Agent skill

Regulatory Complaints

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Manages responses to regulatory complaints lodged with supervisory authorities under GDPR Article 77, covering internal escalation procedures, DPA response coordination, remediation tracking, and…

Apache-2.0Auto-check passedLegal & Compliance

Install Regulatory Complaints

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill regulatory-complaints -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills regulatory-complaints --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/regulatory-complaints .claude/skills/regulatory-complaints && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
regulatory-complaints
GitHub stars
301
Token cost
~2k tokens
SKILL.md length
975 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manages responses to regulatory complaints lodged with supervisory authorities under GDPR Article 77, covering internal escalation procedures, DPA response coordination, remediation tracking, and…

  • Works in 8 steps: Receive and Log the Complaint → Internal Escalation → Internal Investigation → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Legal Foundation, Regulatory Complaint Response… and DPA-Specific Response…
  • Runs Python scripts from its folder

What it does

Regulatory Complaints is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages responses to regulatory complaints lodged with supervisory authorities under GDPR Article 77, covering internal escalation procedures, DPA response coordination, remediation tracking, and compliance documentation. Activate for regulatory complaint, supervisory authority complaint, Art. 77, DPA response, ICO complaint queries.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Regulatory compliance. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Regulatory compliance

Example prompts

  • “Use the regulatory-complaints skill to manage responses to regulatory complaints lodged with supervisory authorities under GDPR Article 77, covering…”
  • “/regulatory-complaints”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Receive and Log the Complaint
  2. Internal Escalation
  3. Internal Investigation
  4. Prepare the Response
  5. DPO Review and Approval
  6. Remediation Tracking
  7. DPA Decision and Follow-Up
  8. Close and Record

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Regulatory Complaints loads about 2k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 975 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 975 words, ~2,003 tokens.

Download SKILL.mdSave it as .claude/skills/regulatory-complaints/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
regulatory-complaints
description
Manages responses to regulatory complaints lodged with supervisory authorities under GDPR Article 77, covering internal escalation procedures, DPA response coordination, remediation tracking, and compliance documentation. Activate for regulatory complaint, supervisory authority complaint, Art. 77, DPA response, ICO complaint queries.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-subject-rights
metadata.tags
regulatory-complaint, gdpr-article-77, supervisory-authority, dpa-response, ico-complaint

Responding to Regulatory Complaints

Overview

Under GDPR Article 77, data subjects have the right to lodge a complaint with a supervisory authority (Data Protection Authority / DPA) if they consider that the processing of their personal data infringes the GDPR. When a DPA receives a complaint and contacts the controller, the controller must respond promptly, cooperate fully, and demonstrate compliance. This skill provides the operational procedure for managing regulatory complaints from receipt through resolution.

GDPR Article 77 — Right to Lodge a Complaint

Every data subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement, if the data subject considers that the processing of personal data relating to them infringes the GDPR.

GDPR Article 31 — Cooperation with the Supervisory Authority

The controller and the processor, and where applicable the controller's or the processor's representative, shall cooperate, on request, with the supervisory authority in the performance of its tasks.

GDPR Article 58 — Powers of Supervisory Authorities

Supervisory authorities have investigative powers (Art. 58(1)), corrective powers (Art. 58(2)), and authorisation and advisory powers (Art. 58(3)), including the power to:

  • Order the controller to provide information (Art. 58(1)(a))
  • Carry out investigations in the form of data protection audits (Art. 58(1)(b))
  • Issue warnings, reprimands, and orders (Art. 58(2)(a)-(d))
  • Impose administrative fines (Art. 58(2)(i) and Art. 83)
GDPR Article 78 — Right to an Effective Judicial Remedy Against a Supervisory Authority

Data subjects (and controllers) have the right to an effective judicial remedy against legally binding decisions of a supervisory authority.

Regulatory Complaint Response Workflow

Step 1: Receive and Log the Complaint
  1. Log the complaint with reference REG-YYYY-NNNN.
  2. Record:
    • Supervisory authority (e.g., ICO, CNIL, BfDI, DPC)
    • DPA reference number
    • Date of DPA correspondence
    • Complainant identity (if disclosed by the DPA)
    • Summary of the complaint allegations
    • DPA's specific requests or questions
    • Response deadline set by the DPA
  3. Immediately notify the Data Protection Officer.
  4. Escalate to the General Counsel if the complaint involves potential enforcement action or fines.
Step 2: Internal Escalation
Complaint SeverityEscalation LevelResponse LeadTimeline
Routine (individual rights exercise issue)DPOPrivacy AnalystDPA deadline (typically 28 days)
Significant (systemic compliance issue)DPO + General CounselDPODPA deadline, with internal briefing within 48 hours
Critical (potential enforcement/fine)DPO + General Counsel + CEODPO + External CounselDPA deadline, with board notification within 24 hours
Step 3: Internal Investigation
  1. Review the complaint allegations against internal records:
    • DSAR/rights request register (was the request handled correctly?)
    • Processing records (Art. 30 register)
    • Consent records
    • Data breach register
    • Privacy impact assessments
  2. Interview relevant staff members and document their accounts.
  3. Collect all supporting evidence (emails, system logs, decision records).
  4. Identify any compliance gaps or procedural failures.
  5. Assess whether the complaint is substantiated, partially substantiated, or unsubstantiated.
Step 4: Prepare the Response

The DPA response must be:

  • Factual: Address each specific allegation or question raised by the DPA.
  • Evidenced: Attach supporting documentation.
  • Cooperative: Demonstrate willingness to engage per Art. 31.
  • Proportionate: Address the complaint scope without volunteering unrelated issues.
Response Structure
  1. Acknowledgement: Confirm receipt of the DPA's correspondence, cite the DPA reference number.
  2. Background: Provide a brief factual overview of the processing activity and the controller's relationship with the complainant.
  3. Response to each allegation: Address each point raised by the DPA with facts and evidence.
  4. Compliance evidence: Attach relevant documentation (privacy notice, consent records, DSAR response copies, DPIAs, processing records).
  5. Remediation: If any issue is identified, describe the remediation steps taken or planned, with timelines.
  6. Cooperation: Confirm willingness to provide any further information the DPA requires.
Show full SKILL.md (366 more words)Show less
Step 5: DPO Review and Approval
  1. The DPO reviews the draft response for accuracy and completeness.
  2. If the complaint involves potential enforcement, external legal counsel reviews the response.
  3. Obtain sign-off from the appropriate authority level per Step 2.
  4. Submit the response to the DPA before the deadline.
Step 6: Remediation Tracking

If the investigation identifies compliance gaps:

  1. Create remediation actions with:
    • Description of the gap
    • Root cause analysis
    • Corrective action
    • Owner (name and role)
    • Target completion date
    • Verification method
  2. Track remediation in the compliance action tracker.
  3. Report progress to the DPO monthly until all actions are closed.
  4. Include remediation status in the next DPA communication if the DPA follows up.
Step 7: DPA Decision and Follow-Up
DPA OutcomeController Action
Complaint dismissed / no further actionFile and close. Update complaint register.
Informal resolution recommendedImplement DPA's recommendations. Confirm completion to DPA.
Formal reprimand issued (Art. 58(2)(b))Record on compliance register. Implement required changes. Report to board.
Order to comply issued (Art. 58(2)(c)-(g))Implement the order within the specified timeframe. Confirm compliance to DPA.
Administrative fine imposed (Art. 83)Engage external legal counsel. Assess appeal options (Art. 78). Pay or appeal within deadline.
Investigation initiatedCooperate fully. Appoint response team. Preserve all relevant records.
Step 8: Close and Record
  1. Update the complaint register with the final outcome.
  2. Record any lessons learned.
  3. Feed findings into the compliance improvement programme.
  4. Retain all complaint documentation for 6 years from the date of the DPA's final decision.
  5. Report complaint outcomes in the annual privacy compliance report to the board.

DPA-Specific Response Requirements

ICO (United Kingdom)
  • The ICO typically sends a preliminary enquiry letter requesting the controller's account of events.
  • Standard response timeframe: 28 calendar days.
  • Correspondence via the ICO's online case management portal or email.
  • The ICO may request a formal response under section 142 of the Data Protection Act 2018 (assessment notice).
CNIL (France)
  • Initial questionnaire or formal mise en demeure.
  • Response timeframe specified in the correspondence (typically 1-3 months).
  • Formal responses must be in French.
DPC (Ireland)
  • Relevant for organisations with main establishment in Ireland (one-stop-shop mechanism under Art. 56).
  • Response timeframe specified in the correspondence.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/regulatory-complaints of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Regulatory Complaints next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Regulatory Complaints compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Regulatory Complaints this skillmukul975/Privacy-Data-Protection-Skills301—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
Regulatory Audit Generatorzebbern/claude-code-guide4.7k1 repos~3.5kAutomated safety check: PassMIT
Reg Gap Analysisanthropics/claude-for-legal9.6k2 repos~2.6kAutomated safety check: PassApache-2.0
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Compliance Checkjosstei/maestro-orchestrate465—~237Automated safety check: PassApache-2.0

Similar skills

  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Regulatory Audit Generator

    zebbern/claude-code-guide

    Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws.

    4.7k GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Reg Gap Analysis

    anthropics/claude-for-legal

    Official

    Diff a new or changed regulation against current privacy policy and practice — outputs a gap list and a remediation plan with owners and dates.

    9.6k GitHub starsUsed in 2 repos~2.6k tokens
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Compliance Check

    josstei/maestro-orchestrate

    Run a Maestro-style regulatory compliance review for GDPR/CCPA, cookie consent, data handling, and licensing

    465 GitHub stars~237 tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Regulatory Complaints

What does Regulatory Complaints do?

Manages responses to regulatory complaints lodged with supervisory authorities under GDPR Article 77, covering internal escalation procedures, DPA response coordination, remediation tracking, and…. Regulatory Complaints is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages responses to regulatory complaints lodged with supervisory authorities under GDPR Article 77, covering internal escalation procedures, DPA response coordination, remediation tracking, and compliance documentation.

When should I use Regulatory Complaints?

Regulatory Complaints fits situations like: tasks that involve Privacy and GDPR; tasks that involve Regulatory compliance.

How do I install Regulatory Complaints in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill regulatory-complaints -a claude-code`. Or copy the skill folder (skills/privacy/regulatory-complaints in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/regulatory-complaints in your project. Claude Code loads it when a task matches its description.

How do I install Regulatory Complaints in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill regulatory-complaints -a codex`. Or copy the skill folder (skills/privacy/regulatory-complaints in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/regulatory-complaints in your project. Codex loads it when a task matches its description.

Can I use Regulatory Complaints in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill regulatory-complaints -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/regulatory-complaints, .gemini/skills/regulatory-complaints, .github/skills/regulatory-complaints and .opencode/skills/regulatory-complaints in your project.

What does Regulatory Complaints need to run?

Going by SKILL.md and its folder, Regulatory Complaints needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Regulatory Complaints access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Regulatory Complaints safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Regulatory Complaints use?

Regulatory Complaints is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Regulatory Complaints use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Regulatory Complaints?

Skills that share tags, products or a category with Regulatory Complaints: Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Regulatory Audit Generator (zebbern/claude-code-guide, 4.7k stars), Reg Gap Analysis (anthropics/claude-for-legal, 9.6k stars) and Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Regulatory Complaints?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.