Agent skill

Legit Interest Vs Consent

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Decision framework for choosing between consent and legitimate interest as the lawful basis for processing.

Apache-2.0Auto-check passedLegal & Compliance

Install Legit Interest Vs Consent

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill legit-interest-vs-consent -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills legit-interest-vs-consent --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/legit-interest-vs-consent .claude/skills/legit-interest-vs-consent && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
legit-interest-vs-consent
GitHub stars
301
Token cost
~2.2k tokens
SKILL.md length
779 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Decision framework for choosing between consent and legitimate interest as the lawful basis for processing.

  • Works in 5 steps: Regulatory requirement: Specific… → Special category data: Processing… → Automated decision-making: Processing… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Decision Framework: When to…, Power Imbalance Indicators and The Three-Part Legitimate…, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Legit Interest Vs Consent is an agent skill from mukul975/Privacy-Data-Protection-Skills. Decision framework for choosing between consent and legitimate interest as the lawful basis for processing. Covers power imbalance indicators, conditionality prohibition under Article 7(4), granularity requirements, the three-part LIA test (purpose, necessity, balancing), and practical decision trees for common scenarios.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “/legit-interest-vs-consent”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Regulatory requirement: Specific legislation mandates consent (e.g., ePrivacy Directive Article 5(3) for non-essential cookies, Article 13…
  2. Special category data: Processing sensitive data under Article 9(2)(a) requires explicit consent
  3. Automated decision-making: Processing under Article 22(2)(c) requires explicit consent
  4. International transfers: Article 49(1)(a) explicit consent for transfers without adequacy/safeguards
  5. User control priority: The processing is entirely optional and the data subject should have full control

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Legit Interest Vs Consent loads about 2.2k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 87 tokens; SKILL.md has 779 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 779 words, ~2,217 tokens.

Download SKILL.mdSave it as .claude/skills/legit-interest-vs-consent/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
legit-interest-vs-consent
description
Decision framework for choosing between consent and legitimate interest as the lawful basis for processing. Covers power imbalance indicators, conditionality prohibition under Article 7(4), granularity requirements, the three-part LIA test (purpose, necessity, balancing), and practical decision trees for common scenarios.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
consent-management
metadata.tags
legitimate-interest, consent-vs-lia, lawful-basis, power-imbalance, article-6

Overview

GDPR Article 6(1) provides six lawful bases for processing. Consent (Article 6(1)(a)) and legitimate interest (Article 6(1)(f)) are the two most commonly used bases for commercial data processing. Choosing the wrong basis creates compliance risk: relying on consent when it cannot be freely given undermines validity, while relying on legitimate interest when consent is required (e.g., for electronic marketing under the ePrivacy Directive) violates sectoral law.

Decision Framework: When to Use Each Basis

  1. Regulatory requirement: Specific legislation mandates consent (e.g., ePrivacy Directive Article 5(3) for non-essential cookies, Article 13 for unsolicited electronic marketing)
  2. Special category data: Processing sensitive data under Article 9(2)(a) requires explicit consent
  3. Automated decision-making: Processing under Article 22(2)(c) requires explicit consent
  4. International transfers: Article 49(1)(a) explicit consent for transfers without adequacy/safeguards
  5. User control priority: The processing is entirely optional and the data subject should have full control
Use Legitimate Interest When:
  1. Power imbalance exists: Consent cannot be freely given (employer-employee, public authority-citizen)
  2. Processing is necessary: The processing is necessary for the controller's or third party's legitimate interest and is proportionate
  3. Reasonable expectation: The data subject would reasonably expect the processing (Recital 47)
  4. Withdrawal would be problematic: If consent withdrawal would cause operational issues (e.g., fraud prevention)
  5. No specific consent requirement: No ePrivacy or sectoral law mandates consent

Power Imbalance Indicators

Per EDPB Guidelines 05/2020 (paragraphs 13-25) and Recital 43, consent is presumed not to be freely given when a clear imbalance exists:

IndicatorExampleImplication
Employment relationshipEmployer asks employee to consent to monitoringUse LI or legal obligation, not consent
Public authorityTax authority processes taxpayer dataUse legal obligation or public task
Service dependencyOnly provider in market; user has no alternativeConsent may not be freely given
Contractual bundlingConsent required as condition of contract (Art. 7(4))Consent likely invalid
Vulnerable data subjectsChildren, elderly, patientsExtra scrutiny; consent may not be free
Significant consequenceRefusing consent leads to job loss or service terminationConsent not freely given

The Three-Part Legitimate Interest Assessment (LIA)

Per CJEU case law (C-13/16 Rigas, C-40/17 Fashion ID) and Article 29 Working Party Opinion 06/2014:

Part 1: Purpose Test

Is the interest legitimate?

  • The interest must be lawful (not in itself illegal)
  • The interest must be real and present (not speculative)
  • The interest must be sufficiently clearly articulated

CloudVault SaaS Inc. examples of legitimate interests:

  • Network and information security (Recital 49)
  • Fraud prevention and detection
  • Direct marketing to existing customers (Recital 47)
  • Internal administrative purposes within a group (Recital 48)
  • Service improvement based on aggregated usage analytics
Part 2: Necessity Test

Is the processing necessary for the legitimate interest?

  • Could the same interest be achieved with less data?
  • Could the same interest be achieved without processing personal data?
  • Is the processing proportionate to the interest pursued?
Show full SKILL.md (303 more words)Show less
Part 3: Balancing Test

Do the data subject's rights and freedoms override the legitimate interest?

FactorWeighs Toward LIWeighs Toward Data Subject
Data sensitivityNon-sensitive dataSpecial category data
Reasonable expectationProcessing expected by data subjectSurprising or unexpected processing
RelationshipExisting customer/user relationshipNo prior relationship
ImpactMinimal impact on individualSignificant consequences
SafeguardsRobust safeguards in placeNo safeguards
Data subject controlEasy opt-out availableNo opt-out mechanism
Vulnerable groupsNo vulnerable individualsChildren or vulnerable adults
Data volumeMinimal data usedExtensive profiling

Decision Tree

START: Need to establish lawful basis for processing activity
  │
  ├─► Q1: Does specific legislation require consent?
  │     (ePrivacy Art. 5(3) for cookies, Art. 13 for e-marketing,
  │      GDPR Art. 9(2)(a) for special categories, Art. 22(2)(c) for automated decisions)
  │     │
  │     ├─ YES → Use CONSENT (mandatory)
  │     │
  │     └─ NO → Continue to Q2
  │
  ├─► Q2: Is there a power imbalance between controller and data subject?
  │     (employer-employee, public authority, service dependency)
  │     │
  │     ├─ YES → Consent likely INVALID; consider LEGITIMATE INTEREST
  │     │         (or legal obligation/public task if applicable)
  │     │
  │     └─ NO → Continue to Q3
  │
  ├─► Q3: Is consent conditioned on the service?
  │     (Would refusing consent result in service denial or degradation?)
  │     │
  │     ├─ YES → Violates Art. 7(4); consent likely INVALID
  │     │         Consider LEGITIMATE INTEREST or restructure the service
  │     │
  │     └─ NO → Continue to Q4
  │
  ├─► Q4: Is consent withdrawal operationally feasible?
  │     (Can you stop processing immediately if consent is withdrawn?)
  │     │
  │     ├─ NO → LEGITIMATE INTEREST may be more appropriate
  │     │        (e.g., fraud prevention cannot stop mid-transaction)
  │     │
  │     └─ YES → Continue to Q5
  │
  ├─► Q5: Does the data subject reasonably expect this processing?
  │     │
  │     ├─ YES → Either CONSENT or LEGITIMATE INTEREST may work
  │     │         Choose based on control preference and overhead
  │     │
  │     └─ NO → CONSENT is more appropriate
  │               (unexpected processing needs explicit agreement)
  │
  └─► Q6: Final determination
        ├─ If consent: Implement full Art. 7 requirements (freely given, specific,
        │   informed, unambiguous, withdrawal as easy as giving)
        └─ If LI: Document three-part LIA, implement opt-out mechanism,
            include in privacy notice per Art. 13(1)(d)/14(2)(b)

Common Scenarios at CloudVault SaaS Inc.

