commit 3c45d1caeff0459eaefa7c78c2363faf56fe29cf Author: skillfactor-pipeline Date: Fri Aug 14 17:34:43 2026 +0200 feat: data-protection-officer skill package v0.1.0 diff --git a/PROVENANCE.md b/PROVENANCE.md new file mode 100644 index 0000000..ca4a09b --- /dev/null +++ b/PROVENANCE.md @@ -0,0 +1,31 @@ +# Data provenance — data-protection-officer + +Where the content of this skill package comes from, counted by +content items (tasks, competences, tools, evidence entries, curated +knowledge). Rendered live by Gitea: + +```mermaid +%%{init: {'theme':'base','themeVariables':{'pie1':'#f9a825','pie2':'#1e88e5','pie3':'#ff355e','pie4':'#d97757','pie5':'#8e24aa','pieOuterStrokeWidth':'0px','pieSectionTextColor':'#fff'}}}%% +pie showData + title Content sources — data-protection-officer + "ESCO (occupation & competences)" : 50 + "O*NET (tasks & tools)" : 136 + "Job boards (market evidence)" : 107 + "Anthropic official Claude skills" : 5 + "External AI skill packs (mapped)" : 156 +``` + +| Source | Items | Share | Files | +|---|---|---|---| +| ESCO (occupation & competences) | 50 | 11.0 % | references/profile.md, references/skills.md | +| O*NET (tasks & tools) | 136 | 30.0 % | references/tasks.md, references/tools.md | +| Job boards (market evidence) | 107 | 23.6 % | references/market.md (full report) + "Market evidence" headline sections | +| Wikipedia & AI expert curation | 0 | 0.0 % | glossary, literature, usecases, intake, quality, evals/ | +| Anthropic official Claude skills | 5 | 1.1 % | references/ai-skills.md, section "anthropics/skills" (official Claude Code skills) | +| External AI skill packs (mapped) | 156 | 34.4 % | references/ai-skills.md (per-source attribution inside) | +| Stack Exchange practitioner Q&A (CC-BY-SA) | 0 | 0.0 % | references/practitioner-qa.md (per-entry attribution inside) | + +Licensing: O*NET (USDOL/ETA, CC BY 4.0) · ESCO (© European Union) · +job-ad evidence via official APIs (JSearch/Adzuna) · Wikipedia content +paraphrased with source URLs — never copied · external AI skills are +linked, not copied (Apache-2.0/MIT/source-available, see ai-skills.md). diff --git a/SKILL.md b/SKILL.md new file mode 100644 index 0000000..a867ed9 --- /dev/null +++ b/SKILL.md @@ -0,0 +1,66 @@ +--- +name: data-protection-officer +description: "Occupational skill for the role 'data protection officer' (also: data compliance officer, data protection and security officer, DPO, compliance officer data privacy, privacy protection officer, data protection legal advisor). Use when the user asks for typical data protection officer work such as: typical data protection officer responsibilities" +--- + +# Data Protection Officer + +Data protection officers ensure that the processing of personal data in an organisation is compliant with data protection standards and with the obligations set out in the applicable legislation such as GDPR. They elaborate and implement the organisation policy related to data protection, are responsible for data protection impact assessments and handle complaints and requests from third parties and regulatory agencies. Data protection officers lead investigations into potential data breaches, conduct internal audits and act as point of contact within the organisation on any matters related to the processing of personal data. Data protection officers may develop training programmes and provide training to other employees on data protection procedures. + +## Core workflow + + +## How to use this skill + +- Read [references/profile.md](references/profile.md) for the occupation profile and scope. +- Consult [references/tasks.md](references/tasks.md) for the full task and activity inventory. +- Check [references/skills.md](references/skills.md) for essential vs. optional competences. +- Check [references/tools.md](references/tools.md) for the software commonly used in this role. +- See [references/ai-skills.md](references/ai-skills.md) — matched external AI agent skills (per-source attribution). + +## Key competences (essential) + +- advise on government policy compliance +- apply information security policies +- cooperate with colleagues +- cyber security +- data ethics +- data protection +- define organisational standards +- develop information security strategy +- develop organisational policies +- develop training programmes +- ensure compliance with legal requirements +- ensure information privacy +- GDPR +- ICT security legislation +- ICT security standards + +## Hot technologies + +- Adobe Acrobat +- Apple Safari +- Microsoft Access +- Microsoft Excel +- Microsoft Office software +- Microsoft Outlook +- Microsoft PowerPoint +- Microsoft Project +- Microsoft SharePoint +- Microsoft Visio + + + + +## Hot technologies + +Top tools from 34 gated job ads (see references/market.md, as of 2026-07-11): + +- Microsoft Excel — 15 % +- Microsoft PowerPoint — 12 % +- OneTrust — 12 % + + + +--- +*Sources: ESCO v1.2.1 (http://data.europa.eu/esco/occupation/1619d7f3-7d95-407c-a20e-47745bfcde73), O*NET 30.3 (11-9199.02, manual nearest match). See manifest.json for licensing/attribution.* diff --git a/manifest.json b/manifest.json new file mode 100644 index 0000000..2cd5b5f --- /dev/null +++ b/manifest.json @@ -0,0 +1,232 @@ +{ + "name": "data-protection-officer", + "title": "data protection officer", + "version": "0.1.0", + "layer": "core", + "language": "en", + "generated": "2026-07-07", + "ids": { + "esco_uri": "http://data.europa.eu/esco/occupation/1619d7f3-7d95-407c-a20e-47745bfcde73", + "esco_code": "2619.4", + "isco_group": "2619", + "onet_soc": "11-9199.02", + "crosswalk_match": "manual nearest via ISCO 2619 (Compliance Managers)" + }, + "sources": [ + { + "name": "ESCO", + "version": "1.2.1", + "url": "https://esco.ec.europa.eu/" + }, + { + "name": "O*NET", + "version": "30.3", + "url": "https://www.onetcenter.org/", + "license": "CC BY 4.0" + } + ], + "attribution": "This package includes information from the O*NET Database (v30.3) by the U.S. Department of Labor, Employment and Training Administration (USDOL/ETA), CC BY 4.0. skillfactor is not endorsed by USDOL/ETA. ESCO data (v1.2.1) (c) European Union, used per the ESCO download conditions: https://esco.ec.europa.eu/en/use-esco/download", + "counts": { + "tasks": 0, + "dwas": 0, + "skills_essential": 33, + "skills_optional": 16, + "software": 0 + }, + "enrichment_ai_skills": { + "generated": "2026-07-14", + "method": "deterministic mapping (ISCO prefix + title/competence keywords)", + "sources": { + "anthropics/skills": { + "repo": "https://github.com/anthropics/skills", + "commit": "f6656c1", + "license": "Apache-2.0; the document skills (docx/pdf/pptx/xlsx) are source-available \u2014 see the LICENSE.txt in the upstream skill folder", + "skills": 2 + }, + "wshobson/agents": { + "repo": "https://github.com/wshobson/agents", + "commit": "6fd3247", + "license": "MIT (c) Seth Hobson", + "skills": 2 + }, + "jeremylongshore/claude-code-plugins-plus-skills": { + "repo": "https://github.com/jeremylongshore/claude-code-plugins-plus-skills", + "commit": "e112938a", + "license": "MIT", + "skills": 12 + }, + "davila7/claude-code-templates": { + "repo": "https://github.com/davila7/claude-code-templates", + "commit": "fa79251", + "license": "MIT", + "skills": 7 + }, + "a5c-ai/babysitter": { + "repo": "https://github.com/a5c-ai/babysitter", + "commit": "44a5d58b", + "license": "MIT", + "skills": 12 + }, + "alirezarezvani/claude-skills": { + "repo": "https://github.com/alirezarezvani/claude-skills", + "commit": "0241f43", + "license": "MIT", + "skills": 3 + }, + "vibeeval/vibecosystem": { + "repo": "https://github.com/vibeeval/vibecosystem", + "commit": "cea9462", + "license": "MIT", + "skills": 5 + }, + "Sushegaad/Claude-Skills-Governance-Risk-and-Compliance": { + "repo": "https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance", + "commit": "71d8920", + "license": "MIT", + "skills": 1 + }, + "zebbern/claude-code-guide": { + "repo": "https://github.com/zebbern/claude-code-guide", + "commit": "d2c5280", + "license": "MIT", + "skills": 1 + }, + "brycewang-stanford/Auto-Empirical-Research-Skills": { + "repo": "https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills", + "commit": "85bf545", + "license": "CC-BY-4.0", + "skills": 3 + }, + "nWave-ai/nWave": { + "repo": "https://github.com/nWave-ai/nWave", + "commit": "1d0f13c", + "license": "MIT", + "skills": 1 + }, + "mukul975/Anthropic-Cybersecurity-Skills": { + "repo": "https://github.com/mukul975/Anthropic-Cybersecurity-Skills", + "commit": "673da1f", + "license": "Apache-2.0", + "skills": 12 + }, + "mohitagw15856/pm-claude-skills": { + "repo": "https://github.com/mohitagw15856/pm-claude-skills", + "commit": "876fa30", + "license": "MIT", + "skills": 4 + }, + "jabrena/plinth": { + "repo": "https://github.com/jabrena/plinth", + "commit": "065eae8", + "license": "Apache-2.0", + "skills": 1 + }, + "samber/cc-skills-golang": { + "repo": "https://github.com/samber/cc-skills-golang", + "commit": "4881c01", + "license": "MIT", + "skills": 1 + }, + "sboghossian/master-claude-for-legal": { + "repo": "https://github.com/sboghossian/master-claude-for-legal", + "commit": "b5dde5f", + "license": "MIT", + "skills": 1 + }, + "rsmdt/the-startup": { + "repo": "https://github.com/rsmdt/the-startup", + "commit": "ff6a0be", + "license": "MIT", + "skills": 1 + }, + "nexu-io/open-design": { + "repo": "https://github.com/nexu-io/open-design", + "commit": "4b66023", + "license": "Apache-2.0", + "skills": 1 + }, + "giuseppe-trisciuoglio/developer-kit": { + "repo": "https://github.com/giuseppe-trisciuoglio/developer-kit", + "commit": "306f428", + "license": "MIT", + "skills": 1 + }, + "rampstackco/claude-skills": { + "repo": "https://github.com/rampstackco/claude-skills", + "commit": "bc6d961", + "license": "MIT", + "skills": 1 + }, + "open-gitagent/opengap": { + "repo": "https://github.com/open-gitagent/opengap", + "commit": "d7a8e2e", + "license": "MIT", + "skills": 1 + }, + "sgcarstrends/backend": { + "repo": "https://github.com/sgcarstrends/backend", + "commit": "7231cbc", + "license": "MIT", + "skills": 1 + }, + "kazukinagata/shinkoku": { + "repo": "https://github.com/kazukinagata/shinkoku", + "commit": "e610b30", + "license": "MIT", + "skills": 1 + }, + "alirezarezvani/claude-code-skill-factory": { + "repo": "https://github.com/alirezarezvani/claude-code-skill-factory", + "commit": "ba18b31", + "license": "MIT", + "skills": 1 + }, + "infrasity-labs/dev-gtm-claude-skills": { + "repo": "https://github.com/infrasity-labs/dev-gtm-claude-skills", + "commit": "02cfefb", + "license": "MIT", + "skills": 1 + }, + "trailofbits/skills": { + "repo": "https://github.com/trailofbits/skills", + "commit": "cfe5d7b", + "license": "custom (see upstream LICENSE)", + "skills": 2 + }, + "ahacker-1/cre-agent-skills": { + "repo": "https://github.com/ahacker-1/cre-agent-skills", + "commit": "618734e", + "license": "Apache-2.0", + "skills": 1 + } + }, + "total_skills": 80, + "tiers": { + "core": 78, + "adjacent": 2 + } + }, + "provenance": { + "items": { + "esco": 50, + "onet": 136, + "jobads": 107, + "wiki_ai": 0, + "anthropic": 5, + "ai_skills": 156, + "stackx": 0 + }, + "share_percent": { + "esco": 11.0, + "onet": 30.0, + "jobads": 23.6, + "wiki_ai": 0.0, + "anthropic": 1.1, + "ai_skills": 34.4, + "stackx": 0.0 + }, + "method": "content items per source category" + }, + "collar": "white", + "computer_work": true +} \ No newline at end of file diff --git a/references/ai-skills.md b/references/ai-skills.md new file mode 100644 index 0000000..2fac872 --- /dev/null +++ b/references/ai-skills.md @@ -0,0 +1,314 @@ +# External AI agent skills — data-protection-officer + +Proven, publicly available AI agent skills mapped to this occupation. +Nothing is copied from the sources: every entry is a name, a one-line +summary and a link to the upstream skill package. Each section names +its source repository, commit, license and retrieval date. + +**Tiers:** `core` = the skill directly exercises a top market hard +skill, tool or method (from gated job-ad evidence) or an essential +ESCO competence of this occupation; `adjacent` = +plausibly useful, secondary. Entries are capped at 12 per source +and 80 in total per occupation (core first, +strongest matches survive); everything beyond the caps is excluded +and logged in the pipeline audit trail, not in this package. + +_Matched deterministically (ISCO group + title/competence keywords, +tiered against market evidence + ESCO essentials) by +`pipeline/p5_enrich_ai_skills.py` on 2026-07-14._ + +## Source: anthropics/skills + +- Repository: [https://github.com/anthropics/skills](https://github.com/anthropics/skills) (commit `f6656c1`, retrieved 2026-07-14) +- License: Apache-2.0; the document skills (docx/pdf/pptx/xlsx) are source-available — see the LICENSE.txt in the upstream skill folder + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `docx` | adjacent | Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to … | [source](https://github.com/anthropics/skills/tree/main/skills/docx) | +| `pdf` | adjacent | Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text/tables from PDFs, combining or merging multiple PDFs into one, splitting PDFs apart, rotating pages, adding watermarks, creating … | [source](https://github.com/anthropics/skills/tree/main/skills/pdf) | + +## Source: wshobson/agents + +- Repository: [https://github.com/wshobson/agents](https://github.com/wshobson/agents) (commit `6fd3247`, retrieved 2026-07-14) +- License: MIT (c) Seth Hobson + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `gdpr-data-handling` | core | Implement GDPR-compliant data handling with consent management, data subject rights, and privacy by design. Use when building systems that process EU personal data, implementing privacy controls, or conducting GDPR compliance reviews. | [source](https://github.com/wshobson/agents/tree/main/plugins/hr-legal-compliance/skills/gdpr-data-handling) | +| `employment-contract-templates` | core | Create employment contracts, offer letters, and HR policy documents following legal best practices. Use when drafting employment agreements, creating HR policies, or standardizing employment documentation. | [source](https://github.com/wshobson/agents/tree/main/plugins/hr-legal-compliance/skills/employment-contract-templates) | + +## Source: a5c-ai/babysitter + +- Repository: [https://github.com/a5c-ai/babysitter](https://github.com/a5c-ai/babysitter) (commit `44a5d58b`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `gdpr-compliance-automator` | core | GDPR compliance assessment and automation for data mapping, consent management, DSAR handling, and privacy impact assessments | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-compliance/skills/gdpr-compliance-automator) | +| `policy-management` | core | Manage corporate policy lifecycle from drafting through compliance | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/business/legal/skills/policy-management) | +| `license-compliance-checker` | core | Automated license compliance verification for dependencies to ensure legal compliance during migration | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/code-migration-modernization/skills/license-compliance-checker) | +| `openzeppelin` | core | Expert usage of OpenZeppelin Contracts library for secure smart contract development. Covers access control, token standards, governance, upgrades, and security utilities. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/openzeppelin) | +| `regulatory-compliance-assessment` | core | Evaluate organizational compliance with healthcare regulations including HIPAA, CMS Conditions of Participation, and accreditation standards through gap analysis and audit procedures | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/social-sciences-humanities/healthcare/skills/regulatory-compliance-assessment) | +| `constitution-creation` | core | Establish project governing principles including dev guidelines, code quality standards, testing policies, UX requirements, performance benchmarks, and security constraints. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/methodologies/spec-kit/skills/constitution-creation) | +| `grant-proposal-writing` | core | Develop compelling funding proposals for foundations, government agencies, and corporations including narrative development, budget creation, and compliance documentation | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/social-sciences-humanities/arts-culture/skills/grant-proposal-writing) | +| `interview-questions` | core | Generate competency-based and behavioral interview questions with legal compliance validation | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/business/human-resources/skills/interview-questions) | +| `bug-bounty` | core | Bug bounty program management and security disclosure expertise for smart contracts. Covers program setup on Immunefi, vulnerability triage, responsible disclosure coordination, bounty payments, and post-disclosure analysis. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/bug-bounty) | +| `compliance-checker` | core | Check compliance with SOC 2, GDPR, HIPAA, and PCI-DSS standards | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/software-architecture/skills/compliance-checker) | +| `echidna-fuzzer` | core | Property-based testing and fuzzing using Echidna for smart contracts. Includes invariant definition, corpus management, coverage analysis, and CI/CD integration for comprehensive security testing. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/echidna-fuzzer) | +| `iso-nanotechnology-compliance-checker` | core | Regulatory compliance skill for ISO nanotechnology standards verification and documentation | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/science/nanotechnology/skills/iso-nanotechnology-compliance-checker) | + +## Source: ahacker-1/cre-agent-skills + +- Repository: [https://github.com/ahacker-1/cre-agent-skills](https://github.com/ahacker-1/cre-agent-skills) (commit `618734e`, retrieved 2026-07-14) +- License: Apache-2.0 + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `cre-legal` | core | CRE Legal review suite — 6 specialist skills for PSA review, title & survey analysis, estoppel tracking, loan document review, insurance coordination, and transfer document preparation for multifamily acquisitions. | [source](https://github.com/ahacker-1/cre-agent-skills/tree/618734e/claude-code-plugins/cre-legal) | + +## Source: alirezarezvani/claude-code-skill-factory + +- Repository: [https://github.com/alirezarezvani/claude-code-skill-factory](https://github.com/alirezarezvani/claude-code-skill-factory) (commit `ba18b31`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `tech-stack-evaluator` | core | Comprehensive technology stack evaluation and comparison tool with TCO analysis, security assessment, and intelligent recommendations for engineering teams | [source](https://github.com/alirezarezvani/claude-code-skill-factory/tree/ba18b31/generated-skills/tech-stack-evaluator) | + +## Source: alirezarezvani/claude-skills + +- Repository: [https://github.com/alirezarezvani/claude-skills](https://github.com/alirezarezvani/claude-skills) (commit `0241f43`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `ciso-advisor` | core | Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting. Use when … | [source](https://github.com/alirezarezvani/claude-skills/tree/0241f43/c-level-advisor/skills/ciso-advisor) | +| `iso42001-specialist` | core | ISO/IEC 42001:2023 AI Management System (AIMS) specialist for compliance teams running internal audits. Three decisions: (1) Where are the gaps against Clauses 4-10 and what do we close first? (2) What goes in the AI risk register and … | [source](https://github.com/alirezarezvani/claude-skills/tree/0241f43/ra-qm-team/compliance-team-iso42001/skills/iso42001-specialist) | +| `social-media-manager` | core | When the user wants to develop social media strategy, plan content calendars, manage community engagement, or grow their social presence across platforms. Also use when the user mentions 'social media strategy,' 'social calendar,' … | [source](https://github.com/alirezarezvani/claude-skills/tree/0241f43/marketing-skill/skills/social-media-manager) | + +## Source: brycewang-stanford/Auto-Empirical-Research-Skills + +- Repository: [https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills) (commit `85bf545`, retrieved 2026-07-14) +- License: CC-BY-4.0 + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `law-skills` | core | 9 legal research skills. Trigger: legal research, case law analysis, regulatory compliance. Design: legal databases, citation networks, and judicial analytics tools. | [source](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills/tree/85bf545/skills/43-wentorai-research-plugins/skills/domains/law) | +| `legal-research-guide` | core | Legal research methods, case law analysis, and compliance tools | [source](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills/tree/85bf545/skills/43-wentorai-research-plugins/skills/domains/law/legal-research-guide) | +| `legal-nlp-guide` | core | NLP techniques for legal text analysis, case law mining, and contracts | [source](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills/tree/85bf545/skills/43-wentorai-research-plugins/skills/domains/law/legal-nlp-guide) | + +## Source: davila7/claude-code-templates + +- Repository: [https://github.com/davila7/claude-code-templates](https://github.com/davila7/claude-code-templates) (commit `fa79251`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `gdpr-dsgvo-expert` | core | Senior GDPR/DSGVO expert and internal/external auditor for data protection compliance. Provides EU GDPR and German DSGVO expertise, privacy impact assessments, data protection auditing, and compliance verification. Use for GDPR compliance … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/enterprise-communication/gdpr-dsgvo-expert) | +| `Data Privacy Compliance` | core | Data privacy and regulatory compliance specialist for GDPR, CCPA, HIPAA, and international data protection laws. Use when implementing privacy controls, conducting data protection impact assessments, ensuring regulatory compliance, or … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/enterprise-communication/data-privacy-compliance) | +| `security-compliance` | core | Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/development/security-compliance) | +| `google-cloud-waf-security` | core | Generates security-focused guidance for Google Cloud workloads based on the Google Cloud Well-Architected Framework (WAF). Use to evaluate a workload, identify security requirements, and provide actionable recommendations for IAM, network … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/security/google-cloud-waf-security) | +| `laravel-expert` | core | Senior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture, security, performance, and modern standards (Laravel 10/11+). | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/development/laravel-expert) | +| `owasp-security` | core | Comprehensive OWASP-aligned security guidance across six standards - Top 10 (2021) for web apps, ASVS 5.0, MASVS v2.1.0 for mobile, API Security Top 10 (2023), Kubernetes Top 10 (2022), and the Agentic Applications 2026 edition for AI/LLM. … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/.claude-plugin/skills/owasp-security) | +| `brenda-database` | core | Access BRENDA enzyme database via SOAP API. Retrieve kinetic parameters (Km, kcat), reaction equations, organism data, and substrate-specific enzyme information for biochemical research and metabolic pathway analysis. | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/scientific/brenda-database) | + +## Source: giuseppe-trisciuoglio/developer-kit + +- Repository: [https://github.com/giuseppe-trisciuoglio/developer-kit](https://github.com/giuseppe-trisciuoglio/developer-kit) (commit `306f428`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `spring-boot-rest-api-standards` | core | Provides REST API design