Agent skill

Law Gdpr Pdpa

by asgard-ai-platform in asgard-ai-platform/skills

Analyze data privacy compliance requirements under GDPR, Taiwan's Personal Data Protection Act (PDPA), and related regulations.

MITAuto-check passedLegal & Compliance

Install Law Gdpr Pdpa

skills CLI
$ npx skills add asgard-ai-platform/skills --skill law-gdpr-pdpa -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install asgard-ai-platform/skills law-gdpr-pdpa --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/asgard-ai-platform/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/law-gdpr-pdpa .claude/skills/law-gdpr-pdpa && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
law-gdpr-pdpa
GitHub stars
242
Token cost
~1.4k tokens
SKILL.md length
525 words
Files
4 (incl. references)
Skills in repo
207
Repo updated
First seen
Licence
MIT

At a glance

Analyze data privacy compliance requirements under GDPR, Taiwan's Personal Data Protection Act (PDPA), and related regulations.

  • Works in 9 steps: Data inventory: What personal data do… → Legal basis audit: What legal basis… → Purpose limitation: Is data used only… → …
  • The user needs to assess data privacy obligations
  • SKILL.md covers Overview, Framework, Output Format and Examples, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Law Gdpr Pdpa is an agent skill from asgard-ai-platform/skills. Analyze data privacy compliance requirements under GDPR, Taiwan's Personal Data Protection Act (PDPA), and related regulations. Use this skill when the user needs to assess data privacy obligations, design compliant data handling processes, evaluate cross-border data transfer risks, or understand data subject rights — even if they say 'do we comply with GDPR', 'can we collect this data', 'what are our privacy obligations', or 'how do we handle user data in Taiwan'.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `examples/sample_scenario.md`, `references/gdpr-articles.md` and `references/taiwan-pdpa.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 301 open-source coding agent skills across 22 domains — methodology, judgment & gotchas packaged as Claude Agent Skills for the Asgard AI Platform. The licence is MIT.

When your agent uses it

  • The user needs to assess data privacy obligations
  • Design compliant data handling processes
  • Evaluate cross-border data transfer risks
  • Understand data subject rights — even if they say do we comply with GDPR

Example prompts

  • “do we comply with GDPR”
  • “can we collect this data”
  • “what are our privacy obligations”
  • “/law-gdpr-pdpa”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Data inventory: What personal data do you collect, process, and store?
  2. Legal basis audit: What legal basis justifies each processing activity?
  3. Purpose limitation: Is data used only for the stated purpose?
  4. Data minimization: Are you collecting only what's necessary?
  5. Storage limitation: How long is data retained? Is there a deletion policy?
  6. Security measures: Are appropriate technical and organizational measures in place?
  7. Rights fulfillment: Can you respond to data subject rights requests?
  8. Cross-border transfers: Does data leave the jurisdiction? Under what mechanism?
  9. Breach response: Is there a breach notification procedure?

What it can do on your machine

Read from SKILL.md and the folder at commit 4e7f4f8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Law Gdpr Pdpa loads about 1.4k tokens when it runs, and up to ~9.7k if it reads all its reference files. Until then it costs about 121 tokens; SKILL.md has 525 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~121
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from asgard-ai-platform/skills at commit 4e7f4f8, republished under its MIT licence (© asgard-ai-platform). 525 words, ~1,432 tokens.

Download SKILL.mdSave it as .claude/skills/law-gdpr-pdpa/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
law-gdpr-pdpa
description
Analyze data privacy compliance requirements under GDPR, Taiwan's Personal Data Protection Act (PDPA), and related regulations. Use this skill when the user needs to assess data privacy obligations, design compliant data handling processes, evaluate cross-border data transfer risks, or understand data subject rights — even if they say 'do we comply with GDPR', 'can we collect this data', 'what are our privacy obligations', or 'how do we handle user data in Taiwan'.
metadata.category
WP-20 法學院
metadata.tags
law, gdpr, pdpa, data-privacy

Data Privacy Compliance (GDPR & Taiwan PDPA)

Overview

Data privacy law governs how organizations collect, process, store, and share personal data. GDPR (EU) is the global benchmark; Taiwan's PDPA (個人資料保護法) applies domestically. Both share core principles but differ in scope, enforcement, and specific requirements.

