Skip to content

feat(skills): add privacy-by-design skill and extended privacy assessment capabilities #2594

Description

@yogitasrivastava

Skill Name

privacy-by-design

Programming Language

Other

Purpose

Provide standalone privacy assessment knowledge bases that complement the existing privacy-standards skill. Most AI projects fail governance reviews due to privacy and data handling gaps, not just security vulnerabilities. The existing privacy-standards skill covers NIST PF, GDPR, CCPA, and OWASP Privacy Risks at a planning level, but lacks dedicated assessment skills for privacy-by-design principles, data minimisation, cross-border transfers, retention/disposal, and production data handling - areas where the security domain already has 7+ OWASP skills.

Prerequisites

  • Familiarity with GDPR, CCPA, and Australian Privacy Principles (APP)
  • Access to project data inventory or processing records (for assessment mode)
  • Existing privacy-standards skill loaded (for cross-referencing standards backbone)

Requirements

Value Proposition

Without this skill With this skill
Privacy Reviewer can only assess against NIST PF, GDPR, CCPA, OWASP Privacy Risks (the 4-standard backbone) Privacy Reviewer can also assess against PbD principles, retention/disposal compliance, and APP
No structured checks for "is privacy the default?" or "is data disposed securely?" Principle-by-principle structured findings with severity ratings
No APP (Australian) coverage Cross-jurisdictional coverage (GDPR + CCPA + APP)

Design alignment (PRD NFR-007): The Privacy Planner and Privacy Reviewer remain thin orchestration over skills; this skill adds domain content the agent consumes without requiring agent modification. The agent loads one more skill and applies the same assess→verify→report pipeline.

Skill Behaviors

  1. Principle-based assessment: When loaded by the Privacy Reviewer or Privacy Planner agent, enable structured assessment against all 7 PbD Foundation Principles, producing per-principle PASS/FAIL/PARTIAL findings with severity ratings.

  2. Retention and disposal verification: Under Principle 05 (End-to-End Security — Full Lifecycle Protection), enable the agent to:

    • Verify data retention periods are purpose-linked and documented
    • Check disposal methods meet regulatory requirements (secure deletion, anonymisation, cryptographic erasure)
    • Identify missing legal hold exception handling
    • Flag indefinite retention without justification
  3. Standards-cited findings: Every finding emitted by the consuming agent must carry a verbatim source citation (gdpr_article, ccpa_section, app_principle, or PbD principle ID) so compliance reviewers can trace it to authoritative law.

  4. Codebase signal detection: Provide signal patterns (consent flows, data collection endpoints, storage configurations, retention policies, deletion endpoints) that the Codebase Profiler subagent uses to determine when this skill is applicable.

  5. Cross-jurisdictional mapping: Map each principle to enforceable obligations across GDPR Art. 25, Australian Privacy Principles (APP 1, 3, 6, 8, 11), and CCPA/CPRA, enabling multi-jurisdiction assessment in a single pass.

  6. Complement existing privacy-standards: Operate alongside (not replace) the privacy-standards skill. This skill adds PbD-specific assessment depth; privacy-standards continues to own data-flow reasoning, DPIA thresholds, and the four-standard backbone.

  7. Structured reference catalog: Provide per-principle reference documents in a references/ subdirectory following the owasp-* skill pattern, loadable on demand by the skill assessor subagent.

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageRequires triage and prioritization

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions