pia-generation

Generate a privacy impact assessment in the configured in-house format.

Updated May 19, 2026
One-click install
npx skills add https://github.com/jrhueiueng/codex-for-legal --skill pia-generation-jrhueiueng
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pia-generation
Source: https://github.com/jrhueiueng/codex-for-legal/tree/main/plugins/jrhueiueng/codex-for-legal/skills/privacy-legal__pia-generation
Command: npx skills add https://github.com/jrhueiueng/codex-for-legal --skill pia-generation-jrhueiueng

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It turns a new product or processing activity into a structured Privacy Impact Assessment (PIA) that the privacy team and stakeholders can review, reducing uncertainty and speeding sign-off while ensuring the analysis checks whether a PIA is actually needed.

Core Features & Use Cases

  • PIA suitability check across regimes: Verifies whether mandatory or strongly indicated privacy assessment triggers apply, with primary-source citations and currency checks.
  • Guided intake from the product team: Collects the specific feature description, data categories, purposes, data flows, storage regions, access controls, retention, and third-party involvement.
  • House-format PIA output with guardrails: Produces an in-house structured PIA including lawful-basis analysis, privacy policy consistency diffing, quantified risks with mitigations and owners, and a conditions-based routing for sign-off.

Quick Start

Run /privacy-legal:pia-generation and tell it which feature or processing activity you want assessed, such as Location sharing feature.

Frequently Asked Questions about pia-generation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a privacy impact assessment for a new product feature?

A privacy impact assessment is needed when mandatory regulatory triggers apply to your processing activity. The system checks regime-specific triggers with primary-source citations and currency verification to determine if an assessment is required.

Do I need a privacy impact assessment for my data processing activity?

A privacy impact assessment is needed when mandatory regulatory triggers apply to your processing activity. The system checks regime-specific triggers with primary-source citations and currency verification to determine if an assessment is required.

What is included in a lawful basis analysis for a privacy review?

To draft a sign-off ready privacy impact assessment, the system outputs structured conditions-based routing, quantified risks with mitigations, and policy-consistency checks. This structured format enables stakeholders to review and approve the assessment efficiently.

How do I draft a sign-off ready privacy impact assessment with risk mitigations?

To draft a sign-off ready privacy impact assessment, the system outputs structured conditions-based routing, quantified risks with mitigations, and policy-consistency checks. This structured format enables stakeholders to review and approve the assessment efficiently.

Can I use my in-house privacy house style format for a PIA?

The privacy impact assessment requires feature description, data categories, purposes, data flows, storage regions, access controls, retention periods, and third-party involvement details to accurately evaluate regulatory triggers and generate comprehensive risk analysis.

What data mapping details are required for a privacy impact assessment?

The privacy impact assessment requires feature description, data categories, purposes, data flows, storage regions, access controls, retention periods, and third-party involvement details to accurately evaluate regulatory triggers and generate comprehensive risk analysis.