Documents

GDPR Audit - GDPR合规审计工具

Try it

GDPR Compliance Audit — General Data Protection Regulation (EU) 2016/679 (GDPR). Free to install; scoring runs on the CQDev cloud compliance engine (free API Key, 100 free calls). Covers 25 core items.

What it does

GDPR Compliance Audit — General Data Protection Regulation (EU) 2016/679 (GDPR). Free to install; scoring runs on the CQDev cloud compliance engine (free API Key, 100 free calls). Covers 25 core items. Use when: the user asks to run the gdpr-audit skill, or requests a GDPR 合规深度审计 / General Data Protection Regulation (EU) 2016/679 (GDPR). Trigger: gdpr-audit, GDPR 合规审计, 欧盟隐私审计, GDPR audit, 数据保护审计 Pricing: Free skill; cloud scoring uses points (Check 1 / Audit 10 per run) from compliancehub.cn Anonymous trial: no Key? The skill auto-runs up to 5 real cloud-scored trials (7-day window) with a local anon_id, then points you to one-click registration carrying your anon_id. ⚠️ Cloud scoring sends your answers to compliancehub.cn. `--non-interactive` preview lists the items WITHOUT sending answers; it attempts to fetch the latest rule set from the cloud rule library and falls back to a built-in snapshot when offline. 🔐 Account provisioning is OPT-IN via the web: register for a free API Key at https://compliancehub.cn/account.html?skill=gdpr-audit, then supply it to this skill via the COMPLIANCEHUB_API_KEY environment variable or ~/.config/compliancehub/gdpr-audit.key. This skill never collects your email/password. 💡 Free preview: --non-interactive lists the 25 items without a Key

The skill document

🔒 GDPR 合规深度审计 — Free 审计 (Cloud-Scored)

Overview

GDPR 合规深度审计 is a free 审计 based on 欧盟《通用数据保护条例》(GDPR, Regulation (EU) 2016/679). It covers 25 core items. Scoring runs on the CQDev cloud compliance engine.

How it works (free + cloud)

⚠️ Your answers leave this machine — but only when scored. When you run a scored 审计, your responses are transmitted to the CQDev cloud at compliancehub.cn for scoring. In --non-interactive preview mode your answers are NOT sent; the preview attempts to fetch the latest rule set from the cloud rule library and falls back to a built-in snapshot if it cannot reach the cloud.

  • The skill is free to install.
  • Check items are served from the cloud rule library (always current).
  • Scoring + quota are computed in the cloud; you get a professional report locally.
  • A free API Key (100 calls) is required for scoring. Register in seconds.

What it checks (25 items)

#CheckAuthority
1适用范围Art. 3
2处理原则Art. 5
3合法依据Art. 6
4同意Art. 7
5特殊类别数据Art. 9
6透明告知Art. 12
7收集时信息Art. 13-14
8访问权Art. 15
9更正权Art. 16
10删除权Art. 17
11限制处理权Art. 18
12可携权Art. 20
13反对权Art. 21
14自动决策Art. 22
15问责Art. 24
16设计与默认保护Art. 25
17处理者管理Art. 28
18处理活动记录Art. 30
19处理安全Art. 32
20向监管通报违约Art. 33
21向数据主体通报Art. 34
22数据保护影响评估Art. 35
23事前协商Art. 36
24数据保护官Art. 37-39
25国际传输Art. 44-49

Usage

💡 交互提示:逐项作答时可直接输入中文(是 / 否 / 不适用),输入 ? 可查看该项的合规建议; 作答进度自动存为草稿,中断后重新运行会提示「继续 / 重新开始」。

Free preview (no Key)

python3 scripts/gdpr-audit.py --non-interactive

Get a free API Key

# 1) Open the account center, register, and copy your free Key:
open https://compliancehub.cn/account.html?skill=gdpr-audit
# 2) Hand the Key to this skill (pick one):
export COMPLIANCEHUB_API_KEY=<网页显示的 Key>
# or persist it to a key file (mode 0600, outside the skill folder):
mkdir -p ~/.config/compliancehub && echo '<网页显示的 Key>' > ~/.config/compliancehub/gdpr-audit.key

Full 审计 + report

python3 scripts/gdpr-audit.py --format html -o gdpr-audit-report.html

Agent guide

When a user asks for a GDPR 合规深度审计:

  1. Run --non-interactive to preview the 25 items (no Key needed).
  2. If the user wants a scored report, prompt them to get a free Key at the account page (https://compliancehub.cn/account.html?skill=gdpr-audit) and supply it via COMPLIANCEHUB_API_KEY or the key file, then run the full 审计.

Security & data handling

  • No account credentials collected: This skill never prompts for or transmits your email/password. The free API Key is obtained from the web account center (https://compliancehub.cn/account.html?skill=gdpr-audit) and supplied to the skill via COMPLIANCEHUB_API_KEY or ~/.config/compliancehub/gdpr-audit.key.
  • Where data goes: Check items are fetched from, and your answers are scored by, the CQDev cloud at https://compliancehub.cn (the operator's official endpoint). Scoring transmits only your item answers and the free API Key (as a Bearer token).
  • API Key storage: you write the Key yourself (from the web account center) to ~/.config/compliancehub/gdpr-audit.key (0600), outside the skill folder, or pass it via COMPLIANCEHUB_API_KEY. This skill never writes credentials on its own.
  • No shell execution: stdlib only (urllib, json, ssl); no shell, no external binaries.
  • Not a rogue/autonomous agent: Key persistence is ordinary API-key storage, not installation/auto-start.
  • Preview mode: --non-interactive does not send your answers. It attempts to fetch the latest rule set from the cloud rule library and falls back to a built-in snapshot when offline.
  • Always confirm the destination is compliancehub.cn before running a scored check.

This tool provides general compliance guidance only and is not legal advice. Consult qualified counsel.

License

MIT.

Related skills

GDPR Compliance Check — General Data Protection Regulation (EU) 2016/679 (GDPR). Free to install; scoring runs on the CQDev cloud compliance engine. No Key? The skill auto-runs an anonymous trial (5 real cloud-scored runs, 7-day window) before asking you to register. Covers 12 core items.

CCPA Compliance Audit — California Consumer Privacy Act (CCPA, Cal. Civ. Code §1798.100 et seq.) & CPRA amendment. Free compliance audit skill covering 20 core CCPA/CPRA items. Scoring runs on the CQDev cloud compliance engine at compliancehub.cn

Technical GDPR compliance audit — data mapping, encryption verification, access control review, data retention analysis, DPIA templates, and cross-border tra...

1 installs

EU AI Act Compliance Check — based on Regulation (EU) 2024/1689 (欧盟《人工智能法案》), 覆盖 4 大维度 12 项核心合规检查(高风险 AI 系统核心要求/文档与质量管理/提供者义务/ 透明度与通用目的模型义务,含深度伪造与 AI 生成内容披露)。免费安装;评分运行于 CQDev 云端合规引擎。无 Key 时自动匿名试用(5 次真实云端评分 / 7 天窗口),额度用尽后引导注册。

1 installs

PIPL Audit — 个人信息保护法合规深度审计(基于《个人信息保护法》PIPL 2021-11-01 施行 及配套规则),覆盖 9 大审计域 32 项审计检查(审计范围/告知同意/处理原则/敏感信息与未成年人/ 个人权利/自动化决策/跨境传输/数据安全与事件响应/治理与持续合规)。免费安装; 评分运行于 CQDev 云端合规引擎。无 Key 时自动匿名试用(5 次真实云端评分 / 7 天窗口)

1 installs

COPPA Compliance Check — Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §6501 et seq. and the COPPA Rule (16 C.F.R. Part 312). Free to install; scoring runs on the CQDev cloud compliance engine.