Agent skill

Privacy Maturity Model

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized.

Apache-2.0Auto-check passedLegal & Compliance

Install Privacy Maturity Model

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-maturity-model --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/privacy-maturity-model .claude/skills/privacy-maturity-model && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
privacy-maturity-model
GitHub stars
297
Token cost
~5.9k tokens
SKILL.md length
2,416 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized.

  • Works in 5 steps: Assessment Planning → Domain Assessment Workshops → Scoring → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Five Maturity Levels, Ten Privacy Domains and Assessment Methodology, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Privacy Maturity Model is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized. Covers assessment methodology across ten privacy domains, scoring criteria, gap analysis, maturity roadmap generation, and benchmarking against industry peers. Keywords: privacy maturity, AICPA, maturity model, assessment, roadmap, benchmarking.

Its SKILL.md is about 5.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the privacy-maturity-model skill to guide privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad…”
  • “/privacy-maturity-model”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Assessment Planning
  2. Domain Assessment Workshops
  3. Scoring
  4. Maturity Profile Visualization
  5. Gap Analysis and Roadmap Generation

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Privacy Maturity Model loads about 5.9k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 2,416 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~5.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,416 words, ~5,863 tokens.

Download SKILL.mdSave it as .claude/skills/privacy-maturity-model/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
privacy-maturity-model
description
Guides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized. Covers assessment methodology across ten privacy domains, scoring criteria, gap analysis, maturity roadmap generation, and benchmarking against industry peers. Keywords: privacy maturity, AICPA, maturity model, assessment, roadmap, benchmarking.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-audit-certification
metadata.tags
privacy-maturity, aicpa, maturity-model, assessment, roadmap, benchmarking

Privacy Maturity Model Assessment

Overview

A privacy maturity model provides a structured framework for assessing the current state of an organization's privacy program, identifying gaps, and creating a prioritized roadmap for improvement. The model measures privacy capabilities across multiple domains on a scale from ad hoc (reactive, undocumented) to optimized (proactive, continuously improving, industry-leading).

This skill implements a privacy maturity model based on the AICPA Generally Accepted Privacy Principles (GAPP) maturity framework, adapted with elements from the NIST Privacy Framework, ISO 27701, and the IAPP's operational privacy program model. The model assesses ten privacy domains across five maturity levels, producing a quantitative maturity score, a visual maturity profile, and a prioritized improvement roadmap.

Sentinel Compliance Group uses this maturity model to conduct annual self-assessments, set board-level privacy targets, and benchmark against industry peers in the SaaS and professional services sectors.

Five Maturity Levels

Level 1: Ad Hoc
CharacteristicDescription
Process StateNo defined privacy processes; activities are reactive and inconsistent
DocumentationLittle to no privacy documentation; policies may be absent or outdated
AccountabilityNo designated privacy role; responsibilities are unclear
Risk ManagementPrivacy risks are not systematically identified or assessed
ComplianceCompliance is coincidental rather than planned
Incident ResponseBreaches are handled on an ad hoc basis without defined procedures
TrainingNo formal privacy training program
MetricsNo privacy metrics collected or reported

Indicators: Organization has experienced privacy complaints or incidents with no structured response; no privacy policy or a generic template not tailored to actual practices; no records of processing activities; GDPR/CCPA obligations acknowledged but not systematically addressed.

Level 2: Repeating
CharacteristicDescription
Process StateBasic privacy processes exist and are followed for major activities but are not fully documented
DocumentationCore privacy documents exist (privacy policy, basic procedures) but may be incomplete or inconsistent
AccountabilityPrivacy responsibilities assigned to an individual but not formalized as a dedicated role
Risk ManagementPrivacy risks are considered for major projects but no systematic assessment methodology
ComplianceKey regulatory requirements are identified and basic compliance activities are in place
Incident ResponseBasic incident response procedures exist but are not regularly tested
TrainingAd hoc privacy training delivered to some staff
MetricsBasic metrics tracked (number of DSARs, incidents) but not systematically reported

Indicators: Privacy policy exists and is published; DSARs are processed but without formal tracking; DPIAs are conducted for major projects but not consistently; some vendor privacy assessments performed but no systematic program.

Level 3: Defined
CharacteristicDescription
Process StatePrivacy processes are documented, standardized, and consistently followed across the organization
DocumentationComprehensive privacy documentation including policies, procedures, standards, and guidelines
AccountabilityDedicated DPO or CPO role; privacy governance structure with defined roles and responsibilities
Risk ManagementSystematic privacy risk assessment methodology applied to all processing activities
ComplianceMulti-jurisdictional compliance program with regulatory tracking and gap analysis
Incident ResponseDocumented breach response plan with defined roles, tested at least annually
TrainingFormal privacy training program with role-based curricula and completion tracking
MetricsPrivacy KPIs defined and reported to management quarterly

Indicators: Records of processing activities maintained and current; DPIAs conducted using a consistent methodology; formal DSAR workflow with SLA tracking; privacy committee meets regularly; vendor privacy program covers all processors.

Level 4: Managed
CharacteristicDescription
Process StatePrivacy processes are measured, controlled, and predictable; quantitative management techniques used
DocumentationLiving documents with version control, regular review cycles, and stakeholder approval workflows
AccountabilityPrivacy function with dedicated staff, budget, and executive sponsorship; board-level reporting
Risk ManagementQuantitative privacy risk management with risk registers, risk appetite statements, and residual risk tracking
ComplianceAutomated compliance monitoring, continuous regulatory tracking, proactive gap remediation
Incident ResponseMature incident response with tabletop exercises, post-incident reviews, and continuous improvement
TrainingAdvanced training program with effectiveness measurement, phishing simulations, and privacy champion network
MetricsComprehensive privacy dashboards with leading and lagging indicators, benchmarking, and trend analysis

Indicators: Privacy by design integrated into SDLC; automated DSAR fulfillment; real-time privacy compliance dashboards; privacy impact assessments conducted for all changes; privacy engineering function established.

Level 5: Optimized
CharacteristicDescription
Process StateContinuous improvement driven by innovation, industry leadership, and anticipation of future requirements
DocumentationDynamically maintained knowledge base with AI-assisted review and update recommendations
AccountabilityPrivacy function is a strategic business partner; CPO reports to CEO/Board; privacy embedded in business strategy
Risk ManagementPredictive privacy risk analytics; threat intelligence integration; proactive risk mitigation
ComplianceOrganization shapes industry standards and regulatory guidance; active participation in codes of conduct and certification schemes
Incident ResponseNear-zero breach occurrence; automated detection and containment; industry benchmark for incident response
TrainingCulture of privacy; employees are privacy advocates; continuous learning integrated into daily work
MetricsPredictive analytics; privacy program ROI quantified; benchmarking demonstrates industry leadership

Indicators: Organization participates in regulatory consultations; privacy innovations published; zero-knowledge architectures implemented; privacy enhancing technologies deployed at scale; recognized as industry leader.

Ten Privacy Domains

Domain 1: Privacy Governance

Assessment Areas:

  • Privacy organizational structure and reporting lines
  • Privacy committee or board charter and meeting cadence
  • Privacy strategy and annual objectives
  • Budget allocation for privacy function
  • Executive sponsorship and board reporting
  • Integration with enterprise risk management

Maturity Criteria:

LevelCriteria
1 - Ad HocNo formal governance; privacy handled reactively by IT or legal
2 - RepeatingPrivacy contact designated; informal reporting to management
3 - DefinedDPO/CPO appointed; privacy committee chartered; quarterly reporting
4 - ManagedPrivacy function with dedicated staff and budget; board-level reporting; KPIs tracked
5 - OptimizedCPO is C-suite member; privacy integrated into business strategy; predictive governance
Domain 2: Data Inventory and Mapping

Assessment Areas:

  • Personal data inventory completeness and accuracy
  • Data flow mapping (internal, third-party, cross-border)
  • Records of processing activities (RoPA)
  • Automated data discovery capabilities
  • Data lineage tracking
  • Classification of data by sensitivity and regulatory requirement

Maturity Criteria:

LevelCriteria
1 - Ad HocNo data inventory; ad hoc knowledge of personal data locations
2 - RepeatingPartial inventory in spreadsheets; major systems covered
3 - DefinedComplete RoPA covering all processing activities; data flow diagrams maintained
4 - ManagedAutomated data discovery tools; real-time data inventory; data lineage tracked
5 - OptimizedAI-driven data classification; continuous discovery; automated RoPA generation
Domain 3: Privacy Risk Management

Assessment Areas:

  • Privacy risk assessment methodology
  • Privacy impact assessment (PIA/DPIA) program
  • Risk register maintenance and review
  • Residual risk tracking and acceptance
  • Integration with information security risk management
  • Vendor privacy risk assessments

Maturity Criteria:

LevelCriteria
1 - Ad HocNo systematic risk identification; risks discovered through incidents
2 - RepeatingRisk assessments for major projects; informal risk tracking
3 - DefinedStandardized DPIA methodology; risk register maintained; vendor assessments
4 - ManagedQuantitative risk scoring; residual risk dashboards; automated risk monitoring
5 - OptimizedPredictive risk analytics; threat intelligence; proactive risk mitigation
Domain 4: Regulatory Compliance

Assessment Areas:

  • Regulatory applicability assessment
  • Compliance gap analysis and remediation
  • Regulatory change management
  • Multi-jurisdictional compliance coordination
  • Supervisory authority engagement
  • Enforcement monitoring and lessons learned

Maturity Criteria:

LevelCriteria
1 - Ad HocLimited awareness of applicable regulations; no compliance tracking
2 - RepeatingKey regulations identified; basic compliance efforts underway
3 - DefinedComprehensive compliance matrix; gap analysis; regulatory tracker
4 - ManagedAutomated compliance monitoring; proactive gap remediation; regulatory change management
5 - OptimizedOrganization contributes to regulatory development; anticipates regulatory trends
Domain 5: Data Subject Rights

Assessment Areas:

  • DSAR intake and fulfillment processes
  • Identity verification procedures
  • Response timeliness and quality
  • Automated vs. manual fulfillment
  • Cross-system data retrieval capabilities
  • Complaint handling and escalation

Maturity Criteria:

LevelCriteria
1 - Ad HocDSARs handled reactively with no tracking; inconsistent responses
2 - RepeatingBasic DSAR process; manual tracking; generally meets deadlines
3 - DefinedFormal DSAR workflow with SLA tracking; identity verification; quality review
4 - ManagedSemi-automated fulfillment; real-time tracking; metrics-driven improvement
5 - OptimizedFully automated self-service DSAR portal; instant fulfillment for most request types

Assessment Areas:

  • Lawful basis determination and documentation
  • Consent collection, recording, and withdrawal mechanisms
  • Cookie and tracking consent management
  • Consent preference centers
  • Legitimate interest assessments
  • Purpose limitation enforcement

Maturity Criteria:

LevelCriteria
1 - Ad HocLawful basis not documented; consent collection inconsistent
2 - RepeatingLawful basis identified for major processing; basic consent forms
3 - DefinedLawful basis documented for all processing; CMP deployed; LIA process defined
4 - ManagedCentralized consent management; automated preference enforcement; audit trails
5 - OptimizedDynamic consent with granular controls; real-time purpose limitation enforcement
Domain 7: Third-Party Management

Assessment Areas:

  • Processor and sub-processor inventory
  • Data processing agreement management
  • Vendor privacy due diligence and risk assessments
  • Ongoing vendor monitoring
  • Sub-processor change management
  • Vendor incident management

Maturity Criteria:

LevelCriteria
1 - Ad HocNo processor inventory; DPAs missing or incomplete
2 - RepeatingKey processors identified; DPAs in place for major vendors
3 - DefinedComplete processor register; standardized DPA templates; vendor assessments
4 - ManagedContinuous vendor monitoring; automated DPA lifecycle management; risk scoring
5 - OptimizedReal-time vendor risk monitoring; automated sub-processor change management
Show full SKILL.md (972 more words)Show less
Domain 8: Incident Management

Assessment Areas:

  • Breach detection capabilities
  • Breach assessment and classification procedures
  • Notification procedures (DPA, data subjects, contractual)
  • Investigation and forensics capabilities
  • Post-incident remediation and improvement
  • Breach simulation exercises

Maturity Criteria:

LevelCriteria
1 - Ad HocNo breach detection; incidents discovered accidentally; no response plan
2 - RepeatingBasic incident response plan; some detection capabilities
3 - DefinedDocumented breach response plan; defined roles; notification templates; annual testing
4 - ManagedAutomated detection and triage; rehearsed response; post-incident reviews; metrics
5 - OptimizedNear-zero breach occurrence; automated containment; industry benchmark
Domain 9: Privacy by Design

Assessment Areas:

  • Integration of privacy into SDLC/project lifecycle
  • Privacy requirements in system design
  • Data minimization practices
  • Pseudonymization and anonymization capabilities
  • Privacy enhancing technologies (PETs) deployment
  • Default privacy settings

Maturity Criteria:

LevelCriteria
1 - Ad HocPrivacy not considered in design; retrofitted when issues arise
2 - RepeatingPrivacy considered for major projects; some design review
3 - DefinedPrivacy integrated into SDLC gates; PTA for all projects; minimization standards
4 - ManagedPrivacy engineering function; PETs deployed; automated privacy testing
5 - OptimizedZero-knowledge architectures; privacy innovation; industry-leading PET deployment
Domain 10: Training and Awareness

