eipd

Generate a GDPR Article 35 DPIA document using the AEPD methodology.

35|19|Updated May 15, 2026
One-click install
npx skills add https://github.com/betobetico/claude-para-abogados --skill eipd
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: eipd
Source: https://github.com/betobetico/claude-para-abogados/tree/main/proteccion-datos/skills/eipd
Command: npx skills add https://github.com/betobetico/claude-para-abogados --skill eipd

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Helps you create a complete Evaluación de Impacto en la Protección de Datos (EIPD/DPIA) that assesses whether a data processing operation is likely to create high risk to individuals’ rights and freedoms under GDPR.

Core Features & Use Cases

  • DPIA aligned to GDPR art. 35 and AEPD methodology: structures the assessment into description, necessity/proportionality, risk evaluation, and mitigation measures.
  • Risk identification with probability-impact matrix: produces a risk register and quantifies risk levels to support decision-making.
  • Mitigation plan with residual risk: proposes measures for each medium-or-higher risk and supports the decision whether to proceed or consult (art. 36) when residual risk remains high.
  • Use case: when you are planning a new processing activity (e.g., large-scale monitoring, sensitive data, profiling with significant effects, or innovative/invasive technologies), use this to document compliance before starting the treatment.

Quick Start

Use the eipd skill to generate an EIPD for the data processing described as: [descripción del tratamiento a evaluar].

Frequently Asked Questions about eipd

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
When do I need a DPIA under GDPR for a new data processing activity?

A DPIA is required for planned high-risk processing under GDPR Article 35, such as large-scale monitoring, profiling with significant effects, systematic monitoring, or processing special categories of data. The AEPD list also identifies specific treatments likely to require this evaluation.

How do I generate an AEPD-style data protection impact assessment?

To generate an AEPD-style DPIA, you describe the planned processing activity and the tool structures the assessment into treatment description, necessity and proportionality, risk evaluation with a probability-impact matrix, and mitigation measures to determine residual risk.

What does a GDPR risk assessment matrix include for privacy compliance?

A GDPR risk assessment matrix includes a risk register that identifies threats to individuals' rights and freedoms, quantifies risk levels using probability and impact, and proposes mitigation plans for each medium-or-higher risk to calculate residual risk.

What happens if residual risk remains high after DPIA mitigation measures?

If residual risk remains high after applying mitigation measures in the DPIA, the final compliance decision must determine whether to proceed or consult the supervisory authority under GDPR Article 36 before starting the data processing treatment.

Can I use this DPIA methodology for large-scale processing of sensitive data?

Yes, the DPIA methodology applies to large-scale processing of special categories of sensitive data and innovative technologies. It documents privacy compliance by evaluating necessity, proportionality, and risk before the treatment begins.