← all plugins

Privacy Data Protection Skills

by @mukul975-2 · plugin · 100 skills

Privacy Data Protection Skills from mukul975/Privacy-Data-Protection-Skills.

Install the whole plugin (CLI)
npx skillmds add mukul975-2/ai-dpia npx skillmds add mukul975-2/china-pipl npx skillmds add mukul975-2/japan-appi npx skillmds add mukul975-2/korea-pipa npx skillmds add mukul975-2/brazil-lgpd npx skillmds add mukul975-2/turkey-kvkk npx skillmds add mukul975-2/uae-pdp-law npx skillmds add mukul975-2/cookie-audit npx skillmds add mukul975-2/dpa-drafting npx skillmds add mukul975-2/new-tech-pia npx skillmds add mukul975-2/nigeria-ndpr npx skillmds add mukul975-2/42-cfr-part-2 npx skillmds add mukul975-2/canada-pipeda npx skillmds add mukul975-2/delaware-dppa npx skillmds add mukul975-2/kentucky-kppa npx skillmds add mukul975-2/montana-mtdpa npx skillmds add mukul975-2/thailand-pdpa npx skillmds add mukul975-2/apac-transfers npx skillmds add mukul975-2/apec-cbpr-cert npx skillmds add mukul975-2/biometric-dpia npx skillmds add mukul975-2/gdpr-dpa-art28 npx skillmds add mukul975-2/india-dpdp-act npx skillmds add mukul975-2/iso-27701-pims npx skillmds add mukul975-2/new-jersey-dpa npx skillmds add mukul975-2/nist-pf-govern npx skillmds add mukul975-2/singapore-pdpa npx skillmds add mukul975-2/dsar-processing npx skillmds add mukul975-2/gdpr-doc-review npx skillmds add mukul975-2/gdpr-ropa-audit npx skillmds add mukul975-2/nist-pf-control npx skillmds add mukul975-2/nist-pf-protect npx skillmds add mukul975-2/pia-health-data npx skillmds add mukul975-2/right-to-object npx skillmds add mukul975-2/breach-forensics npx skillmds add mukul975-2/coppa-compliance npx skillmds add mukul975-2/data-portability npx skillmds add mukul975-2/health-data-dpia npx skillmds add mukul975-2/nist-pf-identify npx skillmds add mukul975-2/right-to-erasure npx skillmds add mukul975-2/transfer-records npx skillmds add mukul975-2/vcdpa-compliance npx skillmds add mukul975-2/ai-data-retention npx skillmds add mukul975-2/art49-derogations npx skillmds add mukul975-2/bcr-establishment npx skillmds add mukul975-2/breach-simulation npx skillmds add mukul975-2/connecticut-ctdpa npx skillmds add mukul975-2/cpra-sensitive-pi npx skillmds add mukul975-2/data-flow-mapping npx skillmds add mukul975-2/data-localization npx skillmds add mukul975-2/dpia-risk-scoring npx skillmds add mukul975-2/gdpr-gap-analysis npx skillmds add mukul975-2/ropa-dpia-linkage npx skillmds add mukul975-2/state-law-tracker npx skillmds add mukul975-2/universal-opt-out npx skillmds add mukul975-2/breach-remediation npx skillmds add mukul975-2/cnil-cookie-banner npx skillmds add mukul975-2/consent-withdrawal npx skillmds add mukul975-2/dpia-register-mgmt npx skillmds add mukul975-2/dsar-intake-system npx skillmds add mukul975-2/eu-code-of-conduct npx skillmds add mukul975-2/gdpr-certification npx skillmds add mukul975-2/gdpr-one-stop-shop npx skillmds add mukul975-2/gdpr-valid-consent npx skillmds add mukul975-2/hipaa-privacy-rule npx skillmds add mukul975-2/hitech-act-privacy npx skillmds add mukul975-2/personal-data-test npx skillmds add mukul975-2/pia-review-cadence npx skillmds add mukul975-2/privacy-api-design npx skillmds add mukul975-2/retention-schedule npx skillmds add mukul975-2/ropa-250-exemption npx skillmds add mukul975-2/scc-implementation npx skillmds add mukul975-2/soc2-privacy-audit npx skillmds add mukul975-2/south-africa-popia npx skillmds add mukul975-2/telehealth-privacy npx skillmds add mukul975-2/us-privacy-federal npx skillmds add mukul975-2/whistleblower-data npx skillmds add mukul975-2/adequacy-assessment npx skillmds add mukul975-2/age-gating-services npx skillmds add mukul975-2/auto-data-discovery npx skillmds add mukul975-2/byod-privacy-policy npx skillmds add mukul975-2/consent-pref-center npx skillmds add mukul975-2/double-opt-in-email npx skillmds add mukul975-2/dpa-inspection-prep npx skillmds add mukul975-2/financial-retention npx skillmds add mukul975-2/gdpr-accountability npx skillmds add mukul975-2/hipaa-breach-notify npx skillmds add mukul975-2/hipaa-mobile-health npx skillmds add mukul975-2/hipaa-phi-inventory npx skillmds add mukul975-2/hipaa-risk-analysis npx skillmds add mukul975-2/hipaa-security-rule npx skillmds add mukul975-2/marketing-objection npx skillmds add mukul975-2/nist-pf-communicate npx skillmds add mukul975-2/pii-in-unstructured npx skillmds add mukul975-2/pseudo-vs-anon-data npx skillmds add mukul975-2/vendor-risk-scoring npx skillmds add mukul975-2/ai-privacy-inference npx skillmds add mukul975-2/ai-transparency-reqs npx skillmds add mukul975-2/audit-report-writing npx skillmds add mukul975-2/breach-documentation npx skillmds add mukul975-2/breach-subject-comms
⬇ Download

Skills in this plugin

  1. ai-dpia · mukul975-2 bundle
    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing. Covers training data lawfulness evaluation, model risk assessment, automated decision triggers, and AI-specific DPIA methodology. Keywords: AI DPIA, machine learning impact assessment, EDPB AI guidelines, model risk, training data.
    228
    repo stars
  2. china-pipl · mukul975-2 bundle
    Guides compliance with China's Personal Information Protection Law (PIPL, effective 1 November 2021). Covers consent requirements, cross-border transfer mechanisms (CAC security assessment, standard contracts, certification), separate consent triggers, and critical information infrastructure obligations. Keywords: PIPL, China data protection, CAC security assessment, cross-border transfer, separate consent, CIIO.
    228
    repo stars
  3. japan-appi · mukul975-2 bundle
    Guides compliance with Japan's Act on the Protection of Personal Information (APPI, 2022 amendments). Covers individual rights expansion, cross-border transfer restrictions including pre-transfer information requirements, PPC enforcement, and pseudonymised and anonymously processed information. Keywords: APPI, Japan data protection, PPC, cross-border transfer, pseudonymised information, individual rights.
    228
    repo stars
  4. korea-pipa · mukul975-2 bundle
    Guides compliance with South Korea's Personal Information Protection Act (PIPA, 개인정보 보호법). Covers pseudonymisation framework, notification requirements, PIPC enforcement, consent standards, and cross-border transfer rules under the 2023 amendments. Keywords: PIPA, Korea data protection, PIPC, pseudonymisation, consent, cross-border transfers.
    228
    repo stars
  5. brazil-lgpd · mukul975-2 bundle
    Guides compliance with Brazil's Lei Geral de Proteção de Dados (LGPD, Lei 13.709/2018). Covers the 10 lawful bases under Art. 7, DPO appointment, ANPD enforcement, data subject rights under Arts. 17-22, and international transfer mechanisms. Keywords: LGPD, Brazil data protection, ANPD, lawful bases, data subject rights, international transfers.
    228
    repo stars
  6. turkey-kvkk · mukul975-2 bundle
    Implements compliance with Turkey's Personal Data Protection Law (Kisisel Verilerin Korunmasi Kanunu, KVKK, Law No. 6698). Covers data controller obligations, data subject rights, VERBIS registration, cross-border transfer restrictions, Board decisions, and administrative fines. Keywords: KVKK, Turkey, VERBIS, data controller registry, Board decision, cross-border.
    228
    repo stars
  7. uae-pdp-law · mukul975-2 bundle
    Implements compliance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDP Law) and its Executive Regulations. Covers data controller and processor obligations, data subject rights, cross-border transfer requirements, sensitive data processing, and UAE Data Office enforcement. Keywords: UAE PDP, Federal Decree-Law 45, UAE Data Office, DIFC, ADGM, cross-border transfer.
    228
    repo stars
  8. cookie-audit · mukul975-2 bundle
    Comprehensive methodology for auditing website cookies and tracking technologies. Covers automated scanning, cookie categorization, lifecycle documentation, and compliance gap analysis referencing the Planet49 CJEU ruling (C-673/17).
    228
    repo stars
  9. dpa-drafting · mukul975-2 bundle
    GDPR-compliant Data Processing Agreement drafting per Article 28(3). Covers all 8 mandatory provisions including subject matter, duration, nature and purpose, data types, categories of data subjects, controller and processor obligations, and sub-processor cascade requirements.
    228
    repo stars
  10. new-tech-pia · mukul975-2 bundle
    Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins. Covers risk identification methodology, proportionality assessment, and technology-specific privacy challenges. Activate when evaluating new technology adoption, innovation projects, or emerging tech procurement. Keywords: PIA, emerging technology, IoT, blockchain, AR/VR, quantum computing, digital twins, innovation privacy.
    228
    repo stars
  11. nigeria-ndpr · mukul975-2 bundle
    Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA) 2023 compliance. Covers lawful basis for processing, data subject rights, cross-border transfer mechanisms, Data Protection Compliance Organisation (DPCO) registration, mandatory DPIA filing, and breach notification. Keywords: NDPR, NDPA, Nigeria, NITDA, DPCO, Africa data protection, cross-border transfer.
    228
    repo stars
  12. 42-cfr-part-2 · mukul975-2 bundle
    Implements 42 CFR Part 2 protections for substance use disorder patient records. Covers written consent requirements stricter than HIPAA, re-disclosure prohibition, court order procedures, qualified service organization agreements, and 2024 amendments aligning Part 2 with HIPAA. Keywords: 42 CFR Part 2, substance use disorder, SUD records, re-disclosure, consent, Part 2 amendments.
    228
    repo stars
  13. canada-pipeda · mukul975-2 bundle
    Guides compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5). Covers the 10 fair information principles in Schedule 1, consent requirements, cross-border transfer obligations, breach notification under Division 1.1, and OPC enforcement. Keywords: PIPEDA, Canada privacy, fair information principles, OPC, breach notification, cross-border transfer, consent.
