Ai Privacy Inference logo

Ai Privacy Inference

Community
mukul975
ai-privacy-inference

Managing privacy risks from AI-driven inferences about individuals including derived data classification, profiling under GDPR Art. 22, inference accuracy obligations, and controlling automated personality/behaviour predictions. Keywords: AI inference, derived data, profiling, automated predictions, GDPR.

Overview

Publishermukul975
RepositoryPrivacy-Data-Protection-Skills
Skill nameai-privacy-inference
Stars
279
Forks
59
Bundled files
4
LicenseApache-2.0
Links
  • Markdown instructions

    A SKILL.md file the model loads on demand, so it only costs tokens when a request actually matches.

  • Works with any LLM

    AI skills are plain Markdown, not provider-specific code, so this works with GPT, Claude, Gemini, Grok, or a local model.

  • 4 bundled files

    Scripts, templates, and references the model can read while it works. Files are read-only and never executed.

  • Open source

    Published by mukul975 on GitHub. Read the source before you install it.

Installation

Install the Ai Privacy Inference AI skill in TypingMind to use it with any LLM, or drop it into another agent that reads SKILL.md.

1

Install in TypingMind

TypingMind installs a skill straight from its GitHub folder — it reads SKILL.md, bundles the resource files, and stores the result locally.

  1. Open the app and go to Plugins → Skills.
  2. Choose "Install from GitHub".
  3. Paste the skill folder URL below and confirm.
  4. Enable the skill in any chat where you want it available.
Plugins → Skills → Add skill → From GitHub URL, then paste the folder URL and press Continue.
2

Install in another agent

Any agent that reads the Agent Skills format can use this skill — copy the folder into that agent's skills directory.

Claude Code — .claude/skills
git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git /tmp/Privacy-Data-Protection-Skills
mkdir -p .claude/skills
cp -r /tmp/Privacy-Data-Protection-Skills/plugins/ai-privacy-governance-skills/skills/ai-privacy-inference .claude/skills/ai-privacy-inference
Restart Claude Code after copying so it picks up the new skill.

Use it in TypingMind

Enable Ai Privacy Inference in any TypingMind chat and the model takes it from there. Its name and description sit in the system prompt, and the moment a request matches, the model loads the full instructions itself — you never invoke it by hand, and it costs no tokens until it is actually used.

The model loads Ai Privacy Inference on its own as soon as a request matches it.

Works with any AI model

AI skills are plain Markdown instructions rather than provider-specific code, so Ai Privacy Inference is not tied to the model it was written for. Install it once in TypingMind and use it with GPT-5, Claude, Gemini, Grok, DeepSeek, Mistral, Llama, or a local model you run yourself — all on your own API keys.

  • Loaded only when it is needed

    The system prompt carries just the name and description. The instructions are fetched on the first matching request, so an idle skill costs nothing.

  • Switch models mid-chat

    Because the skill is instructions rather than code, changing model does not break it — the next model reads the same SKILL.md.

Skill instructions

This is the SKILL.md content the model loads. Read it before installing — a skill is instructions your model will follow.

AI Privacy Inference and Derived Data

Overview

AI systems routinely generate inferences about individuals — predictions about creditworthiness, health risks, personality traits, political opinions, or behavioural patterns that were never directly provided by the data subject. These AI-derived inferences raise critical privacy questions: Are inferences personal data? When does inference become profiling under GDPR Article 22? What accuracy obligations apply to AI predictions? Can data subjects access, rectify, or object to inferences drawn about them? The CJEU, EDPB, and national DPAs have progressively clarified that inferences are personal data when they relate to an identified or identifiable person, and that GDPR rights extend to derived and inferred data. Cerebrum AI Labs must classify, govern, and provide transparency over all inferences its AI systems generate about individuals.

Legal Framework for AI Inferences

When Inferences Are Personal Data

CriterionAnalysisExample
Relates to an identified personInference is linked to a specific customer record or user profile"Customer C-12345 has 78% churn probability"
Relates to an identifiable personInference can be linked to a person through combination with other data"User with session token X-789 is likely aged 25-34"
Used to evaluate a personInference is used to assess, classify, or make decisions about someoneCredit score derived from transaction patterns
Has impact on a personInference affects how the person is treated or what options are availableInsurance premium adjusted based on predicted health risk

CJEU C-434/16 (Nowak, 2017): Personal data includes "any information" relating to a data subject — this encompasses opinions, assessments, and inferences, not only factual data directly provided by the individual.

EDPB Guidelines 8/2020 on Targeting of Social Media Users: Inferred data (data created by the controller through observation or derivation) constitutes personal data and is subject to the full scope of GDPR rights.

GDPR Classification of Inference Types

Inference TypeClassificationGDPR Implications
Observed dataData collected through direct interaction (browsing history, purchase records)Standard personal data — Art. 6 lawful basis required
Derived dataData created by the controller through computation on existing data (credit score, risk rating)Personal data — subject to access, rectification, objection rights
Inferred dataProbabilistic predictions about characteristics not directly observed (personality, health risk)Personal data — potentially special category if predicting Art. 9 characteristics
Aggregated dataStatistical outputs at group level, not linked to individualsNot personal data if truly anonymous (k-anonymity verified)

When Inferences Become Special Category Data

Predicted CharacteristicArt. 9 CategoryTrigger
Ethnic origin from name/location patternsRacial or ethnic originAny inference about ethnic background, even probabilistic
Political leaning from content engagementPolitical opinionsPrediction used to classify or target based on politics
Religious affiliation from purchase patternsReligious beliefsHalal/kosher purchase scoring, prayer time activity patterns
Health condition from behavioural signalsHealth dataStep count decline predicting depression, typing pattern analysis
Sexual orientation from browsing/social dataSexual orientationAny inference about sexual orientation regardless of accuracy
Pregnancy from purchase pattern shiftsHealth data + genderPurchase category analysis predicting pregnancy status

Cerebrum AI Labs Policy: Any inference that predicts, estimates, or classifies an Art. 9 characteristic — even indirectly or probabilistically — must be treated as special category data and requires an Art. 9(2) condition for processing.

Profiling Under GDPR Article 22

Profiling Definition (Art. 4(4))

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning:

  • Work performance
  • Economic situation
  • Health
  • Personal preferences
  • Interests
  • Reliability
  • Behaviour
  • Location
  • Movements

Three-Level Framework

LevelDescriptionGDPR RequirementCerebrum AI Labs Example
Profiling onlyAutomated evaluation without decisionArt. 6 lawful basis + Art. 13-14 transparencyCustomer segmentation for analytics dashboard
Profiling + human decisionAutomated evaluation informing a human decision-makerArt. 6 lawful basis + transparency + meaningful human involvementCredit risk score reviewed by loan officer
Solely automated decision with legal/significant effectsAutomated decision with no meaningful human involvement producing legal or similarly significant effectsArt. 22(1) prohibition applies — must fall within Art. 22(2) exceptionsAutomated loan rejection based solely on AI credit score

Art. 22(2) Exceptions Allowing Solely Automated Decisions

ExceptionRequirementCerebrum AI Labs Application
Art. 22(2)(a) — ContractDecision necessary for entering into or performing a contractAutomated credit pre-approval for existing customers
Art. 22(2)(b) — LawAuthorised by EU or Member State law with suitable safeguardsRegulatory-mandated fraud screening
Art. 22(2)(c) — Explicit consentData subject's explicit consent obtainedCustomer opts in to automated portfolio rebalancing

Safeguards Required (Art. 22(3))

SafeguardImplementation at Cerebrum AI Labs
Right to obtain human interventionEscalation button in customer portal routes to trained human reviewer within 2 business days
Right to express point of viewCustomer can submit additional context through contestation form before human review
Right to contest the decisionAppeal process with independent review panel; decision reversed if AI error demonstrated
Right to explanationIndividual explanation generated using SHAP values showing top 5 factors influencing the AI decision

