C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
GDPR and German DSGVO compliance automation. An agent skill from aAAaqwq/AGI-Super-Team.
$ npx skills add aAAaqwq/AGI-Super-Team --skill gdpr-dsgvo-expert -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team gdpr-dsgvo-expert --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gdpr-dsgvo-expert .claude/skills/gdpr-dsgvo-expert && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gdpr-dsgvo-expert" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/gdpr-dsgvo-expert into .claude/skills/gdpr-dsgvo-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-dsgvo-expert", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/gdpr-dsgvo-expertType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aAAaqwq/AGI-Super-Team --skill gdpr-dsgvo-expert -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team gdpr-dsgvo-expert --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/gdpr-dsgvo-expert .agents/skills/gdpr-dsgvo-expert && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gdpr-dsgvo-expert" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/gdpr-dsgvo-expert into .agents/skills/gdpr-dsgvo-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-dsgvo-expert", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aAAaqwq/AGI-Super-Team --skill gdpr-dsgvo-expert -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team gdpr-dsgvo-expert --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/gdpr-dsgvo-expert .cursor/skills/gdpr-dsgvo-expert && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gdpr-dsgvo-expert" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/gdpr-dsgvo-expert into .cursor/skills/gdpr-dsgvo-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-dsgvo-expert", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aAAaqwq/AGI-Super-Team.git --path skills/gdpr-dsgvo-expert--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aAAaqwq/AGI-Super-Team --skill gdpr-dsgvo-expert -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team gdpr-dsgvo-expert --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/gdpr-dsgvo-expert .gemini/skills/gdpr-dsgvo-expert && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gdpr-dsgvo-expert" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/gdpr-dsgvo-expert into .gemini/skills/gdpr-dsgvo-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-dsgvo-expert", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aAAaqwq/AGI-Super-Team gdpr-dsgvo-expertInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aAAaqwq/AGI-Super-Team --skill gdpr-dsgvo-expert -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/gdpr-dsgvo-expert .github/skills/gdpr-dsgvo-expert && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gdpr-dsgvo-expert" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/gdpr-dsgvo-expert into .github/skills/gdpr-dsgvo-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-dsgvo-expert", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aAAaqwq/AGI-Super-Team --skill gdpr-dsgvo-expert -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team gdpr-dsgvo-expert --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/gdpr-dsgvo-expert .opencode/skills/gdpr-dsgvo-expert && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gdpr-dsgvo-expert" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/gdpr-dsgvo-expert into .opencode/skills/gdpr-dsgvo-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gdpr-dsgvo-expert", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gdpr-dsgvo-expertGDPR and German DSGVO compliance automation. An agent skill from aAAaqwq/AGI-Super-Team.
Gdpr Dsgvo Expert is an agent skill from aAAaqwq/AGI-Super-Team. GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests. Use for GDPR compliance assessments, privacy audits, data protection planning, DPIA generation, and data subject rights management.
Its SKILL.md is about 7.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/dpia_methodology.md`, `references/gdpr_compliance_guide.md` and `references/german_bdsg_requirements.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: An installable, cross-framework AI organization: C-suite agents, expert subagents, curated skills, independent review, and one-command setup across 18 AI client/runtime adapters. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 7cefd81. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gdpr Dsgvo Expert loads about 7.9k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 3,043 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from aAAaqwq/AGI-Super-Team at commit 7cefd81, republished under its MIT licence (© aAAaqwq). 3,043 words, ~7,927 tokens.
.claude/skills/gdpr-dsgvo-expert/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Tools and guidance for EU General Data Protection Regulation (GDPR) and German Bundesdatenschutzgesetz (BDSG) compliance.
Scans codebases for potential GDPR compliance issues including personal data patterns and risky code practices.
# Scan a project directory
python scripts/gdpr_compliance_checker.py /path/to/project
# JSON output for CI/CD integration
python scripts/gdpr_compliance_checker.py . --json --output report.jsonDetects:
Output:
Generates Data Protection Impact Assessment documentation following Art. 35 requirements.
# Get input template
python scripts/dpia_generator.py --template > input.json
# Generate DPIA report
python scripts/dpia_generator.py --input input.json --output dpia_report.mdFeatures:
DPIA Triggers Assessed:
Manages data subject rights requests under GDPR Articles 15-22.
# Add new request
python scripts/data_subject_rights_tracker.py add \
--type access --subject "John Doe" --email "john@example.com"
# List all requests
python scripts/data_subject_rights_tracker.py list
# Update status
python scripts/data_subject_rights_tracker.py status --id DSR-202601-0001 --update verified
# Generate compliance report
python scripts/data_subject_rights_tracker.py report --output compliance.json
# Generate response template
python scripts/data_subject_rights_tracker.py template --id DSR-202601-0001Supported Rights:
| Right | Article | Deadline |
|---|---|---|
| Access | Art. 15 | 30 days |
| Rectification | Art. 16 | 30 days |
| Erasure | Art. 17 | 30 days |
| Restriction | Art. 18 | 30 days |
| Portability | Art. 20 | 30 days |
| Objection | Art. 21 | 30 days |
| Automated decisions | Art. 22 | 30 days |
Features:
references/gdpr_compliance_guide.md
Comprehensive implementation guidance covering:
references/german_bdsg_requirements.md
German-specific requirements including:
references/dpia_methodology.md
Step-by-step DPIA process:
Step 1: Run compliance checker on codebase
→ python scripts/gdpr_compliance_checker.py /path/to/code
Step 2: Review findings and compliance score
→ Address critical and high issues
Step 3: Determine if DPIA required
→ Check references/dpia_methodology.md threshold criteria
Step 4: If DPIA required, generate assessment
→ python scripts/dpia_generator.py --template > input.json
→ Fill in processing details
→ python scripts/dpia_generator.py --input input.json --output dpia.md
Step 5: Document in records of processing activitiesStep 1: Log request in tracker
→ python scripts/data_subject_rights_tracker.py add --type [type] ...
Step 2: Verify identity (proportionate measures)
→ python scripts/data_subject_rights_tracker.py status --id [ID] --update verified
Step 3: Gather data from systems
→ python scripts/data_subject_rights_tracker.py status --id [ID] --update in_progress
Step 4: Generate response
→ python scripts/data_subject_rights_tracker.py template --id [ID]
Step 5: Send response and complete
→ python scripts/data_subject_rights_tracker.py status --id [ID] --update completed
Step 6: Monitor compliance
→ python scripts/data_subject_rights_tracker.py reportStep 1: Determine if DPO required
→ 20+ employees processing personal data automatically
→ OR processing requires DPIA
→ OR business involves data transfer/market research
Step 2: If employees involved, review § 26 BDSG
→ Document legal basis for employee data
→ Check works council requirements
Step 3: If video surveillance, comply with § 4 BDSG
→ Install signage
→ Document necessity
→ Limit retention
Step 4: Register DPO with supervisory authority
→ See references/german_bdsg_requirements.md for authority listRequires explicit consent or Art. 9(2) exception:
All rights must be fulfilled within 30 days (extendable to 90 for complex requests):
| Topic | BDSG Section | Key Requirement |
|---|---|---|
| DPO threshold | § 38 | 20+ employees = mandatory DPO |
| Employment | § 26 | Detailed employee data rules |
| Video | § 4 | Signage and proportionality |
| Scoring | § 31 | Explainable algorithms |
When operating across EU and US jurisdictions, align GDPR compliance with California Consumer Privacy Act (CCPA) as amended by CPRA. Key differences to manage:
| Dimension | GDPR | CCPA/CPRA |
|---|---|---|
| Scope | Any org processing EU resident data | For-profit businesses meeting revenue/data thresholds |
| Legal basis | 6 lawful bases required (Art. 6) | No legal basis requirement; opt-out model |
| Consent | Opt-in by default | Opt-out (except minors and sensitive data) |
| Data subject rights | Access, rectification, erasure, portability, objection | Know, delete, correct, opt-out of sale/sharing, limit sensitive data use |
| Breach notification | 72 hours to supervisory authority (Art. 33) | "Most expedient time possible" to consumers |
| Enforcement | DPAs with fines up to 4% global turnover | California Privacy Protection Agency (CPPA), $2,500-$7,500 per violation |
| DPO requirement | Mandatory in many cases (Art. 37) | No DPO requirement |
| Children's data | Under 16 requires parental consent (Art. 8) | Under 16 opt-in for sale; under 13 parental consent |
Practical alignment: Build a unified privacy program that satisfies the stricter GDPR requirements by default, then layer CCPA/CPRA-specific mechanisms (e.g., "Do Not Sell or Share My Personal Information" link, annual metrics disclosure).
See also:
../ccpa-cpra-specialist/SKILL.mdfor full CCPA/CPRA compliance workflows and tools.
Implement compliant cookie consent per GDPR Art. 6 + ePrivacy Directive:
| Category | Examples | Consent Required | Default State |
|---|---|---|---|
| Strictly Necessary | Session, CSRF, load balancer | No | Active |
| Functional | Language preference, UI settings | Yes | Inactive |
| Analytics | Google Analytics, Matomo, Hotjar | Yes | Inactive |
| Marketing | Facebook Pixel, Google Ads, retargeting | Yes | Inactive |
Implementation requirements:
Per CCPA/CPRA regulations and emerging EU guidance:
Sec-GPC: 1 HTTP header and navigator.globalPrivacyControl JavaScript API| Transfer Mechanism | Status (post-Schrems II) | When to Use |
|---|---|---|
| EU Adequacy Decision | Valid | Transfers to adequate countries (e.g., Japan, UK, South Korea, US via DPF) |
| Standard Contractual Clauses (SCCs) | Valid with TIA | Default mechanism for non-adequate countries |
| Binding Corporate Rules (BCRs) | Valid | Intra-group transfers in multinationals |
| EU-US Data Privacy Framework (DPF) | Valid (since July 2023) | US companies certified under DPF |
| Derogations (Art. 49) | Limited use only | Explicit consent, contract necessity — not for systematic transfers |
Transfer Impact Assessment (TIA) requirements for SCCs:
Art. 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects:
| Requirement | Implementation |
|---|---|
| Right not to be subject to automated decisions | Provide human review mechanism for consequential decisions |
| Right to explanation | Document and explain logic, significance, and consequences |
| Right to contest | Enable data subjects to challenge automated decisions |
| Explicit consent or contract necessity | Secure Art. 22(2) legal basis before deploying |
| Suitable safeguards | Implement human oversight, right to express point of view |
AI transparency checklist:
| Requirement | GDPR Basis | Action |
|---|---|---|
| Lawful basis for training data | Art. 6 | Legitimate interest (with DPIA) or consent |
| Purpose limitation | Art. 5(1)(b) | Training purpose must be compatible with original collection |
| Data minimization | Art. 5(1)(c) | Use minimum data necessary; prefer synthetic/anonymized data |
| Accuracy | Art. 5(1)(d) | Ensure training data is accurate and up-to-date |
| Storage limitation | Art. 5(1)(e) | Define retention for training datasets |
| Special category data | Art. 9 | Explicit consent or Art. 9(2)(j) research exemption for health/biometric data |
| Right to erasure | Art. 17 | Implement mechanism to remove individual data from training sets (or document inability) |
| Data scraping | Art. 14 | Inform data subjects when using publicly available data for training |
For AI systems processing personal data, both GDPR Art. 35 DPIA and EU AI Act conformity assessment may apply:
| AI Risk Level (EU AI Act) | GDPR DPIA Required? | Combined Assessment Approach |
|---|---|---|
| Unacceptable (Art. 5) | N/A — prohibited | Do not deploy |
| High-risk (Annex III) | Almost always yes | Joint DPIA + conformity assessment |
| Limited risk (Art. 50) | Evaluate per Art. 35 criteria | DPIA if systematic monitoring or profiling |
| Minimal risk | Evaluate per Art. 35 criteria | Standard DPIA threshold assessment |
Step 1: AI System Classification
→ Classify under EU AI Act risk levels
→ Map to GDPR Art. 35(3) triggers
Step 2: Data Flow and Processing Analysis
→ Document training data sources and legal basis
→ Map inference data flows
→ Identify automated decision points (Art. 22)
Step 3: AI-Specific Risk Assessment
→ Bias and discrimination risk (protected groups)
→ Accuracy and reliability risk
→ Explainability and transparency gaps
→ Data quality and representativeness
→ Model drift and ongoing monitoring needs
Step 4: Fundamental Rights Impact
→ Right to non-discrimination
→ Right to privacy and data protection
→ Freedom of expression (content moderation AI)
→ Right to an effective remedy
Step 5: Combined Mitigation Measures
→ Technical: differential privacy, federated learning, model cards
→ Organizational: AI ethics board, human oversight procedures
→ Contractual: AI-specific DPA clauses with processors
→ Monitoring: continuous bias monitoring, performance drift detection
Step 6: DPO and Supervisory Authority Consultation
→ Consult DPO on combined assessment
→ Prior consultation with SA if high residual risk (Art. 36)
→ Notify national AI authority if high-risk AI system| Technique | Description | Use Case |
|---|---|---|
| Field-level encryption | Encrypt specific PII fields at rest | Database storage |
| Tokenization | Replace PII with non-reversible tokens | Payment processing, analytics |
| Data masking | Obscure portions of data (e.g., email: j***@example.com) | UI display, logging |
| Aggregation | Process only aggregated/statistical data | Analytics, reporting |
| Purpose-scoped access | Limit data access to specific processing purposes | Multi-purpose systems |
| Automatic expiration | TTL-based data deletion | Session data, temporary processing |
| Method | Reversibility | Strength | Best For |
|---|---|---|---|
| HMAC-based | Reversible with key | Strong | Internal analytics with re-identification need |
| Format-preserving encryption | Reversible with key | Strong | Legacy system compatibility |
| Deterministic hashing (salted) | One-way | Medium | Cross-dataset linkage without PII |
| Random ID mapping | Reversible with lookup table | Strong | Research datasets |
Key management for pseudonymization:
| Layer | Minimum Standard | Recommended |
|---|---|---|
| At rest | AES-256 | AES-256-GCM with envelope encryption |
| In transit | TLS 1.2 | TLS 1.3 |
| Database | Transparent Data Encryption (TDE) | Column-level encryption for PII |
| Backups | AES-256 | AES-256 + separate key from production |
| Key management | Hardware-backed (HSM/KMS) | Cloud KMS with customer-managed keys (BYOK) |
| Requirement | GDPR Article | CCPA/CPRA Section | HIPAA Rule | NIS2 Article |
|---|---|---|---|---|
| Risk assessment | Art. 35 (DPIA) | §1798.185 (risk assessment regs) | §164.308(a)(1) | Art. 21(2)(a) |
| Breach notification | Art. 33-34 (72 hrs to SA) | §1798.150 (to consumers) | §164.404-408 (60 days) | Art. 23 (24 hrs early warning) |
| Data minimization | Art. 5(1)(c) | §1798.100(c) (collection limitation) | §164.502(b) (minimum necessary) | Art. 21(2)(e) |
| Encryption | Art. 32(1)(a) | Implicit (reasonable security) | §164.312(a)(2)(iv) (addressable) | Art. 21(2)(e) |
| Access controls | Art. 32(1)(b) | Implicit (reasonable security) | §164.312(a)(1) (access control) | Art. 21(2)(d) |
| Incident response | Art. 33-34 | §1798.150 | §164.308(a)(6) | Art. 21(2)(b) |
| Supply chain security | Art. 28 (processor agreements) | §1798.140(ag) (service provider contracts) | §164.308(b) (BAAs) | Art. 21(2)(d) |
| Governance/accountability | Art. 5(2), Art. 24 | §1798.185 (audit regs) | §164.308(a)(1) | Art. 20 (governance) |
| Right to delete/erasure | Art. 17 | §1798.105 | Limited (retention rules) | N/A |
| Data portability | Art. 20 | §1798.130(a)(2) | N/A | N/A |
Cross-references: See
../information-security-manager-iso27001/SKILL.mdfor ISO 27001 security controls, and../mdr-745-specialist/SKILL.mdfor healthcare device data protection under MDR.
| Aspect | GDPR | CCPA/CPRA |
|---|---|---|
| Scope | Any org processing EU residents' data | $25M+ revenue, 100K+ consumers, or 50%+ revenue from selling PI |
| Legal Basis | 6 legal bases required (Art. 6) | Opt-out model (no legal basis needed for collection) |
| Consent | Opt-in required | Opt-out for sale/sharing |
| Right to Delete | Art. 17 | §1798.105 |
| Data Portability | Art. 20 | §1798.130 |
| Penalties | Up to €20M or 4% global turnover | $2,500-$7,500 per violation |
| DPO Required | Yes (in many cases) | No |
| DPIA Required | Yes (high risk processing) | Risk assessments (CPRA) |
eu-ai-act-specialist for AI-specific compliance| Control | GDPR | CCPA | HIPAA | NIS2 |
|---|---|---|---|---|
| Privacy Notice | Art. 13-14 | §1798.100 | Privacy Practices | — |
| Data Subject Rights | Art. 15-22 | §1798.100-125 | Access/Amendment | — |
| Breach Notification | Art. 33-34 | §1798.150 | §164.404-408 | Art. 23 |
| DPO/Privacy Officer | Art. 37-39 | — | Privacy Officer | — |
| Risk Assessment | Art. 35 (DPIA) | Risk Assessment | §164.308(a)(1) | Art. 21 |
| Encryption | Art. 32 | Reasonable Security | §164.312(a)(2)(iv) | Art. 21.2.h |
| Training | Art. 39.1.b | — | §164.308(a)(5) | Art. 21.2.g |
| Problem | Possible Cause | Resolution |
|---|---|---|
| Compliance checker reports critical findings for special category data | Code processes health, biometric, or religious data without explicit consent or Art. 9(2) exception | Identify all special category data processing; secure explicit consent or document applicable Art. 9(2) exception; implement field-level encryption for sensitive fields |
| DPIA generator determines assessment required but organization has no DPIA process | Processing triggers Art. 35(3) criteria (systematic monitoring, large-scale special categories, or automated decision-making) | Follow the DPIA methodology in references/dpia_methodology.md; generate template with dpia_generator.py --template; consult DPO before proceeding; consider prior consultation with supervisory authority if high residual risk (Art. 36) |
| Data subject rights requests consistently exceed 30-day deadline | Manual fulfillment without tracking system, unclear data location, or complex verification requirements | Deploy data_subject_rights_tracker.py for automated deadline monitoring; map all personal data locations using data inventory; streamline identity verification to proportionate measures |
| Cross-border transfer mechanism invalidated or uncertain | Reliance on deprecated mechanism or Transfer Impact Assessment not completed for SCCs | Review current adequacy decisions (UK, Japan, South Korea, US via DPF); for SCCs, complete Transfer Impact Assessment per Schrems II requirements; document supplementary measures (encryption, pseudonymization) |
| Cookie consent banner flagged as non-compliant | Pre-checked boxes, cookie wall blocking access, or reject button harder to find than accept | Implement TCF 2.2 compliant CMP; ensure all non-essential cookies blocked until explicit consent; make reject as prominent as accept (per Planet49 ruling, CJEU C-673/17); record consent proof |
| GDPR compliance checker detects personal data in application logs | Application logs contain email addresses, IP addresses, or user identifiers | Implement log sanitization to mask or pseudonymize personal data before storage; configure logging frameworks to exclude PII fields; set log retention limits aligned with purpose |
| AI system processing personal data lacks Art. 22 safeguards | Automated decision-making produces legal or significant effects without human review mechanism | Implement human-in-the-loop for high-stakes decisions; provide right to explanation and right to contest; document algorithmic logic in plain language; include AI decision-making in privacy notice per Art. 13(2)(f) |
data_subject_rights_tracker.py with identity verification completed, response templates generated, and compliance reports showing zero overdue requestsIn Scope:
Out of Scope:
Important Notes:
| Skill | Integration | When to Use |
|---|---|---|
ccpa-cpra-privacy-expert | Unified privacy program covering both GDPR and CCPA/CPRA; cross-framework mapping | When organization processes data of both EU residents and California consumers |
eu-ai-act-specialist | Combined DPIA + AI Act conformity assessment for high-risk AI systems processing personal data | When AI system triggers both GDPR Art. 35 DPIA and EU AI Act high-risk classification |
information-security-manager-iso27001 | ISO 27001 security controls support GDPR Art. 32 security of processing requirements | When implementing technical and organizational measures for personal data protection |
infrastructure-compliance-auditor | Technical privacy controls validation (encryption, access controls, logging, data masking) | When assessing infrastructure supporting GDPR privacy-by-design requirements |
dora-compliance-expert | DORA complements GDPR for financial sector ICT systems processing personal data | When financial entity must align DORA ICT security with GDPR data protection requirements |
Scans codebases for potential GDPR compliance issues including personal data patterns and risky code practices.
| Flag | Required | Description |
|---|---|---|
<project_dir> | Yes | Path to project directory to scan |
--json | No | Output results in JSON format for CI/CD integration |
--output <file> | No | Export report to specified file path |
Detects: Email, phone, IP address, credit card, IBAN, German ID patterns; special category data (health, biometric, religion); risky code patterns (logging PII, missing consent, indefinite retention, unencrypted sensitive data, disabled deletion). Output: Compliance score (0-100), risk categorization (critical/high/medium), and prioritized recommendations with GDPR article references.
