SKILL.md
GDPR Compliance Skill
GDPR compliance is mostly bookkeeping you can defend: knowing every place you process personal data, why you're allowed to, how long you keep it, and how a person can get it out or deleted. This skill builds that record (the ROPA), pins a lawful basis to each activity, and flags the high-risk processing that legally requires a DPIA — turning "are we GDPR-compliant?" into a documented, auditable answer.
Required Inputs
Ask for these only if they aren't already provided:
- Processing activities — what personal data you collect, why, and where it flows (this is the spine; everything hangs off it).
- Role — controller (you decide the why/how) or processor (you act on a controller's instructions); your obligations differ.
- Data subjects & data types — whose data, and whether any is special-category (health, biometrics, etc.) or about children.
- Transfers — any processing or storage outside the EEA (triggers transfer-mechanism requirements).
Output Format
GDPR Assessment: [company] ([controller/processor])
1. ROPA — the Record of Processing Activities (Art. 30); one row per activity:
| Activity | Purpose | Data categories | Subjects | Lawful basis | Recipients | Retention | Transfers |
|---|
2. Lawful basis — the chosen Art. 6 basis per activity (consent / contract / legal obligation / vital interests / public task / legitimate interests) and why. For special-category data, the additional Art. 9 condition. Don't default everything to "consent" — it's often the weakest, hardest-to-maintain basis.
3. DSAR workflow — how you handle access/erasure/portability/objection requests: intake, identity check, the one-month deadline, and how data is located and exported/deleted.
4. DPIA screen — flag activities that legally require a Data Protection Impact Assessment (large-scale special-category processing, systematic monitoring, profiling with legal effects).
5. Gaps — prioritised: missing lawful basis, no retention period, undocumented transfers, no DSAR process.
