all publishers

mukul975

@mukul975-2 source repo

283 published skills · page 1 of 3

  1. ▌
    Age Verification Methods · mukul975-2 bundle
    Evaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
    228 repo stars
  2. ▌
    AI Bias Special Category · mukul975-2 bundle
    Assesses AI bias risks for GDPR Art. 9 special category data and AI Act Art. 10 data governance. Covers fairness metrics, bias detection methods, mitigation strategies, and documentation requirements for protected characteristics. Keywords: AI bias, special category, fairness metrics, discrimination, Art. 9, Art. 10.
    228 repo stars
  3. ▌
    Analytics Cookie Consent · mukul975-2 bundle
    Managing consent for analytics cookies and implementing privacy-preserving measurement. Covers GA4 privacy configuration, consent mode fallback behavior, aggregate reporting alternatives, and cookieless measurement approaches.
    228 repo stars
  4. ▌
    Background Check Privacy · mukul975-2 bundle
    Manages privacy compliance for employee background checks including criminal record processing under Art. 10 GDPR, DBS checks (UK), national law variations, and reference verification. Applies proportionality and data minimisation to pre-employment screening, defines retention limits, and addresses role-based necessity assessments. Keywords: background check, criminal record, Art. 10, DBS, pre-employment screening, vetting, data minimisation, proportionality.
    228 repo stars
  5. ▌
    Backup Retention Erasure · mukul975-2 bundle
    Manages backup and archive data under retention schedules and erasure obligations. Covers the technical infeasibility exception for backup deletion, backup cycle alignment with retention periods, restore-and-delete procedures, and interim protective measures during backup retention. Activate for backup deletion, archive erasure, backup retention, restore and delete, technical infeasibility queries.
    228 repo stars
  6. ▌
    Breach Response Playbook · mukul975-2 bundle
    Builds a comprehensive breach response team playbook defining CSIRT and privacy team structure with named roles (incident commander, legal counsel, communications, IT forensics, DPO), escalation matrices, communication templates, pre-negotiated vendor contacts, and regulatory authority contacts organized by jurisdiction. Keywords: breach response playbook, CSIRT, incident response team, escalation matrix, communication templates, vendor contacts.
    228 repo stars
  7. ▌
    Controller Ropa Creation · mukul975-2 bundle
    Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and contact details, processing purposes, data subject categories, personal data categories, recipient categories, third country transfers, and retention periods. Includes Python generator for automated RoPA creation. Activate for controller RoPA, Art. 30(1), processing records, data mapping.
    228 repo stars
  8. ▌
    Cross Jurisdiction Class · mukul975-2 bundle
    Harmonises data classification across jurisdictions mapping GDPR special categories vs CCPA sensitive PI (1798.140(ae)) vs HIPAA PHI (160.103) vs LGPD sensitive data (Art. 5-II). Provides cross-regulation mapping matrix for multinational compliance. Keywords: cross-jurisdiction, GDPR, CCPA, HIPAA, LGPD, sensitive data, multinational, classification mapping.
    228 repo stars
  9. ▌
    Direct Collection Notice · mukul975-2 bundle
    Provides GDPR Article 13 information at the point of direct data collection, covering all required elements under Art. 13(1)(a)-(f) and Art. 13(2)(a)-(g), layered notice design, and timing requirements. Activate for Art. 13, direct collection notice, privacy notice at collection, data collection information queries.
    228 repo stars
  10. ▌
    Dpia Automated Decisions · mukul975-2 bundle
    Conducts a Data Protection Impact Assessment for automated decision-making and profiling systems under GDPR Article 35(3)(a), covering algorithmic transparency, meaningful human oversight, contestation mechanisms, and Art. 22 safeguards. Activate for DPIA automated decision, profiling DPIA, algorithmic impact assessment, Art. 35(3)(a), ADM risk assessment queries.
    228 repo stars
  11. ▌
    Dpia Stakeholder Consult · mukul975-2 bundle
    Guides data subject and stakeholder consultation requirements during Data Protection Impact Assessments under GDPR Article 35(9). Covers consultation planning, data subject engagement methods, DPO involvement per Art. 35(2), and documentation of views received. Keywords: DPIA consultation, stakeholder engagement, Art. 35(9), data subject views, DPO advice, public consultation, representative groups.
    228 repo stars
  12. ▌
    Employee Monitoring Dpia · mukul975-2 bundle
    Conducts Data Protection Impact Assessments for employee monitoring systems per EDPB Guidelines 3/2019 on workplace data processing. Covers video surveillance, email monitoring, GPS tracking, keystroke logging, and productivity tools. Applies proportionality testing under Art. 35 GDPR. Keywords: DPIA, employee monitoring, surveillance, proportionality, EDPB, workplace privacy, keystroke logging, GPS tracking.
