Skip to content

Commit 9e940c6

Browse files
committed
Added DORA, ISO 27701, and DPDPA skills.
1 parent eb75de5 commit 9e940c6

File tree

318 files changed

+29650
-55
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

318 files changed

+29650
-55
lines changed

.claude-plugin/marketplace.json

Lines changed: 24 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"$schema": "https://anthropic.com/claude-code/marketplace.schema.json",
33
"name": "grc-skills",
4-
"description": "Claude Code skills for Governance, Risk & Compliance \u2014 ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, and DORA Digital Operational Resilience.",
4+
"description": "Claude Code skills for Governance, Risk & Compliance \u2014 ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, DORA Digital Operational Resilience, and DPDPA India Digital Personal Data Protection.",
55
"owner": {
66
"name": "Hemant Naik",
77
"email": "hemant.naik@gmail.com"
@@ -223,6 +223,29 @@
223223
"grc"
224224
]
225225
},
226+
{
227+
"name": "dpdpa",
228+
"source": "./plugins/dpdpa",
229+
"description": "India's Digital Personal Data Protection Act, 2023 (DPDPA) and DPDP Rules, 2025 compliance advisor \u2014 gap analysis, notice and consent requirements, Data Principal rights, breach notification, children\u2019s data, Significant Data Fiduciary obligations, cross-border transfers, Data Protection Board proceedings, and GDPR alignment for global organisations.",
230+
"version": "0.3.0",
231+
"author": {
232+
"name": "Hemant Naik",
233+
"email": "hemant.naik@gmail.com"
234+
},
235+
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
236+
"category": "compliance",
237+
"keywords": [
238+
"dpdpa",
239+
"india-privacy",
240+
"digital-personal-data-protection",
241+
"data-fiduciary",
242+
"data-principal",
243+
"significant-data-fiduciary",
244+
"data-protection-board",
245+
"india-data-law",
246+
"grc"
247+
]
248+
},
226249
{
227250
"name": "dora",
228251
"source": "./plugins/dora",

DPDPA - Claude Skill/dpdpa.skill

41 KB
Binary file not shown.

README.md

Lines changed: 67 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
# Claude Skills for Governance, Risk & Compliance (GRC)
2-
Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, and DORA Digital Operational Resilience — powered by Claude Skills.
2+
Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, DORA Digital Operational Resilience, and India's Digital Personal Data Protection Act (DPDPA) — powered by Claude Skills.
33

4-
Benchmarked across 18 test cases (2 per framework) using the eval framework — each graded against 4–5 verifiable assertions by independent agents. Skills scored **94% ± 10%** vs a baseline of 72% ± 28%.
4+
Benchmarked across 60 test cases (5 per framework) using the eval framework — each graded against 5 verifiable assertions by independent agents. Skills scored **92%** vs a baseline of **84%** across 300 total assertions.
55

66
[![Release: v0.3.0](https://img.shields.io/badge/Release-v0.3.0-brightgreen.svg)](../../releases/tag/v0.3.0)
77
[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)
8-
[![Skills: 11](https://img.shields.io/badge/Skills-11-green.svg)](#the-skills)
8+
[![Skills: 12](https://img.shields.io/badge/Skills-12-green.svg)](#the-skills)
99
[![Built with Claude](https://img.shields.io/badge/Built%20with-Claude-orange.svg)](https://claude.ai)
1010

1111
---
@@ -26,6 +26,7 @@ Benchmarked across 18 test cases (2 per framework) using the eval framework —
2626
- [ISO 42001 AI Management System](#-iso-42001-ai-management-system)
2727
- [ISO 27701 Privacy Information Management](#-iso-27701-privacy-information-management)
2828
- [DORA Digital Operational Resilience](#-dora-digital-operational-resilience)
29+
- [DPDPA India Digital Personal Data Protection](#-dpdpa-india-digital-personal-data-protection)
2930
- [Potential Use Cases](#potential-use-cases)
3031
- [How to Install a Skill](#how-to-install-a-skill)
3132
- [Install via Claude Code Marketplace](#install-via-claude-code-marketplace)
@@ -284,6 +285,28 @@ The DORA skill turns Claude into an expert advisor on **Regulation (EU) 2022/255
284285

285286
---
286287

288+
### 12. 🇮🇳 DPDPA India Digital Personal Data Protection
289+
290+
**File:** `DPDPA - Claude Skill/dpdpa.skill`
291+
292+
The DPDPA skill turns Claude into an expert advisor on India's **Digital Personal Data Protection Act, 2023** and the finalized **DPDP Rules, 2025** (notified 13 November 2025, effective 13 May 2027). It covers all 44 sections of the Act and all 23 Rules, with precise section-level citations, GDPR-alignment mapping, and guidance calibrated for both Indian companies and global organizations with Indian data subjects.
293+
294+
**What it does:**
295+
- Conducts structured **DPDPA gap analyses** covering notice and consent (Sections 5–6 + Rules 3–4), lawful processing (Section 7), Data Fiduciary obligations (Section 8 + Rules 6–9), children's data (Section 9 + Rules 10–12), and SDF obligations (Section 10 + Rule 13)
296+
- **Distinguishes DPDPA from GDPR** across 8 key dimensions — scope (digital-only vs. all personal data), lawful bases (no legitimate interests in DPDPA), consent standard (unconditional + no bundling), cross-border transfers (blacklist vs. whitelist), erasure right (narrower in DPDPA), DPO requirements (SDFs only; India-resident), children's threshold (18 years vs. 16), and enforcement model (single Board vs. multi-DPA)
297+
- Guides **notice design** per Rule 3 — standalone format, plain language, multi-language obligations (Eighth Schedule), and legacy data notice requirements for pre-commencement data
298+
- Advises on the **two lawful bases only** — Consent (Section 6) and the nine Certain Legitimate Uses (Section 7) — and identifies GDPR processing activities that require fresh consent under DPDPA
299+
- Guides **breach notification** per Section 8(6) and Rule 6 — 72-hour Board notification timeline, content requirements, Processor notification obligations, and the difference from GDPR's risk-threshold approach (all breaches notifiable to Board)
300+
- Designs **children's data compliance programmes** — 18-year threshold, Rule 12 parental verification methods (DigiLocker, government tokens, existing verified data, virtual tokens), and absolute prohibitions on tracking/profiling/targeted advertising
301+
- Advises **Significant Data Fiduciaries (SDFs)** on additional obligations — India-resident DPO (Section 10 + Rule 13(2)), annual DPIA (Rule 13(3)), annual independent audit (Rule 13(4)), and data localisation readiness
302+
- Guides **Data Principal rights fulfilment** — access (Section 11), correction/erasure (Section 12), grievance redressal (Section 13 — mandatory exhaustion before Board complaint), and the unique right to nominate (Section 14)
303+
- Advises on **cross-border transfers** — blacklist approach (Section 16), no countries currently notified as restricted (April 2026), and contractual safeguards recommended despite absence of formal restrictions
304+
- Advises **global organisations** on their territorial obligations — India-nexus test (Section 3), GDPR compliance gaps that don't satisfy DPDPA, and GDPR-to-DPDPA migration priorities
305+
306+
**Trigger phrases:** `DPDPA`, `Digital Personal Data Protection Act`, `India data protection`, `Data Fiduciary`, `Data Principal`, `Significant Data Fiduciary`, `SDF`, `Data Protection Board of India`, `DPBI`, `DPDP Rules 2025`, `Section 5 DPDPA`, `Section 6 DPDPA`, `Section 7 DPDPA`, `Section 8 DPDPA`, `Section 9 DPDPA`, `Section 10 DPDPA`, `Rule 3 DPDP`, `Rule 6 DPDP breach notification`, `Rule 12 parental consent`, `India privacy law`, `India digital privacy`, `DPDPA gap analysis`, `DPDPA vs GDPR`, `India data law`, `MeitY data protection`, `DigiLocker consent`, `India children data law`, `DPDPA consent requirements`, `DPDPA breach notification`, `India cross-border data transfer`
307+
308+
---
309+
287310
## Potential Use Cases
288311

289312
| Scenario | Relevant Skill(s) |
@@ -352,6 +375,17 @@ The DORA skill turns Claude into an expert advisor on **Regulation (EU) 2022/255
352375
| Drafting an ICT Third-Party Risk Policy satisfying CDR (EU) 2024/1773 | DORA |
353376
| Advising on the interaction between DORA and NIS2 for a financial entity | DORA |
354377
| Mapping DORA obligations to legacy EBA ICT guidelines and identifying what changed | DORA |
378+
| Running a DPDPA gap analysis for an Indian SaaS company ahead of the May 2027 compliance deadline | DPDPA |
379+
| Identifying which GDPR-compliant processing activities need fresh consent or re-mapping under DPDPA | DPDPA + GDPR |
380+
| Designing a notice compliant with Section 5 and Rule 3, including multi-language obligations | DPDPA |
381+
| Implementing a 72-hour breach notification pipeline per Section 8(6) and Rule 6 | DPDPA |
382+
| Designing a children's data compliance programme with Rule 12 parental verification (DigiLocker, virtual tokens) | DPDPA |
383+
| Assessing whether a digital platform must eliminate targeted advertising and behavioural tracking for under-18 users | DPDPA |
384+
| Advising a global company on its India data transfer obligations — blacklist approach vs. GDPR's whitelist | DPDPA |
385+
| Preparing for potential Significant Data Fiduciary designation — DPO appointment, DPIA, and audit readiness | DPDPA |
386+
| Updating Data Processing Agreements with vendors to satisfy Rule 16 | DPDPA |
387+
| Assessing whether a company relying on legitimate interests for analytics must obtain consent under DPDPA | DPDPA |
388+
| Building a Data Principal rights fulfilment procedure covering access, correction, erasure, and nomination | DPDPA |
355389

