| name | gdpr-audit-prep |
| title | /cs:gdpr-audit-prep — GDPR DPO Forcing Questions |
| description | /cs:gdpr-audit-prep <scope> — GDPR audit 6-question Article-cited forcing interrogation. Use before annual internal GDPR review, post-breach internal audit, DPA investigation readiness, or acquisition due diligence. |
| author | alirezarezvani |
| author_url | https://github.com/alirezarezvani/claude-skills/tree/main/compliance-os/skills/gdpr-audit-prep |
| license | MIT |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
/cs:gdpr-audit-prep — GDPR DPO Forcing Questions
Command: /cs:gdpr-audit-prep <scope>
The GDPR DPO auditor pressure-tests any privacy compliance work. Six Article-cited questions before any internal audit, breach response, DPA investigation, or acquisition due diligence.
When to Run
- Before annual internal GDPR audit
- Before quarterly Article 30 RoPA refresh
- Before launching new high-risk processing (Article 35 DPIA required)
- Post-breach (Articles 33-34)
- Before DPA investigation response or supervisory authority engagement
- During acquisition due diligence (target company privacy posture)
- Quarterly during high-volume new-feature shipping
The Six DPO Questions
1. Show me the Article 30 RoPA — with last-updated date.
Most-cited finding area.
- Must include all Article 30(1)(a)-(g) elements for controllers
- Must include all Article 30(2)(a)-(d) elements for processors
- Updated within reasonable time of changes (90 days expected)
- Joint controller arrangements documented per Article 26
2. For this processing activity, what's the lawful basis under Article 6?
Article 6 is exclusive — pick ONE basis per purpose.
- Six options: consent / contract / legal obligation / vital interests / public task / legitimate interests
- Where "legitimate interests": LIA documented
- Where "consent": records per Article 7; withdrawal mechanism
- Special categories (Article 9) require an Article 9(2) exception
3. For high-risk processing, where's the DPIA per Article 35?
Required for high-risk; sample 3-5 activities.
- Article 35(7)(a)-(d) required elements:
- Systematic description of processing
- Necessity + proportionality assessment
- Risks to rights + freedoms
- Measures to address risks
- DPO consulted per Article 35(2)
- Article 36 prior consultation triggered for residual high risk
- For AI systems: integrates with EU AI Act Article 27 FRIA (cross-check with cs-ai-act-compliance)
4. Show me a DSAR from the last 30 days — and the response timing.
Articles 15-22 operational workflow.
- Response within 1 month (Article 12(3)); extension up to 2 months for complex requests
- Identity verification process documented
- Right of access response includes all Article 15 information