All authors

Claude Skills by ThomasMoreAI
github.com/ThomasMoreAI3,571 skills4 installs3,388 views
- Criminal Data HandlingHandles GDPR Art. 10 criminal conviction and offence data classification including official authority requirements, national law derogations, and comprehensive register restrictions. Covers controller obligations for criminal background checks and offence records. Keywords: criminal data, Art 10, conviction data, offence records, criminal background, DBS check.Votes: 0GitHub stars: 16
- Customize 11Guided customization of your privacy practice profile — change one thing without re-running the whole cold-start interview. Adjust risk posture, escalation contacts, DPA playbook, privacy policy commitments, PIA house style, DSAR process, or matter workspace paths. Use when the user says "change my [thing]", "update my profile", "edit my playbook", or "customize".Votes: 0GitHub stars: 16
- Cybersecurity Breach SummaryProduces structured cybersecurity breach summary documents for regulatory and compliance use. Use when drafting breach summaries, incident response reports, forensic report syntheses, board updates, or regulatory notification prep. Triggers: data breach, cybersecurity incident, breach summary, incident report, forensic analysis, notification timeline, GDPR, CCPA/CPRA, HIPAA, state breach law.Votes: 0GitHub stars: 16
- Data Inventory MappingBuilds comprehensive data inventory per GDPR Art. 30 Records of Processing Activities. Covers system-by-system discovery, data flow diagramming, third-party identification, and legal basis per category. Keywords: data inventory, data mapping, Art 30, RoPA, data flow, processing activities.Votes: 0GitHub stars: 16
- Data PortabilityExecutes GDPR Article 20 data portability requests, covering machine-readable format requirements (JSON, CSV, XML), direct controller-to-controller transfer mechanisms, and scope limitations to data provided by the subject on consent or contract basis. Activate for portability, data export, Art. 20, data transfer queries.Votes: 0GitHub stars: 16
- Data PrivacyEnsure data privacy compliance covering GDPR obligations, user consent management, data retention policies, PII detection, and data anonymisation with realistic synthetic dataVotes: 0GitHub stars: 16
- Data Processing AddendumDrafts a GDPR Article 28-compliant Data Processing Addendum (DPA) between data controllers and processors. Extracts party details, processing scope, and service terms from uploaded documents. Produces an execution-ready DPA with all mandatory Art. 28(3) elements and four schedules. Use when supplementing a service agreement with data protection terms, negotiating processor contracts, or establishing GDPR-compliant EU data processing relationships.Votes: 0GitHub stars: 16
- Data ProtectionGDPR compliance analysis covering lawful basis assessment, privacy notices, processor agreements, and breach response.Votes: 0GitHub stars: 16
- Direct Collection NoticeProvides GDPR Article 13 information at the point of direct data collection, covering all required elements under Art. 13(1)(a)-(f) and Art. 13(2)(a)-(g), layered notice design, and timing requirements. Activate for Art. 13, direct collection notice, privacy notice at collection, data collection information queries.Votes: 0GitHub stars: 16
- Dpa Inspection PrepGuides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for key personnel, technical demonstration procedures, on-site logistics, response protocols, and post-inspection follow-up. Covers unannounced inspections, formal audits, and complaint-triggered investigations. Keywords: DPA inspection, supervisory authority, investigation, readiness, interview preparation, response protocol.Votes: 0GitHub stars: 16
- Dpa Review AnthropicsReview a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook. Use when the user says "review this DPA", "check this data processing addendum", "customer sent their DPA", "is this DPA okay", or attaches a DPA.Votes: 0GitHub stars: 16
- Dpa Review StubbiReview a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook.Votes: 0GitHub stars: 16
- Dpa Review Zhou210712依据你的数据处理协议(DPA)操作手册审查一份DPA——自动检测你是受托处理者 还是处理者,并应用操作手册正确的半部分。当用户说"审查这份DPA""检查这份 数据处理附录""客户发来了他们的DPA""这份DPA可以吗",或附上一份DPA时使用。Votes: 0GitHub stars: 16
- Dpa ReviewReview a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook. Use when the user says "review this DPA", "check this data processing addendum", "customer sent their DPA", "is this DPA okay", or attaches a DPA.Votes: 0GitHub stars: 16
- Dpia Risk ScoringProvides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134. Covers likelihood and severity assessment, risk matrix construction, inherent vs residual risk calculation, and risk appetite thresholds per EDPB WP248rev.01 guidance. Keywords: risk scoring, DPIA risk matrix, likelihood, severity, ENISA, ISO 29134, residual risk, risk appetite.Votes: 0GitHub stars: 16
- Draft Cybersecurity Website Terms And Cookie PoliciesGenerates Terms of Use and Cookie Policy documents for a cybersecurity company website, strictly limiting data usage to newsletters and event updates, prohibiting data sales, and emphasizing security protections.Votes: 0GitHub stars: 16
- Dsar ProcessingGuides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day deadline calculation with extensions, response formatting, exemptions, and fee provisions. Activate when handling DSAR, access request, subject access, Art. 15, or SAR queries.Votes: 0GitHub stars: 16
- Dsar Response AnthropicsWalk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data system-by-system, assess exemptions, draft the acknowledgment and substantive response letters. Use when a DSAR comes in, the user pastes an access/deletion/portability/correction request, or says "DSAR came in", "access request", "right to be forgotten", or "someone wants their data".Votes: 0GitHub stars: 16
- Dsar Response StubbiWalk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data system-by-system, assess exemptions, draft the acknowledgment and substantive response letters.Votes: 0GitHub stars: 16
- Dsar ResponseWalk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data system-by-system, assess exemptions, draft the acknowledgment and substantive response letters. Use when a DSAR comes in, the user pastes an access/deletion/portability/correction request, or says "DSAR came in", "access request", "right to be forgotten", or "someone wants their data".Votes: 0GitHub stars: 16
- Employee Dsar ResponseManages Data Subject Access Request procedures for employee requests under Art. 15 GDPR. Covers scope of disclosable HR records, emails, CCTV footage, performance reviews, monitoring data, and training records. Implements third-party data redaction, legal professional privilege, exemptions for ongoing proceedings, and the one-month response timeline. Keywords: DSAR, subject access request, Art. 15, employee records, redaction, privilege, HR data, SAR.Votes: 0GitHub stars: 16
- Employee Monitoring DpiaConducts Data Protection Impact Assessments for employee monitoring systems per EDPB Guidelines 3/2019 on workplace data processing. Covers video surveillance, email monitoring, GPS tracking, keystroke logging, and productivity tools. Applies proportionality testing under Art. 35 GDPR. Keywords: DPIA, employee monitoring, surveillance, proportionality, EDPB, workplace privacy, keystroke logging, GPS tracking.Votes: 0GitHub stars: 16
- Employment Consent LimitsAnalyses the limitations on consent as a lawful basis for processing employee data under Art. 88 GDPR and WP29 Opinion 2/2017. Addresses power imbalance in employment relationships, identifies alternative lawful bases, and maps national derogations. Keywords: consent, employment, power imbalance, Art. 88, WP29, lawful basis, employee data, labour law.Votes: 0GitHub stars: 16
- EncargoRevisor de encargos de tratamiento — revisa un contrato de encargado del tratamiento contra el playbook configurado (como responsable o como encargado). Comprueba las cláusulas obligatorias del art. 28 RGPD, identifica gaps y genera tabla de cláusulas con posición, contrato y recomendación. Usar cuando el usuario diga "revisa este encargo", "DPA del proveedor", "contrato de encargado" o adjunte un DPA.Votes: 0GitHub stars: 16
- Eprivacy Essential CookiesApplying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent. Covers exemption criteria, functionality cookies, load balancing, session state, and non-exempt categories with regulatory guidance from EDPB and national DPAs.Votes: 0GitHub stars: 16
- Gdpr Audit Prep/cs:gdpr-audit-prep <scope> — GDPR audit 6-question Article-cited forcing interrogation. Use before annual internal GDPR review, post-breach internal audit, DPA investigation readiness, or acquisition due diligence.Votes: 0GitHub stars: 16
- Gdpr CertificationGuides implementation of GDPR Article 42-43 data protection certification mechanisms including accredited certification bodies, criteria development, and periodic review. Activate when pursuing privacy certifications, evaluating certification bodies, or developing certification criteria. Keywords: certification, Article 42, Article 43, accreditation, seal, privacy mark.Votes: 0GitHub stars: 16
- Gdpr Codes Of ConductGuides development of GDPR Article 40-41 codes of conduct for industry sectors including drafting, submission, and monitoring body requirements. Activate when creating industry codes or establishing monitoring bodies. Keywords: codes of conduct, Article 40, Article 41, monitoring body, industry code.Votes: 0GitHub stars: 16
- Gdpr Compliance AuditGuides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37. Includes 50+ control points covering principles, accountability, security, and governance. Activate when performing compliance audits, preparing for supervisory authority inspections, or assessing organisational GDPR maturity. Keywords: data protection audit, compliance audit, GDPR audit, control points, accountability.Votes: 0GitHub stars: 16
- Gdpr Compliance Guia MatthieuEnsure GDPR compliance for marketing activities including consent management, data processing, privacy notices, and data subject rightsVotes: 0GitHub stars: 16
- Gdpr Compliance VibeevalGDPR compliance - data subject rights, lawful basis, DPIA, privacy by design, breach notification, consent management, cross-border transfers, PII maskingVotes: 0GitHub stars: 16
- Gdpr Data Processing AddendumDrafts an Article 28-aligned GDPR Data Processing Addendum (DPA) as an attachable annex for SaaS, cloud, or outsourcing agreements. Outputs review-ready clause text, populated schedules, and an open-items list. Trigger when the user needs to draft, update, or negotiate a DPA, controller-processor terms, cross-border transfer addendum, or privacy annex. Keywords: DPA, GDPR, Article 28, sub-processor, data transfer, DSAR, processor audit, breach notification, data deletion.Votes: 0GitHub stars: 16
- Gdpr DpaDrafts GDPR Article 28-compliant Data Processing Addenda with schedules ready for execution. Use when drafting or updating a DPA, vendor GDPR addendum, controller-processor agreement, or data protection addendum involving sub-processors, breach notification, audits, international transfers, or SCCs.Votes: 0GitHub stars: 16
- Gdpr Eu RepresentativeGuides appointment of GDPR Article 27 EU representative for non-EU controllers or processors. Covers criteria, responsibilities, and documentation. Activate when a non-EU entity processes EU data. Keywords: EU representative, Article 27, non-EU controller, territorial scope.Votes: 0GitHub stars: 16
- Gdpr Parental ConsentImplements GDPR Article 8 parental consent verification for information society services offered to children. Covers age thresholds by EU/EEA Member State (13-16 years), EDPB Guidelines 5/2020 on consent, parental verification mechanisms, and consent record-keeping. Keywords: parental consent, Article 8, children, age threshold, EDPB, verification.Votes: 0GitHub stars: 16
- Gdpr Prior ConsultationGuides the GDPR Article 36 prior consultation process with supervisory authorities when a DPIA indicates high residual risk. Covers timeline requirements, documentation, and outcome handling. Activate when DPIA residual risk remains high or when preparing regulatory submissions. Keywords: prior consultation, Article 36, DPIA, high risk, supervisory authority.Votes: 0GitHub stars: 16
- Gdpr Remediation RoadmapGuides conversion of gap analysis findings into phased implementation plans with milestones and risk-based prioritisation. Activate when building compliance programmes or allocating privacy budgets. Keywords: remediation roadmap, implementation plan, phased approach, prioritisation.Votes: 0GitHub stars: 16
- Gdpr Self AssessmentGuides comprehensive controller self-assessment covering GDPR Articles 5-49 with scoring methodology and reporting format. Activate when conducting internal reviews or benchmarking maturity. Keywords: self-assessment, controller assessment, compliance questionnaire, scoring.Votes: 0GitHub stars: 16
