Agent skill

Eprivacy Essential Cookies

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Applying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent.

Apache-2.0Auto-check passedLegal & Compliance

Install Eprivacy Essential Cookies

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill eprivacy-essential-cookies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills eprivacy-essential-cookies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/eprivacy-essential-cookies .claude/skills/eprivacy-essential-cookies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
eprivacy-essential-cookies
GitHub stars
301
Token cost
~3.2k tokens
SKILL.md length
1,397 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Applying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent.

  • Works in 4 steps: Inventory All Cookies → Apply the Two-Part Test → Classify and Document → …
  • Tasks that involve Cloud networking
  • SKILL.md covers Overview, Exemption Criteria, Non-Exempt Cookie Categories and Borderline Cases and…, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Eprivacy Essential Cookies is an agent skill from mukul975/Privacy-Data-Protection-Skills. Applying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent. Covers exemption criteria, functionality cookies, load balancing, session state, and non-exempt categories with regulatory guidance from EDPB and national DPAs.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Cloud networking, Session handoff and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Cloud networking
  • Tasks that involve Session handoff
  • Tasks that involve Privacy and GDPR

Example prompts

  • “/eprivacy-essential-cookies”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Inventory All Cookies
  2. Apply the Two-Part Test
  3. Classify and Document
  4. Document Justification

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Eprivacy Essential Cookies loads about 3.2k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 78 tokens; SKILL.md has 1,397 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,397 words, ~3,249 tokens.

Download SKILL.mdSave it as .claude/skills/eprivacy-essential-cookies/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
eprivacy-essential-cookies
description
Applying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent. Covers exemption criteria, functionality cookies, load balancing, session state, and non-exempt categories with regulatory guidance from EDPB and national DPAs.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
cookie-consent-compliance
metadata.tags
eprivacy, essential-cookies, strictly-necessary, article-5-3, cookie-exemption

ePrivacy Directive Article 5(3) Essential Cookie Exemption

Overview

Article 5(3) of the ePrivacy Directive (2002/58/EC, as amended by Directive 2009/136/EC) requires informed consent before storing or accessing information on a user's terminal equipment (cookies, LocalStorage, device fingerprints). However, it provides an exemption for storage that is "strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to deliver the service." Correctly classifying cookies under this exemption is critical — over-claiming exemption exposes organizations to enforcement action, while under-claiming creates unnecessary consent friction. The Article 29 Working Party Opinion 04/2012 on Cookie Consent Exemption (WP 194) remains the authoritative guidance on applying this exemption.

Exemption Criteria

The Two-Part Test

A cookie qualifies for the strictly necessary exemption only if BOTH conditions are met:

Condition 1 — The cookie is strictly necessary The cookie must be essential for the specific functionality that the user has actively requested. "Strictly necessary" means the service literally cannot function without it — not merely that it would be degraded or less convenient.

Condition 2 — For a service explicitly requested by the user The user must have actively requested the service that the cookie enables. The cookie must serve the user's purpose, not the website operator's purpose. A cookie that is necessary for the operator's business model (e.g., analytics) but not for the service the user requested (e.g., viewing products) does not qualify.

Article 29 Working Party Exemption Categories

WP 194 (Opinion 04/2012) identified specific cookie categories that can qualify for exemption:

Category A — User Input Cookies (Session-Only)

CriterionRequirement
PurposeKeeping track of user input during a multi-step process (e.g., filling a form, shopping cart)
DurationSession-only (deleted when browser closes) or short-lived (limited to a few hours)
ScopeFirst-party only
ExampleShopping cart contents during a browsing session

Pinnacle E-Commerce Ltd Examples:

CookiePurposeDurationExempt
cart_sessionStores items added to shopping cart during sessionSessionYes
checkout_stepTracks current step in multi-page checkoutSessionYes
form_data_tempPreserves form input if page reloads during checkout30 minutesYes

Category B — Authentication Cookies

CriterionRequirement
PurposeAuthenticating the user to provide access to authenticated content/services
DurationSession-only for session authentication; persistent only if user explicitly chose "remember me"
ScopeFirst-party only
ExampleSession token after login

Pinnacle E-Commerce Ltd Examples:

CookiePurposeDurationExempt
auth_tokenAuthenticates logged-in userSessionYes
refresh_tokenMaintains authentication across browser restarts (when "remember me" selected)30 daysYes — user explicitly requested persistent login
session_idLinks requests to server-side sessionSessionYes

Category C — User Security Cookies

CriterionRequirement
PurposeEnsuring security of the service explicitly requested by the user
DurationLimited to what is necessary
ScopeFirst-party only
ExampleCSRF protection, detecting repeated failed login attempts

