Agent skill

Continuous Compliance

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation…

Apache-2.0Auto-check passedLegal & Compliance

Install Continuous Compliance

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills continuous-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/continuous-compliance .claude/skills/continuous-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
continuous-compliance
GitHub stars
297
Token cost
~4.8k tokens
SKILL.md length
1,465 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation…

  • Works in 6 steps: Document the regulatory change and its… → Draft updated control definitions and… → Review and approve changes through the… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Architecture, Automated Control Testing and Alert-Based Remediation, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Continuous Compliance is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation workflows, regulatory change integration, and deviation management. Covers GRC platform configuration, control framework mapping, and compliance-as-code approaches. Keywords: continuous compliance, automated monitoring, evidence collection, dashboard, regulatory change, compliance-as-code.

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR, Digital forensics and Audit readiness. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Digital forensics
  • Tasks that involve Audit readiness

Example prompts

  • “Use the continuous-compliance skill to guide continuous privacy compliance monitoring implementation including automated control testing, evidence…”
  • “/continuous-compliance”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Document the regulatory change and its impact on existing controls
  2. Draft updated control definitions and test criteria
  3. Review and approve changes through the privacy governance committee
  4. Update automated test configurations
  5. Re-baseline compliance scores (distinguish between score changes due to new requirements vs. degradation)
  6. Communicate changes to control owners and affected stakeholders

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Continuous Compliance loads about 4.8k tokens when it runs, and up to ~5.9k if it reads all its reference files. Until then it costs about 125 tokens; SKILL.md has 1,465 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~125
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,465 words, ~4,837 tokens.

Download SKILL.mdSave it as .claude/skills/continuous-compliance/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
continuous-compliance
description
Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation workflows, regulatory change integration, and deviation management. Covers GRC platform configuration, control framework mapping, and compliance-as-code approaches. Keywords: continuous compliance, automated monitoring, evidence collection, dashboard, regulatory change, compliance-as-code.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-audit-certification
metadata.tags
continuous-compliance, automated-monitoring, evidence-collection, dashboard, regulatory-change

Continuous Privacy Compliance Monitoring

Overview

Continuous compliance monitoring replaces the traditional point-in-time audit model with an ongoing, automated approach to verifying that privacy controls are operating effectively. Rather than discovering compliance gaps during annual audits, continuous monitoring provides real-time visibility into control performance, enabling immediate remediation before gaps become regulatory violations or data breaches.

The shift from periodic to continuous monitoring is driven by several factors: the increasing frequency of regulatory changes (GDPR enforcement guidance, new US state privacy laws, sector-specific regulations), the growing complexity of data ecosystems (cloud, SaaS, APIs, third-party integrations), and supervisory authority expectations for demonstrable accountability under Art. 5(2) GDPR.

Sentinel Compliance Group implemented continuous privacy compliance monitoring in 2023, reducing time-to-detect compliance deviations from an average of 94 days (quarterly audit cycle) to 2.3 days (automated monitoring with alert-based triage).

Architecture

Three-Layer Monitoring Architecture
┌─────────────────────────────────────────────────────┐
│                 LAYER 3: REPORTING                   │
│  Executive Dashboards │ Regulatory Reports │ Alerts  │
├─────────────────────────────────────────────────────┤
│               LAYER 2: ANALYSIS                      │
│  Control Scoring │ Trend Analysis │ Risk Correlation │
├─────────────────────────────────────────────────────┤
│             LAYER 1: DATA COLLECTION                 │
│  Automated Tests │ Evidence Harvest │ External Feeds │
└─────────────────────────────────────────────────────┘
Layer 1: Data Collection

Automated Control Tests execute pre-defined checks against systems, configurations, and data:

