Agent skill

Privacy Compliance Architecture

by devcodex-labs in devcodex-labs/devcodex

隐私与合规架构专家 Owner — 当任务涉及个人信息/PII、数据分类、目的限制、同意、最小化、保留删除、数据驻留、跨境、日志脱敏、主体访问导出删除权或隐私审计时使用;要求把数据生命周期和用户权利映射到真实系统路径与证据。

AGPL-3.0Auto-check passedLegal & Compliance

Install Privacy Compliance Architecture

skills CLI
$ npx skills add devcodex-labs/devcodex --skill privacy-compliance-architecture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install devcodex-labs/devcodex privacy-compliance-architecture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/privacy-compliance-architecture .claude/skills/privacy-compliance-architecture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
privacy-compliance-architecture
GitHub stars
439
Token cost
~426 tokens
SKILL.md length
77 words
Files
3
Skills in repo
70
Repo updated
First seen
Licence
AGPL-3.0

At a glance

隐私与合规架构专家 Owner — 当任务涉及个人信息/PII、数据分类、目的限制、同意、最小化、保留删除、数据驻留、跨境、日志脱敏、主体访问导出删除权或隐私审计时使用;要求把数据生命周期和用户权利映射到真实系统路径与证据。

  • Works in 7 steps: 以真实数据流建立 inventory,不只看数据库 Schema;包含… → 为每项数据绑定 purpose、最小化、访问者、保留、驻留和删除路径。 → 区分 consent 与其他合法基础;定义撤回后的新处理、已有数据和下游传播。 → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers 职责, PrivacyComplianceArchitectureGa…, 执行流程 and 输出字段, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Privacy Compliance Architecture is an agent skill from devcodex-labs/devcodex. 隐私与合规架构专家 Owner — 当任务涉及个人信息/PII、数据分类、目的限制、同意、最小化、保留删除、数据驻留、跨境、日志脱敏、主体访问导出删除权或隐私审计时使用;要求把数据生命周期和用户权利映射到真实系统路径与证据。

Its SKILL.md is about 430 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `agents/openai.yaml` and `intent.json`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “/privacy-compliance-architecture”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. 以真实数据流建立 inventory,不只看数据库 Schema;包含 prompt、日志、trace、analytics、cache、queue、backup 和第三方。
  2. 为每项数据绑定 purpose、最小化、访问者、保留、驻留和删除路径。
  3. 区分 consent 与其他合法基础;定义撤回后的新处理、已有数据和下游传播。
  4. 设计主体权利流程及身份验证,防止导出/删除接口形成越权。
  5. 明确 processor/provider 边界、跨区域传输和供应商退出。
  6. 为超期保留、日志泄露、备份删除失败、下游未传播和权限误配设计探针。
  7. 把法律/政策适用范围标为 project evidence;证据不足时不得编造法规结论。

What it can do on your machine

Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Privacy Compliance Architecture loads about 426 tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 77 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~426

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 77 words, ~426 tokens.

Download SKILL.mdSave it as .claude/skills/privacy-compliance-architecture/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
privacy-compliance-architecture
description
隐私与合规架构专家 Owner — 当任务涉及个人信息/PII、数据分类、目的限制、同意、最小化、保留删除、数据驻留、跨境、日志脱敏、主体访问导出删除权或隐私审计时使用;要求把数据生命周期和用户权利映射到真实系统路径与证据。

Privacy Compliance Architecture

职责

设计从采集、使用、共享、存储、日志、备份到删除的隐私生命周期,并把政策要求落实为系统合同。security 负责攻击面,data 负责模型,growth 负责分析目的;本 Skill 负责隐私权利、目的和合规证据。

PrivacyComplianceArchitectureGate

字段要求
dataClassificationMap数据项、敏感度、主体、来源、存储、日志/trace/备份派生面
purposeConsentMatrixpurpose、lawful basis/consent、使用者、撤回、二次用途限制
minimizationBoundary必需字段、可选字段、派生字段和禁止采集/传播面
retentionDeletionPolicyactive/archive/log/cache/backup 的期限、触发、例外和可验证删除
residencyBoundaryregion、跨区/跨境流、processor/subprocessor 和迁移限制
dataSubjectRightsFlowaccess/export/correct/delete/restrict/withdraw 的身份验证、范围和 SLA
privacyAuditEvidence决策、访问、导出、删除、例外、失败和人工复核证据

执行流程

  1. 以真实数据流建立 inventory,不只看数据库 Schema;包含 prompt、日志、trace、analytics、cache、queue、backup 和第三方。
  2. 为每项数据绑定 purpose、最小化、访问者、保留、驻留和删除路径。
  3. 区分 consent 与其他合法基础;定义撤回后的新处理、已有数据和下游传播。
  4. 设计主体权利流程及身份验证,防止导出/删除接口形成越权。
  5. 明确 processor/provider 边界、跨区域传输和供应商退出。
  6. 为超期保留、日志泄露、备份删除失败、下游未传播和权限误配设计探针。
  7. 把法律/政策适用范围标为 project evidence;证据不足时不得编造法规结论。

