gdpr-data-mapping

Installation
SKILL.md

GDPR Data Mapping

Create the records and workflows that demonstrate GDPR compliance.

1. Data Inventory (Article 30 Records of Processing)

For each processing activity capture:

  • Purpose and lawful basis (consent, contract, legal obligation, vital interests, public task, legitimate interests — with the LI balancing test documented)
  • Categories of data subjects and personal data (special categories flagged: health, biometrics, political, etc.)
  • Recipients including subprocessors and international transfers
  • Retention periods with the justification for each
  • Security measures (technical and organizational)

2. Data Flow Mapping

  • Systems inventory cross-referenced: which system holds which data fields, where backups and logs replicate them
  • Marketing/CRM/analytics flows separately — consent state travels with the data
  • Third-country transfers: identify mechanisms (adequacy decisions, SCCs, EU-US DPF) and conduct transfer impact assessments
Installs
12
First Seen
Aug 24, 2026
gdpr-data-mapping — securityskills/skills