Agent skill

Soc2 Privacy Audit

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution.

Apache-2.0Auto-check passedLegal & Compliance

Install Soc2 Privacy Audit

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill soc2-privacy-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills soc2-privacy-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/soc2-privacy-audit .claude/skills/soc2-privacy-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
soc2-privacy-audit
GitHub stars
301
Token cost
~4.9k tokens
SKILL.md length
2,252 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution.

  • Works in 3 steps: The system description is fairly presented → Controls were suitably designed (Type I… → Controls operated effectively throughout…
  • Tasks that involve SOC 2 and security compliance
  • SKILL.md covers Overview, Privacy Trust Services…, Evidence Collection Framework and Control Testing Procedures, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Soc2 Privacy Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent, collection, use/retention/disposal, access, disclosure, security, and quality. Includes evidence collection, control testing, and report review. Keywords: SOC 2, privacy criteria, TSP, AICPA, Type II, trust services.

Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve SOC 2 and security compliance
  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the soc2-privacy-audit skill to guide SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution”
  • “/soc2-privacy-audit”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. The system description is fairly presented
  2. Controls were suitably designed (Type I and II)
  3. Controls operated effectively throughout the examination period (Type II)

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Soc2 Privacy Audit loads about 4.9k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 102 tokens; SKILL.md has 2,252 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~4.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,252 words, ~4,917 tokens.

Download SKILL.mdSave it as .claude/skills/soc2-privacy-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
soc2-privacy-audit
description
Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent, collection, use/retention/disposal, access, disclosure, security, and quality. Includes evidence collection, control testing, and report review. Keywords: SOC 2, privacy criteria, TSP, AICPA, Type II, trust services.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-audit-certification
metadata.tags
soc2, privacy-criteria, aicpa, tsp, type-ii, trust-services

SOC 2 Type II Privacy Trust Services Criteria

Overview

SOC 2 (System and Organization Controls 2) is a reporting framework developed by the American Institute of Certified Public Accountants (AICPA) that evaluates an organization's controls relevant to the Trust Services Criteria (TSC). The Privacy category is one of five TSC categories (Security, Availability, Processing Integrity, Confidentiality, and Privacy) and specifically addresses how the organization collects, uses, retains, discloses, and disposes of personal information in conformity with commitments in its privacy notice and with criteria set forth by the AICPA.

A SOC 2 Type II report covers a specified examination period (typically 6-12 months) during which the auditor (a licensed CPA firm) tests whether controls were not only designed appropriately (Type I) but also operated effectively throughout the period. For the Privacy TSC, this means demonstrating sustained compliance with criteria P1.0 through P8.1 as defined in TSP Section 100 (2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy).

Sentinel Compliance Group undergoes annual SOC 2 Type II examinations including the Privacy TSC to provide contractual assurance to enterprise clients in financial services, healthcare technology, and SaaS sectors.

Privacy Trust Services Criteria (P1.0 — P8.1)

P1.0 — Notice

Criterion: The entity provides notice to data subjects about its privacy practices.

P1.1: The entity provides notice to data subjects about its privacy practices to meet the entity's objectives related to privacy. The notice is updated and communicated to data subjects in a timely manner for changes to the entity's privacy practices, including changes in the use of personal information.

Required Controls:

Control IDControl DescriptionEvidence Required
P1.1-01Privacy notice is published on all data collection points (website, mobile app, paper forms)Screenshots of privacy notices on all collection points, version history log
P1.1-02Privacy notice describes: types of personal information collected, purposes of collection and use, categories of third parties to whom data is disclosed, data subject rights, retention periodsPrivacy notice text, legal review records
P1.1-03Privacy notice is reviewed and updated at minimum annually and when processing changes occurAnnual review meeting minutes, change log, approval records
P1.1-04Material changes to privacy notice are communicated to affected data subjects via email or in-app notification prior to the change taking effectNotification records, email delivery logs, communication templates
P1.1-05Privacy notice is available in languages corresponding to the user baseTranslated notice versions, translation vendor records

Criterion: The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information.

Required Controls:

Control IDControl DescriptionEvidence Required
P1.2-01Consent is obtained prior to or at the time of collection of personal informationConsent records, timestamp logs, consent mechanism screenshots
P1.2-02Data subjects are informed of consequences of refusing to provide personal informationPrivacy notice text, consent form text
P1.2-03Opt-out mechanisms are provided for marketing communications and non-essential processingOpt-out mechanism evidence, preference center screenshots
P1.2-04Explicit consent is obtained for sensitive personal information (health, financial, biometric, children's data)Explicit consent records, separate consent forms
P1.2-05Consent withdrawal mechanisms are available and accessibleWithdrawal mechanism documentation, processing records showing withdrawal honored
P2.1 — Collection

Criterion: Personal information is collected consistent with the entity's objectives related to privacy.