    228
    repo stars
  14. delaware-dppa · mukul975-2 bundle
    Delaware Personal Data Privacy Act (DPPA) compliance implementation. Covers consumer rights (access, correct, delete, portability, opt-out), controller obligations, processor requirements, sensitive data consent, universal opt-out recognition, DPIA requirements, and AG enforcement. Effective January 1, 2025, with no revenue threshold for applicability.
    228
    repo stars
  15. kentucky-kppa · mukul975-2 bundle
    Kentucky Consumer Privacy Protection Act (KPPA) compliance. Effective January 1, 2026. Covers consumer rights, controller thresholds at 100,000 consumers, sensitive data processing consent, cure period provisions, and AG enforcement framework.
    228
    repo stars
  16. montana-mtdpa · mukul975-2 bundle
    Montana Consumer Data Privacy Act (MTDPA) compliance. Lowest consumer threshold at 50,000 consumers. Covers sensitive data consent, universal opt-out recognition, consumer rights, controller obligations, 60-day cure period, and AG enforcement. Effective October 1, 2024.
    228
    repo stars
  17. thailand-pdpa · mukul975-2 bundle
    Guides compliance with Thailand's Personal Data Protection Act B.E. 2562 (2019). Covers consent framework, DPO requirements, PDPC enforcement, lawful bases for processing, cross-border transfer mechanisms, and data subject rights under the PDPA. Keywords: Thailand PDPA, PDPC, consent, DPO, cross-border transfers, data subject rights.
    228
    repo stars
  18. apac-transfers · mukul975-2 bundle
    Guides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
    228
    repo stars
  19. apec-cbpr-cert · mukul975-2 bundle
    Guides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
    228
    repo stars
  20. biometric-dpia · mukul975-2 bundle
    Guides DPIA for biometric processing systems including facial recognition, fingerprint, voice, iris, and gait analysis. Covers Art. 9 special category requirements, Art. 35(3)(b) mandatory DPIA triggers for large-scale biometric processing, and EDPB Guidelines 3/2019 on video surveillance. Keywords: biometric, facial recognition, fingerprint, DPIA, Art. 9, special category, EDPB Guidelines 3/2019.
    228
    repo stars
  21. gdpr-dpa-art28 · mukul975-2 bundle
    Guides the creation and review of data processing agreements under GDPR Article 28(3), covering all eight mandatory clauses. References the 2021 Standard Contractual Clauses and provides a compliance checklist for processor contracts. Activate when onboarding processors, reviewing DPAs, or auditing processor compliance. Keywords: DPA, data processing agreement, Article 28, processor, mandatory clauses, standard contractual clauses.
    228
    repo stars
  22. india-dpdp-act · mukul975-2 bundle
    Guides compliance with India's Digital Personal Data Protection Act 2023. Covers consent manager registration, data fiduciary obligations under Sections 4-7, significant data fiduciary requirements under Section 10, data principal rights, and Board enforcement framework. Keywords: DPDP Act, India data protection, consent manager, data fiduciary, significant data fiduciary, data principal rights.
    228
    repo stars
  23. iso-27701-pims · mukul975-2 bundle
    Guides ISO 27701 Privacy Information Management System implementation extending ISO 27001/27002. Covers Clause 5 PIMS-specific requirements, Clause 6 PIMS guidance for ISO 27002, Clause 7 PII controller guidance (Annex A), Clause 8 PII processor guidance (Annex B), gap assessment, and certification path. Keywords: ISO 27701, PIMS, privacy management system, ISO 27001 extension, certification, Annex A, Annex B.
    228
    repo stars
  24. new-jersey-dpa · mukul975-2 bundle
    New Jersey Data Privacy Act (NJDPA) compliance, effective January 15, 2025. Covers consumer rights (access, correction, deletion, portability, opt-out), controller obligations, sensitive data requirements, universal opt-out mechanism recognition, 30-day cure period (sunsets after 18 months), and AG enforcement. Keywords: NJDPA, New Jersey, data privacy, consumer rights, sensitive data, universal opt-out, AG enforcement.
    228
    repo stars
  25. nist-pf-govern · mukul975-2 bundle
    Implement the NIST Privacy Framework GOVERN function covering GV.AT awareness and training, GV.MT monitoring and review, GV.PO policy development, and GV.RR roles and responsibilities. Provides governance structure templates, training programs, and accountability frameworks for privacy governance.
    228
    repo stars
  26. singapore-pdpa · mukul975-2 bundle
    Guides compliance with Singapore's Personal Data Protection Act 2012 (PDPA). Covers PDPC advisory guidelines, Do Not Call Registry, data intermediary obligations, deemed consent, notification requirements, and the 2020-2021 amendments. Keywords: Singapore PDPA, PDPC, Do Not Call Registry, deemed consent, data intermediary, advisory guidelines.
    228
    repo stars
  27. dsar-processing · mukul975-2 bundle
    Guides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day deadline calculation with extensions, response formatting, exemptions, and fee provisions. Activate when handling DSAR, access request, subject access, Art. 15, or SAR queries.
