Agent skill

Implementing Data Minimization Architecture

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Architecture patterns for GDPR Article 5(1)(c) data minimization and Article 25(1) data protection by design.

Apache-2.0Auto-check passedLegal & Compliance

Install Implementing Data Minimization Architecture

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill implementing-data-minimization-architecture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills implementing-data-minimization-architecture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/implementing-data-minimization-architecture .claude/skills/implementing-data-minimization-architecture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-data-minimization-architecture
GitHub stars
295
Token cost
~2.8k tokens
SKILL.md length
1,200 words
Files
5 (incl. scripts, references, assets)
Skills in repo
278
Repo updated
First seen
Licence
Apache-2.0

At a glance

Architecture patterns for GDPR Article 5(1)(c) data minimization and Article 25(1) data protection by design.

  • Works in 3 steps: Singling out — the ability to isolate a… → Linkability — the ability to link two… → Inference — the ability to deduce the…
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Data Minimization Architecture…, Data Minimization Assessment… and Key Regulatory References
  • Runs Python scripts from its folder

What it does

Implementing Data Minimization Architecture is an agent skill from mukul975/Privacy-Data-Protection-Skills. Architecture patterns for GDPR Article 5(1)(c) data minimization and Article 25(1) data protection by design. Covers field-level encryption, data masking, aggregation, pseudonymization per Article 4(5), and anonymization per Recital 26. Includes ENISA pseudonymization techniques and a data minimization assessment matrix.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “/implementing-data-minimization-architecture”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Singling out — the ability to isolate a record identifying an individual
  2. Linkability — the ability to link two records relating to the same individual
  3. Inference — the ability to deduce the value of an attribute from other attributes

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Data Minimization Architecture loads about 2.8k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 1,200 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,200 words, ~2,831 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-data-minimization-architecture/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
implementing-data-minimization-architecture
description
Architecture patterns for GDPR Article 5(1)(c) data minimization and Article 25(1) data protection by design. Covers field-level encryption, data masking, aggregation, pseudonymization per Article 4(5), and anonymization per Recital 26. Includes ENISA pseudonymization techniques and a data minimization assessment matrix.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-by-design
metadata.tags
data-minimization, article-25, pseudonymization, anonymization, field-level-encryption

Implementing Data Minimization Architecture

Overview

Data minimization is a core principle of the GDPR under Article 5(1)(c), requiring that personal data be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed." Article 25(1) mandates that controllers implement appropriate technical and organisational measures, such as pseudonymisation, designed to implement data-protection principles effectively and to integrate necessary safeguards into the processing.

The European Data Protection Board (EDPB) Guidelines 4/2019 on Article 25 Data Protection by Design and by Default clarify that data minimization applies across four dimensions: the amount of data collected, the extent of processing, the period of storage, and the accessibility of data. ENISA's 2019 report on pseudonymisation techniques provides the technical foundation for implementing these requirements at scale.

Data Minimization Architecture Layers

Layer 1: Collection Minimization

Reduce data at the point of ingestion before it enters backend systems.

Techniques:

TechniqueDescriptionGDPR BasisImplementation Complexity
Schema enforcementReject fields not explicitly required for the declared purposeArt. 5(1)(c), Art. 25(1)Low
Client-side filteringStrip unnecessary fields in the client SDK before transmissionArt. 5(1)(c)Medium
Progressive collectionRequest additional fields only when a specific feature is activatedArt. 5(1)(c), Recital 39Medium
Purpose-gated formsDisplay only form fields relevant to the selected service tierArt. 5(1)(b), Art. 25(2)Low

Prism Data Systems AG Implementation: Prism Data Systems AG deploys an API gateway validation layer that enforces a strict allowlist of fields per endpoint. The customer onboarding endpoint /api/v2/customers accepts only: email, display_name, country_code, and consent_references[]. Fields like date_of_birth, phone_number, and billing_address are collected only when the customer activates the billing module, implementing progressive collection tied to purpose activation.

Layer 2: Processing Minimization

Reduce the identifiability of data during computation.

Pseudonymization (Article 4(5))

Article 4(5) defines pseudonymisation as "the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures."

ENISA Pseudonymization Techniques (2019 Report):

TechniqueReversibilityCollision RiskSuitable For
Counter-based mappingReversible with lookup tableNoneCustomer IDs, transaction references
HMAC-SHA256 with secret keyReversible with keyNegligible (256-bit)Cross-system linkage where re-identification is needed
Format-preserving encryption (FF1/FF3-1)Reversible with keyNoneStructured data (credit card numbers, SSNs) preserving format constraints
Tokenization with vaultReversible with vault accessNonePayment card data (PCI DSS alignment)
Keyed hash with salt rotationComputationally irreversible after rotationLowSession-level analytics where longitudinal tracking is unnecessary

Prism Data Systems AG Implementation: Prism Data Systems AG uses HMAC-SHA256 pseudonymization for all analytics pipelines. Customer identifiers are pseudonymized at the boundary between the transactional database and the analytics data warehouse. The HMAC key is stored in a Hardware Security Module (HSM) managed by the security operations team, physically and logically separated from the analytics infrastructure per ENISA recommended controls.

Anonymization (Recital 26)

Recital 26 states that the principles of data protection should not apply to anonymous information, namely "information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable." The Article 29 Working Party Opinion 05/2014 on Anonymisation Techniques (WP216) established three risk criteria:

  1. Singling out — the ability to isolate a record identifying an individual
  2. Linkability — the ability to link two records relating to the same individual
  3. Inference — the ability to deduce the value of an attribute from other attributes

Anonymization Techniques:

TechniqueSingling OutLinkabilityInferenceData Utility
k-Anonymity (k=5)MitigatedPartially mitigatedNot mitigatedHigh
l-Diversity (l=3)MitigatedMitigatedPartially mitigatedMedium-High
t-Closeness (t=0.15)MitigatedMitigatedMitigatedMedium
Differential privacy (epsilon=1.0)MitigatedMitigatedMitigatedConfigurable
Data aggregation (min group=11)MitigatedMitigatedPartially mitigatedLow-Medium
Layer 3: Storage Minimization

Limit how much identifiable data persists at rest.

Field-Level Encryption Architecture:

                    ┌────────────────────────┐
                    │   Application Layer    │
                    │  (plaintext in memory) │
                    └──────────┬─────────────┘
                               │
                    ┌──────────▼─────────────┐
                    │  Encryption Service    │
                    │  AES-256-GCM per field │
                    │  Key: KMS / HSM        │
                    └──────────┬─────────────┘
                               │
          ┌────────────────────┼────────────────────┐
          │                    │                    │
 ┌────────▼───────┐  ┌────────▼───────┐  ┌────────▼───────┐
 │  email (enc)   │  │  name (enc)    │  │  country (clr) │
 │  DEK-email-v3  │  │  DEK-name-v3   │  │  (not PII)     │
 └────────────────┘  └────────────────┘  └────────────────┘

Each personally identifiable field is encrypted with a dedicated Data Encryption Key (DEK) wrapped by a Key Encryption Key (KEK) in AWS KMS or Azure Key Vault. This enables selective decryption: analytics queries on country never require decrypting email or name.

Prism Data Systems AG Implementation: Prism Data Systems AG classifies all database columns into four sensitivity tiers:

TierClassificationEncryptionAccess ControlExample Fields
T1Direct identifierAES-256-GCM, field-levelNamed individuals with business justificationemail, full_name, national_id
T2Quasi-identifierAES-256-GCM, field-levelRole-based, loggeddate_of_birth, postal_code, job_title
T3Sensitive attributeAES-256-GCM, field-levelPurpose-restricted, dual approvalhealth_data, financial_score
T4Non-identifyingTransport encryption (TLS 1.3)Standard RBACcountry_code, language_preference
Show full SKILL.md (440 more words)Show less
Layer 4: Access Minimization

Restrict who and what systems can access identifiable data.

Data Masking Patterns:

PatternDescriptionUse Case
Static maskingIrreversibly replace PII in non-production databasesDevelopment and QA environments
Dynamic maskingApply masking rules at query time based on the requester's roleCustomer support dashboards
On-the-fly maskingMask data in transit between microservicesInter-service API calls where full PII is unnecessary
Tokenized viewsDatabase views that return tokens instead of raw valuesReporting layers, third-party integrations

Prism Data Systems AG Implementation: Customer support agents at Prism Data Systems AG see dynamically masked data by default: m***l@example.com for email, ***-***-4892 for phone numbers. Only escalation-tier agents can request unmasked access, which requires a ticket reference, is logged in the audit trail, and auto-expires after 30 minutes.

