Agent skill

Gdpr Audit Prep

by borghei in borghei/Claude-Skills

GDPR audit-prep playbook: sprint to prepare for a supervisory authority inquiry, DPA audit, or internal review.

MITAuto-check passedLegal & Compliance

Install Gdpr Audit Prep

skills CLI
$ npx skills add borghei/Claude-Skills --skill gdpr-audit-prep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills gdpr-audit-prep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/audit-prep/gdpr-audit-prep .claude/skills/gdpr-audit-prep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gdpr-audit-prep
GitHub stars
881
Token cost
~1.8k tokens
SKILL.md length
650 words
Files
5 (incl. scripts, references)
Skills in repo
349
Repo updated
First seen
Licence
MIT

At a glance

GDPR audit-prep playbook: sprint to prepare for a supervisory authority inquiry, DPA audit, or internal review.

  • Works in 8 steps: ROPA (Records of Processing Activities,… → Privacy Notices (Article 13/14) → Data Subject Rights (Article 12-23) → …
  • An audit is scheduled
  • SKILL.md covers When to use this skill, The audit-prep sprint at a…, Critical GDPR audit areas and Clarify First, plus 5 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Gdpr Audit Prep is an agent skill from borghei/Claude-Skills. GDPR audit-prep playbook: sprint to prepare for a supervisory authority inquiry, DPA audit, or internal review. Use when an audit is scheduled, when readiness gaps surface, or when ROPA (Records of Processing Activities) needs completion.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/dpo-engagement-playbook.md`, `references/gdpr-pre-audit-checklist.md` and `scripts/gdpr_readiness_score.py`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • An audit is scheduled
  • Readiness gaps surface
  • ROPA (Records of Processing Activities) needs completion

Example prompts

  • “/gdpr-audit-prep”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. ROPA (Records of Processing Activities, Article 30)
  2. Privacy Notices (Article 13/14)
  3. Data Subject Rights (Article 12-23)
  4. Data Protection Impact Assessments (DPIAs, Article 35)
  5. Data Processing Agreements (Article 28)
  6. Security Measures (Article 32)
  7. Breach Notification (Article 33/34)
  8. International Transfers (Chapter V)

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gdpr Audit Prep loads about 1.8k tokens when it runs, and up to ~6.7k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 650 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 650 words, ~1,761 tokens.

Download SKILL.mdSave it as .claude/skills/gdpr-audit-prep/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
gdpr-audit-prep
description
GDPR audit-prep playbook: sprint to prepare for a supervisory authority inquiry, DPA audit, or internal review. Use when an audit is scheduled, when readiness gaps surface, or when ROPA (Records of Processing Activities) needs completion.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
ra-qm-team
metadata.updated
2026-05-27
metadata.tags
gdpr, audit-prep, ropa, dpia, data-protection, dpo-engagement, eu-privacy

GDPR Audit Prep

Operational playbook for GDPR audit preparation — whether triggered by a Data Protection Authority (DPA) inquiry, customer-side DPA review, internal compliance audit, or annual self-assessment.

When to use this skill vs. gdpr-dsgvo-expert:

  • This skill: audit imminent (4-12 weeks); need execution sprint
  • gdpr-dsgvo-expert: building GDPR program; designing DPIA process; multi-quarter

When to use this skill

SituationSkill applies
Supervisory authority inquiry receivedYes — start immediately; engage DPO
Customer DPA audit / questionnaireYes — scripts/gdpr_readiness_score.py first
Annual internal GDPR auditYes — standard sprint
ROPA needs rapid updateYes — scripts/ropa_completeness_checker.py
New high-risk processing → DPIA neededUse ra-qm-team/gdpr-dsgvo-expert for DPIA design

The audit-prep sprint at a glance

4-week sprint (well-prepared org, periodic review)
Week 1: ROPA review + DPO engagement plan
Week 2: Gap remediation (policies, notices, technical)
Week 3: Evidence compilation + walkthroughs
Week 4: Audit week / submission
8-week sprint (gaps remaining)
Weeks 1-2: ROPA update + gap identification
Weeks 3-5: Gap closure (DPAs, notices, security, retention)
Weeks 6-7: Evidence + walkthroughs
Week 8: Audit
12-week sprint (DPA inquiry response)
Weeks 1-2: Inquiry analysis + response strategy + DPO engagement
Weeks 3-8: Targeted evidence collection + remediation
Weeks 9-10: Formal response drafting + legal review
Weeks 11-12: Submission + ongoing dialogue

See references/gdpr-pre-audit-checklist.md for the full pre-audit punch list and references/dpo-engagement-playbook.md for DPO-coordinated audit response.


Critical GDPR audit areas

1. ROPA (Records of Processing Activities, Article 30)

Every processing activity documented:

  • Purpose of processing
  • Categories of data subjects + data types
  • Recipients (internal + external)
  • International transfers (and lawful basis)
  • Retention periods
  • Security measures
  • Lawful basis (consent, contract, legitimate interest, etc.)
  • DPIA reference (if high-risk)

Audit gap: ROPA incomplete, stale, or missing for processing activities surfaced during audit.

2. Privacy Notices (Article 13/14)
  • Privacy notice published + current
  • Contains all required information (data controller, purposes, lawful basis, retention, rights, complaints contact, etc.)
  • Easily accessible (no dark patterns)
  • Translated for EU member states (where required)
3. Data Subject Rights (Article 12-23)
  • Process documented + tested
  • Response time tracked (< 1 month standard; extension possible)
  • Identity verification
  • Records of requests and responses (last 12 months)
4. Data Protection Impact Assessments (DPIAs, Article 35)
  • High-risk processing activities identified
  • DPIA conducted for each
  • Mitigations documented
  • DPO consulted (Article 35.2)
5. Data Processing Agreements (Article 28)
  • DPA with every processor (vendor, sub-service org)
  • Covers required clauses (Article 28.3)
  • Annual review
6. Security Measures (Article 32)
  • Technical and organizational measures documented
  • Risk-appropriate (encryption, access control, backup, etc.)
  • Tested and reviewed
7. Breach Notification (Article 33/34)
  • Process documented
  • 72-hour authority notification capability
  • Past-period breaches: notified appropriately + documented
8. International Transfers (Chapter V)
  • Mechanism for each transfer (SCCs, BCRs, adequacy decision)
  • Transfer Impact Assessment (TIA) for non-adequacy countries
  • Schrems II compliance for US transfers

Show full SKILL.md (291 more words)Show less

Clarify First

Before running the audit-prep, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Audit trigger — supervisory-authority inquiry, customer DPA audit, internal audit, or annual self-assessment (sets the 4/8/12-week sprint and whether formal response drafting is needed)
  • Org readiness — well-prepared vs gaps remaining (picks the 4-week vs 8-week sprint)
  • Processing scope and role — controller vs processor, and which activities/ROPA are in scope (drives the ROPA and DPA focus)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the readiness assessment.

Quick start

  1. Run readiness score: python3 scripts/gdpr_readiness_score.py --config gdpr-controls.yaml
  2. Check ROPA completeness: python3 scripts/ropa_completeness_checker.py --ropa ropa.yaml
  3. Engage DPO: Walk through findings with DPO; finalize sprint scope
  4. Execute sprint per references/gdpr-pre-audit-checklist.md

Common GDPR audit failures

  • ROPA missing or out-of-date. Often the first thing an auditor asks.
  • Privacy notice generic — boilerplate not actually reflecting actual processing.
  • DPIA missing for high-risk processing (AI / profiling / large-scale monitoring / sensitive data).
  • DPAs not signed with all processors — easy oversight; substantial finding.
  • International transfer mechanism unclear post-Schrems II.
  • Breach notification process untested — first breach is the test.
  • Consent not freely given — bundled consent, pre-ticked boxes, take-it-or-leave-it.
  • No DPO appointed when required (Article 37 — public authority, large-scale monitoring, etc.).
  • Data subject rights process untested — request comes in, no one knows what to do.

Tooling

ScriptPurpose
scripts/gdpr_readiness_score.pyScore current state per GDPR area; identify gaps
scripts/ropa_completeness_checker.pyValidate ROPA structure and completeness per Article 30

References


  • ra-qm-team/gdpr-dsgvo-expert — deep GDPR program management
  • ra-qm-team/audit-prep/compliance-readiness — multi-framework readiness (GDPR + ISO 27001 + SOC 2)
  • ra-qm-team/ccpa-cpra-privacy-expert — US privacy counterpart
  • ra-qm-team/audit-prep/ai-act-readiness — EU AI Act overlay for AI processing

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in ra-qm-team/audit-prep/gdpr-audit-prep of borghei/Claude-Skills.

  • SKILL.md
  • references/dpo-engagement-playbook.md
  • references/gdpr-pre-audit-checklist.md
  • scripts/gdpr_readiness_score.py
  • scripts/ropa_completeness_checker.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Gdpr Audit Prep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gdpr Audit Prep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gdpr Audit Prep this skillborghei/Claude-Skills881—~1.8kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    942 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    942 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from borghei/Claude-Skills

All 349 skills in this repo
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    881 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    881 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    881 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Brainstorm Okrs

    borghei/Claude-Skills

    OKR brainstorming and validation using the Radical Focus framework — outcome objectives, measurable key results, counter-metrics.

    881 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed

Questions about Gdpr Audit Prep

What does Gdpr Audit Prep do?

GDPR audit-prep playbook: sprint to prepare for a supervisory authority inquiry, DPA audit, or internal review. Gdpr Audit Prep is an agent skill from borghei/Claude-Skills. GDPR audit-prep playbook: sprint to prepare for a supervisory authority inquiry, DPA audit, or internal review.

When should I use Gdpr Audit Prep?

Gdpr Audit Prep fits situations like: an audit is scheduled; readiness gaps surface; ROPA (Records of Processing Activities) needs completion.

How do I install Gdpr Audit Prep in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill gdpr-audit-prep -a claude-code`. Or copy the skill folder (ra-qm-team/audit-prep/gdpr-audit-prep in borghei/Claude-Skills) into .claude/skills/gdpr-audit-prep in your project. Claude Code loads it when a task matches its description.

How do I install Gdpr Audit Prep in Codex?

Run `npx skills add borghei/Claude-Skills --skill gdpr-audit-prep -a codex`. Or copy the skill folder (ra-qm-team/audit-prep/gdpr-audit-prep in borghei/Claude-Skills) into .agents/skills/gdpr-audit-prep in your project. Codex loads it when a task matches its description.

Can I use Gdpr Audit Prep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill gdpr-audit-prep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gdpr-audit-prep, .gemini/skills/gdpr-audit-prep, .github/skills/gdpr-audit-prep and .opencode/skills/gdpr-audit-prep in your project.

What does Gdpr Audit Prep need to run?

Going by SKILL.md and its folder, Gdpr Audit Prep needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Gdpr Audit Prep access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gdpr Audit Prep safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Gdpr Audit Prep use?

Gdpr Audit Prep is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gdpr Audit Prep use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.9k tokens, read only when the agent opens those files.

What are the alternatives to Gdpr Audit Prep?

Skills that share tags, products or a category with Gdpr Audit Prep: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gdpr Audit Prep?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 881 GitHub stars. The repository holds 349 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.