The GDPR checklist skill for Claude
You describe what your business does and which systems you use, and the skill walks you through the GDPR basics in seven blocks: which personal data you process, on what legal basis, where it sits, who can access it, which processors you use, how long you keep it and what you do in the event of a data breach. For each part you get a status code, a list of what is missing, an immediate next step and a set of questions for your lawyer. What the skill does not do is give a verdict. It never says whether something is lawful, because that is work for a lawyer and not for a language model.
the lines above come from the zip on this page · SKILL.md is 31,475 bytes
One description in, seven blocks out
reg. A.001This is the first worked example from the SKILL.md, shortened here. Notice what does not happen: no retention period gets filled in that the business owner did not mention, no system gets added that they do not have, and nowhere does it say that something is or is not allowed. Four of the seven blocks end on unknown, and that is the outcome, not a halfway state that still gets tidied away.
What the AI GDPR Checker skill is
The AI GDPR Checker is a free skill from our own library, which with this addition reaches 100 skills. A skill is an instruction file, SKILL.md, that gives an AI assistant a fixed way of working for one task. No software to install, no subscription, no login: one text file of 4,858 words that tells Claude which seven blocks to work through, which questions belong to each one, which status code it sets per part, what it may say about the law and where it has to stop. You download the zip at the top of this page, put it in your Claude environment, and from that moment Claude works to that structure. What a skill actually is and how that file format works is explained in what Claude skills are NL.
The problem the skill solves is not that business owners do not know the GDPR. It is that they do not know what they process. Ask the owner of an installation company which personal data moves through their business and the answer is usually: customer names and addresses, I think. Push further and it becomes twenty: the photos of meter cupboards in a WhatsApp group, the schedule on the foreman's phone, the job applications in a mail folder, the exports in the Downloads folder of a laptop nobody uses any more. Without that overview every checklist is a guessing game, so this skill starts not with the law but with the inventory.
What you get back is deliberately not a document full of ticks. It is an overview of seven blocks in which each part states what you said yourself, what the skill inferred from it, and which status code belongs to it. Five codes: in order, incomplete, missing, unknown and to lawyer. Unknown is a valid outcome and the skill never fills it in to avoid it. That sounds like a detail, but it is exactly where most GDPR tools go wrong: they tick a box because something was filled in, not because something was actually arranged.
The skill is useful for anyone with a business and no privacy department. The sole trader who gets a client on the phone asking if they are GDPR compliant. The fifteen-person SME that has had a webshop for two years and never thought about everything sitting in it. The agency that processes data belonging to its clients' clients and does not know whether it is a processor or a controller. It belongs to the skill library NL that we make available for free through the AI and automation service, with no account and no sales email afterwards.
One thing is stated immediately in the file, and we take it over here word for word: this is not legal advice and the skill never says whether something is lawful. In an ongoing incident, a letter from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), a complaint from a client or employee, or a dispute, it stops the checklist and refers you to a privacy lawyer and to the Autoriteit Persoonsgegevens. That is not in the small print at the bottom, it is stated upfront among the cases where the skill should not start, and it appears in every output it produces.
Why most GDPR checklists get you nowhere
There are hundreds of GDPR checklists in circulation and most of them share the same problem: they ask whether you have arranged something, not what you actually do. You tick that you have a privacy notice, and nobody asks whether it describes what you actually process today. The five patterns below are the reason this skill is built differently, and every one of them can be found in the instructions.
The ticks are about documents, not about data. A privacy notice, a cookie notice and a processing agreement are the visible side. The invisible side is the export file with customer data that someone emailed to their private address last year. This skill therefore starts at blocks 1 to 4, at the data itself, and only afterwards at the paperwork.
The checklist fills itself in. A GDPR overview for a webshop looks like every other GDPR overview for a webshop, and that is exactly why a language model is dangerous here: it knows what usually goes there and fills it in. The file calls this the fastest mistake to make, and the self-check has its own control for it. Anything the user did not say comes out or becomes a question.
It produces a verdict nobody is allowed to give. The moment a tool says you comply, it has turned into a legal verdict. That is refused in both directions: it does not say something is allowed, and it does not say something is wrong either. It describes what you said, sets what the law literally says next to it, and turns the rest into a question for a lawyer. Reassurance is a verdict too, and the self-check removes that just as hard.
It states retention periods that come from nowhere. This is the most common mistake in GDPR text on the internet, and AI models happily copy it. The GDPR itself names almost no concrete retention periods: Article 5(1)(e) only says you do not keep data longer than necessary for the purpose. Periods you do come across come from other laws, such as the seven-year tax retention duty under article 52 of the Dutch General Tax Act (Algemene wet inzake rijksbelastingen). It is therefore not allowed to fill in a period itself, not a single one.
