Install any skill in seconds. Free to start, no credit card required.
Get Started Free →[COMMUNITY] Assess Austrian DSG / DSGVO obligations — Datenschutzbehörde patterns, §§12–13 DSG special provisions, image processing (§12 DSG), and Austrian enforcement practice
.claude/skills/thomasmoreai-arckit-at-dsgvo/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-19 | ✗→✓ | ▲ Improved | 190% | 0% |
| case-04 | ✓→✗ | ▼ Worse | 4% | 0% |
| case-05 | ✓→✗ | ▼ Worse | 27% | 0% |
| case-06 | ✓→✗ | ▼ Worse | -7% | 0% |
| case-07 | ✓→✗ | ▼ Worse | 24% | 0% |
> ⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified DSB-Beauftragter / DPO / Rechtsabteilung before reliance. Citations to Datenschutzbehörde (DSB) / EU regulations may lag the current text — verify against the source. Some citations are marked [NEEDS VERIFICATION] and should be confirmed by an Austrian data protection practitioner before external use.
You are helping an enterprise architect generate an Austrian Data Protection Assessment — the Austrian-specific GDPR layer applied by the Datenschutzbehörde (DSB) under the Datenschutzgesetz (DSG 2018, BGBl. I Nr. 165/1999 as amended). Run this after $arckit-eu-rgpd to add Austrian obligations that go beyond the EU GDPR baseline.
text$ARGUMENTS
> Note: Before generating, scan projects/ for existing project directories. For each project, list all ARC-*.md artifacts, check external/ for reference documents, and check 000-global/ for cross-project policies. If no external docs exist but they would improve output, ask the user.
MANDATORY (warn if missing):
$arckit-at-dsgvo should be run after $arckit-eu-rgpd for best results. Proceed with available data.RECOMMENDED (read if available, note if missing):
OPTIONAL (read if available, skip silently):
external/ — extract previous DSB correspondence, Verarbeitungsverzeichnis (Art. 30 ROPA), existing Auftragsverarbeitungsverträge (DPAs), Betriebsvereinbarungen for employee data000-global/policies/ — extract Datenschutzerklärung, data retention schedule, DSB-Meldungen policyIdentify the target project from the hook context. If the project doesn't exist:
projects/*/ directories and find the highest NNN-* numberprojects/{NNN}-{slug}/README.mdPROJECT_ID and PROJECT_PATHRead all documents from Step 0. Identify:
Read the template (with user override support):
.arckit/templates-custom/at-dsgvo-template.md exists in the project root.arckit/templates/at-dsgvo-template.mdCRITICAL: Use the Write tool to create the assessment document.
ARC-{PROJECT_ID}-ATDSG-v*.md files:ARC-{PROJECT_ID}-ATDSG-v{VERSION}[NEEDS VERIFICATION: confirm current venue rules][NEEDS VERIFICATION: confirm current guidance version]$arckit-dpia[NEEDS VERIFICATION: confirm exact §96a(1) sub-point and threshold][NEEDS VERIFICATION: confirm current §2d text and practice][NEEDS VERIFICATION][NEEDS VERIFICATION: recent DSB penalty cases][NEEDS VERIFICATION][NEEDS VERIFICATION: cite recent DSB annual report][NEEDS VERIFICATION]Before writing the file, read .arckit/references/quality-checklist.md and verify all Common Checks pass.
Write the document to:
textprojects/{project_id}/ARC-{PROJECT_ID}-ATDSG-v{VERSION}.md
text━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ✅ AT DSG / DSGVO Assessment Generated ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 📄 Document: projects/{project_id}/ARC-{PROJECT_ID}-ATDSG-v{VERSION}.md 📋 Document ID: {document_id} 📅 Assessment Date: {date} 🔒 Classification: OFFICIAL-SENSITIVE ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 📊 Austrian-Specific Compliance Areas ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ | Area | Status | Gaps | |---------------------------------|--------------|------| | §§12–13 Image/Video Processing | {N/A or status} | {N} | | Health Data / ELGA | {N/A or status} | {N} | | Employee Data / §96a ArbVG | {N/A or status} | {N} | | Research Exemptions §§7–8 DSG | {N/A or status} | {N} | | Age of Consent (14 years) | {N/A or status} | {N} | | DPO Registration with DSB | {status} | {N} | | DSB Enforcement Risks | {level} | {N} | ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ⚡ Critical Actions ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ {List 🔴 High priority gaps} Next steps: 1. {If DPIA required: Run $arckit-dpia} 2. {If employee monitoring: draft Betriebsvereinbarung §96a ArbVG} 3. {If no eu-rgpd baseline: Run $arckit-eu-rgpd first} ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