Inference Accuracy and Quality Obligations

GDPR Article 5(1)(d) — Accuracy Principle

AI inferences must be accurate, and where necessary, kept up to date. For probabilistic predictions this means:

ObligationImplementation
Accuracy measurementTrack prediction accuracy metrics (precision, recall, F1) per demographic group
Confidence thresholdsDo not present inferences with confidence below 70% as actionable without human review
Staleness detectionRe-evaluate inferences when underlying data changes; flag inferences older than 90 days
Accuracy disclosureInform data subjects of the probabilistic nature and known accuracy of inferences
Rectification of inferencesAllow data subjects to challenge inferences; if input data is corrected, regenerate inference

EDPB Position on Inference Accuracy

The EDPB Guidelines on Automated Decision-Making (WP 251 rev.01) state that controllers must:

  1. Use appropriate mathematical or statistical procedures for profiling
  2. Implement appropriate technical and organisational measures to minimise the risk of errors
  3. Correct inaccuracies and enable rectification
  4. Secure personal data to prevent discriminatory effects

Transparency Requirements for AI Inferences

Art. 13-14 Information Requirements

InformationRequirementCerebrum AI Labs Implementation
Existence of profilingInform data subjects that profiling occursPrivacy notice section: "How we use AI to analyse your data"
Logic involvedMeaningful information about the logic involvedTechnical explainer: "Our AI analyses your transaction patterns, account tenure, and product usage to predict service needs"
SignificanceEnvisaged consequences of such processing"This analysis may affect the products and offers shown to you, and may influence credit decisions"
Categories of data usedWhat data feeds the inference"We use: transaction history, account tenure, product holdings, service interactions"
Inference outputsWhat inferences are generated"We generate: churn probability, product affinity scores, credit risk indicators"

AI Act Transparency Requirements

ObligationAI Act ArticleCerebrum AI Labs Implementation
Inform users they are interacting with AIArt. 52(1)Chat interface disclosure: "You are interacting with an AI assistant"
Disclose AI-generated contentArt. 52(3)Outputs marked: "This recommendation was generated by AI"
Disclose emotion recognitionArt. 52(2)Not applicable — Cerebrum AI Labs does not use emotion recognition
High-risk system deployer transparencyArt. 13Technical documentation available to regulators on request

Inference Governance Framework

Cerebrum AI Labs Inference Registry

All AI systems that generate inferences about individuals must be registered in the Cerebrum AI Labs Inference Registry:

Registry FieldDescription
System IDUnique identifier for the AI system
Inference typeCategory of inference generated (behavioural, demographic, financial, health)
Data subjects affectedCategories and approximate volume of individuals profiled
Input featuresData elements used to generate the inference
Output formatInference output (score, category, probability, ranking)
Accuracy metricsLatest precision, recall, F1 by demographic group
Retention periodHow long inferences are stored before deletion
Art. 22 assessmentWhether the inference feeds a solely automated decision
Lawful basisArt. 6 and (if applicable) Art. 9 basis for generating the inference
DPIA referenceAssociated DPIA document ID

Inference Lifecycle Controls

PhaseControl
GenerationLog all inferences with timestamp, model version, confidence score, input data hash
StorageEncrypt inference outputs; apply access controls limiting who can read individual-level inferences
UsageTrack downstream consumption of inferences; prevent scope creep beyond documented purposes
DisclosureMake inferences available to data subjects on request (Art. 15 access right)
RectificationIf underlying data is corrected, flag dependent inferences for regeneration
DeletionDelete inferences per retention schedule (90 days operational, 12 months audit)

Enforcement and Regulatory Precedents

  • CJEU C-634/21 (SCHUFA, 2023): The CJEU held that the generation of a credit score by a private entity constitutes "automated individual decision-making" under Art. 22 if the score plays a decisive role in a subsequent decision by a third party. This means AI-derived scores used in downstream decisions may trigger Art. 22 protections even if the AI provider is not the final decision-maker.
  • Austrian DPA — Case DSB-D550.038 (2022): Found that inferred political opinions from social media activity constitute special category data under Art. 9, even when the inference is probabilistic and may be inaccurate.
  • Norwegian DPA — Grindr Decision (2021): NOK 65 million fine for sharing data enabling inference of sexual orientation. Established that data enabling inference of Art. 9 characteristics is itself special category data.
  • CNIL — Clearview AI (2022): EUR 20 million fine, finding that biometric inferences (face embeddings) from public photographs are personal data subject to full GDPR compliance.

