Skip to content

/gdpr-expert

GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill gdpr-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/gdpr-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.

SKILL.md

gdpr-expert.SKILL.md
name: gdpr-expert
description: GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.
allowed-tools: Read, Glob, Grep, Write

GDPR Expert

Deep expertise in the General Data Protection Regulation (GDPR) - the European Union's comprehensive data protection law.

Expertise Areas

GDPR Overview

**Regulation (EU) 2016/679**: General Data Protection Regulation **Effective Date**: May 25, 2018 **Scope**: Protection of natural persons with regard to processing of personal data and free movement of such data **Articles**: 99 (11 chapters) **Recitals**: 173 (interpretive guidance)

**Territorial Scope** (Article 3):

  • **Establishment**: Controller/processor established in EU (regardless of where processing occurs)
  • **Targeting**: Offering goods/services to EU data subjects (even if free)
  • **Monitoring**: Monitoring behavior of EU data subjects
  • **Applies**: Even if organization not in EU

**Material Scope**:

  • Automated processing of personal data
  • Non-automated processing in filing systems
  • **Exemptions**: National security, law enforcement (LED applies), purely personal/household

Key Definitions (Article 4)

**Personal Data**:

  • Any information relating to identified/identifiable natural person
  • Direct identifiers: Name, ID number, email
  • Indirect identifiers: Location data, IP address, cookie ID, device ID
  • Combination of factors: Age + ZIP code + occupation

**Special Categories of Personal Data** (Article 9 - "Sensitive Data"):

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data
  • Biometric data (for uniquely identifying a person)
  • Health data
  • Sex life or sexual orientation

**Processing**:

  • Any operation on personal data
  • Collection, recording, storage, retrieval, use, disclosure, erasure, destruction
  • Automated or manual

**Controller**:

  • Determines purposes and means of processing
  • Makes decisions about why and how to process
  • Primary responsibility for compliance

**Processor**:

  • Processes on behalf of controller
  • Acts on controller instructions
  • Limited independent decision-making

**Joint Controllers**:

  • Two or more controllers jointly determine purposes and means
  • Must arrange responsibilities via agreement
  • Each liable for entire processing

**Data Subject**:

  • Identified or identifiable natural person
  • Individual whose data is processed
  • Rights holder under GDPR

**Supervisory Authority**:

  • Independent public authority (Data Protection Authority/DPA)
  • Each EU Member State has one or more
  • Enforces GDPR in jurisdiction

**Lead Supervisory Authority** (Article 56):

  • For cross-border processing
  • Main establishment's DPA
  • One-stop-shop mechanism

7 Principles of Data Processing (Article 5)

1. Lawfulness, Fairness, and Transparency

**Lawfulness**: Must have lawful basis (Article 6) **Fairness**: No deceptive, misleading, or detrimental processing **Transparency**: Clear, plain language communication to data subjects

**Implementation**:

  • Privacy notices at collection
  • Layered notices (short + full)
  • Just-in-time notices
  • Clear language (no legalese)
  • Accessible information

2. Purpose Limitation

**Requirements**:

  • Specified purposes (documented, clear)
  • Explicit purposes (communicated to data subjects)
  • Legitimate purposes (lawful, ethical)
  • No processing for incompatible purposes

**Compatible Processing**:

  • Same or closely related purpose
  • Consider: Link between purposes, context, nature of data, consequences, safeguards

**Exceptions**:

  • Archiving in public interest
  • Scientific/historical research
  • Statistical purposes

3. Data Minimization

**"Adequate, relevant, and limited to what is necessary"**

**Implementation**:

  • Collect only what you need
  • Justify each data element
  • Regular review and purge
  • Limit access (need-to-know)
  • Pseudonymization/anonymization where possible

**Common Violations**:

  • "Nice to have" data collection
  • Speculative future use
  • Excessive profiling data

4. Accuracy

**Requirements**:

  • Personal data must be accurate
  • Kept up to date where necessary
  • Inaccurate data erased or rectified

**Implementation**:

  • Verification at collection
  • Regular reviews and updates
  • Easy rectification process
  • Notify recipients of changes
  • Quality control procedures

5. Storage Limitation

**"Kept no longer than necessary for the purposes"**

**Implementation**:

  • Retention schedules (per purpose)
  • Regular deletion reviews
  • Automated deletion where possible
  • Document retention rationale
  • Legal hold procedures

**Exceptions** (can retain longer):

  • Archiving in public interest
  • Scientific/historical research
  • Statistical purposes
  • With appropriate safeguards

6. Integrity and Confidentiality (Security)

**"Appropriate security... including protection against unauthorized/unlawful processing and accidental loss, destruction or damage"**

**Implementation**: See Article 32 (Security of Processing)

7. Accountability

**"Controller shall be responsible for and able to demonstrate compliance"**

**Demonstration Requirements**:

  • Documentation (policies, procedures, records)
  • Data Protection Impact Assessments (DPIAs)
  • Privacy by Design and Default
  • Data Processing Agreements (DPAs)
  • Records of Processing Activities
  • Training and awareness programs
  • Regular audits and reviews
  • Incident response and breach records

6 Lawful Bases for Processing (Article 6)

**Must identify ONE for each processing purpose**

1. Consent (Article 6(1)(a))

**Requirements**:

  • **Freely given**: No coercion, imbalance of power consideration
  • **Specific**: Separate consent for separate purposes
  • **Informed**: Identity, purposes, data types, rights, withdrawal
  • **Unambiguous*
Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked