C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Guides compliance with South Korea's Personal Information Protection Act (PIPA, 개인정보 보호법).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill korea-pipa -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills korea-pipa --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/korea-pipa .claude/skills/korea-pipa && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "korea-pipa" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/korea-pipa into .claude/skills/korea-pipa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "korea-pipa", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/korea-pipaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill korea-pipa -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills korea-pipa --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/korea-pipa .agents/skills/korea-pipa && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "korea-pipa" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/korea-pipa into .agents/skills/korea-pipa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "korea-pipa", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill korea-pipa -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills korea-pipa --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/korea-pipa .cursor/skills/korea-pipa && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "korea-pipa" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/korea-pipa into .cursor/skills/korea-pipa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "korea-pipa", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/korea-pipa--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill korea-pipa -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills korea-pipa --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/korea-pipa .gemini/skills/korea-pipa && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "korea-pipa" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/korea-pipa into .gemini/skills/korea-pipa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "korea-pipa", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills korea-pipaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill korea-pipa -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/korea-pipa .github/skills/korea-pipa && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "korea-pipa" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/korea-pipa into .github/skills/korea-pipa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "korea-pipa", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill korea-pipa -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills korea-pipa --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/korea-pipa .opencode/skills/korea-pipa && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "korea-pipa" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/korea-pipa into .opencode/skills/korea-pipa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "korea-pipa", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
korea-pipaGuides compliance with South Korea's Personal Information Protection Act (PIPA, 개인정보 보호법).
Korea Pipa is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides compliance with South Korea's Personal Information Protection Act (PIPA, 개인정보 보호법). Covers pseudonymisation framework, notification requirements, PIPC enforcement, consent standards, and cross-border transfer rules under the 2023 amendments. Keywords: PIPA, Korea data protection, PIPC, pseudonymisation, consent, cross-border transfers.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Korea Pipa loads about 3.2k tokens when it runs, and up to ~6.4k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,428 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,428 words, ~3,160 tokens.
.claude/skills/korea-pipa/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.The Personal Information Protection Act (PIPA, 개인정보 보호법) is South Korea's comprehensive data protection law, originally enacted on 29 September 2011 (Act No. 10465) and significantly amended in 2020 (effective 5 August 2020) and 2023 (effective 15 September 2023). The Personal Information Protection Commission (PIPC, 개인정보보호위원회) is the independent supervisory authority with centralised enforcement jurisdiction since the 2020 amendments consolidated regulatory authority from multiple agencies.
South Korea received an adequacy decision from the European Commission on 17 December 2021, recognising PIPA as providing an adequate level of data protection for GDPR transfer purposes.
Information relating to a living individual that identifies or can identify the individual through the information alone or in combination with other information that can be easily used. Includes:
Personal information processed by partially deleting or replacing to make it impossible to identify a specific individual without the use of additional information. Pseudonymised information may be processed for statistical purposes, scientific research, and preservation of records in the public interest without consent (Art. 28-2).
| Requirement | PIPA Provision | Detail |
|---|---|---|
| Informed consent | Art. 15(2) | Must disclose: purpose, items collected, retention period, right to refuse and consequences |
| Separate consent | Art. 22(1) | Consent for processing beyond the purpose must be separated from other consent items |
| Clear distinction | Art. 22(1) | Important content must be clearly displayed (larger font, colour, bold) |
| Opt-in for marketing | Art. 22(2) | Marketing purpose collection requires separate opt-in consent |
| Refusal right | Art. 22(5) | Data handler must not refuse service due to refusal of consent for non-essential information |
| Minor consent | Art. 22(6) | For children under 14, consent from legal representative required |
Processing sensitive information requires the data subject's separate explicit consent or a specific legal basis. The consent must clearly indicate the sensitive categories being processed.
