Agent skill

Vendor Privacy Due Diligence

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Pre-contract vendor privacy due diligence per GDPR Article 28(1).

Apache-2.0Auto-check passedLegal & Compliance

Install Vendor Privacy Due Diligence

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-due-diligence --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/vendor-privacy-due-diligence .claude/skills/vendor-privacy-due-diligence && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-privacy-due-diligence
GitHub stars
301
Token cost
~2.7k tokens
SKILL.md length
1,153 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Pre-contract vendor privacy due diligence per GDPR Article 28(1).

  • Works in 5 steps: Initial Screening → Privacy Risk Questionnaire → Technical Controls Assessment → …
  • Tasks that involve Fundraising and pitch decks
  • SKILL.md covers Overview, Due Diligence Framework, Ongoing Obligations and Key Regulatory References
  • Runs Python scripts from its folder

What it does

Vendor Privacy Due Diligence is an agent skill from mukul975/Privacy-Data-Protection-Skills. Pre-contract vendor privacy due diligence per GDPR Article 28(1). Covers risk questionnaires, technical controls assessment, certification review, data flow analysis, and documented sufficiency decisions for processor engagement.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Fundraising and pitch decks and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Fundraising and pitch decks
  • Tasks that involve Privacy and GDPR

Example prompts

  • “/vendor-privacy-due-diligence”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Initial Screening
  2. Privacy Risk Questionnaire
  3. Technical Controls Assessment
  4. Data Flow Analysis
  5. Sufficiency Decision

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor Privacy Due Diligence loads about 2.7k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 1,153 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,153 words, ~2,713 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-privacy-due-diligence/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
vendor-privacy-due-diligence
description
Pre-contract vendor privacy due diligence per GDPR Article 28(1). Covers risk questionnaires, technical controls assessment, certification review, data flow analysis, and documented sufficiency decisions for processor engagement.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
vendor-privacy-management
metadata.tags
vendor-due-diligence, art-28, processor-assessment, privacy-risk, vendor-onboarding

Vendor Privacy Due Diligence

Overview

GDPR Article 28(1) requires controllers to use only processors providing "sufficient guarantees to implement appropriate technical and organisational measures" to meet GDPR requirements and protect data subject rights. This obligation means controllers must conduct thorough privacy due diligence before engaging any vendor that will process personal data. The European Data Protection Board (EDPB) Guidelines 07/2020 on controller and processor concepts reinforce that this assessment must be documented and proportionate to the risk involved.

At Summit Cloud Partners, the Vendor Privacy Due Diligence Program establishes a structured process for evaluating prospective vendors before any personal data processing begins.

Due Diligence Framework

Phase 1: Initial Screening

Before engaging in detailed evaluation, determine whether the vendor will process personal data at all.

Processing Determination Checklist:

QuestionIf YES
Will the vendor access, store, or transmit personal data?Proceed to full due diligence
Will the vendor host systems containing personal data?Proceed to full due diligence
Will the vendor have logical or physical access to infrastructure holding personal data?Proceed to full due diligence
Is the vendor providing purely non-personal-data services (e.g., office supplies)?No due diligence required — document determination

Data Flow Preliminary Analysis:

Map the anticipated data flows before proceeding:

  1. What categories of personal data will the vendor process?
  2. How many data subjects are affected (approximate volume)?
  3. Will special category data (Article 9) be involved?
  4. Where will processing occur geographically?
  5. Will the vendor engage sub-processors?
Phase 2: Privacy Risk Questionnaire

Summit Cloud Partners issues a standardized Privacy Risk Questionnaire to all prospective vendors scoring above the initial screening threshold.

Section A — Legal and Governance

#QuestionExpected Response
A1Does your organization have a designated Data Protection Officer (DPO) or equivalent privacy lead?Named individual with contact details
A2In which jurisdictions is your organization established?List of all establishment countries
A3What is your GDPR compliance governance structure?Documented privacy program with assigned responsibilities
A4Have you been subject to any regulatory enforcement actions, fines, or investigations in the past 5 years?Disclosure of any actions with remediation status
A5Do you maintain a Record of Processing Activities per Article 30(2)?Confirmation with sample structure
A6What lawful bases do you rely on for your own processing activities?Documented lawful basis assessment
A7Do you have a process for conducting Data Protection Impact Assessments per Article 35?DPIA methodology description

Section B — Technical Security Controls

#QuestionExpected Response
B1Describe your encryption approach for data at rest and in transitAES-256 for at-rest, TLS 1.2+ for in-transit minimum
B2How do you manage access controls and authentication?RBAC, MFA, principle of least privilege
B3Describe your vulnerability management programRegular scanning, patching cadence, penetration testing
B4What logging and monitoring controls are in place?SIEM, access logging, anomaly detection
B5Describe your incident detection and response capabilities24/7 monitoring, documented IRP, mean time to detect
B6How do you secure development practices?SDLC, code review, OWASP compliance
B7What physical security controls protect data processing facilities?Access controls, CCTV, environmental controls

Section C — Data Handling Practices

#QuestionExpected Response
C1How do you segregate client data from other clients?Logical or physical segregation description
C2What is your data retention and deletion approach?Defined retention periods, certified deletion
C3How do you handle data subject access requests forwarded by controllers?Process description with SLA commitments
C4Describe your data backup and recovery proceduresBackup frequency, encryption, tested recovery
C5Do you process personal data in any country outside the EEA?List of all processing locations with transfer mechanisms
C6What is your sub-processor engagement process?Notification mechanism, assessment requirements

Section D — Certifications and Attestations

#QuestionExpected Response
D1Do you hold ISO 27001 certification?Certificate with scope and certification body
D2Do you hold ISO 27701 certification?Certificate with scope
D3Do you hold SOC 2 Type II attestation?Report with scope and period
D4Do you hold any cloud-specific certifications (CSA STAR, ISO 27017/27018)?Certificate details
D5Do you adhere to any approved GDPR Code of Conduct per Article 40?Code of Conduct reference and adherence documentation
D6Have you obtained any GDPR certification per Article 42?Certification details
Show full SKILL.md (456 more words)Show less
Phase 3: Technical Controls Assessment

Beyond questionnaire responses, Summit Cloud Partners conducts independent verification of critical controls.

Assessment Methods:

  1. Documentation Review: Examine vendor security policies, procedures, and architectural documentation
  2. Certification Verification: Independently verify certification validity with issuing bodies
  3. Technical Testing: Where contractually permitted, conduct or review penetration test results
  4. Reference Checks: Contact existing clients of the vendor regarding privacy practices
  5. Public Record Search: Review breach notification databases, regulatory actions, and news reports

Control Verification Matrix:

Control DomainQuestionnaire ClaimVerification Method
Encryption at restAES-256Review architecture docs, request encryption key management details
Encryption in transitTLS 1.2+Technical scan of vendor endpoints
Access managementRBAC with MFAReview IAM policy documentation
Incident response24/7 SOCReview SOC 2 Type II report findings
Data segregationLogical separationArchitecture review and documentation
Patch managementMonthly cycleReview vulnerability management reports
Phase 4: Data Flow Analysis

Document the complete data flow for the proposed processing arrangement.

Data Flow Documentation Requirements:

Data Flow: Summit Cloud Partners → [Vendor Name]

1. Data Categories:
   - [List each category of personal data]
   - Classification level per category (Public/Internal/Confidential/Restricted)

2. Data Subjects:
   - [List each category of data subject]
   - Approximate volume per category

3. Transfer Mechanism:
   - Method: [API / SFTP / Direct database access / etc.]
   - Encryption: [Protocol and strength]
   - Authentication: [Method]

4. Processing Locations:
   - Primary: [Country, City, Data Center]
   - Backup/DR: [Country, City, Data Center]
   - Support access: [Countries where staff may access data]

5. Sub-processors:
   - [List known sub-processors with location and function]

6. Data Retention:
   - Processing retention: [Duration]
   - Backup retention: [Duration]
   - Post-termination: [Return/deletion timeline]

7. Return Path:
   - Data subject requests forwarded via: [mechanism]
   - Response SLA: [timeframe]
Phase 5: Sufficiency Decision

The DPO or Privacy Team Lead reviews all collected evidence and issues a documented sufficiency decision.

Sufficiency Decision Criteria:

CriterionWeightScoring
Legal governance maturity15%1-5 scale
Technical security controls25%1-5 scale
Data handling practices20%1-5 scale
Certifications held15%1-5 scale
Breach and enforcement history10%1-5 scale (inverse)
Sub-processor management10%1-5 scale
Cross-border transfer safeguards5%1-5 scale

Decision Outcomes:

  • Approved (weighted score 4.0+): Vendor provides sufficient guarantees. Proceed to DPA negotiation.
  • Conditionally Approved (weighted score 3.0–3.9): Vendor requires supplementary measures or contractual safeguards before engagement. Document conditions.
  • Rejected (weighted score below 3.0): Vendor does not provide sufficient guarantees. Document reasons. May be reconsidered after vendor remediation.

Documentation Requirements per Article 5(2) Accountability:

The due diligence file must contain:

  1. Completed Privacy Risk Questionnaire with vendor responses
  2. Evidence of verification activities performed
  3. Data flow analysis documentation
  4. Sufficiency scoring worksheet
  5. Written decision with rationale
  6. Approval signature from DPO or designated privacy lead
  7. Date of assessment and scheduled reassessment date

Ongoing Obligations

Due diligence is not a one-time exercise. Article 28(1) imposes a continuing obligation to ensure processors maintain sufficient guarantees. Summit Cloud Partners conducts:

  • Annual Reassessment: Full questionnaire refresh for high-risk vendors, abbreviated for standard risk
  • Trigger-Based Review: Reassessment triggered by vendor breach, regulatory action, material service change, or certification lapse
  • Continuous Monitoring: Automated alerts on vendor security posture changes via risk monitoring services

