C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Manages Data Subject Access Request procedures for employee requests under Art.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-dsar-response --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/employee-dsar-response .claude/skills/employee-dsar-response && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "employee-dsar-response" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-dsar-response into .claude/skills/employee-dsar-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-dsar-response", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-dsar-responseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-dsar-response --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/employee-dsar-response .agents/skills/employee-dsar-response && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "employee-dsar-response" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-dsar-response into .agents/skills/employee-dsar-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-dsar-response", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-dsar-response --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/employee-dsar-response .cursor/skills/employee-dsar-response && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "employee-dsar-response" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-dsar-response into .cursor/skills/employee-dsar-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-dsar-response", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/employee-dsar-response--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-dsar-response --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/employee-dsar-response .gemini/skills/employee-dsar-response && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "employee-dsar-response" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-dsar-response into .gemini/skills/employee-dsar-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-dsar-response", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-dsar-responseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/employee-dsar-response .github/skills/employee-dsar-response && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "employee-dsar-response" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-dsar-response into .github/skills/employee-dsar-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-dsar-response", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-dsar-response --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/employee-dsar-response .opencode/skills/employee-dsar-response && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "employee-dsar-response" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-dsar-response into .opencode/skills/employee-dsar-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-dsar-response", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
employee-dsar-responseManages Data Subject Access Request procedures for employee requests under Art.
Employee Dsar Response is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages Data Subject Access Request procedures for employee requests under Art. 15 GDPR. Covers scope of disclosable HR records, emails, CCTV footage, performance reviews, monitoring data, and training records. Implements third-party data redaction, legal professional privilege, exemptions for ongoing proceedings, and the one-month response timeline. Keywords: DSAR, subject access request, Art. 15, employee records, redaction, privilege, HR data, SAR.
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Employee Dsar Response loads about 4.8k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 2,433 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,433 words, ~4,794 tokens.
.claude/skills/employee-dsar-response/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Employee Data Subject Access Requests (DSARs) are among the most complex and resource-intensive DSARs that organisations receive. Unlike customer DSARs, which typically involve a defined set of transactional data, employee DSARs can span the entire employment lifecycle and encompass data held across dozens of systems: HR records, emails (sent, received, and about the employee), CCTV footage, access control logs, telephone recordings, performance reviews, investigation files, grievance records, occupational health reports, training records, payroll data, expense claims, monitoring data, and informal notes and communications between managers. The scope, combined with the need to redact third-party personal data and assess legal privilege, makes employee DSARs a distinct operational and legal challenge.
This skill provides a structured response process, a comprehensive data source inventory, and decision frameworks for the exemptions and redactions most commonly encountered in employee DSARs.
Under Art. 15(1), the employee has the right to obtain from the controller:
| Information | Detail |
|---|---|
| Confirmation of processing | Whether personal data concerning the employee is being processed |
| Access to the data | A copy of the personal data undergoing processing |
| Purposes | The purposes of the processing |
| Categories | The categories of personal data concerned |
| Recipients | Recipients or categories of recipients to whom data has been or will be disclosed |
| Retention | The envisaged period of storage, or criteria used to determine the period |
| Rights | The right to rectification, erasure, restriction, and objection |
| Source | Where data was not collected from the employee, information about the source |
| Automated decisions | The existence of automated decision-making including profiling under Art. 22, with meaningful information about the logic, significance, and envisaged consequences |
| Transfer safeguards | Where data is transferred to a third country, the appropriate safeguards under Art. 46 |
The controller shall provide a copy of the personal data undergoing processing. For any further copies requested, the controller may charge a reasonable fee based on administrative costs. Where the request is made by electronic means, the information shall be provided in a commonly used electronic form, unless otherwise requested.
"The right to obtain a copy referred to in paragraph 3 shall not adversely affect the rights and freedoms of others."
This provision is the legal basis for redacting third-party personal data from DSAR disclosures.
The following data sources must be searched when processing an employee DSAR:
| Data Source | System/Location | Data Types |
|---|---|---|
| HR Information System | Workday, SAP SuccessFactors, BambooHR, etc. | Personal details, employment history, contract, salary, benefits, absence records, performance ratings |
| Email system | Microsoft 365, Google Workspace | Emails sent by the employee, received by the employee, and about the employee |
| CCTV system | On-premise recording system | Video footage where the employee is identifiable |
| Access control system | Badge/proximity card system | Entry/exit logs, access attempts to restricted areas |
| Time and attendance | Timekeeping system, biometric readers | Clock-in/out records, attendance patterns |
| Payroll system | SAP, ADP, Sage | Salary history, tax records, pension contributions, benefits |
| Performance management | Workday, Lattice, Culture Amp, etc. | Performance reviews, objectives, competency assessments, calibration data, 360 feedback |
| Learning management system | Cornerstone, SAP LMS, etc. | Training records, certifications, mandatory training completion |
| Recruitment system | Greenhouse, Lever, Workable | Application data, interview notes, assessment scores (for recent hires) |
| Disciplinary and grievance files | HR case management, paper files | Investigation notes, witness statements, outcome letters |
| Occupational health records | OH provider system | Fitness-for-work reports, referral correspondence |
| Monitoring systems | DLP, web proxy, MDM | Email monitoring alerts, internet usage logs, device management data |
| Expenses system | Concur, Expensify | Expense claims, receipts, approval records |
| Informal records | Line manager email, notes, instant messages | Notes about the employee, performance observations, management discussions |
| Telephone system | Call recording platform | Recorded calls where the employee is a participant |
| IT system logs | Active Directory, service desk | Account activity, password resets, service desk tickets |
| File servers and SharePoint | Shared drives, collaboration platforms | Documents authored by or concerning the employee |
Not every data source must be searched exhaustively for every DSAR. The search scope should be proportionate to:
Day 1: Receipt and Acknowledgment
Days 2-5: Scoping
Days 5-20: Collection
Days 15-25: Review and Redaction
Days 25-30: Quality Check and Dispatch
The right of access must not adversely affect the rights and freedoms of others. This requires redaction of third-party personal data unless:
Redaction decision matrix:
| Data Type | Redact? | Reasoning |
|---|---|---|
| Names of other employees mentioned in emails about the requesting employee | Generally yes, unless the third party's name is already known to the requestor (e.g., their line manager) | Balance third-party privacy against requestor's right |
| Witness statements in disciplinary investigations | Redact witness identity; disclose substance of allegations | Witness confidentiality vs. right to know allegations |
| 360 feedback with named reviewers | Redact reviewer names; disclose feedback content | Reviewers' reasonable expectation of anonymity |
| Email addresses in CC fields | Generally redact unless already known to requestor | Minimal privacy expectation but apply consistently |
| References provided by the employee's former employer | Disclose — this is the requestor's personal data | The employee has a right to see references about them |
| Performance calibration meeting notes naming other employees | Redact other employees' names and performance data | Other employees' performance data is their personal data |
Personal data is exempt from Art. 15 to the extent that disclosure would involve disclosing information in respect of which a claim to legal professional privilege (LPP) or confidentiality of communications could be maintained in legal proceedings.
| Privilege Type | Scope | Application |
|---|---|---|
| Legal advice privilege | Confidential communications between client and lawyer for the purpose of obtaining or giving legal advice | Employment law advice about the employee's situation, HR consulting legal counsel about a grievance |
| Litigation privilege | Communications created for the dominant purpose of litigation that is in progress or reasonably anticipated | Documents prepared in anticipation of an employment tribunal claim |
| Without prejudice privilege | Communications made in a genuine attempt to settle a dispute | Settlement negotiation correspondence |
Where disclosure would prejudice ongoing legal proceedings, disciplinary investigations, or regulatory investigations:
| Scenario | Exemption | Scope |
|---|---|---|
| Active disciplinary investigation | May withhold investigation materials that would prejudice the investigation | Temporary — must be disclosed once the investigation concludes |
| Pending employment tribunal claim | Litigation privilege applies to documents prepared for the dominant purpose of litigation | Duration of the legal proceedings |
| Regulatory investigation (e.g., FCA, HSE) | May withhold documents that would prejudice the regulatory investigation | Coordinate with the regulator |
Personal data processed for management forecasting or management planning is exempt from Art. 15 to the extent that disclosure would prejudice the planning or forecasting. This may cover:
Limitation: This exemption is narrow and temporary — it applies only while disclosure would genuinely prejudice the planning activity.
Personal data consisting of a record of the controller's intentions in relation to negotiations with the data subject is exempt to the extent that disclosure would prejudice those negotiations. This may cover:
| Pitfall | Risk | Resolution |
|---|---|---|
| Failing to search email for "about" data | Incomplete disclosure; ICO complaint | Search line manager and HR mailboxes for the employee's name |
| Over-redaction of manager names | Excessive withholding undermines the right of access | Manager names may be disclosed where the employment relationship means the employee already knows their identity |
| Missing the one-month deadline | Regulatory complaint; enforcement action | Implement automated deadline tracking; request extension early if needed |
| Disclosing third-party special category data | Breach of Art. 9 + third-party complaint | Review all disclosures for special category data of third parties |
| Ignoring informal records | Manager personal notes are personal data and must be searched | Include managers' informal notes in the search scope |
| Treating all DSAR as routine | Employee DSARs often indicate a grievance or impending legal claim | Alert legal counsel when a DSAR is received from an employee in a dispute |
Atlas received a DSAR from an employee who had recently been placed on a Performance Improvement Plan (PIP). The DSAR coordinator:
| Authority | Case | Fine/Outcome | Key Issue |
|---|---|---|---|
| ICO (UK) | Mermaids, 2023 | Enforcement notice | Failure to respond to employee DSARs within statutory timeframe |
| CNIL (France) | SAN-2022-009 | EUR 800,000 | Employer failed to provide employee with access to performance evaluation data within one month |
| AEPD (Spain) | PS/00231/2021 | EUR 70,000 | Employer refused employee DSAR claiming disproportionate effort without conducting proper search |
| Autoriteit Persoonsgegevens (NL) | 2022 Decision | EUR 525,000 | Employer provided incomplete DSAR response, omitting email data about the employee |
| Garante (Italy) | Provvedimento 2021-0234 | Corrective order | Employer over-redacted employee DSAR response, withholding non-privileged management communications |
| Datainspektionen (Sweden) | DI-2022-1456 | SEK 200,000 | Employer failed to search backup systems for former employee's DSAR |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/employee-dsar-response of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Employee Dsar Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Employee Dsar Response this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Manages Data Subject Access Request procedures for employee requests under Art. Employee Dsar Response is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages Data Subject Access Request procedures for employee requests under Art.
Employee Dsar Response fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a claude-code`. Or copy the skill folder (skills/privacy/employee-dsar-response in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/employee-dsar-response in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a codex`. Or copy the skill folder (skills/privacy/employee-dsar-response in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/employee-dsar-response in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-dsar-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/employee-dsar-response, .gemini/skills/employee-dsar-response, .github/skills/employee-dsar-response and .opencode/skills/employee-dsar-response in your project.
Going by SKILL.md and its folder, Employee Dsar Response needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Employee Dsar Response is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Employee Dsar Response: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.