What problem does it solve? Engineering teams handling EU/UK personal data often miss GDPR obligations like lawful basis, data subject rights, retention limits, and breach notification because these requirements span data flows rather than individual code lines. This Skill provides structured guidance to audit data flows, build rights workflows, and preserve accountability evidence. ## Core Features & Use Cases - Data-Flow Audits: Scriptable sweeps to map personal-data fields, payload logging, and third-party SDKs, keeping the data map generated rather than stale. - Rights and Consent Workflows: Guidance for deletion/export tests across databases, logs, backups, and vendors, plus consent evidence and withdrawal verification. - Decision Rubric and Escalation: A rubric mapping GDPR concerns (Article 5 principles, lawful basis, DPIA triggers, breach) to engineering requirements, with clear handoff rules to legal/privacy owners. - Use Case: Before launching a feature that collects user analytics from EU customers, use this Skill to verify a lawful basis is identified, retention is bounded, and deletion propagates through all storage layers. ## Quick Start Review this feature's handling of EU user personal data against GDPR requirements and flag any gaps in lawful basis, retention, or deletion workflows.