Agent skill

Performing Transfer Impact Assessment

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology.

Apache-2.0Auto-check passedLegal & Compliance

Install Performing Transfer Impact Assessment

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills performing-transfer-impact-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment .claude/skills/performing-transfer-impact-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-transfer-impact-assessment
GitHub stars
301
Token cost
~3.8k tokens
SKILL.md length
1,794 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology.

  • Works in 6 steps: Know Your Transfers → Identify the Transfer Tool — Chapter V… → Assess Third Country Legal Framework → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Legal Foundation, Step 1: Know Your Transfers and Step 2: Identify the Transfer…, plus 8 more sections
  • Runs Python scripts from its folder

What it does

Performing Transfer Impact Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers assessment of third country legal frameworks, supplementary measures evaluation, and TIA scoring. Activate for international data transfers, SCCs, third-country adequacy, or Chapter V compliance. Keywords: TIA, Schrems II, transfer assessment, EDPB, supplementary measures, SCCs, international transfer.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the performing-transfer-impact-assessment skill to guide the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations…”
  • “/performing-transfer-impact-assessment”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Know Your Transfers
  2. Identify the Transfer Tool — Chapter V GDPR
  3. Assess Third Country Legal Framework
  4. Identify and Adopt Supplementary Measures
  5. Procedural Steps for Supplementary Measures
  6. Re-evaluate at Appropriate Intervals

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Transfer Impact Assessment loads about 3.8k tokens when it runs, and up to ~7.4k if it reads all its reference files. Until then it costs about 118 tokens; SKILL.md has 1,794 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~118
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,794 words, ~3,844 tokens.

Download SKILL.mdSave it as .claude/skills/performing-transfer-impact-assessment/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
performing-transfer-impact-assessment
description
Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers assessment of third country legal frameworks, supplementary measures evaluation, and TIA scoring. Activate for international data transfers, SCCs, third-country adequacy, or Chapter V compliance. Keywords: TIA, Schrems II, transfer assessment, EDPB, supplementary measures, SCCs, international transfer.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-impact-assessment
metadata.tags
tia, schrems-ii, international-transfer, edpb, supplementary-measures, sccs

Performing Transfer Impact Assessment

Overview

Following the Court of Justice of the European Union (CJEU) judgment in Data Protection Commissioner v Facebook Ireland and Maximillian Schrems (Case C-311/18, 16 July 2020) — commonly known as Schrems II — controllers and processors transferring personal data outside the EEA must assess whether the legal framework of the destination country provides an essentially equivalent level of protection to that guaranteed by the GDPR and the EU Charter of Fundamental Rights. This assessment is known as a Transfer Impact Assessment (TIA). The European Data Protection Board adopted Recommendations 01/2020 on 18 June 2021, establishing a six-step process for conducting TIAs.

CJEU C-311/18 Key Holdings
  1. Privacy Shield invalidated: The EU-US Privacy Shield framework was declared invalid due to US surveillance programmes (Section 702 FISA, EO 12333) enabling mass access to personal data transferred from the EU, with insufficient remedies for EU data subjects.
  2. Standard Contractual Clauses remain valid in principle: The SCCs decision (2010/87/EU, now replaced by Commission Implementing Decision 2021/914) was upheld but subject to the requirement that data exporters verify the clauses can be complied with in practice in the destination country.
  3. Case-by-case assessment required: Controllers cannot rely on SCCs mechanically; they must assess the destination country's legal framework and, where necessary, implement supplementary measures to ensure essentially equivalent protection.
  4. Supervisory authority intervention: Supervisory authorities are required to suspend or prohibit transfers where essentially equivalent protection cannot be ensured.
EDPB Recommendations 01/2020 — Six-Step Process

The EDPB established a structured methodology for evaluating whether transfers can proceed:

Step 1: Know Your Transfers

Map all transfers of personal data to third countries or international organisations:

Transfer AttributeDocumentation Required
Data exporterLegal entity, establishment, contact details
Data importerLegal entity, country of establishment, sector
Personal data categoriesSpecific categories transferred (identifiers, financial, health, behavioural)
Special categoriesWhether Art. 9 or Art. 10 data is transferred
Data subjectsCategories and approximate number
Transfer mechanismSCCs, BCRs, Art. 49 derogation, adequacy decision
Purpose of transferSpecific purposes for which data is transferred
Onward transfersWhether importer transfers data to further third countries
FormatWhether data is transferred in clear text, pseudonymised, or encrypted
Storage vs transitWhether data is stored in third country or only transits through it

Step 2: Identify the Transfer Tool — Chapter V GDPR

Transfer MechanismGDPR ReferenceAssessment Requirement
Adequacy decisionArt. 45Rely on Commission assessment; monitor for future invalidation
Standard Contractual Clauses (new 2021 SCCs)Art. 46(2)(c)Full TIA required per CJEU C-311/18
Binding Corporate RulesArt. 47Full TIA required; BCRs must include supplementary measures
Codes of conduct with binding commitmentsArt. 46(2)(e)Full TIA required
Certification mechanismsArt. 46(2)(f)Full TIA required
Ad hoc contractual clausesArt. 46(3)(a)Full TIA required plus supervisory authority authorisation
Art. 49 derogationsArt. 49No TIA required but strict conditions apply; derogations must be interpreted restrictively

Evaluate whether the destination country's laws and practices provide essentially equivalent protection. Key assessment areas:

3.1 Government Access to Data
Assessment FactorQuestions to Address
Surveillance legislationWhat laws authorise government access to personal data held by private entities?
Scope of access powersIs access limited to what is strictly necessary and proportionate, or does it enable bulk/indiscriminate collection?
Independent oversightIs government access subject to prior authorisation by an independent body (court or independent administrative authority)?
TransparencyAre data subjects notified of government access, either directly or through transparency reporting?
Effective remediesDo data subjects have access to an independent tribunal or court to challenge government access?
Assessment FactorQuestions to Address
Constitutional protectionsDoes the country's constitution protect the right to privacy and data protection?
Data protection legislationDoes the country have comprehensive data protection legislation?
Independent supervisory authorityIs there an independent data protection authority with enforcement powers?
Judicial independenceIs the judiciary independent from the executive, with power to review government surveillance?
3.3 Practical Application
Assessment FactorSources of Information
Government access requestsTransparency reports from the data importer and major technology companies
Enforcement actionsPublished decisions of the destination country's data protection authority
Legal reformsPending or recent legislative changes affecting surveillance powers
International assessmentsEDPB adequacy referentials, CoE Convention 108+ ratification status

Step 4: Identify and Adopt Supplementary Measures

Where the assessment in Step 3 reveals that the third country framework does not provide essentially equivalent protection, the exporter must identify supplementary measures that, together with the transfer tool, ensure essentially equivalent protection.

Technical Supplementary Measures
MeasureEDPB AssessmentEffective Against
End-to-end encryption where exporter holds the keyEffective — prevents importer and government access to clear text dataGovernment access via importer; importer misuse
Pseudonymisation where exporter holds the mapping tableEffective — if additional information needed to re-identify is held solely in EEAGovernment access where re-identification requires mapping table
Split processing across jurisdictionsEffective — if no single jurisdiction has access to complete datasetGovernment access in any single jurisdiction
Transport encryption (TLS/IPSEC) for data in transitInsufficient alone — protects only against interception during transit, not access at restTransit interception only
Encryption at rest where importer holds decryption keyInsufficient — importer can be compelled to provide decryption keyNot effective against government compulsion
Contractual Supplementary Measures
MeasurePurpose
Obligation to use all available legal remedies to challenge government access requestsEnsures importer resists unlawful government access
Warrant canary or transparency reporting obligationsEnables exporter to detect government access
Obligation to notify exporter of government access requests (where legally permitted)Enables exporter to intervene or suspend transfers
Obligation to conduct annual assessment of government access lawsEnsures ongoing monitoring of legal framework changes
Contractual right for exporter to audit importer's complianceEnables verification of supplementary measure effectiveness
Organisational Supplementary Measures
MeasurePurpose
Adoption of internal policies and procedures for handling government access requestsEnsures structured response to government demands
Appointment of a DPO or privacy officer by the importerEnsures designated responsibility for compliance
Staff training on government access response proceduresEnsures operational readiness
Regular external audits of government access request handlingIndependent verification of compliance

Step 5: Procedural Steps for Supplementary Measures

  1. Document the supplementary measures in writing, either within the SCCs or in a separate supplementary agreement annexed to the SCCs.
  2. Ensure supplementary measures are legally binding on the data importer.
  3. Verify that supplementary measures are technically implementable given the processing purposes.
  4. Assess whether supplementary measures conflict with any obligation of the data importer under the destination country's law.
  5. If supplementary measures conflict with local law obligations of the importer, the transfer cannot proceed.
Show full SKILL.md (696 more words)Show less

Step 6: Re-evaluate at Appropriate Intervals

  1. Monitor developments in the third country legal framework on an ongoing basis.
  2. Conduct formal TIA re-evaluation at minimum annually or upon a trigger event.
  3. Trigger events: new surveillance legislation, court decision affecting data access, adequacy decision adopted or withdrawn, law enforcement action affecting the importer.
  4. Suspend transfers immediately if supplementary measures can no longer ensure essentially equivalent protection.

