Agent skill

Internal Privacy Audit

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation…

Apache-2.0Auto-check passedLegal & Compliance

Install Internal Privacy Audit

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills internal-privacy-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/internal-privacy-audit .claude/skills/internal-privacy-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
internal-privacy-audit
GitHub stars
301
Token cost
~4.8k tokens
SKILL.md length
1,615 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation…

  • Works in 5 steps: Planning and Scoping (1-2 Weeks) → Fieldwork (2-4 Weeks) → Finding Classification and Reporting… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Audit Universe Definition, Annual Audit Plan and Audit Execution Phases, plus 1 more section
  • Runs Python scripts from its folder

What it does

Internal Privacy Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation tracking, and management reporting. Covers audit universe definition, annual audit plan, working papers, and closure verification. Keywords: internal audit, privacy audit, fieldwork, remediation, findings, audit plan.

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Audit readiness. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Audit readiness

Example prompts

  • “Use the internal-privacy-audit skill to guide internal privacy audit program design and execution including risk-based audit planning, scope…”
  • “/internal-privacy-audit”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Planning and Scoping (1-2 Weeks)
  2. Fieldwork (2-4 Weeks)
  3. Finding Classification and Reporting (1-2 Weeks)
  4. Remediation Tracking (Ongoing)
  5. Management Reporting (Quarterly)

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Internal Privacy Audit loads about 4.8k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 1,615 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,615 words, ~4,786 tokens.

Download SKILL.mdSave it as .claude/skills/internal-privacy-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
internal-privacy-audit
description
Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation tracking, and management reporting. Covers audit universe definition, annual audit plan, working papers, and closure verification. Keywords: internal audit, privacy audit, fieldwork, remediation, findings, audit plan.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-audit-certification
metadata.tags
internal-audit, privacy-audit, fieldwork, remediation, audit-plan, findings

Internal Privacy Audit Program

Overview

An internal privacy audit program provides systematic, independent assurance that an organization's privacy practices conform to applicable data protection regulations, internal policies, contractual obligations, and recognized frameworks. Unlike external audits (SOC 2, ISO 27701 certification), internal privacy audits are conducted by or on behalf of the organization itself, giving management direct visibility into compliance gaps before they become regulatory findings or breaches.

The internal privacy audit function operates under the IIA (Institute of Internal Auditors) International Standards for the Professional Practice of Internal Auditing and adapts these standards to the privacy domain. At Sentinel Compliance Group, the internal privacy audit program reports to the Audit Committee of the Board of Directors, maintaining independence from the privacy operations function it audits.

Audit Universe Definition

The privacy audit universe represents the complete set of auditable entities, processes, and systems relevant to privacy compliance. It forms the basis for risk-based audit planning.

Privacy Audit Universe Categories
CategoryAuditable AreasExample Entities
Regulatory ComplianceGDPR, CCPA/CPRA, LGPD, PIPA, sector-specific lawsEU processing operations, California consumer data handling, Brazilian customer data
Data LifecycleCollection, processing, storage, sharing, retention, deletionWeb forms, CRM system, data warehouse, third-party APIs, backup systems
Data Subject RightsAccess, rectification, erasure, portability, restriction, objectionDSAR intake process, identity verification, response workflow, automated systems
Third-Party ManagementProcessors, sub-processors, joint controllers, data sharingCloud hosting, analytics vendors, marketing platforms, payment processors
Privacy GovernancePolicies, training, DPO function, privacy committee, DPIA processPrivacy policy management, training program, DPO independence, DPIA register
Technical ControlsEncryption, access controls, pseudonymization, logging, deletionDatabase encryption, IAM configuration, log management, automated purge jobs
Breach ManagementDetection, assessment, notification, documentation, remediationSIEM configuration, breach assessment process, DPA notification, root cause analysis
Cross-Border TransfersTransfer mechanisms, TIAs, supplementary measuresSCCs, BCRs, adequacy decisions, data localization controls
Consent ManagementCollection, recording, withdrawal, preference managementConsent platforms, cookie banners, preference centers, consent databases
Records of ProcessingRoPA completeness, accuracy, maintenanceController register, processor register, update workflow
Risk-Based Prioritization