standards and best practices for Spring Boot projects. Use when creating or reviewing REST endpoints, DTOs, error handling, pagination, security headers, HATEOAS and architecture patterns. | [source](https://github.com/giuseppe-trisciuoglio/developer-kit/tree/306f428/plugins/developer-kit-java/skills/spring-boot-rest-api-standards) | + +## Source: infrasity-labs/dev-gtm-claude-skills + +- Repository: [https://github.com/infrasity-labs/dev-gtm-claude-skills](https://github.com/infrasity-labs/dev-gtm-claude-skills) (commit `02cfefb`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `millers-law` | core | Apply Miller's Law — chunk information into groups of ~4 to work within working memory limits. | [source](https://github.com/infrasity-labs/dev-gtm-claude-skills/tree/02cfefb/.claude/skills/millers-law) | + +## Source: jabrena/plinth + +- Repository: [https://github.com/jabrena/plinth](https://github.com/jabrena/plinth) (commit `065eae8`, retrieved 2026-07-14) +- License: Apache-2.0 + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `803-regulations-gdpr` | core | Use when reviewing, designing, or modifying Java enterprise systems that process personal data and need GDPR-aware engineering controls. This should trigger for requests such as Review a Java service for GDPR privacy controls; Design … | [source](https://github.com/jabrena/plinth/tree/065eae8/skills/803-regulations-gdpr) | + +## Source: jeremylongshore/claude-code-plugins-plus-skills + +- Repository: [https://github.com/jeremylongshore/claude-code-plugins-plus-skills](https://github.com/jeremylongshore/claude-code-plugins-plus-skills) (commit `e112938a`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `canva-data-handling` | core | Implement Canva Connect API data handling, PII protection, and GDPR/CCPA compliance. Use when handling user design data, implementing data retention policies, or ensuring privacy compliance for Canva integrations. Trigger with phrases like … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/canva-pack/skills/canva-data-handling) | +| `windsurf-code-privacy` | core | Configure code privacy and data retention policies. Activate when users mention "code privacy", "data retention", "privacy settings", "data governance", or "gdpr compliance". Handles privacy and data protection configuration. Use when … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/skill-databases/windsurf/skills/windsurf-code-privacy) | +| `granola-security-basics` | core | Security and privacy configuration for Granola meeting data. Use when reviewing data handling practices, configuring encryption, ensuring SOC 2/GDPR compliance, or securing meeting recordings. Trigger: "granola security", "granola … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/granola-pack/skills/granola-security-basics) | +| `notion-data-handling` | core | Implement data handling, PII protection, and GDPR/CCPA compliance for Notion integrations. Use when handling sensitive data from Notion pages, implementing data redaction, or ensuring compliance with privacy regulations. Trigger with … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/notion-pack/skills/notion-data-handling) | +| `palantir-data-handling` | core | Implement Palantir Foundry data handling with PII protection, markings, and GDPR compliance. Use when handling sensitive data in Foundry, implementing data classifications, or ensuring compliance with privacy regulations. Trigger with … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/palantir-pack/skills/palantir-data-handling) | +| `coderabbit-data-handling` | core | Implement CodeRabbit PII handling, data retention, and GDPR/CCPA compliance patterns. Use when handling sensitive data, implementing data redaction, configuring retention policies, or ensuring compliance with privacy regulations for … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/coderabbit-pack/skills/coderabbit-data-handling) | +| `mistral-data-handling` | core | Implement Mistral AI PII handling, data retention, and GDPR/CCPA compliance patterns. Use when handling sensitive data, implementing data redaction, configuring retention policies, or ensuring compliance with privacy regulations for … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/mistral-pack/skills/mistral-data-handling) | +| `vercel-data-handling` | core | Implement data handling, PII protection, and GDPR/CCPA compliance for Vercel deployments. Use when handling sensitive data in serverless functions, implementing data redaction, or ensuring privacy compliance on Vercel. Trigger with phrases … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/vercel-pack/skills/vercel-data-handling) | +| `adobe-data-handling` | core | Implement data handling for Adobe APIs including PII redaction in logs, Firefly content policy compliance, PDF document data classification, and GDPR/CCPA data subject access requests via Adobe Privacy Service. Trigger with phrases like … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/adobe-pack/skills/adobe-data-handling) | +| `posthog-data-handling` | core | PostHog PII handling, GDPR compliance, consent management, data deletion, property sanitization, and privacy-safe analytics configuration. Trigger: "posthog data", "posthog PII", "posthog GDPR", "posthog data retention", "posthog privacy", … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/posthog-pack/skills/posthog-data-handling) | +| `scanning-for-gdpr-compliance` | core | Scan for GDPR compliance issues in data handling and privacy practices. Use when ensuring EU data protection compliance. Trigger with 'scan GDPR compliance', 'check data privacy', or 'validate GDPR'. | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/security/gdpr-compliance-scanner/skills/scanning-for-gdpr-compliance) | +| `find-law-firm` | core | Use whenever the user wants to find, shortlist, vet, or enrich US B2B law firms — corporate, IP/patent, M&A and securities, employment, commercial litigation, regulatory/compliance, data privacy/cyber, real estate, and tax. Triggers on … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/mcp/servicegraph/skills/find-law-firm) | + +## Source: kazukinagata/shinkoku + +- Repository: [https://github.com/kazukinagata/shinkoku](https://github.com/kazukinagata/shinkoku) (commit `e610b30`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `tax-ebookkeeping-context` | core | Background context for the Electronic Bookkeeping Act (電子帳簿保存法) in the shinkoku tax filing plugin. Contains requirements for electronic bookkeeping, scanner storage, mandatory electronic transaction data storage, and shinkoku's compliance … | [source](https://github.com/kazukinagata/shinkoku/tree/e610b30/skills/tax-ebookkeeping-context) | + +## Source: mohitagw15856/pm-claude-skills + +- Repository: [https://github.com/mohitagw15856/pm-claude-skills](https://github.com/mohitagw15856/pm-claude-skills) (commit `876fa30`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `privacy-policy-drafter` | core | Draft a clear, plain-language privacy policy tailored to what a product actually collects and does with data. Use when asked to write a privacy policy, draft a data-protection notice, or create a GDPR/CCPA-aware privacy statement. Produces … | [source](https://github.com/mohitagw15856/pm-claude-skills/tree/876fa30/plugins/pm-legal/skills/privacy-policy-drafter) | +| `compliance-checklist` | core | Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any … | [source](https://github.com/mohitagw15856/pm-claude-skills/tree/876fa30/plugins/pm-legal/skills/compliance-checklist) | +| `gdpr-compliance` | core | Assess GDPR compliance and build the core records (ROPA, lawful basis, DSAR, DPIA triggers). Use when asked to get GDPR-compliant, build a Record of Processing Activities, decide a lawful basis, handle data-subject requests, or check … | [source](https://github.com/mohitagw15856/pm-claude-skills/tree/876fa30/plugins/pm-compliance/skills/gdpr-compliance) | +| `kyc-escalation` | core | Write an internal KYC/AML escalation