Agent skill

Us Privacy Federal

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the…

Apache-2.0Auto-check passedLegal & Compliance

Install Us Privacy Federal

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill us-privacy-federal -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills us-privacy-federal --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/us-privacy-federal .claude/skills/us-privacy-federal && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
us-privacy-federal
GitHub stars
301
Token cost
~2.5k tokens
SKILL.md length
1,149 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the…

  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Federal Sectoral Privacy Laws, FTC Section 5 Authority and Federal Preemption…, plus 2 more sections
  • Runs Python scripts from its folder
  • Tasks that involve Healthcare and finance regulation

What it does

Us Privacy Federal is an agent skill from mukul975/Privacy-Data-Protection-Skills. Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Healthcare and finance regulation. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Healthcare and finance regulation

Example prompts

  • “/us-privacy-federal”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Us Privacy Federal loads about 2.5k tokens when it runs, and up to ~6.7k if it reads all its reference files. Until then it costs about 87 tokens; SKILL.md has 1,149 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,149 words, ~2,495 tokens.

Download SKILL.mdSave it as .claude/skills/us-privacy-federal/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
us-privacy-federal
description
Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
us-state-privacy-laws
metadata.tags
federal-privacy, hipaa, glba, ferpa, coppa, fcra, ftc, sectoral-privacy

US Federal Privacy Landscape

Overview

The United States does not have a single comprehensive federal data protection law equivalent to the GDPR. Instead, the US employs a sectoral approach, with federal laws addressing privacy in specific contexts: health care (HIPAA), financial services (GLBA), children's online data (COPPA), education (FERPA), consumer reporting (FCRA), electronic communications (ECPA), and video rental records (VPPA). The Federal Trade Commission (FTC) exercises broad privacy enforcement authority under Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices. This patchwork creates a complex compliance landscape that requires mapping federal obligations alongside the growing number of state comprehensive privacy laws.

