Agent skill

Consent Pref Center

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Technical architecture guide for building a multi-purpose consent preference center.

Apache-2.0Auto-check passedBackend & APIs

Install Consent Pref Center

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill consent-pref-center -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills consent-pref-center --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/consent-pref-center .claude/skills/consent-pref-center && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
consent-pref-center
GitHub stars
301
Token cost
~2.1k tokens
SKILL.md length
863 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Technical architecture guide for building a multi-purpose consent preference center.

  • Works in 4 steps: Data Model → API Design → TCF v2.2 Integration → …
  • Tasks that involve API design
  • SKILL.md covers Overview, Architecture Components, Version History and Audit Trail and Key Regulatory References
  • Runs Python scripts from its folder

What it does

Consent Pref Center is an agent skill from mukul975/Privacy-Data-Protection-Skills. Technical architecture guide for building a multi-purpose consent preference center. Covers per-purpose granularity, easy withdrawal under Article 7(3), version history, audit trails, and IAB Transparency and Consent Framework v2.2 integration. Includes database schema, API design, and UI component specifications.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Backend & APIs, covering API design, Database schema design and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve API design
  • Tasks that involve Database schema design
  • Tasks that involve Privacy and GDPR

Example prompts

  • “/consent-pref-center”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Data Model
  2. API Design
  3. TCF v2.2 Integration
  4. UI Component Specification

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Consent Pref Center loads about 2.1k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 84 tokens; SKILL.md has 863 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 863 words, ~2,127 tokens.

Download SKILL.mdSave it as .claude/skills/consent-pref-center/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
consent-pref-center
description
Technical architecture guide for building a multi-purpose consent preference center. Covers per-purpose granularity, easy withdrawal under Article 7(3), version history, audit trails, and IAB Transparency and Consent Framework v2.2 integration. Includes database schema, API design, and UI component specifications.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
consent-management
metadata.tags
consent-preference-center, tcf-v2, consent-management, audit-trail, consent-ui

Overview

A consent preference center is the centralized interface through which data subjects manage their consent choices across all processing purposes. Under GDPR Article 7(3), withdrawal of consent must be as easy as giving it, making a well-designed preference center critical for compliance. The IAB Europe Transparency and Consent Framework (TCF) v2.2 provides a standardized approach for advertising-related consent that integrates with this architecture.

Architecture Components

1. Data Model

The consent preference center requires four core data entities:

Consent Purpose Registry Stores all processing purposes for which consent is the lawful basis.

FieldTypeDescription
purpose_idUUIDUnique identifier for the processing purpose
purpose_nameVARCHAR(256)Human-readable purpose name
purpose_descriptionTEXTPlain-language description (Flesch-Kincaid grade 8 or below)
legal_basisENUM"consent" or "explicit_consent"
data_categoriesJSONBArray of personal data categories processed
recipientsJSONBArray of named third-party recipients
retention_periodVARCHAR(128)Data retention period for this purpose
tcf_purpose_idINTEGERMapped IAB TCF v2.2 purpose ID (1-11) if applicable
is_activeBOOLEANWhether this purpose is currently offered
created_atTIMESTAMPWhen the purpose was registered
updated_atTIMESTAMPLast modification timestamp

Consent Text Version Immutable records of consent text presented to users.

FieldTypeDescription
version_idUUIDUnique version identifier
purpose_idUUIDFK to purpose registry
consent_textTEXTExact text displayed to the user
text_hashCHAR(64)SHA-256 hash of consent_text
effective_fromTIMESTAMPWhen this version went live
effective_untilTIMESTAMPWhen this version was superseded (NULL if current)
approved_byVARCHAR(256)Name of DPO or legal reviewer who approved

Consent Decision Records each consent decision made by a data subject.

FieldTypeDescription
decision_idUUIDUnique decision identifier
subject_idUUIDData subject identifier
purpose_idUUIDFK to purpose registry
version_idUUIDFK to consent text version shown
decisionENUM"granted" or "withdrawn"
mechanismVARCHAR(64)"checkbox_tick", "toggle_switch", "api_call"
timestampTIMESTAMPISO 8601 UTC timestamp
ip_addressINETIP address at time of decision
user_agentTEXTBrowser user agent string
sourceVARCHAR(64)"signup_flow", "preference_center", "cookie_banner", "api"

Consent Propagation Log Tracks downstream system notifications after consent changes.

