
Claude Skills by mukul975
github.com/mukul975Automated enforcement of GDPR Article 5(1)(e) storage limitation principle. Covers TTL-based deletion, retention policy engines, archival workflows, legal hold exemptions, and lifecycle automation. Includes technical implementation patterns for automated data expiry and defensible deletion across distributed systems.
Technical enforcement of GDPR Article 5(1)(b) purpose limitation principle. Covers purpose-tagged data stores, access control per purpose, Article 6(4) compatibility assessment factors, and system design for preventing purpose creep. Includes purpose binding architecture and compatibility test implementation.
Complete guide to LINDDUN privacy threat modeling methodology covering seven threat categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance. Includes DFD-based analysis, threat tree catalogs, mitigation mapping to privacy design patterns, and step-by-step process.
Architecture guide for GDPR-compliant federated learning systems. Covers horizontal and vertical FL, aggregation strategies (FedAvg, FedProx), communication efficiency, secure aggregation, and differential privacy integration. Includes privacy guarantees analysis and deployment patterns for cross-organizational ML without data sharing.
Design privacy-preserving analytics systems using differential privacy, k-anonymity, l-diversity, and t-closeness. Covers privacy budget allocation with epsilon tracking, references Google DP library, OpenDP, and Apple PPML. Includes Python differential privacy implementation for GDPR-compliant statistical analysis.
Architecture patterns for GDPR Article 5(1)(c) data minimization and Article 25(1) data protection by design. Covers field-level encryption, data masking, aggregation, pseudonymization per Article 4(5), and anonymization per Recital 26. Includes ENISA pseudonymization techniques and a data minimization assessment matrix.
Technical implementation of GDPR Article 25(2) data protection by default. Covers strictest privacy settings as default configuration, minimum data collection, limited storage duration, restricted accessibility, and opt-in rather than opt-out patterns. Includes implementation checklist and system design requirements.
Guide to implementing homomorphic encryption for privacy-preserving computation under GDPR. Covers scheme selection (BFV, BGV, CKKS, TFHE), Microsoft SEAL, IBM HELib, and Google FHE transpiler. Includes performance benchmarks, parameter tuning, and basic HE example code for encrypted arithmetic operations.
Implementation guide for secure multi-party computation enabling privacy-preserving analytics across organizations. Covers secret sharing, garbled circuits, reference frameworks MP-SPDZ and CrypTen, practical deployment patterns, and GDPR alignment for joint controller analytics without revealing individual party inputs.
Preparation guide for ISO 31700 privacy by design for consumer goods certification. Covers the 30 requirements across design, production, and disposal phases. Includes gap assessment methodology, remediation planning, and mapping to GDPR Article 25 data protection by design obligations for consumer-facing products and services.
Assessment of pseudonymization techniques and re-identification risk. Covers tokenization, hashing, encryption-based pseudonymization, and hybrid approaches. Includes re-identification risk scoring using the motivated intruder test, quantitative metrics (marketer, journalist, prosecutor models), and linkage attack resilience evaluation. References ENISA 2019 pseudonymization report.
Comprehensive PET selection guide covering differential privacy, homomorphic encryption, secure multi-party computation, federated learning, zero-knowledge proofs, and trusted execution environments. Includes use-case matching matrix, performance comparison, and GDPR alignment assessment for each technology.
Implement the Kantara Initiative consent receipt specification including machine-readable receipt structure, JWT-based verification mechanisms, receipt lifecycle management, and integration patterns for consent management platforms. Supports ISO/IEC 27560 consent record information structure.
Deploy differential privacy in production systems including epsilon selection strategies, noise calibration with Laplace and Gaussian mechanisms, privacy budget tracking, composition theorems, and Python implementation patterns. Covers both central and local differential privacy models.
Conduct LINDDUN privacy threat modeling across all seven categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance. Includes DFD-based analysis, threat trees, privacy-specific mitigation strategies, and integration with STRIDE security threat modeling.
Implement the NIST Privacy Framework COMMUNICATE function covering CM.AW awareness raising and CM.PO communication policies. Provides transparency mechanisms, stakeholder engagement frameworks, privacy notice templates, and communication workflow guidance.
Implement the NIST Privacy Framework CONTROL function covering CT.DM data management, CT.DP data processing policies and procedures, and CT.PO disassociated processing. Provides technical control architectures, data management workflows, and de-identification implementation guidance.
Implement the NIST Privacy Framework GOVERN function covering GV.AT awareness and training, GV.MT monitoring and review, GV.PO policy development, and GV.RR roles and responsibilities. Provides governance structure templates, training programs, and accountability frameworks for privacy governance.
Implement the NIST Privacy Framework IDENTIFY function including ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories. Provides control mapping, gap analysis templates, and implementation workflows for privacy risk identification.
Implement the NIST Privacy Framework PROTECT function covering PR.AC access control, PR.DS data security, and PR.PO protective policies. Provides technical control implementation guidance, encryption standards, access management architectures, and security-privacy integration patterns.
Build automated PII detection and redaction pipelines using spaCy NER, Microsoft Presidio, and AWS Macie integration. Includes confidence scoring, custom entity type definitions, batch processing workflows, and multi-format document scanning for structured and unstructured data sources.
Design privacy API patterns including data subject API for DSAR endpoints, consent API for preference management, deletion API with cascading delete orchestration, and audit API for compliance reporting. Provides OpenAPI specifications, error handling, rate limiting, and authentication patterns.
Build privacy-preserving data sharing platforms using synthetic data generation with the SDV library, data clean rooms, secure enclaves, and utility measurement. Covers end-to-end architecture for sharing analytical datasets while preserving individual privacy guarantees.
Build privacy KPI dashboards tracking DSAR volume and response time, breach count and severity, DPIA completion rate, training coverage, and consent rates. Includes metric definitions, data collection patterns, visualization designs, and executive reporting templates for privacy program measurement.
Implement privacy-preserving record linkage across datasets using Bloom filter encoding, secure hash matching, threshold tuning for precision and recall, and false positive management. Enables entity resolution without exposing raw personally identifiable information between parties.
Design and implement Purpose-Based Access Control (PBAC) architecture including purpose ontology definition, policy engine configuration, audit logging of purpose verification at query time, and integration with existing IAM systems. Enforces GDPR Article 5(1)(b) purpose limitation technically.
Guides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
Guides DPIA for migrating personal data to cloud infrastructure covering controller-processor analysis under Art. 28, international transfer assessment, encryption requirements, and shared responsibility model evaluation. Activate for cloud adoption, SaaS procurement, or data centre migration projects. Keywords: cloud migration, DPIA, Art. 28, processor, encryption, shared responsibility, SaaS, IaaS, PaaS.
Compares PIA/DPIA methodologies: CNIL PIA tool, ICO DPIA template, NIST Privacy Framework, and ISO 29134. Provides methodology selection criteria based on regulatory jurisdiction, organisation maturity, processing complexity, and resource availability. Covers regulatory acceptance, tool features, and cross-methodology mapping. Keywords: PIA methodology, CNIL, ICO, NIST Privacy Framework, ISO 29134, DPIA comparison, assessment.
Guides the end-to-end GDPR Data Protection Impact Assessment process under Article 35, including mandatory trigger identification per Art. 35(3), DPIA content requirements per Art. 35(7), and EDPB WP248rev.01 methodology. Activate for systematic profiling, large-scale special category processing, or large-scale public monitoring. Keywords: DPIA, Article 35, impact assessment, WP248, data protection, risk assessment.
Conducts a Data Protection Impact Assessment for automated decision-making and profiling systems under GDPR Article 35(3)(a), covering algorithmic transparency, meaningful human oversight, contestation mechanisms, and Art. 22 safeguards. Activate for DPIA automated decision, profiling DPIA, algorithmic impact assessment, Art. 35(3)(a), ADM risk assessment queries.
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d). Covers mitigation measure identification, implementation tracking, residual risk acceptance, and Art. 36 prior consultation triggers. Keywords: DPIA mitigation, risk treatment, residual risk, Art. 35(7)(d), safeguards, mitigation tracking, prior consultation.
Provides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134. Covers likelihood and severity assessment, risk matrix construction, inherent vs residual risk calculation, and risk appetite thresholds per EDPB WP248rev.01 guidance. Keywords: risk scoring, DPIA risk matrix, likelihood, severity, ENISA, ISO 29134, residual risk, risk appetite.
Guides data subject and stakeholder consultation requirements during Data Protection Impact Assessments under GDPR Article 35(9). Covers consultation planning, data subject engagement methods, DPO involvement per Art. 35(2), and documentation of views received. Keywords: DPIA consultation, stakeholder engagement, Art. 35(9), data subject views, DPO advice, public consultation, representative groups.
Guides DPIA for workplace monitoring including email surveillance, internet usage monitoring, CCTV, GPS tracking, and keystroke logging. Covers GDPR Art. 88 employment context provisions, WP29 Opinion 2/2017 on data processing at work, and proportionality balancing for employee monitoring. Keywords: employee surveillance, workplace monitoring, DPIA, Art. 88, WP29 Opinion 2/2017, CCTV, email monitoring, GPS tracking.
Guides DPIA for health and medical data processing covering Art. 9(2)(h)-(j) exemptions, HIPAA crosswalk for transatlantic operations, clinical trial data protection under EU CTR 536/2014, and genetic data specifics under Art. 9(1). Activate for healthcare systems, clinical research, health apps, or medical device data. Keywords: health data, DPIA, Art. 9, clinical trial, genetic data, HIPAA, medical records, special category.
Guides DPIA for marketing profiling, behavioural targeting, cross-device tracking, and advertising analytics. Covers ePrivacy Directive Art. 5(3) cookie consent, PECR regulations, legitimate interest balancing for direct marketing, and adtech processing chain assessment. Keywords: marketing analytics, DPIA, profiling, behavioural targeting, cross-device tracking, ePrivacy, PECR, adtech, legitimate interest.
Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins. Covers risk identification methodology, proportionality assessment, and technology-specific privacy challenges. Activate when evaluating new technology adoption, innovation projects, or emerging tech procurement. Keywords: PIA, emerging technology, IoT, blockchain, AR/VR, quantum computing, digital twins, innovation privacy.
Guides implementation of the NIST Privacy Framework IDENTIFY function covering ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories. Maps NIST PF controls to GDPR requirements for dual-framework compliance. Keywords: NIST Privacy Framework, IDENTIFY function, ID.BE, ID.DA, ID.IM, ID.RA, privacy risk assessment, data actions.
Guides the periodic DPIA review lifecycle including trigger identification for regulatory changes, new data categories, technology changes, and breach incidents. Covers version control, stakeholder sign-off procedures, and DPIA register management per Art. 35(11). Keywords: DPIA review, PIA update, review cadence, version control, Art. 35(11), periodic review, trigger events, stakeholder sign-off.
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35. Applies the EDPB WP248rev.01 nine-criteria test, national supervisory authority blacklists, and organisational risk appetite to produce a documented screening decision. Keywords: threshold screening, DPIA trigger, pre-DPIA, WP248, Article 35(1), blacklist, screening decision.
Guides the Art. 36 prior consultation process when a DPIA indicates high residual risk that cannot be mitigated. Covers required documentation per Art. 36(3), the 8-week DPA response timeline, outcome management, and interaction protocols with supervisory authorities. Keywords: prior consultation, Art. 36, supervisory authority, DPA, high residual risk, DPIA escalation, consultation documentation.
Guides the Privacy Threshold Analysis screening process to determine whether a full DPIA is required. Provides a quick-screen questionnaire, threshold criteria based on WP248rev.01, escalation triggers, and documentation requirements. Activate when evaluating new processing activities, system changes, or procurement decisions. Keywords: PTA, privacy threshold analysis, DPIA screening, quick-screen, threshold criteria, WP248, escalation triggers.
Implements 42 CFR Part 2 protections for substance use disorder patient records. Covers written consent requirements stricter than HIPAA, re-disclosure prohibition, court order procedures, qualified service organization agreements, and 2024 amendments aligning Part 2 with HIPAA. Keywords: 42 CFR Part 2, substance use disorder, SUD records, re-disclosure, consent, Part 2 amendments.
Implements age-gating mechanisms for online services to restrict access based on user age. Covers hard gates versus soft gates, neutral age prompts, re-verification triggers, circumvention prevention, and regulatory requirements under GDPR, COPPA, UK Online Safety Act, and DSA. Keywords: age gate, age restriction, neutral prompt, children, online services, access control.
Evaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
Preparing EU AI Act compliance documentation for high-risk AI systems. Covers Annex III classification, technical documentation under Art. 11, conformity assessment, risk management systems, and CE marking requirements. Keywords: EU AI Act, high-risk AI, Annex III, conformity assessment, CE marking.
Implements GDPR Art. 22 automated decision-making and AI Act Art. 14 human oversight requirements for AI systems. Covers identification of solely automated decisions, meaningful human intervention design, logic explanation mechanisms, and contestation procedures. Keywords: Art. 22, automated decision, human oversight, AI Act, profiling, contestation.
Assesses AI bias risks for GDPR Art. 9 special category data and AI Act Art. 10 data governance. Covers fairness metrics, bias detection methods, mitigation strategies, and documentation requirements for protected characteristics. Keywords: AI bias, special category, fairness metrics, discrimination, Art. 9, Art. 10.
Manages AI model retention and machine unlearning requirements. Covers training data deletion verification, model versioning for compliance, machine unlearning techniques (SISA, gradient-based), and retraining triggers. Keywords: AI retention, machine unlearning, model versioning, training data deletion, retraining, storage limitation.