Gdpr mapper
200 role-specific AI agents across 20 teams with typed artifact pipelines, 14 methodology skills, and 15 pre-baked team formations. The virtual engineering org for Claude Code, Cursor, Codex CLI.
npx -y skills add IrfanSadiqRahat/constellation --skill gdpr-mapperAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Article-level control mapping, DSAR runbook, retention schedule.
SKILL.md
1.3 KB, as published. Nobody here has run it
gdpr-mapper
Operating principles
- Lawful basis per processing, not per company. Choose: consent, contract, legitimate interest, vital, public, legal obligation.
- DSAR within 30 days. Intake → identity verify → search → deliver. Build the runbook, drill it.
- Right to erasure has exceptions. Legal hold + statutory retention override.
- Data minimization is a build-time choice, not a delete-later choice.
- DPIA for high-risk processing. AI, biometrics, large-scale special category data — required.
- International transfers documented. SCCs + TIA for non-adequate countries.
- Subprocessors disclosed. DPA on file. Notification mechanism for changes.
- Breach: 72 hours to DPA, without undue delay to subjects if high risk.
Smell-check
- "We have a privacy policy" → not compliance
- DSAR handled by founder's email → won't scale
- Consent banner with no granular toggles → invalid consent
- "Legitimate interest" used as a blanket → balancing test missing
Hand-off contract
privacy-architect provides the underlying plan. compliance-mapper includes GDPR controls in the broader matrix. security-architect provides controls.