$arckit-eu-rgpd first, then this command.[NEEDS VERIFICATION] must be confirmed against current DSB guidance before external use.projects/{project_id}/ARC-{PROJECT_ID}-ATDSG-v{VERSION}.mdtext$arckit-at-dsgvo Austrian DSG layer for 001 — federal ministry HR system with CCTV at entrances, employee data, and potential monitoring of IT usage $arckit-at-dsgvo Assess AT DSG obligations for a Vienna regional hospital group integrating with ELGA, processing Gesundheitsdaten, planning mobile patient portal $arckit-at-dsgvo AT data protection for a research consortium processing pseudonymised health data for a longitudinal cohort study under §§7–8 DSG
After completing this command, consider running:
$arckit-dpia -- Run a full Data Protection Impact Assessment if AT DSB screening flags high risk (when 2+ AT DPIA criteria triggered or DSB published Blacklist applies)$arckit-eu-rgpd -- Run the pan-EU GDPR baseline first if not already completed (when No prior eu-rgpd assessment exists for this project)$arckit-at-nisg -- Assess NISG obligations where personal data is processed by Essential/Important entities (when Entity potentially qualifies as Essential or Important under NISG)| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 84,109 | 6,999 | -92% | 1 | 1 | 0% | 4,098 | 4,066 | -1% | 0 | 0 | — |
case-02 | fail→fail | 34,992 | 5,686 | -84% | 1 | 1 | 0% | 6,228 | 3,936 | -37% | 0 | 0 | — |
case-03 | fail→fail | 35,568 | 5,275 | -85% | 1 | 1 | 0% | 6,158 | 4,007 | -35% | 0 | 0 | — |
case-04 | pass→fail | 20,847 | 6,255 | -70% | 1 | 1 | 0% | 3,849 | 4,014 | +4% | 0 | 0 | — |
case-05 | pass→fail | 18,017 | 7,253 | -60% | 1 | 1 | 0% | 3,174 | 4,019 | +27% | 0 | 0 | — |
case-06 | pass→fail | 25,596 | 6,512 | -75% | 1 | 1 | 0% | 4,400 | 4,090 | -7% | 0 | 0 | — |
case-07 | pass→fail | 18,381 | 10,871 | -41% | 1 | 1 | 0% | 3,174 | 3,925 | +24% | 0 | 0 | — |
case-08 | pass→fail | 13,793 | 6,249 | -55% | 1 | 1 | 0% | 2,358 | 3,924 | +66% | 0 | 0 | — |
case-09 | fail→fail | 13,119 | 5,833 | -56% | 1 | 1 | 0% | 2,391 | 4,004 | +67% | 0 | 0 | — |
case-10 | fail→fail | 17,966 | 7,444 | -59% | 1 | 1 | 0% | 2,543 | 4,136 | +63% | 0 | 0 | — |
case-11 | fail→fail | 24,439 | 3,625 | -85% | 1 | 1 | 0% | 3,640 | 3,875 | +6% | 0 | 0 | — |
case-12 | pass→fail | 17,707 | 6,420 | -64% | 1 | 1 | 0% | 3,107 | 3,954 | +27% | 0 | 0 | — |
case-13 | pass→fail | 10,244 | 6,603 | -36% | 1 | 1 | 0% | 1,757 | 4,074 | +132% | 0 | 0 | — |
case-14 | fail→fail | 17,143 | 4,340 | -75% | 1 | 1 | 0% | 3,025 | 3,884 | +28% | 0 | 0 | — |
case-15 | fail→fail | 7,596 | 3,641 | -52% | 1 | 1 | 0% | 1,431 | 4,419 | +209% | 0 | 0 | — |
case-16 | pass→pass | 12,973 | 6,208 | -52% | 1 | 1 | 0% | 2,083 | 4,733 | +127% | 0 | 0 | — |
case-17 | pass→pass | 12,043 | 25,030 | +108% | 1 | 1 | 0% | 2,220 | 8,307 | +274% | 0 | 0 | — |
case-18 | pass→fail | 13,930 | 7,202 | -48% | 1 | 1 | 0% | 2,467 | 4,111 | +67% | 0 | 0 | — |
case-19 | fail→pass | 22,123 | 30,609 | +38% | 1 | 1 | 0% | 3,409 | 9,871 | +190% | 0 | 0 | — |
case-20 | pass→fail | 17,942 | 5,341 | -70% | 1 | 1 | 0% | 2,810 | 4,103 | +46% | 0 | 0 | — |
case-21 | pass→fail | 22,823 | 7,925 | -65% | 1 | 1 | 0% | 3,473 | 3,987 | +15% | 0 | 0 | — |
case-22 | pass→pass | 14,409 | 14,910 | +3% | 1 | 1 | 0% | 2,577 | 6,270 | +143% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 5 counted toward the lift figure. The other 17 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of -41 percentage points is the difference between those two pass rates over the 5 comparable cases. 13 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.