privacy-impact-assessment-review
Installation
SKILL.md
Privacy Impact Assessment Review
Use this skill to convert privacy impact assessment, data processing, minimization, legal basis, vendor, retention, and mitigation questions into a concrete artifact with owners, gates, metrics, and recovery paths.
Workflow
- Identify feature scope, user groups, data collected, purpose, legal basis, vendors, AI/analytics use, retention, sharing, region, sensitive data, and user controls.
- Read
references/privacy-impact-assessment-patterns.md. - Classify processing as low-risk routine, consent-sensitive, vendor/subprocessor, AI/profiling, cross-border transfer, sensitive data, child/regulated, or high-risk DPIA-needed.
- Define data map, minimization, notice/consent, access controls, retention/deletion, DSAR path, risk mitigations, launch gate, and record of decision.
- Produce PIA report, state machine, decision table, event schema, risk checklist, and mitigation plan.
When not to use
- Do not use for generic advice the base model already handles without this skill's specific artifact contract.