Agent skill

Gdpr Dpa Art28

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides the creation and review of data processing agreements under GDPR Article 28(3), covering all eight mandatory clauses.

Apache-2.0Auto-check passedLegal & Compliance

Install Gdpr Dpa Art28

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-dpa-art28 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills gdpr-dpa-art28 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/gdpr-dpa-art28 .claude/skills/gdpr-dpa-art28 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gdpr-dpa-art28
GitHub stars
301
Token cost
~1.9k tokens
SKILL.md length
945 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides the creation and review of data processing agreements under GDPR Article 28(3), covering all eight mandatory clauses.

  • Works in 5 steps: Audit rights: Ensure meaningful audit… → Sub-processor transparency: Require a… → Breach notification timeline: Art. 33(2)… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Art. 28(3) Mandatory Elements, DPA Compliance Checklist and 2021 Standard Contractual…, plus 1 more section
  • Runs Python scripts from its folder

What it does

Gdpr Dpa Art28 is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides the creation and review of data processing agreements under GDPR Article 28(3), covering all eight mandatory clauses. References the 2021 Standard Contractual Clauses and provides a compliance checklist for processor contracts. Activate when onboarding processors, reviewing DPAs, or auditing processor compliance. Keywords: DPA, data processing agreement, Article 28, processor, mandatory clauses, standard contractual clauses.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Regulatory compliance. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Regulatory compliance

Example prompts

  • “Use the gdpr-dpa-art28 skill to guide the creation and review of data processing agreements under GDPR Article 28(3), covering all eight mandatory…”
  • “/gdpr-dpa-art28”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Audit rights: Ensure meaningful audit rights, not just acceptance of SOC 2 reports as a substitute for on-site audits.
  2. Sub-processor transparency: Require a current list of sub-processors and timely notification (at least 30 days) before changes.
  3. Breach notification timeline: Art. 33(2) requires "without undue delay" — specify a concrete timeline (e.g., 24-48 hours).
  4. Data deletion evidence: Require written certification of deletion with a specific format and timeline.
  5. Liability: Art. 82(2) establishes processor liability for damage caused by non-compliance with processor-specific obligations or acting…

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gdpr Dpa Art28 loads about 1.9k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 945 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 945 words, ~1,946 tokens.

Download SKILL.mdSave it as .claude/skills/gdpr-dpa-art28/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
gdpr-dpa-art28
description
Guides the creation and review of data processing agreements under GDPR Article 28(3), covering all eight mandatory clauses. References the 2021 Standard Contractual Clauses and provides a compliance checklist for processor contracts. Activate when onboarding processors, reviewing DPAs, or auditing processor compliance. Keywords: DPA, data processing agreement, Article 28, processor, mandatory clauses, standard contractual clauses.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
gdpr-compliance
metadata.tags
gdpr, dpa, article-28, processor, data-processing-agreement, scc

Establishing Data Processing Agreements

Overview

Article 28(3) requires that processing by a processor is governed by a contract or other legal act that is binding on the processor and sets out specific mandatory elements. This skill details all eight mandatory clauses, provides a compliance checklist, and references the 2021 EU Standard Contractual Clauses for controller-to-processor transfers.

Art. 28(3) Mandatory Elements

Element 1: Subject-Matter and Duration

The DPA must specify the subject-matter of the processing (what processing is being carried out), the duration (aligned with the service contract term), the nature of the processing (collection, storage, analysis, deletion), and the purpose of the processing.

Element 2: Type of Personal Data

The DPA must list the specific categories of personal data being processed (names, email addresses, financial data, health data, etc.).

Element 3: Categories of Data Subjects

The DPA must identify which data subjects are affected (employees, customers, website visitors, patients, etc.).

Element 4: Obligations and Rights of the Controller

The DPA must set out the controller's documented instructions to the processor, covering what the processor is authorised to do with the data.

Element 5: Processor Obligations (Art. 28(3)(a)-(h))

(a) Documented instructions: The processor shall process personal data only on documented instructions from the controller, including with regard to transfers to third countries, unless required to do so by EU or Member State law — in which case the processor must inform the controller before processing (unless the law prohibits such notification).

(b) Confidentiality: The processor shall ensure that persons authorised to process the personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.

(c) Security measures: The processor shall take all measures required pursuant to Article 32 (security of processing).

(d) Sub-processors: The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor must inform the controller of any intended changes concerning the addition or replacement of sub-processors, giving the controller the opportunity to object (Art. 28(2) and (4)).

(e) Assistance with data subject rights: The processor shall assist the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to data subject requests (Art. 15-22).

(f) Assistance with GDPR obligations: The processor shall assist the controller in ensuring compliance with Articles 32-36 (security, breach notification, DPIAs, prior consultation), taking into account the nature of processing and the information available to the processor.

(g) Data return or deletion: At the choice of the controller, the processor shall delete or return all personal data after the end of the provision of processing services, and delete existing copies unless EU or Member State law requires storage.

(h) Audit and inspection: The processor shall make available to the controller all information necessary to demonstrate compliance with Art. 28 obligations, and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.

Element 6: International Transfers

If the processor or any sub-processor transfers personal data outside the EEA, appropriate safeguards must be in place (SCCs, BCRs, adequacy decision, or derogation).

Element 7: Sub-Processor Chain

The processor must impose the same data protection obligations in the sub-processing contract. The initial processor remains fully liable to the controller for the sub-processor's performance (Art. 28(4)).

Element 8: Written Form

The contract must be in writing, including in electronic form (Art. 28(9)).

Show full SKILL.md (374 more words)Show less

DPA Compliance Checklist

#RequirementArt. ReferencePresent?
1Subject-matter and duration specifiedArt. 28(3)
2Nature and purpose of processing definedArt. 28(3)
3Types of personal data listedArt. 28(3)
4Categories of data subjects identifiedArt. 28(3)
5Processor acts only on documented instructionsArt. 28(3)(a)
6Notification if law requires processing beyond instructionsArt. 28(3)(a)
7Confidentiality commitment for authorised personnelArt. 28(3)(b)
8Art. 32 security measures implementedArt. 28(3)(c)
9Sub-processor authorisation mechanism specifiedArt. 28(3)(d), 28(2)
10Sub-processor change notification procedureArt. 28(4)
11Controller objection right to new sub-processorsArt. 28(2)
12Same obligations imposed on sub-processorsArt. 28(4)
13Assistance with data subject rights requestsArt. 28(3)(e)
14Assistance with Art. 32-36 obligationsArt. 28(3)(f)
15Data return or deletion upon contract endArt. 28(3)(g)
16Audit and inspection rights for controllerArt. 28(3)(h)
17Information to demonstrate complianceArt. 28(3)(h)
18International transfer safeguards (if applicable)Art. 28(3), Ch. V
19Written form (including electronic)Art. 28(9)
20Processor breach notification to controllerArt. 33(2)

2021 Standard Contractual Clauses Reference

Commission Implementing Decision (EU) 2021/914 of 4 June 2021 established new SCCs that include a Module Two (Controller to Processor) and Module Three (Processor to Processor) set. These SCCs can serve as the DPA or can supplement an existing DPA for international transfers. Key clauses in the controller-to-processor module:

  • Clause 7: Docking clause (additional parties can accede)
  • Clause 8: Data protection safeguards including Art. 28(3) requirements
  • Clause 9: Sub-processor provisions with specific or general authorisation
  • Clause 10: Data subject rights
  • Clause 13: Supervision by supervisory authority
  • Clause 14: Transfer impact assessment obligations
  • Clause 15: Obligations in case of government access requests

Practical Considerations

Negotiation Priorities
  1. Audit rights: Ensure meaningful audit rights, not just acceptance of SOC 2 reports as a substitute for on-site audits.
  2. Sub-processor transparency: Require a current list of sub-processors and timely notification (at least 30 days) before changes.
  3. Breach notification timeline: Art. 33(2) requires "without undue delay" — specify a concrete timeline (e.g., 24-48 hours).
  4. Data deletion evidence: Require written certification of deletion with a specific format and timeline.
  5. Liability: Art. 82(2) establishes processor liability for damage caused by non-compliance with processor-specific obligations or acting outside/against controller instructions.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/gdpr-dpa-art28 of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Gdpr Dpa Art28 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gdpr Dpa Art28 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gdpr Dpa Art28 this skillmukul975/Privacy-Data-Protection-Skills301—~1.9kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
Regulatory Audit Generatorzebbern/claude-code-guide4.7k1 repos~3.5kAutomated safety check: PassMIT
Reg Gap Analysisanthropics/claude-for-legal9.6k2 repos~2.6kAutomated safety check: PassApache-2.0
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Compliance Checkjosstei/maestro-orchestrate465—~237Automated safety check: PassApache-2.0

Similar skills

  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Regulatory Audit Generator

    zebbern/claude-code-guide

    Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws.

    4.7k GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Reg Gap Analysis

    anthropics/claude-for-legal

    Official

    Diff a new or changed regulation against current privacy policy and practice — outputs a gap list and a remediation plan with owners and dates.

    9.6k GitHub starsUsed in 2 repos~2.6k tokens
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Compliance Check

    josstei/maestro-orchestrate

    Run a Maestro-style regulatory compliance review for GDPR/CCPA, cookie consent, data handling, and licensing

    465 GitHub stars~237 tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Gdpr Dpa Art28

What does Gdpr Dpa Art28 do?

Guides the creation and review of data processing agreements under GDPR Article 28(3), covering all eight mandatory clauses. Gdpr Dpa Art28 is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides the creation and review of data processing agreements under GDPR Article 28(3), covering all eight mandatory clauses.

When should I use Gdpr Dpa Art28?

Gdpr Dpa Art28 fits situations like: tasks that involve Privacy and GDPR; tasks that involve Regulatory compliance.

How do I install Gdpr Dpa Art28 in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-dpa-art28 -a claude-code`. Or copy the skill folder (skills/privacy/gdpr-dpa-art28 in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/gdpr-dpa-art28 in your project. Claude Code loads it when a task matches its description.

How do I install Gdpr Dpa Art28 in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-dpa-art28 -a codex`. Or copy the skill folder (skills/privacy/gdpr-dpa-art28 in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/gdpr-dpa-art28 in your project. Codex loads it when a task matches its description.

Can I use Gdpr Dpa Art28 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill gdpr-dpa-art28 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gdpr-dpa-art28, .gemini/skills/gdpr-dpa-art28, .github/skills/gdpr-dpa-art28 and .opencode/skills/gdpr-dpa-art28 in your project.

What does Gdpr Dpa Art28 need to run?

Going by SKILL.md and its folder, Gdpr Dpa Art28 needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Gdpr Dpa Art28 access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gdpr Dpa Art28 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Gdpr Dpa Art28 use?

Gdpr Dpa Art28 is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gdpr Dpa Art28 use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Gdpr Dpa Art28?

Skills that share tags, products or a category with Gdpr Dpa Art28: Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Regulatory Audit Generator (zebbern/claude-code-guide, 4.7k stars), Reg Gap Analysis (anthropics/claude-for-legal, 9.6k stars) and Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gdpr Dpa Art28?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.