Key Legal References

  • GDPR Article 4(4) — Definition of profiling
  • GDPR Article 5(1)(d) — Accuracy principle
  • GDPR Article 13(2)(f) — Right to information about profiling logic and significance
  • GDPR Article 15(1)(h) — Right of access to profiling information
  • GDPR Article 22 — Automated individual decision-making including profiling
  • GDPR Recital 71 — Safeguards for profiling and automated decisions
  • GDPR Recital 72 — Guidelines on profiling
  • CJEU C-434/16 (Nowak, 2017) — Broad interpretation of personal data including assessments
  • CJEU C-634/21 (SCHUFA, 2023) — Credit scoring as automated decision-making
  • EDPB Guidelines on Automated Decision-Making (WP 251 rev.01) — Art. 22 interpretation
  • EDPB Guidelines 8/2020 on Targeting of Social Media Users — Inferred data as personal data
  • EU AI Act Article 52 — Transparency obligations for AI systems
  • EU AI Act Article 14 — Human oversight for high-risk AI systems

Bundled files

The model reads these on demand while the skill is loaded. They are exposed as readable files and are never executed.

Frequently asked questions

What does the Ai Privacy Inference AI skill do?

Managing privacy risks from AI-driven inferences about individuals including derived data classification, profiling under GDPR Art. 22, inference accuracy obligations, and controlling automated personality/behaviour predictions. Keywords: AI inference, derived data, profiling, automated predictions, GDPR.

Why use Ai Privacy Inference on TypingMind?

Because you install it once and use it with any model. Ai Privacy Inference is plain Markdown rather than provider-specific code, so the same skill runs on GPT-5, Claude, Gemini, Grok, or a local model — and you can switch model mid-chat without it breaking. TypingMind runs on your own API keys, so you pay providers directly instead of a per-seat subscription, and your skills and chats stay in your own storage.

How do I install Ai Privacy Inference in TypingMind?

Open Plugins → Skills → Install from GitHub in TypingMind and paste https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/plugins/ai-privacy-governance-skills/skills/ai-privacy-inference. TypingMind reads its SKILL.md and bundles its files and installs it as a skill you can enable per chat.

Which AI models can use Ai Privacy Inference?

Any model you connect in TypingMind. AI skills are plain Markdown instructions rather than provider-specific code, so GPT, Claude, Gemini, Grok, and local models can all load this skill when a request matches it.

How many AI models can I use with Ai Privacy Inference?

As many as you like. As long as a model supports skills, you can use Ai Privacy Inference with it — GPT, Claude, Gemini, Grok, DeepSeek, Mistral, Llama and more — all on TypingMind with your own API keys.

Is the Ai Privacy Inference AI skill free?

Yes. It is published on GitHub by mukul975 under the Apache-2.0 license. You only pay your own AI provider for the tokens you use.

What are AI skills?

An AI skill is a reusable instruction bundle that teaches an AI model how to do one specific task. It follows the open Agent Skills format: a SKILL.md file with a name and description, plus any scripts, templates or reference files the model may need. The model reads the instructions only when your request matches the skill, so an installed skill costs nothing until it is used.

How are AI skills different from plugins or MCP servers?

A plugin or MCP server gives a model new tools to call — code that runs somewhere and returns a result. An AI skill gives the model knowledge and process instead: how to approach a task, which steps to follow, what good output looks like. Skills are plain Markdown, so they need no server, no API key and no runtime, and they work with any model.

View all

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