Assessment Areas:

  • General privacy awareness training
  • Role-based specialized training
  • Training effectiveness measurement
  • Privacy champion/ambassador program
  • Awareness campaigns and communications
  • Culture measurement

Maturity Criteria:

LevelCriteria
1 - Ad HocNo formal training; occasional ad hoc awareness
2 - RepeatingAnnual general training; completion tracked for some staff
3 - DefinedRole-based training curricula; annual training for all staff; completion tracked
4 - ManagedTraining effectiveness measured; privacy champions network; targeted campaigns
5 - OptimizedCulture of privacy; continuous learning; employees as privacy advocates

Assessment Methodology

Step 1: Assessment Planning
  1. Define the assessment scope (entire organization or specific business units)
  2. Identify assessment participants (domain owners, subject matter experts)
  3. Schedule assessment workshops (one per domain, 90 minutes each)
  4. Distribute pre-assessment questionnaires to domain owners
  5. Gather existing documentation and evidence for each domain
Step 2: Domain Assessment Workshops

For each of the ten domains, conduct a structured assessment workshop:

Workshop Structure (90 minutes):

PhaseDurationActivity
Context Setting10 minReview domain scope and maturity level definitions
Current State30 minDomain owner presents current capabilities, evidence, and challenges
Evidence Review20 minAssessor reviews documentation and asks clarifying questions
Maturity Rating20 minCollaborative rating using maturity criteria; consensus building
Gap Discussion10 minIdentify priority gaps and quick wins
Step 3: Scoring
Individual Domain Scoring

Each domain is scored on a 1.0 to 5.0 scale with 0.5 increments:

ScoreInterpretation
1.0Fully Ad Hoc — no defined processes
1.5Predominantly Ad Hoc with some repeatable elements
2.0Fully Repeating — basic processes exist
2.5Predominantly Repeating with some defined elements
3.0Fully Defined — processes are standardized and documented
3.5Predominantly Defined with some managed elements
4.0Fully Managed — processes are measured and controlled
4.5Predominantly Managed with some optimized elements
5.0Fully Optimized — continuous improvement, industry leadership
Overall Maturity Score

The overall maturity score is calculated as the weighted average of domain scores:

DomainWeightRationale
Privacy Governance15%Foundation for all other domains
Data Inventory and Mapping10%Essential for compliance with transparency and RoPA obligations
Privacy Risk Management15%Core accountability mechanism
Regulatory Compliance10%Legal obligation fulfillment
Data Subject Rights10%Direct impact on data subject trust
Consent and Lawful Basis10%Foundational processing legitimacy
Third-Party Management10%Supply chain privacy risk
Incident Management5%Breach impact mitigation
Privacy by Design10%Long-term privacy sustainability
Training and Awareness5%Human factor in privacy
Overall Maturity Rating
Score RangeRatingInterpretation
1.0 — 1.9InitialSignificant privacy risk; immediate action required
2.0 — 2.4DevelopingBasic capabilities; substantial gaps remain
2.5 — 2.9EmergingProgressing toward defined program; key gaps exist
3.0 — 3.4EstablishedSolid foundation; opportunities for optimization
3.5 — 3.9AdvancedStrong program; moving toward quantitative management
4.0 — 4.4LeadingMature program; quantitatively managed
4.5 — 5.0ExemplaryIndustry-leading; continuous innovation
Step 4: Maturity Profile Visualization

Generate a radar chart (spider diagram) showing the maturity score for each domain:

                    Privacy Governance (3.5)
                          *
                    /           \
   Training (3.0) *             * Data Inventory (3.0)
                 /                 \
    PbD (2.5)  *                   * Risk Management (3.5)
                 \                 /
   Incident (3.0)*               * Regulatory (3.0)
                   \             /
   Third-Party (2.5)*         * Data Subject Rights (3.5)
                      \     /
                       *
                Consent (3.0)
Step 5: Gap Analysis and Roadmap Generation
Gap Prioritization Matrix

For each domain where the current score is below the target score:

DomainCurrentTargetGapPriorityEffortQuick Win?
Privacy by Design2.53.51.0HighHighNo
Third-Party Management2.53.51.0HighMediumPartial
Data Inventory3.04.01.0MediumHighNo
Consent3.03.50.5MediumLowYes
Training3.03.50.5LowLowYes
Roadmap Generation
Phase 1: Quick Wins (0-3 months)
  - Enhance consent management with preference center (Consent: 3.0 → 3.5)
  - Deploy role-based training curriculum (Training: 3.0 → 3.5)
  - Formalize vendor assessment templates (Third-Party: 2.5 → 3.0)

