gdpr-data-mapper

Map data flows and generate RoPA and GDPR artifacts.

3|2|Updated Jun 9, 2026
One-click install
npx skills add https://github.com/JayRHa/AgentSkills --skill gdpr-data-mapper
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: gdpr-data-mapper
Source: https://github.com/JayRHa/AgentSkills/tree/main/gdpr-data-mapper
Command: npx skills add https://github.com/JayRHa/AgentSkills --skill gdpr-data-mapper

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

GDPR Data Mapper helps teams map how personal data flows through systems and generate auditable GDPR artifacts — RoPA, lawful-basis analysis, retention schedules, and DSAR readiness — for review by counsel or DPO.

Core Features & Use Cases

  • Generate RoPA and Article 30 records for each processing activity
  • Identify lawful bases and data categories with supporting justifications
  • Define concrete retention schedules and rights fulfillment plans
  • Prepare DSAR readiness checks and DPIA triggers for large-scale or sensitive processing

Quick Start

Identify processing activities, map data flows, and draft RoPA and GDPR artifacts for review by counsel.

Frequently Asked Questions about gdpr-data-mapper

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a Record of Processing Activities (RoPA) for GDPR compliance?

To create a RoPA, identify processing activities and map data flows across systems. This produces Article 30 records and GDPR artifacts, covering data categories, lawful bases, retention schedules, and DSAR readiness for DPO review.

What is GDPR data mapping and when do I need a DPIA trigger?

GDPR data mapping identifies how personal data flows through systems. When mapping reveals large-scale or sensitive processing, it automatically flags DPIA triggers to ensure compliant drafting and review.

How do I document lawful basis and data minimization for GDPR processing?

Document lawful basis by identifying data categories and applying supporting justifications using a lawful-basis guide. This maps data flows while enforcing data minimization principles to produce auditable GDPR artifacts.

Can I prepare DSAR readiness checks and retention schedules together?

Yes, you can prepare DSAR readiness checks alongside concrete retention schedules. Mapping data flows and applying rights references ensures both data subject access fulfillment plans and retention periods are documented.

What is the best way to map data flows for a small legal team?

The best way is mapping data flows across processing activities to draft RoPA and GDPR artifacts. Small teams can leverage built-in templates and rights references to produce compliant documentation for counsel review.