gdpr-audit-prep

Pressure-tests GDPR compliance posture using six Article-cited audit questions.

25.3k|3.6k|Updated Oct 19, 2025
One-click install
npx skills add https://github.com/alirezarezvani/claude-skills --skill gdpr-audit-prep
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: gdpr-audit-prep
Source: https://github.com/alirezarezvani/claude-skills/tree/main/compliance-os/skills/gdpr-audit-prep
Command: npx skills add https://github.com/alirezarezvani/claude-skills --skill gdpr-audit-prep

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Preparing for a GDPR internal audit, DPA investigation, or acquisition due diligence requires systematically verifying RoPA records, lawful bases, DPIAs, DSAR workflows, transfer mechanisms, and breach logs — a process that is easy to do incompletely without a structured interrogation framework.

Core Features & Use Cases

  • Six Article-Cited Forcing Questions: Audits Article 30 RoPA, Article 6 lawful basis, Article 35 DPIA, Articles 15-22 DSAR workflows, Schrems II transfer impact assessments, and Article 33-34 breach logging.
  • Structured Audit Report: Produces a markdown verdict (DPA-READY / GAPS-IDENTIFIED / NOT-READY) with per-Article findings and top-3 remediation actions.
  • Cross-Framework Integration: Aligns findings with ISO 27001, SOC 2 Privacy TSC, and EU AI Act Article 27 FRIA requirements.
  • Use Case: Before an annual internal GDPR review, run the audit against your compliance state to surface missing legitimate-interest assessments, overdue RoPA refreshes, and untimely DSAR responses.

Quick Start

Ask the AI to run a GDPR audit prep on your current privacy program scope and produce the Article-cited readiness report.

Frequently Asked Questions about gdpr-audit-prep

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for a GDPR internal audit?

Run a structured audit covering six areas: Article 30 RoPA currency, Article 6 lawful basis per processing purpose, Article 35 DPIAs for high-risk processing, DSAR response timing under Article 12(3), Schrems II transfer impact assessments, and the Article 33(5) breach log.

What must a GDPR Article 30 record of processing contain?

Controllers must document all Article 30(1)(a)-(g) elements and processors all Article 30(2)(a)-(d) elements, updated within a reasonable time of changes (90 days expected). Joint controller arrangements must be documented per Article 26.

When is a DPIA required under GDPR Article 35?

A DPIA is required for processing likely to result in high risk to rights and freedoms. It must contain the Article 35(7)(a)-(d) elements, involve DPO consultation per Article 35(2), and trigger Article 36 prior consultation when residual risk remains high.

Does this GDPR audit cover international data transfers?

Yes, it checks each non-EU transfer for an adequacy decision, SCCs under Article 46, or an Article 49 derogation, plus a Transfer Impact Assessment per EDPB Recommendations 01/2020 and 02/2020 with supplementary measures where risk was flagged.

What are the limits of an automated GDPR audit prep?

The audit identifies gaps and cites Articles but flags Article-level ambiguities — such as Schrems II supplementary measure adequacy or EU AI Act interactions — for outside counsel rather than resolving novel legal questions itself.