Pinnacle E-Commerce Ltd Examples:

CookiePurposeDurationExempt
csrf_tokenPrevents cross-site request forgery attacksSessionYes
login_attemptsTracks failed login count for brute-force protection30 minutesYes
device_verifiedFlags device as verified after 2FA30 daysYes — security for authenticated service

Category D — Multimedia Player Session Cookies

CriterionRequirement
PurposeStoring technical data for media playback (quality settings, buffering)
DurationSession-only
ScopeFirst-party only
ExampleVideo player quality preference for current session

Category E — Load Balancing Cookies

CriterionRequirement
PurposeDistributing web traffic across multiple servers
DurationSession-only (persists only for the browsing session)
ScopeFirst-party only
ExampleLoad balancer session affinity cookie

Pinnacle E-Commerce Ltd Examples:

CookiePurposeDurationExempt
SERVERIDHAProxy server affinity cookieSessionYes
__cfduid (legacy)Cloudflare server identificationSessionYes — if session-only
lb_routeInternal load balancer routingSessionYes

Category F — UI Customisation Cookies (Session-Only)

CriterionRequirement
PurposeStoring user interface preferences explicitly set by the user during the session
DurationSession-only (first visit within a session); persistent requires consent
ScopeFirst-party only
ExampleLanguage selection within a session

Critical Distinction: A language preference cookie set for the current session when the user clicks a language selector is exempt. A persistent language preference cookie that remembers the selection across visits typically requires consent (it exceeds the session scope).

Pinnacle E-Commerce Ltd Examples:

CookiePurposeDurationExempt
locale_sessionLanguage selected during current sessionSessionYes
localePersistent language preference1 yearNo — requires consent
currency_sessionCurrency selected during current sessionSessionYes
currencyPersistent currency preference1 yearNo — requires consent

The following cookie types are explicitly NOT exempt and always require consent:

Analytics and Performance Cookies
Cookie TypeWhy Not Exempt
Google Analytics (_ga, _gid)Serves the operator's analytics purpose, not the user's requested service
Hotjar (_hj*)Session recording and heatmaps serve the operator
A/B testing (optimizely_*)Experimentation serves the operator's optimization goals
Performance monitoringSite performance monitoring benefits the operator

Note: The CNIL has created a separate limited exemption for audience measurement (see analytics-cookie-consent skill), but this is a French-specific interpretation, not a universal ePrivacy Article 5(3) exemption.

Advertising and Targeting Cookies
Cookie TypeWhy Not Exempt
Meta Pixel (_fbp, _fbc)Advertising tracking serves the advertiser
Google Ads (_gcl_au, IDE)Conversion tracking and remarketing serve the advertiser
Retargeting cookiesCross-site tracking for ad personalization
Ad frequency cappingServes the ad delivery system, not the user
Show full SKILL.md (552 more words)Show less
Social Media Plug-in Cookies
Cookie TypeWhy Not Exempt
Facebook Like button cookiesThird-party tracking via social widget
Twitter share widget cookiesThird-party data collection
YouTube embed cookiesGoogle tracking via embedded video
LinkedIn Insight TagProfessional network tracking

Exception: If a social login (e.g., "Login with Google") is explicitly requested by the user, the authentication cookies for that flow may qualify under Category B. The social platform's tracking cookies do not.

Persistent Preference Cookies
Cookie TypeWhy Not Exempt
Persistent language preferenceExceeds session scope
Theme/dark mode preference (persistent)Exceeds session scope
"Don't show again" dismissal cookiesConvenience, not strictly necessary
Recently viewed productsEnhancement, not essential service

Borderline Cases and Regulatory Guidance

The cookie that stores whether the user has accepted or rejected cookies:

DPA PositionExempt?Reasoning
UK ICOYesStrictly necessary to remember the user's privacy choice
CNILYesTechnical necessity for implementing consent
Belgian DPAYesRequired to avoid re-prompting on every page
EDPBYes (implied)Necessary to fulfill the consent obligation

Pinnacle E-Commerce Ltd: The consent_state cookie is classified as strictly necessary.

Fraud Detection Cookies
ScenarioExempt?Reasoning
CSRF token for form submissionYesSecurity for service the user requested (submitting a form)
Bot detection (CAPTCHA)Likely yesSecurity for the service; some DPAs require notice
Device fingerprinting for fraudLikely noGoes beyond what is strictly necessary; may use consent or legitimate interest
reCAPTCHA cookiesContestedGoogle reCAPTCHA sets cookies and communicates with Google; some DPAs require consent
CDN and Infrastructure Cookies
ScenarioExempt?Reasoning
Cloudflare __cf_bm (bot management)ContestedSecurity-related but sets persistent cookie; review with DPO
CDN session routingYesLoad balancing (Category E)
Geographic routingYes if session-onlyInfrastructure necessity
A/B testing server routingNoOptimization, not user-requested service

Classification Process for Pinnacle E-Commerce Ltd

Step 1: Inventory All Cookies

Use the cookie-audit skill to generate a complete cookie inventory.