356390
---
357391

@@ -372,6 +406,7 @@ The DORA skill turns Claude into an expert advisor on **Regulation (EU) 2022/255
372406
| 🤖 ISO 42001 AI Management System | [ISO-42001.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2042001%20-%20Claude%20Skill/ISO-42001.skill) |
373407
| 🔒 ISO 27701 Privacy Information Management | [iso27701.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2027701%20-%20Claude%20Skill/iso27701.skill) |
374408
| 🏦 DORA Digital Operational Resilience | [dora.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/DORA%20-%20Claude%20Skill/dora.skill) |
409+
| 🇮🇳 DPDPA India Digital Personal Data Protection | [dpdpa.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/DPDPA%20-%20Claude%20Skill/dpdpa.skill) |
375410

376411
2. Open Claude and navigate to **Customize → Skills**.
377412
3. Click **Upload Skill** and select the `.skill` file.
@@ -391,7 +426,7 @@ Add the marketplace and install the skills you need directly from the terminal:
391426

392427
```shell
393428
/plugin marketplace add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
394-
/plugin install iso27001@grc-skills soc2@grc-skills fedramp@grc-skills gdpr-compliance@grc-skills hipaa-compliance@grc-skills nist-csf@grc-skills pci-compliance@grc-skills tsa-compliance@grc-skills iso42001@grc-skills iso27701@grc-skills dora@grc-skills
429+
/plugin install iso27001@grc-skills soc2@grc-skills fedramp@grc-skills gdpr-compliance@grc-skills hipaa-compliance@grc-skills nist-csf@grc-skills pci-compliance@grc-skills tsa-compliance@grc-skills iso42001@grc-skills iso27701@grc-skills dora@grc-skills dpdpa@grc-skills
395430
```
396431

397432
Teams can pre-wire the marketplace in `.claude/settings.json` so every developer gets the skills automatically when they open the project — no manual install required.
@@ -402,29 +437,34 @@ Teams can pre-wire the marketplace in `.claude/settings.json` so every developer
402437

