Back to Skills

gdpr-compliance

verified

GDPR compliance planning including lawful bases, data subject rights, DPIA, and implementation patterns

View on GitHub

Marketplace

melodic-software

melodic-software/claude-code-plugins

Plugin

compliance-planning

Repository
Verified Org

melodic-software/claude-code-plugins
13stars

plugins/compliance-planning/skills/gdpr-compliance/SKILL.md

Last Verified

January 21, 2026

Install Skill

Select agents to install to:

Scope:
npx add-skill https://github.com/melodic-software/claude-code-plugins/blob/main/plugins/compliance-planning/skills/gdpr-compliance/SKILL.md -a claude-code --skill gdpr-compliance

Installation paths:

Claude
.claude/skills/gdpr-compliance/
Powered by add-skill CLI

Instructions

# GDPR Compliance Planning

Comprehensive guidance for General Data Protection Regulation compliance before development begins.

## When to Use This Skill

- Planning systems that process EU residents' personal data
- Designing consent management and preference centers
- Implementing data subject rights (access, erasure, portability)
- Conducting Data Protection Impact Assessments (DPIA)
- Defining data processing agreements and controller/processor relationships

## GDPR Fundamentals

### The 7 Principles

| Principle | Description | Implementation Focus |
|-----------|-------------|---------------------|
| **Lawfulness, Fairness, Transparency** | Valid legal basis, fair processing, clear privacy notices | Consent flows, privacy policies |
| **Purpose Limitation** | Collect for specified, explicit purposes | Purpose tracking, use restriction |
| **Data Minimization** | Adequate, relevant, limited to purpose | Field-level justification |
| **Accuracy** | Keep data accurate and up to date | Update mechanisms, verification |
| **Storage Limitation** | Keep only as long as necessary | Retention policies, auto-deletion |
| **Integrity and Confidentiality** | Appropriate security measures | Encryption, access control |
| **Accountability** | Demonstrate compliance | Audit logs, documentation |

### Lawful Bases for Processing

```text
1. Consent - Freely given, specific, informed, unambiguous
2. Contract - Necessary for contract performance
3. Legal Obligation - Required by law
4. Vital Interests - Protect someone's life
5. Public Task - Official authority/public interest
6. Legitimate Interest - Balanced against data subject rights
```

**Legitimate Interest Assessment (LIA):**

1. Purpose test: Is there a legitimate interest?
2. Necessity test: Is processing necessary for that interest?
3. Balancing test: Do subject's interests override?

## Data Subject Rights Implementation

### Rights Checklist

| Right | Description | Response Time | Implementation |
|-------|-----

Validation Details

Front Matter
Required Fields
Valid Name Format
Valid Description
Has Sections
Allowed Tools
Instruction Length:
11596 chars