Step 2: Apply the Two-Part Test

For each cookie, answer:

  1. Is this cookie strictly necessary for the website to deliver a specific function?
  2. Did the user explicitly request that specific function?
Step 3: Classify and Document
CookieUser-Requested ServiceStrictly NecessaryDuration OKExempt
session_idBrowsing the siteYes — session stateSessionYes
auth_tokenLogging inYes — authenticationSessionYes
cart_sessionAdding items to cartYes — cart functionalitySessionYes
csrf_tokenSubmitting formsYes — form securitySessionYes
_gaNone (operator analytics)No2 yearsNo
_fbpNone (operator advertising)No90 daysNo
localeChanging languageDebatable1 yearNo — persistent, needs consent
consent_stateManaging cookie preferencesYes — consent management6 monthsYes
Step 4: Document Justification

For each exempt cookie, maintain a written justification:

Template:

Cookie: [name]
Classification: Strictly Necessary — Exempt from consent
User-Requested Service: [specific service]
Why Strictly Necessary: [explanation of why the service cannot function without this cookie]
Duration Justification: [why this duration is the minimum necessary]
WP 194 Category: [A/B/C/D/E/F]
Reviewed By: [DPO name]
Review Date: [date]
Next Review: [date + 12 months]
  • ePrivacy Directive 2002/58/EC, Article 5(3) — Consent requirement and strictly necessary exemption
  • Directive 2009/136/EC (Citizens' Rights Directive) — Amended Article 5(3) to require informed consent
  • Article 29 Working Party Opinion 04/2012 (WP 194) — Authoritative guidance on cookie consent exemption categories
  • CJEU Case C-673/17 (Planet49) — Active consent; exemption applies only to strictly necessary cookies
  • EDPB Guidelines 05/2020 on Consent — Consent under GDPR applicable to ePrivacy consent
  • UK ICO Guidance on Cookies (2019, updated 2023) — PECR implementation of ePrivacy exemptions
  • CNIL Deliberation No. 2020-091 (17 September 2020) — French implementation of cookie exemptions
  • Recital 66, Directive 2009/136/EC — Exemption for cookies "strictly limited to the provision of an information society service explicitly requested"

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/eprivacy-essential-cookies of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Eprivacy Essential Cookies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Eprivacy Essential Cookies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Eprivacy Essential Cookies this skillmukul975/Privacy-Data-Protection-Skills301—~3.2kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Eprivacy Essential Cookies

What does Eprivacy Essential Cookies do?

Applying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent. Eprivacy Essential Cookies is an agent skill from mukul975/Privacy-Data-Protection-Skills. Applying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent.

When should I use Eprivacy Essential Cookies?

Eprivacy Essential Cookies fits situations like: tasks that involve Cloud networking; tasks that involve Session handoff; tasks that involve Privacy and GDPR.

How do I install Eprivacy Essential Cookies in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill eprivacy-essential-cookies -a claude-code`. Or copy the skill folder (skills/privacy/eprivacy-essential-cookies in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/eprivacy-essential-cookies in your project. Claude Code loads it when a task matches its description.

How do I install Eprivacy Essential Cookies in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill eprivacy-essential-cookies -a codex`. Or copy the skill folder (skills/privacy/eprivacy-essential-cookies in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/eprivacy-essential-cookies in your project. Codex loads it when a task matches its description.

Can I use Eprivacy Essential Cookies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill eprivacy-essential-cookies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eprivacy-essential-cookies, .gemini/skills/eprivacy-essential-cookies, .github/skills/eprivacy-essential-cookies and .opencode/skills/eprivacy-essential-cookies in your project.

What does Eprivacy Essential Cookies need to run?

Going by SKILL.md and its folder, Eprivacy Essential Cookies needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Eprivacy Essential Cookies access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Eprivacy Essential Cookies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Eprivacy Essential Cookies use?

Eprivacy Essential Cookies is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Eprivacy Essential Cookies use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 812 tokens, read only when the agent opens those files.

What are the alternatives to Eprivacy Essential Cookies?

Skills that share tags, products or a category with Eprivacy Essential Cookies: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Eprivacy Essential Cookies?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.