Examination Readiness
JoelLewis/finance_skills
Prepare for and respond to SEC and FINRA regulatory examinations across the full exam lifecycle.
Guides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for key personnel, technical demonstration…
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill dpa-inspection-prep -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills dpa-inspection-prep --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/dpa-inspection-prep .claude/skills/dpa-inspection-prep && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dpa-inspection-prep" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/dpa-inspection-prep into .claude/skills/dpa-inspection-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpa-inspection-prep", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/dpa-inspection-prepType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill dpa-inspection-prep -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills dpa-inspection-prep --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/dpa-inspection-prep .agents/skills/dpa-inspection-prep && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dpa-inspection-prep" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/dpa-inspection-prep into .agents/skills/dpa-inspection-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpa-inspection-prep", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill dpa-inspection-prep -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills dpa-inspection-prep --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/dpa-inspection-prep .cursor/skills/dpa-inspection-prep && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dpa-inspection-prep" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/dpa-inspection-prep into .cursor/skills/dpa-inspection-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpa-inspection-prep", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/dpa-inspection-prep--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill dpa-inspection-prep -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills dpa-inspection-prep --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/dpa-inspection-prep .gemini/skills/dpa-inspection-prep && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dpa-inspection-prep" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/dpa-inspection-prep into .gemini/skills/dpa-inspection-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpa-inspection-prep", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills dpa-inspection-prepInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill dpa-inspection-prep -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/dpa-inspection-prep .github/skills/dpa-inspection-prep && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dpa-inspection-prep" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/dpa-inspection-prep into .github/skills/dpa-inspection-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpa-inspection-prep", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill dpa-inspection-prep -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills dpa-inspection-prep --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/dpa-inspection-prep .opencode/skills/dpa-inspection-prep && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dpa-inspection-prep" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/dpa-inspection-prep into .opencode/skills/dpa-inspection-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dpa-inspection-prep", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dpa-inspection-prepGuides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for key personnel, technical demonstration…
Dpa Inspection Prep is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for key personnel, technical demonstration procedures, on-site logistics, response protocols, and post-inspection follow-up. Covers unannounced inspections, formal audits, and complaint-triggered investigations. Keywords: DPA inspection, supervisory authority, investigation, readiness, interview preparation, response protocol.
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Interview preparation and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dpa Inspection Prep loads about 5k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 123 tokens; SKILL.md has 2,167 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,167 words, ~5,033 tokens.
.claude/skills/dpa-inspection-prep/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Supervisory authorities (Data Protection Authorities, or DPAs) exercise investigative powers under Art. 58(1) GDPR, including the power to order controllers and processors to provide any information required for the performance of their tasks (Art. 58(1)(a)), to carry out investigations in the form of data protection audits (Art. 58(1)(b)), to carry out a review on certifications (Art. 58(1)(c)), to notify the controller or processor of an alleged infringement (Art. 58(1)(d)), to obtain access to all personal data and information necessary (Art. 58(1)(e)), and to obtain access to any premises of the controller and processor, including data processing equipment (Art. 58(1)(f)).
DPA inspections may be triggered by data subject complaints, sector-wide enforcement campaigns, data breach notifications, random selection, media reports, or whistleblower reports. The consequences of inadequate inspection performance include corrective measures under Art. 58(2), administrative fines under Art. 83, and reputational damage through enforcement action publicity.
Sentinel Compliance Group maintains a standing DPA inspection readiness program that ensures the organization can respond effectively to announced and unannounced supervisory authority contact within defined timeframes.
