Data Protection And Encryption
cbrock84/headcount
Protects data itself rather than the systems around it — classifying what you hold, encrypting in transit and at rest and understanding what each actually defends against, managing keys and their…
Guides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill supplementary-measures -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills supplementary-measures --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/supplementary-measures .claude/skills/supplementary-measures && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "supplementary-measures" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/supplementary-measures into .claude/skills/supplementary-measures/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supplementary-measures", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/supplementary-measuresType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill supplementary-measures -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills supplementary-measures --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/supplementary-measures .agents/skills/supplementary-measures && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "supplementary-measures" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/supplementary-measures into .agents/skills/supplementary-measures/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supplementary-measures", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill supplementary-measures -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills supplementary-measures --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/supplementary-measures .cursor/skills/supplementary-measures && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "supplementary-measures" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/supplementary-measures into .cursor/skills/supplementary-measures/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supplementary-measures", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/supplementary-measures--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill supplementary-measures -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills supplementary-measures --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/supplementary-measures .gemini/skills/supplementary-measures && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "supplementary-measures" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/supplementary-measures into .gemini/skills/supplementary-measures/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supplementary-measures", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills supplementary-measuresInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill supplementary-measures -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/supplementary-measures .github/skills/supplementary-measures && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "supplementary-measures" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/supplementary-measures into .github/skills/supplementary-measures/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supplementary-measures", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill supplementary-measures -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills supplementary-measures --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/supplementary-measures .opencode/skills/supplementary-measures && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "supplementary-measures" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/supplementary-measures into .opencode/skills/supplementary-measures/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supplementary-measures", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
supplementary-measuresGuides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020.
Supplementary Measures is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020. Covers encryption, pseudonymisation, split processing, audit rights, transparency obligations, and internal policies. Keywords: supplementary measures, encryption, pseudonymisation, EDPB recommendations, transfer safeguards.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Cryptography and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Supplementary Measures loads about 3.8k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 101 tokens; SKILL.md has 1,875 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,875 words, ~3,792 tokens.
.claude/skills/supplementary-measures/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.EDPB Recommendations 01/2020 (Version 2.0, adopted 18 June 2021) establish that where a Transfer Impact Assessment reveals protection gaps in the destination country's legal framework, supplementary measures must be adopted to bring the level of protection up to the EU standard of essential equivalence. These measures fall into three categories: technical, contractual, and organisational. The measures must be effective in practice — not merely theoretical — and their effectiveness must be reassessed at appropriate intervals.
Description: Personal data is encrypted before leaving the EU/EEA using strong encryption algorithms, with decryption keys held exclusively by the data exporter or a trusted entity within the EU/EEA. The data importer in the third country receives and stores only ciphertext.
Technical specification at Athena Global Logistics:
Effectiveness: High — the third-country government cannot compel the importer to produce plaintext data because the importer does not possess the decryption keys. This measure is effective against compelled disclosure at rest and in transit.
Limitation: Only applicable where the importer does not need to process the data in plaintext. If the importer must read, analyse, or transform the data, this measure alone is insufficient.
Applicable scenario: Backup storage, archival, and transit-only scenarios where the importer serves as a conduit or storage provider.
Description: Directly identifying personal data elements are replaced with pseudonymous identifiers before transfer. The mapping table linking pseudonyms to real identities is held exclusively by the data exporter within the EU/EEA.
Technical specification at Athena Global Logistics:
Effectiveness: High — the transferred dataset cannot be attributed to identified natural persons by the importer or any third party (including government authorities) without access to the mapping table.
Limitation: Requires that the importer can fulfil its processing purpose without accessing the original identifying data. Not suitable where the importer must contact data subjects directly or produce documentation bearing real names.
Description: The processing operation is divided such that no single entity in the third country holds the complete dataset. Each fragment, viewed in isolation, does not constitute personal data or cannot be attributed to an identified individual.