FieldTypeDescription
propagation_idUUIDUnique propagation event ID
decision_idUUIDFK to consent decision that triggered this
target_systemVARCHAR(256)Name of downstream system notified
statusENUM"pending", "delivered", "acknowledged", "failed"
sent_atTIMESTAMPWhen notification was dispatched
acknowledged_atTIMESTAMPWhen downstream system confirmed receipt
2. API Design

GET /api/v1/consent/preferences/{subject_id} Returns current consent state for all purposes for a given data subject.

Response:

json
{
  "subject_id": "usr_7f3a9b2e-41d8-4c76-b5e3-9a8d1c2f4e60",
  "preferences": [
    {
      "purpose_id": "pur_analytics_001",
      "purpose_name": "Service Improvement Analytics",
      "decision": "granted",
      "granted_at": "2026-01-15T10:30:00Z",
      "version_id": "ver_a1b2c3d4"
    },
    {
      "purpose_id": "pur_marketing_002",
      "purpose_name": "Product Update Emails",
      "decision": "withdrawn",
      "withdrawn_at": "2026-02-20T14:45:00Z",
      "version_id": "ver_e5f6g7h8"
    }
  ],
  "last_updated": "2026-02-20T14:45:00Z"
}

PUT /api/v1/consent/preferences/{subject_id} Updates consent for one or more purposes. Triggers downstream propagation.

Request:

json
{
  "decisions": [
    {
      "purpose_id": "pur_marketing_002",
      "decision": "granted",
      "mechanism": "toggle_switch"
    }
  ]
}

GET /api/v1/consent/history/{subject_id} Returns full consent history for audit purposes per Article 7(1).

GET /api/v1/consent/receipt/{decision_id} Returns a single consent receipt in Kantara Initiative Consent Receipt format.

3. TCF v2.2 Integration

The IAB Transparency and Consent Framework v2.2 (released September 2023) requires:

  • TC String Generation: Encode consent signals into the IAB TC String format. The TC String is a base64url-encoded bitfield that captures consent for TCF-defined purposes (1-11) and legitimate interest assertions.
  • CMP Registration: Register with the IAB Europe as a Consent Management Platform. Each registered CMP receives a unique CMP ID used in TC String generation.
  • Vendor List Integration: Consume the IAB Global Vendor List (GVL) to display vendor-level consent options. The GVL is published at vendorlist.consensu.org and updated weekly.
  • Purpose Mapping: Map internal CloudVault SaaS Inc. purposes to TCF v2.2 purposes:
    • TCF Purpose 1 (Store and/or access information on a device) → Cookie consent
    • TCF Purpose 3 (Create profiles for personalised advertising) → If applicable
    • TCF Purpose 7 (Measure ad performance) → Analytics consent
  • Publisher Restrictions: Configure publisher-level restrictions to limit vendors to consent-only legal basis where CloudVault SaaS Inc. policy requires it.
Show full SKILL.md (277 more words)Show less
4. UI Component Specification

The preference center interface at CloudVault SaaS Inc. follows these design principles:

Layout:

  • Accessible at Settings > Privacy > Manage Consent (maximum 2 clicks from any page)
  • Also accessible via direct URL: app.cloudvault-saas.eu/settings/privacy
  • Persistent "Privacy Choices" link in the page footer on every page

Per-Purpose Toggle:

  • Each purpose displays: purpose name, 1-sentence description, current state (on/off toggle)
  • "Learn More" expandable section with: full description, data categories, recipients, retention period
  • Toggle change triggers immediate API call and visual confirmation

Consent History:

  • "View History" link per purpose showing: date, action (granted/withdrawn), consent text version
  • Downloadable consent receipt in JSON format (Kantara Consent Receipt specification v1.1)

Withdrawal Flow:

  • Single toggle click to withdraw (matching the single click to grant during sign-up)
  • Confirmation dialog: "Are you sure you want to withdraw consent for [purpose]? This will stop [specific processing]. You can re-enable this at any time."
  • Post-withdrawal confirmation: "Consent withdrawn. Processing will stop within 24 hours."

Version History and Audit Trail

Every consent text change creates a new version record. The preference center always displays the current version but retains all historical versions. Audit queries can reconstruct:

  • What text was shown to a specific user at a specific time
  • When consent was given and withdrawn for each purpose
  • Whether downstream systems were notified of consent changes
  • The propagation status and timing for each consent change

Key Regulatory References

  • GDPR Article 7(1) — Demonstrating consent
  • GDPR Article 7(3) — Right to withdraw consent, equal ease requirement
  • GDPR Article 12(1) — Transparent, intelligible, easily accessible information
  • IAB TCF v2.2 Specification (September 2023) — TC String encoding, CMP requirements
  • Kantara Initiative Consent Receipt Specification v1.1 — Standard consent receipt format
  • EDPB Guidelines 05/2020 — Consent under Regulation 2016/679

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/consent-pref-center of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Consent Pref Center next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Consent Pref Center compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Consent Pref Center this skillmukul975/Privacy-Data-Protection-Skills301—~2.1kAutomated safety check: PassApache-2.0
Reference EngineNoobyGains/godmode109—~5.4kAutomated safety check: PassMIT
Da Contentadobe/skills197—~2.9kAutomated safety check: PassApache-2.0
System Designopenxlings/xlings6151 repos~328Automated safety check: PassApache-2.0
Backend DevelopmentMoizIbnYousaf/ai-agent-skills1.1k—~853Automated safety check: PassMIT
Light System DesignLight0305/Light-skills640—~3.6kAutomated safety check: PassMIT

Similar skills

  • Reference Engine

    NoobyGains/godmode

    A skill your agent uses when building ANYTHING - the universal reference-first system that routes every task to proven reference implementations instead of generating from assumptions.

    109 GitHub stars~5.4k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Da Content

    adobe/skills

    Use this when generating HTML for Adobe Document Authoring (DA, da.live) upload, uploading media binaries to DA, publishing to aem.live, or driving the DA admin API (auth, source PUT…

    197 GitHub stars~2.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • System Design

    openxlings/xlings

    Design systems, services, and architectures. An agent skill from openxlings/xlings.

    615 GitHub starsUsed in 1 repo~328 tokens
    Backend & APIsAuto-check passed
  • Backend Development

    MoizIbnYousaf/ai-agent-skills

    Backend API design, database architecture, microservices patterns, and test-driven development.

    1.1k GitHub stars~853 tokensUpdated 19 days ago
    Backend & APIsAuto-check passed
  • Light System Design

    Light0305/Light-skills

    Evidence-based workflow for designing or modernizing a software system: current-state inventory, options, API and schema contracts, migration plans, ADRs and verification.

    640 GitHub stars~3.6k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Mas Skills

    AUTO-MAS-Project/AUTO-MAS

    A skill your agent uses when a task needs AUTO-MAS engineering conventions across frontend, UI, code style, schema naming, module boundaries, function design, API contracts, data modeling, script…

    711 GitHub stars~3.6k tokensUpdated today
    DatabasesAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Consent Pref Center

What does Consent Pref Center do?

Technical architecture guide for building a multi-purpose consent preference center. Consent Pref Center is an agent skill from mukul975/Privacy-Data-Protection-Skills. Technical architecture guide for building a multi-purpose consent preference center.

When should I use Consent Pref Center?

Consent Pref Center fits situations like: tasks that involve API design; tasks that involve Database schema design; tasks that involve Privacy and GDPR.

How do I install Consent Pref Center in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill consent-pref-center -a claude-code`. Or copy the skill folder (skills/privacy/consent-pref-center in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/consent-pref-center in your project. Claude Code loads it when a task matches its description.

How do I install Consent Pref Center in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill consent-pref-center -a codex`. Or copy the skill folder (skills/privacy/consent-pref-center in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/consent-pref-center in your project. Codex loads it when a task matches its description.

Can I use Consent Pref Center in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill consent-pref-center -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/consent-pref-center, .gemini/skills/consent-pref-center, .github/skills/consent-pref-center and .opencode/skills/consent-pref-center in your project.

What does Consent Pref Center need to run?

Going by SKILL.md and its folder, Consent Pref Center needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Consent Pref Center access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Consent Pref Center safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Consent Pref Center use?

Consent Pref Center is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Consent Pref Center use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Consent Pref Center?

Skills that share tags, products or a category with Consent Pref Center: Reference Engine (NoobyGains/godmode, 109 stars), Da Content (adobe/skills, 197 stars), System Design (openxlings/xlings, 615 stars) and Backend Development (MoizIbnYousaf/ai-agent-skills, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Consent Pref Center?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.