privacy

Identify privacy risks and generate DPIA documents for personal data projects.

Updated Apr 21, 2026
One-click install
npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill privacy-brucebanner010198-commits
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: privacy
Source: https://github.com/brucebanner010198-commits/DevSecOps-Agency/tree/main/skills/privacy
Command: npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill privacy-brucebanner010198-commits

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Helps teams implement privacy-by-design for projects that handle personal data by guiding DPIAs, classifying data against GDPR, CCPA, and DPDP categories, and producing data-flow diagrams, retention policies, and privacy appendices for ADRs.

Core Features & Use Cases

  • DPIA screening and risk assessment for new data-processing initiatives.
  • Data classification against GDPR/CCPA/DPDP categories to determine safeguards.
  • Data-flow diagram and retention policy generation to document data lifecycle.
  • Privacy appendix generation for ADRs to preserve decision logs and controls.
  • Triggered automatically by project-start checks when personal data is detected.

Quick Start

Run a privacy review at project start to generate a DPIA, data-flow diagram, retention policy, and privacy appendix.

Frequently Asked Questions about privacy

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a DPIA for projects handling personal data?

A privacy-by-design review identifies privacy risks by conducting a DPIA for projects handling personal data. It screens new data-processing initiatives, classifies data against GDPR, CCPA, and DPDP categories, and generates a data-flow diagram, retention policy, and privacy appendix for ADR integration.

When do I need a data-flow diagram and retention policy for GDPR compliance?

You need a data-flow diagram and retention policy for GDPR compliance when initiating new data-processing initiatives. Generating these documents at project start records the personal data lifecycle and ensures privacy-by-design safeguards across data storage and cross-border sharing.

Can I classify data against GDPR, CCPA, and DPDP categories automatically?

Data classification maps personal data types to regulatory requirements by evaluating data against GDPR, CCPA, and DPDP categories. This determines necessary safeguards, enabling privacy-by-design reviews to identify risks and produce compliant retention policies for architecture decision records.

What is the best way to integrate privacy appendices into ADRs?

The best way to integrate privacy appendices into ADRs is to generate them during a privacy-by-design review at project start. This preserves decision logs and documents the specific controls, data-flow diagrams, and retention policies applied to personal data processing initiatives.

Does a privacy-by-design review work for cross-border data sharing?

A privacy-by-design review works for cross-border data sharing by ensuring GDPR, CCPA, and DPDP compliance during DPIA risk assessments. It generates data-flow diagrams that document the lifecycle of personal data across international boundaries and produces retention policies.

Why does my project need a DPIA screening when personal data is detected?

Your project needs a DPIA screening when personal data is detected to identify privacy risks early. Triggered automatically by project-start checks, this screening classifies data against GDPR, CCPA, and DPDP categories to ensure privacy-by-design compliance before data processing begins.