Agent skill

Group Structure Ropa

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Manages RoPA for complex multi-entity corporate groups including entity-level versus group-level records, intra-group transfer documentation, and shared processing coordination.

Apache-2.0Auto-check passedLegal & Compliance

Install Group Structure Ropa

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill group-structure-ropa -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills group-structure-ropa --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/group-structure-ropa .claude/skills/group-structure-ropa && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
group-structure-ropa
GitHub stars
297
Token cost
~3k tokens
SKILL.md length
1,285 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manages RoPA for complex multi-entity corporate groups including entity-level versus group-level records, intra-group transfer documentation, and shared processing coordination.

  • Works in 5 steps: Aggregates all entity-level RoPA entries… → Highlights intra-group data flows and… → Identifies shared processing activities… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Corporate Group Structure —…, Entity-Level vs Group-Level… and Intra-Group Data Flows, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Group Structure Ropa is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages RoPA for complex multi-entity corporate groups including entity-level versus group-level records, intra-group transfer documentation, and shared processing coordination. Activate for group RoPA, multi-entity, corporate group, intra-group transfers, subsidiary records, holding company.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the group-structure-ropa skill to manage RoPA for complex multi-entity corporate groups including entity-level versus group-level records…”
  • “/group-structure-ropa”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Aggregates all entity-level RoPA entries into a single searchable register.
  2. Highlights intra-group data flows and transfer arrangements.
  3. Identifies shared processing activities and joint controller arrangements.
  4. Supports group-level reporting to the board and supervisory authorities.
  5. Enables gap analysis across entities (e.g., one entity has incomplete records).

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Group Structure Ropa loads about 3k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 1,285 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,285 words, ~2,982 tokens.

Download SKILL.mdSave it as .claude/skills/group-structure-ropa/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
group-structure-ropa
description
Manages RoPA for complex multi-entity corporate groups including entity-level versus group-level records, intra-group transfer documentation, and shared processing coordination. Activate for group RoPA, multi-entity, corporate group, intra-group transfers, subsidiary records, holding company.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
records-of-processing
metadata.tags
gdpr, ropa, corporate-group, multi-entity, intra-group-transfers, subsidiary, holding

Group Structure RoPA

Overview

GDPR Art. 30 applies to each controller and each processor individually. In a corporate group comprising a holding company, operating subsidiaries, shared service centres, and joint ventures, each entity that independently determines purposes and means of processing must maintain its own Art. 30(1) records. Entities acting as processors for group companies must maintain Art. 30(2) records. This skill addresses the complexities of group-level RoPA management including entity hierarchy, intra-group data flows, shared processing activities, and consolidated governance.

Corporate Group Structure — Helix Biotech Solutions

Helix Biotech Holdings SE (Netherlands — Holding)
├── Helix Biotech Solutions GmbH (Germany — Primary Operating Entity)
│   ├── Controller for: own employees, clinical trials, marketing
│   └── Processor for: group shared services (see below)
├── Helix Biotech Solutions Ltd (United Kingdom — UK Subsidiary)
│   ├── Controller for: own employees, UK customer data, UK clinical sites
│   └── Joint controller with GmbH for: multi-country clinical trials
├── Helix Biotech Solutions Inc. (United States — US Subsidiary)
│   ├── Controller for: own employees, US customer data
│   └── Processor for: global pharmacovigilance data processing (under GmbH instruction)
├── Helix Shared Services B.V. (Netherlands — Shared Service Centre)
│   ├── Processor for: group-wide IT infrastructure, payroll processing
│   └── Controller for: own employees only
└── Helix Biotech Diagnostics S.A.S. (France — Acquired Entity)
    ├── Controller for: own employees, diagnostic service customers
    └── Integration pending — separate RoPA maintained

Entity-Level vs Group-Level Records

Entity-Level RoPA (Required)

Each legal entity must maintain its own RoPA containing processing activities for which it is controller or processor. This is a legal obligation that cannot be satisfied by a group-level record alone.

EntityController RoPA (Art. 30(1))Processor RoPA (Art. 30(2))
Helix Biotech Holdings SEMinimal — shareholder data, board member dataNone
Helix Biotech Solutions GmbHFull — all German processing activitiesYes — shared services provided to group
Helix Biotech Solutions LtdFull — all UK processing activitiesNone
Helix Biotech Solutions Inc.Full — all US processing activitiesYes — pharmacovigilance processing for GmbH
Helix Shared Services B.V.Minimal — own employee data onlyYes — IT, HR, and finance processing for all group entities
Helix Biotech Diagnostics S.A.S.Full — all French processing activitiesNone

In addition to entity-level records, maintain a consolidated group view that:

  1. Aggregates all entity-level RoPA entries into a single searchable register.
  2. Highlights intra-group data flows and transfer arrangements.
  3. Identifies shared processing activities and joint controller arrangements.
  4. Supports group-level reporting to the board and supervisory authorities.
  5. Enables gap analysis across entities (e.g., one entity has incomplete records).

