GDPR Desk - audit a personal-data inventory and write its Article 30 record
Paste one product's personal-data inventory (system, data, subjects, purpose, lawful basis, retention, recipients, location) and notes on how it works. Your browser flags Art. 9 and Art. 10 data, missing lawful bases, missing or excessive retention, transfers outside the EEA with no safeguard, weak password hashing, unmasked logs and production data in staging, and reads the DPIA criteria - free. Then an audit lane writes findings with the article, a quote and the fix, and a record lane writes the Article 30 record of processing activities. Derived from the agent skills @wshobson/gdpr-data-handling (wshobson/agents, MIT) and @github/gdpr-compliant (github/awesome-copilot, MIT). Not legal advice.
Details
gpt-terra Every public app is built from a security-scanned skill and must pass a clean scan — skill and frontend — before it can be listed. Have a skill of your own? Turn it into an app — or read the step-by-step walkthrough.