memo: a factual time-stamped trigger description, customer-profile vs activity mismatch analysis, red-flag taxonomy mapping, outstanding information, and a recommendation with rationale. Use when asked … | [source](https://github.com/mohitagw15856/pm-claude-skills/tree/876fa30/plugins/pm-banking/skills/kyc-escalation) | + +## Source: mukul975/Anthropic-Cybersecurity-Skills + +- Repository: [https://github.com/mukul975/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills) (commit `673da1f`, retrieved 2026-07-14) +- License: Apache-2.0 + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `performing-privacy-impact-assessment` | core | Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices, GDPR Article 35 DPIA and CCPA/CPRA alignment checks, data inventory cataloging, and remediation tracking. Implements the … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/performing-privacy-impact-assessment) | +| `achieving-cmmc-level-2-compliance` | core | Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/achieving-cmmc-level-2-compliance) | +| `implementing-azure-defender-for-cloud` | core | Implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations, and set up adaptive security controls with … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-azure-defender-for-cloud) | +| `hardening-linux-endpoint-with-cis-benchmark` | core | Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Linux servers, remediating audit … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/hardening-linux-endpoint-with-cis-benchmark) | +| `hardening-windows-endpoint-with-cis-benchmark` | core | Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Windows workstations or servers, … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/hardening-windows-endpoint-with-cis-benchmark) | +| `implementing-aws-security-hub-compliance` | core | Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-aws-security-hub-compliance) | +| `implementing-iso-27001-information-security-management` | core | ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-iso-27001-information-security-management) | +| `implementing-aws-security-hub` | core | This skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that aggregates findings from GuardDuty, Inspector, Macie, and third-party tools. It details enabling security standards like CIS AWS … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-aws-security-hub) | +| `performing-endpoint-forensics-investigation` | core | Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/performing-endpoint-forensics-investigation) | +| `analyzing-macro-malware-in-office-documents` | core | Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/analyzing-macro-malware-in-office-documents) | +| `implementing-kubernetes-pod-security-standards` | core | Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-kubernetes-pod-security-standards) | +| `securing-kubernetes-on-cloud` | core | This skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring. It addresses … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/securing-kubernetes-on-cloud) | + +## Source: nexu-io/open-design + +- Repository: [https://github.com/nexu-io/open-design](https://github.com/nexu-io/open-design) (commit `4b66023`, retrieved 2026-07-14) +- License: Apache-2.0 + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `html-ppt-zhangzara-stencil-tablet` | core | A workplace-safety compliance review for a manufacturing regulator — findings, the evidence chain, and the corrective mandate. Built as a decision-grade policy briefing deck for regulator, plant leadership. | [source](https://github.com/nexu-io/open-design/tree/4b66023/design-templates/html-ppt-zhangzara-stencil-tablet) | + +## Source: nWave-ai/nWave + +- Repository: [https://github.com/nWave-ai/nWave](https://github.com/nWave-ai/nWave) (commit `1d0f13c`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `nw-security-and-governance` | core | Database security (encryption, access control, injection prevention), data governance (lineage, quality, MDM), and compliance frameworks (GDPR, CCPA, HIPAA) | [source](https://github.com/nWave-ai/nWave/tree/1d0f13c/nWave/skills/nw-security-and-governance) | + +## Source: open-gitagent/opengap + +- Repository: [https://github.com/open-gitagent/opengap](https://github.com/open-gitagent/opengap) (commit `d7a8e2e`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `document-review` | core | Reviews financial documents (prospectuses, ADVs, marketing materials) for FINRA 2210 compliance, required disclosures, and balanced presentation. Use when reviewing financial statements, audit documents, regulatory filings, or when the … | [source](https://github.com/open-gitagent/opengap/tree/d7a8e2e/examples/full/skills/document-review) | + +## Source: rampstackco/claude-skills + +- Repository: [https://github.com/rampstackco/claude-skills](https://github.com/rampstackco/claude-skills) (commit `bc6d961`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `content-strategy` | core | Develop a content strategy covering editorial positioning, content pillars, formats, calendar, governance, and topical authority planning. Use this skill whenever the user wants to plan a content program, define content pillars, build an … | [source](https://github.com/rampstackco/claude-skills/tree/bc6d961/skills/content-strategy) | + +## Source: rsmdt/the-startup + +- Repository: [https://github.com/rsmdt/the-startup](https://github.com/rsmdt/the-startup) (commit `ff6a0be`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `code-quality-review` | core | Unified code review skill for correctness, design, readability, security, performance, testability, accessibility, and error-handling conventions. Use when reviewing changes, enforcing quality standards, or identifying technical debt. | [source](https://github.com/rsmdt/the-startup/tree/ff6a0be/plugins/team/skills/quality/code-quality-review) | + +## Source: samber/cc-skills-golang + +- Repository: [https://github.com/samber/cc-skills-golang](https://github.com/samber/cc-skills-golang) (commit `4881c01`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `golang-security` | core | Security best practices and vulnerability prevention for Golang. Covers injection (SQL, command, XSS), cryptography, filesystem safety, network security, cookies, secrets management, memory safety, and logging. Apply when writing, … | [source](https://github.com/samber/cc-skills-golang/tree/4881c01/skills/golang-security) | + +## Source: sboghossian/master-claude-for-legal + +- Repository: [https://github.com/sboghossian/master-claude-for-legal](https://github.com/sboghossian/master-claude-for-legal) (commit `b5dde5f`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `master-claude-for-legal` | core | Master skill for legal teams using Claude. Loads the right reference for the user's question (privilege configuration, MCP hardening, MCP connector catalog, practice-area plugins, Microsoft 365 surfaces, managed agents, cold-start … | [source](https://github.com/sboghossian/master-claude-for-legal/tree/b5dde5f) | + +## Source: sgcarstrends/backend + +- Repository: [https://github.com/sgcarstrends/backend](https://github.com/sgcarstrends/backend) (commit `7231cbc`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `email-best-practices` | core | Use when building email features, emails going to spam, high bounce rates, setting up SPF/DKIM/DMARC authentication, implementing email capture, ensuring compliance (CAN-SPAM, GDPR, CASL), handling webhooks, retry logic, or deciding … | [source](https://github.com/sgcarstrends/backend/tree/7231cbc/.agents/skills/email-best-practices) | + +## Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance + +- Repository: [https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) (commit `71d8920`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `gdpr-compliance` | core | Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing Agreements (DPAs), and consent