pia-generation

Generate privacy impact assessments in the organization's in-house format.

9.1k|1.8k|Updated Apr 21, 2026
One-click install
npx skills add https://github.com/anthropics/claude-for-legal --skill pia-generation-anthropics
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pia-generation
Source: https://github.com/anthropics/claude-for-legal/tree/main/privacy-legal/skills/pia-generation
Command: npx skills add https://github.com/anthropics/claude-for-legal --skill pia-generation-anthropics

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps teams document and assess privacy risk when launching a new feature or processing activity, ensuring the output matches the organization’s in-house PIA format and decision needs attorney review.

Core Features & Use Cases

  • PIA house-structure generation: Produces a privacy impact assessment in the organization’s learned template for product/processing activities.
  • Mandatory assessment gatekeeping: Checks whether a PIA is actually needed by comparing internal triggers with regime-specific mandatory assessment triggers, citing primary sources and surfacing uncertainty.
  • Cross-checks and traceability: Reconciles with prior triage and prior PIA outputs for the same/overlapping activity, and flags privacy policy consistency issues and mismatches before launch.
  • Actionable risk outputs: Captures specific, design-linked risks with likelihood/impact and mitigation owners, then closes with conditions and sign-off routing.

Quick Start

Run /privacy-legal:pia-generation with a short description of the new feature or processing activity, such as "Location sharing feature", to generate a draft PIA ready for attorney review.

Frequently Asked Questions about pia-generation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
When do I need a privacy impact assessment for a new feature?

A privacy impact assessment is needed when a new feature or processing activity triggers internal or jurisdiction-specific mandatory assessment requirements, which this Skill evaluates by comparing your activity against regime-specific triggers with cited primary sources.

How do I generate a privacy impact assessment in my company's format?

You generate a privacy impact assessment in your company's format by loading your internal PIA structure and shared guardrails, then the Skill produces a structured assessment including data flow, lawful basis checks, and risks with mitigations.

What is included in a structured privacy impact assessment output?

A structured privacy impact assessment output includes data flow mapping, lawful basis and regime checks, privacy policy consistency analysis, specific risks with likelihood and impact, mitigation owners, and a next-steps recommendation for sign-off routing.

Can I reconcile a new privacy impact assessment with prior triage outputs?

Yes, you can reconcile a new privacy impact assessment with prior triage and prior PIA outputs for the same or overlapping activity, allowing the Skill to flag privacy policy consistency issues and mismatches before launch.

How does jurisdiction analysis work for privacy impact assessments?

Jurisdiction analysis for privacy impact assessments works by performing a jurisdiction-aware determination of whether a PIA is needed, citing primary sources and surfacing uncertainty when internal triggers intersect with regime-specific mandatory assessment triggers.

What are the limitations of automated privacy risk assessment generation?

Automated privacy risk assessment generation produces a draft structured assessment ready for attorney review, but it does not replace legal decision-making, as the output explicitly requires attorney sign-off routing for final conditions and launch approval.