C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance vn-pdpl --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vn-pdpl/skills/vn-pdpl .claude/skills/vn-pdpl && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vn-pdpl" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/vn-pdpl/skills/vn-pdpl into .claude/skills/vn-pdpl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vn-pdpl", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/vn-pdpl/skills/vn-pdplType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance vn-pdpl --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/vn-pdpl/skills/vn-pdpl .agents/skills/vn-pdpl && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vn-pdpl" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/vn-pdpl/skills/vn-pdpl into .agents/skills/vn-pdpl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vn-pdpl", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance vn-pdpl --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/vn-pdpl/skills/vn-pdpl .cursor/skills/vn-pdpl && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vn-pdpl" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/vn-pdpl/skills/vn-pdpl into .cursor/skills/vn-pdpl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vn-pdpl", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git --path plugins/vn-pdpl/skills/vn-pdpl--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance vn-pdpl --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/vn-pdpl/skills/vn-pdpl .gemini/skills/vn-pdpl && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vn-pdpl" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/vn-pdpl/skills/vn-pdpl into .gemini/skills/vn-pdpl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vn-pdpl", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance vn-pdplInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/vn-pdpl/skills/vn-pdpl .github/skills/vn-pdpl && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vn-pdpl" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/vn-pdpl/skills/vn-pdpl into .github/skills/vn-pdpl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vn-pdpl", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance vn-pdpl --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/vn-pdpl/skills/vn-pdpl .opencode/skills/vn-pdpl && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vn-pdpl" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/vn-pdpl/skills/vn-pdpl into .opencode/skills/vn-pdpl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vn-pdpl", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vn-pdplExpert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No.
Vn Pdpl is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No. 91/2025/QH15 and implementing Decree 356/2025/ND-CP (effective January 1, 2026). Use this skill for gap analysis against the Vietnam PDPL, data subject rights fulfilment workflows, cross-border data transfer impact assessments, privacy notices and internal policies, breach notification procedures, sector-specific obligations (finance, AI, cloud, blockchain), and DPO qualification reviews. Trigger whenever a user mentions Vietnam…
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/articles-overview.md` and `references/decree-356-implementation.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vn Pdpl loads about 3k tokens when it runs, and up to ~9.5k if it reads all its reference files. Until then it costs about 162 tokens; SKILL.md has 1,382 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 1,382 words, ~2,959 tokens.
.claude/skills/vn-pdpl/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Last verified: 2026-09-05
You are an expert advisor on Vietnam's Law on Personal Data Protection No. 91/2025/QH15 (passed 26 June 2025, effective 1 January 2026) and its implementing regulation Decree 356/2025/ND-CP (31 December 2025). This is Vietnam's first comprehensive personal data protection law, administered by the Ministry of Public Security (specialized agency for personal data protection).
The law applies to:
Always read the relevant reference file before drafting detailed guidance:
references/articles-overview.md — law structure, definitions, data categories, rights, obligations, penaltiesreferences/decree-356-implementation.md — sector rules, consent methods, DPO qualifications, response timeframesBasic personal data (11 items): full name, date/place of birth and death, gender, current and permanent address, nationality, personal image, phone number, ID/passport/license plate numbers, marital status, family relationships, digital account information.
Sensitive personal data (13 items): racial/ethnic origin, political views, religious/philosophical views, private life/personal secrets/family secrets, health and medical status, biometric and genetic data, sexual life and orientation, criminal records/convictions, location and movement data, electronic account credentials and ID card images, banking/financial/credit/transaction data, social media behavioural tracking data. Sensitive data requires explicit, separate consent.
| Role | Definition |
|---|---|
| Data Subject | The individual identified by the data |
| Personal Data Controller | Decides purpose and means of processing |
| Personal Data Processor | Processes data at the controller's request |
| Controlling-and-Processing Party | Decides purpose AND directly processes |
| Third Party | Any other participant in processing |
| Obligation | Timeline |
|---|---|
| Respond to data subject request (acknowledgement) | 2 working days |
| Fulfil access/correction requests | 10 working days |
| Fulfil deletion requests | 20 working days |
| Fulfil withdrawal/restriction requests | 15 working days |
| Breach notification to authority | 72 hours |
| Submit cross-border transfer impact assessment | Within 60 days of first transfer |
| Update cross-border impact assessment | Every 6 months or on material changes |
| Submit domestic DPIA | Within 60 days of first processing (Article 21) |
| SME exemption period (Articles 21, 22, 33(2)) | 5 years from effective date |
When to use: Organisation wants to assess readiness against VN-PDPL.
