conducting-gdpr-compliance-assessment skill
Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data subject rights implementation, Data Protection Impact Assessments (DPIAs) under Article 35, breach notification procedures, international transfer safeguards (SCCs, adequacy decisions), and technical/organizational measures under Article 32. Use when processing personal data of EU residents, preparing for supervisory authority audits, implementing privacy-by-design for new systems, scoping compliance gaps for M&A due diligence, assessing third-party processors, or responding to data subject access requests at scale. Incorporates 2026 guidance from ICO, EDPB, and post-Data (Use and Access) Act 2025 UK-GDPR considerations. Do not use for implementing specific Article 32 controls — use implementing-gdpr-data-protection-controls; or for DSAR automation — use implementing-gdpr-data-subject-access-request.
Is the conducting-gdpr-compliance-assessment skill safe?
Clean: nothing in its files matched our rules. We read 9 files in the folder on 2026-09-28.
No findings.
Install the conducting-gdpr-compliance-assessment skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git /tmp/Anthropic-Cybersecurity-Skills mkdir -p ~/.claude/skills cp -r /tmp/Anthropic-Cybersecurity-Skills/skills/conducting-gdpr-compliance-assessment ~/.claude/skills/conducting-gdpr-compliance-assessment
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Conducting GDPR Compliance Assessment
Effective Date: August 2026
Legal Basis: EU Regulation 2016/679 (GDPR), UK GDPR as amended by Data Protection Act 2018 and Data (Use and Access) Act 2025 (ukpga/2025/18)
Pending Changes: Digital Omnibus proposal (COM(2025) 837) would change Article 30(5) threshold from 250 to 750 employees and Article 33 breach notification from 72h to 96h. Still in proposal stage; current requirements remain in force.
When to Use
- When an organization processes personal data of EU residents (Article 3 territorial scope applies)
- When preparing for a supervisory authority audit (ICO, CNIL, BfDI) or responding to formal inquiry
- When implementing privacy-by-design requirements (Article 25) for new systems or data flows
- When scoping compliance gaps before M&A due diligence or contract negotiations with EU entities
- When responding to data subject access requests (DSARs) and discovering gaps in data inventory
- When assessing third-party processors for GDPR compliance before signing Data Processing Agreements (DPAs)
- After data breach incidents to verify notification procedures meet 72-hour requirement (Article 33)
Do not use for:
- Technical implementation of specific GDPR controls (encryption, pseudonymization, access controls) — use implementing-gdpr-data-protection-controls for Article 32 technical/organizational measures
- Automated DSAR processing workflows (identity verification, PII discovery, redaction, delivery) — use implementing-gdpr-data-subject-access-request for DSAR automation
- Non-EU privacy frameworks alone (CCPA, PIPEDA, LGPD); those require separate assessments with jurisdiction-specific criteria
- This skill is for comprehensive compliance assessment across all GDPR articles; use the specialized skills for focused implementation tasks
Prerequisites
- Understanding of GDPR Articles 5-32 and key definitions
- Access to Article 30 records of processing activities
- Data Processing Agreements with third-party processors
- Privacy policies, consent forms, cookie notices
- Knowledge of lawful bases (Article 6)
- Data breach response plan and incident register
- List of international data transfers with safeguards
Workflow
For detailed procedures, templates, and examples, see references/detailed-workflow.md
Phase 1: Determine Territorial Applicability (Article 3)
GDPR applies if:
- Organization has establishment in EU
- Offers goods/services to EU residents
- Monitors behavior of EU residents
Check: EU office? EU website targeting? Behavioral tracking?
Phase 2: Inventory Data Processing Activities (Article 30)
Document for EACH activity:
- Controller/processor details
- Processing purposes (specific)
- Data categories and special categories (Art. 9)
- Recipients and international transfers
- Retention periods
- Security measures
Tools: Use scripts/article30parser.py, article30validator.py, generateropareport.py
Common gaps: Missing retention periods (68%), vague purposes, undocumented transfers
Phase 3: Validate Lawful Basis (Article 6)
Action: Map each Article 30 activity to one lawful basis. Document legitimate interest assessments.
Phase 4: Assess Data Subject Rights (Articles 12-23)
Verify capability for:
- Access (15): Provide copy in machine-readable format within 1 month
- Rectification (16): Correct inaccurate data
- Erasure (17): "Right to be forgotten" (with exceptions)
- Portability (20): Transfer data in structured format
- Objection (21): Opt-out of legitimate interest processing
- Automated Decision-Making (22): Human review of algorithmic decisions
Test: Process sample DSAR through full workflow. Use scripts/ for automation.
Phase 5: Review DPIAs (Article 35)
DPIA mandatory for:
- Large-scale profiling with automated decisions
- Large-scale special categories processing
- Systematic monitoring of public areas (facial recognition)
Template: See references/detailed-workflow.md for complete DPIA structure
Content: Description, necessity, risks, mitigation, consultation (DPO, supervisory authority if novel high-risk)
Phase 6: Audit Breach Notification (Articles 33-34)
72-hour rule: Notify supervisory authority within 72 hours of becoming aware of breach likely to risk rights.
Decision tree:
- Unencrypted SSNs stolen? → NOTIFY + notify data subjects
- Encrypted backup stolen (key secure)? → Document only
- Temporary exposure (2 hours, no financial data)? → NOTIFY authority, assess data subject notification
Content: Nature, categories/numbers, DPO contact, consequences, mitigation
Phase 7: Verify International Transfers (Chapter V)
Mechanisms:
- Adequacy decisions (UK, Japan, etc.)
- Standard Contractual Clauses (SCCs) 2021 + Transfer Impact Assessment
- Binding Corporate Rules (BCRs)
- Derogations (Article 49 - limited)
Post-Schrems II: Assess destination country surveillance laws, implement supplementary measures (encryption with EU-held keys)
Phase 8: Assess Security Measures (Article 32)
"Security appropriate to the risk":
- Low risk: TLS 1.2+, password hashing, access logs, patching
- Medium risk: AES-256 encryption, MFA, RBAC, penetration testing, SOC 2
- High risk: HSMs, key rotation, SIEM, bug bounty, ISO 27001
Pseudonymization vs. Anonymization: Pseudo = reversible (still personal data); Anon = irreversible (no longer GDPR)
Phase 9: Compile Findings and Remediation Roadmap
Generate compliance report:
- Executive summary (overall status, high-priority gaps)
- Article-by-article findings
- Risk-prioritized remediation plan (Critical/High/Medium/Low)
- Cost estimates and timelines
- Responsible parties (DPO, IT, Legal, Business)
Format: See Output Format section below
Key Concepts
Tools & Systems
- ICO Self-Assessment: https://ico.org.uk/for-organisations/sme-web-hub/checklists/gdpr-check-list/
- EDPB Guidelines: https://edpb.europa.eu/our-work-tools/general-guidance_en
- OneTrust / TrustArc: Commercial GRC platforms with DPIA, Article 30, cookie consent modules
- Article 30 Scripts: article30parser.py, article30validator.py (included)
- SCCs (2021): https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en
- DPO Certification: IAPP CIPP/E (Certified Information Privacy Professional/Europe)
Common Scenarios
Scenario: M&A Due Diligence
Context: Acquiring SaaS company with 50K EU customers. Need compliance assessment within 2 weeks.
Approach:
- Request Article 30 records + DPAs with processors (AWS, Stripe, Mailchimp)
- Validate lawful basis: Consent for marketing, Contract for service delivery
- Check breach notification procedures (Article 33): No procedures found → HIGH RISK
- Review international transfers: AWS US-East-1 without SCCs → BLOCKER
- Deliverable: Gap analysis with remediation costs ($120K for SCCs + DPO hire + breach procedures)
Scenario: Supervisory Authority Audit
Context: ICO formal inquiry after consumer complaint about unsubscribe not working.
Response:
More skills from mukul975/Anthropic-Cybersecurity-Skills
- Aabusing-dpapi-for-credential-accessExtract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket's dpapi.py, including domain-wide decryption via the DPAPI backup key. Use during authorized red-team credential-access engagements after gaining a foothold or when triaging DPAPI blobs pulled from a host.
- Aabusing-shadow-credentials-for-privescTake over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or Certipy, then authenticate via PKINIT to recover the target's NT hash without a password reset. Use when BloodHound shows GenericWrite/GenericAll/AddKeyCredentialLink over a target, as a stealthier alternative to ForceChangePassword, during authorized red-team engagements.
- Aachieving-cmmc-level-2-compliancePrepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoD contract, when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for or responding to a CMMC assessment, when computing or improving an SPRS score, when building a System Security Plan or POA&M for 800-171, or when scoping which systems are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2, CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment Methodology, 110 controls, defense industrial base, DIB, FedRAMP equivalency.
- Aacquiring-disk-image-with-dd-and-dcflddCreate forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.
- Aanalyzing-active-directory-acl-abuseDetect dangerous ACL misconfigurations in Active Directory using ldap3
- Aanalyzing-android-malware-with-apktoolPerform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination detection, and identification of obfuscated code, dynamic code loading, and reflection-based API calls. Use to statically triage a suspicious APK without executing it or to build mobile malware detection rules.
- Danalyzing-api-gateway-access-logs'Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
- Aanalyzing-apt-group-with-mitre-navigatorQuery ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap analysis. Use to compare threat-actor technique coverage, find gaps in detection engineering, or produce Navigator visualizations for threat-intel reporting.
- Aanalyzing-azure-activity-logs-for-threats'Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
- Aanalyzing-bootkit-and-rootkit-samples'Analyzes bootkit and advanced rootkit malware infecting the Master
- Aanalyzing-browser-forensics-with-hindsightParse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user's web activity from a browser profile.
- Aanalyzing-campaign-attribution-evidenceSystematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level.