Skill Name
privacy-by-design
Programming Language
Other
Purpose
Provide standalone privacy assessment knowledge bases that complement the existing privacy-standards skill. Most AI projects fail governance reviews due to privacy and data handling gaps, not just security vulnerabilities. The existing privacy-standards skill covers NIST PF, GDPR, CCPA, and OWASP Privacy Risks at a planning level, but lacks dedicated assessment skills for privacy-by-design principles, data minimisation, cross-border transfers, retention/disposal, and production data handling - areas where the security domain already has 7+ OWASP skills.
Prerequisites
- Familiarity with GDPR, CCPA, and Australian Privacy Principles (APP)
- Access to project data inventory or processing records (for assessment mode)
- Existing
privacy-standards skill loaded (for cross-referencing standards backbone)
Requirements
Value Proposition
| Without this skill |
With this skill |
| Privacy Reviewer can only assess against NIST PF, GDPR, CCPA, OWASP Privacy Risks (the 4-standard backbone) |
Privacy Reviewer can also assess against PbD principles, retention/disposal compliance, and APP |
| No structured checks for "is privacy the default?" or "is data disposed securely?" |
Principle-by-principle structured findings with severity ratings |
| No APP (Australian) coverage |
Cross-jurisdictional coverage (GDPR + CCPA + APP) |
Design alignment (PRD NFR-007): The Privacy Planner and Privacy Reviewer remain thin orchestration over skills; this skill adds domain content the agent consumes without requiring agent modification. The agent loads one more skill and applies the same assess→verify→report pipeline.
Skill Behaviors
-
Principle-based assessment: When loaded by the Privacy Reviewer or Privacy Planner agent, enable structured assessment against all 7 PbD Foundation Principles, producing per-principle PASS/FAIL/PARTIAL findings with severity ratings.
-
Retention and disposal verification: Under Principle 05 (End-to-End Security — Full Lifecycle Protection), enable the agent to:
- Verify data retention periods are purpose-linked and documented
- Check disposal methods meet regulatory requirements (secure deletion, anonymisation, cryptographic erasure)
- Identify missing legal hold exception handling
- Flag indefinite retention without justification
-
Standards-cited findings: Every finding emitted by the consuming agent must carry a verbatim source citation (gdpr_article, ccpa_section, app_principle, or PbD principle ID) so compliance reviewers can trace it to authoritative law.
-
Codebase signal detection: Provide signal patterns (consent flows, data collection endpoints, storage configurations, retention policies, deletion endpoints) that the Codebase Profiler subagent uses to determine when this skill is applicable.
-
Cross-jurisdictional mapping: Map each principle to enforceable obligations across GDPR Art. 25, Australian Privacy Principles (APP 1, 3, 6, 8, 11), and CCPA/CPRA, enabling multi-jurisdiction assessment in a single pass.
-
Complement existing privacy-standards: Operate alongside (not replace) the privacy-standards skill. This skill adds PbD-specific assessment depth; privacy-standards continues to own data-flow reasoning, DPIA thresholds, and the four-standard backbone.
-
Structured reference catalog: Provide per-principle reference documents in a references/ subdirectory following the owasp-* skill pattern, loadable on demand by the skill assessor subagent.
Skill Name
privacy-by-design
Programming Language
Other
Purpose
Provide standalone privacy assessment knowledge bases that complement the existing privacy-standards skill. Most AI projects fail governance reviews due to privacy and data handling gaps, not just security vulnerabilities. The existing privacy-standards skill covers NIST PF, GDPR, CCPA, and OWASP Privacy Risks at a planning level, but lacks dedicated assessment skills for privacy-by-design principles, data minimisation, cross-border transfers, retention/disposal, and production data handling - areas where the security domain already has 7+ OWASP skills.
Prerequisites
privacy-standardsskill loaded (for cross-referencing standards backbone)Requirements
Value Proposition
Design alignment (PRD NFR-007): The Privacy Planner and Privacy Reviewer remain thin orchestration over skills; this skill adds domain content the agent consumes without requiring agent modification. The agent loads one more skill and applies the same assess→verify→report pipeline.
Skill Behaviors
Principle-based assessment: When loaded by the Privacy Reviewer or Privacy Planner agent, enable structured assessment against all 7 PbD Foundation Principles, producing per-principle PASS/FAIL/PARTIAL findings with severity ratings.
Retention and disposal verification: Under Principle 05 (End-to-End Security — Full Lifecycle Protection), enable the agent to:
Standards-cited findings: Every finding emitted by the consuming agent must carry a verbatim source citation (
gdpr_article,ccpa_section,app_principle, or PbD principle ID) so compliance reviewers can trace it to authoritative law.Codebase signal detection: Provide signal patterns (consent flows, data collection endpoints, storage configurations, retention policies, deletion endpoints) that the Codebase Profiler subagent uses to determine when this skill is applicable.
Cross-jurisdictional mapping: Map each principle to enforceable obligations across GDPR Art. 25, Australian Privacy Principles (APP 1, 3, 6, 8, 11), and CCPA/CPRA, enabling multi-jurisdiction assessment in a single pass.
Complement existing privacy-standards: Operate alongside (not replace) the
privacy-standardsskill. This skill adds PbD-specific assessment depth;privacy-standardscontinues to own data-flow reasoning, DPIA thresholds, and the four-standard backbone.Structured reference catalog: Provide per-principle reference documents in a
references/subdirectory following theowasp-*skill pattern, loadable on demand by the skill assessor subagent.