The consolidated view is not a legal substitute for entity-level records but serves governance and oversight purposes.

Intra-Group Data Flows

Controller-to-Controller Transfers

When one group entity transfers personal data to another group entity and each determines its own purpose for the processing, this is a controller-to-controller transfer requiring:

  • Legal basis: Art. 6(1) lawful basis for the disclosure (typically Art. 6(1)(f) legitimate interest with intra-group LIA)
  • Transfer mechanism: If the receiving entity is outside the EEA, an appropriate Chapter V safeguard (SCCs, BCRs, adequacy decision)
  • RoPA documentation: Both entities must record the transfer in their respective RoPAs — the disclosing entity as a recipient under Art. 30(1)(d), the receiving entity as data source documentation

Example:

Helix Biotech Solutions GmbH (Germany) shares employee directory data with Helix Biotech Solutions Inc. (US) for internal communications.

AspectGmbH (Disclosing Controller)Inc. (Receiving Controller)
PurposeEnable employee collaboration across groupMaintain employee directory for US operations
Lawful basisArt. 6(1)(f) — legitimate interest (Recital 48: intra-group transfers)Art. 6(1)(f) — legitimate interest
RoPA fieldArt. 30(1)(d): Recipient = Helix Biotech Solutions Inc.; Art. 30(1)(e): US transferArt. 30(1)(c): Data source = Helix Biotech Solutions GmbH
Transfer mechanismEU-US Data Privacy Framework (if Inc. is DPF-listed) OR EU SCCs Module 1 (controller-to-controller)—
LIA referenceLIA-2024-DIR-001LIA-2024-DIR-002
Controller-to-Processor Transfers (Intra-Group)

When a group shared service centre processes data on behalf of another group entity, the relationship is controller-to-processor even though both entities are in the same corporate group:

  • Art. 28 DPA required: An intra-group DPA is required between the controller entity and the processor entity, even within the same group.
  • RoPA documentation: The controller entity records the shared service centre as a processor in Art. 30(1)(d). The shared service centre records the controller entity in its Art. 30(2)(a) processor records.

Example:

Helix Shared Services B.V. (Netherlands) processes payroll for all group entities.

Controller EntityDPA ReferenceProcessing CategoriesData Categories
Helix Biotech Solutions GmbHDPA-IG-2024-SSC-DE-001Payroll calculation, tax reporting, social security reportingEmployee names, tax IDs, bank accounts, salaries
Helix Biotech Solutions LtdDPA-IG-2024-SSC-UK-002Payroll calculation, HMRC reporting, pension contributionsEmployee names, NI numbers, bank accounts, salaries
Helix Biotech Solutions Inc.DPA-IG-2024-SSC-US-003Payroll calculation, IRS reporting, benefits administrationEmployee names, SSNs, bank accounts, salaries
Joint Controller Arrangements (Art. 26)

When two or more group entities jointly determine the purposes and means of processing, they are joint controllers under Art. 26:

  • Art. 26 arrangement required: Formal arrangement determining respective responsibilities.
  • RoPA documentation: Each joint controller records the arrangement in Art. 30(1)(a) with cross-reference to the Art. 26 arrangement.

Example:

Helix Biotech Solutions GmbH and Helix Biotech Solutions Ltd jointly conduct multi-country clinical trials and jointly determine the trial protocol, data collection methods, and analysis purposes.

AspectGmbHLtd
Art. 26 arrangementJCA-2024-CT-001JCA-2024-CT-001
ResponsibilitiesTrial sponsor, EMA reporting, EU site managementUK site management, MHRA reporting
Contact point for data subjectsGmbH (as designated under Art. 26(1))GmbH (as designated)
RoPA Art. 30(1)(a)Joint controller: Helix Biotech Solutions Ltd, ref: JCA-2024-CT-001Joint controller: Helix Biotech Solutions GmbH, ref: JCA-2024-CT-001
Show full SKILL.md (510 more words)Show less

Binding Corporate Rules (BCRs) and Group RoPA

If the group has approved BCRs under Art. 47, the RoPA transfer fields (Art. 30(1)(e)) should reference the BCRs as the transfer mechanism for intra-group transfers:

TransferMechanismReference
GmbH to Ltd (UK)UK adequacy decision (28 June 2021, extended)N/A (adequacy)
GmbH to Inc. (US)BCR-C ref: BCR-HELIX-2024-001 (approved by BfDI as lead SA)BCR-HELIX-2024-001
GmbH to S.A.S. (France)Intra-EEA — no transfer mechanism requiredN/A
Shared Services B.V. to Inc. (US)BCR-P ref: BCR-HELIX-2024-002 (processor BCRs)BCR-HELIX-2024-002

