Agent skill

Gdpr Compliance Audit

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37.

Apache-2.0Auto-check passedLegal & Compliance

Install Gdpr Compliance Audit

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-compliance-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills gdpr-compliance-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/gdpr-compliance-audit .claude/skills/gdpr-compliance-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gdpr-compliance-audit
GitHub stars
301
Token cost
~3.1k tokens
SKILL.md length
1,445 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37.

  • Works in 5 steps: Planning (Week 1) → Document Review (Weeks 2-3) → Testing and Interviews (Weeks 3-4) → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Audit Framework Structure, Domain 1: Data Protection… and Domain 2: Accountability and…, plus 7 more sections
  • Runs Python scripts from its folder

What it does

Gdpr Compliance Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37. Includes 50+ control points covering principles, accountability, security, and governance. Activate when performing compliance audits, preparing for supervisory authority inspections, or assessing organisational GDPR maturity. Keywords: data protection audit, compliance audit, GDPR audit, control points, accountability.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the gdpr-compliance-audit skill to guide a comprehensive organisational data protection audit against key GDPR requirements including Articles…”
  • “/gdpr-compliance-audit”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Planning (Week 1)
  2. Document Review (Weeks 2-3)
  3. Testing and Interviews (Weeks 3-4)
  4. Reporting (Week 5)
  5. Follow-up (Ongoing)

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gdpr Compliance Audit loads about 3.1k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 1,445 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,445 words, ~3,065 tokens.

Download SKILL.mdSave it as .claude/skills/gdpr-compliance-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
gdpr-compliance-audit
description
Guides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37. Includes 50+ control points covering principles, accountability, security, and governance. Activate when performing compliance audits, preparing for supervisory authority inspections, or assessing organisational GDPR maturity. Keywords: data protection audit, compliance audit, GDPR audit, control points, accountability.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
gdpr-compliance
metadata.tags
gdpr, audit, compliance, accountability, security, data-protection

Conducting Data Protection Audit

Overview

A data protection audit systematically evaluates an organisation's compliance with GDPR requirements across governance, processing activities, data subject rights, security measures, and third-party arrangements. This skill provides a structured audit framework with 50+ control points mapped to specific GDPR articles, enabling auditors to produce a comprehensive compliance assessment with prioritised remediation recommendations.

Audit Framework Structure

The audit is organised into eight domains aligned to core GDPR chapters and articles:

  1. Data Protection Principles (Art. 5)
  2. Accountability and Governance (Art. 24, 5(2))
  3. Privacy by Design and Default (Art. 25)
  4. Processor Management (Art. 28)
  5. Records of Processing (Art. 30)
  6. Security of Processing (Art. 32)
  7. Data Protection Impact Assessments (Art. 35)
  8. Data Protection Officer (Art. 37-39)

Domain 1: Data Protection Principles (Art. 5)

#Control PointGDPR RefEvidence Required
1.1Processing purposes are specified, explicit, and documented for each activityArt. 5(1)(a)-(b)RoPA with specific purpose statements
1.2A valid lawful basis is identified and documented for each processing activityArt. 5(1)(a), 6Lawful basis register/assessment records
1.3Personal data collected is adequate, relevant, and limited to what is necessaryArt. 5(1)(c)Data minimisation reviews, field-level justification
1.4Personal data is accurate and kept up to date with rectification proceduresArt. 5(1)(d)Data quality processes, rectification logs
1.5Retention periods are defined for all data categories with deletion/anonymisation proceduresArt. 5(1)(e)Retention schedule, deletion logs
1.6Appropriate security measures protect personal data against unauthorised access, loss, or destructionArt. 5(1)(f)Security controls documentation, pen test reports
1.7The controller can demonstrate compliance with all principles (accountability)Art. 5(2)Compiled evidence portfolio

Domain 2: Accountability and Governance (Art. 24)

#Control PointGDPR RefEvidence Required
2.1A data protection policy is approved by senior management and communicated to all staffArt. 24(2)Signed policy, distribution records
2.2Data protection roles and responsibilities are formally assigned across the organisationArt. 24(1)RACI matrix, job descriptions
2.3Regular data protection training is provided to all staff processing personal dataArt. 39(1)(b)Training records, attendance logs, completion certificates
2.4A data protection governance structure exists with board-level reportingArt. 24, 38(3)Governance charter, board meeting minutes
2.5Documented procedures exist for all GDPR obligations (breach notification, DSAR, DPIA)Art. 24(1)Procedure documents with version control
2.6Internal audits of data protection compliance are conducted at defined intervalsArt. 24(1)Audit schedule, previous audit reports
2.7A data protection risk register is maintained and reviewedArt. 24(1)Risk register with risk scores and treatment plans

