Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

Explore

  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Tags index
  • Submit a server
  • Pricing

Learn

  • Guides hub
  • What is MCP?
  • Install guide
  • Troubleshooting
  • Security
  • Blog
  • Blog RSS

Tools

  • All tools
  • Config generator
  • Config validator
  • MCP playground
  • OpenAPI β†’ MCP
  • Badge generator

For agents

  • API docs
  • Trust & traffic
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
  • Remote MCP β†— (opens in a new tab)

Company

  • About
  • Contact
  • X (@AllMCPs) β†— (opens in a new tab)
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on Buildlist
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. GDPR Shift Left Compliance
G
Health: Not checked yetWe have not completed a health check for this listing yet.Last checked 8/11/2026, 12:04:46 AM

GDPR Shift Left Compliance

Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository

GDPR compliance MCP server - article lookup, DPIA, ROPA, DSR, IaC analysis, Bicep templates.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Install Config Generator

Choose your client
claude_desktop_config.json
{
  "mcpServers": {
    "gdpr-shift-left-compliance": {
      "command": "npx",
      "args": [
        "-y",
        "gdpr-shift-left-compliance"
      ]
    }
  }
}

πŸ’‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)

Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Documentation Overview

GDPR Shift-Left MCP Server

Tests & Judges PyPI version Python versions License: MIT

A Model Context Protocol (MCP) server that brings GDPR compliance knowledge directly into your IDE, enabling developers and compliance teams to "shift left" β€” identifying and addressing data protection requirements early in the development lifecycle.

⚠️ Disclaimer: This tool provides informational guidance only and does not constitute legal advice. Organisations should consult qualified legal counsel for binding GDPR compliance decisions.

Features

πŸ” GDPR Knowledge Base (34 Tools)

  • Article Lookup β€” Retrieve any GDPR article by number, search across all 99 articles and 173 recitals
  • Definitions β€” Art. 4 term definitions with contextual explanations
  • Chapter Navigation β€” Browse articles by chapter with full directory
  • Azure Mappings β€” Map GDPR articles to Azure services and controls

πŸ“‹ Compliance Workflows

  • DPIA Assessment β€” Assess whether a DPIA is required (EDPB 9-criteria test), generate Art. 35 templates
  • ROPA Builder β€” Generate and validate Art. 30 Records of Processing Activities
  • DSR Guidance β€” Step-by-step workflows for all 7 data subject rights (Arts. 12–23)
  • Retention Analysis β€” Assess retention policies against Art. 5(1)(e) storage limitation
  • Controller/Processor Role Classification β€” Assess data roles, get obligations, analyze code patterns, generate DPA checklists

πŸ—οΈ Infrastructure & Code Review

  • Bicep/Terraform/ARM Analyzer β€” Scan IaC for GDPR violations (encryption, access, network, residency, logging, retention)
  • Application Code Analyzer β€” Detect PII logging, hardcoded secrets, missing consent checks, data minimisation issues
  • GDPR Config Validator β€” Pass/fail validation in strict or advisory mode
  • DSR Capability Analyzer β€” Detect implementation of all 7 data subject rights (Arts. 15–22)
  • Cross-Border Transfer Analyzer β€” Identify third-party APIs/SDKs that may transfer data outside EEA, with risk justifications explaining why each provider has its assigned risk level (based on headquarters location, adequacy decisions, and data sensitivity)
  • Breach Readiness Analyzer β€” Assess breach detection, logging, and notification capabilities
  • Data Flow Analyzer β€” Map personal data lifecycle (collection, storage, transmission, deletion)
  • AST Code Analyzer β€” Deep analysis using Abstract Syntax Trees for Python, JavaScript, TypeScript, Java, C#, and Go with:
    • PII detection in function parameters and variables
    • Cross-border transfer detection via import analysis (150+ providers with risk justifications)
    • PII logging violation detection
    • DSR implementation pattern verification
    • Data flow tracking and call graph analysis

