Agent skill

Vendor Cert Acceptance

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Vendor certification acceptance criteria and equivalence mapping.

Apache-2.0Auto-check passedLegal & Compliance

Install Vendor Cert Acceptance

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-cert-acceptance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-cert-acceptance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/vendor-cert-acceptance .claude/skills/vendor-cert-acceptance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-cert-acceptance
GitHub stars
301
Token cost
~2.7k tokens
SKILL.md length
1,141 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Vendor certification acceptance criteria and equivalence mapping.

  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Recognized Certification…, Certification Equivalence Matrix and Gap Supplementation Requirements, plus 2 more sections
  • Runs Python scripts from its folder
  • Tasks that involve User stories

What it does

Vendor Cert Acceptance is an agent skill from mukul975/Privacy-Data-Protection-Skills. Vendor certification acceptance criteria and equivalence mapping. Covers ISO 27701, SOC 2 Privacy, APEC CBPR, EU Code of Conduct evaluation, certification scope analysis, gap supplementation requirements, and cross-framework equivalence assessment.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR, User stories and SOC 2 and security compliance. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve User stories
  • Tasks that involve SOC 2 and security compliance

Example prompts

  • “/vendor-cert-acceptance”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor Cert Acceptance loads about 2.7k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 68 tokens; SKILL.md has 1,141 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,141 words, ~2,695 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-cert-acceptance/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
vendor-cert-acceptance
description
Vendor certification acceptance criteria and equivalence mapping. Covers ISO 27701, SOC 2 Privacy, APEC CBPR, EU Code of Conduct evaluation, certification scope analysis, gap supplementation requirements, and cross-framework equivalence assessment.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
vendor-privacy-management
metadata.tags
vendor-certification, iso-27701, soc-2-privacy, apec-cbpr, certification-equivalence

Vendor Certification Acceptance Criteria

Overview

GDPR Article 42 establishes a framework for data protection certification mechanisms, and Article 28(5) notes that a processor's adherence to an approved certification mechanism may be used as an element to demonstrate sufficient guarantees. The EDPB Guidelines 07/2020 (paragraph 86) confirm that certifications may serve as indicators of processor reliability, though they do not discharge the controller's obligation to conduct its own assessment.

Vendor certifications and attestations provide structured evidence of control implementation, but their value depends on scope coverage, certification body credibility, recency, and relevance to the specific processing relationship. Summit Cloud Partners maintains a Certification Acceptance Framework that defines which certifications are recognized, how they are evaluated, and what supplementary measures are needed when certification coverage has gaps.

Recognized Certification Frameworks

Tier A: Strong Privacy Certifications

Certifications specifically designed for privacy/data protection management, independently audited.

ISO/IEC 27701:2019 — Privacy Information Management System (PIMS)

AspectDetail
StandardExtension to ISO 27001/27002 for PII management
ScopePII controller (Annex A) and PII processor (Annex B) controls
Certification bodyAccredited ISO certification bodies
Audit typeThird-party certification audit (Stage 1 + Stage 2)
Validity3-year cycle with annual surveillance audits
GDPR relevanceHigh — maps directly to GDPR requirements per Annex D
Acceptance criteriaCertificate scope must cover processing services provided to Summit
VerificationCheck accreditation body registry; verify scope statement
Supplementation neededVerify that Annex B (processor) controls are in scope; if only Annex A (controller), supplementary processor assessment required

GDPR Certification per Article 42

AspectDetail
StandardCertification per criteria approved by supervisory authority or EDPB
Certification bodyAccredited per Article 43 by national accreditation body and supervisory authority
GDPR relevanceMaximum — specifically designed for GDPR compliance demonstration
Acceptance criteriaCertificate issued by Article 43 accredited body; scope covers processing
Current statusVery few Article 42 certifications currently available (as of March 2026)
Supplementation neededMinimal if scope covers all processing activities
Tier B: Strong Security Certifications with Privacy Elements

Certifications primarily security-focused but including privacy-relevant controls.

SOC 2 Type II with Privacy Trust Services Criterion

AspectDetail
StandardAICPA Trust Services Criteria — Privacy criterion
ScopeNotice, choice, collection, use/retention/disposal, access, disclosure, security, quality, monitoring
Audit typeIndependent CPA examination over minimum 6-month period
GDPR relevanceModerate-High — covers many Article 28/32 requirements but US-centric
Acceptance criteriaType II (not Type I); Privacy criterion included; no qualified opinions; scope covers relevant services
VerificationRequest full report under NDA; review scope, findings, exceptions
Supplementation neededGDPR-specific gap assessment required: cross-border transfer controls, DPA-specific obligations, sub-processor cascade

SOC 2 Type II (Security Criterion Only)

AspectDetail
Acceptance criteriaType II; no qualified opinions; scope covers relevant services
GDPR relevanceModerate — covers Article 32 security measures
Supplementation neededFull privacy assessment required for non-security GDPR obligations

ISO/IEC 27001:2022 — Information Security Management System

AspectDetail
Acceptance criteriaCurrent version (2022 preferred); scope covers processing services; accredited certification body
GDPR relevanceModerate — strong for Article 32 security; does not address privacy-specific requirements
Supplementation neededPrivacy gap assessment covering Art. 28(3) obligations, DSR assistance, breach notification, data handling
Tier C: Domain-Specific Certifications

ISO/IEC 27018:2019 — Cloud Privacy

AspectDetail
ScopeCloud-specific PII protection controls
AcceptanceRelevant only for cloud service providers; supplements ISO 27001
SupplementationMust be combined with ISO 27001; does not stand alone

CSA STAR Level 2 — Cloud Security

AspectDetail
ScopeCloud Controls Matrix (CCM) third-party audit
AcceptanceLevel 2 (third-party audit) required; Level 1 (self-assessment) insufficient as standalone
SupplementationCloud security focus; privacy gap assessment required

APEC Cross-Border Privacy Rules (CBPR) System

AspectDetail
ScopeAsia-Pacific cross-border data transfer framework
AcceptanceRecognized for APEC economy vendors; does not substitute for GDPR compliance
GDPR relevanceLimited — different legal framework; may indicate privacy program maturity
SupplementationFull GDPR compliance assessment still required

EU Cloud Code of Conduct (SCOPE Europe)

AspectDetail
StandardGDPR Article 40 approved code of conduct for cloud services
ScopeCloud service provider GDPR compliance
AcceptanceApproved by Belgian DPA as monitoring body (2021)
GDPR relevanceHigh — specifically mapped to GDPR obligations
SupplementationMinimal for in-scope cloud processing; verify monitoring body oversight
Show full SKILL.md (469 more words)Show less
Tier D: Self-Assessments and Basic Certifications
CertificationAcceptance Level
CSA STAR Level 1 (self-assessment)Accepted as supplementary evidence only; not standalone
Vendor privacy policy / self-declarationNot accepted as certification; supplementary only
HITRUST CSFAccepted for healthcare contexts; GDPR gap assessment required
Cyber Essentials (UK)Basic security only; full assessment required

Certification Equivalence Matrix

Maps certification coverage against GDPR Article 28 requirements:

GDPR RequirementISO 27701SOC 2 PrivacySOC 2 SecurityISO 27001ISO 27018Art. 42 Cert
Art. 28(3)(a) Documented instructionsFullPartialNoneNoneFullFull
Art. 28(3)(b) ConfidentialityFullFullPartialFullFullFull
Art. 28(3)(c) Security (Art. 32)FullFullFullFullFullFull
Art. 28(3)(d) Sub-processor mgmtFullPartialNonePartialFullFull
Art. 28(3)(e) DSR assistanceFullPartialNoneNonePartialFull
Art. 28(3)(f) Compliance assistanceFullPartialNoneNoneNoneFull
Art. 28(3)(g) Deletion/returnFullFullNonePartialFullFull
Art. 28(3)(h) Audit rightsFullPartialNonePartialFullFull
Art. 33(2) Breach notificationFullFullPartialPartialPartialFull
Ch. V International transfersPartialNoneNoneNoneNoneFull

Legend: Full = requirement addressed, Partial = partially addressed, None = not addressed

Gap Supplementation Requirements

When a vendor holds certifications that do not fully cover GDPR requirements, Summit Cloud Partners requires supplementary evidence for uncovered obligations:

GapSupplementation Method
DSR assistance capabilityVendor provides DSR handling procedure documentation and SLA commitments
Sub-processor managementVendor provides sub-processor list, notification mechanism, and flow-down DPA sample
Breach notification processVendor provides incident response plan with notification timeframes
International transfer controlsVendor provides Transfer Impact Assessment and supplementary measures documentation
Deletion/return capabilitiesVendor demonstrates deletion procedure and provides sample deletion certificate
Audit facilitationDPA audit rights clause verified; vendor confirms practical audit access

Certification Verification Process

StepActivityEvidence
1Obtain copy of certificate and audit reportPDF certificate; SOC 2 report under NDA
2Verify certification body accreditationCheck national accreditation body registry
3Verify certificate validity (not expired)Certificate dates; annual surveillance confirmation
4Verify scope covers relevant servicesScope statement includes services provided to Summit
5Review exceptions or qualified opinions (SOC 2)No material exceptions affecting Summit data
6Identify gaps per equivalence matrixDocument uncovered requirements
7Request supplementary evidence for gapsPer gap supplementation table
8Document acceptance decisionRecord in vendor assessment file

Key Regulatory References

  • GDPR Article 42 — Data protection certification mechanisms
  • GDPR Article 43 — Certification bodies
  • GDPR Article 40 — Codes of conduct
  • GDPR Article 28(5) — Adherence to certifications as element of sufficient guarantees
  • EDPB Guidelines 07/2020 — Paragraph 86 on certifications as sufficiency indicators
  • EDPB Guidelines 1/2018 — Certification and identifying certification criteria per Article 42
  • ISO/IEC 27701:2019 — Privacy information management system
  • AICPA Trust Services Criteria — Privacy criterion (2017 revision with 2022 updates)
  • APEC Cross-Border Privacy Rules System — Policies, Rules, and Guidelines
  • EU Cloud Code of Conduct — SCOPE Europe (approved 2021)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/vendor-cert-acceptance of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Vendor Cert Acceptance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor Cert Acceptance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor Cert Acceptance this skillmukul975/Privacy-Data-Protection-Skills301—~2.7kAutomated safety check: PassApache-2.0
Pii Contract Analyzegregmos/PII-Shield150—~8.9kAutomated safety check: NotesMIT
Privacy Eukimlawtech/korean-privacy-terms587—~968Automated safety check: PassApache-2.0
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Terms Of Service Generatorzubair-trabzada/ai-legal-claude1.8k—~2.9kAutomated safety check: PassNone

Similar skills

  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes
  • Privacy Eu

    kimlawtech/korean-privacy-terms

    EU 사용자 대상 서비스용 Privacy Notice·Terms of Service·Consent Modal·Cookie Banner 자동 생성.

    587 GitHub stars~968 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Terms Of Service Generator

    zubair-trabzada/ai-legal-claude

    Generates complete, GDPR/CCPA-compliant Terms of Service for a website or SaaS product, with plain English summaries for each section

    1.8k GitHub stars~2.9k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    946 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Vendor Cert Acceptance

What does Vendor Cert Acceptance do?

Vendor certification acceptance criteria and equivalence mapping. Vendor Cert Acceptance is an agent skill from mukul975/Privacy-Data-Protection-Skills. Vendor certification acceptance criteria and equivalence mapping.

When should I use Vendor Cert Acceptance?

Vendor Cert Acceptance fits situations like: tasks that involve Privacy and GDPR; tasks that involve User stories; tasks that involve SOC 2 and security compliance.

How do I install Vendor Cert Acceptance in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-cert-acceptance -a claude-code`. Or copy the skill folder (skills/privacy/vendor-cert-acceptance in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/vendor-cert-acceptance in your project. Claude Code loads it when a task matches its description.

How do I install Vendor Cert Acceptance in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-cert-acceptance -a codex`. Or copy the skill folder (skills/privacy/vendor-cert-acceptance in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/vendor-cert-acceptance in your project. Codex loads it when a task matches its description.

Can I use Vendor Cert Acceptance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-cert-acceptance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-cert-acceptance, .gemini/skills/vendor-cert-acceptance, .github/skills/vendor-cert-acceptance and .opencode/skills/vendor-cert-acceptance in your project.

What does Vendor Cert Acceptance need to run?

Going by SKILL.md and its folder, Vendor Cert Acceptance needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Vendor Cert Acceptance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor Cert Acceptance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vendor Cert Acceptance use?

Vendor Cert Acceptance is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor Cert Acceptance use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Vendor Cert Acceptance?

Skills that share tags, products or a category with Vendor Cert Acceptance: Pii Contract Analyze (gregmos/PII-Shield, 150 stars), Privacy Eu (kimlawtech/korean-privacy-terms, 587 stars), Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Audit Report (harness/harness-skills, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor Cert Acceptance?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.