TIA Scoring Rubric

Government Access Risk Score
FactorWeightScore 1 (Low Risk)Score 3 (Medium Risk)Score 5 (High Risk)
Surveillance legislation scope25%Targeted access only, strictly necessary and proportionateMix of targeted and bulk powers, some proportionality limitationsBulk/indiscriminate access powers without proportionality requirements
Independent prior authorisation20%Judicial authorisation required for all accessJudicial authorisation for some; administrative for othersNo independent authorisation required; self-authorisation
Effective remedies20%Independent court with full review powers, accessible to foreign nationalsAdministrative review body with limited powersNo effective remedy available to foreign nationals
Transparency and notification15%Mandatory notification and public transparency reportingPartial transparency; notification in some casesNo notification obligation; limited or no transparency
Rule of law and judicial independence20%Strong constitutional protections; independent judiciary; ratified CoE 108+Some constitutional protections; judiciary generally independentWeak or absent constitutional protections; executive influence over judiciary
Overall TIA Risk Level
Total Weighted ScoreRisk LevelRecommendation
1.0 — 2.0LowTransfer may proceed with standard transfer tool
2.1 — 3.0MediumTransfer may proceed with appropriate supplementary measures
3.1 — 4.0HighTransfer may proceed only with robust technical supplementary measures (encryption with exporter-held key, pseudonymisation)
4.1 — 5.0Very HighTransfer should not proceed unless data is encrypted with exporter-held key and importer has no access to clear text data

Country-Specific Assessment Notes

United States
  • Post-Schrems II status: EU-US Data Privacy Framework adopted 10 July 2023 (Commission Implementing Decision C(2023) 4745). US companies self-certified under the DPF benefit from an adequacy decision. Non-certified companies require SCCs with TIA.
  • Key legislation: FISA Section 702 (amended by FISA Section 702 reauthorisation in April 2024), EO 14086 (7 October 2022) establishing proportionality requirements and Data Protection Review Court.
  • Assessment: For DPF-certified companies, adequacy finding applies. For non-certified companies, TIA must assess whether EO 14086 safeguards are sufficient given the specific data and importer.
United Kingdom
  • Post-Brexit status: Adequacy decision adopted 28 June 2021 (Commission Implementing Decision C(2021) 4800), valid until 27 June 2025, extended by new adequacy assessment.
  • Key legislation: Investigatory Powers Act 2016, Data Protection Act 2018, UK GDPR.
  • Assessment: Adequacy decision currently in force. Monitor for changes to IPA bulk powers and UK divergence from GDPR standards.
India
  • Status: No adequacy decision. Digital Personal Data Protection Act 2023 enacted but implementation through rules pending.
  • Key legislation: Information Technology Act 2000, DPDP Act 2023, Indian Telegraph Act 1885.
  • Assessment: Government access powers under IT Act Section 69 and Telegraph Act are broad. TIA should assess proportionality and remedy availability. Supplementary measures recommended.

Common TIA Deficiencies

  1. Generic country assessments: Using a template country assessment without considering the specific data, importer, and processing context.
  2. Reliance on contractual measures alone: Contractual obligations cannot override a government compulsion order; technical measures must supplement contractual ones.
  3. Failure to assess onward transfers: The importer may transfer data to further third countries with different legal frameworks.
  4. No ongoing monitoring: TIA conducted once and never updated despite legal framework changes.
  5. Conflating adequacy with absence of risk: Even countries with adequacy decisions may present risks for specific data types or sectors.

Enforcement Precedents

  • CJEU C-311/18 Schrems II (2020): Invalidated Privacy Shield; required case-by-case assessment for SCCs.
  • Austrian DPA (DSB) — Decision D155.027 of 22 December 2021: Google Analytics transfers to US found unlawful; TIA inadequate because Google's SCCs and supplementary measures did not prevent US government access under FISA 702.
  • CNIL (France) — Decision of 10 February 2022: Google Analytics transfers to US found unlawful; echoed Austrian DPA reasoning regarding FISA 702 access.
  • DPC Ireland — Meta Platforms Decision (May 2023): EUR 1.2 billion fine for continued transfers to US without valid transfer mechanism following Schrems II.
  • EDPS — Decision on European Parliament COVID testing (January 2022): Found that transfers to US by Ecolog (processor) lacked adequate supplementary measures.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Performing Transfer Impact Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Transfer Impact Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Transfer Impact Assessment this skillmukul975/Privacy-Data-Protection-Skills301—~3.8kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Performing Transfer Impact Assessment

What does Performing Transfer Impact Assessment do?

Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Performing Transfer Impact Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology.

When should I use Performing Transfer Impact Assessment?

Performing Transfer Impact Assessment fits situations like: tasks that involve Privacy and GDPR.

How do I install Performing Transfer Impact Assessment in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a claude-code`. Or copy the skill folder (skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/performing-transfer-impact-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Performing Transfer Impact Assessment in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a codex`. Or copy the skill folder (skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/performing-transfer-impact-assessment in your project. Codex loads it when a task matches its description.

Can I use Performing Transfer Impact Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-transfer-impact-assessment, .gemini/skills/performing-transfer-impact-assessment, .github/skills/performing-transfer-impact-assessment and .opencode/skills/performing-transfer-impact-assessment in your project.

What does Performing Transfer Impact Assessment need to run?

Going by SKILL.md and its folder, Performing Transfer Impact Assessment needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Performing Transfer Impact Assessment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Performing Transfer Impact Assessment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Transfer Impact Assessment use?

Performing Transfer Impact Assessment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Transfer Impact Assessment use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.6k tokens, read only when the agent opens those files.

What are the alternatives to Performing Transfer Impact Assessment?

Skills that share tags, products or a category with Performing Transfer Impact Assessment: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Transfer Impact Assessment?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.