Skip to content
Back to skills

Gdpr Review

ASecurity

Review how the codebase collects, stores, and shares PII for GDPR compliance

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 3, 2026
ai-agentsgo

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill gdpr-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Gdpr Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Gdpr Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-gdpr-review/badge)](https://www.skillsdirectory.com/skills/black141312-gdpr-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: gdpr-review
description: Review how the codebase collects, stores, and shares PII for GDPR compliance
category: compliance
---

# GDPR Review

Use when auditing a feature or service that touches personal data, or before shipping anything that collects user information into the EU/EEA scope.

1. Inventory PII: grep for fields and patterns (email, name, phone, IP, address, `user_id`, device IDs, geolocation, cookies) and list every place personal data enters the system.
2. Trace data flow for each item — where it is stored (DB tables, logs, caches, analytics, third-party SaaS), how long, and who it is shared with.
3. Check the legal basis and consent: is collection tied to a stated purpose, is consent recorded and revocable, and is data minimized to what the purpose needs.
4. Verify data-subject rights are implementable: export (portability), deletion/erasure, and rectification — confirm a delete actually purges across DB, backups policy, logs, and downstream processors.
5. Check protection controls: encryption at rest/in transit, access scoping, and that PII is not leaking into logs, error traces, URLs, or analytics events.
6. Confirm cross-border transfers and sub-processors have a lawful mechanism, and that retention/auto-expiry is enforced in code, not just documented.
7. Report findings ranked by risk with concrete file/line references and a remediation per gap.

## Rules
- Flag any PII written to plaintext logs, analytics, or third-party trackers without consent — this is a common and serious leak.
- "Soft delete" (a flag) does not satisfy erasure; verify the data is truly removed or anonymized.
- Pseudonymized data is still personal data if it can be re-linked; treat reversible hashing/IDs as PII.
- Do not assume backups are out of scope — note the retention and deletion policy for them.
- You are reviewing engineering controls, not giving legal advice; recommend legal/DPO sign-off for basis and contracts.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…