pia-generation

Generate a structured Privacy Impact Assessment draft with risk and sign-off conditions.

Updated Dec 4, 2025
One-click install
npx skills add https://github.com/PolliticalSolutions/political-portal --skill pia-generation-polliticalsolutions
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pia-generation
Source: https://github.com/PolliticalSolutions/political-portal/tree/main/.claude/skills/privacy-legal/pia-generation
Command: npx skills add https://github.com/PolliticalSolutions/political-portal --skill pia-generation-polliticalsolutions

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps teams produce a structured Privacy Impact Assessment (PIA) for a new feature or processing activity, ensuring the privacy review covers what data is used, why it’s needed, where it flows, what risks exist, and what mitigations and sign-off requirements follow.

Core Features & Use Cases

  • PIA readiness and trigger checking: Determines whether a PIA is needed by applying house triggers and researching mandatory-assessment triggers across applicable privacy regimes, with primary-source citations and currency checks.
  • Guided product-team intake: Prompts for concrete answers about data categories, purposes, lawful-basis/regime checks, storage/access, retention, third parties, and what could go wrong.
  • House-format output with reconciled history: Pulls prior triage/PIAs and any relevant vendor/DPA findings from the configured outputs folder to avoid contradictions, then writes a PIA in the learned in-house structure including policy-consistency review and conditions/owners for handoff.

Quick Start

Run /privacy-legal:pia-generation with a short feature description to generate a house-format PIA draft with risk, mitigations, and sign-off conditions.

Frequently Asked Questions about pia-generation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
When do I need a privacy impact assessment for a new feature?

A privacy impact assessment is required when personal data is newly collected or processed, data flows to third parties, retention or access changes occur, or lawful-basis and regulatory triggers must be documented.

How do I generate a PIA draft for a processing activity?

Generate a PIA draft by submitting a short feature description; the tool runs trigger checks, prompts for intake details on data categories and purposes, and outputs a structured assessment with risk mitigations.

What should be included in a privacy risk review intake?

A privacy risk review intake captures data categories, purposes, lawful-basis checks, storage access, retention schedules, third parties, and potential failure scenarios to document policy consistency.

Does this PIA tool check regulatory triggers across different privacy regimes?

Yes, the PIA tool checks regulatory triggers by researching mandatory-assessment requirements across applicable privacy regimes, providing primary-source citations and currency checks for compliance validation.

Can I reconcile a new PIA with prior triage and vendor findings?

Yes, the tool pulls prior triage records, existing PIAs, and vendor DPA findings from configured outputs to avoid contradictions and produce a reconciled house-format draft.

How are legal sign-off conditions handled in a privacy impact assessment?

Legal sign-off conditions are handled by appending a conditions and ownership handoff section to the PIA draft, specifying required approvals and responsible parties for regulatory compliance.