agency-data-privacy-officer

Advises on GDPR and CCPA compliance programs including DPIAs, breach response, and data subject rights.

Updated Jul 27, 2026
One-click install
npx skills add https://github.com/imMamdouhaboammar/Mimera --skill agency-data-privacy-officer-immamdouhaboammar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: agency-data-privacy-officer
Source: https://github.com/imMamdouhaboammar/Mimera/tree/main/.agents/skills/data-privacy-officer
Command: npx skills add https://github.com/imMamdouhaboammar/Mimera --skill agency-data-privacy-officer-immamdouhaboammar

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Organizations handling personal data struggle to translate complex privacy regulations like GDPR and CCPA into concrete operational controls, risking fines, breach mishandling, and unlawful processing. ## Core Features & Use Cases - Privacy Program Governance: Build Article 30 records of processing, data flow maps, and lawful basis documentation for every processing activity. - DPIA & Risk Assessment: Run structured Data Protection Impact Assessments with trigger checklists, risk scoring matrices, and DPO sign-off workflows. - Breach & DSR Operations: Execute the 72-hour GDPR breach notification protocol and fulfill data subject requests within statutory deadlines. - Use Case: A product team launching an AI profiling feature asks whether it can proceed; the Skill identifies the mandatory DPIA trigger, walks through the assessment template, and flags cross-border transfer requirements before launch. ## Quick Start Act as our Data Privacy Officer and assess whether our planned customer analytics pipeline requires a DPIA under GDPR.

Frequently Asked Questions about agency-data-privacy-officer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a DPIA under GDPR?

A DPIA under GDPR Article 35 follows six sections: describe the processing, assess necessity and proportionality, score risks by likelihood times severity, define mitigating measures, obtain DPO sign-off, and consult the supervisory authority if residual risk remains high. It is mandatory before launching high-risk processing such as large-scale profiling or special category data handling.

What lawful basis should I use for processing personal data?

GDPR Article 6 offers six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Consent is fragile because it is revocable; legitimate interests is often more defensible for activities like fraud prevention, but requires a documented three-part legitimate interest assessment.

Does GDPR require breach notification within 72 hours?

Yes, GDPR requires notifying the supervisory authority within 72 hours of becoming aware of a breach likely to risk individuals' rights and freedoms. If the breach poses high risk to individuals, affected data subjects must also be notified without undue delay in plain, actionable language.

How do I handle cross-border data transfers under GDPR?

First check whether the destination country has an EU adequacy decision. If not, implement Standard Contractual Clauses plus a Transfer Impact Assessment, or rely on Binding Corporate Rules. Derogations under Article 49, such as explicit consent, are last-resort options for occasional transfers.

What must a GDPR-compliant data processing agreement include?

A DPA under GDPR Article 28 must cover the subject matter and duration of processing, data types and subject categories, documented controller instructions, confidentiality obligations, security measures, sub-processor approval, DSR assistance, data return or deletion at contract end, and audit rights.

When is consent not a valid lawful basis?

Consent fails when it is not freely given, such as in employer-employee relationships with power imbalance, or when bundled as a condition of service unnecessarily. It is also weak for core processing because withdrawal forces deletion, making legitimate interests or contract more stable alternatives.