gdpr-dpia-enlisted
Install: claude install-skill matematicsolutions/awesome-matematic-skills-en
# GDPR DPIA EN - Data Protection Impact Assessment (Art. 35-36)
## Philosophy
A DPIA is not a checkbox - it is a process for managing risk to the rights and freedoms of natural
persons. This skill runs the process and produces a **draft**; the residual-risk acceptance and the
go/no-go decision belong to the controller.
## Step 1 - Is a DPIA REQUIRED (Art. 35(1) threshold)
Mandatory where processing is **likely to result in a high risk**. Three routes:
1. **Supervisory authority's mandatory list** (Art. 35(4)) - each EU SA publishes a list of
operations always requiring a DPIA. Check the relevant national list.
2. **EDPB's 9 criteria (WP248)** - rule of thumb: **>=2 criteria met => DPIA**. Criteria:
evaluation/scoring, automated decisions with significant effect (Art. 22), systematic monitoring,
sensitive/highly personal data, large-scale data, matching/combining datasets, vulnerable data
subjects (children, employees), innovative technology (AI, IoT), preventing exercise of a right
or use of a service.
3. **Art. 35(3)** - explicit cases: systematic and extensive evaluation (profiling), large-scale
special-category/criminal data, large-scale systematic monitoring of public areas.
Output: `dpia_required: yes/no/recommended` + per-criterion justification.
## Step 2 - DPIA structure (Art. 35(7) minimum)
Four pillars:
- **(a) Systematic description** of the processing and its purposes (incl. legitimate interest if relied on).
- **(b) Necessity and proport