C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Agent skill
Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills performing-transfer-impact-assessment --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment .claude/skills/performing-transfer-impact-assessment && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "performing-transfer-impact-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment into .claude/skills/performing-transfer-impact-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-transfer-impact-assessment", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessmentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills performing-transfer-impact-assessment --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment .agents/skills/performing-transfer-impact-assessment && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "performing-transfer-impact-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment into .agents/skills/performing-transfer-impact-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-transfer-impact-assessment", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills performing-transfer-impact-assessment --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment .cursor/skills/performing-transfer-impact-assessment && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "performing-transfer-impact-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment into .cursor/skills/performing-transfer-impact-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-transfer-impact-assessment", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills performing-transfer-impact-assessment --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment .gemini/skills/performing-transfer-impact-assessment && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "performing-transfer-impact-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment into .gemini/skills/performing-transfer-impact-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-transfer-impact-assessment", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills performing-transfer-impact-assessmentInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment .github/skills/performing-transfer-impact-assessment && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "performing-transfer-impact-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment into .github/skills/performing-transfer-impact-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-transfer-impact-assessment", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills performing-transfer-impact-assessment --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment .opencode/skills/performing-transfer-impact-assessment && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "performing-transfer-impact-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment into .opencode/skills/performing-transfer-impact-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-transfer-impact-assessment", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
performing-transfer-impact-assessmentGuides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology.
Performing Transfer Impact Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers assessment of third country legal frameworks, supplementary measures evaluation, and TIA scoring. Activate for international data transfers, SCCs, third-country adequacy, or Chapter V compliance. Keywords: TIA, Schrems II, transfer assessment, EDPB, supplementary measures, SCCs, international transfer.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Performing Transfer Impact Assessment loads about 3.8k tokens when it runs, and up to ~7.4k if it reads all its reference files. Until then it costs about 118 tokens; SKILL.md has 1,794 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,794 words, ~3,844 tokens.
.claude/skills/performing-transfer-impact-assessment/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Following the Court of Justice of the European Union (CJEU) judgment in Data Protection Commissioner v Facebook Ireland and Maximillian Schrems (Case C-311/18, 16 July 2020) — commonly known as Schrems II — controllers and processors transferring personal data outside the EEA must assess whether the legal framework of the destination country provides an essentially equivalent level of protection to that guaranteed by the GDPR and the EU Charter of Fundamental Rights. This assessment is known as a Transfer Impact Assessment (TIA). The European Data Protection Board adopted Recommendations 01/2020 on 18 June 2021, establishing a six-step process for conducting TIAs.
The EDPB established a structured methodology for evaluating whether transfers can proceed:
Map all transfers of personal data to third countries or international organisations:
| Transfer Attribute | Documentation Required |
|---|---|
| Data exporter | Legal entity, establishment, contact details |
| Data importer | Legal entity, country of establishment, sector |
| Personal data categories | Specific categories transferred (identifiers, financial, health, behavioural) |
| Special categories | Whether Art. 9 or Art. 10 data is transferred |
| Data subjects | Categories and approximate number |
| Transfer mechanism | SCCs, BCRs, Art. 49 derogation, adequacy decision |
| Purpose of transfer | Specific purposes for which data is transferred |
| Onward transfers | Whether importer transfers data to further third countries |
| Format | Whether data is transferred in clear text, pseudonymised, or encrypted |
| Storage vs transit | Whether data is stored in third country or only transits through it |
| Transfer Mechanism | GDPR Reference | Assessment Requirement |
|---|---|---|
| Adequacy decision | Art. 45 | Rely on Commission assessment; monitor for future invalidation |
| Standard Contractual Clauses (new 2021 SCCs) | Art. 46(2)(c) | Full TIA required per CJEU C-311/18 |
| Binding Corporate Rules | Art. 47 | Full TIA required; BCRs must include supplementary measures |
| Codes of conduct with binding commitments | Art. 46(2)(e) | Full TIA required |
| Certification mechanisms | Art. 46(2)(f) | Full TIA required |
| Ad hoc contractual clauses | Art. 46(3)(a) | Full TIA required plus supervisory authority authorisation |
| Art. 49 derogations | Art. 49 | No TIA required but strict conditions apply; derogations must be interpreted restrictively |
Evaluate whether the destination country's laws and practices provide essentially equivalent protection. Key assessment areas:
| Assessment Factor | Questions to Address |
|---|---|
| Surveillance legislation | What laws authorise government access to personal data held by private entities? |
| Scope of access powers | Is access limited to what is strictly necessary and proportionate, or does it enable bulk/indiscriminate collection? |
| Independent oversight | Is government access subject to prior authorisation by an independent body (court or independent administrative authority)? |
| Transparency | Are data subjects notified of government access, either directly or through transparency reporting? |
| Effective remedies | Do data subjects have access to an independent tribunal or court to challenge government access? |
| Assessment Factor | Questions to Address |
|---|---|
| Constitutional protections | Does the country's constitution protect the right to privacy and data protection? |
| Data protection legislation | Does the country have comprehensive data protection legislation? |
| Independent supervisory authority | Is there an independent data protection authority with enforcement powers? |
| Judicial independence | Is the judiciary independent from the executive, with power to review government surveillance? |
| Assessment Factor | Sources of Information |
|---|---|
| Government access requests | Transparency reports from the data importer and major technology companies |
| Enforcement actions | Published decisions of the destination country's data protection authority |
| Legal reforms | Pending or recent legislative changes affecting surveillance powers |
| International assessments | EDPB adequacy referentials, CoE Convention 108+ ratification status |
Where the assessment in Step 3 reveals that the third country framework does not provide essentially equivalent protection, the exporter must identify supplementary measures that, together with the transfer tool, ensure essentially equivalent protection.
