C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Guides GDPR certification mechanism implementation per Articles 42-43 including accredited certification body selection, certification criteria per EDPB guidelines, certification scope, periodic…
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-certification-scheme -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills gdpr-certification-scheme --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/gdpr-certification-scheme .claude/skills/gdpr-certification-scheme && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gdpr-certification-scheme" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/gdpr-certification-scheme into .claude/skills/gdpr-certification-scheme/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-certification-scheme", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/gdpr-certification-schemeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-certification-scheme -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills gdpr-certification-scheme --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/gdpr-certification-scheme .agents/skills/gdpr-certification-scheme && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gdpr-certification-scheme" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/gdpr-certification-scheme into .agents/skills/gdpr-certification-scheme/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-certification-scheme", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-certification-scheme -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills gdpr-certification-scheme --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/gdpr-certification-scheme .cursor/skills/gdpr-certification-scheme && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gdpr-certification-scheme" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/gdpr-certification-scheme into .cursor/skills/gdpr-certification-scheme/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-certification-scheme", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/gdpr-certification-scheme--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-certification-scheme -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills gdpr-certification-scheme --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/gdpr-certification-scheme .gemini/skills/gdpr-certification-scheme && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gdpr-certification-scheme" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/gdpr-certification-scheme into .gemini/skills/gdpr-certification-scheme/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-certification-scheme", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills gdpr-certification-schemeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-certification-scheme -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/gdpr-certification-scheme .github/skills/gdpr-certification-scheme && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gdpr-certification-scheme" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/gdpr-certification-scheme into .github/skills/gdpr-certification-scheme/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-certification-scheme", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-certification-scheme -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills gdpr-certification-scheme --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/gdpr-certification-scheme .opencode/skills/gdpr-certification-scheme && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gdpr-certification-scheme" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/gdpr-certification-scheme into .opencode/skills/gdpr-certification-scheme/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-certification-scheme", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gdpr-certification-schemeGuides GDPR certification mechanism implementation per Articles 42-43 including accredited certification body selection, certification criteria per EDPB guidelines, certification scope, periodic…
Gdpr Certification Scheme is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides GDPR certification mechanism implementation per Articles 42-43 including accredited certification body selection, certification criteria per EDPB guidelines, certification scope, periodic audit requirements, seal and mark usage rules, and relationship to codes of conduct. Covers EDPB/ENISA certification framework and national accreditation. Keywords: GDPR certification, Article 42, Article 43, certification body, EDPB, seal, mark, accreditation.
Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gdpr Certification Scheme loads about 4.9k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 121 tokens; SKILL.md has 2,151 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,151 words, ~4,911 tokens.
.claude/skills/gdpr-certification-scheme/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Articles 42-43 GDPR establish a voluntary data protection certification mechanism to demonstrate compliance with the Regulation. Art. 42(1) states that Member States, supervisory authorities, the Board, and the Commission shall encourage the establishment of data protection certification mechanisms, seals, and marks for the purpose of demonstrating compliance with the GDPR of processing operations by controllers and processors.
GDPR certification is distinct from ISO 27701 certification or SOC 2 attestation in that it is specifically authorized by the GDPR itself and must be issued by an accredited certification body (Art. 42(5)) or by a competent supervisory authority (Art. 42(5)). The certification criteria must be approved by the competent supervisory authority pursuant to Art. 58(3)(f) or by the EDPB pursuant to Art. 63 for transnational certification schemes (the European Data Protection Seal — Art. 42(5)).
As of 2024, the GDPR certification ecosystem is maturing with the EDPB having adopted criteria for the first European Data Protection Seal (Europrivacy/EuroPrivacy) and several national supervisory authorities developing domestic certification schemes.
Sentinel Compliance Group is pursuing Europrivacy certification for its cloud-based SaaS processing operations, targeting certification by Q3 2025.
Art. 42(1): Encouragement of data protection certification mechanisms, seals, and marks to demonstrate GDPR compliance.
Art. 42(2): Certification shall be voluntary, does not reduce the controller/processor's responsibility for GDPR compliance, and is without prejudice to supervisory authority tasks and powers.
Art. 42(3): Certification is issued by accredited certification bodies (Art. 43) or by the competent supervisory authority based on criteria approved by the competent supervisory authority or by the EDPB.
Art. 42(4): A controller or processor seeking certification shall provide the certification body or supervisory authority with all information and access necessary for the certification procedure.
Art. 42(5): Certification is issued for a maximum period of three years. It may be renewed under the same conditions if the relevant requirements continue to be met. Certification shall be withdrawn by the certification body or supervisory authority where the requirements are not or are no longer met.
Art. 42(6): The Board shall collate all certification mechanisms and seals in a register and make them publicly available.
Art. 42(7): Certification shall not affect the supervisory authority's task to monitor compliance or the exercise of its corrective powers under Art. 58.
Art. 43(1): Certification bodies shall have an appropriate level of expertise in data protection.