Technical specification at Athena Global Logistics:
Effectiveness: High — neither the importer nor the destination country government can reconstruct the full personal dataset from the transferred fragment alone.
Limitation: Requires significant architectural investment and may reduce the importer's processing efficiency. Applicable only where the processing can be meaningfully divided.
Description: All data transfers are protected by transport-layer security (TLS 1.3 or equivalent) to prevent interception in transit.
Technical specification at Athena Global Logistics:
Effectiveness: Medium — protects data against interception in transit by third parties but does not protect against compelled disclosure of data at rest by the importer or government authorities accessing the importer's systems.
Applicable as: Baseline measure for all transfers, combined with other measures for comprehensive protection.
Description: Personal data is irreversibly anonymised before transfer, rendering the transferred dataset outside the scope of the GDPR (Recital 26).
Technical specification at Athena Global Logistics:
Effectiveness: Complete — anonymised data is not personal data and Chapter V transfer rules do not apply. However, the utility of the data for the importer may be significantly reduced.
Contractual clause: The data importer undertakes to challenge any government access request that: (a) is disproportionate to the stated legal objective; (b) exceeds the scope authorised by the applicable legislation; (c) is incompatible with the protections afforded by the SCCs. The importer shall exhaust all available legal remedies before disclosing any data in response to a government request.
Implementation at Athena Global Logistics: Included as Clause 3.1 of the SCC Supplementary Measures Addendum executed with TransPacific Freight Solutions Ltd on 15 March 2025.
Contractual clause: The data importer shall notify the data exporter within 48 hours of receiving any government access request relating to transferred personal data. Where local law prohibits notification, the importer shall use best efforts to obtain a waiver of the prohibition and shall, at minimum, provide aggregated statistical information about government requests received on an annual basis.
Implementation: Included as Clause 3.2 of the SCC Supplementary Measures Addendum. Additionally, TransPacific Freight Solutions publishes an annual transparency report covering all government data access requests by jurisdiction and legal basis.
Contractual clause: The data exporter or its designated independent auditor has the right to conduct on-site or remote audits of the data importer's data processing facilities, systems, and records at least once during each 12-month period, with 30 days' prior written notice. The importer shall cooperate fully with the audit and provide access to all relevant personnel, systems, and documentation.
Implementation: Included in SCC Clause 8.9 and supplemented by Clause 3.3 of the Addendum specifying the audit scope, methodology, and reporting requirements.
Contractual clause: The data importer shall publish a monthly statement confirming that, during the preceding month, it has not received any government order that would require the disclosure of transferred personal data under circumstances that would prevent notification to the data exporter. The absence of such a statement shall serve as notice to the exporter.
Implementation: TransPacific Freight Solutions publishes the warrant canary statement on the 5th business day of each month on a dedicated page of its corporate website accessible to Athena Global Logistics.
Contractual clause: The data importer shall not transfer, store, or process the transferred personal data in any jurisdiction other than the agreed destination country (Hong Kong SAR) without the prior written consent of the data exporter. Sub-processor processing in other jurisdictions requires execution of separate SCCs or equivalent safeguards.
Implementation: Included as Clause 3.5 of the Addendum; enforced through technical controls restricting data replication to the Hong Kong data centre only.
Description: The data importer implements strict role-based access controls limiting data access to the minimum number of named personnel with a documented business need.
Implementation at TransPacific Freight Solutions:
Description: The data importer publishes periodic transparency reports detailing the number and nature of government data access requests received, to the extent permitted by local law.
Implementation: Annual transparency report published in Q1 covering the preceding calendar year. Report includes: number of requests by jurisdiction, legal basis cited, data categories requested, and outcome (full disclosure, partial disclosure, challenge, withdrawal).
Description: The data importer obtains and maintains independent certification against ISO 27001:2022 (information security) and ISO 27701:2019 (privacy information management), providing third-party verification that technical and organisational measures meet international standards.
Implementation: TransPacific Freight Solutions certified to ISO 27001:2022 (certificate valid to 31 December 2026) and ISO 27701:2019 (certificate valid to 31 December 2026). Surveillance audits conducted annually by TUV Rheinland.
