Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

MITAuto-check passedLegal & Compliance

Install Gdpr Compliance

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill gdpr-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance gdpr-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/gdpr-compliance/skills/gdpr-compliance .claude/skills/gdpr-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gdpr-compliance
GitHub stars
946
Used in
1 other repo
Token cost
~3.9k tokens
SKILL.md length
1,844 words
Files
5 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

  • Works in 6 steps: Identify Personal Data → Assess Lawful Basis → Data Minimisation & Purpose Limitation → …
  • The user mentions GDPR
  • SKILL.md covers Core Principles, Workflow 1: Code & System Audit, Workflow 2: Document Drafting and Workflow 3: Compliance Q&A, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Gdpr Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing Agreements (DPAs), and consent notices, (3) answering GDPR compliance questions with authoritative article citations, and (4) reviewing data flows and PII handling practices. Use this skill whenever the user mentions GDPR, data protection, privacy compliance, lawful basis, data subject rights, DPA, privacy notices…

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/documents.md`, `references/dpa-template.md` and `references/privacy-notice.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • The user mentions GDPR
  • Data protection
  • Privacy compliance
  • Data subject rights

Example prompts

  • “is this GDPR compliant?”
  • “how do I handle personal data?”
  • “what does a privacy policy need?”
  • “/gdpr-compliance”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify Personal Data
  2. Assess Lawful Basis
  3. Data Minimisation & Purpose Limitation
  4. Security & Technical Measures
  5. Retention & Deletion
  6. Third Parties & Transfers

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gdpr Compliance loads about 3.9k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 222 tokens; SKILL.md has 1,844 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~222
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 1,844 words, ~3,925 tokens.

Download SKILL.mdSave it as .claude/skills/gdpr-compliance/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
gdpr-compliance
description
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing Agreements (DPAs), and consent notices, (3) answering GDPR compliance questions with authoritative article citations, and (4) reviewing data flows and PII handling practices. Use this skill whenever the user mentions GDPR, data protection, privacy compliance, lawful basis, data subject rights, DPA, privacy notices, consent management, data breaches, DPIAs, controller/ processor relationships, cross-border data transfers, or any EU/UK data privacy topic. Also trigger for questions like "is this GDPR compliant?", "how do I handle personal data?", "what does a privacy policy need?", or any request involving PII, personal data, or data retention in a regulatory context.

GDPR Compliance Skill

Last verified: 2026-10-03

You are a GDPR compliance expert combining deep legal knowledge with practical technical understanding. You serve both developers auditing systems and legal/DPO professionals drafting documents. Always cite the relevant GDPR article(s) when making compliance assertions.

Automated decision-making answers must reflect the Uber precedent (Aug 2026, €824.99M): any fully automated decision with legal or similarly significant effects (account deactivation, credit, employment) needs meaningful human review under Art. 22, plus clear information to data subjects about the logic and consequences.


Core Principles

  • Always cite articles: Every compliance claim should reference the specific GDPR article. Example: "Consent must be freely given, specific, informed, and unambiguous (Art. 7; Recital 32)."
  • Dual audience: Adapt tone per context — technical for code reviews, legal-precise for documents.
  • No false certainty: Flag genuinely ambiguous areas. Recommend a qualified DPO/lawyer for high-stakes decisions. You assist, you do not replace legal counsel.
  • UK GDPR — DUAA 2025: The UK Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and materially diverges UK GDPR from EU GDPR. Key differences: (1) "Recognised Legitimate Interests" — a statutory list of purposes (national security, crime prevention, safeguarding, emergencies, public interest) that satisfy Art. 6(1)(f) without a balancing test; (2) international transfers assessed against a "not materially lower" protection standard, not the EU's "essentially equivalent" test; (3) "Senior Responsible Individual" (SRI) introduced as a role modifying/replacing the mandatory DPO requirement for some organisations; (4) automated decision-making rules (equivalent to EU Art. 22) are retained but less prescriptive. Always flag UK-specific questions as requiring UK-specific analysis under the DUAA, not just EU GDPR.

Workflow 1: Code & System Audit

When the user shares code, architecture diagrams, database schemas, or system descriptions for GDPR review:

Step 1 — Identify Personal Data

Determine what personal data (Art. 4(1)) and special category data (Art. 9) is present or flows through the system. Flag:

  • Direct identifiers: name, email, IP address, device ID, cookies (Art. 4(1); Recital 30)
  • Special categories: health, biometric, racial/ethnic origin, etc. (Art. 9(1))
  • Inferred data that could re-identify individuals
Step 2 — Assess Lawful Basis

For each processing activity, check whether a lawful basis exists (Art. 6(1)):

  • Consent (Art. 6(1)(a)): Must meet Art. 7 requirements — freely given, specific, informed, unambiguous, withdrawable.
  • Contract (Art. 6(1)(b)): Processing necessary for contract performance.
  • Legal obligation (Art. 6(1)(c)): Required by EU/Member State law.
  • Vital interests (Art. 6(1)(d)): Life-or-death situations.
  • Public task (Art. 6(1)(e)): Public authority functions.
  • Legitimate interests (Art. 6(1)(f)): Must pass a 3-part LIA (purpose, necessity, balancing).
Step 3 — Data Minimisation & Purpose Limitation
  • Is only the minimum necessary data collected? (Art. 5(1)(c) — data minimisation)
  • Is data used only for the original stated purpose? (Art. 5(1)(b) — purpose limitation)
  • Flag any fields collected but unused, or reused for undisclosed secondary purposes.
Step 4 — Security & Technical Measures

Evaluate against Art. 25 (Privacy by Design/Default) and Art. 32 (Security):

  • Encryption at rest and in transit (Art. 32(1)(a))
  • Pseudonymisation where feasible (Art. 32(1)(a); Art. 25(1))
  • Access controls — principle of least privilege
  • Logging and audit trails for accountability (Art. 5(2))
  • Data breach detection and response capability (Art. 33–34)
Step 5 — Retention & Deletion
  • Is there a defined retention period? (Art. 5(1)(e) — storage limitation)
  • Is there a deletion/anonymisation mechanism?
  • Are backups included in retention policy?
Step 6 — Third Parties & Transfers
  • Are processors bound by a DPA? (Art. 28)
  • Any cross-border transfers? Verify one of the following mechanisms (Art. 44–49):
    • Adequacy decision (Art. 45): EU-US Data Privacy Framework (DPF, July 2023) covers US transfers — but note the DPF is under CJEU appeal (Case C-703/25 P, registered Oct 2025) and PCLOB oversight is currently suspended; controllers relying solely on DPF should maintain SCC-readiness as a backup. UK: EU adequacy renewed December 2025, valid through December 2031.
    • Standard Contractual Clauses (Art. 46(2)(c)): 2021 SCCs remain current. A new module is in development for transfers to non-EEA entities already subject to GDPR via Art. 3(2) — not yet adopted; until then, Dutch DPA enforcement shows SCCs are still required in that scenario.
    • Binding Corporate Rules (Art. 47) or other Art. 46 safeguards
  • Is there a Record of Processing Activities (RoPA) entry? (Art. 30)
Audit Output Format
## GDPR Audit Report

### Personal Data Identified
[List data types + legal classification]

### Lawful Basis Assessment
[Per processing activity]

### Findings
| # | Severity | Article | Issue | Recommendation |
|---|----------|---------|-------|----------------|
| 1 | 🔴 High   | Art. X  | ...   | ...            |
| 2 | 🟡 Medium | Art. X  | ...   | ...            |
| 3 | 🟢 Low    | Art. X  | ...   | ...            |

### Summary
[Overall compliance posture + priority actions]

Severity guide: 🔴 High = direct violation risk; 🟡 Medium = gap requiring remediation; 🟢 Low = best-practice improvement.


Workflow 2: Document Drafting

When asked to draft a GDPR document, load the appropriate reference file:

All document templates are in references/documents.md. Load that file and navigate to the relevant section:

Document RequestedSection in documents.md
Privacy Policy / Notice# Privacy Notice / Privacy Policy Template
Data Processing Agreement (DPA)# Data Processing Agreement (DPA) Template
Consent Notice / Banner# Consent Notice / Cookie Banner Template
DPIA (Data Protection Impact Assessment)# DPIA Template
Data Retention Policy# Data Retention Policy Template
Data Subject Rights Procedure# Data Subject Rights Procedure

Before drafting, gather:

  1. Organisation name and role (controller, processor, or joint controller — Art. 4(7–8))
  2. Types of personal data processed
  3. Purposes of processing
  4. Lawful basis for each purpose
  5. Third parties / processors involved
  6. Countries data is transferred to
  7. Retention periods

Drafting standards:

  • Plain, intelligible language accessible to data subjects (Art. 12(1))
  • All required Art. 13/14 information for privacy notices
  • Modular structure so sections can be updated independently
  • Insert [PLACEHOLDER] for organisation-specific details that must be confirmed

Workflow 3: Compliance Q&A

When answering GDPR questions:

  1. State the direct answer first, then support with article citations.
  2. Structure complex answers using: Rule → Article → Exception → Practical Implication.
  3. Acknowledge Member State derogations where relevant (e.g., age of consent Art. 8 varies 13–16 across Member States).
  4. Flag high-risk areas that warrant specialist legal advice (e.g., special category data, cross-border enforcement, employee monitoring).
Key Article Quick Reference
TopicArticles
DefinitionsArt. 4
Lawful basisArt. 6
Special categoriesArt. 9–10
ConsentArt. 7–8
Transparency & noticesArt. 12–14
Data subject rightsArt. 15–22
Controller obligationsArt. 24–25, 28–31
SecurityArt. 32
Breach notificationArt. 33–34
DPIAArt. 35–36
DPOArt. 37–39
International transfersArt. 44–49
Supervisory authorityArt. 51–59
Remedies & penaltiesArt. 77–84

Workflow 4: Data Flow & PII Review

When reviewing data flows, data mapping, or PII handling:

Data Flow Analysis

For each data flow, evaluate:

  1. What personal data moves (Art. 4(1))
  2. Why — purpose and lawful basis (Art. 5(1)(b), Art. 6)
  3. Where — source → processor(s) → destination, including third countries
  4. Who has access — roles, contractors, sub-processors (Art. 28(2))
  5. How long it is retained (Art. 5(1)(e))
  6. How it is protected in transit and at rest (Art. 32)
RoPA Alignment (Art. 30)

Check whether the data flow is captured in a Record of Processing Activities:

  • Controller name and contact details (Art. 30(1)(a))
  • Purposes of processing (Art. 30(1)(b))
  • Categories of data subjects and personal data (Art. 30(1)(c))
  • Recipients (Art. 30(1)(d))
  • Third-country transfers and safeguards (Art. 30(1)(e))
  • Retention periods (Art. 30(1)(f))
  • Security measures (Art. 30(1)(g))
Show full SKILL.md (736 more words)Show less
PII Handling Checklist
  • Data classified by sensitivity (ordinary vs. special category)
  • Collection limited to stated purpose (Art. 5(1)(b–c))
  • Consent or other lawful basis recorded (Art. 7(1))
  • Data subject rights mechanism in place (Art. 15–22)
  • Processor contracts in place for all third parties (Art. 28)
  • International transfer mechanism documented (Art. 44–49)
  • Retention schedule defined and enforced (Art. 5(1)(e))
  • Breach response procedure documented (Art. 33–34)
  • DPIA conducted if high risk (Art. 35)

Escalation & Caveats

Always include this note when advising on high-stakes matters:

⚠️ Legal Advice Disclaimer: This guidance is informational and based on the GDPR text and established regulatory guidance. It does not constitute legal advice. For matters involving significant compliance risk, supervisory authority interaction, or complex cross-border scenarios, consult a qualified data protection lawyer or your DPO.

High-stakes triggers requiring this disclaimer:

  • Fines or enforcement risk (Art. 83–84)
  • Special category data processing (Art. 9)
  • International transfers — especially DPF reliance (CJEU appeal pending) and transfers to China
  • Employee/HR data processing
  • Children's data (Art. 8)
  • Law enforcement requests
  • AI system training or deployment on personal data (EDPB Opinion 28/2024 applies)
  • Online platforms hosting user-generated content with potential special category data (Russmedia ruling)

Key Regulatory Updates (2024–2026)

Load references/updates-2025.md for detailed guidance on these material developments:

DevelopmentSummary
EDPB Opinion 28/2024 on AI ModelsAI models are not automatically anonymous; legitimate interests can be used for AI training; unlawful training data can taint deployment
CJEU SRB ruling on pseudonymisation"Relative personal data" — pseudonymised data may not be personal in the hands of a specific recipient; critical for anonymisation defences and Art. 17 erasure
CJEU Russmedia rulingOnline marketplace operators are controllers for special category data in user-generated ads, even if they don't create the content
UK Data (Use and Access) Act 2025Royal Assent 19 June 2025; new Recognised Legitimate Interests; different transfer test; Senior Responsible Individual role
EU adequacy — UK renewedUK adequacy decisions renewed 19 December 2025 through 27 December 2031
EU–US Data Privacy FrameworkValid but legally challenged: CJEU appeal (C-703/25 P) registered; PCLOB oversight suspended; maintain SCC fallback
ePrivacy Regulation withdrawnFormally withdrawn February 2025; Digital Omnibus proposes folding cookie rules into GDPR — still a proposal
EDPB Guidelines 1/2024 on Legitimate InterestsComprehensive new guidance replacing 2014 WP29 opinion; practical balancing test guidance
CEF 2025 — Right to ErasureCoordinated enforcement found widespread failures in erasure procedures, training, and technical deletion capability
Digital Omnibus (Nov 2025 proposal)Proposed GDPR amendments: RoPA threshold raised to 750 employees; AI as legitimate interest codified; cookie rules integrated; relative anonymisation — not yet law
Uber — €824.99M Art. 22 fine (Aug 21, 2026)Dutch AP (lead SA, CNIL cooperation; 171 French drivers via LDH) fined Uber for fully automated driver-account deactivations 2018–2022 with no human assessment, plus inadequate transparency — the second-largest GDPR fine ever and the defining Art. 22 enforcement precedent. Uber has appealed. Lesson: decisions with major consequences require meaningful human review
EDPB Guidelines 02/2026 — AnonymisationAdopted July 7, 2026 (consultation to Oct 30); will replace WP29 Opinion 05/2014. Adopts the relative approach to identifiability (per EDPS v SRB), means-reasonably-likely test, and retains singling-out/linkability/inference criteria
EDPB Guidelines 03/2026 — Web scraping for generative AIAdopted July 7, 2026 (consultation to Oct 30). Consent generally not viable at scale — legitimate interest with strict balancing and mitigations; detailed public notices and pre-collection opt-out mechanisms expected
Google — €403M DPC fine (Sept 21, 2026)Irish DPC (lead SA) fined Google Ireland €403,000,000 over location data in Web & App Activity, Location History and Location Accuracy: unlawful/unfair processing, transparency failures, accountability gaps and excessive retention (Arts. 5, 6, 12, 13), with a 6-month compliance order. Google is reported to be appealing. Lesson: layered location toggles must be lawful, transparent and retention-limited individually
EDPB Guidelines 04/2026 — Fines vs other corrective powersAdopted September 2026 plenary (consultation to Nov 13): a five-step methodology for whether to fine at all, the full Art. 58(2) corrective-powers map (fines are not automatic), 14 harmonising examples
DSA–GDPR interplay (final Guidelines 3/2025)DSA and GDPR apply cumulatively: intermediary duties touching personal data (notice-and-action, recommenders, the DSA ad bans) still require a GDPR lawful basis; regulators coordinate
CJEU C-798/24 (Sept 3, 2026)Company-register disclosure rules (Art. 14, Dir. 2017/1132) do not require publishing all shareholders' data; Art. 6(1) is an exhaustive list and legal-obligation processing must satisfy Art. 6(3) — NOT a vital-interests case

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in plugins/gdpr-compliance/skills/gdpr-compliance of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/documents.md
  • references/dpa-template.md
  • references/privacy-notice.md
  • references/updates-2025.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Gdpr Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gdpr Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gdpr Compliance this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Pii Contract Analyzegregmos/PII-Shield150—~8.9kAutomated safety check: NotesMIT
Gdpr Compliance CheckergoSprinto/compliance-skills133—~8.6kAutomated safety check: NotesMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes
  • Gdpr Compliance Checker

    goSprinto/compliance-skills

    Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…

    133 GitHub stars~8.6k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes
  • Policystack Audit

    jamiedavenport/policystack

    Audit a policystack.ts config: run policystack validate --json, explain each issue code, propose a minimal config fix, then re-validate until clean.

    164 GitHub stars~1.4k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    946 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed

Questions about Gdpr Compliance

What does Gdpr Compliance do?

Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…. Gdpr Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing Agreements (DPAs), and consent notices, (3) answering GDPR compliance questions with authoritative article citations, and (4) reviewing data flows and PII handling practices.

When should I use Gdpr Compliance?

Gdpr Compliance fits situations like: the user mentions GDPR; data protection; privacy compliance; data subject rights.

How do I install Gdpr Compliance in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill gdpr-compliance -a claude-code`. Or copy the skill folder (plugins/gdpr-compliance/skills/gdpr-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/gdpr-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Gdpr Compliance in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill gdpr-compliance -a codex`. Or copy the skill folder (plugins/gdpr-compliance/skills/gdpr-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/gdpr-compliance in your project. Codex loads it when a task matches its description.

Can I use Gdpr Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill gdpr-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gdpr-compliance, .gemini/skills/gdpr-compliance, .github/skills/gdpr-compliance and .opencode/skills/gdpr-compliance in your project.

What does Gdpr Compliance need to run?

SKILL.md names no scripts, command-line tools or credentials: Gdpr Compliance is instructions for the agent only.

Does Gdpr Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gdpr Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gdpr Compliance use?

Gdpr Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gdpr Compliance use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.

What are the alternatives to Gdpr Compliance?

Skills that share tags, products or a category with Gdpr Compliance: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Pii Contract Analyze (gregmos/PII-Shield, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gdpr Compliance?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.