CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/gdpr-test-patterns

Reference catalog of GDPR-aligned test patterns - data-subject-rights workflows (Art. 15 access, Art. 16 rectification, Art. 17 erasure / "right to be forgotten", Art. 18 restriction, Art. 20 portability, Art. 21 objection); consent recording + revocation per Art. 7; data-residency assertions per Art. 44 - 50 international transfers; breach-notification timing tests per Art. 33 (72 hours); data-minimization assertions in fixtures per Art. 5(1)(c). The California analogue - CCPA/CPRA patterns by Cal. Civ. Code section, including Global Privacy Control (GPC) opt-out, right-to-know, deletion, right-to-correct, and sensitive-PI limits - lives in references/ccpa.md. Use when authoring GDPR- or CCPA/CPRA-readiness tests for any product processing EU or California personal data.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong reference-catalog skill body: executable per-Article test patterns, a validated multi-step workflow with a worked fail→fix→green example, and correct use of a single one-level-deep reference file for the CCPA analogue. The only deductions are minor: some Overview text re-teaches GDPR facts Claude already knows, the two gap/anti-pattern tables partially duplicate each other, and two code snippets have small executability defects.

Suggestions

Trim the Overview's GDPR background (in-force date, fine amounts) and merge the overlapping 'Key compliance gaps' and 'Anti-patterns' tables into one, keeping conciseness tight.

Fix the two executability defects in the code patterns: define/look up `user` in test_consent_revocable, and parse the X-Processing-Time header into a timedelta (or compare dates) instead of comparing the raw header string to timedelta(days=30).

Ground the SAR deadline assertion in the workflow's own step 6 advice ('Pin every timeline assertion to your written policy doc') — the Art. 15 snippet hardcodes 30 days, contradicting the anti-pattern table's warning about hardcoded 30-day assumptions.

DimensionReasoningScore

Conciseness

The body is largely lean — compact code blocks, tables, and no library tutorials — but has minor over-explanation that could be trimmed: the Overview states GDPR basics Claude already knows ('in force 2018-05-25', 'fines up to €20M or 4% of global annual turnover'), and the 'Key compliance gaps' and 'Anti-patterns' tables overlap substantially (multi-store erasure, hardcoded 30-day window, consent revocation appear in both). This matches 'Efficient; minor instances of over-explanation that could be trimmed' rather than 5, and is well above the 3 anchor's 'some unnecessary explanation'.

4 / 5

Actionability

The seven per-Article Python patterns are concrete, framework-realistic, and nearly copy-paste ready, with a specific fixture tool named ('Generate fixture data with `synthetic-pii-generator`'). Not 5 because of minor executability gaps: `test_consent_revocable` uses `user` without defining it, and `assert response.headers['X-Processing-Time'] < timedelta(days=30)` compares a header string to a timedelta, which would fail as written. Not 3 because the guidance is genuinely executable apart from these small spots, not pseudocode.

4 / 5

Workflow Clarity

'How to use' gives a clear 7-step sequence from PII inventory through CI wiring, with an explicit validation checkpoint ('Wire the tests into CI so a schema change that reintroduces PII or skips a system fails the build'), and the 'Worked example' section demonstrates an explicit fail → fix → re-run feedback loop. The gaps and anti-patterns tables function as checklists. This matches the top anchor: clear sequence, explicit validation, feedback loop, and checklists.

5 / 5

Progressive Disclosure

The body is a well-sectioned overview (when/how to use, patterns, worked example, limitations, references) and the CCPA/CPRA catalog is appropriately split into references/ccpa.md — verified to exist and to be one level deep (only external links inside, no nested .md references). It is well-signaled in three places (Overview, frontmatter description, References section), matching 'Clear overview with well-signaled one-level-deep references; content appropriately split'.

5 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: concrete, per-Article capability enumeration paired with an explicit 'Use when' trigger clause covering both EU and California regimes. Dense but every clause carries a distinct capability or trigger term, so the length is informational rather than padded.

DimensionReasoningScore

Specificity

The description enumerates concrete capabilities exhaustively: 'data-subject-rights workflows (Art. 15 access, Art. 16 rectification, Art. 17 erasure / "right to be forgotten", Art. 18 restriction, Art. 20 portability, Art. 21 objection); consent recording + revocation per Art. 7; data-residency assertions... breach-notification timing tests per Art. 33 (72 hours); data-minimization assertions in fixtures per Art. 5(1)(c)'. Each clause names a specific test pattern rather than vague capability language, matching the 'multiple specific concrete actions; comprehensive coverage' anchor. It is not score 4 territory because there is no gap in coverage — even the CCPA/CPRA analogue capabilities are itemized ('GPC opt-out, right-to-know, deletion, right-to-correct, and sensitive-PI limits').

5 / 5

Completeness

Both questions are answered explicitly: the 'what' is 'Reference catalog of GDPR-aligned test patterns' with the full per-Article enumeration, and the 'when' is the explicit trigger clause 'Use when authoring GDPR- or CCPA/CPRA-readiness tests for any product processing EU or California personal data'. This matches the top anchor with concrete trigger phrases; the 'Use when...' clause is present, so the completeness cap of 3 does not apply.

5 / 5

Trigger Term Quality

Natural phrases users would say when they need this skill are comprehensively covered with synonyms: 'GDPR', 'CCPA/CPRA', 'erasure / "right to be forgotten"', 'data portability', 'consent', 'breach notification', 'international transfers', 'readiness tests', 'personal data'. Not 4 because common variations and synonyms are present (erasure + right to be forgotten, GPC opt-out + Global Privacy Control, EU + California framing).

5 / 5

Distinctiveness Conflict Risk

The skill occupies a clear niche (GDPR/CCPA compliance test authoring) with distinct triggers ('Art. 17 erasure', 'Art. 33 breach notification', 'GPC opt-out') unlikely to collide with general testing or privacy skills. Voice is third person ('lives in references/ccpa.md'), so no voice penalty applies.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Reviewed

Table of Contents