CtrlK
BlogDocsLog inGet started
Tessl Logo

gdpr-dsgvo-expert

GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests with Art. 12(3) one-month deadlines. Use when running GDPR compliance assessments, privacy audits, data protection planning, DPIA generation, or data subject rights (DSAR) management (e.g., 'check this service for GDPR risks', 'track an access request deadline'). Final compliance determinations route to the DPO or legal counsel.

73

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is gdpr-dsgvo-expert in alirezarezvani/claude-skills

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and highly actionable with concrete commands and clear workflows, but it references three reference guides and three scripts that are absent from the bundle, and some concept content overlaps earlier tables. Fixing the missing bundle and trimming redundancy would lift the lower dimensions.

Suggestions

Add the missing bundle files referenced in the body (scripts/gdpr_compliance_checker.py, scripts/dpia_generator.py, scripts/data_subject_rights_tracker.py, references/gdpr_compliance_guide.md, references/german_bdsg_requirements.md, references/dpia_methodology.md), or remove the references if those materials are not provided.

Add explicit validation/verification checkpoints to the workflows (e.g., after running the compliance checker, verify the report was generated and critical issues are addressed before proceeding to DPIA generation).

Trim redundancy between the 'Supported Rights' table and the 'Data Subject Rights' concept list, and reduce basic domain explanations in 'Key GDPR Concepts' to only the article-specific details Claude would not reliably recall.

DimensionReasoningScore

Conciseness

Mostly lean with executable commands, tables, and lists, but the 'Key GDPR Concepts' section partially restates rights already tabulated above and explains some domain basics Claude largely knows, so it could be trimmed.

4 / 5

Actionability

Every tool is shown with copy-paste-ready bash commands including flags and example arguments, and each workflow step maps to a specific executable command — fully actionable.

5 / 5

Workflow Clarity

Three workflows give clear numbered sequences with concrete commands and one checkpoint (identity verification in Workflow 2), but they lack explicit validate→fix→retry feedback loops for the state-changing tracker operations.

4 / 5

Progressive Disclosure

Structure and navigation are good — a TOC, clear sections, and one-level-deep reference paths — but the referenced bundle files (references/*.md and scripts/*.py) do not exist in the bundle, so the signaled references are broken and disclosure is incomplete.

3 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: third-person voice, concrete capabilities, explicit 'Use when' triggers with example phrases, and a clear scope boundary. It hits the top anchor on every dimension.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Scans codebases for privacy risks', 'generates DPIA documentation', 'tracks data subject rights requests with Art. 12(3) one-month deadlines' — with comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

Explicitly answers both what (scan/generate/track) and when ('Use when running GDPR compliance assessments, privacy audits, data protection planning, DPIA generation, or data subject rights (DSAR) management') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural trigger coverage including synonyms (GDPR, DSGVO, DSAR) and example user phrases like 'check this service for GDPR risks' and 'track an access request deadline'.

5 / 5

Distinctiveness Conflict Risk

Clear GDPR/DSGVO compliance niche with distinct triggers and minimal conflict risk; the boundary note 'Final compliance determinations route to the DPO or legal counsel' further sharpens scope.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 23 missing

Warning

Total

15

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.