We have released a free, open-source plugin that turns Claude Code into a GDPR working assistant. It has seven skills, and before publishing it we ran them on our own website. They found real problems, which we have since fixed, and they also got a few things wrong. This post covers what the plugin does, what it found, and how to get good results from it. It is now listed in Anthropic's plugin directory.
What the plugin does
The GDPR Compliance plugin adds seven skills to Claude Code. Each one follows a fixed method and returns a working draft in a set format, so the output is easy to review.
| Skill | What it produces |
|---|---|
| dpia | A screening against the EDPB criteria and a draft DPIA (Art. 35). See why AI features need one |
| ropa | A record of processing activities, with gaps and open questions (Art. 30) |
| privacy-policy-review | A findings table against the transparency rules (Arts. 12 to 14), with replacement wording |
| cookie-tracker-audit | A list of cookies, trackers and embeds, and whether they fire before consent |
| dpa-review | A clause-by-clause review of a processor agreement (Art. 28) with proposed redlines |
| breach-response | A risk assessment, the 72-hour notification deadline and draft notices (Arts. 33 and 34) |
| dsar-response | A response plan and letter for access, erasure and other requests (Arts. 15 to 22) |
Two commands tie them together: /gdprgard-compliance:gdpr-check reviews a file or folder and returns a prioritised list of issues, and /gdprgard-compliance:breach starts a breach response.
What happened when we ran it on our own site
We pointed the skills at gdprgard.eu: the AI chat assistant and its backend function, the privacy policy and the cookie banner. The review turned up issues we had missed, and we have fixed all of them:
- A retention promise we did not keep. The chat consent screen said conversations were deleted after 30 days. The code stored nothing, so the claim was wrong. It now says plainly that we do not store messages.
- A consent record that was not one. The widget said consent was recorded, but the choice lived only in memory and was lost on every page load. It is now saved in the browser, and the Withdraw link works.
- A policy that disagreed with the product. The privacy policy relied on legitimate interest for the chat while the widget asked for consent. We aligned the two.
- Missing disclosures. Purchases run through Stripe and delivery emails through Resend, and neither was in the privacy policy. Both are now listed, with their roles, their transfer safeguards and a stated retention period for purchase records.
- A weak origin check. The chat function accepted any origin that began with our domain name, so a look-alike domain would have passed. It now compares the exact origin and limits how often a visitor can call it.
Where it got things wrong
An AI review is a first pass, not a verdict. In our run, one check reported that a Meta cookie was missing from our cookie table when it was already there, because it had read an out-of-date copy of the page. That is also why the skills list their open questions, mark what they could not verify, and tell you to check each finding against the live source. The same care applies to cookie banner findings: confirm what actually loads before consent.
The same applies to the law. The skills summarise what the GDPR requires, and they do not replace your DPO or a lawyer. Treat the output as a working draft and check the cited articles yourself.
Install it in two commands
You need Claude Code. Then run these two commands inside it:
- /plugin marketplace add zsrrica-pixel/gdpr-compliance-plugin
- /plugin install gdprgard-compliance@gdprgard-plugins
Restart Claude Code, then ask for what you need, for example "review this privacy policy" or "do we need a DPIA for this feature?". The plugin runs inside your own Claude Code session, so the documents and websites you analyse are not sent to GDPRGard. Full details are on the plugin page. It is also listed in Anthropic's plugin directory, so you can add it from there as well.
How to get good results
- Give it the real text. Point it at the actual policy, contract or source file, not a summary of it.
- Answer the open questions. The skills list what they could not know, and your answers turn a generic draft into a usable one.
- Check every finding. Verify it against the live page or the contract before you act on it.
- Start with the check command. Run it on one file or folder, then use the specific skills for the issues it finds.
The bottom line
An AI assistant will not make you compliant, but it finds the gaps between what you say and what you do faster than a manual review, and that is where most GDPR problems hide. The plugin is free, open source under the MIT licence, and open to contributions on GitHub.
Book a free consultation with GDPRGard β if you want a person to go through the results with you.
Sources
- GDPR Compliance plugin for Claude Code on GitHub
- Claude Code documentation: plugins
- Regulation (EU) 2016/679 (GDPR) on EUR-Lex
Also read:
- Your AI chatbot isn't anonymising anything
- Why every SaaS company needs a DPIA before launching AI features
- The 5 most common cookie banner mistakes β and how to fix them