输出字段

dataClassificationMap、purposeConsentMatrix、minimizationBoundary、retentionDeletionPolicy、residencyBoundary、dataSubjectRightsFlow、processorMap、privacyAuditEvidence、verificationRoute、evidenceMatrix。

反模式

  • 把加密或鉴权等同于隐私合规。
  • 只定义数据库删除,不覆盖缓存、搜索、日志、队列和备份。
  • 所有采集都写“用户已同意”,却无 purpose、撤回和证据。
  • 日志脱敏只 grep 源码,不验证 runtime artifact。
  • 复制法规名称或地区结论,没有项目适用证据。
  • 为了“合规最佳实践”覆盖用户/项目明确的数据和秘密策略。

验证

至少覆盖超期保留、撤回同意、访问/导出/更正/删除、跨区传输、日志/trace 泄露、cache/search/backup 删除、processor 传播、权限越权和审计证据完整性。

© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in content/skills/privacy-compliance-architecture of devcodex-labs/devcodex.

  • SKILL.md
  • agents/openai.yaml
  • intent.json

Open the folder on GitHubat commit 1dd4525

Compare with similar skills

Privacy Compliance Architecture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Privacy Compliance Architecture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Privacy Compliance Architecture this skilldevcodex-labs/devcodex439—~426Automated safety check: PassAGPL-3.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from devcodex-labs/devcodex

All 70 skills in this repo
  • Accessibility I18n

    devcodex-labs/devcodex

    无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。

    439 GitHub stars~718 tokensUpdated 22 days ago
    Auto-check passed
  • AI Agent System Architecture

    devcodex-labs/devcodex

    AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。

    439 GitHub stars~2.4k tokensUpdated 22 days ago
    Auto-check passed
  • API Contract Architecture

    devcodex-labs/devcodex

    API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。

    439 GitHub stars~865 tokensUpdated 22 days ago
    Auto-check passed
  • Architecture Design

    devcodex-labs/devcodex

    架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。

    439 GitHub stars~1.1k tokensUpdated 22 days ago
    Auto-check passed
  • Audit Common

    devcodex-labs/devcodex

    审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层

    439 GitHub stars~4.1k tokensUpdated 22 days ago
    Auto-check passed
  • Audit Session

    devcodex-labs/devcodex

    审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

    439 GitHub stars~1.8k tokensUpdated 22 days ago
    Auto-check passed

Questions about Privacy Compliance Architecture

What does Privacy Compliance Architecture do?

隐私与合规架构专家 Owner — 当任务涉及个人信息/PII、数据分类、目的限制、同意、最小化、保留删除、数据驻留、跨境、日志脱敏、主体访问导出删除权或隐私审计时使用;要求把数据生命周期和用户权利映射到真实系统路径与证据。. Privacy Compliance Architecture is an agent skill from devcodex-labs/devcodex.

When should I use Privacy Compliance Architecture?

Privacy Compliance Architecture fits situations like: tasks that involve Privacy and GDPR.

How do I install Privacy Compliance Architecture in Claude Code?

Run `npx skills add devcodex-labs/devcodex --skill privacy-compliance-architecture -a claude-code`. Or copy the skill folder (content/skills/privacy-compliance-architecture in devcodex-labs/devcodex) into .claude/skills/privacy-compliance-architecture in your project. Claude Code loads it when a task matches its description.

How do I install Privacy Compliance Architecture in Codex?

Run `npx skills add devcodex-labs/devcodex --skill privacy-compliance-architecture -a codex`. Or copy the skill folder (content/skills/privacy-compliance-architecture in devcodex-labs/devcodex) into .agents/skills/privacy-compliance-architecture in your project. Codex loads it when a task matches its description.

Can I use Privacy Compliance Architecture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill privacy-compliance-architecture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-compliance-architecture, .gemini/skills/privacy-compliance-architecture, .github/skills/privacy-compliance-architecture and .opencode/skills/privacy-compliance-architecture in your project.

What does Privacy Compliance Architecture need to run?

SKILL.md names no scripts, command-line tools or credentials: Privacy Compliance Architecture is instructions for the agent only.

Does Privacy Compliance Architecture access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Privacy Compliance Architecture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Privacy Compliance Architecture use?

Privacy Compliance Architecture is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Privacy Compliance Architecture use?

About 426 tokens (SKILL.md is roughly 1.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Privacy Compliance Architecture?

Skills that share tags, products or a category with Privacy Compliance Architecture: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Privacy Compliance Architecture?

devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.

Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.