Dsgvo Health Data Compliance
ahmadvh/octochains
Audits architectural proposals and data schemas for GDPR/DSGVO Article 9 (Special Categories of Personal Data) violations.
Identifies and classifies GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills special-category-data --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/special-category-data .claude/skills/special-category-data && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "special-category-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/special-category-data into .claude/skills/special-category-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "special-category-data", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/special-category-dataType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills special-category-data --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/special-category-data .agents/skills/special-category-data && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "special-category-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/special-category-data into .agents/skills/special-category-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "special-category-data", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills special-category-data --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/special-category-data .cursor/skills/special-category-data && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "special-category-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/special-category-data into .cursor/skills/special-category-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "special-category-data", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/special-category-data--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills special-category-data --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/special-category-data .gemini/skills/special-category-data && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "special-category-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/special-category-data into .gemini/skills/special-category-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "special-category-data", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills special-category-dataInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/special-category-data .github/skills/special-category-data && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "special-category-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/special-category-data into .github/skills/special-category-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "special-category-data", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills special-category-data --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/special-category-data .opencode/skills/special-category-data && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "special-category-data" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/special-category-data into .opencode/skills/special-category-data/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "special-category-data", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
special-category-dataIdentifies and classifies GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills.
Special Category Data is an agent skill from mukul975/Privacy-Data-Protection-Skills. Identifies and classifies GDPR Art. 9 special category data including racial origin, political opinions, religious beliefs, trade union membership, genetic, biometric, health, and sexual orientation data. Covers processing conditions under Art. 9(2)(a)-(j). Keywords: special category, Art 9, sensitive data, biometric, genetic, health data, explicit consent.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR and Health and fitness tracking. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Special Category Data loads about 3.7k tokens when it runs, and up to ~7.1k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 1,804 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,804 words, ~3,748 tokens.
.claude/skills/special-category-data/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Article 9(1) of the GDPR establishes a general prohibition on processing special categories of personal data. These categories were identified by the European legislature as carrying heightened risk to fundamental rights and freedoms due to their potential for discrimination, social stigma, or irreversible harm. Processing is permitted only when one of the ten conditions in Art. 9(2)(a)-(j) is satisfied, in addition to a valid lawful basis under Art. 6. This skill provides a systematic framework for identifying special category data across enterprise systems and mapping each instance to an appropriate processing condition.
Definition: Data revealing or from which racial or ethnic origin can be inferred, including direct declarations, photographs, names characteristic of particular ethnic groups, or nationality data when used as a proxy for ethnic origin.
Examples at Vanguard Financial Services:
Boundary Cases:
Definition: Data revealing political views, party membership, voting behaviour, political donations, or participation in political activities.
Examples at Vanguard Financial Services:
Key Precedent: Austrian Post (Österreichische Post AG) — Austrian DPA and subsequently CJEU Case C-300/21 (2023) — fined EUR 18 million for processing political affinity scores derived from statistical models applied to demographic data. The CJEU confirmed that data revealing political opinions includes inferred data, not only data directly provided by the data subject.
Definition: Data revealing religious faith, atheism, agnosticism, philosophical convictions, or related practices. Includes dietary preferences when they indicate religious observance (halal, kosher), religious holiday requests, and membership of religious organisations.
Examples at Vanguard Financial Services:
Definition: Data revealing whether an individual is or was a member of a trade union. Includes union dues deductions from payroll, attendance at union meetings, and communications with union representatives.
Examples at Vanguard Financial Services:
Definition: Personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or health of that natural person, resulting in particular from an analysis of a biological sample from the natural person in question.
Examples at Vanguard Financial Services:
Regulatory Note: The Genetic Information Nondiscrimination Act (GINA) in the US prohibits use of genetic information in health insurance and employment. In the EU, genetic data receives dual protection under both Art. 9 and specific Member State genetic data legislation.
Definition: Personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.
Critical Distinction: Biometric data is special category ONLY when processed "for the purpose of uniquely identifying a natural person" (Art. 9(1)). A photograph stored in an HR file is personal data but not special category. The same photograph processed through facial recognition software for access control is special category biometric data.
Examples at Vanguard Financial Services:
Key Precedent: Clearview AI — CNIL Decision SAN-2022-019 (20 October 2022) — EUR 20 million fine for processing biometric data (facial recognition) without lawful basis and without conducting DPIA.
Definition: Personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about their health status. Recital 35 specifies this includes data pertaining to the health status of a data subject which reveals information relating to the past, current, or future physical or mental health of the data subject, including: registration for health care services, number/symbol/identifier assigned for health purposes, information derived from testing or examination of a body part or bodily substance, and any information on a disease, disability, disease risk, medical history, clinical treatment, or physiological or biomedical condition.
Examples at Vanguard Financial Services:
Breadth of Health Data: The CJEU has interpreted health data broadly. In Case C-184/20 (Vyriausioji tarnybinės etikos komisija, 2022), the Court held that data which indirectly reveals health information (such as a spouse's name in a declaration of interests that could reveal sexual orientation or health status) may constitute special category data.
Definition: Data concerning sexual behaviour, sexual preferences, or sexual orientation. Includes data from which sexual orientation can be inferred.
Examples at Vanguard Financial Services:
Processing of special category data is lawful ONLY when one of these conditions is met (in addition to Art. 6 lawful basis):
| Condition | Art. 9(2) | Requirements | Vanguard Application |
|---|---|---|---|
| Explicit consent | (a) | Must be freely given, specific, informed, unambiguous, and EXPLICIT (higher standard than Art. 6(1)(a) consent). Must be a clear affirmative statement, not implied. | Employee diversity monitoring with opt-in explicit consent |
| Employment and social security law | (b) | Processing necessary for obligations under employment, social security, or social protection law. Must be authorised by EU or Member State law or collective agreement with appropriate safeguards. | Payroll processing of trade union dues, occupational health assessments required by law |
| Vital interests | (c) | Processing necessary to protect vital interests where data subject is physically or legally incapable of giving consent. | Emergency medical situations where employee is incapacitated |
| Legitimate activities of non-profit | (d) | Processing by foundation, association, or not-for-profit body with political, philosophical, religious, or trade union aims, relating to members or regular contacts, with no disclosure outside the body without consent. | Not applicable to Vanguard (commercial entity) |
| Data manifestly made public | (e) | Data subject has manifestly made the data public (e.g., publicly declared political views on social media, public disclosure of health condition). | Customer data voluntarily posted on public forums |
| Legal claims | (f) | Processing necessary for establishment, exercise, or defence of legal claims, or whenever courts are acting in their judicial capacity. | Litigation holds involving health data in employment disputes |
| Substantial public interest | (g) | Processing necessary for reasons of substantial public interest, on basis of EU or Member State law, proportionate to the aim, with appropriate safeguards. | Regulatory reporting obligations (e.g., AML suspicious activity involving special category data) |
| Health care and occupational medicine | (h) | Processing necessary for preventive or occupational medicine, assessment of working capacity, medical diagnosis, health/social care provision, or management of health systems. Must be processed by or under responsibility of a professional with secrecy obligation. | Occupational health surveillance mandated by workplace health regulations |
| Public health | (i) | Processing necessary for public health reasons such as protection against serious cross-border threats to health, ensuring high standards of quality and safety for medicines/medical devices. | COVID-19 workplace safety measures (now largely wound down) |
| Archiving, research, statistics | (j) | Processing necessary for archiving in the public interest, scientific or historical research, or statistical purposes under Art. 89(1), with appropriate safeguards including data minimisation. | Internal workforce diversity statistical analysis |
| Indicator Type | Detection Approach | Special Category Flag |
|---|---|---|
| Field names containing health terminology | Regex pattern matching: `diagnosis | symptom |
| ICD-10/ICD-11 codes | Code format detection: [A-Z][0-9]{2}(\.[0-9]{1,4})? | Health data |
| Biometric template formats | Binary header detection for ISO 19795, ANSI/INCITS 378 fingerprint templates | Biometric data |
| Diversity form fields | Field labels matching: `ethnicity | race |
| Genetic marker identifiers | SNP identifiers (rs-numbers), gene names (HUGO nomenclature) | Genetic data |
Processing activities that warrant manual special category review:
Under Art. 35(3)(b), processing special category data on a large scale automatically triggers a mandatory DPIA. For Vanguard Financial Services:
| Processing Activity | Scale Assessment | DPIA Required? |
|---|---|---|
| Employee health records | 12,000 employees — large scale for employer | YES |
| Fingerprint access control | All office buildings, 8,500 users | YES |
| Customer KYC photographs | 2.4 million customers | YES (if facial recognition applied) |
| Diversity monitoring survey | Voluntary, ~3,000 respondents | YES (special category + employment context) |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/special-category-data of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Special Category Data next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Special Category Data this skillmukul975/Privacy-Data-Protection-Skills | 297 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | |
| Dsgvo Health Data Complianceahmadvh/octochains | 376 | — | ~403 | Automated safety check: Pass | Custom licence | |
| Uae GrcSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Privacy Policygustavscirulis/snapgrid | 117 | 1 repos | ~3k | Automated safety check: Pass | Custom licence | |
| Privacy Publishrshankras/claude-code-apple-skills | 785 | — | ~911 | Automated safety check: Notes | MIT | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 |
ahmadvh/octochains
Audits architectural proposals and data schemas for GDPR/DSGVO Article 9 (Special Categories of Personal Data) violations.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
United Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router.
gustavscirulis/snapgrid
Generate privacy policies, terms of service, and EULAs for Apple platform apps.
rshankras/claude-code-apple-skills
Turn drafted legal docs (privacy policy, terms) into hosted pages and set the App Store Connect Privacy Policy / Support / Marketing URLs via the ASC REST API.
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Identifies and classifies GDPR Art. An agent skill from mukul975/Privacy-Data-Protection-Skills. Special Category Data is an agent skill from mukul975/Privacy-Data-Protection-Skills. Identifies and classifies GDPR Art.
Special Category Data fits situations like: tasks that involve Privacy and GDPR; tasks that involve Health and fitness tracking.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a claude-code`. Or copy the skill folder (skills/privacy/special-category-data in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/special-category-data in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a codex`. Or copy the skill folder (skills/privacy/special-category-data in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/special-category-data in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill special-category-data -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/special-category-data, .gemini/skills/special-category-data, .github/skills/special-category-data and .opencode/skills/special-category-data in your project.
Going by SKILL.md and its folder, Special Category Data needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Special Category Data is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Special Category Data: Dsgvo Health Data Compliance (ahmadvh/octochains, 376 stars), Uae Grc (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars), Privacy Policy (gustavscirulis/snapgrid, 117 stars) and Privacy Publish (rshankras/claude-code-apple-skills, 785 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.