Required Controls:

Control IDControl DescriptionEvidence Required
P2.1-01Personal information collected is limited to that described in the privacy notice and necessary for identified purposesData inventory, data mapping, comparison against privacy notice
P2.1-02Data collection points are inventoried and reviewed quarterlyCollection point inventory, quarterly review records
P2.1-03Collection of personal information from third-party sources is documented and subject to due diligenceThird-party data source register, due diligence records
P2.1-04Implicit collection (cookies, device fingerprinting, tracking pixels) is disclosed in the privacy noticeCookie audit results, tracking technology inventory
P3.1 — Use, Retention, and Disposal

Criterion: Personal information is used, retained, and disposed of consistent with the entity's objectives.

Required Controls:

Control IDControl DescriptionEvidence Required
P3.1-01Personal information is used only for purposes identified in the privacy noticePurpose limitation audit results, processing activity register
P3.1-02Retention schedules are defined for each category of personal informationRetention schedule document, category-level retention periods
P3.1-03Automated deletion or anonymization processes execute upon retention period expiryDeletion job logs, anonymization records, automated process configuration
P3.1-04Disposal methods ensure personal information is rendered unrecoverable (NIST SP 800-88 Rev. 1 media sanitization)Disposal certificates, sanitization logs, destruction vendor contracts
P3.1-05Retention exceptions (litigation hold, regulatory requirement) are documented and time-boundLitigation hold register, exception approval records
P4.1 — Access

Criterion: The entity provides data subjects with access to their personal information for review and update.

Required Controls:

Control IDControl DescriptionEvidence Required
P4.1-01Data subject access request (DSAR) intake mechanism is available (web form, email, in-app)DSAR portal screenshots, process documentation
P4.1-02Identity verification is performed prior to fulfilling access requestsVerification procedure document, verification logs
P4.1-03Access requests are fulfilled within documented timeframes (30 days for GDPR, 45 days for CCPA)DSAR tracking log with timestamps, response time metrics
P4.1-04Data subjects can request corrections to inaccurate personal informationCorrection mechanism documentation, correction request logs
P4.1-05Denials of access requests are documented with reasons and communicated to the data subjectDenial records, denial notification templates
P5.1 — Disclosure to Third Parties

Criterion: Personal information is disclosed to third parties only for identified purposes and with consent.

Required Controls:

Control IDControl DescriptionEvidence Required
P5.1-01Third parties receiving personal information are identified and documentedThird-party recipient register, data flow diagrams
P5.1-02Data processing agreements or equivalent contracts are in place with all third parties receiving personal informationExecuted DPAs, contract inventory
P5.1-03Third-party disclosures are consistent with purposes described in the privacy noticeDisclosure audit results, purpose-to-recipient mapping
P5.1-04Third parties are assessed for adequate privacy and security controls prior to disclosureThird-party assessment records, vendor risk assessments
P5.1-05Unauthorized disclosures are reported and investigatedIncident response records, disclosure investigation logs
P6.1 — Security for Privacy

Criterion: Personal information is protected against unauthorized access, whether physical or logical.

This criterion is met through the Security TSC (CC1.0 through CC9.0, the Common Criteria). Privacy-specific security controls include:

Control IDControl DescriptionEvidence Required
P6.1-01Personal information is encrypted at rest using AES-256 or equivalentEncryption configuration evidence, key management documentation
P6.1-02Personal information is encrypted in transit using TLS 1.2 or higherTLS configuration scans, certificate inventory
P6.1-03Access to personal information is restricted using role-based access controls (RBAC)RBAC matrix, access review records, least privilege evidence
P6.1-04Access to personal information is logged and logs are retained per the audit log retention policyLog configuration evidence, sample log entries, retention policy
P6.1-05Privacy-impacting security incidents trigger the breach notification processIncident classification criteria, breach notification procedure
P7.1 — Quality

Criterion: Personal information is maintained accurately, completely, and timely for the purposes for which it is used.

Required Controls:

Control IDControl DescriptionEvidence Required
P7.1-01Data quality processes validate personal information at point of collectionValidation rules documentation, input validation configurations
P7.1-02Data subjects can request correction of inaccurate personal informationCorrection mechanism documentation, correction log
P7.1-03Personal information is reviewed for accuracy on a periodic basisData quality review schedule, review results
P8.1 — Monitoring and Enforcement

Criterion: The entity monitors compliance with its privacy policies and procedures and has procedures to address privacy-related inquiries, complaints, and disputes.

