Agent skill

AI Privacy Inference

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Managing privacy risks from AI-driven inferences about individuals including derived data classification, profiling under GDPR Art.

Apache-2.0Auto-check passedLegal & Compliance

Install AI Privacy Inference

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill ai-privacy-inference -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills ai-privacy-inference --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/ai-privacy-inference .claude/skills/ai-privacy-inference && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-privacy-inference
GitHub stars
301
Token cost
~3.5k tokens
SKILL.md length
1,636 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Managing privacy risks from AI-driven inferences about individuals including derived data classification, profiling under GDPR Art.

  • Works in 4 steps: Use appropriate mathematical or… → Implement appropriate technical and… → Correct inaccuracies and enable… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Legal Framework for AI…, Profiling Under GDPR Article 22 and Inference Accuracy and Quality…, plus 4 more sections
  • Runs Python scripts from its folder

What it does

AI Privacy Inference is an agent skill from mukul975/Privacy-Data-Protection-Skills. Managing privacy risks from AI-driven inferences about individuals including derived data classification, profiling under GDPR Art. 22, inference accuracy obligations, and controlling automated personality/behaviour predictions. Keywords: AI inference, derived data, profiling, automated predictions, GDPR.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Data analysis. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Data analysis

Example prompts

  • “/ai-privacy-inference”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Use appropriate mathematical or statistical procedures for profiling
  2. Implement appropriate technical and organisational measures to minimise the risk of errors
  3. Correct inaccuracies and enable rectification
  4. Secure personal data to prevent discriminatory effects

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Privacy Inference loads about 3.5k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 1,636 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,636 words, ~3,495 tokens.

Download SKILL.mdSave it as .claude/skills/ai-privacy-inference/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
ai-privacy-inference
description
Managing privacy risks from AI-driven inferences about individuals including derived data classification, profiling under GDPR Art. 22, inference accuracy obligations, and controlling automated personality/behaviour predictions. Keywords: AI inference, derived data, profiling, automated predictions, GDPR.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
ai-privacy-governance
metadata.tags
ai-inference, derived-data, profiling, automated-predictions, gdpr-art-22

AI Privacy Inference and Derived Data

Overview

AI systems routinely generate inferences about individuals — predictions about creditworthiness, health risks, personality traits, political opinions, or behavioural patterns that were never directly provided by the data subject. These AI-derived inferences raise critical privacy questions: Are inferences personal data? When does inference become profiling under GDPR Article 22? What accuracy obligations apply to AI predictions? Can data subjects access, rectify, or object to inferences drawn about them? The CJEU, EDPB, and national DPAs have progressively clarified that inferences are personal data when they relate to an identified or identifiable person, and that GDPR rights extend to derived and inferred data. Cerebrum AI Labs must classify, govern, and provide transparency over all inferences its AI systems generate about individuals.

When Inferences Are Personal Data
CriterionAnalysisExample
Relates to an identified personInference is linked to a specific customer record or user profile"Customer C-12345 has 78% churn probability"
Relates to an identifiable personInference can be linked to a person through combination with other data"User with session token X-789 is likely aged 25-34"
Used to evaluate a personInference is used to assess, classify, or make decisions about someoneCredit score derived from transaction patterns
Has impact on a personInference affects how the person is treated or what options are availableInsurance premium adjusted based on predicted health risk

CJEU C-434/16 (Nowak, 2017): Personal data includes "any information" relating to a data subject — this encompasses opinions, assessments, and inferences, not only factual data directly provided by the individual.

EDPB Guidelines 8/2020 on Targeting of Social Media Users: Inferred data (data created by the controller through observation or derivation) constitutes personal data and is subject to the full scope of GDPR rights.

GDPR Classification of Inference Types
Inference TypeClassificationGDPR Implications
Observed dataData collected through direct interaction (browsing history, purchase records)Standard personal data — Art. 6 lawful basis required
Derived dataData created by the controller through computation on existing data (credit score, risk rating)Personal data — subject to access, rectification, objection rights
Inferred dataProbabilistic predictions about characteristics not directly observed (personality, health risk)Personal data — potentially special category if predicting Art. 9 characteristics
Aggregated dataStatistical outputs at group level, not linked to individualsNot personal data if truly anonymous (k-anonymity verified)
When Inferences Become Special Category Data
Predicted CharacteristicArt. 9 CategoryTrigger
Ethnic origin from name/location patternsRacial or ethnic originAny inference about ethnic background, even probabilistic
Political leaning from content engagementPolitical opinionsPrediction used to classify or target based on politics
Religious affiliation from purchase patternsReligious beliefsHalal/kosher purchase scoring, prayer time activity patterns
Health condition from behavioural signalsHealth dataStep count decline predicting depression, typing pattern analysis
Sexual orientation from browsing/social dataSexual orientationAny inference about sexual orientation regardless of accuracy
Pregnancy from purchase pattern shiftsHealth data + genderPurchase category analysis predicting pregnancy status

Cerebrum AI Labs Policy: Any inference that predicts, estimates, or classifies an Art. 9 characteristic — even indirectly or probabilistically — must be treated as special category data and requires an Art. 9(2) condition for processing.

