Agent skill

Special Category Data

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Identifies and classifies GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills.

Apache-2.0Auto-check passedLegal & Compliance

Install Special Category Data

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills special-category-data --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/special-category-data .claude/skills/special-category-data && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
special-category-data
GitHub stars
297
Token cost
~3.7k tokens
SKILL.md length
1,804 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Identifies and classifies GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills.

  • Works in 5 steps: Any processing involving employee HR… → Customer onboarding with identity… → Marketing analytics using behavioural… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, The Eight Special Categories —…, Processing Conditions — Art.… and Identification Methodology, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Special Category Data is an agent skill from mukul975/Privacy-Data-Protection-Skills. Identifies and classifies GDPR Art. 9 special category data including racial origin, political opinions, religious beliefs, trade union membership, genetic, biometric, health, and sexual orientation data. Covers processing conditions under Art. 9(2)(a)-(j). Keywords: special category, Art 9, sensitive data, biometric, genetic, health data, explicit consent.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Health and fitness tracking. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Health and fitness tracking

Example prompts

  • “Use the special-category-data skill to identify and classifies GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills”
  • “/special-category-data”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Any processing involving employee HR data (may contain health, union, diversity data)
  2. Customer onboarding with identity verification (photographs may become biometric)
  3. Marketing analytics using behavioural profiling (may infer political views, health status)
  4. Insurance or benefits processing (health data inherent)
  5. AI/ML training using customer or employee data (risk of inferring special categories)

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Special Category Data loads about 3.7k tokens when it runs, and up to ~7.1k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 1,804 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,804 words, ~3,748 tokens.

Download SKILL.mdSave it as .claude/skills/special-category-data/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
special-category-data
description
Identifies and classifies GDPR Art. 9 special category data including racial origin, political opinions, religious beliefs, trade union membership, genetic, biometric, health, and sexual orientation data. Covers processing conditions under Art. 9(2)(a)-(j). Keywords: special category, Art 9, sensitive data, biometric, genetic, health data, explicit consent.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-classification
metadata.tags
special-category, art-9, sensitive-data, biometric, genetic, health-data

Special Category Data Classification — GDPR Art. 9

Overview

Article 9(1) of the GDPR establishes a general prohibition on processing special categories of personal data. These categories were identified by the European legislature as carrying heightened risk to fundamental rights and freedoms due to their potential for discrimination, social stigma, or irreversible harm. Processing is permitted only when one of the ten conditions in Art. 9(2)(a)-(j) is satisfied, in addition to a valid lawful basis under Art. 6. This skill provides a systematic framework for identifying special category data across enterprise systems and mapping each instance to an appropriate processing condition.

The Eight Special Categories — Art. 9(1)

Category 1: Racial or Ethnic Origin

Definition: Data revealing or from which racial or ethnic origin can be inferred, including direct declarations, photographs, names characteristic of particular ethnic groups, or nationality data when used as a proxy for ethnic origin.

Examples at Vanguard Financial Services:

  • Employee self-identification forms for diversity monitoring
  • Customer photographs in KYC documentation
  • Nationality fields when used to infer ethnicity
  • Language preference data when combined with geographic data to infer origin

Boundary Cases:

  • Nationality alone is not necessarily racial/ethnic origin data, but becomes special category when processed for diversity analysis (EDPB, WP251rev.01)
  • Photographs are special category only when processed through facial recognition for the purpose of uniquely identifying — a passport photo stored for KYC is not biometric data, but the same photo run through facial comparison software becomes biometric data
Category 2: Political Opinions

Definition: Data revealing political views, party membership, voting behaviour, political donations, or participation in political activities.

Examples at Vanguard Financial Services:

  • Employee political donation records (where legally collected for compliance with US PAC reporting requirements)
  • Customer complaints referencing political views
  • Social media data processed for marketing that reveals political affiliations

Key Precedent: Austrian Post (Österreichische Post AG) — Austrian DPA and subsequently CJEU Case C-300/21 (2023) — fined EUR 18 million for processing political affinity scores derived from statistical models applied to demographic data. The CJEU confirmed that data revealing political opinions includes inferred data, not only data directly provided by the data subject.

Category 3: Religious or Philosophical Beliefs

Definition: Data revealing religious faith, atheism, agnosticism, philosophical convictions, or related practices. Includes dietary preferences when they indicate religious observance (halal, kosher), religious holiday requests, and membership of religious organisations.

Examples at Vanguard Financial Services:

  • Employee religious holiday accommodation requests
  • Dietary restriction data for corporate event catering
  • Charitable donation patterns to religious organisations (from transaction data)
Category 4: Trade Union Membership

Definition: Data revealing whether an individual is or was a member of a trade union. Includes union dues deductions from payroll, attendance at union meetings, and communications with union representatives.

Examples at Vanguard Financial Services:

  • Payroll deduction records for union dues
  • HR records of union membership status
  • Meeting room booking records for union activities
Category 5: Genetic Data — Art. 4(13)

Definition: Personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or health of that natural person, resulting in particular from an analysis of a biological sample from the natural person in question.

Examples at Vanguard Financial Services:

  • Genetic test results in employee wellness programs (if offered)
  • Insurance underwriting data derived from genetic testing (prohibited in many jurisdictions)
  • Biobank research data from corporate health initiatives

Regulatory Note: The Genetic Information Nondiscrimination Act (GINA) in the US prohibits use of genetic information in health insurance and employment. In the EU, genetic data receives dual protection under both Art. 9 and specific Member State genetic data legislation.

Category 6: Biometric Data — Art. 4(14)

Definition: Personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.

Critical Distinction: Biometric data is special category ONLY when processed "for the purpose of uniquely identifying a natural person" (Art. 9(1)). A photograph stored in an HR file is personal data but not special category. The same photograph processed through facial recognition software for access control is special category biometric data.

Examples at Vanguard Financial Services:

  • Fingerprint scanners for building access control
  • Facial recognition for secure facility entry
  • Voice recognition for telephone banking authentication
  • Behavioural biometrics (keystroke dynamics) for fraud detection

Key Precedent: Clearview AI — CNIL Decision SAN-2022-019 (20 October 2022) — EUR 20 million fine for processing biometric data (facial recognition) without lawful basis and without conducting DPIA.

Category 7: Health Data — Recital 35

Definition: Personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about their health status. Recital 35 specifies this includes data pertaining to the health status of a data subject which reveals information relating to the past, current, or future physical or mental health of the data subject, including: registration for health care services, number/symbol/identifier assigned for health purposes, information derived from testing or examination of a body part or bodily substance, and any information on a disease, disability, disease risk, medical history, clinical treatment, or physiological or biomedical condition.

Examples at Vanguard Financial Services:

  • Employee sick leave records and medical certificates
  • Disability accommodation requests
  • Occupational health assessment results
  • Health insurance claims data
  • Wellness program participation data (step counts, health metrics)
  • COVID-19 vaccination status records
  • Drug and alcohol testing results
  • Ergonomic assessment data indicating physical conditions

Breadth of Health Data: The CJEU has interpreted health data broadly. In Case C-184/20 (Vyriausioji tarnybinės etikos komisija, 2022), the Court held that data which indirectly reveals health information (such as a spouse's name in a declaration of interests that could reveal sexual orientation or health status) may constitute special category data.

Category 8: Sex Life or Sexual Orientation

Definition: Data concerning sexual behaviour, sexual preferences, or sexual orientation. Includes data from which sexual orientation can be inferred.

Examples at Vanguard Financial Services:

  • Employee diversity monitoring data including sexual orientation
  • Beneficiary designations that reveal same-sex partnerships
  • Customer data from which sexual orientation can be inferred (partner names, household composition)
Show full SKILL.md (800 more words)Show less

Processing Conditions — Art. 9(2)(a)-(j)

Processing of special category data is lawful ONLY when one of these conditions is met (in addition to Art. 6 lawful basis):

ConditionArt. 9(2)RequirementsVanguard Application
Explicit consent(a)Must be freely given, specific, informed, unambiguous, and EXPLICIT (higher standard than Art. 6(1)(a) consent). Must be a clear affirmative statement, not implied.Employee diversity monitoring with opt-in explicit consent
Employment and social security law(b)Processing necessary for obligations under employment, social security, or social protection law. Must be authorised by EU or Member State law or collective agreement with appropriate safeguards.Payroll processing of trade union dues, occupational health assessments required by law
Vital interests(c)Processing necessary to protect vital interests where data subject is physically or legally incapable of giving consent.Emergency medical situations where employee is incapacitated
Legitimate activities of non-profit(d)Processing by foundation, association, or not-for-profit body with political, philosophical, religious, or trade union aims, relating to members or regular contacts, with no disclosure outside the body without consent.Not applicable to Vanguard (commercial entity)
Data manifestly made public(e)Data subject has manifestly made the data public (e.g., publicly declared political views on social media, public disclosure of health condition).Customer data voluntarily posted on public forums
Legal claims(f)Processing necessary for establishment, exercise, or defence of legal claims, or whenever courts are acting in their judicial capacity.Litigation holds involving health data in employment disputes
Substantial public interest(g)Processing necessary for reasons of substantial public interest, on basis of EU or Member State law, proportionate to the aim, with appropriate safeguards.Regulatory reporting obligations (e.g., AML suspicious activity involving special category data)
Health care and occupational medicine(h)Processing necessary for preventive or occupational medicine, assessment of working capacity, medical diagnosis, health/social care provision, or management of health systems. Must be processed by or under responsibility of a professional with secrecy obligation.Occupational health surveillance mandated by workplace health regulations
Public health(i)Processing necessary for public health reasons such as protection against serious cross-border threats to health, ensuring high standards of quality and safety for medicines/medical devices.COVID-19 workplace safety measures (now largely wound down)
Archiving, research, statistics(j)Processing necessary for archiving in the public interest, scientific or historical research, or statistical purposes under Art. 89(1), with appropriate safeguards including data minimisation.Internal workforce diversity statistical analysis

Identification Methodology

Automated Detection Indicators
Indicator TypeDetection ApproachSpecial Category Flag
Field names containing health terminologyRegex pattern matching: `diagnosissymptom
ICD-10/ICD-11 codesCode format detection: [A-Z][0-9]{2}(\.[0-9]{1,4})?Health data
Biometric template formatsBinary header detection for ISO 19795, ANSI/INCITS 378 fingerprint templatesBiometric data
Diversity form fieldsField labels matching: `ethnicityrace
Genetic marker identifiersSNP identifiers (rs-numbers), gene names (HUGO nomenclature)Genetic data
Manual Review Triggers

Processing activities that warrant manual special category review:

  1. Any processing involving employee HR data (may contain health, union, diversity data)
  2. Customer onboarding with identity verification (photographs may become biometric)
  3. Marketing analytics using behavioural profiling (may infer political views, health status)
  4. Insurance or benefits processing (health data inherent)
  5. AI/ML training using customer or employee data (risk of inferring special categories)

Data Protection Impact Assessment Requirement

Under Art. 35(3)(b), processing special category data on a large scale automatically triggers a mandatory DPIA. For Vanguard Financial Services:

Processing ActivityScale AssessmentDPIA Required?
Employee health records12,000 employees — large scale for employerYES
Fingerprint access controlAll office buildings, 8,500 usersYES
Customer KYC photographs2.4 million customersYES (if facial recognition applied)
Diversity monitoring surveyVoluntary, ~3,000 respondentsYES (special category + employment context)

Enforcement Precedents

  • Österreichische Post AG (Austrian DPA / CJEU C-300/21, 2023): EUR 18 million fine for processing inferred political affinity scores. Established that data need not be directly provided by the data subject to constitute special category data — statistical inference suffices.
  • Clearview AI (CNIL SAN-2022-019, 2022): EUR 20 million fine for biometric data processing without lawful basis or DPIA.
  • Asociación Profesional Elite Taxi v Uber Systems Spain (CJEU C-434/15, 2017): While primarily an internal market case, the opinion addressed processing of driver data that could reveal trade union membership.
  • Hungarian NAIH (2021): Fined a retailer HUF 100 million for processing employee health data (COVID-19 test results) beyond the scope authorised by public health legislation.
  • Swedish DPA (2019): Fined a school SEK 200,000 for using facial recognition (biometric data) for student attendance tracking without valid legal basis under Art. 9(2).

Integration Points

  • personal-data-test: Special category classification presupposes personal data classification — Art. 9 applies only to data that is first personal data under Art. 4(1)
  • criminal-data-handling: Art. 10 criminal data has separate rules but is often processed alongside special categories
  • classification-policy: Special category designation drives the highest classification tier (Restricted)
  • data-inventory-mapping: Art. 30 RoPA must identify special category data per processing activity

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/special-category-data of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Special Category Data next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Special Category Data compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Special Category Data this skillmukul975/Privacy-Data-Protection-Skills297—~3.7kAutomated safety check: PassApache-2.0
Dsgvo Health Data Complianceahmadvh/octochains376—~403Automated safety check: PassCustom licence
Uae GrcSushegaad/Claude-Skills-Governance-Risk-and-Compliance943—~2.3kAutomated safety check: PassMIT
Privacy Policygustavscirulis/snapgrid1171 repos~3kAutomated safety check: PassCustom licence
Privacy Publishrshankras/claude-code-apple-skills785—~911Automated safety check: NotesMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Audits architectural proposals and data schemas for GDPR/DSGVO Article 9 (Special Categories of Personal Data) violations.

    376 GitHub stars~403 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Uae Grc

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    United Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router.

    943 GitHub stars~2.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Privacy Policy

    gustavscirulis/snapgrid

    Generate privacy policies, terms of service, and EULAs for Apple platform apps.

    117 GitHub starsUsed in 1 repo~3k tokens
    Legal & ComplianceAuto-check passed
  • Privacy Publish

    rshankras/claude-code-apple-skills

    Turn drafted legal docs (privacy policy, terms) into hosted pages and set the App Store Connect Privacy Policy / Support / Marketing URLs via the ASC REST API.

    785 GitHub stars~911 tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check: notes
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    297 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    297 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    297 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Special Category Data

What does Special Category Data do?

Identifies and classifies GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills. Special Category Data is an agent skill from mukul975/Privacy-Data-Protection-Skills. Identifies and classifies GDPR Art.

When should I use Special Category Data?

Special Category Data fits situations like: tasks that involve Privacy and GDPR; tasks that involve Health and fitness tracking.

How do I install Special Category Data in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a claude-code`. Or copy the skill folder (skills/privacy/special-category-data in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/special-category-data in your project. Claude Code loads it when a task matches its description.

How do I install Special Category Data in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a codex`. Or copy the skill folder (skills/privacy/special-category-data in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/special-category-data in your project. Codex loads it when a task matches its description.

Can I use Special Category Data in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/special-category-data, .gemini/skills/special-category-data, .github/skills/special-category-data and .opencode/skills/special-category-data in your project.

What does Special Category Data need to run?

Going by SKILL.md and its folder, Special Category Data needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Special Category Data access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Special Category Data safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Special Category Data use?

Special Category Data is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Special Category Data use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.

What are the alternatives to Special Category Data?

Skills that share tags, products or a category with Special Category Data: Dsgvo Health Data Compliance (ahmadvh/octochains, 376 stars), Uae Grc (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars), Privacy Policy (gustavscirulis/snapgrid, 117 stars) and Privacy Publish (rshankras/claude-code-apple-skills, 785 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Special Category Data?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.