gdpr-compliance
Installation
SKILL.md
GDPR Compliance Skill
GDPR compliance is mostly bookkeeping you can defend: knowing every place you process personal data, why you're allowed to, how long you keep it, and how a person can get it out or deleted. This skill builds that record (the ROPA), pins a lawful basis to each activity, and flags the high-risk processing that legally requires a DPIA — turning "are we GDPR-compliant?" into a documented, auditable answer.
Required Inputs
Ask for these only if they aren't already provided:
- Processing activities — what personal data you collect, why, and where it flows (this is the spine; everything hangs off it).
- Role — controller (you decide the why/how) or processor (you act on a controller's instructions); your obligations differ.
- Data subjects & data types — whose data, and whether any is special-category (health, biometrics, etc.) or about children.
- Transfers — any processing or storage outside the EEA (triggers transfer-mechanism requirements).