本文へ移動
cccskills
無料GitHub で公開

personal-data-protection

Personal-data-protection compliance reference for engineers building applications subject to Singapore PDPA, Indonesia UU PDP, Thailand PDPA, Malaysia PDPA, Philippines DPA (RA 10173), or Vietnam PDPL (91/2025/QH15). Use when reviewing or modifying code that touches personal data — signup/auth/consent, data export, account deletion, retention/purging, admin access to personal-data stores, third-party processors, breach response, or privacy/T&C documents.

インストール方法を見る

含まれるファイル(70)

  • SKILL.md14.5 KB
  • checklists/breach-response.md5.6 KB
  • checklists/new-data-field.md6.8 KB
  • checklists/new-feature.md11.2 KB
  • checklists/new-vendor.md7.1 KB
  • jurisdictions/_index.md12.6 KB
  • jurisdictions/id-pdp/obligations/01-accountability.md12.4 KB
  • jurisdictions/id-pdp/obligations/02-consent.md7.5 KB
  • jurisdictions/id-pdp/obligations/03-purpose.md7.0 KB
  • jurisdictions/id-pdp/obligations/04-access-correction.md8.9 KB
  • jurisdictions/id-pdp/obligations/05-care.md7.1 KB
  • jurisdictions/id-pdp/obligations/06-breach-notification.md7.4 KB
  • jurisdictions/id-pdp/obligations/07-offences.md7.6 KB
  • jurisdictions/id-pdp/README.md8.7 KB
  • jurisdictions/id-pdp/statute-map.md12.5 KB
  • jurisdictions/my-pdpa/obligations/01-accountability.md6.5 KB
  • jurisdictions/my-pdpa/obligations/02-consent.md10.0 KB
  • jurisdictions/my-pdpa/obligations/03-purpose.md9.1 KB
  • jurisdictions/my-pdpa/obligations/04-access-correction.md11.1 KB
  • jurisdictions/my-pdpa/obligations/05-care.md11.5 KB
  • jurisdictions/my-pdpa/obligations/06-breach-notification.md7.6 KB
  • jurisdictions/my-pdpa/obligations/07-offences.md8.1 KB
  • jurisdictions/my-pdpa/README.md10.2 KB
  • jurisdictions/my-pdpa/statute-map.md10.4 KB
  • jurisdictions/ph-dpa/obligations/01-accountability.md8.3 KB
  • jurisdictions/ph-dpa/obligations/02-consent.md12.0 KB
  • jurisdictions/ph-dpa/obligations/03-purpose.md8.7 KB
  • jurisdictions/ph-dpa/obligations/04-access-correction.md13.4 KB
  • jurisdictions/ph-dpa/obligations/05-care.md13.6 KB
  • jurisdictions/ph-dpa/obligations/06-breach-notification.md11.2 KB
  • jurisdictions/ph-dpa/obligations/07-offences.md11.3 KB
  • jurisdictions/ph-dpa/README.md12.8 KB
  • jurisdictions/ph-dpa/statute-map.md10.9 KB
  • jurisdictions/sg-pdpa/obligations/01-accountability.md4.0 KB
  • jurisdictions/sg-pdpa/obligations/02-consent.md6.9 KB
  • jurisdictions/sg-pdpa/obligations/03-purpose.md4.4 KB
  • jurisdictions/sg-pdpa/obligations/04-access-correction.md6.5 KB
  • jurisdictions/sg-pdpa/obligations/05-care.md6.9 KB
  • jurisdictions/sg-pdpa/obligations/06-breach-notification.md10.5 KB
  • jurisdictions/sg-pdpa/obligations/07-offences.md6.6 KB
  • jurisdictions/sg-pdpa/README.md5.4 KB
  • jurisdictions/sg-pdpa/statute-map.md8.0 KB
  • jurisdictions/th-pdpa/obligations/01-accountability.md7.1 KB
  • jurisdictions/th-pdpa/obligations/02-consent.md8.5 KB
  • jurisdictions/th-pdpa/obligations/03-purpose.md4.9 KB
  • jurisdictions/th-pdpa/obligations/04-access-correction.md7.0 KB
  • jurisdictions/th-pdpa/obligations/05-care.md7.3 KB
  • jurisdictions/th-pdpa/obligations/06-breach-notification.md7.0 KB
  • jurisdictions/th-pdpa/obligations/07-offences.md8.5 KB
  • jurisdictions/th-pdpa/README.md7.3 KB
  • jurisdictions/th-pdpa/statute-map.md8.1 KB
  • jurisdictions/vn-pdpl/obligations/01-accountability.md5.0 KB
  • jurisdictions/vn-pdpl/obligations/02-consent.md5.1 KB
  • jurisdictions/vn-pdpl/obligations/03-purpose.md6.7 KB
  • jurisdictions/vn-pdpl/obligations/04-access-correction.md4.9 KB
  • jurisdictions/vn-pdpl/obligations/05-care.md5.0 KB
  • jurisdictions/vn-pdpl/obligations/06-breach-notification.md5.6 KB
  • jurisdictions/vn-pdpl/obligations/07-offences.md3.0 KB
  • jurisdictions/vn-pdpl/obligations/08-sector-specific.md4.4 KB
  • jurisdictions/vn-pdpl/README.md9.9 KB
  • jurisdictions/vn-pdpl/statute-map.md9.5 KB
  • layers/01-non-technical.md4.9 KB
  • layers/02-architecture.md8.0 KB
  • layers/03-data-model.md8.4 KB
  • layers/04-controls-and-processes.md9.1 KB
  • layers/05-feature-ux.md9.0 KB
  • layers/06-disclosure.md6.5 KB
  • layers/07-operational.md9.5 KB
  • templates/INCIDENT_RESPONSE.md.template13.2 KB
  • templates/pdp-nudge.sh.template4.5 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Personal Data Protection Compliance — Layered Reference

