Agent skill

Employee Monitoring Dpia

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Conducts Data Protection Impact Assessments for employee monitoring systems per EDPB Guidelines 3/2019 on workplace data processing.

Apache-2.0Auto-check passedLegal & Compliance

Install Employee Monitoring Dpia

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-monitoring-dpia -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-monitoring-dpia --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/employee-monitoring-dpia .claude/skills/employee-monitoring-dpia && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
employee-monitoring-dpia
GitHub stars
301
Token cost
~4.8k tokens
SKILL.md length
2,328 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conducts Data Protection Impact Assessments for employee monitoring systems per EDPB Guidelines 3/2019 on workplace data processing.

  • Works in 6 steps: Preliminary Assessment (Week 1) → Systematic Description (Week 2) → Necessity and Proportionality Assessment… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, DPIA Trigger Analysis for…, Monitoring Categories and Risk… and DPIA Methodology for Employee…, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Employee Monitoring Dpia is an agent skill from mukul975/Privacy-Data-Protection-Skills. Conducts Data Protection Impact Assessments for employee monitoring systems per EDPB Guidelines 3/2019 on workplace data processing. Covers video surveillance, email monitoring, GPS tracking, keystroke logging, and productivity tools. Applies proportionality testing under Art. 35 GDPR. Keywords: DPIA, employee monitoring, surveillance, proportionality, EDPB, workplace privacy, keystroke logging, GPS tracking.

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the employee-monitoring-dpia skill to conduct Data Protection Impact Assessments for employee monitoring systems per EDPB Guidelines 3/2019 on…”
  • “/employee-monitoring-dpia”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Preliminary Assessment (Week 1)
  2. Systematic Description (Week 2)
  3. Necessity and Proportionality Assessment (Week 3)
  4. Risk Assessment (Week 3-4)
  5. Mitigation Measures (Week 4-5)
  6. DPO Review and Works Council Consultation (Week 5-6)

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Employee Monitoring Dpia loads about 4.8k tokens when it runs, and up to ~7.6k if it reads all its reference files. Until then it costs about 109 tokens; SKILL.md has 2,328 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,328 words, ~4,821 tokens.

Download SKILL.mdSave it as .claude/skills/employee-monitoring-dpia/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
employee-monitoring-dpia
description
Conducts Data Protection Impact Assessments for employee monitoring systems per EDPB Guidelines 3/2019 on workplace data processing. Covers video surveillance, email monitoring, GPS tracking, keystroke logging, and productivity tools. Applies proportionality testing under Art. 35 GDPR. Keywords: DPIA, employee monitoring, surveillance, proportionality, EDPB, workplace privacy, keystroke logging, GPS tracking.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
employee-data-privacy
metadata.tags
dpia, employee-monitoring, surveillance, proportionality, edpb, workplace-privacy

Employee Monitoring DPIA

Overview

Employee monitoring represents one of the highest-risk processing activities under GDPR because it combines multiple EDPB WP248rev.01 risk factors: systematic monitoring (criterion 3), data concerning vulnerable data subjects — employees are explicitly classified as vulnerable due to the inherent power imbalance in the employment relationship (criterion 7), and often innovative technology (criterion 8). The European Data Protection Board's Guidelines 3/2019 on processing of personal data through video devices and the Article 29 Working Party's Opinion 2/2017 on data processing at work establish that any employee monitoring system requires a DPIA under Art. 35(1) GDPR before deployment.

This skill provides a structured DPIA methodology tailored specifically to employee monitoring scenarios, incorporating the proportionality framework from Barbulescu v Romania (Grand Chamber, ECHR, Application No. 61496/08, 5 September 2017) and national supervisory authority guidance from the CNIL, ICO, and German Federal Commissioner for Data Protection.

DPIA Trigger Analysis for Employee Monitoring

Why Employee Monitoring Always Requires a DPIA

Employee monitoring meets at least three of the nine EDPB WP248rev.01 criteria:

CriterionApplicability to Employee Monitoring
Criterion 3: Systematic monitoringAll forms of employee monitoring constitute systematic observation of individuals in the workplace
Criterion 7: Vulnerable data subjectsEmployees are explicitly listed as vulnerable data subjects by the EDPB due to the power imbalance inherent in the employment relationship
Criterion 5: Large-scale processingEnterprise monitoring systems typically process data about all employees continuously
Criterion 8: Innovative technologyAI-powered productivity tools, keystroke dynamics, screen capture, and behavioural analytics involve novel technologies
Criterion 1: Evaluation or scoringMonitoring data used for performance evaluation constitutes scoring of individuals

Meeting two or more criteria triggers a presumptive DPIA requirement. Employee monitoring typically meets three to five, making a DPIA mandatory in virtually all cases.

National Supervisory Authority Confirmation
  • CNIL (France): Deliberation No. 2018-327 explicitly lists "systematic employee monitoring (productivity, keystroke, screen capture)" as requiring a DPIA.
  • ICO (UK): Employment Practices Data Protection Code, Part 3: Monitoring at Work confirms DPIA requirement for all workplace monitoring systems.
  • BfDI (Germany): Section 26 BDSG (Federal Data Protection Act) imposes additional requirements for employee data processing, reinforcing the DPIA obligation.
  • AEPD (Spain): Guide on Data Protection in Labour Relations (2021) mandates DPIA for all systematic employee monitoring.

Monitoring Categories and Risk Profiles

Category 1: Video Surveillance (CCTV)

Description: Fixed or mobile camera systems recording visual images of employees in the workplace.

Applicable EDPB Guidance: Guidelines 3/2019 on processing of personal data through video devices, Section 8 (Processing in the employment context).

Legal Basis Analysis:

  • Art. 6(1)(f) legitimate interest is the most common lawful basis for workplace CCTV
  • Art. 6(1)(c) legal obligation where national law mandates security monitoring (e.g., financial institutions)
  • Art. 6(1)(a) consent is not valid due to the employment power imbalance (WP29 Opinion 2/2017, Section 5.1)

Proportionality Requirements:

  • Cameras must not be positioned in break rooms, toilets, changing areas, or trade union meeting rooms
  • Recording should be limited to security-relevant areas: entrances, server rooms, cash handling areas, warehouse loading docks
  • Continuous recording must be justified; motion-activated recording is less intrusive
  • Retention period must not exceed 72 hours unless a specific security incident requires longer retention for investigation — CNIL recommends a maximum of 30 days
  • Audio recording alongside video is prohibited in most jurisdictions absent specific statutory authorisation

Atlas Manufacturing Group Example: Atlas Manufacturing Group operates 14 CCTV cameras across its production facility. The DPIA identified that 3 cameras positioned in the staff canteen were disproportionate to the stated security purpose. The DPIA recommended removal of canteen cameras and retention reduction from 30 days to 72 hours for all remaining cameras, with exception procedures for documented security incidents.

Category 2: Email and Internet Monitoring

Description: Systems that log, scan, or analyse employee email communications and internet browsing activity.

Legal Basis Analysis:

  • Art. 6(1)(f) legitimate interest for preventing data leakage, detecting security threats, and enforcing acceptable use policies
  • Must be balanced against Art. 8 ECHR right to respect for private life and correspondence

Proportionality Requirements per Barbulescu v Romania (Grand Chamber): The ECHR Grand Chamber established six criteria that must be satisfied:

  1. Has the employee been notified in advance of the possibility that their communications may be monitored?
  2. What is the extent of the monitoring and the degree of intrusion into the employee's privacy?
  3. Does the employer have legitimate reasons to justify monitoring?
  4. Would monitoring with less intrusive methods be possible?
  5. What are the consequences of the monitoring for the employee?
  6. Has the employee been provided with adequate safeguards?

Risk Assessment Specific Factors:

  • Content monitoring (reading actual emails) is significantly more intrusive than metadata monitoring (sender/recipient/time)
  • Keyword scanning represents an intermediate level of intrusion
  • Personal email accounts must never be monitored even if accessed from corporate devices
  • Privileged communications (with legal counsel, trade union representatives, medical professionals) must be excluded
Category 3: GPS and Location Tracking

Description: Vehicle tracking systems, mobile device location monitoring, and geofencing for field employees.

Legal Basis Analysis:

  • Art. 6(1)(f) legitimate interest for fleet management, lone worker safety, and route optimisation
  • Art. 6(1)(b) performance of employment contract where location tracking is essential to the role (delivery drivers, field engineers)

Proportionality Requirements:

  • Tracking must be limited to working hours; tracking outside working hours is disproportionate unless the vehicle is used exclusively for business
  • Real-time tracking is more intrusive than periodic location logging and requires stronger justification
  • Geofencing alerts are less intrusive than continuous tracking and should be preferred where sufficient
  • Employees must be able to disable tracking when using a company vehicle for personal purposes (if permitted)
  • Speed monitoring and driving behaviour analysis must be justified by specific safety concerns

Atlas Manufacturing Group Example: Atlas Manufacturing Group implemented GPS tracking on 23 delivery vehicles. The DPIA identified that real-time tracking was active 24/7 despite drivers being permitted limited personal vehicle use. The DPIA required implementation of a "personal use" toggle on the vehicle dashboard that suspends tracking and notifies fleet management that the vehicle is in personal use mode.

Category 4: Keystroke Logging and Screen Capture

Description: Software that records individual keystrokes, takes periodic or triggered screenshots, and monitors application usage.

Risk Classification: Very High — this is the most intrusive form of employee monitoring.

Legal Basis Analysis:

  • Art. 6(1)(f) legitimate interest is difficult to establish because the severity of the intrusion typically outweighs any legitimate interest
  • National DPAs have consistently found keystroke logging to be disproportionate for general productivity monitoring
  • CNIL Decision No. MED-2019-006: Keystroke logging is justified only when investigating a specific, documented security incident and must be time-limited

Proportionality Requirements:

  • Keystroke logging as a default monitoring tool is almost certainly disproportionate and will fail the DPIA
  • Screen capture at fixed intervals (e.g., every 5 minutes) captures private information and personal passwords
  • Application-level monitoring (which applications are open and for how long) is less intrusive than screen capture
  • Any deployment must be time-limited, targeted to specific roles or individuals, and supported by a documented security justification

Supervisory Authority Enforcement:

  • CNIL (France): Fined an employer EUR 20,000 for deploying keystroke logging software on employee workstations without conducting a DPIA and without adequate transparency (Decision SAN-2021-003).
  • Garante (Italy): Prohibited a company from using continuous screen capture software, ruling it disproportionate to the stated productivity monitoring purpose (Provvedimento No. 9834141, 2022).
Category 5: Productivity and Behavioural Analytics

Description: Software platforms that aggregate data from multiple sources (email, calendar, application usage, badge swipes, collaboration tools) to generate productivity scores and behavioural profiles.

Risk Classification: Very High — combines evaluation/scoring with systematic monitoring and innovative technology.

Legal Basis Analysis:

  • Art. 6(1)(f) legitimate interest requires a rigorous balancing test
  • If productivity scores are used for employment decisions (promotion, dismissal, pay), Art. 22 automated decision-making restrictions apply
  • Profiling under Art. 4(4) is triggered when monitoring data is used to evaluate work performance aspects

Proportionality Requirements:

  • Aggregate/team-level analytics are less intrusive than individual-level scoring
  • Employees must be informed of exactly which data sources contribute to productivity metrics
  • Employees must have the right to access and challenge their productivity profiles under Art. 15 and Art. 22(3)
  • Human review must be guaranteed before any adverse employment decision based on monitoring data

DPIA Methodology for Employee Monitoring

Show full SKILL.md (983 more words)Show less
Phase 1: Preliminary Assessment (Week 1)
  1. Identify the monitoring system: Document the specific technology, vendor, deployment scope, and data flows.
  2. Classify the monitoring category: Map to one or more of the five categories above.
  3. Confirm DPIA obligation: Count WP248rev.01 criteria met (employee monitoring will always meet at least two).
  4. Assemble the DPIA team: Processing owner (typically HR Director), DPO, IT Security Officer, Legal Counsel, and employee representative or works council member per Art. 35(9).
  5. Notify the works council: In jurisdictions with works council requirements (Germany, France, Netherlands, Austria), the works council has co-determination rights over monitoring systems under national labour law.
Phase 2: Systematic Description (Week 2)

Document the following for each monitoring system:

ElementDetails Required
Data categoriesPrecisely what data is collected (e.g., email metadata, email content, URLs visited, keystrokes, screenshots, GPS coordinates, video images)
Data subjectsAll employees, specific departments, specific roles, contractors, visitors
VolumeNumber of employees monitored, frequency of data collection, daily data volume
RetentionHow long monitoring data is stored, deletion procedures, archive policies
AccessWho can access raw monitoring data, who can access reports/dashboards, role-based access controls
RecipientsInternal recipients (HR, line managers, IT security), external recipients (monitoring software vendor, cloud hosting provider)
TransfersWhether monitoring data is transferred outside the EEA (common with US-based SaaS monitoring tools)
Legal basisSpecific Art. 6(1) basis and, where applicable, Art. 9(2) condition
Phase 3: Necessity and Proportionality Assessment (Week 3)

Apply the following proportionality test for each monitoring measure:

Step 1 — Legitimate aim: What specific, documented objective does the monitoring serve? (Security, fraud prevention, regulatory compliance, productivity management, health and safety)

Step 2 — Necessity: Is monitoring necessary to achieve the objective, or can the objective be achieved through less intrusive means?

Monitoring MeasureLess Intrusive Alternative
Continuous video surveillanceMotion-activated recording, access control logs
Email content scanningMetadata analysis, data loss prevention rules on attachments only
Keystroke loggingApplication usage logging, output-based performance measurement
Real-time GPS trackingRoute completion verification, periodic check-ins
Continuous screen captureActive window logging, time-tracking software with manual entries
Behavioural analytics scoringRegular supervisor reviews, objective output metrics

Step 3 — Proportionality: Even if necessary, is the monitoring proportionate to the aim? Apply the Barbulescu six-factor test.

Step 4 — Safeguards: What measures mitigate the impact on employees? (Transparency, access rights, retention limits, data minimisation, grievance procedures)

Phase 4: Risk Assessment (Week 3-4)

Assess risks specific to employee monitoring:

RiskLikelihoodSeverityInherent Risk
Chilling effect on legitimate workplace communication and trade union activityLikelySignificantHigh
Disproportionate surveillance creating hostile work environmentPossibleSignificantHigh
Monitoring data used for discriminatory employment decisionsPossibleMaximumHigh
Unauthorised access to monitoring data by line managersLikelyLimitedMedium
Function creep: monitoring data used for purposes beyond original justificationLikelySignificantHigh
Cross-border transfer of monitoring data to non-adequate jurisdictionsPossibleSignificantHigh
Employee inability to exercise DSAR rights over monitoring dataPossibleSignificantHigh
Capture of privileged communications (legal, medical, union)PossibleMaximumVery High
Phase 5: Mitigation Measures (Week 4-5)

For each identified risk, document specific technical and organisational measures:

Technical Measures:

  • Automated exclusion of privileged communications from monitoring scope (whitelisting legal counsel, medical providers, and trade union email addresses)
  • Role-based access controls restricting monitoring dashboard access to authorised HR personnel only
  • Automated retention enforcement with irreversible deletion at expiry
  • Data minimisation: collect metadata before content; aggregate before individual-level data
  • Encryption of monitoring data at rest (AES-256) and in transit (TLS 1.3)
  • Audit logging of all access to monitoring data with tamper-proof logs

Organisational Measures:

  • Acceptable Use Policy updated to reflect monitoring scope and provided to all employees before monitoring begins
  • Privacy notice under Art. 13/14 specifically addressing monitoring, delivered before system activation
  • Employee grievance procedure for challenging monitoring decisions
  • Annual proportionality review to confirm monitoring remains necessary
  • Training for managers on permissible use of monitoring data
  • Restriction on using monitoring data as sole basis for adverse employment decisions
Phase 6: DPO Review and Works Council Consultation (Week 5-6)
  1. Present completed DPIA to the DPO for independent advice per Art. 35(2).
  2. Document DPO advice and whether it was accepted; if not, record the justification.
  3. Submit DPIA findings to the works council where co-determination rights apply.
  4. Conduct employee consultation per Art. 35(9) — this may be satisfied through works council engagement.
  5. Obtain senior management sign-off acknowledging residual risks.
  6. If residual risk remains High or Very High after mitigation, initiate Art. 36 prior consultation with the supervisory authority.

Ongoing Review Requirements

Employee monitoring DPIAs must be reviewed:

  • Before any new monitoring technology is deployed
  • When the monitoring scope is expanded (new departments, new data categories)
  • When monitoring software is upgraded or vendor is changed
  • Following any employee complaint related to monitoring
  • Following any supervisory authority guidance or enforcement action relevant to employee monitoring
  • At minimum annually as part of the privacy programme calendar

Enforcement Precedents

AuthorityCaseFine/OutcomeRelevance
CNIL (France)SAN-2021-003EUR 20,000Keystroke logging deployed without DPIA or transparency
Garante (Italy)Provvedimento 9834141, 2022Processing prohibitedContinuous screen capture ruled disproportionate
AEPD (Spain)PS/00120/2021EUR 60,000GPS tracking of employee vehicles outside working hours
Datainspektionen (Sweden)DI-2020-11370SEK 300,000Facial recognition for employee time tracking without valid consent or DPIA
Hellenic DPA (Greece)Decision 26/2019EUR 150,000Continuous employee CCTV monitoring without proportionality assessment
ICO (UK)ENF/2021/00352Enforcement noticeEmployer required to cease covert monitoring of employee personal devices

Integration Points

  • Employment Consent Limits: This DPIA must confirm that consent has not been relied upon as the lawful basis for monitoring (see employment-consent-limits skill).
  • Workplace Email Privacy: Email monitoring components of this DPIA feed into the workplace-email-privacy skill for detailed Barbulescu compliance.
  • Employee DSAR Response: Monitoring data is within scope of employee DSARs (see employee-dsar-response skill).
  • Remote Work Monitoring: Remote monitoring raises additional proportionality concerns covered in the remote-work-monitoring skill.
  • Art. 36 Prior Consultation: Where residual risk remains high, escalation to the supervisory authority is required.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/employee-monitoring-dpia of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Employee Monitoring Dpia next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Employee Monitoring Dpia compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Employee Monitoring Dpia this skillmukul975/Privacy-Data-Protection-Skills301—~4.8kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Employee Monitoring Dpia

What does Employee Monitoring Dpia do?

Conducts Data Protection Impact Assessments for employee monitoring systems per EDPB Guidelines 3/2019 on workplace data processing. Employee Monitoring Dpia is an agent skill from mukul975/Privacy-Data-Protection-Skills. Conducts Data Protection Impact Assessments for employee monitoring systems per EDPB Guidelines 3/2019 on workplace data processing.

When should I use Employee Monitoring Dpia?

Employee Monitoring Dpia fits situations like: tasks that involve Privacy and GDPR.

How do I install Employee Monitoring Dpia in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-monitoring-dpia -a claude-code`. Or copy the skill folder (skills/privacy/employee-monitoring-dpia in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/employee-monitoring-dpia in your project. Claude Code loads it when a task matches its description.

How do I install Employee Monitoring Dpia in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-monitoring-dpia -a codex`. Or copy the skill folder (skills/privacy/employee-monitoring-dpia in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/employee-monitoring-dpia in your project. Codex loads it when a task matches its description.

Can I use Employee Monitoring Dpia in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-monitoring-dpia -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/employee-monitoring-dpia, .gemini/skills/employee-monitoring-dpia, .github/skills/employee-monitoring-dpia and .opencode/skills/employee-monitoring-dpia in your project.

What does Employee Monitoring Dpia need to run?

Going by SKILL.md and its folder, Employee Monitoring Dpia needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Employee Monitoring Dpia access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Employee Monitoring Dpia safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Employee Monitoring Dpia use?

Employee Monitoring Dpia is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Employee Monitoring Dpia use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.8k tokens, read only when the agent opens those files.

What are the alternatives to Employee Monitoring Dpia?

Skills that share tags, products or a category with Employee Monitoring Dpia: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Employee Monitoring Dpia?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.