Domain 3: Privacy by Design and Default (Art. 25)

#Control PointGDPR RefEvidence Required
3.1Privacy requirements are integrated into the systems development lifecycleArt. 25(1)SDLC documentation with privacy checkpoints
3.2Privacy impact is assessed before deploying new systems or changing existing processingArt. 25(1)DPIA screening records, change management logs
3.3Default settings ensure only necessary personal data is processedArt. 25(2)Configuration reviews, default settings documentation
3.4Data minimisation is applied at the design stage of systems and processesArt. 25(1)Design documents showing minimisation decisions
3.5Pseudonymisation and encryption are considered in system designArt. 25(1), 32(1)(a)Architecture documents, encryption standards
3.6User interfaces facilitate data subject rights (access, deletion, portability)Art. 25(1)-(2)UI/UX specifications, data export functionality

Domain 4: Processor Management (Art. 28)

#Control PointGDPR RefEvidence Required
4.1All processors are identified and recorded in a vendor registerArt. 28(1)Vendor register with processor classifications
4.2Written data processing agreements are in place with all processors containing Art. 28(3) mandatory clausesArt. 28(3)DPA register, sample DPA review
4.3Processor due diligence is conducted before engagement and periodically thereafterArt. 28(1)Due diligence questionnaires, assessment reports
4.4Sub-processor authorisation and notification procedures are documentedArt. 28(2)-(4)Sub-processor clauses, notification records
4.5Processor compliance is monitored through audits, certifications, or self-assessmentsArt. 28(3)(h)Audit rights exercised, SOC 2/ISO 27001 certificates
4.6Processors return or delete personal data upon contract terminationArt. 28(3)(g)Data return/deletion confirmations
4.7Processor breach notification obligations are contractually defined and testedArt. 28(3)(f), 33DPA breach clauses, incident response test results

Domain 5: Records of Processing (Art. 30)

#Control PointGDPR RefEvidence Required
5.1A comprehensive RoPA is maintained for all controller processing activitiesArt. 30(1)Complete RoPA with all Art. 30(1)(a)-(g) fields
5.2Processor records are maintained for all processing on behalf of controllersArt. 30(2)Processor RoPA with Art. 30(2)(a)-(d) fields
5.3RoPA is kept up to date with a defined review and update processArt. 30(1)-(2)Last review dates, update procedure
5.4RoPA can be made available to the supervisory authority on requestArt. 30(4)Export capability, access procedure
5.5RoPA is maintained in writing (including electronic form)Art. 30(3)Electronic RoPA system or documented spreadsheet
Show full SKILL.md (655 more words)Show less

Domain 6: Security of Processing (Art. 32)

#Control PointGDPR RefEvidence Required
6.1Risk assessments are conducted to determine appropriate security measuresArt. 32(1)-(2)Risk assessment reports for processing activities
6.2Pseudonymisation and encryption of personal data are implemented where appropriateArt. 32(1)(a)Encryption at rest and in transit documentation
6.3Ongoing confidentiality, integrity, availability, and resilience of systems is ensuredArt. 32(1)(b)ISO 27001 controls, access management, BCP/DR plans
6.4Ability to restore access to personal data in a timely manner after an incidentArt. 32(1)(c)Backup procedures, restoration testing records
6.5Regular testing and evaluation of security measures is performedArt. 32(1)(d)Penetration test reports, vulnerability scans, audit results
6.6Access to personal data is restricted on a need-to-know basisArt. 32(1)(b)Access control matrices, user access reviews
6.7Physical security controls protect premises where personal data is processedArt. 32(1)(b)Physical security policy, access logs
6.8Personal data breach detection and response procedures are in placeArt. 33-34Incident response plan, breach register

Domain 7: Data Protection Impact Assessments (Art. 35)

