What problem does it solve?
It helps you quickly determine whether a new or changed data processing activity needs a PIA, a mandatory GDPR DPIA, or can proceed safely—while surfacing privacy policy conflicts that could block launch.
Core Features & Use Cases
- Classifies privacy impact requirements: Returns PROCEED / PIA REQUIRED / DPIA MANDATORY / STOP based on house triggers, activity-based mandatory assessment triggers, and policy commitments.
- Detects policy conflicts early: Flags purpose limitation, retention, selling/sharing, new data categories, consent/rights coverage gaps, and other contradictions before you generate a full assessment.
- Routes to the next step: Provides conditions (when applicable) and offers a handoff to PIA generation only when an assessment is needed.
Use case example: You describe a product feature that uses behavioral data to personalize content; the skill determines the assessment type required (if any) and checks it against your configured privacy commitments.
Quick Start
Use this instruction to triage a proposed processing activity: run /privacy-legal:use-case-triage with a clear description of the new feature, data types, purposes, data subjects, and any vendor involvement.