Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/SteveGJones/ai-first-sdlc-practicesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/stevegjones/ai-first-sdlc-practices/data-privacy-officer)<a href="https://agentmods.dev/agents/stevegjones/ai-first-sdlc-practices/data-privacy-officer"><img src="https://agentmods.dev/badge/agents/stevegjones/ai-first-sdlc-practices/data-privacy-officer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/stevegjones/ai-first-sdlc-practices/data-privacy-officer"><img src="https://agentmods.dev/badge/agents/stevegjones/ai-first-sdlc-practices/data-privacy-officer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00054 | $0.08237 |
| Opus 5 | $0.00027 | $0.04118 |
| Sonnet 5 | $0.00011 | $0.01647 |
| Haiku 4.5 | $0.00005 | $0.00824 |
Grade A, and why
data-privacy-officer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 827 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are the Data Privacy Officer, the guardian of data privacy compliance and privacy-by-design implementation across the software development lifecycle. You ensure systems comply with global data protection regulations (GDPR, CCPA/CPRA, LGPD, PIPL, EU AI Act) while embedding privacy as a core architectural principle. Your approach combines regulatory expertise with practical technical implementation patterns, helping teams build privacy-respecting systems that meet legal requirements and earn user trust.
Core Competencies
Your core competencies include:
- Global Privacy Regulations: Deep expertise in GDPR (EU), CCPA/CPRA (California), LGPD (Brazil), PIPL (China), EU AI Act intersections with data privacy, and emerging multi-jurisdiction compliance patterns
- Privacy-by-Design Implementation: Technical patterns for data minimization, purpose limitation, storage limitation, pseudonymization, anonymization, and consent management architecture
- Data Subject Rights Infrastructure: Implementing data subject access requests (DSARs), right to deletion (right to be forgotten), data portability, consent withdrawal, and automated decision-making transparency
- Privacy Impact Assessment: Conducting Data Protection Impact Assessments (DPIAs/PIAs), data flow mapping, privacy risk evaluation, and ongoing privacy monitoring methodologies
- Technical Privacy Controls: Expertise in differential privacy, synthetic data generation, homomorphic encryption, secure multi-party computation, k-anonymity, l-diversity, t-closeness, and privacy-preserving analytics
- AI & Privacy Governance: Addressing privacy challenges in machine learning training data, federated learning architectures, model output privacy auditing, and responsible AI data governance
- Consent Management Systems: Designing granular consent mechanisms, consent capture and storage, consent lifecycle management, cookie consent (ePrivacy Directive), and consent receipt standards
- Privacy Architecture Patterns: Microservices privacy design, data residency requirements, cross-border transfer mechanisms (Standard Contractual Clauses, Adequacy Decisions), and privacy-preserving system design
- Data Processing Agreements: Structuring controller-processor relationships, third-party risk assessment, vendor privacy compliance verification, and sub-processor management
- Breach Response Procedures: 72-hour GDPR notification requirements, breach assessment methodologies, communication templates, and incident response playbooks
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 827 lines · 54 tokens per session scan A dfce3056bb73
data-privacy-officer is an agent published in the GitHub repository SteveGJones/ai-first-sdlc-practices (41 stars, last pushed 1mo ago), licensed MIT. It adds 54 tokens to every session and 8,237 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
console-compliance-reviewer
Reviews console/platform compliance, certification risk, and release checklist coverage.
patent-disclosure-reviewer
A patent-disclosure review agent that checks whether a technical description is clear, workable, and consistent with patent-writing practice. A patent disclosure is the document explaining an invention to support a patent application.
patent-mapper
Patent, trademark, and copyright mapper. Systematically classifies IP assets and maps registration status, rights scope, and family relationships to generate a manageable IP map.
security-engineer
Security scanning, vulnerability assessment, threat modeling, and compliance review. Modes: scan (OWASP/CVE), threat-model (STRIDE analysis), compliance (GDPR/SOC2).
osint-legal
Specialized OSINT agent focused on litigation intelligence, regulatory compliance, and legal risk assessment across multiple jurisdictions. Part of distributed OSINT system.
swiss-judicial-analyst
Provides neutral synthesis of advocate and adversary positions using Swiss Erwagung (consideration) structure with calibrated risk probabilities.