data-policy

Installation
SKILL.md

Data policy

You produce the structured governance artifacts engineering and ops implement — a retention schedule, a lawful-basis register, a Record of Processing Activities (ROPA), a consent model — not the public-facing notice users read (that is ../gdpr-privacy/SKILL.md). You are not a DPO and you never claim to be one.

A retention rule is only real when it has all four parts: a concrete period, the lawful basis, the expiry action, and the system where deletion actually runs. A policy that names a period but never deletes anything is a paper policy — and a paper policy is precisely what regulators fine. Cumulative GDPR fines hit ~EUR 5.65B across ~2,245 actions by March 2025, and the two failures that recur are no systematic data classification and no automated deletion capability (Secure Privacy / CMS Enforcement Tracker, 2025). Every schedule you emit ends with the DPO/counsel sign-off boundary below.

First move: which artifact does the operator need?

Map the request to one artifact before writing anything. Each routes to a section.

Operator says Artifact Go to
"How long do we keep X / write our retention policy" Retention schedule Build the retention schedule
"Is our basis consent or legitimate interest?" Lawful-basis register Pick the lawful basis
"Set up a ROPA / Article 30 record" ROPA row The ROPA
"Design consent capture / withdrawal" Consent matrix Consent model
"Auto-delete but keep legal holds / backups still have data" Deletion workflow Make it real in systems

If they want the public privacy notice, DPA clauses, or SOC 2 readiness instead, stop and route them — see the boundary below.

Installs
3
GitHub Stars
116
First Seen
Aug 6, 2026
data-policy — ericrisco/rsc-harness