Agent skill · magnus919
privacy-engineering
Translate privacy principles and legal requirements into data-flow, lifecycle, acceptance, and verification artifacts. Map data classification, purpose, processing, access, retention, deletion, residency, and consent; define verifiable privacy acceptance criteria; and produce data-lifecycle records, retention/deletion verification plans, and privacy change reviews. Use when engineering privacy into a system, feature, or data flow — not for legal advice, jurisdiction-specific regulatory interpretation, or replacing security engineering or incident response.
What it needs
About 8k tokens when loaded.
What this skill does
Privacy Engineering Translate privacy principles into engineering artifacts that are observable, testable, and verifiable. This skill does not provide legal advice and does not substitute for jurisdiction-specific regulatory interpretation; those belong to qualified legal counsel and to legal-strategy. Disclaimer This skill does not provide legal advice. It provides an engineering method for translating privacy requirements (whether derived from GDPR, CCPA, HIPAA, internal policy, or contractual obligations) into verifiable technical artifacts. Jurisdiction-specific regulatory interpretation must be escalated to qualified legal counsel. Do not use this skill to determine whether a specific regulatory regime applies or to interpret the legal scope of a privacy obligation. When to use Load this skill when the task involves engineering privacy into a system, feature, or data flow: Map data classification, purpose, processing activities, access patterns, retention periods, deletion workflows, residency constraints, and consent flows. Define privacy acceptance criteria that are testable and verifiable — not policy prose alone. Produce a data-lifecycle record that traces data from collection through deletion across all stores and backups. Design a retention/deletion verification plan with measurable success conditions (e.g., "data for user X deleted from all primary stores within Y hours of verified account closure"). Map data flows across service boundaries, tenant boundaries, and geographic regions, identifying where PII transits or resides. Review a change (feature, schema, integration, AI pipeline) for privacy impact and produce a privacy change review. Address privacy implications of agent traces (LLM conversation logs, tool-call history) and product analytics telemetry. Integrate consent and revocation signals into system behavior. Apply data minimization and purpose limitation at the engineering level. …
How to use it
Reference it in AdaL, Claude Code, Cursor or any coding agent — nothing to install:
@skills magnus919/privacy-engineering