Agent skill

Dpia Assessment

by borghei in borghei/Claude-Skills

GDPR Art. An agent skill from borghei/Claude-Skills.

MITAuto-check passedLegal & Compliance

Install Dpia Assessment

skills CLI
$ npx skills add borghei/Claude-Skills --skill dpia-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills dpia-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/legal/dpia-assessment .claude/skills/dpia-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dpia-assessment
GitHub stars
886
Token cost
~4.1k tokens
SKILL.md length
1,397 words
Files
5 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

GDPR Art. An agent skill from borghei/Claude-Skills.

  • DPIA evaluations
  • SKILL.md covers Table of Contents, Clarify First, Tools and Reference Guides, plus 8 more sections
  • Runs Python scripts from its folder; calls python
  • Tasks that involve Privacy and GDPR

What it does

Dpia Assessment is an agent skill from borghei/Claude-Skills. GDPR Art. 35 Data Protection Impact Assessment with threshold checking, risk registers, and EDPB criteria scoring. Use for DPIA evaluations.

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/edpb_criteria.md`, `references/risk_scoring_methodology.md` and `scripts/dpia_risk_register.py`).

It sits in Legal & Compliance, covering Privacy and GDPR and Legal risk assessment. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • DPIA evaluations
  • Tasks that involve Privacy and GDPR
  • Tasks that involve Legal risk assessment

Example prompts

  • “/dpia-assessment”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dpia Assessment loads about 4.1k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 39 tokens; SKILL.md has 1,397 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 1,397 words, ~4,147 tokens.

Download SKILL.mdSave it as .claude/skills/dpia-assessment/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
dpia-assessment
description
GDPR Art. 35 Data Protection Impact Assessment with threshold checking, risk registers, and EDPB criteria scoring. Use for DPIA evaluations.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
The Glass Room
metadata.category
legal
metadata.domain
data-protection
metadata.updated
2026-04-10
metadata.tags
dpia, gdpr, data-protection, edpb, privacy-risk

⚠️ EXPERIMENTAL — This skill is provided for educational and informational purposes only. It does NOT constitute legal advice. All responsibility for usage rests with the user. Consult qualified legal professionals before acting on any output.

DPIA Assessment

GDPR Article 35 Data Protection Impact Assessment tooling. Evaluates whether a DPIA is required, manages risk registers with mitigation tracking, and generates documentation meeting supervisory authority expectations.


Table of Contents


Clarify First

Before the assessment, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Processing activity description — purpose, data types, automation level, scale — drives the Art. 35(3) trigger matches and EDPB criteria scoring (the whole verdict)
  • Special-category data + scale — determines the Art. 35(3)(b) trigger, the Art. 9 cumulative-basis requirement, and the large-scale four-factor test
  • Jurisdiction(s) — which national blacklists apply (DE/FR/IE/BE/NL/IT/PL); the most restrictive governs
  • Whether an AI system is involved — triggers dual-phase (training/inference) analysis per EDPB Opinion 28/2024 and the separate FRIA distinction

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the assessment.

Tools

DPIA Threshold Checker

Evaluates whether a DPIA is required based on processing activity description. Checks Art. 35(3) mandatory triggers and 9 EDPB criteria.

bash
# Check a processing activity (interactive prompts)
python scripts/dpia_threshold_checker.py --activity "AI-based credit scoring using financial and behavioral data of retail banking customers across EU"

# Check from JSON description
python scripts/dpia_threshold_checker.py --input processing.json

# JSON output
python scripts/dpia_threshold_checker.py --activity "Employee monitoring via CCTV in workplace" --json

# Generate blank input template
python scripts/dpia_threshold_checker.py --template > processing.json

Checks performed:

  • Art. 35(3)(a): Automated decision-making with legal/significant effect
  • Art. 35(3)(b): Large-scale processing of special category data (Art. 9) or criminal data (Art. 10)
  • Art. 35(3)(c): Systematic monitoring of publicly accessible area on large scale
  • 9 EDPB criteria from WP 248 rev.01 with two-criterion presumption rule

Output:

  • Verdict: Required / Recommended / Not Required
  • Art. 35(3) trigger matches
  • EDPB criteria scores with reasoning
  • Two-criterion presumption analysis

DPIA Risk Register

Manages a DPIA risk register in JSON format. Add risks, apply mitigations, and calculate residual risk.

bash
# Initialize a new risk register
python scripts/dpia_risk_register.py init --output dpia_risks.json

# Add a risk
python scripts/dpia_risk_register.py add --register dpia_risks.json \
  --description "Unauthorized access to profiling data" \
  --rights-category "right-to-privacy" \
  --likelihood 4 --severity 3