Each auditable area is scored on a risk matrix:

Risk FactorWeightScoring (1-5)
Regulatory exposure25%1 = No regulation, 5 = Multiple strict regulations with active enforcement
Volume of personal data20%1 = Minimal PII, 5 = Large-scale special category data
Prior audit findings15%1 = No findings, 5 = Unresolved critical findings
Organizational change15%1 = Stable, 5 = Major system/process changes
Third-party dependency10%1 = No third parties, 5 = Critical third-party processing
Complaint/incident history10%1 = No incidents, 5 = Multiple privacy incidents
Time since last audit5%1 = Audited this quarter, 5 = Never audited or >2 years

Risk Score Calculation: Weighted sum of all factors (maximum 5.0)

Risk ScoreAudit Frequency
4.0 — 5.0Every 6 months
3.0 — 3.9Annual
2.0 — 2.9Every 18 months
1.0 — 1.9Every 24 months or as resources permit

Annual Audit Plan

Plan Development Process
  1. Update Audit Universe (Q4 of preceding year): Review the audit universe for new systems, regulations, processing activities, and organizational changes
  2. Conduct Risk Assessment (Q4): Score each auditable area using the risk matrix above
  3. Allocate Resources (Q4): Determine available audit hours based on team size and skill sets
  4. Draft Annual Plan (Q4): Schedule audits by quarter, balancing risk priority with resource availability and organizational calendar constraints
  5. Management Approval (Q4): Present the annual audit plan to the Audit Committee for approval
  6. Quarterly Review (each quarter): Adjust the plan based on emerging risks, regulatory changes, or management requests
Annual Plan Template
Sentinel Compliance Group — Privacy Audit Annual Plan 2025

Approved By: Audit Committee, December 15, 2024
Plan Owner: Chief Audit Executive

Q1 2025:
  - DSAR Response Process (Risk Score: 4.3, Last Audit: Jun 2024)
  - Cookie Consent Management (Risk Score: 3.8, Last Audit: Mar 2024)

Q2 2025:
  - Third-Party Processor Management (Risk Score: 4.5, Last Audit: Dec 2023)
  - Cross-Border Data Transfers (Risk Score: 4.1, Last Audit: Sep 2024)

Q3 2025:
  - Data Retention and Deletion (Risk Score: 3.9, Last Audit: Jun 2024)
  - Privacy Training Effectiveness (Risk Score: 3.2, Last Audit: Dec 2024)

Q4 2025:
  - Breach Notification Process (Risk Score: 4.0, Last Audit: Mar 2024)
  - Records of Processing Activities (Risk Score: 3.5, Last Audit: Sep 2024)

Reserve/Contingency (50 hours):
  - Ad hoc investigations, management requests, regulatory-triggered audits

Audit Execution Phases

Phase 1: Planning and Scoping (1-2 Weeks)
1.1 Audit Charter Confirmation

Confirm that the internal audit charter authorizes privacy audits and defines:

  • Audit authority and independence
  • Access to records, personnel, and systems
  • Reporting relationships
  • Confidentiality obligations of audit staff
1.2 Preliminary Research
  • Review applicable regulations and recent enforcement actions
  • Review prior audit reports and outstanding findings
  • Review recent privacy incidents, complaints, and DSAR metrics
  • Review organizational changes affecting the audit scope
  • Review regulatory guidance and supervisory authority publications
1.3 Scope Definition

Document the audit scope including:

Scope ElementDescription
ObjectiveWhat the audit intends to evaluate (e.g., adequacy and effectiveness of DSAR response controls)
PeriodThe timeframe under examination (e.g., January 1 — June 30, 2025)
EntitiesOrganizational units in scope
SystemsIT systems and platforms in scope
RegulationsApplicable legal requirements
StandardsApplicable internal policies and external frameworks
ExclusionsExplicitly out-of-scope areas with justification
1.4 Audit Program Development

Create the detailed audit program (test procedures) for each control objective:

Control Objective: DSARs are processed within regulatory timeframes
  Test 1: Obtain DSAR tracking log for the audit period
  Test 2: Select sample of [n] DSARs per sampling methodology
  Test 3: For each sampled DSAR, verify:
    a. Identity verification was completed before disclosure
    b. Response was provided within 30 days (GDPR) or 45 days (CCPA)
    c. Response contained all required information per Art. 15
    d. Extension, if used, was communicated within initial deadline
    e. Denial, if applicable, was justified and communicated with appeal rights
  Test 4: Review DSAR metrics for trend analysis
  Test 5: Interview DSAR coordinators on process adherence
1.5 Engagement Letter

Issue the engagement letter to the audit client (privacy operations team) containing:

  • Audit objective and scope
  • Audit period
  • Expected fieldwork dates
  • Information and access requirements
  • Key contacts
  • Preliminary meeting schedule
Phase 2: Fieldwork (2-4 Weeks)
2.1 Opening Meeting

Conduct an opening meeting with the audit client to:

  • Confirm scope and timing
  • Identify key contacts for each area
  • Discuss logistics (room access, system access, document sharing)
  • Address any concerns or constraints
2.2 Evidence Gathering Techniques
TechniqueApplicationExample
Document ReviewPolicies, procedures, records, reportsReview privacy policy against GDPR Art. 13-14 requirements
InterviewProcess understanding, control awarenessInterview DPO on DPIA review process
ObservationProcess walkthrough, system demonstrationObserve DSAR fulfillment from intake to response
Data AnalysisPopulation analysis, trend identification, anomaly detectionAnalyze DSAR response times across the full population
Technical TestingSystem configuration verificationVerify encryption-at-rest configuration on database
SamplingRepresentative testing of transactionsSelect 30 DSARs from population of 450 for detailed testing
ReperformanceIndependent control executionSubmit test DSAR and verify correct handling
2.3 Sampling Methodology

Internal privacy audit sampling follows IIA Practice Guide "Audit Sampling":

Attribute Sampling (for compliance testing):

Population SizeExpected Error Rate95% Confidence Sample
50-1000% expected30
101-5000% expected40
501-10000% expected50
1000+0% expected60
Any1-5% expectedAdd 10-20 to above

Judgmental Sampling (risk-focused selection):

  • High-value transactions (DSARs involving sensitive data)
  • Edge cases (DSARs with extensions, partial denials, cross-border elements)
  • Time-based distribution (ensure coverage across the entire audit period)
  • New process implementation (overweight periods after process changes)
Show full SKILL.md (627 more words)Show less
2.4 Working Paper Standards

Every audit test must be documented in working papers containing:

Working Paper ElementDescription
Reference NumberUnique identifier linked to the audit program test step
ObjectiveWhat the test is designed to evaluate
ProcedureDetailed steps performed
PopulationDescription and size of the population tested
SampleSize and selection methodology
ResultsFactual findings for each sample item
ConclusionPass/Fail determination with reasoning
EvidenceAttached or cross-referenced supporting documentation
PreparerAuditor name and date
ReviewerReviewer name and date
Phase 3: Finding Classification and Reporting (1-2 Weeks)
3.1 Finding Classification

Each finding is classified by severity:

SeverityCriteriaResponse Time
CriticalSystemic non-compliance with regulation; imminent risk of enforcement action, significant data breach, or harm to data subjects; complete control failureImmediate: interim remediation within 5 business days; full remediation within 30 days
HighMaterial non-compliance; control design deficiency or widespread operating failure; significant gap between policy and practiceRemediation plan within 10 business days; full remediation within 60 days
MediumIsolated non-compliance; control operating inconsistently; documentation gaps that could lead to material issuesRemediation within 90 days
LowMinor documentation gaps; process improvement opportunities; control enhancements that would strengthen compliance postureRemediation within 180 days
AdvisoryBest practice recommendations; emerging risk observations; no current non-complianceNo required response; tracked for information
3.2 Finding Structure

Each finding is documented using the Condition-Criteria-Cause-Consequence-Recommendation format:

Finding ID: PA-2025-Q2-003
Title: Incomplete identity verification for DSAR fulfillment
Severity: High
Status: Open

Condition (What did we find?):
  In 6 of 30 sampled DSARs (20%), the identity verification step was not
  completed or documented prior to disclosing personal data to the requestor.
  Affected requests: DSAR-2025-0147, DSAR-2025-0203, DSAR-2025-0289,
  DSAR-2025-0312, DSAR-2025-0378, DSAR-2025-0401.

Criteria (What should be happening?):
  GDPR Art. 12(6) requires controllers to verify the identity of the data
  subject making the request, particularly where the controller has reasonable
  doubts. Sentinel Compliance Group Privacy Procedure PR-DSAR-001 Section 4.2
  requires two-factor identity verification for all DSARs before any personal
  data is disclosed.

Cause (Why did it happen?):
  The DSAR workflow system does not enforce a mandatory verification step before
  allowing the coordinator to mark the request as "in progress." Three of the
  six cases involved requests received via email rather than the self-service
  portal, where the verification workflow is not automated.

Consequence (What is the risk?):
  Without proper identity verification, personal data may be disclosed to
  unauthorized individuals, constituting a personal data breach under Art. 4(12)
  GDPR. This could result in supervisory authority enforcement action, reputational
  harm, and direct harm to data subjects. The ICO fined a UK company GBP 175,000
  in 2023 for disclosing personal data in response to a fraudulent DSAR.

Recommendation:
  1. Implement a mandatory verification gate in the DSAR workflow system that
     blocks progression until verification is completed and documented.
  2. Extend automated verification to email-originated DSARs by redirecting
     requestors to the self-service portal.
  3. Retrain DSAR coordinators on verification requirements.

Management Response: [To be completed by management]
Remediation Owner: [To be assigned]
Target Date: [To be set]
3.3 Audit Report Structure
INTERNAL PRIVACY AUDIT REPORT
Report Number: PA-2025-Q2
Classification: Confidential

1. Executive Summary
   - Audit objective and scope
   - Overall rating (Satisfactory / Needs Improvement / Unsatisfactory)
   - Summary of findings by severity
   - Key themes and systemic issues

2. Audit Scope and Approach
   - Detailed scope description
   - Regulations and standards tested against
   - Methodology (sampling, testing approach)
   - Period covered
   - Limitations and constraints

3. Findings and Recommendations
   - Critical findings (if any)
   - High findings
   - Medium findings
   - Low findings
   - Advisory observations

4. Management Action Plans
   - Agreed remediation actions per finding
   - Responsible owners
   - Target completion dates

5. Prior Audit Follow-Up
   - Status of findings from prior audits
   - Closed findings with verification evidence
   - Overdue findings with escalation status

6. Appendices
   - Detailed test results
   - Population and sample details
   - Documents reviewed
   - Personnel interviewed
3.4 Overall Audit Rating
RatingCriteria
SatisfactoryNo critical or high findings; medium and low findings do not indicate systemic issues; controls are generally effective
Needs ImprovementOne or more high findings OR multiple medium findings indicating a pattern; controls are partially effective but require strengthening
UnsatisfactoryOne or more critical findings OR multiple high findings; fundamental control failures exist; immediate management attention required
Phase 4: Remediation Tracking (Ongoing)
4.1 Remediation Lifecycle
Finding Issued → Management Response (10 business days) → Remediation In Progress
→ Owner Reports Completion → Audit Verification Testing → Finding Closed OR
→ Reopened with Revised Plan
4.2 Tracking Dashboard
MetricMeasurement
Open Findings by SeverityCount of open findings per critical/high/medium/low
Overdue FindingsCount and percentage of findings past target date
Average Time to RemediateMean days from finding issuance to verified closure
Remediation EffectivenessPercentage of findings closed on first attempt (not reopened)
Recurrence RatePercentage of findings that reappear in subsequent audits
4.3 Escalation Protocol
ConditionEscalation Level
Critical finding not addressed within 5 business daysChief Privacy Officer and CISO
High finding overdue by 30+ daysChief Audit Executive to Audit Committee
Medium finding overdue by 60+ daysChief Audit Executive to management
Pattern of repeated findings in same areaChief Audit Executive to Audit Committee
Management refuses to remediateChief Audit Executive to Audit Committee and Board
Phase 5: Management Reporting (Quarterly)
5.1 Quarterly Privacy Audit Report to Audit Committee
  • Summary of audits completed in the quarter
  • Summary of findings by severity and theme
  • Remediation progress dashboard
  • Emerging privacy risks identified
  • Annual audit plan status and any proposed adjustments
  • Resource utilization and any capacity constraints
5.2 Annual Privacy Audit Summary
  • All audits completed during the year
  • Trend analysis of findings across the year
  • Assessment of the organization's overall privacy posture
  • Comparison to prior year
  • Recommendations for the following year's audit plan
  • Lessons learned and methodology improvements

Sentinel Compliance Group Internal Privacy Audit Program

Sentinel Compliance Group operates an internal privacy audit program with the following characteristics:

  • Team: Two dedicated privacy auditors plus one co-sourced external privacy audit specialist
  • Annual Audit Hours: 1,200 hours allocated to privacy audits
  • Audits Per Year: 8-10 privacy audits plus continuous monitoring activities
  • Reporting Line: Chief Audit Executive reports to the Audit Committee; privacy audit results shared with the DPO
  • Tools: AuditBoard for working papers and finding management; ServiceNow for remediation tracking
  • 2024 Results: 9 audits completed, 47 findings issued (2 critical, 8 high, 22 medium, 15 low), 89% remediation rate within target dates, overall privacy posture rated "Needs Improvement" trending toward "Satisfactory"

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/internal-privacy-audit of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Internal Privacy Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Internal Privacy Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Internal Privacy Audit this skillmukul975/Privacy-Data-Protection-Skills301—~4.8kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Implementing Complianceancoleman/ai-design-components525—~4kAutomated safety check: PassMIT
Compliance Checklistmohitagw15856/pm-claude-skills1.4k—~1.2kAutomated safety check: PassMIT
Compliance Checklist Generationseb1n/awesome-ai-agent-skills206—~2.5kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance Checklist

    mohitagw15856/pm-claude-skills

    Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Compliance Checklist Generation

    seb1n/awesome-ai-agent-skills

    Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Internal Privacy Audit

What does Internal Privacy Audit do?

Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation…. Internal Privacy Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation tracking, and management reporting.

When should I use Internal Privacy Audit?

Internal Privacy Audit fits situations like: tasks that involve Privacy and GDPR; tasks that involve Audit readiness.

How do I install Internal Privacy Audit in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a claude-code`. Or copy the skill folder (skills/privacy/internal-privacy-audit in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/internal-privacy-audit in your project. Claude Code loads it when a task matches its description.

How do I install Internal Privacy Audit in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a codex`. Or copy the skill folder (skills/privacy/internal-privacy-audit in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/internal-privacy-audit in your project. Codex loads it when a task matches its description.

Can I use Internal Privacy Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/internal-privacy-audit, .gemini/skills/internal-privacy-audit, .github/skills/internal-privacy-audit and .opencode/skills/internal-privacy-audit in your project.

What does Internal Privacy Audit need to run?

Going by SKILL.md and its folder, Internal Privacy Audit needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Internal Privacy Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Internal Privacy Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Internal Privacy Audit use?

Internal Privacy Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Internal Privacy Audit use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Internal Privacy Audit?

Skills that share tags, products or a category with Internal Privacy Audit: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Compliance Os (alirezarezvani/claude-skills, 28k stars), Implementing Compliance (ancoleman/ai-design-components, 525 stars) and Compliance Checklist (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Internal Privacy Audit?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.