Required Controls:

Control IDControl DescriptionEvidence Required
P8.1-01Privacy compliance monitoring is conducted at minimum quarterlyCompliance monitoring reports, finding logs
P8.1-02A privacy complaint intake mechanism is available and publicizedComplaint mechanism screenshots, privacy notice reference
P8.1-03Privacy complaints are tracked, investigated, and resolved within documented timeframesComplaint tracking log, resolution records, SLA metrics
P8.1-04Employees are trained on privacy obligations at onboarding and annually thereafterTraining records, completion rates, training content
P8.1-05Disciplinary actions are taken for privacy policy violationsDisciplinary policy, anonymized violation records

Evidence Collection Framework

Documentation Categories
CategoryExamplesRetention Requirement
Policies and ProceduresPrivacy policy, DSAR procedure, breach notification procedureCurrent versions plus two prior versions
Operational EvidenceDSAR logs, consent records, deletion logs, training recordsThroughout examination period plus one year
Technical ConfigurationEncryption settings, RBAC matrices, log configurationsPoint-in-time screenshots plus change records
Governance RecordsCommittee meeting minutes, management review records, risk assessmentsThroughout examination period
Third-Party DocumentationDPAs, vendor assessments, sub-processor listsCurrent plus examination period
Show full SKILL.md (868 more words)Show less
Evidence Collection Timeline

Month 1-2 (Pre-Examination Period):

  • Establish evidence repository with access controls
  • Create evidence request list mapped to each P-criterion
  • Assign evidence owners for each control
  • Conduct readiness assessment against all P-criteria

Months 3-8 (During Examination Period):

  • Collect operational evidence continuously (DSAR logs, deletion records, consent records)
  • Maintain running evidence calendar with monthly evidence capture checkpoints
  • Document all exceptions and compensating controls
  • Conduct mid-period self-assessment at month 5

Month 9-10 (Pre-Audit Preparation):

  • Complete evidence gap analysis against auditor's request list
  • Prepare evidence binders (physical or digital) organized by criterion
  • Pre-review all evidence for completeness and consistency
  • Prepare key personnel for auditor interviews
Sample Population Testing

SOC 2 auditors test controls using sampling methodologies based on AICPA AU-C Section 530:

Examination PeriodPopulation SizeMinimum Sample Size
6 months1-50All
6 months51-25025
6 months251+40
12 months1-50All
12 months51-25030
12 months251+45

For privacy controls, common populations tested include:

  • DSAR processing records (testing response timeliness and completeness)
  • Consent records (testing capture and withdrawal mechanisms)
  • Third-party DPAs (testing completeness and signature)
  • Data deletion records (testing timeliness per retention schedule)
  • Privacy complaint records (testing investigation and resolution)

Control Testing Procedures

Inquiry

The auditor interviews control owners and operators to understand how the control operates in practice:

  • Privacy Officer: Overall privacy program governance, policy management, risk assessment
  • IT Security: Encryption, access controls, logging, incident response
  • Legal: DPA management, privacy notice updates, regulatory monitoring
  • Customer Support: DSAR handling, complaint management, consent processes
  • HR: Employee training, disciplinary procedures, onboarding privacy requirements
Observation

The auditor observes controls in operation:

  • Walkthrough of DSAR intake and fulfillment process
  • Demonstration of consent management platform
  • Demonstration of data deletion/anonymization processes
  • Walkthrough of privacy complaint handling
  • Demonstration of access control review process
Inspection

The auditor examines evidence artifacts:

  • Privacy notice versions and change logs
  • DSAR tracking spreadsheets or ticketing system records
  • Consent database records with timestamps
  • Data deletion job execution logs
  • Third-party DPA repository
  • Privacy training completion records
  • Privacy committee meeting minutes
  • Privacy risk assessment documentation
Reperformance

The auditor independently reperforms a control to verify its effectiveness:

  • Submit a test DSAR and verify the response process
  • Verify that retention period expiry triggers automated deletion
  • Verify that access controls prevent unauthorized access to personal information
  • Verify that privacy notice accurately reflects current processing activities

Report Review

Management Assertion

The service organization's management provides a written assertion that:

  1. The system description is fairly presented
  2. Controls were suitably designed (Type I and II)
  3. Controls operated effectively throughout the examination period (Type II)
Auditor's Opinion

The auditor's report contains:

  • Unqualified (clean) opinion: Controls were suitably designed and operated effectively
  • Qualified opinion: One or more exceptions noted but controls are generally effective
  • Adverse opinion: Significant deficiencies exist in control design or operation
  • Disclaimer of opinion: Sufficient evidence could not be obtained
Exception Handling

