
Claude Skills by mukul975
github.com/mukul975Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI. Covers legitimate interest balancing tests, consent challenges for ML training, public dataset assessment, and web scraping lawfulness. Keywords: AI training data, lawful basis, EDPB LLM, legitimate interest, consent, web scraping.
Implements AI transparency requirements under EU AI Act Arts. 13-14 and GDPR Arts. 13-14. Covers user notification of AI interaction, system capability disclosure, limitation documentation, and meaningful information about automated logic. Keywords: AI transparency, EU AI Act, GDPR notification, explainability, automated decision.
Determines controller-processor relationships for AI services and conducts privacy due diligence. Covers SaaS AI (processor), embedded AI (joint controller), API-based AI (assessment framework), and vendor risk assessment. Keywords: AI vendor, controller-processor, due diligence, SaaS AI, joint controller, Art. 28.
Assessing privacy risks in large language model outputs including training data memorisation, PII leakage in generated text, prompt injection leading to data extraction, and hallucinated personal data. Covers output filtering, guardrails, and monitoring. Keywords: LLM privacy, output risk, memorisation, PII leakage, prompt injection, hallucinated PII.
Implements age-gating mechanisms for online services to restrict access based on user age. Covers hard gates versus soft gates, neutral age prompts, re-verification triggers, circumvention prevention, and regulatory requirements under GDPR, COPPA, UK Online Safety Act, and DSA. Keywords: age gate, age restriction, neutral prompt, children, online services, access control.
Evaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
Implements strict data minimization and retention limits for children's personal data under GDPR Art. 5(1)(c), Recital 38, UK AADC Standard 8, and COPPA Section 312.7. Covers strict necessity testing, shorter retention periods, limited profiling, parental dashboard design, and automated deletion. Keywords: data minimization, children, retention, necessity test, parental dashboard.
Manages deletion requests for children's personal data. Covers parental-initiated versus child-initiated requests, age of capacity assessment, identity verification, scope determination, third-party notification obligations, and regulatory timelines under GDPR Art. 17, COPPA Section 312.6, and UK AADC Standard 15. Keywords: deletion, children, right to erasure, parental request, data deletion, COPPA.
Designs and implements privacy notices for children that comply with GDPR Articles 12-14, UK AADC Standard 4, and COPPA Section 312.4. Covers plain language, visual explanations, layered information, age-appropriate vocabulary, and interactive notice elements. Keywords: children privacy notice, transparency, plain language, visual, age-appropriate, layered notice.
Implements profiling restrictions for children under GDPR Recital 71, Article 22, UK AADC Standard 12, and COPPA. Covers prohibition of behavioural advertising to children, recommendation algorithm limitations, nudge technique prohibition, and automated decision-making safeguards. Keywords: profiling, children, behavioural advertising, recommendation algorithm, AADC, automated decision.
Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312. Covers verifiable parental consent methods including signed forms, credit card verification, government ID, knowledge-based authentication, and video call. Includes FTC safe harbor programs and enforcement actions. Keywords: COPPA, FTC, children, parental consent, safe harbor, verifiable consent.
Assesses children's data protection in educational technology. Covers COPPA school exception under Section 312.5(c)(4), FERPA intersection, parental rights, teacher consent authority, data deletion at year-end, and Student Privacy Pledge compliance. Keywords: edtech, COPPA school exception, FERPA, student privacy, teacher consent, educational data.
Implements GDPR Article 8 parental consent verification for information society services offered to children. Covers age thresholds by EU/EEA Member State (13-16 years), EDPB Guidelines 5/2020 on consent, parental verification mechanisms, and consent record-keeping. Keywords: parental consent, Article 8, children, age threshold, EDPB, verification.
Implements the UK Age Appropriate Design Code (Children's Code) 15 standards under the Data Protection Act 2018 Section 123. Covers best interests assessment, age-appropriate application, transparency, data minimization, geolocation restrictions, and profiling defaults. Keywords: AADC, Children's Code, ICO, age appropriate design, UK.
Implementation guide for CNIL cookie guidelines compliance. References the EUR 150M Google fine and EUR 60M Meta fine. Covers equal prominence accept/reject buttons, cookie wall prohibition, 6-month reconsent intervals, essential cookies exemption, and detailed CNIL Deliberation No. 2020-091 requirements.
Guide for obtaining explicit consent for international data transfers under GDPR Article 49(1)(a). Covers informed consent requirements including risks of transfers without adequacy decisions or appropriate safeguards, specific destination country disclosure, and the narrow scope of derogation-based transfers.
Framework for evaluating and selecting Consent Management Platforms (CMPs). Covers TCF v2.2 certification requirements, Global Privacy Control support, multi-regulation compliance (GDPR, CCPA, LGPD), A/B testing capabilities, API integration options, reporting features, and a structured vendor comparison methodology.
Technical architecture guide for building a multi-purpose consent preference center. Covers per-purpose granularity, easy withdrawal under Article 7(3), version history, audit trails, and IAB Transparency and Consent Framework v2.2 integration. Includes database schema, API design, and UI component specifications.
Guide for building a consent record-keeping system to demonstrate valid consent per GDPR Article 7(1). Covers required fields including timestamp, version, purpose, mechanism, and identity. Implements audit-ready consent receipts per the Kantara Initiative Consent Receipt Specification and supervisory authority expectations.
Implementation guide for GDPR Article 7(3) consent withdrawal mechanisms. Covers the equal ease requirement ensuring withdrawal is as easy as giving consent, one-click withdrawal implementation, cascading effects on downstream processing, third-party notification workflows, and technical architecture for real-time consent revocation.
Methodology for auditing A/B testing of consent banners to ensure compliance with equal ease of acceptance and rejection. Covers CNIL enforcement patterns including the EUR 150M Google fine, dark pattern detection methodology, manipulative design identification, and regulatory-compliant experimentation boundaries.
Implementation guide for ePrivacy Directive compliant double opt-in email consent. Covers confirmation email workflow design, token expiration handling, record-keeping requirements, suppression list management, and integration with CAN-SPAM Act and CASL requirements for multi-jurisdiction compliance.
Guide for implementing GDPR-valid consent under Article 7 conditions and Article 4(11) definition. Covers five core requirements: freely given, specific, informed, unambiguous, and clear affirmative action. Includes pre-ticked boxes prohibition per Planet49 CJEU C-673/17, consent form audit checklist, and practical implementation patterns.
Implementation guide for Global Privacy Control (GPC) automated opt-out signal per CPRA Section 1798.135(e). Covers Sec-GPC HTTP header detection, JavaScript navigator.globalPrivacyControl API, and state-specific requirements for CA, CO, CT, MT, TX, and OR. Includes server-side detection code and compliance mapping.
Decision framework for choosing between consent and legitimate interest as the lawful basis for processing. Covers power imbalance indicators, conditionality prohibition under Article 7(4), granularity requirements, the three-part LIA test (purpose, necessity, balancing), and practical decision trees for common scenarios.
Guide for managing consent for children's personal data under GDPR Article 8 and COPPA. Covers parental consent mechanisms, age verification methods, country-specific age thresholds (ranging from 13 to 16), parental authorization workflows, and age-appropriate design per the UK ICO Children's Code.
Guide for managing consent for scientific research under GDPR Article 89 and Recital 33 broad consent provisions. Covers ethical review board coordination, purpose evolution management, appropriate safeguards including pseudonymization, and the interplay between consent and other lawful bases for research processing.
Guide for mobile-specific consent management covering Apple ATT framework for iOS, Android permission model, in-app consent flows, SDK consent propagation to third-party libraries, and IDFA/GAID handling. Addresses platform-specific requirements alongside GDPR and ePrivacy compliance for mobile applications.
Managing consent for analytics cookies and implementing privacy-preserving measurement. Covers GA4 privacy configuration, consent mode fallback behavior, aggregate reporting alternatives, and cookieless measurement approaches.
Designing and implementing CNIL-compliant cookie consent banners for French and EU audiences. References the EUR 100M Google LLC fine and EUR 150M Meta Platforms fine for non-compliant cookie practices. Covers equal prominence, reject-all buttons, cookie walls prohibition, and 6-month reconsent cycles.
Comprehensive methodology for auditing website cookies and tracking technologies. Covers automated scanning, cookie categorization, lifecycle documentation, and compliance gap analysis referencing the Planet49 CJEU ruling (C-673/17).
Automated cookie consent validation using Selenium and Playwright. Covers banner interaction testing, consent state verification, tag firing audit after consent choices, regression testing for cookie compliance, and CI/CD pipeline integration.
Auditing cookie lifetimes against regulatory recommendations and browser policies. Covers CNIL 13-month maximum recommendation, session vs persistent classification, third-party cookie phase-out impact, and Safari ITP duration caps.
