Token导航 LogoToken导航TokenDH.com
待分类只读github未标认证来源可访问许可证需确认审计通过

privacy-compliance隐私合规性

Agent Skill

privacy-compliance 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

441

周安装

18

GitHub Stars

55

下载量

141
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:privacy-compliance(隐私合规性)
来源仓库:https://github.com/vm0-ai/vm0-skills
仓库路径:skills/privacy-compliance
安装命令:
npx skills add https://github.com/vm0-ai/vm0-skills --skill privacy-compliance
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/vm0-ai/vm0-skills --skill privacy-compliance

简介

privacy-compliance 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息。

  • 适合在 Codex、Claude、Cursor、Gemini CLI 中围绕仓库状态、代码变更或协作事项进行整理。
  • 通过 npx skills add 命令从指定仓库安装并使用。
  • 安装前需确认权限范围和维护状态,注意是否会触发联网、命令执行或文件读写。
  • 建议结合原始 README 核验具体用法和功能边界。

SKILL.md

Global Privacy Landscape

EU General Data Protection Regulation (GDPR)

Territorial reach: Governs the processing of personal data belonging to individuals located in the EU/EEA, irrespective of where the processing entity is based.

Core obligations for in-house legal teams:

  • Legal basis documentation: Every processing activity must rest on one of six recognized grounds -- consent, contractual necessity, legitimate interest, statutory obligation, protection of vital interests, or public authority function
  • Individual rights fulfillment: Requests for access, correction, deletion, portability, processing restriction, and objection must be resolved within one calendar month, with a two-month extension available for particularly involved requests
  • Impact assessments (DPIAs): Mandatory when processing is expected to create elevated risk for individuals
  • Incident reporting: The competent supervisory authority must be notified within 72 hours of detecting a personal data breach; affected individuals require prompt notification when the breach poses high risk
  • Processing inventory: Maintain the register of processing activities mandated by Article 30
  • Cross-border safeguards: Transfers outside the EEA require valid mechanisms such as Standard Contractual Clauses, adequacy determinations, or Binding Corporate Rules
  • Data Protection Officer: Appointment is required in specific situations -- public bodies, organizations conducting large-scale processing of sensitive categories, or those engaged in systematic large-scale monitoring

Where in-house teams most often engage:

  • Evaluating vendor DPAs for regulatory alignment
  • Counseling product teams on embedding privacy into design
  • Managing communications with supervisory authorities
  • Maintaining and updating transfer mechanisms
  • Reviewing consent flows and privacy disclosures

California CCPA / CPRA

Territorial reach: Applies to businesses handling the personal information of California residents that satisfy specified revenue, data volume, or data monetization thresholds.

Core obligations:

  • Disclosure right: Individuals may request a full accounting of personal information collected, used, and disclosed
  • Deletion right: Individuals may demand erasure of their personal information
  • Opt-out right: Individuals may prohibit the sale or sharing of their personal information
  • Correction right: Individuals may require amendment of inaccurate records (added by CPRA)
  • Sensitive data limitation: Individuals may restrict the use of sensitive personal information to enumerated purposes (added by CPRA)
  • Equal treatment: Organizations may not penalize individuals who exercise their statutory rights
  • Collection notice: A privacy disclosure must be provided at or before the point of collection, detailing categories gathered and their purposes
  • Vendor agreements: Contracts with service providers must confine personal information use to the specified business function

Fulfillment deadlines:

  • Acknowledge receipt: 10 business days
  • Provide substantive response: 45 calendar days, with a 45-day extension available upon notice

Additional Jurisdictions to Track

FrameworkTerritoryDistinguishing Features
LGPDBrazilClosely modeled on GDPR; DPO appointment mandatory; enforced by the ANPD
POPIASouth AfricaOverseen by the Information Regulator; processing registration required
PIPEDACanada (federal)Consent-centric model; OPC oversight; modernization in progress
PDPASingaporeIncludes Do Not Call registry; mandatory breach notification; PDPC enforcement
Privacy ActAustraliaAustralian Privacy Principles (APPs); notifiable data breaches scheme
PIPLChinaStringent cross-border transfer requirements; data localization mandates; CAC oversight
UK GDPRUnited KingdomPost-Brexit adaptation; ICO supervision; substantively parallel to EU GDPR with UK-specific adequacy framework

Data Processing Agreement Review

When evaluating a DPA or data processing addendum, verify the presence and adequacy of the following elements.