Federal Sectoral Privacy Laws

Health Insurance Portability and Accountability Act (HIPAA)
  • Statute: Pub. L. 104-191 (1996); HITECH Act, Pub. L. 111-5 (2009)
  • Regulations: 45 CFR Parts 160, 162, 164
  • Scope: Covered entities (health plans, health care clearinghouses, health care providers who transmit health information electronically) and their business associates
  • Key Requirements:
    • Privacy Rule (45 CFR 164 Subpart E): use and disclosure limitations for Protected Health Information (PHI)
    • Security Rule (45 CFR 164 Subpart C): administrative, physical, and technical safeguards for ePHI
    • Breach Notification Rule (45 CFR 164 Subpart D): notification to individuals, HHS, and media for breaches of unsecured PHI
    • Individual rights: access, amendment, accounting of disclosures, restriction requests
  • Enforcement: HHS Office for Civil Rights (OCR); state attorneys general
  • Penalties: Up to USD 2,067,813 per violation per calendar year (2024 adjusted); criminal penalties up to USD 250,000 and 10 years imprisonment
Gramm-Leach-Bliley Act (GLBA)
  • Statute: Pub. L. 106-102 (1999)
  • Regulations: Regulation P (12 CFR 1016); FTC Safeguards Rule (16 CFR 314)
  • Scope: Financial institutions — broadly defined to include entities significantly engaged in financial activities (banks, insurance companies, securities firms, but also tax preparers, auto dealers offering financing, etc.)
  • Key Requirements:
    • Financial Privacy Rule: notice of privacy practices and opt-out for sharing with non-affiliated third parties
    • Safeguards Rule: comprehensive information security programme with risk assessment, access controls, encryption, multi-factor authentication, incident response
    • Pretexting protections: prohibition on obtaining customer information through false pretences
  • Enforcement: Prudential regulators (OCC, Fed, FDIC, NCUA), FTC, state insurance regulators, SEC, CFTC
  • 2023 Amendments: FTC Safeguards Rule substantially updated effective June 2023 — mandatory encryption, MFA, CISO designation, written incident response plan, periodic penetration testing
Family Educational Rights and Privacy Act (FERPA)
  • Statute: 20 U.S.C. 1232g; 34 CFR Part 99
  • Scope: Educational agencies and institutions receiving federal funding
  • Key Requirements:
    • Parents (or eligible students over 18) have the right to access education records and request amendments
    • Written consent required before disclosure of personally identifiable information from education records, with exceptions (directory information, legitimate educational interest, health/safety emergency, judicial order)
    • Annual notification of rights
  • Enforcement: US Department of Education, Family Policy Compliance Office
  • Penalties: Withdrawal of federal funding (in practice, compliance agreements and corrective action)
Children's Online Privacy Protection Act (COPPA)
  • Statute: 15 U.S.C. 6501-6506 (1998)
  • Regulations: 16 CFR Part 312 (COPPA Rule)
  • Scope: Operators of commercial websites and online services directed to children under 13, or that have actual knowledge of collecting personal information from children under 13
  • Key Requirements:
    • Verifiable parental consent before collecting personal information from children
    • Clear privacy notice describing information practices
    • Parents' rights: review, delete, refuse further collection
    • Reasonable security measures
    • Data retention limitations
  • Enforcement: FTC; state attorneys general
  • Penalties: Up to USD 50,120 per violation (2024 adjusted)
Fair Credit Reporting Act (FCRA)
  • Statute: 15 U.S.C. 1681 et seq. (1970, amended by FACTA 2003)
  • Scope: Consumer reporting agencies, users of consumer reports, furnishers of information
  • Key Requirements:
    • Permissible purpose required to obtain consumer reports (credit, employment, insurance, government benefit, legitimate business need)
    • Accuracy obligations for furnishers
    • Consumer rights: free annual report, dispute inaccurate information, fraud alerts, credit freezes
    • Adverse action notices when consumer report information is used against the consumer
  • Enforcement: CFPB, FTC, state attorneys general
  • Private Right of Action: Yes — statutory damages, actual damages, attorney's fees
Electronic Communications Privacy Act (ECPA)
  • Statute: 18 U.S.C. 2510-2522 (Wiretap Act), 18 U.S.C. 2701-2712 (Stored Communications Act), 18 U.S.C. 3121-3127 (Pen Register Act)
  • Scope: Interception of electronic communications, access to stored electronic communications, pen register and trap-and-trace devices
  • Key Requirements:
    • Wiretap Act: prohibits intentional interception of wire, oral, or electronic communications (with consent and law enforcement exceptions)
    • Stored Communications Act: protects stored electronic communications from unauthorised access; governs law enforcement access
    • Pen Register Act: regulates real-time collection of metadata
  • Enforcement: DOJ (criminal); private right of action (Wiretap Act and SCA)
Show full SKILL.md (421 more words)Show less
Video Privacy Protection Act (VPPA)
  • Statute: 18 U.S.C. 2710 (1988)
  • Scope: Video tape service providers (interpreted broadly to include streaming services)
  • Key Requirements: Prohibits disclosure of personally identifiable rental or purchase information without consumer consent
  • Enforcement: Private right of action; actual damages, punitive damages, attorney's fees
  • Note: Increasingly relevant to streaming and OTT platforms; active plaintiff class action litigation

FTC Section 5 Authority

The FTC's authority under Section 5 of the FTC Act (15 U.S.C. 45(a)) serves as a de facto federal privacy enforcement baseline:

  • Unfairness prong: Practice causes or is likely to cause substantial injury not reasonably avoidable and not outweighed by countervailing benefits
  • Deception prong: Material representation, omission, or practice likely to mislead consumers acting reasonably
  • Privacy-specific enforcement areas:
    • Failure to honour privacy policy commitments
    • Inadequate data security practices
    • Deceptive data collection and sharing
    • Dark patterns in consent interfaces
    • Children's privacy violations (COPPA enforcement)
    • Health data practices (Health Breach Notification Rule, 16 CFR 318)
FTC Health Breach Notification Rule (16 CFR Part 318)
  • Applies to vendors of personal health records and PHR-related entities NOT covered by HIPAA
  • Requires notification to FTC, individuals, and media of breaches of unsecured health information
  • FTC has expanded interpretation to include health apps and connected devices

Federal Preemption Considerations

The interaction between federal sectoral laws and state comprehensive privacy laws creates complex preemption questions:

  • HIPAA: Preempts state laws that are contrary to HIPAA, but state laws providing greater protection survive (45 CFR 160.203)
  • GLBA: Financial Privacy Rule preempts inconsistent state laws; Safeguards Rule does not preempt stricter state requirements
  • FCRA: Broad preemption of state laws in areas where FCRA is comprehensive (Section 1681t)
  • COPPA: Does not preempt state laws that are not inconsistent
  • State privacy laws: Generally exempt HIPAA-covered data, GLBA-covered data, and FCRA-regulated activities from scope

Proposed Federal Comprehensive Legislation

American Data Privacy and Protection Act (ADPPA)
  • H.R. 8152, 117th Congress (2022) — advanced through committee but not enacted
  • Would have established federal consumer privacy rights: access, correction, deletion, portability, opt-out of targeted advertising
  • Key unresolved issue: scope of federal preemption over state laws (especially California CCPA/CPRA)
American Privacy Rights Act (APRA)
  • Discussion draft, 118th Congress (2024)
  • Bipartisan proposal with data minimisation requirements, private right of action, and FTC enforcement
  • Preemption provisions remain the primary obstacle to enactment

Integration Points

  • 42-cfr-part-2: Substance use disorder records under federal confidentiality protections
  • hipaa-compliance: HIPAA Privacy, Security, and Breach Notification Rules
  • state-law-tracker: Federal-state interaction and preemption analysis
  • vendor-privacy-due-diligence: Business associate agreements (HIPAA) and service provider requirements (GLBA)
  • children-data-protection: COPPA compliance for services directed at or used by children

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/us-privacy-federal of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Us Privacy Federal next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Us Privacy Federal compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Us Privacy Federal this skillmukul975/Privacy-Data-Protection-Skills301—~2.5kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Anne WojcickiK-Dense-AI/mimeographs129—~1.5kAutomated safety check: PassMIT
Dpa Checklist ReviewLegalQuants/lq-ai150—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Anne Wojcicki

    K-Dense-AI/mimeographs

    Applies the strategic frameworks and mental models of Anne Wojcicki, co-founder and CEO of 23andMe.

    129 GitHub stars~1.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Dpa Checklist Review

    LegalQuants/lq-ai

    A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…

    150 GitHub stars~3.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Auditing Deidentification Runs

    maziyarpanahi/openmed

    Produce a signed, reproducible, no-PHI audit trail for an OpenMed de-identification run via deidentify(audit=True).

    5.5k GitHub stars~1.8k tokensUpdated today
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Us Privacy Federal

What does Us Privacy Federal do?

Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the…. Us Privacy Federal is an agent skill from mukul975/Privacy-Data-Protection-Skills. Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes.

When should I use Us Privacy Federal?

Us Privacy Federal fits situations like: tasks that involve Privacy and GDPR; tasks that involve Healthcare and finance regulation.

How do I install Us Privacy Federal in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill us-privacy-federal -a claude-code`. Or copy the skill folder (skills/privacy/us-privacy-federal in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/us-privacy-federal in your project. Claude Code loads it when a task matches its description.

How do I install Us Privacy Federal in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill us-privacy-federal -a codex`. Or copy the skill folder (skills/privacy/us-privacy-federal in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/us-privacy-federal in your project. Codex loads it when a task matches its description.

Can I use Us Privacy Federal in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill us-privacy-federal -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/us-privacy-federal, .gemini/skills/us-privacy-federal, .github/skills/us-privacy-federal and .opencode/skills/us-privacy-federal in your project.

What does Us Privacy Federal need to run?

Going by SKILL.md and its folder, Us Privacy Federal needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Us Privacy Federal access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Us Privacy Federal safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Us Privacy Federal use?

Us Privacy Federal is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Us Privacy Federal use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.2k tokens, read only when the agent opens those files.

What are the alternatives to Us Privacy Federal?

Skills that share tags, products or a category with Us Privacy Federal: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Audit Report (harness/harness-skills, 115 stars) and Anne Wojcicki (K-Dense-AI/mimeographs, 129 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Us Privacy Federal?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.