Agent skill

AI Training Lawfulness

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI.

Apache-2.0Auto-check passedData & Analytics

Install AI Training Lawfulness

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill ai-training-lawfulness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills ai-training-lawfulness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/ai-training-lawfulness .claude/skills/ai-training-lawfulness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-training-lawfulness
GitHub stars
301
Token cost
~3.7k tokens
SKILL.md length
1,883 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI.

  • Works in 4 steps: Training datasets contain personal data… → The model is trained on data that… → The resulting model retains the… → …
  • Tasks that involve Web scraping
  • SKILL.md covers Overview, Fundamental Principles, Lawful Basis Analysis for AI… and Training Data Retention, plus 3 more sections
  • Runs Python scripts from its folder

What it does

AI Training Lawfulness is an agent skill from mukul975/Privacy-Data-Protection-Skills. Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI. Covers legitimate interest balancing tests, consent challenges for ML training, public dataset assessment, and web scraping lawfulness. Keywords: AI training data, lawful basis, EDPB LLM, legitimate interest, consent, web scraping.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Data & Analytics, covering Web scraping and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Web scraping
  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the ai-training-lawfulness skill to assess lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI”
  • “/ai-training-lawfulness”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Training datasets contain personal data (directly or indirectly identifiable natural persons)
  2. The model is trained on data that includes personal data, even if the intent is to learn general patterns
  3. The resulting model retains the capability to generate or reproduce personal data from training sets
  4. Personal data is used in any pipeline stage: collection, cleaning, annotation, augmentation, validation, testing

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Training Lawfulness loads about 3.7k tokens when it runs, and up to ~8.9k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 1,883 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,883 words, ~3,671 tokens.

Download SKILL.mdSave it as .claude/skills/ai-training-lawfulness/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
ai-training-lawfulness
description
Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI. Covers legitimate interest balancing tests, consent challenges for ML training, public dataset assessment, and web scraping lawfulness. Keywords: AI training data, lawful basis, EDPB LLM, legitimate interest, consent, web scraping.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
ai-privacy-governance
metadata.tags
ai-training, lawful-basis, edpb-llm, legitimate-interest, web-scraping, consent

Lawful Basis for AI Training Data

Overview

The processing of personal data for AI model training constitutes a distinct processing operation requiring its own lawful basis under GDPR Art. 6(1). The EDPB Guidelines 04/2025 and the coordinated ChatGPT Taskforce findings establish that AI training creates unique lawful basis challenges: the scale of data collection, the difficulty of obtaining meaningful consent for open-ended AI training purposes, the tension between legitimate interest and data subject expectations, and the complexity of determining lawfulness for web-scraped and third-party datasets. This skill provides the comprehensive lawful basis assessment framework for AI training data processing, addressing each Art. 6(1) basis as applied to ML training contexts.

Fundamental Principles

AI Training as Personal Data Processing

The EDPB has confirmed that AI model training constitutes processing of personal data under Art. 4(2) GDPR when:

  1. Training datasets contain personal data (directly or indirectly identifiable natural persons)
  2. The model is trained on data that includes personal data, even if the intent is to learn general patterns
  3. The resulting model retains the capability to generate or reproduce personal data from training sets
  4. Personal data is used in any pipeline stage: collection, cleaning, annotation, augmentation, validation, testing

The controller cannot avoid GDPR obligations by claiming the model has "learned" rather than "stored" personal data. The processing occurs at the point of training, regardless of whether the model can later reproduce specific records.

Purpose Specification for AI Training

Art. 5(1)(b) requires that personal data be collected for specified, explicit, and legitimate purposes. For AI training, this means:

  • "Training an AI model" is insufficiently specific — the controller must articulate the specific capability being developed
  • "Improving our services" through AI training must be disaggregated into concrete purposes
  • Each purpose must be documented before training begins, not retroactively justified
  • The purpose must be communicated to data subjects in privacy notices per Arts. 13-14

