From gdpr-compliance
EU GDPR compliance knowledge base for AI projects and data processing in the EU/EEA. Use this skill EVERY TIME the conversation involves: personal data, privacy, cookies, consent, data processing, data processing agreements (DPA), DPIA, privacy policies, third-country transfers, data subject rights (access, erasure, rectification, portability), EU AI Act interplay, or when the user is building AI systems, SaaS products, apps, automations or integrations that handle European users' data. Also trigger on mention of GDPR, data protection law, Article 5/6/9/13/22/28/30/32/33/35, PII stripping, machine unlearning, zero data retention, national IDs, sensitive personal data, or compliance checklists. ALWAYS trigger when the user types "/gdpr" — this is an explicit activation command. Covers the full EU/EEA regulation with Danish national specifics as a reference example for member state implementations.
How this skill is triggered — by the user, by Claude, or both
Slash command
/gdpr-compliance:gdpr-complianceThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
> **Regulation (EU) 2016/679 · Skill version 2.0.0**
Regulation (EU) 2016/679 · Skill version 2.0.0 Does NOT replace individual legal advice. State this to the user when relevant.
Any conversation touching personal data in an EU/EEA context — whether or not the user explicitly mentions "GDPR". If a system is being built, designed, architected or discussed that handles data about identifiable persons, this skill is relevant.
When the user types /gdpr, respond with a status card:
GDPR Compliance Skill — active
Knowledge base last updated: [read status_date from JSON]
Days since update: [calculate from today's date]
Coverage: Regulation (EU) 2016/679 + EDPB Opinion 28/2024 + Danish national specifics
Companion: EU AI Act skill (/euaiact)
How can I help? Examples:
• Assess GDPR compliance for a new project
• Review a data processing setup
• Check third-country transfer requirements
• Walk through the 12-step compliance checklist
If the knowledge base is older than 180 days, add a warning:
⚠️ This knowledge base is [X] months old. GDPR interpretation evolves.
Searching for recent regulatory changes...
Then use web search to check for recent EDPB guidelines, Datatilsynet decisions, or significant CJEU rulings that may affect the advice.
Every time this skill is loaded, compare the status_date field in the JSON
against today's date:
ALWAYS load the full knowledge base before responding to any GDPR-related question. Do not rely on the summary in this file alone — the JSON contains critical legal detail, article-level specifics, and AI-specific guidance that this overview omits.
view references/gdpr_skill_en.json
The JSON is structured by GDPR chapter and includes: article-level definitions, all 6 legal bases with AI recommendations, 8 data subject rights with AI challenges, full DPIA trigger criteria, DPA checklists, security measures, breach procedures, third-country transfer mechanisms, EDPB Opinion 28/2024 on AI, and a 12-step compliance checklist for new AI projects.
React proactively with a friendly warning if you spot:
When the user starts a new project involving personal data, guide them through this sequence (from the reference data):
GDPR is often confused with cookie rules. The actual cookie requirement comes from the ePrivacy Directive (2002/58/EC) as implemented by each member state, but GDPR governs what happens with the personal data collected via cookies.
When the user mentions cookies, tracking, or analytics:
Practical note: cookie consent banners that use dark patterns (e.g. hiding the reject button, pre-checked boxes) are increasingly being fined by supervisory authorities.
When advising on Data Processing Agreements (Art. 28), point the user to these:
GDPR and the AI Act apply cumulatively. If the user is building an AI system, mention that there may be parallel obligations under the AI Act — in particular:
For detailed AI Act compliance guidance, see the companion skill: eu-ai-act-compliance. When both skills are available, use them together — start with AI Act Art. 5 screening, then proceed to GDPR analysis.
Use consistent abbreviations and explain them on first use:
| Abbreviation | Meaning |
|---|---|
| DPA | Data Processing Agreement |
| DPIA | Data Protection Impact Assessment |
| DPO | Data Protection Officer |
| LIA | Legitimate Interest Assessment |
| ROPA | Record of Processing Activities |
| SCC | Standard Contractual Clauses |
| TIA | Transfer Impact Assessment |
| DPF | EU-US Data Privacy Framework |
Searches MemPalace before answering questions about past work, people, projects, or prior decisions. Returns verbatim stored content instead of guessing from model memory.
Guides Payload CMS config (payload.config.ts), collections, fields, hooks, access control, APIs. Debugs validation errors, security, relationships, queries, transactions, hook behavior.
Implements vector databases with Pinecone, Weaviate, Qdrant, Milvus, pgvector for semantic search, RAG, recommendations, and similarity systems. Optimizes embeddings, indexing, and hybrid search.
npx claudepluginhub sm4rtenheimer/gdpr-compliance