microsoft/privacy-standards
Privacy planning reference for data-flow reasoning, standards mapping, and DPIA thresholds
npx skills add https://github.com/microsoft/hve-core --skill privacy-standards
This skill is the reusable privacy reference package for the Privacy Planner and Privacy Reviewer. It consolidates the privacy standards backbone, the core data-flow and classification heuristics, and the DPIA threshold logic needed to keep privacy reviews focused on workflow, evidence, and implementation readiness.
> [!NOTE]
> This skill is a planning aid, not legal advice. Its standards summaries support privacy reasoning and review preparation; they do not substitute for qualified legal counsel or a formal regulatory interpretation.
Use these fields when capturing a finding, control, or risk so the reviewer can assert a stable source-control reference:
gdpr_articleccpa_sectionnist_pf_categorynistir8062_objectiveowasp_privacy_id| Privacy phase | Primary standards package | Notes |
|-----------------------|----------------------------------------------|------------------------------------------------------|
| Phase 1 Capture | NIST Privacy Framework + GDPR | Context, scope, and legal basis framing |
| Phase 2 Data Mapping | NIST Privacy Framework + NISTIR 8062 | Data inventory, purpose, and minimization reasoning |
| Phase 3 Risk and DPIA | GDPR + CCPA/CPRA + NISTIR 8062 | DPIA triggers, risk analysis, and proportionality |
| Phase 4 Controls | NIST Privacy Framework + OWASP Privacy Risks | Controls for collection, use, sharing, and retention |
| Phase 5 Impact | GDPR + CCPA/CPRA + OWASP Privacy Risks | Potential harm, mitigation, and monitoring |
| Phase 6 Handoff | All sources | Evidence handoff, review notes, and action tracking |
Use the links below as the reference catalog for open privacy standards and governance resources. Treat the material as planning and review guidance rather than a substitute for legal advice or formal regulatory interpretation.
Take microsoft/privacy-standards from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.