What problem does it solve?
It helps teams produce a structured Privacy Impact Assessment (PIA) for a new feature or processing activity, ensuring the privacy review covers what data is used, why it’s needed, where it flows, what risks exist, and what mitigations and sign-off requirements follow.
Core Features & Use Cases
- PIA readiness and trigger checking: Determines whether a PIA is needed by applying house triggers and researching mandatory-assessment triggers across applicable privacy regimes, with primary-source citations and currency checks.
- Guided product-team intake: Prompts for concrete answers about data categories, purposes, lawful-basis/regime checks, storage/access, retention, third parties, and what could go wrong.
- House-format output with reconciled history: Pulls prior triage/PIAs and any relevant vendor/DPA findings from the configured outputs folder to avoid contradictions, then writes a PIA in the learned in-house structure including policy-consistency review and conditions/owners for handoff.
Quick Start
Run /privacy-legal:pia-generation with a short feature description to generate a house-format PIA draft with risk, mitigations, and sign-off conditions.