Vendor Due Diligence Patrick Munro
lawve-ai/awesome-legal-skills
Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.
Pre-contract vendor privacy due diligence per GDPR Article 28(1).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-due-diligence --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/vendor-privacy-due-diligence .claude/skills/vendor-privacy-due-diligence && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vendor-privacy-due-diligence" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-due-diligence into .claude/skills/vendor-privacy-due-diligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-due-diligence", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-due-diligenceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-due-diligence --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/vendor-privacy-due-diligence .agents/skills/vendor-privacy-due-diligence && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vendor-privacy-due-diligence" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-due-diligence into .agents/skills/vendor-privacy-due-diligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-due-diligence", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-due-diligence --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/vendor-privacy-due-diligence .cursor/skills/vendor-privacy-due-diligence && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vendor-privacy-due-diligence" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-due-diligence into .cursor/skills/vendor-privacy-due-diligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-due-diligence", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/vendor-privacy-due-diligence--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-due-diligence --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/vendor-privacy-due-diligence .gemini/skills/vendor-privacy-due-diligence && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vendor-privacy-due-diligence" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-due-diligence into .gemini/skills/vendor-privacy-due-diligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-due-diligence", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-due-diligenceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/vendor-privacy-due-diligence .github/skills/vendor-privacy-due-diligence && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vendor-privacy-due-diligence" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-due-diligence into .github/skills/vendor-privacy-due-diligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-due-diligence", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-privacy-due-diligence --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/vendor-privacy-due-diligence .opencode/skills/vendor-privacy-due-diligence && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vendor-privacy-due-diligence" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-privacy-due-diligence into .opencode/skills/vendor-privacy-due-diligence/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-due-diligence", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vendor-privacy-due-diligencePre-contract vendor privacy due diligence per GDPR Article 28(1).
Vendor Privacy Due Diligence is an agent skill from mukul975/Privacy-Data-Protection-Skills. Pre-contract vendor privacy due diligence per GDPR Article 28(1). Covers risk questionnaires, technical controls assessment, certification review, data flow analysis, and documented sufficiency decisions for processor engagement.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Fundraising and pitch decks and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vendor Privacy Due Diligence loads about 2.7k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 1,153 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,153 words, ~2,713 tokens.
.claude/skills/vendor-privacy-due-diligence/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.GDPR Article 28(1) requires controllers to use only processors providing "sufficient guarantees to implement appropriate technical and organisational measures" to meet GDPR requirements and protect data subject rights. This obligation means controllers must conduct thorough privacy due diligence before engaging any vendor that will process personal data. The European Data Protection Board (EDPB) Guidelines 07/2020 on controller and processor concepts reinforce that this assessment must be documented and proportionate to the risk involved.
At Summit Cloud Partners, the Vendor Privacy Due Diligence Program establishes a structured process for evaluating prospective vendors before any personal data processing begins.
Before engaging in detailed evaluation, determine whether the vendor will process personal data at all.
Processing Determination Checklist:
| Question | If YES |
|---|---|
| Will the vendor access, store, or transmit personal data? | Proceed to full due diligence |
| Will the vendor host systems containing personal data? | Proceed to full due diligence |
| Will the vendor have logical or physical access to infrastructure holding personal data? | Proceed to full due diligence |
| Is the vendor providing purely non-personal-data services (e.g., office supplies)? | No due diligence required — document determination |
Data Flow Preliminary Analysis:
Map the anticipated data flows before proceeding:
Summit Cloud Partners issues a standardized Privacy Risk Questionnaire to all prospective vendors scoring above the initial screening threshold.
