pia-generation

Generate a Privacy Impact Assessment in house format for new features or processing activities.

Updated Jun 17, 2026
One-click install
npx skills add https://github.com/tk1cntt/PhapChe --skill pia-generation-tk1cntt
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pia-generation
Source: https://github.com/tk1cntt/PhapChe/tree/main/docs/claude-for-legal-main/privacy-legal/skills/pia-generation
Command: npx skills add https://github.com/tk1cntt/PhapChe --skill pia-generation-tk1cntt

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Drafting a Privacy Impact Assessment from scratch is slow and inconsistent — teams struggle to know whether a PIA is legally required, what questions to ask the product team, and how to match the organization's established format. This Skill structures the entire PIA workflow so the output looks like the assessments your team already produces. ## Core Features & Use Cases - Trigger Analysis: Determines whether a PIA is actually needed by checking house trigger criteria and researching mandatory-assessment triggers under GDPR, CCPA/CPRA, and other applicable regimes with cited primary sources. - Structured Intake: Guides a conversational intake with the product team covering data categories, lawful bases, access, retention, and risk scenarios. - House-Format Output: Writes the PIA using the structure learned from your seed PIA, including lawful basis tables, data flow, privacy policy consistency checks, risk/mitigation tables, and sign-off routing. - Use Case: A product manager proposes a location-sharing feature. Run the Skill to confirm a DPIA is triggered under GDPR, intake the data flow details, and produce a draft PIA with conditions and named owners ready for attorney sign-off. ## Quick Start Ask the assistant to write a privacy impact assessment for your new feature, for example by saying: write a PIA for the location sharing feature.

Frequently Asked Questions about pia-generation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a privacy impact assessment for a new feature?

Provide the feature name or PRD and the Skill checks whether a PIA is required, runs a structured intake covering data categories, lawful basis, access, and retention, then drafts the PIA in your team's house format with risks, mitigations, and sign-off routing.

When is a DPIA required under GDPR or CCPA?

The Skill researches the currently operative mandatory-assessment triggers for each applicable regime, citing controlling statutes and regulator guidance. It also flags strong indicators like children's data, novel technology, or unexpected processing even when not strictly mandatory.

Does the PIA check consistency with our privacy policy?

Yes. Every PIA cross-checks the processing against the privacy policy commitments stored in the plugin configuration and flags mismatches, such as new data categories, ad-partner sharing that may constitute a sale, or retention beyond stated limits.

Can this skill submit a DPIA to a regulator?

No. It produces the internal assessment only. Submitting to a supervisory authority is gated behind an explicit attorney-review confirmation, and non-lawyer users receive a briefing summary to bring to counsel before any filing.

What are the limitations of an automated PIA draft?

The Skill does not approve processing, design mitigations, or produce the formal DPIA a supervisory authority requires. A human signs the PIA, engineering designs the fixes, and citations tagged for verification must be checked against primary sources.