The 2023 amendments introduced additional lawful processing bases beyond consent:
| Basis | Article | Description |
|---|---|---|
| Consent | Art. 15(1)(1) | Data subject's consent obtained per Art. 22 |
| Legal obligation | Art. 15(1)(2) | Special provisions in laws or compliance with legal obligations |
| Public institution duty | Art. 15(1)(3) | Necessary for public institutions to perform statutory duties |
| Contract performance | Art. 15(1)(4) | Necessary for contract with data subject |
| Legitimate interest | Art. 15(1)(6) | Necessary for legitimate interest of the data handler, where substantially related to the purpose and within the data subject's reasonable expectations (added 2023) |
| Urgent necessity | Art. 15(1)(5) | Urgently necessary for life, body, or property of the data subject or third party |
Legitimate interest (Art. 15(1)(6)) requirements:
Pseudonymised information may be processed without consent for:
| Measure | Requirement |
|---|---|
| Separation of additional information | Additional information enabling re-identification must be stored and managed separately |
| Technical safeguards | Encryption or equivalent protection for additional information |
| Access restrictions | Designation of authorised personnel; access logging |
| Prohibition on re-identification | Prohibited from using pseudonymised information to re-identify individuals; if re-identification occurs accidentally, immediate destruction or cessation of processing required |
| Data Set | Purpose | Pseudonymisation Method | Additional Information Storage | PIPC Compliance |
|---|---|---|---|---|
| Customer shipping patterns | Statistical analysis of route optimisation | k-anonymity (k=5) with generalisation of location data | Key mapping table stored in HSM, separate from analytics environment | Compliant |
| Employee performance metrics | Industrial research on workforce productivity | Tokenisation of employee identifiers | Token-identifier mapping in isolated database with MFA access | Compliant |
| Logistics volume trends | Public interest statistical reporting | Aggregation to postal code level with suppression of groups < 10 | No additional information retained (anonymised output) | Not applicable (anonymised) |
The 2023 amendments significantly reformed cross-border transfer provisions:
| Mechanism | Article | Detail |
|---|---|---|
| Consent | Art. 28-8(1)(1) | Data subject's consent with disclosure of: recipient, destination country, transfer purpose, PI items, right to refuse and consequences |
| Contract necessity | Art. 28-8(1)(2) | Transfer necessary for contract with data subject |
| Adequacy recognition | Art. 28-8(1)(3) | Transfer to a country or international organisation recognised by the PIPC as having adequate protection |
| Standard contractual clauses | Art. 28-8(1)(4) | PIPC-approved standard contractual clauses between the parties |
| BCR equivalent | Art. 28-8(1)(4) | PIPC-approved data protection rules within a corporate group |
| PIPC certification | Art. 28-8(1)(5) | Recipient certified by a PIPC-designated certification body |
As of March 2026, the PIPC has recognised:
The data handler must notify the data subject of:
Zenith Global Enterprises Cross-Border Transfer Register:
| Transfer ID | Flow | Destination | Mechanism | Notification | Status |
|---|---|---|---|---|---|
| CBT-KR-001 | Customer data → EU HQ | Germany (EU) | Adequacy recognition | Privacy notice updated | Active |
| CBT-KR-002 | Employee data → Regional HR | Singapore | Standard contractual clauses | Employee notice provided | Active |
| CBT-KR-003 | Logistics data → APAC ops | Japan | Consent (Art. 28-8(1)(1)) | Consent collected | Active |
| CBT-KR-004 | Payment data → Treasury | United Kingdom | Adequacy recognition | Privacy notice updated | Active |
| Sanction Type | PIPA Provision | Detail |
|---|---|---|
| Corrective orders | Art. 64 | Orders to cease violations, take corrective measures, or implement safeguards |
| Administrative fines (과태료) | Art. 75 | Up to KRW 50 million for procedural violations |
| Penalty surcharges (과징금) | Art. 64-2 | Up to 3% of related revenue (increased from prior cap by 2023 amendments) |
| Criminal penalties | Art. 71-73 | Imprisonment up to 5 years or fine up to KRW 50 million for serious violations |
| Public naming | Art. 64(4) | Public disclosure of violators |
Meta Platforms (September 2022):
Kakao (2023):
Scatter Lab (2021):
| Right | Article | Response Deadline | Implementation |
|---|---|---|---|
| Right to access | Art. 35 | 10 days | Self-service portal in Korean |
| Right to correction/deletion | Art. 36 | 10 days | Correction through customer portal; deletion workflow with legal hold check |
| Right to suspension | Art. 37 | 10 days | Processing suspension within 10 days of request |
| Right to notification | Art. 34 | Without delay | Breach notification to affected individuals |
| Right to data portability | Art. 35-2 (2023) | Per PIPC regulation | Structured export (implementation timeline per PIPC guidance) |
| Right regarding automated decisions | Art. 37-2 (2023) | Per PIPC regulation | Right to explanation and refusal of automated decisions |
| Element | Requirement |
|---|---|
| Individual notification | Without delay upon discovery of breach |
| PIPC notification | Within 72 hours of discovery for breaches affecting 1,000+ individuals |
| Content | Facts of breach, items of PI leaked, countermeasures, grievance procedures |
| Large-scale breach | 10,000+ individuals: additional reporting to PIPC and public notification through the website |
| Investigation cooperation | Cooperate fully with PIPC investigation |
| Component | Detail |
|---|---|
| Internal management plan | Documented plan per Art. 29 and Enforcement Decree Art. 30 |
| Chief Privacy Officer (CPO) | Designated officer meeting PIPA qualifications (Art. 31) |
| Annual training | PIPA compliance training for all Korean employees |
| Technical safeguards | Encryption of resident registration numbers and sensitive data (Art. 24-2) |
| Data destruction | Destruction within 5 days of retention period expiry (Art. 21) |
| Privacy impact assessment | Required for public institutions; recommended for private sector for large-scale processing |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/korea-pipa of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Korea Pipa next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Korea Pipa this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Guides compliance with South Korea's Personal Information Protection Act (PIPA, 개인정보 보호법). Korea Pipa is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides compliance with South Korea's Personal Information Protection Act (PIPA, 개인정보 보호법).
Korea Pipa fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill korea-pipa -a claude-code`. Or copy the skill folder (skills/privacy/korea-pipa in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/korea-pipa in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill korea-pipa -a codex`. Or copy the skill folder (skills/privacy/korea-pipa in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/korea-pipa in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill korea-pipa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/korea-pipa, .gemini/skills/korea-pipa, .github/skills/korea-pipa and .opencode/skills/korea-pipa in your project.
Going by SKILL.md and its folder, Korea Pipa needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Korea Pipa is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Korea Pipa: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.