← ClaudeAtlas

privacy-impact-assessmentlisted

Conducts structured Privacy Impact Assessments (PIA) and Data Protection Impact Assessments (DPIA) in compliance with GDPR Art. 35, Quebec Law 25 Art. 63.5, HIPAA § 164.308(a)(1) risk analysis, and analogous requirements across PIPEDA, LGPD, PIPL, PDPA, and the EU AI Act. Use when user says "PIA", "DPIA", "privacy impact assessment", "data protection impact assessment", "risk analysis for this system", "I need to document privacy risks", "compliance documentation for a new project", "is a DPIA required", "assess privacy risks before launch", or when starting a new product, feature, AI system, or processing activity that involves personal data. Also triggers when user is responding to a regulator, auditor, or client requesting privacy documentation, or when another skill (data-minimization, threat-model-privacy) has produced findings that require formal documentation. Produces a complete, regulator-ready PIA/DPIA document as output.
fevra-dev/Subrosa · ★ 0 · Data & Documents · score 72
Install: claude install-skill fevra-dev/Subrosa
# Privacy Impact Assessment Structured PIA/DPIA workflow producing regulator-ready documentation. Mandatory under GDPR Art. 35, Quebec Law 25 Art. 63.5, and recommended/required under HIPAA, PIPEDA, LGPD, PIPL, EU AI Act Art. 9, and Singapore PDPA. **Composable with:** - `threat-model-privacy` — Phase 3 (risk identification) imports adversary profiles directly - `data-minimization` — Phase 2 (processing description) and Phase 4 (risk mitigation) import schema audit findings - `opsec-review` — Phase 4 mitigations include artifact-level controls - `redact` — Identify fields requiring sanitization as a mitigation --- ## Regulatory Source of Truth Statutory citations and jurisdiction facts in this skill and its reference files derive from the normalized taxonomy: `taxonomy/regulatory-taxonomy.md` + the per-jurisdiction records (`taxonomy/regulatory-taxonomy--*.md`; DPIA/PIA triggers are axis **A12**). Records consumed here: `ca-pipeda-law25`, `eu-gdpr-uk`, `us-ca-ccpa`, `br-lgpd`, `cn-pipl`, `sg-pdpa` (+ HIPAA § 164.308 and EU AI Act Art. 9 as sectoral overlays — S-profile records `us-hipaa`, `eu-ai-act`). On any discrepancy between this skill's files and a record: **the record wins** — unless this file is more specific or more correct, in which case fix the record and log the reconciliation in `.fable/reconciliation-log.md`. Never resolve a conflict by inventing a citation. The assessment floor (PIA-before-any-risky-project, Law 25 Art. 63.5) lives in `taxonomy/regulatory-