Agent skill

Nist Privacy Identify

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides implementation of the NIST Privacy Framework IDENTIFY function covering ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories.

Apache-2.0Auto-check passedLegal & Compliance

Install Nist Privacy Identify

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill nist-privacy-identify -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills nist-privacy-identify --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/nist-privacy-identify .claude/skills/nist-privacy-identify && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nist-privacy-identify
GitHub stars
301
Token cost
~2.3k tokens
SKILL.md length
1,013 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides implementation of the NIST Privacy Framework IDENTIFY function covering ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories.

  • Works in 4 steps: Establish Inventory and Mapping (Months… → Business Environment Analysis (Month 2-3) → Risk Assessment (Months 3-5) → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, IDENTIFY Function Structure, NIST PF to GDPR Mapping and Implementation Methodology, plus 1 more section
  • Runs Python scripts from its folder

What it does

Nist Privacy Identify is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides implementation of the NIST Privacy Framework IDENTIFY function covering ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories. Maps NIST PF controls to GDPR requirements for dual-framework compliance. Keywords: NIST Privacy Framework, IDENTIFY function, ID.BE, ID.DA, ID.IM, ID.RA, privacy risk assessment, data actions.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the nist-privacy-identify skill to guide implementation of the NIST Privacy Framework IDENTIFY function covering ID.BE business environment…”
  • “/nist-privacy-identify”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Establish Inventory and Mapping (Months 1-3)
  2. Business Environment Analysis (Month 2-3)
  3. Risk Assessment (Months 3-5)
  4. Ecosystem Risk Management (Months 4-6)

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nist Privacy Identify loads about 2.3k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 101 tokens; SKILL.md has 1,013 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,013 words, ~2,327 tokens.

Download SKILL.mdSave it as .claude/skills/nist-privacy-identify/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
nist-privacy-identify
description
Guides implementation of the NIST Privacy Framework IDENTIFY function covering ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories. Maps NIST PF controls to GDPR requirements for dual-framework compliance. Keywords: NIST Privacy Framework, IDENTIFY function, ID.BE, ID.DA, ID.IM, ID.RA, privacy risk assessment, data actions.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-impact-assessment
metadata.tags
nist-privacy-framework, identify-function, privacy-risk, data-actions

Implementing NIST Privacy Framework IDENTIFY Function

Overview

The NIST Privacy Framework Version 1.0 (January 2020) provides a voluntary enterprise risk management tool structured around five core functions: IDENTIFY, GOVERN, CONTROL, COMMUNICATE, and PROTECT. The IDENTIFY function develops the organisational understanding to manage privacy risk arising from data processing. This skill covers the four IDENTIFY subcategories: Inventory and Mapping (ID.IM), Business Environment (ID.BE), Risk Assessment (ID.RA), and Data Processing Ecosystem Risk Management (ID.DE).

IDENTIFY Function Structure

ID.IM — Inventory and Mapping

Data processing inventory and mapping activities are understood by the organisation.

SubcategoryDescriptionImplementation
ID.IM-P1Systems/products/services that process data are inventoriedMaintain a comprehensive register of all systems processing personal data, including SaaS tools, internal databases, and third-party integrations
ID.IM-P2Owners of systems/products/services are identifiedAssign a data processing owner to each system with documented responsibility for privacy compliance
ID.IM-P3Categories of individuals whose data are processed are inventoriedMap all data subject categories (employees, customers, patients, vendors, website visitors)
ID.IM-P4Data actions of the systems/products/services are inventoriedDocument data lifecycle actions: collection, retention, logging, generation, transformation, use, disclosure, sharing, transmission, disposal
ID.IM-P5Purposes for data actions are inventoriedDocument specific purposes for each data action, aligned with GDPR Art. 5(1)(b) purpose limitation
ID.IM-P6Data elements within the data actions are inventoriedCatalogue all personal data elements processed per system and per purpose
ID.IM-P7Environmental factors affecting the data processing ecosystem are understoodAssess external factors: legal/regulatory requirements, industry standards, market expectations, organisational risk tolerance
ID.IM-P8Data processing is mappedCreate and maintain data flow maps showing how personal data moves through the organisation
ID.BE — Business Environment

The organisation's mission, objectives, stakeholders, and activities are understood and prioritised.

SubcategoryDescriptionImplementation
ID.BE-P1The organisation's role in the data processing ecosystem is identified and communicatedDetermine controller/processor/joint controller status for each processing activity
ID.BE-P2Priorities for organisational mission, objectives, and activities are established and communicatedAlign privacy programme with business objectives; ensure privacy is a design requirement
ID.BE-P3Systems/products/services that support organisational priorities are identified and key requirements communicatedIdentify which processing activities are critical to business operations and prioritise privacy investment accordingly
ID.RA — Risk Assessment

The organisation understands the privacy risks to individuals and how such processing creates privacy risks to the organisation.

SubcategoryDescriptionImplementation
ID.RA-P1Contextual factors related to the systems/products/services and data actions are identifiedAssess context: relationship with data subjects, data subject expectations, sensitivity, volume, collection method
ID.RA-P2Data analytic inputs and outputs are identified and evaluatedFor data analytics and AI, identify inputs (training data, inference data) and outputs (predictions, scores, decisions)
ID.RA-P3Potential problems for individuals that arise from data processing are identifiedIdentify privacy harms: loss of autonomy, discrimination, economic loss, physical harm, reputational damage, loss of trust
ID.RA-P4Problematic data actions, the likelihood that they occur, and the resulting problems for individuals are identified and assessedAssess likelihood and severity of each problematic data action — aligned with GDPR DPIA risk assessment
ID.RA-P5Risk responses are identified and prioritisedFor each identified risk, determine response: mitigate, transfer, avoid, accept
ID.DE — Data Processing Ecosystem Risk Management

The organisation identifies, assesses, and manages privacy risks associated with data processing by third parties.

SubcategoryDescriptionImplementation
ID.DE-P1Data processing ecosystem risk management policies, processes, and procedures are identified, established, assessed, and managedVendor privacy management programme with due diligence, contractual requirements, and ongoing monitoring
ID.DE-P2Data processing ecosystem parties are identified, prioritised, and assessedMap all processors, sub-processors, and third-party recipients with risk rating
ID.DE-P3Contracts with data processing ecosystem parties are established, maintained, and managedArt. 28 DPAs with all processors; joint controller arrangements per Art. 26
ID.DE-P4Interoperability frameworks or mechanisms are established for data processing ecosystem partiesStandard data formats, APIs, and privacy-preserving data exchange protocols
ID.DE-P5Data processing ecosystem parties are managed consistent with the organisation's risk strategyOngoing processor performance monitoring, audit rights exercise, sub-processor change management
Show full SKILL.md (368 more words)Show less

NIST PF to GDPR Mapping

NIST PF SubcategoryGDPR EquivalentImplementation Overlap
ID.IM-P1 through P8Art. 30 Records of Processing ActivitiesRoPA fulfils the core inventory and mapping requirements
ID.BE-P1Art. 26 Joint Controllers, Art. 28 ProcessorsRole determination aligns directly
ID.RA-P1 through P5Art. 35 DPIADPIA risk assessment methodology maps to NIST risk assessment
ID.DE-P1 through P5Art. 28 Processor RequirementsProcessor governance maps to ecosystem risk management

Implementation Methodology

Phase 1: Establish Inventory and Mapping (Months 1-3)
  1. Deploy a data discovery tool to identify personal data across all systems.
  2. Conduct departmental interviews to identify informal data processing.
  3. Create the system-level processing inventory (ID.IM-P1, P2).
  4. Map data subject categories (ID.IM-P3) and data elements (ID.IM-P6).
  5. Document data actions per system (ID.IM-P4) and purposes (ID.IM-P5).
  6. Create data flow maps (ID.IM-P8).
  7. Cross-reference with existing Art. 30 RoPA.
Phase 2: Business Environment Analysis (Month 2-3)
  1. Determine controller/processor/joint controller roles (ID.BE-P1).
  2. Align privacy programme priorities with business strategy (ID.BE-P2).
  3. Identify critical processing activities (ID.BE-P3).
Phase 3: Risk Assessment (Months 3-5)
  1. For each processing activity, assess contextual factors (ID.RA-P1).
  2. Identify problematic data actions using the NIST problematic data action taxonomy:
    • Appropriation: use of data in ways beyond data subject expectations
    • Distortion: use of inaccurate data or misleading inferences
    • Induced disclosure: pressure to reveal more data than intended
    • Insecurity: inadequate protection of data
    • Re-identification: linking anonymised data back to individuals
    • Stigmatisation: association with disfavoured groups
    • Surveillance: excessive monitoring
    • Unanticipated revelation: discovery of information beyond original data
    • Unwarranted restriction: limiting access to services based on data
  3. Assess likelihood and severity for each problematic data action (ID.RA-P4).
  4. Determine risk responses (ID.RA-P5).
Phase 4: Ecosystem Risk Management (Months 4-6)
  1. Inventory all third-party data processors and recipients (ID.DE-P2).
  2. Conduct vendor privacy due diligence assessments.
  3. Verify DPA compliance for all processors (ID.DE-P3).
  4. Establish ongoing monitoring programme (ID.DE-P5).

Enforcement Context

While the NIST Privacy Framework is voluntary and not directly enforceable, organisations demonstrating NIST PF implementation show a mature privacy programme that can support GDPR accountability under Art. 5(2) and Art. 24. US state privacy laws (California CPRA, Virginia VCDPA, Colorado CPA) increasingly reference the NIST PF as a compliance resource.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/nist-privacy-identify of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Nist Privacy Identify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nist Privacy Identify compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nist Privacy Identify this skillmukul975/Privacy-Data-Protection-Skills301—~2.3kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Nist Privacy Identify

What does Nist Privacy Identify do?

Guides implementation of the NIST Privacy Framework IDENTIFY function covering ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories. Nist Privacy Identify is an agent skill from mukul975/Privacy-Data-Protection-Skills.RA risk assessment subcategories.

When should I use Nist Privacy Identify?

Nist Privacy Identify fits situations like: tasks that involve Privacy and GDPR.

How do I install Nist Privacy Identify in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill nist-privacy-identify -a claude-code`. Or copy the skill folder (skills/privacy/nist-privacy-identify in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/nist-privacy-identify in your project. Claude Code loads it when a task matches its description.

How do I install Nist Privacy Identify in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill nist-privacy-identify -a codex`. Or copy the skill folder (skills/privacy/nist-privacy-identify in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/nist-privacy-identify in your project. Codex loads it when a task matches its description.

Can I use Nist Privacy Identify in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill nist-privacy-identify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nist-privacy-identify, .gemini/skills/nist-privacy-identify, .github/skills/nist-privacy-identify and .opencode/skills/nist-privacy-identify in your project.

What does Nist Privacy Identify need to run?

Going by SKILL.md and its folder, Nist Privacy Identify needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Nist Privacy Identify access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nist Privacy Identify safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Nist Privacy Identify use?

Nist Privacy Identify is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nist Privacy Identify use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 415 tokens, read only when the agent opens those files.

What are the alternatives to Nist Privacy Identify?

Skills that share tags, products or a category with Nist Privacy Identify: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nist Privacy Identify?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.