ScenarioRecommended BasisReasoning
Essential cookies for session managementNot consent; exempt under ePrivacy Art. 5(3)Strictly necessary; no consent required
Analytics cookies (non-essential)ConsentePrivacy Art. 5(3) requires consent for non-essential cookies
Email marketing to existing customersLegitimate interest (soft opt-in)ePrivacy Art. 13(2) allows soft opt-in for existing customers with opt-out
Email marketing to new contactsConsentePrivacy Art. 13(1) requires prior consent for unsolicited e-marketing
Fraud detection on transactionsLegitimate interestCannot withdraw; Recital 47 recognizes fraud prevention
Sharing data with Datalytics Partners Ltd.ConsentThird-party sharing not reasonably expected; user control appropriate
Network security monitoringLegitimate interestRecital 49 explicitly recognizes network security as LI
Employee performance monitoringLegitimate interestPower imbalance makes employee consent invalid (WP29 Opinion 2/2017)

Key Regulatory References

  • GDPR Article 6(1)(a) — Consent as lawful basis
  • GDPR Article 6(1)(f) — Legitimate interest as lawful basis
  • GDPR Article 7(4) — Conditionality prohibition
  • GDPR Recitals 47, 48, 49 — Guidance on legitimate interest scenarios
  • Article 29 WP Opinion 06/2014 on Legitimate Interest (WP217)
  • EDPB Guidelines 05/2020 on Consent — Power imbalance analysis
  • CJEU C-13/16 (Rigas) — Legitimate interest balancing test
  • CJEU C-40/17 (Fashion ID) — Joint controller LI responsibility
  • ePrivacy Directive Articles 5(3) and 13 — Sector-specific consent requirements
  • WP29 Opinion 2/2017 on Data Processing at Work — Employee consent limitations

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/legit-interest-vs-consent of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Legit Interest Vs Consent next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Legit Interest Vs Consent compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Legit Interest Vs Consent this skillmukul975/Privacy-Data-Protection-Skills301—~2.2kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Legit Interest Vs Consent

What does Legit Interest Vs Consent do?

Decision framework for choosing between consent and legitimate interest as the lawful basis for processing. Legit Interest Vs Consent is an agent skill from mukul975/Privacy-Data-Protection-Skills. Decision framework for choosing between consent and legitimate interest as the lawful basis for processing.

When should I use Legit Interest Vs Consent?

Legit Interest Vs Consent fits situations like: tasks that involve Privacy and GDPR.

How do I install Legit Interest Vs Consent in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill legit-interest-vs-consent -a claude-code`. Or copy the skill folder (skills/privacy/legit-interest-vs-consent in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/legit-interest-vs-consent in your project. Claude Code loads it when a task matches its description.

How do I install Legit Interest Vs Consent in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill legit-interest-vs-consent -a codex`. Or copy the skill folder (skills/privacy/legit-interest-vs-consent in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/legit-interest-vs-consent in your project. Codex loads it when a task matches its description.

Can I use Legit Interest Vs Consent in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill legit-interest-vs-consent -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/legit-interest-vs-consent, .gemini/skills/legit-interest-vs-consent, .github/skills/legit-interest-vs-consent and .opencode/skills/legit-interest-vs-consent in your project.

What does Legit Interest Vs Consent need to run?

Going by SKILL.md and its folder, Legit Interest Vs Consent needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Legit Interest Vs Consent access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Legit Interest Vs Consent safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Legit Interest Vs Consent use?

Legit Interest Vs Consent is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Legit Interest Vs Consent use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Legit Interest Vs Consent?

Skills that share tags, products or a category with Legit Interest Vs Consent: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Legit Interest Vs Consent?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.