All skills
wshobson avatar

/gdpr-data-handling

@be57c0b
by Seth Hobsonwshobson/agents40k stars
4,281

Implement GDPR-compliant data handling with consent management, data subject rights, and privacy by design. Use when building systems that process EU personal data, implementing privacy controls, or conducting GDPR compliance reviews.

Use this Skill: https://skilld.dev/gh/wshobson/agents/gdpr-data-handling

This session only. Nothing lands on disk.

SKILL.md

โ‰ˆ64 tokens always: the name and description. โ‰ˆ600 when used: this file. โ‰ˆ4.4k more on demand in 1 file.

GDPR Data Handling

Practical implementation guide for GDPR-compliant data processing, consent management, and privacy controls.

When to Use This Skill

  • Building systems that process EU personal data
  • Implementing consent management
  • Handling data subject requests (DSRs)
  • Conducting GDPR compliance reviews
  • Designing privacy-first architectures
  • Creating data processing agreements

Core Concepts

1. Personal Data Categories

Category Examples Protection Level
Basic Name, email, phone Standard
Sensitive (Art. 9) Health, religion, ethnicity Explicit consent
Criminal (Art. 10) Convictions, offenses Official authority
Children's Under 16 data Parental consent

2. Legal Bases for Processing

Article 6 - Lawful Bases:
โ”œโ”€โ”€ Consent: Freely given, specific, informed
โ”œโ”€โ”€ Contract: Necessary for contract performance
โ”œโ”€โ”€ Legal Obligation: Required by law
โ”œโ”€โ”€ Vital Interests: Protecting someone's life
โ”œโ”€โ”€ Public Interest: Official functions
โ””โ”€โ”€ Legitimate Interest: Balanced against rights

3. Data Subject Rights

Right to Access (Art. 15)      โ”€โ”
Right to Rectification (Art. 16) โ”‚
Right to Erasure (Art. 17)       โ”‚ Must respond
Right to Restrict (Art. 18)      โ”‚ within 1 month
Right to Portability (Art. 20)   โ”‚
Right to Object (Art. 21)       โ”€โ”˜

Detailed worked examples and patterns

Detailed sections (starting with ## Implementation Patterns) live in references/details.md. Read that file when the navigation summary above is insufficient.

Best Practices

Do's

  • Minimize data collection - Only collect what's needed
  • Document everything - Processing activities, legal bases
  • Encrypt PII - At rest and in transit
  • Implement access controls - Need-to-know basis
  • Regular audits - Verify compliance continuously

Don'ts

  • Don't pre-check consent boxes - Must be opt-in
  • Don't bundle consent - Separate purposes separately
  • Don't retain indefinitely - Define and enforce retention
  • Don't ignore DSARs - 30-day response required
  • Don't transfer without safeguards - SCCs or adequacy decisions

Source: SKILL.md on GitHub

2 warnings16d5 checks ยท Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides safe and instructional documentation for implementing GDPR-compliant systems, including patterns for consent management and data subject request handling. No malicious instructions, obfuscation, or security risks were identified.

  • Socket16d

    1 alert: gptAnomaly

  • Snyk16d

    Risk: LOW ยท No issues

  • Runlayer6mo

    1/1 file flagged

  • ZeroLeaks5mo

    Score: 93/100 ยท 2 sections analyzed

Signed by skilld at be57c0b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 4 months ago
  • gdpr
  • privacy
  • compliance
  • consent-management
  • data-protection
  • eu-regulation
  • dsar
  • encryption
  • access-control
  • data-retention

README badge

README badge for wshobson/agents/gdpr-data-handling

Implements GDPR-compliant data handling workflows including consent management, data subject rights fulfillment, and privacy controls. Covers legal bases for processing, personal data categories, retention policies, and audit patterns for EU personal data systems.

Generated from the current SKILL.md.

Does this skill cover consent management implementation?
Yes. The skill includes consent management as a core topic, covering how to structure lawful consent under Article 6, how to avoid pre-checked boxes, and how to keep consent separate by purpose.
What data subject rights does this skill address?
It covers the six main rights under GDPR: access, rectification, erasure, restriction, portability, and objection. It notes that responses must be completed within one month.
Does this skill apply to non-EU data processing?
No. The skill is specific to EU personal data and GDPR compliance. It does not address CCPA, LGPD, or other regional privacy regimes.
Does this provide code or just compliance guidance?
It provides practical patterns and best practices for implementing GDPR controls, including documentation of processing activities, encryption, access controls, and audit approaches. Detailed implementation patterns are in a referenced details.md file.

Generated from the current SKILL.md. These answers refresh after source changes.