Skill 詳細

803-regulations-gdpr

Relevant to privacy controls in data pipelines, but primarily a Java/GDPR compliance skill.

一致度一致の可能性データエンジニア 向けにレビュー済み
出典jabrena/plinth外部ソース
報告インストール数96人気度の参考値

使用前に確認

自動レビューは関連性のみを確認し、安全性や推奨を保証しません。使用前に出典の説明を読んでください。

保存された出典プレビュー

SKILL.md

これはレビュー時に保存された抜粋です。完全で最新の内容は外部ソースを確認してください。

---
name: 803-regulations-gdpr
description: Use when reviewing, designing, or modifying Java enterprise systems that process personal data and need GDPR-aware engineering controls. This should trigger for requests such as Review a Java service for GDPR privacy controls; Design data-subject rights workflows; Add retention, deletion, pseudonymization, or privacy-safe logging; Assess data transfer, DPIA, breach evidence, or processor/controller boundary concerns before production release. Part of Plinth Toolkit
license: Apache-2.0
metadata:
  author: Juan Antonio Breña Moral
  version: 0.18.0
---
# GDPR Regulation for Java Enterprise Personal Data Protection

Use this Skill to review Java enterprise applications, APIs, data pipelines, integrations, batch jobs, AI workflows, or operational tooling that collect, store, transform, expose, log, export, or delete personal data.

Apply this Skill to determine what engineering controls, evidence, and escalation paths are needed before the system is released, connected to production data, or used for personal-data processing.

This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, and reviewers identify when GDPR concerns may apply and how to translate data protection expectations into enterprise architecture controls such as personal-data inventories, minimization, purpose limitation, privacy by design, security of processing, data-subject rights workflows, retention and deletion, pseudonymization, transfer-review evidence, breach-response evidence, and privacy-safe logging.

The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, or a final regulatory determination.

The main question is:

> When does a Java enterprise system require GDPR-aware personal-data controls, and what should developers build differently?

External reference: [GDPR Regulation (EU) 2016/679](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679).

GDPR chapters summary reference: [GDPR chapters summary](references/803-regulations-gdpr-chapters-summary.md).

Java engineering examples reference: [GDPR engineering examples](references/803-regulations-gdpr-engineering-examples.md).

Questionnaire asset: [GDPR engineering review questionnaire](assets/questions/803-gdpr-engineering-review-questionnaire.md).

Report template asset: [GDPR engineering review report template](assets/reports/803-gdpr-engineering-review-report-template.md).

## Scope

This Skill applies to:

- Java systems that process personal data, user profiles, account data, identifiers, contact data, behavioral data, telemetry tied to users, or sensitive categories of data
- REST APIs, message consumers, batch jobs, data exports, reporting, search indexes, logs, caches, backups, and analytics pipelines containing personal data
- Spring Boot, Quarkus, Micronaut, and framework-agnostic Java services with privacy and data protection requirements
- Systems requiring data-subject rights workflows such as access, rectification, erasure, restriction, objection, portability, or consent preference handling
- Cross-border data transfers, processor/controller boundaries, subprocessor integrations, third-party SaaS providers, or vendor APIs
- DPIA escalation, privacy by design review, breach-response evidence, data retention, deletion, pseudonymization, anonymization, and privacy-safe observability

## GDPR Engineering Review

Treat lawful basis, controller or processor role, jurisdiction, transfer mechanism, special-category processing, DPIA requirements, and regulatory interpretation as governance decisions for legal, privacy, data protection officer, compliance, security, and risk owners.

Engineering teams should still create evidence that makes those decisions reviewable:

- Which personal data is processed and where it flows
- Why ea
GitHub で全文を読む (外部ページ)
関連情報

関連する仕事