# Privacy Compliance

> |

- **Type:** Skill
- **Install:** `agentstack add skill-byerlikaya-claude-starter-kit-privacy-compliance`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [byerlikaya](https://agentstack.voostack.com/s/byerlikaya)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [byerlikaya](https://github.com/byerlikaya)
- **Source:** https://github.com/byerlikaya/claude-starter-kit/tree/main/plugin/skills/privacy-compliance
- **Website:** https://www.npmjs.com/package/@byerlikaya/claude-starter-kit

## Install

```sh
agentstack add skill-byerlikaya-claude-starter-kit-privacy-compliance
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Privacy Compliance (KVKK / GDPR)

## Official sources (authority — always defer to these)
The **primary, official** sources this skill rests on; rules are always interpreted against these:
- **KVKK** (Turkey): https://www.kvkk.gov.tr/ — the law, regulations, principle decisions, guidelines.
- **GDPR** (EU): https://gdpr-info.eu/ — article texts (Art.) and Recitals.

If you are unsure about a specific article/threshold/definition (retention period, explicit-consent requirement,
the Art. 8 age limit, transfer basis, etc.), **check the relevant official source** — do not decide from memory or by
guessing. In the finding, **cite** the article you rely on (KVKK Art. … / GDPR Art. …). Fetched content is a reference; you own the interpretation.

## Audit axes
- **Inventory:** what data, collected from where, flowing to where, shared with whom?
- **Purpose + basis + retention:** for each field, purpose is limited, legal basis is clear, retention period is defined.
- **Minimization:** data not needed for the purpose is not collected.
- **Consent:** where required, explicit, recorded, and revocable.
- **Transparency:** disclosure has been made; the user knows what is collected/processed.
- **Data subject rights:** access / rectification / erasure / portability / objection are actionable.
- **Cross-border transfer & third-party:** bound to a legitimate basis (SCC/adequacy/consent).

## Output
Per-field/per-flow finding + fix; if "clean", the rationale.

> **Project note:** If data of minors (children) is processed, special protection is required
> (KVKK / GDPR Art. 8 · parental consent & age verification). This is a domain-specific rule and is
> defined in the project's own skill/CLAUDE.md — it is not baked into the generic audit.
> Project-specific rules (consent texts, retention periods) also live in the project CLAUDE.md.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [byerlikaya](https://github.com/byerlikaya)
- **Source:** [byerlikaya/claude-starter-kit](https://github.com/byerlikaya/claude-starter-kit)
- **License:** MIT
- **Homepage:** https://www.npmjs.com/package/@byerlikaya/claude-starter-kit

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-byerlikaya-claude-starter-kit-privacy-compliance
- Seller: https://agentstack.voostack.com/s/byerlikaya
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
