Skip to main content

privacy-data-protection-operations-method

Prepare source-bound personal-data inventory, privacy-impact, data-subject request, retention/deletion, and incident evidence when qualified privacy teams need operational review without legal conclusions or production-system action.

Ir a la instalación

Datos de origen

Repositorio
yangheng95/opencorvus
Última actividad en el origen
11 de agosto de 2026 a las 04:09
Idioma detectado de SKILL.md
inglés
Estrellas
312
Forks
40

Opciones de instalación

De forma predeterminada está seleccionado el prompt que primero revisa el origen. Puedes cambiar a un comando directo o descargar una copia local.

Revisa los archivos de origen

Lee SKILL.md y los archivos complementarios que muestra SkillsMP antes de decidir si quieres instalarlo.

Explorador de archivos
10 archivos

Mostrando SKILL.md

SKILL.md
Instrucciones de origen · Vista previa de solo lectura
name
privacy-data-protection-operations-method
description
Prepare source-bound personal-data inventory, privacy-impact, data-subject request, retention/deletion, and incident evidence when qualified privacy teams need operational review without legal conclusions or production-system action.
# Privacy Data Protection Operations Method ## Freeze authority, scope, and minimization 1. Record scope ID, organization and controller/processor roles exactly as supplied, processing/request/incident scope, jurisdictions as questions for counsel, authorized systems and sources with versions, effective date and data cutoff, privacy/security classification, minimization rule, owner, and qualified reviewers. 2. Record decisions supplied by counsel, the Data Protection Officer (DPO), records management, security, and accountable governance as attributed evidence. Never derive legal applicability, role, lawful basis, exemption, deadline, notification duty, compliance, or risk acceptance. 3. Minimize personal data. Use stable evidence references instead of direct identifiers or identity documents. Never store credentials, query strings, exports, response payloads, deletion instructions, or live endpoints. 4. State `decision_not_made`: no legal advice; applicability/basis/role/exemption/refusal/notification/risk decision; identity verification action; production search/export/disclosure/response/deletion/anonymization; retention change or hold release; incident containment; regulator/data-subject contact. ## Map processing inventories and flows Create stable IDs for processing activities, systems, stores, interfaces, transfers, recipients/processors/subprocessors, data-subject groups, and personal-data categories. Trace collection or creation, observation, derivation or inference, use, enrichment, decision support, sharing, transfer, archive, backup, log/cache, and deletion-state evidence. Record purposes, roles, legal bases, safeguards, recipients, transfers, and retention values only as supplied claims with source/version/effective date and accountable owner. Distinguish expected design from observed evidence and active, archive, backup, log, cache, and processor copies. Preserve unknown lineage, unverified processor chains, and inconsistent system inventories. ## Structure privacy-impact evidence Describe processing nature, scope, context, and purpose from the frozen inventory. Link necessity and proportionality claims to their source and owner instead of generating legal conclusions. Build rights-and-freedoms scenarios: affected group; event or cause; exposure or action; potential effect; existing measure; design, implementation, and test evidence; uncertainty; and reviewer. Use only the authorized risk method and scale. Never create a threshold. Separate inherent-scenario evidence, measure design, implementation proof, test result, residual uncertainty, DPO advice, consultation question, and accountable risk decision. A completed template is not a completed or approved Data Protection Impact Assessment (DPIA). ## Trace data-subject requests, retention, and deletion controls Build an immutable chain: intake ID/type/source; receipt-date semantics; identity-evidence status; scope and clarification; deadline supplied by counsel; inventory-driven system list; authorized search-plan and completed search records; result inventory; duplicate/version handling; redaction, third-party, privilege, and exemption questions; response-decision evidence; and closure record supplied by its owner. Do not verify identity, calculate a legal deadline, query production, choose records, redact, disclose, send a response, or decide an exemption. For retention, map each category to source schedule/version/effective date, trigger, supplied period, active/archive/backup/processor copies, hold/exception conflicts, deletion/anonymization request record, and sampled verification evidence. Do not calculate disposal eligibility unless the authorized owner supplies the rule and calculation; never execute it. ## Reconstruct personal-data incident evidence Build a facts-first chronology separating occurrence, detection, discovery, triage, escalation, evidence capture, containment records, assessment, and decision records. Preserve source/log versions, timezones, clock uncertainty, hypotheses, contradictions, and later corrections. Map affected systems and processing activities, data/subject categories, approximate record/subject counts with method and denominator, geographic/recipient context, and confidentiality-integrity-availability effects. Record possible rights-and-freedoms consequences as scenarios rather than findings. Trace remedial evidence and controller/processor communications without operating them. Record a supplied notification decision, its authority, source, and version, but never decide that a breach occurred, calculate a reporting clock, or contact any party. ## Join without legal or operational inference Require compatible inventory, system, source, role, date, request/incident, and jurisdiction scope or preserve mismatch. Cross-link assessment scenarios, request searches, retention rules, and incident evidence to stable processing/activity/system/flow IDs. Reconcile counts only when populations, units, denominators, and cutoffs agree. Retain estimates and conflicts. Classify each branch or joined claim as evidence-complete, qualified-review-required, stopped, or superseded. Populate exactly the five assets in `assets/`. Every material row records stable ID, source locator/version/date, effective date/cutoff, value or quantity with unit/denominator, owner, qualified reviewer, applicability/jurisdiction, assumptions, uncertainty, privacy/license boundary, status, decision_not_made, and stop/escalation reason. ## Stop, escalate, and honor provenance Stop on unauthorized or excessive personal data, credentials, unverifiable source/system versions, absent role/jurisdiction owners, uncontrolled data exposure, retention/hold conflict, or any live/legal/external action request. Do not supply time-sensitive law from memory. Route legal interpretation and privacy risk to the DPO and privacy counsel; inventories and purposes to business/data owners; technical paths to system/security owners; schedules and holds to records and legal-hold owners; containment to security incident response; special employment or sector issues to Human Resources or sector counsel; external decisions to controller/processor governance. Read `references/UPSTREAM.md`, `references/ADAPTATION.md`, `references/LICENSE`, and `references/PRIMARY-SOURCES.md`. This is a bounded modification of selected workflow concepts from the pinned Anthropic Apache-2.0 Skill plus clean-room privacy-operations methodology. It excludes upstream legal summaries, fixed deadlines, recommendations, responses, deletions, and system actions. The upstream file is modified; no NOTICE exists in the nearest licensed subtree.
Ver en GitHub