gdpr-compliance

Audit systems, draft GDPR documents, and answer data protection questions with article citations.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill gdpr-compliance-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: gdpr-compliance
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/gdpr-compliance
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill gdpr-compliance-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Navigating GDPR compliance requires deep legal knowledge combined with technical understanding of how systems process personal data. This Skill provides structured workflows for auditing code and systems for GDPR violations, drafting compliant legal documents, answering regulatory questions with precise article citations, and reviewing data flows and PII handling practices. ## Core Features & Use Cases - Code & System Audits: Six-step audit workflow covering personal data identification, lawful basis assessment, data minimisation, security measures, retention, and third-party transfers, producing a severity-rated findings report. - Document Drafting: Templates for privacy notices, Data Processing Agreements (DPAs), consent banners, DPIAs, retention policies, and data subject rights procedures, all mapped to required GDPR articles. - Compliance Q&A: Answers GDPR questions with direct answers first, supported by specific article citations and a quick-reference article table. - Regulatory Currency: Covers 2024–2026 developments including the UK Data (Use and Access) Act 2025, EDPB Opinion 28/2024 on AI models, CJEU rulings on pseudonymisation, and EU–US Data Privacy Framework status. - Use Case: A developer shares a database schema and asks "is this GDPR compliant?" The Skill identifies personal data fields, assesses lawful basis per processing activity, flags missing retention policies and processor contracts, and outputs a prioritized findings table with article references. ## Quick Start Ask the assistant to audit your system or code for GDPR compliance, draft a privacy policy or DPA, or answer a specific data protection question with article citations.

Frequently Asked Questions about gdpr-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my code or system for GDPR compliance?

Share your code, architecture diagrams, or database schemas for a six-step audit covering personal data identification, lawful basis, data minimisation, security measures, retention, and third-party transfers. The output is a findings report with severity ratings and specific GDPR article references for each issue.

What GDPR documents can be drafted with this skill?

It drafts privacy notices, Data Processing Agreements (DPAs), consent notices and cookie banners, DPIAs, data retention policies, and data subject rights procedures. Each template maps to the required GDPR articles, such as Art. 13/14 for privacy notices and Art. 28(3) for DPAs.

What lawful basis should I use for processing personal data?

GDPR Art. 6(1) provides six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. The skill assesses each processing activity against these bases, including the three-part legitimate interests assessment required for Art. 6(1)(f).

Does this cover UK GDPR after the Data (Use and Access) Act 2025?

Yes, it covers UK-specific divergence under the DUAA 2025, including Recognised Legitimate Interests, the 'not materially lower' transfer standard, and the Senior Responsible Individual role. UK questions are flagged as requiring UK-specific analysis rather than EU GDPR alone.

Can I rely on the EU-US Data Privacy Framework for data transfers?

The DPF remains valid but is under CJEU appeal (Case C-703/25 P) with PCLOB oversight suspended. The skill recommends maintaining Standard Contractual Clauses as a fallback safeguard and documenting both mechanisms in privacy notices.

Is the GDPR guidance provided a substitute for legal advice?

No, the guidance is informational and based on the GDPR text and regulatory guidance, not legal advice. High-stakes matters like enforcement risk, special category data, or complex cross-border transfers should be reviewed by a qualified data protection lawyer or DPO.