⚠ Reference material, not legal advice

This skill is engineering reference material, not legal advice. The maintainers and contributors are not licensed to practise law in Singapore, Thailand, Indonesia, Malaysia, the Philippines, Vietnam, or any other jurisdiction. No attorney–client relationship is created by use of this skill.

Do not rely on this skill as your sole source of truth for personal-data-protection compliance. Always (a) verify any statute citation, threshold, or obligation against the official source, and (b) engage a qualified Data Protection Officer or privacy lawyer before making compliance decisions that materially affect your obligations or your users' rights.

Source-text posture: this skill does not reproduce or republish any of the underlying statutes. It provides engineer-facing interpretation and short attributed quotations of operative phrases under fair-dealing principles, with links to the official sources. Anyone planning to package or redistribute the content beyond similar engineering-reference use should read DISCLAIMER.md § Copyright in source materials — Malaysia's PNMB-published Act 709 / Act A1727 carry the strictest publisher's notice of the populated jurisdictions and may require prior permission.

By using this skill you accept the full disclaimer in DISCLAIMER.md, including the "use at your own risk" terms and the maintainers' zero liability for any decision taken in reliance on this content.

This skill helps engineers ship features that comply with personal-data-protection statutes in Singapore, Thailand, Indonesia, Malaysia, the Philippines and Vietnam. It is organised by where in the stack the obligation lives rather than by statute section number — engineers shouldn't need to learn statute references to do their job.

Step 1 — Identify the active jurisdiction(s)

On first use in a project, check for .pdp-compliance.json at the project root. If present, use personalDataProtection.jurisdictions and load only the matching jurisdictions/<code>/README.md files. If absent, ask the user which jurisdiction(s) apply. The answer depends on where the application's users are located, not where the company is registered.

"Which personal-data-protection regimes does this application need to comply with? Pick all that apply: Singapore (PDPA 2012), Indonesia (UU PDP 27/2022), Thailand (PDPA B.E. 2562), Malaysia (PDPA 2010 with 2024 Amendments), Philippines (DPA / RA 10173), Vietnam (PDPL 91/2025/QH15). If users span multiple jurisdictions — and note Vietnam applies to Vietnamese citizens wherever they are —, pick all relevant — the strictest rule will usually win."

Once selected, suggest creating .pdp-compliance.json in the project root so future sessions and local guardrails do not need to re-ask:

{
  "personalDataProtection": {
    "jurisdictions": ["sg-pdpa"],
    "mode": "strictest-wins",
    "reviewPolicy": "warn"
  }
}

Then load only the relevant jurisdictions/<code>/README.md files. Cross-jurisdiction comparison lives in jurisdictions/_index.md.

Codes: sg-pdpa, th-pdpa, id-pdp, my-pdpa, ph-dpa, vn-pdpl — all populated. Per-jurisdiction status and the full comparison grid live in jurisdictions/_index.md.

Once the user has chosen, persist that choice in .pdp-compliance.json when the project allows file changes. If the project cannot accept that file, persist the choice somewhere project-specific (a comment in the project's AGENTS.md, CLAUDE.md, or equivalent project-instruction file) so subsequent sessions don't need to re-ask.

Step 2 — Pick the right entry point

You're starting work on something. Open the matching checklist:

TaskChecklist
Adding or modifying a feature that touches personal datachecklists/new-feature.md
Adding a column / field that holds personal datachecklists/new-data-field.md
Adding a third-party SDK or vendor that will process personal datachecklists/new-vendor.md
Responding to a security incidentchecklists/breach-response.md

You want depth on a specific layer. Open the matching layer file:

LayerWhat it covers
01 Non-technicalDPO, staff acceptable-use, vendor contracts, complaint handling
02 ArchitectureData residency, isolation, encryption, secret handling, defence-in-depth
03 Data modelConsent records, audit records, retention markers, deletion conventions, PII inventory
04 Controls and processesAccess control, retention sweeps, log hygiene, breach detection signals
05 Feature / UXSignup consent, settings, account deletion, data export, primer dialogs, EXIF strip
06 DisclosurePrivacy policy, T&C, OS permission strings, contextual notices
07 OperationalIncident response, retention sweeps, backups, vendor reviews, monitoring

Layer files are universal across all populated jurisdictions — implementation patterns are shared. Jurisdiction-specific obligations live in jurisdictions/<code>/obligations/.

Jurisdiction files

Once the active jurisdiction is known, open its files directly from this table rather than following links from one file to the next. Each README.md states scope, statute version and verification date; statute-map.md maps sections to layers; the obligation files hold the per-statute rules.

CodeStart hereStatute mapObligations
sg-pdpaREADMEstatute-map01 accountability · 02 consent · 03 purpose · 04 access correction · 05 care · 06 breach notification · 07 offences
th-pdpaREADMEstatute-map01 accountability · 02 consent · 03 purpose · 04 access correction · 05 care · 06 breach notification · 07 offences
id-pdpREADMEstatute-map01 accountability · 02 consent · 03 purpose · 04 access correction · 05 care · 06 breach notification · 07 offences
my-pdpaREADMEstatute-map01 accountability · 02 consent · 03 purpose · 04 access correction · 05 care · 06 breach notification · 07 offences
ph-dpaREADMEstatute-map01 accountability · 02 consent · 03 purpose · 04 access correction · 05 care · 06 breach notification · 07 offences
vn-pdplREADMEstatute-map01 accountability · 02 consent · 03 purpose · 04 access correction · 05 care · 06 breach notification · 07 offences · 08 sector specific

Templates to copy into a project: INCIDENT_RESPONSE.md.template (breach runbook) and pdp-nudge.sh.template (changed-file reminder hook).

Critical thresholds (commit to memory)

These vary by jurisdiction — the active one(s) determine which apply.

Singapore PDPAThailand PDPAIndonesia UU PDPMalaysia PDPAPhilippines DPAVietnam PDPL
Breach notification window to authority3 calendar days after assessing as notifiable (s26D(1))72 hours from awareness (s37(4))72 hours from awareness — to both subject AND regulator (Pasal 46(1))72 hours from discovery to Commissioner (s12B(1) + JPDP Guideline 25 Feb 2025); 7 days post-Commissioner to affected subject72 hours from knowledge / reasonable belief — to both NPC AND affected subject (§ 38 IRR + NPC Circular 16-03 § 12)72 hours from detection of the act (Điều 23(1)) — no assessment step
Significant-scale / risk threshold≥ 500 affected individuals"Risk to rights and freedoms"; "high risk" triggers individual notificationAlways notify subject; "certain circumstances" trigger public notification (Pasal 46(3))"Significant harm" triggers subject notification (s12B(2)) — no fixed scale thresholdInformation-type-driven: SPI or identity-fraud-enabling info, acquired by unauthorised person, real risk of serious harm (NPC Circular 16-03 § 11); ≥ 100 persons triggers § 35 penalty aggravationNone — harm-based trigger covering national defence/security and the subject's life, health, honour, dignity, property (Điều 23(1)); Điều 23(3) also covers purpose-creep and rights failures
Maximum financial penalty capSGD 1M / 10% SG turnover (s48J(3))THB 1M / 3M / 5M tiered (s82–84); plus criminal up to 1 year + THB 1M (s79)2% of annual revenue per violation (Pasal 57(3)); plus corporate criminal — fines up to 10× + suspension / dissolution (Pasal 70)RM 1M / 3 years per principle breach (s5(2), raised by A1727 from RM 300k / 2y); per-offence not turnover-based; offences stack₱5M / 6 years for combination or series (§ 33); ₱4M / 6 years for SPI offences (§§ 25(b), 26(b)); ≥ 100 persons triggers maximum-period aggravation (§ 35)5% of revenue for cross-border violations (Điều 8(4)) — highest here; 10× the gain for buying/selling data (Điều 8(3))
Individual criminal liabilityYes (s48D/E/F) — SGD 5,000 / 2 yearsYes (s79–81); s81 catches director / manager omissions, broader than SGYes (Pasal 67–68): up to 6 years + IDR 6B; corporate liability extends to dissolution (Pasal 70(4))Yes (s130 unlawful collecting RM 500k / 3y); s133 deeming liability for directors / managers unless they prove no-knowledge + due-diligence defenceYes — § 34 makes responsible officers personally liable for the prison terms of corporate offences (in addition to the corporate fine); § 30 concealment is its own offence (1.5–5 years + ₱500k–₱1M)Yes — Điều 8(1) routes to criminal prosecution; Điều 7 prohibits appropriating, intentionally disclosing or losing data, and buying/selling it

How to use the layer ↔ obligation split

The pattern is implement once, check against multiple jurisdictions.

A new-feature checklist run looks like:

  1. Identify what personal data the feature touches.
  2. Walk the universal layers/ to plan the implementation (data model, access controls, UX, disclosure, operational).
  3. For each active jurisdiction, walk jurisdictions/<code>/obligations/ to verify the implementation satisfies the statute-level obligations. Note where multiple jurisdictions disagree — usually the strictest rule controls.
  4. Update the project's privacy policy / consent records / runbook as needed.

Statute version

Each jurisdiction's README.md records:

  • Which version of the statute the obligation files reflect
  • When the content was last verified against official sources
  • Pending amendments to watch for

When statutes amend, this skill is updated and tagged. See the upstream CHANGELOG.md and pin to a version if you need stability.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use AtomLane to compile and execute safe atomic parallel plans on macOS and native Windows Preview for worthwhile independent argv tasks, dependency DAGs, supported platform entrypoints, or Apple-silicon operators. Use at task start or an execution boundary when structured local work may contain two or more worthwhile units; skip plain answers, one quick command, and work whose effects cannot be safely bounded.

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2752026年10月11日 更新

add

無料

Register a deferred decision in the debt registry. Trigger by judgment, not a marker scan, whenever a future reader would ask "why this way?": an unmade decision, stub, loosened type, bypassed check, swallowed error, a default picked "for now", or a TODO/FIXME/HACK/XXX marker. Trigger immediately whenever you defer work, or when the user invokes $add. Over-register freely; the developer drops with "drop A", "drop A,C", or "drop all".

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2752026年10月11日 更新

ADK 框架适配层。为 LangChain / EINO / AutoGen / AgentScope / CrewAI 提供框架特定的 代码模板、惯用模式、API 映射和项目结构,供 agent-dev-workshop Phase 5 代码生成使用。 每个框架 reference 文件标注 verified_date 用于版本锁定。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2752026年10月11日 更新

中文调试修复技能。用于报错、测试失败、页面异常、功能不符合预期、需要定位根因并做最小修复时。触发语包括"进入调试模式""帮我修问题""报错了""测试失败""页面坏了""找根因"。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2752026年10月11日 更新

交互式 AI Agent 开发工作坊:通过 6 阶段深度协作对话,引导用户完成 Agent 需求分析、架构设计、 工具定义、Prompt 与编排设计、代码生成、验证迭代,产出可直接运行的 Agent 项目。 框架无关设计优先,支持 LangChain / EINO / AutoGen / AgentScope / CrewAI 等 ADK 框架。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2752026年10月11日 更新

中文漂移审计技能。用于项目或学习过程变乱、上下文漂移、任务分叉、多个方案冲突、命名不一致、Codex 可能顺手改多了时。触发语包括"漂移检查""感觉跑偏了""项目变乱了""检查是否失控""分叉太多""上下文漂移"。

日本語の概要は準備中です。原文の説明を表示しています。

hashgraph-online/awesome-codex-plugins1,2752026年10月11日 更新

hashgraph-online のスキルをすべて見る

このスキルの問題を報告する