Implementing Compliance
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation…
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills continuous-compliance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/continuous-compliance .claude/skills/continuous-compliance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "continuous-compliance" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/continuous-compliance into .claude/skills/continuous-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "continuous-compliance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/continuous-complianceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills continuous-compliance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/continuous-compliance .agents/skills/continuous-compliance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "continuous-compliance" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/continuous-compliance into .agents/skills/continuous-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "continuous-compliance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills continuous-compliance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/continuous-compliance .cursor/skills/continuous-compliance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "continuous-compliance" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/continuous-compliance into .cursor/skills/continuous-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "continuous-compliance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/continuous-compliance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills continuous-compliance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/continuous-compliance .gemini/skills/continuous-compliance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "continuous-compliance" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/continuous-compliance into .gemini/skills/continuous-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "continuous-compliance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills continuous-complianceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/continuous-compliance .github/skills/continuous-compliance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "continuous-compliance" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/continuous-compliance into .github/skills/continuous-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "continuous-compliance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills continuous-compliance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/continuous-compliance .opencode/skills/continuous-compliance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "continuous-compliance" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/continuous-compliance into .opencode/skills/continuous-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "continuous-compliance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
continuous-complianceGuides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation…
Continuous Compliance is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation workflows, regulatory change integration, and deviation management. Covers GRC platform configuration, control framework mapping, and compliance-as-code approaches. Keywords: continuous compliance, automated monitoring, evidence collection, dashboard, regulatory change, compliance-as-code.
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR, Digital forensics and Audit readiness. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Continuous Compliance loads about 4.8k tokens when it runs, and up to ~5.9k if it reads all its reference files. Until then it costs about 125 tokens; SKILL.md has 1,465 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,465 words, ~4,837 tokens.
.claude/skills/continuous-compliance/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Continuous compliance monitoring replaces the traditional point-in-time audit model with an ongoing, automated approach to verifying that privacy controls are operating effectively. Rather than discovering compliance gaps during annual audits, continuous monitoring provides real-time visibility into control performance, enabling immediate remediation before gaps become regulatory violations or data breaches.
The shift from periodic to continuous monitoring is driven by several factors: the increasing frequency of regulatory changes (GDPR enforcement guidance, new US state privacy laws, sector-specific regulations), the growing complexity of data ecosystems (cloud, SaaS, APIs, third-party integrations), and supervisory authority expectations for demonstrable accountability under Art. 5(2) GDPR.
Sentinel Compliance Group implemented continuous privacy compliance monitoring in 2023, reducing time-to-detect compliance deviations from an average of 94 days (quarterly audit cycle) to 2.3 days (automated monitoring with alert-based triage).
┌─────────────────────────────────────────────────────┐
│ LAYER 3: REPORTING │
│ Executive Dashboards │ Regulatory Reports │ Alerts │
├─────────────────────────────────────────────────────┤
│ LAYER 2: ANALYSIS │
│ Control Scoring │ Trend Analysis │ Risk Correlation │
├─────────────────────────────────────────────────────┤
│ LAYER 1: DATA COLLECTION │
│ Automated Tests │ Evidence Harvest │ External Feeds │
└─────────────────────────────────────────────────────┘Automated Control Tests execute pre-defined checks against systems, configurations, and data:
| Test Category | Data Source | Test Examples | Frequency |
|---|---|---|---|
| Configuration Compliance | Cloud APIs (AWS, Azure, GCP) | Encryption at rest enabled, access logging active, data residency verified | Daily |
| Access Control | IAM systems (Okta, Azure AD) | Privileged access reviews current, terminated users deprovisioned, RBAC aligned with data classification | Daily |
| Data Lifecycle | Database metadata, storage systems | Retention periods enforced, deletion jobs executing, backup encryption verified | Daily |
| Consent Records | CMP platforms (OneTrust, Cookiebot) | Consent records complete, withdrawal honored, opt-out signals processed | Real-time |
| DSAR Processing | DSAR management system | Open DSARs within SLA, response quality checks, identity verification completed | Daily |
| Vendor Compliance | Vendor management platform | DPAs current, certifications valid, sub-processor lists updated | Weekly |
| Training Compliance | LMS (Learning Management System) | Training completion rates, overdue assignments, content currency | Weekly |
| Policy Currency | Document management system | Policy review dates, approval status, version control | Weekly |
| Breach Readiness | Incident response tools | Response plan current, tabletop exercise conducted, contact lists updated | Monthly |
| Transfer Safeguards | Contract management, TIA register | SCCs executed, TIAs current, adequacy decisions monitored | Weekly |
Evidence Harvesting automatically collects and timestamps compliance artifacts:
| Evidence Type | Collection Method | Storage | Retention |
|---|---|---|---|
| System screenshots | Automated screenshot capture via API | Evidence repository with hash verification | 3 years |
| Configuration exports | API calls to target systems | Versioned configuration store | 3 years |
| Log extracts | SIEM/log aggregator queries | Immutable audit log archive | Per regulatory requirement |
| Consent records | CMP database export | Dedicated consent evidence store | Duration of processing + 5 years |
| DSAR records | Workflow system export | DSAR archive with access controls | 3 years after request closure |
| Training records | LMS completion export | HR evidence repository | Employment duration + 2 years |
| Contract documents | Contract management system | Legal document repository | Contract duration + 6 years |
External Feeds ingest regulatory and threat intelligence:
| Feed Type | Source | Purpose |
|---|---|---|
| Regulatory changes | OneTrust DataGuidance, IAPP, Official Journals | Detect new laws, guidance, and enforcement actions |
| Enforcement actions | Supervisory authority RSS feeds, GDPRhub | Learn from peer enforcement and adjust controls |
| Vendor risk intelligence | BitSight, SecurityScorecard | Monitor vendor security posture changes |
| Threat intelligence | CISA, ENISA, sector ISACs | Correlate privacy risks with emerging threats |
Control Scoring Engine:
Each control is scored based on automated test results:
| Score | Status | Definition |
|---|---|---|
| 100 | Effective | All automated tests pass; evidence is current and complete |
| 75-99 | Mostly Effective | Minor deviations detected; evidence gaps exist but are non-material |
| 50-74 | Partially Effective | Material deviations detected; some evidence missing or outdated |
| 25-49 | Largely Ineffective | Multiple failures; significant evidence gaps; control is not reliably operating |
| 0-24 | Ineffective | Control is not operating; no evidence of implementation |
Aggregation Logic:
Trend Analysis:
Risk Correlation:
Real-Time Dashboards:
| Dashboard | Audience | Content | Refresh Rate |
|---|---|---|---|
| Privacy Operations | Privacy team | Control-level scores, open deviations, DSAR metrics, vendor status | Real-time |
| Executive Privacy | CPO, CISO, CLO | Domain-level scores, trend analysis, top risks, regulatory exposure | Daily |
| Board Privacy | Board/Audit Committee | Overall compliance score, year-over-year trend, peer benchmarking, material incidents | Quarterly |
| Regulatory | DPO, Legal | Regulation-specific scores, gap details, enforcement tracker | Weekly |
| Vendor | Procurement, Third-Party Risk | Vendor compliance scores, DPA status, certification expiry | Weekly |
For each privacy control, define:
control_id: PCC-DSAR-001
control_name: DSAR Response Timeliness
regulation_mapping:
- GDPR Art. 12(3)
- CCPA Section 1798.130(a)(2)
- LGPD Art. 18
domain: Data Subject Rights
test_definition:
test_type: data_query
data_source: dsar_management_system
query: |
SELECT request_id, received_date, response_date,
DATEDIFF(day, received_date, COALESCE(response_date, GETDATE())) as days_elapsed,
jurisdiction, status
FROM dsar_requests
WHERE status IN ('open', 'in_progress', 'completed')
AND received_date >= DATEADD(day, -90, GETDATE())
pass_criteria:
- field: days_elapsed
condition: less_than_or_equal