Phase 2: Foundation Building (3-6 months)
  - Integrate privacy into SDLC gates (PbD: 2.5 → 3.0)
  - Deploy automated data discovery (Data Inventory: 3.0 → 3.5)
  - Implement continuous vendor monitoring (Third-Party: 3.0 → 3.5)

Phase 3: Maturation (6-12 months)
  - Establish privacy engineering function (PbD: 3.0 → 3.5)
  - Deploy automated compliance monitoring (Regulatory: 3.0 → 3.5)
  - Implement quantitative risk management (Risk: 3.5 → 4.0)

Phase 4: Optimization (12-18 months)
  - Deploy real-time data inventory (Data Inventory: 3.5 → 4.0)
  - Automate DSAR fulfillment (Data Subject Rights: 3.5 → 4.0)
  - Implement predictive risk analytics (Risk: 4.0 → 4.5)

Benchmarking

Industry Benchmarks (2024 Survey Data)
DomainFinancial ServicesHealthcareTechnology/SaaSRetail
Privacy Governance3.53.03.02.5
Data Inventory3.02.53.52.0
Risk Management3.53.03.02.5
Regulatory Compliance3.53.53.02.5
Data Subject Rights3.02.53.52.5
Consent3.02.53.53.0
Third-Party Management3.02.53.02.0
Incident Management3.53.03.52.5
Privacy by Design2.52.03.02.0
Training3.03.02.52.0
Overall3.12.83.12.3
Peer Comparison

For meaningful benchmarking, compare against organizations with similar:

  • Industry sector and sub-sector
  • Company size (revenue, employees, customers)
  • Geographic operating scope
  • Regulatory exposure (number of jurisdictions)
  • Processing complexity (volume and sensitivity of data)

Sentinel Compliance Group Maturity Assessment Results

Assessment Date: October 2024 Assessor: Internal Privacy Audit team with external validation by KPMG Privacy Advisory

Domain2022 Score2023 Score2024 Score2025 Target
Privacy Governance2.53.03.54.0
Data Inventory2.02.53.03.5
Risk Management2.53.03.54.0
Regulatory Compliance2.53.03.03.5
Data Subject Rights2.03.03.54.0
Consent2.02.53.03.5
Third-Party Management2.02.52.53.5
Incident Management2.53.03.03.5
Privacy by Design1.52.02.53.5
Training2.02.53.03.5
Overall Weighted2.22.73.13.6

Overall Rating: Established (3.1), up from Emerging (2.7) in 2023 Board Target: Achieve Advanced (3.5+) by end of 2025 Key Improvement Areas for 2025: Third-Party Management (+1.0), Privacy by Design (+1.0), Regulatory Compliance (+0.5)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/privacy-maturity-model of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Privacy Maturity Model next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Privacy Maturity Model compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Privacy Maturity Model this skillmukul975/Privacy-Data-Protection-Skills297—~5.9kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    297 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    297 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    297 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Privacy Maturity Model

What does Privacy Maturity Model do?

Guides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized. Privacy Maturity Model is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized.

When should I use Privacy Maturity Model?

Privacy Maturity Model fits situations like: tasks that involve Privacy and GDPR.

How do I install Privacy Maturity Model in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a claude-code`. Or copy the skill folder (skills/privacy/privacy-maturity-model in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/privacy-maturity-model in your project. Claude Code loads it when a task matches its description.

How do I install Privacy Maturity Model in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a codex`. Or copy the skill folder (skills/privacy/privacy-maturity-model in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/privacy-maturity-model in your project. Codex loads it when a task matches its description.

Can I use Privacy Maturity Model in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-maturity-model, .gemini/skills/privacy-maturity-model, .github/skills/privacy-maturity-model and .opencode/skills/privacy-maturity-model in your project.

What does Privacy Maturity Model need to run?

Going by SKILL.md and its folder, Privacy Maturity Model needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Privacy Maturity Model access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Privacy Maturity Model safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Privacy Maturity Model use?

Privacy Maturity Model is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Privacy Maturity Model use?

About 5.9k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 945 tokens, read only when the agent opens those files.

What are the alternatives to Privacy Maturity Model?

Skills that share tags, products or a category with Privacy Maturity Model: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Privacy Maturity Model?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.