dpo-reporting

Solid

Data Protection Officer reporting discipline for Brazilian LGPD compliance. Covers the Registro de Operações (Art. 37), Relatório de Impacto à Proteção de Dados (RIPD, Art. 38), Data Subject Request response SLAs and tooling, incident notification to ANPD within the 72-hour window (Art. 48), and the signed-trail artifacts auditors expect. Use when designing the DPO dashboard, wiring DSR endpoints, writing incident playbooks, or preparing for an ANPD audit. Combines with compliance-lgpd (core) for the legal framework and with consent-lifecycle + pii-data-flow (core) for the underlying data.

AI & Automation 3 stars 0 forks Updated today MIT

Install

View on GitHub

Quality Score: 82/100

Stars 20%
20
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# DPO Reporting ## Cardinal Rule **Every DSR is a deadline. Every incident is a stopwatch. Every disclosure has a signed trail.** Anything less is a report you can't defend, a deadline you missed, or an incident you'll regret. ## The four DPO deliverables | Deliverable | Source | Cadence | Audience | |---|---|---|---| | **Registro de Operações (Art. 37)** | pii-inventory + consent_events + processing log | continuous; snapshot quarterly | ANPD on request; internal DPO | | **RIPD (Art. 38)** | RIPD template per processing activity | before launching new processing; reviewed yearly | internal DPO; ANPD on request | | **DSR response log** | DSR endpoint telemetry | continuous | requesting user + DPO | | **Incident notification** | incident response runbook | within 72 h of confirmed incident | ANPD + affected users | ## DSR response SLAs | DSR type (LGPD Art. 18) | SLA | Notes | |---|---|---| | Acesso (confirm + copy) | 15 calendar days | Extendable once by 15d with justification | | Correção | 15 calendar days | — | | Anonimização / bloqueio / eliminação | 15 calendar days | Subject to legal retention holds | | Portabilidade | 15 calendar days | Machine-readable format (JSON or CSV) | | Informação sobre compartilhamentos | 15 calendar days | From pii-inventory egress map | | Informação sobre recusa de consentimento | 15 calendar days | Explain consequences of refusal | | Revogação de consentimento | 24 h propagation (internal SLA; LGPD is "without undue delay") | Cascades...

Details

Author
Canhada-Labs
Repository
Canhada-Labs/ceo-orchestration
Created
4 weeks ago
Last Updated
today
Language
Python
License
MIT

Integrates with

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

Data & Documents Solid

lgpd

Expert LGPD compliance advisor for Brazil's Lei Geral de Proteção de Dados (Law 13,709/2018). Use this skill whenever a user asks about LGPD, Brazilian data protection, ANPD, personal data processing in Brazil, data subject rights under Brazilian law, legal bases for processing, sensitive data handling, DPO appointment in Brazil, data breach notification to ANPD, LGPD penalties (fines up to 2% of revenue / R$50M), international data transfers from Brazil, Brazil-EU mutual adequacy (January 2026 — SCCs/BCRs no longer needed for Brazil-EU transfers), LGPD gap assessments, privacy policy drafting for Brazilian operations, DPIA under LGPD, consent management, or comparing LGPD with GDPR. Trigger for any Brazil privacy or data protection question even if LGPD is not named explicitly.

780 Updated 1 weeks ago
Sushegaad
Code & Development Solid

digital-brasil

Use para LGPD, proteção de dados, Marco Civil da Internet, cookies, termos de uso, privacidade em apps e sites, direitos digitais, vazamento de dados, adequação LGPD. Ativa em "LGPD", "proteção de dados", "política de privacidade", "vazamento de dados", "cookies", "Marco Civil", "direito ao esquecimento".

5 Updated 1 weeks ago
AlissonSantos1
AI & Automation Listed

pdpl-compliance-checker

Runs Saudi PDPL (Personal Data Protection Law) compliance readiness reviews against systems, apps, data flows, vendors, or codebases. Use whenever the user mentions "PDPL", "Saudi data protection", "SDAIA", "data residency Saudi", "cross-border transfer KSA", "privacy compliance Saudi", asks whether a product/feature/data flow is PDPL-compliant, asks what PDPL requires for consent, breach notification, DPO, controller registration, or data subject rights, or asks to prepare for a SDAIA audit or enforcement inquiry. Also use when reviewing an AI system, LLM feature, or app architecture that processes personal data of people in Saudi Arabia, even if the user doesn't say "PDPL" explicitly.

0 Updated 1 weeks ago
cherifYM