Profiling Under GDPR Article 22

Profiling Definition (Art. 4(4))

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning:

  • Work performance
  • Economic situation
  • Health
  • Personal preferences
  • Interests
  • Reliability
  • Behaviour
  • Location
  • Movements
Three-Level Framework
LevelDescriptionGDPR RequirementCerebrum AI Labs Example
Profiling onlyAutomated evaluation without decisionArt. 6 lawful basis + Art. 13-14 transparencyCustomer segmentation for analytics dashboard
Profiling + human decisionAutomated evaluation informing a human decision-makerArt. 6 lawful basis + transparency + meaningful human involvementCredit risk score reviewed by loan officer
Solely automated decision with legal/significant effectsAutomated decision with no meaningful human involvement producing legal or similarly significant effectsArt. 22(1) prohibition applies — must fall within Art. 22(2) exceptionsAutomated loan rejection based solely on AI credit score
Art. 22(2) Exceptions Allowing Solely Automated Decisions
ExceptionRequirementCerebrum AI Labs Application
Art. 22(2)(a) — ContractDecision necessary for entering into or performing a contractAutomated credit pre-approval for existing customers
Art. 22(2)(b) — LawAuthorised by EU or Member State law with suitable safeguardsRegulatory-mandated fraud screening
Art. 22(2)(c) — Explicit consentData subject's explicit consent obtainedCustomer opts in to automated portfolio rebalancing
Safeguards Required (Art. 22(3))
SafeguardImplementation at Cerebrum AI Labs
Right to obtain human interventionEscalation button in customer portal routes to trained human reviewer within 2 business days
Right to express point of viewCustomer can submit additional context through contestation form before human review
Right to contest the decisionAppeal process with independent review panel; decision reversed if AI error demonstrated
Right to explanationIndividual explanation generated using SHAP values showing top 5 factors influencing the AI decision

Inference Accuracy and Quality Obligations

GDPR Article 5(1)(d) — Accuracy Principle

AI inferences must be accurate, and where necessary, kept up to date. For probabilistic predictions this means:

ObligationImplementation
Accuracy measurementTrack prediction accuracy metrics (precision, recall, F1) per demographic group
Confidence thresholdsDo not present inferences with confidence below 70% as actionable without human review
Staleness detectionRe-evaluate inferences when underlying data changes; flag inferences older than 90 days
Accuracy disclosureInform data subjects of the probabilistic nature and known accuracy of inferences
Rectification of inferencesAllow data subjects to challenge inferences; if input data is corrected, regenerate inference
EDPB Position on Inference Accuracy

The EDPB Guidelines on Automated Decision-Making (WP 251 rev.01) state that controllers must:

  1. Use appropriate mathematical or statistical procedures for profiling
  2. Implement appropriate technical and organisational measures to minimise the risk of errors
  3. Correct inaccuracies and enable rectification
  4. Secure personal data to prevent discriminatory effects

Transparency Requirements for AI Inferences

Show full SKILL.md (663 more words)Show less
Art. 13-14 Information Requirements
InformationRequirementCerebrum AI Labs Implementation
Existence of profilingInform data subjects that profiling occursPrivacy notice section: "How we use AI to analyse your data"
Logic involvedMeaningful information about the logic involvedTechnical explainer: "Our AI analyses your transaction patterns, account tenure, and product usage to predict service needs"
SignificanceEnvisaged consequences of such processing"This analysis may affect the products and offers shown to you, and may influence credit decisions"
Categories of data usedWhat data feeds the inference"We use: transaction history, account tenure, product holdings, service interactions"
Inference outputsWhat inferences are generated"We generate: churn probability, product affinity scores, credit risk indicators"
AI Act Transparency Requirements
ObligationAI Act ArticleCerebrum AI Labs Implementation
Inform users they are interacting with AIArt. 52(1)Chat interface disclosure: "You are interacting with an AI assistant"
Disclose AI-generated contentArt. 52(3)Outputs marked: "This recommendation was generated by AI"
Disclose emotion recognitionArt. 52(2)Not applicable — Cerebrum AI Labs does not use emotion recognition
High-risk system deployer transparencyArt. 13Technical documentation available to regulators on request

Inference Governance Framework

Cerebrum AI Labs Inference Registry

All AI systems that generate inferences about individuals must be registered in the Cerebrum AI Labs Inference Registry:

Registry FieldDescription
System IDUnique identifier for the AI system
Inference typeCategory of inference generated (behavioural, demographic, financial, health)
Data subjects affectedCategories and approximate volume of individuals profiled
Input featuresData elements used to generate the inference
Output formatInference output (score, category, probability, ranking)
Accuracy metricsLatest precision, recall, F1 by demographic group
Retention periodHow long inferences are stored before deletion
Art. 22 assessmentWhether the inference feeds a solely automated decision
Lawful basisArt. 6 and (if applicable) Art. 9 basis for generating the inference
DPIA referenceAssociated DPIA document ID
Inference Lifecycle Controls
PhaseControl
GenerationLog all inferences with timestamp, model version, confidence score, input data hash
StorageEncrypt inference outputs; apply access controls limiting who can read individual-level inferences
UsageTrack downstream consumption of inferences; prevent scope creep beyond documented purposes
DisclosureMake inferences available to data subjects on request (Art. 15 access right)
RectificationIf underlying data is corrected, flag dependent inferences for regeneration
DeletionDelete inferences per retention schedule (90 days operational, 12 months audit)

Enforcement and Regulatory Precedents

  • CJEU C-634/21 (SCHUFA, 2023): The CJEU held that the generation of a credit score by a private entity constitutes "automated individual decision-making" under Art. 22 if the score plays a decisive role in a subsequent decision by a third party. This means AI-derived scores used in downstream decisions may trigger Art. 22 protections even if the AI provider is not the final decision-maker.
  • Austrian DPA — Case DSB-D550.038 (2022): Found that inferred political opinions from social media activity constitute special category data under Art. 9, even when the inference is probabilistic and may be inaccurate.
  • Norwegian DPA — Grindr Decision (2021): NOK 65 million fine for sharing data enabling inference of sexual orientation. Established that data enabling inference of Art. 9 characteristics is itself special category data.
  • CNIL — Clearview AI (2022): EUR 20 million fine, finding that biometric inferences (face embeddings) from public photographs are personal data subject to full GDPR compliance.
  • GDPR Article 4(4) — Definition of profiling
  • GDPR Article 5(1)(d) — Accuracy principle
  • GDPR Article 13(2)(f) — Right to information about profiling logic and significance
  • GDPR Article 15(1)(h) — Right of access to profiling information
  • GDPR Article 22 — Automated individual decision-making including profiling
  • GDPR Recital 71 — Safeguards for profiling and automated decisions
  • GDPR Recital 72 — Guidelines on profiling
  • CJEU C-434/16 (Nowak, 2017) — Broad interpretation of personal data including assessments
  • CJEU C-634/21 (SCHUFA, 2023) — Credit scoring as automated decision-making
  • EDPB Guidelines on Automated Decision-Making (WP 251 rev.01) — Art. 22 interpretation
  • EDPB Guidelines 8/2020 on Targeting of Social Media Users — Inferred data as personal data
  • EU AI Act Article 52 — Transparency obligations for AI systems
  • EU AI Act Article 14 — Human oversight for high-risk AI systems

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/ai-privacy-inference of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

AI Privacy Inference next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Privacy Inference compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Privacy Inference this skillmukul975/Privacy-Data-Protection-Skills301—~3.5kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about AI Privacy Inference

What does AI Privacy Inference do?

Managing privacy risks from AI-driven inferences about individuals including derived data classification, profiling under GDPR Art. AI Privacy Inference is an agent skill from mukul975/Privacy-Data-Protection-Skills. Managing privacy risks from AI-driven inferences about individuals including derived data classification, profiling under GDPR Art.

When should I use AI Privacy Inference?

AI Privacy Inference fits situations like: tasks that involve Privacy and GDPR; tasks that involve Data analysis.

How do I install AI Privacy Inference in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ai-privacy-inference -a claude-code`. Or copy the skill folder (skills/privacy/ai-privacy-inference in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/ai-privacy-inference in your project. Claude Code loads it when a task matches its description.

How do I install AI Privacy Inference in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ai-privacy-inference -a codex`. Or copy the skill folder (skills/privacy/ai-privacy-inference in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/ai-privacy-inference in your project. Codex loads it when a task matches its description.

Can I use AI Privacy Inference in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ai-privacy-inference -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-privacy-inference, .gemini/skills/ai-privacy-inference, .github/skills/ai-privacy-inference and .opencode/skills/ai-privacy-inference in your project.

What does AI Privacy Inference need to run?

Going by SKILL.md and its folder, AI Privacy Inference needs Python for the scripts in its folder. Our summary lists: Python 3.

Does AI Privacy Inference access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AI Privacy Inference safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does AI Privacy Inference use?

AI Privacy Inference is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Privacy Inference use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.

What are the alternatives to AI Privacy Inference?

Skills that share tags, products or a category with AI Privacy Inference: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Privacy Inference?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.