HIPAA Safe Harbor Coverage Audit
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation…
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills internal-privacy-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/internal-privacy-audit .claude/skills/internal-privacy-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "internal-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/internal-privacy-audit into .claude/skills/internal-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "internal-privacy-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/internal-privacy-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills internal-privacy-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/internal-privacy-audit .agents/skills/internal-privacy-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "internal-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/internal-privacy-audit into .agents/skills/internal-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "internal-privacy-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills internal-privacy-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/internal-privacy-audit .cursor/skills/internal-privacy-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "internal-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/internal-privacy-audit into .cursor/skills/internal-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "internal-privacy-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/internal-privacy-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills internal-privacy-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/internal-privacy-audit .gemini/skills/internal-privacy-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "internal-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/internal-privacy-audit into .gemini/skills/internal-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "internal-privacy-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills internal-privacy-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/internal-privacy-audit .github/skills/internal-privacy-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "internal-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/internal-privacy-audit into .github/skills/internal-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "internal-privacy-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills internal-privacy-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/internal-privacy-audit .opencode/skills/internal-privacy-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "internal-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/internal-privacy-audit into .opencode/skills/internal-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "internal-privacy-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
internal-privacy-auditGuides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation…
Internal Privacy Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation tracking, and management reporting. Covers audit universe definition, annual audit plan, working papers, and closure verification. Keywords: internal audit, privacy audit, fieldwork, remediation, findings, audit plan.
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR and Audit readiness. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Internal Privacy Audit loads about 4.8k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 1,615 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,615 words, ~4,786 tokens.
.claude/skills/internal-privacy-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.An internal privacy audit program provides systematic, independent assurance that an organization's privacy practices conform to applicable data protection regulations, internal policies, contractual obligations, and recognized frameworks. Unlike external audits (SOC 2, ISO 27701 certification), internal privacy audits are conducted by or on behalf of the organization itself, giving management direct visibility into compliance gaps before they become regulatory findings or breaches.
The internal privacy audit function operates under the IIA (Institute of Internal Auditors) International Standards for the Professional Practice of Internal Auditing and adapts these standards to the privacy domain. At Sentinel Compliance Group, the internal privacy audit program reports to the Audit Committee of the Board of Directors, maintaining independence from the privacy operations function it audits.
The privacy audit universe represents the complete set of auditable entities, processes, and systems relevant to privacy compliance. It forms the basis for risk-based audit planning.
| Category | Auditable Areas | Example Entities |
|---|---|---|
