
Claude Skills by mukul975
github.com/mukul975Handles GDPR Article 18 right to restriction of processing requests, covering the four grounds for restriction (accuracy contest, unlawful processing, erasure opposition, legitimate interest pending), technical flagging mechanisms, and lifting procedures. Activate for restriction request, Art. 18, processing freeze queries.
Manages retention exception workflows including request-approval processes, duration limits, periodic review cycles, documentation requirements, and audit trail maintenance. Covers legitimate grounds for extending retention beyond scheduled periods and governance controls to prevent indefinite data hoarding. Activate for retention exception, retention extension, data hoarding prevention, retention override queries.
Conducts retention impact assessments for new processing activities to determine appropriate data retention periods. Covers regulatory requirements scanning, proportionality review, purpose-based retention determination, and retention period documentation aligned with GDPR Article 5(1)(e) and Article 25 data protection by design. Activate for retention assessment, new processing retention, retention period determination queries.
Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle. Maps data categories to retention periods with legal basis justification, regulatory minimum holding periods, and automated review triggers for schedule maintenance. Activate for retention policy, storage limitation, data lifecycle, retention period queries.
Implements the GDPR Article 17 right to erasure (right to be forgotten) workflow, covering all six grounds for erasure, five exceptions, technical deletion versus anonymization decisions, and third-party notification under Article 19. Activate for erasure request, deletion request, right to be forgotten, Art. 17 queries.
Handles GDPR Article 21 right to object to processing, including compelling legitimate grounds assessment, ceasing processing obligations, documentation requirements, and the relationship with erasure under Article 17(1)(c). Activate for right to object, Art. 21, objection to processing, legitimate interest queries.
Processes GDPR Article 16 right to rectification requests, covering verification of corrected data accuracy, notification to recipients under Article 19, timeline management, and completion of incomplete data. Activate for rectification, correction request, inaccurate data, Art. 16, data correction queries.
Assesses the GDPR Article 30(5) exemption for organisations under 250 employees. Covers the three exception conditions that negate the exemption: non-occasional processing, risk to data subject rights, and special category data processing. Activate for Art. 30(5), 250 employee exemption, small business RoPA, SME exemption, occasional processing.
Audits Records of Processing Activities against supervisory authority templates from CNIL, ICO, and BfDI. Provides completeness scoring, gap identification, and remediation tracking. Activate for RoPA audit, completeness check, supervisory authority readiness, CNIL template, ICO template, BfDI template, gap analysis.
Links RoPA entries to Data Protection Impact Assessments and lawful basis assessments. Covers cross-reference systems, dependency tracking, and update cascade triggers between RoPA, DPIA register, and lawful basis documentation. Activate for RoPA-DPIA link, cross-reference, dependency tracking, impact assessment linkage, cascade updates.
Creates executive reporting and visualization from RoPA data including processing activity counts, risk heatmaps, compliance scores, trend analysis, and supervisory authority readiness indicators. Activate for RoPA dashboard, executive reporting, risk heatmap, compliance score, trend analysis, board reporting, KPI.
Establishes ongoing RoPA maintenance processes including update triggers, change management integration, version control, stakeholder review cycles, and completeness verification procedures. Activate for RoPA updates, record maintenance, change management, version history, review scheduling.
Integrates Records of Processing Activities with privacy management platforms including OneTrust, TrustArc, Collibra, and DataGrail. Covers API-based synchronization, data mapping import, and automated RoPA population from enterprise tools. Activate for RoPA tool setup, OneTrust integration, TrustArc sync, privacy platform configuration.
SaaS vendor data processing inventory management. Covers shadow IT discovery, API-based data flow detection, processing purpose mapping, contract status tracking, and continuous inventory reconciliation for cloud service providers.
Guides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C). Covers clause-by-clause completion, Annex I-III drafting, and SCC module selection. Keywords: SCCs, standard contractual clauses, module selection, data transfers, Annex completion.
Implements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12). Covers delisting request procedures, criteria assessment balancing privacy against public interest, and geographic scope determination. Activate for right to be forgotten, search delisting, Google Spain, de-indexing queries.
