Borrowing it
Nothing to install: this file belongs to Hack23/European-Parliament-MCP-Server. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Hack23/European-Parliament-MCP-Server/main/.github/skills/gdpr-compliance/SKILL.mdgit clone --depth 1 https://github.com/Hack23/European-Parliament-MCP-ServerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hack23/european-parliament-mcp-server/gdpr-compliance)<a href="https://agentmods.dev/skills/hack23/european-parliament-mcp-server/gdpr-compliance"><img src="https://agentmods.dev/badge/skills/hack23/european-parliament-mcp-server/gdpr-compliance/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hack23/european-parliament-mcp-server/gdpr-compliance"><img src="https://agentmods.dev/badge/skills/hack23/european-parliament-mcp-server/gdpr-compliance.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00021 | $0.01642 |
| Opus 5 | $0.00010 | $0.00821 |
| Sonnet 5 | $0.00004 | $0.00328 |
| Haiku 4.5 | $0.00002 | $0.00164 |
Grade A, and why
gdpr-compliance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 216 lines — stays where its author put it; the contents beside it link to each section on GitHub.
GDPR Compliance Skill
Context
This skill applies when:
- Processing personal data from European Parliament (MEP information)
- Implementing data minimization strategies
- Supporting GDPR rights (access, rectification, erasure)
- Implementing audit logging for personal data access
- Designing privacy-by-design features
- Handling data retention and deletion
- Implementing consent mechanisms
- Creating data protection impact assessments
GDPR (EU Regulation 2016/679) applies to all processing of EU citizens' personal data. Even though MEP data is public, GDPR principles still apply.
Rules
- Data Minimization: Only collect necessary personal data fields
- Purpose Limitation: Use data only for stated purpose (parliamentary information)
- Storage Limitation: Cache personal data for max 24 hours
- Accuracy: Maintain data integrity, support corrections
- Lawful Basis: Public interest (GDPR Art. 6(1)(e)) for MEP data
- Audit Logging: Log all personal data access
- Right to Rectification: Support data correction requests
- Right to Erasure: Limited for public figures (GDPR Art. 17(3)(e))
- Data Protection by Design: Build privacy into architecture
- Transparency: Document all data processing activities
Examples
✅ Good Pattern: Data Minimization
// GOOD: Only public information
interface MEPPublicData {
id: number;
fullName: string;
country: string;
partyGroup: string;
active: boolean;
// DO NOT collect: private addresses, personal phones, family data
}
// Define data purpose
const DATA_PURPOSE = 'Providing public parliamentary information via MCP protocol';
✅ Good Pattern: Audit Logging
/**
* GDPR-compliant audit logging
* Requirement: GDPR Art. 30 (Records of processing activities)
*/
function logPersonalDataAccess(
actor: string,
subject: string,
purpose: string
): void {
auditLog.record({
timestamp: new Date().toISOString(),
eventType: 'personal_data_access',
actor,
subject,
purpose,
legalBasis: 'GDPR_Art_6_1_e_Public_Interest',
});
}
// Usage
logPersonalDataAccess(
'mcp_client',
'mep:12345',
'Parliamentary information query'
);
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 216 lines · 21 tokens per session scan A 80040df8d010
gdpr-compliance is a skill published in the GitHub repository Hack23/European-Parliament-MCP-Server (28 stars, last pushed yesterday), licensed Apache-2.0. It adds 21 tokens to every session and 1,642 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
check-country-risk
Retrieve composite country risk intelligence — Country Instability Index (CII), travel advisory level, and active sanctions exposure — for one country by ISO code. Use when the user asks how risky or unstable a country is right now.
check-sanctions-pressure
Retrieve normalized OFAC sanctions pressure — designation summaries, recent additions, and per-country/per-program aggregates including sanctioned vessels and aircraft. Use when the user asks which countries or programs face sanctions pressure, or what was recently designated.
prior-art-search
Systematic 7-step methodology for comprehensive patent prior art searches and patentability assessments using BigQuery and CPC classification.
mpep-search
Expert system for searching USPTO MPEP, 35 USC statutes, 37 CFR regulations, and post-Jan 2024 updates.
source-verification
Walks through structured verification of sources, claims, images, video, and documents across five verification modes — visual media, documents, anonymous sources, expert credentials, and social media content — using the SIFT framework, forensic metadata inspection, deepfake indicators, C2PA Content Credentials, and…
Australia — ABR / ASIC Lookup
Live, real-time queries to Australian Business Register (ABR — ABN Lookup) (Australia). Drops the OpenRegistry MCP toolset onto a single-country workflow when the user names ABR / ASIC, the country, or its registry directly. ID format: 11-digit ABN or 9-digit ACN (e.g. ABN 33 123 456 789, ACN 004 028 077 for BHP Group…