    228
    repo stars
  28. gdpr-doc-review · mukul975-2 bundle
    Guides systematic review of processing documentation for completeness against GDPR Articles 5, 13-14, 24, 28, and 30. Activate when auditing documentation or preparing for inspections. Keywords: documentation review, processing records, completeness, privacy notices, RoPA.
    228
    repo stars
  29. gdpr-ropa-audit · mukul975-2 bundle
    Guides the audit of Records of Processing Activities (RoPA) against GDPR Article 30 requirements for both controllers and processors. Activate when verifying RoPA completeness, validating mandatory fields, or preparing for supervisory authority inspections. Keywords: RoPA, Article 30, records audit, processing activities, controller records, processor records.
    228
    repo stars
  30. nist-pf-control · mukul975-2 bundle
    Implement the NIST Privacy Framework CONTROL function covering CT.DM data management, CT.DP data processing policies and procedures, and CT.PO disassociated processing. Provides technical control architectures, data management workflows, and de-identification implementation guidance.
    228
    repo stars
  31. nist-pf-protect · mukul975-2 bundle
    Implement the NIST Privacy Framework PROTECT function covering PR.AC access control, PR.DS data security, and PR.PO protective policies. Provides technical control implementation guidance, encryption standards, access management architectures, and security-privacy integration patterns.
    228
    repo stars
  32. pia-health-data · mukul975-2 bundle
    Conducts Privacy Impact Assessment for health data processing under GDPR Article 9, HIPAA, and sector-specific health privacy regulations. Covers special category data safeguards, clinical research data, patient portals, health wearables, genetic data, and cross-border health data transfers. Keywords: health data PIA, DPIA, Article 9, HIPAA, special category data, clinical research, patient privacy, genetic data.
    228
    repo stars
  33. right-to-object · mukul975-2 bundle
    Handles GDPR Article 21 right to object to processing, including compelling legitimate grounds assessment, ceasing processing obligations, documentation requirements, and the relationship with erasure under Article 17(1)(c). Activate for right to object, Art. 21, objection to processing, legitimate interest queries.
    228
    repo stars
  34. breach-forensics · mukul975-2 bundle
    Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis. References industry-standard tools including Splunk, ELK Stack, and Wireshark. Provides forensic workflow from initial evidence collection through final investigation report. Keywords: digital forensics, breach investigation, evidence preservation, chain of custody, root cause analysis, Splunk, ELK, Wireshark.
    228
    repo stars
  35. coppa-compliance · mukul975-2 bundle
    Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312. Covers verifiable parental consent methods including signed forms, credit card verification, government ID, knowledge-based authentication, and video call. Includes FTC safe harbor programs and enforcement actions. Keywords: COPPA, FTC, children, parental consent, safe harbor, verifiable consent.
    228
    repo stars
  36. data-portability · mukul975-2 bundle
    Executes GDPR Article 20 data portability requests, covering machine-readable format requirements (JSON, CSV, XML), direct controller-to-controller transfer mechanisms, and scope limitations to data provided by the subject on consent or contract basis. Activate for portability, data export, Art. 20, data transfer queries.
    228
    repo stars
  37. health-data-dpia · mukul975-2 bundle
    Guides DPIA for health and medical data processing covering Art. 9(2)(h)-(j) exemptions, HIPAA crosswalk for transatlantic operations, clinical trial data protection under EU CTR 536/2014, and genetic data specifics under Art. 9(1). Activate for healthcare systems, clinical research, health apps, or medical device data. Keywords: health data, DPIA, Art. 9, clinical trial, genetic data, HIPAA, medical records, special category.
    228
    repo stars
  38. nist-pf-identify · mukul975-2 bundle
    Implement the NIST Privacy Framework IDENTIFY function including ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories. Provides control mapping, gap analysis templates, and implementation workflows for privacy risk identification.
    228
    repo stars
  39. right-to-erasure · mukul975-2 bundle
    Implements the GDPR Article 17 right to erasure (right to be forgotten) workflow, covering all six grounds for erasure, five exceptions, technical deletion versus anonymization decisions, and third-party notification under Article 19. Activate for erasure request, deletion request, right to be forgotten, Art. 17 queries.
    228
    repo stars
  40. transfer-records · mukul975-2 bundle
    Guides maintenance of cross-border transfer registers, audit trails, and compliance documentation under GDPR Art. 30 and Art. 46, EDPB record-keeping guidance, and supervisory authority expectations. Keywords: transfer register, audit trail, Art. 30, Art. 46, documentation, compliance records.
    228
    repo stars
  41. vcdpa-compliance · mukul975-2 bundle
    Virginia Consumer Data Protection Act (VCDPA) compliance implementation. Covers 5 consumer rights, controller obligations, processor requirements, opt-in for sensitive data, data protection impact assessments, AG enforcement, and cure period provisions. Effective January 1, 2023.
    228
    repo stars
  42. ai-data-retention · mukul975-2 bundle
    Manages AI model retention and machine unlearning requirements. Covers training data deletion verification, model versioning for compliance, machine unlearning techniques (SISA, gradient-based), and retraining triggers. Keywords: AI retention, machine unlearning, model versioning, training data deletion, retraining, storage limitation.
    228
    repo stars
  43. art49-derogations · mukul975-2 bundle
    Guides assessment and application of GDPR Article 49 derogation conditions for international data transfers in the absence of adequacy decisions or appropriate safeguards. Covers explicit consent, contract necessity, public interest, vital interests, public register, and compelling legitimate interests with restrictive interpretation per EDPB Guidelines 2/2018. Keywords: Art. 49, derogations, transfer exceptions, explicit consent, compelling legitimate interests.
