gdpr-compliance

Generate GDPR data subject access request reports with deadline tracking.

1|1|Updated Dec 20, 2025
One-click install
npx skills add https://github.com/orkestra-cc/orkestra --skill gdpr-compliance-orkestra-cc
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: gdpr-compliance
Source: https://github.com/orkestra-cc/orkestra/tree/main/.claude/skills/gdpr-compliance
Command: npx skills add https://github.com/orkestra-cc/orkestra --skill gdpr-compliance-orkestra-cc

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill addresses the complexity of maintaining GDPR compliance, managing data subject rights, and responding to security incidents, ensuring your system meets strict EU/EEA regulatory requirements.

Core Features & Use Cases

  • DSR Management: Streamlines workflows for data access, rectification, and erasure requests with deadline tracking.
  • Privacy by Design: Provides technical patterns for PII masking, encryption, and automated data retention.
  • Breach Response: Offers a structured 72-hour notification workflow and risk assessment framework for supervisory authority interactions.

Quick Start

Use the gdpr-compliance skill to generate a data subject access request report for the user with ID 12345.

Frequently Asked Questions about gdpr-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manage data subject access requests and track GDPR response deadlines?

GDPR data subject access requests are managed by streamlining workflows for access, rectification, and erasure while tracking mandatory response deadlines. This ensures DSR handling meets regulatory timelines without manual oversight.

What is the required framework for 72-hour breach notification under EU law?

A 72-hour breach notification framework requires structured risk assessment and supervisory authority interaction workflows. It ensures mandatory reporting timelines under EU law are met during security incidents involving PII.

How do I implement privacy by design controls for PII masking and data retention?

Privacy by design controls for PII masking and data retention are implemented using provided technical patterns for encryption and automated data lifecycle management. This satisfies EU/EEA regulatory requirements for PII handling.

Can I use this to maintain Records of Processing Activities and assess cross-border data transfers?

Yes, RoPA maintenance and cross-border transfer assessments are supported directly. It provides frameworks to document lawful basis and evaluate data transfer mechanisms required for GDPR compliance.

Do I need a Data Protection Officer to document lawful basis for data processing?

A Data Protection Officer is supported but not strictly required to document lawful basis. The framework provides structured documentation tools enabling both developers and DPOs to manage compliance requirements effectively.

What are the limitations of using automated workflows for GDPR consent management?

Automated GDPR consent management workflows handle technical PII handling and documentation but do not replace legal counsel. They satisfy regulatory requirements for consent tracking but require human review for complex cross-border transfer assessments.