Agent skill

Controller Ropa Creation

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and contact details, processing purposes, data subject…

Apache-2.0Auto-check passedLegal & Compliance

Install Controller Ropa Creation

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill controller-ropa-creation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills controller-ropa-creation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/controller-ropa-creation .claude/skills/controller-ropa-creation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
controller-ropa-creation
GitHub stars
295
Token cost
~3.2k tokens
SKILL.md length
1,468 words
Files
5 (incl. scripts, references, assets)
Skills in repo
278
Repo updated
First seen
Licence
Apache-2.0

At a glance

Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and contact details, processing purposes, data subject…

  • Works in 8 steps: Identify the processing activity: Start… → Interview the processing owner: Conduct… → Validate against source systems:… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Mandatory Field Requirements, RoPA Entry Assembly Workflow and Common Pitfalls
  • Runs Python scripts from its folder

What it does

Controller Ropa Creation is an agent skill from mukul975/Privacy-Data-Protection-Skills. Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and contact details, processing purposes, data subject categories, personal data categories, recipient categories, third country transfers, and retention periods. Includes Python generator for automated RoPA creation. Activate for controller RoPA, Art. 30(1), processing records, data mapping.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. It works with Python. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the controller-ropa-creation skill to create GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven…”
  • “/controller-ropa-creation”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Identify the processing activity: Start with a specific processing activity, not a department or system. One system may support multiple…
  2. Interview the processing owner: Conduct a structured interview covering all seven fields. Use the data flow as the narrative: "Data comes…
  3. Validate against source systems: Cross-reference interview responses with actual system configurations, data flow diagrams, and…
  4. Draft the RoPA entry: Populate all seven fields using the templates and examples above.
  5. Review with DPO: The DPO reviews the entry for legal accuracy, particularly the purpose description, lawful basis alignment, and transfer…
  6. Obtain processing owner sign-off: The business owner confirms factual accuracy of the data flows, recipients, and retention periods.
  7. Register in the RoPA management system: Enter the validated record into the organisation's RoPA tool (e.g., OneTrust, TrustArc, or…
  8. Set review date: Schedule the next review no later than 12 months from creation, or earlier if the processing activity is high-risk.

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Controller Ropa Creation loads about 3.2k tokens when it runs, and up to ~6.7k if it reads all its reference files. Until then it costs about 115 tokens; SKILL.md has 1,468 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,468 words, ~3,151 tokens.

Download SKILL.mdSave it as .claude/skills/controller-ropa-creation/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
controller-ropa-creation
description
Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and contact details, processing purposes, data subject categories, personal data categories, recipient categories, third country transfers, and retention periods. Includes Python generator for automated RoPA creation. Activate for controller RoPA, Art. 30(1), processing records, data mapping.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
records-of-processing
metadata.tags
gdpr, article-30, ropa, controller, processing-records, data-mapping, accountability

Controller RoPA Creation

Overview

GDPR Article 30(1) requires every controller to maintain a written record of processing activities carried out under its responsibility. This skill provides a complete methodology for creating controller RoPA entries that satisfy all seven mandatory field requirements specified in Art. 30(1)(a) through (g), ensuring the organisation can demonstrate accountability under Art. 5(2) and respond to supervisory authority requests under Art. 30(4).

Mandatory Field Requirements

Field 1: Controller Identity and Contact Details — Art. 30(1)(a)

This field must identify:

  • Legal entity name: The registered name of the controller as it appears in the national business register (e.g., Companies House, Handelsregister, Registre du Commerce).
  • Registered address: The official registered office address.
  • Contact details: General contact email and telephone for data protection inquiries.
  • Joint controller(s): Where processing is jointly determined under Art. 26, the identity and contact details of each joint controller and a reference to the Art. 26 arrangement.
  • EU Representative: Where the controller is not established in the EEA, the identity and contact details of the Art. 27 representative.
  • Data Protection Officer: Name, email, and telephone of the DPO appointed under Art. 37, or a statement that no DPO is required with justification.

