Agent skill

Workplace Email Privacy

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Implements email and internet monitoring compliance in the workplace per Barbulescu v Romania (ECHR Grand Chamber), EDPB guidance, and national labour law.

Apache-2.0Auto-check passedLegal & Compliance

Install Workplace Email Privacy

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill workplace-email-privacy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills workplace-email-privacy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/workplace-email-privacy .claude/skills/workplace-email-privacy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
workplace-email-privacy
GitHub stars
301
Token cost
~4.4k tokens
SKILL.md length
2,156 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements email and internet monitoring compliance in the workplace per Barbulescu v Romania (ECHR Grand Chamber), EDPB guidance, and national labour law.

  • Works in 6 steps: Audit Current Monitoring Capabilities → Conduct Proportionality Assessment → Draft or Update Acceptable Use Policy → …
  • Tasks that involve Policy and terms drafting
  • SKILL.md covers Overview, Legal Framework, Monitoring Categories and… and Acceptable Use Policy…, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Workplace Email Privacy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements email and internet monitoring compliance in the workplace per Barbulescu v Romania (ECHR Grand Chamber), EDPB guidance, and national labour law. Covers acceptable use policies, legitimate expectation of privacy, proportionality testing, and content vs metadata monitoring. Keywords: email monitoring, Barbulescu, workplace privacy, internet monitoring, acceptable use policy, ECHR, proportionality.

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Policy and terms drafting and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Policy and terms drafting
  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the workplace-email-privacy skill to implement email and internet monitoring compliance in the workplace per Barbulescu v Romania (ECHR Grand…”
  • “/workplace-email-privacy”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Audit Current Monitoring Capabilities
  2. Conduct Proportionality Assessment
  3. Draft or Update Acceptable Use Policy
  4. Configure Technical Controls
  5. Train Relevant Staff
  6. Conduct DPIA

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Workplace Email Privacy loads about 4.4k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 2,156 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,156 words, ~4,432 tokens.

Download SKILL.mdSave it as .claude/skills/workplace-email-privacy/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
workplace-email-privacy
description
Implements email and internet monitoring compliance in the workplace per Barbulescu v Romania (ECHR Grand Chamber), EDPB guidance, and national labour law. Covers acceptable use policies, legitimate expectation of privacy, proportionality testing, and content vs metadata monitoring. Keywords: email monitoring, Barbulescu, workplace privacy, internet monitoring, acceptable use policy, ECHR, proportionality.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
employee-data-privacy
metadata.tags
email-monitoring, barbulescu, workplace-privacy, internet-monitoring, acceptable-use, proportionality

Workplace Email Privacy

Overview

Workplace email and internet monitoring sits at the intersection of employer legitimate interests and employee fundamental rights to privacy and correspondence under Art. 8 of the European Convention on Human Rights (ECHR), Art. 7 of the EU Charter of Fundamental Rights, and the GDPR. The landmark Grand Chamber judgment in Barbulescu v Romania (Application No. 61496/08, 5 September 2017) established a six-factor proportionality test that all European employers must satisfy before monitoring employee electronic communications. This skill provides a compliance framework for implementing email and internet monitoring that respects these legal boundaries.

ECHR Art. 8 — Right to Respect for Private Life and Correspondence

Art. 8(1): "Everyone has the right to respect for his private life, family life, his home and his correspondence."

Art. 8(2): Interference is permitted only where it is "in accordance with the law," pursues a "legitimate aim," and is "necessary in a democratic society."

The ECHR has consistently held that "correspondence" includes electronic communications sent from the workplace, and that "private life" encompasses activities in the professional context (Niemietz v Germany, Application No. 13710/88, 1992).

Barbulescu v Romania — The Six-Factor Test

The Grand Chamber overturned the Chamber's earlier judgment and established that States have a positive obligation to ensure that domestic law provides adequate protection for employees' Art. 8 rights in the workplace monitoring context. The Court articulated six factors that national courts and employers must consider:

Factor 1: Prior Notification Has the employee been notified in advance of the nature and extent of monitoring? The notification must be clear, specific, and provided before monitoring begins. A general statement that "communications may be monitored" is insufficient — the employee must understand what is monitored (content, metadata, or both), when monitoring occurs, and who has access to the results.