No first step comes out of it. Fifty recommendations are about as useful as zero. So it produces one immediate next step, with who does it and what counts as done when it is finished, and puts the rest in a list of questions for the lawyer. That way you know what you solve yourself and what you are paying for. That saves on the lawyer's bill, because the searching is yours to do and the judging is theirs.
In diff form, with the correction the self-check makes in almost every first draft: the verdict out, the description with the question in.
Seven questions, five status codes
reg. A.002This is the core of the file: seven blocks in a fixed order, each with three to five concrete questions. The order is not arbitrary. The first four are about the data itself, and only once that is in view do the last three carry any meaning. Under each block, in mono, is what the GDPR says about it, with the article attached. Below that the five status codes the skill works with, because there is nothing between in order and unknown.
What is actually inside the SKILL.md
A skill is only as good as its instructions, so we just describe them here. The file opens with a frontmatter that states when Claude should pick up the skill. Not only for the obvious terms such as gdpr checklist, creating a record of processing, working out a legal basis or needing a processing agreement, but also for sentences people actually use: i have no idea where all our customer data sits, we have never done anything about the gdpr, my accountant asked about a processing register, a client is asking if we are gdpr compliant, am i still allowed to send my newsletter, how long do i have to keep cvs. The same frontmatter also states when it should specifically not start, and below that the licence: MIT, version 1.0.0.
Then comes the core: nine fixed actions. First it establishes whether this is an inventory or an incident, because with something happening right now the checklist stops.
It draws out the context. It works through the seven blocks with three to five questions per block, in small portions rather than a list of thirty lines. For every answer it notes whether it was said by the user or inferred by itself. It sets a status code per part. It adds what the GDPR literally says, with the article, and what it specifically does not say. It makes the immediate next step concrete. It runs the self-check pass. And it closes with the limits block, which never lapses, even if you ask it to.
Before the blocks get filled in the skill runs through a mandatory input checklist of eight points: what the business does and how many people work there, who the data subjects are, which types of data are involved, which systems and tools are used including loose phones and paper folders, which parties process on its instructions, whether any data ends up outside the European Economic Area, what documents already exist, and whether anything has ever gone wrong. On that last point sits the referral: if it is happening now, the checklist does not go ahead. One line in that checklist stands out and is typical for this subject: do not ask for real personal data. Categories are enough, and a supplied customer list is not used by the skill.
The output has a fixed structure of eight blocks. A header with the business, the date and how many answers are marked unknown. The seven blocks with the source and the status code per line. What is in order, and that block is allowed to be empty. What is missing or unknown, ordered by how many other answers depend on it and explicitly not by risk, because assessing risk is legal work. The immediate next step. Five to ten questions for your lawyer, worded exactly as given, with the facts from the conversation attached. The limit of this overview. And finally a block stating what the self-check adjusted.
That block with questions for the lawyer is where the skill earns its keep, even though it costs nothing. In the example in the file it produces seven, including: is our accountancy firm a processor or an independent controller for the payroll administration, and do we fall under the registration duty of article 30 or under the exemption in paragraph 5. Those are questions a lawyer can act on immediately, and where a business owner gets stuck alone because the answer depends on the circumstances.
The file also contains two fully worked examples with input and full output, a chapter of writing rules, the eleven things the skill never does, a list of moments when you need a lawyer or the Autoriteit Persoonsgegevens, and a source list with four main sources plus two laws that come up alongside the GDPR. Want to learn to set up this kind of instruction file yourself? The approach is in writing a SKILL.md NL.
The draft attacks itself
reg. A.003This is the part where it differs most from an ordinary questionnaire. It never delivers a first draft. It writes the overview, then attacks it against its own rules, corrects whatever does not survive and reports at the bottom what was changed. Seven checks, in fixed order. Under each check sits the correction exactly as it was actually made in the example from the file: the red line came out, the green one went back in its place.
What the skill rests on, and what the law does and does not say
The source list in the file is short, and that is deliberate. Four sources: the text of the General Data Protection Regulation itself, Regulation (EU) 2016/679, in force since 25 May 2018 and readable via EUR-Lex; the Dutch GDPR Implementation Act (Uitvoeringswet AVG) via wetten.overheid.nl; the guidance and reporting channels of the Autoriteit Persoonsgegevens; and the guidelines of the European Data Protection Board. Everything the skill says about the law has to be traceable to those. If it invents an article number or a threshold, the self-check takes it out.
The legal bases sit in article 6(1). Six of them: consent, performance of a contract, legal obligation, vital interest, public interest or official authority, and legitimate interest. What is not in there is which basis fits your newsletter, your camera surveillance or your customer file. Which basis you think you are using therefore gets noted, and not confirmed. With legitimate interest the part goes to the lawyer by default, because that is the basis with the most real-world debate around it.
The record of processing activities sits in article 30, with an exemption in paragraph 5. That exemption applies to organisations with fewer than 250 employees, unless the processing could pose a risk to the rights and freedoms of data subjects, the processing is not occasional, or it involves special categories of personal data or data on criminal convictions. Those exceptions always get added, with no conclusion on whether your business falls under it. That is exactly the kind of question you take to the lawyer, and the overview you build with the skill contains most of what they will then want to know.
The processing agreement sits in article 28. The relationship with a processor is set out in a contract or another legal act, and the article lists what has to be arranged in it. What is not in there is whether a specific party is a processor in your case. For an accountancy firm that answer is not always the same, and the skill does not take a side on it.
The data breach notification sits in article 33. A breach is reported to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely that the breach poses a risk to the rights and freedoms of individuals. Paragraph 5 of that same article says you document every breach, including the ones not reported. Article 34 covers informing the data subjects themselves in the event of a likely high risk. Those words likely and risk are exactly why the skill does not make that call: that is a legal judgement about a specific situation.
Two things that often get mixed up, and that the file keeps apart. Retention periods rarely come from the GDPR: article 5(1)(e) only names the principle of storage limitation, and concrete periods come from other laws such as the seven-year tax retention duty in article 52 of the Dutch General Tax Act (Algemene wet inzake rijksbelastingen). And cookies in the Netherlands are governed by article 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet), not by the GDPR. It can therefore name cookies as a separate subject, but it does not assess a cookie banner. Anyone who wants their website checked on that point is better off with a WordPress specialist who knows the technique behind it, and after that still with a lawyer for the verdict.
What the skill refuses
reg. A.004The SKILL.md contains a list of eleven things the skill never does, and on a subject with a law wrapped around it, that list matters more than what it does do. A wrong GDPR answer spreads: it goes into an email to a client, it ends up in a tender, and nobody knows any more where it came from. Eleven requests you might make, with the response the skill gives according to its own instructions.
Installing in Claude Code, Claude.ai or Codex
The zip contains one folder, ai-gdpr-checker, with the SKILL.md inside it. Installing is a matter of putting the file in the right place, and that place differs per environment. SKILL.md has been an open standard since December 2025, so the same skill also works in Codex, Cursor and Gemini CLI. So you are not downloading a Claude file but a working instruction that any modern AI assistant can read.
- Unzip it into
~/.claude/skills/(or.claude/skills/in your project). - Claude then recognises the skill by itself as soon as you bring up the GDPR, personal data or a processing agreement.
- You can also call it directly, with
/ai-avg-checker.
- Go to Customize and then Skills.
- Upload the zip there as a skill.
- Or paste the contents of SKILL.md into the project instructions of a Project.
- Open
AGENTS.mdin your repository. - Paste the contents of SKILL.md into it, or put SKILL.md next to it as a separate file and refer to it from
AGENTS.md. - Codex reads that along at every session.
After that, using it is simple: say what your business does, how many people work there and which tools you use. It asks itself for whatever is missing, block by block, and it does not ask for real customer data. How long that conversation takes depends mostly on how much you have to hand: as soon as you have to start searching for where things sit, it gets longer. That searching is, by the way, not wasted time but the point of the exercise. If you get stuck while installing, the full step-by-step plan per environment is in installing Claude skills NL, and the broader explanation of working with AI is in the knowledge base.
When to use it, and when not
It is at its strongest when nothing is arranged yet and nobody knows exactly what moves through the business. Then it does what it was built for: completing the picture and naming the gaps. It is also useful as preparation for a conversation with a lawyer or an adviser, and that may be the most honest use of all: you then pay for the judgement and not for the inventory. And it is useful when someone in your organisation claims it will all be arranged somehow, because seven blocks with unknown marked four times is a more convincing conversation than an opinion.
There are also situations where you are better off leaving it aside, and the file is brief about that. Not for an incident happening right now: then you call a lawyer and check the website of the Autoriteit Persoonsgegevens, and the skill says that too, first. Not for a letter from the regulator or a complaint from a client or employee. Not to get confirmation that something is allowed. And not if you are hoping for a document you can send a client as proof it is arranged, because it does not produce that document and does not make that statement.
One more honest limit, and it applies to every skill: this is a language model with an instruction, not a system that looks inside your business. It does not see your systems, cannot check whether what you say is correct, and does not know what sits in your mailbox. Everything it produces rests on your own answers. That is not a shortcoming of this file but the nature of the tool, so the skill says it again in every overview.
What does work well is combining it with a few other skills from the same library. The Pre-Mortem Analyst NL lets you think ahead about what goes wrong before it goes wrong, and that is exactly the conversation that belongs with block 7. The Red Team Analyst attacks your own assumptions, for instance the assumption that only you can get into the mailbox. And the MECE Problem Structure Coach is the completeness check for anyone who wants to be sure no category of data has stayed out of sight.
Run it yourself, or have it run for you
reg. A.005This skill is the free do-it-yourself version of work we also deliver as a service. It stays complete and without a catch, but be aware of what a skill is: it teaches your AI how to do something, while every new session starts empty. It is not the engine and not the memory. You prompt, you supply your previous overview again every time, you check the result. On this subject that stands out even more, because a GDPR overview starts going stale from the moment you switch on a new tool. Anyone who wants it differently has two next steps: hand off the engine, or sort out the memory.
where you are now The skill: you are the engine You run the GDPR Checker yourself in Claude, Codex or Cursor. Costs nothing, works today, and you keep it fully in your own hands: no trial period, no locked-off parts. The limit is your own time: the overview only comes into being when you ask for it, and the tool you switched on last month does not get added to it by itself.
having it prepared for you The AI employee: it sits ready without you prompting The verdict stays with your lawyer, that does not get outsourced to software. The work around it does: keeping the overview up to date as a new tool arrives, putting the open points back in front of you every month, getting the question list ready for the conversation with your adviser. That is what an AI employee sets up daily, with human final review as a fixed part of it: output stays a draft until a human approves it. We deliver that through Mansotti, the business that trades as TheSEO, which today builds three employees: the Quote Employee, the Sales Employee and the Reporting Employee. For this subject there is no separate employee, so this becomes a role built to measure, and we only set that up once the process is repeatable and checkable.
everything from one source Jarvis: all your AIs work from the same company knowledge The skill teaches the AI, the brain is where the memory lives. Want all your AIs to work from the same company knowledge: that is Jarvis, the organisation brain. It connects ChatGPT, Claude, Codex and your people to the same projects, core knowledge and decisions, so your next AI session does not start over. On this subject that is the difference between seven separate snapshots and a register that grows with you: which tool you switched on in March, who had access then and what your lawyer said at the time, it is all still there. What that delivers in practice, from the plans to your first week, is at Jarvis itself.
What Jarvis actually delivers
reg. A.006Step 3 deserves more than a paragraph, because this is the difference between a smart chat and a system you can build on. Jarvis is the organisation brain: it remembers what your AIs need to know, divides the work and keeps track of what happened. On this subject that stands out, because an overview of what you process is by definition something you keep up to date, not something you make once. Which tool got added, who got access and which question your lawyer already answered: that is exactly the kind of knowledge that evaporates in a chat window. You notice it first at the start of a new session.
We have been running our own shop on this system for months. Every agent session, every task and every decision is logged in it and can be read back afterwards. So a new session does not start blank: it first fetches the recorded decisions, the running projects and the latest changes, and carries on from where the last one stopped. So we are describing not a promise but the way we work ourselves, every day.
See the four plans at jarvis/pricing NL. Through the waiting list NL you only pass on your preferred plan, without obligation. That does not create an account, an order or a duty to pay. We discuss business terms separately first.
The skills around it
reg. A.007The GDPR Checker makes visible what moves through your business. These skills from the same library pick up the pieces around it: thinking ahead about what goes wrong, the data flows in your model, and following up on what comes out of the overview.
Thinking ahead about risk
the attackBlock 7 is about what you do when it goes wrong. These two help you work out how it goes wrong, before it gets that far.
Pre-mortem AnalystImagine it has already gone wrong and work back to the cause. The conversation that belongs with your data breach agreement.SKILL NL Red Team AnalystAttacks your own assumptions, for instance that only you can get into the shared mailbox.SKILL Second Order ThinkerWhat happens after the first step: who gets access to the new system you switch on.SKILLThe data flows themselves
the inventoryFor anyone who wants to widen the overview beyond just the legal side.
