gdpr-data-mapping
Installation
SKILL.md
GDPR Data Mapping
Create the records and workflows that demonstrate GDPR compliance.
1. Data Inventory (Article 30 Records of Processing)
For each processing activity capture:
- Purpose and lawful basis (consent, contract, legal obligation, vital interests, public task, legitimate interests — with the LI balancing test documented)
- Categories of data subjects and personal data (special categories flagged: health, biometrics, political, etc.)
- Recipients including subprocessors and international transfers
- Retention periods with the justification for each
- Security measures (technical and organizational)
2. Data Flow Mapping
- Systems inventory cross-referenced: which system holds which data fields, where backups and logs replicate them
- Marketing/CRM/analytics flows separately — consent state travels with the data
- Third-country transfers: identify mechanisms (adequacy decisions, SCCs, EU-US DPF) and conduct transfer impact assessments