    228 repo stars
  13. ▌
    Gdpr Remediation Roadmap · mukul975-2 bundle
    Guides conversion of gap analysis findings into phased implementation plans with milestones and risk-based prioritisation. Activate when building compliance programmes or allocating privacy budgets. Keywords: remediation roadmap, implementation plan, phased approach, prioritisation.
    228 repo stars
  14. ▌
    Hr System Privacy Config · mukul975-2 bundle
    Configures privacy settings for enterprise HR systems including SAP SuccessFactors, Workday, and BambooHR. Covers role-based access controls, automated data retention enforcement, cross-border transfer configurations, audit logging, data subject rights facilitation, and field-level security. Keywords: HR system, SAP SuccessFactors, Workday, BambooHR, RBAC, retention automation, cross-border transfer, privacy configuration.
    228 repo stars
  15. ▌
    Marketing Analytics Dpia · mukul975-2 bundle
    Guides DPIA for marketing profiling, behavioural targeting, cross-device tracking, and advertising analytics. Covers ePrivacy Directive Art. 5(3) cookie consent, PECR regulations, legitimate interest balancing for direct marketing, and adtech processing chain assessment. Keywords: marketing analytics, DPIA, profiling, behavioural targeting, cross-device tracking, ePrivacy, PECR, adtech, legitimate interest.
    228 repo stars
  16. ▌
    Privacy Law Gap Analysis · mukul975-2 bundle
    Guides conducting privacy law gap analysis for market entry into new jurisdictions. Covers target jurisdiction assessment, existing compliance mapping, remediation effort estimation, and implementation timeline planning. Keywords: gap analysis, market entry, jurisdiction assessment, remediation planning, compliance mapping.
    228 repo stars
  17. ▌
    Retention Exception Mgmt · mukul975-2 bundle
    Manages retention exception workflows including request-approval processes, duration limits, periodic review cycles, documentation requirements, and audit trail maintenance. Covers legitimate grounds for extending retention beyond scheduled periods and governance controls to prevent indefinite data hoarding. Activate for retention exception, retention extension, data hoarding prevention, retention override queries.
    228 repo stars
  18. ▌
    Ropa Executive Dashboard · mukul975-2 bundle
    Creates executive reporting and visualization from RoPA data including processing activity counts, risk heatmaps, compliance scores, trend analysis, and supervisory authority readiness indicators. Activate for RoPA dashboard, executive reporting, risk heatmap, compliance score, trend analysis, board reporting, KPI.
    228 repo stars
  19. ▌
    Sub Processor Management · mukul975-2 bundle
    GDPR Article 28(2) sub-processor approval workflow management. Covers prior specific and general authorization mechanisms, change notification procedures, objection windows, flow-down obligation enforcement, and sub-processor chain risk monitoring.
    228 repo stars
  20. ▌
    Anonymization Alternative · mukul975-2 bundle
    Evaluates anonymization as a retention alternative under GDPR Recital 26, applying the WP29 Opinion 05/2014 techniques including randomization and generalization. Validates anonymization effectiveness using k-anonymity, l-diversity, and t-closeness metrics. Activate for anonymization, de-identification, k-anonymity, retention alternative queries.
    228 repo stars
  21. ▌
    Audit Remediation Program · mukul975-2 bundle
    Guides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking, verification testing, closure criteria, escalation protocols, and management reporting. Covers remediation lifecycle from finding issuance to verified closure. Keywords: audit remediation, finding management, prioritization, verification testing, closure criteria, remediation tracking.
    228 repo stars
  22. ▌
    Automated Decision Rights · mukul975-2 bundle
    Manages GDPR Article 22 rights related to solely automated decision-making and profiling, including identification of automated decisions, meaningful human oversight implementation, logic explanation requirements, and contestation mechanisms. Activate for automated decision, profiling, Art. 22, algorithmic decision, AI decision queries.
    228 repo stars
  23. ▌
    Automated Ropa Generation · mukul975-2 bundle
    Generates Records of Processing Activities automatically from IT system inventories including Active Directory, cloud service catalogs, API gateway logs, and database schemas. Covers automated field population, data flow discovery, and system-to-RoPA mapping. Activate for automated RoPA, system inventory, data discovery, auto-population, IT-driven records.
    228 repo stars
  24. ▌
    Breach Multi Jurisdiction · mukul975-2 bundle
    Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notification laws (varying timelines from 30 to 90 days), and other international regimes. Covers conflict resolution when notification timelines differ, lead supervisory authority determination, and parallel notification execution. Keywords: multi-jurisdiction, cross-border breach, notification coordination, GDPR, US state laws, international breach notification.
    228 repo stars
  25. ▌
    Children Profiling Limits · mukul975-2 bundle
    Implements profiling restrictions for children under GDPR Recital 71, Article 22, UK AADC Standard 12, and COPPA. Covers prohibition of behavioural advertising to children, recommendation algorithm limitations, nudge technique prohibition, and automated decision-making safeguards. Keywords: profiling, children, behavioural advertising, recommendation algorithm, AADC, automated decision.
    228 repo stars
  26. ▌
    Cloud Provider Assessment · mukul975-2 bundle
    Cloud service provider privacy assessment framework. Covers ISO 27018 cloud privacy controls, CSA STAR certification, SOC 2 Type II evaluation, shared responsibility model mapping, data residency verification, and cloud-specific privacy risk analysis.
    228 repo stars
  27. ▌
    Differential Privacy Prod · mukul975-2 bundle
    Deploy differential privacy in production systems including epsilon selection strategies, noise calibration with Laplace and Gaussian mechanisms, privacy budget tracking, composition theorems, and Python implementation patterns. Covers both central and local differential privacy models.
    228 repo stars
  28. ▌
    Edtech Privacy Assessment · mukul975-2 bundle
    Assesses children's data protection in educational technology. Covers COPPA school exception under Section 312.5(c)(4), FERPA intersection, parental rights, teacher consent authority, data deletion at year-end, and Student Privacy Pledge compliance. Keywords: edtech, COPPA school exception, FERPA, student privacy, teacher consent, educational data.
    228 repo stars
  29. ▌
    Employment Consent Limits · mukul975-2 bundle
    Analyses the limitations on consent as a lawful basis for processing employee data under Art. 88 GDPR and WP29 Opinion 2/2017. Addresses power imbalance in employment relationships, identifies alternative lawful bases, and maps national derogations. Keywords: consent, employment, power imbalance, Art. 88, WP29, lawful basis, employee data, labour law.
    228 repo stars
  30. ▌
    Gdpr Certification Scheme · mukul975-2 bundle
    Guides GDPR certification mechanism implementation per Articles 42-43 including accredited certification body selection, certification criteria per EDPB guidelines, certification scope, periodic audit requirements, seal and mark usage rules, and relationship to codes of conduct. Covers EDPB/ENISA certification framework and national accreditation. Keywords: GDPR certification, Article 42, Article 43, certification body, EDPB, seal, mark, accreditation.
    228 repo stars
  31. ▌
    Hipaa Breach Notification · mukul975-2 bundle
    Executes breach notification under HIPAA Breach Notification Rule (45 CFR 164.400-414). Covers 60-day individual notification, HHS/OCR reporting for breaches of 500+ individuals (immediate) and under 500 (annual log), state attorney general notification, media notification for 500+ in a single state, and breach risk assessment using the four-factor test. Keywords: HIPAA, breach notification, PHI, HHS, OCR, covered entity, business associate.
    228 repo stars
  32. ▌
    Legit Interest Vs Consent · mukul975-2 bundle
    Decision framework for choosing between consent and legitimate interest as the lawful basis for processing. Covers power imbalance indicators, conditionality prohibition under Article 7(4), granularity requirements, the three-part LIA test (purpose, necessity, balancing), and practical decision trees for common scenarios.
    228 repo stars
  33. ▌
    Multi Jurisdiction Matrix · mukul975-2 bundle
    Guides building a multi-jurisdiction privacy compliance matrix for organisations operating across multiple countries. Covers common requirements identification, jurisdiction-specific deltas, gap analysis, and harmonised control frameworks. Keywords: multi-jurisdiction, compliance matrix, harmonised controls, gap analysis, jurisdiction mapping.
    228 repo stars
  34. ▌
    Privacy Metrics Dashboard · mukul975-2 bundle
    Build privacy KPI dashboards tracking DSAR volume and response time, breach count and severity, DPIA completion rate, training coverage, and consent rates. Includes metric definitions, data collection patterns, visualization designs, and executive reporting templates for privacy program measurement.
    228 repo stars
  35. ▌
    Restriction Of Processing · mukul975-2 bundle
    Handles GDPR Article 18 right to restriction of processing requests, covering the four grounds for restriction (accuracy contest, unlawful processing, erasure opposition, legitimate interest pending), technical flagging mechanisms, and lifting procedures. Activate for restriction request, Art. 18, processing freeze queries.
    228 repo stars
  36. ▌
    Ropa Maintenance Workflow · mukul975-2 bundle
    Establishes ongoing RoPA maintenance processes including update triggers, change management integration, version control, stakeholder review cycles, and completeness verification procedures. Activate for RoPA updates, record maintenance, change management, version history, review scheduling.
    228 repo stars
  37. ▌
    Transparent Communication · mukul975-2 bundle
    Implements GDPR Article 12 transparent information and communication requirements, covering concise, intelligible, and plain language obligations, response timelines, fee and refusal provisions, and layered notice design. Activate for transparent communication, Art. 12, privacy notice, plain language, response timeline queries.
    228 repo stars
  38. ▌
    Vendor Monitoring Program · mukul975-2 bundle
    Ongoing vendor privacy compliance monitoring program. Covers annual reassessment procedures, continuous monitoring signals, contract renewal privacy triggers, performance metrics, KPIs, and vendor governance reporting dashboards.
    228 repo stars
  39. ▌
    AI Privacy Impact Template · mukul975-2 bundle
    Provides combined DPIA and AI Act conformity assessment template with integrated risk scoring matrix. Covers GDPR Art. 35 DPIA elements, AI Act high-risk system requirements, mitigation measures, and human oversight assessment. Keywords: DPIA template, conformity assessment, risk scoring, AI Act, combined assessment, high-risk AI.
    228 repo stars
  40. ▌
    California Consumer Rights · mukul975-2 bundle
    California consumer privacy rights workflow implementation under CCPA/CPRA. Covers right to know, delete, opt-out of sale/sharing, correct, and limit sensitive PI processing. Includes 45-day response timelines, identity verification procedures, and authorized agent handling.
    228 repo stars
  41. ▌
    Children Data Minimization · mukul975-2 bundle
    Implements strict data minimization and retention limits for children's personal data under GDPR Art. 5(1)(c), Recital 38, UK AADC Standard 8, and COPPA Section 312.7. Covers strict necessity testing, shorter retention periods, limited profiling, parental dashboard design, and automated deletion. Keywords: data minimization, children, retention, necessity test, parental dashboard.
    228 repo stars
  42. ▌
    Children Deletion Requests · mukul975-2 bundle
    Manages deletion requests for children's personal data. Covers parental-initiated versus child-initiated requests, age of capacity assessment, identity verification, scope determination, third-party notification obligations, and regulatory timelines under GDPR Art. 17, COPPA Section 312.6, and UK AADC Standard 15. Keywords: deletion, children, right to erasure, parental request, data deletion, COPPA.
    228 repo stars
  43. ▌
    Cross Jurisdiction Cookies · mukul975-2 bundle
    Implementing cookie compliance across multiple jurisdictions including EU ePrivacy Directive, UK PECR, US California CCPA/CPRA opt-out model, and Brazil LGPD. Provides a requirements matrix and geolocation-based implementation approach.
    228 repo stars
  44. ▌
    Employee Surveillance Dpia · mukul975-2 bundle
    Guides DPIA for workplace monitoring including email surveillance, internet usage monitoring, CCTV, GPS tracking, and keystroke logging. Covers GDPR Art. 88 employment context provisions, WP29 Opinion 2/2017 on data processing at work, and proportionality balancing for employee monitoring. Keywords: employee surveillance, workplace monitoring, DPIA, Art. 88, WP29 Opinion 2/2017, CCTV, email monitoring, GPS tracking.
    228 repo stars
  45. ▌
    Eprivacy Essential Cookies · mukul975-2 bundle
    Applying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent. Covers exemption criteria, functionality cookies, load balancing, session state, and non-exempt categories with regulatory guidance from EDPB and national DPAs.
    228 repo stars
  46. ▌
    Indirect Collection Notice · mukul975-2 bundle
    Provides GDPR Article 14 information for personal data obtained from sources other than the data subject, covering timing requirements (within reasonable period, max one month), source disclosure, all required elements, and exemptions under Art. 14(5). Activate for Art. 14, indirect collection, third-party data source, indirect data notice queries.
    228 repo stars
  47. ▌
    Privacy Threshold Analysis · mukul975-2 bundle
    Guides the Privacy Threshold Analysis screening process to determine whether a full DPIA is required. Provides a quick-screen questionnaire, threshold criteria based on WP248rev.01, escalation triggers, and documentation requirements. Activate when evaluating new processing activities, system changes, or procurement decisions. Keywords: PTA, privacy threshold analysis, DPIA screening, quick-screen, threshold criteria, WP248, escalation triggers.
    228 repo stars
  48. ▌
    Transfer Impact Assessment · mukul975-2 bundle
    Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers destination country surveillance law assessment, European Essential Guarantees evaluation, and supplementary measures determination. Keywords: TIA, transfer impact assessment, Schrems II, EDPB recommendations, supplementary measures.
    228 repo stars
  49. ▌
    Comparing Pia Methodologies · mukul975-2 bundle
    Compares PIA/DPIA methodologies: CNIL PIA tool, ICO DPIA template, NIST Privacy Framework, and ISO 29134. Provides methodology selection criteria based on regulatory jurisdiction, organisation maturity, processing complexity, and resource availability. Covers regulatory acceptance, tool features, and cross-methodology mapping. Keywords: PIA methodology, CNIL, ICO, NIST Privacy Framework, ISO 29134, DPIA comparison, assessment.
    228 repo stars
  50. ▌
    Managing Mobile App Consent · mukul975-2 bundle
    Guide for mobile-specific consent management covering Apple ATT framework for iOS, Android permission model, in-app consent flows, SDK consent propagation to third-party libraries, and IDFA/GAID handling. Addresses platform-specific requirements alongside GDPR and ePrivacy compliance for mobile applications.
    228 repo stars
  51. ▌
    Vendor Privacy Due Diligence · mukul975-2 bundle
    Pre-contract vendor privacy due diligence per GDPR Article 28(1). Covers risk questionnaires, technical controls assessment, certification review, data flow analysis, and documented sufficiency decisions for processor engagement.
    228 repo stars
  52. ▌
    Managing Consent For Children · mukul975-2 bundle
    Guide for managing consent for children's personal data under GDPR Article 8 and COPPA. Covers parental consent mechanisms, age verification methods, country-specific age thresholds (ranging from 13 to 16), parental authorization workflows, and age-appropriate design per the UK ICO Children's Code.
    228 repo stars
  53. ▌
    Managing Consent For Research · mukul975-2 bundle
    Guide for managing consent for scientific research under GDPR Article 89 and Recital 33 broad consent provisions. Covers ethical review board coordination, purpose evolution management, appropriate safeguards including pseudonymization, and the interplay between consent and other lawful bases for research processing.
    228 repo stars
  54. ▌
    Applying Privacy Design Patterns · mukul975-2 bundle
    Systematic application of the eight privacy design patterns per Hoepman: minimize, hide, separate, abstract, inform, control, enforce, and demonstrate. Covers pattern selection methodology per processing activity, mapping to GDPR principles, and practical implementation guidance for privacy-by-design system architecture.
    228 repo stars
  55. ▌
    Preparing Iso 31700 Certification · mukul975-2 bundle
    Preparation guide for ISO 31700 privacy by design for consumer goods certification. Covers the 30 requirements across design, production, and disposal phases. Includes gap assessment methodology, remediation planning, and mapping to GDPR Article 25 data protection by design obligations for consumer-facing products and services.
    228 repo stars
  56. ▌
    Conducting Linddun Threat Modeling · mukul975-2 bundle
    Complete guide to LINDDUN privacy threat modeling methodology covering seven threat categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance. Includes DFD-based analysis, threat tree catalogs, mitigation mapping to privacy design patterns, and step-by-step process.
    228 repo stars
  57. ▌
    Implementing Homomorphic Encryption · mukul975-2 bundle
    Guide to implementing homomorphic encryption for privacy-preserving computation under GDPR. Covers scheme selection (BFV, BGV, CKKS, TFHE), Microsoft SEAL, IBM HELib, and Google FHE transpiler. Includes performance benchmarks, parameter tuning, and basic HE example code for encrypted arithmetic operations.
    228 repo stars
  58. ▌
    Automating Storage Limitation Controls · mukul975-2 bundle
    Automated enforcement of GDPR Article 5(1)(e) storage limitation principle. Covers TTL-based deletion, retention policy engines, archival workflows, legal hold exemptions, and lifecycle automation. Includes technical implementation patterns for automated data expiry and defensible deletion across distributed systems.
    228 repo stars
  59. ▌
    Designing Privacy Preserving Analytics · mukul975-2 bundle
    Design privacy-preserving analytics systems using differential privacy, k-anonymity, l-diversity, and t-closeness. Covers privacy budget allocation with epsilon tracking, references Google DP library, OpenDP, and Apple PPML. Includes Python differential privacy implementation for GDPR-compliant statistical analysis.
    228 repo stars
  60. ▌
    Building Purpose Limitation Enforcement · mukul975-2 bundle
    Technical enforcement of GDPR Article 5(1)(b) purpose limitation principle. Covers purpose-tagged data stores, access control per purpose, Article 6(4) compatibility assessment factors, and system design for preventing purpose creep. Includes purpose binding architecture and compatibility test implementation.
    228 repo stars
  61. ▌
    Implementing Data Protection By Default · mukul975-2 bundle
    Technical implementation of GDPR Article 25(2) data protection by default. Covers strictest privacy settings as default configuration, minimum data collection, limited storage duration, restricted accessibility, and opt-in rather than opt-out patterns. Includes implementation checklist and system design requirements.
    228 repo stars
  62. ▌
    Selecting Privacy Enhancing Technologies · mukul975-2 bundle
    Comprehensive PET selection guide covering differential privacy, homomorphic encryption, secure multi-party computation, federated learning, zero-knowledge proofs, and trusted execution environments. Includes use-case matching matrix, performance comparison, and GDPR alignment assessment for each technology.
    228 repo stars
  63. ▌
    Designing Federated Learning Architecture · mukul975-2 bundle
    Architecture guide for GDPR-compliant federated learning systems. Covers horizontal and vertical FL, aggregation strategies (FedAvg, FedProx), communication efficiency, secure aggregation, and differential privacy integration. Includes privacy guarantees analysis and deployment patterns for cross-organizational ML without data sharing.
    228 repo stars
  64. ▌
    Implementing Data Minimization Architecture · mukul975-2 bundle
    Architecture patterns for GDPR Article 5(1)(c) data minimization and Article 25(1) data protection by design. Covers field-level encryption, data masking, aggregation, pseudonymization per Article 4(5), and anonymization per Recital 26. Includes ENISA pseudonymization techniques and a data minimization assessment matrix.
    228 repo stars
  65. ▌
    Implementing Secure Multi Party Computation · mukul975-2 bundle
    Implementation guide for secure multi-party computation enabling privacy-preserving analytics across organizations. Covers secret sharing, garbled circuits, reference frameworks MP-SPDZ and CrypTen, practical deployment patterns, and GDPR alignment for joint controller analytics without revealing individual party inputs.
    228 repo stars
  66. ▌
    Performing Transfer Impact Assessment · mukul975-2 bundle
    Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers assessment of third country legal frameworks, supplementary measures evaluation, and TIA scoring. Activate for international data transfers, SCCs, third-country adequacy, or Chapter V compliance. Keywords: TIA, Schrems II, transfer assessment, EDPB, supplementary measures, SCCs, international transfer.
    228 repo stars
  67. ▌
    Ccpa Cpra Compliance · mukul975-2 bundle
    Complete CCPA/CPRA compliance implementation covering California Civil Code §1798.100-199. Includes consumer rights framework, business obligations, service provider and contractor requirements, enforcement mechanisms, and CPPA rulemaking. Triggers on CCPA, CPRA, California privacy, consumer rights.
    228 repo stars
  68. ▌
    Ccpa Right To Delete · mukul975-2 bundle
    Implements CCPA Section 1798.105 right to delete and CPRA amendments including service provider obligations, statutory exceptions for legal, security, and internal uses, consumer identity verification procedures, and 45-day response timeline management. Activate for CCPA deletion, CPRA right to delete, California privacy, consumer deletion queries.
    228 repo stars
  69. ▌
    Cloud Migration Dpia · mukul975-2 bundle
    Guides DPIA for migrating personal data to cloud infrastructure covering controller-processor analysis under Art. 28, international transfer assessment, encryption requirements, and shared responsibility model evaluation. Activate for cloud adoption, SaaS procurement, or data centre migration projects. Keywords: cloud migration, DPIA, Art. 28, processor, encryption, shared responsibility, SaaS, IaaS, PaaS.
    228 repo stars
  70. ▌
    Conducting Gdpr Dpia · mukul975-2 bundle
    Guides the end-to-end GDPR Data Protection Impact Assessment process under Article 35, including mandatory trigger identification per Art. 35(3), DPIA content requirements per Art. 35(7), and EDPB WP248rev.01 methodology. Activate for systematic profiling, large-scale special category processing, or large-scale public monitoring. Keywords: DPIA, Article 35, impact assessment, WP248, data protection, risk assessment.
    228 repo stars
  71. ▌
    Consent Receipt Spec · mukul975-2 bundle
    Implement the Kantara Initiative consent receipt specification including machine-readable receipt structure, JWT-based verification mechanisms, receipt lifecycle management, and integration patterns for consent management platforms. Supports ISO/IEC 27560 consent record information structure.
    228 repo stars
  72. ▌
    Cpra Opt Out Signals · mukul975-2 bundle
    Implements CPRA Section 1798.135 opt-out preference signal handling, covering Global Privacy Control (GPC) technical detection, automated signal honoring, cross-device consistency, and the relationship between browser signals and explicit consumer choices. Activate for GPC, opt-out preference signal, CPRA 1798.135, browser privacy signal, Do Not Sell queries.
    228 repo stars
  73. ▌
    Data Labeling System · mukul975-2 bundle
    Implements data classification labels and tagging systems including metadata tagging, DLP integration, automated label propagation, user-applied labels, and label inheritance rules. Covers Microsoft Purview sensitivity labels and enterprise labeling architecture. Keywords: data labeling, sensitivity labels, metadata tagging, DLP integration, label propagation, Purview, classification.
