Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.
gdpr-dsgvo-expert
Security Scan Summary
Status: Safe
Source: Syntic Skills registry
Automated security scan completed with no high-risk patterns detected. Manual review is still required.
About This Skill
Use when running GDPR/DSGVO compliance assessments, privacy audits, DPIA generation, or data subject rights (DSAR) tracking, e.g. checking GDPR risk or an access-request deadline under Art. 12(3).
Downloadable SKILL.md
Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.
--- name: gdpr-dsgvo-expert description: Use when running GDPR/DSGVO compliance assessments, privacy audits, DPIA generation, or data subject rights (DSAR) tracking, e.g. checking GDPR risk or an access-request deadline under Art. 12(3). category: Regulatory & Quality version: 1.0.0 tools: [] --- # GDPR/DSGVO Expert Assess EU General Data Protection Regulation (GDPR) and German Bundesdatenschutzgesetz (BDSG) compliance, produce DPIA documentation, and track data subject rights deadlines. Final compliance determinations route to the DPO or legal counsel. ## GDPR Compliance Assessment When asked to check a system, process, or codebase description for GDPR risk, evaluate it for: - **Personal data patterns**: email, phone, IP addresses. - **Special category data** (Art. 9): health, biometric, religion, and other sensitive categories. - **Financial data**: credit cards, IBAN. - **Risky practices**: logging personal data, missing consent mechanisms, indefinite data retention, unencrypted sensitive data, disabled deletion functionality. Score compliance 0-100, categorize risk as critical, high, or medium, and give prioritized recommendations, each citing the relevant GDPR article. ## DPIA Methodology Determine whether a Data Protection Impact Assessment is required under Art. 35, then produce the assessment: 1. **Threshold assessment** — check whether processing triggers a mandatory DPIA: systematic monitoring (Art. 35(3)(c)), large-scale special category data (Art. 35(3)(b)), automated decision-making (Art. 35(3)(a)), or any EDPB-endorsed high-risk criteria (WP248 rev.01). 2. **Risk identification** — based on the processing characteristics found above. 3. **Legal basis documentation** — record the Art. 6 (and, where relevant, Art. 9) basis relied on. 4. **Mitigation recommendations** — proportionate to the identified risks. 5. Return the DPIA as a structured written report in chat. ## Data Subject Rights Tracking Manage requests under GDPR Articles 15-22: | Right | Article | Deadline | |-------|---------|----------| | Access | Art. 15 | One month (Art. 12(3)) | | Rectification | Art. 16 | One month (Art. 12(3)) | | Erasure | Art. 17 | One month (Art. 12(3)) | | Restriction | Art. 18 | One month (Art. 12(3)) | | Portability | Art. 20 | One month (Art. 12(3)) | | Objection | Art. 21 | One month (Art. 12(3)) | | Automated decisions | Art. 22 | One month (Art. 12(3)) | All rights must be fulfilled within **one month of receipt** (Art. 12(3)). The deadline runs by calendar month, not 30 days, and may be extended by **two further months** for complex or numerous requests — inform the data subject of the extension, with reasons, within the first month. Workflow: log the request with type/subject/email, verify identity with proportionate measures, track status (verified → in progress → completed), flag overdue requests, and generate a response template appropriate to the right requested. ## Key GDPR Concepts **Legal bases (Art. 6)**: Consent (marketing, newsletters, analytics — must be freely given, specific, informed); Contract (order fulfillment, service delivery); Legal obligation (tax, employment law); Legitimate interests (fraud prevention, security — requires a balancing test). **Special category data (Art. 9)** requires explicit consent or an Art. 9(2) exception: health data, biometric data, racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, sexual orientation. **Breach notification**: Art. 33-34. **Accountability**: Art. 30 records of processing. **International transfers**: Chapter V. ## German BDSG Requirements | Topic | BDSG Section | Key Requirement | |-------|--------------|-----------------| | DPO threshold | § 38 | 20+ employees = mandatory DPO | | Employment | § 26 | Detailed employee data rules | | Video | § 4 | Signage and proportionality | | Scoring | § 31 | Explainable algorithms | If a DPO is required, check the § 38 threshold (20+ employees processing personal data automatically, or processing requiring a DPIA, or business involving data transfer/market research) and confirm registration with the supervisory authority. For employee data, document the § 26 legal basis and check works council co-determination rights. Video surveillance under § 4 requires signage, documented necessity, and limited retention. Credit scoring under § 31 requires explainable algorithms. State data protection laws (Landesdatenschutzgesetze) may add further requirements.
Bundle Download
Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.
Install Targets
Syntic App
- 1. Create a dedicated folder for this skill in your local skills library.
- 2. Place SKILL.md into that folder.
- 3. Restart Syntic and invoke this skill on matching tasks.
Syntic Code (CLI)
- 1. Save SKILL.md in your local Syntic Code skills directory.
- 2. Keep related files in the same skill folder.
- 3. Run in a safe environment and validate outputs.
Source
https://github.com/alirezarezvani/claude-skills/blob/main/ra-qm-team/skills/gdpr-dsgvo-expert/SKILL.md
Open Source LinkRelated Skills
agent-decision-receipts
Use when an autonomous agent takes a consequential, side-effecting action (deploy, delete, pay, grant-access...
Regulatory & Qualitycapa-officer
Use when running CAPA investigations, 5-Why or fishbone root cause analysis, corrective action planning and...
Regulatory & Qualityeu-ai-act-specialist
Use when classifying an AI system's EU AI Act risk tier, planning Article 43 conformity assessment for a...
Regulatory & Qualityfda-consultant-specialist
Use when handling FDA submission pathway selection (510(k)/PMA/De Novo), QMSR/ISO 13485 compliance, medical...