CtrlK
BlogDocsLog inGet started
Tessl Logo

data-privacy-governance

Data privacy governance: privacy-by-design, PII/PHI classification and minimization, encryption, anonymization, retention, access evidence, and tamper-evident audit trails. Routes data quality to data-quality and catalog/lineage strategy to data-strategy.

SKILL.md
Quality
Evals
Security

Data Privacy & Governance

"Govern data like a liability until proven an asset: know what it is, where it flows, and who may touch it." [INFERENCE]

TL;DR

Applies data privacy governance: privacy-by-design (PII/PHI classification, minimization, encryption, anonymization/pseudonymization), retention/access policy, and tamper-evident audit evidence. It does not own data-quality pipelines or catalog/lineage strategy. [EXPLICIT][CONFIG]

For Claude Platform this skill is supporting, never the primary API owner: it reviews PHI/schema-cache boundaries, ZDR/retention claims, file privacy, computer/memory evidence, and cache diagnostics after the relevant runtime/server/client/files/context skill has established the API contract. [CONFIG]

When to use

  • Applying privacy-by-design to a data flow (classify PII/PHI, minimize, encrypt, anonymize). [EXPLICIT]
  • Designing audit trails (tamper-evident, temporal, compliance-ready). [EXPLICIT]
  • Reviewing privacy boundaries around a data pipeline; route the quality implementation to data-quality. [CONFIG]
  • Reviewing classification/retention implications of a catalog; route catalog and lineage strategy to data-strategy. [CONFIG]

Sub-capabilities (resource map)

CapabilityReference
Privacy-by-designreferences/data-privacy-patterns.md
Audit trailsreferences/audit-trail-design.md
Quality implementation boundarydata-quality (references/pipeline-governance.md is legacy context only)
Catalog/lineage boundarydata-strategy (references/data-documentation.md is legacy context only)

Procedure

  1. Classify data (public/internal/PII/PHI); minimize collection to purpose. [DOC]
  2. Protect: encrypt at rest/in transit; anonymize/pseudonymize where identity is not needed. [DOC]
  3. Audit: tamper-evident, append-only trails with who/what/when; align to retention policy. [DOC]
  4. Route schema/quality implementation to data-quality and catalog/lineage ownership to data-strategy; retain only privacy requirements and evidence here. [CONFIG]

Quality Criteria

  • Data classified; collection minimized to purpose. [DOC]
  • PII/PHI encrypted; anonymized where identity is unneeded. [DOC]
  • Audit trails tamper-evident with retention aligned to policy. [DOC]
  • Quality and catalog work has an explicit handoff rather than duplicate ownership. [CONFIG]
  • Claims evidence-tagged. [EXPLICIT]

Anti-Patterns

  • Collecting PII "just in case" with no purpose or retention limit. [DOC]
  • Mutable/over-writable audit logs (non-evidentiary). [DOC]
  • Claiming ownership of generic quality, observability, or catalog implementation from a privacy review. [CONFIG]

Contract

  • Aceptación: datos clasificados y minimizados; PII/PHI cifrada/anonimizada; retención/acceso definidos; audit trails tamper-evident; handoffs explícitos para calidad y catálogo. [EXPLICIT][CONFIG]
  • Límites: capa de privacidad; no implementa calidad (data-quality), catálogo/lineage/estrategia (data-strategy) ni modela esquemas (database-design). [EXPLICIT]
  • Casos borde: anonimización reversible vs irreversible; derecho al olvido vs trails inmutables → diseñar conciliación. [INFERENCE]
  • Supuestos: marco regulatorio aplicable identificable (GDPR/CCPA/HIPAA según sector). [SUPUESTO]
  • Trade-off: controles de privacidad reducen riesgo legal a cambio de fricción operativa y menos datos crudos. [EXPLICIT]

Related Skills

  • data-strategy — sets direction this governs. [EXPLICIT]
  • data-quality — owns pipeline validation and quality gates. [CONFIG]
  • database-design — schemas this classifies and protects. [EXPLICIT]
  • application-security — encryption/access controls at the app layer. [EXPLICIT]
  • claude-api-server-tools, claude-api-client-tools, claude-api-files-documents, claude-api-context-management — own the API mechanics this skill reviews for privacy and retention. [CONFIG]

Packet

Capas del packet, cargables bajo demanda (disciplina ICM: una capa por vez, nunca todas juntas): references/ guías de profundidad (cargar UNA por etapa) · knowledge/ cuerpo de conocimiento · prompts/ prompts listos · examples/ salida de ejemplo · agents/ subagentes del packet · assets/ recursos estáticos.

Repository
JaviMontano/claude-plugins
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.