When the auditor identifies exceptions during testing:

  1. Deviation: A single instance where a control did not operate as designed (e.g., one DSAR exceeded the 30-day response window). The auditor documents the deviation and evaluates whether it represents a systematic failure.
  2. Exception: A pattern of deviations or a significant individual deviation. Exceptions are described in the report with management's response.
  3. Modified Opinion Threshold: Typically 3+ exceptions in a single control or exceptions across multiple controls in the same criterion may result in a qualified opinion for that criterion.
User Entity Considerations (Complementary User Entity Controls — CUECs)

The SOC 2 report identifies controls that user entities (customers) must implement for the system of controls to be effective. Privacy-related CUECs commonly include:

  • User entities are responsible for providing accurate personal information to the service organization
  • User entities are responsible for reviewing and approving data processing purposes
  • User entities are responsible for obtaining consent from their own data subjects before providing personal information to the service organization
  • User entities are responsible for notifying the service organization of DSARs that require the service organization's assistance

SOC 2 Privacy vs. GDPR Comparison

AspectSOC 2 Privacy TSCGDPR
Regulatory natureVoluntary attestationMandatory legislation
ScopeService organization's systemAll personal data processing
EnforcerCPA auditor (AICPA standards)Supervisory authorities
Consequence of failureQualified/adverse reportFines up to EUR 20M or 4% global turnover
CoverageEight criteria (P1-P8)99 articles, 173 recitals
Lawful basisNot addressed (consent-focused)Six lawful bases under Art. 6
Cross-border transfersNot specifically addressedChapters V (Art. 44-49)
Data subject rightsAccess and correction (P4)Eight rights (Art. 15-22)
Breach notificationCovered under Security TSC72-hour DPA notification, data subject notification

Sentinel Compliance Group SOC 2 Privacy Implementation

Sentinel Compliance Group maintains an annual SOC 2 Type II examination (12-month period, January 1 — December 31) including the Privacy TSC alongside Security and Confidentiality:

  • Examination Period: January 1, 2025 — December 31, 2025
  • Auditor: Deloitte & Touche LLP
  • Criteria Included: Security (CC), Confidentiality (C), Privacy (P)
  • Controls Tested: 142 total controls, 38 Privacy-specific
  • Result: Unqualified opinion with zero exceptions for Privacy criteria
  • Key Metrics During Period: 847 DSARs processed (average response time: 12 days), 0 privacy complaints unresolved beyond 30 days, 100% employee privacy training completion, 4 privacy notice updates published
  • Bridge Letter: Issued quarterly to address the gap between examination period end and report issuance (typically 8-12 weeks after period end)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/soc2-privacy-audit of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Soc2 Privacy Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Soc2 Privacy Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Soc2 Privacy Audit this skillmukul975/Privacy-Data-Protection-Skills301—~4.9kAutomated safety check: PassApache-2.0
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4.2kAutomated safety check: PassMIT
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    946 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Soc2 Privacy Audit

What does Soc2 Privacy Audit do?

Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Soc2 Privacy Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution.

When should I use Soc2 Privacy Audit?

Soc2 Privacy Audit fits situations like: tasks that involve SOC 2 and security compliance; tasks that involve Privacy and GDPR.

How do I install Soc2 Privacy Audit in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill soc2-privacy-audit -a claude-code`. Or copy the skill folder (skills/privacy/soc2-privacy-audit in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/soc2-privacy-audit in your project. Claude Code loads it when a task matches its description.

How do I install Soc2 Privacy Audit in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill soc2-privacy-audit -a codex`. Or copy the skill folder (skills/privacy/soc2-privacy-audit in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/soc2-privacy-audit in your project. Codex loads it when a task matches its description.

Can I use Soc2 Privacy Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill soc2-privacy-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/soc2-privacy-audit, .gemini/skills/soc2-privacy-audit, .github/skills/soc2-privacy-audit and .opencode/skills/soc2-privacy-audit in your project.

What does Soc2 Privacy Audit need to run?

Going by SKILL.md and its folder, Soc2 Privacy Audit needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Soc2 Privacy Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Soc2 Privacy Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Soc2 Privacy Audit use?

Soc2 Privacy Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Soc2 Privacy Audit use?

About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Soc2 Privacy Audit?

Skills that share tags, products or a category with Soc2 Privacy Audit: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Audit Report (harness/harness-skills, 115 stars), Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Security Compliance (sangrokjung/claude-forge, 852 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Soc2 Privacy Audit?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.