C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-schedule --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/retention-schedule .claude/skills/retention-schedule && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "retention-schedule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-schedule into .claude/skills/retention-schedule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-schedule", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-scheduleType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-schedule --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/retention-schedule .agents/skills/retention-schedule && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "retention-schedule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-schedule into .agents/skills/retention-schedule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-schedule", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-schedule --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/retention-schedule .cursor/skills/retention-schedule && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "retention-schedule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-schedule into .cursor/skills/retention-schedule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-schedule", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/retention-schedule--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-schedule --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/retention-schedule .gemini/skills/retention-schedule && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "retention-schedule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-schedule into .gemini/skills/retention-schedule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-schedule", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-scheduleInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/retention-schedule .github/skills/retention-schedule && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "retention-schedule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-schedule into .github/skills/retention-schedule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-schedule", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-schedule --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/retention-schedule .opencode/skills/retention-schedule && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "retention-schedule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/retention-schedule into .opencode/skills/retention-schedule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "retention-schedule", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
retention-scheduleDesigns and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.
Retention Schedule is an agent skill from mukul975/Privacy-Data-Protection-Skills. Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle. Maps data categories to retention periods with legal basis justification, regulatory minimum holding periods, and automated review triggers for schedule maintenance. Activate for retention policy, storage limitation, data lifecycle, retention period queries.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Retention Schedule loads about 3.3k tokens when it runs, and up to ~4.8k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 1,478 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,478 words, ~3,280 tokens.
.claude/skills/retention-schedule/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.A data retention schedule is the foundational governance document that specifies how long each category of personal data is retained, the legal basis for that retention period, and the triggers for review or deletion. GDPR Article 5(1)(e) establishes the storage limitation principle: personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. This skill provides the complete framework for building, maintaining, and enforcing a category-based retention schedule.
Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1), subject to implementation of appropriate technical and organisational measures.
Personal data should be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. Personal data should be processed only if the purpose of the processing could not reasonably be fulfilled by other means. In order to ensure that the personal data are not kept longer than necessary, time limits should be established by the controller for erasure or for a periodic review.
The controller shall provide the data subject with the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period.
Where possible, the envisaged time limits for erasure of the different categories of data must be recorded in the Records of Processing Activities.
Identify and categorize all personal data processed by the organization:
| Category ID | Data Category | Example Data Elements | Processing Purpose | Legal Basis (Art. 6) |
|---|---|---|---|---|
| CAT-001 | Employee HR Records | Name, address, NI number, salary, performance reviews | Employment administration | Art. 6(1)(b) Contract + Art. 6(1)(c) Legal obligation |
| CAT-002 | Customer Account Data | Name, email, phone, address, account preferences | Service delivery | Art. 6(1)(b) Contract |
| CAT-003 | Customer Transaction Records | Purchase history, payment details, invoices | Contract performance and legal obligation | Art. 6(1)(b) Contract + Art. 6(1)(c) Legal obligation |
| CAT-004 | Marketing Contact Data | Name, email, consent records, campaign interactions | Direct marketing | Art. 6(1)(a) Consent |
| CAT-005 | Website Analytics | IP address, device data, browsing behaviour, cookies | Website optimization | Art. 6(1)(f) Legitimate interest |
| CAT-006 | Job Applicant Data | CV, cover letter, interview notes, references | Recruitment | Art. 6(1)(b) Pre-contractual steps |
| CAT-007 | CCTV Footage | Video recordings of premises | Security and safety | Art. 6(1)(f) Legitimate interest |
| CAT-008 | Supplier Contact Data | Name, email, phone, company, contract terms | Vendor management | Art. 6(1)(b) Contract |
| CAT-009 | Customer Support Records | Tickets, correspondence, complaint records | Service delivery and quality | Art. 6(1)(b) Contract + Art. 6(1)(f) Legitimate interest |
| CAT-010 | Financial and Tax Records | Accounts, tax filings, audit reports, bank statements | Legal compliance | Art. 6(1)(c) Legal obligation |
For each data category, determine the retention period based on:
The following is the retention schedule for Orion Data Vault Corp:
| Category ID | Data Category | Retention Period | Legal Basis for Retention | Retention Trigger | Review Frequency |
|---|---|---|---|---|---|
| CAT-001 | Employee HR Records | Duration of employment + 6 years | Limitation Act 1980 s.5 (contract); Employment Rights Act 1996 | Employment termination date | Annual |
| CAT-002 | Customer Account Data | Duration of account + 2 years | Contractual necessity; limitation period buffer | Account closure date | Annual |
| CAT-003 | Customer Transaction Records | 6 years from transaction date | HMRC record-keeping; Companies Act 2006 s.386; Limitation Act 1980 | Transaction completion date | Annual |
| CAT-004 | Marketing Contact Data | Until consent withdrawn + 30 days processing | Consent-based; deletion upon withdrawal | Consent withdrawal date or 24 months since last engagement | Biannual |
| CAT-005 | Website Analytics | 26 months from collection | ICO guidance; CNIL recommendation on analytics cookies | Data collection date | Annual |
| CAT-006 | Job Applicant Data | 6 months from recruitment decision (unsuccessful); duration of employment + 6 years (successful) | ICO Employment Practices Code; limitation period for discrimination claims (6 months from decision) | Recruitment decision date | After each recruitment cycle |
| CAT-007 | CCTV Footage | 30 days from recording (standard); up to 6 months if incident flagged | ICO CCTV Code of Practice; proportionality principle | Recording date | Monthly |
| CAT-008 | Supplier Contact Data | Duration of contract + 6 years | Limitation Act 1980; contractual necessity | Contract termination date | Annual |
| CAT-009 | Customer Support Records | 3 years from case closure | Legitimate interest; limitation period for service-related claims | Case closure date | Annual |
| CAT-010 | Financial and Tax Records | 6 years from end of financial year (standard); 20 years (deeds and title documents) | HMRC requirements; Companies Act 2006 s.388; Limitation Act 1980 s.8 | End of relevant financial year | Annual |
For each retention period exceeding the minimum statutory requirement, document the justification:
RETENTION PERIOD JUSTIFICATION — Orion Data Vault Corp
------------------------------------------------------
Category: [CAT-XXX — Category Name]
Proposed Period: [X years from trigger event]
Statutory Minimum: [X years, cite statute]
Proposed Excess: [X additional months/years]
Justification for Excess Period:
1. [Specific business need — e.g., contractual warranty period extends 12 months beyond statutory minimum]
2. [Risk assessment — e.g., historical claims data shows 3% of claims filed in year 5-6]
3. [Regulatory expectation — e.g., FCA expects retention beyond statutory minimum for conduct risk purposes]
Proportionality Assessment:
- Volume of data subjects affected: [number]
- Sensitivity of data: [low/medium/high]
- Risk to data subjects from extended retention: [assessment]
- Mitigating measures: [e.g., access restriction, pseudonymization after statutory minimum]
Approved by: [DPO Name]
Date: [YYYY-MM-DD]
Next Review: [YYYY-MM-DD]The following events trigger an immediate review of the applicable retention period:
| Review Type | Frequency | Scope | Responsible |
|---|---|---|---|
| Category-level review | As per schedule (see retention matrix) | Individual data category retention period, legal basis, and justification | Data Owner + DPO |
| Full schedule review | Annual (Q1) | Entire retention schedule, all categories, legislative scan | DPO + Legal + IT |
| Regulatory alignment check | Biannual | Cross-reference retention periods against current statutory requirements | Legal Counsel |
| Technical compliance audit | Annual (Q3) | Verify that automated deletion and archiving systems enforce scheduled periods | IT + DPO |
| Requirement | Statutory Period | Source |
|---|---|---|
| Tax records (UK) | 6 years from end of accounting period | HMRC; TMA 1970 s.34 |
| Company accounting records | 6 years from end of financial year | Companies Act 2006 s.388 |
| Employment records (general) | 6 years from termination | Limitation Act 1980 s.5 |
| Payroll records | 6 years from end of tax year | Income Tax (PAYE) Regulations 2003 |
| Health and safety records | 40 years from last entry | COSHH Regulations 2002; Ionising Radiations Regulations 2017 |
| Anti-money laundering records | 5 years from end of business relationship | Money Laundering Regulations 2017 reg.40 |
| Consumer contracts | 6 years from breach | Limitation Act 1980 s.5 |
| Personal injury claims | 3 years from date of knowledge | Limitation Act 1980 s.11 |
| Discrimination claims (employment) | 6 months from act complained of | Equality Act 2010 s.123 |
| CCTV footage | 30 days (ICO guidance) | ICO CCTV Code of Practice |
| Pension records | 6 years from end of scheme year (minimum); 12 years recommended | Pensions Act 2004; Limitation Act 1980 |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/retention-schedule of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Retention Schedule next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Retention Schedule this skillmukul975/Privacy-Data-Protection-Skills | 297 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 586 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle. Retention Schedule is an agent skill from mukul975/Privacy-Data-Protection-Skills. Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.
Retention Schedule fits situations like: schedule maintenance; tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a claude-code`. Or copy the skill folder (skills/privacy/retention-schedule in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/retention-schedule in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a codex`. Or copy the skill folder (skills/privacy/retention-schedule in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/retention-schedule in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/retention-schedule, .gemini/skills/retention-schedule, .github/skills/retention-schedule and .opencode/skills/retention-schedule in your project.
Going by SKILL.md and its folder, Retention Schedule needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Retention Schedule is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Retention Schedule: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.