dpia-sentinel-oliver-schmidt-prietz

Assess GDPR Article 35 DPIA requirements using EDPB criteria and Art. 35(3) triggers.

630|79|Updated Dec 18, 2025
One-click install
npx skills add https://github.com/lawve-ai/awesome-legal-skills --skill dpia-sentinel-oliver-schmidt-prietz
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpia-sentinel-oliver-schmidt-prietz
Source: https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/dpia-sentinel-oliver-schmidt-prietz
Command: npx skills add https://github.com/lawve-ai/awesome-legal-skills --skill dpia-sentinel-oliver-schmidt-prietz

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill provides a structured DPIA framework and repository guidance to help privacy teams assess high-risk data processing under GDPR Article 35, including multi-jurisdictional blacklist analysis, EDPB criteria, and AI-specific risk considerations.

Core Features & Use Cases

  • Threshold analysis using the EDPB nine criteria and Article 35 triggers
  • Multi-jurisdictional blacklist/whitelist checks with consolidated DPIA scope
  • Risk scoring (5x5) with heat maps and templates for DPIA deliverables
  • AI-specific dual-phase DPIA alignment per EDPB Opinion 28/2024
  • Documentation templates for Full DPIA, Threshold Justification Memo, Executive Summary, and Art. 36 package
  • Supports Art. 36 prior consultation and cross-jurisdiction reporting

Quick Start

Load the DPIA framework for a cross-border processing activity and generate threshold findings, risk register, and mitigation plan.

Frequently Asked Questions about dpia-sentinel-oliver-schmidt-prietz

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
When is a GDPR DPIA required for a data processing activity?

A GDPR DPIA is required when processing meets the EDPB nine criteria or triggers under Article 35(3), such as large-scale profiling or systematic monitoring of publicly accessible areas.

How do I assess DPIA requirements across multiple EU jurisdictions?

You assess multi-jurisdictional DPIA requirements by checking local blacklist and whitelist rules against the EDPB criteria, then consolidating the findings into a unified DPIA scope with per-jurisdiction conclusions.

How do I generate a DPIA risk register and residual risk heat map?

Generate a DPIA risk register and residual risk heat map by applying 5x5 risk scoring to identified threats, mapping mitigations, and producing visual heat maps for executive review.

Does this DPIA framework support AI-specific risk assessments?

Yes, the DPIA framework supports AI-specific risk assessments by aligning with the dual-phase approach outlined in the EDPB Opinion 28/2024 for high-risk AI processing activities.

What templates are needed for an Article 36 prior consultation package?

An Article 36 prior consultation package requires a threshold justification memo, executive summary, full DPIA document, and a residual risk report to submit to the supervisory authority.

Can I use this for cross-border processing activities without a full DPIA?

Yes, you can use the threshold analysis to document why a full DPIA is not required for cross-border processing, generating a threshold justification memo instead of a full DPIA report.