Implements NIST SP 800-88 Rev. 1 media sanitization procedures including Clear, Purge, and Destroy methods for all media types. Covers certificate of destruction generation, verification procedures, vendor management for third-party destruction, and chain of custody documentation. Activate for data destruction, media sanitization, secure erasure, certificate of destruction queries.
Comprehensive PET selection guide covering differential privacy, homomorphic encryption, secure multi-party computation, federated learning, zero-knowledge proofs, and trusted execution environments. Includes use-case matching matrix, performance comparison, and GDPR alignment assessment for each technology.
Guides compliance with Singapore's Personal Data Protection Act 2012 (PDPA). Covers PDPC advisory guidelines, Do Not Call Registry, data intermediary obligations, deemed consent, notification requirements, and the 2020-2021 amendments. Keywords: Singapore PDPA, PDPC, Do Not Call Registry, deemed consent, data intermediary, advisory guidelines.
Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent, collection, use/retention/disposal, access, disclosure, security, and quality. Includes evidence collection, control testing, and report review. Keywords: SOC 2, privacy criteria, TSP, AICPA, Type II, trust services.
Implements compliance with South Africa's Protection of Personal Information Act (POPIA), Act No. 4 of 2013. Covers conditions for lawful processing, data subject rights, cross-border transfer restrictions, Information Regulator enforcement, and responsible party obligations. Keywords: POPIA, South Africa, Information Regulator, responsible party, operator, prior authorisation.
Identifies and classifies GDPR Art. 9 special category data including racial origin, political opinions, religious beliefs, trade union membership, genetic, biometric, health, and sexual orientation data. Covers processing conditions under Art. 9(2)(a)-(j). Keywords: special category, Art 9, sensitive data, biometric, genetic, health data, explicit consent.
US state privacy law applicability assessment tool. Evaluates revenue thresholds, data volume thresholds, business exemptions (GLBA, HIPAA, nonprofits), employee data carve-outs, and SBA small business determinations across all enacted state privacy laws.
Tracks and monitors US state privacy legislation across all 50 states, DC, and territories. Covers enacted comprehensive privacy laws (California CCPA/CPRA, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and subsequent enactments), pending bills, effective dates, and key requirement differences. Keywords: state privacy law, CCPA, CPRA, VCDPA, CPA, CTDPA, UCPA, multi-state.
GDPR Article 28(2) sub-processor approval workflow management. Covers prior specific and general authorization mechanisms, change notification procedures, objection windows, flow-down obligation enforcement, and sub-processor chain risk monitoring.
Guides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020. Covers encryption, pseudonymisation, split processing, audit rights, transparency obligations, and internal policies. Keywords: supplementary measures, encryption, pseudonymisation, EDPB recommendations, transfer safeguards.
Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors, cross-state prescribing rules, and OCR enforcement discretion during public health emergencies. Keywords: telehealth privacy, virtual care, HIPAA, recording consent, platform BAA, cross-state licensing, OCR enforcement.
Texas Data Privacy and Security Act (TDPSA) compliance. No revenue threshold applies to all businesses. Covers data broker registration requirements, biometric identifier provisions under CUBI, consumer rights, AG enforcement, and 30-day cure period. Effective July 1, 2024.
Guides compliance with Thailand's Personal Data Protection Act B.E. 2562 (2019). Covers consent framework, DPO requirements, PDPC enforcement, lawful bases for processing, cross-border transfer mechanisms, and data subject rights under the PDPA. Keywords: Thailand PDPA, PDPC, consent, DPO, cross-border transfers, data subject rights.
Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers destination country surveillance law assessment, European Essential Guarantees evaluation, and supplementary measures determination. Keywords: TIA, transfer impact assessment, Schrems II, EDPB recommendations, supplementary measures.
Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers assessment of third country legal frameworks, supplementary measures evaluation, and TIA scoring. Activate for international data transfers, SCCs, third-country adequacy, or Chapter V compliance. Keywords: TIA, Schrems II, transfer assessment, EDPB, supplementary measures, SCCs, international transfer.
Guides maintenance of cross-border transfer registers, audit trails, and compliance documentation under GDPR Art. 30 and Art. 46, EDPB record-keeping guidance, and supervisory authority expectations. Keywords: transfer register, audit trail, Art. 30, Art. 46, documentation, compliance records.
Implements GDPR Article 12 transparent information and communication requirements, covering concise, intelligible, and plain language obligations, response timelines, fee and refusal provisions, and layered notice design. Activate for transparent communication, Art. 12, privacy notice, plain language, response timeline queries.
Implements compliance with Turkey's Personal Data Protection Law (Kisisel Verilerin Korunmasi Kanunu, KVKK, Law No. 6698). Covers data controller obligations, data subject rights, VERBIS registration, cross-border transfer restrictions, Board decisions, and administrative fines. Keywords: KVKK, Turkey, VERBIS, data controller registry, Board decision, cross-border.
Implements compliance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDP Law) and its Executive Regulations. Covers data controller and processor obligations, data subject rights, cross-border transfer requirements, sensitive data processing, and UAE Data Office enforcement. Keywords: UAE PDP, Federal Decree-Law 45, UAE Data Office, DIFC, ADGM, cross-border transfer.
Implements the UK Age Appropriate Design Code (Children's Code) 15 standards under the Data Protection Act 2018 Section 123. Covers best interests assessment, age-appropriate application, transparency, data minimization, geolocation restrictions, and profiling defaults. Keywords: AADC, Children's Code, ICO, age appropriate design, UK.
Guides implementation of UK international data transfer mechanisms post-Brexit including the International Data Transfer Agreement (IDTA), UK Addendum to EU SCCs, UK adequacy assessments, and ICO transfer risk assessment tool. Keywords: UK IDTA, UK addendum, ICO TRA, post-Brexit transfers, UK GDPR.
Universal opt-out mechanism implementation across US state privacy laws. Covers Global Privacy Control (GPC) signal technical implementation, state-by-state recognition requirements, browser detection methods, authenticated vs unauthenticated handling, and compliance testing.
Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.
Virginia Consumer Data Protection Act (VCDPA) compliance implementation. Covers 5 consumer rights, controller obligations, processor requirements, opt-in for sensitive data, data protection impact assessments, AG enforcement, and cure period provisions. Effective January 1, 2023.
Vendor breach notification cascade management per GDPR Article 33(2). Covers processor-to-controller notification without undue delay, escalation paths, coordinated multi-party breach response, liability allocation, and regulatory notification coordination.
Vendor certification acceptance criteria and equivalence mapping. Covers ISO 27701, SOC 2 Privacy, APEC CBPR, EU Code of Conduct evaluation, certification scope analysis, gap supplementation requirements, and cross-framework equivalence assessment.
Ongoing vendor privacy compliance monitoring program. Covers annual reassessment procedures, continuous monitoring signals, contract renewal privacy triggers, performance metrics, KPIs, and vendor governance reporting dashboards.
On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classification, remediation tracking, and audit report generation for processor compliance verification.
Pre-contract vendor privacy due diligence per GDPR Article 28(1). Covers risk questionnaires, technical controls assessment, certification review, data flow analysis, and documented sufficiency decisions for processor engagement.
Vendor privacy risk tiering methodology for processor management. Covers scoring factors including data volume, sensitivity, transfer locations, certifications, breach history, and control maturity with weighted risk calculation and tier assignment.
Vendor termination data return and deletion procedures per GDPR Article 28(3)(g). Covers data extraction formats, deletion certification requirements, transition planning, residual data handling, and post-termination verification.
Implements data protection compliance for whistleblowing systems under EU Directive 2019/1937 and GDPR. Covers anonymous reporting channels, identity protection for whistleblowers and accused persons, retention limits, access restrictions, and retaliation prevention. Addresses national transpositions and DPA guidance. Keywords: whistleblower, Directive 2019/1937, anonymous reporting, identity protection, retaliation, retention, reporting channel.
Implements email and internet monitoring compliance in the workplace per Barbulescu v Romania (ECHR Grand Chamber), EDPB guidance, and national labour law. Covers acceptable use policies, legitimate expectation of privacy, proportionality testing, and content vs metadata monitoring. Keywords: email monitoring, Barbulescu, workplace privacy, internet monitoring, acceptable use policy, ECHR, proportionality.
Active Directory attack reference — BloodHound Cypher queries, Kerberos attack decision tree, ACE/ACL abuse, ADCS ESC1-8, and AD misconfig checklist