Agent skill

Lawful Basis Assessment

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides determination of the correct lawful basis under GDPR Article 6(1)(a)-(f) for each processing activity.

Apache-2.0Auto-check passedLegal & Compliance

Install Lawful Basis Assessment

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill lawful-basis-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills lawful-basis-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/lawful-basis-assessment .claude/skills/lawful-basis-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
lawful-basis-assessment
GitHub stars
301
Token cost
~2.2k tokens
SKILL.md length
1,141 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides determination of the correct lawful basis under GDPR Article 6(1)(a)-(f) for each processing activity.

  • Works in 6 steps: Is the processing required by law? → Is the processing necessary to perform a… → Is this a life-threatening or medical… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, The Six Lawful Bases — Art. 6(1), Decision Tree for Lawful Basis… and Documentation Requirements, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Lawful Basis Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides determination of the correct lawful basis under GDPR Article 6(1)(a)-(f) for each processing activity. Includes decision tree logic for consent vs legitimate interest vs contract necessity. Activate when evaluating legal grounds for processing or reviewing lawful basis selections. Keywords: lawful basis, Article 6, consent, legitimate interest, legal obligation, contract.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the lawful-basis-assessment skill to guide determination of the correct lawful basis under GDPR Article 6(1)(a)-(f) for each processing activity”
  • “/lawful-basis-assessment”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Is the processing required by law?
  2. Is the processing necessary to perform a contract with the data subject?
  3. Is this a life-threatening or medical emergency?
  4. Is the controller a public authority performing a statutory function?
  5. Does the controller have a legitimate interest that requires this processing?
  6. Can the data subject provide valid consent?

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Lawful Basis Assessment loads about 2.2k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 101 tokens; SKILL.md has 1,141 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,141 words, ~2,208 tokens.

Download SKILL.mdSave it as .claude/skills/lawful-basis-assessment/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
lawful-basis-assessment
description
Guides determination of the correct lawful basis under GDPR Article 6(1)(a)-(f) for each processing activity. Includes decision tree logic for consent vs legitimate interest vs contract necessity. Activate when evaluating legal grounds for processing or reviewing lawful basis selections. Keywords: lawful basis, Article 6, consent, legitimate interest, legal obligation, contract.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
gdpr-compliance
metadata.tags
gdpr, lawful-basis, article-6, consent, legitimate-interest, processing-grounds

Implementing Lawful Basis Assessment

Overview

Every processing activity under GDPR must have a valid lawful basis established before processing begins. Article 6(1) provides six mutually non-exclusive bases. Selecting the wrong basis creates compliance risk, may invalidate the processing entirely, and can result in enforcement action. This skill provides a systematic methodology for evaluating and documenting the appropriate lawful basis.

The Six Lawful Bases — Art. 6(1)

The data subject has given consent to the processing of their personal data for one or more specific purposes.

Requirements per Art. 7 and Recital 32:

  • Freely given: genuine choice, no imbalance of power, no conditionality (Art. 7(4))
  • Specific: granular consent for distinct processing purposes
  • Informed: clear plain language about identity, purpose, data types, rights
  • Unambiguous: clear affirmative action (no pre-ticked boxes, no silence)
  • Withdrawable: as easy to withdraw as to give (Art. 7(3))

Best suited for: Marketing communications, cookies/tracking, research participation, sharing data with third parties for their own purposes.

Not appropriate when: There is a power imbalance (employer-employee, public authority-citizen), processing is necessary for another basis, or withdrawal would be impractical.

(b) Contract Performance

Processing is necessary for the performance of a contract to which the data subject is party, or to take steps at the data subject's request prior to entering into a contract.

Key test: Would the contract be impossible to perform without this specific processing? The processing must be objectively necessary, not merely useful or standard practice.

Best suited for: Delivering purchased goods, processing payments, providing contracted services, pre-contractual enquiries at the data subject's request.

Not appropriate when: Processing is useful but not necessary for the contract (e.g., profiling customers is not necessary to deliver their order).

Processing is necessary for compliance with a legal obligation to which the controller is subject.

Requirements:

  • The obligation must be laid down by EU or Member State law (not contractual obligations)
  • The law must be sufficiently clear about the processing required
  • The processing must be limited to what is necessary to comply

Best suited for: Tax reporting, employment law obligations, anti-money laundering checks, regulatory reporting, court orders.

(d) Vital Interests

Processing is necessary to protect the vital interests of the data subject or of another natural person.

Requirements:

  • Relates to life-or-death situations or serious medical emergencies
  • Cannot be used if another lawful basis is available (Recital 46)
  • Very narrow scope in practice

Best suited for: Emergency medical treatment for unconscious patients, disaster response, humanitarian crises.

(e) Public Task

Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Requirements:

  • Must have a basis in EU or Member State law
  • The specific task or function must be defined in law
  • Primarily applies to public authorities and bodies

Best suited for: Public administration, law enforcement, statutory functions of public bodies, public health monitoring.

(f) Legitimate Interests

Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.

Requirements (three-part test):

  1. Purpose test: Is there a legitimate interest? (commercial, societal, or individual)
  2. Necessity test: Is the processing necessary for that interest? (no less intrusive alternative)
  3. Balancing test: Do the data subject's interests override the controller's?

Best suited for: Fraud prevention, network security, direct marketing to existing customers, intra-group administrative transfers, internal analytics.

Not available to: Public authorities in the performance of their tasks (Art. 6(1) final paragraph).

Decision Tree for Lawful Basis Selection

Step 1: Is the processing required by law?
  • YES → Art. 6(1)(c) Legal Obligation. Identify the specific law and provision.
  • NO → Proceed to Step 2.
Step 2: Is the processing necessary to perform a contract with the data subject?
  • YES → Art. 6(1)(b) Contract Performance. Verify objective necessity (not just convenience).
  • NO → Proceed to Step 3.
Step 3: Is this a life-threatening or medical emergency?
  • YES → Art. 6(1)(d) Vital Interests. Document why no other basis applies.
  • NO → Proceed to Step 4.
Show full SKILL.md (465 more words)Show less
Step 4: Is the controller a public authority performing a statutory function?
  • YES → Art. 6(1)(e) Public Task. Identify the legal basis for the task.
  • NO → Proceed to Step 5.
Step 5: Does the controller have a legitimate interest that requires this processing?
  • YES → Conduct a Legitimate Interest Assessment (three-part test).
    • If the LIA concludes the controller's interest is not overridden → Art. 6(1)(f).
    • If the LIA concludes the data subject's rights prevail → Consider consent or do not process.
  • NO → Proceed to Step 6.
  • Verify: no power imbalance, genuine choice, specific purpose, can withdraw without detriment.
  • YES → Art. 6(1)(a) Consent. Implement compliant consent mechanism.
  • NO → Processing may not have a valid lawful basis. Do not proceed. Consult the DPO.

Documentation Requirements

For each processing activity, document:

  1. Processing activity name and RoPA reference: Link to the Art. 30 record.
  2. Selected lawful basis: Cite the specific Art. 6(1) paragraph.
  3. Rationale: Explain why this basis was selected and why alternatives were rejected.
  4. Necessity analysis: Demonstrate why the processing is necessary for the stated basis (not merely useful).
  5. Supporting evidence: Reference the specific law (for legal obligation), contract (for contract performance), LIA (for legitimate interest), or consent mechanism (for consent).
  6. Special category data: If Art. 9 data is involved, identify the additional Art. 9(2) condition.
  7. Criminal offence data: If Art. 10 data is involved, confirm the specific authorisation in EU/Member State law.
  8. Review date: Set the next review date (recommended: annually or upon material change).

Common Assessment Errors

  1. Defaulting to consent: Using consent when another basis is more appropriate, creating unnecessary withdrawal risk.
  2. Stretching contract performance: Claiming processing is necessary for a contract when it is merely beneficial (e.g., profiling for cross-selling is not necessary to fulfil a purchase order).
  3. Citing non-existent legal obligations: Referencing industry standards or contractual requirements as "legal obligations" when they do not constitute EU or Member State law.
  4. Ignoring the necessity test: Selecting a basis without demonstrating that the specific processing is necessary (not just the purpose).
  5. Switching bases post-hoc: Changing the lawful basis after processing has begun when the original basis fails, without valid justification.
  6. Overlooking power imbalances: Relying on employee consent for workplace processing where genuine free choice is absent.

Integration with Other GDPR Requirements

  • Transparency (Art. 13/14): The lawful basis must be communicated to data subjects in the privacy notice.
  • Data subject rights: The lawful basis determines which rights are available (e.g., right to erasure is limited where legal obligation applies; right to data portability only applies to consent and contract).
  • RoPA (Art. 30): The lawful basis should be recorded alongside each processing activity.
  • DPIA (Art. 35): High-risk processing may require a DPIA regardless of which lawful basis is selected.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/lawful-basis-assessment of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Lawful Basis Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Lawful Basis Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Lawful Basis Assessment this skillmukul975/Privacy-Data-Protection-Skills301—~2.2kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Lawful Basis Assessment

What does Lawful Basis Assessment do?

Guides determination of the correct lawful basis under GDPR Article 6(1)(a)-(f) for each processing activity. Lawful Basis Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides determination of the correct lawful basis under GDPR Article 6(1)(a)-(f) for each processing activity.

When should I use Lawful Basis Assessment?

Lawful Basis Assessment fits situations like: tasks that involve Privacy and GDPR.

How do I install Lawful Basis Assessment in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill lawful-basis-assessment -a claude-code`. Or copy the skill folder (skills/privacy/lawful-basis-assessment in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/lawful-basis-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Lawful Basis Assessment in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill lawful-basis-assessment -a codex`. Or copy the skill folder (skills/privacy/lawful-basis-assessment in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/lawful-basis-assessment in your project. Codex loads it when a task matches its description.

Can I use Lawful Basis Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill lawful-basis-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/lawful-basis-assessment, .gemini/skills/lawful-basis-assessment, .github/skills/lawful-basis-assessment and .opencode/skills/lawful-basis-assessment in your project.

What does Lawful Basis Assessment need to run?

Going by SKILL.md and its folder, Lawful Basis Assessment needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Lawful Basis Assessment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Lawful Basis Assessment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Lawful Basis Assessment use?

Lawful Basis Assessment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Lawful Basis Assessment use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.

What are the alternatives to Lawful Basis Assessment?

Skills that share tags, products or a category with Lawful Basis Assessment: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Lawful Basis Assessment?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.