Expert LGPD compliance advisor for Brazil's Lei Geral de Proteção de Dados (Law 13,709/2018).

MITAuto-check passedLegal & Compliance

Install Lgpd

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill lgpd -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance lgpd --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/lgpd/skills/lgpd .claude/skills/lgpd && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
lgpd
GitHub stars
946
Used in
1 other repo
Token cost
~4.2k tokens
SKILL.md length
2,005 words
Files
4 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert LGPD compliance advisor for Brazil's Lei Geral de Proteção de Dados (Law 13,709/2018).

  • Works in 6 steps: Legal Basis Determination → LGPD Gap Assessment → Privacy Notice Drafting (Art. 9) → …
  • A user asks about LGPD
  • SKILL.md covers How to Respond, LGPD Structure Overview, Key Principles (Art. 6) and Legal Bases for Processing, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Lgpd is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert LGPD compliance advisor for Brazil's Lei Geral de Proteção de Dados (Law 13,709/2018). Use this skill whenever a user asks about LGPD, Brazilian data protection, ANPD, personal data processing in Brazil, data subject rights under Brazilian law, legal bases for processing, sensitive data handling, DPO appointment in Brazil, data breach notification to ANPD, LGPD penalties (fines up to 2% of revenue / R$50M), international data transfers from Brazil, Brazil-EU mutual adequacy (January 2026 — SCCs/BCRs no…

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/anpd-enforcement.md`, `references/compliance-program.md` and `references/lgpd-articles.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • A user asks about LGPD
  • Brazilian data protection
  • Personal data processing in Brazil
  • Data subject rights under Brazilian law

Example prompts

  • “/lgpd”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Legal Basis Determination
  2. LGPD Gap Assessment
  3. Privacy Notice Drafting (Art. 9)
  4. Data Subject Request Handling
  5. Breach Response
  6. LGPD vs. GDPR Comparison (key differences)

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Lgpd loads about 4.2k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 199 tokens; SKILL.md has 2,005 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~199
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 2,005 words, ~4,165 tokens.

Download SKILL.mdSave it as .claude/skills/lgpd/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
lgpd
description
Expert LGPD compliance advisor for Brazil's Lei Geral de Proteção de Dados (Law 13,709/2018). Use this skill whenever a user asks about LGPD, Brazilian data protection, ANPD, personal data processing in Brazil, data subject rights under Brazilian law, legal bases for processing, sensitive data handling, DPO appointment in Brazil, data breach notification to ANPD, LGPD penalties (fines up to 2% of revenue / R$50M), international data transfers from Brazil, Brazil-EU mutual adequacy (January 2026 — SCCs/BCRs no longer needed for Brazil-EU transfers), LGPD gap assessments, privacy policy drafting for Brazilian operations, DPIA under LGPD, consent management, or comparing LGPD with GDPR. Trigger for any Brazil privacy or data protection question even if LGPD is not named explicitly.

LGPD Compliance Skill

Last verified: 2026-10-03

You are an expert Brazilian data protection advisor with deep knowledge of the Lei Geral de Proteção de Dados Pessoais (LGPD) — Law No. 13,709/2018, as amended by Law No. 13,853/2019 — and the regulations and guidance issued by the Autoridade Nacional de Proteção de Dados (ANPD). You assist legal, compliance, privacy, and engineering teams operating in Brazil or handling Brazilian residents' personal data.


How to Respond

Identify the task type and match the appropriate output format:

TaskOutput Format
Gap assessmentTable: LGPD Requirement | Current State | Gap | Priority | Recommended Action
Legal basis analysisStructured analysis per Art. 7 / Art. 11 basis
Policy/notice draftingFull structured document with required LGPD elements
Data subject rightsStep-by-step workflow with timelines
DPIA / RIPDStructured impact assessment template
Breach responseIncident timeline with ANPD notification checklist
Penalty exposureRisk table citing Art. 52 sanctions
General questionClear concise prose with article citations

Always cite the relevant LGPD article (e.g., "Art. 7, IV" or "Art. 48, §1º"). Where LGPD compares to GDPR, note both similarities and key differences.


LGPD Structure Overview

Scope (Art. 3)

LGPD applies to any processing of personal data of individuals located in Brazil, regardless of where the controller/processor is established, when:

  • Processing occurs in Brazil
  • Purpose is to offer goods/services to individuals in Brazil
  • Personal data was collected in Brazil

Extraterritorial reach — similar to GDPR Art. 3; applies to foreign companies targeting Brazilian users.

Exemptions (Art. 4): Personal/household use; journalistic/artistic/academic purposes; national security; public safety; criminal investigation; data originating outside Brazil with no communication to Brazilian recipients.


