .opencode/skills/privacy-compliance in your project.

What does Privacy Compliance need to run?

Going by SKILL.md and its folder, Privacy Compliance needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Privacy Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Privacy Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Privacy Compliance use?

Privacy Compliance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Privacy Compliance use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Privacy Compliance?

Skills that share tags, products or a category with Privacy Compliance: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Privacy Compliance?

aAAaqwq (a GitHub user) maintains it in aAAaqwq/AGI-Super-Team, which has 105 GitHub stars. The repository holds 167 skills in this directory. The repository was last updated on October 8, 2026.

Source: aAAaqwq/AGI-Super-Team on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.