πŸ“ Guided Prompts (8 Expert Prompts)

  • Gap Analysis, DPIA Assessment, Compliance Roadmap, Data Mapping
  • Incident Response, Azure Privacy Review, Vendor Assessment, Cross-Border Transfers

πŸ“ Azure Bicep Templates (19 Templates)

  • Storage Account β€” CMK encryption, Private Endpoint, lifecycle policies (Art. 5, 25, 32, 44-49)
  • Key Vault β€” HSM-backed Premium, purge protection, RBAC (Art. 25, 32)
  • Azure SQL β€” Entra-only auth, TDE, auditing (Art. 25, 32)
  • Log Analytics β€” 365-day retention, saved GDPR queries for breach/access/erasure tracking (Art. 5(2), 30, 33)
  • Cosmos DB β€” EU-only regions, strong consistency, continuous backup, TTL-enabled ROPA container (Art. 25, 32, 44-49)
  • App Service β€” Managed identity, TLS 1.2, VNet integration, staging slot, full audit logging (Art. 25, 32)
  • Virtual Network β€” 3 subnets, NSGs with least-privilege rules, service endpoints (Art. 25, 32, 5(1)(f))
  • Container Apps β€” Internal ingress, mutual TLS, zone redundancy, managed identity (Art. 25, 32)
  • Monitor Alerts β€” DPO action group, 4 scheduled alerts for sign-in/exfiltration/escalation/Key Vault (Art. 33, 34, 32)
  • PostgreSQL Flexible Server β€” Zone-redundant HA, Entra ID auth, pgaudit, geo-redundant backups (Art. 25, 32, 5(1)(e))
  • Service Bus Premium β€” CMK encryption, GDPR queues for DSR/consent/breach/retention (Art. 25, 32, 5(1)(f))
  • AKS β€” Private cluster, Azure CNI, Defender for Containers, workload identity, network policies (Art. 25, 32, 5(1)(f))
  • Confidential Ledger β€” TEE-backed tamper-proof audit trail for GDPR accountability records (Art. 5(2), 30, 33)
  • Confidential VM β€” AMD SEV-SNP encrypted memory, vTPM, secure boot, ephemeral OS disk (Art. 25, 32, 5(1)(f))
  • Entra ID Configuration β€” Audit log routing, sign-in monitoring, Conditional Access checklist (Art. 32, 5(2))
  • Azure Policy β€” EU region restriction, CMK enforcement, tag requirements, HTTPS-only (Art. 25, 32, 44)
  • Defender for Cloud β€” All Defender plans, security contacts, auto-provisioning, GDPR compliance dashboard (Art. 32, 33)
  • API Management β€” Internal VNet, TLS 1.2+, rate limiting, data masking policies, audit logging (Art. 25, 32, 30)
  • Front Door with WAF β€” OWASP rules, EU/EEA geo-filtering, bot protection, rate limiting (Art. 25, 32, 44)

Quick Start

Prerequisites

  • Python 3.10+
  • VS Code with GitHub Copilot

Installation

Install from the MCP Registry (recommended)

The server is published to the MCP Registry. You can install it directly in VS Code:

  1. Open the Extensions view (Ctrl+Shift+X)
  2. Type @mcp GDPR in the search field
  3. Click Install on "GDPR Shift-Left Compliance"

Note: The VS Code MCP gallery shows a curated subset of servers by default. If the server doesn't appear, add this to your VS Code User Settings (Ctrl+, β†’ Open Settings JSON):

json
"chat.mcp.gallery.serviceUrl": "https://registry.modelcontextprotocol.io"

This points VS Code at the full MCP Registry (5,000+ servers) instead of GitHub's curated list.

Install via uvx (no clone needed)

bash
uvx gdpr-shift-left-mcp

Install from source

bash
# Clone the repository
git clone https://github.com/KevinRabun/GDPRShiftLeftMCP.git
cd GDPRShiftLeftMCP

# Install in development mode
pip install -e ".[dev]"

VS Code Integration

The repository includes .vscode/mcp.json for automatic MCP server registration. After installation, the GDPR tools appear in GitHub Copilot's tool list.

To configure manually, add to your VS Code settings:

config.json
{
  "mcp": {
    "servers": {
      "gdpr-shift-left-mcp": {
        "type": "stdio",
        "command": "python",
        "args": ["-m", "gdpr_shift_left_mcp"]
      }
    }
  }
}

Running the Server

bash
# Run directly
python -m gdpr_shift_left_mcp

# Or via the installed entry point
gdpr-shift-left-mcp

Tool Reference

ToolDescriptionGDPR Articles
get_articleRetrieve a GDPR article by numberAll
list_chapter_articlesList all articles in a chapterAll
search_gdprFull-text search across GDPRAll
get_recitalRetrieve a recital by numberAll
get_azure_mappingAzure services for a GDPR articleAll
get_definitionArt. 4 term definitionArt. 4
list_definitionsList all definitionsArt. 4
search_definitionsSearch definitionsArt. 4
assess_dpia_needCheck if DPIA is requiredArt. 35
generate_dpia_templateGenerate DPIA documentArt. 35
get_dpia_guidanceDPIA area guidanceArt. 35–36
generate_ropa_templateArt. 30 ROPA templateArt. 30
validate_ropaValidate ROPA completenessArt. 30
get_ropa_requirementsROPA field requirementsArt. 30
get_dsr_guidanceDSR handling guidanceArts. 12–23
generate_dsr_workflowDSR fulfilment workflowArts. 12–23
get_dsr_timelineDSR response timelinesArt. 12(3)
analyze_infrastructure_codeScan IaC for GDPR issuesArt. 25, 32, 44
analyze_application_codeScan app code for GDPR issuesArt. 5, 25, 32
validate_gdpr_configPass/fail GDPR validationAll
assess_retention_policyAssess retention policyArt. 5(1)(e)
get_retention_guidanceCategory-specific retentionArt. 5(1)(e)
check_deletion_requirementsDeletion capability checklistArt. 17
assess_controller_processor_roleAssess data controller/processor roleArt. 4, 24, 26, 28
get_role_obligationsRole-specific GDPR obligationsArt. 24, 26, 28
analyze_code_for_role_indicatorsDetect controller/processor code patternsArt. 4, 24, 28
generate_dpa_checklistArt. 28 DPA agreement checklistArt. 28
get_role_scenariosCommon role classification scenariosArt. 4, 24, 26, 28
analyze_dsr_capabilitiesDetect DSR implementation (access, erase, portability, etc.)Arts. 15–22
analyze_cross_border_transfersDetect third-party APIs/SDKs with risk justificationsArts. 44–49
analyze_breach_readinessAssess breach detection, logging, and notification capabilitiesArts. 33–34
analyze_data_flowMap personal data lifecycle (collection, storage, transmission, deletion)Art. 30
analyze_code_astDeep AST analysis for Python/JS/TS/Java/C#/Go (PII, cross-border, DSR)Art. 5, 25, 32, 44
get_ast_capabilitiesGet AST analyzer supported languages and featuresAll

Architecture

Code
src/gdpr_shift_left_mcp/
β”œβ”€β”€ __init__.py              # Package init
β”œβ”€β”€ __main__.py              # Entry point
β”œβ”€β”€ server.py                # FastMCP server + prompt registration
β”œβ”€β”€ disclaimer.py            # Legal disclaimer utility
β”œβ”€β”€ data_loader.py           # Online GDPR data fetching + caching
β”œβ”€β”€ tools/
β”‚   β”œβ”€β”€ __init__.py          # Tool registration (34 tools)
β”‚   β”œβ”€β”€ articles.py          # Article/recital/search tools
β”‚   β”œβ”€β”€ definitions.py       # Art. 4 definition tools
β”‚   β”œβ”€β”€ dpia.py              # DPIA assessment tools
β”‚   β”œβ”€β”€ ropa.py              # ROPA builder tools
β”‚   β”œβ”€β”€ dsr.py               # Data subject rights tools
β”‚   β”œβ”€β”€ analyzer.py          # IaC + app code analyzer
β”‚   β”œβ”€β”€ ast_analyzer.py      # AST-based deep code analysis
β”‚   β”œβ”€β”€ retention.py         # Retention/deletion tools
β”‚   └── role_classifier.py   # Controller/processor role classification
β”œβ”€β”€ prompts/
β”‚   β”œβ”€β”€ __init__.py          # Prompt loader
β”‚   └── *.txt                # 8 expert prompt templates
└── templates/
    β”œβ”€β”€ __init__.py           # Template loader
    └── *.bicep               # GDPR-aligned Azure Bicep templates

Testing

bash
# Run all tests
pytest

# Run with coverage
pytest --cov=gdpr_shift_left_mcp --cov-report=html

# Run judges (end-to-end evaluators)
python -m tests.evaluator.run_judges

Online Updates

The server fetches GDPR data from a configurable online source, with local caching:

  • Source URL: Set via GDPR_SOURCE_URL environment variable
  • Cache TTL: Default 1 hour (configurable via GDPR_CACHE_TTL)
  • Cache directory: __gdpr_cache__/ (configurable via GDPR_CACHE_DIR)
  • Fallback: Built-in data if online fetch fails

Contributing

See CONTRIBUTING.md for guidelines. This project follows Git Flow branching:

  • feature/<name> for new features
  • bugfix/<name> for fixes
  • release/<version> for releases
  • hotfix/<name> for production fixes

All PRs must pass automated tests and judges before merging.

License

MIT β€” see LICENSE for details.

Acknowledgements

  • Architecture inspired by FedRAMP20xMCP
  • GDPR text from EUR-Lex
  • EDPB guidelines from edpb.europa.eu

Related MCP Servers

View all in Security View all alternatives
  • C
    CrowdStrike Falcon MCP Server

    Connects AI agents with CrowdStrike Falcon for security analysis and automation.

    πŸ”’ Security0 views
    Compare vs CrowdStrike Falcon MCP Server β†’
  • Mcp Maigret logoMcp Maigret

    MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.

    πŸ”’ Security3 views
    Compare vs Mcp Maigret β†’
  • N
    Nis2 Compliance Mcp

    NIS2 Directive (EU 2022/2555) compliance for AI agents. 10 Article 21 risk-management measur...

    πŸ”’ Security0 views
    Compare vs Nis2 Compliance Mcp β†’
  • Agentward logoAgentward

    Permission control plane for AI agents. MCP proxy that enforces least-privilege YAML policies on every tool call, classifies sensitive data (PII/PHI), detects dangerous skill chains, and generates compliance audit trails. Supports stdio and HTTP proxy modes.

    πŸ”’ Security2 views
    Compare vs Agentward β†’

Frequently Asked Questions about GDPR Shift Left Compliance

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "gdpr-shift-left-compliance": { "command": "npx", "args": ["-y", "GDPR Shift-Left Compliance"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewGDPR Shift Left Compliance AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/gdpr-shift-left-compliance?style=directory)](https://allmcps.com/mcp/gdpr-shift-left-compliance)
HTML Embed
<a href="https://allmcps.com/mcp/gdpr-shift-left-compliance"><img src="https://allmcps.com/api/badge/gdpr-shift-left-compliance?style=directory" alt="GDPR Shift Left Compliance on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
0/5 checks healthy over the last 6h
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
27Quality signal: Emerging Β· 27/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools11/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to get the verified badge and attach your website.

Free dofollow backlink: after claiming, verify your product site and place a dofollow AllMCPs badge β€” we recheck it stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to GDPR Shift Left Compliance β†’Install in Claude DesktopInstall in CursorInstall in VS Code