Agent skill

Data Policy

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art.

MITAuto-check passedLegal & Compliance

Install Data Policy

skills CLI
$ npx skills add ericrisco/rsc-harness --skill data-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness data-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/data-policy .claude/skills/data-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
data-policy
GitHub stars
156
Token cost
~3.1k tokens
SKILL.md length
1,463 words
Files
6 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art.

  • Works in 3 steps: Purpose — is the interest legitimate and… → Necessity — is the processing actually… → Balancing — does it override the data…
  • Building internal data-governance machinery: a retention schedule (period
  • SKILL.md covers First move: which artifact…, Build the retention schedule, Pick the lawful basis and The ROPA, plus 5 more sections
  • Runs Shell scripts from its folder

What it does

Data Policy is an agent skill from ericrisco/rsc-harness. Use when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art. 6 lawful-basis register, an Art. 30 ROPA, or a consent capture/withdrawal model. NOT the public privacy notice or DSAR handling (that is gdpr-privacy), NOT SOC 2 posture (that is compliance).

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/consent-and-ropa.md`).

It sits in Legal & Compliance, covering Privacy and GDPR, SOC 2 and security compliance and Data governance. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Building internal data-governance machinery: a retention schedule (period
  • System where deletion runs)

Example prompts

  • “/data-policy”

Requirements

  • A Bash shell

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Purpose — is the interest legitimate and clearly stated?
  2. Necessity — is the processing actually needed, or would less-intrusive data do?
  3. Balancing — does it override the data subject's rights and reasonable expectations?

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Data Policy loads about 3.1k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,463 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,463 words, ~3,132 tokens.

Download SKILL.mdSave it as .claude/skills/data-policy/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
data-policy
description
Use when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art. 6 lawful-basis register, an Art. 30 ROPA, or a consent capture/withdrawal model. NOT the public privacy notice or DSAR handling (that is `gdpr-privacy`), NOT SOC 2 posture (that is `compliance`).
tags
data-governance, retention, gdpr, ropa, consent, lawful-basis, privacy, data-minimization
recommends
gdpr-privacy, compliance, contracts, secure-coding, db-migrations, postgresdb
origin
risco

Data policy

You produce the structured governance artifacts engineering and ops implement — a retention schedule, a lawful-basis register, a Record of Processing Activities (ROPA), a consent model — not the public-facing notice users read (that is ../gdpr-privacy/SKILL.md). You are not a DPO and you never claim to be one.

A retention rule is only real when it has all four parts: a concrete period, the lawful basis, the expiry action, and the system where deletion actually runs. A policy that names a period but never deletes anything is a paper policy — and a paper policy is precisely what regulators fine. Cumulative GDPR fines hit ~EUR 5.65B across ~2,245 actions by March 2025, and the two failures that recur are no systematic data classification and no automated deletion capability (Secure Privacy / CMS Enforcement Tracker, 2025). Every schedule you emit ends with the DPO/counsel sign-off boundary below.

First move: which artifact does the operator need?

Map the request to one artifact before writing anything. Each routes to a section.

Operator saysArtifactGo to
"How long do we keep X / write our retention policy"Retention scheduleBuild the retention schedule
"Is our basis consent or legitimate interest?"Lawful-basis registerPick the lawful basis
"Set up a ROPA / Article 30 record"ROPA rowThe ROPA
"Design consent capture / withdrawal"Consent matrixConsent model
"Auto-delete but keep legal holds / backups still have data"Deletion workflowMake it real in systems

If they want the public privacy notice, DPA clauses, or SOC 2 readiness instead, stop and route them — see the boundary below.

Build the retention schedule

This is the core artifact. For every category of personal data, walk five columns in order: data category -> purpose -> lawful basis -> retention period -> expiry action -> system of record. GDPR's storage-limitation principle (Art. 5(1)(e)) requires data be held in identifiable form no longer than necessary for the purpose it was collected for; GDPR sets no fixed periods — duration is driven by purpose plus sector law (gdpr-info.eu Art. 5; Usercentrics, 2026).

The expiry action is one of three, and you must pick one explicitly:

  • delete — the row is gone.
  • anonymize — identifiers stripped so the record is no longer personal data (then storage limitation no longer bites); valid only if re-identification is genuinely infeasible.
  • archive — kept under Art. 89(1) safeguards for a lawful long-term purpose (statutory, archival, statistical).

Worked example. The Bad version is what gets fined; the Good version is enforceable.

text
Bad:  Customer data — kept as long as necessary.
Good: | Category        | Purpose        | Lawful basis      | Period                  | Expiry   | System of record       |
      | Customer orders | fulfil + tax   | Art. 6(1)(b) +(c) | 36 mo after last order  | anonymize| Postgres `orders` + DWH|

Working default periods — starting points, never asserted as universally lawful; validate against local + sector law (Usercentrics; Secure Privacy, 2026):

CategoryCommon defaultBasis it usually rides on
Accounting / tax records~10 years (statutory in most EU states)Art. 6(1)(c) legal obligation
HR records (post-employment)~3–6 yearsArt. 6(1)(b)/(c)
Customer / CRM~3 years after last interactionArt. 6(1)(b)/(f)
Marketing consent recordslife of consent + proofArt. 6(1)(a) consent
Support tickets1–3 yearsArt. 6(1)(b)/(f)
Server / access logsshort (30–180 days typical)Art. 6(1)(f) legitimate interest

Every processing activity in the ROPA should appear as a row here. The full fillable template with the delete-vs-anonymize-vs-archive note and the validation checklist lives in references/retention-schedule.md.

Pick the lawful basis

Art. 6 gives six lawful bases, and you must identify one before processing starts: consent, contract, legal obligation, vital interests, public task, legitimate interests (gdpr-info.eu Art. 6; IAPP). Consent is one of six and is often the weakest choice for operational data.

The trap: defaulting everything to consent. Consent is revocable at any time, so building contract-essential processing on it means a withdrawal can leave you unable to deliver the service. Use contract (Art. 6(1)(b)) for what the service requires, legal obligation (Art. 6(1)(c)) for statutory keep-periods, and legitimate interest (Art. 6(1)(f)) for fraud prevention, security logging, and most analytics. Reserve consent (Art. 6(1)(a)) for marketing and non-essential cookies/trackers.

When you lean on legitimate interest, run the three-part balancing test and write it down:

  1. Purpose — is the interest legitimate and clearly stated?
  2. Necessity — is the processing actually needed, or would less-intrusive data do?
  3. Balancing — does it override the data subject's rights and reasonable expectations?

Anchor this to the EDPB Guidelines 1/2024 on legitimate interest (Oct 2024). The worksheet is in references/consent-and-ropa.md.

The ROPA

A ROPA (Art. 30) is the central inventory: one row per processing activity. Minimum columns: activity, purpose, data categories + data subjects, recipients, transfers, retention period, security measures. Art. 30 does not strictly require logging the Art. 6 basis — but record it per row anyway; it speeds audits, DPIAs, and notice updates (TermsFeed; Legiscope, 2026).

text
Activity:    Customer support ticketing
Purpose:     resolve and track support requests
Data cats:   name, email, account ID, message content | Subjects: customers
Recipients:  internal support team; Zendesk (processor)
Transfers:   US (SCCs in place) — point to gdpr-privacy for the mechanism
Retention:   2 years after ticket closed, then delete
Security:    RBAC, encryption at rest, access logging
Lawful basis: Art. 6(1)(b) contract  ← log it even though Art. 30 doesn't demand it

The full ROPA template with a second worked row — plus the consent-matrix template and the withdrawal/refresh workflow — is in references/consent-and-ropa.md.

Where consent is the basis, it must be valid under Art. 4(11) / Art. 7: freely given, specific, informed, and unambiguous — a positive opt-in act (EDPB).

  • Capture: an affirmative action, never a pre-ticked box. Granular per purpose (marketing email != product analytics). Reject must be as easy as accept — no dark patterns.
  • Proof / logging: store enough to prove consent later — timestamp, the consent-text version, the scope/purposes granted, and the capture method.
  • Withdrawal: must be as easy as giving it. One click, no retention-by-friction.
  • Refresh: EDPB recommends refreshing after ~12 months or on a material change.
text
| Purpose          | Basis        | Capture point      | Proof fields stored              | Withdrawal      |
| Marketing email  | Art. 6(1)(a) | signup checkbox    | ts, text v2.1, scope, method     | one-click unsub |
| Product analytics| Art. 6(1)(a) | cookie banner      | ts, banner vN, categories, method| banner re-open  |

One note so you don't over-promise on cookies: the ePrivacy Regulation was formally withdrawn by the European Commission in February 2025, so the ePrivacy Directive (and its national implementations) still governs cookies and trackers (Hunton; Clym, 2026). Don't cite a Regulation that does not exist.

Show full SKILL.md (558 more words)Show less

Make it real in systems

The policy is worthless until deletion runs in the systems that actually hold the data — including backups and archives, which is exactly where regulators find data that should be gone.

Checklist:

  • Classify the data first — you can't apply a period to a category you haven't mapped.
  • Automate deletion — a scheduled job, not a human promising to remember.
  • Cover backups and archives, not just live tables. Retention limits apply everywhere a copy lives.
  • Legal-hold exception path — a row under litigation/regulatory hold is skipped by the deletion job, and the basis for the hold is documented.
  • Immutable audit log — every deletion writes a record (what category, when, by which job) you can show a regulator.
text
Bad:  A nightly cron deletes expired rows from the prod database.
Good: The deletion job covers prod + the data warehouse + backup snapshots;
      it skips any row flagged under legal hold; and it writes a deletion
      audit record (category, count, timestamp, job id) for every run.

The deletion mechanics — TTL columns, partition drops, soft-delete schema — belong to ../db-migrations/SKILL.md and ../postgresdb/SKILL.md. You write the policy that those mechanics must satisfy.