- Generate Compliance Audit DocumentGenerate a formatted PDF compliance audit document with findings, risk ratings, remediation recommendations, and sign-off sections.Votes: 0GitHub stars: 16
- Generating Compliance ReportsGenerate comprehensive compliance reports for security standards. Use when creating compliance documentation. Trigger with 'generate compliance report', 'compliance status', or 'audit compliance'.Votes: 0GitHub stars: 16
- Google Consent Mode V2Configuring Google Consent Mode v2 for privacy-compliant measurement and advertising. Covers default and update commands, consent state mapping to GA4 and Google Ads, conversion modeling with cookieless pings, and EEA requirements effective March 2024.Votes: 0GitHub stars: 16
- Indirect Collection NoticeProvides GDPR Article 14 information for personal data obtained from sources other than the data subject, covering timing requirements (within reasonable period, max one month), source disclosure, all required elements, and exemptions under Art. 14(5). Activate for Art. 14, indirect collection, third-party data source, indirect data notice queries.Votes: 0GitHub stars: 16
- Information Security PolicyDrafts a board-approvable Information Security Policy covering data classification, access controls, encryption, incident response, breach notification, and enforcement. Tailored by industry and regulatory environment (HIPAA, GDPR, CCPA, GLBA, FERPA, PCI DSS). Use when drafting or overhauling an organization's foundational information security governance framework or cybersecurity policy.Votes: 0GitHub stars: 16
- Ir Tabletop ExerciseDrafts a tabletop exercise script to stress-test an organization's Incident Response Plan against cybersecurity threats and breach notification obligations (GDPR, CCPA, HIPAA, GLBA, PCI DSS, NERC CIP, DFARS, SEC). Produces scenario injects, participant role assignments, facilitation guides, and after-action report frameworks. Use when creating IR tabletop exercises, cybersecurity drills, breach response simulations, or incident preparedness assessments.Votes: 0GitHub stars: 16
- Iso27701Expert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 27701:2025, ISO/IEC 27701:2019, privacy information management, PIMS certification, PII controller or processor obligations, privacy risk assessment, Statement of Applicability for privacy, privacy by design, data subject rights, DPIA, records of processing activities, transitioning from ISO 27701:2019, GDPR alignment with ISO 27701, or any privacy management sys...Votes: 0GitHub stars: 16
- Joint Controller Art26Guides the establishment and management of joint controller arrangements under GDPR Article 26, including determination of joint controllership, allocation of responsibilities, and transparency obligations. Activate when two or more controllers jointly determine purposes and means of processing, or when evaluating shared data platforms. Keywords: joint controller, Article 26, shared responsibility, arrangement, joint determination.Votes: 0GitHub stars: 16
- Kwp Legal Canned ResponsesGenerate templated responses for common legal inquiries and identify when situations require individualized attention. Use when responding to routine legal questions — data subject requests, vendor inquiries, NDA requests, discovery holds — or when managing response templates. Do NOT use for tasks outside the legal domain. Korean triggers: "생성", "데이터".Votes: 0GitHub stars: 16
- Lawful Basis AssessmentGuides determination of the correct lawful basis under GDPR Article 6(1)(a)-(f) for each processing activity. Includes decision tree logic for consent vs legitimate interest vs contract necessity. Activate when evaluating legal grounds for processing or reviewing lawful basis selections. Keywords: lawful basis, Article 6, consent, legitimate interest, legal obligation, contract.Votes: 0GitHub stars: 16
- Legal Advisor V2legal-advisor workflow skill. Use this skill when the user needs Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.Votes: 0GitHub stars: 16
- Legal Advisorlegal-advisor workflow skill. Use this skill when the user needs Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.Votes: 0GitHub stars: 16