notices, … | [source](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/71d8920/plugins/gdpr-compliance/skills/gdpr-compliance) | + +## Source: trailofbits/skills + +- Repository: [https://github.com/trailofbits/skills](https://github.com/trailofbits/skills) (commit `cfe5d7b`, retrieved 2026-07-14) +- License: custom (see upstream LICENSE) + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `audit-prep-assistant` | core | Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user … | [source](https://github.com/trailofbits/skills/tree/cfe5d7b/plugins/building-secure-contracts/skills/audit-prep-assistant) | +| `trailmark` | core | Builds and queries multi-language source code graphs for security analysis. Includes pre-analysis passes for blast radius, taint propagation, privilege boundaries, and entry point enumeration. Use when analyzing call paths, mapping attack … | [source](https://github.com/trailofbits/skills/tree/cfe5d7b/plugins/trailmark/skills/trailmark) | + +## Source: vibeeval/vibecosystem + +- Repository: [https://github.com/vibeeval/vibecosystem](https://github.com/vibeeval/vibecosystem) (commit `cea9462`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `gdpr-compliance` | core | GDPR compliance - data subject rights, lawful basis, DPIA, privacy by design, breach notification, consent management, cross-border transfers, PII masking | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/gdpr-compliance) | +| `compliance-patterns` | core | GDPR data handling, audit logging, data classification, retention policies, and consent management for regulatory compliance. | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/compliance-patterns) | +| `saas-launch-checklist` | core | Pre-launch verification across infrastructure, security, legal, payment, email, analytics, and performance. Day-1 monitoring, rollback plan, incident response skeleton, and post-launch week-1 checklist. | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/saas-launch-checklist) | +| `hipaa-compliance` | core | HIPAA compliance - PHI protection, technical/administrative/physical safeguards, minimum necessary standard, BAA requirements, de-identification, access logging | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/hipaa-compliance) | +| `kvkk-compliance` | core | KVKK and GDPR compliance patterns - consent management, right to erasure, breach notification, audit logging, cookie consent, and data classification. | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/kvkk-compliance) | + +## Source: zebbern/claude-code-guide + +- Repository: [https://github.com/zebbern/claude-code-guide](https://github.com/zebbern/claude-code-guide) (commit `d2c5280`, retrieved 2026-07-14) +- License: MIT + +| Skill | Tier | What it adds | Upstream | +|---|---|---|---| +| `regulatory-audit-generator` | core | Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like \"run … | [source](https://github.com/zebbern/claude-code-guide/tree/d2c5280/skills/regulatory-audit-generator) | diff --git a/references/market.md b/references/market.md new file mode 100644 index 0000000..63b3907 --- /dev/null +++ b/references/market.md @@ -0,0 +1,155 @@ +# Market evidence report — data-protection-officer + +Source: **34 real job ads** (JSearch API, countries: us 34), extracted into the MSSQL evidence store; as of 2026-07-11. +This report contains extracted, aggregated facts only — no ad text is +reproduced (copyright / platform terms). + +## Seniority distribution + +| Seniority | Ads | Share | +|---|---|---| +| mid | 16 | 47 % | +| senior | 12 | 35 % | +| lead | 4 | 12 % | +| junior | 1 | 3 % | +| n/a | 1 | 3 % | + +## Tools — full market ranking + +| # | Item | Ads | Share | +|---|---|---|---| +| 1 | Microsoft Excel | 5 | 15 % | +| 2 | Microsoft PowerPoint | 4 | 12 % | +| 3 | OneTrust | 4 | 12 % | + +## Hard skills — full market ranking + +| # | Item | Ads | Share | +|---|---|---|---| +| 1 | risk assessment | 16 | 47 % | +| 2 | data protection | 12 | 35 % | +| 3 | regulatory compliance | 12 | 35 % | +| 4 | incident response | 10 | 29 % | +| 5 | risk management | 9 | 26 % | +| 6 | data governance | 8 | 24 % | +| 7 | privacy law | 6 | 18 % | +| 8 | compliance monitoring | 5 | 15 % | +| 9 | contract drafting | 4 | 12 % | +| 10 | data analysis | 4 | 12 % | +| 11 | government contract law | 4 | 12 % | +| 12 | policy development | 4 | 12 % | +| 13 | privacy governance | 4 | 12 % | +| 14 | cybersecurity risk management | 3 | 9 % | +| 15 | gdpr compliance | 3 | 9 % | +| 16 | privacy compliance | 3 | 9 % | +| 17 | privacy risk assessment | 3 | 9 % | +| 18 | regulatory interpretation | 3 | 9 % | + +## Methods — full market ranking + +| # | Item | Ads | Share | +|---|---|---|---| +| 1 | privacy impact assessments | 4 | 12 % | +| 2 | privacy-by-design | 4 | 12 % | +| 3 | compliance audits | 3 | 9 % | +| 4 | data protection impact assessments (dpias) | 3 | 9 % | +| 5 | privacy by design | 3 | 9 % | +| 6 | records of data processing activities | 3 | 9 % | + +## Responsibilities — full market ranking + +| # | Item | Ads | Share | +|---|---|---|---| +| 1 | policy implementation | 6 | 18 % | +| 2 | regulatory monitoring | 5 | 15 % | +| 3 | compliance assessment | 4 | 12 % | +| 4 | employee training | 4 | 12 % | +| 5 | training delivery | 4 | 12 % | +| 6 | training development | 4 | 12 % | +| 7 | contract negotiation | 3 | 9 % | +| 8 | cross-functional collaboration | 3 | 9 % | +| 9 | incident coordination | 3 | 9 % | +| 10 | incident investigation | 3 | 9 % | +| 11 | legal counsel | 3 | 9 % | +| 12 | policy development | 3 | 9 % | +| 13 | policy maintenance | 3 | 9 % | +| 14 | privacy program advice | 3 | 9 % | +| 15 | regulatory engagement | 3 | 9 % | +| 16 | training program development | 3 | 9 % | + +## Regional breakdown + +> **Corpus note:** 34 relevant ads in total — below the 100-ad target for a fully reliable ranking. Percentages above should be read as indicative. + +### US (us) + +34 ads. + +**Top hard skills:** + +- risk assessment — 47 % (16 ads) +- data protection — 35 % (12 ads) +- regulatory compliance — 35 % (12 ads) +- incident response — 29 % (10 ads) +- risk management — 26 % (9 ads) +- data governance — 24 % (8 ads) +- privacy law — 18 % (6 ads) +- compliance monitoring — 15 % (5 ads) +- contract drafting — 12 % (4 ads) +- data analysis — 12 % (4 ads) + +**Top tools:** + +- Microsoft Excel — 15 % (5 ads) +- Microsoft PowerPoint — 12 % (4 ads) +- OneTrust — 12 % (4 ads) +- Anomalo — 6 % (2 ads) +- Atlan — 6 % (2 ads) +- BigQuery — 6 % (2 ads) +- Confluence — 6 % (2 ads) +- DataBricks — 6 % (2 ads) +- Jira — 6 % (2 ads) +- Microsoft Word — 6 % (2 ads) + +**Seniority:** mid 47 % · senior 35 % · lead 12 % · junior 3 % · n/a 3 % + +### UK (gb) + +**Insufficient evidence** — 0 ads (minimum for a regional ranking: 30). No ranking is reported for this region. + +### EU/DACH (de, at, ch, nl) + +**Insufficient evidence** — 0 ads (minimum for a regional ranking: 30). No ranking is reported for this region. + + +## Job title variants in the market + +| Title | Ads | +|---|---| +| Associate General Counsel - Government Contracts & Data Protection Officer | 4 | +| Senior Analyst, Data Privacy - Americas | 3 | +| Data Privacy Officer | 2 | +| Data Protection Officer | 2 | +| Chief Data Protection and Privacy Officer | 1 | +| Chief Privacy & Data Protection Officer | 1 | +| Chief Privacy Officer 21 | 1 | +| Compliance Officer/ Manager/Data Protection Officer | 1 | +| Compliance Privacy Advisor, Principal Associate | 1 | +| Corporate Vice President - Data Protection & Data Risk Management Lead | 1 | +| Data Compliance and Monitoring Specialist | 1 | +| Data Privacy & Compliance Counsel | 1 | +| Data Privacy and Security Coordinator | 1 | +| Data Privacy Operations Manager | 1 | +| Data Privacy Risk Officer - STAAI PO | 1 | +| Data Protection & Risk Management Lead | 1 | +| Data Protection Manager (Associate) | 1 | +| HR Data Privacy Officer | 1 | +| Information Security & Data Privacy Officer | 1 | +| Legal & Data Compliance - Hedge Fund | 1 | +| Privacy & Data Protection