pia-generation

Generate a house-format Privacy Impact Assessment with jurisdictional checks and sign-off outputs.

Updated May 15, 2026
One-click install
npx skills add https://github.com/az9713/claude-for-legal-tutorial --skill pia-generation-az9713
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pia-generation
Source: https://github.com/az9713/claude-for-legal-tutorial/tree/main/privacy-legal/skills/pia-generation
Command: npx skills add https://github.com/az9713/claude-for-legal-tutorial --skill pia-generation-az9713

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps teams quickly produce a privacy impact assessment in their house format by structuring the required analysis and documentation around the specific product change and data processing activity.

Core Features & Use Cases

  • PIA readiness check: Determines whether a PIA is needed by combining the plugin’s house trigger with a research-backed review of mandatory assessment triggers across applicable privacy regimes, with citations and currency checks.
  • Structured intake and drafting: Guides product-team questioning (data, purposes, processing, third parties, storage regions, retention) and writes a tailored PIA using the configured house style and seed template.
  • Quality and consistency guardrails: Reconciles with prior triage and prior PIAs for the same activity to avoid contradictions, applies a cross-skill severity floor, and cross-checks privacy policy consistency to flag drift.
  • Actionable outputs: Produces risks and mitigations tied to the actual design, assigns named owners for conditions, and routes for sign-off rather than stopping at generic recommendations.

Quick Start

Generate a privacy impact assessment for a feature called "Location sharing feature" using the privacy-legal house format.

Frequently Asked Questions about pia-generation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
When do I need a privacy impact assessment for a new data processing activity?

A privacy impact assessment is needed when a new data processing activity triggers mandatory assessment requirements under applicable privacy regimes, which this tool validates using source-attributed jurisdictional checks and currency verifications.

How do I draft a privacy impact assessment for a new product feature?

To draft a privacy impact assessment, this tool structures required intake questioning around data, purposes, third parties, and retention, then writes a tailored sign-off-ready PIA using your configured house style and seed template.

How do I check if my privacy policy is consistent with a new data processing activity?

Privacy policy consistency is checked by cross-referencing the new data processing activity against existing policies to flag drift, ensuring the PIA reconciles with prior triage and prior assessments to avoid contradictions.

Can I use this to assess regulatory triggers across multiple privacy regimes?

Yes, this tool performs mandatory-trigger research across multiple applicable privacy regimes, providing citations and currency checks to determine whether a PIA is legally required for your specific processing activity.

What is included in a sign-off-ready privacy impact assessment?

A sign-off-ready privacy impact assessment includes identified risks and mitigations tied to the actual design, assigned named owners for conditions, and a next-steps decision tree routing the document for formal approval.

How does this tool handle cross-skill severity floors in risk assessments?

Cross-skill severity floors are enforced during PIA generation by applying minimum risk severity thresholds, ensuring that the privacy impact assessment reconciles with prior triage and maintains consistent risk grading across assessments.