C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
A skill your agent uses when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art.
$ npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness gdpr-privacy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gdpr-privacy .claude/skills/gdpr-privacy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gdpr-privacy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gdpr-privacy into .claude/skills/gdpr-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-privacy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/gdpr-privacyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness gdpr-privacy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/gdpr-privacy .agents/skills/gdpr-privacy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gdpr-privacy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gdpr-privacy into .agents/skills/gdpr-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-privacy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness gdpr-privacy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/gdpr-privacy .cursor/skills/gdpr-privacy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gdpr-privacy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gdpr-privacy into .cursor/skills/gdpr-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-privacy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/gdpr-privacy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness gdpr-privacy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/gdpr-privacy .gemini/skills/gdpr-privacy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gdpr-privacy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gdpr-privacy into .gemini/skills/gdpr-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-privacy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness gdpr-privacyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/gdpr-privacy .github/skills/gdpr-privacy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gdpr-privacy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gdpr-privacy into .github/skills/gdpr-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-privacy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness gdpr-privacy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/gdpr-privacy .opencode/skills/gdpr-privacy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gdpr-privacy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gdpr-privacy into .opencode/skills/gdpr-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-privacy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gdpr-privacyA skill your agent uses when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art.
Gdpr Privacy is an agent skill from ericrisco/rsc-harness. Use when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art. 28 DPA, an SCC transfer mechanism, or a DSAR flow. Drafts for counsel review. NOT internal retention rules (that is data-policy), NOT consumer ToS (that is terms-conditions).
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/dpa-and-transfers.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e3d5b33. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gdpr Privacy loads about 3.5k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 1,790 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit e3d5b33, republished under its MIT licence (© ericrisco). 1,790 words, ~3,511 tokens.
.claude/skills/gdpr-privacy/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.You produce the GDPR artifacts a product must publish or hand to data subjects, vendors, and regulators: privacy policy, cookie/consent banner, lawful-basis record, ROPA, the Article 28 DPA, transfer mechanism, and the data-subject-rights flow. You are not a lawyer and you never say you are.
Three standing rules. Hold them through every task.
Current law is the 2016 GDPR (Regulation 2016/679). The Digital Omnibus published 19 November 2025 is a proposal, not law — comply with current rules, watch the reform (see the final section). Do not draft to proposed rules as if enacted.
You cannot write a truthful policy without knowing the processing. Before any artifact, get the inventory — this is the Article 30 ROPA, and it is the source of truth that feeds everything else:
If you don't have these answers, ask for them or state the assumption explicitly in the draft. Do not invent processing to fill a template.
Then route the request to the artifact it actually needs:
| The request | Artifact you produce | Load-bearing rule | Reference |
|---|---|---|---|
| "Write a privacy policy" | Art. 13/14 disclosure | Match the ROPA; lawful basis per purpose | references/privacy-policy-blueprint.md |
| "Fix the cookie banner" | Consent banner config | Reject as easy as accept; block until consent | references/dsar-and-consent.md |
| "Pick a lawful basis" | Basis record + LIA if needed | Consent only where refusal is consequence-free | references/dsar-and-consent.md |
| "Review/draft a DPA" | Art. 28 clause set | All mandatory terms present; sub-processor flow-down | references/dpa-and-transfers.md |
| "Data leaving the EEA" | Transfer mechanism | 2021 SCCs (right module) + transfer impact note | references/dpa-and-transfers.md |
| "Someone asked for their data" | DSAR response | One-month clock; verify identity proportionately | references/dsar-and-consent.md |
| "New high-risk feature" | DPIA | Mandatory before high-risk processing starts | this file, §ROPA/DPIA/breach |
Six bases, pick at least one per purpose, record it before processing: consent, contract (necessary to perform a contract with the person), legal obligation, vital interests, public task, legitimate interests. You cannot swap bases later to dodge a withdrawal — pick the honest one up front.
The pivotal call is consent vs legitimate interest:
Bad: "We rely on consent for analytics." — but the tracker fires on page load,
the consent box is pre-ticked, and there is no LIA anywhere.
=> invalid consent (pre-ticked, not affirmative) AND no fallback basis.
Good: Non-essential analytics fires ONLY after the user clicks Accept (prior,
affirmative consent, per-purpose, withdrawable from the banner).
Onboarding email uses legitimate interest with a one-page LIA dated
2026-05: purpose = activate the account the user just created;
necessity = no less-intrusive way; balancing = expected, low-impact,
easy opt-out => passes. Marketing email uses consent (separate opt-in).LIA template lives in references/dsar-and-consent.md.
Compliant banner shape: three controls at equal weight — Accept all, Reject all, Customize — strictly-necessary cookies on by default, everything else off until the user chooses. Config shape in references/dsar-and-consent.md.
Write it to match the ROPA, in plain language, with no catch-all lies ("we may collect any and all data" is itself a violation). Mandatory disclosures:
Fill-in blueprint with a "why required" per section: references/privacy-policy-blueprint.md.
Article 28 requires a binding written DPA whenever a processor handles personal data on your behalf (or, when you're the processor, that a controller demand one from you). Mandatory clauses — check every one is present, demand them as controller, offer them as processor:
Transfers outside the EEA need a valid mechanism. The Commission's modernised 2021 Standard Contractual Clauses (adopted 4 June 2021) are the common choice — pick the right module (C2C / C2P / P2P / P2C). The 2021 SCCs already incorporate Art. 28 terms, so the transfer doesn't need a separate DPA on top. Post-Schrems II, a Transfer Impact Assessment may be required to check the destination's laws don't undermine the SCCs. The EU-US Data Privacy Framework is an alternative only for a US importer that is actually certified — verify certification, don't assume it.
Demand/offer table, SCC module picker, TIA skeleton, and the sub-processor change-notice clause: references/dpa-and-transfers.md.
The clock is one month from receipt to respond (access Art. 15, erasure Art. 17, portability, rectification, objection, restriction). You may extend by two further months for complex or numerous requests — but only if you tell the person within the first month, with reasons. Silent extension is a breach.
The flow:
Per-right runbook: references/dsar-and-consent.md.
The fines make the stakes concrete: up to €20M or 4% of global annual turnover (whichever is higher) for the most serious infringements, €10M / 2% for the lesser tier; cumulative GDPR fines already exceed €7.1B. This is not a Big-Tech-only risk.
Hand off what isn't yours:
../data-policy/SKILL.md.../terms-conditions/SKILL.md.../contracts/SKILL.md.../compliance/SKILL.md.../secure-coding/SKILL.md.../email-deliverability/SKILL.md (the consent substance stays here).| Anti-pattern | Fix |
|---|---|
| Drafts a policy describing data the product doesn't process (boilerplate-lie) | Write from the ROPA; if you don't have it, get it or state the assumption |
| Cookie banner: Accept one click, Reject buried two layers down | Equal-weight Accept-all / Reject-all at the same level |
| Sets trackers on page load behind the banner | Block non-essential cookies until affirmative consent — timing is the violation |
| Uses consent for something the person can't refuse (e.g. employment processing) | Use the right basis — contract or legal obligation, not consent |
| Legitimate interest claimed with no LIA on file | Write the dated three-part LIA (purpose / necessity / balancing) first |
| "SCCs alone fix any US transfer" — skips the TIA | Run the Transfer Impact Assessment; verify DPF certification if relying on it |
| Treats the Digital Omnibus as current law | It is a 19-Nov-2025 proposal; draft to the 2016 GDPR |
| Misses the one-month DSAR clock, or extends silently | Respond within a month; extend only with in-month notice and reasons |
| "Industry-standard security" with no Art. 32 reference | Cite Article 32 and describe the actual measures |
| Says it's giving legal advice / the policy is safe to publish unreviewed | Flag for qualified privacy counsel / DPO every time |
Run scripts/verify.sh <artifact-file> over any policy/banner/DPA you emit to catch missing Art. 13/14 tokens, placeholder leftovers, boilerplate-lies, and a banner missing its reject control (banlist rationale in references/dsar-and-consent.md).
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in skills/gdpr-privacy of ericrisco/rsc-harness.
Open the folder on GitHubat commit e3d5b33
Gdpr Privacy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gdpr Privacy this skillericrisco/rsc-harness | 167 | — | ~3.5k | Automated safety check: Pass | MIT | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 586 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 942 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 942 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Categories
A skill your agent uses when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art. Gdpr Privacy is an agent skill from ericrisco/rsc-harness. Use when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art.
Gdpr Privacy fits situations like: producing the GDPR artifacts a product publishes; hands over: a privacy policy true to what it processes; A cookie/consent banner; A lawful basis per purpose.
Run `npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a claude-code`. Or copy the skill folder (skills/gdpr-privacy in ericrisco/rsc-harness) into .claude/skills/gdpr-privacy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a codex`. Or copy the skill folder (skills/gdpr-privacy in ericrisco/rsc-harness) into .agents/skills/gdpr-privacy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill gdpr-privacy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gdpr-privacy, .gemini/skills/gdpr-privacy, .github/skills/gdpr-privacy and .opencode/skills/gdpr-privacy in your project.
Going by SKILL.md and its folder, Gdpr Privacy needs a shell for the scripts in its folder. Our summary lists: A Bash shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Gdpr Privacy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Gdpr Privacy: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 167 GitHub stars. The repository holds 227 skills in this directory. The repository was last updated on October 7, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.