Implementing Compliance
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
On-site and remote vendor audit procedures per GDPR Article 28(3)(h).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/vendor-privacy-audit .claude/skills/vendor-privacy-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vendor-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-audit into .claude/skills/vendor-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/vendor-privacy-audit .agents/skills/vendor-privacy-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vendor-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-audit into .agents/skills/vendor-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/vendor-privacy-audit .cursor/skills/vendor-privacy-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vendor-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-audit into .cursor/skills/vendor-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/vendor-privacy-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/vendor-privacy-audit .gemini/skills/vendor-privacy-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vendor-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-audit into .gemini/skills/vendor-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/vendor-privacy-audit .github/skills/vendor-privacy-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vendor-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-audit into .github/skills/vendor-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/vendor-privacy-audit .opencode/skills/vendor-privacy-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vendor-privacy-audit" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-audit into .opencode/skills/vendor-privacy-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vendor-privacy-auditOn-site and remote vendor audit procedures per GDPR Article 28(3)(h).
Vendor Privacy Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classification, remediation tracking, and audit report generation for processor compliance verification.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR and Digital forensics. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vendor Privacy Audit loads about 2.6k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 1,141 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,141 words, ~2,631 tokens.
.claude/skills/vendor-privacy-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.GDPR Article 28(3)(h) requires that the processor "make available to the controller all information necessary to demonstrate compliance with the obligations laid down in Article 28, and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller." This audit right is a cornerstone of the controller's accountability obligations and must be exercisable in practice.
The EDPB Guidelines 07/2020 (paragraph 110) emphasize that audit rights must be practical and exercisable, not merely theoretical. Controllers must develop structured audit programs proportionate to the risk of the processing.
At Summit Cloud Partners, the Vendor Privacy Audit Program provides a systematic approach to verifying processor compliance through on-site inspections, remote audits, and documentation reviews.
Suitable for standard-risk vendors with current third-party certifications.
| Aspect | Detail |
|---|---|
| Scope | Review of processor-provided documentation and certifications |
| Duration | 3-5 business days |
| Frequency | Annual |
| Deliverable | Documentation Audit Report |
| Cost allocation | Controller bears own costs |
Evidence Reviewed:
Suitable for standard-to-high-risk vendors where on-site access is not practical.
| Aspect | Detail |
|---|---|
| Scope | Remote assessment including technical verification |
| Duration | 5-10 business days |
| Frequency | Annual for high-risk; biennial for standard-risk |
| Deliverable | Remote Audit Report |
| Cost allocation | Per DPA terms (typically split) |
Activities:
Required for high-risk vendors and when triggered by compliance concerns.
| Aspect | Detail |
|---|---|
| Scope | Physical inspection of processing facilities and controls |
| Duration | 1-3 days on-site, plus pre/post work |
| Frequency | As needed; minimum biennial for highest-risk vendors |
| Deliverable | On-Site Inspection Report |
| Cost allocation | Per DPA terms |
Activities:
60 Days Before Audit:
| Activity | Responsible |
|---|---|
| Select vendors for audit based on risk tier and schedule | Privacy Team |
| Determine audit type (Documentation / Remote / On-Site) | Privacy Team Lead |
| Assign audit team lead and members | Privacy Team Lead |
| Notify vendor of audit intent per DPA notification requirements | Audit Team Lead |
30 Days Before Audit:
| Activity | Responsible |
|---|---|
| Issue formal audit notification letter to vendor | Audit Team Lead |
| Submit document request list to vendor | Audit Team |
| Schedule interview slots (for Type 2 and 3) | Audit Team |
| Book travel and facilities (for Type 3) | Operations |
| Prepare audit checklist customized for vendor's processing | Audit Team |
7 Days Before Audit:
| Activity | Responsible |
|---|---|
| Review vendor-provided documentation | Audit Team |
| Prepare interview question sets | Audit Team |
| Finalize on-site agenda (Type 3) | Audit Team Lead |
| Conduct team briefing | Audit Team Lead |
A. DPA Compliance Verification
| # | Check Item | Article | Evidence Required |
|---|---|---|---|
| A1 | Processing limited to documented controller instructions | 28(3)(a) | Processing logs, instruction register |
| A2 | All authorized personnel bound by confidentiality | 28(3)(b) | Signed confidentiality agreements, HR records |
| A3 | Article 32 security measures implemented per DPA Annex II | 28(3)(c) | Security configuration evidence |
| A4 | Sub-processors authorized and DPAs in place | 28(3)(d) | Sub-processor register, executed DPAs |
| A5 | DSR assistance capability demonstrated | 28(3)(e) | DSR handling procedures, response metrics |
| A6 | Compliance assistance provided for Art. 32-36 | 28(3)(f) | DPIA contributions, breach investigation support |
| A7 | Deletion/return capabilities verified | 28(3)(g) | Deletion procedures, test results |
| A8 | Audit information and access provided | 28(3)(h) | Audit cooperation evidence |
B. Technical Controls Verification
| # | Check Item | Evidence Required |
|---|---|---|
| B1 | Encryption at rest implemented per DPA specifications | Key management documentation, configuration screenshots |
| B2 | Encryption in transit per DPA specifications | TLS configuration, certificate management |
| B3 | Access controls configured per principle of least privilege | RBAC configuration, access review records |
| B4 | MFA enabled for all administrative access | MFA enrollment records, policy configuration |
| B5 | Logging enabled and retained per DPA retention period | Log storage configuration, sample logs |
| B6 | Vulnerability scanning performed per schedule | Scan reports, remediation records |
| B7 | Penetration testing performed per schedule | Pen test reports, finding remediation |
| B8 | Backup and recovery procedures tested | DR test results, RPO/RTO metrics |
C. Organizational Controls Verification
| # | Check Item | Evidence Required |
|---|---|---|
| C1 | Privacy training delivered to all relevant staff | Training records with completion dates |
| C2 | Incident response plan documented and tested | IRP document, tabletop exercise records |
| C3 | Change management process followed | Change log, approval records |
| C4 | Physical security controls in place (Type 3 only) | Badge access logs, CCTV coverage, visitor log |
| C5 | Data retention and deletion procedures operational | Retention schedule, deletion logs |
| C6 | Records of processing maintained per Art. 30(2) | ROPA documentation |
D. Breach Notification Readiness
| # | Check Item | Evidence Required |
|---|---|---|
| D1 | Breach detection capabilities operational | SIEM configuration, alert rules |
| D2 | Breach notification procedure documented with DPA-compliant timeframe | IRP with notification section, contact matrix |
| D3 | Breach notification contact details current | Verified contact information |
| D4 | Breach register maintained | Breach log (redacted if necessary) |
| Severity | Definition | Remediation Timeline | Follow-Up |
|---|---|---|---|
| Critical | Immediate risk to personal data or fundamental DPA violation | Immediate (within 7 days) | Verification audit within 30 days |
| Major | Significant gap in controls or DPA non-compliance | 30 calendar days | Written evidence of remediation |
| Minor | Control weakness not immediately impacting data protection | 90 calendar days | Verified at next scheduled audit |
| Observation | Area for improvement, not a compliance gap | Noted for next assessment | Tracked in audit records |
Examples by Severity:
| Severity | Example |
|---|---|
| Critical | Personal data accessible to unauthorized personnel; no encryption at rest despite DPA requirement |
| Major | Sub-processor engaged without notification; MFA not enforced for administrative access |
| Minor | Privacy training completion at 85% (target 100%); access review 2 weeks overdue |
| Observation | Incident response plan would benefit from more specific processor notification procedures |
All findings above Observation severity enter the remediation tracking system:
| Field | Description |
|---|---|
| Finding ID | Unique identifier |
| Vendor | Processor name |
| Audit date | When finding was identified |
| Severity | Critical / Major / Minor |
| Description | Detailed description of the finding |
| Root cause | Why the gap exists |
| Remediation plan | Vendor's proposed corrective action |
| Deadline | Date by which remediation must be complete |
| Evidence required | What the vendor must provide to close the finding |
| Status | Open / In Progress / Remediated / Verified / Overdue |
| Verification method | How Summit Cloud Partners will verify remediation |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/vendor-privacy-audit of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Vendor Privacy Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vendor Privacy Audit this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Complianceancoleman/ai-design-components | 525 | — | ~4k | Automated safety check: Pass | MIT | |
| Cursor Compliance Auditjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.3k | Automated safety check: Notes | MIT | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 |
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
jeremylongshore/tons-of-skills-marketplace
Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Vendor Privacy Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. On-site and remote vendor audit procedures per GDPR Article 28(3)(h).
Vendor Privacy Audit fits situations like: tasks that involve Privacy and GDPR; tasks that involve Digital forensics.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a claude-code`. Or copy the skill folder (skills/privacy/vendor-privacy-audit in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/vendor-privacy-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a codex`. Or copy the skill folder (skills/privacy/vendor-privacy-audit in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/vendor-privacy-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-privacy-audit, .gemini/skills/vendor-privacy-audit, .github/skills/vendor-privacy-audit and .opencode/skills/vendor-privacy-audit in your project.
Going by SKILL.md and its folder, Vendor Privacy Audit needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Vendor Privacy Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Vendor Privacy Audit: Implementing Compliance (ancoleman/ai-design-components, 525 stars), Cursor Compliance Audit (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), C15t (c15t/c15t, 1.9k stars) and HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.