Install
openclaw skills install privacy-gdprDeep privacy/GDPR-oriented workflow—lawful basis, data inventory, minimization, DSAR process, DPIA triggers, subprocessors, and breach notification mindset. Use when designing data practices, vendor review, or user rights operations. Not legal advice.
openclaw skills install privacy-gdprThis skill supports structured thinking about personal data. Legal and compliance teams must approve binding interpretations—this is not legal advice.
Trigger conditions:
Initial offer:
Use six stages: (1) scope & roles, (2) inventory & purposes, (3) lawful basis & notices, (4) rights & DSAR, (5) security & subprocessors, (6) DPIA & transfers). Confirm jurisdiction (EU/UK vs broader).
Goal: Identify controller vs processor roles and whose data is involved (employees, customers, minors).
Simple RACI for privacy decisions.
Exit condition: Data subjects and systems in scope are listed.
Goal: Record of processing activities (ROPA-style): what data, why, where stored, retention, who accesses.
Goal: Map processing to lawful basis (consent, contract, legitimate interests, etc.)—lawyers validate per jurisdiction.
Goal: Operational playbook for access, erasure, portability, restriction—with SLAs and identity verification.
Goal: DPAs, SCCs or adequacy for transfers; subprocessor list public where required.
Goal: Recognize when DPIA is likely required (high-risk processing)—escalate to DPO/legal.