Art. 43(2): Accreditation of certification bodies shall be granted by:
| Accreditation Path | Authority | Requirements |
|---|---|---|
| Option (a) | Competent supervisory authority alone | Based on criteria approved by that SA |
| Option (b) | National accreditation body (per Regulation (EC) No 765/2008) | In accordance with EN-ISO/IEC 17065/2012 AND additional requirements established by the competent supervisory authority |
Art. 43(3): Accreditation is issued for a maximum period of five years, renewable.
Art. 43(4): Accredited certification bodies must provide reasons for granting or withdrawing certification to the competent supervisory authority.
Art. 43(6): Certification body requirements include:
The EDPB adopted Guidelines 1/2018 providing guidance to supervisory authorities and certification bodies on certification criteria:
Key Principles:
Based on EDPB Guidelines 1/2018, certification criteria must address relevant GDPR provisions. The following framework maps GDPR requirements to certification evaluation areas:
| Criterion ID | Assessment Area | Evidence Required |
|---|---|---|
| C1.1 | Lawful basis identified and documented for each processing activity | Lawful basis register, LIA documentation |
| C1.2 | Privacy notices meet Art. 13-14 requirements | Published privacy notices, version history |
| C1.3 | Fair processing practices demonstrated | Processing documentation, data subject feedback |
| C1.4 | No hidden or deceptive processing | Data flow documentation, technical audit results |
| Criterion ID | Assessment Area | Evidence Required |
|---|---|---|
| C2.1 | Purposes specified, explicit, and legitimate | Purpose register, RoPA |
| C2.2 | No incompatible further processing | Purpose limitation controls, change management records |
| C2.3 | Compatibility assessment for further processing | Compatibility assessment documentation |
| Criterion ID | Assessment Area | Evidence Required |
|---|---|---|
| C3.1 | Data collected is adequate, relevant, and limited | Data element justification per purpose |
| C3.2 | Minimisation practices embedded in system design | Design documentation, technical review |
| C3.3 | Regular review of data necessity | Data review records, cleanup logs |
| Criterion ID | Assessment Area | Evidence Required |
|---|---|---|
| C4.1 | Data accuracy measures at collection | Validation controls, input rules |
| C4.2 | Rectification mechanisms available | Correction process documentation, logs |
| C4.3 | Periodic accuracy verification | Data quality review records |
| Criterion ID | Assessment Area | Evidence Required |
|---|---|---|
| C5.1 | Retention periods defined per purpose | Retention schedule |
| C5.2 | Deletion/anonymisation executed upon expiry | Deletion logs, automation configuration |
| C5.3 | Retention exceptions documented and time-bound | Exception register |
| Criterion ID | Assessment Area | Evidence Required |
|---|---|---|
| C6.1 | Encryption at rest (AES-256 or equivalent) | Configuration evidence |
| C6.2 | Encryption in transit (TLS 1.2+) | Certificate inventory, scan results |
| C6.3 | Access controls (RBAC, least privilege) | IAM configuration, access reviews |
| C6.4 | Audit logging and monitoring | Log configuration, SIEM rules |
| C6.5 | Vulnerability management | Pen test results, vulnerability scan reports |
| C6.6 | Incident response procedures | IR plan, tabletop exercise results |
| Criterion ID | Assessment Area | Evidence Required |
|---|---|---|
| C7.1 | Privacy governance structure | Organizational chart, governance charter |
| C7.2 | Records of processing activities | Complete RoPA |
| C7.3 | Data protection impact assessments | DPIA register, completed DPIAs |
| C7.4 | Data processing agreements | DPA inventory, executed agreements |
| C7.5 | DPO appointment and independence | DPO designation, independence documentation |
| C7.6 | Training and awareness program | Training records, content, completion rates |
| Criterion ID | Assessment Area | Evidence Required |
|---|---|---|
| C8.1 | DSAR intake and fulfillment procedures | Process documentation, DSAR logs |
| C8.2 | Response within regulatory timeframes | Response time metrics |
| C8.3 | Identity verification | Verification procedures, logs |
| C8.4 | Right to erasure implementation | Deletion procedures, verification |
| C8.5 | Right to data portability | Export functionality, format documentation |
| C8.6 | Automated decision-making safeguards | Art. 22 compliance documentation |
| Criterion ID | Assessment Area | Evidence Required |
|---|---|---|
| C9.1 | Transfer mechanisms in place | SCC execution, adequacy reliance |
| C9.2 | Transfer impact assessments | TIA documentation |
| C9.3 | Supplementary measures | Technical/organizational/contractual measures |
| Criterion ID | Assessment Area | Evidence Required |
|---|---|---|
| C10.1 | Breach detection capabilities | Detection tools, monitoring configuration |
| C10.2 | 72-hour DPA notification process | Notification procedures, templates |
| C10.3 | Data subject notification process | Notification criteria, templates |
| C10.4 | Breach documentation | Incident records, post-incident reviews |
Europrivacy (formerly EuroPrivacy) is the first European Data Protection Seal recognized by the EDPB. It was developed under the European research program and is administered by the European Centre for Certification and Privacy (ECCP) in Luxembourg.
| Aspect | Description |
|---|---|
| Legal Basis | Art. 42 GDPR; EDPB-approved certification criteria |
| Scope | Processing operations of controllers and processors |
| Validity | 3 years (Art. 42(7)) with annual surveillance |
| Certification Body | Accredited certification bodies meeting Art. 43 and ISO/IEC 17065 |
| Criteria Version | Europrivacy criteria v1.0 (approved by EDPB 2022) |
| Assessment Method | Documentation review + on-site audit + technical testing |
| Output | Europrivacy certificate and seal with public register entry |
| Decision | Criteria |
|---|---|
| Certified | All applicable criteria met; no major nonconformities |
| Certified with conditions | Minor nonconformities identified; corrective action plan accepted; certification granted pending verification within 90 days |
| Not certified | Major nonconformities; organization may reapply after remediation |
| Use Case | Rules |
|---|---|
| Website | Display certification seal on privacy notice or trust center page with link to certificate details |
| Marketing Materials | Reference certification in brochures, presentations, and proposals with accurate scope description |
| Contracts | Reference certification in DPAs and customer agreements; certification does not replace contractual obligations |
| Product Packaging | Display seal only if the certified processing operation is integral to the product |
| Press Releases | Announce certification with accurate scope description; avoid implying total GDPR compliance |
| Prohibition | Rationale |
|---|---|
| Implying certification covers all processing activities when scope is limited | Misleading to data subjects and customers |
| Using the seal after certificate expiry or withdrawal | No longer authorized |
| Modifying the seal design (color, proportions, text) | Seal integrity must be maintained |
| Implying certification replaces regulatory compliance obligations | Art. 42(4): certification does not reduce controller/processor responsibility |
| Transferring the seal to non-certified entities (subsidiaries, partners) | Certification is entity- and scope-specific |
| Using the seal in a way that implies supervisory authority endorsement | Certification body issues certification, not the DPA |
| Aspect | GDPR Certification (Art. 42) | ISO 27701 |
|---|---|---|
| Legal basis | GDPR Art. 42-43 | ISO/IEC 27701:2019 |
| Scope | Processing operations | Privacy Information Management System |
| Criteria approval | Supervisory authority / EDPB | ISO standards body |
| Certification body | GDPR-accredited (Art. 43) | ISO 17021 / 17065 accredited |
| Regulatory weight | Explicit GDPR recognition (Art. 24, 28, 42, 83) | Recognized by practice; no express GDPR recognition |
| Duration | 3 years | 3 years |
| Transfer mechanism | Potentially under Art. 46(2)(f) | Not a transfer mechanism |
| Aspect | GDPR Certification (Art. 42) | Codes of Conduct (Art. 40) |
|---|---|---|
| Governance | Certification body | Code owner + monitoring body |
| Assessment | External audit by certification body | Self-assessment + monitoring body oversight |
| Criteria | GDPR-rooted, SA/EDPB approved | Sector-specific, SA/EDPB approved |
| Flexibility | Standardized criteria per scheme | Sector-adapted rules |
| Transfer mechanism | Art. 46(2)(f) | Art. 46(2)(e) |
| Art. 83(2)(j) factor | Yes (mitigating for fines) | Yes (mitigating for fines) |
| Country | DPA | Scheme Status | Notes |
|---|---|---|---|
| Luxembourg | CNPD | Europrivacy implementation | First to operationalize Europrivacy |
| France | CNIL | Developing national criteria | Focus on health data processing |
| Germany | DSK/LDAs | Criteria development underway | Sector-specific schemes under consideration |
| Spain | AEPD | Criteria published for public sector | AEPD Seal for public administration processing |
| Italy | Garante | Exploring certification for controller compliance | Early stage |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/gdpr-certification-scheme of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Gdpr Certification Scheme next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gdpr Certification Scheme this skillmukul975/Privacy-Data-Protection-Skills | 297 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 586 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Guides GDPR certification mechanism implementation per Articles 42-43 including accredited certification body selection, certification criteria per EDPB guidelines, certification scope, periodic…. Gdpr Certification Scheme is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides GDPR certification mechanism implementation per Articles 42-43 including accredited certification body selection, certification criteria per EDPB guidelines, certification scope, periodic audit requirements, seal and mark usage rules, and relationship to codes of conduct.
Gdpr Certification Scheme fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-certification-scheme -a claude-code`. Or copy the skill folder (skills/privacy/gdpr-certification-scheme in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/gdpr-certification-scheme in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-certification-scheme -a codex`. Or copy the skill folder (skills/privacy/gdpr-certification-scheme in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/gdpr-certification-scheme in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-certification-scheme -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gdpr-certification-scheme, .gemini/skills/gdpr-certification-scheme, .github/skills/gdpr-certification-scheme and .opencode/skills/gdpr-certification-scheme in your project.
Going by SKILL.md and its folder, Gdpr Certification Scheme needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Gdpr Certification Scheme is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Gdpr Certification Scheme: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.