AI reuse and cross-border transfers

State explicitly in the policy whether production data may be reused for AI/model training. GDPR purpose limitation (Art. 5(1)(b)) restricts reusing data collected for one purpose to train a model — that is a new purpose needing its own basis. The EU AI Act adds documentation and logging-retention duties, with high-risk obligations applying from 2 Aug 2026; the Commission's Digital Omnibus proposal would let AI providers lean on legitimate interest for development with enhanced safeguards and an unconditional opt-out (TechGDPR; IAPP, 2026). Practical rule: the retention policy must say whether AI reuse is allowed, on what basis, and how a subject opts out.

For cross-border transfers, name the mechanism in the ROPA row (e.g. SCCs) and point to ../gdpr-privacy/SKILL.md for the SCC/notice depth — that is its territory, not yours.

The boundary

Retention periods are jurisdiction- and sector-specific, so a period you assert as final is legal advice you are not qualified to give — that is why this line has no exceptions. You produce governance drafts, not legal sign-off. Every policy you emit ends with a statement that a qualified DPO or privacy counsel must validate the schedule and lawful-basis register before adoption, and that this is not legal advice. You never assert a period is universally lawful.

Hand off the edges: public-facing privacy notice + data-subject access/erasure (DSAR) handling -> ../gdpr-privacy/SKILL.md; audit posture, SOC 2 / ISO 27001, control mapping -> ../compliance/SKILL.md; a negotiated DPA's contractual clauses or a two-party data contract -> ../contracts/SKILL.md; encryption, access hardening, threat controls on the systems -> ../secure-coding/SKILL.md; the actual deletion mechanics in the database -> ../db-migrations/SKILL.md / ../postgresdb/SKILL.md.

Anti-patterns

Anti-patternWhy it bitesDo instead
Consent as the default basis for everythingConsent is revocable; a withdrawal breaks contract-essential processingUse contract / legal obligation / legitimate interest for operational data; reserve consent for marketing
"As long as necessary" / "indefinitely" as the only periodNo concrete clock means nothing ever deletes — the classic paper policyGive months/years or named criteria per category, validated against local law
Delete from prod but leave backups/archives untouchedThe data regulators find is the copy you forgotDeletion job must cover prod + warehouse + backups
No legal-hold exception in the auto-deletion jobThe job destroys data under litigation hold — spoliationFlag held rows; skip them; document the hold basis
Copy a generic retention template unchangedPeriods are jurisdiction/sector-specific; a copied period can be unlawfulTag every period "validate vs local + sector law"; adjust
Emit the policy as final / "compliant"Crosses into legal advice you can't giveEnd with DPO/counsel sign-off + not-legal-advice line

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/data-policy of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/consent-and-ropa.md
  • references/retention-schedule.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Data Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Data Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Data Policy this skillericrisco/rsc-harness156—~3.1kAutomated safety check: PassMIT
Cometchat Compliancecometchat/cometchat-skills129—~1.7kAutomated safety check: PassMIT
Nw Security And GovernancenWave-ai/nWave617—~1.7kAutomated safety check: PassMIT
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~3.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~4.2kAutomated safety check: PassMIT

Similar skills

  • Cometchat Compliance

    cometchat/cometchat-skills

    Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery…

    129 GitHub stars~1.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Database security (encryption, access control, injection prevention), data governance (lineage, quality, MDM), and compliance frameworks (GDPR, CCPA, HIPAA)

    617 GitHub stars~1.7k tokensUpdated 21 days ago
    Legal & ComplianceAuto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    939 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    939 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    849 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Questions about Data Policy

What does Data Policy do?

A skill your agent uses when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art. Data Policy is an agent skill from ericrisco/rsc-harness. Use when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art.

When should I use Data Policy?

Data Policy fits situations like: building internal data-governance machinery: a retention schedule (period; system where deletion runs).

How do I install Data Policy in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill data-policy -a claude-code`. Or copy the skill folder (skills/data-policy in ericrisco/rsc-harness) into .claude/skills/data-policy in your project. Claude Code loads it when a task matches its description.

How do I install Data Policy in Codex?

Run `npx skills add ericrisco/rsc-harness --skill data-policy -a codex`. Or copy the skill folder (skills/data-policy in ericrisco/rsc-harness) into .agents/skills/data-policy in your project. Codex loads it when a task matches its description.

Can I use Data Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill data-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/data-policy, .gemini/skills/data-policy, .github/skills/data-policy and .opencode/skills/data-policy in your project.

What does Data Policy need to run?

Going by SKILL.md and its folder, Data Policy needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Data Policy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Data Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Data Policy use?

Data Policy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Data Policy use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Data Policy?

Skills that share tags, products or a category with Data Policy: Cometchat Compliance (cometchat/cometchat-skills, 129 stars), Nw Security And Governance (nWave-ai/nWave, 617 stars), Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars) and Audit Report (harness/harness-skills, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Data Policy?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.