doncheli-data-policy skill
Audit and document what personal or sensitive data the project collects, processes, and stores. Activate when user mentions "privacy", "data policy", "what data", "GDPR", "personal data", "data retention", "PII".
A100/100content scan
Is the doncheli-data-policy skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the doncheli-data-policy skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/doncheli/don-cheli-sdd.git /tmp/don-cheli-sdd mkdir -p ~/.claude/skills cp -r /tmp/don-cheli-sdd/.agent/skills/doncheli-data-policy ~/.claude/skills/doncheli-data-policy
available in every project
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Don Cheli: Data Policy Auditor
Instructions
- Scan the codebase for PII and sensitive data patterns:
- Database models / schemas for fields like email, phone, name, address, IP, location
- API request/response payloads
- Logging statements that may capture sensitive fields
- Third-party integrations that receive user data
- Build a data inventory table: field name, model, purpose, retention, shared with
- Check against common compliance requirements:
- GDPR: lawful basis, right to erasure, data minimization
- CCPA: disclosure, opt-out
- SOC2: access controls, encryption at rest/transit
- Flag violations as [critical | warning | info]
- Generate a draft Privacy Notice section if requested (--generate-notice)
- Save the audit to .dc/data-policy-audit-.md
- Never make assumptions about compliance status — only report findings and flag gaps
Output Format
## Data Policy Audit — 2026-03-28
### Data Inventory
| Field | Model | Purpose | Retention | Shared With |
|-----------|-----------|---------------|-----------|----------------|
| email | User | Auth, comms | Indefinite| SendGrid, Auth0|
| ip_address| AuditLog | Security | 90 days | Internal only |
### Compliance Gaps
🔴 CRITICAL: ip_address logged in plain text in audit_logs — encrypt or hash
🟡 WARNING: No data retention policy enforced for User.email — GDPR Art. 5(e)
🟢 INFO: No right-to-erasure endpoint found — required for GDPR compliance
### Recommendations
1. Add @Encrypted() decorator to ip_address field
2. Implement DELETE /users/:id endpoint that purges all PII
3. Document data retention in Privacy PolicyMore skills from doncheli/don-cheli-sdd
- Adoncheli-api-contractDesign complete API contracts covering endpoints, auth, rate limiting, error handling, retries, circuit breaker and idempotency. Activate when user mentions "api contract", "api design", "endpoint", "webhook", "REST", "GraphQL", "OpenAPI", "design the API".
- Adoncheli-api-contractDesign complete API contracts covering endpoints, auth, rate limiting, error handling, retries, circuit breaker and idempotency. Activate when user mentions "api contract", "api design", "endpoint", "webhook", "REST", "GraphQL", "OpenAPI", "design the API".
- Adoncheli-audit-trailRecord and query the decision log for a project. Activate when user mentions "audit", "trail", "log decisions", "decision history", "why was this decided", "ADR", "architecture decision".
- Adoncheli-audit-trailRecord and query the decision log for a project. Activate when user mentions "audit", "trail", "log decisions", "decision history", "why was this decided", "ADR", "architecture decision".
- Adoncheli-changelogAuto-generate CHANGELOG.md entries from git commit history. Activate when user mentions "changelog", "release notes", "what changed", "generate changelog", "CHANGELOG", "release history".
- Adoncheli-changelogAuto-generate CHANGELOG.md entries from git commit history. Activate when user mentions "changelog", "release notes", "what changed", "generate changelog", "CHANGELOG", "release history".
- Adoncheli-context-healthReport the current state of the context window and recommend compression or cleanup actions. Activate when user mentions "context health", "context window", "how much context", "context full", "running out of context", "compress context".
- Adoncheli-context-healthReport the current state of the context window and recommend compression or cleanup actions. Activate when user mentions "context health", "context window", "how much context", "context full", "running out of context", "compress context".
- Adoncheli-data-policyAudit and document what personal or sensitive data the project collects, processes, and stores. Activate when user mentions "privacy", "data policy", "what data", "GDPR", "personal data", "data retention", "PII".
- Adoncheli-debateRun an adversarial multi-role debate to surface trade-offs and reach a reasoned decision. Activate when user mentions "debate", "discuss", "trade-off", "decision", "compare options", "pros and cons", "choose between".
- Adoncheli-debateRun an adversarial multi-role debate to surface trade-offs and reach a reasoned decision. Activate when user mentions "debate", "discuss", "trade-off", "decision", "compare options", "pros and cons", "choose between".
- Adoncheli-diagramAuto-generate Mermaid or C4 diagrams from code analysis. Activate when user mentions "diagram", "mermaid", "architecture diagram", "C4", "class diagram", "sequence diagram", "ERD", "flowchart", "visualize code".