mukul975
- 283 skills
- 0 followers
- 228 repo stars
- last month last updated
- ▌ Gdpr Codes Of Conduct · mukul975-2 bundleGuides development of GDPR Article 40-41 codes of conduct for industry sectors including drafting, submission, and monitoring body requirements. Activate when creating industry codes or establishing monitoring bodies. Keywords: codes of conduct, Article 40, Article 41, monitoring body, industry code.
- ▌ Gdpr Compliance Audit · mukul975-2 bundleGuides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37. Includes 50+ control points covering principles, accountability, security, and governance. Activate when performing compliance audits, preparing for supervisory authority inspections, or assessing organisational GDPR maturity. Keywords: data protection audit, compliance audit, GDPR audit, control points, accountability.
- ▌ Gdpr Parental Consent · mukul975-2 bundleImplements GDPR Article 8 parental consent verification for information society services offered to children. Covers age thresholds by EU/EEA Member State (13-16 years), EDPB Guidelines 5/2020 on consent, parental verification mechanisms, and consent record-keeping. Keywords: parental consent, Article 8, children, age threshold, EDPB, verification.
- ▌ Gdpr Policy Framework · mukul975-2 bundleGuides creation of organisational privacy policy hierarchy aligned to GDPR chapters including top-level policy, supporting procedures, operational guidelines, and training materials. Activate when building or updating policy frameworks. Keywords: policy framework, privacy policy, procedures, guidelines, policy hierarchy.
- ▌ Healthcare AI Privacy · mukul975-2 bundleAddresses healthcare AI privacy at the intersection of HIPAA and the EU AI Act for clinical decision support systems. Covers training data PHI handling, model transparency and explainability, patient rights in algorithmic decisions, FDA/OCR regulatory coordination, and bias monitoring. Keywords: healthcare AI, HIPAA, AI Act, clinical decision support, PHI training data, model transparency.
- ▌ Iowa Consumer Privacy · mukul975-2 bundleIowa Consumer Data Protection Act (ICDPA) compliance. Effective January 1, 2025. Covers consumer rights (access, delete, opt-out), controller thresholds at 100,000 consumers, sensitive data opt-in consent, 90-day cure period, and AG-only enforcement. Iowa Code Chapter 715D.
- ▌ Nist Privacy Identify · mukul975-2 bundleGuides implementation of the NIST Privacy Framework IDENTIFY function covering ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk assessment subcategories. Maps NIST PF controls to GDPR requirements for dual-framework compliance. Keywords: NIST Privacy Framework, IDENTIFY function, ID.BE, ID.DA, ID.IM, ID.RA, privacy risk assessment, data actions.
- ▌ Pia Vendor Processing · mukul975-2 bundleConducts Privacy Impact Assessment for vendor and third-party data processing arrangements. Covers processor due diligence, Data Processing Agreement (DPA) requirements under GDPR Article 28, sub-processor management, cross-border vendor transfers, cloud service provider assessments, and ongoing vendor monitoring. Keywords: vendor PIA, processor assessment, DPA, Article 28, sub-processor, cloud privacy, third-party risk.
- ▌ Pseudonymization Risk · mukul975-2 bundleAssessment of pseudonymization techniques and re-identification risk. Covers tokenization, hashing, encryption-based pseudonymization, and hybrid approaches. Includes re-identification risk scoring using the motivated intruder test, quantitative metrics (marketer, journalist, prosecutor models), and linkage attack resilience evaluation. References ENISA 2019 pseudonymization report.
- ▌ Regulatory Complaints · mukul975-2 bundleManages responses to regulatory complaints lodged with supervisory authorities under GDPR Article 77, covering internal escalation procedures, DPA response coordination, remediation tracking, and compliance documentation. Activate for regulatory complaint, supervisory authority complaint, Art. 77, DPA response, ICO complaint queries.
- ▌ Ropa Tool Integration · mukul975-2 bundleIntegrates Records of Processing Activities with privacy management platforms including OneTrust, TrustArc, Collibra, and DataGrail. Covers API-based synchronization, data mapping import, and automated RoPA population from enterprise tools. Activate for RoPA tool setup, OneTrust integration, TrustArc sync, privacy platform configuration.
- ▌ Saas Vendor Inventory · mukul975-2 bundleSaaS vendor data processing inventory management. Covers shadow IT discovery, API-based data flow detection, processing purpose mapping, contract status tracking, and continuous inventory reconciliation for cloud service providers.
- ▌ Search Engine Erasure · mukul975-2 bundleImplements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12). Covers delisting request procedures, criteria assessment balancing privacy against public interest, and geographic scope determination. Activate for right to be forgotten, search delisting, Google Spain, de-indexing queries.
- ▌ Special Category Data · mukul975-2 bundleIdentifies and classifies GDPR Art. 9 special category data including racial origin, political opinions, religious beliefs, trade union membership, genetic, biometric, health, and sexual orientation data. Covers processing conditions under Art. 9(2)(a)-(j). Keywords: special category, Art 9, sensitive data, biometric, genetic, health data, explicit consent.
- ▌ Tcf V2 Implementation · mukul975-2 bundleImplementing the IAB Transparency and Consent Framework v2.2 for programmatic advertising consent management. Covers CMP registration, Global Vendor List integration, TC String encoding, publisher restrictions, and compliance validation.
- ▌ Vendor Breach Cascade · mukul975-2 bundleVendor breach notification cascade management per GDPR Article 33(2). Covers processor-to-controller notification without undue delay, escalation paths, coordinated multi-party breach response, liability allocation, and regulatory notification coordination.
- ▌ AI Automated Decisions · mukul975-2 bundleImplements GDPR Art. 22 automated decision-making and AI Act Art. 14 human oversight requirements for AI systems. Covers identification of solely automated decisions, meaningful human intervention design, logic explanation mechanisms, and contestation procedures. Keywords: Art. 22, automated decision, human oversight, AI Act, profiling, contestation.
- ▌ AI Data Subject Rights · mukul975-2 bundleImplements data subject rights mechanisms for AI systems including right to explanation of AI decisions, contestation procedures, human review, model output correction, and training data access. Covers GDPR Arts. 15-22 and AI Act Art. 86. Keywords: data subject rights, AI explanation, contestation, human review, training data access, model correction.
- ▌ AI Model Privacy Audit · mukul975-2 bundleConducts privacy auditing of AI models including training data extraction testing, membership inference attacks, model inversion testing, and attribute inference assessment. Uses ML Privacy Meter and related tools to quantify privacy leakage. Keywords: model audit, membership inference, privacy meter, model inversion, training data extraction.
- ▌ AI Training Data Class · mukul975-2 bundleClassifies sensitive data in AI/ML training datasets including bias detection for Art. 9 categories, data card documentation, provenance tracking, and consent verification for model training. Keywords: AI training data, ML dataset, bias detection, data card, model training, Art 9, consent, GDPR AI.
- ▌ AI Training Lawfulness · mukul975-2 bundleAssesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI. Covers legitimate interest balancing tests, consent challenges for ML training, public dataset assessment, and web scraping lawfulness. Keywords: AI training data, lawful basis, EDPB LLM, legitimate interest, consent, web scraping.
- ▌ Audit Evidence Collect · mukul975-2 bundleGuides privacy audit evidence collection processes including evidence planning, sampling strategies, documentation standards, chain of custody, interview techniques, system walkthrough procedures, and evidence evaluation. Covers ISO 19011 evidence categories (records, statements of fact, observations) and ISACA audit evidence requirements for privacy compliance assessments. Keywords: audit evidence, evidence collection, sampling, chain of custody, audit documentation, interview techniques.
- ▌ Audit Follow Up Verify · mukul975-2 bundleGuides audit follow-up and verification processes including follow-up scheduling, remediation effectiveness testing, finding closure criteria, re-testing procedures, status reporting, and escalation of unremediated findings. Implements IIA Standard 2500 monitoring requirements and ISO 19011 follow-up guidance for privacy audit engagements. Keywords: audit follow-up, verification testing, finding closure, remediation effectiveness, re-testing, follow-up audit.
- ▌ Audit Sampling Methods · mukul975-2 bundleGuides privacy audit sampling methodology including statistical and non-statistical sampling, sample size determination, stratification techniques, attribute sampling for compliance testing, confidence level selection, tolerable deviation rates, and extrapolation of results to the population. Keywords: audit sampling, statistical sampling, attribute testing, sample size, confidence level, stratified sampling, privacy audit.
- ▌ Auto Deletion Workflow · mukul975-2 bundleImplements automated data deletion workflows for GDPR Article 17 right to erasure and retention period expiry. Covers cascading deletion across dependent systems, dependency handling for referential integrity, confirmation logging, and audit trail generation. Activate for automated deletion, erasure automation, data purge, retention expiry queries.
- ▌ Breach Risk Assessment · mukul975-2 bundleDetermines whether a personal data breach triggers notification obligations under GDPR Articles 33 and 34 using structured risk assessment methodology. Covers breach type classification (CIA triad), data sensitivity scoring, volume assessment, identifiability analysis, and consequence severity evaluation. References EDPB Guidelines 01/2021 with 18 breach scenarios. Keywords: breach risk assessment, GDPR, Article 33, Article 34, EDPB, notification threshold.
- ▌ Ca Breach Notification · mukul975-2 bundleExecutes breach notification under California Civil Code Section 1798.82 (California data breach notification law). Covers data elements triggering notification, timing requirements (most expedient time possible), AG notification for 500+ California residents, specific content and format requirements, and substitute notice provisions. Keywords: California, breach notification, Cal. Civ. Code 1798.82, attorney general, CCPA, data elements.
- ▌ Ccpa Consumer Requests · mukul975-2 bundleManages California Consumer Privacy Act (CCPA) consumer rights requests under Civil Code sections 1798.100-125, covering the right to know, right to delete, right to opt-out of sale, and non-discrimination. Includes 45-day response window and identity verification requirements. Activate for CCPA, California privacy, right to know, right to delete, opt-out of sale queries.
- ▌ Cloud Retention Config · mukul975-2 bundleConfigures cloud storage retention policies across AWS S3, Azure Blob Storage, and Google Cloud Storage. Covers lifecycle rules, object lock, legal hold, immutability policies, cross-region replication retention alignment, and compliance mode configuration. Activate for cloud retention, S3 lifecycle, Azure retention, GCP retention policy queries.
- ▌ Cnil Compliant Cookies · mukul975-2 bundleImplementation guide for CNIL cookie guidelines compliance. References the EUR 150M Google fine and EUR 60M Meta fine. Covers equal prominence accept/reject buttons, cookie wall prohibition, 6-month reconsent intervals, essential cookies exemption, and detailed CNIL Deliberation No. 2020-091 requirements.
- ▌ Consent Record Keeping · mukul975-2 bundleGuide for building a consent record-keeping system to demonstrate valid consent per GDPR Article 7(1). Covers required fields including timestamp, version, purpose, mechanism, and identity. Implements audit-ready consent receipts per the Kantara Initiative Consent Receipt Specification and supervisory authority expectations.
- ▌ Cookie Consent Testing · mukul975-2 bundleAutomated cookie consent validation using Selenium and Playwright. Covers banner interaction testing, consent state verification, tag firing audit after consent choices, regression testing for cookie compliance, and CI/CD pipeline integration.
- ▌ Criminal Data Handling · mukul975-2 bundleHandles GDPR Art. 10 criminal conviction and offence data classification including official authority requirements, national law derogations, and comprehensive register restrictions. Covers controller obligations for criminal background checks and offence records. Keywords: criminal data, Art 10, conviction data, offence records, criminal background, DBS check.
- ▌ Data Inventory Mapping · mukul975-2 bundleBuilds comprehensive data inventory per GDPR Art. 30 Records of Processing Activities. Covers system-by-system discovery, data flow diagramming, third-party identification, and legal basis per category. Keywords: data inventory, data mapping, Art 30, RoPA, data flow, processing activities.
- ▌ Dpia Biometric Systems · mukul975-2 bundleConducts Data Protection Impact Assessments for biometric identification and authentication systems under GDPR Article 35 and Article 9 special category rules. Covers facial recognition, fingerprint, iris scanning, voice recognition, and behavioural biometrics. Applies EDPB Guidelines 3/2019, CNIL Reglement Type Biometrie, and ISO/IEC 24745 biometric template protection. Keywords: DPIA biometric, facial recognition, fingerprint, Art. 35, Art. 9, biometric template, special category.
- ▌ Employee Dsar Response · mukul975-2 bundleManages Data Subject Access Request procedures for employee requests under Art. 15 GDPR. Covers scope of disclosable HR records, emails, CCTV footage, performance reviews, monitoring data, and training records. Implements third-party data redaction, legal professional privilege, exemptions for ongoing proceedings, and the one-month response timeline. Keywords: DSAR, subject access request, Art. 15, employee records, redaction, privilege, HR data, SAR.
- ▌ Gdpr Eu Representative · mukul975-2 bundleGuides appointment of GDPR Article 27 EU representative for non-EU controllers or processors. Covers criteria, responsibilities, and documentation. Activate when a non-EU entity processes EU data. Keywords: EU representative, Article 27, non-EU controller, territorial scope.
- ▌ Global Privacy Control · mukul975-2 bundleImplementation guide for Global Privacy Control (GPC) automated opt-out signal per CPRA Section 1798.135(e). Covers Sec-GPC HTTP header detection, JavaScript navigator.globalPrivacyControl API, and state-specific requirements for CA, CO, CT, MT, TX, and OR. Includes server-side detection code and compliance mapping.
- ▌ Google Consent Mode V2 · mukul975-2 bundleConfiguring Google Consent Mode v2 for privacy-compliant measurement and advertising. Covers default and update commands, consent state mapping to GA4 and Google Ads, conversion modeling with cookieless pings, and EEA requirements effective March 2024.
- ▌ Gpc Cookie Integration · mukul975-2 bundleIntegrating Global Privacy Control (GPC) signals with cookie consent platforms. Covers GPC signal detection in browsers, automatic opt-out triggering, mapping GPC to US state privacy laws, and CMP integration for CCPA, CPA, and CTDPA compliance.
- ▌ Hipaa Deidentification · mukul975-2 bundleImplements HIPAA de-identification methods under 45 CFR §164.514(a)-(b). Covers expert determination method and safe harbor method with 18 identifiers removal, re-identification risk assessment, limited dataset requirements, and data use agreements. Keywords: HIPAA de-identification, safe harbor, expert determination, 18 identifiers, limited dataset, PHI.
- ▌ Hipaa Interoperability · mukul975-2 bundleAddresses HIPAA privacy and security requirements for health data interoperability under the 21st Century Cures Act, ONC Health IT Certification Program, and CMS Interoperability and Patient Access Final Rule. Covers information blocking prohibitions, FHIR API patient access, TEFCA exchange purposes, and privacy safeguards for health information exchange. Keywords: interoperability, information blocking, FHIR, TEFCA, Cures Act, patient access API, health information exchange.
- ▌ Hipaa Research Privacy · mukul975-2 bundleImplements HIPAA Privacy Rule requirements for research uses of protected health information under 45 CFR §164.512(i). Covers IRB and Privacy Board waivers of authorization, individual authorization for research, limited data set and data use agreements, preparatory to research provisions, and decedent research provisions. Keywords: HIPAA research, IRB waiver, Privacy Board, authorization, limited data set, preparatory research, de-identification, Common Rule.
- ▌ Internal Privacy Audit · mukul975-2 bundleGuides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation tracking, and management reporting. Covers audit universe definition, annual audit plan, working papers, and closure verification. Keywords: internal audit, privacy audit, fieldwork, remediation, findings, audit plan.
- ▌ Joint Controller Art26 · mukul975-2 bundleGuides the establishment and management of joint controller arrangements under GDPR Article 26, including determination of joint controllership, allocation of responsibilities, and transparency obligations. Activate when two or more controllers jointly determine purposes and means of processing, or when evaluating shared data platforms. Keywords: joint controller, Article 26, shared responsibility, arrangement, joint determination.
- ▌ Multi State Compliance · mukul975-2 bundleMulti-state harmonized privacy compliance program. Common requirements matrix across all US state privacy laws, state-specific deltas, unified privacy program architecture, and implementation strategy for operating across California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and Kentucky.
- ▌ Oregon Ocpa Compliance · mukul975-2 bundleOregon Consumer Privacy Act (OCPA) compliance. Unique provisions for de-identified data requirements, employee data partial exemption, nonprofit applicability, 14-day cure period, and consumer rights. Effective July 1, 2024. AG enforcement only.
- ▌ Pii Detection Pipeline · mukul975-2 bundleBuild automated PII detection and redaction pipelines using spaCy NER, Microsoft Presidio, and AWS Macie integration. Includes confidence scoring, custom entity type definitions, batch processing workflows, and multi-format document scanning for structured and unstructured data sources.
- ▌ Prior Consultation Dpa · mukul975-2 bundleGuides the Art. 36 prior consultation process when a DPIA indicates high residual risk that cannot be mitigated. Covers required documentation per Art. 36(3), the 8-week DPA response timeline, outcome management, and interaction protocols with supervisory authorities. Keywords: prior consultation, Art. 36, supervisory authority, DPA, high residual risk, DPIA escalation, consultation documentation.
- ▌ Privacy Law Monitoring · mukul975-2 bundleGuides privacy law change monitoring and impact assessment for multi-jurisdiction organisations. Covers regulatory tracking sources, change classification, impact scoring methodology, and implementation prioritisation. Keywords: law monitoring, regulatory tracking, change management, impact assessment, implementation priority.
- ▌ Privacy Maturity Model · mukul975-2 bundleGuides privacy program maturity assessment using the AICPA/CIPT Privacy Maturity Model with five levels: Ad Hoc, Repeating, Defined, Managed, and Optimized. Covers assessment methodology across ten privacy domains, scoring criteria, gap analysis, maturity roadmap generation, and benchmarking against industry peers. Keywords: privacy maturity, AICPA, maturity model, assessment, roadmap, benchmarking.
- ▌ Privacy Record Linkage · mukul975-2 bundleImplement privacy-preserving record linkage across datasets using Bloom filter encoding, secure hash matching, threshold tuning for precision and recall, and false positive management. Enables entity resolution without exposing raw personally identifiable information between parties.
- ▌ Remote Work Monitoring · mukul975-2 bundleEstablishes boundaries for monitoring remote and hybrid workers including screen capture, productivity tracking, camera and microphone activation, attendance verification, and activity logging. Applies proportionality principles, transparency requirements, and evaluates less intrusive alternatives per EDPB and national DPA guidance. Keywords: remote work, monitoring, screen capture, productivity tracking, webcam, home office, hybrid work, proportionality, surveillance.
- ▌ Right To Rectification · mukul975-2 bundleProcesses GDPR Article 16 right to rectification requests, covering verification of corrected data accuracy, notification to recipients under Article 19, timeline management, and completion of incomplete data. Activate for rectification, correction request, inaccurate data, Art. 16, data correction queries.
- ▌ Supplementary Measures · mukul975-2 bundleGuides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020. Covers encryption, pseudonymisation, split processing, audit rights, transparency obligations, and internal policies. Keywords: supplementary measures, encryption, pseudonymisation, EDPB recommendations, transfer safeguards.
- ▌ Texas Tdpsa Compliance · mukul975-2 bundleTexas Data Privacy and Security Act (TDPSA) compliance. No revenue threshold applies to all businesses. Covers data broker registration requirements, biometric identifier provisions under CUBI, consumer rights, AG enforcement, and 30-day cure period. Effective July 1, 2024.
- ▌ Uk Aadc Implementation · mukul975-2 bundleImplements the UK Age Appropriate Design Code (Children's Code) 15 standards under the Data Protection Act 2018 Section 123. Covers best interests assessment, age-appropriate application, transparency, data minimization, geolocation restrictions, and profiling defaults. Keywords: AADC, Children's Code, ICO, age appropriate design, UK.
- ▌ Uk Transfer Mechanisms · mukul975-2 bundleGuides implementation of UK international data transfer mechanisms post-Brexit including the International Data Transfer Agreement (IDTA), UK Addendum to EU SCCs, UK adequacy assessments, and ICO transfer risk assessment tool. Keywords: UK IDTA, UK addendum, ICO TRA, post-Brexit transfers, UK GDPR.
- ▌ Vendor Cert Acceptance · mukul975-2 bundleVendor certification acceptance criteria and equivalence mapping. Covers ISO 27701, SOC 2 Privacy, APEC CBPR, EU Code of Conduct evaluation, certification scope analysis, gap supplementation requirements, and cross-framework equivalence assessment.
- ▌ AI Deployment Checklist · mukul975-2 bundlePre-deployment privacy compliance checklist for AI/ML systems covering DPIA completion, lawful basis verification, transparency notices, human oversight mechanisms, bias testing, and post-deployment monitoring setup. Keywords: AI deployment, privacy checklist, go-live, model deployment, compliance gate.
- ▌ Breach 72h Notification · mukul975-2 bundleExecutes the GDPR Article 33 mandatory breach notification to the supervisory authority within 72 hours of becoming aware of a personal data breach. Covers required notification content, deadline calculation, risk assessment for notification threshold, and DPO involvement. Keywords: GDPR, Article 33, breach notification, 72 hours, supervisory authority, DPO, EDPB.
- ▌ Breach Detection System · mukul975-2 bundleImplements technical breach detection capabilities including SIEM integration, DLP alert configuration, anomaly detection rules, and insider threat monitoring. Provides a breach classification taxonomy across confidentiality, integrity, and availability dimensions. Covers detection tool selection, alert tuning, and integration with privacy incident response workflows. Keywords: breach detection, SIEM, DLP, anomaly detection, insider threat, classification.