| Measure | EDPB Assessment | Effective Against |
|---|---|---|
| End-to-end encryption where exporter holds the key | Effective — prevents importer and government access to clear text data | Government access via importer; importer misuse |
| Pseudonymisation where exporter holds the mapping table | Effective — if additional information needed to re-identify is held solely in EEA | Government access where re-identification requires mapping table |
| Split processing across jurisdictions | Effective — if no single jurisdiction has access to complete dataset | Government access in any single jurisdiction |
| Transport encryption (TLS/IPSEC) for data in transit | Insufficient alone — protects only against interception during transit, not access at rest | Transit interception only |
| Encryption at rest where importer holds decryption key | Insufficient — importer can be compelled to provide decryption key | Not effective against government compulsion |
| Measure | Purpose |
|---|---|
| Obligation to use all available legal remedies to challenge government access requests | Ensures importer resists unlawful government access |
| Warrant canary or transparency reporting obligations | Enables exporter to detect government access |
| Obligation to notify exporter of government access requests (where legally permitted) | Enables exporter to intervene or suspend transfers |
| Obligation to conduct annual assessment of government access laws | Ensures ongoing monitoring of legal framework changes |
| Contractual right for exporter to audit importer's compliance | Enables verification of supplementary measure effectiveness |
| Measure | Purpose |
|---|---|
| Adoption of internal policies and procedures for handling government access requests | Ensures structured response to government demands |
| Appointment of a DPO or privacy officer by the importer | Ensures designated responsibility for compliance |
| Staff training on government access response procedures | Ensures operational readiness |
| Regular external audits of government access request handling | Independent verification of compliance |
| Factor | Weight | Score 1 (Low Risk) | Score 3 (Medium Risk) | Score 5 (High Risk) |
|---|---|---|---|---|
| Surveillance legislation scope | 25% | Targeted access only, strictly necessary and proportionate | Mix of targeted and bulk powers, some proportionality limitations | Bulk/indiscriminate access powers without proportionality requirements |
| Independent prior authorisation | 20% | Judicial authorisation required for all access | Judicial authorisation for some; administrative for others | No independent authorisation required; self-authorisation |
| Effective remedies | 20% | Independent court with full review powers, accessible to foreign nationals | Administrative review body with limited powers | No effective remedy available to foreign nationals |
| Transparency and notification | 15% | Mandatory notification and public transparency reporting | Partial transparency; notification in some cases | No notification obligation; limited or no transparency |
| Rule of law and judicial independence | 20% | Strong constitutional protections; independent judiciary; ratified CoE 108+ | Some constitutional protections; judiciary generally independent | Weak or absent constitutional protections; executive influence over judiciary |
| Total Weighted Score | Risk Level | Recommendation |
|---|---|---|
| 1.0 — 2.0 | Low | Transfer may proceed with standard transfer tool |
| 2.1 — 3.0 | Medium | Transfer may proceed with appropriate supplementary measures |
| 3.1 — 4.0 | High | Transfer may proceed only with robust technical supplementary measures (encryption with exporter-held key, pseudonymisation) |
| 4.1 — 5.0 | Very High | Transfer should not proceed unless data is encrypted with exporter-held key and importer has no access to clear text data |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Performing Transfer Impact Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Performing Transfer Impact Assessment this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Performing Transfer Impact Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology.
Performing Transfer Impact Assessment fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a claude-code`. Or copy the skill folder (skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/performing-transfer-impact-assessment in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a codex`. Or copy the skill folder (skills/privacy/transfer-impact-assessment/performing-transfer-impact-assessment in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/performing-transfer-impact-assessment in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill performing-transfer-impact-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-transfer-impact-assessment, .gemini/skills/performing-transfer-impact-assessment, .github/skills/performing-transfer-impact-assessment and .opencode/skills/performing-transfer-impact-assessment in your project.
Going by SKILL.md and its folder, Performing Transfer Impact Assessment needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Performing Transfer Impact Assessment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Performing Transfer Impact Assessment: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.