C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Classifies personal vs non-personal data per GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill personal-data-test -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills personal-data-test --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/personal-data-test .claude/skills/personal-data-test && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "personal-data-test" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/personal-data-test into .claude/skills/personal-data-test/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "personal-data-test", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/personal-data-testType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill personal-data-test -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills personal-data-test --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/personal-data-test .agents/skills/personal-data-test && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "personal-data-test" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/personal-data-test into .agents/skills/personal-data-test/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "personal-data-test", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill personal-data-test -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills personal-data-test --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/personal-data-test .cursor/skills/personal-data-test && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "personal-data-test" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/personal-data-test into .cursor/skills/personal-data-test/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "personal-data-test", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/personal-data-test--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill personal-data-test -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills personal-data-test --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/personal-data-test .gemini/skills/personal-data-test && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "personal-data-test" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/personal-data-test into .gemini/skills/personal-data-test/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "personal-data-test", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills personal-data-testInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill personal-data-test -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/personal-data-test .github/skills/personal-data-test && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "personal-data-test" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/personal-data-test into .github/skills/personal-data-test/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "personal-data-test", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill personal-data-test -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills personal-data-test --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/personal-data-test .opencode/skills/personal-data-test && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "personal-data-test" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/personal-data-test into .opencode/skills/personal-data-test/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "personal-data-test", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
personal-data-testClassifies personal vs non-personal data per GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills.
Personal Data Test is an agent skill from mukul975/Privacy-Data-Protection-Skills. Classifies personal vs non-personal data per GDPR Art. 4(1) definition test with decision tree for borderline cases. References Breyer v Germany CJEU C-582/14 dynamic IP ruling and WP29 Opinion 4/2007. Keywords: personal data, GDPR Art 4, data classification, Breyer ruling, identifiability test, PII.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Personal Data Test loads about 3.9k tokens when it runs, and up to ~7.3k if it reads all its reference files. Until then it costs about 80 tokens; SKILL.md has 1,689 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,689 words, ~3,915 tokens.
.claude/skills/personal-data-test/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Article 4(1) of the GDPR defines personal data as "any information relating to an identified or identifiable natural person ('data subject')." This definition is deliberately broad and technology-neutral. The European Court of Justice in Breyer v Bundesrepublik Deutschland (C-582/14, 19 October 2016) confirmed that even dynamic IP addresses can constitute personal data when the controller has legal means to obtain additional information enabling identification. This skill provides a systematic decision framework for classifying data elements as personal, non-personal, or borderline requiring contextual assessment.
Personal data exists when ALL four elements are satisfied:
| Element | Definition | Assessment Criteria |
|---|---|---|
| Any information | No restriction on nature, content, or format of information | Includes objective facts (age, blood type) and subjective assessments (credit rating, performance review). Covers all formats: text, image, audio, biometric, metadata, behavioural |
| Relating to | Information must have a content, purpose, or result link to the individual | Content link: information is about the person. Purpose link: information is used to evaluate or influence the person. Result link: processing has an impact on the person's rights or interests |
| Identified or identifiable | The person is or can be distinguished from all other persons | Identified: directly singled out. Identifiable: can be singled out by using additional data, taking into account all means reasonably likely to be used |
| Natural person | Living human being, not legal entities or deceased persons | Excludes companies, government bodies, associations. Member State law may extend protections to deceased persons (e.g., Italy extends to 20 years post-mortem) |
To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly. The assessment must consider:
Patrick Breyer challenged the German Federal Government's practice of storing dynamic IP addresses of visitors to government websites. Germany argued that dynamic IP addresses were not personal data because the website operator could not identify visitors without additional data held by the internet service provider (ISP).
The CJEU ruled that dynamic IP addresses constitute personal data for the website operator when:
After Breyer, the following are presumptively personal data for most controllers:
Data Element
│
├── About a living natural person? ──► YES → Go to Stage 2
│
├── About a deceased person? ──► Check Member State law (may still be protected)
│
├── About a legal entity only? ──► NOT personal data under GDPR
│ (but may contain personal data of individuals within,
│ e.g., sole trader name = personal data)
│
└── About an anonymous aggregate? ──► Go to Stage 3 (verify truly anonymous)Data relates to a natural person
│
├── Person is DIRECTLY identified?
│ (name, photograph, unique ID number)
│ ──► PERSONAL DATA
│
├── Person is INDIRECTLY identifiable?
│ (combination of data points enables singling out)
│ ──► Apply Recital 26 "reasonably likely" test → Stage 2a
│
└── Person cannot be identified by any means reasonably likely?
──► NOT personal data (but document the assessment)Indirect identifiers present
│
├── Does the controller hold additional data enabling identification?
│ ──► YES → PERSONAL DATA
│
├── Does a third party hold such data, and does the controller
│ have legal means to access it? (Breyer test)
│ ──► YES → PERSONAL DATA
│
├── Could publicly available data be combined to identify?
│ (social media, public registers, news articles)
│ ──► YES → PERSONAL DATA
│
├── Is re-identification feasible considering:
│ - Cost vs. value of identification
│ - Time required vs. retention period
│ - Current and foreseeable technology
│ ──► YES → PERSONAL DATA
│
└── Identification requires disproportionate effort with no
reasonable motivation?
──► NOT personal data (document reasoning)Data claimed to be anonymous/aggregated
│
├── Can any individual be singled out from the dataset?
│ ──► YES → PERSONAL DATA (pseudonymised, not anonymised)
│
├── Can records be linked to form a profile of an individual?
│ ──► YES → PERSONAL DATA
│
├── Can information be inferred about a specific individual?
│ ──► YES → PERSONAL DATA
│
└── Passes all three tests (singling out, linkability, inference)?
──► Anonymised data — NOT personal data
(Apply WP29 Opinion 05/2014 framework)| Data Element | Reason |
|---|---|
| Full name | Direct identifier |
| National ID number (SSN, Aadhaar, BSN) | Unique direct identifier |
| Email address (personal) | Directly identifies in most contexts |
| Photograph of a face | Direct visual identifier (also biometric if processed for identification) |
| Biometric data (fingerprint, iris scan) | Unique to individual, Art. 9 special category when used for identification |
| Genetic data | Unique biological identifier, Art. 9 special category |
| Health records with patient name | Direct identifier plus Art. 9 special category |
| Home address with name | Direct identifier with location |
| Data Element | When Personal | When Not Personal |
|---|---|---|
| Dynamic IP address | When controller has legal means to obtain subscriber info from ISP (Breyer) | When controller has no means and no motivation to identify (rare) |
| Cookie identifier | When linked to browsing profile that enables singling out | When session-only cookie with no profile building |
| Device fingerprint | When used to track across sites/sessions | When used only for aggregate device statistics with k-anonymity |
| Employee ID number | When linked to HR records by same controller | When used in anonymised survey with no re-identification key |
| Location data (GPS coordinates) | When tracking individual movement patterns | When aggregated to postcode-level with >1000 individuals per cell |
| Purchase history | When linked to customer account | When stripped of all identifiers and aggregated by product category |
| Vehicle registration number | When plate-to-owner lookup is legally available | Not applicable — plate lookup is available in most jurisdictions, so nearly always personal |
| Data Element | Condition for Non-Personal Status |
|---|---|
| Weather data | General environmental data not relating to individuals |
| Stock prices | Corporate financial data |
| Machine sensor readings | Equipment telemetry with no operator identification |
| Aggregated census statistics | Published statistical tables with adequate anonymisation |
| Chemical compound properties | Scientific data about substances |
| Company financial statements | Legal entity data (but may contain director names) |
Pseudonymised data remains personal data under GDPR (Recital 26, Art. 4(5)). The existence of a re-identification key — even if held by a separate entity — means the data relates to an identifiable person. Pseudonymisation is a security measure, not an anonymisation technique.
Vanguard Financial Services Application: Customer transaction records where account numbers are replaced with random tokens. The mapping table is held by a separate internal department with access controls. These remain personal data because:
A profile built from browsing behaviour, purchase patterns, and location data — even without a name or email — constitutes personal data when the profile enables singling out the individual. The Article 29 Working Party in Opinion 4/2007 on the concept of personal data confirmed that "a profile can in itself be sufficient to identify a specific user."
Encrypted personal data remains personal data for the controller who holds the decryption key. For a third party without the key and no reasonable means to obtain it, the encrypted data may not constitute personal data (applying the Breyer relative approach). However, this assessment must account for future cryptanalytic capabilities.
The Article 29 Working Party Opinion 4/2007 on the concept of personal data established foundational interpretive guidance:
For each system, catalogue every data element collected, stored, or processed. Record:
For each data element, document the assessment against Art. 4(1):
For elements not clearly personal or non-personal:
Apply classification labels:
PERSONAL_DIRECT: Directly identifies a natural personPERSONAL_INDIRECT: Indirectly identifies through combination or third-party dataSPECIAL_CATEGORY: Art. 9 special category personal dataPSEUDONYMISED: Personal data with re-identification key separatedANONYMISED: Verified anonymous data (not personal data)NON_PERSONAL: Not personal data under any reasonable assessmentBORDERLINE_REVIEW: Requires periodic reassessmentspecial-category-data skill© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/personal-data-test of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Personal Data Test next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Personal Data Test this skillmukul975/Privacy-Data-Protection-Skills | 295 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 586 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 942 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 942 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
mukul975/Privacy-Data-Protection-Skills
Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.
Categories
Classifies personal vs non-personal data per GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills. Personal Data Test is an agent skill from mukul975/Privacy-Data-Protection-Skills. Classifies personal vs non-personal data per GDPR Art.
Personal Data Test fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill personal-data-test -a claude-code`. Or copy the skill folder (skills/privacy/personal-data-test in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/personal-data-test in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill personal-data-test -a codex`. Or copy the skill folder (skills/privacy/personal-data-test in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/personal-data-test in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill personal-data-test -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/personal-data-test, .gemini/skills/personal-data-test, .github/skills/personal-data-test and .opencode/skills/personal-data-test in your project.
Going by SKILL.md and its folder, Personal Data Test needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Personal Data Test is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Personal Data Test: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.