Coach
felixrieseberg/claude-coach
Create personalized triathlon, marathon, and ultra-endurance training plans.
Governs employee health data processing for fitness-for-work assessments, occupational health surveillance, COVID testing legacy programmes, and absence management.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-health-data -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-health-data --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/employee-health-data .claude/skills/employee-health-data && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "employee-health-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-health-data into .claude/skills/employee-health-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-health-data", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-health-dataType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-health-data -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-health-data --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/employee-health-data .agents/skills/employee-health-data && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "employee-health-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-health-data into .agents/skills/employee-health-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-health-data", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-health-data -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-health-data --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/employee-health-data .cursor/skills/employee-health-data && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "employee-health-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-health-data into .cursor/skills/employee-health-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-health-data", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/employee-health-data--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-health-data -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-health-data --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/employee-health-data .gemini/skills/employee-health-data && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "employee-health-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-health-data into .gemini/skills/employee-health-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-health-data", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-health-dataInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-health-data -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/employee-health-data .github/skills/employee-health-data && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "employee-health-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-health-data into .github/skills/employee-health-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-health-data", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-health-data -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-health-data --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/employee-health-data .opencode/skills/employee-health-data && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "employee-health-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-health-data into .opencode/skills/employee-health-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-health-data", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
employee-health-dataGoverns employee health data processing for fitness-for-work assessments, occupational health surveillance, COVID testing legacy programmes, and absence management.
Employee Health Data is an agent skill from mukul975/Privacy-Data-Protection-Skills. Governs employee health data processing for fitness-for-work assessments, occupational health surveillance, COVID testing legacy programmes, and absence management. Applies Art. 9(2)(b) employment obligations and Art. 9(2)(h) health professional exceptions. Covers data minimisation, occupational health provider relationships, and return-to-work procedures. Keywords: health data, Art. 9, occupational health, fitness-for-work, special category, employment, sickness absence.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Productivity & Automation, covering Health and fitness tracking. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Employee Health Data loads about 3.9k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 124 tokens; SKILL.md has 1,884 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,884 words, ~3,859 tokens.
.claude/skills/employee-health-data/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Employee health data is among the most sensitive categories of personal data processed in the employment context. It falls under Art. 9(1) GDPR as "data concerning health," defined in Art. 4(15) as "personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status." Employers routinely process health data for absence management, fitness-for-work assessments, occupational health surveillance, workplace adjustments for disability, and return-to-work programmes. Each of these processing activities requires identification of a valid Art. 9(2) exception, strict data minimisation, and clear boundaries between what the employer needs to know (fitness/unfitness and any required adjustments) and clinical details (diagnosis, treatment, prognosis) that must remain with the occupational health provider.
| Exception | Article | Employment Application |
|---|---|---|
| Explicit consent | Art. 9(2)(a) | Rarely valid due to power imbalance; may apply for genuinely voluntary wellness programmes |
| Employment law obligations | Art. 9(2)(b) | Primary basis: processing necessary for carrying out obligations in employment, social security, and social protection law — to the extent authorised by national law with appropriate safeguards |
| Vital interests | Art. 9(2)(c) | Emergency situations where employee is physically incapacitated and health data is needed for emergency response |
| Health professional processing | Art. 9(2)(h) | Processing for preventive or occupational medicine, assessment of working capacity, medical diagnosis — by or under the responsibility of a health professional bound by professional secrecy |
| Public health | Art. 9(2)(i) | Public health threats (pandemic response) — must be based on national or EU law |
| Substantial public interest | Art. 9(2)(g) | Where national law establishes a substantial public interest basis, e.g., disability discrimination legislation requiring processing to assess reasonable adjustments |
This is the most commonly relied upon exception. It requires:
National implementations:
| Jurisdiction | Legal Basis | Scope |
|---|---|---|
| UK | DPA 2018, Schedule 1, Part 1, Para 1 | Processing necessary for employment obligations including health and safety duties, statutory sick pay, disability adjustments |
| Germany | BDSG Section 26(3) | Processing of special category data for employment purposes where necessary for exercising rights or obligations under employment or social security law |
| France | Labour Code Art. L.4624-1 et seq. | Occupational health surveillance; employer receives fitness/unfitness conclusion only, not diagnosis |
| Netherlands | UAVG Art. 30(1)(a) | Processing necessary for employment rights and obligations under law or collective agreement |
| Italy | D.Lgs. 81/2008, Art. 25 and 41 | Occupational health surveillance; competent doctor (medico competente) conducts assessments and communicates fitness judgment only |
Processing is permitted when carried out by or under the responsibility of a health professional subject to professional secrecy. This applies to:
Critical limitation: The health professional may share with the employer only the conclusion (fit/unfit/fit with adjustments) and not the underlying clinical details. The diagnosis remains confidential between the health professional and the employee.
What the employer needs: Dates of absence, whether the absence is certified, expected return date, any workplace adjustments required.
What the employer must not receive: Diagnosis, treatment details, prognosis, medication, mental health specifics.
Data flow:
Atlas Manufacturing Group Example: Atlas's sickness absence policy states that employees self-certify for absences up to 7 days and provide a fit note for absences exceeding 7 days. The HR system records absence dates and the fit/unfit conclusion only. The diagnosis field from fit notes is not entered into the HR system. If an employee's absence exceeds 4 weeks, a referral to occupational health is offered — the occupational health report to the employer addresses fitness, adjustments, and anticipated return date, but not clinical diagnosis.
Trigger: Safety-critical roles (drivers, machine operators, work at height), return from long-term absence, concerns about an employee's capacity to perform their role safely.
Data flow:
Art. 9(2)(h) application: The occupational health provider is a health professional bound by professional secrecy (GMC, NMC, or equivalent registration). The processing is carried out under their responsibility. They share with the employer only what is necessary for the employment decision.
Scope: Statutory health surveillance required for employees exposed to occupational hazards (noise, vibration, hazardous substances, ionising radiation, asbestos, lead).
Legal basis: Art. 9(2)(b) — legal obligation under national health and safety law implementing Framework Directive 89/391/EEC.
Key obligations:
Legal basis: Art. 9(2)(b) read with national disability discrimination law (UK: Equality Act 2010; EU: Framework Employment Directive 2000/78/EC).
Data minimisation principle: The employer needs to know:
The employer does not need: The specific diagnosis, medication, treatment history, or prognosis — unless the employee voluntarily shares this information to support the adjustment process.
Context: Many organisations implemented COVID-19 testing and vaccination status checking during the pandemic. Residual data and policies may remain.
Current obligations:
Atlas Manufacturing Group Example: Atlas collected COVID test results and vaccination status during 2020-2022 under Art. 9(2)(b) (UK health and safety legal obligation) and Art. 9(2)(i) (public health). Following the revocation of mandatory testing guidance in 2022, Atlas conducted a retention review and deleted all COVID testing data and vaccination records in March 2023, retaining only aggregate statistical data for occupational health reporting.
Description: Employer-offered wellness programmes including health risk assessments, fitness challenges, mental health support, and biometric screenings.
Lawful basis: Art. 9(2)(a) explicit consent — wellness programmes are the rare employment scenario where consent may be valid, because:
Conditions:
| Data Element | Permitted | Lawful Basis |
|---|---|---|
| Absence dates | Yes | Art. 6(1)(b) contract + Art. 9(2)(b) employment obligation |
| Fit/unfit conclusion | Yes | Art. 9(2)(b) employment obligation |
| Required workplace adjustments | Yes | Art. 9(2)(b) disability legislation |
| Occupational health referral correspondence | Yes | Art. 9(2)(h) health professional |
| Fitness-for-work certificates | Yes | Art. 9(2)(b) health and safety obligation |
| Data Element | Prohibited | Reason |
|---|---|---|
| Clinical diagnosis | Yes (unless voluntarily shared) | Not necessary for employment decisions |
| Treatment details | Yes | Not necessary; disproportionate intrusion |
| Medication information | Yes | Not necessary; may reveal conditions not relevant to work |
| Mental health counselling records | Yes | Processed under professional secrecy by health professional |
| GP/hospital records | Yes | No lawful basis for employer access |
| Genetic test results | Yes | Art. 9(1) + Art. 9(4) specific national restrictions |
| Role | Access Level |
|---|---|
| HR Manager (employee relations) | Absence dates, fit/unfit conclusion, adjustment requirements |
| Line Manager | Absence dates and expected return date only; no health details |
| Occupational Health Provider | Full clinical information (under professional secrecy) |
| DPO | Access to processing records and policy compliance; no individual health data |
| Payroll | Absence dates for statutory sick pay calculation only |
| IT | No access to health data content; system administration only |
| Authority | Case | Fine/Outcome | Key Issue |
|---|---|---|---|
| LfDI Hamburg (Germany) | H&M, 2020 | EUR 35,258,707.95 | Employer systematically recorded employee health details from return-to-work conversations, including diagnoses and family health issues |
| CNIL (France) | SAN-2021-015 | EUR 150,000 | Employer collected excessive health data during COVID screening beyond what was legally required |
| Garante (Italy) | Provvedimento 2022-0156 | Processing restricted | Employer required employees to disclose diagnosis on sickness absence forms |
| ICO (UK) | Enforcement notice, 2021 | Processing ordered to cease | Employer shared employee mental health data with line managers without necessity or consent |
| AEPD (Spain) | PS/00142/2022 | EUR 100,000 | Employer processed employee COVID vaccination status after legal basis expired |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/employee-health-data of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Employee Health Data next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Employee Health Data this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Coachfelixrieseberg/claude-coach | 199 | 1 repos | ~4.9k | Automated safety check: Pass | MIT | |
| Fitness Analyzerhuifer/WellAlly-health | 960 | 5 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Master Ajahn Chahxr843/Master-skill | 447 | 1 repos | ~2k | Automated safety check: Pass | CC-BY-NC-SA-4.0 | |
| Mental Health Analyzerhuifer/WellAlly-health | 960 | 5 repos | ~3.2k | Automated safety check: Pass | MIT | |
| Nutrition Analyzerhuifer/WellAlly-health | 960 | 5 repos | ~3.3k | Automated safety check: Pass | MIT |
felixrieseberg/claude-coach
Create personalized triathlon, marathon, and ultra-endurance training plans.
huifer/WellAlly-health
分析运动数据、识别运动模式、评估健身进展,并提供个性化训练建议。支持与慢性病数据的关联分析. An agent skill from huifer/WellAlly-health.
xr843/Master-skill
A skill your agent uses when user asks about 南传佛教, 上座部, Theravada, 巴利经典, 正念 sati, 放下, 三法印, 四念处, 出入息念 anapanasati, 戒定慧, 毗婆舍那, 森林禅林派, 巴蓬寺, 阿姜查, 杜多行, 中道, or wants teaching in 阿姜查 Ajahn Chah's voice.
huifer/WellAlly-health
分析心理健康数据、识别心理模式、评估心理健康状况、提供个性化心理健康建议。支持与睡眠、运动、营养等其他健康数据的关联分析。
huifer/WellAlly-health
分析营养数据、识别营养模式、评估营养状况,并提供个性化营养建议。支持与运动、睡眠、慢性病数据的关联分析. An agent skill from huifer/WellAlly-health.
Google-Health-API/google-health-cli
Query Google Health API v4 — steps, heart rate, exercise, sleep, weight, SpO2, HRV, ECG, blood glucose, nutrition, and 40 total data types
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Governs employee health data processing for fitness-for-work assessments, occupational health surveillance, COVID testing legacy programmes, and absence management. Employee Health Data is an agent skill from mukul975/Privacy-Data-Protection-Skills. Governs employee health data processing for fitness-for-work assessments, occupational health surveillance, COVID testing legacy programmes, and absence management.
Employee Health Data fits situations like: tasks that involve Health and fitness tracking.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-health-data -a claude-code`. Or copy the skill folder (skills/privacy/employee-health-data in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/employee-health-data in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-health-data -a codex`. Or copy the skill folder (skills/privacy/employee-health-data in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/employee-health-data in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-health-data -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/employee-health-data, .gemini/skills/employee-health-data, .github/skills/employee-health-data and .opencode/skills/employee-health-data in your project.
Going by SKILL.md and its folder, Employee Health Data needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Employee Health Data is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Employee Health Data: Coach (felixrieseberg/claude-coach, 199 stars), Fitness Analyzer (huifer/WellAlly-health, 960 stars), Master Ajahn Chah (xr843/Master-skill, 447 stars) and Mental Health Analyzer (huifer/WellAlly-health, 960 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.