Lawful Basis Analysis for AI Training

RequirementAI Training Application
Freely givenData subjects must have genuine choice; consent cannot be bundled with service access unless AI training is necessary for the service
Specific"AI training" alone is insufficient — must specify what type of model, for what purpose, what data elements are used
InformedMust explain how personal data will be used in training, retention period for training data, risk of model memorization, inability to fully delete data from trained models
UnambiguousClear affirmative action; pre-ticked boxes or implied consent from terms of service are insufficient
WithdrawableController must provide mechanism to withdraw consent; but model already trained on the data presents technical challenge
  1. Granularity problem: AI training often uses all available data — difficult to obtain specific consent for each data element's use in training
  2. Withdrawal complexity: Once a model is trained on personal data, true erasure requires model retraining or verified machine unlearning
  3. Purpose evolution: Foundation models and transfer learning mean the model may be repurposed — original consent may not cover downstream uses
  4. Scale impracticality: Obtaining consent from millions of data subjects whose data appears in web-scraped training corpora is practically impossible
  5. Power imbalance: When AI service use requires consent to training (e.g., "use our AI assistant and your conversations train our model"), consent may not be freely given
  • Users explicitly opt into a research programme where AI model training is a primary purpose
  • Users contribute data to a specific AI system with clear disclosure (e.g., "your feedback trains this recommendation engine")
  • Fine-tuning on user-provided data where the user understands and consents to the training purpose
Art. 6(1)(b) — Contract Necessity

AI training can rely on contractual necessity only when:

  • The AI model training is genuinely necessary for performing the contract with the data subject
  • The data subject has entered into a contract that requires AI-powered features
  • The training cannot be separated from the service delivery

Limitations per EDPB:

  • General improvement of AI systems through aggregate training is not "necessary" for any individual contract
  • Training a general-purpose model that benefits future users is not necessary for the current data subject's contract
  • Fine-tuning based on individual user interactions may qualify if the personalised model is part of the contracted service
Art. 6(1)(f) — Legitimate Interest

This is the most commonly relied-upon basis for AI training. The EDPB requires a rigorous three-part assessment:

Part 1: Legitimate Interest Identification

The controller must identify a specific, real, and lawful interest:

Interest TypeExampleEDPB Assessment
Commercial product improvementTraining a fraud detection model to protect customersGenerally legitimate — concrete benefit to data subjects
Research and developmentTraining models for medical imaging analysisLegitimate if research purpose is genuine and specific
General AI capabilityTraining a foundation model for general-purpose useScrutinised — interest must be articulated with specificity
Competitive advantageTraining to match competitor AI capabilitiesLegitimate commercial interest but weak in balancing
Part 2: Necessity Assessment
QuestionAssessment Criteria
Is AI training necessary for the identified interest?Could the interest be pursued without training on personal data?
Could anonymised data achieve the same result?Has the controller tested model performance with anonymised data?
Could synthetic data supplement or replace personal data?Has synthetic data generation been evaluated?
Is the volume of personal data proportionate?Has the minimum effective dataset been determined?
Could federated learning avoid centralising personal data?Has distributed training been assessed?
Part 3: Balancing Test

Factors weighing in favour of the controller:

  • Training data is publicly available (but this alone is not decisive)
  • Model serves a beneficial purpose (fraud prevention, medical research)
  • Strong technical safeguards applied (differential privacy, access controls)
  • Data subjects can exercise opt-out rights effectively
  • Training data is pseudonymised before use

Factors weighing in favour of data subjects:

  • Data was not collected with AI training in mind — processing is far from original expectations
  • Large-scale data collection from diverse sources without data subjects' awareness
  • Special category data is present or can be inferred from training data
  • Children's data is present in the training corpus
  • No practical opt-out mechanism exists
  • Model may memorize and regurgitate personal data
  • Web scraping bypasses data subjects' choices about data sharing
EDPB Position on Legitimate Interest for AI Training

The EDPB Guidelines 04/2025 establish that:

  1. Legitimate interest for AI training is not automatically available — it requires case-by-case assessment
  2. Web scraping of personal data for AI training faces a particularly high bar
  3. The scale of data collection is a relevant factor — larger datasets require stronger justification
  4. The controller must demonstrate necessity: evidence that personal data is required rather than anonymised or synthetic alternatives
  5. Effective opt-out mechanisms are expected as a minimum safeguard
  6. The balancing test should consider the cumulative impact of multiple AI developers scraping and training on the same data subjects' data
Show full SKILL.md (757 more words)Show less
Art. 6(1)(e) — Public Interest

Available to public bodies and organisations performing tasks in the public interest:

  • Academic research institutions training AI models for publicly beneficial research
  • Government agencies training AI for public service delivery
  • Must have a basis in national or Union law
  • Proportionality requirements apply
Special Situations
Web-Scraped Data

The EDPB has given specific guidance on web scraping for AI training:

  1. Robots.txt is not consent: Compliance with robots.txt does not establish lawful basis
  2. Public availability is not a lawful basis: Data being publicly accessible does not mean it can be freely used for AI training
  3. Reasonable expectations: Data subjects who post content online do not reasonably expect it to be used for AI training
  4. Children's data: Web-scraped data likely contains children's data — heightened protections apply
  5. Technical measures: Data subjects who implement privacy settings have expressed a preference against broad data use

Assessment framework for web-scraped training data:

FactorHigh Lawfulness IndicatorLow Lawfulness Indicator
Data sourceExplicitly open-licence data (CC0, public domain)Personal profiles, social media, private websites
Data typeFactual, non-personal contentIdentifiable personal information, photos, opinions
Data subject expectationsData published with intent for wide reuseData shared in specific context (social media, forums)
SafeguardsDifferential privacy, PII filtering pre-trainingNo preprocessing to remove personal data
Opt-outEffective and accessible opt-out mechanismNo opt-out or technically impractical opt-out
TransparencyPrivacy notice covers AI training useNo notice to data subjects about AI training
Third-Party Datasets

When using datasets obtained from third parties:

  1. Upstream lawful basis verification: The controller must verify that the data provider had a lawful basis to collect and share the data
  2. Contractual warranties: Obtain warranties from the provider regarding lawful collection, consent scope, and right to license for AI training
  3. Due diligence: Conduct reasonable due diligence on the provider's data collection practices
  4. Chain of accountability: The AI developer remains a controller responsible for lawful processing, even if the data was provided by a third party
Public Datasets

Academic and government datasets require assessment:

  1. Is personal data present? (Many datasets contain inadvertent personal data)
  2. What was the original purpose of the dataset? Is AI training compatible?
  3. Does the dataset licence permit commercial AI training?
  4. Has the dataset been ethically reviewed for consent and privacy?
  5. Are there known issues (bias, PII leakage, consent gaps)?

Training Data Retention

Art. 5(1)(e) storage limitation applies to AI training data:

  • Training data must not be retained longer than necessary for the training purpose
  • Once the model is trained, is continued retention of training data justified?
  • If training data is retained for retraining, what is the maximum retention period?
  • Model artefacts (weights, embeddings) that encode personal data are also subject to retention limits
  • Deletion verification: can the controller demonstrate that training data has been effectively deleted?

Data Subject Rights for Training Data

RightAI Training ApplicationTechnical Challenge
Access (Art. 15)Data subject can request confirmation that their data was used in training and receive a copyIdentifying specific records in large training datasets
Rectification (Art. 16)Inaccurate personal data in training sets must be correctedCorrection may require model retraining
Erasure (Art. 17)Data subjects can request deletion of their data from training setsRequires machine unlearning or model retraining
Objection (Art. 21)Data subjects can object to processing based on legitimate interestController must cease processing unless compelling grounds override
Restriction (Art. 18)Processing must be restricted while accuracy or objection is contestedMay require quarantining data from training pipeline

Enforcement Precedents

  • Garante v. OpenAI (2023): Temporary processing ban — no lawful basis identified for ChatGPT training data. Ordered OpenAI to identify Art. 6(1) basis for training data, implement age verification, and provide opt-out mechanism.
  • CNIL v. Clearview AI (SAN-2022-019, 2022): EUR 20M fine — web scraping of biometric data without lawful basis. No consent, legitimate interest balancing test not conducted.
  • Datatilsynet (Norway) v. Meta (2023): Temporary ban on using Norwegian user data for AI training — legitimate interest basis not sufficiently documented; balancing test inadequate.
  • DPC (Ireland) v. Meta (2024): Investigation into use of public Facebook/Instagram posts for AI training under legitimate interest basis. Meta paused EU AI training following DPC engagement.
  • EDPB Taskforce on ChatGPT (2024): Coordinated finding that legitimate interest for LLM training requires comprehensive balancing test, transparency, and effective opt-out — mere assertion of legitimate interest is insufficient.

