C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Guides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-maturity-model --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/privacy-maturity-model .claude/skills/privacy-maturity-model && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "privacy-maturity-model" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-maturity-model into .claude/skills/privacy-maturity-model/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-maturity-model", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-maturity-modelType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-maturity-model --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/privacy-maturity-model .agents/skills/privacy-maturity-model && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "privacy-maturity-model" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-maturity-model into .agents/skills/privacy-maturity-model/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-maturity-model", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-maturity-model --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/privacy-maturity-model .cursor/skills/privacy-maturity-model && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "privacy-maturity-model" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-maturity-model into .cursor/skills/privacy-maturity-model/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-maturity-model", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/privacy-maturity-model--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-maturity-model --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/privacy-maturity-model .gemini/skills/privacy-maturity-model && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "privacy-maturity-model" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-maturity-model into .gemini/skills/privacy-maturity-model/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-maturity-model", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-maturity-modelInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/privacy-maturity-model .github/skills/privacy-maturity-model && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "privacy-maturity-model" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-maturity-model into .github/skills/privacy-maturity-model/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-maturity-model", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-maturity-model --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/privacy-maturity-model .opencode/skills/privacy-maturity-model && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "privacy-maturity-model" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-maturity-model into .opencode/skills/privacy-maturity-model/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-maturity-model", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
privacy-maturity-modelGuides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized.
Privacy Maturity Model is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized. Covers assessment methodology across ten privacy domains, scoring criteria, gap analysis, maturity roadmap generation, and benchmarking against industry peers. Keywords: privacy maturity, AICPA, maturity model, assessment, roadmap, benchmarking.
Its SKILL.md is about 5.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Privacy Maturity Model loads about 5.9k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 2,416 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,416 words, ~5,863 tokens.
.claude/skills/privacy-maturity-model/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.A privacy maturity model provides a structured framework for assessing the current state of an organization's privacy program, identifying gaps, and creating a prioritized roadmap for improvement. The model measures privacy capabilities across multiple domains on a scale from ad hoc (reactive, undocumented) to optimized (proactive, continuously improving, industry-leading).
This skill implements a privacy maturity model based on the AICPA Generally Accepted Privacy Principles (GAPP) maturity framework, adapted with elements from the NIST Privacy Framework, ISO 27701, and the IAPP's operational privacy program model. The model assesses ten privacy domains across five maturity levels, producing a quantitative maturity score, a visual maturity profile, and a prioritized improvement roadmap.
Sentinel Compliance Group uses this maturity model to conduct annual self-assessments, set board-level privacy targets, and benchmark against industry peers in the SaaS and professional services sectors.
| Characteristic | Description |
|---|---|
| Process State | No defined privacy processes; activities are reactive and inconsistent |
| Documentation | Little to no privacy documentation; policies may be absent or outdated |
| Accountability | No designated privacy role; responsibilities are unclear |
| Risk Management | Privacy risks are not systematically identified or assessed |
| Compliance | Compliance is coincidental rather than planned |
| Incident Response | Breaches are handled on an ad hoc basis without defined procedures |
| Training | No formal privacy training program |
| Metrics | No privacy metrics collected or reported |
Indicators: Organization has experienced privacy complaints or incidents with no structured response; no privacy policy or a generic template not tailored to actual practices; no records of processing activities; GDPR/CCPA obligations acknowledged but not systematically addressed.
| Characteristic | Description |
|---|---|
| Process State | Basic privacy processes exist and are followed for major activities but are not fully documented |
| Documentation | Core privacy documents exist (privacy policy, basic procedures) but may be incomplete or inconsistent |
| Accountability | Privacy responsibilities assigned to an individual but not formalized as a dedicated role |
| Risk Management | Privacy risks are considered for major projects but no systematic assessment methodology |
| Compliance | Key regulatory requirements are identified and basic compliance activities are in place |
| Incident Response | Basic incident response procedures exist but are not regularly tested |
| Training | Ad hoc privacy training delivered to some staff |
| Metrics | Basic metrics tracked (number of DSARs, incidents) but not systematically reported |
Indicators: Privacy policy exists and is published; DSARs are processed but without formal tracking; DPIAs are conducted for major projects but not consistently; some vendor privacy assessments performed but no systematic program.
