Implement data privacy, PII handling, and compliance patterns for Claude API.

MITAuto-check passedLegal & Compliance

Install Anth Data Handling

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill anth-data-handling -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace anth-data-handling --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/anth-data-handling .claude/skills/anth-data-handling && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
anth-data-handling
GitHub stars
2.8k
Token cost
~1.7k tokens
SKILL.md length
464 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Implement data privacy, PII handling, and compliance patterns for Claude API.

  • Works in 5 steps: Classify the input and reject fields… → Run the redaction, prompt, and response… → Call the Messages API with the… → …
  • Handling sensitive data
  • SKILL.md covers Overview, Anthropic Data Policies, PII Redaction Before API Calls and Audit Logging, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Anth Data Handling is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement data privacy, PII handling, and compliance patterns for Claude API. Use when handling sensitive data, implementing PII redaction, or configuring data retention for GDPR/CCPA compliance with Claude. Trigger with phrases like "anthropic data privacy", "claude PII", "anthropic gdpr", "claude data handling", "redact data claude".

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Privacy and GDPR and LLM API integration. It works with Anthropic API. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Handling sensitive data
  • Implementing PII redaction
  • Configuring data retention for GDPR/CCPA compliance with Claude
  • With phrases like anthropic data privacy

Example prompts

  • “anthropic data privacy”
  • “claude PII”
  • “anthropic gdpr”
  • “/anth-data-handling”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Classify the input and reject fields outside the approved purpose or destination. Apply deterministic redaction before constructing the…
  2. Run the redaction, prompt, and response scanners against synthetic fixtures. A failed scan, missing consent, or unexpected content block…
  3. Call the Messages API with the least-privileged credential and only the approved model, workspace, and retention configuration. Do not…
  4. Scan the response before restoration or release. Record only aggregate counts, policy decisions, request identifier, and token metadata…
  5. Verify deletion in the sandbox and retain a redacted audit receipt for the owner and compliance reviewer.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • anthropic.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Anth Data Handling loads about 1.7k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 464 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 464 words, ~1,692 tokens.

Download SKILL.mdSave it as .claude/skills/anth-data-handling/SKILL.md (or your agent's skills folder).
name
anth-data-handling
description
Implement data privacy, PII handling, and compliance patterns for Claude API. Use when handling sensitive data, implementing PII redaction, or configuring data retention for GDPR/CCPA compliance with Claude. Trigger with phrases like "anthropic data privacy", "claude PII", "anthropic gdpr", "claude data handling", "redact data claude".
allowed-tools
Read, Write, Edit, Grep
compatibility
Designed for Claude Code
version
1.7.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, ai, anthropic

Anthropic Data Handling

Overview

Anthropic's data policies: API inputs/outputs are NOT used for model training (commercial API). Zero-day retention is available. This skill covers PII redaction before sending to Claude and compliance patterns.

Anthropic Data Policies

PolicyDetails
Training dataAPI data is NOT used for training (commercial API)
Data retention30-day default; 0-day available via agreement
EncryptionTLS 1.2+ in transit, AES-256 at rest
SOC 2 Type IICertified
HIPAA BAAAvailable for eligible customers

PII Redaction Before API Calls

python
import re
import anthropic

def redact_pii(text: str) -> tuple[str, dict]:
    """Redact PII before sending to Claude, return redaction map for restoration."""
    redaction_map = {}
    patterns = [
        (r'\b\d{3}-\d{2}-\d{4}\b', 'SSN', '[SSN-REDACTED-{}]'),
        (r'\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b', 'EMAIL', '[EMAIL-REDACTED-{}]'),
        (r'\b\d{3}[-.]?\d{3}[-.]?\d{4}\b', 'PHONE', '[PHONE-REDACTED-{}]'),
        (r'\b\d{4}[- ]?\d{4}[- ]?\d{4}[- ]?\d{4}\b', 'CARD', '[CARD-REDACTED-{}]'),
    ]

    counter = 0
    for pattern, label, replacement in patterns:
        for match in re.finditer(pattern, text):
            counter += 1
            placeholder = replacement.format(counter)
            redaction_map[placeholder] = match.group()
            text = text.replace(match.group(), placeholder, 1)

    return text, redaction_map

def restore_pii(text: str, redaction_map: dict) -> str:
    """Restore redacted PII in Claude's response."""
    for placeholder, original in redaction_map.items():
        text = text.replace(placeholder, original)
    return text

# Usage
user_input = "Contact John at john@example.com or 555-123-4567"
safe_input, redactions = redact_pii(user_input)
# safe_input: "Contact John at [EMAIL-REDACTED-1] or [PHONE-REDACTED-2]"

client = anthropic.Anthropic()
msg = client.messages.create(
    model="claude-sonnet-4-20250514",
    max_tokens=256,
    messages=[{"role": "user", "content": safe_input}]
)
final_output = restore_pii(msg.content[0].text, redactions)

Audit Logging

python
import json
import logging
from datetime import datetime, timezone

audit_logger = logging.getLogger("claude.audit")

def audited_request(client, user_id: str, purpose: str, **kwargs):
    """Wrap Claude API calls with audit logging."""
    # Log request metadata (never log content)
    audit_logger.info(json.dumps({
        "event": "claude.request",
        "timestamp": datetime.now(timezone.utc).isoformat(),
        "user_id": user_id,
        "purpose": purpose,
        "model": kwargs.get("model"),
        "max_tokens": kwargs.get("max_tokens"),
    }))

    response = client.messages.create(**kwargs)

    audit_logger.info(json.dumps({
        "event": "claude.response",
        "request_id": response._request_id,
        "input_tokens": response.usage.input_tokens,
        "output_tokens": response.usage.output_tokens,
        "stop_reason": response.stop_reason,
    }))

    return response

Data Handling Checklist

  • PII redacted before sending to Claude API
  • Audit logs capture who accessed what and when
  • Logs never contain message content or PII
  • Data retention policy matches your compliance needs
  • Zero-day retention enabled if required (contact Anthropic)
  • HIPAA BAA in place if handling PHI
  • User consent obtained for AI processing
  • Data deletion procedures documented

