# GDPR audit of your codebase (/legal--gdpr-audit)

/legal--gdpr-audit is a Claude Code skill in the Business section. Audits your code for GDPR gaps in consent, retention and data subject rights, with file-level evidence for each finding.

- Web version: https://skills.sgomez.dev/en/s/legal--gdpr-audit
- Section: [Business](https://skills.sgomez.dev/en/business.md)
- Author: Santiago Gómez de la Torre
- License: MIT
- Source: https://github.com/sgomez-dev/claude-skills/blob/main/skills/legal/gdpr-audit.md
- Updated 10 Jul 2026

## Use it when

- You want to find compliance gaps before a customer or regulator does
- You need to check whether account deletion really removes data
- You are about to write a privacy policy or DPA and want to start from reality

## Not for

- Replacing the advice of a lawyer
- Products with no users in the EU, EEA or UK: it offers a closer regime instead

## What you get

A Markdown report in legal/ with each finding, its severity, GDPR article, evidence (file and line) and fix, plus a summary of the top 5 risks.

## How to ask for it

- `/legal--gdpr-audit review my app for GDPR gaps`
- `/legal--gdpr-audit check whether I handle consent and retention correctly`
- `/legal--gdpr-audit audit how I handle data subject rights`

## Install

macOS · Linux:

```
curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash
```

Windows:

```
irm https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.ps1 | iex
```

Claude Code plugin:

```
/plugin marketplace add sgomez-dev/claude-skills
/plugin install legal-skills@claude-skills-collection
```

## Permissions

- Reads: `**/*`
- Writes: `legal/**`, `GDPR_AUDIT*.md`
- Runs: —
- Network: No
- Destructive: No

## Author's description

Audit the codebase for GDPR gaps - consent, retention, data subject rights

## Questions about this skill

### Does it inspect code or just ask questions?

It inspects code: models, forms, logs, third parties and deletion flows. Each finding must point to a file, config or observed behavior.

### What if it cannot find a deletion flow?

It reports "not found in code" rather than claiming none exists anywhere.

### Does it work for a B2B backend?

Yes. If you are only a processor, it reframes rights findings as capabilities the controller will demand through a DPA.


- [How we review this](https://skills.sgomez.dev/en/methodology.md)
