Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices, GDPR Article 35 DPIA and CCPA/CPRA alignment checks, data inventory cataloging, and remediation tracking. Implements the NIST Privacy Framework PRAM methodology and ICO DPIA guidance for systematic identification and mitigation of privacy risks across processing activities. Use when conducting privacy assessments for new systems, evaluating regulatory compliance posture, or building automated privacy governance programs.
.claude/skills/performing-privacy-impact-assessment/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-16 | ✗→✓ | ▲ Improved | — | — |
| case-08 | ✗→✓ | ▲ Improved | — | — |
| case-15 | ✗→✓ | ▲ Improved | — | — |
| case-03 | ✗→✓ | ▲ Improved | — | — |
| case-20 | ✗→✓ | ▲ Improved | — | — |
Build a complete inventory of personal data processing activities. Each record of processing activity (ROPA) entry must capture the data categories, legal basis, retention periods, and data subjects involved.
pythonfrom agent import PrivacyImpactAssessmentEngine engine = PrivacyImpactAssessmentEngine() # Register a processing activity for assessment activity = engine.register_processing_activity( name="Customer Analytics Platform", description="Collects browsing behavior and purchase history for personalization", data_controller="Acme Corp", data_processor="CloudAnalytics Inc", data_categories=["browsing_history", "purchase_records", "ip_address", "device_id"], data_subjects=["customers", "website_visitors"], legal_basis="consent", retention_period_days=730, cross_border_transfer=True, transfer_destinations=["US", "IN"], automated_decision_making=True, ) print(f"Registered activity: {activity['activity_id']}")
Map all data flows from collection to deletion, identifying every touchpoint, transformation, and storage location. This reveals hidden privacy risks in data movement across systems.
python# Build the data flow map flow_map = engine.map_data_flows( activity_id=activity["activity_id"], flows=[ { "stage": "collection", "source": "Web browser cookie + form submission", "destination": "CDN edge server", "data_elements": ["ip_address", "device_id", "browsing_history"], "encryption_in_transit": True, "protocol": "TLS 1.3", }, { "stage": "processing", "source": "CDN edge server", "destination": "Analytics data warehouse (US-East)", "data_elements": ["browsing_history", "purchase_records", "device_id"], "encryption_in_transit": True, "encryption_at_rest": True, "protocol": "mTLS", }, { "stage": "storage", "source": "Analytics data warehouse", "destination": "S3 encrypted bucket", "data_elements": ["browsing_history", "purchase_records"], "encryption_at_rest": True, "retention_days": 730, "access_controls": "IAM role-based, MFA required", }, { "stage": "sharing", "source": "Analytics data warehouse", "destination": "Third-party ML provider (IN)", "data_elements": ["browsing_history", "purchase_records"], "encryption_in_transit": True, "data_processing_agreement": True, "cross_border": True, }, { "stage": "deletion", "source": "S3 bucket + data warehouse", "destination": "Secure erasure", "method": "Cryptographic erasure + lifecycle policy", "verification": "Automated deletion audit log", }, ], ) engine.render_data_flow_diagram(flow_map)
Apply a structured risk scoring methodology evaluating likelihood and impact across multiple privacy risk dimensions. The matrix aligns with both the NIST PRAM and ICO DPIA risk assessment approaches.
python# Run the risk assessment risk_report = engine.assess_privacy_risks( activity_id=activity["activity_id"], assessment_type="full_dpia", ) # Display risk matrix results for risk in risk_report["risks"]: print(f"[{risk['severity']}] {risk['category']}: {risk['description']}") print(f" Likelihood: {risk['likelihood']}/5 | Impact: {risk['impact']}/5 | Score: {risk['risk_score']}/25") print(f" Mitigation: {risk['recommended_mitigation']}")
Risk categories evaluated include:
Run automated compliance checks against specific regulatory requirements. The engine maps each processing activity against article-level GDPR obligations and CCPA/CPRA consumer rights requirements.
python# GDPR compliance check gdpr_report = engine.check_gdpr_compliance(activity_id=activity["activity_id"]) print(f"GDPR Score: {gdpr_report['compliance_score']}/100") for finding in gdpr_report["findings"]: print(f" [{finding['status']}] Art.{finding['article']}: {finding['description']}") # CCPA/CPRA compliance check ccpa_report = engine.check_ccpa_compliance(activity_id=activity["activity_id"]) print(f"CCPA Score: {ccpa_report['compliance_score']}/100") for finding in ccpa_report["findings"]: print(f" [{finding['status']}] Sec.{finding['section']}: {finding['description']}")
Generate a prioritized remediation plan with specific action items, responsible parties, deadlines, and generate the formal PIA/DPIA report document.
python# Generate remediation plan remediation = engine.generate_remediation_plan( activity_id=activity["activity_id"], risk_report=risk_report, gdpr_report=gdpr_report, ccpa_report=ccpa_report, ) for item in remediation["action_items"]: print(f"[{item['priority']}] {item['action']}") print(f" Owner: {item['owner']} | Deadline: {item['deadline']}") print(f" Addresses: {', '.join(item['addresses_risks'])}") # Generate formal DPIA report engine.generate_dpia_report( activity_id=activity["activity_id"], output_path="dpia_report_customer_analytics.json", format="json", ) print("[+] DPIA report generated")
Determine whether a full DPIA is required using the ICO screening checklist:
pythonengine = PrivacyImpactAssessmentEngine() screening = engine.run_screening_checklist( uses_special_category_data=False, large_scale_processing=True, systematic_monitoring=True, automated_decision_making=True, cross_border_transfer=True, vulnerable_data_subjects=False, innovative_technology=True, denial_of_service_or_rights=False, ) print(f"DPIA Required: {screening['dpia_required']}") print(f"Triggers: {screening['triggers']}") # Output: DPIA Required: True # Triggers: ['large_scale_processing', 'systematic_monitoring', # 'automated_decision_making', 'cross_border_transfer', # 'innovative_technology']
pythonengine = PrivacyImpactAssessmentEngine() activities = [ {"name": "Email Marketing", "data_categories": ["email", "name"], "legal_basis": "consent", "cross_border_transfer": False}, {"name": "HR Analytics", "data_categories": ["employee_id", "performance_scores", "health_data"], "legal_basis": "legitimate_interest", "cross_border_transfer": True}, {"name": "Fraud Detection", "data_categories": ["transaction_data", "ip_address", "device_fingerprint"], "legal_basis": "legitimate_interest", "automated_decision_making": True, "cross_border_transfer": False}, ] for act_def in activities: activity = engine.register_processing_activity(**act_def) risk = engine.assess_privacy_risks(activity_id=activity["activity_id"]) print(f"{act_def['name']}: Overall Risk={risk['overall_risk_level']} " f"({risk['risk_count_by_severity']})")
pythonengine = PrivacyImpactAssessmentEngine() profile = engine.generate_nist_privacy_profile( activity_id=activity["activity_id"], target_tier="tier_3", # Repeatable ) for function_id, outcomes in profile["functions"].items(): print(f"\n{function_id}:") for outcome in outcomes: status = "PASS" if outcome["implemented"] else "GAP" print(f" [{status}] {outcome['subcategory']}: {outcome['description']}")
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-16 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-06 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-22 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-08 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-15 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-03 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-20 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-14 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-10 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-11 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-09 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-13 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-05 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-17 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-07 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-19 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-01 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-02 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-04 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-12 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-18 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-21 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +73 percentage points is the difference between those two pass rates over the 22 comparable cases.
The per-case answers from this run were removed by the retention sweep, so the case table below shows the verdicts without the text either arm produced. The counts above were recorded at the time and are unaffected. Answers are now kept for 180 days.
Other measured skills in the registry, with their headline benchmark lift.