Mandatory Components (per GDPR Article 28)

  • Processing scope and timeline: Clearly articulated subject matter, duration, and boundaries
  • Processing activities: Specific description of what operations will be performed and for what business reason
  • Data categories: Enumeration of the types of personal data involved
  • Data subject populations: Identification of whose data is being processed
  • Controller prerogatives: Specification of the controller's instruction authority and oversight rights

Processor Commitments

  • Instruction adherence: Processor undertakes to act solely on documented controller instructions, except where overridden by applicable law
  • Personnel confidentiality: All individuals authorized to handle personal data have binding confidentiality commitments
  • Security posture: Adequate technical and organizational safeguards are described, referencing Article 32 standards
  • Sub-processing governance:

- Prior written authorization requirement (general or specific) - For general authorization: advance notification of sub-processor changes with a meaningful objection window - Sub-processors contractually bound to equivalent obligations - Processor retains liability for sub-processor conduct

  • Rights request support: Processor commits to assisting the controller with individual rights fulfillment
  • Incident and assessment support: Processor provides assistance with security compliance, breach reporting, impact assessments, and prior consultation
  • End-of-term data handling: Upon contract conclusion, all personal data is deleted or returned at the controller's election; residual copies are destroyed unless law mandates retention
  • Verification rights: Controller holds the right to audit and inspect, or to accept independent third-party audit reports
  • Breach alerting: Processor will report personal data breaches without undue delay, ideally within 24 to 48 hours, ensuring the controller can meet the 72-hour regulatory window

International Transfer Provisions

  • Mechanism specified: SCCs, adequacy determination, Binding Corporate Rules, or other recognized safeguard identified
  • SCC version: Current EU SCCs (adopted June 2021) employed where applicable
  • Module selection: Correct SCC module chosen for the relationship (Controller-to-Processor, Controller-to-Controller, Processor-to-Processor, Processor-to-Controller)
  • Transfer risk evaluation: Completed for destinations lacking an adequacy determination
  • Supplemental safeguards: Technical, organizational, or contractual measures addressing gaps revealed by the transfer risk evaluation
  • UK coverage: If UK personal data is within scope, the UK International Data Transfer Addendum is appended

Operational Alignment

  • Liability coordination: DPA liability terms are consistent with (and do not undermine) the master services agreement
  • Term synchronization: DPA duration aligns with the underlying services contract
  • Geographic specificity: Processing locations are enumerated and acceptable
  • Security certifications: Relevant standards or attestations required (SOC 2 Type II, ISO 27001, etc.)
  • Risk transfer: Adequate insurance coverage for data processing activities confirmed

Recurring DPA Weaknesses

WeaknessExposureRecommended Position
Blanket sub-processor approval without notificationErodes controller oversight of the processing chainMandate advance notice with right to object
Breach notification window exceeding 72 hoursController may miss regulatory reporting deadlineSet notification at 24 to 48 hours
Audit rights limited to third-party reports onlyNo direct verification capabilityAccept SOC 2 Type II as baseline plus direct audit on cause
No data deletion timeline specifiedData may persist indefinitely after contract endRequire deletion within 30 to 90 days of termination
Processing locations undisclosedData could move to any jurisdiction without noticeRequire enumeration of all processing locations
Legacy SCCs still referencedTransfer mechanism may be legally invalidMandate current 2021 EU SCCs

Individual Rights Request Management

Intake Procedure

When an individual rights request arrives:

  1. Categorize the request:

- Access (provide a copy of their personal data) - Correction (fix inaccurate records) - Erasure (remove personal data, the "right to be forgotten") - Processing restriction (pause certain uses) - Portability (deliver data in a structured, machine-readable format) - Objection (challenge a specific processing activity) - Sale/sharing opt-out (CCPA/CPRA) - Sensitive data use limitation (CPRA)

  1. Determine governing law:

- Where does the individual reside? - Which statutes apply given the organization's geographic presence and activities? - What specific procedural requirements and deadlines govern?