- ▌ Children Privacy Notice · mukul975-2 bundleDesigns and implements privacy notices for children that comply with GDPR Articles 12-14, UK AADC Standard 4, and COPPA Section 312.4. Covers plain language, visual explanations, layered information, age-appropriate vocabulary, and interactive notice elements. Keywords: children privacy notice, transparency, plain language, visual, age-appropriate, layered notice.
- ▌ Colorado Cpa Compliance · mukul975-2 bundleColorado Privacy Act (CPA) compliance implementation. Covers universal opt-out mechanism required since July 2024, profiling opt-out rights, sensitive data consent requirements, AG rulemaking under 4 CCR 904-3, and consumer rights framework. Effective July 1, 2023.
- ▌ Cookie Consent Ab Audit · mukul975-2 bundleMethodology for auditing A/B testing of consent banners to ensure compliance with equal ease of acceptance and rejection. Covers CNIL enforcement patterns including the EUR 150M Google fine, dark pattern detection methodology, manipulative design identification, and regulatory-compliant experimentation boundaries.
- ▌ Cookieless Alternatives · mukul975-2 bundleEvaluating and implementing cookie-less tracking alternatives for a post-cookie era. Covers the Privacy Sandbox APIs (Topics, Attribution Reporting, Protected Audiences), server-side analytics, and privacy-preserving measurement techniques.
- ▌ Employee Biometric Data · mukul975-2 bundleGoverns biometric data processing for employee timekeeping and access control under Art. 9 GDPR special category rules. Covers fingerprint, facial recognition, iris scanning, and voice recognition. Applies necessity tests, evaluates less intrusive alternatives, and implements employee objection procedures. Keywords: biometric data, Art. 9, fingerprint, facial recognition, access control, timekeeping, special category.
- ▌ Gdpr Prior Consultation · mukul975-2 bundleGuides the GDPR Article 36 prior consultation process with supervisory authorities when a DPIA indicates high residual risk. Covers timeline requirements, documentation, and outcome handling. Activate when DPIA residual risk remains high or when preparing regulatory submissions. Keywords: prior consultation, Article 36, DPIA, high risk, supervisory authority.
- ▌ Hipaa Employee Training · mukul975-2 bundleImplements HIPAA workforce training requirements under 45 CFR §164.530(b) (Privacy Rule) and 45 CFR §164.308(a)(5) (Security Rule). Covers initial onboarding training, periodic refresher cadence, role-based content differentiation, documentation of training completion, and sanction policy integration. Keywords: HIPAA training, workforce training, security awareness, privacy training, §164.530(b), §164.308(a)(5).
- ▌ Hipaa Minimum Necessary · mukul975-2 bundleImplements HIPAA minimum necessary standard under 45 CFR §164.502(b). Covers role-based access policies per workforce member category, routine vs non-routine disclosure protocols, reasonable reliance doctrine, documentation requirements, and HITECH amendments. Keywords: minimum necessary, role-based access, workforce, routine disclosure, HIPAA.
- ▌ Lawful Basis Assessment · mukul975-2 bundleGuides determination of the correct lawful basis under GDPR Article 6(1)(a)-(f) for each processing activity. Includes decision tree logic for consent vs legitimate interest vs contract necessity. Activate when evaluating legal grounds for processing or reviewing lawful basis selections. Keywords: lawful basis, Article 6, consent, legitimate interest, legal obligation, contract.
- ▌ Legitimate Interest Lia · mukul975-2 bundleGuides the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose test, necessity test, and balancing test. Activate when evaluating legitimate interest as a lawful basis, conducting LIA reviews, or documenting proportionality analysis. Keywords: LIA, legitimate interest, balancing test, necessity test, purpose test, Article 6(1)(f).
- ▌ LLM Output Privacy Risk · mukul975-2 bundleAssessing privacy risks in large language model outputs including training data memorisation, PII leakage in generated text, prompt injection leading to data extraction, and hallucinated personal data. Covers output filtering, guardrails, and monitoring. Keywords: LLM privacy, output risk, memorisation, PII leakage, prompt injection, hallucinated PII.
- ▌ Pia Large Scale Monitor · mukul975-2 bundleConducts Privacy Impact Assessment for large-scale systematic monitoring under GDPR Article 35(3)(c). Covers CCTV and video surveillance, employee monitoring, location tracking, internet monitoring, and behavioural analytics. Applies EDPB WP248rev.01 criteria for systematic monitoring of publicly accessible areas. Keywords: DPIA, large-scale monitoring, CCTV, employee monitoring, systematic monitoring, surveillance, location tracking.
- ▌ Pia Threshold Screening · mukul975-2 bundleConducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35. Applies the EDPB WP248rev.01 nine-criteria test, national supervisory authority blacklists, and organisational risk appetite to produce a documented screening decision. Keywords: threshold screening, DPIA trigger, pre-DPIA, WP248, Article 35(1), blacklist, screening decision.
- ▌ Privacy Program Metrics · mukul975-2 bundleGuides privacy program effectiveness measurement including leading and lagging indicators, KPI definition, benchmarking methodology, executive reporting formats, board-level privacy dashboards, and metric-driven program improvement. Covers operational, compliance, risk, and strategic privacy metrics across the program lifecycle. Keywords: privacy metrics, KPIs, benchmarking, executive reporting, dashboard, program effectiveness.
- ▌ Processor Ropa Creation · mukul975-2 bundleCreates GDPR Article 30(2) Records of Processing Activities for data processors with all four mandatory fields: processor and controller names and contact details, categories of processing, third country transfers, and security measures description. Activate for processor RoPA, Art. 30(2), processor records, sub-processor documentation.
- ▌ Retention Impact Assess · mukul975-2 bundleConducts retention impact assessments for new processing activities to determine appropriate data retention periods. Covers regulatory requirements scanning, proportionality review, purpose-based retention determination, and retention period documentation aligned with GDPR Article 5(1)(e) and Article 25 data protection by design. Activate for retention assessment, new processing retention, retention period determination queries.
- ▌ Ropa Completeness Audit · mukul975-2 bundleAudits Records of Processing Activities against supervisory authority templates from CNIL, ICO, and BfDI. Provides completeness scoring, gap identification, and remediation tracking. Activate for RoPA audit, completeness check, supervisory authority readiness, CNIL template, ICO template, BfDI template, gap analysis.
- ▌ Secure Data Destruction · mukul975-2 bundleImplements NIST SP 800-88 Rev. 1 media sanitization procedures including Clear, Purge, and Destroy methods for all media types. Covers certificate of destruction generation, verification procedures, vendor management for third-party destruction, and chain of custody documentation. Activate for data destruction, media sanitization, secure erasure, certificate of destruction queries.
- ▌ State Law Applicability · mukul975-2 bundleUS state privacy law applicability assessment tool. Evaluates revenue thresholds, data volume thresholds, business exemptions (GLBA, HIPAA, nonprofits), employee data carve-outs, and SBA small business determinations across all enacted state privacy laws.
- ▌ Vendor Termination Data · mukul975-2 bundleVendor termination data return and deletion procedures per GDPR Article 28(3)(g). Covers data extraction formats, deletion certification requirements, transition planning, residual data handling, and post-termination verification.
- ▌ Workplace Email Privacy · mukul975-2 bundleImplements email and internet monitoring compliance in the workplace per Barbulescu v Romania (ECHR Grand Chamber), EDPB guidance, and national labour law. Covers acceptable use policies, legitimate expectation of privacy, proportionality testing, and content vs metadata monitoring. Keywords: email monitoring, Barbulescu, workplace privacy, internet monitoring, acceptable use policy, ECHR, proportionality.
- ▌ Ropa 250 Exemption · mukul975-2 bundleAssesses the GDPR Article 30(5) exemption for organisations under 250 employees. Covers the three exception conditions that negate the exemption: non-occasional processing, risk to data subject rights, and special category data processing. Activate for Art. 30(5), 250 employee exemption, small business RoPA, SME exemption, occasional processing.
- ▌ Scc Implementation · mukul975-2 bundleGuides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C). Covers clause-by-clause completion, Annex I-III drafting, and SCC module selection. Keywords: SCCs, standard contractual clauses, module selection, data transfers, Annex completion.
- ▌ Soc2 Privacy Audit · mukul975-2 bundleGuides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent, collection, use/retention/disposal, access, disclosure, security, and quality. Includes evidence collection, control testing, and report review. Keywords: SOC 2, privacy criteria, TSP, AICPA, Type II, trust services.
- ▌ South Africa Popia · mukul975-2 bundleImplements compliance with South Africa's Protection of Personal Information Act (POPIA), Act No. 4 of 2013. Covers conditions for lawful processing, data subject rights, cross-border transfer restrictions, Information Regulator enforcement, and responsible party obligations. Keywords: POPIA, South Africa, Information Regulator, responsible party, operator, prior authorisation.
- ▌ Telehealth Privacy · mukul975-2 bundleImplements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors, cross-state prescribing rules, and OCR enforcement discretion during public health emergencies. Keywords: telehealth privacy, virtual care, HIPAA, recording consent, platform BAA, cross-state licensing, OCR enforcement.
- ▌ Us Privacy Federal · mukul975-2 bundleMaps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.
- ▌ Whistleblower Data · mukul975-2 bundleImplements data protection compliance for whistleblowing systems under EU Directive 2019/1937 and GDPR. Covers anonymous reporting channels, identity protection for whistleblowers and accused persons, retention limits, access restrictions, and retaliation prevention. Addresses national transpositions and DPA guidance. Keywords: whistleblower, Directive 2019/1937, anonymous reporting, identity protection, retaliation, retention, reporting channel.
- ▌ Adequacy Assessment · mukul975-2 bundleGuides assessment of third-country adequacy decisions under GDPR Article 45 for international data transfers. Covers the current EC adequacy decisions list, adequacy assessment criteria, partial adequacy handling, and monitoring of adequacy decision reviews. Keywords: adequacy decision, Article 45, third country, adequate protection, EC adequacy list.
- ▌ Age Gating Services · mukul975-2 bundleImplements age-gating mechanisms for online services to restrict access based on user age. Covers hard gates versus soft gates, neutral age prompts, re-verification triggers, circumvention prevention, and regulatory requirements under GDPR, COPPA, UK Online Safety Act, and DSA. Keywords: age gate, age restriction, neutral prompt, children, online services, access control.
- ▌ Auto Data Discovery · mukul975-2 bundleImplements automated PII discovery and classification using tools like Microsoft Purview, BigID, OneTrust DataDiscovery, and AWS Macie. Covers scanning schedules, accuracy tuning, false positive management, and integration patterns. Keywords: data discovery, PII scanning, Purview, BigID, Macie, OneTrust, automated classification, data cataloging.
- ▌ Byod Privacy Policy · mukul975-2 bundleImplements BYOD privacy compliance frameworks for personal device use in the workplace. Covers personal vs corporate data separation, MDM capabilities and limitations, employee consent requirements, data wiping boundaries, and monitoring restrictions on personal devices. Keywords: BYOD, mobile device management, MDM, personal device, data separation, containerisation, remote wipe, employee privacy.
- ▌ Consent Pref Center · mukul975-2 bundleTechnical architecture guide for building a multi-purpose consent preference center. Covers per-purpose granularity, easy withdrawal under Article 7(3), version history, audit trails, and IAB Transparency and Consent Framework v2.2 integration. Includes database schema, API design, and UI component specifications.
- ▌ Double Opt In Email · mukul975-2 bundleImplementation guide for ePrivacy Directive compliant double opt-in email consent. Covers confirmation email workflow design, token expiration handling, record-keeping requirements, suppression list management, and integration with CAN-SPAM Act and CASL requirements for multi-jurisdiction compliance.
- ▌ Dpa Inspection Prep · mukul975-2 bundleGuides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for key personnel, technical demonstration procedures, on-site logistics, response protocols, and post-inspection follow-up. Covers unannounced inspections, formal audits, and complaint-triggered investigations. Keywords: DPA inspection, supervisory authority, investigation, readiness, interview preparation, response protocol.
- ▌ Financial Retention · mukul975-2 bundleImplements financial records retention requirements across EU directives (5-7 years), SOX Section 802 (7 years), MiFID II (5-7 years), tax records, payment data, and AML obligations under AMLD. Maps financial data categories to statutory retention periods with cross-jurisdictional reconciliation. Activate for financial retention, SOX records, MiFID retention, AML retention, tax record keeping queries.
- ▌ Gdpr Accountability · mukul975-2 bundleGuides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs. Activate when establishing or reviewing accountability measures, preparing evidence portfolios, or demonstrating compliance to supervisory authorities. Keywords: accountability, Article 5(2), Article 24, documentation, compliance evidence, governance.
- ▌ Hipaa Breach Notify · mukul975-2 bundleImplements HIPAA breach notification requirements under 45 CFR §164.400-414. Covers individual notification within 60 days, HHS reporting thresholds (500+ immediate, under 500 annual), state attorney general notification, media notification for 500+ in a state, and breach risk assessment. Keywords: HIPAA breach notification, HHS reporting, OCR breach portal, individual notice, state attorney general.