/gdpr-expert
GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill gdpr-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/gdpr-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.
SKILL.md
gdpr-expert.SKILL.mdname: gdpr-expert
description: GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.
allowed-tools: Read, Glob, Grep, Write
GDPR Expert
Deep expertise in the General Data Protection Regulation (GDPR) - the European Union's comprehensive data protection law.
Expertise Areas
GDPR Overview
**Regulation (EU) 2016/679**: General Data Protection Regulation **Effective Date**: May 25, 2018 **Scope**: Protection of natural persons with regard to processing of personal data and free movement of such data **Articles**: 99 (11 chapters) **Recitals**: 173 (interpretive guidance)
**Territorial Scope** (Article 3):
- **Establishment**: Controller/processor established in EU (regardless of where processing occurs)
- **Targeting**: Offering goods/services to EU data subjects (even if free)
- **Monitoring**: Monitoring behavior of EU data subjects
- **Applies**: Even if organization not in EU
**Material Scope**:
- Automated processing of personal data
- Non-automated processing in filing systems
- **Exemptions**: National security, law enforcement (LED applies), purely personal/household
Key Definitions (Article 4)
**Personal Data**:
- Any information relating to identified/identifiable natural person
- Direct identifiers: Name, ID number, email
- Indirect identifiers: Location data, IP address, cookie ID, device ID
- Combination of factors: Age + ZIP code + occupation
**Special Categories of Personal Data** (Article 9 - "Sensitive Data"):
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Biometric data (for uniquely identifying a person)
- Health data
- Sex life or sexual orientation
**Processing**:
- Any operation on personal data
- Collection, recording, storage, retrieval, use, disclosure, erasure, destruction
- Automated or manual
**Controller**:
- Determines purposes and means of processing
- Makes decisions about why and how to process
- Primary responsibility for compliance
**Processor**:
- Processes on behalf of controller
- Acts on controller instructions
- Limited independent decision-making
**Joint Controllers**:
- Two or more controllers jointly determine purposes and means
- Must arrange responsibilities via agreement
- Each liable for entire processing
**Data Subject**:
- Identified or identifiable natural person
- Individual whose data is processed
- Rights holder under GDPR
**Supervisory Authority**:
- Independent public authority (Data Protection Authority/DPA)
- Each EU Member State has one or more
- Enforces GDPR in jurisdiction
**Lead Supervisory Authority** (Article 56):
- For cross-border processing
- Main establishment's DPA
- One-stop-shop mechanism
7 Principles of Data Processing (Article 5)
1. Lawfulness, Fairness, and Transparency
**Lawfulness**: Must have lawful basis (Article 6) **Fairness**: No deceptive, misleading, or detrimental processing **Transparency**: Clear, plain language communication to data subjects
**Implementation**:
- Privacy notices at collection
- Layered notices (short + full)
- Just-in-time notices
- Clear language (no legalese)
- Accessible information
2. Purpose Limitation
**Requirements**:
- Specified purposes (documented, clear)
- Explicit purposes (communicated to data subjects)
- Legitimate purposes (lawful, ethical)
- No processing for incompatible purposes
**Compatible Processing**:
- Same or closely related purpose
- Consider: Link between purposes, context, nature of data, consequences, safeguards
**Exceptions**:
- Archiving in public interest
- Scientific/historical research
- Statistical purposes
3. Data Minimization
**"Adequate, relevant, and limited to what is necessary"**
**Implementation**:
- Collect only what you need
- Justify each data element
- Regular review and purge
- Limit access (need-to-know)
- Pseudonymization/anonymization where possible
**Common Violations**:
- "Nice to have" data collection
- Speculative future use
- Excessive profiling data
4. Accuracy
**Requirements**:
- Personal data must be accurate
- Kept up to date where necessary
- Inaccurate data erased or rectified
**Implementation**:
- Verification at collection
- Regular reviews and updates
- Easy rectification process
- Notify recipients of changes
- Quality control procedures
5. Storage Limitation
**"Kept no longer than necessary for the purposes"**
**Implementation**:
- Retention schedules (per purpose)
- Regular deletion reviews
- Automated deletion where possible
- Document retention rationale
- Legal hold procedures
**Exceptions** (can retain longer):
- Archiving in public interest
- Scientific/historical research
- Statistical purposes
- With appropriate safeguards
6. Integrity and Confidentiality (Security)
**"Appropriate security... including protection against unauthorized/unlawful processing and accidental loss, destruction or damage"**
**Implementation**: See Article 32 (Security of Processing)
7. Accountability
**"Controller shall be responsible for and able to demonstrate compliance"**
**Demonstration Requirements**:
- Documentation (policies, procedures, records)
- Data Protection Impact Assessments (DPIAs)
- Privacy by Design and Default
- Data Processing Agreements (DPAs)
- Records of Processing Activities
- Training and awareness programs
- Regular audits and reviews
- Incident response and breach records
6 Lawful Bases for Processing (Article 6)
**Must identify ONE for each processing purpose**
1. Consent (Article 6(1)(a))
**Requirements**:
- **Freely given**: No coercion, imbalance of power consideration
- **Specific**: Separate consent for separate purposes
- **Informed**: Identity, purposes, data types, rights, withdrawal
- **Unambiguous*
Read more
name: gdpr-expert description: GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement. allowed-tools: Read, Glob, Grep, Write
GDPR Expert
Deep expertise in the General Data Protection Regulation (GDPR) - the European Union's comprehensive data protection law.
Expertise Areas
GDPR Overview
**Regulation (EU) 2016/679**: General Data Protection Regulation **Effective Date**: May 25, 2018 **Scope**: Protection of natural persons with regard to processing of personal data and free movement of such data **Articles**: 99 (11 chapters) **Recitals**: 173 (interpretive guidance)
**Territorial Scope** (Article 3):
- **Establishment**: Controller/processor established in EU (regardless of where processing occurs)
- **Targeting**: Offering goods/services to EU data subjects (even if free)
- **Monitoring**: Monitoring behavior of EU data subjects
- **Applies**: Even if organization not in EU
**Material Scope**:
- Automated processing of personal data
- Non-automated processing in filing systems
- **Exemptions**: National security, law enforcement (LED applies), purely personal/household
Key Definitions (Article 4)
**Personal Data**:
- Any information relating to identified/identifiable natural person
- Direct identifiers: Name, ID number, email
- Indirect identifiers: Location data, IP address, cookie ID, device ID
- Combination of factors: Age + ZIP code + occupation
**Special Categories of Personal Data** (Article 9 - "Sensitive Data"):
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Biometric data (for uniquely identifying a person)
- Health data
- Sex life or sexual orientation
**Processing**:
- Any operation on personal data
- Collection, recording, storage, retrieval, use, disclosure, erasure, destruction
- Automated or manual
**Controller**:
- Determines purposes and means of processing
- Makes decisions about why and how to process
- Primary responsibility for compliance
**Processor**:
- Processes on behalf of controller
- Acts on controller instructions
- Limited independent decision-making
**Joint Controllers**:
- Two or more controllers jointly determine purposes and means
- Must arrange responsibilities via agreement
- Each liable for entire processing
**Data Subject**:
- Identified or identifiable natural person
- Individual whose data is processed
- Rights holder under GDPR
**Supervisory Authority**:
- Independent public authority (Data Protection Authority/DPA)
- Each EU Member State has one or more
- Enforces GDPR in jurisdiction
**Lead Supervisory Authority** (Article 56):
- For cross-border processing
- Main establishment's DPA
- One-stop-shop mechanism
7 Principles of Data Processing (Article 5)
1. Lawfulness, Fairness, and Transparency
**Lawfulness**: Must have lawful basis (Article 6) **Fairness**: No deceptive, misleading, or detrimental processing **Transparency**: Clear, plain language communication to data subjects
**Implementation**:
- Privacy notices at collection
- Layered notices (short + full)
- Just-in-time notices
- Clear language (no legalese)
- Accessible information
2. Purpose Limitation
**Requirements**:
- Specified purposes (documented, clear)
- Explicit purposes (communicated to data subjects)
- Legitimate purposes (lawful, ethical)
- No processing for incompatible purposes
**Compatible Processing**:
- Same or closely related purpose
- Consider: Link between purposes, context, nature of data, consequences, safeguards
**Exceptions**:
- Archiving in public interest
- Scientific/historical research
- Statistical purposes
3. Data Minimization
**"Adequate, relevant, and limited to what is necessary"**
**Implementation**:
- Collect only what you need
- Justify each data element
- Regular review and purge
- Limit access (need-to-know)
- Pseudonymization/anonymization where possible
**Common Violations**:
- "Nice to have" data collection
- Speculative future use
- Excessive profiling data
4. Accuracy
**Requirements**:
- Personal data must be accurate
- Kept up to date where necessary
- Inaccurate data erased or rectified
**Implementation**:
- Verification at collection
- Regular reviews and updates
- Easy rectification process
- Notify recipients of changes
- Quality control procedures
5. Storage Limitation
**"Kept no longer than necessary for the purposes"**
**Implementation**:
- Retention schedules (per purpose)
- Regular deletion reviews
- Automated deletion where possible
- Document retention rationale
- Legal hold procedures
**Exceptions** (can retain longer):
- Archiving in public interest
- Scientific/historical research
- Statistical purposes
- With appropriate safeguards
6. Integrity and Confidentiality (Security)
**"Appropriate security... including protection against unauthorized/unlawful processing and accidental loss, destruction or damage"**
**Implementation**: See Article 32 (Security of Processing)
7. Accountability
**"Controller shall be responsible for and able to demonstrate compliance"**
**Demonstration Requirements**:
- Documentation (policies, procedures, records)
- Data Protection Impact Assessments (DPIAs)
- Privacy by Design and Default
- Data Processing Agreements (DPAs)
- Records of Processing Activities
- Training and awareness programs
- Regular audits and reviews
- Incident response and breach records
6 Lawful Bases for Processing (Article 6)
**Must identify ONE for each processing purpose**
1. Consent (Article 6(1)(a))
**Requirements**:
- **Freely given**: No coercion, imbalance of power consideration
- **Specific**: Separate consent for separate purposes
- **Informed**: Identity, purposes, data types, rights, withdrawal
- **Unambiguous*
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

