C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Guides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill scc-implementation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills scc-implementation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/scc-implementation .claude/skills/scc-implementation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "scc-implementation" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/scc-implementation into .claude/skills/scc-implementation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scc-implementation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/scc-implementationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill scc-implementation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills scc-implementation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/scc-implementation .agents/skills/scc-implementation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "scc-implementation" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/scc-implementation into .agents/skills/scc-implementation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scc-implementation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill scc-implementation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills scc-implementation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/scc-implementation .cursor/skills/scc-implementation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "scc-implementation" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/scc-implementation into .cursor/skills/scc-implementation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scc-implementation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/scc-implementation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill scc-implementation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills scc-implementation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/scc-implementation .gemini/skills/scc-implementation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "scc-implementation" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/scc-implementation into .gemini/skills/scc-implementation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scc-implementation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills scc-implementationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill scc-implementation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/scc-implementation .github/skills/scc-implementation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "scc-implementation" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/scc-implementation into .github/skills/scc-implementation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scc-implementation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill scc-implementation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills scc-implementation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/scc-implementation .opencode/skills/scc-implementation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "scc-implementation" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/scc-implementation into .opencode/skills/scc-implementation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scc-implementation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
scc-implementationGuides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C).
Scc Implementation is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C). Covers clause-by-clause completion, Annex I-III drafting, and SCC module selection. Keywords: SCCs, standard contractual clauses, module selection, data transfers, Annex completion.
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Scc Implementation loads about 3.6k tokens when it runs, and up to ~6.4k if it reads all its reference files. Until then it costs about 85 tokens; SKILL.md has 1,734 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,734 words, ~3,638 tokens.
.claude/skills/scc-implementation/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Commission Implementing Decision (EU) 2021/914 of 4 June 2021 introduced modernised Standard Contractual Clauses (SCCs) for the transfer of personal data to third countries under Regulation (EU) 2016/679. These SCCs replaced the prior sets adopted under Directive 95/46/EC and became the mandatory instrument from 27 December 2022. The modular architecture allows parties to select the appropriate clause set based on their roles in the transfer relationship.
When to use: The data exporter is a controller and the data importer independently determines the purposes and means of processing the imported data as a separate controller.
Typical scenarios at Athena Global Logistics:
Key Module 1 clauses:
When to use: The data exporter is a controller and the data importer processes data on behalf of the exporter as a processor.
Typical scenarios at Athena Global Logistics:
Key Module 2 clauses:
When to use: The data exporter is a processor (acting on behalf of an EU controller) and the data importer is a sub-processor.
Typical scenarios at Athena Global Logistics:
Key Module 3 clauses:
When to use: The data exporter is a processor and the data importer is the controller whose data is being returned or transferred.
Typical scenarios at Athena Global Logistics:
Key Module 4 clauses:
START: Identify the role of the data EXPORTER (EU-based party)
|
├── Exporter is a CONTROLLER
| |
| ├── Importer determines its OWN purposes → MODULE 1 (C2C)
| |
| └── Importer processes ON BEHALF of exporter → MODULE 2 (C2P)
|
└── Exporter is a PROCESSOR
|
├── Importer is a SUB-PROCESSOR → MODULE 3 (P2P)
|
└── Importer is the CONTROLLER (data return) → MODULE 4 (P2C)| Field | Data Exporter | Data Importer |
|---|---|---|
| Name | Athena Global Logistics GmbH | TransPacific Freight Solutions Ltd |
| Address | Friedrichstrasse 112, 10117 Berlin, Germany | 88 Harbour Road, Wan Chai, Hong Kong SAR |
| Contact person | Elisa Brandt, Head of Data Protection | James Leung, Chief Privacy Officer |
| Activities relevant to transfer | International freight forwarding, customs brokerage, warehouse management for European operations | Regional freight consolidation, last-mile delivery coordination, customs clearance for Asia-Pacific operations |
| Role | Controller | Processor (Module 2) |
| Element | Detail |
|---|---|
| Categories of data subjects | Shipping customers (consignors and consignees), employees of customer companies, customs brokers, warehouse workers |
| Categories of personal data | Full name, business email, business phone number, company name, shipping address, customs identification numbers, consignment reference numbers, delivery scheduling preferences |
| Sensitive data | None transferred under this agreement |
| Frequency of transfer | Continuous real-time transfer via API integration; batch file transfer daily at 02:00 UTC |
| Nature of processing | Storage, retrieval, matching of consignment records, generation of customs documentation, delivery status tracking, exception reporting |
| Purpose of transfer | Fulfilment of freight forwarding contracts requiring regional processing of shipment data for customs clearance and last-mile delivery in Asia-Pacific jurisdictions |
| Retention period | 36 months from completion of the relevant shipment, after which data is securely deleted in accordance with Annex III procedures |
The competent supervisory authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), identified in accordance with Clause 13 as the supervisory authority of the Member State in which the data exporter is established.
| Measure Category | Specific Measures Implemented |
|---|---|
| Encryption of data in transit | TLS 1.3 for all API communications; SFTP with AES-256 encryption for batch transfers |
| Encryption of data at rest | AES-256 encryption on all database storage volumes; encrypted backup tapes with separate key management |
| Access control | Role-based access control (RBAC) with least-privilege principle; multi-factor authentication for all administrative access; quarterly access reviews |
| Data minimisation | API payloads stripped of fields not required for the specific processing purpose; data masking applied to non-essential personal identifiers in development and testing environments |
| Logging and monitoring | Centralised SIEM with 12-month log retention; real-time alerting on anomalous access patterns; daily log review by security operations centre |
| Incident response | Documented incident response plan with 24-hour initial assessment SLA; notification to data exporter within 48 hours of confirmed breach; annual tabletop exercises |
| Physical security | ISO 27001-certified data centres; biometric access controls; 24/7 CCTV surveillance; clean desk policy in processing areas |
| Business continuity | RPO of 4 hours and RTO of 8 hours; geographically separated disaster recovery site; annual DR testing with documented results |
| Staff measures | Mandatory data protection training upon onboarding and annually thereafter; background checks for all staff with access to personal data; confidentiality agreements |
| Sub-processor management | Due diligence assessment before engagement; contractual flow-down of equivalent security obligations; annual audit of sub-processor compliance |
| Sub-Processor | Location | Processing Activity | Safeguard Mechanism |
|---|---|---|---|
| CloudVault Asia Pte Ltd | Singapore | Cloud infrastructure hosting for the regional freight management platform | SCCs Module 3 (P2P) executed 15 March 2025 |
| Pinnacle Data Services Co Ltd | Bangkok, Thailand | Data entry and validation for customs documentation | SCCs Module 3 (P2P) executed 22 January 2025 |
| Clause | Subject | Implementation Action |
|---|---|---|
| Clause 1 | Purpose and scope | Confirm selected module is recorded in the preamble; verify parties have initialled the correct module |
| Clause 2 | Effect and invariability | Verify no modifications to the standard text; confirm any additional safeguards are in a separate addendum, not in the SCC body |
| Clause 3 | Third-party beneficiaries | Confirm data subjects can enforce Clauses 1-3, 8, 9, 12, 15-17 as third-party beneficiaries |
| Clause 4 | Interpretation | Confirm interpretation aligned with GDPR; terms have the same meaning as in the Regulation |
| Clause 5 | Hierarchy | Verify that in case of contradiction, the SCCs prevail over other contractual arrangements |
| Clause 6 | Description of transfer | Verify Annex I.B is complete with all required elements |
| Clause 7 | Docking clause | Determine if additional parties will accede; if so, prepare Annex I.A amendment procedure |
| Clause | Subject | Implementation Action |
|---|---|---|
| Clause 8 | Data protection safeguards | Module-specific; verify all sub-clauses completed per selected module |
| Clause 9 | Use of sub-processors | Module 2/3: Document prior authorisation mechanism (specific or general); maintain sub-processor list; establish notification procedure for changes |
| Clause 10 | Data subject rights | Establish procedure for the importer to handle data subject requests; define response timelines (within 30 days per GDPR Art. 12(3)) |
| Clause 11 | Redress | Confirm independent dispute resolution body identified; verify importer will accept jurisdiction of competent courts |
| Clause 12 | Liability | Confirm liability allocation between parties; verify insurance or financial capacity to meet potential claims |
| Clause | Subject | Implementation Action |
|---|---|---|
| Clause 14 | Local laws affecting compliance | Document the Transfer Impact Assessment results; identify specific laws in the importer's jurisdiction that may impinge on SCC protections |
| Clause 15 | Government access obligations | Importer must notify exporter of government access requests (unless legally prohibited); importer must challenge disproportionate requests; importer must provide transparency report |
| Clause | Subject | Implementation Action |
|---|---|---|
| Clause 16 | Non-compliance and termination | Establish escalation procedure: notification → 30-day cure period → suspension → termination; data return or deletion upon termination |
| Clause 17 | Governing law | Select law of the EU Member State of the exporter (Germany, for Athena Global Logistics) |
| Clause 18 | Choice of forum and jurisdiction | Select courts of the EU Member State of the exporter (Berlin, Germany) |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/scc-implementation of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Scc Implementation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Scc Implementation this skillmukul975/Privacy-Data-Protection-Skills | 295 | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 586 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 942 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 942 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
mukul975/Privacy-Data-Protection-Skills
Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.
Categories
Guides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C). Scc Implementation is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C).
Scc Implementation fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill scc-implementation -a claude-code`. Or copy the skill folder (skills/privacy/scc-implementation in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/scc-implementation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill scc-implementation -a codex`. Or copy the skill folder (skills/privacy/scc-implementation in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/scc-implementation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill scc-implementation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scc-implementation, .gemini/skills/scc-implementation, .github/skills/scc-implementation and .opencode/skills/scc-implementation in your project.
Going by SKILL.md and its folder, Scc Implementation needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Scc Implementation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Scc Implementation: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.