Framework

IRON LAW: No Collection Without Legal Basis

You CANNOT collect or process personal data just because you want to.
Every data processing activity requires a legal basis:
- GDPR: 6 legal bases (consent, contract, legal obligation, vital interests, public task, legitimate interests)
- Taiwan PDPA: Specific purposes listed in the act, with consent as primary basis

"We need this data for analytics" is NOT a legal basis.
GDPR vs Taiwan PDPA Comparison
AspectGDPRTaiwan PDPA
ScopeAny org processing EU residents' dataAny org processing personal data in Taiwan
Legal bases6 enumerated basesConsent-centric + specific purpose limitation
Consent standardFreely given, specific, informed, unambiguous, opt-inWritten consent required for sensitive data; implied consent possible for non-sensitive
Data subject rightsAccess, rectification, erasure, portability, restriction, objectionAccess, correction, deletion, cessation of processing
Cross-border transferAdequacy decision, SCCs, BCRsRequires central authority approval or adequate protection
Breach notification72 hours to authorityReport to authority + notify affected individuals "without delay"
PenaltiesUp to €20M or 4% global turnoverUp to NT$500K per violation (criminal penalties possible)
DPO required?Yes (in certain cases)Not explicitly required
Compliance Assessment Steps
  1. Data inventory: What personal data do you collect, process, and store?
  2. Legal basis audit: What legal basis justifies each processing activity?
  3. Purpose limitation: Is data used only for the stated purpose?
  4. Data minimization: Are you collecting only what's necessary?
  5. Storage limitation: How long is data retained? Is there a deletion policy?
  6. Security measures: Are appropriate technical and organizational measures in place?
  7. Rights fulfillment: Can you respond to data subject rights requests?
  8. Cross-border transfers: Does data leave the jurisdiction? Under what mechanism?
  9. Breach response: Is there a breach notification procedure?

Output Format

markdown
# Privacy Compliance Assessment: {Organization}

## Data Inventory
| Data Category | Types | Legal Basis | Purpose | Retention |
|-------------|-------|-------------|---------|-----------|
| {category} | {specific fields} | {basis} | {why collected} | {period} |

## Compliance Gaps
| Requirement | Status | Gap | Priority |
|------------|--------|-----|----------|
| Legal basis | ✓/✗ | {detail} | H/M/L |
| Consent mechanism | ✓/✗ | ... | ... |
| Data subject rights | ✓/✗ | ... | ... |
| Breach notification | ✓/✗ | ... | ... |
| Cross-border transfer | ✓/✗ | ... | ... |

## Remediation Plan
1. {action} — priority: {H/M/L} — timeline: {X weeks}

Examples

Correct Application

Scenario: Privacy assessment for a Taiwanese e-commerce site selling to EU customers

  • Applies: Both PDPA (Taiwan customers) AND GDPR (EU customers)
  • Gap found: Cookie consent banner only says "By using this site you agree to cookies" → Fails GDPR (not freely given, not specific, no opt-out for non-essential cookies). Must implement granular cookie consent with opt-in for marketing cookies ✓
  • Gap found: Customer data shared with logistics partner in China without cross-border transfer mechanism → Fails both GDPR (no adequacy/SCC) and PDPA (no authority approval)
Show full SKILL.md (175 more words)Show less
Incorrect Application
  • "We're a Taiwan company, GDPR doesn't apply to us" → GDPR applies to ANY organization processing EU residents' data, regardless of where the organization is located. If you sell to EU customers or monitor EU users' behavior, GDPR applies.

Gotchas

  • Consent is not always the best legal basis: Under GDPR, "legitimate interests" may be more appropriate than consent for some processing (e.g., fraud prevention). Consent can be withdrawn, creating operational complexity.
  • "Anonymous" data may not be anonymous: If data can be re-identified by combining with other datasets, it's pseudonymous, not anonymous, and still subject to privacy law.
  • Taiwan PDPA covers public and private sector: Unlike GDPR which primarily targets private sector, PDPA applies to government agencies as well.
  • Privacy by design, not afterthought: Both GDPR and best practice require considering privacy at the system design stage, not bolting it on later.
  • This is educational guidance, not legal advice: Privacy compliance requires a qualified data protection specialist familiar with applicable jurisdictions.

References

  • For GDPR Article-by-article reference, see references/gdpr-articles.md
  • For Taiwan PDPA implementation guide, see references/taiwan-pdpa.md

© asgard-ai-platform, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in law-gdpr-pdpa of asgard-ai-platform/skills.

  • SKILL.md
  • examples/sample_scenario.md
  • references/gdpr-articles.md
  • references/taiwan-pdpa.md

Open the folder on GitHubat commit 4e7f4f8

Compare with similar skills

Law Gdpr Pdpa next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Law Gdpr Pdpa compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Law Gdpr Pdpa this skillasgard-ai-platform/skills242—~1.4kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from asgard-ai-platform/skills

All 207 skills in this repo
  • Algo Ecom Bm25

    asgard-ai-platform/skills

    Implement BM25 ranking function for e-commerce product search relevance scoring.

    242 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Algo Mfg Cpk

    asgard-ai-platform/skills

    Calculate Cpk process capability index to assess whether a process meets specification requirements.

    242 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Algo Price Elasticity

    asgard-ai-platform/skills

    Calculate price elasticity of demand to quantify how price changes affect sales volume.

    242 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Algo Rank Bayesian

    asgard-ai-platform/skills

    Apply Bayesian averaging to rank items by combining observed ratings with prior expectations.

    242 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Algo Rank Elo

    asgard-ai-platform/skills

    Implement Elo rating system to rank items or players from pairwise comparison outcomes.

    242 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Algo Rank Wilson

    asgard-ai-platform/skills

    Calculate Wilson Score confidence intervals for ranking items by positive proportion with sample size correction.

    242 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed

Questions about Law Gdpr Pdpa

What does Law Gdpr Pdpa do?

Analyze data privacy compliance requirements under GDPR, Taiwan's Personal Data Protection Act (PDPA), and related regulations. Law Gdpr Pdpa is an agent skill from asgard-ai-platform/skills. Analyze data privacy compliance requirements under GDPR, Taiwan's Personal Data Protection Act (PDPA), and related regulations.

When should I use Law Gdpr Pdpa?

Law Gdpr Pdpa fits situations like: the user needs to assess data privacy obligations; design compliant data handling processes; evaluate cross-border data transfer risks; understand data subject rights — even if they say do we comply with GDPR.

How do I install Law Gdpr Pdpa in Claude Code?

Run `npx skills add asgard-ai-platform/skills --skill law-gdpr-pdpa -a claude-code`. Or copy the skill folder (law-gdpr-pdpa in asgard-ai-platform/skills) into .claude/skills/law-gdpr-pdpa in your project. Claude Code loads it when a task matches its description.

How do I install Law Gdpr Pdpa in Codex?

Run `npx skills add asgard-ai-platform/skills --skill law-gdpr-pdpa -a codex`. Or copy the skill folder (law-gdpr-pdpa in asgard-ai-platform/skills) into .agents/skills/law-gdpr-pdpa in your project. Codex loads it when a task matches its description.

Can I use Law Gdpr Pdpa in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add asgard-ai-platform/skills --skill law-gdpr-pdpa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/law-gdpr-pdpa, .gemini/skills/law-gdpr-pdpa, .github/skills/law-gdpr-pdpa and .opencode/skills/law-gdpr-pdpa in your project.

What does Law Gdpr Pdpa need to run?

SKILL.md names no scripts, command-line tools or credentials: Law Gdpr Pdpa is instructions for the agent only.

Does Law Gdpr Pdpa access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Law Gdpr Pdpa safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Law Gdpr Pdpa use?

Law Gdpr Pdpa is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Law Gdpr Pdpa use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.3k tokens, read only when the agent opens those files.

What are the alternatives to Law Gdpr Pdpa?

Skills that share tags, products or a category with Law Gdpr Pdpa: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Law Gdpr Pdpa?

asgard-ai-platform (a GitHub organization) maintains it in asgard-ai-platform/skills, which has 242 GitHub stars. The repository holds 207 skills in this directory. The repository was last updated on June 6, 2026.

Source: asgard-ai-platform/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.