pia-generation

Creates structured PRD-based PIAs with risk, mitigation, and sign-off workflows.

109|20|Updated Mar 7, 2025
One-click install
npx skills add https://github.com/stakwork/stakgraph --skill pia-generation-stakwork
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pia-generation
Source: https://github.com/stakwork/stakgraph/tree/main/mcp/skills/privacy-legal/pia-generation
Command: npx skills add https://github.com/stakwork/stakgraph --skill pia-generation-stakwork

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps product and legal teams determine whether a Privacy Impact Assessment is needed and produce a consistent, well-supported assessment for new features, products, and processing activities.

Core Features & Use Cases

  • PIA Generation: Create assessments using the configured house style, seed PIA structure, and required sign-off process.
  • Privacy Risk Analysis: Evaluate data flows, lawful bases, retention, access, sharing, data subject rights, and specific privacy risks.
  • Regulatory Research Coordination: Identify mandatory assessment triggers and require current, attributed sources for applicable privacy regimes.
  • Workflow Safeguards: Reconcile prior triage and PIA outputs, check privacy policy consistency, assign mitigation owners, and route consequential regulatory submissions for attorney review.
  • Use Case: A product team can provide a feature description or PRD and receive a draft PIA with risks, mitigations, conditions, owners, and a sign-off decision tree.

Quick Start

Use the pia-generation skill to assess the privacy impact of the proposed location sharing feature and draft the required internal PIA.

Frequently Asked Questions about pia-generation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a privacy impact assessment for a new product feature?

Generate a privacy impact assessment by providing a feature description or PRD to receive a structured draft covering lawful bases, data flows, retention, risks, mitigations, and a sign-off decision tree. The output applies configured house style and regulatory triggers.

When do I need a privacy review for personal data processing activities?

A privacy review is needed when introducing new features or processing activities that require evaluating regulatory assessment triggers, data subject rights, and policy consistency. The assessment determines if mandatory regulatory submissions or attorney review are required.

How do I conduct regulatory compliance research for a PIA?

Conduct regulatory compliance research by identifying mandatory assessment triggers and requiring current, source-attributed legal research for applicable privacy regimes. The assessment reconciles prior triage outputs and routes consequential regulatory submissions for attorney review.

What is the best way to document data flows and lawful bases in a privacy assessment?

Document data flows and lawful bases by applying the PIA workflow to evaluate access, sharing, retention, and data subject rights. The structured output assigns named mitigation owners and checks privacy policy consistency before sign-off.

Can I use a PRD to draft a privacy risk analysis with mitigation owners?

Yes, use a PRD to draft a privacy risk analysis that evaluates specific privacy risks, assigns mitigation owners, and establishes a sign-off decision tree. The output reconciles prior triage and ensures policy consistency.

Does a privacy impact assessment require attorney review before submitting to a regulator?

Attorney review is required for consequential regulatory submissions before submitting an assessment to a regulator. The workflow routes these submissions for attorney sign-off and ensures current, source-attributed legal research supports applicable privacy regimes.