Specialist, CHAMP | 1 | +| Privacy Officer | 1 | +| Privacy Officer and Counsel | 1 | +| Senior Data Protection Officer (DPO) Remote/Hybrid | 1 | +| Senior Director Compliance and Privacy | 1 | + +Methodology: entities extracted per ad ({hard_skills, tools, methods, responsibilities, seniority}), normalized, counted as DISTINCT ads per entity; report threshold ≥ 3 ads. Headline sections in skills.md/tools.md use the stricter ≥ 20 % threshold. diff --git a/references/profile.md b/references/profile.md new file mode 100644 index 0000000..419b468 --- /dev/null +++ b/references/profile.md @@ -0,0 +1,28 @@ +# Occupation profile — data protection officer + +- **ESCO URI:** http://data.europa.eu/esco/occupation/1619d7f3-7d95-407c-a20e-47745bfcde73 +- **ESCO code:** 2619.4 +- **ISCO-08 group:** 2619 — Legal professionals not elsewhere classified + +## Description (ESCO) + +Data protection officers ensure that the processing of personal data in an organisation is compliant with data protection standards and with the obligations set out in the applicable legislation such as GDPR. They elaborate and implement the organisation policy related to data protection, are responsible for data protection impact assessments and handle complaints and requests from third parties and regulatory agencies. Data protection officers lead investigations into potential data breaches, conduct internal audits and act as point of contact within the organisation on any matters related to the processing of personal data. Data protection officers may develop training programmes and provide training to other employees on data protection procedures. + +## Definition + +nan + +## Alternative labels + +- data compliance officer +- data protection and security officer +- DPO +- compliance officer data privacy +- privacy protection officer +- data protection legal advisor +- data protection advisor +- privacy officer +- GDPR expert +- data protection counsel +- legal and data protection officer +- data protection specialist diff --git a/references/skills.md b/references/skills.md new file mode 100644 index 0000000..d0bf05b --- /dev/null +++ b/references/skills.md @@ -0,0 +1,80 @@ +# Competences — data protection officer + +Source: ESCO v1.2.1 occupation-skill relations (http://data.europa.eu/esco/occupation/1619d7f3-7d95-407c-a20e-47745bfcde73). + +## Essential + +- **advise on government policy compliance** (skill/competence) +- **apply information security policies** (skill/competence) +- **cooperate with colleagues** (skill/competence) +- **cyber security** (knowledge) +- **data ethics** (knowledge) +- **data protection** (knowledge) +- **define organisational standards** (skill/competence) +- **develop information security strategy** (skill/competence) +- **develop organisational policies** (skill/competence) +- **develop training programmes** (skill/competence) +- **ensure compliance with legal requirements** (skill/competence) +- **ensure information privacy** (skill/competence) +- **GDPR** (knowledge) +- **ICT security legislation** (knowledge) +- **ICT security standards** (knowledge) +- **identify legal requirements** (skill/competence) +- **implement ICT security policies** (skill/competence) +- **information confidentiality** (knowledge) +- **information governance compliance** (knowledge) +- **information security strategy** (knowledge) +- **internal auditing** (knowledge) +- **internal risk management policy** (knowledge) +- **keep up-to-date with regulations** (skill/competence) +- **legal research** (knowledge) +- **legal terminology** (knowledge) +- **manage data for legal matters** (skill/competence) +- **monitor legislation developments** (skill/competence) +- **protect personal data and privacy** (skill/competence) +- **provide legal advice** (skill/competence) +- **respect data protection principles** (skill/competence) +- **respond to enquiries** (skill/competence) +- **train employees** (skill/competence) +- **use consulting techniques** (skill/competence) + +## Optional + +- address identified risks (skill/competence) +- analyse legal enforceability (skill/competence) +- apply system organisational policies (skill/competence) +- assist with litigation matters (skill/competence) +- conduct impact evaluation of ICT processes on business (skill/competence) +- document project progress (skill/competence) +- estimate impact of risks (skill/competence) +- legal case management (knowledge) +- maintain internal communication systems (skill/competence) +- manage digital identity (skill/competence) +- manage keys for data protection (skill/competence) +- perform data cleansing (skill/competence) +- perform project management (skill/competence) +- risk management (knowledge) +- support managers (skill/competence) +- write work-related reports (skill/competence) + + + +## Market evidence (job-ad analysis, 34 ads, as of 2026-07-11) + +Share of analyzed job ads mentioning the item (threshold ≥ 20 %). Source: JSearch/Adzuna APIs. + +### Hard skills + +- risk assessment — **47 %** +- regulatory compliance — **35 %** +- data protection — **35 %** +- incident response — **29 %** +- risk management — **26 %** +- data governance — **24 %** +- privacy law — **18 %** + +### Responsibilities + +- policy implementation — **18 %** + + diff --git a/references/tasks.md b/references/tasks.md new file mode 100644 index 0000000..4461510 --- /dev/null +++ b/references/tasks.md @@ -0,0 +1,69 @@ +# Tasks & work activities — data protection officer + +Source: O*NET 30.3, occupation 11-9199.02 (Compliance Managers) — manual nearest-occupation mapping via ISCO group 2619; the official ESCO crosswalk has no entry for this ESCO occupation. + +## Task statements + +- **[Supplemental]** Verify that software technology is in place to adequately provide oversight and monitoring in all required areas. +- **[Core]** Serve as a confidential point of contact for employees to communicate with management, seek clarification on issues or dilemmas, or report irregularities. +- **[Core]** Maintain documentation of compliance activities, such as complaints received or investigation outcomes. +- **[Core]** Consult with corporate attorneys as necessary to address difficult legal compliance issues. +- **[Core]** Collaborate with human resources departments to ensure the implementation of consistent disciplinary action strategies in cases of compliance standard violations. +- **[Core]** Advise internal management or business partners on the implementation or operation of compliance programs. +- **[Supplemental]** Review communications such as securities sales advertising to ensure there are no violations of standards or regulations. +- **[Core]** Provide employee training on compliance related topics, policies, or procedures. +- **[Core]** Report violations of compliance or regulatory standards to duly authorized enforcement agencies as appropriate or required. +- **[Core]** Provide assistance to internal or external auditors in compliance reviews. +- **[Core]** Prepare management reports regarding compliance operations and progress. +- **[Core]** Monitor compliance systems to ensure their effectiveness. +- **[Core]** Identify compliance issues that require follow-up or investigation. +- **[Core]** Disseminate written policies and procedures related to compliance activities. +- **[Core]** File appropriate compliance reports with regulatory agencies. +- **[Core]** Design or implement improvements in communication, monitoring, or enforcement of compliance standards. +- **[Core]** Conduct periodic internal reviews or audits to ensure that compliance procedures are followed. +- **[Core]** Conduct or direct the internal investigation of compliance issues. +- **[Supplemental]** Advise technical professionals on the development or use of environmental compliance or reporting tools. +- **[Supplemental]** Conduct environmental audits to ensure adherence to environmental standards. +- **[Supplemental]** Direct environmental programs, such as air or water compliance, aboveground