| Characteristic | Description |
|---|---|
| Process State | Privacy processes are documented, standardized, and consistently followed across the organization |
| Documentation | Comprehensive privacy documentation including policies, procedures, standards, and guidelines |
| Accountability | Dedicated DPO or CPO role; privacy governance structure with defined roles and responsibilities |
| Risk Management | Systematic privacy risk assessment methodology applied to all processing activities |
| Compliance | Multi-jurisdictional compliance program with regulatory tracking and gap analysis |
| Incident Response | Documented breach response plan with defined roles, tested at least annually |
| Training | Formal privacy training program with role-based curricula and completion tracking |
| Metrics | Privacy KPIs defined and reported to management quarterly |
Indicators: Records of processing activities maintained and current; DPIAs conducted using a consistent methodology; formal DSAR workflow with SLA tracking; privacy committee meets regularly; vendor privacy program covers all processors.
| Characteristic | Description |
|---|---|
| Process State | Privacy processes are measured, controlled, and predictable; quantitative management techniques used |
| Documentation | Living documents with version control, regular review cycles, and stakeholder approval workflows |
| Accountability | Privacy function with dedicated staff, budget, and executive sponsorship; board-level reporting |
| Risk Management | Quantitative privacy risk management with risk registers, risk appetite statements, and residual risk tracking |
| Compliance | Automated compliance monitoring, continuous regulatory tracking, proactive gap remediation |
| Incident Response | Mature incident response with tabletop exercises, post-incident reviews, and continuous improvement |
| Training | Advanced training program with effectiveness measurement, phishing simulations, and privacy champion network |
| Metrics | Comprehensive privacy dashboards with leading and lagging indicators, benchmarking, and trend analysis |
Indicators: Privacy by design integrated into SDLC; automated DSAR fulfillment; real-time privacy compliance dashboards; privacy impact assessments conducted for all changes; privacy engineering function established.
| Characteristic | Description |
|---|---|
| Process State | Continuous improvement driven by innovation, industry leadership, and anticipation of future requirements |
| Documentation | Dynamically maintained knowledge base with AI-assisted review and update recommendations |
| Accountability | Privacy function is a strategic business partner; CPO reports to CEO/Board; privacy embedded in business strategy |
| Risk Management | Predictive privacy risk analytics; threat intelligence integration; proactive risk mitigation |
| Compliance | Organization shapes industry standards and regulatory guidance; active participation in codes of conduct and certification schemes |
| Incident Response | Near-zero breach occurrence; automated detection and containment; industry benchmark for incident response |
| Training | Culture of privacy; employees are privacy advocates; continuous learning integrated into daily work |
| Metrics | Predictive analytics; privacy program ROI quantified; benchmarking demonstrates industry leadership |
Indicators: Organization participates in regulatory consultations; privacy innovations published; zero-knowledge architectures implemented; privacy enhancing technologies deployed at scale; recognized as industry leader.
