Tech Contract Negotiation Patrick Munro
lawve-ai/awesome-legal-skills
Systematic contract negotiation strategies for technology services agreements with German/EU law specificity.
Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills new-tech-pia --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/new-tech-pia .claude/skills/new-tech-pia && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "new-tech-pia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/new-tech-pia into .claude/skills/new-tech-pia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "new-tech-pia", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/new-tech-piaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills new-tech-pia --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/new-tech-pia .agents/skills/new-tech-pia && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "new-tech-pia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/new-tech-pia into .agents/skills/new-tech-pia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "new-tech-pia", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills new-tech-pia --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/new-tech-pia .cursor/skills/new-tech-pia && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "new-tech-pia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/new-tech-pia into .cursor/skills/new-tech-pia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "new-tech-pia", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/new-tech-pia--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills new-tech-pia --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/new-tech-pia .gemini/skills/new-tech-pia && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "new-tech-pia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/new-tech-pia into .gemini/skills/new-tech-pia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "new-tech-pia", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills new-tech-piaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/new-tech-pia .github/skills/new-tech-pia && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "new-tech-pia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/new-tech-pia into .github/skills/new-tech-pia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "new-tech-pia", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills new-tech-pia --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/new-tech-pia .opencode/skills/new-tech-pia && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "new-tech-pia" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/new-tech-pia into .opencode/skills/new-tech-pia/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "new-tech-pia", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
new-tech-piaGuides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins.
New Tech Pia is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins. Covers risk identification methodology, proportionality assessment, and technology-specific privacy challenges. Activate when evaluating new technology adoption, innovation projects, or emerging tech procurement. Keywords: PIA, emerging technology, IoT, blockchain, AR/VR, quantum computing, digital twins, innovation privacy.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Research & Science, covering Privacy and GDPR, Quantum computing and Vendor and procurement management. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
New Tech Pia loads about 3.3k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 118 tokens; SKILL.md has 1,498 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,498 words, ~3,300 tokens.
.claude/skills/new-tech-pia/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Article 35(1) of the GDPR explicitly references new technologies as a factor increasing the likelihood of high risk to data subjects' rights and freedoms. The EDPB in WP248rev.01 identifies innovative use of technology as one of nine criteria triggering a DPIA. This skill provides a structured PIA methodology for emerging technologies where the privacy implications are not yet fully understood, including Internet of Things (IoT), blockchain and distributed ledger technologies, augmented and virtual reality (AR/VR), quantum computing, digital twins, brain-computer interfaces, and ambient computing.
| Risk Area | Description | Privacy Impact |
|---|---|---|
| Pervasive data collection | IoT devices continuously collect environmental and behavioural data, often without visible indicators | Data subjects may be unaware of the scope of data collection; transparency obligations under Art. 13-14 are difficult to fulfil on devices without screens |
| Data minimisation challenges | Sensors often collect more data than needed for the immediate purpose to enable future analytics | Violation of Art. 5(1)(c) data minimisation; purpose creep through accumulated data |
| Device-to-device communication | IoT ecosystems share data between devices without user awareness | Unexpected recipients; difficulty identifying all processors and sub-processors |
| Insecure by default | Many IoT devices ship with default credentials, unencrypted communications, and no update mechanism | Art. 25 data protection by design and Art. 32 security of processing obligations not met |
| Location and behavioural tracking | Connected devices reveal location patterns, daily routines, and behavioural habits | Systematic monitoring (WP248 C3); profiling risk (WP248 C1) |
| Cross-device correlation | Data from multiple IoT devices can be combined to create comprehensive behavioural profiles | Matching or combining datasets (WP248 C6); disproportionate surveillance |
EDPB Guidelines 02/2023 on IoT and Wearable Devices: Emphasized that IoT devices must implement data protection by design, provide clear privacy notices (adapted to device constraints), and enable genuine consent mechanisms.
| Risk Area | Description | Privacy Impact |
|---|---|---|
| Immutability vs right to erasure | Blockchain's append-only nature conflicts with Art. 17 right to erasure | Technical inability to delete personal data recorded on-chain |
| Transparency of transactions | Public blockchains expose transaction data to all participants | Personal data potentially accessible to unlimited recipients |
| Pseudonymity not anonymity | Blockchain addresses are pseudonymous but can be linked to real identities through transaction analysis | Re-identification risk; Art. 4(5) pseudonymisation does not equal anonymisation |
| Controller identification | Decentralised governance makes it difficult to identify the data controller | Art. 26 joint controller arrangements may be needed; accountability unclear |
| Cross-border by design | Distributed ledger nodes are typically located across multiple jurisdictions | Chapter V international transfer obligations triggered |
| Smart contract automation | Smart contracts execute automatically without human intervention | Art. 22 automated decision-making implications when smart contracts affect individuals |
CNIL Blockchain Guidance (2018): Recommended storing personal data off-chain with only hashes on-chain; using commitment schemes; designating participants who decide to use blockchain as controllers.
