mcpbeat

Privacy Compliance

cosmicstack-labs/privacy-compliance

GDPR, CCPA, HIPAA, data mapping, consent management, DSR handling, and privacy program management

499 tokens
context cost
the whole folder, loaded on every use
1
files
instructions only
0
copies elsewhere
how many repositories repackaged it
365
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/cosmicstack-labs/mercury-agent-skills --skill privacy-compliance

The instruction itself

7 sections, as written by the author

Privacy & Compliance

Build and maintain privacy compliance programs.

Major Regulations

| Regulation | Scope | Key Requirements |

|------------|-------|------------------|

| GDPR | EU residents | Consent, data rights, breach notification, DPO |

| CCPA/CPRA | California residents | Right to know, delete, opt-out |

| HIPAA | US healthcare | PHI protection, BAAs, security rule |

| LGPD | Brazil | Similar to GDPR |

| PIPEDA | Canada | Consent, access, accuracy |

Core Program Components

Data Mapping

  • Catalog all data collected (PII, sensitive, financial)
  • Document flow: collection → storage → processing → deletion
  • Identify third-party processors and sub-processors
  • Map legal basis for each processing activity
  • Review and update quarterly
  • Obtain explicit, informed consent before collection
  • Record consent with timestamp and version
  • Make withdrawal as easy as giving consent
  • Refresh consent annually or when purpose changes

Data Subject Requests (DSR)

| Request Type | Timeline | Process |

|-------------|----------|---------|

| Access | 30 days | Provide all data in machine-readable format |

| Deletion | 30 days | Delete + request deletion from third parties |

| Correction | 30 days | Fix inaccurate data |

| Portability | 30 days | Export in structured format |

| Objection | 30 days | Stop processing for specific purpose |

Privacy by Design

  • Proactive not reactive — embed privacy from the start
  • Default settings should be most private
  • Minimize data collection to what's necessary
  • Encrypt everywhere (transit and at rest)
  • Retain only as long as needed, then delete

How to use it

Copy the folder

Take cosmicstack-labs/privacy-compliance from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.