academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill gdpr-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/gdpr-expertContext preview
The summary Claude sees to decide when to auto-load this skill.
GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.
name: gdpr-expert description: GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement. allowed-tools: Read, Glob, Grep, Write
Deep expertise in the General Data Protection Regulation (GDPR) - the European Union's comprehensive data protection law.
**Regulation (EU) 2016/679**: General Data Protection Regulation **Effective Date**: May 25, 2018 **Scope**: Protection of natural persons with regard to processing of personal data and free movement of such data **Articles**: 99 (11 chapters) **Recitals**: 173 (interpretive guidance)
**Territorial Scope** (Article 3):
**Material Scope**:
**Personal Data**:
**Special Categories of Personal Data** (Article 9 - "Sensitive Data"):
**Processing**:
**Controller**:
**Processor**:
**Joint Controllers**:
**Data Subject**:
**Supervisory Authority**:
**Lead Supervisory Authority** (Article 56):
**Lawfulness**: Must have lawful basis (Article 6) **Fairness**: No deceptive, misleading, or detrimental processing **Transparency**: Clear, plain language communication to data subjects
**Implementation**:
**Requirements**:
**Compatible Processing**:
**Exceptions**:
**"Adequate, relevant, and limited to what is necessary"**
**Implementation**:
**Common Violations**:
**Requirements**:
**Implementation**:
**"Kept no longer than necessary for the purposes"**
**Implementation**:
**Exceptions** (can retain longer):
**"Appropriate security... including protection against unauthorized/unlawful processing and accidental loss, destruction or damage"**
**Implementation**: See Article 32 (Security of Processing)
**"Controller shall be responsible for and able to demonstrate compliance"**
**Demonstration Requirements**:
**Must identify ONE for each processing purpose**
**Requirements**:
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.