C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of…
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ccpa --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ccpa/skills/ccpa .claude/skills/ccpa && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ccpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ccpa/skills/ccpa into .claude/skills/ccpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ccpa", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ccpa/skills/ccpaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ccpa --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/ccpa/skills/ccpa .agents/skills/ccpa && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ccpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ccpa/skills/ccpa into .agents/skills/ccpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ccpa", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ccpa --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/ccpa/skills/ccpa .cursor/skills/ccpa && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ccpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ccpa/skills/ccpa into .cursor/skills/ccpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ccpa", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git --path plugins/ccpa/skills/ccpa--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ccpa --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/ccpa/skills/ccpa .gemini/skills/ccpa && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ccpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ccpa/skills/ccpa into .gemini/skills/ccpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ccpa", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ccpaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/ccpa/skills/ccpa .github/skills/ccpa && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ccpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ccpa/skills/ccpa into .github/skills/ccpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ccpa", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ccpa --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/ccpa/skills/ccpa .opencode/skills/ccpa && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ccpa" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ccpa/skills/ccpa into .opencode/skills/ccpa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ccpa", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ccpaCalifornia Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of…
Ccpa is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of sale/sharing, limit SPI, ADMT opt-out), privacy notice drafting, service provider vs. contractor vs. third-party classification, sensitive personal information (SPI) handling, data minimization, opt-out mechanisms (including GPC), cybersecurity audits and risk assessments (live since Jan 1, 2026), ADMT obligations…
Its SKILL.md is about 7.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/ccpa-gdpr-comparison.md` and `references/consumer-rights-workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ccpa loads about 7.1k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 183 tokens; SKILL.md has 3,682 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 3,682 words, ~7,077 tokens.
.claude/skills/ccpa/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Last verified: 2026-10-03
You are an expert on California's comprehensive privacy laws:
Work through these steps in order for any organization asking "does CCPA/CPRA apply to us?"
| # | Threshold | Exact Figure |
|---|---|---|
| 1 | Annual gross revenue | Exceeds $25 million in the preceding calendar year |
| 2 | Data volume | Annually buys, sells, receives, or shares the personal information of 100,000 or more consumers or households |
| 3 | Revenue from data monetization | Derives 50% or more of annual revenue from selling or sharing consumers' personal information |
| Classification | Definition | Sale? |
|---|---|---|
| Service Provider | Processes PI on behalf of the business under a written contract that prohibits further use beyond the specified business purpose | Not a sale |
| Contractor (CPRA addition) | Receives PI under a contract that prohibits use for any purpose other than specified; must certify compliance | Not a sale |
| Third Party | Receives PI but is not a service provider or contractor | May constitute a sale or sharing |
| Right | Description | Response Deadline |
|---|---|---|
| Right to Know (§1798.110 / §1798.115) | Access specific PI collected, categories, sources, purposes, third parties | 45 days (+ 45-day extension) |
| Right to Delete (§1798.105) | Delete PI collected from the consumer; exceptions apply | 45 days (+ 45-day extension) |
| Right to Correct (§1798.106) | Correct inaccurate PI (CPRA addition) | 45 days (+ 45-day extension) |
| Right to Opt-Out of Sale/Sharing (§1798.120) | Stop sale or sharing of PI to third parties | Immediate upon request; propagate within 15 business days |
| Right to Limit SPI Use (§1798.121) | Limit use/disclosure of SPI to what's necessary (CPRA addition) | 15 business days |
| Right to Non-Discrimination (§1798.125) | Cannot deny goods/services or charge different prices for exercising rights | N/A |
| Right to Data Portability | Receive PI in portable, usable format | Included in right to know |
| Right to Opt-In (minors) | Opt-in required for sale/sharing of minors' PI (under 16); parental consent under 13 | N/A |
| Automated Decision-Making (ADMT) (§1798.185(a)(16)) | Right to opt-out of ADMT; right to access logic; right to human review. Regulations finalized and effective January 1, 2026. Compliance deadline for ADMT opt-out mechanism: January 1, 2027. | Per CPPA regulations |
Must disclose: specific pieces of PI collected; categories of PI; categories of sources; business/commercial purpose for collecting, selling, or sharing; categories of third parties PI was disclosed to; categories of PI sold or shared and to whom.
Scope: default lookback is the 12 months prior to the request; for PI collected on or after January 1, 2022, the consumer may request information beyond 12 months and the business must provide it unless doing so proves impossible or would involve disproportionate effort (§1798.130(a)(2)(B)).
Exceptions: disclosure would reveal third-party trade secrets; would conflict with federal/state law; PI was collected for a single one-time transaction and not retained; PI is used solely for internal operations consistent with context of collection; PI is used solely to complete the transaction for which it was collected.
| Step | Action |
|---|---|
| 1 | Receive and log request with timestamp |
| 2 | Verify consumer identity (2-point match for standard requests) |
| 3 | Search PI systems using identifying data |
| 4 | Compile responsive PI across all systems (CRM, analytics, ad tech, etc.) |
| 5 | Apply exceptions — remove third-party trade secrets, conflicting legal holds |
| 6 | Deliver response in portable, readily usable format within 45 days |
| 7 | Provide extension notice if needed (within the original 45-day window) |
Business must delete the consumer's PI from its records and direct service providers and contractors to delete it.
Exceptions (business may retain PI if necessary to): (1) complete a transaction or perform a contract; (2) detect security incidents or protect against malicious, deceptive, fraudulent, or illegal activity; (3) fix errors that impair intended functionality; (4) exercise free speech or ensure another consumer's right to free speech; (5) comply with a legal obligation (§1798.145(a)); (6) use PI solely for internal purposes compatible with the context of collection (limited CPRA exception); (7) research, journalism, or statistical purposes in the public interest.
Two-step deletion confirmation workflow:
| Step | Action |
|---|---|
| 1 | Receive and log deletion request |
| 2 | Verify consumer identity |
| 3 | Check whether any exception applies; document reasoning if invoking one |
| 4 | Step one — execute: if proceeding, identify all PI records and propagate deletion instructions to service providers and contractors |
| 5 | Step two — confirm: confirm deletion to the consumer (or explain the exception invoked) within 45 days |
| 6 | Retain deletion-request records as proof of compliance (retaining the request record itself is not a contradiction of the deletion) |
Business must take commercially reasonable steps to correct inaccurate PI and instruct service providers and contractors to correct it. Consumer must provide documentation if the business contests the claimed inaccuracy. Business may decline if correction would require revealing another individual's PI, or if it disagrees the PI is inaccurate and documents its decision.
| Step | Action |
|---|---|
| 1 | Receive correction request with claimed correction details |
| 2 | Verify consumer identity |
| 3 | Evaluate accuracy of the claimed correction (may request supporting documentation) |
| 4 | If agreeing to correct: update all relevant systems; instruct service providers and contractors |
| 5 | Notify consumer of outcome within 45 days |
Scope: "Sale" = disclosure of PI to a third party for monetary or other valuable consideration. "Sharing" (CPRA) = disclosure of PI to a third party for cross-context behavioral advertising.
Sale vs. sharing analysis for ad tech: any pipeline that passes PI (cookie IDs, device fingerprints, hashed emails, IP addresses) to ad exchanges, DMPs, or ad tech partners for cross-context behavioral advertising is "sharing" even absent monetary payment, and must be covered by the opt-out mechanism. First-party analytics tools that do not disclose PI to third parties are typically unaffected. Once a consumer opts out, the business must wait 12 months before asking them to re-consent.
The service-provider workaround does not exist for CCBA (Regs §7050(c)): a person who contracts with a business to provide cross-context behavioral advertising is a third party, not a service provider or contractor, with respect to those services — restricted-use contract terms cannot convert CCBA disclosures into service-provider activity. Service providers may still provide contextual advertising and non-CCBA marketing services, but must not combine opted-out consumers' PI with PI from other sources. State this rule explicitly in any ad-tech classification answer.
GPC / opt-out preference signal handling: the business must honor the Global Privacy Control (GPC) signal as a valid opt-out — the CPPA has confirmed GPC compliance is required. GPC signals must be treated equivalently to a manual click on the "Do Not Sell or Share" link; no separate identity verification is required to act on an opt-out (only reasonable verification that the requester is the consumer).
| Step | Action |
|---|---|
| 1 | Consumer submits opt-out via link, form, or GPC signal |
| 2 | No identity verification required for opt-out beyond reasonable confirmation the requester is the consumer |
| 3 | Update consent/preference management platform within 15 business days |
| 4 | Propagate opt-out to service providers and contractors engaged in sale/sharing |
| 5 | Do not contact the consumer for 12 months to ask them to reconsider |
SPI categories (applicability trigger for the right to limit):
The right to limit does NOT apply when SPI is used only for these permitted purposes:
| Step | Action |
|---|---|
| 1 | Provide "Limit the Use of My Sensitive Personal Information" link on the homepage (alongside or combined with the "Do Not Sell or Share" link) |
| 2 | Consumer exercises the right — no identity verification required beyond confirming consumer identity |
| 3 | Process within 15 business days |
| 4 | Restrict SPI use to only the permitted purposes listed above |
| 5 | Propagate the limitation instruction to service providers and contractors |
Businesses cannot, because a consumer exercised a CCPA/CPRA right: deny goods or services; charge a different price (except where directly related to the value of the data); provide a different level or quality of goods/services; or suggest that any of the above will occur.
Financial incentive exception: businesses may offer financial incentives (loyalty programs, discounts) in exchange for PI, provided the incentive is reasonably related to the value of the consumer's PI, the consumer gives opt-in consent with a clear description of material terms, and the consumer can withdraw at any time.
Consumers may designate an authorized agent to submit requests on their behalf. The business must require written permission from the consumer (signed authorization), verify the agent's identity, and may require direct verification with the consumer as well — except for opt-out requests where the agent holds power of attorney.
Inform consumers at or before PI collection: categories collected, purposes, whether PI is sold or shared, retention periods (CPRA requirement), and link to privacy policy.
Must include: categories of PI collected in last 12 months, purposes of use, categories of third parties PI disclosed to, consumer rights and how to exercise them, contact info for requests, and "Do Not Sell or Share My Personal Information" link (or opt-out of SPI limitation where applicable). Update the privacy policy annually.
PI collected must be adequate, relevant, and limited to what is necessary for the disclosed purpose. Cannot use PI for undisclosed purposes.
Disclose retention periods or criteria for each category. Cannot retain PI longer than reasonably necessary.
Contracts with service providers and contractors must include: purpose limitations, prohibition on further sale/sharing, obligation to comply with consumer requests, rights to audit, and data deletion obligations. Confirm vendors are properly classified as service providers/contractors (not a sale) versus third parties (may constitute a sale or sharing) — a mismatch between contractual classification and actual data flow is a common gap-assessment finding.
Businesses that process PI that presents significant risk to consumers' security must conduct annual cybersecurity audits. Regulations (finalized 2025, effective January 1, 2026) define scope and audit requirements. Non-compliance is an enforcement risk — the Disney $2.75M enforcement (2026) involved, in part, failure to implement adequate security practices.
Businesses must conduct and document risk assessments before processing PI that presents significant risk to consumers. Assessments must be submitted to the CPPA upon request. Regulations are live (effective January 1, 2026).
CPPA: Independent enforcement agency (created by CPRA). Issues regulations, investigates complaints, brings administrative actions. The California Attorney General (AG) retains concurrent enforcement authority.
Civil penalties (§1798.155):
Cure provisions: a 30-day cure period applies to AG actions (CPPA administrative actions may differ and are not subject to the same formal cure notice process).
Private right of action (§1798.150) — data breach only:
These cases define the current enforcement posture and penalty expectations:
| Company | Fine | Key Violations |
|---|---|---|
| The Walt Disney Company | $2.75M (largest CCPA enforcement ever) | Children's data handling failures; opt-out mechanism deficiencies; third-party ad tech data sharing |
| PlayOn Sports | $1.1M | Unauthorized sharing of consumer PI with third parties; inadequate consumer rights processes |
| Ford Motor Company | $375K | Failure to process consumer data deletion and access requests within required timeframes |
These cases signal that the CPPA is actively pursuing large enterprises for systematic violations, not just technical non-compliance. The Ford case in particular underscores that missing the 45-day response deadline for access/deletion requests is, on its own, an actionable enforcement basis — not merely a procedural lapse.
