SKILLS/implementing-gdpr-data-protection-controls/SKILL.md
The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. This skill cover
npx skillsauth add pinkpixel-dev/skills-collection-2 implementing-gdpr-data-protection-controlsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. This skill covers implementing the technical and organizational measures required by GDPR, including data protection by design and by default, Data Protection Impact Assessments (DPIAs), data subject rights management, breach notification procedures, and cross-border data transfer mechanisms.
| Article | Requirement | |---------|-------------| | Art. 5 | Principles: lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, accountability | | Art. 6 | Lawful basis for processing (consent, contract, legal obligation, vital interests, public task, legitimate interest) | | Art. 25 | Data protection by design and by default | | Art. 28 | Processor obligations and contractual requirements | | Art. 30 | Records of processing activities (ROPA) | | Art. 32 | Security of processing (technical and organizational measures) | | Art. 33 | Breach notification to supervisory authority (72 hours) | | Art. 34 | Communication of breach to data subjects | | Art. 35 | Data Protection Impact Assessment (DPIA) | | Art. 37-39 | Data Protection Officer (DPO) appointment and role | | Art. 44-49 | Cross-border data transfers (adequacy, SCCs, BCRs) |
The regulation requires organizations to implement measures appropriate to the risk:
| Right | Article | Description | |-------|---------|-------------| | Right to be informed | 13-14 | Transparent information about processing | | Right of access | 15 | Obtain copy of personal data | | Right to rectification | 16 | Correct inaccurate data | | Right to erasure | 17 | "Right to be forgotten" | | Right to restrict processing | 18 | Limit processing of data | | Right to data portability | 20 | Receive data in machine-readable format | | Right to object | 21 | Object to processing (especially direct marketing) | | Automated decision-making | 22 | Not be subject to solely automated decisions |
development
Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated vulnerability scanning across enterprise environments.
testing
Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex vaccination and kill switch domain monitoring to prevent ransomware from executing. Activates for requests involving ransomware kill switch analysis, mutex vaccination, WannaCry-style domain kill switches, or malware execution guard detection.
testing
Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors on restore verification). Configures backup schedules aligned to RPO/RTO requirements, implements backup credential isolation to prevent ransomware from compromising backup infrastructure, and establishes automated restore testing. Activates for requests involving ransomware backup planning, backup resilience, air-gapped backup design, or backup recovery point objective configuration.
testing
Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate industrial control system networks into hierarchical security zones from Level 0 physical process through Level 5 enterprise, enforcing strict traffic control between OT and IT domains.