Business Model Canvas CoachShows which channels and partners bring your customers in, and therefore where data flows into your business.SKILL MECE Problem Structure CoachThe completeness check: is there a data category that stayed out of sight.SKILL Intake SummaryTurns a conversation into an ordered summary, useful groundwork for the overview.SKILLWhat you do next
the follow-upAn overview marked unknown four times is a list of work. These three help make sure that work does not sit unfinished.
MoSCoW Prioritisation CoachSorts the open points into what really has to happen and what can wait.SKILL Getting Things Done CoachPuts the immediate next step somewhere it will not disappear.SKILL Minutes WriterFor the conversation with your lawyer: decisions and action points with an owner attached.SKILLThe fundamentals
understand firstNew to skills? These three explain the file format, from understanding it to writing one yourself.
What Claude skills areThe file format, the open standard and what a skill can and cannot do.DOC NL Installing Claude skillsThe full step-by-step plan per environment, from Claude Code to Gemini CLI.DOC NL Writing a SKILL.mdBuild a skill yourself using the same approach as this library.DOC NL The whole skill libraryAll 100 free skills in a row, sorted by subject.HUB NLFrequently asked questions
What does the GDPR checklist skill cost?
Nothing. The skill is free, is stated in the file itself to be under the MIT licence, and you do not have to create an account or leave an email address. You download a 10.8 KB zip containing a folder and a single file, SKILL.md, and that is the complete skill. There is no paid version and no sales email follows.
Does this skill also work in Codex, Cursor or Gemini CLI?
Yes. SKILL.md has been an open standard since December 2025, so the same file also works in Codex, Cursor, Gemini CLI and other tools that follow the standard. In Codex you unzip it into .agents/skills/ in your project, or into ~/.agents/skills/ for all your projects; Codex has supported SKILL.md directly since the open standard of December 2025. Putting the contents of SKILL.md into your AGENTS.md still works too. The instructions themselves are plain readable text, so any assistant that accepts instruction files can handle it.
Is this legal advice?
No, and the skill says so itself in every output too. It makes no judgement whatsoever on whether something is lawful, in either direction: not that something is allowed and not that something is wrong. What you get is an overview of what you said, with what the text of the law literally says next to it and a list of questions worded the way you would put them to a lawyer. For the verdict you need a privacy lawyer, and with an incident or a letter from the regulator the skill refers you on straight away.
Do I get a record of processing activities from this?
You get the groundwork for it, not the register itself. The overview contains, per block, what you process, for what purpose, where it sits, who can access it, which processors you use and how long you keep it, and that is the material a register gets built from. What the skill does not do is decide whether you are subject to the registration duty. Article 30(5) gives an exemption for organisations with fewer than 250 employees, with a number of conditions attached, and whether your business falls under that is a question for your lawyer. That question is therefore included in the question block by default.
What does the skill do if there is a data breach?
It stops the checklist. With something happening right now, such as a stolen laptop or a lost phone with customer data on it, a checklist is the wrong tool. The skill says so, gives the text of article 33 on notification within 72 hours of becoming aware, refers to a privacy lawyer and to the Autoriteit Persoonsgegevens, and delivers a factual overview with open fields: when did it happen, when did someone find out, which categories of data are involved, how many people, what security was in place. Whether it has to be reported is not for it to decide.
Why does the skill not fill in retention periods?
Because the GDPR does not name them. Article 5(1)(e) says you do not keep personal data longer than necessary for the purpose, and that is as far as it goes. Concrete periods come from other laws, such as the seven-year tax retention duty in article 52 of the Dutch General Tax Act (Algemene wet inzake rijksbelastingen), or from an agreement you made yourself. Filling in a period the skill cannot point to would be an invention, and that is exactly the mistake that shows up most often in GDPR text on the internet. So the part stays marked unknown with the question of which rule applies here attached.
When should I specifically not use this skill?
Not with an incident happening right now, not with a letter from the Autoriteit Persoonsgegevens, not with a complaint from a client or employee and not with a dispute. Also not to get confirmation that something is allowed, because it does not do that, and not to have a privacy notice, processing agreement or DPIA written that you then use. And not if you are hoping for a document with which you can show a client it is arranged, because no language model makes that statement with any authority.
First know what you have
Almost every conversation about the GDPR starts with the documents and gets stuck there because of it. Start with the data and the rest follows on its own: whoever knows which personal data comes in, where it sits and who can access it, has done the hard part.
If you then put AI to work on tasks involving personal data, you want to know in advance what happens with it. What we agree and what we do not promise is in the AI policy, and what we make public about our own use of AI is in the AI transparency NL page. If you want your team to work with AI without data ending up somewhere it should not, that belongs with the AI training NL.