GDPR is generally the more demanding law. A GDPR-compliant program covers most CCPA/CPRA obligations (privacy notices, rights processes, processor agreements, minimization, retention, security), but these CCPA/CPRA-specific items still need to be added: (1) "Do Not Sell or Share My Personal Information" link and opt-out workflow; (2) honor GPC signals; (3) "Limit the Use of My Sensitive Personal Information" link and 15-business-day workflow; (4) confirm vendor classification maps to service provider/contractor vs. third party, with contracts meeting the §1798.100(d) required terms; (5) a compliant notice at collection (§1798.100(a)-(b)) — a distinct artifact from a GDPR Art. 13 notice, delivered at or before collection, listing PI/SPI categories, purposes, retention periods per category, and sale/sharing status with the opt-out link; (6) minors' opt-in for sale/sharing (under 16; parental consent under 13); (7) financial incentive/loyalty disclosures, if applicable; (8) annual reconfirmation of the three business thresholds; (9) cybersecurity audit and risk assessment obligations (effective January 1, 2026) and ADMT opt-out (deadline January 1, 2027). Name notice-at-collection explicitly in every GDPR-to-CCPA gap answer — it is the most commonly missed delta because GDPR programmes assume their existing privacy notice covers it.
Structural differences to state in every GDPR-comparison answer:
Key enforcement contrast: GDPR penalties run up to €10M/2% or €20M/4% of global annual turnover with no formal cure period in most cases, versus CCPA/CPRA's per-violation civil penalties of $2,500 (unintentional) / $7,500 (intentional) with a 30-day AG cure period.
September 2026 signings (effective January 1, 2027 unless noted):
Enforcement posture (CPPA): data-broker registration blitz — SalesIntel Research fined $36,400 (Sept 1) for failing to register; Enforcement Advisory 2026-01 (Sept 3) targets registration accuracy with $200/day exposure; DROP deletion processing live since August 1, 2026. Earlier 2026: GM $12.75M (connected cars), PlayOn Sports $1.1M, Ford $375K (opt-out friction).
ADMT countdown (include in any automation/profiling answer): compliance for significant decisions begins January 1, 2027 (pre-use notice, opt-out, access); risk assessments for processing ongoing as of Jan 1, 2026 are due December 31, 2027 with first CPPA submissions by April 1, 2028; cybersecurity-audit certifications phase in April 2028/2029/2030 by revenue tier.
references/consumer-rights-workflows.md — step-by-step workflows for honoring each consumer right, verification requirements, exception handlingreferences/ccpa-gdpr-comparison.md — side-by-side comparison of CCPA/CPRA vs. GDPR for global compliance teamsThis skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in plugins/ccpa/skills/ccpa of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Open the folder on GitHubat commit aab13e1
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.
Ccpa next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ccpa this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~7.1k | Automated safety check: Pass | MIT | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Pii Contract Analyzegregmos/PII-Shield | 150 | — | ~8.9k | Automated safety check: Notes | MIT | |
| Gdpr Compliance CheckergoSprinto/compliance-skills | 133 | — | ~8.6k | Automated safety check: Notes | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
goSprinto/compliance-skills
Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…
jamiedavenport/policystack
Audit a policystack.ts config: run policystack validate --json, explain each issue code, propose a minimal config fix, then re-validate until clean.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
Categories
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of…. Ccpa is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment (access, delete, correct, opt-out of sale/sharing, limit SPI, ADMT opt-out), privacy notice drafting, service provider vs.
Ccpa fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a claude-code`. Or copy the skill folder (plugins/ccpa/skills/ccpa in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/ccpa in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a codex`. Or copy the skill folder (plugins/ccpa/skills/ccpa in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/ccpa in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ccpa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ccpa, .gemini/skills/ccpa, .github/skills/ccpa and .opencode/skills/ccpa in your project.
SKILL.md names no scripts, command-line tools or credentials: Ccpa is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ccpa is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 7.1k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Ccpa: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Pii Contract Analyze (gregmos/PII-Shield, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.
Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.