Agent skill

Data Protection

by Hack23 in Hack23/cia

Data classification (CIA triad), GDPR privacy by design, encryption standards, data lifecycle management

Apache-2.0Auto-check passedLegal & Compliance

Install Data Protection

skills CLI
$ npx skills add Hack23/cia --skill data-protection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia data-protection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/data-protection .claude/skills/data-protection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
data-protection
GitHub stars
239
Token cost
~1.8k tokens
SKILL.md length
421 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Data classification (CIA triad), GDPR privacy by design, encryption standards, data lifecycle management

  • Works in 7 steps: Proactive, not reactive — Embed privacy… → Privacy as default — Minimize personal… → Privacy embedded in design — Use… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Purpose, When to Use This Skill, Data Classification Framework and GDPR Privacy by Design, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Data Protection is an agent skill from Hack23/cia. Data classification (CIA triad), GDPR privacy by design, encryption standards, data lifecycle management

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “/data-protection”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Proactive, not reactive — Embed privacy into political data imports
  2. Privacy as default — Minimize personal data collection
  3. Privacy embedded in design — Use pseudonymization where possible
  4. Full functionality — Privacy without sacrificing analysis quality
  5. End-to-end security — Encrypt data at rest and in transit
  6. Visibility and transparency — Document all data processing activities
  7. Respect for user privacy — Provide data access and deletion mechanisms

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • gdpr-info.eu
    • csrc.nist.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Data Protection loads about 1.8k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 421 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 421 words, ~1,752 tokens.

Download SKILL.mdSave it as .claude/skills/data-protection/SKILL.md (or your agent's skills folder).
name
data-protection
description
Data classification (CIA triad), GDPR privacy by design, encryption standards, data lifecycle management
license
Apache-2.0

Data Protection Skill

Purpose

This skill provides comprehensive data protection guidance for the CIA platform, covering data classification, GDPR privacy by design, encryption standards, and data lifecycle management. It ensures political intelligence data is handled according to Hack23 ISMS classification and data protection policies.

When to Use This Skill

Apply this skill when:

  • ✅ Handling personal data of politicians or citizens
  • ✅ Designing database schemas with sensitive fields
  • ✅ Implementing data import/export functionality
  • ✅ Configuring data retention or deletion policies
  • ✅ Integrating external data sources (Riksdagen, World Bank)
  • ✅ Processing election or voting records
  • ✅ Implementing caching strategies for sensitive data

Do NOT use for:

  • ❌ Public open data with no personal information
  • ❌ Static UI component changes
  • ❌ Build system or CI/CD pipeline changes

Data Classification Framework

CIA Platform Data Categories
Classification Levels (Hack23 ISMS)
│
├─ PUBLIC
│  ├─ Parliamentary voting records
│  ├─ Published committee documents
│  ├─ Official election results
│  └─ World Bank economic indicators
│
├─ INTERNAL
│  ├─ Aggregated analysis results
│  ├─ Risk scoring algorithms
│  ├─ Platform usage analytics
│  └─ System configuration data
│
├─ CONFIDENTIAL
│  ├─ User account credentials
│  ├─ Session tokens and API keys
│  ├─ Audit logs with user actions
│  └─ Internal security assessments
│
└─ RESTRICTED
   ├─ Database credentials
   ├─ Encryption keys (KMS)
   ├─ AWS access credentials
   └─ Security incident data
Classification Decision Tree
Data Classification Decision
│
├─→ Is it publicly available from official sources?
│   ├─ YES → PUBLIC
│   └─ NO ↓
│
├─→ Does it contain personal identifiers?
│   ├─ YES → CONFIDENTIAL (minimum)
│   └─ NO ↓
│
├─→ Is it a credential, key, or secret?
│   ├─ YES → RESTRICTED
│   └─ NO ↓
│
└─→ Is it internal analysis or configuration?
    ├─ YES → INTERNAL
    └─ NO → Assess case-by-case

GDPR Privacy by Design

Seven Principles Applied to CIA Platform
  1. Proactive, not reactive — Embed privacy into political data imports
  2. Privacy as default — Minimize personal data collection
  3. Privacy embedded in design — Use pseudonymization where possible
  4. Full functionality — Privacy without sacrificing analysis quality
  5. End-to-end security — Encrypt data at rest and in transit
  6. Visibility and transparency — Document all data processing activities
  7. Respect for user privacy — Provide data access and deletion mechanisms
Data Processing Patterns
java
// ✅ SECURE: Minimize personal data in analysis
@Service
public class PoliticianAnalysisService {

    public PoliticianSummary analyzePolitician(String personId) {
        // Only retrieve fields needed for analysis
        PoliticianData data = repository.findPublicDataById(personId);

        // Never include unnecessary personal details
        return PoliticianSummary.builder()
            .personId(personId)
            .votingRecord(data.getVotingRecord())
            .committeeAssignments(data.getCommittees())
            .partyAffiliation(data.getParty())
            .build();
        // Excluded: personal address, phone, private email
    }
}

// ❌ INSECURE: Over-collection of personal data
public PoliticianData getAllPersonalData(String personId) {
    return repository.findById(personId); // Returns ALL fields
}
Data Subject Rights Implementation
GDPR RightCIA Platform Implementation
Right to access (Art. 15)User data export endpoint
Right to rectification (Art. 16)Profile update mechanism
Right to erasure (Art. 17)Account deletion with cascade
Right to restrict (Art. 18)Account deactivation option
Right to portability (Art. 20)JSON/CSV data export
Right to object (Art. 21)Opt-out of analytics processing
Show full SKILL.md (158 more words)Show less

Encryption Standards

Data at Rest
Encryption Requirements by Classification
│
├─ PUBLIC → No encryption required
├─ INTERNAL → AES-256 recommended
├─ CONFIDENTIAL → AES-256 required (AWS KMS)
└─ RESTRICTED → AES-256 + envelope encryption (KMS CMK)
Data in Transit
  • TLS 1.2+ for all HTTP connections
  • Certificate pinning for external API calls
  • mTLS for internal service communication
  • HSTS headers enforced
Database Encryption
java
// Column-level encryption for sensitive fields
@Entity
@Table(name = "application_user")
public class ApplicationUser {

    @Column(name = "username")
    private String username; // PUBLIC - no encryption

    @Column(name = "email")
    @Convert(converter = EncryptedStringConverter.class)
    private String email; // CONFIDENTIAL - encrypted

    @Column(name = "password_hash")
    private String passwordHash; // Already hashed (bcrypt)
}

Data Lifecycle Management

Retention Policies
Data TypeRetention PeriodAction at Expiry
Voting recordsIndefiniteArchive (public record)
User sessions30 daysAutomatic deletion
Audit logs2 yearsArchive to cold storage
User accountsUntil deletion requestAnonymize + delete
API cache24 hoursAutomatic expiry
Analytics data1 yearAggregate + anonymize
Secure Deletion
java
// Implement secure deletion for user data
@Service
public class DataDeletionService {

    @Transactional
    public void deleteUserAccount(Long userId) {
        // 1. Remove personal data
        userRepository.anonymizeUser(userId);

        // 2. Delete session data
        sessionRepository.deleteByUserId(userId);

        // 3. Audit the deletion (GDPR compliance)
        auditService.logDeletion(userId, "GDPR erasure request");

        // 4. Remove from caches
        cacheManager.evict("user:" + userId);
    }
}

ISMS Alignment

ControlRequirementImplementation
ISO 27001 A.5.12Classification of informationData classification labels
ISO 27001 A.5.33Protection of recordsRetention policy enforcement
ISO 27001 A.8.10Information deletionSecure deletion procedures
ISO 27001 A.8.24Use of cryptographyAES-256, TLS 1.2+
NIST CSF PR.DSData securityEncryption at rest/transit
GDPR Art. 25Data protection by designPrivacy impact assessments

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/data-protection of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Data Protection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Data Protection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Data Protection this skillHack23/cia239—~1.8kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    939 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    939 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Questions about Data Protection

What does Data Protection do?

Data classification (CIA triad), GDPR privacy by design, encryption standards, data lifecycle management. Data Protection is an agent skill from Hack23/cia.

When should I use Data Protection?

Data Protection fits situations like: tasks that involve Privacy and GDPR.

How do I install Data Protection in Claude Code?

Run `npx skills add Hack23/cia --skill data-protection -a claude-code`. Or copy the skill folder (.github/skills/data-protection in Hack23/cia) into .claude/skills/data-protection in your project. Claude Code loads it when a task matches its description.

How do I install Data Protection in Codex?

Run `npx skills add Hack23/cia --skill data-protection -a codex`. Or copy the skill folder (.github/skills/data-protection in Hack23/cia) into .agents/skills/data-protection in your project. Codex loads it when a task matches its description.

Can I use Data Protection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill data-protection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/data-protection, .gemini/skills/data-protection, .github/skills/data-protection and .opencode/skills/data-protection in your project.

What does Data Protection need to run?

SKILL.md names no scripts, command-line tools or credentials: Data Protection is instructions for the agent only.

Does Data Protection access the network?

SKILL.md names 3 domains. As links in the text: github.com, gdpr-info.eu and csrc.nist.gov. This is read from the text; nothing was executed.

Is Data Protection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Data Protection use?

Data Protection is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Data Protection use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Data Protection?

Skills that share tags, products or a category with Data Protection: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Data Protection?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.