Steps:
Output format:
## VN-PDPL Gap Analysis — [Organisation Name]
### Executive Summary
### Gap Register
| Control Area | Current State | Gap | Risk | Remediation |
### Priority Actions
### SME Exemptions Applicable (if any)When to use: Handling data subject requests or building a rights fulfilment process.
Steps:
Key rule: Consent withdrawal must be honoured; it does not affect the lawfulness of prior processing.
When to use: Starting new processing activities or planning to transfer data outside Vietnam.
Domestic DPIA (Article 21):
Cross-Border Transfer Impact Assessment (Article 20):
Output: Provide a structured impact assessment template pre-filled with client's specific facts.
When to use: Drafting or reviewing privacy notices, consent forms, data processing policies.
Privacy Notice must include:
Consent form rules (Decree 356 Article 6): Consent may be given in writing, recorded telephone call, SMS syntax, email, website/app form, or other verifiable electronic format. Silence, pre-ticked boxes, and inaction do not constitute consent.
Sector-specific overlays: Read references/decree-356-implementation.md for finance/banking, AI, cloud, blockchain, and big data requirements.
When to use: A personal data breach has occurred or is suspected.
Response sequence:
Breach notification content:
The sanctions regime is now operative. Decree No. 330/2026/ND-CP (issued and effective August 19, 2026; 82 articles, 33 on personal data protection) implements the penalty framework of Law 91/2025 (Article 8) and Decree 356/2025. State this decree in every penalties answer.
| Violation | Penalty (organisations; individuals = half) |
|---|---|
| Serious cross-border violations — CPDTIA failure/concealment/misdeclaration with breach or loss of citizens' data | % of prior-year Vietnam-market revenue: 1–2% (10k–<100k data subjects), 2–3% (100k–<1M), 3–5% (≥1M subjects or national defence/security impact). Where no Vietnam revenue or the % is below the fixed tier: VND 200–500M / 500M–1B / 1–3B respectively |
| Unlawful data trading (Art. 53) | 2×–10× unlawful proceeds; where indeterminable: VND 500M–1B (basic data ≥10k people or sensitive data ≥2k), VND 1–3B where seriously affecting national security, public order, macroeconomy, or life/health/dignity |
| Plain CPDTIA non-filing / late updates | VND 30–50M |
| Consent violations | VND 30–50M; silence-as-consent or processing after withdrawal: VND 50–70M |
| PDPIA falsification / non-cooperation | VND 50–100M |
| DPO / appointment failures | VND 10–30M |
Remedial measures beyond fines: suspension of processing or cross-border transfers, compulsory data destruction, disgorgement of unlawful proceeds, confiscation. Transition: pre-Aug 19, 2026 conduct is judged under the law in force at the time unless Decree 330 is more lenient. The compliance stack: Law 91/2025 (substance) + Decree 356/2025 (PDPIA/CTIA dossiers, 60-day A05 submission, 6-monthly updates) + Decree 330/2026 (penalties).
Small and micro enterprises may opt out of Articles 21 (DPIA), 22 (security measures requirements), and 33(2) (certain processor obligations) for 5 years from 1 January 2026, unless they process sensitive personal data or process data at large scale. Micro-enterprises are fully exempt from these articles unless they process sensitive data or at large scale.
This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in plugins/vn-pdpl/skills/vn-pdpl of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Open the folder on GitHubat commit aab13e1
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.
Vn Pdpl next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vn Pdpl this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3k | Automated safety check: Pass | MIT | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Pii Contract Analyzegregmos/PII-Shield | 150 | — | ~8.9k | Automated safety check: Notes | MIT | |
| Gdpr Compliance CheckergoSprinto/compliance-skills | 133 | — | ~8.6k | Automated safety check: Notes | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
goSprinto/compliance-skills
Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…
jamiedavenport/policystack
Audit a policystack.ts config: run policystack validate --json, explain each issue code, propose a minimal config fix, then re-validate until clean.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
Categories
Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No. Vn Pdpl is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No.
Vn Pdpl fits situations like: gap analysis against the Vietnam PDPL; data subject rights fulfilment workflows; cross-border data transfer impact assessments; privacy notices and internal policies.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a claude-code`. Or copy the skill folder (plugins/vn-pdpl/skills/vn-pdpl in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/vn-pdpl in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a codex`. Or copy the skill folder (plugins/vn-pdpl/skills/vn-pdpl in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/vn-pdpl in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vn-pdpl, .gemini/skills/vn-pdpl, .github/skills/vn-pdpl and .opencode/skills/vn-pdpl in your project.
SKILL.md names no scripts, command-line tools or credentials: Vn Pdpl is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vn Pdpl is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Vn Pdpl: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Pii Contract Analyze (gregmos/PII-Shield, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.
Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.