C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Implements BYOD privacy compliance frameworks for personal device use in the workplace.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill byod-privacy-policy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills byod-privacy-policy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/byod-privacy-policy .claude/skills/byod-privacy-policy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "byod-privacy-policy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/byod-privacy-policy into .claude/skills/byod-privacy-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "byod-privacy-policy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/byod-privacy-policyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill byod-privacy-policy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills byod-privacy-policy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/byod-privacy-policy .agents/skills/byod-privacy-policy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "byod-privacy-policy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/byod-privacy-policy into .agents/skills/byod-privacy-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "byod-privacy-policy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill byod-privacy-policy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills byod-privacy-policy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/byod-privacy-policy .cursor/skills/byod-privacy-policy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "byod-privacy-policy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/byod-privacy-policy into .cursor/skills/byod-privacy-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "byod-privacy-policy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/byod-privacy-policy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill byod-privacy-policy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills byod-privacy-policy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/byod-privacy-policy .gemini/skills/byod-privacy-policy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "byod-privacy-policy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/byod-privacy-policy into .gemini/skills/byod-privacy-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "byod-privacy-policy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills byod-privacy-policyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill byod-privacy-policy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/byod-privacy-policy .github/skills/byod-privacy-policy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "byod-privacy-policy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/byod-privacy-policy into .github/skills/byod-privacy-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "byod-privacy-policy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill byod-privacy-policy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills byod-privacy-policy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/byod-privacy-policy .opencode/skills/byod-privacy-policy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "byod-privacy-policy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/byod-privacy-policy into .opencode/skills/byod-privacy-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "byod-privacy-policy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
byod-privacy-policyImplements BYOD privacy compliance frameworks for personal device use in the workplace.
Byod Privacy Policy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements BYOD privacy compliance frameworks for personal device use in the workplace. Covers personal vs corporate data separation, MDM capabilities and limitations, employee consent requirements, data wiping boundaries, and monitoring restrictions on personal devices. Keywords: BYOD, mobile device management, MDM, personal device, data separation, containerisation, remote wipe, employee privacy.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Byod Privacy Policy loads about 3.8k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 1,829 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,829 words, ~3,768 tokens.
.claude/skills/byod-privacy-policy/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Bring Your Own Device (BYOD) programmes create a complex privacy intersection where corporate data security requirements meet employee personal privacy rights. When employees use personal smartphones, tablets, and laptops for work purposes, the employer gains a legitimate interest in protecting corporate data on those devices — but this interest must be balanced against the employee's right to privacy in their personal data, communications, and device usage. The GDPR, national labour laws, and ECHR Art. 8 jurisprudence impose strict limits on what employers can monitor, access, and delete on personal devices.
This skill provides a compliance framework for BYOD programmes that satisfies corporate security requirements while respecting employee privacy boundaries, including data separation architecture, MDM configuration, consent management, and data wiping limitations.
Lawful Basis for BYOD Data Processing:
Transparency — Art. 13/14: Employees must receive a comprehensive privacy notice before enrolling in the BYOD programme, detailing exactly what data the employer can and cannot access on the personal device.
Data Minimisation — Art. 5(1)(c): The employer must collect only the minimum data necessary to protect corporate information. This prohibits blanket monitoring of personal device activity.
France — CNIL Guidance (2019):
Germany — BDSG Section 26 + Works Council Rights:
Italy — Workers' Statute Art. 4:
The foundational privacy requirement for BYOD is that corporate data and personal data must occupy separate, isolated environments on the device. The employer has legitimate access to the corporate environment only.
Definition: A software container creates an encrypted, isolated space on the personal device where corporate data is stored and accessed. Corporate applications run within the container; personal applications run outside it.
Technical Implementation:
| Feature | Corporate Container | Personal Space |
|---|---|---|
| Corporate email accessed via managed email client within container | Personal email unaffected and inaccessible to employer | |
| Files | Corporate documents stored in container with encryption | Personal files unaffected and inaccessible to employer |
| Browsing | Corporate intranet accessed via managed browser | Personal browsing unaffected and not logged |
| Applications | Corporate apps installed within container (managed app catalogue) | Personal apps unaffected; employer cannot see installed personal apps |
| Clipboard | Cross-container clipboard may be disabled to prevent data leakage | Personal clipboard within personal space |
| Camera | Photos taken within corporate apps stored in container | Personal photos inaccessible to employer |
Platform Solutions:
| Approach | Employer Capabilities | Privacy Impact | Recommendation |
|---|---|---|---|
| Full Device MDM Enrolment | Full device inventory, location tracking, browsing history, app list, remote full wipe | Very High — employer has visibility into personal data | Not recommended for BYOD; use only for corporate-owned devices |
| Work Profile / Container | Corporate container management, selective wipe of corporate data only, no visibility into personal space | Low to Medium — personal data isolated | Recommended for BYOD |
| App-Level Management (MAM) | Per-app policies (encryption, DLP, remote app data wipe), no device-level access | Lowest — management limited to specific corporate apps | Recommended for light BYOD scenarios |
Atlas Manufacturing Group Example: Atlas implemented Microsoft Intune with App Protection Policies for its BYOD programme. Instead of full device enrolment, Atlas deploys managed versions of Outlook, Teams, OneDrive, and the corporate intranet app. These managed apps enforce encryption, prevent copy-paste of corporate data to personal apps, and can be selectively wiped without affecting personal data. Atlas explicitly chose not to require full MDM enrolment on personal devices after the DPO advised that full enrolment would grant disproportionate access to personal data.