Factor 2: Extent of Monitoring and Degree of Intrusion What is the scope of the monitoring? Content monitoring (reading the actual text of communications) is significantly more intrusive than metadata monitoring (sender, recipient, time, subject line). Real-time monitoring is more intrusive than retrospective review. Continuous monitoring is more intrusive than targeted, incident-based monitoring.

Factor 3: Legitimate Reasons Does the employer have legitimate reasons to justify the monitoring and access to the actual content of communications? Legitimate reasons include: preventing data leakage, enforcing information security policies, investigating specific misconduct, complying with regulatory obligations (financial services), and protecting trade secrets.

Factor 4: Less Intrusive Alternatives Could the employer's aims be achieved through less intrusive methods? This is the proportionality requirement — if monitoring email metadata would suffice, monitoring content is unjustified. If automated keyword scanning detects policy violations, human review of content is disproportionate.

Factor 5: Consequences for the Employee What are the consequences of the monitoring for the employee subjected to it? If monitoring data can lead to disciplinary action or dismissal, the intrusion is more severe and requires stronger justification. The Court found that in Barbulescu's case, the monitoring directly led to his dismissal, making the intrusion particularly severe.

Factor 6: Adequate Safeguards Has the employee been provided with adequate safeguards, particularly when the monitoring is intrusive? Safeguards include: limitation on who can access monitoring data, prohibition on monitoring privileged communications, right to be informed of monitoring results, right to challenge monitoring decisions, time limits on data retention, and independent oversight.

Libert v France (ECHR, Application No. 588/13, 2018)

The Court held that files clearly marked as "personal" on an employee's work computer could not be opened by the employer without the employee being present or having been duly summoned, unless there was a "serious risk" to the company.

Köpke v Germany (ECHR, Application No. 420/07, 2010)

Covert video surveillance of an employee suspected of theft was held to be justified, but only because: (a) there was a concrete suspicion, (b) the surveillance was limited in time and scope, (c) there were no less intrusive alternatives to detect the theft, and (d) the footage was used only for the specific investigation.

Monitoring Categories and Compliance Requirements

Category 1: Email Metadata Monitoring

What is captured: Sender address, recipient address(es), timestamp, subject line, attachment names and sizes, email volume per employee.

Intrusiveness level: Low to Medium.

Typical legitimate purposes: Information security (detecting unusual data transfer patterns), capacity management, regulatory compliance (financial services communications monitoring).

Compliance requirements:

  • Prior notification: Inform employees that metadata is logged
  • Acceptable use policy: Reference metadata logging in the AUP
  • Retention: Metadata logs should be retained no longer than necessary for the stated purpose (typically 90 days for security purposes, up to 7 years for regulated financial communications)
  • Access: Restrict access to IT security team; line managers should not have routine access to individual email metadata
Category 2: Email Content Monitoring

What is captured: Full text of email messages, attachments.

Intrusiveness level: High.

Typical legitimate purposes: Data loss prevention (DLP), regulatory compliance (financial services), investigation of specific alleged misconduct.

Compliance requirements:

  • Prior notification: Explicit, detailed notification that email content may be reviewed under specified circumstances
  • Proportionality: Content monitoring must be targeted, not blanket. Automated DLP scanning with keyword triggers is more proportionate than human review of all emails
  • Exclusions: Legal professional privilege communications, trade union correspondence, medical correspondence must be excluded from monitoring scope
  • Access: Content review limited to authorised personnel (DLP team, compliance officer) — never to direct line managers
  • Retention: Content captured by DLP alerts should be reviewed promptly and deleted if no policy violation is confirmed

Atlas Manufacturing Group Example: Atlas implemented Microsoft Purview DLP policies scanning outbound emails for patterns matching customer credit card numbers, employee national insurance numbers, and files classified as "Confidential." The DLP system flags matching emails for review by the Information Security Manager. The employee's line manager is not notified unless a confirmed policy violation is escalated through HR. Atlas's acceptable use policy explicitly states that outbound emails are subject to automated content scanning for data protection purposes.

Category 3: Internet Browsing Monitoring

What is captured: URLs visited, browsing duration, bandwidth consumption, download activity.

Intrusiveness level: Medium to High (browsing history can reveal sensitive information about health, political views, religion, sexual orientation).

Typical legitimate purposes: IT security (preventing malware), bandwidth management, enforcement of acceptable use policies, preventing access to illegal content.

Compliance requirements:

  • Prior notification: Inform employees that browsing activity is logged
  • Filtering vs. monitoring: URL blocking (preventing access to categories of sites) is less intrusive than logging (recording which sites were visited). Prefer blocking over logging where the purpose is prevention
  • Sensitive categories: Browsing data may inadvertently reveal special category data (health websites, political forums, religious sites). Processing this data without an Art. 9(2) condition is unlawful
  • Personal browsing: If the employer permits limited personal use of internet during breaks, monitoring of personal browsing during permitted times requires specific justification
  • Aggregation: Aggregate browsing statistics (bandwidth usage per department) are less intrusive than individual browsing logs
Category 4: Instant Messaging and Collaboration Tools

What is captured: Messages in corporate chat platforms (Microsoft Teams, Slack, Google Chat), file sharing activity, meeting participation.

Intrusiveness level: Medium to High — messaging platforms create an expectation of conversational informality that increases the privacy expectation.

Compliance requirements:

  • Prior notification: Employees must know that messages on corporate platforms are logged and may be reviewed
  • Retention: Corporate messaging platforms retain messages by default. Retention policies must be configured to delete messages after a defined period (typically 1-3 years, or as required by industry regulation)
  • eDiscovery: Distinguish between routine monitoring and litigation/regulatory hold requirements. eDiscovery searches should be authorised by legal counsel and limited in scope
  • Personal communications: Employees may use corporate messaging for personal conversations. Monitoring policies must address this reality

Acceptable Use Policy Requirements

An Acceptable Use Policy (AUP) is the foundational document for workplace communications monitoring compliance. The AUP serves as the transparency mechanism under Art. 13/14 GDPR and satisfies Barbulescu Factor 1 (prior notification).

Show full SKILL.md (864 more words)Show less
Mandatory AUP Elements
ElementContent Required
ScopeWhich systems are covered (email, internet, messaging, phone, BYOD)
Permitted personal useWhether personal use is permitted, and under what conditions
Monitoring disclosureWhat monitoring takes place (metadata, content, both), when, and by whom
Monitoring purposeThe specific purposes for which monitoring is conducted
Content exclusionsCategories excluded from monitoring (privileged communications, medical, union)
Access controlsWho has access to monitoring data
ConsequencesWhat may happen as a result of policy violation or monitoring detection
Employee rightsRight to access monitoring data about them, right to challenge, grievance procedure
RetentionHow long monitoring data is retained
ReviewWhen the policy is reviewed and how employees are notified of changes
Legitimate Expectation of Privacy

The AUP directly shapes whether employees have a "legitimate expectation of privacy" in their workplace communications:

  • AUP prohibits all personal use and warns of monitoring: Employee's privacy expectation is reduced but not eliminated. The ECHR in Barbulescu held that even where personal use was prohibited, the employee retained some privacy expectation because the employer had not clearly communicated the nature and extent of monitoring.
  • AUP permits personal use with monitoring warning: Employee has a moderate privacy expectation for personal communications. Monitoring of personal communications during permitted personal use time requires strong justification.
  • No AUP exists: Employee has a strong legitimate expectation of privacy. Any monitoring is likely to be disproportionate.

