dpia-generation

Generate UK GDPR Article 35 DPIAs with trigger validation and Article 36 flags.

9|Updated May 18, 2026
One-click install
npx skills add https://github.com/uk-agents/uk-legal-plugins --skill dpia-generation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpia-generation
Source: https://github.com/uk-agents/uk-legal-plugins/tree/main/privacy-legal-uk/skills/dpia-generation
Command: npx skills add https://github.com/uk-agents/uk-legal-plugins --skill dpia-generation

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill generates a UK GDPR Article 35 Data Protection Impact Assessment (DPIA) for new features or processing activities, including a structured check of mandatory triggers, required DPO consultation, and whether prior ICO consultation (Article 36) may be needed due to residual high risk.

Core Features & Use Cases

  • DPIA needed check (Art.35 + ICO guidance): Verifies whether a DPIA is required using Article 35(3) mandatory triggers and the ICO’s DPIA “always required” list, with citations and currency checks.
  • DPO consultation and Art.36 flagging: Captures whether DPO consultation is required under Article 35(2) and flags an Article 36 prior consultation requirement when residual high risk remains.
  • House-style DPIA output: Produces a DPIA in the team’s house format (sourced from practice-level configuration), including risks that are design-specific, a mitigations table with owners/due dates, and a clear sign-off and conditions section.
  • Change-aware drafting: Looks for prior outputs (triage results, earlier DPIAs, and DPA/vendor review findings) to prevent contradictory conclusions for overlapping processing.

Quick Start

Use the dpia-generation skill to draft a DPIA for the Location sharing feature by running the command: /privacy-legal-uk:dpia-generation "Location sharing feature".

Frequently Asked Questions about dpia-generation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
When do I need a DPIA under UK GDPR Article 35?

A DPIA is required under UK GDPR Article 35 when processing involves mandatory triggers like novel technology, large-scale profiling, or children's data. This Skill validates your scenario against ICO guidance and Article 35(3) criteria to confirm if an assessment is mandatory.

How do I draft a UK GDPR DPIA with Article 36 prior consultation flags?

Generate a UK GDPR DPIA by validating mandatory triggers, assessing residual risk, and applying DPO consultation requirements. This Skill drafts an ICO-structured assessment and automatically flags when Article 36 prior consultation with the ICO is needed due to remaining high risk.

Does a DPIA require DPO consultation under Article 35(2)?

Yes, DPO consultation is required under Article 35(2) for high-risk processing. This Skill captures DPO consultation requirements during the DPIA generation process and includes them in the final ICO-structured house-style output document.

What is the best way to document residual risk in a DPIA?

Document residual risk by evaluating design-specific threats and tracking mitigations in a table with owners and due dates. This Skill produces a house-style DPIA featuring a residual risk assessment and a structured mitigations table to ensure clear sign-off conditions.

Can I use prior triage results to prevent contradictory DPIA conclusions?

Yes, change-aware drafting uses prior triage results, earlier DPIAs, and vendor review findings to prevent contradictory conclusions for overlapping processing activities. This ensures your Article 35 assessment remains consistent with existing privacy evaluations.

Does this DPIA generation process apply to children's data signals?

Yes, this DPIA generation process applies to children's data signals and novel technology use. It evaluates these scenarios against ICO mandatory triggers to determine if a full Article 35 Data Protection Impact Assessment is legally required.