    228 repo stars
  74. ▌
    Dpia Mitigation Plan · mukul975-2 bundle
    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d). Covers mitigation measure identification, implementation tracking, residual risk acceptance, and Art. 36 prior consultation triggers. Keywords: DPIA mitigation, risk treatment, residual risk, Art. 35(7)(d), safeguards, mitigation tracking, prior consultation.
    228 repo stars
  75. ▌
    Employee Health Data · mukul975-2 bundle
    Governs employee health data processing for fitness-for-work assessments, occupational health surveillance, COVID testing legacy programmes, and absence management. Applies Art. 9(2)(b) employment obligations and Art. 9(2)(h) health professional exceptions. Covers data minimisation, occupational health provider relationships, and return-to-work procedures. Keywords: health data, Art. 9, occupational health, fitness-for-work, special category, employment, sickness absence.
    228 repo stars
  76. ▌
    Eu Us Dpf Assessment · mukul975-2 bundle
    Guides assessment and use of the EU-US Data Privacy Framework adequacy decision for transatlantic data transfers. Covers DPF self-certification with the Department of Commerce, DPF principles compliance, Data Protection Review Court, and annual EC review. Keywords: DPF, EU-US, adequacy, Privacy Shield, transatlantic transfers.
    228 repo stars
  77. ▌
    Gdpr Dpa Cooperation · mukul975-2 bundle
    Guides cooperation with GDPR supervisory authorities under Article 31, including procedures for responding to investigations, information requests, and on-site inspections. Covers controller and processor obligations during supervisory authority interactions. Keywords: supervisory authority, Article 31, cooperation, DPA investigation, information request, inspection.
    228 repo stars
  78. ▌
    Gdpr Self Assessment · mukul975-2 bundle
    Guides comprehensive controller self-assessment covering GDPR Articles 5-49 with scoring methodology and reporting format. Activate when conducting internal reviews or benchmarking maturity. Keywords: self-assessment, controller assessment, compliance questionnaire, scoring.
    228 repo stars
  79. ▌
    Group Structure Ropa · mukul975-2 bundle
    Manages RoPA for complex multi-entity corporate groups including entity-level versus group-level records, intra-group transfer documentation, and shared processing coordination. Activate for group RoPA, multi-entity, corporate group, intra-group transfers, subsidiary records, holding company.
    228 repo stars
  80. ▌
    Hipaa Baa Management · mukul975-2 bundle
    Manages HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e). Covers required BAA provisions, business associate vs subcontractor obligations, breach notification chain, downstream BA requirements, and termination remedies. Keywords: BAA, business associate, subcontractor, HIPAA compliance, PHI disclosure, termination.
    228 repo stars
  81. ▌
    Linddun Threat Model · mukul975-2 bundle
    Conduct LINDDUN privacy threat modeling across all seven categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance. Includes DFD-based analysis, threat trees, privacy-specific mitigation strategies, and integration with STRIDE security threat modeling.
    228 repo stars
  82. ▌
    Litigation Hold Mgmt · mukul975-2 bundle
    Manages legal hold and data preservation processes including triggering events, custodian notification, hold-in-place technical implementation, release procedures, and interaction with retention schedules. Covers litigation hold registers, compliance monitoring, and Art. 17(3)(e) exception documentation. Activate for legal hold, litigation preservation, data freeze, e-discovery hold queries.
    228 repo stars
  83. ▌
    Privacy Data Sharing · mukul975-2 bundle
    Build privacy-preserving data sharing platforms using synthetic data generation with the SDV library, data clean rooms, secure enclaves, and utility measurement. Covers end-to-end architecture for sharing analytical datasets while preserving individual privacy guarantees.
    228 repo stars
  84. ▌
    Purpose Based Access · mukul975-2 bundle
    Design and implement Purpose-Based Access Control (PBAC) architecture including purpose ontology definition, policy engine configuration, audit logging of purpose verification at query time, and integration with existing IAM systems. Enforces GDPR Article 5(1)(b) purpose limitation technically.
    228 repo stars
  85. ▌
    Server Side Tracking · mukul975-2 bundle
    Implementing server-side tracking with privacy controls using Google Tag Manager server containers. Covers first-party data collection, IP anonymization, consent-aware event forwarding, and reducing client-side third-party cookie exposure.
    228 repo stars
  86. ▌
    Vendor Privacy Audit · mukul975-2 bundle
    On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classification, remediation tracking, and audit report generation for processor compliance verification.
    228 repo stars
  87. ▌
    AI Act High Risk Docs · mukul975-2 bundle
    Preparing EU AI Act compliance documentation for high-risk AI systems. Covers Annex III classification, technical documentation under Art. 11, conformity assessment, risk management systems, and CE marking requirements. Keywords: EU AI Act, high-risk AI, Annex III, conformity assessment, CE marking.
    228 repo stars
  88. ▌
    AI Federated Learning · mukul975-2 bundle
    Implements federated learning architecture patterns for GDPR compliance. Covers secure aggregation protocols, differential privacy integration, communication protocols, and privacy-by-design distributed ML training. Keywords: federated learning, distributed training, secure aggregation, differential privacy, privacy-preserving ML.
    228 repo stars
  89. ▌
    AI Privacy Assessment · mukul975-2 bundle
    Guides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
    228 repo stars
  90. ▌
    AI Vendor Privacy Due · mukul975-2 bundle
    Determines controller-processor relationships for AI services and conducts privacy due diligence. Covers SaaS AI (processor), embedded AI (joint controller), API-based AI (assessment framework), and vendor risk assessment. Keywords: AI vendor, controller-processor, due diligence, SaaS AI, joint controller, Art. 28.
    228 repo stars
  91. ▌
    Audit Risk Assessment · mukul975-2 bundle
    Guides privacy audit risk assessment including risk universe development, inherent and residual risk scoring, control effectiveness evaluation, risk-based audit planning, heat map generation, risk appetite alignment, and audit prioritization by risk exposure. Covers the full audit risk assessment cycle from scoping through ongoing monitoring. Keywords: audit risk assessment, risk universe, inherent risk, residual risk, control effectiveness, risk-based audit planning.
    228 repo stars
  92. ▌
    Australia Privacy Act · mukul975-2 bundle
    Guides compliance with Australia's Privacy Act 1988 including the 2024 reform amendments. Covers automated decision-making transparency, children's privacy code, individual rights expansion, enforcement strengthening, and the Australian Privacy Principles (APPs). Keywords: Australia Privacy Act, APPs, OAIC, automated decisions, children privacy code, privacy reform.
    228 repo stars
  93. ▌
    Breach Credit Monitor · mukul975-2 bundle
    Coordinates credit monitoring and identity theft protection services for individuals affected by a data breach. Covers vendor selection criteria, enrollment logistics, coverage duration (12-24 months), identity theft insurance options, communication to affected individuals, and enrollment rate tracking. Keywords: credit monitoring, identity protection, breach response, Experian, enrollment, identity theft insurance.
    228 repo stars
  94. ▌
    Classification Policy · mukul975-2 bundle
    Develops data classification policies with tiered handling (public, internal, confidential, restricted), labeling requirements, enforcement mechanisms, and procedures per tier. Covers policy governance, exception handling, and compliance monitoring. Keywords: classification policy, data tiers, handling procedures, labeling, enforcement, data governance, information security.
    228 repo stars
  95. ▌
    Conflicting Laws Mgmt · mukul975-2 bundle
    Guides managing conflicting privacy requirements across jurisdictions. Covers data localisation vs transfer freedom, consent standards variation, age thresholds, breach timelines, and resolution frameworks for incompatible obligations. Keywords: conflicting laws, data localisation, consent variation, age thresholds, resolution framework.
    228 repo stars
  96. ▌
    Consent For Transfers · mukul975-2 bundle
    Guide for obtaining explicit consent for international data transfers under GDPR Article 49(1)(a). Covers informed consent requirements including risks of transfers without adequacy decisions or appropriate safeguards, specific destination country disclosure, and the narrow scope of derogation-based transfers.
    228 repo stars
  97. ▌
    Consent Platform Eval · mukul975-2 bundle
    Framework for evaluating and selecting Consent Management Platforms (CMPs). Covers TCF v2.2 certification requirements, Global Privacy Control support, multi-regulation compliance (GDPR, CCPA, LGPD), A/B testing capabilities, API integration options, reporting features, and a structured vendor comparison methodology.
    228 repo stars
  98. ▌
    Continuous Compliance · mukul975-2 bundle
    Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation workflows, regulatory change integration, and deviation management. Covers GRC platform configuration, control framework mapping, and compliance-as-code approaches. Keywords: continuous compliance, automated monitoring, evidence collection, dashboard, regulatory change, compliance-as-code.
    228 repo stars
  99. ▌
    Cookie Lifetime Audit · mukul975-2 bundle
    Auditing cookie lifetimes against regulatory recommendations and browser policies. Covers CNIL 13-month maximum recommendation, session vs persistent classification, third-party cookie phase-out impact, and Safari ITP duration caps.
    228 repo stars
  100. ▌
    Data Lineage Tracking · mukul975-2 bundle
    Implements data lineage tracking for privacy compliance including origin tracking, transformation logging, access auditing, deletion verification, and cross-system lineage graphs. Covers source-to-sink mapping, GDPR Art. 30 RoPA integration, automated lineage discovery, and breach impact scoping. Keywords: data lineage, data provenance, data flow mapping, transformation logging, deletion verification.
    228 repo stars