Assessment Areas:
Maturity Criteria:
| Level | Criteria |
|---|---|
| 1 - Ad Hoc | No formal governance; privacy handled reactively by IT or legal |
| 2 - Repeating | Privacy contact designated; informal reporting to management |
| 3 - Defined | DPO/CPO appointed; privacy committee chartered; quarterly reporting |
| 4 - Managed | Privacy function with dedicated staff and budget; board-level reporting; KPIs tracked |
| 5 - Optimized | CPO is C-suite member; privacy integrated into business strategy; predictive governance |
Assessment Areas:
Maturity Criteria:
| Level | Criteria |
|---|---|
| 1 - Ad Hoc | No data inventory; ad hoc knowledge of personal data locations |
| 2 - Repeating | Partial inventory in spreadsheets; major systems covered |
| 3 - Defined | Complete RoPA covering all processing activities; data flow diagrams maintained |
| 4 - Managed | Automated data discovery tools; real-time data inventory; data lineage tracked |
| 5 - Optimized | AI-driven data classification; continuous discovery; automated RoPA generation |
Assessment Areas:
Maturity Criteria:
| Level | Criteria |
|---|---|
| 1 - Ad Hoc | No systematic risk identification; risks discovered through incidents |
| 2 - Repeating | Risk assessments for major projects; informal risk tracking |
| 3 - Defined | Standardized DPIA methodology; risk register maintained; vendor assessments |
| 4 - Managed | Quantitative risk scoring; residual risk dashboards; automated risk monitoring |
| 5 - Optimized | Predictive risk analytics; threat intelligence; proactive risk mitigation |
Assessment Areas:
Maturity Criteria:
| Level | Criteria |
|---|---|
| 1 - Ad Hoc | Limited awareness of applicable regulations; no compliance tracking |
| 2 - Repeating | Key regulations identified; basic compliance efforts underway |
| 3 - Defined | Comprehensive compliance matrix; gap analysis; regulatory tracker |
| 4 - Managed | Automated compliance monitoring; proactive gap remediation; regulatory change management |
| 5 - Optimized | Organization contributes to regulatory development; anticipates regulatory trends |
Assessment Areas:
Maturity Criteria:
| Level | Criteria |
|---|---|
| 1 - Ad Hoc | DSARs handled reactively with no tracking; inconsistent responses |
| 2 - Repeating | Basic DSAR process; manual tracking; generally meets deadlines |
| 3 - Defined | Formal DSAR workflow with SLA tracking; identity verification; quality review |
| 4 - Managed | Semi-automated fulfillment; real-time tracking; metrics-driven improvement |
| 5 - Optimized | Fully automated self-service DSAR portal; instant fulfillment for most request types |
Assessment Areas:
Maturity Criteria:
| Level | Criteria |
|---|---|
| 1 - Ad Hoc | Lawful basis not documented; consent collection inconsistent |
| 2 - Repeating | Lawful basis identified for major processing; basic consent forms |
| 3 - Defined | Lawful basis documented for all processing; CMP deployed; LIA process defined |
| 4 - Managed | Centralized consent management; automated preference enforcement; audit trails |
| 5 - Optimized | Dynamic consent with granular controls; real-time purpose limitation enforcement |
Assessment Areas:
Maturity Criteria:
| Level | Criteria |
|---|---|
| 1 - Ad Hoc | No processor inventory; DPAs missing or incomplete |
| 2 - Repeating | Key processors identified; DPAs in place for major vendors |
| 3 - Defined | Complete processor register; standardized DPA templates; vendor assessments |
| 4 - Managed | Continuous vendor monitoring; automated DPA lifecycle management; risk scoring |
| 5 - Optimized | Real-time vendor risk monitoring; automated sub-processor change management |
Assessment Areas:
Maturity Criteria:
| Level | Criteria |
|---|---|
| 1 - Ad Hoc | No breach detection; incidents discovered accidentally; no response plan |
| 2 - Repeating | Basic incident response plan; some detection capabilities |
| 3 - Defined | Documented breach response plan; defined roles; notification templates; annual testing |
| 4 - Managed | Automated detection and triage; rehearsed response; post-incident reviews; metrics |
| 5 - Optimized | Near-zero breach occurrence; automated containment; industry benchmark |
Assessment Areas:
Maturity Criteria:
| Level | Criteria |
|---|---|
| 1 - Ad Hoc | Privacy not considered in design; retrofitted when issues arise |
| 2 - Repeating | Privacy considered for major projects; some design review |
| 3 - Defined | Privacy integrated into SDLC gates; PTA for all projects; minimization standards |
| 4 - Managed | Privacy engineering function; PETs deployed; automated privacy testing |
| 5 - Optimized | Zero-knowledge architectures; privacy innovation; industry-leading PET deployment |
Assessment Areas:
Maturity Criteria:
| Level | Criteria |
|---|---|
| 1 - Ad Hoc | No formal training; occasional ad hoc awareness |
| 2 - Repeating | Annual general training; completion tracked for some staff |
| 3 - Defined | Role-based training curricula; annual training for all staff; completion tracked |
| 4 - Managed | Training effectiveness measured; privacy champions network; targeted campaigns |
| 5 - Optimized | Culture of privacy; continuous learning; employees as privacy advocates |
For each of the ten domains, conduct a structured assessment workshop:
Workshop Structure (90 minutes):
| Phase | Duration | Activity |
|---|---|---|
| Context Setting | 10 min | Review domain scope and maturity level definitions |
| Current State | 30 min | Domain owner presents current capabilities, evidence, and challenges |
| Evidence Review | 20 min | Assessor reviews documentation and asks clarifying questions |
| Maturity Rating | 20 min | Collaborative rating using maturity criteria; consensus building |
| Gap Discussion | 10 min | Identify priority gaps and quick wins |
Each domain is scored on a 1.0 to 5.0 scale with 0.5 increments:
| Score | Interpretation |
|---|---|
| 1.0 | Fully Ad Hoc — no defined processes |
| 1.5 | Predominantly Ad Hoc with some repeatable elements |
| 2.0 | Fully Repeating — basic processes exist |
| 2.5 | Predominantly Repeating with some defined elements |
| 3.0 | Fully Defined — processes are standardized and documented |
| 3.5 | Predominantly Defined with some managed elements |
| 4.0 | Fully Managed — processes are measured and controlled |
| 4.5 | Predominantly Managed with some optimized elements |
| 5.0 | Fully Optimized — continuous improvement, industry leadership |
The overall maturity score is calculated as the weighted average of domain scores:
| Domain | Weight | Rationale |
|---|---|---|
| Privacy Governance | 15% | Foundation for all other domains |
| Data Inventory and Mapping | 10% | Essential for compliance with transparency and RoPA obligations |
| Privacy Risk Management | 15% | Core accountability mechanism |
| Regulatory Compliance | 10% | Legal obligation fulfillment |
| Data Subject Rights | 10% | Direct impact on data subject trust |
| Consent and Lawful Basis | 10% | Foundational processing legitimacy |
| Third-Party Management | 10% | Supply chain privacy risk |
| Incident Management | 5% | Breach impact mitigation |
| Privacy by Design | 10% | Long-term privacy sustainability |
| Training and Awareness | 5% | Human factor in privacy |
| Score Range | Rating | Interpretation |
|---|---|---|
| 1.0 — 1.9 | Initial | Significant privacy risk; immediate action required |
| 2.0 — 2.4 | Developing | Basic capabilities; substantial gaps remain |
| 2.5 — 2.9 | Emerging | Progressing toward defined program; key gaps exist |
| 3.0 — 3.4 | Established | Solid foundation; opportunities for optimization |
| 3.5 — 3.9 | Advanced | Strong program; moving toward quantitative management |
| 4.0 — 4.4 | Leading | Mature program; quantitatively managed |
| 4.5 — 5.0 | Exemplary | Industry-leading; continuous innovation |
Generate a radar chart (spider diagram) showing the maturity score for each domain:
Privacy Governance (3.5)
*
/ \
Training (3.0) * * Data Inventory (3.0)
/ \
PbD (2.5) * * Risk Management (3.5)
\ /
Incident (3.0)* * Regulatory (3.0)
\ /
Third-Party (2.5)* * Data Subject Rights (3.5)
\ /
*
Consent (3.0)For each domain where the current score is below the target score:
| Domain | Current | Target | Gap | Priority | Effort | Quick Win? |
|---|---|---|---|---|---|---|
| Privacy by Design | 2.5 | 3.5 | 1.0 | High | High | No |
| Third-Party Management | 2.5 | 3.5 | 1.0 | High | Medium | Partial |
| Data Inventory | 3.0 | 4.0 | 1.0 | Medium | High | No |
| Consent | 3.0 | 3.5 | 0.5 | Medium | Low | Yes |
| Training | 3.0 | 3.5 | 0.5 | Low | Low | Yes |
Phase 1: Quick Wins (0-3 months)
- Enhance consent management with preference center (Consent: 3.0 → 3.5)
- Deploy role-based training curriculum (Training: 3.0 → 3.5)
- Formalize vendor assessment templates (Third-Party: 2.5 → 3.0)
Phase 2: Foundation Building (3-6 months)
- Integrate privacy into SDLC gates (PbD: 2.5 → 3.0)
- Deploy automated data discovery (Data Inventory: 3.0 → 3.5)
- Implement continuous vendor monitoring (Third-Party: 3.0 → 3.5)
Phase 3: Maturation (6-12 months)
- Establish privacy engineering function (PbD: 3.0 → 3.5)
- Deploy automated compliance monitoring (Regulatory: 3.0 → 3.5)
- Implement quantitative risk management (Risk: 3.5 → 4.0)
Phase 4: Optimization (12-18 months)
- Deploy real-time data inventory (Data Inventory: 3.5 → 4.0)
- Automate DSAR fulfillment (Data Subject Rights: 3.5 → 4.0)
- Implement predictive risk analytics (Risk: 4.0 → 4.5)| Domain | Financial Services | Healthcare | Technology/SaaS | Retail |
|---|---|---|---|---|
| Privacy Governance | 3.5 | 3.0 | 3.0 | 2.5 |
| Data Inventory | 3.0 | 2.5 | 3.5 | 2.0 |
| Risk Management | 3.5 | 3.0 | 3.0 | 2.5 |
| Regulatory Compliance | 3.5 | 3.5 | 3.0 | 2.5 |
| Data Subject Rights | 3.0 | 2.5 | 3.5 | 2.5 |
| Consent | 3.0 | 2.5 | 3.5 | 3.0 |
| Third-Party Management | 3.0 | 2.5 | 3.0 | 2.0 |
| Incident Management | 3.5 | 3.0 | 3.5 | 2.5 |
| Privacy by Design | 2.5 | 2.0 | 3.0 | 2.0 |
| Training | 3.0 | 3.0 | 2.5 | 2.0 |
| Overall | 3.1 | 2.8 | 3.1 | 2.3 |
For meaningful benchmarking, compare against organizations with similar:
Assessment Date: October 2024 Assessor: Internal Privacy Audit team with external validation by KPMG Privacy Advisory
| Domain | 2022 Score | 2023 Score | 2024 Score | 2025 Target |
|---|---|---|---|---|
| Privacy Governance | 2.5 | 3.0 | 3.5 | 4.0 |
| Data Inventory | 2.0 | 2.5 | 3.0 | 3.5 |
| Risk Management | 2.5 | 3.0 | 3.5 | 4.0 |
| Regulatory Compliance | 2.5 | 3.0 | 3.0 | 3.5 |
| Data Subject Rights | 2.0 | 3.0 | 3.5 | 4.0 |
| Consent | 2.0 | 2.5 | 3.0 | 3.5 |
| Third-Party Management | 2.0 | 2.5 | 2.5 | 3.5 |
| Incident Management | 2.5 | 3.0 | 3.0 | 3.5 |
| Privacy by Design | 1.5 | 2.0 | 2.5 | 3.5 |
| Training | 2.0 | 2.5 | 3.0 | 3.5 |
| Overall Weighted | 2.2 | 2.7 | 3.1 | 3.6 |
Overall Rating: Established (3.1), up from Emerging (2.7) in 2023 Board Target: Achieve Advanced (3.5+) by end of 2025 Key Improvement Areas for 2025: Third-Party Management (+1.0), Privacy by Design (+1.0), Regulatory Compliance (+0.5)
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/privacy-maturity-model of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Privacy Maturity Model next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Privacy Maturity Model this skillmukul975/Privacy-Data-Protection-Skills | 297 | — | ~5.9k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 586 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Guides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized. Privacy Maturity Model is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized.
Privacy Maturity Model fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a claude-code`. Or copy the skill folder (skills/privacy/privacy-maturity-model in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/privacy-maturity-model in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a codex`. Or copy the skill folder (skills/privacy/privacy-maturity-model in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/privacy-maturity-model in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-maturity-model -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-maturity-model, .gemini/skills/privacy-maturity-model, .github/skills/privacy-maturity-model and .opencode/skills/privacy-maturity-model in your project.
Going by SKILL.md and its folder, Privacy Maturity Model needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Privacy Maturity Model is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.9k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 945 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Privacy Maturity Model: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.