| Type | Description | Notice Period | GDPR Basis |
|---|---|---|---|
| Written Inquiry | DPA sends written questions requiring documented responses | 14-30 days typically | Art. 58(1)(a) |
| Announced Audit | Formal data protection audit with advance notice | 2-8 weeks | Art. 58(1)(b) |
| Unannounced Inspection | On-site visit without prior notice | None | Art. 58(1)(f) |
| Complaint Investigation | Investigation triggered by data subject complaint | Variable; often begins with written inquiry | Art. 57(1)(f), 77 |
| Breach Investigation | Investigation following a breach notification under Art. 33 | Days to weeks following notification | Art. 58(1)(a), (e) |
| Sector Sweep | Coordinated investigation across multiple organizations in a sector | Varies by DPA | Art. 57(1)(a), 58(1)(b) |
| Prior Consultation Follow-Up | DPA follow-up on an Art. 36 prior consultation | Variable | Art. 36(2) |
| Trigger | Likelihood | DPA Approach |
|---|---|---|
| Data subject complaint | High | Written inquiry focused on specific processing; may escalate to audit |
| Breach notification (Art. 33) | High | Written questions; on-site audit if breach is significant |
| Media coverage | Medium | Preliminary inquiry; may escalate based on findings |
| Sector-wide campaign | Medium | Standardized questionnaire sent to multiple organizations simultaneously |
| Whistleblower report | Medium | Targeted investigation, possibly unannounced |
| Random selection | Low-Medium | Full compliance audit; common in some DPAs (e.g., CNIL, AEPD) |
| Prior consultation obligation | Low | Follow-up on DPIA consultation outcomes |
| # | Document | GDPR Reference | Location | Owner | Last Updated |
|---|---|---|---|---|---|
| 1 | Records of Processing Activities (Controller) | Art. 30(1) | OneTrust RoPA module | DPO | Quarterly |
| 2 | Records of Processing Activities (Processor) | Art. 30(2) | OneTrust RoPA module | DPO | Quarterly |
| 3 | Privacy Policy (all versions, change history) | Art. 13-14 | Legal document repository | Legal | Per change |
| 4 | Data Protection Impact Assessments (all) | Art. 35 | DPIA register | DPO | Per assessment |
| 5 | Data Processing Agreements (all processors) | Art. 28 | Contract management system | Legal/Procurement | Per agreement |
| 6 | Legitimate Interest Assessments (all) | Art. 6(1)(f) | LIA register | Legal | Per assessment |
| 7 | International Transfer Mechanisms (SCCs, BCRs, TIAs) | Art. 44-49 | Transfer register | Legal | Per transfer |
| 8 | Breach Notification Records (all incidents) | Art. 33-34 | Incident management system | CISO/DPO | Per incident |
| 9 | DSAR Records (all requests and responses) | Art. 12-22 | DSAR management system | Privacy Ops | Per request |
| 10 | Consent Records (collection, withdrawal, preferences) | Art. 7 | CMP database | Privacy Ops | Continuous |
| 11 | DPO Appointment Documentation | Art. 37-39 | HR/Legal | Legal | Annual review |
| 12 | Privacy Training Records (all employees) | Art. 39(1)(b) | LMS | HR/Privacy | Per completion |
| 13 | Data Protection Policy and Procedures Manual | Art. 24(2) | Policy repository | DPO | Annual |
| 14 | Information Security Policy | Art. 32 | Policy repository | CISO | Annual |
| 15 | Vendor Risk Assessment Records | Art. 28(1) | Vendor management platform | Procurement | Per assessment |
| # | Document | GDPR Reference | Owner |
|---|---|---|---|
| 16 | Data flow diagrams and system architecture | Art. 30, 35(7)(a) | IT Architecture |
| 17 | Data classification inventory | Art. 5(1)(c), (e) | Data Governance |
| 18 | Retention schedule with legal basis for each period | Art. 5(1)(e) | Records Management |
| 19 | Privacy committee meeting minutes (last 24 months) | Art. 24(1) | DPO |
| 20 | Internal audit reports (privacy-related) | Art. 24(1) | Internal Audit |
| 21 | Privacy risk register | Art. 24(1), 32(1) | DPO |
| 22 | Employee privacy policy (workplace monitoring, BYOD) | Art. 13-14 | HR/Legal |
| 23 | Cookie audit results and CMP configuration | ePrivacy Directive Art. 5(3) | Marketing/IT |
| 24 | Sub-processor lists (per processor) | Art. 28(2) | Procurement |
| 25 | Privacy by design documentation for recent projects | Art. 25 | IT/Engineering |
| 26 | Supervisory authority correspondence history | Art. 31 | DPO |
| 27 | Certification and code of conduct documentation | Art. 42, 40 | DPO |
| 28 | Cross-border enforcement cooperation records | Art. 60-66 | Legal |
| 29 | EU representative appointment (if applicable) | Art. 27 | Legal |
| 30 | Binding Corporate Rules (if applicable) | Art. 47 | Legal |
| Readiness Level | Criteria | Score |
|---|---|---|
| Green (Ready) | Document exists, is current (reviewed within policy cycle), easily retrievable, and in presentable format | 3 |
| Yellow (Partially Ready) | Document exists but is overdue for review, incomplete, or requires compilation from multiple sources | 2 |
| Red (Not Ready) | Document does not exist, is significantly outdated, or cannot be located | 1 |
| N/A | Document is not applicable to the organization | — |
Readiness Score: Sum of all applicable document scores / (3 × number of applicable documents) × 100
Target: >90% Green readiness at all times
DPAs typically interview the following roles during inspections:
Topics to be prepared for:
| Topic | Key Points to Communicate | Evidence to Have Ready |
|---|---|---|
| DPO Role and Independence | DPO reports to highest management level; no instructions regarding exercise of tasks; not dismissed for performing tasks; provided adequate resources | DPO appointment letter, organizational chart, budget records, board reporting schedule |
| Privacy Program Overview | Structured program with governance, policies, training, monitoring, and continuous improvement | Privacy program charter, annual plan, maturity assessment |
| Risk Management | Systematic risk identification, DPIA program, risk register, residual risk management | DPIA register, risk assessment methodology, risk register extract |
| Regulatory Compliance | Multi-jurisdictional compliance framework, regulatory change management, gap analysis | Compliance matrix, regulatory tracker, gap remediation status |
| Data Subject Rights | Established DSAR procedures with SLA tracking, quality review, and escalation | DSAR metrics, sample responses (redacted), process documentation |
| International Transfers | Transfer mapping, appropriate safeguards, TIA methodology | Transfer register, TIAs, SCC execution records |
DPO Interview Principles:
Topics to be prepared for:
| Topic | Key Points | Evidence |
|---|---|---|
| Security Measures (Art. 32) | Encryption (at rest, in transit), access controls, logging, patch management, vulnerability management | Security architecture diagram, encryption configuration, RBAC matrix, pen test results |
| Breach Detection and Response | SIEM configuration, detection rules, incident response plan, notification procedures | SIEM dashboard, incident response plan, tabletop exercise records |
| Data Deletion and Retention | Technical enforcement of retention periods, secure deletion methods, backup deletion | Deletion job logs, NIST SP 800-88 compliance, retention automation configuration |
| Access Management | Identity and access management, privileged access controls, access reviews, deprovisioning | IAM configuration, access review records, deprovisioning SOP |
| Pseudonymisation and Anonymisation | Techniques used, reversibility assessments, key management | Technical documentation, anonymisation risk assessments |
Topics to be prepared for:
| Topic | Key Points | Evidence |
|---|---|---|
| Processing Purpose and Lawful Basis | Clearly articulate why data is collected and processed; identify lawful basis | RoPA entry, LIA (if legitimate interest), consent records (if consent) |
| Data Minimisation | Explain why each data element is necessary | Data element justification per purpose |
| Data Subject Information | How data subjects are informed about the processing | Privacy notice, layered notices, just-in-time notifications |
| Retention | How long data is kept and why | Retention schedule, legal basis for retention periods |
| Third-Party Sharing | Who receives the data and why | Recipient list, DPAs, data flow diagrams |
Before the Interview:
During the Interview:
After the Interview:
| Demonstration | What the DPA Wants to See | Preparation Steps |
|---|---|---|
| DSAR Fulfillment | End-to-end DSAR processing from intake to response | Prepare test DSAR in staging environment; walk through each step; show identity verification, data retrieval from all systems, response review, and delivery |
| Consent Management | Consent collection, storage, withdrawal processing | Show CMP configuration; demonstrate consent capture; show consent database records; demonstrate withdrawal processing and downstream enforcement |
| Data Deletion | Technical deletion process upon retention expiry or erasure request | Show deletion job configuration; demonstrate deletion execution in staging; show verification that data is unrecoverable; address backup deletion |
| Access Controls | RBAC configuration for personal data access | Show IAM system; demonstrate role assignments; show access review process; demonstrate that unauthorized users cannot access PII |
| Encryption | Encryption at rest and in transit for personal data | Show database encryption configuration; demonstrate TLS certificate deployment; show key management procedures |
| Breach Detection | How breaches are detected and assessed | Show SIEM rules; demonstrate alert workflow; walk through a simulated breach scenario |
| Logging and Audit Trail | Access logging for personal data | Show log configuration; demonstrate log review process; show log retention and integrity controls |
DPA Arrives On-Site
↓
Reception notifies DPO/Legal (immediate phone call)
↓
DPO/Legal arrives at reception within 15 minutes
↓
Verify inspector credentials (official ID, authorization letter)
↓
Confirm scope of inspection (which processing activities, which legal basis)
↓
Escort inspectors at all times (never leave unaccompanied)
↓
Provide requested documents (copies, not originals)
↓
Designate meeting room for interviews
↓
Note-taker present at all interactions
↓
Do not obstruct (Art. 83(5)(e): failure to cooperate is fineable)
↓
At conclusion: obtain list of follow-up requests and deadlines
↓
Internal debrief within 2 hours of departureWritten Inquiry Received (email, letter, secure portal)
↓
DPO acknowledges receipt within 2 business days
↓
Legal reviews the inquiry for scope and legal basis
↓
DPO assigns response owner(s) for each question
↓
Response drafting (owner gathers evidence, drafts responses)
↓
DPO reviews draft responses for accuracy and completeness
↓
Legal reviews for legal privilege, scope compliance, and strategic considerations
↓
Senior management approves (if required by response materiality)
↓
Response submitted via the DPA's specified channel
↓
Response logged in DPA correspondence register
↓
Deadline: per DPA instruction (typically 14-30 days; request extension if needed)| Situation | Escalation Level | Action |
|---|---|---|
| Routine written inquiry | DPO + responsible business unit | Standard response process |
| Announced audit | DPO + Legal + CISO + CPO | Formal preparation, legal strategy session |
| Unannounced inspection | DPO + Legal + CPO + CEO notification | Immediate response protocol |
| Complaint investigation (material) | DPO + Legal + business unit head | Targeted response, root cause analysis |
| Breach investigation | DPO + Legal + CISO + CPO + CEO | Full incident response team activation |
| Formal enforcement proceedings | DPO + Legal + external counsel + CPO + CEO + Board notification | Legal defense strategy, external counsel engagement |
When the DPA issues findings or recommendations:
| DPA Action | Required Response | Timeline |
|---|---|---|
| Informal recommendation | Voluntary implementation; document decision | 30-60 days |
| Formal warning (Art. 58(2)(a)) | Acknowledge; implement corrective measures; report back | Per DPA instruction |
| Order to comply (Art. 58(2)(c)-(j)) | Implement required changes; report compliance | Per DPA instruction (typically 30-90 days) |
| Administrative fine (Art. 83) | Pay fine OR appeal; implement corrective measures regardless | Payment per DPA instruction; appeal within national deadline |
| Processing ban (Art. 58(2)(f)) | Immediately cease processing; implement required measures; request lifting of ban | Immediate; restoration upon compliance demonstration |
After every DPA interaction:
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/dpa-inspection-prep of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Dpa Inspection Prep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dpa Inspection Prep this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~5k | Automated safety check: Pass | Apache-2.0 | |
| Examination ReadinessJoelLewis/finance_skills | 206 | — | ~9.8k | Automated safety check: Pass | MIT | |
| Tech Contract Negotiation Patrick Munrolawve-ai/awesome-legal-skills | 847 | — | ~4.9k | Automated safety check: Pass | AGPL-3.0 | |
| Vendor Due Diligence Patrick Munrolawve-ai/awesome-legal-skills | 847 | — | ~4.1k | Automated safety check: Pass | AGPL-3.0 | |
| Operational Designmagnus919/agent-skills | 115 | — | ~1.4k | Automated safety check: Pass | MIT | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 |
JoelLewis/finance_skills
Prepare for and respond to SEC and FINRA regulatory examinations across the full exam lifecycle.
lawve-ai/awesome-legal-skills
Systematic contract negotiation strategies for technology services agreements with German/EU law specificity.
lawve-ai/awesome-legal-skills
Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.
magnus919/agent-skills
Design and improve operational processes, controls, metrics, vendors, and scaling models through bounded pilots and evidence.
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Guides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for key personnel, technical demonstration…. Dpa Inspection Prep is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for key personnel, technical demonstration procedures, on-site logistics, response protocols, and post-inspection follow-up.
Dpa Inspection Prep fits situations like: tasks that involve Interview preparation; tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill dpa-inspection-prep -a claude-code`. Or copy the skill folder (skills/privacy/dpa-inspection-prep in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/dpa-inspection-prep in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill dpa-inspection-prep -a codex`. Or copy the skill folder (skills/privacy/dpa-inspection-prep in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/dpa-inspection-prep in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill dpa-inspection-prep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dpa-inspection-prep, .gemini/skills/dpa-inspection-prep, .github/skills/dpa-inspection-prep and .opencode/skills/dpa-inspection-prep in your project.
Going by SKILL.md and its folder, Dpa Inspection Prep needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Dpa Inspection Prep is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dpa Inspection Prep: Examination Readiness (JoelLewis/finance_skills, 206 stars), Tech Contract Negotiation Patrick Munro (lawve-ai/awesome-legal-skills, 847 stars), Vendor Due Diligence Patrick Munro (lawve-ai/awesome-legal-skills, 847 stars) and Operational Design (magnus919/agent-skills, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.