    228
    repo stars
  44. bcr-establishment · mukul975-2 bundle
    Guides development and approval of Binding Corporate Rules under GDPR Article 47 for intra-group international data transfers. Covers Art. 47(2)(a)-(n) content requirements, BCR approval process with lead supervisory authority, and WP256/WP257 referentials. Keywords: BCR, binding corporate rules, intra-group transfers, Art. 47.
    228
    repo stars
  45. breach-simulation · mukul975-2 bundle
    Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities. Covers scenario creation with realistic inject timelines, participant role assignment, communication testing across internal and external channels, decision-point evaluation, and after-action report generation. Keywords: tabletop exercise, breach simulation, incident response testing, scenario design, after-action report.
    228
    repo stars
  46. connecticut-ctdpa · mukul975-2 bundle
    Connecticut Data Privacy Act (CTDPA) compliance. Covers consumer rights, controller obligations, dark pattern prohibition, loyalty program exemption, universal opt-out requirement effective January 2025, sensitive data consent, and AG enforcement. Effective July 1, 2023.
    228
    repo stars
  47. cpra-sensitive-pi · mukul975-2 bundle
    CPRA §1798.121 sensitive personal information restrictions and compliance. Covers all 9 sensitive PI categories including SSN, precise geolocation, racial/ethnic origin, biometric, genetic, health, and sex life data. Right to limit use/disclosure, permitted purposes, and implementation.
    228
    repo stars
  48. data-flow-mapping · mukul975-2 bundle
    Guides systematic mapping of international personal data flows across an organisation. Covers system-by-system inventory methodology, third-party identification, transfer mechanism assignment, gap analysis, and data flow visualisation. Keywords: data flow mapping, international transfers, data inventory, transfer register, cross-border data flows.
    228
    repo stars
  49. data-localization · mukul975-2 bundle
    Guides compliance with country-specific data localization requirements across key jurisdictions including Russia (242-FZ), China (PIPL Art. 40, CAC measures), India (DPDP Act), Turkey, Vietnam, and Indonesia. Covers localization assessment, architecture design, and exemption procedures. Keywords: data localization, data residency, PIPL, 242-FZ, cross-border restrictions.
    228
    repo stars
  50. dpia-risk-scoring · mukul975-2 bundle
    Provides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134. Covers likelihood and severity assessment, risk matrix construction, inherent vs residual risk calculation, and risk appetite thresholds per EDPB WP248rev.01 guidance. Keywords: risk scoring, DPIA risk matrix, likelihood, severity, ENISA, ISO 29134, residual risk, risk appetite.
    228
    repo stars
  51. gdpr-gap-analysis · mukul975-2 bundle
    Guides systematic assessment of current state versus GDPR requirements across all chapters with prioritised remediation matrix. Activate when starting compliance programmes or conducting periodic reassessment. Keywords: gap analysis, compliance assessment, remediation matrix, GDPR readiness.
    228
    repo stars
  52. ropa-dpia-linkage · mukul975-2 bundle
    Links RoPA entries to Data Protection Impact Assessments and lawful basis assessments. Covers cross-reference systems, dependency tracking, and update cascade triggers between RoPA, DPIA register, and lawful basis documentation. Activate for RoPA-DPIA link, cross-reference, dependency tracking, impact assessment linkage, cascade updates.
    228
    repo stars
  53. state-law-tracker · mukul975-2 bundle
    Tracks and monitors US state privacy legislation across all 50 states, DC, and territories. Covers enacted comprehensive privacy laws (California CCPA/CPRA, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and subsequent enactments), pending bills, effective dates, and key requirement differences. Keywords: state privacy law, CCPA, CPRA, VCDPA, CPA, CTDPA, UCPA, multi-state.
    228
    repo stars
  54. universal-opt-out · mukul975-2 bundle
    Universal opt-out mechanism implementation across US state privacy laws. Covers Global Privacy Control (GPC) signal technical implementation, state-by-state recognition requirements, browser detection methods, authenticated vs unauthenticated handling, and compliance testing.
    228
    repo stars
  55. breach-remediation · mukul975-2 bundle
    Conducts structured post-breach remediation using a lessons learned framework covering root cause remediation, control gap closure, policy updates, training modifications, monitoring enhancements, and regulatory follow-up. Provides a systematic approach to preventing breach recurrence and demonstrating accountability to supervisory authorities. Keywords: post-breach, remediation, lessons learned, root cause, control gap, policy update, training.
    228
    repo stars
  56. cnil-cookie-banner · mukul975-2 bundle
    Designing and implementing CNIL-compliant cookie consent banners for French and EU audiences. References the EUR 100M Google LLC fine and EUR 150M Meta Platforms fine for non-compliant cookie practices. Covers equal prominence, reject-all buttons, cookie walls prohibition, and 6-month reconsent cycles.
    228
    repo stars
  57. consent-withdrawal · mukul975-2 bundle
    Implementation guide for GDPR Article 7(3) consent withdrawal mechanisms. Covers the equal ease requirement ensuring withdrawal is as easy as giving consent, one-click withdrawal implementation, cascading effects on downstream processing, third-party notification workflows, and technical architecture for real-time consent revocation.
    228
    repo stars
  58. dpia-register-mgmt · mukul975-2 bundle
    Manages the organisational DPIA register tracking all Data Protection Impact Assessments across the enterprise. Covers DPIA lifecycle management, status tracking, review scheduling, Art. 35(11) periodic reassessment, and supervisory authority reporting. Implements a centralised register linking DPIAs to RoPA entries, risk registers, and mitigation plans. Keywords: DPIA register, DPIA tracking, Art. 35(11), review schedule, DPIA lifecycle, centralised register, DPIA portfolio management.
    228
    repo stars
  59. dsar-intake-system · mukul975-2 bundle
    Builds a multi-channel DSAR intake system supporting web form, email, phone, and in-person requests with identity verification tiers, automated routing logic, SLA tracking, and response generation. Activate for DSAR intake, rights request portal, multi-channel intake, SLA tracking, request management queries.
    228
    repo stars
  60. eu-code-of-conduct · mukul975-2 bundle
    Guides EU Code of Conduct adherence under GDPR Articles 40-41 including EDPB approval requirements, monitoring body accreditation, code drafting, adherence declaration, compliance verification, and complaint handling. Covers sector-specific codes, transnational codes, and Art. 40(3) approval by supervisory authorities. Keywords: code of conduct, Article 40, Article 41, EDPB, monitoring body, adherence.
    228
    repo stars
  61. gdpr-certification · mukul975-2 bundle
    Guides implementation of GDPR Article 42-43 data protection certification mechanisms including accredited certification bodies, criteria development, and periodic review. Activate when pursuing privacy certifications, evaluating certification bodies, or developing certification criteria. Keywords: certification, Article 42, Article 43, accreditation, seal, privacy mark.
    228
    repo stars
  62. gdpr-one-stop-shop · mukul975-2 bundle
    Guides the GDPR Article 56 one-stop-shop mechanism for determining lead supervisory authority in cross-border processing. Covers main establishment identification and cooperation. Activate when processing across EU borders. Keywords: one-stop-shop, Article 56, lead authority, cross-border.
    228
    repo stars
  63. gdpr-valid-consent · mukul975-2 bundle
    Guide for implementing GDPR-valid consent under Article 7 conditions and Article 4(11) definition. Covers five core requirements: freely given, specific, informed, unambiguous, and clear affirmative action. Includes pre-ticked boxes prohibition per Planet49 CJEU C-673/17, consent form audit checklist, and practical implementation patterns.
    228
    repo stars
  64. hipaa-privacy-rule · mukul975-2 bundle
    Implements HIPAA Privacy Rule requirements under 45 CFR §164.500-534 for covered entities and business associates. Covers minimum necessary standard, treatment-payment-operations exceptions, directory opt-out, personal representative rules, and authorization requirements. Keywords: HIPAA Privacy Rule, PHI, minimum necessary, TPO, authorization, covered entity.
    228
    repo stars
  65. hitech-act-privacy · mukul975-2 bundle
    Implements HITECH Act privacy and security requirements including breach notification expansion, four-tier penalty structure, state attorney general enforcement authority, EHR meaningful use privacy conditions, and business associate direct liability. Keywords: HITECH Act, breach notification, penalty tiers, state AG enforcement, meaningful use, EHR privacy.
    228
    repo stars
  66. personal-data-test · mukul975-2 bundle
    Classifies personal vs non-personal data per GDPR Art. 4(1) definition test with decision tree for borderline cases. References Breyer v Germany CJEU C-582/14 dynamic IP ruling and WP29 Opinion 4/2007. Keywords: personal data, GDPR Art 4, data classification, Breyer ruling, identifiability test, PII.
    228
    repo stars
  67. pia-review-cadence · mukul975-2 bundle
    Guides the periodic DPIA review lifecycle including trigger identification for regulatory changes, new data categories, technology changes, and breach incidents. Covers version control, stakeholder sign-off procedures, and DPIA register management per Art. 35(11). Keywords: DPIA review, PIA update, review cadence, version control, Art. 35(11), periodic review, trigger events, stakeholder sign-off.
    228
    repo stars
  68. privacy-api-design · mukul975-2 bundle
    Design privacy API patterns including data subject API for DSAR endpoints, consent API for preference management, deletion API with cascading delete orchestration, and audit API for compliance reporting. Provides OpenAPI specifications, error handling, rate limiting, and authentication patterns.
    228
    repo stars
  69. retention-schedule · mukul975-2 bundle
    Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle. Maps data categories to retention periods with legal basis justification, regulatory minimum holding periods, and automated review triggers for schedule maintenance. Activate for retention policy, storage limitation, data lifecycle, retention period queries.
    228
    repo stars
  70. ropa-250-exemption · mukul975-2 bundle
    Assesses the GDPR Article 30(5) exemption for organisations under 250 employees. Covers the three exception conditions that negate the exemption: non-occasional processing, risk to data subject rights, and special category data processing. Activate for Art. 30(5), 250 employee exemption, small business RoPA, SME exemption, occasional processing.
    228
    repo stars
  71. scc-implementation · mukul975-2 bundle
    Guides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C). Covers clause-by-clause completion, Annex I-III drafting, and SCC module selection. Keywords: SCCs, standard contractual clauses, module selection, data transfers, Annex completion.
    228
    repo stars
  72. soc2-privacy-audit · mukul975-2 bundle
    Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent, collection, use/retention/disposal, access, disclosure, security, and quality. Includes evidence collection, control testing, and report review. Keywords: SOC 2, privacy criteria, TSP, AICPA, Type II, trust services.
    228
    repo stars
  73. south-africa-popia · mukul975-2 bundle
    Implements compliance with South Africa's Protection of Personal Information Act (POPIA), Act No. 4 of 2013. Covers conditions for lawful processing, data subject rights, cross-border transfer restrictions, Information Regulator enforcement, and responsible party obligations. Keywords: POPIA, South Africa, Information Regulator, responsible party, operator, prior authorisation.
    228
    repo stars
  74. telehealth-privacy · mukul975-2 bundle
    Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors, cross-state prescribing rules, and OCR enforcement discretion during public health emergencies. Keywords: telehealth privacy, virtual care, HIPAA, recording consent, platform BAA, cross-state licensing, OCR enforcement.
    228
    repo stars
  75. us-privacy-federal · mukul975-2 bundle
    Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.
    228
    repo stars
  76. whistleblower-data · mukul975-2 bundle
    Implements data protection compliance for whistleblowing systems under EU Directive 2019/1937 and GDPR. Covers anonymous reporting channels, identity protection for whistleblowers and accused persons, retention limits, access restrictions, and retaliation prevention. Addresses national transpositions and DPA guidance. Keywords: whistleblower, Directive 2019/1937, anonymous reporting, identity protection, retaliation, retention, reporting channel.
    228
    repo stars
  77. adequacy-assessment · mukul975-2 bundle
    Guides assessment of third-country adequacy decisions under GDPR Article 45 for international data transfers. Covers the current EC adequacy decisions list, adequacy assessment criteria, partial adequacy handling, and monitoring of adequacy decision reviews. Keywords: adequacy decision, Article 45, third country, adequate protection, EC adequacy list.
    228
    repo stars
  78. age-gating-services · mukul975-2 bundle
    Implements age-gating mechanisms for online services to restrict access based on user age. Covers hard gates versus soft gates, neutral age prompts, re-verification triggers, circumvention prevention, and regulatory requirements under GDPR, COPPA, UK Online Safety Act, and DSA. Keywords: age gate, age restriction, neutral prompt, children, online services, access control.
    228
    repo stars
  79. auto-data-discovery · mukul975-2 bundle
    Implements automated PII discovery and classification using tools like Microsoft Purview, BigID, OneTrust DataDiscovery, and AWS Macie. Covers scanning schedules, accuracy tuning, false positive management, and integration patterns. Keywords: data discovery, PII scanning, Purview, BigID, Macie, OneTrust, automated classification, data cataloging.
    228
    repo stars
  80. byod-privacy-policy · mukul975-2 bundle
    Implements BYOD privacy compliance frameworks for personal device use in the workplace. Covers personal vs corporate data separation, MDM capabilities and limitations, employee consent requirements, data wiping boundaries, and monitoring restrictions on personal devices. Keywords: BYOD, mobile device management, MDM, personal device, data separation, containerisation, remote wipe, employee privacy.
    228
    repo stars
  81. consent-pref-center · mukul975-2 bundle
    Technical architecture guide for building a multi-purpose consent preference center. Covers per-purpose granularity, easy withdrawal under Article 7(3), version history, audit trails, and IAB Transparency and Consent Framework v2.2 integration. Includes database schema, API design, and UI component specifications.
    228
    repo stars
  82. double-opt-in-email · mukul975-2 bundle
    Implementation guide for ePrivacy Directive compliant double opt-in email consent. Covers confirmation email workflow design, token expiration handling, record-keeping requirements, suppression list management, and integration with CAN-SPAM Act and CASL requirements for multi-jurisdiction compliance.
    228
    repo stars
  83. dpa-inspection-prep · mukul975-2 bundle
    Guides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for key personnel, technical demonstration procedures, on-site logistics, response protocols, and post-inspection follow-up. Covers unannounced inspections, formal audits, and complaint-triggered investigations. Keywords: DPA inspection, supervisory authority, investigation, readiness, interview preparation, response protocol.
    228
    repo stars
  84. financial-retention · mukul975-2 bundle
    Implements financial records retention requirements across EU directives (5-7 years), SOX Section 802 (7 years), MiFID II (5-7 years), tax records, payment data, and AML obligations under AMLD. Maps financial data categories to statutory retention periods with cross-jurisdictional reconciliation. Activate for financial retention, SOX records, MiFID retention, AML retention, tax record keeping queries.
    228
    repo stars
  85. gdpr-accountability · mukul975-2 bundle
    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs. Activate when establishing or reviewing accountability measures, preparing evidence portfolios, or demonstrating compliance to supervisory authorities. Keywords: accountability, Article 5(2), Article 24, documentation, compliance evidence, governance.
    228
    repo stars
  86. hipaa-breach-notify · mukul975-2 bundle
    Implements HIPAA breach notification requirements under 45 CFR §164.400-414. Covers individual notification within 60 days, HHS reporting thresholds (500+ immediate, under 500 annual), state attorney general notification, media notification for 500+ in a state, and breach risk assessment. Keywords: HIPAA breach notification, HHS reporting, OCR breach portal, individual notice, state attorney general.