| Risk Area | Description | Privacy Impact |
|---|---|---|
| Biometric data collection | Eye tracking, facial expressions, body movements, voice patterns | Art. 9 special category data (biometric data for identification); Art. 35(3)(b) trigger |
| Spatial mapping | AR/VR devices scan and map physical environments including private spaces | Collection of data about third parties present in the environment without their consent |
| Behavioural profiling | Gaze tracking reveals interests, attention patterns, and cognitive state | Highly personal data; evaluation and scoring (WP248 C1) |
| Immersive manipulation | VR environments can influence behaviour through environmental design | Art. 5(1)(a) fairness; potential for subliminal manipulation |
| Persistent identity | Avatar and behavioural biometrics create persistent identifiable profiles | Long-term tracking across virtual environments |
| Child safety | Minors using VR platforms face enhanced risks | Vulnerable data subjects (WP248 C7); Art. 8 child consent requirements |
| Risk Area | Description | Privacy Impact |
|---|---|---|
| Cryptographic vulnerability | Quantum computers may break current encryption standards (RSA, ECC) | Art. 32 security measures based on current encryption become insufficient |
| Retroactive decryption | Encrypted data harvested today can be decrypted when quantum computers mature (harvest now, decrypt later) | Data currently protected may become exposed; long-term confidentiality compromised |
| Enhanced data analytics | Quantum machine learning can process data at scales impossible for classical computers | New forms of profiling and inference; privacy-preserving techniques may be defeated |
| Post-quantum migration | Transitioning to quantum-resistant cryptography requires significant infrastructure changes | Interim vulnerability period during migration |
ENISA Post-Quantum Cryptography Report (2024): Recommended organisations begin quantum risk assessment and plan migration to NIST-standardised post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA).
| Risk Area | Description | Privacy Impact |
|---|---|---|
| Comprehensive data aggregation | Digital twins aggregate data from multiple sources to create a virtual replica | Matching or combining datasets (WP248 C6); comprehensive profiling |
| Predictive modelling of individuals | Digital twins of patients or employees predict future states and behaviours | Evaluation and scoring (WP248 C1); Art. 22 implications for predictions affecting individuals |
| Continuous synchronisation | Real-time data feeds maintain the digital twin's accuracy | Systematic monitoring (WP248 C3); proportionality concerns |
| Blurred anonymisation boundary | Even without direct identifiers, a sufficiently detailed digital twin may be re-identifiable | Pseudonymisation vs anonymisation assessment required |
For each data processing element of the technology:
| Assessment Question | Analysis Required |
|---|---|
| Is this processing necessary for the stated purpose? | Document why the technology cannot achieve its purpose without this data |
| Could the purpose be achieved with less data? | Evaluate data minimisation alternatives (aggregation, sampling, synthetic data) |
| Could the purpose be achieved with less identifying data? | Evaluate anonymisation, pseudonymisation, and differential privacy options |
| Could the purpose be achieved with a less invasive technology? | Compare the proposed technology against established alternatives |
| Are the benefits proportionate to the privacy intrusion? | Balancing test: public interest vs individual privacy impact |
| Have data subjects been consulted on the acceptability of the intrusion? | Art. 35(9) data subject views; user acceptance research |
| Principle | Implementation for Emerging Tech |
|---|---|
| Proactive not reactive | Conduct PIA before technology deployment, not after incidents |
| Privacy as default | Technology must ship with privacy-protective defaults; opt-in for additional data collection |
| Privacy embedded in design | Privacy requirements must be part of the technology specification, not bolt-on |
| Full functionality | Privacy protections should not degrade the technology's core functionality |
| End-to-end security | Data protection from collection through deletion, including inter-device communication |
| Visibility and transparency | Clear indicators when technology is collecting data; accessible privacy notices |
| Respect for user privacy | User-centric design; genuine choice and control over personal data |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/new-tech-pia of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
New Tech Pia next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| New Tech Pia this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Tech Contract Negotiation Patrick Munrolawve-ai/awesome-legal-skills | 847 | — | ~4.9k | Automated safety check: Pass | AGPL-3.0 | |
| Operational Designmagnus919/agent-skills | 115 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Regulatory Deal Card Generator Patrick Munrolawve-ai/awesome-legal-skills | 847 | — | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| AI Governance Reviewer Carl Ditzlerlawve-ai/awesome-legal-skills | 847 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | |
| Operational Designmagnus919/hermes-profiles | 289 | — | ~1.3k | Automated safety check: Pass | MIT |
lawve-ai/awesome-legal-skills
Systematic contract negotiation strategies for technology services agreements with German/EU law specificity.
magnus919/agent-skills
Design and improve operational processes, controls, metrics, vendors, and scaling models through bounded pilots and evidence.
lawve-ai/awesome-legal-skills
Generates standalone interactive HTML "deal cards" that translate complex regulations into negotiation-ready reference tools, systematically distinguishing mandatory obligations from negotiable…
lawve-ai/awesome-legal-skills
A skill your agent uses when the user wants an AI governance, legal-risk, privacy, compliance, procurement, or vendor-risk review of an internal AI use case, an AI product feature, an LLM workflow…
magnus919/hermes-profiles
COO methodology for process design, organizational scaling, operational metrics, compliance and audit, vendor management, and team topology.
aiming-lab/AutoResearchClaw
Reference patterns for writing qiskit 2.x code for variational quantum machine learning: feature maps, VQC training, VQE for chemistry, MPS circuits and noise models.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins. New Tech Pia is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins.
New Tech Pia fits situations like: tasks that involve Privacy and GDPR; tasks that involve Quantum computing; tasks that involve Vendor and procurement management.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a claude-code`. Or copy the skill folder (skills/privacy/new-tech-pia in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/new-tech-pia in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a codex`. Or copy the skill folder (skills/privacy/new-tech-pia in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/new-tech-pia in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/new-tech-pia, .gemini/skills/new-tech-pia, .github/skills/new-tech-pia and .opencode/skills/new-tech-pia in your project.
Going by SKILL.md and its folder, New Tech Pia needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
New Tech Pia is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with New Tech Pia: Tech Contract Negotiation Patrick Munro (lawve-ai/awesome-legal-skills, 847 stars), Operational Design (magnus919/agent-skills, 115 stars), Regulatory Deal Card Generator Patrick Munro (lawve-ai/awesome-legal-skills, 847 stars) and AI Governance Reviewer Carl Ditzler (lawve-ai/awesome-legal-skills, 847 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.