privacy-impact-assessment

Evaluate proposed data processing for necessity, proportionality, rights, retention, and jurisdictional obligations.

Updated Aug 22, 2026
One-click install
npx skills add https://github.com/fritzgeraldz/Vibe-Managing --skill privacy-impact-assessment-fritzgeraldz
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: privacy-impact-assessment
Source: https://github.com/fritzgeraldz/Vibe-Managing/tree/main/skills/security-privacy/privacy-impact-assessment
Command: npx skills add https://github.com/fritzgeraldz/Vibe-Managing --skill privacy-impact-assessment-fritzgeraldz

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Founders and operators often launch data processing activities without a structured review of privacy risk, lawful basis, retention, and jurisdictional obligations, creating regulatory exposure and eroding customer trust. This Skill produces an evidence-backed privacy impact assessment with a clear decision, plan, and monitoring record. ## Core Features & Use Cases - Structured PIA Framework: Walks through purpose and data flow description, data minimization, rights identification, lawful basis review with counsel, risk evaluation, control design, and approve-or-stop gating. - Risk-Adjusted Decisioning: Ranks options using risk-adjusted value, confidence weighting, and hard-constraint checks, with explicit escalation rules for regulated judgments. - Governance Integration: Reads and writes business memory (company, goals, strategy, metrics, decisions, security_privacy) and simulates scenarios in the Business Digital Twin. - Use Case: Before launching a new customer analytics pipeline, run this Skill to assess whether the data collected is necessary and proportional, identify affected data subject rights, design controls, and produce an approval-ready plan with KPIs like high-risk processing coverage and unresolved privacy risk. ## Quick Start Run a privacy impact assessment on our proposed customer data processing activity and recommend controls, approvals, and monitoring before we commit resources.

Frequently Asked Questions about privacy-impact-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a privacy impact assessment for a new data processing activity?▼

Describe the purpose and data flow, minimize collected data, identify affected people and their rights, assess lawful basis with counsel, evaluate risk, design controls, then approve or stop. This Skill walks each step with evidence, confidence, and decision implications.

When should a privacy impact assessment be performed?▼

Run one when a founder requests a privacy diagnosis, decision, plan, or review, when a KPI or event signals privacy may constrain an objective, or before committing resources to a material data processing decision.

Can this Skill make legal determinations about GDPR or other privacy laws?▼

No. It does not make legal or regulated determinations that require a licensed specialist. Regulated interpretations are escalated to qualified legal and compliance professionals, and lawful basis is assessed with counsel.

What inputs are needed to run a privacy impact assessment?▼

It needs the intent, decision horizon, objective with baseline and target, constraints, current state, options, evidence with confidence, industry and business model profiles, stage, maturity, jurisdictions, risk tolerance, and authority levels.

What happens if required information is missing during the assessment?▼

The Skill retrieves permitted facts from memory, derives only formula-backed values, asks one concise batch for material facts, and continues with labeled scenarios. It stops if a missing fact could reverse the decision or change an approval boundary.

Which actions require human approval in a privacy impact assessment?▼

Approval is required for personal-data use, external communication, binding commitments, money movement, policy exceptions, access changes, and any action above budget or risk limits. The Skill only executes authorized low-risk reversible internal actions.