Example for Helix Biotech Solutions:

Sub-fieldValue
Legal entity nameHelix Biotech Solutions GmbH
Registered addressLeopoldstraße 42, 80802 Munich, Germany
RegistrationHRB 267891, Amtsgericht Munich
Contact emailprivacy@helix-biotech.eu
DPODr. Elena Voss, dpo@helix-biotech.eu, +49 89 7654 3210
EU RepresentativeNot applicable (established in EEA)
Joint controllersNone for this processing activity
Field 2: Purposes of Processing — Art. 30(1)(b)

Each processing activity must have one or more specific, explicit, and legitimate purposes documented. Purposes must be granular enough to demonstrate compliance with the purpose limitation principle under Art. 5(1)(b).

Avoid vague purposes such as:

  • "Business operations"
  • "Internal use"
  • "General purposes"
  • "As needed"

Acceptable purpose examples:

Processing ActivityPurpose StatementLawful Basis Reference
Employee payrollCalculation and disbursement of monthly salaries and statutory deductions under employment contract obligationArt. 6(1)(b) — contract performance
Clinical trial data collectionRecording of participant vital signs, adverse events, and treatment outcomes for Phase III oncology trial protocol HBX-2025-ONC-04Art. 6(1)(a) — explicit consent; Art. 9(2)(a) — explicit consent for health data
Customer account managementMaintaining customer identity, contact, and billing records to fulfil supply agreements for laboratory reagent ordersArt. 6(1)(b) — contract performance
Pharmacovigilance reportingCollection and assessment of adverse drug reaction reports for submission to EMA under EU Regulation 726/2004Art. 6(1)(c) — legal obligation
Field 3: Categories of Data Subjects — Art. 30(1)(c)

Identify all groups of individuals whose personal data is processed within each activity. Be exhaustive; omitting a data subject category creates a compliance gap.

Common categories for a biotech organisation:

  • Employees (permanent and fixed-term)
  • Contractors and consultants
  • Job applicants
  • Clinical trial participants
  • Patients (post-market surveillance)
  • Healthcare professionals (KOL engagement)
  • Suppliers and vendor representatives
  • Website visitors
  • Shareholders and investors
Field 4: Categories of Personal Data — Art. 30(1)(c)

For each processing activity, specify the types of personal data collected and processed. Flag special category data under Art. 9(1) and criminal conviction data under Art. 10.

Example data categories by processing activity:

Processing ActivityPersonal Data CategoriesSpecial Category (Art. 9)
Employee payrollName, employee ID, bank account (IBAN), tax ID, salary grade, working hoursNo
Clinical trial managementParticipant ID, date of birth, sex, medical history, genetic markers, treatment allocation, adverse eventsYes — health data, genetic data
PharmacovigilanceReporter name, patient initials, age, diagnosis, medication history, adverse reaction descriptionYes — health data
Visitor managementName, company affiliation, photo ID, visit date/time, host employeeNo
Field 5: Categories of Recipients — Art. 30(1)(d)

Document all entities that receive personal data, including:

  • Internal recipients: Departments or roles with access (HR, Finance, IT)
  • Processors: Third-party service providers acting under Art. 28 DPA (identify by name and reference the DPA)
  • Joint controllers: Entities jointly determining purposes under Art. 26
  • Public authorities: Regulators, tax authorities, law enforcement (identify the legal basis for disclosure)
  • Other controllers: Independent controllers receiving data (e.g., insurance providers)

Example:

RecipientTypeDPA/Agreement Reference
SAP SuccessFactors (SAP SE)ProcessorDPA-2024-SAP-001, executed 2024-02-15
ADP Employer Services GmbHProcessorDPA-2023-ADP-002, executed 2023-09-01
Finanzamt MunichPublic authoritySection 93 AO — tax reporting obligation
AOK BayernOther controllerStatutory health insurance reporting under SGB V
Helix Biotech Solutions Ltd (UK subsidiary)Intra-group controllerArt. 26 joint controller arrangement, ref: JCA-2024-UK-001
Field 6: International Transfers — Art. 30(1)(e)

Record every transfer of personal data to a third country (outside the EEA) or international organisation. For each transfer, document:

  • Destination country
  • Recipient entity
  • Transfer mechanism relied upon:
    • Adequacy decision under Art. 45 (specify which decision)
    • Standard Contractual Clauses under Art. 46(2)(c) (specify module and execution date)
    • Binding Corporate Rules under Art. 47 (specify approval reference)
    • Derogation under Art. 49 (specify which derogation and why it applies)
  • Transfer Impact Assessment reference (required per EDPB Recommendations 01/2020 for SCCs)

Example:

DestinationRecipientMechanismTIA Reference
United StatesVeeva Systems Inc.EU-US Data Privacy Framework adequacy decision (10 July 2023) — Veeva listed on DPF ListTIA-2024-VEEVA-001
United KingdomHelix Biotech Solutions LtdUK adequacy decision (28 June 2021, extended)Not required (adequacy)
IndiaWipro Ltd (IT support)EU SCCs Module 2 (controller-to-processor), executed 2024-06-01TIA-2024-WIPRO-003
Show full SKILL.md (618 more words)Show less
Field 7: Retention Periods — Art. 30(1)(f)

Specify the envisaged time limits for erasure of each category of data, or the criteria used to determine the retention period. Periods must be concrete and objectively determinable.

Example retention schedule:

Data CategoryRetention PeriodLegal Basis for RetentionDeletion Method
Employee payroll records10 years from end of employmentSection 257 HGB, Section 147 AOAutomated deletion from SAP HCM
Clinical trial data25 years from trial completionSection 13(10) GCP-V; ICH E6(R2)Archived then destroyed per SOP-DM-012
Job applicant data6 months from hiring decisionAGG limitation periodAutomated purge from ATS
Website analytics14 months from collectionCNIL recommendation on analytics retentionGA4 automatic data expiration
CCTV footage72 hours rollingProportionality assessment (DPO approved)Automated overwrite on NVR
Security Measures Description — Art. 30(1)(g)

While not a numbered "field" in the same sense, Art. 30(1)(g) requires a general description of Art. 32 technical and organisational security measures. This description should be meaningful without revealing specific vulnerabilities.

Example:

Technical measures: AES-256 encryption at rest for all databases containing personal data; TLS 1.3 for data in transit; role-based access control (RBAC) with quarterly access reviews; multi-factor authentication for all systems processing personal data; daily encrypted backups with 30-day retention; network segmentation isolating clinical trial systems from corporate IT; endpoint detection and response (EDR) on all workstations; annual penetration testing by independent assessor.

Organisational measures: Mandatory data protection training for all employees (annual refresher); background checks for employees with access to special category data; clean desk policy; data classification scheme (Public, Internal, Confidential, Restricted); incident response procedure with 4-hour initial assessment SLA; vendor security assessments prior to engagement; ISO 27001:2022 certified ISMS (certificate ref: IS 782341).

RoPA Entry Assembly Workflow

  1. Identify the processing activity: Start with a specific processing activity, not a department or system. One system may support multiple processing activities, each requiring its own RoPA entry.

  2. Interview the processing owner: Conduct a structured interview covering all seven fields. Use the data flow as the narrative: "Data comes from [source] about [data subjects], containing [data categories], for the purpose of [purpose], shared with [recipients], transferred to [countries], kept for [duration], protected by [measures]."

  3. Validate against source systems: Cross-reference interview responses with actual system configurations, data flow diagrams, and contractual documents.

  4. Draft the RoPA entry: Populate all seven fields using the templates and examples above.

  5. Review with DPO: The DPO reviews the entry for legal accuracy, particularly the purpose description, lawful basis alignment, and transfer mechanism adequacy.

  6. Obtain processing owner sign-off: The business owner confirms factual accuracy of the data flows, recipients, and retention periods.

  7. Register in the RoPA management system: Enter the validated record into the organisation's RoPA tool (e.g., OneTrust, TrustArc, or structured spreadsheet).

  8. Set review date: Schedule the next review no later than 12 months from creation, or earlier if the processing activity is high-risk.

Common Pitfalls

  1. Department-level records instead of activity-level: A single "HR" record covering all HR processing is non-compliant. Each distinct processing activity (payroll, recruitment, performance management, time tracking) requires its own entry.

  2. Missing processor chain documentation: When a processor engages sub-processors, the RoPA must reflect the entire processing chain, not just the primary processor.

  3. Conflating controller and processor roles: Where the organisation acts as both controller (for its own processing) and processor (for client data), separate RoPA entries under Art. 30(1) and Art. 30(2) are required.

  4. Ignoring informal processing: Spreadsheet-based processing, shared drives, and email-based data handling are processing activities that require RoPA entries.

  5. Static retention periods for dynamic data: Different data elements within the same processing activity may have different retention periods (e.g., contract data vs. marketing preferences collected during onboarding).

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/controller-ropa-creation of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Controller Ropa Creation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Controller Ropa Creation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Controller Ropa Creation this skillmukul975/Privacy-Data-Protection-Skills295—~3.2kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
De-identification Leakage Auditmaziyarpanahi/openmed5.5k—~1.9kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Tw Legal RAGaa0101181514/tw-legal-rag327—~580Automated safety check: PassCustom licence
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • De-identification Leakage Audit

    maziyarpanahi/openmed

    Scans text that has already been de-identified for leftover identifiers such as SSNs, card numbers, emails and dates, and blocks release if anything turns up.

    5.5k GitHub stars~1.9k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Tw Legal RAG

    aa0101181514/tw-legal-rag

    Retrieve real Taiwan court judgments with verifiable citations before answering any question about Taiwan law or case law.

    327 GitHub stars~580 tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    939 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 278 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    295 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    295 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    295 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed
  • Retention Schedule

    mukul975/Privacy-Data-Protection-Skills

    Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

    295 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Questions about Controller Ropa Creation

What does Controller Ropa Creation do?

Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and contact details, processing purposes, data subject…. Controller Ropa Creation is an agent skill from mukul975/Privacy-Data-Protection-Skills. Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and contact details, processing purposes, data subject categories, personal data categories, recipient categories, third country transfers, and retention periods.

When should I use Controller Ropa Creation?

Controller Ropa Creation fits situations like: tasks that involve Privacy and GDPR.

How do I install Controller Ropa Creation in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill controller-ropa-creation -a claude-code`. Or copy the skill folder (skills/privacy/controller-ropa-creation in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/controller-ropa-creation in your project. Claude Code loads it when a task matches its description.

How do I install Controller Ropa Creation in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill controller-ropa-creation -a codex`. Or copy the skill folder (skills/privacy/controller-ropa-creation in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/controller-ropa-creation in your project. Codex loads it when a task matches its description.

Can I use Controller Ropa Creation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill controller-ropa-creation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/controller-ropa-creation, .gemini/skills/controller-ropa-creation, .github/skills/controller-ropa-creation and .opencode/skills/controller-ropa-creation in your project.

What does Controller Ropa Creation need to run?

Going by SKILL.md and its folder, Controller Ropa Creation needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Controller Ropa Creation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Controller Ropa Creation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Controller Ropa Creation use?

Controller Ropa Creation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Controller Ropa Creation use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Controller Ropa Creation?

Skills that share tags, products or a category with Controller Ropa Creation: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), De-identification Leakage Audit (maziyarpanahi/openmed, 5.5k stars), C15t (c15t/c15t, 1.9k stars) and Tw Legal RAG (aa0101181514/tw-legal-rag, 327 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Controller Ropa Creation?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.