Agent skill

Pseudonymizing For Gdpr

by maziyarpanahi in maziyarpanahi/openmed

Apply GDPR-grade pseudonymization to clinical or personal text with OpenMed, keeping a separately-held re-linkage key so the data can be controlled-re-linked later.

Apache-2.0Auto-check passedLegal & Compliance

Install Pseudonymizing For Gdpr

skills CLI
$ npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maziyarpanahi/openmed pseudonymizing-for-gdpr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pseudonymizing-for-gdpr .claude/skills/pseudonymizing-for-gdpr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pseudonymizing-for-gdpr
GitHub stars
5.5k
Token cost
~2k tokens
SKILL.md length
785 words
Files
1
Skills in repo
74
Repo updated
First seen
Licence
Apache-2.0

At a glance

Apply GDPR-grade pseudonymization to clinical or personal text with OpenMed, keeping a separately-held re-linkage key so the data can be controlled-re-linked later.

  • Works in 5 steps: Choose reversible pseudonymization, not… → Split the data from the key immediately.… → Process the pseudonymized text freely.… → …
  • The user must process EU personal/health data under GDPR
  • SKILL.md covers When to use, Quick start, Workflow and Hand-off to / from OpenMed, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Pseudonymizing For Gdpr is an agent skill from maziyarpanahi/openmed. Apply GDPR-grade pseudonymization to clinical or personal text with OpenMed, keeping a separately-held re-linkage key so the data can be controlled-re-linked later. Use when the user must process EU personal/health data under GDPR, asks for pseudonymization vs anonymization, needs Art. 4(5) / Art. 9 / Recital 26 alignment, wants a reversible mapping/key vault held apart from the data, or needs controlled re-linkage. Covers openmed.deidentify(policy="gdprpseudonymization", keepmapping=True), storing the mapping in…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Local-first healthcare AI: clinical NER & HIPAA PII de-identification that runs 100% on-device. 2,200+ medical models, 21 languages, Apple MLX + Python, no cloud, no patient data…. The licence is Apache-2.0.

When your agent uses it

  • The user must process EU personal/health data under GDPR
  • Asks for pseudonymization vs anonymization

Example prompts

  • “gdprpseudonymization”
  • “/pseudonymizing-for-gdpr”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Choose reversible pseudonymization, not masking. Use method="replace"
  2. Split the data from the key immediately. The moment deidentify returns,
  3. Process the pseudonymized text freely. Run analyze_text, analytics,
  4. Re-link only under authorization. When a lawful basis exists (e.g. an
  5. Apply retention to the key. The mapping has its own retention clock. When

What it can do on your machine

Read from SKILL.md and the folder at commit 6b1bb2c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • gdpr-info.eu
    • enisa.europa.eu
    • edpb.europa.eu

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pseudonymizing For Gdpr loads about 2k tokens when it runs. Until then it costs about 173 tokens; SKILL.md has 785 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~173
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from maziyarpanahi/openmed at commit 6b1bb2c, republished under its Apache-2.0 licence (© maziyarpanahi). 785 words, ~1,973 tokens.

Download SKILL.mdSave it as .claude/skills/pseudonymizing-for-gdpr/SKILL.md (or your agent's skills folder).
name
pseudonymizing-for-gdpr
description
Apply GDPR-grade pseudonymization to clinical or personal text with OpenMed, keeping a separately-held re-linkage key so the data can be controlled-re-linked later. Use when the user must process EU personal/health data under GDPR, asks for pseudonymization vs anonymization, needs Art. 4(5) / Art. 9 / Recital 26 alignment, wants a reversible mapping/key vault held apart from the data, or needs controlled re-linkage. Covers openmed.deidentify(policy="gdpr_pseudonymization", keep_mapping=True), storing the mapping in a separate key vault, reidentify() for authorized re-linkage, and retention. Pairs after extracting-pii-entities and configuring-privacy-policies.
license
Apache-2.0
metadata.project
OpenMed
metadata.category
de-identification
metadata.pairs
after
metadata.version
1.0

Pseudonymizing for GDPR

Pseudonymization under the GDPR (Art. 4(5)) means processing personal data so it "can no longer be attributed to a specific data subject without the use of additional information" — provided that additional information (the re-linkage key) is "kept separately and is subject to technical and organisational measures." Crucially, pseudonymized data is still personal data (Recital 26): re-linkage is possible, so GDPR still applies. This is the opposite of anonymization, where re-identification is irreversibly prevented and the data falls outside the GDPR.