Integration Points

  • ai-dpia: Training data lawfulness feeds into DPIA Phase 2 assessment
  • ai-data-subject-rights: Rights exercise mechanisms for training data
  • ai-data-retention: Retention and deletion requirements for training datasets
  • ai-transparency-reqs: Transparency obligations regarding training data use

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/ai-training-lawfulness of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

AI Training Lawfulness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Training Lawfulness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Training Lawfulness this skillmukul975/Privacy-Data-Protection-Skills301—~3.7kAutomated safety check: PassApache-2.0
Anti Bot Analyzerrevfactory/harness-1001.3k—~1.1kAutomated safety check: PassApache-2.0
Page Prepadobe/skills197—~2.1kAutomated safety check: PassApache-2.0
Tmuxtrpc-group/trpc-agent-go1.9k23 repos~868Automated safety check: PassApache-2.0
Ketch1broseidon/ketch7021 repos~3.9kAutomated safety check: PassMIT
Boss Zhipin Scrapereatmoreduck/boss-zhipin-scraper1.5k—~2.6kAutomated safety check: PassMIT

Similar skills

  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Data & AnalyticsAuto-check passed
  • Page Prep

    adobe/skills

    Prepare any webpage for clean interaction by detecting and removing disruptive overlays (cookie banners, GDPR consent, modals, popups, newsletter signups, paywalls, login walls).

    197 GitHub stars~2.1k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Tmux

    trpc-group/trpc-agent-go

    Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output.

    1.9k GitHub starsUsed in 23 repos~868 tokens
    Data & AnalyticsAuto-check passed
  • Ketch

    1broseidon/ketch

    Research skill for ketch — a fast stateless CLI for web search, OSS code search, curated library docs, page scraping, and site crawling; an optional MCP server exists for operators who want it, but…

    702 GitHub starsUsed in 1 repo~3.9k tokens
    Data & AnalyticsAuto-check passed
  • Boss Zhipin Scraper

    eatmoreduck/boss-zhipin-scraper

    Scrape BOSS直聘 (job listing site) via Chrome CDP. An agent skill from eatmoreduck/boss-zhipin-scraper.

    1.5k GitHub stars~2.6k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Crawl4AI Web Scraping

    smallnest/goclaw

    Scrapes sites, handles JavaScript-heavy pages and extracts structured data with Crawl4AI, through its crwl CLI or Python SDK, including schema-based extraction without an LLM.

    599 GitHub starsUsed in 1 repo~2.5k tokens
    Data & AnalyticsAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about AI Training Lawfulness

What does AI Training Lawfulness do?

Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI. AI Training Lawfulness is an agent skill from mukul975/Privacy-Data-Protection-Skills. Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI.

When should I use AI Training Lawfulness?

AI Training Lawfulness fits situations like: tasks that involve Web scraping; tasks that involve Privacy and GDPR.

How do I install AI Training Lawfulness in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ai-training-lawfulness -a claude-code`. Or copy the skill folder (skills/privacy/ai-training-lawfulness in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/ai-training-lawfulness in your project. Claude Code loads it when a task matches its description.

How do I install AI Training Lawfulness in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ai-training-lawfulness -a codex`. Or copy the skill folder (skills/privacy/ai-training-lawfulness in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/ai-training-lawfulness in your project. Codex loads it when a task matches its description.

Can I use AI Training Lawfulness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ai-training-lawfulness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-training-lawfulness, .gemini/skills/ai-training-lawfulness, .github/skills/ai-training-lawfulness and .opencode/skills/ai-training-lawfulness in your project.

What does AI Training Lawfulness need to run?

Going by SKILL.md and its folder, AI Training Lawfulness needs Python for the scripts in its folder. Our summary lists: Python 3.

Does AI Training Lawfulness access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AI Training Lawfulness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does AI Training Lawfulness use?

AI Training Lawfulness is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Training Lawfulness use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.2k tokens, read only when the agent opens those files.

What are the alternatives to AI Training Lawfulness?

Skills that share tags, products or a category with AI Training Lawfulness: Anti Bot Analyzer (revfactory/harness-100, 1.3k stars), Page Prep (adobe/skills, 197 stars), Tmux (trpc-group/trpc-agent-go, 1.9k stars) and Ketch (1broseidon/ketch, 702 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Training Lawfulness?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.