Evaluating and implementing cookie-less tracking alternatives for a post-cookie era. Covers the Privacy Sandbox APIs (Topics, Attribution Reporting, Protected Audiences), server-side analytics, and privacy-preserving measurement techniques.
Implementing cookie compliance across multiple jurisdictions including EU ePrivacy Directive, UK PECR, US California CCPA/CPRA opt-out model, and Brazil LGPD. Provides a requirements matrix and geolocation-based implementation approach.
Applying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent. Covers exemption criteria, functionality cookies, load balancing, session state, and non-exempt categories with regulatory guidance from EDPB and national DPAs.
Configuring Google Consent Mode v2 for privacy-compliant measurement and advertising. Covers default and update commands, consent state mapping to GA4 and Google Ads, conversion modeling with cookieless pings, and EEA requirements effective March 2024.
Integrating Global Privacy Control (GPC) signals with cookie consent platforms. Covers GPC signal detection in browsers, automatic opt-out triggering, mapping GPC to US state privacy laws, and CMP integration for CCPA, CPA, and CTDPA compliance.
Guides assessment and application of GDPR Article 49 derogation conditions for international data transfers in the absence of adequacy decisions or appropriate safeguards. Covers explicit consent, contract necessity, public interest, vital interests, public register, and compelling legitimate interests with restrictive interpretation per EDPB Guidelines 2/2018. Keywords: Art. 49, derogations, transfer exceptions, explicit consent, compelling legitimate interests.
Guides systematic mapping of international personal data flows across an organisation. Covers system-by-system inventory methodology, third-party identification, transfer mechanism assignment, gap analysis, and data flow visualisation. Keywords: data flow mapping, international transfers, data inventory, transfer register, cross-border data flows.
Guides compliance with country-specific data localization requirements across key jurisdictions including Russia (242-FZ), China (PIPL Art. 40, CAC measures), India (DPDP Act), Turkey, Vietnam, and Indonesia. Covers localization assessment, architecture design, and exemption procedures. Keywords: data localization, data residency, PIPL, 242-FZ, cross-border restrictions.
Guides assessment and use of the EU-US Data Privacy Framework adequacy decision for transatlantic data transfers. Covers DPF self-certification with the Department of Commerce, DPF principles compliance, Data Protection Review Court, and annual EC review. Keywords: DPF, EU-US, adequacy, Privacy Shield, transatlantic transfers.
Guides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C). Covers clause-by-clause completion, Annex I-III drafting, and SCC module selection. Keywords: SCCs, standard contractual clauses, module selection, data transfers, Annex completion.
Guides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020. Covers encryption, pseudonymisation, split processing, audit rights, transparency obligations, and internal policies. Keywords: supplementary measures, encryption, pseudonymisation, EDPB recommendations, transfer safeguards.
Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers destination country surveillance law assessment, European Essential Guarantees evaluation, and supplementary measures determination. Keywords: TIA, transfer impact assessment, Schrems II, EDPB recommendations, supplementary measures.
Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers assessment of third country legal frameworks, supplementary measures evaluation, and TIA scoring. Activate for international data transfers, SCCs, third-country adequacy, or Chapter V compliance. Keywords: TIA, Schrems II, transfer assessment, EDPB, supplementary measures, SCCs, international transfer.
Guides maintenance of cross-border transfer registers, audit trails, and compliance documentation under GDPR Art. 30 and Art. 46, EDPB record-keeping guidance, and supervisory authority expectations. Keywords: transfer register, audit trail, Art. 30, Art. 46, documentation, compliance records.
Guides implementation of UK international data transfer mechanisms post-Brexit including the International Data Transfer Agreement (IDTA), UK Addendum to EU SCCs, UK adequacy assessments, and ICO transfer risk assessment tool. Keywords: UK IDTA, UK addendum, ICO TRA, post-Brexit transfers, UK GDPR.
Executes breach notification under California Civil Code Section 1798.82 (California data breach notification law). Covers data elements triggering notification, timing requirements (most expedient time possible), AG notification for 500+ California residents, specific content and format requirements, and substitute notice provisions. Keywords: California, breach notification, Cal. Civ. Code 1798.82, attorney general, CCPA, data elements.
Executes breach notification under HIPAA Breach Notification Rule (45 CFR 164.400-414). Covers 60-day individual notification, HHS/OCR reporting for breaches of 500+ individuals (immediate) and under 500 (annual log), state attorney general notification, media notification for 500+ in a single state, and breach risk assessment using the four-factor test. Keywords: HIPAA, breach notification, PHI, HHS, OCR, covered entity, business associate.