Agent skill

Data Privacy Controls

by sickn33 in sickn33/agentic-awesome-skills

Data privacy control register: data category, lawful basis, retention period, access roles, encryption and consent requirement per module.

MITAuto-check passedLegal & Compliance

Install Data Privacy Controls

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill data-privacy-controls -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills data-privacy-controls --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/data-privacy-controls .claude/skills/data-privacy-controls && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
data-privacy-controls
GitHub stars
47k
Used in
1 other repo
Token cost
~3.4k tokens
SKILL.md length
1,360 words
Files
1
Skills in repo
1,354
Repo updated
First seen
Licence
MIT

At a glance

Data privacy control register: data category, lawful basis, retention period, access roles, encryption and consent requirement per module.

  • Works in 5 steps: Identify intent → Ask only what is missing → Hold the internal context → …
  • GDPR compliance
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Field Reference, plus 9 more sections
  • Reaches json-schema.org

What it does

Data Privacy Controls is an agent skill from sickn33/agentic-awesome-skills. Data privacy control register: data category, lawful basis, retention period, access roles, encryption and consent requirement per module. Use for GDPR compliance.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • GDPR compliance
  • Tasks that involve Privacy and GDPR

Example prompts

  • “/data-privacy-controls”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify intent
  2. Ask only what is missing
  3. Hold the internal context
  4. Recommend the smallest workflow
  5. Build only on request

What it can do on your machine

Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml, csv, sql, json and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • json-schema.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Data Privacy Controls loads about 3.4k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 1,360 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its MIT licence (© sickn33). 1,360 words, ~3,376 tokens.

Download SKILL.mdSave it as .claude/skills/data-privacy-controls/SKILL.md (or your agent's skills folder).
name
data-privacy-controls
description
Data privacy control register: data category, lawful basis, retention period, access roles, encryption and consent requirement per module. Use for GDPR compliance.
category
business
risk
safe
source
self
source_type
self
date_added
2026-09-26
author
WHOISABHISHEKADHIKARI
tags
sme, business, operations, database, csv, notion, sql, protect
source_repo
WHOISABHISHEKADHIKARI/sme-ops-system-builder

Data Privacy Controls

What it is: GDPR/CCPA.

Overview

Works out the smallest useful Data Privacy Controls setup for the business in front of it, then builds it only when asked. The default output is a short recommendation, not a spreadsheet. Artifacts - CSV, SQL DDL, JSON Schema, Notion mapping - are produced on request, from one field list so they cannot drift apart.

Layer: Layer 7: Protect. Fits: Scale stage. Table code: n/a.

When to Use This Skill

  • gdpr compliance
  • data privacy register
  • ccpa controls
  • data protection tracker

Also use it when the user says "gdpr/ccpa", or describes the same process happening in a spreadsheet, a document or someone inboxes.

Do not use it for: payroll calculation, tax filing, or legal advice. This skill produces empty templates only - it never holds or processes real employee or customer data.

How It Works

Follow the shared execution contract. The module-specific rules below define only domain fields, decisions, calculations, and safety constraints.

Step 1 - Identify intent

Read the request and pick the intent before asking anything.

  • "set up" or "build" or "create" -> the user wants artifacts; go to Step 2.
  • "our process is ..." or "it is in a sheet" -> the user wants to move an existing process; capture it, then Step 2.
  • "is this right" or "review" or "audit" -> the user wants a check, not a build; answer from what they share.
  • "how do I ..." -> advice question; answer directly and offer the build only if it helps.

Ask only if this is the highest-value missing fact; otherwise proceed without an opener:

Q: What personal data do you hold?

Step 2 - Ask only what is missing

Skip anything the user already answered, in any earlier message. Ask the rest one at a time, and stop as soon as the remaining answers would not change the output.

  • Data - Which categories? / Employee, customer or both? / How many people affected?
  • Purpose - Why is it held? / Consent given? / Any special categories?
  • Controls - Who can access it? / Retention rules? / Deletion process?
  • Current process - Is it documented? / Any privacy notice? / Has a breach happened?
  • Outcome - What do you need? / A data inventory, a control list or both?

Never invent an answer. If the user does not know, record it as unknown and carry on.

Step 3 - Hold the internal context

Hold the answers in this shape. It stays internal - it is not shown to the user unless they ask, and it never carries a value the user did not give.

yaml
module: data-privacy-controls
intent: null            # setup | advice | review | fix | build | convert | export
scale: null             # Starter | Growth | Scale, only if the answer changes it
areas:
  "Data": null
  "Purpose": null
  "Controls": null
  "Current process": null
  "Outcome": null
requested_outputs: []   # csv | sql | json | notion | xlsx - requested formats only
confirmed_facts: []     # only what the user actually said
open_questions: []      # the unanswered ones, in the order worth asking
Step 4 - Recommend the smallest workflow

If an artifact was requested, build it after resolving essential missing facts. Otherwise give a short recommendation and offer the relevant artifact.

Recommended approach: Start with an inventory of what is held and why, then attach an owner and a retention rule to each item.

Why this one: Privacy work fails without an inventory, because you cannot protect data you have not listed. The inventory comes first.

Workflow: Data category listed → Purpose recorded → Owner and access → Retention rule → Review

Step 5 - Build only on request

Once the user asks for it, derive the fields from the confirmed context and emit the requested artifacts. For machine-readable text, keep prose outside the data; for files, provide a usable link. Report material validation failures or limitations separately.

A selected Notion output is rendered by notion-manual-import, so route the Notion step there. When the user selects Notion, hand that step to @notion-manual-import: it holds the CSV, the property mapping, the import steps and the verification checklist, and it renders the Field Reference below instead of defining a table of its own. Do not restate the mapping here and do not improvise the import steps. Manual CSV and mapping outputs need no connection. For requested workspace changes, follow the shared contract: verify actual tool access and the target before writing. A user saying "connected" is not tool evidence. Never ask for a Notion password or token.

For an Excel-compatible CSV, use UTF-8 with a byte order mark so Excel opens the text correctly. A CSV is not an .xlsx workbook; create .xlsx only when the user requests a workbook. A CSV carries no types, so after it, name the columns that need a number, date or currency format applied.

csv
Control,Data Category,Module,Legal Basis,Retention Period,Access Roles,Encryption,Consent Required,Owner,Last Reviewed,Status,Control ID
Employee data retention,Personal,Invoices & Billing,Contractual necessity,24 months after last activity,"People team, Finance",At rest and in transit,FALSE,Sneha Iyer,2026-01-15,Implemented,
sql
CREATE TABLE data_privacy_controls (
  control VARCHAR(255),
  data_category VARCHAR(100) NOT NULL,
  module VARCHAR(255),
  legal_basis VARCHAR(255),
  retention_period VARCHAR(255),
  access_roles VARCHAR(255),
  encryption VARCHAR(255),
  consent_required BOOLEAN NOT NULL,
  owner VARCHAR(255),
  last_reviewed DATE NOT NULL,
  status VARCHAR(100) NOT NULL,
  control_id SERIAL PRIMARY KEY,
  created_at TIMESTAMP DEFAULT NOW(),
  updated_at TIMESTAMP DEFAULT NOW()
);

CREATE INDEX idx_data_privacy_controls_status ON data_privacy_controls (status);
json
{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "title": "Data Privacy Controls",
  "type": "object",
  "additionalProperties": false,
  "properties": {
      "Control": { "type": "string" },
      "Data Category": { "type": "string" },
      "Module": { "type": "string" },
      "Legal Basis": { "type": "string" },
      "Retention Period": { "type": "string" },
      "Access Roles": { "type": "string" },
      "Encryption": { "type": "string" },
      "Consent Required": { "type": "boolean" },
      "Owner": { "type": "string" },
      "Last Reviewed": { "type": "string", "format": "date" },
      "Status": { "type": "string" },
      "Control ID": { "type": "integer" }
  },
  "required": [
      "Data Category",
      "Last Reviewed",
      "Status"
  ]
}
markdown
| CSV column | Notion property | Set after import |
|---|---|---|
| Control | Title | Use as the database title |
| Data Category | Select (add options after import) | Convert to Select, add options: "Personal", "Sensitive", "Financial", "Health", "Biometric", "Location" |
| Module | Text | Leave as Text |
| Legal Basis | Text | Leave as Text |
| Retention Period | Text | Leave as Text |
| Access Roles | Text | Leave as Text |
| Encryption | Text | Leave as Text |
| Consent Required | Checkbox | Convert to Checkbox |
| Owner | Text | Leave as Text |
| Last Reviewed | Date | Convert to Date |
| Status | Select (add options after import) | Convert to Select, add options: "Draft", "In Review", "Approved", "Implemented", "Retired" |
| Control ID | Text (preserve source ID) | Keep imported IDs as Text; optionally add a separate Unique ID property |

The rows above are documentation examples only. Emit empty templates unless the user explicitly requests examples. Money stays currency, dates stay date, and anything pointing at another table stays relation.

Field Reference

#FieldTypeSQLJSON SchemaNotionCSV example
1ControltextVARCHAR(255)stringTextEmployee data retention
2Data CategoryselectVARCHAR(100)stringSelect (add options after import)Personal
3ModuletextVARCHAR(255)stringTextInvoices & Billing
4Legal BasistextVARCHAR(255)stringTextContractual necessity
5Retention PeriodtextVARCHAR(255)stringText24 months after last activity
6Access RolestextVARCHAR(255)stringTextPeople team, Finance
7EncryptiontextVARCHAR(255)stringTextAt rest and in transit
8Consent RequiredcheckboxBOOLEANbooleanCheckboxFALSE
9OwnertextVARCHAR(255)stringTextSneha Iyer
10Last RevieweddateDATEstring, format: dateDate2026-01-15
11StatusselectVARCHAR(100)stringSelect (add options after import)Implemented
12Control IDidSERIAL PRIMARY KEYintegerText (preserve source ID)(blank)
Show full SKILL.md (501 more words)Show less

Select Options

Data Category

Personal | Sensitive | Financial | Health | Biometric | Location

Status

Draft | In Review | Approved | Implemented | Retired

Relations

Link fields: none

Examples

Prompt

We hold a lot of employee data and cannot say who owns it.

Context first - one question per message, nothing already answered:

Q: Which categories? A: Employee and customer contact details.

Q: Consent given? A: For customers, yes.

Q: Is it documented? A: No.

Recommended next step - offered, not built:

Start with an inventory of what is held and why, then attach an owner and a retention rule to each item.

Workflow: Data category listed → Purpose recorded → Owner and access → Retention rule → Review

Want the CSV, SQL, JSON Schema and Notion mapping for this?

Best Practices

  • Build when requested; recommend and offer a build for advice-only requests.
  • One question per message. A batched intake reads as a form and gets guessed at.
  • Keep display names identical across CSV and JSON; document normalized SQL identifiers.
  • Use relation for anything that points at another table, text only for free text.
  • Money fields are currency, never text. Dates are date, never free text.
  • If the user requests an example row, keep it obviously fake so nobody imports it as real data.

Limitations

  • Empty template only. It does not compute payroll, tax, leave balances or KPIs.
  • Notion relations need both databases imported before the link column resolves.
  • Select options are a starting set. Rename them to match how the business talks.
  • No automation, reminders or sync. Those need the integration layer.
  • Does not provide legal advice, and you should involve a qualified reviewer for compliance obligations.
  • Legal, tax and HR review is still required before this drives real decisions.

Security & Safety Notes

  • Never fill in real names, salaries, medical or banking data. Placeholders only.
  • Label example rows as synthetic, and keep bank details masked.
  • Local reads, generation commands, and validation are part of a requested artifact build. External writes, messages, provisioning, and publication require authorization for that action and target; existing explicit authorization does not need to be repeated.
  • If sensitive data is supplied, avoid repeating unnecessary identifiers. Use only what the requested review needs; keep generated templates empty. Do not claim deletion from the conversation or service storage.
  • Privacy, legal and disciplinary cases need a qualified human reviewer before anything is acted on.

Common Pitfalls

  • Problem: a static mapping is described as a completed workspace build. Solution: deliver manual mappings without a connection; claim a live change only after the authorized tool operation succeeds.
  • Problem: asked all six questions in one message. Solution: ask one, wait, and drop any the first answer already covered.
  • Problem: built a full system when one table was asked for. Solution: build what was requested; mention the parent skill separately.
  • Problem: all four artifacts drift apart. Solution: derive all four from the field list in this file, never by hand.
  • Problem: Notion import shows every column as Text. Solution: that is expected. Apply the property mapping table once, after import.

Reusable Prompt

I want to set up gdpr/ccpa for my company.
Ask me one short question at a time, and only about what I have not already told you.
Then recommend the smallest setup that fits, and wait for me to ask before you build it.
When I ask, output CSV, SQL DDL, JSON Schema, a Notion property mapping or an Excel workbook. Data only.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/data-privacy-controls of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit ec02547

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Data Privacy Controls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Data Privacy Controls compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Data Privacy Controls this skillsickn33/agentic-awesome-skills47k1 repos~3.4kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    942 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    942 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from sickn33/agentic-awesome-skills

All 1,354 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed
  • Content Creator

    sickn33/agentic-awesome-skills

    Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed

Questions about Data Privacy Controls

What does Data Privacy Controls do?

Data privacy control register: data category, lawful basis, retention period, access roles, encryption and consent requirement per module. Data Privacy Controls is an agent skill from sickn33/agentic-awesome-skills. Data privacy control register: data category, lawful basis, retention period, access roles, encryption and consent requirement per module.

When should I use Data Privacy Controls?

Data Privacy Controls fits situations like: GDPR compliance; tasks that involve Privacy and GDPR.

How do I install Data Privacy Controls in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill data-privacy-controls -a claude-code`. Or copy the skill folder (skills/data-privacy-controls in sickn33/agentic-awesome-skills) into .claude/skills/data-privacy-controls in your project. Claude Code loads it when a task matches its description.

How do I install Data Privacy Controls in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill data-privacy-controls -a codex`. Or copy the skill folder (skills/data-privacy-controls in sickn33/agentic-awesome-skills) into .agents/skills/data-privacy-controls in your project. Codex loads it when a task matches its description.

Can I use Data Privacy Controls in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill data-privacy-controls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/data-privacy-controls, .gemini/skills/data-privacy-controls, .github/skills/data-privacy-controls and .opencode/skills/data-privacy-controls in your project.

What does Data Privacy Controls need to run?

SKILL.md names no scripts, command-line tools or credentials: Data Privacy Controls is instructions for the agent only.

Does Data Privacy Controls access the network?

SKILL.md names 1 domain. In commands or code: json-schema.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Data Privacy Controls safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Data Privacy Controls use?

Data Privacy Controls is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Data Privacy Controls use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Data Privacy Controls?

Skills that share tags, products or a category with Data Privacy Controls: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Data Privacy Controls?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.