Data Minimization Assessment Matrix

Use this matrix to evaluate each data field against minimization requirements before approving a new processing activity or system design.

Assessment CriterionQuestionScoring
NecessityIs this field required to fulfill the stated purpose?0 = No, 1 = Partially, 2 = Yes
ProportionalityCould a less identifying alternative achieve the same result?0 = Yes (use alternative), 1 = Partially, 2 = No alternative exists
Aggregation potentialCan this field be aggregated or generalized without losing required utility?0 = Fully aggregable, 1 = Partially, 2 = Must remain granular
Pseudonymization feasibilityCan this field be pseudonymized for this processing purpose?0 = Easily pseudonymized, 1 = With effort, 2 = Not feasible
Temporal scopeIs this field needed beyond the immediate transaction?0 = No (delete after use), 1 = Short retention, 2 = Long retention required
Access scopeHow many roles need access to the raw value?0 = None (mask/encrypt), 1 = Limited roles, 2 = Broad access required

Scoring interpretation:

  • 0-4: Strong candidate for elimination, aggregation, or pseudonymization
  • 5-8: Apply masking, field-level encryption, and access controls
  • 9-12: Justified retention with full technical safeguards and documentation

Prism Data Systems AG Implementation: Before any new microservice is deployed, the data architecture review board at Prism Data Systems AG requires a completed minimization assessment for every personal data field. Fields scoring below 5 must be eliminated or pseudonymized before the service passes the privacy gate in the CI/CD pipeline.

Key Regulatory References

  • GDPR Article 4(5) — Definition of pseudonymisation
  • GDPR Article 5(1)(c) — Data minimization principle
  • GDPR Article 25(1) — Data protection by design
  • GDPR Article 25(2) — Data protection by default
  • GDPR Article 32(1)(a) — Pseudonymisation and encryption as security measures
  • GDPR Recital 26 — Scope of anonymous information
  • GDPR Recital 78 — Appropriate technical and organisational measures
  • EDPB Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
  • ENISA Report: Pseudonymisation techniques and best practices (November 2019)
  • Article 29 Working Party Opinion 05/2014 on Anonymisation Techniques (WP216)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/implementing-data-minimization-architecture of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Implementing Data Minimization Architecture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Data Minimization Architecture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Data Minimization Architecture this skillmukul975/Privacy-Data-Protection-Skills295—~2.8kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    939 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    939 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 278 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    295 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    295 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    295 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed
  • Retention Schedule

    mukul975/Privacy-Data-Protection-Skills

    Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

    295 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Implementing Data Minimization Architecture

What does Implementing Data Minimization Architecture do?

Architecture patterns for GDPR Article 5(1)(c) data minimization and Article 25(1) data protection by design. Implementing Data Minimization Architecture is an agent skill from mukul975/Privacy-Data-Protection-Skills. Architecture patterns for GDPR Article 5(1)(c) data minimization and Article 25(1) data protection by design.

When should I use Implementing Data Minimization Architecture?

Implementing Data Minimization Architecture fits situations like: tasks that involve Privacy and GDPR.

How do I install Implementing Data Minimization Architecture in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill implementing-data-minimization-architecture -a claude-code`. Or copy the skill folder (skills/privacy/implementing-data-minimization-architecture in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/implementing-data-minimization-architecture in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Data Minimization Architecture in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill implementing-data-minimization-architecture -a codex`. Or copy the skill folder (skills/privacy/implementing-data-minimization-architecture in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/implementing-data-minimization-architecture in your project. Codex loads it when a task matches its description.

Can I use Implementing Data Minimization Architecture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill implementing-data-minimization-architecture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-data-minimization-architecture, .gemini/skills/implementing-data-minimization-architecture, .github/skills/implementing-data-minimization-architecture and .opencode/skills/implementing-data-minimization-architecture in your project.

What does Implementing Data Minimization Architecture need to run?

Going by SKILL.md and its folder, Implementing Data Minimization Architecture needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Data Minimization Architecture access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Data Minimization Architecture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Data Minimization Architecture use?

Implementing Data Minimization Architecture is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Data Minimization Architecture use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Data Minimization Architecture?

Skills that share tags, products or a category with Implementing Data Minimization Architecture: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Data Minimization Architecture?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.