Section A — Legal and Governance
| # | Question | Expected Response |
|---|---|---|
| A1 | Does your organization have a designated Data Protection Officer (DPO) or equivalent privacy lead? | Named individual with contact details |
| A2 | In which jurisdictions is your organization established? | List of all establishment countries |
| A3 | What is your GDPR compliance governance structure? | Documented privacy program with assigned responsibilities |
| A4 | Have you been subject to any regulatory enforcement actions, fines, or investigations in the past 5 years? | Disclosure of any actions with remediation status |
| A5 | Do you maintain a Record of Processing Activities per Article 30(2)? | Confirmation with sample structure |
| A6 | What lawful bases do you rely on for your own processing activities? | Documented lawful basis assessment |
| A7 | Do you have a process for conducting Data Protection Impact Assessments per Article 35? | DPIA methodology description |
Section B — Technical Security Controls
| # | Question | Expected Response |
|---|---|---|
| B1 | Describe your encryption approach for data at rest and in transit | AES-256 for at-rest, TLS 1.2+ for in-transit minimum |
| B2 | How do you manage access controls and authentication? | RBAC, MFA, principle of least privilege |
| B3 | Describe your vulnerability management program | Regular scanning, patching cadence, penetration testing |
| B4 | What logging and monitoring controls are in place? | SIEM, access logging, anomaly detection |
| B5 | Describe your incident detection and response capabilities | 24/7 monitoring, documented IRP, mean time to detect |
| B6 | How do you secure development practices? | SDLC, code review, OWASP compliance |
| B7 | What physical security controls protect data processing facilities? | Access controls, CCTV, environmental controls |
Section C — Data Handling Practices
| # | Question | Expected Response |
|---|---|---|
| C1 | How do you segregate client data from other clients? | Logical or physical segregation description |
| C2 | What is your data retention and deletion approach? | Defined retention periods, certified deletion |
| C3 | How do you handle data subject access requests forwarded by controllers? | Process description with SLA commitments |
| C4 | Describe your data backup and recovery procedures | Backup frequency, encryption, tested recovery |
| C5 | Do you process personal data in any country outside the EEA? | List of all processing locations with transfer mechanisms |
| C6 | What is your sub-processor engagement process? | Notification mechanism, assessment requirements |
Section D — Certifications and Attestations
| # | Question | Expected Response |
|---|---|---|
| D1 | Do you hold ISO 27001 certification? | Certificate with scope and certification body |
| D2 | Do you hold ISO 27701 certification? | Certificate with scope |
| D3 | Do you hold SOC 2 Type II attestation? | Report with scope and period |
| D4 | Do you hold any cloud-specific certifications (CSA STAR, ISO 27017/27018)? | Certificate details |
| D5 | Do you adhere to any approved GDPR Code of Conduct per Article 40? | Code of Conduct reference and adherence documentation |
| D6 | Have you obtained any GDPR certification per Article 42? | Certification details |
Beyond questionnaire responses, Summit Cloud Partners conducts independent verification of critical controls.
Assessment Methods:
Control Verification Matrix:
| Control Domain | Questionnaire Claim | Verification Method |
|---|---|---|
| Encryption at rest | AES-256 | Review architecture docs, request encryption key management details |
| Encryption in transit | TLS 1.2+ | Technical scan of vendor endpoints |
| Access management | RBAC with MFA | Review IAM policy documentation |
| Incident response | 24/7 SOC | Review SOC 2 Type II report findings |
| Data segregation | Logical separation | Architecture review and documentation |
| Patch management | Monthly cycle | Review vulnerability management reports |
Document the complete data flow for the proposed processing arrangement.
Data Flow Documentation Requirements:
Data Flow: Summit Cloud Partners → [Vendor Name]
1. Data Categories:
- [List each category of personal data]
- Classification level per category (Public/Internal/Confidential/Restricted)
2. Data Subjects:
- [List each category of data subject]
- Approximate volume per category
3. Transfer Mechanism:
- Method: [API / SFTP / Direct database access / etc.]
- Encryption: [Protocol and strength]
- Authentication: [Method]
4. Processing Locations:
- Primary: [Country, City, Data Center]
- Backup/DR: [Country, City, Data Center]
- Support access: [Countries where staff may access data]
5. Sub-processors:
- [List known sub-processors with location and function]
6. Data Retention:
- Processing retention: [Duration]
- Backup retention: [Duration]
- Post-termination: [Return/deletion timeline]
7. Return Path:
- Data subject requests forwarded via: [mechanism]
- Response SLA: [timeframe]The DPO or Privacy Team Lead reviews all collected evidence and issues a documented sufficiency decision.
Sufficiency Decision Criteria:
| Criterion | Weight | Scoring |
|---|---|---|
| Legal governance maturity | 15% | 1-5 scale |
| Technical security controls | 25% | 1-5 scale |
| Data handling practices | 20% | 1-5 scale |
| Certifications held | 15% | 1-5 scale |
| Breach and enforcement history | 10% | 1-5 scale (inverse) |
| Sub-processor management | 10% | 1-5 scale |
| Cross-border transfer safeguards | 5% | 1-5 scale |
Decision Outcomes:
Documentation Requirements per Article 5(2) Accountability:
The due diligence file must contain:
Due diligence is not a one-time exercise. Article 28(1) imposes a continuing obligation to ensure processors maintain sufficient guarantees. Summit Cloud Partners conducts:
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/vendor-privacy-due-diligence of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Vendor Privacy Due Diligence next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vendor Privacy Due Diligence this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Vendor Due Diligence Patrick Munrolawve-ai/awesome-legal-skills | 847 | — | ~4.1k | Automated safety check: Pass | AGPL-3.0 | |
| General Counsel Advisoralirezarezvani/claude-skills | 28k | — | ~2.3k | Automated safety check: Pass | MIT | |
| TprmSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Cross Regulatory Impact Analyzer Patrick Munrolawve-ai/awesome-legal-skills | 847 | — | ~3.1k | Automated safety check: Pass | AGPL-3.0 | |
| Preparing Launch AssetsGTM-Strategist/gtm-strategist-skills | 264 | — | ~5k | Automated safety check: Pass | MIT |
lawve-ai/awesome-legal-skills
Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.
alirezarezvani/claude-skills
General Counsel advisory for startups: contract review (MSA, SaaS, NDA, DPA, employment), IP strategy, term sheet decoding, and regulatory landscape mapping.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert third-party risk management (TPRM) advisor — a vendor risk analyst for the full lifecycle: risk-based vendor tiering, tailored due-diligence questionnaires (SIG-style or mapped to ISO 27001…
lawve-ai/awesome-legal-skills
Analyzes how multiple regulations interact for a specific product, service, or business model.
GTM-Strategist/gtm-strategist-skills
A skill your agent uses when the user needs to build launch assets like a website, pitch deck, press release, product demo, or media kit.
alirezarezvani/claude-skills
/cs:gc-review <plan — General Counsel interrogation of contracts, IP, regulatory, term sheets, and employment-law surface.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Pre-contract vendor privacy due diligence per GDPR Article 28(1). Vendor Privacy Due Diligence is an agent skill from mukul975/Privacy-Data-Protection-Skills. Pre-contract vendor privacy due diligence per GDPR Article 28(1).
Vendor Privacy Due Diligence fits situations like: tasks that involve Fundraising and pitch decks; tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a claude-code`. Or copy the skill folder (skills/privacy/vendor-privacy-due-diligence in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/vendor-privacy-due-diligence in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a codex`. Or copy the skill folder (skills/privacy/vendor-privacy-due-diligence in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/vendor-privacy-due-diligence in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-privacy-due-diligence -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-privacy-due-diligence, .gemini/skills/vendor-privacy-due-diligence, .github/skills/vendor-privacy-due-diligence and .opencode/skills/vendor-privacy-due-diligence in your project.
Going by SKILL.md and its folder, Vendor Privacy Due Diligence needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Vendor Privacy Due Diligence is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Vendor Privacy Due Diligence: Vendor Due Diligence Patrick Munro (lawve-ai/awesome-legal-skills, 847 stars), General Counsel Advisor (alirezarezvani/claude-skills, 28k stars), Tprm (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Cross Regulatory Impact Analyzer Patrick Munro (lawve-ai/awesome-legal-skills, 847 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.