Agent skill

Employee Dsar Response

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Manages Data Subject Access Request procedures for employee requests under Art.

Apache-2.0Auto-check passedLegal & Compliance

Install Employee Dsar Response

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-dsar-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/employee-dsar-response .claude/skills/employee-dsar-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
employee-dsar-response
GitHub stars
301
Token cost
~4.8k tokens
SKILL.md length
2,433 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manages Data Subject Access Request procedures for employee requests under Art.

  • Works in 3 steps: The request scope: If the employee has… → The employment context: A current… → Reasonableness: Art. 12(5) allows…
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Art. 15 — Right of Access, Employee DSAR Data Source… and Response Timeline, plus 7 more sections
  • Runs Python scripts from its folder

What it does

Employee Dsar Response is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages Data Subject Access Request procedures for employee requests under Art. 15 GDPR. Covers scope of disclosable HR records, emails, CCTV footage, performance reviews, monitoring data, and training records. Implements third-party data redaction, legal professional privilege, exemptions for ongoing proceedings, and the one-month response timeline. Keywords: DSAR, subject access request, Art. 15, employee records, redaction, privilege, HR data, SAR.

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the employee-dsar-response skill to manage Data Subject Access Request procedures for employee requests under Art”
  • “/employee-dsar-response”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. The request scope: If the employee has specified particular data they are seeking (e.g., "I request copies of all performance reviews from…
  2. The employment context: A current employee's DSAR typically spans the entire employment period; a former employee's data may have been…
  3. Reasonableness: Art. 12(5) allows refusal of requests that are "manifestly unfounded or excessive" — a request for "every email I was ever…

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Employee Dsar Response loads about 4.8k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 2,433 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,433 words, ~4,794 tokens.

Download SKILL.mdSave it as .claude/skills/employee-dsar-response/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
employee-dsar-response
description
Manages Data Subject Access Request procedures for employee requests under Art. 15 GDPR. Covers scope of disclosable HR records, emails, CCTV footage, performance reviews, monitoring data, and training records. Implements third-party data redaction, legal professional privilege, exemptions for ongoing proceedings, and the one-month response timeline. Keywords: DSAR, subject access request, Art. 15, employee records, redaction, privilege, HR data, SAR.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
employee-data-privacy
metadata.tags
dsar, subject-access-request, article-15, employee-records, redaction, privilege

Employee DSAR Response

Overview

Employee Data Subject Access Requests (DSARs) are among the most complex and resource-intensive DSARs that organisations receive. Unlike customer DSARs, which typically involve a defined set of transactional data, employee DSARs can span the entire employment lifecycle and encompass data held across dozens of systems: HR records, emails (sent, received, and about the employee), CCTV footage, access control logs, telephone recordings, performance reviews, investigation files, grievance records, occupational health reports, training records, payroll data, expense claims, monitoring data, and informal notes and communications between managers. The scope, combined with the need to redact third-party personal data and assess legal privilege, makes employee DSARs a distinct operational and legal challenge.

This skill provides a structured response process, a comprehensive data source inventory, and decision frameworks for the exemptions and redactions most commonly encountered in employee DSARs.

Art. 15 — Right of Access

What the Employee Is Entitled To

Under Art. 15(1), the employee has the right to obtain from the controller:

InformationDetail
Confirmation of processingWhether personal data concerning the employee is being processed
Access to the dataA copy of the personal data undergoing processing
PurposesThe purposes of the processing
CategoriesThe categories of personal data concerned
RecipientsRecipients or categories of recipients to whom data has been or will be disclosed
RetentionThe envisaged period of storage, or criteria used to determine the period
RightsThe right to rectification, erasure, restriction, and objection
SourceWhere data was not collected from the employee, information about the source
Automated decisionsThe existence of automated decision-making including profiling under Art. 22, with meaningful information about the logic, significance, and envisaged consequences
Transfer safeguardsWhere data is transferred to a third country, the appropriate safeguards under Art. 46
Art. 15(3) — Format

The controller shall provide a copy of the personal data undergoing processing. For any further copies requested, the controller may charge a reasonable fee based on administrative costs. Where the request is made by electronic means, the information shall be provided in a commonly used electronic form, unless otherwise requested.

Art. 15(4) — Third-Party Rights

"The right to obtain a copy referred to in paragraph 3 shall not adversely affect the rights and freedoms of others."

This provision is the legal basis for redacting third-party personal data from DSAR disclosures.

Employee DSAR Data Source Inventory

Comprehensive Search Scope

The following data sources must be searched when processing an employee DSAR:

Data SourceSystem/LocationData Types
HR Information SystemWorkday, SAP SuccessFactors, BambooHR, etc.Personal details, employment history, contract, salary, benefits, absence records, performance ratings
Email systemMicrosoft 365, Google WorkspaceEmails sent by the employee, received by the employee, and about the employee
CCTV systemOn-premise recording systemVideo footage where the employee is identifiable
Access control systemBadge/proximity card systemEntry/exit logs, access attempts to restricted areas
Time and attendanceTimekeeping system, biometric readersClock-in/out records, attendance patterns
Payroll systemSAP, ADP, SageSalary history, tax records, pension contributions, benefits
Performance managementWorkday, Lattice, Culture Amp, etc.Performance reviews, objectives, competency assessments, calibration data, 360 feedback
Learning management systemCornerstone, SAP LMS, etc.Training records, certifications, mandatory training completion
Recruitment systemGreenhouse, Lever, WorkableApplication data, interview notes, assessment scores (for recent hires)
Disciplinary and grievance filesHR case management, paper filesInvestigation notes, witness statements, outcome letters
Occupational health recordsOH provider systemFitness-for-work reports, referral correspondence
Monitoring systemsDLP, web proxy, MDMEmail monitoring alerts, internet usage logs, device management data
Expenses systemConcur, ExpensifyExpense claims, receipts, approval records
Informal recordsLine manager email, notes, instant messagesNotes about the employee, performance observations, management discussions
Telephone systemCall recording platformRecorded calls where the employee is a participant
IT system logsActive Directory, service deskAccount activity, password resets, service desk tickets
File servers and SharePointShared drives, collaboration platformsDocuments authored by or concerning the employee
Search Strategy

Not every data source must be searched exhaustively for every DSAR. The search scope should be proportionate to:

  1. The request scope: If the employee has specified particular data they are seeking (e.g., "I request copies of all performance reviews from 2022-2025"), the search can be focused accordingly
  2. The employment context: A current employee's DSAR typically spans the entire employment period; a former employee's data may have been partially deleted under retention policies
  3. Reasonableness: Art. 12(5) allows refusal of requests that are "manifestly unfounded or excessive" — a request for "every email I was ever mentioned in" across a 20-year career may be excessive, but the bar for refusal is high

Response Timeline

Standard Timeline — Art. 12(3)
  • One calendar month from receipt of the DSAR
  • The month runs from the day after receipt (if received on 15 March, the deadline is 15 April)
  • If the deadline falls on a weekend or public holiday, the deadline extends to the next working day (ICO guidance)
Extension — Art. 12(3)
  • The deadline may be extended by two further months where the request is complex or the controller has received numerous requests from the same individual
  • The controller must inform the employee of the extension within one month of receipt, together with the reasons for the delay
  • Employee DSARs frequently justify extension due to the volume of data sources, redaction complexity, and legal privilege review
Employee DSAR Response Process

Day 1: Receipt and Acknowledgment

  1. Log the DSAR in the central DSAR register with a unique reference number
  2. Verify the employee's identity (for current employees, identity is typically confirmed through the employment relationship; for former employees, additional verification may be needed)
  3. Send acknowledgment confirming receipt and expected response date
  4. Assign a DSAR coordinator (typically from the privacy/DPO team)

Days 2-5: Scoping

  1. Review the request to determine scope — is the request for all data, or specific categories?
  2. If the request is unclear, contact the employee to clarify scope (the clarification period does not pause the clock unless the request genuinely cannot be processed without clarification — ICO guidance)
  3. Map the request to the data source inventory
  4. Identify custodians for each data source and issue collection instructions
  5. Assess whether an extension is likely needed; if so, notify the employee within the first month

Days 5-20: Collection

  1. Each data custodian searches their system(s) and exports relevant data
  2. Email searches: search for the employee's name and email address in mailboxes of direct managers, HR business partners, and relevant stakeholders
  3. CCTV: identify time periods and locations where footage may contain the employee
  4. Paper files: retrieve physical personnel file and any archived records
  5. All collected data must be logged with source, custodian, and date of extraction

Days 15-25: Review and Redaction

  1. Review all collected data for personal data of the requesting employee
  2. Identify and redact third-party personal data (see redaction framework below)
  3. Identify and withhold legally privileged material (see privilege framework below)
  4. Identify and assess any other applicable exemptions
  5. Compile the disclosure package

Days 25-30: Quality Check and Dispatch

  1. DPO or senior privacy officer reviews the disclosure package for completeness and proper redaction
  2. Prepare a covering letter explaining: scope of search, any exemptions applied, the employee's right to complain to the supervisory authority
  3. Deliver the disclosure to the employee via secure channel (encrypted email, secure portal, or registered post)

Redaction Framework

Third-Party Personal Data — Art. 15(4)

The right of access must not adversely affect the rights and freedoms of others. This requires redaction of third-party personal data unless:

  • The third party has consented to disclosure, or
  • It is reasonable in all circumstances to disclose without consent

Redaction decision matrix:

Data TypeRedact?Reasoning
Names of other employees mentioned in emails about the requesting employeeGenerally yes, unless the third party's name is already known to the requestor (e.g., their line manager)Balance third-party privacy against requestor's right
Witness statements in disciplinary investigationsRedact witness identity; disclose substance of allegationsWitness confidentiality vs. right to know allegations
360 feedback with named reviewersRedact reviewer names; disclose feedback contentReviewers' reasonable expectation of anonymity
Email addresses in CC fieldsGenerally redact unless already known to requestorMinimal privacy expectation but apply consistently
References provided by the employee's former employerDisclose — this is the requestor's personal dataThe employee has a right to see references about them
Performance calibration meeting notes naming other employeesRedact other employees' names and performance dataOther employees' performance data is their personal data
Practical Redaction Technique
  • Use permanent redaction (not highlight or track-changes redaction)
  • Replace names with "Person A," "Person B" consistently throughout the disclosure
  • Redact email addresses, phone numbers, and job titles that could identify third parties
  • Do not redact the requesting employee's own data or information they already know
Show full SKILL.md (981 more words)Show less
UK — DPA 2018, Schedule 2, Part 4, Paragraph 19

Personal data is exempt from Art. 15 to the extent that disclosure would involve disclosing information in respect of which a claim to legal professional privilege (LPP) or confidentiality of communications could be maintained in legal proceedings.

Types of Privilege
Privilege TypeScopeApplication
Legal advice privilegeConfidential communications between client and lawyer for the purpose of obtaining or giving legal adviceEmployment law advice about the employee's situation, HR consulting legal counsel about a grievance
Litigation privilegeCommunications created for the dominant purpose of litigation that is in progress or reasonably anticipatedDocuments prepared in anticipation of an employment tribunal claim
Without prejudice privilegeCommunications made in a genuine attempt to settle a disputeSettlement negotiation correspondence
Privilege Review Process
  1. All documents flagged as potentially privileged must be reviewed by legal counsel
  2. Legal counsel determines whether privilege applies to each document
  3. Privileged documents are withheld and listed in a privilege log
  4. The covering letter to the employee must state that certain information has been withheld under the legal privilege exemption, without revealing the privileged content
  5. If only part of a document is privileged, the non-privileged portions must be disclosed

Other Exemptions Applicable to Employee DSARs

Ongoing Proceedings Exemption

Where disclosure would prejudice ongoing legal proceedings, disciplinary investigations, or regulatory investigations:

ScenarioExemptionScope
Active disciplinary investigationMay withhold investigation materials that would prejudice the investigationTemporary — must be disclosed once the investigation concludes
Pending employment tribunal claimLitigation privilege applies to documents prepared for the dominant purpose of litigationDuration of the legal proceedings
Regulatory investigation (e.g., FCA, HSE)May withhold documents that would prejudice the regulatory investigationCoordinate with the regulator
Management Planning Exemption — UK DPA 2018, Schedule 2, Part 4, Paragraph 24

Personal data processed for management forecasting or management planning is exempt from Art. 15 to the extent that disclosure would prejudice the planning or forecasting. This may cover:

  • Redundancy selection criteria before announcement
  • Organisational restructuring plans naming affected employees
  • Succession planning documents

Limitation: This exemption is narrow and temporary — it applies only while disclosure would genuinely prejudice the planning activity.

Negotiations Exemption — UK DPA 2018, Schedule 2, Part 4, Paragraph 25

Personal data consisting of a record of the controller's intentions in relation to negotiations with the data subject is exempt to the extent that disclosure would prejudice those negotiations. This may cover:

  • Employer's settlement offer strategy
  • Planned salary adjustment before communication
  • Internal discussion of disciplinary sanction before outcome notification

Common Pitfalls

PitfallRiskResolution
Failing to search email for "about" dataIncomplete disclosure; ICO complaintSearch line manager and HR mailboxes for the employee's name
Over-redaction of manager namesExcessive withholding undermines the right of accessManager names may be disclosed where the employment relationship means the employee already knows their identity
Missing the one-month deadlineRegulatory complaint; enforcement actionImplement automated deadline tracking; request extension early if needed
Disclosing third-party special category dataBreach of Art. 9 + third-party complaintReview all disclosures for special category data of third parties
Ignoring informal recordsManager personal notes are personal data and must be searchedInclude managers' informal notes in the search scope
Treating all DSAR as routineEmployee DSARs often indicate a grievance or impending legal claimAlert legal counsel when a DSAR is received from an employee in a dispute

Atlas Manufacturing Group Example

Atlas received a DSAR from an employee who had recently been placed on a Performance Improvement Plan (PIP). The DSAR coordinator:

  1. Logged the request and acknowledged within 24 hours
  2. Scoped the request: employee sought "all personal data held about me"
  3. Mapped data sources: HR system (SAP SuccessFactors), email (Microsoft 365 — employee's mailbox, line manager's mailbox, HR BP's mailbox), performance management (SuccessFactors Performance & Goals), time and attendance (badge system), occupational health (two referrals on file), CCTV (not requested but technically in scope — employee informed that CCTV search would require specific dates/locations), and the disciplinary file containing the PIP documentation
  4. Extended the deadline by two months due to the volume of email data and the need for legal privilege review (the employee had instructed a solicitor, and settlement discussions were ongoing)
  5. Redacted: names of other employees mentioned in performance calibration, witness names from an earlier informal investigation, and third-party email addresses
  6. Withheld under privilege: three emails between the HR Director and employment lawyer regarding the PIP and potential tribunal claim, and the without-prejudice settlement correspondence
  7. Disclosed: 847 pages of material including HR records, performance reviews, PIP documentation, line manager emails about performance, training records, and absence records
  8. The covering letter listed exemptions applied, advised the employee of the right to complain to the ICO, and confirmed the search methodology

Enforcement Precedents

AuthorityCaseFine/OutcomeKey Issue
ICO (UK)Mermaids, 2023Enforcement noticeFailure to respond to employee DSARs within statutory timeframe
CNIL (France)SAN-2022-009EUR 800,000Employer failed to provide employee with access to performance evaluation data within one month
AEPD (Spain)PS/00231/2021EUR 70,000Employer refused employee DSAR claiming disproportionate effort without conducting proper search
Autoriteit Persoonsgegevens (NL)2022 DecisionEUR 525,000Employer provided incomplete DSAR response, omitting email data about the employee
Garante (Italy)Provvedimento 2021-0234Corrective orderEmployer over-redacted employee DSAR response, withholding non-privileged management communications
Datainspektionen (Sweden)DI-2022-1456SEK 200,000Employer failed to search backup systems for former employee's DSAR

Integration Points

  • Employee Monitoring DPIA: Monitoring data is within DSAR scope (see employee-monitoring-dpia skill).
  • Employee Health Data: Health data in DSARs must be handled with particular care regarding access controls (see employee-health-data skill).
  • HR System Privacy Config: DSAR compliance depends on the HR system's ability to extract and export employee data (see hr-system-privacy-config skill).
  • Background Check Privacy: Background check data for current/former employees is within DSAR scope (see background-check-privacy skill).
  • Whistleblower Data: Whistleblower identity data has special access restrictions that may limit DSAR disclosure (see whistleblower-data skill).

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/employee-dsar-response of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Employee Dsar Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Employee Dsar Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Employee Dsar Response this skillmukul975/Privacy-Data-Protection-Skills301—~4.8kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Employee Dsar Response

What does Employee Dsar Response do?

Manages Data Subject Access Request procedures for employee requests under Art. Employee Dsar Response is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages Data Subject Access Request procedures for employee requests under Art.

When should I use Employee Dsar Response?

Employee Dsar Response fits situations like: tasks that involve Privacy and GDPR.

How do I install Employee Dsar Response in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a claude-code`. Or copy the skill folder (skills/privacy/employee-dsar-response in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/employee-dsar-response in your project. Claude Code loads it when a task matches its description.

How do I install Employee Dsar Response in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a codex`. Or copy the skill folder (skills/privacy/employee-dsar-response in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/employee-dsar-response in your project. Codex loads it when a task matches its description.

Can I use Employee Dsar Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/employee-dsar-response, .gemini/skills/employee-dsar-response, .github/skills/employee-dsar-response and .opencode/skills/employee-dsar-response in your project.

What does Employee Dsar Response need to run?

Going by SKILL.md and its folder, Employee Dsar Response needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Employee Dsar Response access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Employee Dsar Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Employee Dsar Response use?

Employee Dsar Response is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Employee Dsar Response use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Employee Dsar Response?

Skills that share tags, products or a category with Employee Dsar Response: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Employee Dsar Response?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.