Test CategoryData SourceTest ExamplesFrequency
Configuration ComplianceCloud APIs (AWS, Azure, GCP)Encryption at rest enabled, access logging active, data residency verifiedDaily
Access ControlIAM systems (Okta, Azure AD)Privileged access reviews current, terminated users deprovisioned, RBAC aligned with data classificationDaily
Data LifecycleDatabase metadata, storage systemsRetention periods enforced, deletion jobs executing, backup encryption verifiedDaily
Consent RecordsCMP platforms (OneTrust, Cookiebot)Consent records complete, withdrawal honored, opt-out signals processedReal-time
DSAR ProcessingDSAR management systemOpen DSARs within SLA, response quality checks, identity verification completedDaily
Vendor ComplianceVendor management platformDPAs current, certifications valid, sub-processor lists updatedWeekly
Training ComplianceLMS (Learning Management System)Training completion rates, overdue assignments, content currencyWeekly
Policy CurrencyDocument management systemPolicy review dates, approval status, version controlWeekly
Breach ReadinessIncident response toolsResponse plan current, tabletop exercise conducted, contact lists updatedMonthly
Transfer SafeguardsContract management, TIA registerSCCs executed, TIAs current, adequacy decisions monitoredWeekly

Evidence Harvesting automatically collects and timestamps compliance artifacts:

Evidence TypeCollection MethodStorageRetention
System screenshotsAutomated screenshot capture via APIEvidence repository with hash verification3 years
Configuration exportsAPI calls to target systemsVersioned configuration store3 years
Log extractsSIEM/log aggregator queriesImmutable audit log archivePer regulatory requirement
Consent recordsCMP database exportDedicated consent evidence storeDuration of processing + 5 years
DSAR recordsWorkflow system exportDSAR archive with access controls3 years after request closure
Training recordsLMS completion exportHR evidence repositoryEmployment duration + 2 years
Contract documentsContract management systemLegal document repositoryContract duration + 6 years

External Feeds ingest regulatory and threat intelligence:

Feed TypeSourcePurpose
Regulatory changesOneTrust DataGuidance, IAPP, Official JournalsDetect new laws, guidance, and enforcement actions
Enforcement actionsSupervisory authority RSS feeds, GDPRhubLearn from peer enforcement and adjust controls
Vendor risk intelligenceBitSight, SecurityScorecardMonitor vendor security posture changes
Threat intelligenceCISA, ENISA, sector ISACsCorrelate privacy risks with emerging threats
Layer 2: Analysis

Control Scoring Engine:

Each control is scored based on automated test results:

ScoreStatusDefinition
100EffectiveAll automated tests pass; evidence is current and complete
75-99Mostly EffectiveMinor deviations detected; evidence gaps exist but are non-material
50-74Partially EffectiveMaterial deviations detected; some evidence missing or outdated
25-49Largely IneffectiveMultiple failures; significant evidence gaps; control is not reliably operating
0-24IneffectiveControl is not operating; no evidence of implementation

Aggregation Logic:

  • Control Level: Average of all test results for that control (weighted by test criticality)
  • Domain Level: Weighted average of all control scores within the domain
  • Regulation Level: Weighted average of all controls mapped to a specific regulation
  • Overall Compliance Score: Weighted average of all domain scores

Trend Analysis:

  • 7-day rolling average to smooth transient deviations
  • 30-day trend to identify systematic degradation
  • Quarter-over-quarter comparison for management reporting
  • Year-over-year comparison for board reporting

Risk Correlation:

  • Cross-reference control failures with data sensitivity classifications
  • Correlate compliance deviations with recent system changes
  • Map control failures to regulatory exposure (which regulations are affected)
  • Identify compounding risks (multiple control failures in the same data flow)
Layer 3: Reporting

Real-Time Dashboards:

DashboardAudienceContentRefresh Rate
Privacy OperationsPrivacy teamControl-level scores, open deviations, DSAR metrics, vendor statusReal-time
Executive PrivacyCPO, CISO, CLODomain-level scores, trend analysis, top risks, regulatory exposureDaily
Board PrivacyBoard/Audit CommitteeOverall compliance score, year-over-year trend, peer benchmarking, material incidentsQuarterly
RegulatoryDPO, LegalRegulation-specific scores, gap details, enforcement trackerWeekly
VendorProcurement, Third-Party RiskVendor compliance scores, DPA status, certification expiryWeekly

Automated Control Testing

Control Testing Framework

For each privacy control, define:

yaml
control_id: PCC-DSAR-001
control_name: DSAR Response Timeliness
regulation_mapping:
  - GDPR Art. 12(3)
  - CCPA Section 1798.130(a)(2)
  - LGPD Art. 18
domain: Data Subject Rights
test_definition:
  test_type: data_query
  data_source: dsar_management_system
  query: |
    SELECT request_id, received_date, response_date,
           DATEDIFF(day, received_date, COALESCE(response_date, GETDATE())) as days_elapsed,
           jurisdiction, status
    FROM dsar_requests
    WHERE status IN ('open', 'in_progress', 'completed')
      AND received_date >= DATEADD(day, -90, GETDATE())
  pass_criteria:
    - field: days_elapsed
      condition: less_than_or_equal
      value: 30
      filter: "jurisdiction = 'GDPR' AND status != 'completed'"
    - field: days_elapsed
      condition: less_than_or_equal
      value: 45
      filter: "jurisdiction = 'CCPA' AND status != 'completed'"
    - field: days_elapsed
      condition: less_than_or_equal
      value: 30
      filter: "status = 'completed'"
      threshold: 0.95  # 95% of completed requests must meet deadline
  frequency: daily
  alert_threshold: 0.90  # Alert if pass rate drops below 90%
  alert_recipients:
    - privacy-operations@sentinelcompliance.com
    - dpo@sentinelcompliance.com
  evidence_collection:
    - type: query_result
      description: Full DSAR status report with elapsed days
    - type: screenshot
      description: DSAR dashboard showing current queue status
Common Automated Test Patterns
Configuration Compliance Test
yaml
control_id: PCC-ENC-001
control_name: Database Encryption at Rest
test_type: api_check
data_source: aws_rds_api
check:
  api_call: describe_db_instances
  assertion: StorageEncrypted == true
  scope: all_instances
frequency: daily
remediation_automation:
  enabled: true
  action: create_jira_ticket
  priority: high
  assignee: database-team
Evidence Currency Test
yaml
control_id: PCC-DPA-001
control_name: DPA Currency
test_type: data_query
data_source: contract_management_system
query: |
  SELECT vendor_name, dpa_expiry_date,
         DATEDIFF(day, GETDATE(), dpa_expiry_date) as days_until_expiry
  FROM vendor_contracts
  WHERE contract_type = 'DPA' AND status = 'active'
pass_criteria:
  - field: days_until_expiry
    condition: greater_than
    value: 0
    description: No expired DPAs
alert_rules:
  - condition: days_until_expiry <= 30
    severity: warning
    message: "DPA for {vendor_name} expires in {days_until_expiry} days"
  - condition: days_until_expiry <= 0
    severity: critical
    message: "DPA for {vendor_name} has expired"
frequency: daily
Training Compliance Test
yaml
control_id: PCC-TRN-001
control_name: Privacy Training Completion
test_type: api_check
data_source: lms_api
check:
  api_call: get_course_completion
  course_id: PRIV-001-ANNUAL
  assertion: completion_rate >= 0.95
  scope: all_active_employees
frequency: weekly
alert_threshold: 0.90
escalation:
  - level: 1
    condition: completion_rate < 0.95
    action: notify_manager
  - level: 2
    condition: completion_rate < 0.90
    action: notify_cpo
  - level: 3
    condition: completion_rate < 0.80
    action: notify_audit_committee

Alert-Based Remediation

Alert Severity Classification
SeverityCriteriaResponse SLANotification
CriticalControl failure affecting high-sensitivity data OR regulatory deadline at risk OR active data exposure4 hoursCPO, CISO, DPO, Privacy Ops lead — immediate notification via PagerDuty/Slack
HighControl failure affecting personal data OR compliance score below threshold OR vendor DPA expired24 hoursPrivacy Ops team, control owner — email + Slack notification
MediumControl degradation (score decrease >10 points) OR evidence gap detected OR training overdue72 hoursControl owner — email notification
LowMinor deviation OR informational alert OR upcoming deadline1 weekControl owner — daily digest
Remediation Workflow
Alert Triggered
  ↓
Auto-Triage (severity classification, deduplication, correlation)
  ↓
Alert Assigned to Control Owner
  ↓
Control Owner Acknowledges (within SLA)
  ↓
Root Cause Analysis
  ↓
Remediation Plan Documented
  ↓
Remediation Executed
  ↓
Automated Re-Test
  ↓
Pass? → Alert Closed → Evidence Archived
  ↓
Fail? → Escalate → Revised Remediation Plan
Show full SKILL.md (603 more words)Show less
Auto-Remediation

For specific control failures, automated remediation can be configured:

Control FailureAuto-Remediation ActionHuman Approval Required
Terminated user still has accessDisable account via IAM APINo (immediate)
Encryption disabled on new resourceEnable encryption via cloud APINo (immediate)
Expired DPA detectedGenerate renewal notification to vendor managerYes (notification only)
Training overdue > 30 daysSend automated reminder to employee and managerNo (notification)
Consent record missing timestampFlag record for manual reviewYes (review required)
DSAR approaching SLA deadlineEscalate to privacy operations leadNo (escalation only)

Regulatory Change Integration

Regulatory Change Management Process
External Regulatory Feed
  ↓
Change Detection (new law, amendment, guidance, enforcement action)
  ↓
Relevance Assessment (automated keyword matching + manual review)
  ↓
Impact Analysis (which controls, processes, and systems are affected)
  ↓
Gap Assessment (current compliance vs. new requirement)
  ↓
Remediation Planning (control updates, policy changes, system modifications)
  ↓
Implementation and Testing
  ↓
Control Framework Updated
  ↓
Monitoring Rules Adjusted
Regulatory Change Categories
CategoryResponse TimelineExample
New regulation enactedAssessment within 30 days; implementation by effective dateNew US state privacy law with 12-month implementation window
Existing regulation amendedAssessment within 14 days; implementation per amendment effective dateGDPR delegated act modifying adequacy decision
Supervisory authority guidanceAssessment within 30 days; implementation within 90 daysEDPB guidelines on consent for cookie walls
Enforcement action (peer)Lessons-learned review within 14 days; control gap check within 30 daysDPA fine for inadequate DSAR response process
Court decisionLegal review within 14 days; impact assessment within 30 daysCJEU judgment invalidating transfer mechanism
Control Framework Versioning

When regulatory changes require control updates:

  1. Document the regulatory change and its impact on existing controls
  2. Draft updated control definitions and test criteria
  3. Review and approve changes through the privacy governance committee
  4. Update automated test configurations
  5. Re-baseline compliance scores (distinguish between score changes due to new requirements vs. degradation)
  6. Communicate changes to control owners and affected stakeholders

Compliance-as-Code

Infrastructure Privacy Compliance

Embed privacy compliance checks into infrastructure-as-code (IaC) pipelines:

yaml
# Example: Terraform compliance policy for data residency
policy "data_residency_eu" {
  description = "Ensure EU personal data is stored in EU regions only"
  enforcement_level = "mandatory"

  rule "storage_location" {
    condition = resource.aws_s3_bucket.region in ["eu-west-1", "eu-central-1", "eu-north-1"]
    message   = "S3 buckets containing EU personal data must be in EU regions"
  }

  rule "encryption_required" {
    condition = resource.aws_s3_bucket.server_side_encryption_configuration != null
    message   = "S3 buckets containing personal data must have encryption enabled"
  }

  rule "versioning_enabled" {
    condition = resource.aws_s3_bucket.versioning[0].enabled == true
    message   = "S3 buckets containing personal data must have versioning enabled for audit trail"
  }

  rule "public_access_blocked" {
    condition = resource.aws_s3_bucket_public_access_block.block_public_acls == true
    message   = "S3 buckets containing personal data must block public access"
  }
}
Application Privacy Compliance

Integrate privacy checks into CI/CD pipelines:

Pipeline StagePrivacy CheckBlocking?
Code ReviewPII detection in code comments, logs, and test dataYes
Static AnalysisPrivacy annotation verification (data classification, retention, purpose)Yes
BuildDependency check for privacy-impacting librariesWarning
Integration TestConsent enforcement verification, DSAR endpoint testingYes
Pre-DeployData residency verification, encryption verificationYes
Post-DeployPrivacy header verification, cookie consent verificationMonitoring

Dashboard Design

Executive Dashboard Components

Overall Compliance Score (large numeric display):

  • Current score: 94.2%
  • 30-day trend: +1.3%
  • Target: 95%

Compliance by Regulation (horizontal bar chart):

GDPR:         ████████████████████░  96%
CCPA/CPRA:    ███████████████████░░  93%
LGPD:         ██████████████████░░░  91%
PIPA:         ████████████████████░  97%
UK GDPR:      ███████████████████░░  94%

Open Deviations by Severity (donut chart):

  • Critical: 0
  • High: 2
  • Medium: 8
  • Low: 15

Control Health Heatmap (10x grid, one cell per domain):

  • Green (>90%): Privacy Governance, Risk Management, Incident Management, Training
  • Yellow (75-90%): Data Inventory, Regulatory, DSR, Consent, Third-Party
  • Red (<75%): None
  • Grey: Privacy by Design (assessment in progress)

Top 5 Deviations Requiring Attention (table):

IDControlScoreDays OpenOwner
DEV-2025-089Vendor DPA Renewal (Vendor X)012Procurement
DEV-2025-091DSAR Response SLA (LGPD)675Privacy Ops
DEV-2025-088Training Completion (Engineering)8821L&D
DEV-2025-092Cookie Consent Banner (FR site)723Marketing
DEV-2025-087Retention Job Failure (Archive DB)508Data Engineering

Sentinel Compliance Group Implementation

  • Platform: OneTrust GRC for compliance management; custom Python automation layer for evidence harvesting; Grafana for dashboards
  • Controls Monitored: 312 privacy controls across 10 domains, mapped to GDPR, CCPA/CPRA, LGPD, PIPA, and UK GDPR
  • Automated Tests: 478 automated test cases executing daily/weekly per schedule
  • Evidence Collection: 12,400 evidence artifacts automatically collected per quarter
  • Alert Volume: Average 23 alerts per week (2 high, 7 medium, 14 low); average resolution time: 2.3 days
  • Overall Compliance Score: 94.2% (December 2024), up from 87.1% at program launch (January 2024)
  • Audit Impact: External auditors (SOC 2 and ISO 27701) accepted continuous monitoring evidence, reducing audit fieldwork by 30%
  • Regulatory Changes Processed: 47 regulatory changes assessed in 2024; 12 required control updates; average time from change detection to control update: 18 days

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/continuous-compliance of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Continuous Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Continuous Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Continuous Compliance this skillmukul975/Privacy-Data-Protection-Skills297—~4.8kAutomated safety check: PassApache-2.0
Implementing Complianceancoleman/ai-design-components526—~4kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Performing Soc2 Type2 Audit Preparationmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Cursor Compliance Auditjeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: NotesMIT

Similar skills

  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    526 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Performing Soc2 Type2 Audit Preparation

    mukul975/Anthropic-Cybersecurity-Skills

    Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Cursor Compliance Audit

    jeremylongshore/tons-of-skills-marketplace

    Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.

    2.8k GitHub stars~2.3k tokensUpdated yesterday
    Legal & ComplianceAuto-check: notes
  • Compliance Checklist

    mohitagw15856/pm-claude-skills

    Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    297 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    297 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    297 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Continuous Compliance

What does Continuous Compliance do?

Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation…. Continuous Compliance is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation workflows, regulatory change integration, and deviation management.

When should I use Continuous Compliance?

Continuous Compliance fits situations like: tasks that involve Privacy and GDPR; tasks that involve Digital forensics; tasks that involve Audit readiness.

How do I install Continuous Compliance in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a claude-code`. Or copy the skill folder (skills/privacy/continuous-compliance in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/continuous-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Continuous Compliance in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a codex`. Or copy the skill folder (skills/privacy/continuous-compliance in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/continuous-compliance in your project. Codex loads it when a task matches its description.

Can I use Continuous Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/continuous-compliance, .gemini/skills/continuous-compliance, .github/skills/continuous-compliance and .opencode/skills/continuous-compliance in your project.

What does Continuous Compliance need to run?

Going by SKILL.md and its folder, Continuous Compliance needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Continuous Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Continuous Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Continuous Compliance use?

Continuous Compliance is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Continuous Compliance use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Continuous Compliance?

Skills that share tags, products or a category with Continuous Compliance: Implementing Compliance (ancoleman/ai-design-components, 526 stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Performing Soc2 Type2 Audit Preparation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Compliance Os (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Continuous Compliance?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.