C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Handles GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill criminal-data-handling -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills criminal-data-handling --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/criminal-data-handling .claude/skills/criminal-data-handling && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "criminal-data-handling" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/criminal-data-handling into .claude/skills/criminal-data-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "criminal-data-handling", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/criminal-data-handlingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill criminal-data-handling -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills criminal-data-handling --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/criminal-data-handling .agents/skills/criminal-data-handling && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "criminal-data-handling" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/criminal-data-handling into .agents/skills/criminal-data-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "criminal-data-handling", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill criminal-data-handling -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills criminal-data-handling --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/criminal-data-handling .cursor/skills/criminal-data-handling && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "criminal-data-handling" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/criminal-data-handling into .cursor/skills/criminal-data-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "criminal-data-handling", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/criminal-data-handling--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill criminal-data-handling -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills criminal-data-handling --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/criminal-data-handling .gemini/skills/criminal-data-handling && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "criminal-data-handling" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/criminal-data-handling into .gemini/skills/criminal-data-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "criminal-data-handling", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills criminal-data-handlingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill criminal-data-handling -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/criminal-data-handling .github/skills/criminal-data-handling && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "criminal-data-handling" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/criminal-data-handling into .github/skills/criminal-data-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "criminal-data-handling", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill criminal-data-handling -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills criminal-data-handling --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/criminal-data-handling .opencode/skills/criminal-data-handling && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "criminal-data-handling" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/criminal-data-handling into .opencode/skills/criminal-data-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "criminal-data-handling", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
criminal-data-handlingHandles GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills.
Criminal Data Handling is an agent skill from mukul975/Privacy-Data-Protection-Skills. Handles GDPR Art. 10 criminal conviction and offence data classification including official authority requirements, national law derogations, and comprehensive register restrictions. Covers controller obligations for criminal background checks and offence records. Keywords: criminal data, Art 10, conviction data, offence records, criminal background, DBS check.
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Criminal Data Handling loads about 3.6k tokens when it runs, and up to ~6.7k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 1,709 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,709 words, ~3,638 tokens.
.claude/skills/criminal-data-handling/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Article 10 of the GDPR establishes a separate regime for processing personal data relating to criminal convictions and offences, or related security measures. Unlike Art. 9 special category data which is subject to a general prohibition with listed exceptions, Art. 10 permits processing only under the control of official authority, or when authorised by EU or Member State law providing appropriate safeguards. The maintenance of a comprehensive register of criminal convictions is restricted to processing under the control of official authority. This skill provides a framework for identifying, classifying, and lawfully processing criminal data within enterprise contexts.
"Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority."
| Requirement | Description | Practical Implication |
|---|---|---|
| Official authority control | Processing must be supervised by or conducted under the authority of a public body with legal competence | Private sector organisations generally cannot process criminal data unless authorised by specific national law |
| National law authorisation | EU or Member State law must specifically authorise the processing and provide appropriate safeguards | Controllers must identify the specific legal provision authorising each criminal data processing activity |
| Comprehensive register prohibition | No private entity may maintain a comprehensive register of criminal convictions | Aggregating criminal records across individuals for database purposes requires official authority status |
Art. 10 operates as an additional layer on top of Art. 6. A controller processing criminal data must satisfy BOTH:
Criminal data is NOT listed in Art. 9(1) as a special category, but Member States may impose Art. 9-equivalent protections. Some data may fall under both Art. 9 and Art. 10 — for example, data about a criminal offence that also reveals racial profiling concerns or political activity.
| Category | Examples | Notes |
|---|---|---|
| Criminal convictions | Conviction records, sentences, court judgments | Core Art. 10 scope |
| Criminal offences | Charges, indictments, allegations of criminal conduct | Includes unproven allegations |
| Related security measures | Probation orders, restraining orders, electronic monitoring conditions | Post-conviction measures |
| Criminal proceedings | Arrest records, bail conditions, court appearance dates | Procedural data |
| Acquittals and dismissals | Records of charges dropped or acquittals | Still criminal data under Art. 10 |
| Cautions and warnings | Police cautions, penalty notices for disorder | Out-of-court disposals |
| Spent convictions | Convictions that are rehabilitated under national law (UK: Rehabilitation of Offenders Act 1974) | May have additional protections under national law |
| Data | Reason |
|---|---|
| Civil litigation records | Art. 10 covers criminal matters only |
| Regulatory enforcement actions (fines by supervisory authorities) | Administrative, not criminal |
| Disciplinary proceedings (employment misconduct) | Internal employment matter, not criminal |
| Credit defaults and county court judgments | Civil debt matters |
| Self-reported general "good character" statements | Not specific criminal data |
| Scenario | Art. 10 Applicable? | Reasoning |
|---|---|---|
| DBS (Disclosure and Barring Service) check results for new hires in regulated roles | YES | Contains criminal conviction and caution data |
| FCA (Financial Conduct Authority) fitness and propriety checks | YES — where criminal history is assessed | FCA Senior Managers and Certification Regime requires criminal history disclosure |
| Anti-money laundering suspicious activity reports (SARs) | BORDERLINE — YES when the SAR relates to suspected criminal activity | SAR data may constitute data relating to criminal offences (suspected fraud, money laundering) |
| Internal investigation into suspected employee fraud | YES — if the investigation relates to conduct that would constitute a criminal offence | Even where no charges are brought, investigation data relating to criminal offences falls under Art. 10 |
| Sanctions screening results | NO — unless a sanctions match relates to criminal conviction or offence | Sanctions are typically administrative/regulatory measures |
For each system, scan for data elements that may contain criminal data:
| Detection Pattern | Field Examples | Confidence |
|---|---|---|
| Criminal record identifiers | criminal_record_number, dbs_certificate_number, police_reference | High |
| Offence classifications | offence_code, charge_description, conviction_type | High |
| Court and sentencing data | court_name, sentence_type, sentence_duration, judge_name | High |
| Investigation references | investigation_id, sar_reference, fraud_case_number | Medium |
| Background check results | dbs_result, background_check_status, criminal_history_flag | High |
| Free-text fields containing criminal terminology | Any field containing "convicted", "arrested", "charged", "offence", "sentence" | Low — requires manual review |
For each identified element:
For each Art. 10 data element:
Review whether any system maintains what could constitute a "comprehensive register of criminal convictions":
CRIMINAL_ART10: Data within Art. 10 scope with identified national law authorisationCRIMINAL_ART10_NO_AUTH: Data within Art. 10 scope WITHOUT identified national law authorisation (processing must cease until authorisation established)CRIMINAL_SPENT: Spent conviction data subject to additional Rehabilitation of Offenders Act protectionsNOT_CRIMINAL: Data reviewed and confirmed outside Art. 10 scope| System | Data Elements | National Law Basis | Purpose |
|---|---|---|---|
| HR Recruitment Platform | DBS check results (basic and enhanced), criminal declaration forms | UK DPA 2018 Sch.1 Part 1 para 1 (employment); Rehabilitation of Offenders Act 1974 (Exceptions) Order 1975 | Pre-employment screening for FCA-regulated roles |
| Compliance Case Management | SAR data, internal investigation records, regulatory referral records | UK Proceeds of Crime Act 2002 s.330-332 (SAR obligations); UK DPA 2018 Sch.1 Part 2 para 14 (preventing/detecting unlawful acts) | AML compliance, fraud investigation |
| FCA Regulatory Reporting | Senior Manager criminal history declarations, Approved Person criminal record disclosures | Financial Services and Markets Act 2000 s.61 (fitness and propriety); FCA SUP 10C | Regulatory fitness and propriety assessments |
| Third-Party Due Diligence | Criminal background check results for vendors and counterparties | UK DPA 2018 Sch.1 Part 2 para 6 (regulatory requirements); Money Laundering Regulations 2017 reg.28 | Know Your Customer, vendor risk management |
| Safeguard | Implementation |
|---|---|
| Access restriction | Criminal data accessible only to designated Compliance and HR personnel with specific role-based access. Named individual authorisation list maintained. |
| Purpose limitation | Criminal data processed only for the specific purpose authorised by law. No secondary use for general HR analytics or performance management. |
| Retention limitation | DBS check results retained for maximum 6 months after recruitment decision. SAR data retained per Proceeds of Crime Act retention schedules. |
| Data minimisation | Only the outcome of criminal checks recorded (clear/not clear + relevant details), not the full criminal record unless required by specific regulation. |
| Logging and audit | All access to criminal data logged with user identity, timestamp, and purpose. Quarterly audit of access logs by DPO. |
| Spent conviction handling | System flag for spent convictions. Spent convictions excluded from standard employment checks. Visible only for roles exempt under the Exceptions Order (FCA-regulated positions). |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/criminal-data-handling of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Criminal Data Handling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Criminal Data Handling this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Handles GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills. Criminal Data Handling is an agent skill from mukul975/Privacy-Data-Protection-Skills. Handles GDPR Art.
Criminal Data Handling fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill criminal-data-handling -a claude-code`. Or copy the skill folder (skills/privacy/criminal-data-handling in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/criminal-data-handling in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill criminal-data-handling -a codex`. Or copy the skill folder (skills/privacy/criminal-data-handling in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/criminal-data-handling in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill criminal-data-handling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/criminal-data-handling, .gemini/skills/criminal-data-handling, .github/skills/criminal-data-handling and .opencode/skills/criminal-data-handling in your project.
Going by SKILL.md and its folder, Criminal Data Handling needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Criminal Data Handling is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Criminal Data Handling: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.