privacy-data-handling

Creates GDPR/CCPA-compliant data retention, access control, and deletion policies for sensitive data.

6|1|Updated Feb 25, 2026
One-click install
npx skills add https://github.com/vibbs/company-os --skill privacy-data-handling
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: privacy-data-handling
Source: https://github.com/vibbs/company-os/tree/main/.claude/skills/privacy-data-handling
Command: npx skills add https://github.com/vibbs/company-os --skill privacy-data-handling

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the critical need to establish and maintain robust data privacy and handling policies, ensuring compliance with regulations and protecting sensitive user information.

Core Features & Use Cases

  • Data Inventory & Classification: Identifies and categorizes all personal and sensitive data collected.
  • Policy Definition: Establishes clear rules for data retention, access control, and deletion.
  • Compliance Assurance: Helps align data handling practices with regulations like GDPR and CCPA.
  • Use Case: A startup needs to define how it will store and protect customer email addresses and payment information, ensuring it meets GDPR requirements before launching its service.

Quick Start

Define the data handling policy for personal and sensitive data collected by the system.

Frequently Asked Questions about privacy-data-handling

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I establish data retention policies for GDPR and CCPA compliance?

Data retention policies for GDPR and CCPA compliance are established by defining data lifecycle management rules, lawful bases for processing, and clear deletion procedures for personal and sensitive data.

What is data lifecycle management and how does it handle sensitive data?

Data lifecycle management governs personal and sensitive data from collection to deletion, requiring inventory classification by sensitivity and mapping data flows to third-party processors to ensure regulatory compliance.

How do I map data flows to third-party processors for privacy compliance?

Mapping data flows to third-party processors involves inventorying collected data, classifying it by sensitivity, and tracking its movement to external processors to maintain lawful processing and compliance.

When do I need breach notification protocols for data handling?

Breach notification protocols are needed when handling personal and sensitive data, ensuring regulatory requirements are met by defining procedures for notifying relevant parties during a data breach.

Can I define access controls for personal data without mapping data flows?

Defining access controls requires inventorying data and classifying it by sensitivity, while mapping data flows to third-party processors is essential to fully establish lawful processing and compliance.

Does this approach to data handling work for a startup launching a new service?

Data handling policies support startups launching new services by defining how to store and protect customer information like email addresses and payment data, ensuring GDPR requirements are met pre-launch.