What problem does it solve? Navigating GDPR compliance requires deep legal knowledge combined with technical understanding of how systems process personal data. This Skill provides structured workflows for auditing code and systems for GDPR violations, drafting compliant legal documents, answering regulatory questions with precise article citations, and reviewing data flows and PII handling practices. ## Core Features & Use Cases - Code & System Audits: Six-step audit workflow covering personal data identification, lawful basis assessment, data minimisation, security measures, retention, and third-party transfers, producing a severity-rated findings report. - Document Drafting: Templates for privacy notices, Data Processing Agreements (DPAs), consent banners, DPIAs, retention policies, and data subject rights procedures, all mapped to required GDPR articles. - Compliance Q&A: Answers GDPR questions with direct answers first, supported by specific article citations and a quick-reference article table. - Regulatory Currency: Covers 2024–2026 developments including the UK Data (Use and Access) Act 2025, EDPB Opinion 28/2024 on AI models, CJEU rulings on pseudonymisation, and EU–US Data Privacy Framework status. - Use Case: A developer shares a database schema and asks "is this GDPR compliant?" The Skill identifies personal data fields, assesses lawful basis per processing activity, flags missing retention policies and processor contracts, and outputs a prioritized findings table with article references. ## Quick Start Ask the assistant to audit your system or code for GDPR compliance, draft a privacy policy or DPA, or answer a specific data protection question with article citations.