Agent skill

Ccpa Cpra Privacy Expert

by borghei in borghei/Claude-Skills

CCPA and CPRA California privacy compliance. An agent skill from borghei/Claude-Skills.

MITAuto-check passedLegal & Compliance

Install Ccpa Cpra Privacy Expert

skills CLI
$ npx skills add borghei/Claude-Skills --skill ccpa-cpra-privacy-expert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills ccpa-cpra-privacy-expert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/ccpa-cpra-privacy-expert .claude/skills/ccpa-cpra-privacy-expert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ccpa-cpra-privacy-expert
GitHub stars
891
Token cost
~5.7k tokens
SKILL.md length
2,137 words
Files
5 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

CCPA and CPRA California privacy compliance. An agent skill from borghei/Claude-Skills.

  • CCPA/CPRA readiness assessments
  • SKILL.md covers Table of Contents, Tools, Reference Guides and Clarify First, plus 7 more sections
  • Runs Python scripts from its folder; calls python
  • Personal information data mapping

What it does

Ccpa Cpra Privacy Expert is an agent skill from borghei/Claude-Skills. CCPA and CPRA California privacy compliance. Use for CCPA/CPRA readiness assessments, personal information data mapping, consumer rights handling, privacy policy review, opt-out mechanisms, and California privacy audits.

Its SKILL.md is about 5.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/ccpa-cpra-requirements-guide.md`, `references/ccpa-implementation-playbook.md` and `scripts/ccpa_compliance_checker.py`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • CCPA/CPRA readiness assessments
  • Personal information data mapping
  • Consumer rights handling
  • Privacy policy review

Example prompts

  • “/ccpa-cpra-privacy-expert”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ccpa Cpra Privacy Expert loads about 5.7k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 2,137 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~5.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 2,137 words, ~5,722 tokens.

Download SKILL.mdSave it as .claude/skills/ccpa-cpra-privacy-expert/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
ccpa-cpra-privacy-expert
description
CCPA and CPRA California privacy compliance. Use for CCPA/CPRA readiness assessments, personal information data mapping, consumer rights handling, privacy policy review, opt-out mechanisms, and California privacy audits.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
privacy-compliance
metadata.updated
2026-03-31
metadata.tags
ccpa, cpra, california-privacy, data-mapping, opt-out

CCPA/CPRA Privacy Expert

Tools and guidance for California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance.


Table of Contents


Tools

CCPA Compliance Checker

Evaluates organizational readiness against all CCPA/CPRA requirements. Validates privacy policies, consumer rights handling, technical safeguards, and opt-out mechanisms.

bash
# Check compliance from a JSON profile
python scripts/ccpa_compliance_checker.py --input company_profile.json

# Generate a blank input template
python scripts/ccpa_compliance_checker.py --template > company_profile.json

# JSON output for automation
python scripts/ccpa_compliance_checker.py --input company_profile.json --json

# Export report to file
python scripts/ccpa_compliance_checker.py --input company_profile.json --output report.json

Assessment Categories:

CategoryKey Checks
ApplicabilityRevenue threshold, consumer count, data selling revenue
Privacy PolicyRequired disclosures, update cadence, accessibility
Consumer RightsRequest handling, verification, timelines
Opt-Out Mechanisms"Do Not Sell" link, GPC signal, cookie consent
Sensitive PISPI categories, use limitation link, handling controls
Technical SafeguardsEncryption, access controls, security measures
Service ProvidersAgreement requirements, data processing terms
Risk AssessmentsAnnual audits, processing risk evaluations

Output:

  • Overall compliance score (0-100)
  • Per-category scores with pass/fail/partial status
  • Prioritized findings with regulatory references
  • Remediation recommendations

CCPA Data Mapper

Maps personal information categories, identifies sensitive personal information, tracks data flows across collection, use, sharing, and selling. Generates data inventory reports.

bash
# Map data from a JSON data inventory
python scripts/ccpa_data_mapper.py --input data_inventory.json