# Add mitigation to a risk
python scripts/dpia_risk_register.py mitigate --register dpia_risks.json \
  --risk-id 1 --measure "Implement role-based access control" \
  --likelihood-reduction 2 --severity-reduction 1

# View risk register table
python scripts/dpia_risk_register.py view --register dpia_risks.json

# Generate residual risk summary
python scripts/dpia_risk_register.py summary --register dpia_risks.json --json

# Check Art. 36 consultation threshold
python scripts/dpia_risk_register.py art36-check --register dpia_risks.json

Rights categories: right-to-privacy, non-discrimination, freedom-of-expression, right-to-information, right-to-not-be-subject-to-automated-decisions, right-to-physical-safety


Reference Guides

EDPB Criteria

references/edpb_criteria.md

Complete EDPB 9-criteria assessment framework:

  • Each criterion with description, indicators, and scoring guidance
  • Art. 35(3) mandatory triggers
  • Two-criterion presumption rule (WP 248 rev.01)
  • Multi-jurisdictional DPIA analysis
  • National blacklist/whitelist overview (DE, FR, IE, BE, NL, IT, PL)
Risk Scoring Methodology

references/risk_scoring_methodology.md

DPIA risk scoring from the data subject perspective:

  • Likelihood and severity scales (1-5)
  • Rights categories per Recital 75
  • Risk level thresholds (Low/Medium/High/Very High)
  • Mitigation effectiveness scoring
  • Residual risk calculation
  • Art. 36 consultation triggers
  • Risk catalog: 20+ common DPIA risks

Workflows

Workflow 1: Full DPIA Assessment
Step 1: Threshold check — determine if DPIA required
        → python scripts/dpia_threshold_checker.py --activity "description"

Step 2: If Required or Recommended, describe the processing
        → Document purpose, legal basis, data categories, recipients, retention

Step 3: Assess necessity and proportionality
        → Confirm lawful basis (Art. 6, cumulative with Art. 9 if special categories)
        → Verify purpose limitation, data minimization, storage limitation

Step 4: Identify risks from data subject perspective
        → python scripts/dpia_risk_register.py init --output dpia_risks.json
        → Add risks using references/risk_scoring_methodology.md catalog

Step 5: Apply mitigations and calculate residual risk
        → python scripts/dpia_risk_register.py mitigate --register dpia_risks.json ...

Step 6: Check Art. 36 consultation requirement
        → python scripts/dpia_risk_register.py art36-check --register dpia_risks.json

Step 7: Document and review
        → python scripts/dpia_risk_register.py summary --register dpia_risks.json
Workflow 2: Quick Threshold Assessment
Step 1: Describe the processing activity
        → python scripts/dpia_threshold_checker.py --template > processing.json
        → Fill in processing details

Step 2: Run threshold check
        → python scripts/dpia_threshold_checker.py --input processing.json --json

Step 3: Review verdict and reasoning
        → Required: proceed to full DPIA (Workflow 1)
        → Recommended: proceed unless strong justification to skip (document)
        → Not Required: document the assessment and rationale
Workflow 3: AI System DPIA
Step 1: Classify AI system (EU AI Act risk level if applicable)
        → Map to DPIA triggers (automated decision-making, profiling, scoring)

Step 2: Run threshold check with AI-specific indicators
        → python scripts/dpia_threshold_checker.py --activity "AI system description"

Step 3: Dual-phase risk analysis (EDPB Opinion 28/2024)
        → Phase 1: Training data risks (collection, bias, consent)
        → Phase 2: Inference risks (decisions, profiling, transparency)

Step 4: Assess from data subject perspective
        → Add risks covering both training and inference phases
        → Include algorithmic bias, lack of transparency, unfair outcomes

Step 5: Apply mitigations specific to AI
        → Explainability measures, human oversight, bias testing
        → Document FRIA distinction per EU AI Act Art. 27 if applicable

12 points of legal precision that distinguish expert-level DPIA work.

