GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests. Use for GDPR compliance assessments, privacy audits, data protection planning, DPIA generation, and data subject rights management.
88
72%
Does it follow best practices?
Impact
99%
1.28xAverage score across 6 eval scenarios
Passed
No known issues
Optimize this skill with Tessl
npx tessl skill review --optimize ./ra-qm-team/gdpr-dsgvo-expert/SKILL.mdGDPR codebase compliance scanning
Uses checker script
0%
100%
JSON output flag
0%
100%
Output file flag
0%
100%
Compliance score mentioned
50%
100%
Risk categories addressed
100%
100%
GDPR article references
100%
100%
Logging risk identified
100%
100%
Retention risk identified
100%
100%
Top 3 recommendations
50%
50%
Report file present
100%
100%
Data subject rights request management
Uses tracker script
0%
100%
Add subcommand used
0%
100%
Status subcommand used
0%
100%
Template subcommand used
0%
100%
Report subcommand used
0%
100%
Correct request types
100%
100%
30-day deadline referenced
100%
100%
Deadline calculation
100%
100%
Response template output
50%
100%
Compliance report output
50%
100%
DPIA generation for new processing activity
DPIA template step
0%
100%
DPIA generate step
0%
100%
WP29 criteria cited
100%
100%
DPIA required conclusion
100%
100%
DPO threshold identified
100%
100%
§ 26 BDSG requirement
100%
100%
Video surveillance requirement
20%
100%
Works council mentioned
100%
100%
dpia_input.json present
100%
100%
dpia_report.md present
100%
100%
Breach notification compliance
72-hour deadline identified
70%
100%
Nature of breach documented
100%
100%
Categories of data included
100%
100%
Approximate numbers included
100%
100%
DPO contact details included
100%
100%
Likely consequences described
100%
100%
Measures taken or proposed
100%
100%
Special category data risk identified
100%
100%
High-risk conclusion for data subjects
100%
100%
Art. 34 exceptions considered
100%
100%
All breaches documented
100%
100%
Art. 33 or Art. 34 referenced
100%
100%
International transfer safeguards
No adequacy decision
100%
100%
SCCs as mechanism
100%
100%
Correct SCC module
100%
100%
Module 2 described
100%
100%
TIA: third-country legal framework
100%
100%
TIA: contractual safeguards
100%
100%
TIA: technical safeguards
100%
100%
TIA: supplementary measures needed
100%
100%
Employment data context
100%
100%
2021 SCCs referenced
100%
100%
transfer_summary.json structure
100%
100%
Data governance and legal basis documentation
Consent for email marketing
100%
100%
Consent requirements listed
100%
100%
No pre-ticked boxes
100%
100%
ROPA: controller name and contact
100%
100%
ROPA: purposes of processing
100%
100%
ROPA: categories of data and subjects
100%
100%
ROPA: recipients and processors
100%
100%
ROPA: retention periods
100%
100%
ROPA: technical and organizational measures
100%
100%
DPA: documented instructions clause
100%
100%
DPA: sub-processor requirements
100%
100%
DPA: return or delete data
100%
100%
DPA: audit rights
100%
100%
Privacy by design: data minimization
100%
100%
Privacy by design: pseudonymization
100%
100%
967fe01
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.