gdpr-developer-guard is an open-source skill package that translates five CNIL GDPR Developer Guide modules into practical engineering guidance for developers.
It is intentionally limited to:
- data minimization
- informing users
- rights exercise
- retention
- analytics
The skill supports two working modes:
Build mode: shape schemas, UI flows, deletion logic, logging, retention, and analytics before code is finalizedReview mode: inspect existing code, UI, configuration, and flows for likely privacy engineering issues
It is not a statement of full GDPR compliance and does not replace legal review.
gdpr-developer-guard/
├── AGENTS.md
├── SKILL.md
├── agents/
│ └── openai.yaml
├── references/
├── rules/
└── templates/
Codex discovers local skills from ~/.codex/skills when CODEX_HOME is not set.
You can install this skill by symlinking or copying the package directory:
ln -s /absolute/path/to/gdpr-developer-guard ~/.codex/skills/gdpr-developer-guardOr:
cp -R /absolute/path/to/gdpr-developer-guard ~/.codex/skills/gdpr-developer-guardAfter installation, invoke it explicitly with prompts such as:
Use $gdpr-developer-guard in build mode for this signup flow.Use $gdpr-developer-guard to review this delete-account implementation.
For non-Codex setups, the minimum useful context is:
gdpr-developer-guard/SKILL.md- only the relevant file or files from
gdpr-developer-guard/rules/ - only the relevant file or files from
gdpr-developer-guard/references/
Do not load the entire package by default. Start from the relevant module, then pull in only the rule and reference files needed for the current task.
- forms, payloads, schemas, DTOs, or logging -> data minimization
- notices, privacy links, or explanatory copy -> informing users
- export, correction, deletion, or restriction flows -> rights exercise
- cleanup jobs, archival, anonymization, or deletion lifecycle -> retention
- cookies, trackers, analytics scripts, consent, or audience measurement -> analytics
Use $gdpr-developer-guard in build mode for a signup form that asks for birth date, full address, and job title.Use $gdpr-developer-guard to review this account deletion flow that only sets deleted_at.Use $gdpr-developer-guard to review this analytics SDK setup and cookie banner.
This repository is released under the Apache-2.0 license. See LICENSE.