cpo

Guide architecture reviews and generate DPIAs for GDPR, CCPA, SOC 2, and HIPAA compliance.

Updated Mar 11, 2026
One-click install
npx skills add https://github.com/elcoosp/elcoosp-skills --skill cpo-elcoosp
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: cpo
Source: https://github.com/elcoosp/elcoosp-skills/tree/main/virtual-saas-team/agents/core/cpo
Command: npx skills add https://github.com/elcoosp/elcoosp-skills --skill cpo-elcoosp

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill acts as a Compliance & Privacy Officer, ensuring that all product development adheres to regulatory requirements, privacy standards, and security best practices from the outset.

Core Features & Use Cases

  • Architecture Review: Vets system designs for security risks before implementation.
  • DPIA Generation: Conducts Data Protection Impact Assessments for features handling PII.
  • Compliance Monitoring: Maintains security controls and assesses regulatory adherence (GDPR, CCPA, SOC 2, HIPAA).
  • Use Case: Before a new feature that collects user location data can be built, this Skill will guide the team through creating a Data Protection Impact Assessment (DPIA) to identify and mitigate privacy risks.

Quick Start

Use the cpo skill to produce a DPIA for a new feature that collects user email addresses.

Frequently Asked Questions about cpo

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a Data Protection Impact Assessment for a new feature collecting PII?▼

To generate a Data Protection Impact Assessment (DPIA), provide the feature details to identify and mitigate privacy risks for collecting PII. The skill guides you through evaluating privacy-by-design controls and proactively assessing risks before implementation.

When do I need a Data Protection Impact Assessment for GDPR compliance?▼

You need a Data Protection Impact Assessment for GDPR compliance when developing features that handle personally identifiable information (PII) like user location or email addresses. It ensures privacy-by-design by identifying and mitigating risks early in the software development lifecycle.

Can I use this to vet system architecture for SOC 2 and HIPAA security controls?▼

Yes, you can use this to vet system architecture for SOC 2 and HIPAA security controls. It reviews system designs for security risks before implementation and maintains a security controls matrix to assess regulatory adherence.

What is the best way to ensure privacy by design during the software development lifecycle?▼

The best way to ensure privacy by design during the software development lifecycle is using a Compliance & Privacy Officer agent. It proactively identifies risks, conducts DPIAs, and vets architecture to enforce GDPR, CCPA, SOC 2, and HIPAA adherence.

How do I maintain a security controls matrix for CCPA and GDPR adherence?▼

Maintain a security controls matrix for CCPA and GDPR adherence by applying expert compliance monitoring guidance. It assesses regulatory adherence, ensures privacy-by-design, and helps mitigate risks throughout the software development lifecycle.