Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Assess GDPR compliance and build the core records (ROPA, lawful basis, DSAR, DPIA triggers). Use when asked to get GDPR-compliant, build a Record of Processing Activities, decide a lawful basis, handle data-subject requests, or check whether a DPIA is needed. Produces a GDPR assessment — a ROPA, lawful-basis mapping per activity, DSAR workflow, DPIA-trigger screen, and a prioritised gap list.
.claude/skills/mohitagw15856-gdpr-compliance/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 13% | 0% |
| case-03 | ✗→✓ | ▲ Improved | -21% | 0% |
| case-13 | ✗→✓ | ▲ Improved | -8% | 0% |
| case-16 | ✗→✓ | ▲ Improved | 31% | 0% |
| case-07 | ✓→✓ | = Same ✓ | 87% | 0% |
GDPR compliance is mostly bookkeeping you can defend: knowing every place you process personal data, why you're allowed to, how long you keep it, and how a person can get it out or deleted. This skill builds that record (the ROPA), pins a lawful basis to each activity, and flags the high-risk processing that legally requires a DPIA — turning "are we GDPR-compliant?" into a documented, auditable answer.
Ask for these only if they aren't already provided:
1. ROPA — the Record of Processing Activities (Art. 30); one row per activity:
| Activity | Purpose | Data categories | Subjects | Lawful basis | Recipients | Retention | Transfers | |---|---|---|---|---|---|---|---|
2. Lawful basis — the chosen Art. 6 basis per activity (consent / contract / legal obligation / vital interests / public task / legitimate interests) and why. For special-category data, the additional Art. 9 condition. Don't default everything to "consent" — it's often the weakest, hardest-to-maintain basis.
3. DSAR workflow — how you handle access/erasure/portability/objection requests: intake, identity check, the one-month deadline, and how data is located and exported/deleted.
4. DPIA screen — flag activities that legally require a Data Protection Impact Assessment (large-scale special-category processing, systematic monitoring, profiling with legal effects).
5. Gaps — prioritised: missing lawful basis, no retention period, undocumented transfers, no DSAR process.
scripts/ropa_check.py (stdlib only) validates a ROPA and scores completeness so gaps are found mechanically:
bash# ropa.json: [{"activity":"...","purpose":"...","lawful_basis":"contract","retention":"3y","recipients":["..."],"special_category":false,"large_scale":true}, ...] python3 scripts/ropa_check.py ropa.json python3 scripts/ropa_check.py ropa.json --json
It flags activities missing a lawful basis, purpose, or retention, and marks those that trigger a DPIA.
EU GDPR — Art. 6 (lawful basis), Art. 9 (special category), Art. 30 (ROPA), Art. 35 (DPIA), data-subject rights.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-07 | pass→pass | 10,199 | 13,362 | +31% | 1 | 1 | 0% | 1,809 | 3,386 | +87% | 0 | 0 | — |
case-01 | fail→pass | 25,249 | 23,970 | -5% | 1 | 1 | 0% | 4,732 | 5,362 | +13% | 0 | 0 | — |
case-02 | fail→fail | 35,957 | 18,025 | -50% | 1 | 1 | 0% | 6,231 | 4,152 | -33% | 0 | 0 | — |
case-03 | fail→pass | 28,557 | 18,171 | -36% | 1 | 1 | 0% | 5,192 | 4,078 | -21% | 0 | 0 | — |
case-04 | pass→pass | 10,738 | 11,426 | +6% | 1 | 1 | 0% | 1,978 | 2,831 | +43% | 0 | 0 | — |
case-05 | pass→pass | 14,774 | 15,440 | +5% | 1 | 1 | 0% | 2,485 | 3,642 | +47% | 0 | 0 | — |
case-06 | pass→pass | 4,804 | 4,144 | -14% | 1 | 1 | 0% | 852 | 1,628 | +91% | 0 | 0 | — |
case-08 | pass→pass | 12,909 | 10,879 | -16% | 1 | 1 | 0% | 2,335 | 2,845 | +22% | 0 | 0 | — |
case-09 | pass→pass | 11,447 | 8,920 | -22% | 1 | 1 | 0% | 2,091 | 2,472 | +18% | 0 | 0 | — |
case-10 | pass→pass | 12,464 | 11,939 | -4% | 1 | 1 | 0% | 2,093 | 3,019 | +44% | 0 | 0 | — |
case-11 | pass→pass | 9,354 | 11,192 | +20% | 1 | 1 | 0% | 1,665 | 2,835 | +70% | 0 | 0 | — |
case-12 | pass→pass | 10,888 | 10,252 | -6% | 1 | 1 | 0% | 1,972 | 2,820 | +43% | 0 | 0 | — |
case-13 | fail→pass | 9,708 | 4,425 | -54% | 1 | 1 | 0% | 1,930 | 1,785 | -8% | 0 | 0 | — |
case-14 | pass→pass | 15,801 | 16,814 | +6% | 1 | 1 | 0% | 2,838 | 3,960 | +40% | 0 | 0 | — |
case-15 | pass→pass | 13,496 | 13,737 | +2% | 1 | 1 | 0% | 2,615 | 3,645 | +39% | 0 | 0 | — |
case-16 | fail→pass | 5,384 | 1,713 | -68% | 1 | 1 | 0% | 960 | 1,258 | +31% | 0 | 0 | — |
case-17 | pass→pass | 4,367 | 5,179 | +19% | 1 | 1 | 0% | 805 | 1,832 | +128% | 0 | 0 | — |
case-18 | pass→pass | 4,773 | 5,281 | +11% | 1 | 1 | 0% | 868 | 1,912 | +120% | 0 | 0 | — |
case-19 | pass→pass | 9,142 | 8,012 | -12% | 1 | 1 | 0% | 1,872 | 2,470 | +32% | 0 | 0 | — |
case-20 | pass→pass | 10,687 | 10,924 | +2% | 1 | 1 | 0% | 2,119 | 2,866 | +35% | 0 | 0 | — |
case-21 | pass→pass | 9,695 | 9,925 | +2% | 1 | 1 | 0% | 1,883 | 2,785 | +48% | 0 | 0 | — |
case-22 | pass→pass | 15,499 | 13,443 | -13% | 1 | 1 | 0% | 2,845 | 3,594 | +26% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +18 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.