cpo

Guide architecture reviews and generate DPIAs for GDPR, CCPA, SOC 2, and HIPAA compliance.

Updated Mar 11, 2026
One-click install
npx skills add https://github.com/elcoosp/elcoosp-skills --skill cpo-elcoosp
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cpo
Source: https://github.com/elcoosp/elcoosp-skills/tree/main/virtual-saas-team/agents/core/cpo
Command: npx skills add https://github.com/elcoosp/elcoosp-skills --skill cpo-elcoosp

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill acts as a Compliance & Privacy Officer, ensuring that all product development adheres to regulatory requirements, privacy standards, and security best practices from the outset.

Core Features & Use Cases

  • Architecture Review: Vets system designs for security risks before implementation.
  • DPIA Generation: Conducts Data Protection Impact Assessments for features handling PII.
  • Compliance Monitoring: Maintains security controls and assesses regulatory adherence (GDPR, CCPA, SOC 2, HIPAA).
  • Use Case: Before a new feature that collects user location data can be built, this Skill will guide the team through creating a Data Protection Impact Assessment (DPIA) to identify and mitigate privacy risks.

Quick Start

Use the cpo skill to produce a DPIA for a new feature that collects user email addresses.

Frequently Asked Questions about cpo

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a Data Protection Impact Assessment for a new feature collecting PII?

To generate a Data Protection Impact Assessment (DPIA), provide the feature details to identify and mitigate privacy risks for collecting PII. The skill guides you through evaluating privacy-by-design controls and proactively assessing risks before implementation.

When do I need a Data Protection Impact Assessment for GDPR compliance?

You need a Data Protection Impact Assessment for GDPR compliance when developing features that handle personally identifiable information (PII) like user location or email addresses. It ensures privacy-by-design by identifying and mitigating risks early in the software development lifecycle.

Can I use this to vet system architecture for SOC 2 and HIPAA security controls?

Yes, you can use this to vet system architecture for SOC 2 and HIPAA security controls. It reviews system designs for security risks before implementation and maintains a security controls matrix to assess regulatory adherence.

What is the best way to ensure privacy by design during the software development lifecycle?

The best way to ensure privacy by design during the software development lifecycle is using a Compliance & Privacy Officer agent. It proactively identifies risks, conducts DPIAs, and vets architecture to enforce GDPR, CCPA, SOC 2, and HIPAA adherence.

How do I maintain a security controls matrix for CCPA and GDPR adherence?

Maintain a security controls matrix for CCPA and GDPR adherence by applying expert compliance monitoring guidance. It assesses regulatory adherence, ensures privacy-by-design, and helps mitigate risks throughout the software development lifecycle.