Group RoPA Governance Model

Centralised Governance with Local Execution
RoleScopeResponsible Entity
Group DPOOverall RoPA governance, consolidated reporting, group-level standardsHelix Biotech Holdings SE (Dr. Elena Voss)
Entity Privacy LeadEntity-level RoPA creation and maintenanceEach subsidiary
Shared Services Privacy LeadProcessor RoPA for all shared servicesHelix Shared Services B.V.
Group Privacy AnalystConsolidated view management, cross-entity gap analysisHoldings SE
Governance Workflow
  1. Entity-level creation: Each entity's privacy lead creates and maintains entity-level RoPA entries following group standards.
  2. Group template: All entities use the same RoPA template and field definitions to ensure consistency.
  3. Centralised aggregation: Entity-level records are aggregated into the group consolidated view quarterly.
  4. Cross-entity review: Group DPO reviews the consolidated view for intra-group transfer completeness, joint controller arrangement consistency, and entity-level gap identification.
  5. Board reporting: Group DPO presents consolidated RoPA metrics to the Holdings SE board annually.
Post-Acquisition Integration

When a new entity is acquired (e.g., Helix Biotech Diagnostics S.A.S.):

  1. Immediate (Day 1): Identify the acquired entity's existing RoPA and assess its format, completeness, and quality.
  2. 30 days: Conduct a gap analysis against the group RoPA template and identify intra-group data flows that will be established.
  3. 60 days: Migrate the acquired entity's RoPA to the group template format.
  4. 90 days: Establish intra-group DPAs for shared services and document intra-group transfers in both entities' RoPAs.
  5. 6 months: Full integration into the group consolidated view and ongoing governance cycle.

Common Group Structure Pitfalls

  1. Assuming a single group RoPA satisfies all entities: Each legal entity must have its own records. A group-level consolidated view does not replace entity-level obligations.

  2. Missing intra-group DPAs: The GDPR does not exempt intra-group processing from the Art. 28 DPA requirement. A holding company providing IT services to subsidiaries must have DPAs in place.

  3. Undocumented intra-group transfers: Data flows between group entities (shared directories, consolidated HR systems, group-wide analytics) are transfers that must be recorded in Art. 30(1)(d) and (e).

  4. Inconsistent entity identification: Using trade names instead of legal entity names across different entities' RoPAs creates confusion during supervisory authority inspections.

  5. Missing joint controller arrangements: When two group entities jointly determine processing purposes (e.g., a global marketing campaign managed by two subsidiaries), an Art. 26 arrangement is required but frequently overlooked within corporate groups.

  6. One-stop-shop confusion: The lead supervisory authority under Art. 56 is determined by the location of the main establishment, not by where most processing occurs. Group RoPA must clearly identify each entity's establishment and the lead SA for cross-border processing.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/group-structure-ropa of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Group Structure Ropa next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Group Structure Ropa compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Group Structure Ropa this skillmukul975/Privacy-Data-Protection-Skills297—~3kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    297 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    297 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    297 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Group Structure Ropa

What does Group Structure Ropa do?

Manages RoPA for complex multi-entity corporate groups including entity-level versus group-level records, intra-group transfer documentation, and shared processing coordination. Group Structure Ropa is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages RoPA for complex multi-entity corporate groups including entity-level versus group-level records, intra-group transfer documentation, and shared processing coordination.

When should I use Group Structure Ropa?

Group Structure Ropa fits situations like: tasks that involve Privacy and GDPR.

How do I install Group Structure Ropa in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill group-structure-ropa -a claude-code`. Or copy the skill folder (skills/privacy/group-structure-ropa in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/group-structure-ropa in your project. Claude Code loads it when a task matches its description.

How do I install Group Structure Ropa in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill group-structure-ropa -a codex`. Or copy the skill folder (skills/privacy/group-structure-ropa in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/group-structure-ropa in your project. Codex loads it when a task matches its description.

Can I use Group Structure Ropa in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill group-structure-ropa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/group-structure-ropa, .gemini/skills/group-structure-ropa, .github/skills/group-structure-ropa and .opencode/skills/group-structure-ropa in your project.

What does Group Structure Ropa need to run?

Going by SKILL.md and its folder, Group Structure Ropa needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Group Structure Ropa access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Group Structure Ropa safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Group Structure Ropa use?

Group Structure Ropa is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Group Structure Ropa use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Group Structure Ropa?

Skills that share tags, products or a category with Group Structure Ropa: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Group Structure Ropa?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.