Agent skill

Pipl Gdpr Crosswalk

by mohitagw15856 in mohitagw15856/pm-claude-skills

Compare China's Personal Information Protection Law (PIPL) with the EU GDPR for a specific data flow, and produce the gap list and cross-border transfer path for a company operating in both.

MITAuto-check passedLegal & Compliance

Install Pipl Gdpr Crosswalk

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill pipl-gdpr-crosswalk -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills pipl-gdpr-crosswalk --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pipl-gdpr-crosswalk .claude/skills/pipl-gdpr-crosswalk && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pipl-gdpr-crosswalk
GitHub stars
1.4k
Token cost
~1.3k tokens
SKILL.md length
631 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Compare China's Personal Information Protection Law (PIPL) with the EU GDPR for a specific data flow, and produce the gap list and cross-border transfer path for a company operating in both.

  • Works in 4 steps: Classify the flow: which data, which… → Choose the transfer mechanism for each… → List gaps: what the company does today… → …
  • Asked PIPL vs GDPR
  • SKILL.md covers What This Skill Produces, Required Inputs, Framework and Output Format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Pipl Gdpr Crosswalk is an agent skill from mohitagw15856/pm-claude-skills. Compare China's Personal Information Protection Law (PIPL) with the EU GDPR for a specific data flow, and produce the gap list and cross-border transfer path for a company operating in both. Use when asked PIPL vs GDPR, 个人信息保护法和 GDPR 的区别, how do we transfer personal data out of China, our app serves users in China and Europe, or 数据出境 compliance. Produces a requirement crosswalk for the described processing, the transfer mechanism that likely applies in each direction, a prioritised gap list, and the questions to…

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked PIPL vs GDPR
  • 个人信息保护法和 GDPR 的区别
  • How do we transfer personal data out of China
  • Our app serves users in China and Europe

Example prompts

  • “/pipl-gdpr-crosswalk”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Classify the flow: which data, which direction, which volume band.
  2. Choose the transfer mechanism for each direction and list its documents.
  3. List gaps: what the company does today against what each regime requires.
  4. Prioritise by likelihood of enforcement and harm: transfers and sensitive data first.

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pipl Gdpr Crosswalk loads about 1.3k tokens when it runs. Until then it costs about 143 tokens; SKILL.md has 631 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~143
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 631 words, ~1,301 tokens.

Download SKILL.mdSave it as .claude/skills/pipl-gdpr-crosswalk/SKILL.md (or your agent's skills folder).
name
pipl-gdpr-crosswalk
description
Compare China's Personal Information Protection Law (PIPL) with the EU GDPR for a specific data flow, and produce the gap list and cross-border transfer path for a company operating in both. Use when asked PIPL vs GDPR, 个人信息保护法和 GDPR 的区别, how do we transfer personal data out of China, our app serves users in China and Europe, or 数据出境 compliance. Produces a requirement crosswalk for the described processing, the transfer mechanism that likely applies in each direction, a prioritised gap list, and the questions to take to counsel. Not legal advice.
version
1.0.0

PIPL and GDPR Crosswalk

Companies serving users in both China and Europe face two strict regimes that look alike and differ in the details that matter: consent, sensitive data, and above all moving data across borders. This skill maps one described data flow against both, identifies the transfer path, and lists the gaps to close, so the conversation with counsel starts from specifics.

Part of the pm-chuhai bundle. For a general framework checklist, see compliance-checklist.

What This Skill Produces

  • A crosswalk for the described processing: each requirement under PIPL and GDPR, and what the company must do
  • The transfer path in each direction (China to abroad, EU to China)
  • A gap list, prioritised by risk
  • Questions for counsel

Required Inputs

Ask for these if not provided:

  • The data flow: what personal information, about whom, collected where, stored where, accessed from where
  • Volumes: roughly how many individuals per year, and whether any sensitive information is involved
  • The entities: where the company and its processors are established
  • The purpose of processing and the legal basis currently relied on

Framework

Compare on these points. State each as a general description and mark it "verify current text", because implementing rules change.

PointPIPL (China)GDPR (EU)
Legal basesConsent and several other bases (contract, legal duty, emergencies, news reporting, public information, HR management); no general "legitimate interests" basisSix bases, including legitimate interests
Separate consentRequired for sensitive information, transfers abroad, public disclosure, sharing with another handler, and some image or ID usesExplicit consent for special categories when consent is the basis
Sensitive informationBroad, including financial accounts, location tracking, and all data of minors under 14Special categories (health, biometrics, beliefs and others)
Transfer abroadOne of: CAC security assessment, the standard contract, or certification, depending on volume and data type; a personal information protection impact assessment; separate consent. Exemptions introduced in 2024 for some lower-volume and necessary transfers: verify current thresholdsAdequacy decision, standard contractual clauses with a transfer impact assessment, binding corporate rules, or derogations
Local representativeRequired for overseas handlers processing data of people in China in scopeArticle 27 representative for non-EU controllers in scope
Data protection officerRequired above set volume thresholdsRequired in defined cases
Breach notificationPromptly to the authority and individualsWithin 72 hours to the authority where required

Then:

  1. Classify the flow: which data, which direction, which volume band.
  2. Choose the transfer mechanism for each direction and list its documents.
  3. List gaps: what the company does today against what each regime requires.
  4. Prioritise by likelihood of enforcement and harm: transfers and sensitive data first.
Show full SKILL.md (196 more words)Show less

Output Format

PIPL and GDPR crosswalk: [company], [data flow]

1. Flow summary (data, people, locations, volume) 2. Crosswalk | Requirement | PIPL | GDPR | What we must do | 3. Transfer path | Direction | Mechanism | Documents | Verify | 4. Gap list | Gap | Regime | Priority | Fix | 5. Questions for counsel

End verbatim: "This is a structured starting point, not legal advice. Data transfer rules in China and the EU change through implementing regulations; confirm every point with qualified counsel in both jurisdictions."

Quality Checks

  • Every row that depends on thresholds or recent rules is marked "verify"
  • The transfer mechanism is identified for each direction separately
  • Sensitive information and minors' data are explicitly checked
  • Gaps are prioritised with transfers and sensitive data first
  • The disclaimer appears verbatim

Anti-Patterns

  • Treating PIPL as "GDPR in China". Legal bases and transfer rules differ materially.
  • Quoting volume thresholds as settled. They have changed; verify.
  • Forgetting the EU to China direction. It has its own requirements.
  • Giving a compliance verdict. Map, prioritise and hand to counsel.

Example Trigger Phrases

  • "我们的 App 同时服务中国和欧洲用户,数据出境要怎么做?"
  • "Compare PIPL and GDPR for our HR data flow from Shanghai to Dublin."
  • "个人信息保护法和 GDPR 有什么关键区别?"
  • "What do we need to transfer customer data out of China?"

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/pipl-gdpr-crosswalk of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Pipl Gdpr Crosswalk next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pipl Gdpr Crosswalk compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pipl Gdpr Crosswalk this skillmohitagw15856/pm-claude-skills1.4k—~1.3kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Pipl Gdpr Crosswalk

What does Pipl Gdpr Crosswalk do?

Compare China's Personal Information Protection Law (PIPL) with the EU GDPR for a specific data flow, and produce the gap list and cross-border transfer path for a company operating in both. Pipl Gdpr Crosswalk is an agent skill from mohitagw15856/pm-claude-skills. Compare China's Personal Information Protection Law (PIPL) with the EU GDPR for a specific data flow, and produce the gap list and cross-border transfer path for a company operating in both.

When should I use Pipl Gdpr Crosswalk?

Pipl Gdpr Crosswalk fits situations like: asked PIPL vs GDPR; 个人信息保护法和 GDPR 的区别; how do we transfer personal data out of China; our app serves users in China and Europe.

How do I install Pipl Gdpr Crosswalk in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill pipl-gdpr-crosswalk -a claude-code`. Or copy the skill folder (skills/pipl-gdpr-crosswalk in mohitagw15856/pm-claude-skills) into .claude/skills/pipl-gdpr-crosswalk in your project. Claude Code loads it when a task matches its description.

How do I install Pipl Gdpr Crosswalk in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill pipl-gdpr-crosswalk -a codex`. Or copy the skill folder (skills/pipl-gdpr-crosswalk in mohitagw15856/pm-claude-skills) into .agents/skills/pipl-gdpr-crosswalk in your project. Codex loads it when a task matches its description.

Can I use Pipl Gdpr Crosswalk in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill pipl-gdpr-crosswalk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pipl-gdpr-crosswalk, .gemini/skills/pipl-gdpr-crosswalk, .github/skills/pipl-gdpr-crosswalk and .opencode/skills/pipl-gdpr-crosswalk in your project.

What does Pipl Gdpr Crosswalk need to run?

SKILL.md names no scripts, command-line tools or credentials: Pipl Gdpr Crosswalk is instructions for the agent only.

Does Pipl Gdpr Crosswalk access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pipl Gdpr Crosswalk safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pipl Gdpr Crosswalk use?

Pipl Gdpr Crosswalk is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pipl Gdpr Crosswalk use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pipl Gdpr Crosswalk?

Skills that share tags, products or a category with Pipl Gdpr Crosswalk: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pipl Gdpr Crosswalk?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.