gdpr-data-mapperlisted
Install: claude install-skill JayRHa/AgentSkills
# GDPR Data Mapper
## Overview
Produce a clear, auditable map of personal-data processing and the core GDPR artifacts that depend on it. Output is a structured draft to be reviewed by a DPO or counsel — **this skill does not give legal advice**.
Keywords: GDPR, data mapping, RoPA, Article 30, record of processing, lawful basis, consent, legitimate interest, retention schedule, data subject rights, DSAR, data minimization, special category data, processor, controller, cross-border transfer, DPIA.
## Workflow
1. **Inventory processing activities.** List each distinct purpose for which personal data is used (e.g. "account management", "marketing emails", "fraud detection"). One activity per purpose.
2. **For each activity, capture the RoPA fields** (see `templates/ropa-template.md`): controller/processor role, purpose, data categories, data subjects, recipients, retention, transfers, and security measures.
3. **Classify the data.** Flag **special category** data (health, biometrics, religion, etc., Art. 9) and children's data — these need stronger justification. Apply data minimization: challenge every field ("why do we hold this?").
4. **Determine the lawful basis** for each activity using the decision guide in `references/lawful-basis-guide.md`. Exactly one of the six bases per purpose; document the reasoning. For legitimate interest, note that a balancing test (LIA) is required.
5. **Set retention.** Define a concrete retention period and trigger per data category (see `