pia-generation

Generate structured PIA documents with risk, legal basis, and routing decisions.

183|37|Updated May 15, 2026
One-click install
npx skills add https://github.com/zhou210712/claude-for-legal-ZH --skill pia-generation-zhou210712
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pia-generation
Source: https://github.com/zhou210712/claude-for-legal-ZH/tree/main/privacy-legal/skills/pia-generation
Command: npx skills add https://github.com/zhou210712/claude-for-legal-ZH --skill pia-generation-zhou210712

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you produce a structured Personal Information Impact Assessment (PIA) for a new feature or processing activity, so privacy review becomes a repeatable, auditable workflow rather than ad-hoc writing.

Core Features & Use Cases

  • PIA requirement check: Evaluates whether a PIA is internally triggered and cross-checks statutory assessment triggers for applicable privacy regimes, with source traceability and timeliness handling.
  • Product onboarding intake: Extracts required facts by asking the product team what the feature does, what data it touches, why it processes it, and which third parties and storage/retention arrangements apply.
  • PIA drafting in internal format: Writes a PIA using the team’s seed template/structure, including legal framework alignment, data flow, rights handling, risk/mitigation detail, and routing to approvals.
  • Continuity and conflict prevention: Reuses and references prior outputs (triage results, prior PIA drafts, DPA review findings) to avoid silent contradictions across runs.

Quick Start

Run /privacy-legal:pia-generation "位置共享功能" to generate a PIA draft in the plugin’s internal format for the described new processing activity.

Frequently Asked Questions about pia-generation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a privacy impact assessment for a new product feature?

A privacy impact assessment (PIA) is needed when a new product feature or processing activity triggers internal privacy review or statutory assessment requirements. The system verifies these statutory triggers with source traceability and timeliness handling to determine if a full PIA is required for compliant product onboarding.

What information do I need to provide for a personal information protection assessment?

A privacy impact assessment (PIA) is needed when a new product feature or processing activity triggers internal privacy review or statutory assessment requirements. The system verifies these statutory triggers with source traceability and timeliness handling to determine if a full PIA is required for compliant product onboarding.

Can I reuse prior privacy triage results and DPA review findings in a new PIA draft?

Yes, you can reuse prior privacy triage results, prior PIA drafts, and DPA review findings in a new PIA draft. The system references these prior outputs to enforce consistency checks, prevent silent contradictions across runs, and maintain continuity throughout the privacy review process.

Does the PIA generation process check for statutory assessment triggers?

Yes, the PIA generation process enforces statutory assessment trigger verification by cross-checking applicable privacy regimes. It applies internal trigger checks with source tagging and timeliness handling to ensure the privacy impact assessment meets statutory thresholds before producing destination-ready outputs for approvals.

What limitations exist when drafting a PIA using automated templates?

When drafting a PIA using automated templates, the output depends entirely on the accuracy of the product team's intake data regarding data flows and retention. The system cannot invent legal basis or risk mitigation strategies beyond the provided seed template structure and internal review artifacts.