dpia-ai

Automate GDPR Article 35 DPIAs for AI systems with risk assessments and mitigation documentation.

2|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/lexbeam-software/eu-ai-governance-plugin --skill dpia-ai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpia-ai
Source: https://github.com/lexbeam-software/eu-ai-governance-plugin/tree/main/skills/dpia-ai
Command: npx skills add https://github.com/lexbeam-software/eu-ai-governance-plugin --skill dpia-ai

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

DPIA processes for AI systems are complex and require structured documentation to meet GDPR Article 35 and AI Act obligations. This skill provides a guided, repeatable workflow to identify triggers, capture risk assessments, and document mitigations with governance-ready outputs.

Core Features & Use Cases

  • GDPR Art. 35 DPIA workflow for AI systems, including data processing, risk assessment, and DPO consultation records.
  • AI Act-aligned fundamental rights impact considerations with traceability and monitoring plans.
  • Generate audit-ready DPIA artifacts: risk registers, mitigations, and decision records for regulatory inspection.

Quick Start

Initiate a GDPR Article 35 DPIA workflow for an AI system to document data processing, risks, and mitigations.

Frequently Asked Questions about dpia-ai

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
When do I need a GDPR Article 35 DPIA for an AI system?

A GDPR Article 35 DPIA is required for AI systems posing high risks to privacy, such as automated profiling or large-scale processing. This workflow triggers assessments for bias, explainability, and fundamental rights impacts to ensure compliance.

How do I document AI Act fundamental rights impacts during a DPIA?

You document AI Act fundamental rights impacts by following a structured workflow that captures risk assessments, mitigation strategies, and monitoring plans. This ensures traceability and aligns your AI system's risk governance with regulatory obligations.

What is the best way to generate audit-ready risk registers for AI compliance?

The best way to generate audit-ready risk registers is to use a guided DPIA workflow that systematically documents data processing activities, identified risks, and applied safeguards. This produces decision records suitable for regulatory inspection.

How do I structure a DPIA workflow that includes DPO consultation records?

You structure a DPIA workflow by dividing it into administration, data processing, risk assessment, safeguards, and approvals. This framework captures DPO consultation records and ensures traceability throughout the risk governance process.

Can I use this DPIA workflow for high-risk AI use cases involving bias and automation?

Yes, this DPIA workflow is designed for high-risk AI use cases involving bias, automation, and explainability. It systematically assesses these specific risks and documents mitigations to meet GDPR and AI Act compliance requirements.