#PointDetail
1Art. 35(3) absolute triggersThree mandatory triggers require DPIA regardless of other analysis: (a) automated decisions with legal effect, (b) large-scale special category/criminal data, (c) systematic public area monitoring
2Two-criterion presumptionIf 2 or more of the 9 EDPB criteria are met, DPIA is presumptively required (WP 248 rev.01). Can rebut only with documented justification
3Art. 9 cumulative with Art. 6Special category data requires BOTH an Art. 6 lawful basis AND an Art. 9(2) exception. Neither alone is sufficient
4Large scale four-factor testAssess: (a) number of data subjects, (b) volume of data, (c) geographic extent, (d) duration/permanence. No fixed numeric threshold
5National blacklists additiveSA-published lists of processing operations requiring DPIA add to (not replace) Art. 35(3) and EDPB criteria
6Multi-jurisdictional checkingIf processing spans multiple member states, check each SA's blacklist. Most restrictive list applies
7Pre-processing obligationDPIA must be completed BEFORE processing begins (Art. 35(1)). Retroactive DPIAs do not satisfy the requirement
8AI dual-phase analysisEDPB Opinion 28/2024: AI systems require separate risk analysis for training phase and inference/deployment phase
9Art. 36 sequentialPrior consultation with SA (Art. 36) is triggered only AFTER DPIA is completed and residual risk remains high. Cannot skip the DPIA
10Pseudonymization nuanceEDPB Guidelines 01/2025: pseudonymization reduces risk but does not eliminate DPIA requirement. Still personal data
11Data subject perspectiveAll risks must be assessed from the data subject's perspective (Recital 75), not the controller's business perspective
12AI Act FRIA distinctionEU AI Act Art. 27 requires Fundamental Rights Impact Assessment (FRIA) for high-risk AI. FRIA is separate from GDPR DPIA — both may be required

Output Formats

Threshold Verdict
VERDICT: DPIA REQUIRED
Reason: Art. 35(3)(a) trigger matched (automated decision-making with legal effect)
        + 4 of 9 EDPB criteria met (two-criterion presumption applies)
Matched triggers: automated_decision_making, evaluation_scoring, sensitive_data, large_scale
Risk Register Table
IDDescriptionRights CategoryLSScoreLevelMitigationResidual LResidual SResidual ScoreResidual Level
1Unauthorized profilingRight to privacy4312HighRBAC + encryption224Low
2Discriminatory outcomesNon-discrimination3412HighBias testing + human review236Medium
Residual Risk Overview
Total risks: 8
Mitigated: 6 (75%)
Residual risk distribution:
  Low:       3 (37.5%)
  Medium:    3 (37.5%)
  High:      2 (25.0%)
  Very High: 0 (0.0%)

Art. 36 consultation: NOT TRIGGERED (no Very High residual risks)

Show full SKILL.md (627 more words)Show less

Troubleshooting

ProblemPossible CauseResolution
Threshold checker says "Not Required" but processing feels riskyActivity description too vague or missing key detailsProvide more specific description including data types, scale, automation level, and data subject categories
Two-criterion presumption triggered but controller disagreesController must document justification for rebutting presumptionDocument specific reasons why DPIA is not needed despite criteria match; SA may challenge this
Risk register shows High residual risk after mitigationsMitigations insufficient or not properly scoredReview mitigation effectiveness; consider additional controls; if residual risk remains high, Art. 36 consultation required
Multi-jurisdictional check produces conflicting resultsDifferent SAs have different blacklists and thresholdsApply the most restrictive requirement; document the analysis for each jurisdiction
AI system DPIA unclear on training vs. inference risksTraining and inference phases have different risk profilesSeparate the analysis per EDPB Opinion 28/2024; assess each phase independently then combine
Art. 36 check unclear on thresholdResidual risk near the boundary between High and Very HighDocument the borderline assessment; consider voluntary consultation as good practice

Success Criteria

  • All high-risk processing activities assessed -- threshold check completed before processing begins, with documented verdict and reasoning
  • Risk register complete with mitigations -- every identified risk has likelihood, severity, rights category, and at least one mitigation measure
  • Residual risk acceptable or Art. 36 consultation initiated -- no unaddressed Very High residual risks
  • Documentation meets SA expectations -- assessment follows Art. 35(7) requirements: systematic description, necessity/proportionality, risks, mitigations
  • EDPB criteria properly applied -- two-criterion presumption correctly evaluated with documented reasoning

Scope & Limitations

In Scope:

  • DPIA threshold assessment against Art. 35(3) triggers and EDPB criteria
  • Risk register management with mitigation tracking and residual risk calculation
  • Art. 36 prior consultation threshold assessment
  • Multi-jurisdictional blacklist awareness (DE, FR, IE, BE, NL, IT, PL)
  • AI system dual-phase DPIA analysis guidance
  • Data subject perspective risk assessment per Recital 75

Out of Scope:

  • Legal advice on lawful basis selection (Art. 6) or Art. 9(2) exception applicability
  • Supervisory authority submission or interaction
  • Technical implementation of mitigations (encryption, access control)
  • DPO appointment or consultation logistics
  • National blacklist exhaustive coverage beyond listed jurisdictions
  • EU AI Act conformity assessment (see eu-ai-act-specialist)

Anti-Patterns

  • Conducting DPIA after processing has started -- Art. 35(1) requires DPIA before processing begins; retroactive DPIAs do not satisfy the legal obligation and create enforcement exposure
  • Assessing risk from the controller's perspective -- DPIA risks must be evaluated from the data subject's perspective per Recital 75; business impact is irrelevant to this analysis; a breach that is minor for the company may be catastrophic for affected individuals
  • Treating pseudonymization as eliminating DPIA need -- pseudonymized data remains personal data under GDPR (Recital 26); pseudonymization is a mitigation that reduces risk scores, not a basis for skipping the DPIA entirely
  • Skipping Art. 36 consultation when residual risk is high -- if residual risk remains Very High after mitigations, prior consultation with the supervisory authority is mandatory, not optional
  • Conflating DPIA with FRIA -- the EU AI Act's Fundamental Rights Impact Assessment (Art. 27) is a separate obligation from GDPR DPIA; completing one does not satisfy the other; both may be required for AI systems processing personal data

Tool Reference

dpia_threshold_checker.py

Evaluates whether a DPIA is required based on Art. 35(3) triggers and EDPB criteria.

FlagRequiredDescription
--activity <text>Yes (unless --input or --template)Processing activity description
--input <file>Yes (unless --activity)Path to JSON processing description
--templateNoGenerate blank input template
--jsonNoOutput in JSON format
dpia_risk_register.py

Manages DPIA risk register with mitigation tracking and residual risk calculation.

SubcommandDescription
initCreate new empty risk register (--output required)
addAdd risk (--register, --description, --rights-category, --likelihood, --severity required)
mitigateAdd mitigation (--register, --risk-id, --measure, --likelihood-reduction, --severity-reduction required)
viewDisplay risk register table (--register required)
summaryGenerate summary with distribution (--register required, --json optional)
art36-checkCheck Art. 36 consultation requirement (--register required)

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in legal/dpia-assessment of borghei/Claude-Skills.

  • SKILL.md
  • references/edpb_criteria.md
  • references/risk_scoring_methodology.md
  • scripts/dpia_risk_register.py
  • scripts/dpia_threshold_checker.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Dpia Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dpia Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dpia Assessment this skillborghei/Claude-Skills886—~4.1kAutomated safety check: PassMIT
Legal Compliancetravisjneuman/.claude101—~3.4kAutomated safety check: PassMIT
Dpia Risk Scoringmukul975/Privacy-Data-Protection-Skills297—~1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0

Similar skills

  • Legal Compliance

    travisjneuman/.claude

    Legal and compliance expertise for corporate governance, contract analysis, regulatory compliance (SOX, GDPR, HIPAA), risk assessment, intellectual property, and litigation management.

    101 GitHub stars~3.4k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Dpia Risk Scoring

    mukul975/Privacy-Data-Protection-Skills

    Provides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134.

    297 GitHub stars~1k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    886 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    886 GitHub stars~4.2k tokensUpdated 2 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    886 GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    886 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Dpia Assessment

What does Dpia Assessment do?

GDPR Art. An agent skill from borghei/Claude-Skills. Dpia Assessment is an agent skill from borghei/Claude-Skills. GDPR Art.

When should I use Dpia Assessment?

Dpia Assessment fits situations like: DPIA evaluations; tasks that involve Privacy and GDPR; tasks that involve Legal risk assessment.

How do I install Dpia Assessment in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill dpia-assessment -a claude-code`. Or copy the skill folder (legal/dpia-assessment in borghei/Claude-Skills) into .claude/skills/dpia-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Dpia Assessment in Codex?

Run `npx skills add borghei/Claude-Skills --skill dpia-assessment -a codex`. Or copy the skill folder (legal/dpia-assessment in borghei/Claude-Skills) into .agents/skills/dpia-assessment in your project. Codex loads it when a task matches its description.

Can I use Dpia Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill dpia-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dpia-assessment, .gemini/skills/dpia-assessment, .github/skills/dpia-assessment and .opencode/skills/dpia-assessment in your project.

What does Dpia Assessment need to run?

Going by SKILL.md and its folder, Dpia Assessment needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Dpia Assessment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dpia Assessment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dpia Assessment use?

Dpia Assessment is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dpia Assessment use?

About 4.1k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.1k tokens, read only when the agent opens those files.

What are the alternatives to Dpia Assessment?

Skills that share tags, products or a category with Dpia Assessment: Legal Compliance (travisjneuman/.claude, 101 stars), Dpia Risk Scoring (mukul975/Privacy-Data-Protection-Skills, 297 stars), C15t (c15t/c15t, 1.9k stars) and HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dpia Assessment?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 886 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.