Agent skill

Vendor Privacy Audit

by mukul975 in mukul975/Privacy-Data-Protection-Skills

On-site and remote vendor audit procedures per GDPR Article 28(3)(h).

Apache-2.0Auto-check passedLegal & Compliance

Install Vendor Privacy Audit

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/vendor-privacy-audit .claude/skills/vendor-privacy-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-privacy-audit
GitHub stars
301
Token cost
~2.6k tokens
SKILL.md length
1,141 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

On-site and remote vendor audit procedures per GDPR Article 28(3)(h).

  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Audit Types, Audit Planning and Finding Classification, plus 2 more sections
  • Runs Python scripts from its folder
  • Tasks that involve Digital forensics

What it does

Vendor Privacy Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classification, remediation tracking, and audit report generation for processor compliance verification.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Digital forensics. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Digital forensics

Example prompts

  • “/vendor-privacy-audit”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor Privacy Audit loads about 2.6k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 1,141 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,141 words, ~2,631 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-privacy-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
vendor-privacy-audit
description
On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classification, remediation tracking, and audit report generation for processor compliance verification.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
vendor-privacy-management
metadata.tags
vendor-audit, article-28-audit, processor-compliance, audit-rights, remediation-tracking

Vendor Privacy Audit

Overview

GDPR Article 28(3)(h) requires that the processor "make available to the controller all information necessary to demonstrate compliance with the obligations laid down in Article 28, and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller." This audit right is a cornerstone of the controller's accountability obligations and must be exercisable in practice.

The EDPB Guidelines 07/2020 (paragraph 110) emphasize that audit rights must be practical and exercisable, not merely theoretical. Controllers must develop structured audit programs proportionate to the risk of the processing.

At Summit Cloud Partners, the Vendor Privacy Audit Program provides a systematic approach to verifying processor compliance through on-site inspections, remote audits, and documentation reviews.

Audit Types

Type 1: Documentation-Based Audit (Remote)

Suitable for standard-risk vendors with current third-party certifications.

AspectDetail
ScopeReview of processor-provided documentation and certifications
Duration3-5 business days
FrequencyAnnual
DeliverableDocumentation Audit Report
Cost allocationController bears own costs

Evidence Reviewed:

  • Current ISO 27001/27701 certificates and audit reports
  • SOC 2 Type II report (including management assertions and exceptions)
  • DPA compliance self-assessment questionnaire
  • Sub-processor register and DPA coverage confirmation
  • Incident log summary for audit period
  • Training records and confidentiality agreement coverage
  • Data subject request handling metrics
Type 2: Remote Technical Audit

Suitable for standard-to-high-risk vendors where on-site access is not practical.

AspectDetail
ScopeRemote assessment including technical verification
Duration5-10 business days
FrequencyAnnual for high-risk; biennial for standard-risk
DeliverableRemote Audit Report
Cost allocationPer DPA terms (typically split)

Activities:

  • All documentation review activities from Type 1
  • Video-conference interviews with vendor privacy and security teams
  • Screen-sharing walkthrough of access control configurations
  • Review of logging and monitoring dashboards
  • Live demonstration of data subject request handling process
  • Review of encryption key management procedures
  • Penetration test report review (vendor-provided under NDA)
Type 3: On-Site Inspection

Required for high-risk vendors and when triggered by compliance concerns.

AspectDetail
ScopePhysical inspection of processing facilities and controls
Duration1-3 days on-site, plus pre/post work
FrequencyAs needed; minimum biennial for highest-risk vendors
DeliverableOn-Site Inspection Report
Cost allocationPer DPA terms

Activities:

  • All remote audit activities
  • Physical security inspection of data processing facilities
  • Server room and network infrastructure walkthrough
  • Badge access system review and testing
  • Clean desk policy verification
  • Environmental controls inspection (fire suppression, climate, power)
  • Personnel interviews (privacy officer, security team, operations staff)
  • Observation of operational procedures (incident response, change management)

Audit Planning

Pre-Audit Activities

60 Days Before Audit:

ActivityResponsible
Select vendors for audit based on risk tier and schedulePrivacy Team
Determine audit type (Documentation / Remote / On-Site)Privacy Team Lead
Assign audit team lead and membersPrivacy Team Lead
Notify vendor of audit intent per DPA notification requirementsAudit Team Lead

30 Days Before Audit:

ActivityResponsible
Issue formal audit notification letter to vendorAudit Team Lead
Submit document request list to vendorAudit Team
Schedule interview slots (for Type 2 and 3)Audit Team
Book travel and facilities (for Type 3)Operations
Prepare audit checklist customized for vendor's processingAudit Team

7 Days Before Audit:

ActivityResponsible
Review vendor-provided documentationAudit Team
Prepare interview question setsAudit Team
Finalize on-site agenda (Type 3)Audit Team Lead
Conduct team briefingAudit Team Lead
Show full SKILL.md (605 more words)Show less
Audit Checklist

A. DPA Compliance Verification

#Check ItemArticleEvidence Required
A1Processing limited to documented controller instructions28(3)(a)Processing logs, instruction register
A2All authorized personnel bound by confidentiality28(3)(b)Signed confidentiality agreements, HR records
A3Article 32 security measures implemented per DPA Annex II28(3)(c)Security configuration evidence
A4Sub-processors authorized and DPAs in place28(3)(d)Sub-processor register, executed DPAs
A5DSR assistance capability demonstrated28(3)(e)DSR handling procedures, response metrics
A6Compliance assistance provided for Art. 32-3628(3)(f)DPIA contributions, breach investigation support
A7Deletion/return capabilities verified28(3)(g)Deletion procedures, test results
A8Audit information and access provided28(3)(h)Audit cooperation evidence

B. Technical Controls Verification

#Check ItemEvidence Required
B1Encryption at rest implemented per DPA specificationsKey management documentation, configuration screenshots
B2Encryption in transit per DPA specificationsTLS configuration, certificate management
B3Access controls configured per principle of least privilegeRBAC configuration, access review records
B4MFA enabled for all administrative accessMFA enrollment records, policy configuration
B5Logging enabled and retained per DPA retention periodLog storage configuration, sample logs
B6Vulnerability scanning performed per scheduleScan reports, remediation records
B7Penetration testing performed per schedulePen test reports, finding remediation
B8Backup and recovery procedures testedDR test results, RPO/RTO metrics

C. Organizational Controls Verification

#Check ItemEvidence Required
C1Privacy training delivered to all relevant staffTraining records with completion dates
C2Incident response plan documented and testedIRP document, tabletop exercise records
C3Change management process followedChange log, approval records
C4Physical security controls in place (Type 3 only)Badge access logs, CCTV coverage, visitor log
C5Data retention and deletion procedures operationalRetention schedule, deletion logs
C6Records of processing maintained per Art. 30(2)ROPA documentation

D. Breach Notification Readiness

#Check ItemEvidence Required
D1Breach detection capabilities operationalSIEM configuration, alert rules
D2Breach notification procedure documented with DPA-compliant timeframeIRP with notification section, contact matrix
D3Breach notification contact details currentVerified contact information
D4Breach register maintainedBreach log (redacted if necessary)

Finding Classification

SeverityDefinitionRemediation TimelineFollow-Up
CriticalImmediate risk to personal data or fundamental DPA violationImmediate (within 7 days)Verification audit within 30 days
MajorSignificant gap in controls or DPA non-compliance30 calendar daysWritten evidence of remediation
MinorControl weakness not immediately impacting data protection90 calendar daysVerified at next scheduled audit
ObservationArea for improvement, not a compliance gapNoted for next assessmentTracked in audit records

Examples by Severity:

SeverityExample
CriticalPersonal data accessible to unauthorized personnel; no encryption at rest despite DPA requirement
MajorSub-processor engaged without notification; MFA not enforced for administrative access
MinorPrivacy training completion at 85% (target 100%); access review 2 weeks overdue
ObservationIncident response plan would benefit from more specific processor notification procedures

Remediation Tracking

All findings above Observation severity enter the remediation tracking system:

FieldDescription
Finding IDUnique identifier
VendorProcessor name
Audit dateWhen finding was identified
SeverityCritical / Major / Minor
DescriptionDetailed description of the finding
Root causeWhy the gap exists
Remediation planVendor's proposed corrective action
DeadlineDate by which remediation must be complete
Evidence requiredWhat the vendor must provide to close the finding
StatusOpen / In Progress / Remediated / Verified / Overdue
Verification methodHow Summit Cloud Partners will verify remediation

Key Regulatory References

  • GDPR Article 28(3)(h) — Audit rights and compliance information
  • GDPR Article 5(2) — Accountability principle
  • GDPR Article 24 — Responsibility of the controller
  • GDPR Article 32 — Security of processing
  • EDPB Guidelines 07/2020 — Controller and processor concepts (paragraph 110 on practical audit rights)
  • Bavarian DPA (BayLDA) — Processor Audit Guidelines (2022)
  • ISO 19011:2018 — Guidelines for auditing management systems

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/vendor-privacy-audit of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Vendor Privacy Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor Privacy Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor Privacy Audit this skillmukul975/Privacy-Data-Protection-Skills301—~2.6kAutomated safety check: PassApache-2.0
Implementing Complianceancoleman/ai-design-components525—~4kAutomated safety check: PassMIT
Cursor Compliance Auditjeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: NotesMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Cursor Compliance Audit

    jeremylongshore/tons-of-skills-marketplace

    Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.

    2.8k GitHub stars~2.3k tokensUpdated yesterday
    Legal & ComplianceAuto-check: notes
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Vendor Privacy Audit

What does Vendor Privacy Audit do?

On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Vendor Privacy Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. On-site and remote vendor audit procedures per GDPR Article 28(3)(h).

When should I use Vendor Privacy Audit?

Vendor Privacy Audit fits situations like: tasks that involve Privacy and GDPR; tasks that involve Digital forensics.

How do I install Vendor Privacy Audit in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a claude-code`. Or copy the skill folder (skills/privacy/vendor-privacy-audit in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/vendor-privacy-audit in your project. Claude Code loads it when a task matches its description.

How do I install Vendor Privacy Audit in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a codex`. Or copy the skill folder (skills/privacy/vendor-privacy-audit in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/vendor-privacy-audit in your project. Codex loads it when a task matches its description.

Can I use Vendor Privacy Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-privacy-audit, .gemini/skills/vendor-privacy-audit, .github/skills/vendor-privacy-audit and .opencode/skills/vendor-privacy-audit in your project.

What does Vendor Privacy Audit need to run?

Going by SKILL.md and its folder, Vendor Privacy Audit needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Vendor Privacy Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor Privacy Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vendor Privacy Audit use?

Vendor Privacy Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor Privacy Audit use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to Vendor Privacy Audit?

Skills that share tags, products or a category with Vendor Privacy Audit: Implementing Compliance (ancoleman/ai-design-components, 525 stars), Cursor Compliance Audit (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), C15t (c15t/c15t, 1.9k stars) and HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor Privacy Audit?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.