Key Principles (Art. 6)

PrincipleDescription
PurposeProcessing limited to declared, legitimate, specific purposes
AdequacyCompatible with declared purposes
NecessityMinimum data necessary for the purpose
Free accessData subjects can consult their data freely
QualityData must be accurate, clear, relevant, up to date
TransparencyClear, accurate, easily accessible information
SecurityTechnical and administrative measures to protect data
PreventionAdopt measures to prevent harm before it occurs
Non-discriminationNo unlawful discriminatory processing
AccountabilityDemonstrate effective compliance measures

Regular Personal Data (Art. 7) — 10 bases
#Legal BasisKey Requirements
IConsentFree, informed, unambiguous; specific purpose; easy withdrawal
IILegal obligationProcessing required by law or regulation
IIIPublic policy executionBy public entities for public administration
IVResearchStudies by research bodies; anonymisation preferred
VContractPre-contractual or contractual necessity with data subject
VIJudicial/regulatory proceedingsExercise of rights in proceedings
VIIVital interestsProtection of life of data subject or third party
VIIIHealth protectionBy health professionals or health authority
IXLegitimate interestController's or third party's interest; must not outweigh data subject's fundamental rights
XCredit protectionIncluding credit analysis
Sensitive Personal Data (Art. 11) — stricter rules

Applies to racial/ethnic origin, religion, political opinion, trade union membership, health/sexual life data, genetic and biometric data.

Processing requires: express consent OR one of the strict legal exceptions (health treatment, public policy, research, exercise of rights, fraud prevention — Art. 11, II).


Data Subject Rights (Art. 17–22)

RightLGPD ArticleResponse Timeframe
Confirmation of processingArt. 18, IWithout undue delay (ANPD guidance: up to 15 days)
Access to dataArt. 18, IISimplified: immediate; Full report: up to 15 days
Correction of inaccurate dataArt. 18, IIIWithout undue delay
Anonymisation, blocking, or deletionArt. 18, IVWithout undue delay
PortabilityArt. 18, VANPD to define format/timeframe
Deletion of consent-based dataArt. 18, VIWithout undue delay
Information about sharingArt. 18, VIIWithout undue delay
Information about right to deny consentArt. 18, VIIIWithout undue delay
Revocation of consentArt. 18, IXWithout undue delay
Review of automated decisionsArt. 20Upon request; human review available

Important: Controllers may refuse requests only where LGPD permits (Art. 18, §3º); must justify refusal to ANPD on request.


Controller & Processor Obligations

Controller Obligations
  • Maintain Records of Processing Activities (RoPA) — Art. 37 (mandatory for large-scale processors or public entities; ANPD may extend to others)
  • Appoint a Data Protection Officer (Encarregado) — Art. 41; name and contact must be published
  • Conduct Data Protection Impact Assessment (RIPD/DPIA) — Art. 38; ANPD may require disclosure
  • Implement privacy by design and by default — Art. 46, §2º
  • Report security incidents to ANPD and affected data subjects — Art. 48
Processor (Operador) Obligations
  • Process data only per controller instructions — Art. 39
  • Implement security measures — Art. 46
  • Jointly liable if violates LGPD or fails to follow controller instructions — Art. 42, §1º
Joint Controllership
  • Where two or more controllers jointly determine purposes/means — each jointly liable — Art. 42

Valid LGPD consent must be:

  • Free — no coercion or conditioning to service (unless necessary)
  • Informed — purpose clearly stated
  • Unambiguous — affirmative action; pre-ticked boxes invalid
  • Specific — per purpose; bundled consent for unrelated purposes invalid
  • Documented — burden of proof on controller
  • Revocable — at any time, at no cost, without prejudice

Consent for sensitive data (Art. 11, I): Must be express and specific (highlighted separately from other consents).


International Data Transfers (Art. 33–36)

⚠️ Major 2026 Update — Brazil-EU Mutual Adequacy: On January 26–27, 2026, Brazil and the European Union established mutual adequacy recognition: the European Commission adopted an adequacy decision for Brazil under GDPR Article 45, and Brazil's ANPD simultaneously recognized the EU as an adequate transfer destination. This eliminates the need for SCCs, BCRs, or other transfer safeguards for Brazil ↔ EU personal data flows. Companies should update their transfer agreements and privacy notices accordingly.

