You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"description": "Claude Code skills for Governance, Risk & Compliance \u2014 ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, and DORA Digital Operational Resilience.",
4
+
"description": "Claude Code skills for Governance, Risk & Compliance \u2014 ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, DORA Digital Operational Resilience, and DPDPA India Digital Personal Data Protection.",
5
5
"owner": {
6
6
"name": "Hemant Naik",
7
7
"email": "hemant.naik@gmail.com"
@@ -223,6 +223,29 @@
223
223
"grc"
224
224
]
225
225
},
226
+
{
227
+
"name": "dpdpa",
228
+
"source": "./plugins/dpdpa",
229
+
"description": "India's Digital Personal Data Protection Act, 2023 (DPDPA) and DPDP Rules, 2025 compliance advisor \u2014 gap analysis, notice and consent requirements, Data Principal rights, breach notification, children\u2019s data, Significant Data Fiduciary obligations, cross-border transfers, Data Protection Board proceedings, and GDPR alignment for global organisations.",
Copy file name to clipboardExpand all lines: README.md
+67-27Lines changed: 67 additions & 27 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,11 +1,11 @@
1
1
# Claude Skills for Governance, Risk & Compliance (GRC)
2
-
Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, and DORA Digital Operational Resilience — powered by Claude Skills.
2
+
Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, DORA Digital Operational Resilience, and India's Digital Personal Data Protection Act (DPDPA) — powered by Claude Skills.
3
3
4
-
Benchmarked across 18 test cases (2 per framework) using the eval framework — each graded against 4–5 verifiable assertions by independent agents. Skills scored **94% ± 10%** vs a baseline of 72% ± 28%.
4
+
Benchmarked across 60 test cases (5 per framework) using the eval framework — each graded against 5 verifiable assertions by independent agents. Skills scored **92%** vs a baseline of **84%** across 300 total assertions.
[](https://claude.ai)
10
10
11
11
---
@@ -26,6 +26,7 @@ Benchmarked across 18 test cases (2 per framework) using the eval framework —
26
26
-[ISO 42001 AI Management System](#-iso-42001-ai-management-system)
27
27
-[ISO 27701 Privacy Information Management](#-iso-27701-privacy-information-management)
28
28
-[DORA Digital Operational Resilience](#-dora-digital-operational-resilience)
29
+
-[DPDPA India Digital Personal Data Protection](#-dpdpa-india-digital-personal-data-protection)
29
30
-[Potential Use Cases](#potential-use-cases)
30
31
-[How to Install a Skill](#how-to-install-a-skill)
31
32
-[Install via Claude Code Marketplace](#install-via-claude-code-marketplace)
@@ -284,6 +285,28 @@ The DORA skill turns Claude into an expert advisor on **Regulation (EU) 2022/255
284
285
285
286
---
286
287
288
+
### 12. 🇮🇳 DPDPA India Digital Personal Data Protection
289
+
290
+
**File:**`DPDPA - Claude Skill/dpdpa.skill`
291
+
292
+
The DPDPA skill turns Claude into an expert advisor on India's **Digital Personal Data Protection Act, 2023** and the finalized **DPDP Rules, 2025** (notified 13 November 2025, effective 13 May 2027). It covers all 44 sections of the Act and all 23 Rules, with precise section-level citations, GDPR-alignment mapping, and guidance calibrated for both Indian companies and global organizations with Indian data subjects.
293
+
294
+
**What it does:**
295
+
- Conducts structured **DPDPA gap analyses** covering notice and consent (Sections 5–6 + Rules 3–4), lawful processing (Section 7), Data Fiduciary obligations (Section 8 + Rules 6–9), children's data (Section 9 + Rules 10–12), and SDF obligations (Section 10 + Rule 13)
296
+
-**Distinguishes DPDPA from GDPR** across 8 key dimensions — scope (digital-only vs. all personal data), lawful bases (no legitimate interests in DPDPA), consent standard (unconditional + no bundling), cross-border transfers (blacklist vs. whitelist), erasure right (narrower in DPDPA), DPO requirements (SDFs only; India-resident), children's threshold (18 years vs. 16), and enforcement model (single Board vs. multi-DPA)
297
+
- Guides **notice design** per Rule 3 — standalone format, plain language, multi-language obligations (Eighth Schedule), and legacy data notice requirements for pre-commencement data
298
+
- Advises on the **two lawful bases only** — Consent (Section 6) and the nine Certain Legitimate Uses (Section 7) — and identifies GDPR processing activities that require fresh consent under DPDPA
299
+
- Guides **breach notification** per Section 8(6) and Rule 6 — 72-hour Board notification timeline, content requirements, Processor notification obligations, and the difference from GDPR's risk-threshold approach (all breaches notifiable to Board)
300
+
- Designs **children's data compliance programmes** — 18-year threshold, Rule 12 parental verification methods (DigiLocker, government tokens, existing verified data, virtual tokens), and absolute prohibitions on tracking/profiling/targeted advertising
301
+
- Advises **Significant Data Fiduciaries (SDFs)** on additional obligations — India-resident DPO (Section 10 + Rule 13(2)), annual DPIA (Rule 13(3)), annual independent audit (Rule 13(4)), and data localisation readiness
302
+
- Guides **Data Principal rights fulfilment** — access (Section 11), correction/erasure (Section 12), grievance redressal (Section 13 — mandatory exhaustion before Board complaint), and the unique right to nominate (Section 14)
303
+
- Advises on **cross-border transfers** — blacklist approach (Section 16), no countries currently notified as restricted (April 2026), and contractual safeguards recommended despite absence of formal restrictions
304
+
- Advises **global organisations** on their territorial obligations — India-nexus test (Section 3), GDPR compliance gaps that don't satisfy DPDPA, and GDPR-to-DPDPA migration priorities
305
+
306
+
**Trigger phrases:**`DPDPA`, `Digital Personal Data Protection Act`, `India data protection`, `Data Fiduciary`, `Data Principal`, `Significant Data Fiduciary`, `SDF`, `Data Protection Board of India`, `DPBI`, `DPDP Rules 2025`, `Section 5 DPDPA`, `Section 6 DPDPA`, `Section 7 DPDPA`, `Section 8 DPDPA`, `Section 9 DPDPA`, `Section 10 DPDPA`, `Rule 3 DPDP`, `Rule 6 DPDP breach notification`, `Rule 12 parental consent`, `India privacy law`, `India digital privacy`, `DPDPA gap analysis`, `DPDPA vs GDPR`, `India data law`, `MeitY data protection`, `DigiLocker consent`, `India children data law`, `DPDPA consent requirements`, `DPDPA breach notification`, `India cross-border data transfer`
307
+
308
+
---
309
+
287
310
## Potential Use Cases
288
311
289
312
| Scenario | Relevant Skill(s) |
@@ -352,6 +375,17 @@ The DORA skill turns Claude into an expert advisor on **Regulation (EU) 2022/255
352
375
| Drafting an ICT Third-Party Risk Policy satisfying CDR (EU) 2024/1773 | DORA |
353
376
| Advising on the interaction between DORA and NIS2 for a financial entity | DORA |
354
377
| Mapping DORA obligations to legacy EBA ICT guidelines and identifying what changed | DORA |
378
+
| Running a DPDPA gap analysis for an Indian SaaS company ahead of the May 2027 compliance deadline | DPDPA |
379
+
| Identifying which GDPR-compliant processing activities need fresh consent or re-mapping under DPDPA | DPDPA + GDPR |
380
+
| Designing a notice compliant with Section 5 and Rule 3, including multi-language obligations | DPDPA |
381
+
| Implementing a 72-hour breach notification pipeline per Section 8(6) and Rule 6 | DPDPA |
382
+
| Designing a children's data compliance programme with Rule 12 parental verification (DigiLocker, virtual tokens) | DPDPA |
383
+
| Assessing whether a digital platform must eliminate targeted advertising and behavioural tracking for under-18 users | DPDPA |
384
+
| Advising a global company on its India data transfer obligations — blacklist approach vs. GDPR's whitelist | DPDPA |
385
+
| Preparing for potential Significant Data Fiduciary designation — DPO appointment, DPIA, and audit readiness | DPDPA |
386
+
| Updating Data Processing Agreements with vendors to satisfy Rule 16 | DPDPA |
387
+
| Assessing whether a company relying on legitimate interests for analytics must obtain consent under DPDPA | DPDPA |
388
+
| Building a Data Principal rights fulfilment procedure covering access, correction, erasure, and nomination | DPDPA |
355
389
356
390
---
357
391
@@ -372,6 +406,7 @@ The DORA skill turns Claude into an expert advisor on **Regulation (EU) 2022/255
372
406
| 🤖 ISO 42001 AI Management System |[ISO-42001.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2042001%20-%20Claude%20Skill/ISO-42001.skill)|
373
407
| 🔒 ISO 27701 Privacy Information Management |[iso27701.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2027701%20-%20Claude%20Skill/iso27701.skill)|
374
408
| 🏦 DORA Digital Operational Resilience |[dora.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/DORA%20-%20Claude%20Skill/dora.skill)|
409
+
| 🇮🇳 DPDPA India Digital Personal Data Protection |[dpdpa.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/DPDPA%20-%20Claude%20Skill/dpdpa.skill)|
375
410
376
411
2. Open Claude and navigate to **Customize → Skills**.
377
412
3. Click **Upload Skill** and select the `.skill` file.
@@ -391,7 +426,7 @@ Add the marketplace and install the skills you need directly from the terminal:
Teams can pre-wire the marketplace in `.claude/settings.json` so every developer gets the skills automatically when they open the project — no manual install required.
@@ -402,29 +437,34 @@ Teams can pre-wire the marketplace in `.claude/settings.json` so every developer
402
437
403
438
## Skill Evaluation
404
439
405
-
These skills were benchmarked using the [Claude Skill Creator](https://claude.ai) eval framework. **18 realistic test cases** were run across all 9 skills — 2 per framework — covering gap analysis, policy drafting, control narratives, code audits, breach response, CRMP drafting, and AI system impact assessments. Each test case was evaluated against 4–5 objectively verifiable assertions by independent grader agents comparing skill-assisted vs. baseline Claude responses.
406
-
407
-
| Configuration | Pass Rate |
408
-
|---------------|-----------|
409
-
|**With GRC Skills installed**|**94% ± 10%**|
410
-
| Without skills (baseline Claude) | 72% ± 28% |
411
-
|**Delta**|**+22 points**|
412
-
413
-
### Per-Skill Results (with skills)
414
-
415
-
| Skill | Test Cases | Pass Rate | What Was Tested |
| ISO 42001 | 2 | 90% | AI user gap assessment; AISIA for resume screening |
426
-
427
-
The skills add the most measurable value on highly framework-specific tasks: producing correct Annex A control IDs for ISO 27001, mapping gaps to CC criteria for SOC 2, generating formal third-person SSP prose with enhancement references for FedRAMP, applying article-level citations for GDPR, distinguishing Required vs. Addressable HIPAA specifications, using CSF 2.0 subcategory IDs for NIST, correctly identifying SAQ types for PCI, referencing specific TSA Security Directives and CISA contact details, and classifying AI system impact levels with AISIA methodology for ISO 42001.
440
+
These skills were benchmarked using the [Claude Skill Creator](https://claude.ai) eval framework. **60 realistic test cases** were run across all 12 skills — 5 per framework — covering gap analysis, policy drafting, control deep-dives, edge cases, and compliance advice scenarios. Each test case was evaluated against 5 objectively verifiable assertions by independent grader agents comparing skill-assisted vs. baseline Claude responses.
| ISO 27701 | 5 |**76%**| 84% | -8% | Extension to ISO 27001; GDPR mapping; Processor controls; PIA methodology; Certification as GDPR evidence |
462
+
| DORA | 5 |**88%**| 72% | +16% | Five pillars; ICT incident reporting timelines; TLPT requirements; Third-party contracts; DORA vs EBA |
463
+
| DPDPA | 5 |**96%**| 80% | +16% | Applicability to foreign entities; Consent vs GDPR; Children's data (18-year threshold); Cross-border transfers; SDF obligations |
464
+
465
+
Skills add the most measurable value on highly framework-specific tasks: clause-level precision for ISO 27001, CC criteria mapping for SOC 2, exact FedRAMP POA&M timeframes and document names, GDPR article citations, HIPAA regulatory section references, CSF 2.0 subcategory IDs, PCI DSS v4.0.1 requirement numbers, TSA Security Directive citations, ISO 42001 AIMS clause references, DORA Article citations and exact incident reporting timelines (4h/72h/1 month), and DPDPA-specific terminology (Data Fiduciary, 8 legitimate uses, blacklist transfers).
466
+
467
+
The ISO 27701 skill shows a slight negative delta in keyword-matching grading because baseline Claude already has substantial GDPR/privacy knowledge; qualitative review of the outputs confirms the skill still provides more structured, citation-precise responses.
428
468
429
469
📊 **[View the full eval results →](grc-skills-eval-results.html)**
0 commit comments