Adequacy Assessment logo

Adequacy Assessment

Community
mukul975
adequacy-assessment

Guides assessment of third-country adequacy decisions under GDPR Article 45 for international data transfers. Covers the current EC adequacy decisions list, adequacy assessment criteria, partial adequacy handling, and monitoring of adequacy decision reviews. Keywords: adequacy decision, Article 45, third country, adequate protection, EC adequacy list.

Overview

Publishermukul975
RepositoryPrivacy-Data-Protection-Skills
Skill nameadequacy-assessment
Stars
279
Forks
59
Bundled files
4
LicenseApache-2.0
Links
  • Markdown instructions

    A SKILL.md file the model loads on demand, so it only costs tokens when a request actually matches.

  • Works with any LLM

    AI skills are plain Markdown, not provider-specific code, so this works with GPT, Claude, Gemini, Grok, or a local model.

  • 4 bundled files

    Scripts, templates, and references the model can read while it works. Files are read-only and never executed.

  • Open source

    Published by mukul975 on GitHub. Read the source before you install it.

Installation

Install the Adequacy Assessment AI skill in TypingMind to use it with any LLM, or drop it into another agent that reads SKILL.md.

1

Install in TypingMind

TypingMind installs a skill straight from its GitHub folder — it reads SKILL.md, bundles the resource files, and stores the result locally.

  1. Open the app and go to Plugins → Skills.
  2. Choose "Install from GitHub".
  3. Paste the skill folder URL below and confirm.
  4. Enable the skill in any chat where you want it available.
Plugins → Skills → Add skill → From GitHub URL, then paste the folder URL and press Continue.
2

Install in another agent

Any agent that reads the Agent Skills format can use this skill — copy the folder into that agent's skills directory.

Claude Code — .claude/skills
git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git /tmp/Privacy-Data-Protection-Skills
mkdir -p .claude/skills
cp -r /tmp/Privacy-Data-Protection-Skills/plugins/cross-border-transfers-skills/skills/adequacy-assessment .claude/skills/adequacy-assessment
Restart Claude Code after copying so it picks up the new skill.

Use it in TypingMind

Enable Adequacy Assessment in any TypingMind chat and the model takes it from there. Its name and description sit in the system prompt, and the moment a request matches, the model loads the full instructions itself — you never invoke it by hand, and it costs no tokens until it is actually used.

The model loads Adequacy Assessment on its own as soon as a request matches it.

Works with any AI model

AI skills are plain Markdown instructions rather than provider-specific code, so Adequacy Assessment is not tied to the model it was written for. Install it once in TypingMind and use it with GPT-5, Claude, Gemini, Grok, DeepSeek, Mistral, Llama, or a local model you run yourself — all on your own API keys.

  • Loaded only when it is needed

    The system prompt carries just the name and description. The instructions are fetched on the first matching request, so an idle skill costs nothing.

  • Switch models mid-chat

    Because the skill is instructions rather than code, changing model does not break it — the next model reads the same SKILL.md.

Skill instructions

This is the SKILL.md content the model loads. Read it before installing — a skill is instructions your model will follow.

Assessing Third-Country Adequacy

Overview

GDPR Article 45 provides that the European Commission may determine that a third country, a territory, or one or more specified sectors within a third country, or an international organisation ensures an adequate level of protection for personal data. Where such an adequacy decision exists, transfers of personal data to the covered country, territory, or sector may take place without any specific authorisation or additional safeguard requirement. This skill guides the assessment of existing adequacy decisions and the handling of partial adequacy coverage.

Current EC Adequacy Decisions

As of March 2026, the European Commission has adopted adequacy decisions for the following countries and territories:

Country/TerritoryDecision ReferenceDate AdoptedScopePeriodic Review
AndorraDecision 2010/625/EU19 October 2010Full countryOngoing monitoring
ArgentinaDecision 2003/490/EC30 June 2003Full countryOngoing monitoring
CanadaDecision 2002/2/EC20 December 2001Commercial organisations subject to PIPEDA onlyOngoing monitoring
Faroe IslandsDecision 2010/146/EU5 March 2010Full territoryOngoing monitoring
GuernseyDecision 2003/821/EC21 November 2003Full territoryOngoing monitoring
IsraelDecision 2011/61/EU31 January 2011Full countryOngoing monitoring
Isle of ManDecision 2004/411/EC28 April 2004Full territoryOngoing monitoring
JapanDecision (EU) 2019/41923 January 2019Commercial sector subject to APPI supplementary rulesBiennial review; first review completed January 2021; second review 2023
JerseyDecision 2008/393/EC8 May 2008Full territoryOngoing monitoring
New ZealandDecision 2013/65/EU19 December 2012Full countryOngoing monitoring
South KoreaDecision (EU) 2022/25417 December 2021 (effective 2022)Commercial and public sector subject to PIPABiennial review
SwitzerlandDecision 2000/518/EC26 July 2000Full countryOngoing monitoring; assessed under revised FADP effective 1 September 2023
United KingdomDecision (EU) 2021/177228 June 2021Full countrySunset clause: expires 27 June 2025 unless renewed; renewal assessment underway
UruguayDecision 2012/484/EU21 August 2012Full countryOngoing monitoring
United States (DPF)Decision (EU) 2023/179510 July 2023Self-certified organisations under the EU-US DPF onlyAnnual review; first review October 2024

Adequacy Assessment Criteria (Art. 45(2))

When the Commission assesses the adequacy of the level of protection in a third country, it considers:

(a) Rule of Law and Human Rights

  • Respect for human rights and fundamental freedoms
  • General and sectoral legislation, including public security, defence, national security, and criminal law
  • Access by public authorities to personal data
  • Effective and enforceable data subject rights

(b) Independent Supervisory Authority

  • Existence and effective functioning of one or more independent supervisory authorities with responsibility for ensuring and enforcing data protection rules
  • Adequate enforcement powers including the power to investigate, intervene, and impose corrective measures
  • Independence from government interference

(c) International Commitments

  • International commitments the third country has entered into, including multilateral and bilateral agreements relating to the protection of personal data
  • Binding and enforceable obligations arising from such commitments

Partial Adequacy Handling

Several adequacy decisions cover only specific sectors or types of organisations within a country. Proper handling of partial adequacy is essential.

Canada — PIPEDA Partial Adequacy

Scope: Only transfers to Canadian organisations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) are covered by the adequacy decision. Provincial private-sector privacy laws that have been declared substantially similar to PIPEDA by the Governor in Council also fall within scope (e.g., Alberta PIPA, British Columbia PIPA, Quebec Act respecting the protection of personal information in the private sector).

Not covered:

  • Canadian public sector organisations (federal and provincial government agencies)
  • Organisations operating under provincial health information legislation
  • Organisations not subject to PIPEDA or substantially similar legislation

Verification: Before relying on the Canada adequacy decision, confirm that the specific Canadian recipient is subject to PIPEDA or a substantially similar provincial law.

Japan — APPI Supplementary Rules

Scope: The adequacy decision covers commercial sector entities subject to Japan's Act on the Protection of Personal Information (APPI) and the supplementary rules adopted by the Personal Information Protection Commission (PPC) of Japan specifically for the purpose of the EU adequacy finding.

Supplementary rules:

  1. Treatment of sensitive data: Japanese operators receiving data from the EU must treat all data received as "requiring special care" regardless of its category under APPI
  2. Retention limitation: Data must be deleted when no longer necessary for the purpose of use
  3. Onward transfers: Transfers outside Japan require either the data subject's consent or assurance that the recipient country provides equivalent protection
  4. Anonymously processed information: Restrictions on the use of anonymised data equivalent to GDPR standards

Verification: Confirm the Japanese recipient is subject to APPI and has implemented the supplementary rules.

United States — DPF Self-Certification

Scope: Only transfers to US organisations that have actively self-certified to the DPF with the Department of Commerce and are subject to FTC or DoT jurisdiction.

Not covered:

  • US government agencies
  • Non-certified US organisations
  • Organisations subject to regulators other than FTC/DoT (e.g., national banks, telecommunications carriers, insurance companies regulated by state insurance commissioners)

Verification: Check dataprivacyframework.gov for active certification status before each transfer.

South Korea — PIPA Coverage

Scope: Covers both commercial and public sector organisations subject to the Personal Information Protection Act (PIPA), as amended in 2023.

Not covered: Processing by intelligence and national security agencies exempt from PIPA.

Adequacy Decision Monitoring

Periodic Review Obligations

Under Art. 45(3), the Commission must periodically review adequacy decisions at least every four years. Some decisions include more frequent review commitments:

DecisionReview FrequencyLast ReviewNext Review Due
JapanBiennial20232025
South KoreaBiennial20242026
United States (DPF)AnnualOctober 2024October 2025
United KingdomBefore sunset (June 2025)OngoingJune 2025
Legacy decisions (Andorra, Argentina, etc.)At least every 4 yearsVariousVaries

Monitoring Actions for Organisations

  1. Subscribe to Commission notifications: Monitor the EC's data protection page and the EDPB's news section for announcements regarding adequacy reviews.
  2. Track legislative changes: Monitor data protection legislative developments in countries where the organisation relies on adequacy decisions.
  3. UK adequacy sunset: The UK adequacy decision contains a sunset clause expiring 27 June 2025. If not renewed, organisations must transition UK transfers to SCCs or other mechanisms immediately.
  4. DPF legal challenges: Monitor CJEU proceedings for any challenge to the DPF adequacy decision.
  5. Maintain backup mechanisms: For transfers relying on adequacy decisions with upcoming reviews or known risks, maintain executed SCCs as a contingency.

Practical Verification Workflow

For each transfer relying on an adequacy decision:

  1. Identify the adequacy decision: Confirm which decision covers the destination country or sector.
  2. Verify scope coverage: Confirm the specific recipient falls within the scope of the adequacy decision (not a partial adequacy gap).
  3. Verify the decision remains in force: Check the EC's list of adequacy decisions and any recent amendments, suspensions, or repeals.
  4. Document in the transfer register: Record the adequacy decision reference, scope coverage verification, and next review date.
  5. Set a monitoring reminder: Calendar the next periodic review date and any sunset clause deadlines.
  6. Contingency planning: For decisions with known risks (UK sunset, DPF legal challenges), prepare backup SCCs.

Bundled files

The model reads these on demand while the skill is loaded. They are exposed as readable files and are never executed.

Frequently asked questions

What does the Adequacy Assessment AI skill do?

Guides assessment of third-country adequacy decisions under GDPR Article 45 for international data transfers. Covers the current EC adequacy decisions list, adequacy assessment criteria, partial adequacy handling, and monitoring of adequacy decision reviews. Keywords: adequacy decision, Article 45, third country, adequate protection, EC adequacy list.

Why use Adequacy Assessment on TypingMind?

Because you install it once and use it with any model. Adequacy Assessment is plain Markdown rather than provider-specific code, so the same skill runs on GPT-5, Claude, Gemini, Grok, or a local model — and you can switch model mid-chat without it breaking. TypingMind runs on your own API keys, so you pay providers directly instead of a per-seat subscription, and your skills and chats stay in your own storage.

How do I install Adequacy Assessment in TypingMind?

Open Plugins → Skills → Install from GitHub in TypingMind and paste https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/plugins/cross-border-transfers-skills/skills/adequacy-assessment. TypingMind reads its SKILL.md and bundles its files and installs it as a skill you can enable per chat.

Which AI models can use Adequacy Assessment?

Any model you connect in TypingMind. AI skills are plain Markdown instructions rather than provider-specific code, so GPT, Claude, Gemini, Grok, and local models can all load this skill when a request matches it.

How many AI models can I use with Adequacy Assessment?

As many as you like. As long as a model supports skills, you can use Adequacy Assessment with it — GPT, Claude, Gemini, Grok, DeepSeek, Mistral, Llama and more — all on TypingMind with your own API keys.

Is the Adequacy Assessment AI skill free?

Yes. It is published on GitHub by mukul975 under the Apache-2.0 license. You only pay your own AI provider for the tokens you use.

What are AI skills?

An AI skill is a reusable instruction bundle that teaches an AI model how to do one specific task. It follows the open Agent Skills format: a SKILL.md file with a name and description, plus any scripts, templates or reference files the model may need. The model reads the instructions only when your request matches the skill, so an installed skill costs nothing until it is used.

How are AI skills different from plugins or MCP servers?

A plugin or MCP server gives a model new tools to call — code that runs somewhere and returns a result. An AI skill gives the model knowledge and process instead: how to approach a task, which steps to follow, what good output looks like. Skills are plain Markdown, so they need no server, no API key and no runtime, and they work with any model.

View all

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