# Generate a blank inventory template
python scripts/ccpa_data_mapper.py --template > data_inventory.json

# Export mapping report
python scripts/ccpa_data_mapper.py --input data_inventory.json --output mapping_report.json

# Generate data flow diagram (text-based)
python scripts/ccpa_data_mapper.py --input data_inventory.json --flow-diagram

Features:

  • Maps all 11 CCPA personal information categories
  • Identifies sensitive personal information (SPI) per CPRA definitions
  • Tracks data flows: collection sources, business purposes, sharing/selling recipients
  • Maps data to service providers, contractors, and third parties
  • Generates CCPA-compliant data inventory for privacy policy disclosures
  • Flags cross-border data transfers
  • Detects data retention gaps

Personal Information Categories Tracked:

CategoryCCPA SectionExamples
Identifiers1798.140(v)(1)(A)Name, SSN, IP address, email
Customer Records1798.140(v)(1)(B)Financial info, medical info
Protected Classifications1798.140(v)(1)(C)Race, sex, age, disability
Commercial Information1798.140(v)(1)(D)Purchase history, tendencies
Biometric Information1798.140(v)(1)(E)Fingerprints, face geometry
Internet Activity1798.140(v)(1)(F)Browsing, search, interaction
Geolocation Data1798.140(v)(1)(G)Precise location
Sensory Data1798.140(v)(1)(H)Audio, visual, thermal
Professional Info1798.140(v)(1)(I)Employment, education
Education Info1798.140(v)(1)(J)Non-public education records
Inferences1798.140(v)(1)(K)Profiles, preferences

Reference Guides

CCPA/CPRA Requirements Guide

references/ccpa-cpra-requirements-guide.md

Complete regulatory requirements covering:

  • Full CCPA/CPRA text analysis with section references
  • Consumer rights implementation guidance (Right to Know, Delete, Opt-Out, Correct, Portability, Limit SPI Use)
  • Privacy policy content requirements and templates
  • Service provider and contractor agreement requirements
  • Comparison with Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and GDPR
  • Enforcement and penalty structure
CCPA Implementation Playbook

references/ccpa-implementation-playbook.md

Step-by-step implementation guidance:

  • 6-month implementation roadmap
  • Data mapping methodology and templates
  • Privacy policy drafting guide
  • Opt-out mechanism implementation (website, GPC, universal opt-out)
  • Consumer request workflow design with SLA tracking
  • Employee and vendor training program outline
  • Annual cybersecurity audit planning
  • Ongoing compliance monitoring

Clarify First

Before running the assessment, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Applicability — whether the business meets a CCPA threshold ($25M revenue, 100K+ consumers/households, or 50%+ revenue from selling/sharing PI) (determines whether obligations apply at all)
  • Entity role — business, service provider, contractor, or third party (determines which obligation set applies)
  • Assessment goal — compliance readiness, data mapping, consumer-request handling, or privacy-policy review (selects the tool and workflow)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the assessment.

Workflows

Workflow 1: Initial CCPA/CPRA Compliance Assessment
Step 1: Determine applicability
        → Check $25M revenue, 100K+ consumers, 50%+ PI revenue thresholds
        → Review exemptions (HIPAA, GLBA, employment data)

Step 2: Generate compliance profile template
        → python scripts/ccpa_compliance_checker.py --template > profile.json
        → Fill in organizational details

Step 3: Run compliance assessment
        → python scripts/ccpa_compliance_checker.py --input profile.json

Step 4: Review scores and findings
        → Address critical gaps first (opt-out link, privacy policy)
        → Plan remediation by category

Step 5: Create data inventory
        → python scripts/ccpa_data_mapper.py --template > inventory.json
        → Document all PI categories collected
        → python scripts/ccpa_data_mapper.py --input inventory.json

Step 6: Develop implementation plan
        → See references/ccpa-implementation-playbook.md
Workflow 2: Consumer Rights Request Handling
Step 1: Receive consumer request
        → Identify request type (Know, Delete, Opt-Out, Correct, Portability, Limit SPI)

Step 2: Acknowledge within 10 business days (confirm receipt)
        → Document request in tracking system

Step 3: Verify consumer identity
        → Match 2+ data points for standard requests
        → Match 3+ data points for sensitive data requests
        → No verification needed for opt-out requests

Step 4: Fulfill request within 45 calendar days
        → Extension: up to 45 additional days with notice
        → Search all systems using data inventory
        → python scripts/ccpa_data_mapper.py --input inventory.json

Step 5: Deliver response
        → Provide information in portable format if requested
        → Document completion and response

Step 6: Monitor compliance
        → Track response times and completion rates
        → Generate quarterly compliance reports
Workflow 3: Privacy Policy Update Cycle
Step 1: Review current privacy policy against requirements
        → python scripts/ccpa_compliance_checker.py --input profile.json
        → Check privacy_policy category score

Step 2: Update data inventory
        → python scripts/ccpa_data_mapper.py --input inventory.json
        → Verify all PI categories are disclosed

Step 3: Verify required disclosures
        → Categories of PI collected (past 12 months)
        → Sources of PI
        → Business/commercial purposes
        → Categories of third parties
        → Consumer rights description
        → "Do Not Sell or Share" link
        → "Limit the Use of My Sensitive PI" link

Step 4: Update and publish
        → Annual update at minimum
        → Update within 30 days of material changes
        → Maintain prior version archive

Regulatory Overview

CCPA/CPRA Timeline
DateMilestone
Jan 1, 2020CCPA effective
Jul 1, 2020AG enforcement begins
Nov 3, 2020CPRA passed (Proposition 24)
Jan 1, 2023CPRA amendments effective
Jul 1, 2023CPPA enforcement of CPRA begins
2026Employment and B2B data exemptions status review
Scope and Applicability

A business is subject to CCPA/CPRA if it:

  • Has annual gross revenue exceeding $25 million
  • Buys, sells, or shares PI of 100,000+ consumers or households annually
  • Derives 50% or more of annual revenue from selling or sharing consumers' PI

Entity Types:

EntityDefinitionObligations
BusinessDetermines purposes and means of processingFull CCPA/CPRA compliance
Service ProviderProcesses PI on behalf of a business (contractual)Limited use, deletion obligations
ContractorProcesses PI via written contract (CPRA addition)Certification, limited use, audit rights
Third PartyReceives PI not as service provider/contractorSubject to opt-out rights

Exemptions:

  • HIPAA-covered entities: Health data governed by HIPAA exempt
  • GLBA: Financial data subject to GLBA exempt
  • Employment data: Employee/applicant PI (subject to review through 2026)
  • B2B data: Business contact PI in B2B transactions (subject to review through 2026)
  • FCRA: Data subject to Fair Credit Reporting Act
Consumer Rights
RightCCPA SectionDescriptionTimeline
Right to Know§1798.100, §1798.110Categories and specific pieces of PI collected45 days
Right to Delete§1798.105Delete PI collected from the consumer45 days
Right to Opt-Out§1798.120Opt out of sale or sharing of PIImmediate
Right to Non-Discrimination§1798.125No retaliation for exercising rightsOngoing
Right to Correct§1798.106Correct inaccurate PI (CPRA)45 days
Right to Limit SPI Use§1798.121Limit use of sensitive PI (CPRA)Immediate
Right to Data Portability§1798.130Receive PI in portable format (CPRA)45 days
Sensitive Personal Information (CPRA)

SPI categories requiring enhanced protections under CPRA §1798.140(ae):

  • Social Security number, driver's license, state ID, passport number
  • Account log-in credentials (username + password/security question)
  • Financial account number with access credentials
  • Precise geolocation (within 1,850 feet / radius)
  • Racial or ethnic origin
  • Religious or philosophical beliefs
  • Union membership
  • Contents of mail, email, and text messages (unless business is intended recipient)
  • Genetic data
  • Biometric data for identification
  • Health information
  • Sex life or sexual orientation data
Enforcement and Penalties
Violation TypePenaltyEnforcer
Unintentional violation$2,500 per violationCPPA / AG
Intentional violation$7,500 per violationCPPA / AG
Violations involving minors (under 16)$7,500 per violationCPPA / AG
Data breach (private action)$100-$750 per consumer per incidentConsumer (court)

Enforcement Bodies:

  • California Privacy Protection Agency (CPPA): Primary enforcer under CPRA (operational 2023)
  • California Attorney General: Retains enforcement authority
  • Private right of action: Limited to data breaches from failure to maintain reasonable security
CCPA vs GDPR Comparison
AspectCCPA/CPRAGDPR
ScopeCalifornia consumersEU/EEA data subjects
Legal basisOpt-out modelOpt-in (consent or legal basis)
Data coveredPersonal informationPersonal data
Sensitive dataSPI with limit-use rightSpecial category with explicit consent
Breach notificationAG notification, private action72-hour DPA notification
DPO requirementNoneRequired for certain processing
Penalties$2,500-$7,500 per violationUp to 4% global revenue or €20M
Private right of actionData breaches onlyVaries by member state
Cross-border transfersNo restrictionsAdequacy decisions, SCCs, BCRs
Children's dataOpt-in for under 16, parental for under 13Parental consent for under 16 (variable)
Infrastructure Privacy Controls

Cookie Consent Management:

  • Implement cookie consent banner for non-essential cookies
  • Honor Global Privacy Control (GPC) browser signals (legally required)
  • Maintain cookie inventory with retention periods
  • Categorize cookies: strictly necessary, functional, analytics, advertising

Global Privacy Control (GPC):

  • Businesses must treat GPC signal as valid opt-out request (§1798.135)
  • Technical implementation: detect Sec-GPC: 1 header or navigator.globalPrivacyControl
  • Apply opt-out to sale AND sharing of PI
  • No re-authentication required for GPC

Privacy by Design:

  • Data minimization: collect only PI necessary for disclosed purposes
  • Purpose limitation: use PI only for purposes disclosed at collection
  • Storage limitation: retain PI only as long as necessary
  • Security by default: encrypt PI at rest and in transit

Data Inventory and Mapping:

  • Maintain comprehensive PI inventory across all systems
  • Map data flows: collection → processing → sharing → deletion
  • Document retention schedules per PI category
  • Track cross-border data transfers

Automated Decision-Making:

  • Disclose use of automated decision-making technology
  • Provide opt-out for profiling that produces legal or significant effects
  • CPRA regulations may require access to logic of automated decisions
Compliance Roadmap

Month 1-2: Discovery and Assessment

  • Determine CCPA/CPRA applicability
  • Conduct data inventory and mapping
  • Gap analysis against requirements
  • Assign compliance ownership

Month 3-4: Implementation

  • Draft/update privacy policy
  • Implement "Do Not Sell or Share" link
  • Implement "Limit Use of SPI" link
  • Deploy GPC signal detection
  • Build consumer request intake and fulfillment workflows
  • Draft service provider/contractor agreements

Month 5-6: Operationalization

  • Train employees on privacy obligations
  • Test consumer request workflows end-to-end
  • Conduct initial risk assessment
  • Plan annual cybersecurity audit
  • Establish ongoing monitoring and metrics
  • Document compliance program for regulatory defense

Show full SKILL.md (841 more words)Show less

Troubleshooting

ProblemPossible CauseResolution
Compliance score unexpectedly low despite privacy policy updatesPolicy disclosures incomplete -- missing SPI categories, retention periods, or sale/sharing categoriesRun ccpa_compliance_checker.py --input profile.json and review per-category scores; cross-reference privacy policy against the 17+ required disclosure elements
Data mapper flags cross-border transfers but organization operates only in USData inventory includes cloud services with non-US processing locationsReview data inventory entries for cloud provider data processing locations; document all sub-processor locations per service provider agreements
Consumer rights requests consistently exceed 45-day response deadlineManual fulfillment process without tracking system or unclear ownershipImplement ccpa_data_mapper.py to map PI across all systems; deploy request tracking with automated deadline alerts; assign per-system data stewards
GPC signal detection not workingApplication does not check Sec-GPC: 1 header or navigator.globalPrivacyControlImplement server-side header detection and client-side JavaScript check; test with browsers that support GPC (Firefox, Brave); log detection events
CPPA enforcement inquiry receivedPotential compliance gap discovered during regulatory sweep or consumer complaintImmediately run full compliance assessment; prioritize critical gaps (opt-out link, GPC, privacy policy); engage privacy counsel; document remediation timeline
Vendor contracts missing CCPA-required provisionsService provider agreements predate CPRA amendmentsAudit all vendor agreements against CCPA service provider/contractor requirements; update contracts to include certification, limited use, audit rights, and data deletion obligations
Risk assessment requirements unclearNew CPRA regulations (effective January 1, 2026) mandate risk assessments for six processing categoriesReview processing activities against the six "significant risk" categories; document risk assessments per CPPA regulatory template; plan for April 2028 attestation deadline

Success Criteria

  • Overall compliance score of 80+ on initial assessment -- indicating foundational CCPA/CPRA controls are in place, with per-category scores identifying targeted remediation areas
  • All consumer rights requests fulfilled within 45 calendar days -- with 10-business-day acknowledgment, tracked through a request management system with automated deadline alerts
  • Privacy policy updated at least annually -- with documented reviews quarterly, disclosing all 11 PI categories collected, sources, purposes, third-party sharing, and all seven consumer rights
  • GPC signal honored automatically -- detected via Sec-GPC: 1 header and navigator.globalPrivacyControl, applied to both sale and sharing of PI, with no re-authentication required
  • Complete data inventory maintained -- all PI categories mapped to collection sources, business purposes, sharing recipients, and retention schedules using ccpa_data_mapper.py
  • Service provider and contractor agreements include all CCPA-required provisions -- including certification of limited use, deletion obligations, audit rights, and sub-contractor chain documentation
  • Risk assessments completed for all applicable processing activities -- covering the six CPRA significant-risk categories, with attestation readiness by the April 2028 deadline

Scope & Limitations

In Scope:

  • CCPA/CPRA applicability determination (revenue, consumer count, PI revenue thresholds)
  • Privacy policy compliance assessment against all required disclosures
  • Consumer rights readiness validation (Know, Delete, Opt-Out, Correct, Portability, Limit SPI Use)
  • Data inventory mapping across all 11 CCPA personal information categories
  • Sensitive personal information identification per CPRA definitions
  • Technical safeguard assessment (encryption, access controls, opt-out mechanisms)
  • Service provider and contractor agreement requirements

Out of Scope:

  • Legal advice or determination of exemption applicability (HIPAA, GLBA, FCRA, employment data) -- consult privacy counsel for exemption analysis
  • Implementation of cookie consent management platforms or GPC signal handling code
  • CCPA private right of action defense (data breach litigation) -- consult legal counsel
  • Other state privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA) beyond the comparison tables provided -- use jurisdiction-specific guidance
  • Automated decision-making technology (ADMT) compliance under CPRA regulations effective January 2027 -- monitor CPPA rulemaking for final requirements

Important Notes:

  • CPPA enforcement is escalating significantly in 2025-2026, with fines exceeding $1.3M in individual cases and joint multi-state enforcement sweeps targeting GPC non-compliance
  • New CPRA regulations effective January 1, 2026 add risk assessment, cybersecurity audit, and updated compliance requirements -- plan implementation accordingly

Integration Points

SkillIntegrationWhen to Use
gdpr-dsgvo-expertUnified privacy program satisfying both GDPR and CCPA; cross-framework privacy mappingWhen organization operates in both EU and California markets
infrastructure-compliance-auditorTechnical safeguard validation (encryption, access controls, logging) for CCPA reasonable securityWhen assessing infrastructure controls supporting CCPA compliance
information-security-manager-iso27001Security controls supporting CCPA "reasonable security" requirementWhen building security program that satisfies both ISO 27001 and CCPA
soc2-compliance-expertSOC 2 controls mapped to CCPA technical safeguard requirementsWhen SOC 2 audit evidence supports CCPA security compliance

Tool Reference

ccpa_compliance_checker.py

Evaluates organizational readiness against all CCPA/CPRA requirements across 8 assessment categories.

FlagRequiredDescription
--input <file>Yes (unless --template)Path to JSON company profile for assessment
--templateNoGenerate blank input template to stdout
--jsonNoOutput results in JSON format for automation
--output <file>NoExport report to specified file path

Output: Overall compliance score (0-100), per-category scores with pass/fail/partial status, prioritized findings with regulatory references, and remediation recommendations.

ccpa_data_mapper.py

Maps personal information categories, tracks data flows, and generates data inventory reports.

FlagRequiredDescription
--input <file>Yes (unless --template)Path to JSON data inventory for mapping
--templateNoGenerate blank inventory template to stdout
--output <file>NoExport mapping report to specified file path
--flow-diagramNoGenerate text-based data flow diagram showing collection, use, sharing, and selling paths

Output: PI category mapping across all 11 CCPA categories, SPI identification, data flow analysis (sources, purposes, recipients), cross-border transfer flags, and data retention gap detection.

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in ra-qm-team/ccpa-cpra-privacy-expert of borghei/Claude-Skills.

  • SKILL.md
  • references/ccpa-cpra-requirements-guide.md
  • references/ccpa-implementation-playbook.md
  • scripts/ccpa_compliance_checker.py
  • scripts/ccpa_data_mapper.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Ccpa Cpra Privacy Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ccpa Cpra Privacy Expert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ccpa Cpra Privacy Expert this skillborghei/Claude-Skills891—~5.7kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    891 GitHub stars~3.1k tokensUpdated 4 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    891 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    891 GitHub stars~3.4k tokensUpdated 4 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    891 GitHub stars~3.6k tokensUpdated 4 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    891 GitHub stars~3.4k tokensUpdated 4 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    891 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check passed

Questions about Ccpa Cpra Privacy Expert

What does Ccpa Cpra Privacy Expert do?

CCPA and CPRA California privacy compliance. An agent skill from borghei/Claude-Skills. Ccpa Cpra Privacy Expert is an agent skill from borghei/Claude-Skills. CCPA and CPRA California privacy compliance.

When should I use Ccpa Cpra Privacy Expert?

Ccpa Cpra Privacy Expert fits situations like: CCPA/CPRA readiness assessments; personal information data mapping; consumer rights handling; privacy policy review.

How do I install Ccpa Cpra Privacy Expert in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill ccpa-cpra-privacy-expert -a claude-code`. Or copy the skill folder (ra-qm-team/ccpa-cpra-privacy-expert in borghei/Claude-Skills) into .claude/skills/ccpa-cpra-privacy-expert in your project. Claude Code loads it when a task matches its description.

How do I install Ccpa Cpra Privacy Expert in Codex?

Run `npx skills add borghei/Claude-Skills --skill ccpa-cpra-privacy-expert -a codex`. Or copy the skill folder (ra-qm-team/ccpa-cpra-privacy-expert in borghei/Claude-Skills) into .agents/skills/ccpa-cpra-privacy-expert in your project. Codex loads it when a task matches its description.

Can I use Ccpa Cpra Privacy Expert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill ccpa-cpra-privacy-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ccpa-cpra-privacy-expert, .gemini/skills/ccpa-cpra-privacy-expert, .github/skills/ccpa-cpra-privacy-expert and .opencode/skills/ccpa-cpra-privacy-expert in your project.

What does Ccpa Cpra Privacy Expert need to run?

Going by SKILL.md and its folder, Ccpa Cpra Privacy Expert needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Ccpa Cpra Privacy Expert access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ccpa Cpra Privacy Expert safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ccpa Cpra Privacy Expert use?

Ccpa Cpra Privacy Expert is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ccpa Cpra Privacy Expert use?

About 5.7k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.6k tokens, read only when the agent opens those files.

What are the alternatives to Ccpa Cpra Privacy Expert?

Skills that share tags, products or a category with Ccpa Cpra Privacy Expert: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ccpa Cpra Privacy Expert?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 891 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.