Generates Data Protection Impact Assessment documentation following Art. 35 requirements.
| Flag | Required | Description |
|---|---|---|
--template | No | Generate blank DPIA input template to stdout |
--input <file> | Yes (unless --template or --interactive) | Path to JSON processing activity description |
--output <file> | No | Export DPIA report to specified file path (markdown format) |
--interactive | No | Launch interactive mode for guided DPIA creation |
Features: Automatic DPIA threshold assessment against Art. 35(3) triggers and WP29 criteria, risk identification based on processing characteristics, legal basis documentation, mitigation recommendations, and markdown report generation.
Manages data subject rights requests under GDPR Articles 15-22 with deadline tracking and response templates.
| Subcommand | Description |
|---|---|
add | Add new request (--type, --subject, --email required) |
list | List all tracked requests |
status | View or update request status (--id required, --update to change status) |
report | Generate compliance report (--output for file export) |
template | Generate response template for specific request (--id required) |
| Flag | Description |
|---|---|
--type <right> | Right type: access, rectification, erasure, restriction, portability, objection, automated |
--subject <name> | Data subject name |
--email <email> | Data subject email address |
--id <request_id> | Request identifier (e.g., DSR-202601-0001) |
--update <status> | New status: received, verified, in_progress, completed, denied, extended |
--output <file> | Export report or template to specified file path |
Features: 30-day deadline tracking with overdue alerts, identity verification workflow, response template generation per right type, and compliance reporting with metrics.
© aAAaqwq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in skills/gdpr-dsgvo-expert of aAAaqwq/AGI-Super-Team.
Open the folder on GitHubat commit 7cefd81
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in aAAaqwq/AGI-Super-Team, which our catalogue first saw on October 7, 2026.
Gdpr Dsgvo Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gdpr Dsgvo Expert this skillaAAaqwq/AGI-Super-Team | 105 | 3 repos | ~7.9k | Automated safety check: Pass | MIT | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
aAAaqwq/AGI-Super-Team
Create SEO-optimized marketing content with consistent brand voice.
aAAaqwq/AGI-Super-Team
Advanced financial calculator with future value tables, present value, discount calculations, markup pricing, and compound interest.
aAAaqwq/AGI-Super-Team
Transaction-verified trading signals on Base blockchain. An agent skill from aAAaqwq/AGI-Super-Team.
aAAaqwq/AGI-Super-Team
Register AI agents on Ethereum mainnet using ERC-8004 (Trustless Agents).
aAAaqwq/AGI-Super-Team
Create distinctive, production-grade static sites with React, Tailwind CSS, and shadcn/ui — no mockups needed.
aAAaqwq/AGI-Super-Team
Publish and manage content on 知识星球 (zsxq.com). An agent skill from aAAaqwq/AGI-Super-Team.
Categories
GDPR and German DSGVO compliance automation. An agent skill from aAAaqwq/AGI-Super-Team. Gdpr Dsgvo Expert is an agent skill from aAAaqwq/AGI-Super-Team. GDPR and German DSGVO compliance automation.
Gdpr Dsgvo Expert fits situations like: GDPR compliance assessments; data protection planning; DPIA generation; data subject rights management.
Run `npx skills add aAAaqwq/AGI-Super-Team --skill gdpr-dsgvo-expert -a claude-code`. Or copy the skill folder (skills/gdpr-dsgvo-expert in aAAaqwq/AGI-Super-Team) into .claude/skills/gdpr-dsgvo-expert in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aAAaqwq/AGI-Super-Team --skill gdpr-dsgvo-expert -a codex`. Or copy the skill folder (skills/gdpr-dsgvo-expert in aAAaqwq/AGI-Super-Team) into .agents/skills/gdpr-dsgvo-expert in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aAAaqwq/AGI-Super-Team --skill gdpr-dsgvo-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gdpr-dsgvo-expert, .gemini/skills/gdpr-dsgvo-expert, .github/skills/gdpr-dsgvo-expert and .opencode/skills/gdpr-dsgvo-expert in your project.
Going by SKILL.md and its folder, Gdpr Dsgvo Expert needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Gdpr Dsgvo Expert is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 7.9k tokens (SKILL.md is roughly 32k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Gdpr Dsgvo Expert: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aAAaqwq (a GitHub user) maintains it in aAAaqwq/AGI-Super-Team, which has 105 GitHub stars. The repository holds 167 skills in this directory. The repository was last updated on October 8, 2026.
Source: aAAaqwq/AGI-Super-Team on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.