Agent skill

Gdpr Privacy

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art.

MITAuto-check passedLegal & Compliance

Install Gdpr Privacy

skills CLI
$ npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness gdpr-privacy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gdpr-privacy .claude/skills/gdpr-privacy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gdpr-privacy
GitHub stars
167
Token cost
~3.5k tokens
SKILL.md length
1,790 words
Files
7 (incl. scripts, references)
Skills in repo
227
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art.

  • Works in 3 steps: Every artifact maps to a real processing… → Name the lawful basis and its why for… → Always emit the counsel/DPO-review…
  • Producing the GDPR artifacts a product publishes
  • SKILL.md covers First move: inventory before…, Lawful basis (Article 6), Cookies & consent and The privacy policy (Articles…, plus 5 more sections
  • Runs Shell scripts from its folder

What it does

Gdpr Privacy is an agent skill from ericrisco/rsc-harness. Use when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art. 28 DPA, an SCC transfer mechanism, or a DSAR flow. Drafts for counsel review. NOT internal retention rules (that is data-policy), NOT consumer ToS (that is terms-conditions).

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/dpa-and-transfers.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Producing the GDPR artifacts a product publishes
  • Hands over: a privacy policy true to what it processes
  • A cookie/consent banner
  • A lawful basis per purpose

Example prompts

  • “/gdpr-privacy”

Requirements

  • A Bash shell

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Every artifact maps to a real processing activity. Never describe data the product does not process. An inaccurate policy is not harmless…
  2. Name the lawful basis and its why for each purpose. Article 6 requires at least one of six bases, fixed before processing and recorded…
  3. Always emit the counsel/DPO-review boundary before anything is published or relied on. You draft and you flag; a qualified privacy counsel…

What it can do on your machine

Read from SKILL.md and the folder at commit e3d5b33. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gdpr Privacy loads about 3.5k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 1,790 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit e3d5b33, republished under its MIT licence (© ericrisco). 1,790 words, ~3,511 tokens.

Download SKILL.mdSave it as .claude/skills/gdpr-privacy/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
gdpr-privacy
description
Use when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art. 28 DPA, an SCC transfer mechanism, or a DSAR flow. Drafts for counsel review. NOT internal retention rules (that is `data-policy`), NOT consumer ToS (that is `terms-conditions`).
tags
gdpr, privacy, data-protection, cookies, consent, lawful-basis, dpa, scc, dsar, ropa, dpia, rgpd
recommends
data-policy, terms-conditions, contracts, compliance, secure-coding, email-deliverability
origin
risco

GDPR privacy

You produce the GDPR artifacts a product must publish or hand to data subjects, vendors, and regulators: privacy policy, cookie/consent banner, lawful-basis record, ROPA, the Article 28 DPA, transfer mechanism, and the data-subject-rights flow. You are not a lawyer and you never say you are.

Three standing rules. Hold them through every task.

  1. Every artifact maps to a real processing activity. Never describe data the product does not process. An inaccurate policy is not harmless boilerplate — it is the Article 12-14 transparency violation that the EDPB's 2026 coordinated enforcement action targets. The policy is downstream of the inventory, never a template you fill blind.
  2. Name the lawful basis and its why for each purpose. Article 6 requires at least one of six bases, fixed before processing and recorded. "We process emails" is not a record; "we send onboarding emails under legitimate interest, LIA dated 2026-05, balancing passed because the user just signed up and expects them" is.
  3. Always emit the counsel/DPO-review boundary before anything is published or relied on. You draft and you flag; a qualified privacy counsel or the org's DPO signs off. Say so every time.

Current law is the 2016 GDPR (Regulation 2016/679). The Digital Omnibus published 19 November 2025 is a proposal, not law — comply with current rules, watch the reform (see the final section). Do not draft to proposed rules as if enacted.

First move: inventory before you draft

You cannot write a truthful policy without knowing the processing. Before any artifact, get the inventory — this is the Article 30 ROPA, and it is the source of truth that feeds everything else:

  • What personal data (categories: contact, usage/analytics, payment, special categories under Art. 9)?
  • Why — the purpose, stated per use, not "to run the service"?
  • From whom, and is it collected from the person (Art. 13) or obtained elsewhere (Art. 14)?
  • Retained how long, and on what trigger does it get deleted?
  • Shared with which recipients and sub-processors?
  • Transferred where — does any of it leave the EEA?

If you don't have these answers, ask for them or state the assumption explicitly in the draft. Do not invent processing to fill a template.

Then route the request to the artifact it actually needs:

The requestArtifact you produceLoad-bearing ruleReference
"Write a privacy policy"Art. 13/14 disclosureMatch the ROPA; lawful basis per purposereferences/privacy-policy-blueprint.md
"Fix the cookie banner"Consent banner configReject as easy as accept; block until consentreferences/dsar-and-consent.md
"Pick a lawful basis"Basis record + LIA if neededConsent only where refusal is consequence-freereferences/dsar-and-consent.md
"Review/draft a DPA"Art. 28 clause setAll mandatory terms present; sub-processor flow-downreferences/dpa-and-transfers.md
"Data leaving the EEA"Transfer mechanism2021 SCCs (right module) + transfer impact notereferences/dpa-and-transfers.md
"Someone asked for their data"DSAR responseOne-month clock; verify identity proportionatelyreferences/dsar-and-consent.md
"New high-risk feature"DPIAMandatory before high-risk processing startsthis file, §ROPA/DPIA/breach

Lawful basis (Article 6)

Six bases, pick at least one per purpose, record it before processing: consent, contract (necessary to perform a contract with the person), legal obligation, vital interests, public task, legitimate interests. You cannot swap bases later to dodge a withdrawal — pick the honest one up front.

The pivotal call is consent vs legitimate interest:

  • Consent (Art. 4(11) + Recital 32): freely given, specific, informed, unambiguous, and as easy to withdraw as to give. Use it only where the person has a genuine, consequence-free ability to refuse. You cannot use consent for something the person can't actually decline (e.g. processing necessary for the employment relationship — use contract or legal obligation there).
  • Legitimate interest (Art. 6(1)(f)): requires a written, dated three-part Legitimate Interests Assessment (LIA) — purpose, necessity, balancing — kept on file. No LIA, no legitimate-interest basis.
text
Bad:  "We rely on consent for analytics." — but the tracker fires on page load,
      the consent box is pre-ticked, and there is no LIA anywhere.
      => invalid consent (pre-ticked, not affirmative) AND no fallback basis.

Good: Non-essential analytics fires ONLY after the user clicks Accept (prior,
      affirmative consent, per-purpose, withdrawable from the banner).
      Onboarding email uses legitimate interest with a one-page LIA dated
      2026-05: purpose = activate the account the user just created;
      necessity = no less-intrusive way; balancing = expected, low-impact,
      easy opt-out => passes. Marketing email uses consent (separate opt-in).

LIA template lives in references/dsar-and-consent.md.

  • Reject must be as easy as accept. Surface Accept-all and Reject-all at the same level, same friction, same prominence. A banner where Accept is one click and Reject is buried two layers down is non-compliant. CNIL fined Google €325M and Shein €150M in September 2025 over exactly this; the EDPB Cookie Banner Task Force position is settled.
  • Block non-essential cookies/trackers until affirmative consent. A banner that sets analytics or ad trackers on page load is non-compliant regardless of the copy — the timing is the violation, not the wording.
  • Consent is per-purpose and withdrawable. No bundling "analytics + ads + personalization" into one toggle; withdrawing must be as easy as giving.
  • The rule is the ePrivacy Directive (2002/58/EC), transposed per member state. The ePrivacy Regulation was formally withdrawn by the Commission in February 2025 — there is no single EU-wide cookie rule. Banner rules vary by country; flag that variance, don't assume one config covers all of the EEA.

Compliant banner shape: three controls at equal weight — Accept all, Reject all, Customize — strictly-necessary cookies on by default, everything else off until the user chooses. Config shape in references/dsar-and-consent.md.

The privacy policy (Articles 13/14)

Write it to match the ROPA, in plain language, with no catch-all lies ("we may collect any and all data" is itself a violation). Mandatory disclosures:

  • Identity and contact details of the controller (and EU representative if applicable).
  • DPO contact, if you have one.
  • The purposes and the lawful basis per purpose — and where the basis is legitimate interest, state the interest.
  • Recipients or categories of recipients (including sub-processors).
  • International transfers and the mechanism relied on (SCCs / DPF / adequacy).
  • Retention period per category, or the criteria used to set it.
  • The full data-subject-rights list, how to exercise each, and the right to lodge a complaint with a supervisory authority.
  • Whether there is automated decision-making / profiling, with meaningful info about the logic.
  • Source of the data, if not collected from the person (Art. 14 case).

Fill-in blueprint with a "why required" per section: references/privacy-policy-blueprint.md.

DPAs & transfers

Article 28 requires a binding written DPA whenever a processor handles personal data on your behalf (or, when you're the processor, that a controller demand one from you). Mandatory clauses — check every one is present, demand them as controller, offer them as processor:

  • Process only on the controller's documented instructions.
  • Confidentiality commitment from anyone handling the data.
  • Article 32 security measures (technical and organizational).
  • Sub-processor authorization plus flow-down of the same obligations, and a change-notice right.
  • Assist the controller with data-subject rights and with breach notification.
  • Delete or return the data at the end of the engagement.
  • Submit to and contribute to audits.

Transfers outside the EEA need a valid mechanism. The Commission's modernised 2021 Standard Contractual Clauses (adopted 4 June 2021) are the common choice — pick the right module (C2C / C2P / P2P / P2C). The 2021 SCCs already incorporate Art. 28 terms, so the transfer doesn't need a separate DPA on top. Post-Schrems II, a Transfer Impact Assessment may be required to check the destination's laws don't undermine the SCCs. The EU-US Data Privacy Framework is an alternative only for a US importer that is actually certified — verify certification, don't assume it.

Demand/offer table, SCC module picker, TIA skeleton, and the sub-processor change-notice clause: references/dpa-and-transfers.md.

Show full SKILL.md (628 more words)Show less

Data-subject rights flow

The clock is one month from receipt to respond (access Art. 15, erasure Art. 17, portability, rectification, objection, restriction). You may extend by two further months for complex or numerous requests — but only if you tell the person within the first month, with reasons. Silent extension is a breach.

The flow:

  1. Log receipt with the date — that starts the clock.
  2. Verify identity proportionately. Confirm who they are, but don't over-collect to do it (don't demand a passport scan to release an email address you already hold).
  3. Route by right: access (give a copy + the Art. 15 context), erasure, portability (machine-readable, commonly used format), rectification, objection, restriction.
  4. Apply exceptions. Erasure is not absolute — legal-obligation retention, freedom of expression, and establishment/exercise of legal claims are carve-outs. Note which applies and why.
  5. Respond free of charge unless the request is manifestly unfounded or excessive (then you may charge a reasonable fee or refuse, with reasons).

Per-right runbook: references/dsar-and-consent.md.

ROPA + DPIA + breach (the documentation trio)

  • ROPA (Art. 30): maintain it; the supervisory authority can demand it on request. It is the spine that feeds the policy, the DPA, and the transfer record. If the org has no ROPA, building one is the first deliverable.
  • DPIA (Art. 35): mandatory before any processing "likely to result in a high risk." Trigger checklist — do a DPIA if any apply: large-scale processing of special categories (Art. 9 data), systematic monitoring of a public area, or novel/high-risk technology (e.g. new biometric or AI-driven profiling). When in doubt, do it.
  • Breach (Art. 33/34): notify the supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in risk; notify affected individuals when the risk to them is high. Have the contact and the template ready before a breach, not during.

Stakes, and what isn't yours

The fines make the stakes concrete: up to €20M or 4% of global annual turnover (whichever is higher) for the most serious infringements, €10M / 2% for the lesser tier; cumulative GDPR fines already exceed €7.1B. This is not a Big-Tech-only risk.

Hand off what isn't yours:

  • Internal data retention, classification, governance posture → ../data-policy/SKILL.md.
  • The user-facing Terms of Service / EULA → ../terms-conditions/SKILL.md.
  • The commercial paper around a DPA (liability, indemnity, the MSA) → ../contracts/SKILL.md.
  • SOC 2 / ISO 27001 / audit-evidence posture → ../compliance/SKILL.md.
  • The Article 32 code-level controls (encryption, authz, secrets) → ../secure-coding/SKILL.md.
  • Email opt-in mechanics / SPF / DKIM / list hygiene → ../email-deliverability/SKILL.md (the consent substance stays here).

Anti-patterns

Anti-patternFix
Drafts a policy describing data the product doesn't process (boilerplate-lie)Write from the ROPA; if you don't have it, get it or state the assumption
Cookie banner: Accept one click, Reject buried two layers downEqual-weight Accept-all / Reject-all at the same level
Sets trackers on page load behind the bannerBlock non-essential cookies until affirmative consent — timing is the violation
Uses consent for something the person can't refuse (e.g. employment processing)Use the right basis — contract or legal obligation, not consent
Legitimate interest claimed with no LIA on fileWrite the dated three-part LIA (purpose / necessity / balancing) first
"SCCs alone fix any US transfer" — skips the TIARun the Transfer Impact Assessment; verify DPF certification if relying on it
Treats the Digital Omnibus as current lawIt is a 19-Nov-2025 proposal; draft to the 2016 GDPR
Misses the one-month DSAR clock, or extends silentlyRespond within a month; extend only with in-month notice and reasons
"Industry-standard security" with no Art. 32 referenceCite Article 32 and describe the actual measures
Says it's giving legal advice / the policy is safe to publish unreviewedFlag for qualified privacy counsel / DPO every time

Run scripts/verify.sh <artifact-file> over any policy/banner/DPA you emit to catch missing Art. 13/14 tokens, placeholder leftovers, boilerplate-lies, and a banner missing its reject control (banlist rationale in references/dsar-and-consent.md).

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/gdpr-privacy of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/dpa-and-transfers.md
  • references/dsar-and-consent.md
  • references/privacy-policy-blueprint.md
  • scripts/verify.sh

Open the folder on GitHubat commit e3d5b33

Compare with similar skills

Gdpr Privacy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gdpr Privacy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gdpr Privacy this skillericrisco/rsc-harness167—~3.5kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    942 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    942 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from ericrisco/rsc-harness

All 227 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    167 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    167 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    167 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    167 GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    167 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    167 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed

Questions about Gdpr Privacy

What does Gdpr Privacy do?

A skill your agent uses when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art. Gdpr Privacy is an agent skill from ericrisco/rsc-harness. Use when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art.

When should I use Gdpr Privacy?

Gdpr Privacy fits situations like: producing the GDPR artifacts a product publishes; hands over: a privacy policy true to what it processes; A cookie/consent banner; A lawful basis per purpose.

How do I install Gdpr Privacy in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a claude-code`. Or copy the skill folder (skills/gdpr-privacy in ericrisco/rsc-harness) into .claude/skills/gdpr-privacy in your project. Claude Code loads it when a task matches its description.

How do I install Gdpr Privacy in Codex?

Run `npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a codex`. Or copy the skill folder (skills/gdpr-privacy in ericrisco/rsc-harness) into .agents/skills/gdpr-privacy in your project. Codex loads it when a task matches its description.

Can I use Gdpr Privacy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gdpr-privacy, .gemini/skills/gdpr-privacy, .github/skills/gdpr-privacy and .opencode/skills/gdpr-privacy in your project.

What does Gdpr Privacy need to run?

Going by SKILL.md and its folder, Gdpr Privacy needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Gdpr Privacy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gdpr Privacy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Gdpr Privacy use?

Gdpr Privacy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gdpr Privacy use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.

What are the alternatives to Gdpr Privacy?

Skills that share tags, products or a category with Gdpr Privacy: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gdpr Privacy?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 167 GitHub stars. The repository holds 227 skills in this directory. The repository was last updated on October 7, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.