Agent skill

Employment Consent Limits

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Analyses the limitations on consent as a lawful basis for processing employee data under Art.

Apache-2.0Auto-check passedLegal & Compliance

Install Employment Consent Limits

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill employment-consent-limits -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills employment-consent-limits --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/employment-consent-limits .claude/skills/employment-consent-limits && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
employment-consent-limits
GitHub stars
301
Token cost
~4k tokens
SKILL.md length
1,828 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyses the limitations on consent as a lawful basis for processing employee data under Art.

  • Works in 3 steps: Purpose test: Is there a legitimate… → Necessity test: Is the processing… → Balancing test: Do the employer's…
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, The Consent Problem in…, Narrow Exceptions — When… and Alternative Lawful Bases for…, plus 5 more sections
  • Runs Python scripts from its folder

What it does

Employment Consent Limits is an agent skill from mukul975/Privacy-Data-Protection-Skills. Analyses the limitations on consent as a lawful basis for processing employee data under Art. 88 GDPR and WP29 Opinion 2/2017. Addresses power imbalance in employment relationships, identifies alternative lawful bases, and maps national derogations. Keywords: consent, employment, power imbalance, Art. 88, WP29, lawful basis, employee data, labour law.

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the employment-consent-limits skill to analyse the limitations on consent as a lawful basis for processing employee data under Art”
  • “/employment-consent-limits”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Purpose test: Is there a legitimate interest? (Business security, fraud prevention, IT security, organisational efficiency)
  2. Necessity test: Is the processing necessary for that interest, or could the aim be achieved by less intrusive means?
  3. Balancing test: Do the employer's interests override the employees' fundamental rights? Consider

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Employment Consent Limits loads about 4k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 1,828 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,828 words, ~3,979 tokens.

Download SKILL.mdSave it as .claude/skills/employment-consent-limits/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
employment-consent-limits
description
Analyses the limitations on consent as a lawful basis for processing employee data under Art. 88 GDPR and WP29 Opinion 2/2017. Addresses power imbalance in employment relationships, identifies alternative lawful bases, and maps national derogations. Keywords: consent, employment, power imbalance, Art. 88, WP29, lawful basis, employee data, labour law.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
employee-data-privacy
metadata.tags
consent, employment, power-imbalance, article-88, wp29, lawful-basis

Overview

Consent is rarely a valid lawful basis for processing employee personal data under GDPR. The Article 29 Working Party's Opinion 2/2017 on data processing at work (WP249) and the EDPB's subsequent guidance establish a clear presumption against reliance on consent in the employment context. The rationale is straightforward: the inherent power imbalance between employer and employee means that consent cannot be "freely given" as required by Art. 4(11) GDPR when refusal or withdrawal of consent may result in real or perceived adverse consequences for the employee.

Art. 88(1) GDPR explicitly empowers Member States to provide more specific rules for processing in the employment context, and many have enacted legislation that further restricts or modifies the role of consent in employment data processing. This skill maps the consent prohibition landscape, identifies the narrow exceptions where consent may be valid, and provides a decision framework for selecting appropriate alternative lawful bases.

Consent must be:

  • Freely given: The data subject must have a genuine and free choice and must be able to refuse or withdraw consent without detriment
  • Specific: Consent must be given for one or more specific purposes
  • Informed: The data subject must be informed about the controller's identity, the purpose, the data processed, the right to withdraw, and any automated decision-making
  • Unambiguous indication: A clear affirmative action is required

The Article 29 Working Party stated in Section 5.1 of Opinion 2/2017:

"Employees are almost never in a position to freely give, refuse, or revoke consent, given the dependency that results from the employer/employee relationship. Given the imbalance of power, employees can only give free consent in exceptional circumstances, when no consequences at all are connected to acceptance or rejection of an offer."

Key factors that negate free consent in employment:

FactorExplanation
Power imbalanceThe employer controls terms of employment, pay, promotion, and termination
Perceived consequencesEven where no actual consequence follows refusal, employees reasonably fear adverse effects
Inability to refuseProcessing may be presented as mandatory regardless of the consent mechanism
Withdrawal difficultyEmployees may fear that withdrawing consent will be noted negatively
Granularity problemsConsent for multiple processing activities may be bundled, preventing genuine choice
Recital 43 — Imbalance of Power

Recital 43 GDPR states: "Consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller." The employer-employee relationship is the paradigmatic example of this imbalance.

EDPB Confirmation

The EDPB Guidelines 05/2020 on consent under Regulation 2016/679 (Section 3.1.1) reaffirmed that consent is "highly unlikely to be a legal basis for data processing at work, unless employees can refuse without adverse consequences."

Despite the general presumption against consent in employment, there are limited scenarios where genuine free choice may exist:

Exception 1: Purely Voluntary Benefits

Where an employer offers an optional benefit and participation is genuinely voluntary with no consequence for declining:

  • Optional corporate wellness programme with health data processing
  • Voluntary employee discount programme requiring sharing of personal preferences
  • Optional employee photo directory

Conditions: The benefit must be genuinely optional, non-participation must have no negative consequences, and the employee must be able to withdraw at any time with immediate cessation of processing.

Atlas Manufacturing Group Example: Atlas offers an optional cycle-to-work scheme that requires processing of home address data for distance calculation. Employees who decline are not disadvantaged in any way. The DPO approved consent as the lawful basis with documented safeguards: the consent form explicitly states that non-participation has no employment consequences, and the scheme administrator is separate from line management.

Exception 2: Employee-Initiated Processing

Where the employee specifically requests processing for their own benefit:

  • Employee requests a reference letter (requiring disclosure of employment data to a third party)
  • Employee requests salary advance (requiring additional financial data processing)
  • Employee requests flexible working arrangement (requiring processing of personal circumstances)

In limited circumstances, explicit consent under Art. 9(2)(a) may be appropriate for special category data where:

  • No other Art. 9(2) condition applies
  • The processing is genuinely in the employee's interest
  • Refusal has absolutely no adverse consequence
  • National law does not prohibit or restrict consent for this purpose

Example: An employee voluntarily discloses a disability to access workplace adjustments, and no legal obligation to process this data exists under national disability discrimination law.

Alternative Lawful Bases for Employment Processing

Art. 6(1)(b) — Performance of the Employment Contract

Scope: Processing necessary for the performance of the contract of employment.

Processing ActivityArt. 6(1)(b) Applicability
Payroll processingYes — directly necessary for contract performance
Work scheduling and shift managementYes — necessary for organising contractual duties
Performance management against contractual objectivesYes — contractual performance evaluation
Absence managementYes — managing contractual leave entitlements
Provision of contractual benefits (pension, insurance)Yes — contractual obligation
Background checks beyond contractual requirementsNo — extends beyond contract necessity
Post-termination data retention beyond legal requirementsNo — contract has ended

Limitation: The processing must be genuinely necessary for the contract, not merely useful or convenient. The EDPB has emphasised that "necessary" must be interpreted strictly — what is necessary is determined by the nature of the contract, not the employer's business model.

Scope: Processing required by law, including employment law, tax law, social security law, and health and safety law.

Processing ActivityLegal Obligation
Tax withholding and reportingNational tax law (e.g., Income Tax Act, PAYE regulations)
Social security contributionsNational social security legislation
Working time recordingEU Working Time Directive 2003/88/EC, as confirmed in CCOO v Deutsche Bank (CJEU, C-55/18, 2019)
Health and safety incident reportingFramework Directive 89/391/EEC
Right-to-work verificationNational immigration law
Gender pay gap reporting (UK)Equality Act 2010 (Gender Pay Gap Information) Regulations 2017
Whistleblower channel operationEU Whistleblowing Directive 2019/1937
Art. 6(1)(f) — Legitimate Interest

Scope: Processing necessary for the legitimate interests of the employer, provided these interests are not overridden by the interests, rights, or freedoms of the employee.