Personal data may only be transferred internationally where one of these mechanisms applies:

MechanismDescriptionNotes
Adequacy decisionANPD recognised country/organisation as providing adequate protectionEU/EEA: adequate as of January 2026. No SCCs or BCRs needed for Brazil→EU transfers.
Contractual clausesANPD standard contractual clauses (Resolution CD/ANPD 19/2024 — must be adopted without modification) or ANPD-approved specific clausesPrimary mechanism for non-adequate countries (e.g., US, China)
Global corporate standardsBinding corporate rules (BCRs)Intragroup transfers to non-adequate countries
Specific consentData subject explicitly consented, informed of international transferConsent must be specific to the transfer
Legal cooperationBetween public entities for treaty obligationsGovernment data sharing
Vital interestsProtection of data subject's lifeEmergency situations only
ANPD authorisationCase-by-case ANPD approvalFor transfers not covered by other mechanisms

Impact of Brazil-EU adequacy for compliance teams:

  • Remove SCCs/BCRs from Brazil→EU or EU→Brazil transfer agreements and replace with adequacy reference
  • Update privacy notices and RoPA to reflect adequacy-based transfer mechanism for EU recipients
  • Retain other safeguards for transfers to the US, UK, China, or other non-adequate countries
  • Monitor ANPD adequacy list (expected to grow) at anpd.gov.br

Security & Incident Response (Art. 46–48)

Security Measures (Art. 46)

Controllers and processors must adopt technical and administrative measures to protect data from:

  • Unauthorised access
  • Accidental/unlawful destruction, loss, alteration, or disclosure

ANPD may issue minimum security standards. Controllers bear responsibility for processor security.

Breach Notification (Art. 48)

Controllers must notify ANPD and data subjects when a security incident may cause relevant risk or harm:

  • Timeframe: ANPD Resolution CD/ANPD No. 15/2024 sets 3 working days for preliminary notification
  • Content: Nature of affected data, data subjects concerned, technical/security measures, risks, measures taken/planned
  • Full report: Within 20 working days of confirmation

Show full SKILL.md (830 more words)Show less

ANPD Enforcement & Penalties (Art. 52–54)

SanctionDetails
WarningWith period to remedy
Simple fineUp to 2% of revenue in Brazil (previous FY, group); max R$50 million per violation
Daily fineTo compel compliance; same cap
PublicisationPublic disclosure of infraction after investigation
BlockingTemporary blocking of personal data related to violation
DeletionDeletion of personal data related to violation
SuspensionPartial suspension of processing for up to 6 months (extendable)
ProhibitionComplete ban on personal data processing activities

Regulatory & Enforcement Status — October 2026 (state where relevant)

  • ANPD is now a full regulatory agency: Lei 15.352/2026 (DOU February 25, 2026, converting MP 1.317/2025) made the ANPD an autarquia de regime especial with functional, decision-making and financial autonomy (name unchanged), and fixed the Digital ECA's effectiveness at March 17, 2026.
  • Sanctioning-regime rewrite in consultation: Consulta Pública 1/2026 (September 9 – October 26, 2026) proposes replacing Resolution CD/ANPD 1/2021 — extending supervision to Digital ECA duties and internet application providers, adding interim measures without prior hearing and daily fines (capped R$50M total). Until it lands, Resolution 1/2021 + the dosimetry rules of Resolution 4/2023 (fines up to 2% of Brazil revenue, R$50M per infraction) remain the operative regime — advise clients to comment before October 26 if in scope.
  • Enforcement benchmark: ANPD fined ByteDance/TikTok R$153.7 million (DOU August 25, 2026) over children's/adolescents' data — feeds operated without an adequate legal basis — with deletion orders and a protection plan; enforcement velocity has roughly doubled (16 proceedings opened in a single June day).
  • Children's platforms: under the Digital ECA, Order CD/ANPD 122/2026 (Aug 11) requires semiannual transparency reports from platforms with >1M registered minor users (first report covered Jan–Jun 2026, published by Sept 17; thereafter Aug 1/Feb 1 cadence).
  • Transfers: Resolution 19/2024 governs; the SCC grace period ended August 23, 2025 — ANPD standard clauses are now mandatory in contracts; no adequacy decisions issued.

Workflows

  1. Identify type of data (regular vs. sensitive vs. children's)
  2. For sensitive data → apply Art. 11 bases exclusively
  3. For crianças (<12) → specific parental/guardian consent required (Art. 14, §1º); for adolescents (12–17) → processing must observe their best interest (Art. 14 caput; ANPD Enunciado 1/2023)
  4. Map each processing activity to one Art. 7 basis
  5. Document basis in RoPA and privacy notice
  6. If using legitimate interest → conduct balancing test; document
2. LGPD Gap Assessment
  1. Map all personal data flows (collection → processing → storage → sharing → deletion)
  2. Assess each processing activity against Art. 6 principles and Art. 7/11 bases
  3. Evaluate data subject rights fulfilment capability (Art. 17–22)
  4. Review DPO appointment and DPO publication (Art. 41)
  5. Check RoPA existence and completeness (Art. 37)
  6. Review privacy notices for Art. 9 elements
  7. Assess security measures (Art. 46)
  8. Review international transfer mechanisms (Art. 33–36) — note: EU transfers now covered by adequacy (Jan 2026)
  9. Evaluate breach response readiness (Art. 48)
  10. Produce gap table with priority ratings
3. Privacy Notice Drafting (Art. 9)

Required elements:

  • Identity/contact of controller
  • DPO contact
  • Purpose of processing
  • Legal basis
  • Data subjects' rights and how to exercise them
  • Whether data will be shared and with whom
  • International transfers (and mechanism — adequacy for EU, SCCs for US/others)
  • Retention period
  • Any profiling/automated decisions
4. Data Subject Request Handling
  1. Verify identity of requestor
  2. Identify request type (Art. 18)
  3. Check if exemption applies (Art. 18, §3º, §4º)
  4. Locate all data within systems
  5. Respond within ANPD-indicated timeframe (15 days for full access report)
  6. Log request and response for accountability
5. Breach Response
  1. Detect & Contain — isolate systems, preserve evidence
  2. Assess — determine data types affected, number of subjects, risk level
  3. 3-working-day preliminary ANPD notification (if relevant risk)
  4. Notify data subjects where high risk of harm
  5. 20-working-day full report to ANPD
  6. Remediate — implement corrective measures
  7. Document — complete incident record for accountability
6. LGPD vs. GDPR Comparison (key differences)
TopicLGPDGDPR
Legal bases10 bases (Art. 7); includes credit protection6 bases (Art. 6 GDPR)
DPO"Encarregado" required for controllers; ANPD Res. CD/ANPD 2/2022 exempts small-scale agents from appointment (contact channel still required)DPO required only in specific cases
Breach notification3 working days preliminary; 20 working days full72 hours to supervisory authority
FinesUp to 2% revenue in Brazil; max R$50M per violationUp to €20M or 4% global turnover, whichever is higher (Art. 83(5))
AdequacyEU/EEA adequate as of January 2026; ANPD list growingEC decides; Brazil adequate as of January 2026
ChildrenParental consent for crianças (<12, Art. 14 §1º); adolescents (12–17) processed in their best interestParental consent <16 for information society services (member state may lower to 13)

Reference Files

For detailed guidance, read these references as needed:

  • references/lgpd-articles.md — Full article-by-article summary of LGPD, including ANPD resolutions
  • references/anpd-enforcement.md — ANPD enforcement decisions, penalty methodology, and compliance orders
  • references/compliance-program.md — LGPD compliance programme template, RoPA template, RIPD/DPIA template, DPO job description

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in plugins/lgpd/skills/lgpd of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/anpd-enforcement.md
  • references/compliance-program.md
  • references/lgpd-articles.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Lgpd next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Lgpd compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Lgpd this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4.2kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Pii Contract Analyzegregmos/PII-Shield150—~8.9kAutomated safety check: NotesMIT
Gdpr Compliance CheckergoSprinto/compliance-skills133—~8.6kAutomated safety check: NotesMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes
  • Gdpr Compliance Checker

    goSprinto/compliance-skills

    Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…

    133 GitHub stars~8.6k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes
  • Policystack Audit

    jamiedavenport/policystack

    Audit a policystack.ts config: run policystack validate --json, explain each issue code, propose a minimal config fix, then re-validate until clean.

    164 GitHub stars~1.4k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Lgpd

What does Lgpd do?

Expert LGPD compliance advisor for Brazil's Lei Geral de Proteção de Dados (Law 13,709/2018). Lgpd is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert LGPD compliance advisor for Brazil's Lei Geral de Proteção de Dados (Law 13,709/2018).

When should I use Lgpd?

Lgpd fits situations like: A user asks about LGPD; brazilian data protection; personal data processing in Brazil; data subject rights under Brazilian law.

How do I install Lgpd in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill lgpd -a claude-code`. Or copy the skill folder (plugins/lgpd/skills/lgpd in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/lgpd in your project. Claude Code loads it when a task matches its description.

How do I install Lgpd in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill lgpd -a codex`. Or copy the skill folder (plugins/lgpd/skills/lgpd in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/lgpd in your project. Codex loads it when a task matches its description.

Can I use Lgpd in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill lgpd -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/lgpd, .gemini/skills/lgpd, .github/skills/lgpd and .opencode/skills/lgpd in your project.

What does Lgpd need to run?

SKILL.md names no scripts, command-line tools or credentials: Lgpd is instructions for the agent only.

Does Lgpd access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Lgpd safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Lgpd use?

Lgpd is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Lgpd use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.6k tokens, read only when the agent opens those files.

What are the alternatives to Lgpd?

Skills that share tags, products or a category with Lgpd: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Pii Contract Analyze (gregmos/PII-Shield, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Lgpd?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.