value: 30
filter: "jurisdiction = 'GDPR' AND status != 'completed'"
- field: days_elapsed
condition: less_than_or_equal
value: 45
filter: "jurisdiction = 'CCPA' AND status != 'completed'"
- field: days_elapsed
condition: less_than_or_equal
value: 30
filter: "status = 'completed'"
threshold: 0.95 # 95% of completed requests must meet deadline
frequency: daily
alert_threshold: 0.90 # Alert if pass rate drops below 90%
alert_recipients:
- privacy-operations@sentinelcompliance.com
- dpo@sentinelcompliance.com
evidence_collection:
- type: query_result
description: Full DSAR status report with elapsed days
- type: screenshot
description: DSAR dashboard showing current queue statuscontrol_id: PCC-ENC-001
control_name: Database Encryption at Rest
test_type: api_check
data_source: aws_rds_api
check:
api_call: describe_db_instances
assertion: StorageEncrypted == true
scope: all_instances
frequency: daily
remediation_automation:
enabled: true
action: create_jira_ticket
priority: high
assignee: database-teamcontrol_id: PCC-DPA-001
control_name: DPA Currency
test_type: data_query
data_source: contract_management_system
query: |
SELECT vendor_name, dpa_expiry_date,
DATEDIFF(day, GETDATE(), dpa_expiry_date) as days_until_expiry
FROM vendor_contracts
WHERE contract_type = 'DPA' AND status = 'active'
pass_criteria:
- field: days_until_expiry
condition: greater_than
value: 0
description: No expired DPAs
alert_rules:
- condition: days_until_expiry <= 30
severity: warning
message: "DPA for {vendor_name} expires in {days_until_expiry} days"
- condition: days_until_expiry <= 0
severity: critical
message: "DPA for {vendor_name} has expired"
frequency: dailycontrol_id: PCC-TRN-001
control_name: Privacy Training Completion
test_type: api_check
data_source: lms_api
check:
api_call: get_course_completion
course_id: PRIV-001-ANNUAL
assertion: completion_rate >= 0.95
scope: all_active_employees
frequency: weekly
alert_threshold: 0.90
escalation:
- level: 1
condition: completion_rate < 0.95
action: notify_manager
- level: 2
condition: completion_rate < 0.90
action: notify_cpo
- level: 3
condition: completion_rate < 0.80
action: notify_audit_committee| Severity | Criteria | Response SLA | Notification |
|---|---|---|---|
| Critical | Control failure affecting high-sensitivity data OR regulatory deadline at risk OR active data exposure | 4 hours | CPO, CISO, DPO, Privacy Ops lead — immediate notification via PagerDuty/Slack |
| High | Control failure affecting personal data OR compliance score below threshold OR vendor DPA expired | 24 hours | Privacy Ops team, control owner — email + Slack notification |
| Medium | Control degradation (score decrease >10 points) OR evidence gap detected OR training overdue | 72 hours | Control owner — email notification |
| Low | Minor deviation OR informational alert OR upcoming deadline | 1 week | Control owner — daily digest |
Alert Triggered
↓
Auto-Triage (severity classification, deduplication, correlation)
↓
Alert Assigned to Control Owner
↓
Control Owner Acknowledges (within SLA)
↓
Root Cause Analysis
↓
Remediation Plan Documented
↓
Remediation Executed
↓
Automated Re-Test
↓
Pass? → Alert Closed → Evidence Archived
↓
Fail? → Escalate → Revised Remediation PlanFor specific control failures, automated remediation can be configured:
| Control Failure | Auto-Remediation Action | Human Approval Required |
|---|---|---|
| Terminated user still has access | Disable account via IAM API | No (immediate) |
| Encryption disabled on new resource | Enable encryption via cloud API | No (immediate) |
| Expired DPA detected | Generate renewal notification to vendor manager | Yes (notification only) |
| Training overdue > 30 days | Send automated reminder to employee and manager | No (notification) |
| Consent record missing timestamp | Flag record for manual review | Yes (review required) |
| DSAR approaching SLA deadline | Escalate to privacy operations lead | No (escalation only) |
External Regulatory Feed
↓
Change Detection (new law, amendment, guidance, enforcement action)
↓
Relevance Assessment (automated keyword matching + manual review)
↓
Impact Analysis (which controls, processes, and systems are affected)
↓
Gap Assessment (current compliance vs. new requirement)
↓
Remediation Planning (control updates, policy changes, system modifications)
↓
Implementation and Testing
↓
Control Framework Updated
↓
Monitoring Rules Adjusted| Category | Response Timeline | Example |
|---|---|---|
| New regulation enacted | Assessment within 30 days; implementation by effective date | New US state privacy law with 12-month implementation window |
| Existing regulation amended | Assessment within 14 days; implementation per amendment effective date | GDPR delegated act modifying adequacy decision |
| Supervisory authority guidance | Assessment within 30 days; implementation within 90 days | EDPB guidelines on consent for cookie walls |
| Enforcement action (peer) | Lessons-learned review within 14 days; control gap check within 30 days | DPA fine for inadequate DSAR response process |
| Court decision | Legal review within 14 days; impact assessment within 30 days | CJEU judgment invalidating transfer mechanism |
When regulatory changes require control updates:
Embed privacy compliance checks into infrastructure-as-code (IaC) pipelines:
# Example: Terraform compliance policy for data residency
policy "data_residency_eu" {
description = "Ensure EU personal data is stored in EU regions only"
enforcement_level = "mandatory"
rule "storage_location" {
condition = resource.aws_s3_bucket.region in ["eu-west-1", "eu-central-1", "eu-north-1"]
message = "S3 buckets containing EU personal data must be in EU regions"
}
rule "encryption_required" {
condition = resource.aws_s3_bucket.server_side_encryption_configuration != null
message = "S3 buckets containing personal data must have encryption enabled"
}
rule "versioning_enabled" {
condition = resource.aws_s3_bucket.versioning[0].enabled == true
message = "S3 buckets containing personal data must have versioning enabled for audit trail"
}
rule "public_access_blocked" {
condition = resource.aws_s3_bucket_public_access_block.block_public_acls == true
message = "S3 buckets containing personal data must block public access"
}
}Integrate privacy checks into CI/CD pipelines:
| Pipeline Stage | Privacy Check | Blocking? |
|---|---|---|
| Code Review | PII detection in code comments, logs, and test data | Yes |
| Static Analysis | Privacy annotation verification (data classification, retention, purpose) | Yes |
| Build | Dependency check for privacy-impacting libraries | Warning |
| Integration Test | Consent enforcement verification, DSAR endpoint testing | Yes |
| Pre-Deploy | Data residency verification, encryption verification | Yes |
| Post-Deploy | Privacy header verification, cookie consent verification | Monitoring |
Overall Compliance Score (large numeric display):
Compliance by Regulation (horizontal bar chart):
GDPR: ████████████████████░ 96%
CCPA/CPRA: ███████████████████░░ 93%
LGPD: ██████████████████░░░ 91%
PIPA: ████████████████████░ 97%
UK GDPR: ███████████████████░░ 94%Open Deviations by Severity (donut chart):
Control Health Heatmap (10x grid, one cell per domain):
Top 5 Deviations Requiring Attention (table):
| ID | Control | Score | Days Open | Owner |
|---|---|---|---|---|
| DEV-2025-089 | Vendor DPA Renewal (Vendor X) | 0 | 12 | Procurement |
| DEV-2025-091 | DSAR Response SLA (LGPD) | 67 | 5 | Privacy Ops |
| DEV-2025-088 | Training Completion (Engineering) | 88 | 21 | L&D |
| DEV-2025-092 | Cookie Consent Banner (FR site) | 72 | 3 | Marketing |
| DEV-2025-087 | Retention Job Failure (Archive DB) | 50 | 8 | Data Engineering |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/continuous-compliance of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Continuous Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Continuous Compliance this skillmukul975/Privacy-Data-Protection-Skills | 297 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Complianceancoleman/ai-design-components | 526 | — | ~4k | Automated safety check: Pass | MIT | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Performing Soc2 Type2 Audit Preparationmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Compliance Osalirezarezvani/claude-skills | 28k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Cursor Compliance Auditjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.3k | Automated safety check: Notes | MIT |
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
mukul975/Anthropic-Cybersecurity-Skills
Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing…
alirezarezvani/claude-skills
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…
jeremylongshore/tons-of-skills-marketplace
Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.
mohitagw15856/pm-claude-skills
Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation…. Continuous Compliance is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation workflows, regulatory change integration, and deviation management.
Continuous Compliance fits situations like: tasks that involve Privacy and GDPR; tasks that involve Digital forensics; tasks that involve Audit readiness.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a claude-code`. Or copy the skill folder (skills/privacy/continuous-compliance in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/continuous-compliance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a codex`. Or copy the skill folder (skills/privacy/continuous-compliance in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/continuous-compliance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill continuous-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/continuous-compliance, .gemini/skills/continuous-compliance, .github/skills/continuous-compliance and .opencode/skills/continuous-compliance in your project.
Going by SKILL.md and its folder, Continuous Compliance needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Continuous Compliance is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Continuous Compliance: Implementing Compliance (ancoleman/ai-design-components, 526 stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Performing Soc2 Type2 Audit Preparation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Compliance Os (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.