gdpr-data-mapper

A personal-data mapping assistant for GDPR, the European Union’s privacy law. It organizes how personal information is used and drafts records such as a Record of Processing Activities (RoPA), which documents an organization’s data processing.

In plain words
What is it for?
Use it to document processing activities, assess lawful bases, set retention periods, identify sensitive or children’s data, and prepare for data-subject requests.
Why use it?
It provides a structured view of where personal data goes, why it is used, how long it is kept, and how people can exercise their rights.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/jayrha/agentskills/gdpr-data-mapper
Any agent
npx skills add JayRHa/AgentSkills --skill gdpr-data-mapper
Clone the repo
git clone --depth 1 https://github.com/JayRHa/AgentSkills

Made for: Claude Code, Codex.

Per session 127 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,084 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00127 $0.01084
Opus 5 $0.00063 $0.00542
Sonnet 5 $0.00025 $0.00217
Haiku 4.5 $0.00013 $0.00108

Measured 2d ago against content hash 9859d85e7ab7, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

gdpr-data-mapper scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

gdpr-data-mapper/SKILL.md · 69 lines

How it starts

The opening of the file, as written. The whole thing — 69 lines — stays where its author put it; the contents beside it link to each section on GitHub.

GDPR Data Mapper

Overview

Produce a clear, auditable map of personal-data processing and the core GDPR artifacts that depend on it. Output is a structured draft to be reviewed by a DPO or counsel — this skill does not give legal advice.

Keywords: GDPR, data mapping, RoPA, Article 30, record of processing, lawful basis, consent, legitimate interest, retention schedule, data subject rights, DSAR, data minimization, special category data, processor, controller, cross-border transfer, DPIA.

Workflow

  1. Inventory processing activities. List each distinct purpose for which personal data is used (e.g. "account management", "marketing emails", "fraud detection"). One activity per purpose.
  2. For each activity, capture the RoPA fields (see templates/ropa-template.md): controller/processor role, purpose, data categories, data subjects, recipients, retention, transfers, and security measures.
  3. Classify the data. Flag special category data (health, biometrics, religion, etc., Art. 9) and children's data — these need stronger justification. Apply data minimization: challenge every field ("why do we hold this?").
  4. Determine the lawful basis for each activity using the decision guide in references/lawful-basis-guide.md. Exactly one of the six bases per purpose; document the reasoning. For legitimate interest, note that a balancing test (LIA) is required.
  5. Set retention. Define a concrete retention period and trigger per data category (see references/retention-and-rights.md). "Indefinite" is not acceptable.
  6. Map data-subject rights readiness. For each activity, note how access, erasure, rectification, portability, restriction, and objection would be fulfilled — and any blockers (e.g. data in backups, third parties).
  7. Flag transfers and DPIA triggers. Note any transfers outside the EEA (and the safeguard: adequacy decision, SCCs) and whether the activity likely needs a DPIA (large-scale, special category, systematic monitoring).
  8. Summarize risks and gaps — missing basis, over-retention, undocumented processors, no DSAR path.

Read the full file on GitHub · 69 lines

Files

What ships with it

3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 69 lines · 127 tokens per session scan A 9859d85e7ab7

Subscribe to this mod's changes

gdpr-data-mapper is a skill published in the GitHub repository JayRHa/AgentSkills (4 stars, last pushed 1mo ago), licensed MIT. It adds 127 tokens to every session and 1,084 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

personal-data-protection

Personal-data-protection compliance reference for engineers building applications subject to Singapore PDPA, Indonesia UU PDP 27/2022, Thailand PDPA B.E. 2562 (2019), Malaysia PDPA 2010 (with the 2024 Amendments), or Philippines DPA (RA 10173). Use when reviewing or modifying code that touches personal data …

hashgraph-online/awesome-codex-plugins · 132 tokens

general-counsel-reviewer

Reviews a proposal, business case, deck or plan in character as a General Counsel archetype, then saves a structured review document with a verdict, findings that cite the artifact, legal risks and five interrogation questions. Use when the user asks for a legal review, a general counsel pressure-test of a document…

kesslernity/awesome-copilot-cowork-skills · 82 tokens

procurement-reviewer

Reviews a proposal, business case, deck or vendor contract in character as a Head of Procurement archetype, then saves a structured review document with a verdict, findings that cite the artifact, commercial risks and five interrogation questions. Use when the user asks for a procurement review, a commercial or…

kesslernity/awesome-copilot-cowork-skills · 85 tokens

contract-review-pack

Abstracts one contract into a key-terms table, compares each term against the user's own playbook of standard positions, and produces a DRAFT contract review pack with a deviations and issues list, open questions and a reviewer checklist. Flags governing law and never gives legal advice, interpretation, or…

kesslernity/awesome-copilot-cowork-skills · 95 tokens

dpia-draft-pack

Reads a project or processing description and produces a DRAFT DPIA pack — processing description, necessity and proportionality questions, a risk table with rating cells left blank, mitigations to consider, and open questions. Never rates risk, determines the lawful basis, or judges adequacy; the DPO assesses and…

kesslernity/awesome-copilot-cowork-skills · 95 tokens

controls-gap-pack

Reads a requirement, regulation, or policy and the organisation's control descriptions, then produces a DRAFT controls-and-gap pack — the requirement broken into obligations, mapped controls, apparent coverage, gaps, and actions to assess. Never concludes compliance or that a control is effective; control owners and…

kesslernity/awesome-copilot-cowork-skills · 82 tokens