Syntic

Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.

ComplianceFree Safe

gdpr-audit-prep

Security Scan Summary

Status: Safe

Source: Syntic Skills registry

Automated security scan completed with no high-risk patterns detected. Manual review is still required.

About This Skill

Use when prepping an annual internal GDPR review, a post-breach audit, DPA investigation readiness, or acquisition due diligence on a target's privacy posture.

Downloadable SKILL.md

Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.

SKILL.md
---
name: gdpr-audit-prep
description: Use when prepping an annual internal GDPR review, a post-breach audit, DPA investigation readiness, or acquisition due diligence on a target's privacy posture.
category: Compliance
version: 1.0.0
tools: []
---

# GDPR Audit Prep

Six Article-cited forcing questions from the DPO/auditor perspective, applied before an internal GDPR review, a breach response, a DPA investigation, or acquisition due diligence.

## When to run

Before the annual internal GDPR audit; before the quarterly Article 30 RoPA refresh; before launching new high-risk processing that requires an Article 35 DPIA; post-breach (Articles 33-34); before responding to a DPA investigation or engaging a supervisory authority; during acquisition due diligence on a target's privacy posture; or quarterly during high-volume new-feature shipping.

## The six questions

### 1. Show the Article 30 RoPA — with a last-updated date.
The most-cited finding area. It must include every Article 30(1)(a)-(g) element for controllers and every Article 30(2)(a)-(d) element for processors, updated within a reasonable time of changes (90 days expected), with joint-controller arrangements documented per Article 26.

### 2. For this processing activity, what's the lawful basis under Article 6?
Article 6 is exclusive — pick one basis per purpose, from consent, contract, legal obligation, vital interests, public task, or legitimate interests. Where the basis is legitimate interests, a Legitimate Interests Assessment must be documented; where it's consent, records must exist per Article 7 with a withdrawal mechanism. Special categories under Article 9 require an Article 9(2) exception.

### 3. For high-risk processing, where's the DPIA per Article 35?
Required for high-risk processing; sample 3-5 activities. Article 35(7)(a)-(d) requires a systematic description of the processing, a necessity/proportionality assessment, risks to rights and freedoms, and measures to address those risks. The DPO must be consulted per Article 35(2), and Article 36 prior consultation is triggered for residual high risk. For AI systems, this integrates with the EU AI Act's Article 27 Fundamental Rights Impact Assessment.

### 4. Show a DSAR from the last 30 days — and the response timing.
Covers the Articles 15-22 operational workflow. Response is due within 1 month (Article 12(3)), extendable up to 2 months for complex requests, with a documented identity-verification process. A right-of-access response must include all Article 15 information, and the right-to-erasure (Article 17) workflow must cover backups and processors.

### 5. Show Transfer Impact Assessments for the largest non-EU transfers.
Schrems II discipline. Each transfer needs an adequacy decision, Standard Contractual Clauses (Article 46), or a derogation (Article 49), with a TIA per EDPB Recommendations 01/2020 and 02/2020 and supplementary measures where the TIA flags risk. US transfers can rely on the EU-US Data Privacy Framework adequacy decision (July 2023) — verify the transferee is on the certified-entity list.

### 6. Show the breach log per Article 33(5) — all breaches, not just notifiable ones.
Article 33(5) requires logging every breach, not only the reportable ones. Check for a documented internal breach-detection mechanism, Article 33 DPA notification within 72 hours where required, Article 34 data-subject notification where risk is high, and root-cause/corrective action flowing through the CAPA system — cross-check alignment with ISO 27001 A.5.24-27 incident management.

## What to produce

Name the decision being made (RoPA-refresh / DPIA-required / DSAR-workflow / transfer-risk / breach-followup / DPA-readiness), and cite the specific Article and paragraph behind every finding — no paraphrase. Cover: Article 30 RoPA status (last refresh date, required elements present per activity, joint-controller documentation); Article 6 lawful-basis discipline (activities reviewed, legitimate-interests claims missing an LIA, Article 9 exception documentation); Article 35 DPIA quality (which high-risk activities require one, pass/fail per activity against Article 35(7), Article 36 consultations triggered); data-subject rights under Articles 12-22 (DSARs in the last 90 days, average response time against a ≤30-day target, erasure workflow completeness for backups/processors); Article 28 processor management (processors reviewed, % of contracts with all Article 28(3)(a)-(j) clauses, sub-processor flow-down notification); Schrems II transfer status (non-EU transfers, mechanism per transfer, TIA on file, supplementary measures where needed); and Article 33-34 breach discipline (breach count over 12 months, 72-hour notification ratio, on-time data-subject notification ratio). Note cross-framework impact: ISO 27001 Article 32 alignment, EU AI Act Article 27 FRIA integration where applicable, SOC 2 Privacy TSC alignment if in scope.

Close with a verdict — DPA-READY / GAPS-IDENTIFIED / NOT-READY — the top 3 actions with an owner and an Article-cited timeline each, and a flag for anything needing outside counsel: Schrems II supplementary-measure adequacy, EU AI Act/GDPR interaction, sectoral derogation interpretation, or novel DPA enforcement.

## Escalate to a teammate

For the multi-framework view, ISO 27001 Article 32 organizational measures, EU AI Act Article 27 FRIA integration, SOC 2 Privacy TSC overlap, or novel-case legal review, @mention the relevant compliance, security, or legal teammate.

Bundle Download

Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.

Install Targets

Syntic App

  1. 1. Create a dedicated folder for this skill in your local skills library.
  2. 2. Place SKILL.md into that folder.
  3. 3. Restart Syntic and invoke this skill on matching tasks.

Syntic Code (CLI)

  1. 1. Save SKILL.md in your local Syntic Code skills directory.
  2. 2. Keep related files in the same skill folder.
  3. 3. Run in a safe environment and validate outputs.

Source

https://github.com/alirezarezvani/claude-skills/blob/main/compliance-os/skills/gdpr-audit-prep/SKILL.md

Open Source Link
Compliance

Related Skills