Screen, conduct, and document data-protection or privacy impact assessments for new or changed processing. Use when evaluating necessity, proportionality, high-risk triggers, risks to people, automated decisions, sensitive data, children, monitoring, new technology, safeguards, and residual-risk approval.
Scanned 9/4/2026
Install to Claude Code
npx -y skills add Cancellationperiplocagraeca503/legal-ai-skills --skill dpia-documenter --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Dpia Documenter?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cancellationperiplocagraeca503-dpia-documenter)More formats (shields.io, HTML) on the badges page.
---
name: dpia-documenter
description: >-
Screen, conduct, and document data-protection or privacy impact assessments
for new or changed processing. Use when evaluating necessity, proportionality,
high-risk triggers, risks to people, automated decisions, sensitive data,
children, monitoring, new technology, safeguards, and residual-risk approval.
---
# DPIA Documenter
Complete the assessment before high-risk processing begins and revisit it when
purpose, data, technology, scale, recipients, threat, law, or safeguards change.
## Intake
Obtain the proposal and decision owner, jurisdictions, processing purpose,
business outcome, data-flow and architecture, parties and roles, data and people,
sources, scale, frequency, matching, monitoring, profiling, automated decisions,
AI models, biometrics, children, locations, transfers, retention, security,
alternatives, prior assessments, incidents, and stakeholder views.
## Assessment method
1. Record the screening decision against current law, regulator lists, sector
rules, and organisation thresholds. Explain both required and not-required outcomes.
2. Describe the full lifecycle: collect, generate, infer, combine, use, access,
disclose, transfer, retain, archive, delete, and train or evaluate models.
3. Identify roles, legal bases or permissions, notices, consent, rights, contracts,
secrecy, localisation, and governance dependencies.
4. Test necessity: connect each data element and operation to a specific outcome
and identify less intrusive means.
5. Test proportionality: purpose compatibility, minimisation, accuracy, access,
retention, transparency, choice, contestability, human review, and fairness.
6. Assess risk from the individual's perspective, including surveillance,
exclusion, bias, denial of opportunity, manipulation, exposure, identity harm,
financial loss, safety, confidentiality, autonomy, and chilling effects.
7. Score likelihood and severity before controls using explained criteria, not
unsupported arithmetic.
8. Document existing and proposed technical, contractual, organisational, and
product safeguards, evidence, owner, due date, and test method.
9. Reassess residual risk, record accepted assumptions and dissent, consult the
DPO, security, legal, affected groups, representatives, or regulator as required.
10. Obtain accountable approval, conditions, launch gates, monitoring metrics,
incident triggers, review date, and stop or reassessment criteria.
## Output
Provide the screening record, processing and data-flow description, stakeholder
consultation, necessity and proportionality analysis, risk register, safeguard
plan, residual-risk decision, approval record, and monitoring schedule.
## Guardrails
Do not use a DPIA to legitimise unlawful processing, hide unresolved high risk,
or substitute organisational impact for harm to people. Do not claim
anonymisation without technical evidence. Escalate residual high risk and obtain
required prior consultation before launch.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!