  1. Authenticate the requester:

- Confirm the individual's identity through proportionate verification measures - Scale verification rigor to the sensitivity of the data involved - Avoid demanding excessive proof that could itself become a barrier to exercising rights

  1. Record the request:

- Date of receipt - Request category - Requester identity - Applicable statute(s) - Response due date - Assigned team member

Statutory Deadlines

StatuteInitial AcknowledgmentFull ResponseAvailable Extension
GDPRBest practice: promptly30 calendar days+60 days with notice
CCPA/CPRA10 business days45 calendar days+45 days with notice
UK GDPRBest practice: promptly30 calendar days+60 days with notice
LGPDNot prescribed15 calendar daysNarrow extension options

Grounds for Declining or Limiting Fulfillment

Assess whether any recognized exception applies before acting on a request:

Widely recognized exceptions:

  • Establishment, exercise, or defense of legal claims
  • Retention mandated by law or regulation
  • Public interest or exercise of official functions
  • Freedom of expression and information (erasure context)
  • Archival, scientific, or historical research purposes in the public interest

Organization-specific factors:

  • Active litigation hold: data under legal preservation cannot be destroyed
  • Regulatory retention schedules: financial records, employment files, and other categories may have prescribed minimum retention periods
  • Third-party rights: fulfilling the request could adversely affect the rights or freedoms of another individual

Fulfillment Workflow

  1. Locate all personal data pertaining to the requester across organizational systems
  2. Evaluate and document any applicable exceptions
  3. Prepare the response: honor the request or clearly explain why it cannot be fulfilled (in whole or in part)
  4. For any partial or full refusal: cite the precise legal basis
  5. Advise the requester of their right to file a complaint with the relevant supervisory authority
  6. Retain a complete record of the request, the response, and the supporting rationale

Staying Current with Regulatory Change

Areas to Monitor

Keep a continuous watch on:

  • Supervisory authority publications: New or revised guidance from the ICO, CNIL, FTC, state attorneys general, and comparable bodies
  • Enforcement activity: Penalties, orders, and settlements that reveal regulatory priorities and thresholds
  • Legislative movement: Enactment of new privacy statutes, amendments to existing law, and implementing regulations
  • Technical standards evolution: Revisions to ISO 27001, SOC 2, NIST frameworks, and sector-specific requirements
  • Transfer mechanism developments: New or revoked adequacy decisions, SCC modifications, data localization mandates

Practical Monitoring Approach

  1. Official channels: Subscribe to regulatory authority email alerts, RSS feeds, and formal gazette notices
  2. Legal analysis: Follow reputable privacy law publications that contextualize new developments
  3. Industry bodies: Monitor trade association and industry group communications for sector-tailored guidance
  4. Compliance calendar: Maintain a timeline of known effective dates, filing deadlines, and compliance milestones
  5. Team updates: Regularly brief the legal team on developments that affect the organization's data processing activities

When to Escalate

Bring regulatory developments to senior counsel or leadership attention when:

  • New legislation or guidance directly impacts the organization's core processing activities
  • An enforcement action in the organization's industry signals increased regulatory focus
  • An approaching compliance deadline requires operational or technical changes
  • A transfer mechanism the organization depends on faces legal challenge or invalidation
  • A supervisory authority opens a formal inquiry or investigation involving the organization

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

33.95%
按下载量换算48

Claude

30.34%
按下载量换算43

Cursor

19.5%
按下载量换算27

Gemini CLI

10.22%
按下载量换算14

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

只读

该 Skill 主要提供规则、说明或参考内容,本身偏只读;真正读写文件、联网或执行命令仍取决于宿主 Agent 的任务。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills