What problem does it solve? Founders and operators often launch data processing activities without a structured review of privacy risk, lawful basis, retention, and jurisdictional obligations, creating regulatory exposure and eroding customer trust. This Skill produces an evidence-backed privacy impact assessment with a clear decision, plan, and monitoring record. ## Core Features & Use Cases - Structured PIA Framework: Walks through purpose and data flow description, data minimization, rights identification, lawful basis review with counsel, risk evaluation, control design, and approve-or-stop gating. - Risk-Adjusted Decisioning: Ranks options using risk-adjusted value, confidence weighting, and hard-constraint checks, with explicit escalation rules for regulated judgments. - Governance Integration: Reads and writes business memory (company, goals, strategy, metrics, decisions, security_privacy) and simulates scenarios in the Business Digital Twin. - Use Case: Before launching a new customer analytics pipeline, run this Skill to assess whether the data collected is necessary and proportional, identify affected data subject rights, design controls, and produce an approval-ready plan with KPIs like high-risk processing coverage and unresolved privacy risk. ## Quick Start Run a privacy impact assessment on our proposed customer data processing activity and recommend controls, approvals, and monitoring before we commit resources.