C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Guides maintenance of cross-border transfer registers, audit trails, and compliance documentation under GDPR Art.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill transfer-records -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills transfer-records --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/transfer-records .claude/skills/transfer-records && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "transfer-records" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-records into .claude/skills/transfer-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "transfer-records", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-recordsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill transfer-records -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills transfer-records --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/transfer-records .agents/skills/transfer-records && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "transfer-records" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-records into .agents/skills/transfer-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "transfer-records", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill transfer-records -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills transfer-records --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/transfer-records .cursor/skills/transfer-records && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "transfer-records" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-records into .cursor/skills/transfer-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "transfer-records", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/transfer-records--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill transfer-records -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills transfer-records --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/transfer-records .gemini/skills/transfer-records && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "transfer-records" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-records into .gemini/skills/transfer-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "transfer-records", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills transfer-recordsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill transfer-records -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/transfer-records .github/skills/transfer-records && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "transfer-records" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-records into .github/skills/transfer-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "transfer-records", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill transfer-records -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills transfer-records --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/transfer-records .opencode/skills/transfer-records && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "transfer-records" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/transfer-records into .opencode/skills/transfer-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "transfer-records", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
transfer-recordsGuides maintenance of cross-border transfer registers, audit trails, and compliance documentation under GDPR Art.
Transfer Records is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides maintenance of cross-border transfer registers, audit trails, and compliance documentation under GDPR Art. 30 and Art. 46, EDPB record-keeping guidance, and supervisory authority expectations. Keywords: transfer register, audit trail, Art. 30, Art. 46, documentation, compliance records.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Transfer Records loads about 3.2k tokens when it runs, and up to ~7.6k if it reads all its reference files. Until then it costs about 78 tokens; SKILL.md has 1,484 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,484 words, ~3,156 tokens.
.claude/skills/transfer-records/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Maintaining comprehensive transfer records and documentation is a foundational obligation under the GDPR and a practical necessity for demonstrating compliance with cross-border data transfer requirements. Articles 5(2) and 24 impose a general accountability obligation, while Article 30 mandates specific records of processing activities — including details of international transfers. Beyond these baseline requirements, each transfer mechanism (SCCs, BCRs, adequacy reliance, derogations) carries its own documentation expectations. This skill provides a structured approach to building, maintaining, and auditing transfer records across all mechanisms.
Every cross-border transfer must be documented with the following information:
| Field | Description | Legal Basis |
|---|---|---|
| Transfer ID | Unique identifier for the transfer entry | Internal governance |
| Data Exporter | Identity and contact details of the transferring entity | Art. 30(1)(a) |
| Data Importer | Identity and contact details of the receiving entity | Art. 30(1)(a) |
| Exporter Country | Country from which data is transferred | Art. 30(1)(e) |
| Importer Country | Destination country or international organisation | Art. 30(1)(e) |
| Categories of Data Subjects | Types of individuals whose data is transferred | Art. 30(1)(c) |
| Categories of Personal Data | Types of personal data transferred | Art. 30(1)(c) |
| Special Category Data | Whether Art. 9 special categories are included | Art. 9(1), Art. 30(1)(c) |
| Purpose of Transfer | Business and legal purpose for the transfer | Art. 30(1)(b) |
| Legal Basis for Processing | Lawful basis under Art. 6 (and Art. 9 if applicable) | Art. 30(1)(b) |
| Transfer Mechanism | The Chapter V mechanism relied upon | Art. 30(1)(e), Art. 46 |
| Mechanism Reference | SCC execution date, BCR approval reference, adequacy decision reference, etc. | Art. 46 |
| TIA Reference | Reference to the Transfer Impact Assessment (if applicable) | EDPB Rec. 01/2020 |
| Supplementary Measures | Technical, contractual, and organisational measures applied | EDPB Rec. 01/2020 |
| Data Retention Period | How long transferred data will be retained by the importer | Art. 30(1)(f) |
| Review Date | Next scheduled review date for the transfer | Accountability (Art. 5(2)) |
| Status | Active, Under Review, Suspended, Terminated | Internal governance |
| Risk Rating | Overall risk assessment (Low, Medium, High, Critical) | Accountability (Art. 5(2)) |
For SCC-based transfers:
| Field | Description |
|---|---|
| SCC Module | Module 1 (C2C), 2 (C2P), 3 (P2P), or 4 (P2C) |
