Marketplace Create skill Sign in

Privacy Check Skill

Use to assess Privacy by Design compliance and GDPR/data protection alignment for a feature or system.

ID: 7dd8cdc9-f8a3-48de-9838-3b3052de4b12 Version: 0.1.0 License: MIT Author: haabe Language: en Added: 2026-06-15
⬇ Download

Privacy Check Skill

Privacy by Design assessment.

Workflow

7 Foundational Principles (Cavoukian)

  1. Proactive not Reactive: Are privacy measures built in from the start?

    • [ ] Privacy considered in design phase, not bolted on
    • [ ] Risks identified before implementation
  2. Privacy as Default: Is the most private option the default?

    • [ ] Data collection opt-in, not opt-out
    • [ ] Minimum data collected by default
    • [ ] Sharing disabled by default
  3. Privacy Embedded in Design: Is privacy integral to the system?

    • [ ] Privacy controls are core features, not add-ons
    • [ ] Architecture supports data minimization
  4. Positive-Sum, not Zero-Sum (originally "Full Functionality"): Privacy without trade-offs?

    • [ ] Privacy features don't degrade user experience
    • [ ] Not a false choice between privacy and functionality
    • [ ] Avoid false dichotomies: privacy vs. security, privacy vs. business value
  5. End-to-End Security: Data protected throughout its lifecycle?

    • [ ] Encryption at rest and in transit
    • [ ] Secure deletion when no longer needed
    • [ ] Access controls throughout the data lifecycle
  6. Visibility and Transparency: Is data processing transparent?

    • [ ] Users know what data is collected and why
    • [ ] Processing purposes documented and communicated
    • [ ] Third-party sharing disclosed
  7. Respect for User Privacy: Are user interests centered?

    • [ ] Users can access their data
    • [ ] Users can correct their data
    • [ ] Users can delete their data
    • [ ] Consent is informed, specific, and revocable

Data Protection Assessment

  • What data is collected? List all personal data fields.
  • Why? Lawful basis for each data element.
  • How long? Retention period for each data type.
  • Who accesses it? List all parties with access.
  • Where is it stored? Data residency and cross-border transfers.
  • How is it protected? Encryption, access control, monitoring.
  • What if breached? Incident response plan exists?

Output

## Privacy Assessment: [Feature/System]

### PbD Principles
| Principle | Status | Notes |
|-----------|--------|-------|
| Proactive | Pass/Fail | ... |
| Default privacy | Pass/Fail | ... |
| Embedded | Pass/Fail | ... |
| Full functionality | Pass/Fail | ... |
| End-to-end security | Pass/Fail | ... |
| Transparency | Pass/Fail | ... |
| User respect | Pass/Fail | ... |

### Data Inventory
| Data | Purpose | Basis | Retention | Protection |
|------|---------|-------|-----------|-----------|
| ... | ... | ... | ... | ... |

### Risks and Recommendations
1. [risk and recommended action]

Decision Log (MANDATORY per G-P4)

APPEND a ### Privacy Assessment entry to .claude/harness/decision-log.md with: principles assessed, data flows identified, risks found, GDPR compliance status.

Theory Citations

  • Cavoukian: Privacy by Design (7 principles)
  • GDPR: Data protection regulation

Comments

Loading…

Related Skills

GENERAL · data-protection

Vendor Privacy Due Diligence

Pre-contract vendor privacy due diligence per GDPR Article 28(1). Covers risk questionnaires, technical controls assessment, certification review, da…

mukul975
GENERAL · data-protection

Vendor Privacy Audit

On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classificatio…

mukul975
GENERAL · data-protection

vendor-ai-review-anthropics

Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model chang…

anthropics
GENERAL · data-protection

use-case-triage

Quickly determine whether a processing activity needs a PIA, a mandatory GDPR DPIA, or can proceed — surfaces privacy policy conflicts and routes to …

anthropics
GENERAL · data-protection

Implementing Transparent Communication

Implements GDPR Article 12 transparent information and communication requirements, covering concise, intelligible, and plain language obligations, re…

mukul975