Error Handling

RiskMitigation
PII in promptsPre-call redaction pipeline
PII in responsesPost-call output scanning
Audit log gapsCentralized logging with alerting
Data subject access requestSearchable audit trail by user_id

Prerequisites

  • Define the data classification, processing purpose, legal basis or user consent, and retention owner before sending anything to the API.
  • Provide an approved redaction policy, a secret-manager-backed API credential, and an allowlisted Anthropic workspace or service boundary.
  • Prepare synthetic fixtures that exercise each PII class and a deletion test; do not use real customer records while validating the pipeline.
Show full SKILL.md (233 more words)Show less

Instructions

  1. Classify the input and reject fields outside the approved purpose or destination. Apply deterministic redaction before constructing the request; keep any restoration map encrypted, access-controlled, and short-lived.
  2. Run the redaction, prompt, and response scanners against synthetic fixtures. A failed scan, missing consent, or unexpected content block is a hard stop; do not retry with the original data.
  3. Call the Messages API with the least-privileged credential and only the approved model, workspace, and retention configuration. Do not place prompts, responses, redaction maps, or secrets in logs, traces, metrics, or exception text.
  4. Scan the response before restoration or release. Record only aggregate counts, policy decisions, request identifier, and token metadata, then enforce the documented retention and deletion procedure.
  5. Verify deletion in the sandbox and retain a redacted audit receipt for the owner and compliance reviewer.

Output

Produce a redacted data-handling receipt containing the purpose, policy version, environment, workspace class, redaction and response-scan outcomes, request identifier, token counts, retention deadline, deletion result, and reviewer. Exclude names, contact details, prompt/response text, raw identifiers, redaction maps, and credentials.

Examples

For a synthetic fixture such as customer_id=fixture-017; email=test@example.invalid; purpose=classification, redact the email, call a sandbox workspace, assert raw_pii_sent=0 and sensitive_content_logged=0, and emit redaction=pass; output_scan=pass; retention=24h; deletion=verified. Never substitute a real person or production record in this example.

Resources

Next Steps

For enterprise access control, see anth-enterprise-rbac.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/.curated/anth-data-handling of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Anth Data Handling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Anth Data Handling compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Anth Data Handling this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: PassMIT
Claude Cookbooks Reference2025Emma/vibe-coding-cn23k1 repos~2.2kAutomated safety check: PassMIT
ModLens Image Vision Bridgeliustack/modlens4.2k—~1.3kAutomated safety check: NotesMIT
Claude APIKocoro-lab/Kocoro4147 repos~4.5kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Claude Cookbooks Reference

    2025Emma/vibe-coding-cn

    Reference of Claude API examples and guides covering tool use, vision, RAG, classification, summarization, text-to-SQL, prompt caching and agent patterns.

    23k GitHub starsUsed in 1 repo~2.2k tokens
    AI & LLM EngineeringAuto-check passed
  • Gives text-only models sight by running the modlens CLI on an image path or URL and returning structured JSON evidence with transcribed text, layout and semantics.

    4.2k GitHub stars~1.3k tokensUpdated 7 days ago
    AI & LLM EngineeringAuto-check: notes
  • Claude API

    Kocoro-lab/Kocoro

    Build apps with the Claude API or Anthropic SDK. An agent skill from Kocoro-lab/Kocoro.

    414 GitHub starsUsed in 7 repos~4.5k tokens
    AI & LLM EngineeringAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Using Ccproxy Inspector

    starbaser/ccproxy

    Operates the ccproxy inspector MITM system for intercepting, inspecting, and transforming LLM API traffic.

    350 GitHub stars~2.7k tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Anth Data Handling

What does Anth Data Handling do?

Implement data privacy, PII handling, and compliance patterns for Claude API. Anth Data Handling is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement data privacy, PII handling, and compliance patterns for Claude API.

When should I use Anth Data Handling?

Anth Data Handling fits situations like: handling sensitive data; implementing PII redaction; configuring data retention for GDPR/CCPA compliance with Claude; with phrases like anthropic data privacy.

How do I install Anth Data Handling in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill anth-data-handling -a claude-code`. Or copy the skill folder (skills/.curated/anth-data-handling in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/anth-data-handling in your project. Claude Code loads it when a task matches its description.

How do I install Anth Data Handling in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill anth-data-handling -a codex`. Or copy the skill folder (skills/.curated/anth-data-handling in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/anth-data-handling in your project. Codex loads it when a task matches its description.

Can I use Anth Data Handling in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill anth-data-handling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/anth-data-handling, .gemini/skills/anth-data-handling, .github/skills/anth-data-handling and .opencode/skills/anth-data-handling in your project.

What does Anth Data Handling need to run?

SKILL.md names no scripts, command-line tools or credentials: Anth Data Handling is instructions for the agent only. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Anth Data Handling access the network?

SKILL.md names 1 domain. As links in the text: anthropic.com. This is read from the text; nothing was executed.

Is Anth Data Handling safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Anth Data Handling use?

Anth Data Handling is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Anth Data Handling use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Anth Data Handling?

Skills that share tags, products or a category with Anth Data Handling: Claude Cookbooks Reference (2025Emma/vibe-coding-cn, 23k stars), ModLens Image Vision Bridge (liustack/modlens, 4.2k stars), Claude API (Kocoro-lab/Kocoro, 414 stars) and C15t (c15t/c15t, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Anth Data Handling?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.