dpo-specialist

Generate GDPR Art. 30 Records of Processing Activities aligned with ISO 27701.

10|1|Updated Nov 5, 2025
One-click install
npx skills add https://github.com/moag1000/Little-ISMS-Helper --skill dpo-specialist
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpo-specialist
Source: https://github.com/moag1000/Little-ISMS-Helper/tree/main/.claude/skills/dpo-specialist
Command: npx skills add https://github.com/moag1000/Little-ISMS-Helper --skill dpo-specialist

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The DPO Specialist automates privacy and data protection tasks, helping you manage GDPR (DSGVO), BDSG, and privacy programs while smartly integrating privacy controls with your ISMS. It reduces manual effort, accelerates DPIAs, and streamlines rights management and data transfer assessments.

Core Features & Use Cases

  • GDPR & BaFin Guidance: supports Art. 30 records of processing activities, DPIAs, and data subject rights workflows.
  • DPIA & Privacy by Design: guidance and templates to assess privacy risks for new projects and systems.
  • Data Subject Rights Automation: automates responses and documentation for access, rectification, erasure, and portability requests.
  • Transfers & Legal Bases: maps third-country transfers (SCCs, adequacy, BCRs) and retention requirements to ISMS controls.
  • ISMS Alignment: links DPO activities to ISO 27001/27701 controls, enabling reuse with existing governance.

Quick Start

DPO, perform a DPIA for a new processing activity and draft the Records of Processing Activities for the project named 'Customer Analytics'.

Frequently Asked Questions about dpo-specialist

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate GDPR Records of Processing Activities documentation?

Records of Processing Activities automate GDPR Article 30 compliance by generating DPO-grade documentation that tracks legal bases, processors, and data flows. The Skill creates aligned records for processing activities across your organization, reducing manual effort and ensuring governance requirements are met consistently.

What's the best way to conduct a DPIA and integrate it with my ISMS controls?

Conduct a DPIA by using privacy-by-design guidance and templates to assess risks for new processing activities, then map findings to ISO 27001/27701 controls within your existing ISMS. This integration links privacy assessments directly to your security control framework, enabling reuse and alignment across governance.

Can I automate data subject rights requests like access and erasure under GDPR?

Data subject rights automation streamlines responses to access, rectification, erasure, and portability requests by automating documentation and tracking workflows. The Skill manages request timelines, legal obligations, and audit trails to ensure compliance with GDPR Articles 15–22.

How do I manage third-country data transfers with SCCs and adequacy decisions?

Transfer management maps legal safeguards—Standard Contractual Clauses, adequacy decisions, and Binding Corporate Rules—to retention requirements and ISMS controls. The Skill documents transfer mechanisms and cross-references privacy controls to ensure compliance with cross-border transfer restrictions.

Does this support breach notification timelines and processor engagement tracking?

Breach management tracks notification timelines under GDPR Articles 33–34 and automates processor engagement documentation per Article 28. The Skill manages joint controller arrangements, legal base tracking, and automated decision-making governance to satisfy functional and technical requirements.

Can I use this for BDSG compliance and BaFin-regulated organizations?

GDPR and BaFin guidance support BDSG compliance and regulated financial organizations through Art. 30 records, DPIAs, and data subject workflows aligned with German privacy law. The Skill provides organization-wide governance applicable to regulated sectors and cross-border operations.