| SCC Execution Date | Date the SCCs were signed by both parties |
| SCC Annex I Completed | Whether the transfer description annex is completed |
| SCC Annex II Completed | Whether the technical/organisational measures annex is completed |
| SCC Annex III Completed | Whether the sub-processor list is completed (Modules 2/3) |
| Clause 7 Docking | Whether a docking clause has been used for additional parties |
For BCR-based transfers:
| Field | Description |
|---|---|
| BCR Approval Authority | Lead supervisory authority that approved the BCRs |
| BCR Approval Date | Date of BCR approval |
| BCR Version | Current version of the BCRs |
| Entity Coverage | Whether the specific entities are listed in the BCR member list |
| BCR Audit Date | Date of last BCR compliance audit |
For adequacy-based transfers:
| Field | Description |
|---|---|
| Adequacy Decision Reference | EC decision number and date |
| Adequacy Scope | Full or partial adequacy; any sector/type limitations |
| Adequacy Review Date | Date of next EC review of the adequacy decision |
| Monitoring Status | Whether developments in the destination country are being tracked |
For Art. 49 derogation-based transfers:
| Field | Description |
|---|---|
| Derogation Relied Upon | Specific Art. 49 paragraph |
| Necessity Assessment | Documentation of why the transfer is strictly necessary |
| Frequency | Whether the transfer is occasional or repetitive |
| DPA Notification | Whether the supervisory authority has been informed (Art. 49(1)(2)) |
The audit trail for transfer records must capture:
| Event Type | Details to Log | Retention |
|---|---|---|
| Transfer Created | Creator identity, creation date, all initial field values | Life of transfer + 5 years |
| Transfer Modified | Modifier identity, modification date, field changed, old value, new value | Life of transfer + 5 years |
| Mechanism Changed | Old mechanism, new mechanism, reason for change, approver | Life of transfer + 5 years |
| TIA Completed/Updated | TIA reference, assessment date, outcome, assessor | Life of transfer + 5 years |
| Review Conducted | Reviewer identity, review date, outcome, next review date | Life of transfer + 5 years |
| Transfer Suspended | Suspension date, reason, authoriser | Life of transfer + 5 years |
| Transfer Terminated | Termination date, reason, data return/deletion confirmation | Life of transfer + 5 years |
| Document Attached | Document type, filename, upload date, uploader | Life of transfer + 5 years |
| SA Inquiry Received | Inquiry reference, SA identity, date, scope | Life of transfer + 10 years |
A complete SCC documentation package for each transfer includes:
Supervisory authorities expect organisations to produce the following within a reasonable timeframe (typically 2-4 weeks):
| Finding | Description | Remediation |
|---|---|---|
| Incomplete register | Missing transfers or incomplete fields | Conduct full inventory; populate all mandatory fields |
| Stale TIAs | TIAs not updated after significant legal developments | Establish TIA review triggers and periodic review schedule |
| Missing execution dates | SCCs without documented execution dates | Obtain signed copies with dates; implement document management |
| No review schedule | No evidence of periodic transfer reviews | Establish annual review cycle; document in governance framework |
| Inadequate audit trail | Changes to transfer records not tracked | Implement audit logging; migrate to system with built-in audit trail |
| Missing sub-processor records | Incomplete or outdated sub-processor lists | Audit sub-processor chains; update SCC Annex III |
| Quarter | Activity |
|---|---|
| Q1 | Full transfer register review: verify all active transfers, close terminated transfers, update mechanism status |
| Q2 | TIA refresh: reassess all transfers to non-adequate countries against current legal developments |
| Q3 | Mechanism review: verify SCC execution dates, BCR compliance, adequacy decision status, derogation continuing necessity |
| Q4 | Governance review: assess documentation completeness, audit trail integrity, SA readiness, update policies |
In addition to the annual cycle, reviews must be triggered by:
| Transfer ID | Exporter | Importer | Dest Country | Mechanism | TIA Ref | Review Date | Status |
|---|---|---|---|---|---|---|---|
| ATH-INT-001 | Athena GmbH (DE) | TransPacific Ltd (HK) | Hong Kong | SCCs Module 2 | TIA-2024-003 | 2025-06-30 | Active |
| ATH-INT-002 | Athena GmbH (DE) | CloudVault Pte Ltd (SG) | Singapore | SCCs Module 3 | TIA-2024-005 | 2025-06-30 | Active |
| ATH-INT-003 | Athena GmbH (DE) | Athena Japan KK (JP) | Japan | EU Adequacy (2019/419) | N/A | 2025-12-31 | Active |
| ATH-INT-004 | Athena GmbH (DE) | Athena India Pvt Ltd (IN) | India | SCCs Module 1 | TIA-2024-008 | 2025-06-30 | Active |
| ATH-INT-005 | Athena GmbH (DE) | Pinnacle TH (TH) | Thailand | SCCs Module 3 | TIA-2024-010 | 2025-06-30 | Active |
| ATH-INT-006 | Athena GmbH (DE) | Athena US Inc (US) | United States | DPF + SCCs fallback | TIA-2024-012 | 2025-06-30 | Active |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/transfer-records of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Transfer Records next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Transfer Records this skillmukul975/Privacy-Data-Protection-Skills | 297 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 586 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Guides maintenance of cross-border transfer registers, audit trails, and compliance documentation under GDPR Art. Transfer Records is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides maintenance of cross-border transfer registers, audit trails, and compliance documentation under GDPR Art.
Transfer Records fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill transfer-records -a claude-code`. Or copy the skill folder (skills/privacy/transfer-records in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/transfer-records in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill transfer-records -a codex`. Or copy the skill folder (skills/privacy/transfer-records in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/transfer-records in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill transfer-records -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/transfer-records, .gemini/skills/transfer-records, .github/skills/transfer-records and .opencode/skills/transfer-records in your project.
Going by SKILL.md and its folder, Transfer Records needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Transfer Records is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Transfer Records: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.