write-dpia

Document GDPR Article 35 DPIAs for high-risk personal data processing.

Updated Apr 1, 2026
One-click install
npx skills add https://github.com/hpsgd/turtlestack --skill write-dpia
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: write-dpia
Source: https://github.com/hpsgd/turtlestack/tree/main/plugins/leadership/grc-lead/skills/write-dpia
Command: npx skills add https://github.com/hpsgd/turtlestack --skill write-dpia

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

DPIA is required for high-risk personal data processing under GDPR Article 35; this Skill provides a structured, repeatable template to document processing, assess risks, and ensure DPO review.

Core Features & Use Cases

  • Structured Step-by-Step DPIA framework covering data description, necessity and proportionality, risk assessment, mitigations, DPO review, and potential supervisory consultation.
  • Generates outputs for each step, including data flows, risk scoring, and compliance evidence suitable for audit and regulator inquiries.
  • Use Case: When a new data processing activity involves high-risk personal data (e.g., large-scale health or financial data processing), run this DPIA to document lawful basis, data minimisation, retention, and risk mitigations, and obtain DPO sign-off.

Quick Start

Describe your processing in Step 1 and follow the DPIA flow to complete the assessment for your high-risk data processing.

Frequently Asked Questions about write-dpia

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
When do I need to perform a DPIA for GDPR compliance?

A DPIA is required for high-risk personal data processing under GDPR Article 35, specifically when dealing with sensitive data, large-scale monitoring, or profiling that necessitates DPO involvement.

How do I conduct a Data Protection Impact Assessment for high-risk processing?

Document your processing description, assess necessity and proportionality, evaluate risks, define mitigations, and complete DPO review using a structured framework to generate audit-ready compliance evidence.

What should be included in a GDPR Article 35 risk assessment document?

A GDPR Article 35 risk assessment document must include data flow descriptions, necessity and proportionality evaluations, risk scoring, defined mitigations, DPO review records, and potential supervisory consultation details.

Can I use a structured DPIA template for large-scale sensitive data processing?

Yes, a structured DPIA template guides you through documenting lawful basis, data minimisation, retention policies, and risk mitigations specifically for large-scale health or financial data processing scenarios.

Does a DPIA require DPO sign-off and supervisory consultation?

A DPIA requires DPO review and sign-off to validate the assessment, and necessitates potential supervisory authority consultation if high residual risks to personal data privacy cannot be fully mitigated.