C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Guides DPIA for workplace monitoring including email surveillance, internet usage monitoring, CCTV, GPS tracking, and keystroke logging.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-surveillance-dpia -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-surveillance-dpia --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/employee-surveillance-dpia .claude/skills/employee-surveillance-dpia && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "employee-surveillance-dpia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-surveillance-dpia into .claude/skills/employee-surveillance-dpia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-surveillance-dpia", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-surveillance-dpiaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-surveillance-dpia -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-surveillance-dpia --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/employee-surveillance-dpia .agents/skills/employee-surveillance-dpia && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "employee-surveillance-dpia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-surveillance-dpia into .agents/skills/employee-surveillance-dpia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-surveillance-dpia", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-surveillance-dpia -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-surveillance-dpia --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/employee-surveillance-dpia .cursor/skills/employee-surveillance-dpia && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "employee-surveillance-dpia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-surveillance-dpia into .cursor/skills/employee-surveillance-dpia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-surveillance-dpia", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/employee-surveillance-dpia--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-surveillance-dpia -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-surveillance-dpia --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/employee-surveillance-dpia .gemini/skills/employee-surveillance-dpia && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "employee-surveillance-dpia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-surveillance-dpia into .gemini/skills/employee-surveillance-dpia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-surveillance-dpia", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-surveillance-dpiaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-surveillance-dpia -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/employee-surveillance-dpia .github/skills/employee-surveillance-dpia && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "employee-surveillance-dpia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-surveillance-dpia into .github/skills/employee-surveillance-dpia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-surveillance-dpia", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-surveillance-dpia -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills employee-surveillance-dpia --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/employee-surveillance-dpia .opencode/skills/employee-surveillance-dpia && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "employee-surveillance-dpia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/employee-surveillance-dpia into .opencode/skills/employee-surveillance-dpia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "employee-surveillance-dpia", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
employee-surveillance-dpiaGuides DPIA for workplace monitoring including email surveillance, internet usage monitoring, CCTV, GPS tracking, and keystroke logging.
Employee Surveillance Dpia is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides DPIA for workplace monitoring including email surveillance, internet usage monitoring, CCTV, GPS tracking, and keystroke logging. Covers GDPR Art. 88 employment context provisions, WP29 Opinion 2/2017 on data processing at work, and proportionality balancing for employee monitoring. Keywords: employee surveillance, workplace monitoring, DPIA, Art. 88, WP29 Opinion 2/2017, CCTV, email monitoring, GPS tracking.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Employee Surveillance Dpia loads about 3.3k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 1,399 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,399 words, ~3,347 tokens.
.claude/skills/employee-surveillance-dpia/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Workplace monitoring represents one of the most sensitive areas of data protection because of the inherent power imbalance between employer and employee. GDPR Art. 88 allows Member States to provide more specific rules for processing in the employment context, and WP29 Opinion 2/2017 on data processing at work provides detailed guidance on proportionality, transparency, and data minimisation for employee monitoring. This skill provides a DPIA methodology for all forms of workplace surveillance: email monitoring, internet usage tracking, CCTV, GPS vehicle and personnel tracking, keystroke and screen capture logging, telephone call monitoring, and wearable device monitoring.
Art. 88(1) permits Member States to provide, by law or collective agreement, more specific rules for processing in the employment context, covering recruitment, performance of the employment contract, management, planning and organisation of work, equality and diversity, health and safety, protection of employer's property, and exercise of employment-related rights.
Art. 88(2) requires that such rules include suitable and specific measures to safeguard the data subject's human dignity, legitimate interests, and fundamental rights, with particular regard to transparency, intra-group transfers, and monitoring systems in the workplace.
Key principles established:
| Principle | Application to Workplace Monitoring |
|---|---|
| Necessity | Monitoring must be strictly necessary for the stated purpose; less intrusive alternatives must be evaluated first |
| Purpose limitation | Data collected for security monitoring cannot be repurposed for performance management without separate justification |
| Data minimisation | Monitoring should capture the minimum data necessary — metadata over content, aggregate over individual |
| Transparency | Employees must be clearly informed about the nature, scope, and purpose of monitoring before it begins |
| Proportionality | The intrusiveness of monitoring must be proportionate to the legitimate interest pursued; blanket monitoring is rarely proportionate |
| Consent limitations | Employee consent is generally not a valid lawful basis due to the power imbalance; legitimate interest (Art. 6(1)(f)) is more appropriate but requires rigorous balancing |
| Country | Legislation | Key Provisions |
|---|---|---|
| Germany | BDSG Section 26 | Employee data processing only lawful when necessary for the employment relationship. Works council co-determination right (BetrVG Section 87(1)(6)) for technical monitoring equipment. |
| France | Labour Code L1121-1, L1222-4 | Proportionality and transparency requirements. CNIL Guidance on employee monitoring (2020). Prior works council consultation required. |
| Italy | Workers' Statute Art. 4 | Remote surveillance equipment prohibited unless agreed with trade unions or authorised by labour inspectorate. |
| Spain | LOPDGDD Art. 87-91 | Specific provisions for digital rights in the workplace, including right to digital disconnection. |
| Netherlands | UAVG Implementation Act | Works council consent required for employee monitoring systems per WOR Art. 27(1)(l). |
| Aspect | Assessment |
|---|---|
| Legitimate purposes | Regulatory compliance (FCA SYSC 10A, MiFID II), insider threat detection, intellectual property protection, harassment prevention |
| Proportionality levels | Metadata only (sender, recipient, timestamp) < Subject line + metadata < Full content scanning < Real-time content review |
| Data minimisation | Metadata monitoring is significantly less intrusive than content review; content should only be accessed with specific justification |
| Transparency | Employees must be informed of the scope of email monitoring in the privacy notice and employment contract |
| Private use | If employer permits private email use, monitoring must not extend to private communications; separation mechanisms should be implemented |
| Retention | Email monitoring data should have shorter retention than business email retention; monitoring metadata should be deleted within 30-90 days |
| Aspect | Assessment |
|---|---|
| Legitimate purposes | Network security (malware prevention), bandwidth management, acceptable use enforcement, regulatory compliance |
| Proportionality levels | Category-level monitoring < Domain-level logging < Full URL logging < Content inspection (DPI) |
| Data minimisation | Category-level classification is proportionate for most purposes; URL-level logging requires specific justification |
| Transparency | Employees must be informed of what is monitored and any automated blocking |
| Personal browsing | If personal internet use is permitted, monitoring should not capture personal browsing details; automatic exclusion of personal browsing categories where feasible |
| Aspect | Assessment |
|---|---|
| Legitimate purposes | Physical security, health and safety, theft prevention, regulatory compliance |
| Proportionality levels | External perimeter only < Reception and entry points < Common areas (excluding toilets, break rooms, changing areas) < Individual workstations |
| Prohibited areas | Toilets, changing rooms, break rooms, and prayer rooms must never be monitored by CCTV |
| Covert monitoring | Only permissible in exceptional circumstances (suspected criminal activity) for a limited period, with prior DPO approval and legal counsel sign-off |
| Retention | Maximum 30 days unless footage is required for a specific investigation; automated deletion |
| Audio recording | Generally disproportionate in the workplace; separate justification required |
| Aspect | Assessment |
|---|---|
| Legitimate purposes | Fleet management, delivery route optimisation, lone worker safety, vehicle theft prevention |
| Proportionality | GPS tracking of company vehicles during working hours is generally proportionate; continuous tracking outside working hours is disproportionate |
| Data minimisation | Tracking frequency should be proportionate (periodic location updates vs continuous tracking); geofencing (alerts on boundary crossing) is less intrusive than continuous tracking |
| Personal vehicles | GPS tracking of employees' personal vehicles is highly intrusive and rarely proportionate |
| Working hours only | GPS tracking should automatically deactivate outside working hours or when vehicle is used for personal purposes (if permitted) |
| Aspect | Assessment |
|---|---|
| Legitimate purposes | Insider threat detection in high-security environments, fraud investigation |
| Proportionality | Keystroke logging is one of the most intrusive forms of monitoring — captures personal passwords, private messages, health searches, and intimate communications |
| Recommendation | Generally disproportionate for routine monitoring; may be justified only in specific high-risk roles (financial traders, classified information handlers) with strict access controls and short retention |
| DPO and WP29 position | WP29 Opinion 2/2017 states that technologies that monitor keystrokes or capture screenshots are very intrusive and should be considered a last resort |
For each monitoring type, apply the proportionality framework:
START: Proposed monitoring measure
│
├─ Is the monitoring measure necessary for the stated purpose?
│ ├─ NO → Monitoring is not justified. Remove from scope.
│ └─ YES → Continue.
│
├─ Could a less intrusive measure achieve the same purpose?
│ ├─ YES → Adopt the less intrusive measure instead.
│ └─ NO → Continue.
│
├─ Is the scope of monitoring proportionate?
│ ├─ Blanket monitoring of all employees?
│ │ └─ Generally disproportionate. Target monitoring to specific roles or risk areas.
│ ├─ Continuous monitoring during all working hours?
│ │ └─ Consider periodic or event-triggered monitoring instead.
│ └─ Monitoring extends to personal/private activity?
│ └─ Disproportionate. Implement exclusion mechanisms.
│
├─ Is the retention period proportionate?
│ ├─ Monitoring data retained indefinitely?
│ │ └─ Disproportionate. Set specific retention periods with automated deletion.
│ └─ Retention aligned with the monitoring purpose?
│ └─ Document justification for retention period.
│
└─ END: Document the proportionality assessment for each monitoring type.Assess monitoring-specific risks:
| Risk | Description |
|---|---|
| Chilling effect | Employees modify legitimate behaviour due to awareness of monitoring, reducing creativity, communication, and wellbeing |
| Discriminatory application | Monitoring applied more intensively to certain employee groups based on role, location, or other characteristics |
| Personal data exposure | Monitoring captures personal communications, health information, or political/religious content |
| Repurposing | Data collected for security used for performance management or disciplinary purposes |
| Excessive access | Line managers or HR accessing individual monitoring data without justification |
| Psychological harm | Continuous monitoring causing stress, anxiety, and reduced job satisfaction |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/employee-surveillance-dpia of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Employee Surveillance Dpia next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Employee Surveillance Dpia this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Guides DPIA for workplace monitoring including email surveillance, internet usage monitoring, CCTV, GPS tracking, and keystroke logging. Employee Surveillance Dpia is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides DPIA for workplace monitoring including email surveillance, internet usage monitoring, CCTV, GPS tracking, and keystroke logging.
Employee Surveillance Dpia fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-surveillance-dpia -a claude-code`. Or copy the skill folder (skills/privacy/employee-surveillance-dpia in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/employee-surveillance-dpia in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-surveillance-dpia -a codex`. Or copy the skill folder (skills/privacy/employee-surveillance-dpia in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/employee-surveillance-dpia in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employee-surveillance-dpia -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/employee-surveillance-dpia, .gemini/skills/employee-surveillance-dpia, .github/skills/employee-surveillance-dpia and .opencode/skills/employee-surveillance-dpia in your project.
Going by SKILL.md and its folder, Employee Surveillance Dpia needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Employee Surveillance Dpia is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Employee Surveillance Dpia: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.