OpenMed implements this with a single reversible de-identification pass plus a mapping you store away from the data. This skill covers producing that mapping, vaulting the key separately, and re-linking under authorization.

When to use

  • You process EU residents' personal or special-category health data (Art. 9) and need a lawful, reversible safeguard rather than full anonymization.
  • You need to keep a record-linkage capability (e.g. to recontact a patient, reconcile longitudinal records, or honor a Subject Access Request) but must separate the linkage key from the working dataset.
  • A reviewer asks for the pseudonymization-vs-anonymization distinction in writing, or for the ENISA-style "additional information kept separately" control to be demonstrable.

Do not use this when the goal is irreversible anonymization for open release — there, drop the mapping entirely and gate residual risk with reviewing-reidentification-risk. Pseudonymization keeps a key; anonymization must not.

Quick start

python
import openmed

# Synthetic record — never run this skill's examples on real PHI.
note = "Patient Maria Schmidt (ID 4471) seen 2024-03-02; contact maria@example.de."

result = openmed.deidentify(
    note,
    method="replace",                 # realistic surrogates, not [LABEL] holes
    policy="gdpr_pseudonymization",   # bundled GDPR profile
    keep_mapping=True,                # produce the reversible re-linkage map
    consistent=True,                  # same input -> same surrogate in the doc
    seed=20240302,                    # cross-run reproducibility of surrogates
)

pseudonymized_text = result.deidentified_text   # safe to process / analyze
relink_key = result.mapping                      # surrogate -> original; SECRET

result.deidentified_text is the pseudonymized payload. result.mapping is the "additional information" GDPR Art. 4(5) requires be kept separately — it is the key that makes re-linkage possible, and therefore the most sensitive artifact in the whole flow.

Workflow

  1. Choose reversible pseudonymization, not masking. Use method="replace" with policy="gdpr_pseudonymization" and keep_mapping=True. Replacement surrogates keep the text usable for downstream NLP while remaining non-identifying. consistent=True (optionally with seed=) makes repeated mentions resolve to one stable surrogate so intra-document linkage survives.
  2. Split the data from the key immediately. The moment deidentify returns, route result.deidentified_text to your working store and result.mapping to a separate, access-controlled key vault — different system, different credentials, different backups. Never persist them in the same row, file, bucket, or log line. This separation is the technical-and-organisational measure that makes the data pseudonymized rather than just "personal data with PII in it."
  3. Process the pseudonymized text freely. Run analyze_text, analytics, model training, or transfer on deidentified_text. The key never leaves the vault during ordinary processing.
  4. Re-link only under authorization. When a lawful basis exists (e.g. an authorized SAR or recontact), fetch the mapping from the vault and call openmed.reidentify(deidentified_text, mapping). Log that a re-linkage happened (who, when, why, record id) — but never log the restored plaintext.
  5. Apply retention to the key. The mapping has its own retention clock. When the lawful basis for re-linkage ends, destroy the mapping. Once the key is irreversibly gone and no other re-identification path remains, the remaining text approaches anonymization and GDPR obligations shrink accordingly. Verify that claim with reviewing-reidentification-risk before relying on it.
Show full SKILL.md (301 more words)Show less

Hand-off to / from OpenMed

  • From extracting-pii-entities / configuring-privacy-policies: confirm the detector recall and the active policy profile before pseudonymizing, since any identifier the detector misses leaks into deidentified_text.
  • OpenMed call: Python from openmed import deidentify, reidentify; the same capability is exposed as MCP tool openmed_deidentify and REST /deidentify. Pass policy="gdpr_pseudonymization", keep_mapping=True.
  • To auditing-deid-leakage: scan result.deidentified_text for residual identifiers before it leaves the boundary — pseudonymization is only as strong as detection.
  • To reviewing-reidentification-risk: quasi-identifier (age, ZIP, dates) re-identification still applies to pseudonymized data; score k-anonymity on the output and document residual risk.

Edge cases & gotchas

  • Pseudonymized ≠ anonymized. As long as mapping exists anywhere, the data is personal data under Recital 26. Do not market a keep_mapping=True output as "anonymous."
  • The mapping is the crown jewel. A leaked mapping re-identifies everything at once. Treat it as the highest-sensitivity secret: encrypt at rest, restrict access, audit reads.
  • Surrogates can still carry quasi-identifiers. method="replace" swaps the identifier text, but free-text age, rare diagnosis, ZIP, or admission dates remain. Pseudonymization does not address singling-out; pair with QI risk scoring.
  • Reproducibility cuts both ways. A fixed seed makes surrogates stable across runs (good for linkage) but means an attacker who learns the seed and algorithm can reproduce surrogates — keep the seed with the key, not the data.
  • Special-category data (Art. 9). Health data needs a lawful basis before processing; pseudonymization is a safeguard, not a lawful basis on its own.
  • Local-first. Run entirely on-device. Do not send EU personal data to a cloud de-identification service to satisfy GDPR — that may itself be a transfer.

Standards & references

© maziyarpanahi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/pseudonymizing-for-gdpr of maziyarpanahi/openmed.

Open the folder on GitHubat commit 6b1bb2c

Compare with similar skills

Pseudonymizing For Gdpr next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pseudonymizing For Gdpr compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pseudonymizing For Gdpr this skillmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.3kAutomated safety check: PassMIT
Pii Contract Analyzegregmos/PII-Shield149—~8.9kAutomated safety check: NotesMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes
  • Gdpr Compliance Checker

    goSprinto/compliance-skills

    Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…

    133 GitHub stars~8.6k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes

More from maziyarpanahi/openmed

All 74 skills in this repo
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • OpenMed Model Card Writer

    maziyarpanahi/openmed

    Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.

    5.5k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • ICD-10 Coding Assistant

    maziyarpanahi/openmed

    Suggests candidate ICD-10-CM diagnosis and ICD-10-PCS procedure codes for clinical text extracted by OpenMed, with rationale for a certified coder to review.

    5.5k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • OpenMed ETL to OMOP CDM

    maziyarpanahi/openmed

    Maps OpenMed-extracted, terminology-coded conditions, drugs and measurements into OMOP CDM v5.4 tables for OHDSI and ATLAS analytics.

    5.5k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Extracting SDOH and Z-Codes

    maziyarpanahi/openmed

    Finds social risks such as housing instability or food insecurity in clinical notes and proposes matching ICD-10-CM Z-codes for a coder to confirm.

    5.5k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed

Questions about Pseudonymizing For Gdpr

What does Pseudonymizing For Gdpr do?

Apply GDPR-grade pseudonymization to clinical or personal text with OpenMed, keeping a separately-held re-linkage key so the data can be controlled-re-linked later. Pseudonymizing For Gdpr is an agent skill from maziyarpanahi/openmed. Apply GDPR-grade pseudonymization to clinical or personal text with OpenMed, keeping a separately-held re-linkage key so the data can be controlled-re-linked later.

When should I use Pseudonymizing For Gdpr?

Pseudonymizing For Gdpr fits situations like: the user must process EU personal/health data under GDPR; asks for pseudonymization vs anonymization.

How do I install Pseudonymizing For Gdpr in Claude Code?

Run `npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a claude-code`. Or copy the skill folder (skills/pseudonymizing-for-gdpr in maziyarpanahi/openmed) into .claude/skills/pseudonymizing-for-gdpr in your project. Claude Code loads it when a task matches its description.

How do I install Pseudonymizing For Gdpr in Codex?

Run `npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a codex`. Or copy the skill folder (skills/pseudonymizing-for-gdpr in maziyarpanahi/openmed) into .agents/skills/pseudonymizing-for-gdpr in your project. Codex loads it when a task matches its description.

Can I use Pseudonymizing For Gdpr in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pseudonymizing-for-gdpr, .gemini/skills/pseudonymizing-for-gdpr, .github/skills/pseudonymizing-for-gdpr and .opencode/skills/pseudonymizing-for-gdpr in your project.

What does Pseudonymizing For Gdpr need to run?

SKILL.md names no scripts, command-line tools or credentials: Pseudonymizing For Gdpr is instructions for the agent only. Our summary lists: Python 3.

Does Pseudonymizing For Gdpr access the network?

SKILL.md names 3 domains. As links in the text: gdpr-info.eu, enisa.europa.eu and edpb.europa.eu. This is read from the text; nothing was executed.

Is Pseudonymizing For Gdpr safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pseudonymizing For Gdpr use?

Pseudonymizing For Gdpr is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pseudonymizing For Gdpr use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pseudonymizing For Gdpr?

Skills that share tags, products or a category with Pseudonymizing For Gdpr: C15t (c15t/c15t, 1.9k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars), Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars) and Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pseudonymizing For Gdpr?

maziyarpanahi (a GitHub user) maintains it in maziyarpanahi/openmed, which has 5,493 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on October 9, 2026.

Source: maziyarpanahi/openmed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.