| Regulatory Compliance | GDPR, CCPA/CPRA, LGPD, PIPA, sector-specific laws | EU processing operations, California consumer data handling, Brazilian customer data |
| Data Lifecycle | Collection, processing, storage, sharing, retention, deletion | Web forms, CRM system, data warehouse, third-party APIs, backup systems |
| Data Subject Rights | Access, rectification, erasure, portability, restriction, objection | DSAR intake process, identity verification, response workflow, automated systems |
| Third-Party Management | Processors, sub-processors, joint controllers, data sharing | Cloud hosting, analytics vendors, marketing platforms, payment processors |
| Privacy Governance | Policies, training, DPO function, privacy committee, DPIA process | Privacy policy management, training program, DPO independence, DPIA register |
| Technical Controls | Encryption, access controls, pseudonymization, logging, deletion | Database encryption, IAM configuration, log management, automated purge jobs |
| Breach Management | Detection, assessment, notification, documentation, remediation | SIEM configuration, breach assessment process, DPA notification, root cause analysis |
| Cross-Border Transfers | Transfer mechanisms, TIAs, supplementary measures | SCCs, BCRs, adequacy decisions, data localization controls |
| Consent Management | Collection, recording, withdrawal, preference management | Consent platforms, cookie banners, preference centers, consent databases |
| Records of Processing | RoPA completeness, accuracy, maintenance | Controller register, processor register, update workflow |
Each auditable area is scored on a risk matrix:
| Risk Factor | Weight | Scoring (1-5) |
|---|---|---|
| Regulatory exposure | 25% | 1 = No regulation, 5 = Multiple strict regulations with active enforcement |
| Volume of personal data | 20% | 1 = Minimal PII, 5 = Large-scale special category data |
| Prior audit findings | 15% | 1 = No findings, 5 = Unresolved critical findings |
| Organizational change | 15% | 1 = Stable, 5 = Major system/process changes |
| Third-party dependency | 10% | 1 = No third parties, 5 = Critical third-party processing |
| Complaint/incident history | 10% | 1 = No incidents, 5 = Multiple privacy incidents |
| Time since last audit | 5% | 1 = Audited this quarter, 5 = Never audited or >2 years |
Risk Score Calculation: Weighted sum of all factors (maximum 5.0)
| Risk Score | Audit Frequency |
|---|---|
| 4.0 — 5.0 | Every 6 months |
| 3.0 — 3.9 | Annual |
| 2.0 — 2.9 | Every 18 months |
| 1.0 — 1.9 | Every 24 months or as resources permit |
Sentinel Compliance Group — Privacy Audit Annual Plan 2025
Approved By: Audit Committee, December 15, 2024
Plan Owner: Chief Audit Executive
Q1 2025:
- DSAR Response Process (Risk Score: 4.3, Last Audit: Jun 2024)
- Cookie Consent Management (Risk Score: 3.8, Last Audit: Mar 2024)
Q2 2025:
- Third-Party Processor Management (Risk Score: 4.5, Last Audit: Dec 2023)
- Cross-Border Data Transfers (Risk Score: 4.1, Last Audit: Sep 2024)
Q3 2025:
- Data Retention and Deletion (Risk Score: 3.9, Last Audit: Jun 2024)
- Privacy Training Effectiveness (Risk Score: 3.2, Last Audit: Dec 2024)
Q4 2025:
- Breach Notification Process (Risk Score: 4.0, Last Audit: Mar 2024)
- Records of Processing Activities (Risk Score: 3.5, Last Audit: Sep 2024)
Reserve/Contingency (50 hours):
- Ad hoc investigations, management requests, regulatory-triggered auditsConfirm that the internal audit charter authorizes privacy audits and defines:
Document the audit scope including:
| Scope Element | Description |
|---|---|
| Objective | What the audit intends to evaluate (e.g., adequacy and effectiveness of DSAR response controls) |
| Period | The timeframe under examination (e.g., January 1 — June 30, 2025) |
| Entities | Organizational units in scope |
| Systems | IT systems and platforms in scope |
| Regulations | Applicable legal requirements |
| Standards | Applicable internal policies and external frameworks |
| Exclusions | Explicitly out-of-scope areas with justification |
Create the detailed audit program (test procedures) for each control objective:
Control Objective: DSARs are processed within regulatory timeframes
Test 1: Obtain DSAR tracking log for the audit period
Test 2: Select sample of [n] DSARs per sampling methodology
Test 3: For each sampled DSAR, verify:
a. Identity verification was completed before disclosure
b. Response was provided within 30 days (GDPR) or 45 days (CCPA)
c. Response contained all required information per Art. 15
d. Extension, if used, was communicated within initial deadline
e. Denial, if applicable, was justified and communicated with appeal rights
Test 4: Review DSAR metrics for trend analysis
Test 5: Interview DSAR coordinators on process adherenceIssue the engagement letter to the audit client (privacy operations team) containing:
Conduct an opening meeting with the audit client to:
| Technique | Application | Example |
|---|---|---|
| Document Review | Policies, procedures, records, reports | Review privacy policy against GDPR Art. 13-14 requirements |
| Interview | Process understanding, control awareness | Interview DPO on DPIA review process |
| Observation | Process walkthrough, system demonstration | Observe DSAR fulfillment from intake to response |
| Data Analysis | Population analysis, trend identification, anomaly detection | Analyze DSAR response times across the full population |
| Technical Testing | System configuration verification | Verify encryption-at-rest configuration on database |
| Sampling | Representative testing of transactions | Select 30 DSARs from population of 450 for detailed testing |
| Reperformance | Independent control execution | Submit test DSAR and verify correct handling |
Internal privacy audit sampling follows IIA Practice Guide "Audit Sampling":
Attribute Sampling (for compliance testing):
| Population Size | Expected Error Rate | 95% Confidence Sample |
|---|---|---|
| 50-100 | 0% expected | 30 |
| 101-500 | 0% expected | 40 |
| 501-1000 | 0% expected | 50 |
| 1000+ | 0% expected | 60 |
| Any | 1-5% expected | Add 10-20 to above |
Judgmental Sampling (risk-focused selection):
Every audit test must be documented in working papers containing:
| Working Paper Element | Description |
|---|---|
| Reference Number | Unique identifier linked to the audit program test step |
| Objective | What the test is designed to evaluate |
| Procedure | Detailed steps performed |
| Population | Description and size of the population tested |
| Sample | Size and selection methodology |
| Results | Factual findings for each sample item |
| Conclusion | Pass/Fail determination with reasoning |
| Evidence | Attached or cross-referenced supporting documentation |
| Preparer | Auditor name and date |
| Reviewer | Reviewer name and date |
Each finding is classified by severity:
| Severity | Criteria | Response Time |
|---|---|---|
| Critical | Systemic non-compliance with regulation; imminent risk of enforcement action, significant data breach, or harm to data subjects; complete control failure | Immediate: interim remediation within 5 business days; full remediation within 30 days |
| High | Material non-compliance; control design deficiency or widespread operating failure; significant gap between policy and practice | Remediation plan within 10 business days; full remediation within 60 days |
| Medium | Isolated non-compliance; control operating inconsistently; documentation gaps that could lead to material issues | Remediation within 90 days |
| Low | Minor documentation gaps; process improvement opportunities; control enhancements that would strengthen compliance posture | Remediation within 180 days |
| Advisory | Best practice recommendations; emerging risk observations; no current non-compliance | No required response; tracked for information |
Each finding is documented using the Condition-Criteria-Cause-Consequence-Recommendation format:
Finding ID: PA-2025-Q2-003
Title: Incomplete identity verification for DSAR fulfillment
Severity: High
Status: Open
Condition (What did we find?):
In 6 of 30 sampled DSARs (20%), the identity verification step was not
completed or documented prior to disclosing personal data to the requestor.
Affected requests: DSAR-2025-0147, DSAR-2025-0203, DSAR-2025-0289,
DSAR-2025-0312, DSAR-2025-0378, DSAR-2025-0401.
Criteria (What should be happening?):
GDPR Art. 12(6) requires controllers to verify the identity of the data
subject making the request, particularly where the controller has reasonable
doubts. Sentinel Compliance Group Privacy Procedure PR-DSAR-001 Section 4.2
requires two-factor identity verification for all DSARs before any personal
data is disclosed.
Cause (Why did it happen?):
The DSAR workflow system does not enforce a mandatory verification step before
allowing the coordinator to mark the request as "in progress." Three of the
six cases involved requests received via email rather than the self-service
portal, where the verification workflow is not automated.
Consequence (What is the risk?):
Without proper identity verification, personal data may be disclosed to
unauthorized individuals, constituting a personal data breach under Art. 4(12)
GDPR. This could result in supervisory authority enforcement action, reputational
harm, and direct harm to data subjects. The ICO fined a UK company GBP 175,000
in 2023 for disclosing personal data in response to a fraudulent DSAR.
Recommendation:
1. Implement a mandatory verification gate in the DSAR workflow system that
blocks progression until verification is completed and documented.
2. Extend automated verification to email-originated DSARs by redirecting
requestors to the self-service portal.
3. Retrain DSAR coordinators on verification requirements.
Management Response: [To be completed by management]
Remediation Owner: [To be assigned]
Target Date: [To be set]INTERNAL PRIVACY AUDIT REPORT
Report Number: PA-2025-Q2
Classification: Confidential
1. Executive Summary
- Audit objective and scope
- Overall rating (Satisfactory / Needs Improvement / Unsatisfactory)
- Summary of findings by severity
- Key themes and systemic issues
2. Audit Scope and Approach
- Detailed scope description
- Regulations and standards tested against
- Methodology (sampling, testing approach)
- Period covered
- Limitations and constraints
3. Findings and Recommendations
- Critical findings (if any)
- High findings
- Medium findings
- Low findings
- Advisory observations
4. Management Action Plans
- Agreed remediation actions per finding
- Responsible owners
- Target completion dates
5. Prior Audit Follow-Up
- Status of findings from prior audits
- Closed findings with verification evidence
- Overdue findings with escalation status
6. Appendices
- Detailed test results
- Population and sample details
- Documents reviewed
- Personnel interviewed| Rating | Criteria |
|---|---|
| Satisfactory | No critical or high findings; medium and low findings do not indicate systemic issues; controls are generally effective |
| Needs Improvement | One or more high findings OR multiple medium findings indicating a pattern; controls are partially effective but require strengthening |
| Unsatisfactory | One or more critical findings OR multiple high findings; fundamental control failures exist; immediate management attention required |
Finding Issued → Management Response (10 business days) → Remediation In Progress
→ Owner Reports Completion → Audit Verification Testing → Finding Closed OR
→ Reopened with Revised Plan| Metric | Measurement |
|---|---|
| Open Findings by Severity | Count of open findings per critical/high/medium/low |
| Overdue Findings | Count and percentage of findings past target date |
| Average Time to Remediate | Mean days from finding issuance to verified closure |
| Remediation Effectiveness | Percentage of findings closed on first attempt (not reopened) |
| Recurrence Rate | Percentage of findings that reappear in subsequent audits |
| Condition | Escalation Level |
|---|---|
| Critical finding not addressed within 5 business days | Chief Privacy Officer and CISO |
| High finding overdue by 30+ days | Chief Audit Executive to Audit Committee |
| Medium finding overdue by 60+ days | Chief Audit Executive to management |
| Pattern of repeated findings in same area | Chief Audit Executive to Audit Committee |
| Management refuses to remediate | Chief Audit Executive to Audit Committee and Board |
Sentinel Compliance Group operates an internal privacy audit program with the following characteristics:
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/internal-privacy-audit of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Internal Privacy Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Internal Privacy Audit this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Compliance Osalirezarezvani/claude-skills | 28k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Implementing Complianceancoleman/ai-design-components | 525 | — | ~4k | Automated safety check: Pass | MIT | |
| Compliance Checklistmohitagw15856/pm-claude-skills | 1.4k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Compliance Checklist Generationseb1n/awesome-ai-agent-skills | 206 | — | ~2.5k | Automated safety check: Pass | MIT |
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
alirezarezvani/claude-skills
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
mohitagw15856/pm-claude-skills
Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.
seb1n/awesome-ai-agent-skills
Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities.
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation…. Internal Privacy Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation tracking, and management reporting.
Internal Privacy Audit fits situations like: tasks that involve Privacy and GDPR; tasks that involve Audit readiness.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a claude-code`. Or copy the skill folder (skills/privacy/internal-privacy-audit in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/internal-privacy-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a codex`. Or copy the skill folder (skills/privacy/internal-privacy-audit in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/internal-privacy-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill internal-privacy-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/internal-privacy-audit, .gemini/skills/internal-privacy-audit, .github/skills/internal-privacy-audit and .opencode/skills/internal-privacy-audit in your project.
Going by SKILL.md and its folder, Internal Privacy Audit needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Internal Privacy Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Internal Privacy Audit: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Compliance Os (alirezarezvani/claude-skills, 28k stars), Implementing Compliance (ancoleman/ai-design-components, 525 stars) and Compliance Checklist (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.