or underground storage tanks, spill prevention or control, hazardous waste or materials management, solid waste recycling, medical waste management, indoor air quality, integrated pest management, employee training, or disaster preparedness. +- **[Supplemental]** Evaluate testing procedures to meet the specifications of environmental monitoring programs. +- **[Supplemental]** Review or modify policies or operating guidelines to comply with changes to environmental standards or regulations. +- **[Core]** Discuss emerging compliance issues to ensure that management and employees are informed about compliance reporting systems, policies, and practices. +- **[Core]** Verify that all regulatory policies and procedures have been documented, implemented, and communicated. +- **[Core]** Keep informed regarding pending industry changes, trends, or best practices. +- **[Core]** Direct the development or implementation of policies and procedures related to compliance throughout an organization. +- **[Supplemental]** Develop risk management strategies based on assessment of product, compliance, or operational risks. +- **[Supplemental]** Oversee internal reporting systems, such as corporate compliance hotlines. + +## Detailed work activities + +- Advise others on business or operational matters. +- Advise others on legal or regulatory compliance matters. +- Analyze risks to minimize losses or damages. +- Collaborate on research activities with scientists or technical specialists. +- Communicate organizational policies and procedures. +- Communicate with government agencies. +- Conduct employee training programs. +- Conduct environmental audits. +- Conduct financial or regulatory audits. +- Confer with organizational members to accomplish work activities. +- Coordinate reporting or editing activities. +- Determine operational compliance with regulations or standards. +- Develop computer or information systems. +- Develop emergency response plans or procedures. +- Develop operating strategies, plans, or procedures. +- Develop organizational policies or programs. +- Evaluate green operations or programs for compliance with standards or regulations. +- Examine marketing materials to ensure compliance with policies or regulations. +- Identify actions needed to bring properties or facilities into compliance with regulations. +- Implement organizational process or policy changes. +- Liaise between departments or other groups to improve function or communication. +- Maintain knowledge of current developments in area of expertise. +- Maintain regulatory or compliance documentation. +- Manage control system activities in organizations. +- Manage environmental sustainability projects. +- Monitor organizational compliance with regulations. +- Monitor organizational procedures to ensure proper functioning. +- Prepare reports related to compliance matters. +- Stay informed about current developments in field of specialization. +- Update knowledge about emerging industry or technology trends. +- Verify accuracy of records. diff --git a/references/tools.md b/references/tools.md new file mode 100644 index 0000000..bb84a5d --- /dev/null +++ b/references/tools.md @@ -0,0 +1,81 @@ +# Tools & technology — data protection officer + +Source: O*NET 30.3, occupation 11-9199.02 (Compliance Managers) — manual nearest-occupation mapping via ISCO group 2619; the official ESCO crosswalk has no entry for this ESCO occupation. + +| Software | Category | Hot technology | +|---|---|---| +| Adobe Acrobat | Document management software | yes | +| Apple Safari | Internet browser software | yes | +| Microsoft Access | Data base user interface and query software | yes | +| Microsoft Excel | Spreadsheet software | yes | +| Microsoft Office software | Office suite software | yes | +| Microsoft Outlook | Electronic mail software | yes | +| Microsoft PowerPoint | Presentation software | yes | +| Microsoft Project | Project management software | yes | +| Microsoft SharePoint | Document management software | yes | +| Microsoft Visio | Process mapping and design software | yes | +| Microsoft Windows | Operating system software | yes | +| Microsoft Word | Word processing software | yes | +| Mozilla Firefox | Internet browser software | yes | +| 80-20 Software Leaders4 | Compliance software | | +| Actimize Brokerage Compliance Solutions | Compliance software | | +| Agiliance Compliance Manager | Compliance software | | +| Aline GRC | Compliance software | | +| ARC Logics Sword | Compliance software | | +| Archer Compliance Management | Compliance software | | +| AssurX CATSWeb | Compliance software | | +| AssurX Financial Services Compliance Management System | Compliance software | | +| Audit2 AdaptiveGRC | Compliance software | | +| Axentis Compliance Management | Compliance software | | +| BPS Compliance | Compliance software | | +| BWise Compliance Management | Compliance software | | +| CMO Compliance Regulatory Compliance Solution | Compliance software | | +| Compliance 360 | Compliance software | | +| Compliance11 Supervisory Suite | Compliance software | | +| ComplianceBridge Total Compliance | Compliance software | | +| ControlCase Compliance Manager | Compliance software | | +| Cura Software Solutions Cura for Compliance Management | Compliance software | | +| Data analysis software | Analytical or scientific software | | +| Database management software | Data base management system software | | +| DoubleCheck GRC&T Platform | Compliance software | | +| Email software | Electronic mail software | | +| EtQ Environmental Health and Safety Software | Compliance software | | +| EtQ FDA cGxP Compliance Software for Life Sciences | Compliance software | | +| Fidessa Compliance Manager | Compliance software | | +| FRSGlobal RegPro | Compliance software | | +| Governance, risk, and compliance GRC software | Compliance software | | +| Guideline Risk Technologies RUBI | Compliance software | | +| Healthcare common procedure coding system HCPCS | Medical software | | +| Horwath Software Magique | Analytical or scientific software | | +| Human resource information system (HRIS) | Human resources software | | +| IBM Notes | Electronic mail software | | +| Keane SCORE | Compliance software | | +| LexisNexis | Information retrieval or search software | | +| LRN Ethics and Compliance Alliance | Compliance software | | +| MasterControl MD | Risk management data and analysis software | | +| MasterControl TotalPharma | Risk management data and analysis software | | +| MediRegs ComplyTrack | Compliance software | | +| Methodware ERA | Compliance software | | +| MetricStream Compliance Management | Compliance software | | +| MetricStream Enterprise Compliance Platform | Compliance software | | +| MetricStream Regulatory Reporting | Compliance software | | +| Microsoft Internet Explorer | Internet browser software | | +| Modulo Risk Manager | Compliance software | | +| MyComplianceOffice Compliance Operations Management System | Compliance software | | +| Neohapsis Certus GRC | Compliance software | | +| Oracle Enterprise Governance, Risk, and Compliance Manager | Compliance software | | +| Oracle Insurance Compliance Tracker | Compliance software | | +| policyIQ | Compliance software | | +| Protiviti Governance Portal | Compliance software | | +| QUMAS quality management solution software | Compliance software | | +| Resolve Legislative Compliance Management | Compliance software | | +| RVR Systems Compliance | Compliance software | | +| SAP BEx Report Designer | Data base reporting software | | +| Scheduling software | Calendar and scheduling software | | +| StataCorp Stata | Analytical or scientific software | | +| Sword Achiever Compliance Portal Dashboard | Compliance software | | +| Tax accounting software | Tax preparation software | | +| Tax software | Accounting software | | +| The Garland Group RiskKey | Compliance software | | +| Thomson Reuters Paisley Enterprise GRC | Compliance software | | +| Web browser software | Internet browser software | |