Key Regulatory References

  • GDPR Article 28(1) — Controller obligation to use processors with sufficient guarantees
  • GDPR Article 28(3) — Required DPA provisions
  • GDPR Article 5(2) — Accountability principle
  • GDPR Article 30(2) — Processor records of processing
  • GDPR Article 35 — DPIA requirements
  • EDPB Guidelines 07/2020 — Controller and processor concepts under GDPR
  • EDPB Recommendations 01/2020 — Supplementary measures for international transfers

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/vendor-privacy-due-diligence of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Vendor Privacy Due Diligence next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor Privacy Due Diligence compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor Privacy Due Diligence this skillmukul975/Privacy-Data-Protection-Skills301—~2.7kAutomated safety check: PassApache-2.0
Vendor Due Diligence Patrick Munrolawve-ai/awesome-legal-skills847—~4.1kAutomated safety check: PassAGPL-3.0
General Counsel Advisoralirezarezvani/claude-skills28k—~2.3kAutomated safety check: PassMIT
TprmSushegaad/Claude-Skills-Governance-Risk-and-Compliance946—~2.3kAutomated safety check: PassMIT
Cross Regulatory Impact Analyzer Patrick Munrolawve-ai/awesome-legal-skills847—~3.1kAutomated safety check: PassAGPL-3.0
Preparing Launch AssetsGTM-Strategist/gtm-strategist-skills264—~5kAutomated safety check: PassMIT

Similar skills

  • Vendor Due Diligence Patrick Munro

    lawve-ai/awesome-legal-skills

    Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.

    847 GitHub stars~4.1k tokensUpdated 8 days ago
    Legal & ComplianceAuto-check passed
  • General Counsel Advisor

    alirezarezvani/claude-skills

    General Counsel advisory for startups: contract review (MSA, SaaS, NDA, DPA, employment), IP strategy, term sheet decoding, and regulatory landscape mapping.

    28k GitHub stars~2.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Tprm

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert third-party risk management (TPRM) advisor — a vendor risk analyst for the full lifecycle: risk-based vendor tiering, tailored due-diligence questionnaires (SIG-style or mapped to ISO 27001…

    946 GitHub stars~2.3k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Analyzes how multiple regulations interact for a specific product, service, or business model.

    847 GitHub stars~3.1k tokensUpdated 8 days ago
    Legal & ComplianceAuto-check passed
  • Preparing Launch Assets

    GTM-Strategist/gtm-strategist-skills

    A skill your agent uses when the user needs to build launch assets like a website, pitch deck, press release, product demo, or media kit.

    264 GitHub stars~5k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • Gc Review

    alirezarezvani/claude-skills

    /cs:gc-review <plan — General Counsel interrogation of contracts, IP, regulatory, term sheets, and employment-law surface.

    28k GitHub stars~1.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Vendor Privacy Due Diligence

What does Vendor Privacy Due Diligence do?

Pre-contract vendor privacy due diligence per GDPR Article 28(1). Vendor Privacy Due Diligence is an agent skill from mukul975/Privacy-Data-Protection-Skills. Pre-contract vendor privacy due diligence per GDPR Article 28(1).

When should I use Vendor Privacy Due Diligence?

Vendor Privacy Due Diligence fits situations like: tasks that involve Fundraising and pitch decks; tasks that involve Privacy and GDPR.

How do I install Vendor Privacy Due Diligence in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a claude-code`. Or copy the skill folder (skills/privacy/vendor-privacy-due-diligence in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/vendor-privacy-due-diligence in your project. Claude Code loads it when a task matches its description.

How do I install Vendor Privacy Due Diligence in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a codex`. Or copy the skill folder (skills/privacy/vendor-privacy-due-diligence in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/vendor-privacy-due-diligence in your project. Codex loads it when a task matches its description.

Can I use Vendor Privacy Due Diligence in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-privacy-due-diligence, .gemini/skills/vendor-privacy-due-diligence, .github/skills/vendor-privacy-due-diligence and .opencode/skills/vendor-privacy-due-diligence in your project.

What does Vendor Privacy Due Diligence need to run?

Going by SKILL.md and its folder, Vendor Privacy Due Diligence needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Vendor Privacy Due Diligence access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor Privacy Due Diligence safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vendor Privacy Due Diligence use?

Vendor Privacy Due Diligence is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor Privacy Due Diligence use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.

What are the alternatives to Vendor Privacy Due Diligence?

Skills that share tags, products or a category with Vendor Privacy Due Diligence: Vendor Due Diligence Patrick Munro (lawve-ai/awesome-legal-skills, 847 stars), General Counsel Advisor (alirezarezvani/claude-skills, 28k stars), Tprm (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Cross Regulatory Impact Analyzer Patrick Munro (lawve-ai/awesome-legal-skills, 847 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor Privacy Due Diligence?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.