arckit-us-privacy-pia

Generate Privacy Impact Assessments for US federal civilian systems.

Updated Jul 24, 2026
One-click install
npx skills add https://github.com/tractorjuice/arckit-kimi --skill arckit-us-privacy-pia
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: arckit-us-privacy-pia
Source: https://github.com/tractorjuice/arckit-kimi/tree/main/skills/arckit-us-privacy-pia
Command: npx skills add https://github.com/tractorjuice/arckit-kimi --skill arckit-us-privacy-pia

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This skill automates the complex, multi-step process of generating a Privacy Impact Assessment (PIA) compliant with the E-Government Act of 2002 and OMB M-03-22 for US federal systems.

Core Features & Use Cases

  • Regulatory Alignment: Ensures documentation meets Privacy Act of 1974, NIST SP 800-122, and OMB M-03-22 standards.
  • Automated Compliance Checks: Performs SORN trigger analysis and FIPPs conformance mapping.
  • Use Case: An enterprise architect needs to document a new federal system handling PII; this skill generates the required PIA, identifies SORN requirements, and maps data flows to ensure the system is ready for SAOP sign-off.

Quick Start

Invoke the arckit-us-privacy-pia skill by providing the project name to generate a compliant privacy assessment for your federal system.

Frequently Asked Questions about arckit-us-privacy-pia

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a Privacy Impact Assessment for a federal IT system?

To generate a Privacy Impact Assessment, provide your federal system project name to initiate automated PII inventory mapping, SORN trigger determination, and FIPPs conformance analysis compliant with OMB M-03-22.

What triggers the need for a Privacy Impact Assessment under the E-Government Act?

A Privacy Impact Assessment is required when a federal civilian system handles personally identifiable information, triggering statutory documentation under E-Government Act Section 208 and requiring SORN determination analysis.

Can I use this to map PII data flows for NIST SP 800-122 compliance?

Yes, this maps PII inventory and data flows to ensure your system documentation meets NIST SP 800-122, Privacy Act of 1974, and OMB M-03-22 standards for federal compliance readiness.

How do I determine if my federal system requires a System of Record Notice?

This performs an automated SORN trigger analysis during the Privacy Impact Assessment generation, evaluating your system's PII handling against Privacy Act of 1974 requirements to determine SORN necessity.

Does this support Fair Information Practice Principles conformance analysis?

Yes, it includes automated FIPPs conformance mapping as part of the comprehensive Privacy Impact Assessment, aligning your federal system documentation with established fair information practice principles.

What are the limitations of automated PIA generation for federal systems?

While it automates PII inventory mapping and SORN trigger determination, the generated Privacy Impact Assessment still requires enterprise architect review and SAOP sign-off to satisfy statutory documentation requirements for federal IT systems.