| Capability | Permitted | Justification |
|---|---|---|
| Enforce device passcode/biometric lock | Yes | Necessary to protect corporate data if device is lost/stolen |
| Encrypt corporate container | Yes | Necessary to protect corporate data at rest |
| Remote wipe of corporate container only | Yes | Necessary to protect corporate data on lost/stolen devices or termination |
| Push corporate apps to container | Yes | Necessary to provide access to corporate applications |
| Enforce OS version minimum | Yes, with caveat | Acceptable to ensure security patches are applied; must allow reasonable update period |
| VPN configuration for corporate traffic | Yes | Necessary to secure corporate data in transit |
| Certificate-based authentication | Yes | Necessary for secure corporate access |
| Capability | Prohibited | Reason |
|---|---|---|
| Full device remote wipe | Yes | Disproportionate; destroys personal data. Only selective corporate data wipe is permitted |
| Personal app inventory | Yes | Reveals personal interests, health conditions (medical apps), political views (news apps), religion (prayer apps) — constitutes special category processing without lawful basis |
| Personal browsing history | Yes | Reveals sensitive personal information; not necessary for corporate data protection |
| Personal location tracking | Yes | Disproportionate; corporate need does not extend to tracking employee personal movements |
| Personal email access | Yes | Violates Art. 8 ECHR right to correspondence |
| Personal photo/media access | Yes | No corporate justification; disproportionate invasion of personal privacy |
| Microphone/camera remote activation | Yes | Extreme intrusion; no lawful basis |
| Personal call log access | Yes | Violates correspondence privacy |
| Keylogging on personal device | Yes | Captures both corporate and personal input; disproportionate |
BYOD participation must be genuinely voluntary. The employer must offer a corporate-provided alternative device for employees who decline BYOD:
Before enrolment, employees must receive a clear privacy notice covering:
| Element | Content |
|---|---|
| What is collected | Specific data elements collected from the device (device type, OS version, corporate app data) |
| What is not collected | Explicit statement of data not collected (personal apps, photos, messages, browsing, location) |
| Who has access | Which corporate roles can access device management data |
| Remote actions | What remote actions the employer can take (selective wipe only — not full wipe) |
| Monitoring | Whether any activity monitoring occurs within the corporate container |
| Termination | What happens to corporate data on the device if employment ends |
| Withdrawal | How to un-enrol from BYOD and what happens to data |
| Retention | How long enrolment logs and device data are retained |
The BYOD agreement is a separate document from the employment contract and must include:
Selective wipe removes only corporate data and applications from the personal device. This is triggered by:
Implementation: Using containerisation, the selective wipe removes the corporate container, managed apps, and associated data. Personal data remains intact.
Full device wipe resets the device to factory settings, destroying all personal data. This action is:
Enforcement: The Autoriteit Persoonsgegevens (Netherlands) investigated an employer that remotely wiped an employee's personal phone after termination, destroying personal photos and contacts. The DPA found the action disproportionate and ordered the employer to compensate the employee and implement a selective wipe solution.
Remote work BYOD introduces additional considerations:
| Authority | Case | Outcome | Key Issue |
|---|---|---|---|
| Autoriteit Persoonsgegevens (NL) | 2020 Investigation | Compensation order | Employer remotely wiped personal phone; disproportionate |
| CNIL (France) | Guidance Note 2019 | Compliance framework | Employers must limit MDM to corporate data; personal data inaccessible |
| Garante (Italy) | Provvedimento 2021-0547 | Processing restriction | MDM on BYOD devices granted employer access to personal app list — disproportionate |
| ICO (UK) | Employment Practices Code Part 3 | Guidance | MDM must be proportionate; full device wipe on personal devices is not acceptable |
| LfDI Hamburg (Germany) | 2021 Audit | Corrective measures | Employer's BYOD programme lacked works council agreement and collected personal app data |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/byod-privacy-policy of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Byod Privacy Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Byod Privacy Policy this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Implements BYOD privacy compliance frameworks for personal device use in the workplace. Byod Privacy Policy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements BYOD privacy compliance frameworks for personal device use in the workplace.
Byod Privacy Policy fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill byod-privacy-policy -a claude-code`. Or copy the skill folder (skills/privacy/byod-privacy-policy in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/byod-privacy-policy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill byod-privacy-policy -a codex`. Or copy the skill folder (skills/privacy/byod-privacy-policy in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/byod-privacy-policy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill byod-privacy-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/byod-privacy-policy, .gemini/skills/byod-privacy-policy, .github/skills/byod-privacy-policy and .opencode/skills/byod-privacy-policy in your project.
Going by SKILL.md and its folder, Byod Privacy Policy needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Byod Privacy Policy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Byod Privacy Policy: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.