#Control PointGDPR RefEvidence Required
7.1Criteria for mandatory DPIA are defined and communicated to the organisationArt. 35(1),(3)DPIA threshold criteria, DPA blacklist consideration
7.2DPIAs are conducted before processing that is likely to result in high riskArt. 35(1)DPIA register with completion dates
7.3DPIAs contain all Art. 35(7) mandatory elements (description, necessity, risks, measures)Art. 35(7)Sample DPIA review for completeness
7.4The DPO is consulted during the DPIA processArt. 35(2)DPO consultation records, sign-off
7.5Data subject views are sought where appropriateArt. 35(9)Consultation records or documented rationale for not consulting
7.6DPIA outcomes are implemented and monitoredArt. 35(11)Remediation tracking, follow-up reviews
7.7Prior consultation with the supervisory authority is initiated when residual risk remains highArt. 36Prior consultation records (if applicable)

Domain 8: Data Protection Officer (Art. 37-39)

#Control PointGDPR RefEvidence Required
8.1A DPO is appointed where required (public authority, large-scale monitoring, special categories)Art. 37(1)DPO appointment letter, published contact details
8.2The DPO has sufficient resources, independence, and access to senior managementArt. 38(1)-(3)Budget allocation, reporting line documentation
8.3The DPO does not receive instructions regarding the exercise of their tasksArt. 38(3)Independence clause in employment/service contract
8.4The DPO's contact details are published and communicated to the supervisory authorityArt. 37(7)Website publication, DPA notification records
8.5The DPO is involved in all data protection matters in a timely mannerArt. 38(1)Meeting invitations, consultation records
8.6The DPO monitors compliance, provides advice, and cooperates with the supervisory authorityArt. 39(1)DPO activity reports, advisory records

Audit Execution Methodology

Phase 1: Planning (Week 1)
  1. Define audit scope (full organisation or targeted domains).
  2. Assemble audit team with data protection and information security expertise.
  3. Issue audit notification to business units 2 weeks in advance.
  4. Request pre-audit documentation package from each domain owner.
Phase 2: Document Review (Weeks 2-3)
  1. Review all requested evidence against each control point.
  2. Classify each control as: Effective, Partially Effective, Ineffective, or Not Implemented.
  3. Identify gaps where evidence is missing or insufficient.
Phase 3: Testing and Interviews (Weeks 3-4)
  1. Conduct interviews with processing owners, IT security, HR, legal, and the DPO.
  2. Perform sample testing of key controls (e.g., access reviews, breach simulations, DSAR process walkthroughs).
  3. Verify technical controls through configuration reviews or tool demonstrations.
Phase 4: Reporting (Week 5)
  1. Produce audit report with findings classified by severity (Critical, Major, Minor, Observation).
  2. Include a compliance score per domain and overall maturity rating.
  3. Provide prioritised remediation roadmap with owners and deadlines.
  4. Present findings to the Data Protection Steering Committee and Board.
Phase 5: Follow-up (Ongoing)
  1. Track remediation actions through the findings register.
  2. Conduct follow-up reviews at 30/60/90 day intervals depending on severity.
  3. Feed audit findings into the annual DPO report and risk register updates.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/gdpr-compliance-audit of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Gdpr Compliance Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gdpr Compliance Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gdpr Compliance Audit this skillmukul975/Privacy-Data-Protection-Skills301—~3.1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Gdpr Compliance Audit

What does Gdpr Compliance Audit do?

Guides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37. Gdpr Compliance Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37.

When should I use Gdpr Compliance Audit?

Gdpr Compliance Audit fits situations like: tasks that involve Privacy and GDPR.

How do I install Gdpr Compliance Audit in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-compliance-audit -a claude-code`. Or copy the skill folder (skills/privacy/gdpr-compliance-audit in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/gdpr-compliance-audit in your project. Claude Code loads it when a task matches its description.

How do I install Gdpr Compliance Audit in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-compliance-audit -a codex`. Or copy the skill folder (skills/privacy/gdpr-compliance-audit in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/gdpr-compliance-audit in your project. Codex loads it when a task matches its description.

Can I use Gdpr Compliance Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-compliance-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gdpr-compliance-audit, .gemini/skills/gdpr-compliance-audit, .github/skills/gdpr-compliance-audit and .opencode/skills/gdpr-compliance-audit in your project.

What does Gdpr Compliance Audit need to run?

Going by SKILL.md and its folder, Gdpr Compliance Audit needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Gdpr Compliance Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gdpr Compliance Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Gdpr Compliance Audit use?

Gdpr Compliance Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gdpr Compliance Audit use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to Gdpr Compliance Audit?

Skills that share tags, products or a category with Gdpr Compliance Audit: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gdpr Compliance Audit?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.