    228
    repo stars
  87. hipaa-mobile-health · mukul975-2 bundle
    Addresses HIPAA compliance for mobile health (mHealth) applications, wearable devices, and remote patient monitoring. Covers OCR guidance on mobile device PHI, FDA-regulated mobile medical applications, FTC Health Breach Notification Rule for non-HIPAA apps, BYOD policies, and encryption requirements for ePHI on mobile platforms. Keywords: mHealth, mobile health, HIPAA mobile, wearable, remote monitoring, BYOD, mobile device management, app privacy.
    228
    repo stars
  88. hipaa-phi-inventory · mukul975-2 bundle
    Conducts comprehensive inventory of protected health information across the enterprise per HIPAA Security Rule requirements at 45 CFR §164.308(a)(1)(ii)(A) and §164.310(d). Covers identification of all ePHI repositories, data flow mapping, classification of PHI by sensitivity, and integration with risk analysis. Keywords: PHI inventory, ePHI, data mapping, information asset, data flow, HIPAA risk analysis, designated record set.
    228
    repo stars
  89. hipaa-risk-analysis · mukul975-2 bundle
    Conducts HIPAA risk analysis per 45 CFR §164.308(a)(1) following OCR guidance methodology. Covers threat identification, vulnerability assessment, likelihood and impact determination, risk scoring, and mitigation planning for electronic protected health information. Keywords: HIPAA risk analysis, OCR guidance, threat assessment, vulnerability, risk management, ePHI.
    228
    repo stars
  90. hipaa-security-rule · mukul975-2 bundle
    Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. Covers access controls with unique user identification, emergency access procedures, automatic logoff, encryption, audit controls, integrity controls, and transmission security. Keywords: HIPAA Security Rule, ePHI, access controls, encryption, audit controls, technical safeguards.
    228
    repo stars
  91. marketing-objection · mukul975-2 bundle
    Manages the absolute right to object to direct marketing under GDPR Article 21(2)-(3), covering immediate cessation of all direct marketing processing, suppression list management, cross-channel enforcement, and profiling for marketing purposes. Activate for marketing opt-out, unsubscribe, Art. 21(2), direct marketing objection queries.
    228
    repo stars
  92. nist-pf-communicate · mukul975-2 bundle
    Implement the NIST Privacy Framework COMMUNICATE function covering CM.AW awareness raising and CM.PO communication policies. Provides transparency mechanisms, stakeholder engagement frameworks, privacy notice templates, and communication workflow guidance.
    228
    repo stars
  93. pii-in-unstructured · mukul975-2 bundle
    Detects PII in unstructured data including emails, documents, images, and logs using NER-based detection with spaCy and Microsoft Presidio, regex patterns, OCR integration, and confidence scoring. Keywords: PII detection, unstructured data, NER, spaCy, Presidio, OCR, regex, email scanning, document scanning.
    228
    repo stars
  94. pseudo-vs-anon-data · mukul975-2 bundle
    Classifies data as pseudonymised or anonymised using Recital 26 reasonably likely test, Breyer ruling C-582/14, motivated intruder test, and WP29 Opinion 05/2014 on anonymisation techniques. Covers singling out, linkability, and inference tests. Keywords: pseudonymisation, anonymisation, Recital 26, re-identification, k-anonymity, differential privacy, WP29 Opinion 05/2014.
    228
    repo stars
  95. vendor-risk-scoring · mukul975-2 bundle
    Vendor privacy risk tiering methodology for processor management. Covers scoring factors including data volume, sensitivity, transfer locations, certifications, breach history, and control maturity with weighted risk calculation and tier assignment.
    228
    repo stars
  96. ai-privacy-inference · mukul975-2 bundle
    Managing privacy risks from AI-driven inferences about individuals including derived data classification, profiling under GDPR Art. 22, inference accuracy obligations, and controlling automated personality/behaviour predictions. Keywords: AI inference, derived data, profiling, automated predictions, GDPR.
    228
    repo stars
  97. ai-transparency-reqs · mukul975-2 bundle
    Implements AI transparency requirements under EU AI Act Arts. 13-14 and GDPR Arts. 13-14. Covers user notification of AI interaction, system capability disclosure, limitation documentation, and meaningful information about automated logic. Keywords: AI transparency, EU AI Act, GDPR notification, explainability, automated decision.
    228
    repo stars
  98. audit-report-writing · mukul975-2 bundle
    Guides privacy audit report writing including executive summary drafting, findings classification (critical, high, medium, low), evidence referencing, root cause analysis documentation, recommendation formulation, management response tracking, and report distribution protocols. Covers report structure from scope definition through appendices and sign-off. Keywords: audit report, findings documentation, executive summary, recommendations, report structure, privacy audit deliverables.
    228
    repo stars
  99. breach-documentation · mukul975-2 bundle
    Maintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was required. Covers mandatory register fields including facts, effects, and remedial actions, retention periods, audit readiness, and integration with the accountability framework. Keywords: breach register, Article 33(5), breach documentation, accountability, audit readiness, remedial actions.
    228
    repo stars
  100. breach-subject-comms · mukul975-2 bundle
    Manages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in a high risk to their rights and freedoms. Covers the high risk threshold, required notification content per Art. 34(2), exemptions under Art. 34(3), and breach notification letter templates for five scenarios. Keywords: data subject notification, Article 34, high risk, breach communication, GDPR.
    228
    repo stars