Three-part legitimate interest test (Art. 6(1)(f) + WP217):

  1. Purpose test: Is there a legitimate interest? (Business security, fraud prevention, IT security, organisational efficiency)
  2. Necessity test: Is the processing necessary for that interest, or could the aim be achieved by less intrusive means?
  3. Balancing test: Do the employer's interests override the employees' fundamental rights? Consider:
    • The nature of the data (sensitive vs. non-sensitive)
    • The reasonable expectations of employees
    • The impact on the employee
    • The safeguards in place
Processing ActivityLegitimate Interest Analysis
CCTV in production areas for safetyLikely valid — safety interest is strong, cameras in work areas expected
Email metadata monitoring for securityLikely valid if limited to metadata and employees are informed
Productivity scoring from monitoring dataUnlikely valid — significant impact on employee autonomy, less intrusive alternatives available
Social media screening of job applicantsQuestionable — high intrusiveness, limited to publicly available professional profiles if at all
Show full SKILL.md (668 more words)Show less
Art. 6(1)(e) — Public Interest (Public Sector Employers)

For public sector employers, processing may be based on the performance of a task carried out in the public interest or in the exercise of official authority.

Art. 88 — National Derogations

Art. 88(1) permits Member States to provide more specific rules for processing in the employment context by law or collective agreements. Key national implementations:

Germany — Section 26 BDSG
  • Employee data may be processed if necessary for the employment decision, performance of the employment contract, exercise or enjoyment of rights from collective agreements, or termination of employment
  • Consent in the employment context is valid only if the employee derives a legal or economic advantage or the employer and employee pursue the same interest
  • Consent must be in writing (unless electronic consent is appropriate due to circumstances)
  • The works council (Betriebsrat) has co-determination rights under Section 87(1)(6) BetrVG for any technical monitoring of employee behaviour
France — Labour Code (Code du travail)
  • Art. L.1121-1: No employer may restrict the rights of individuals or individual and collective freedoms unless justified by the nature of the task and proportionate to the aim pursued
  • Art. L.1222-4: No information concerning an employee personally may be collected by a device that has not been previously brought to their attention
  • CNIL Deliberation No. 2019-160: Specific requirements for employee monitoring transparency and proportionality
Netherlands — UAVG (Implementing Act GDPR)
  • Art. 30 UAVG: Employee consent for processing by the employer is deemed not freely given due to the dependency relationship, unless the processing is clearly in the interest of the employee
  • Works council (ondernemingsraad) has consent rights under Art. 27(1)(k) and (l) WOR for personal data processing decisions
Spain — Organic Law 3/2018 (LOPDGDD)
  • Art. 87-91: Specific provisions for digital rights in the employment context
  • Art. 87: Right to digital privacy at work
  • Art. 89: Right to digital privacy in relation to video surveillance and sound recording at the workplace — employees must be informed of monitoring in advance
  • Art. 90: Right to digital privacy in the context of geolocation at work
Italy — Workers' Statute (Legge 300/1970) and Jobs Act (D.Lgs. 151/2015)
  • Art. 4: Remote monitoring of employees is permitted only for organisational, production, safety, or asset protection purposes, and only with trade union agreement or labour inspectorate authorisation
  • Individual performance monitoring through remote control systems remains prohibited

Decision Framework: Selecting the Lawful Basis

START: Employer needs to process employee personal data
│
├─ Is the processing required by a specific law or regulation?
│  ├─ YES → Art. 6(1)(c) — Legal Obligation
│  └─ NO → Continue
│
├─ Is the processing necessary for performance of the employment contract?
│  ├─ YES → Art. 6(1)(b) — Contract Performance
│  │  └─ Apply strict necessity test: would the contract fail without this processing?
│  └─ NO → Continue
│
├─ Is the employer a public authority processing for a public task?
│  ├─ YES → Art. 6(1)(e) — Public Interest
│  └─ NO → Continue
│
├─ Does the employer have a legitimate interest?
│  ├─ YES → Conduct three-part LIA under Art. 6(1)(f)
│  │  ├─ Balancing test favours employer → Art. 6(1)(f) — Legitimate Interest
│  │  └─ Balancing test favours employee → Processing cannot proceed on this basis
│  └─ NO → Continue
│
├─ Is the processing genuinely voluntary with zero employment consequences?
│  ├─ YES → Art. 6(1)(a) — Consent (with documented safeguards)
│  │  └─ Document: (1) no consequence for refusal, (2) easy withdrawal, (3) separate from employment terms
│  └─ NO → Consent is not valid. Reassess whether processing is necessary at all.
│
└─ END: If no lawful basis can be identified, the processing must not proceed.

Common Compliance Failures

FailureRiskRemediation
Using consent as default lawful basis for all employment processingInvalid processing; enforcement action; employee claimsAudit all employment processing and reassign to appropriate lawful basis
Bundling consent for multiple purposes in one formConsent is not specific per Art. 4(11)Separate consent requests with granular choices
No mechanism for consent withdrawalConsent invalid from inceptionImplement withdrawal mechanism and cease processing on withdrawal
Presenting consent as mandatory during onboardingConsent not freely givenSeparate mandatory processing (with alternative lawful basis) from optional processing
Ignoring national Art. 88 derogationsNon-compliance with national lawMap all employment processing to applicable national requirements

Enforcement Precedents

AuthorityCaseFine/OutcomeIssue
Hellenic DPADecision 26/2019EUR 150,000Employer relied on consent for employee CCTV monitoring — consent invalid due to power imbalance
Austrian DPADSB-D123.270/0009-DSB/2018EUR 4,800,000 (reduced on appeal)Systematic employee monitoring based on invalid consent
ICO (UK)Mermaids Charity, 2023Enforcement noticeProcessing of employee special category data without valid lawful basis
CNIL (France)Deliberation SAN-2022-018EUR 600,000Employer collected excessive employee data, purporting to rely on consent
LfDI Baden-Württemberg2020EUR 35,258,707.95Employer processed employee health data based on consent that was not freely given (H&M case, contributed to by German Federal Commissioner)

Integration Points

  • Employee Monitoring DPIA: DPIAs for monitoring must confirm that consent is not relied upon (see employee-monitoring-dpia skill).
  • Employee Biometric Data: Biometric processing requires Art. 9 condition — consent validity is even more constrained (see employee-biometric-data skill).
  • Employee Health Data: Health data processing has specific Art. 9(2)(b) and (h) alternatives to consent (see employee-health-data skill).
  • BYOD Privacy Policy: BYOD arrangements may appear to require consent but often have alternative bases (see byod-privacy-policy skill).

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/employment-consent-limits of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Employment Consent Limits next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Employment Consent Limits compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Employment Consent Limits this skillmukul975/Privacy-Data-Protection-Skills301—~4kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Employment Consent Limits

What does Employment Consent Limits do?

Analyses the limitations on consent as a lawful basis for processing employee data under Art. Employment Consent Limits is an agent skill from mukul975/Privacy-Data-Protection-Skills. Analyses the limitations on consent as a lawful basis for processing employee data under Art.

When should I use Employment Consent Limits?

Employment Consent Limits fits situations like: tasks that involve Privacy and GDPR.

How do I install Employment Consent Limits in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employment-consent-limits -a claude-code`. Or copy the skill folder (skills/privacy/employment-consent-limits in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/employment-consent-limits in your project. Claude Code loads it when a task matches its description.

How do I install Employment Consent Limits in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employment-consent-limits -a codex`. Or copy the skill folder (skills/privacy/employment-consent-limits in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/employment-consent-limits in your project. Codex loads it when a task matches its description.

Can I use Employment Consent Limits in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill employment-consent-limits -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/employment-consent-limits, .gemini/skills/employment-consent-limits, .github/skills/employment-consent-limits and .opencode/skills/employment-consent-limits in your project.

What does Employment Consent Limits need to run?

Going by SKILL.md and its folder, Employment Consent Limits needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Employment Consent Limits access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Employment Consent Limits safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Employment Consent Limits use?

Employment Consent Limits is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Employment Consent Limits use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Employment Consent Limits?

Skills that share tags, products or a category with Employment Consent Limits: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Employment Consent Limits?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.