Implementation Workflow

Step 1: Audit Current Monitoring Capabilities

Document all existing email and internet monitoring systems, including:

  • Email archiving and DLP tools
  • Web proxy and content filtering systems
  • Messaging platform retention settings
  • Network traffic analysis tools
Step 2: Conduct Proportionality Assessment

For each monitoring capability, apply the Barbulescu six-factor test:

For each monitoring system:
  1. Is prior notification provided? [Yes/No → Remediate]
  2. What is the extent of monitoring? [Metadata only / Content / Both]
  3. What is the legitimate reason? [Document specific purpose]
  4. Is there a less intrusive alternative? [If yes → Switch to less intrusive method]
  5. What are the consequences for employees? [Document potential adverse effects]
  6. What safeguards are in place? [Document access controls, retention, exclusions]

  If any factor is not satisfied → Monitoring must be modified or ceased.
Step 3: Draft or Update Acceptable Use Policy

Ensure the AUP covers all mandatory elements listed above. The AUP must be:

  • Written in clear, plain language
  • Provided to all employees before monitoring begins
  • Acknowledged in writing by each employee
  • Refreshed when monitoring capabilities change
Step 4: Configure Technical Controls
  • Implement whitelists excluding privileged communications from monitoring scope
  • Configure DLP rules to minimise false positives and reduce unnecessary content review
  • Set retention periods on email archives and messaging platforms
  • Implement role-based access controls on monitoring dashboards
  • Enable audit logging for all access to monitoring data
Step 5: Train Relevant Staff
  • Train IT security staff on permissible scope of monitoring reviews
  • Train HR staff on the boundary between monitoring data and disciplinary evidence
  • Train line managers that they do not have direct access to email monitoring data
Step 6: Conduct DPIA

Email and internet monitoring requires a DPIA (see employee-monitoring-dpia skill). Document the proportionality assessment and residual risks.

Covert Monitoring — Exceptional Circumstances Only

Covert monitoring (monitoring without employee knowledge) is permissible only in narrowly defined circumstances:

Requirements for lawful covert monitoring (based on Köpke v Germany and ICO guidance):

  1. There must be reasonable suspicion of criminal activity or serious misconduct
  2. The investigation must be authorised at a senior level (typically CEO or Board level)
  3. The monitoring must be proportionate to the suspected misconduct
  4. The monitoring must be time-limited (typically no more than a few weeks)
  5. The scope must be narrowly defined (targeted employee, specific communication channels)
  6. Less intrusive investigation methods must have been considered and found insufficient
  7. The investigation must be documented in advance
  8. Legal counsel must be consulted before covert monitoring begins
  9. The results of the monitoring must be disclosed to the employee within a reasonable time, even if no misconduct is found

Atlas Manufacturing Group Example: Atlas suspected an employee of leaking confidential product designs to a competitor. After consulting legal counsel and the DPO, the CEO authorised targeted monitoring of the suspect's outbound email attachments for a period of 14 days. The monitoring was limited to attachments containing CAD file formats and was not extended to personal communications. The investigation was documented in advance with a written justification and time limit.

Enforcement Precedents

AuthorityCaseOutcomeKey Issue
ECHR Grand ChamberBarbulescu v Romania (2017)Violation of Art. 8Employer monitored employee Yahoo Messenger without adequate prior notification or safeguards
ECHRLibert v France (2018)No violationEmployer accessed non-personal files on work computer; personal files were identifiably marked and protected
CNIL (France)SAN-2020-012EUR 75,000Employer conducted systematic monitoring of employee internet browsing without transparency or proportionality assessment
Garante (Italy)Provvedimento 303/2016Processing prohibitedEmployer used software to monitor all employee emails in real time without DPIA or adequate transparency
AEPD (Spain)PS/00050/2020EUR 40,000Employer read employee personal emails sent from corporate account without prior notification
BfDI (Germany)Federal Labour Court BAG 2-AZR-681/16 (2017)Dismissal overturnedEmployer used keystroke logger evidence; court ruled monitoring was disproportionate and evidence inadmissible

Integration Points

  • Employee Monitoring DPIA: Email monitoring must be assessed through the DPIA process (see employee-monitoring-dpia skill).
  • Employment Consent Limits: Consent is not a valid lawful basis for email monitoring (see employment-consent-limits skill).
  • Remote Work Monitoring: Email monitoring of remote workers raises additional proportionality concerns (see remote-work-monitoring skill).
  • Employee DSAR Response: Employees have the right to access monitoring data about their own communications (see employee-dsar-response skill).
  • BYOD Privacy Policy: Monitoring of email on personal devices requires specific BYOD policy provisions (see byod-privacy-policy skill).

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/workplace-email-privacy of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Workplace Email Privacy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Workplace Email Privacy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Workplace Email Privacy this skillmukul975/Privacy-Data-Protection-Skills301—~4.4kAutomated safety check: PassApache-2.0
Pii Contract Analyzegregmos/PII-Shield150—~8.9kAutomated safety check: NotesMIT
Privacy Eukimlawtech/korean-privacy-terms587—~968Automated safety check: PassApache-2.0
Terms Of Service Generatorzubair-trabzada/ai-legal-claude1.8k—~2.9kAutomated safety check: PassNone
Tos Clause Scannerzebbern/claude-code-guide4.7k1 repos~3.3kAutomated safety check: PassMIT
Legal Advisoraiskillstore/marketplace4339 repos~615Automated safety check: PassNone

Similar skills

  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes
  • Privacy Eu

    kimlawtech/korean-privacy-terms

    EU 사용자 대상 서비스용 Privacy Notice·Terms of Service·Consent Modal·Cookie Banner 자동 생성.

    587 GitHub stars~968 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Terms Of Service Generator

    zubair-trabzada/ai-legal-claude

    Generates complete, GDPR/CCPA-compliant Terms of Service for a website or SaaS product, with plain English summaries for each section

    1.8k GitHub stars~2.9k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Tos Clause Scanner

    zebbern/claude-code-guide

    Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues.

    4.7k GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Legal Advisor

    aiskillstore/marketplace

    Draft privacy policies, terms of service, disclaimers, and legal notices.

    433 GitHub starsUsed in 9 repos~615 tokens
    Legal & ComplianceAuto-check passed
  • Legal Pages

    theopenco/llmgateway

    Edit LLM Gateway legal documents — Terms of Use, Privacy Policy, sub-processors, and product-specific supplemental terms such as DevPass.

    1.7k GitHub stars~215 tokensUpdated today
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Workplace Email Privacy

What does Workplace Email Privacy do?

Implements email and internet monitoring compliance in the workplace per Barbulescu v Romania (ECHR Grand Chamber), EDPB guidance, and national labour law. Workplace Email Privacy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements email and internet monitoring compliance in the workplace per Barbulescu v Romania (ECHR Grand Chamber), EDPB guidance, and national labour law.

When should I use Workplace Email Privacy?

Workplace Email Privacy fits situations like: tasks that involve Policy and terms drafting; tasks that involve Privacy and GDPR.

How do I install Workplace Email Privacy in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill workplace-email-privacy -a claude-code`. Or copy the skill folder (skills/privacy/workplace-email-privacy in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/workplace-email-privacy in your project. Claude Code loads it when a task matches its description.

How do I install Workplace Email Privacy in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill workplace-email-privacy -a codex`. Or copy the skill folder (skills/privacy/workplace-email-privacy in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/workplace-email-privacy in your project. Codex loads it when a task matches its description.

Can I use Workplace Email Privacy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill workplace-email-privacy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/workplace-email-privacy, .gemini/skills/workplace-email-privacy, .github/skills/workplace-email-privacy and .opencode/skills/workplace-email-privacy in your project.

What does Workplace Email Privacy need to run?

Going by SKILL.md and its folder, Workplace Email Privacy needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Workplace Email Privacy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Workplace Email Privacy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Workplace Email Privacy use?

Workplace Email Privacy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Workplace Email Privacy use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Workplace Email Privacy?

Skills that share tags, products or a category with Workplace Email Privacy: Pii Contract Analyze (gregmos/PII-Shield, 150 stars), Privacy Eu (kimlawtech/korean-privacy-terms, 587 stars), Terms Of Service Generator (zubair-trabzada/ai-legal-claude, 1.8k stars) and Tos Clause Scanner (zebbern/claude-code-guide, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Workplace Email Privacy?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.