403438
## Skill Evaluation
404439

405-
These skills were benchmarked using the [Claude Skill Creator](https://claude.ai) eval framework. **18 realistic test cases** were run across all 9 skills — 2 per framework — covering gap analysis, policy drafting, control narratives, code audits, breach response, CRMP drafting, and AI system impact assessments. Each test case was evaluated against 4–5 objectively verifiable assertions by independent grader agents comparing skill-assisted vs. baseline Claude responses.
406-
407-
| Configuration | Pass Rate |
408-
|---------------|-----------|
409-
| **With GRC Skills installed** | **94% ± 10%** |
410-
| Without skills (baseline Claude) | 72% ± 28% |
411-
| **Delta** | **+22 points** |
412-
413-
### Per-Skill Results (with skills)
414-
415-
| Skill | Test Cases | Pass Rate | What Was Tested |
416-
|-------|-----------|-----------|-----------------|
417-
| ISO 27001 | 2 | 100% | Stage 2 gap analysis; Access Control Policy drafting |
418-
| SOC 2 | 2 | 100% | First-time audit guidance; CC6.3 control documentation |
419-
| FedRAMP | 2 | 88% | AC-2 SSP narrative; Impact level & LI-SaaS guidance |
420-
| GDPR | 2 | 100% | API endpoint audit with article citations; DPA drafting |
421-
| HIPAA | 2 | 100% | Technical safeguards (45 CFR 164.312); Breach notification |
422-
| NIST CSF | 2 | 78% | CSF 2.0 OT/IT gap assessment; Target profile for healthcare |
423-
| PCI DSS | 2 | 90% | Stripe.js SAQ/CDE scope; v4.0.1 new requirements |
424-
| TSA Cybersecurity | 2 | 100% | Pipeline CRMP obligations; Incident Reporting section |
425-
| ISO 42001 | 2 | 90% | AI user gap assessment; AISIA for resume screening |
426-
427-
The skills add the most measurable value on highly framework-specific tasks: producing correct Annex A control IDs for ISO 27001, mapping gaps to CC criteria for SOC 2, generating formal third-person SSP prose with enhancement references for FedRAMP, applying article-level citations for GDPR, distinguishing Required vs. Addressable HIPAA specifications, using CSF 2.0 subcategory IDs for NIST, correctly identifying SAQ types for PCI, referencing specific TSA Security Directives and CISA contact details, and classifying AI system impact levels with AISIA methodology for ISO 42001.
440+
These skills were benchmarked using the [Claude Skill Creator](https://claude.ai) eval framework. **60 realistic test cases** were run across all 12 skills — 5 per framework — covering gap analysis, policy drafting, control deep-dives, edge cases, and compliance advice scenarios. Each test case was evaluated against 5 objectively verifiable assertions by independent grader agents comparing skill-assisted vs. baseline Claude responses.
441+
442+
| Configuration | Pass Rate | Assertions Passed |
443+
|---------------|-----------|-------------------|
444+
| **With GRC Skills installed** | **92%** | **276 / 300** |
445+
| Without skills (baseline Claude) | 84% | 252 / 300 |
446+
| **Delta** | **+8 points** | **+24 assertions** |
447+
448+
### Per-Skill Results
449+
450+
| Skill | Test Cases | With Skill | Baseline | Delta | What Was Tested |
451+
|-------|-----------|-----------|---------|-------|-----------------|
452+
| ISO 27001 | 5 | **100%** | 84% | +16% | Gap assessment; Policy drafting; 2013→2022 transition; Risk assessment; Management review CAP |
453+
| SOC 2 | 5 | **100%** | 84% | +16% | Type 1 vs 2; CC controls checklist; Availability criteria; Access control policy; Audit exception response |
454+
| FedRAMP | 5 | **84%** | 76% | +8% | Authorization pathways; Impact levels; FedRAMP 20x; System boundary; POA&M remediation timelines |
455+
| GDPR | 5 | **88%** | 88% | +0% | US company checklist; Article 28 DPA; Subject access request; Cookie consent; 72-hour breach notification |
456+
| HIPAA | 5 | **92%** | 88% | +4% | Covered entity analysis; BAA template; Encryption (addressable vs required); Risk analysis; Workforce violation |
457+
| NIST CSF | 5 | **96%** | 84% | +12% | CSF 2.0 overview; Ransomware recovery plan; Profile creation; Control mapping; Board reporting |
458+
| PCI DSS | 5 | **92%** | 88% | +4% | SAQ type selection; Req 3 stored data (v4.0); Breach obligations; Penetration testing; Tokenization scope |
459+
| TSA Cybersecurity | 5 | **100%** | 96% | +4% | Pipeline directive requirements; CIRP elements; OT/IT segmentation; Airport applicability; TSA vs CIRCIA |
460+
| ISO 42001 | 5 | **92%** | 80% | +12% | AIMS applicability; Key requirements; AI-specific risks; Third-party LLM management; AI ethics controls |
461+
| ISO 27701 | 5 | **76%** | 84% | -8% | Extension to ISO 27001; GDPR mapping; Processor controls; PIA methodology; Certification as GDPR evidence |
462+
| DORA | 5 | **88%** | 72% | +16% | Five pillars; ICT incident reporting timelines; TLPT requirements; Third-party contracts; DORA vs EBA |
463+
| DPDPA | 5 | **96%** | 80% | +16% | Applicability to foreign entities; Consent vs GDPR; Children's data (18-year threshold); Cross-border transfers; SDF obligations |
464+
465+
Skills add the most measurable value on highly framework-specific tasks: clause-level precision for ISO 27001, CC criteria mapping for SOC 2, exact FedRAMP POA&M timeframes and document names, GDPR article citations, HIPAA regulatory section references, CSF 2.0 subcategory IDs, PCI DSS v4.0.1 requirement numbers, TSA Security Directive citations, ISO 42001 AIMS clause references, DORA Article citations and exact incident reporting timelines (4h/72h/1 month), and DPDPA-specific terminology (Data Fiduciary, 8 legitimate uses, blacklist transfers).
466+
467+
The ISO 27701 skill shows a slight negative delta in keyword-matching grading because baseline Claude already has substantial GDPR/privacy knowledge; qualitative review of the outputs confirms the skill still provides more structured, citation-precise responses.
428468

429469
📊 **[View the full eval results →](grc-skills-eval-results.html)**
430470

0 commit comments

Comments
 (0)