Description: Documented procedure for the importer to escalate data protection incidents, including government access events, to the exporter within defined timeframes.
Implementation:
| Measure | Technical Risk Addressed | Effectiveness Against Compelled Disclosure | Effectiveness Against Bulk Surveillance | Residual Risk |
|---|---|---|---|---|
| T1 — E2E encryption with EU keys | Data at rest and in transit | High | High | None if keys remain in EU |
| T2 — Pseudonymisation | Re-identification | High | High | Low — sophisticated attacks may enable re-identification through auxiliary data |
| T3 — Split processing | Complete dataset exposure | High | High | Low — requires careful architecture to prevent fragment recombination |
| T4 — TLS 1.3 | Transit interception | High (transit only) | Medium | Medium — does not protect at rest |
| T5 — Anonymisation | All — data is no longer personal | Complete | Complete | None — but utility is reduced |
| C1 — Challenge obligation | Disproportionate requests | Medium | Low | Medium — effectiveness depends on importer's legal standing and judiciary |
| C2 — Transparency | Visibility | Medium | Low | Medium — may be blocked by gag orders |
| C3 — Audit rights | Compliance verification | Medium | Low | Medium — retrospective, not preventive |
| C4 — Warrant canary | Gag order detection | Low-Medium | Low | High — indirect signal only |
| O1 — Access policies | Insider risk | Medium | Low | Medium — does not prevent compelled disclosure |
| O2 — Transparency reports | Accountability | Medium | Low | Medium — aggregate data only |
| O3 — ISO certification | Control assurance | Medium | Low | Medium — certification is point-in-time |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/supplementary-measures of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Supplementary Measures next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Supplementary Measures this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Data Protection And Encryptioncbrock84/headcount | 2k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Security Compliancesangrokjung/claude-forge | 852 | 2 repos | ~7.2k | Automated safety check: Pass | MIT | |
| Incident Reporting Navigatordavila7/claude-code-templates | 33k | 1 repos | ~4.7k | Automated safety check: Pass | CC-BY-4.0 | |
| Implementing Hashicorp Vault Dynamic Secretsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~5.2k | Automated safety check: Pass | Apache-2.0 | |
| Performing Ssl Tls Inspection Configurationmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Notes | Apache-2.0 |
cbrock84/headcount
Protects data itself rather than the systems around it — classifying what you hold, encrypting in transit and at rest and understanding what each actually defends against, managing keys and their…
sangrokjung/claude-forge
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…
davila7/claude-code-templates
A skill your agent uses when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU…
mukul975/Anthropic-Cybersecurity-Skills
Configures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates, with automatic generation, lease management, and rotation to eliminate static secrets…
mukul975/Anthropic-Cybersecurity-Skills
Configure SSL/TLS break-and-inspect on next-generation firewalls and forward proxies to decrypt, inspect, and re-encrypt HTTPS traffic for malware and exfiltration detection, including deploying…
alirezarezvani/claude-skills
Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Guides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020. Supplementary Measures is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020.
Supplementary Measures fits situations like: tasks that involve Cryptography; tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill supplementary-measures -a claude-code`. Or copy the skill folder (skills/privacy/supplementary-measures in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/supplementary-measures in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill supplementary-measures -a codex`. Or copy the skill folder (skills/privacy/supplementary-measures in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/supplementary-measures in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill supplementary-measures -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supplementary-measures, .gemini/skills/supplementary-measures, .github/skills/supplementary-measures and .opencode/skills/supplementary-measures in your project.
Going by SKILL.md and its folder, Supplementary Measures needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Supplementary Measures is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Supplementary Measures: Data Protection And Encryption (cbrock84/headcount, 2k stars), Security Compliance (sangrokjung/claude-forge, 852 stars), Incident Reporting Navigator (davila7/claude-code-templates, 33k stars) and Implementing Hashicorp Vault Dynamic Secrets (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.