[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-anthropic-pia-generation":3,"mdc-f3ir2y-key":37,"related-repo-anthropic-pia-generation":2659,"related-org-anthropic-pia-generation":2755},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":12,"stars":26,"repoUrl":27,"updatedAt":28,"license":29,"forks":30,"topics":31,"repo":32,"sourceUrl":35,"mdContent":36},"pia-generation","generate privacy impact assessments","Generate a Privacy Impact Assessment in house format for a new feature, product, or processing activity, using the structure learned from your seed PIA. Use when the user says \"write a PIA\", \"privacy impact assessment for\", \"do we need a PIA for this\", \"privacy review this feature\", or describes a new data processing activity.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},"anthropic","Anthropic","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Fanthropic.png","anthropics",[13,17,20,23],{"name":14,"slug":15,"type":16},"Compliance","compliance","tag",{"name":18,"slug":19,"type":16},"Documentation","documentation",{"name":21,"slug":22,"type":16},"Legal","legal",{"name":24,"slug":25,"type":16},"Privacy","privacy",8721,"https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fclaude-for-legal","2026-05-14T06:01:13.272953",null,1642,[],{"repoUrl":27,"stars":26,"forks":30,"topics":33,"description":34},[],"A suite of plugins for legal workflows","https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fclaude-for-legal\u002Ftree\u002FHEAD\u002Fprivacy-legal\u002Fskills\u002Fpia-generation","---\nname: pia-generation\ndescription: >\n  Generate a Privacy Impact Assessment in house format for a new feature, product,\n  or processing activity, using the structure learned from your seed PIA. Use when\n  the user says \"write a PIA\", \"privacy impact assessment for\", \"do we need a PIA\n  for this\", \"privacy review this feature\", or describes a new data processing\n  activity.\nargument-hint: \"[feature name or description]\"\n---\n\n# \u002Fpia-generation\n\n1. Load `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → PIA house style (trigger, structure, depth, sign-off).\n2. Run the workflow below.\n3. Check: is a PIA actually needed? (House trigger + research the mandatory-assessment triggers for each applicable regime — cite primary sources, verify currency.)\n4. Intake: ask the product-team questions. Can pull from PRD if provided.\n5. Write PIA in house format. Include privacy policy consistency check.\n6. Output with conditions list and named owners. Route for sign-off.\n\n```\n\u002Fprivacy-legal:pia-generation \"Location sharing feature\"\n```\n\n```\n\u002Fprivacy-legal:pia-generation\nPRD: [Drive link]\n```\n\n---\n\n# PIA Generation\n\n## Matter context\n\n**Matter context.** Check `## Matter workspaces` in the practice-level CLAUDE.md. If `Enabled` is `✗` (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: \"Which matter is this for? Run `\u002Fprivacy-legal:matter-workspace switch \u003Cslug>` or say `practice-level`.\" Load the active matter's `matter.md` for matter-specific context and overrides. Write outputs to the matter folder at `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002Fmatters\u002F\u003Cmatter-slug>\u002F`. Never read another matter's files unless `Cross-matter context` is `on`.\n\n---\n\n## Destination check\n\nBefore producing output, check where it's going. If the user has named a destination (a channel, a distribution list, a counterparty, \"everyone\"), ask whether it's inside the privilege circle. Public channels, company-wide lists, counterparty\u002Fopposing counsel, vendors, and clients (for work product) waive the protection. When the destination looks outside the circle, flag it and offer (a) the privileged version for legal only, (b) a sanitized version for the broader channel, or (c) both — don't silently apply a privileged header and then help paste it somewhere the header won't protect it. See the canonical `## Shared guardrails → Destination check` in this plugin's CLAUDE.md.\n\n## Purpose\n\nA PIA is a conversation with the product team, captured. It asks: what data, why, how long, who sees it, what could go wrong. This skill structures that conversation and writes the output in this team's format — the one learned from the seed PIA during cold-start.\n\n## Jurisdiction assumption\n\nThis assessment assumes the jurisdictional scope specified in your configuration. Privacy rules, assessment triggers, and lawful bases vary materially by jurisdiction (GDPR vs. state consumer privacy laws vs. sectoral). If the processing activity, controller, or affected data subjects fall under a different jurisdiction, this analysis may not apply as written.\n\n## Load prior context on this feature \u002F activity\n\nBefore writing a new PIA, check the outputs folder for prior work on the same feature, processing activity, or counterparty. Read `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → `## Outputs` for the path. Scan for:\n\n- **Prior `use-case-triage` results** covering this activity — the triage's risk rating, mandatory conditions, and called-out concerns are the entry point for the PIA.\n- **Prior `pia-generation` outputs** for the same or an overlapping activity — a superseding PIA should reconcile (what changed, what carried over). A PIA that silently produces different conclusions than a prior PIA on the same activity is a contradiction a reviewing attorney cannot see.\n- **Prior `dpa-review` outputs** for vendors in scope — the DPA review's findings inform the PIA's analysis of subprocessor \u002F cross-border \u002F retention risk.\n\nIf a prior output is found, cite it in the PIA:\n\n> \"Prior triage ([date]) rated this [risk level] and required [conditions]. This PIA builds on that finding — [which conditions are satisfied, which remain, which are re-scoped].\"\n\nIf a prior PIA exists:\n> \"This PIA supersedes the [date] PIA because [reason — scope change, new data category, vendor change, regulatory change]. Conclusions carried over: [X]. Conclusions revised: [Y, because Z].\"\n\n**Carry severity from upstream as a floor** per the cross-skill severity floor rule in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → `## Shared guardrails`. A use-case-triage that rated the activity high-risk cannot become a PIA that concludes low-risk without stating why and what changed.\n\nIf no prior output is found, say so explicitly — \"No prior triage or PIA on this activity in outputs folder; this is a cold start\" — so the reviewing attorney knows the check ran and didn't find anything to reconcile.\n\n## Load house style\n\nRead `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → `## PIA house style`. That has:\n- What triggers a PIA here (may not match regulatory DPIA triggers — some teams PIA everything, some only high-risk)\n- The structure template extracted from the seed PIA\n- Typical depth\n- Who signs off\n\nIf the seed PIA structure is in the config CLAUDE.md, **use it**. The point is that this PIA looks like the other PIAs this team produces, not like a generic one.\n\n## Step 0: Is a PIA needed?\n\nCheck the trigger criteria in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md`. That is the team's house answer.\n\nIn addition, **research the currently operative mandatory-assessment triggers** for each regime in the regulatory footprint (GDPR\u002FUK GDPR DPIA triggers, CCPA\u002FCPRA risk-assessment triggers, other US state data-protection assessment triggers, sectoral regimes). Cite the controlling statute, regulation, or regulator guidance with pinpoint references. Verify currency — assessment thresholds and definitions shift through new state laws, rulemaking, and enforcement guidance. Flag uncertainty rather than guess.\n\n> **No silent supplement.** If a research query to the configured legal research tool returns few or no results for a regime's DPIA \u002F risk-assessment triggers or lawful-basis rules, report what was found and stop. Do NOT fill the gap from web search or model knowledge without asking. Say: \"The search returned [N] results from [tool]. Coverage appears thin for [regime \u002F question]. Options: (1) broaden the search query, (2) try a different research tool, (3) search the web — results will be tagged `[web search — verify]` and should be checked against a primary source before relying, or (4) flag as unverified and stop. Which would you like?\" A lawyer decides whether to accept lower-confidence sources.\n>\n> **Source attribution.** Tag every citation in the PIA with where it came from: `[Westlaw]`, `[regulator site]`, or the MCP tool name for citations retrieved from a legal research connector; `[web search — verify]` for web-search citations; `[model knowledge — verify]` for citations recalled from training data; `[user provided]` for citations the user supplied. Citations tagged `verify` carry higher fabrication risk and should be checked first. Never strip or collapse the tags.\n\nBeyond statutory mandates, treat these as **strong indicators** that a PIA is worth doing even if not strictly mandatory (research whether any of them independently triggers a mandatory assessment under the applicable regime):\n\n- New technology or novel use of existing tech\n- Children's data\n- Combining datasets that weren't collected together\n- Data that could enable discrimination\n- Processing that users wouldn't expect\n\nIf no statutory trigger applies and the house trigger also isn't met → \"Doesn't look like this needs a PIA. Here's a one-paragraph note for the file explaining why, in case anyone asks.\"\n\n## The intake\n\nBefore writing anything, get answers to these from the product team. Conversational is fine — this isn't a form to send them.\n\n### What and why\n\n- What's the feature\u002Fproduct\u002Fchange?\n- What problem does it solve for users?\n- What personal data does it touch? Be specific — \"user data\" is not an answer. Which fields?\n- Is any of it new collection, or is it all data you already have?\n- What's the processing — storage, analysis, sharing, automated decisions?\n\n### Legal basis \u002F regime-specific checks\n\nFor each applicable regime, **research the currently operative framework** for the question below and cite primary sources:\n\n- Under regimes that require an identified lawful basis for processing (e.g., GDPR, UK GDPR), identify the basis for each purpose (contract \u002F legitimate interest \u002F consent \u002F legal obligation \u002F vital interests \u002F public task \u002F other). Research the specific requirements and any balancing-test or consent-standard expectations; cite controlling authority.\n- Under regimes that regulate disclosures (e.g., CCPA\u002FCPRA and other US state privacy laws), check whether any flow looks like a \"sale,\" \"share,\" or other regulated disclosure under the currently operative statutory definitions. Third-party advertising is a recurring trap — research whether it falls within the regulated category for the applicable regime.\n- Under sectoral regimes (HIPAA, GLBA, COPPA, FERPA, etc.), research any regime-specific basis or disclosure rules.\n\nVerify currency; statutory definitions and bases are amended often. Flag uncertainty for attorney verification.\n\n### Who and where\n\n- Who inside the company can see this data? Engineers? Support? Analysts?\n- Any third parties? Vendors, partners, analytics?\n- Where is it stored? Which region? New infrastructure or existing?\n- How long is it kept? Is there a deletion schedule or does it live forever?\n\n### What could go wrong\n\n- If this data leaked, what's the harm to the person?\n- Could this data be used to discriminate, even accidentally?\n- Would users be surprised this is happening? (The \"creepy test\" — not a legal standard but a useful one.)\n- Is there an opt-out? Should there be?\n\n## Writing the PIA\n\n**Use the seed PIA structure from the config CLAUDE.md.** If none was captured, use this default. Prepend the work-product header from `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` `## Outputs` (it differs by user role — see `## Who's using this`).\n\n```markdown\n[WORK-PRODUCT HEADER — per plugin config ## Outputs]\n\n# Privacy Impact Assessment: [Feature\u002FProduct Name]\n\n**Prepared by:** [name] | **Date:** [date] | **Status:** DRAFT \u002F APPROVED\n**Product owner:** [name] | **Privacy reviewer:** [name]\n\n---\n\n## Executive summary\n\n[Two sentences: what this is, whether it's okay. E.g., \"Feature X collects\nlocation data to provide Y. Processing is consistent with existing privacy\npolicy commitments and uses consent as lawful basis. Two mitigations\nrecommended below; no blockers identified.\"]\n\n**Overall risk:** [Reviewer to set: 🟢 Low \u002F 🟡 Medium \u002F 🟠 High \u002F 🔴 Very high]\n\n---\n\n## 1. Description of processing\n\n**What:** [the feature, in plain English]\n**Data categories:** [specific fields — not \"user data\"]\n**Data subjects:** [customers \u002F end users \u002F employees \u002F etc.]\n**Purpose:** [why — tie to user benefit]\n**New collection?** [yes — these fields are new \u002F no — reusing existing data]\n\n---\n\n## 2. Lawful basis\n\n| Purpose | Basis | Notes |\n|---|---|---|\n| [purpose 1] | [Contract \u002F LI \u002F Consent \u002F etc.] | [if LI: balancing test summary; if consent: how obtained] |\n\n---\n\n## 3. Data flow\n\n**Collection:** [how\u002Fwhere data enters]\n**Storage:** [system, region, encryption]\n**Access:** [who, via what controls]\n**Sharing:** [third parties, purpose, governed by which DPA]\n**Retention:** [how long, deletion mechanism]\n\n---\n\n## 4. Privacy policy consistency\n\n| Policy commitment | Consistent? | Notes |\n|---|---|---|\n| [commitment from config CLAUDE.md privacy policy section] | 🟢 \u002F 🟡 | |\n\n[If any 🟡: policy update needed before launch, or processing needs to change]\n\n---\n\n## 5. Risks and mitigations\n\n| # | Risk | Likelihood | Impact | Mitigation | Status | Owner |\n|---|---|---|---|---|---|---|\n| 1 | [specific risk, tied to the design — not \"data breach\" generically] | L\u002FM\u002FH | L\u002FM\u002FH | [specific control] | Done \u002F Planned \u002F Gap | [name] |\n\n**Residual risk after mitigations:** [assessment]\n\n---\n\n## 6. Data subject rights\n\n| Right | Can be exercised? | How |\n|---|---|---|\n| Access | | |\n| Deletion | | |\n| Correction | | |\n| Portability | | |\n| Objection | | |\n\n---\n\n## 7. Recommendation\n\n[APPROVED \u002F APPROVED WITH CONDITIONS \u002F CHANGES REQUIRED \u002F NOT APPROVED]\n\n**Conditions (if any):**\n- [ ] [specific thing that has to happen before launch]\n\n**Sign-off:** [name, date]\n```\n\n## Risk quality standards\n\nRisks in a PIA should be **specific and tied to the design**, not generic. Bad risks pad the document and train readers to skim.\n\n| Bad risk | Why bad | Better |\n|---|---|---|\n| \"Data breach\" | Applies to everything; says nothing | \"Location history accessible by support staff via the admin panel without audit logging — a malicious insider could track a user undetected\" |\n| \"Non-compliance with GDPR\" | Circular — the PIA is supposed to *assess* compliance | Name the specific article and the gap |\n| \"Users might not like it\" | Vague | \"Users who opted out of marketing may still receive this because the opt-out flag isn't checked in this flow\" |\n\nAim for 2-5 real risks, not 15 padded ones.\n\n## Privacy policy diff\n\nEvery PIA should cross-check against the privacy policy commitments in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md`. The common drift:\n\n- Policy says \"we collect X, Y, Z\" — new feature collects W. Policy needs updating, or stop collecting W.\n- Policy says \"we don't sell data\" — new feature shares with an ad partner. That might be a CCPA sale.\n- Policy says retention is \"as long as your account is active\" — new feature keeps data post-deletion.\n\nFlag every mismatch. One of them has to change before launch.\n\n## Handoff\n\n- **To product team:** Conditions list with owners and deadlines. Not \"improve security\" — \"add audit logging to the admin panel's location lookup, owner: [eng lead], before launch.\"\n- **To reg-gap-analysis skill:** If the PIA uncovered a policy inconsistency, that skill tracks the policy update.\n- **To the sign-off process:** Per `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md` → who approves PIAs.\n\n## Gate: submitting a DPIA to a regulator\n\nProducing an internal PIA is research and documentation. *Submitting a DPIA to a supervisory authority* — or voluntarily disclosing one to a regulator in response to an inquiry — is the consequential act.\n\n**Before proceeding to submit a DPIA (or any equivalent impact assessment) to a regulator, supervisory authority, or enforcement body:** Read `## Who's using this` in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md`. If the Role is Non-lawyer:\n\n> Submitting to a regulator has legal consequences — the document becomes part of the supervisory record and any material omission or error becomes enforcement exposure. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:\n>\n> [Generate a 1-page summary: regime and regulator, why a submission is being made (mandatory trigger or voluntary), the risks identified, residual risk after mitigations, any flagged uncertainty, and the three things to ask the attorney before filing.]\n>\n> If you need to find a licensed attorney, solicitor, barrister, or other authorised legal professional in your jurisdiction: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA\u002FBar Standards Board in England & Wales, Law Society in Scotland\u002FNI\u002FIreland\u002FCanada\u002FAustralia, or your jurisdiction's equivalent).\n\nDo not proceed past this gate without an explicit yes.\n\n## Close with the next-steps decision tree\n\nEnd with the next-steps decision tree per CLAUDE.md `## Outputs`. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.\n\n## What this skill does not do\n\n- It doesn't approve the processing. A human signs the PIA.\n- It doesn't write a DPIA for a supervisory authority — that's a more formal document with specific regulatory requirements. This is the internal assessment.\n- It doesn't design the mitigation. It describes what needs mitigating; engineering designs the fix.\n",{"data":38,"body":40},{"name":4,"description":6,"argument-hint":39},"[feature name or description]",{"type":41,"children":42},"root",[43,51,95,107,116,120,126,133,216,219,225,238,244,249,255,260,266,286,340,345,383,388,422,446,451,457,476,499,511,517,529,541,640,652,680,685,691,696,703,731,737,749,767,772,778,801,807,830,836,868,2331,2337,2349,2444,2449,2455,2467,2485,2490,2496,2543,2549,2561,2585,2606,2611,2617,2629,2635,2653],{"type":44,"tag":45,"props":46,"children":47},"element","h1",{"id":4},[48],{"type":49,"value":50},"text","\u002Fpia-generation",{"type":44,"tag":52,"props":53,"children":54},"ol",{},[55,70,75,80,85,90],{"type":44,"tag":56,"props":57,"children":58},"li",{},[59,61,68],{"type":49,"value":60},"Load ",{"type":44,"tag":62,"props":63,"children":65},"code",{"className":64},[],[66],{"type":49,"value":67},"~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002FCLAUDE.md",{"type":49,"value":69}," → PIA house style (trigger, structure, depth, sign-off).",{"type":44,"tag":56,"props":71,"children":72},{},[73],{"type":49,"value":74},"Run the workflow below.",{"type":44,"tag":56,"props":76,"children":77},{},[78],{"type":49,"value":79},"Check: is a PIA actually needed? (House trigger + research the mandatory-assessment triggers for each applicable regime — cite primary sources, verify currency.)",{"type":44,"tag":56,"props":81,"children":82},{},[83],{"type":49,"value":84},"Intake: ask the product-team questions. Can pull from PRD if provided.",{"type":44,"tag":56,"props":86,"children":87},{},[88],{"type":49,"value":89},"Write PIA in house format. Include privacy policy consistency check.",{"type":44,"tag":56,"props":91,"children":92},{},[93],{"type":49,"value":94},"Output with conditions list and named owners. Route for sign-off.",{"type":44,"tag":96,"props":97,"children":101},"pre",{"className":98,"code":100,"language":49},[99],"language-text","\u002Fprivacy-legal:pia-generation \"Location sharing feature\"\n",[102],{"type":44,"tag":62,"props":103,"children":105},{"__ignoreMap":104},"",[106],{"type":49,"value":100},{"type":44,"tag":96,"props":108,"children":111},{"className":109,"code":110,"language":49},[99],"\u002Fprivacy-legal:pia-generation\nPRD: [Drive link]\n",[112],{"type":44,"tag":62,"props":113,"children":114},{"__ignoreMap":104},[115],{"type":49,"value":110},{"type":44,"tag":117,"props":118,"children":119},"hr",{},[],{"type":44,"tag":45,"props":121,"children":123},{"id":122},"pia-generation-1",[124],{"type":49,"value":125},"PIA Generation",{"type":44,"tag":127,"props":128,"children":130},"h2",{"id":129},"matter-context",[131],{"type":49,"value":132},"Matter context",{"type":44,"tag":134,"props":135,"children":136},"p",{},[137,143,145,151,153,159,161,167,169,175,177,183,185,191,193,199,201,207,208,214],{"type":44,"tag":138,"props":139,"children":140},"strong",{},[141],{"type":49,"value":142},"Matter context.",{"type":49,"value":144}," Check ",{"type":44,"tag":62,"props":146,"children":148},{"className":147},[],[149],{"type":49,"value":150},"## Matter workspaces",{"type":49,"value":152}," in the practice-level CLAUDE.md. If ",{"type":44,"tag":62,"props":154,"children":156},{"className":155},[],[157],{"type":49,"value":158},"Enabled",{"type":49,"value":160}," is ",{"type":44,"tag":62,"props":162,"children":164},{"className":163},[],[165],{"type":49,"value":166},"✗",{"type":49,"value":168}," (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: \"Which matter is this for? Run ",{"type":44,"tag":62,"props":170,"children":172},{"className":171},[],[173],{"type":49,"value":174},"\u002Fprivacy-legal:matter-workspace switch \u003Cslug>",{"type":49,"value":176}," or say ",{"type":44,"tag":62,"props":178,"children":180},{"className":179},[],[181],{"type":49,"value":182},"practice-level",{"type":49,"value":184},".\" Load the active matter's ",{"type":44,"tag":62,"props":186,"children":188},{"className":187},[],[189],{"type":49,"value":190},"matter.md",{"type":49,"value":192}," for matter-specific context and overrides. Write outputs to the matter folder at ",{"type":44,"tag":62,"props":194,"children":196},{"className":195},[],[197],{"type":49,"value":198},"~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fprivacy-legal\u002Fmatters\u002F\u003Cmatter-slug>\u002F",{"type":49,"value":200},". Never read another matter's files unless ",{"type":44,"tag":62,"props":202,"children":204},{"className":203},[],[205],{"type":49,"value":206},"Cross-matter context",{"type":49,"value":160},{"type":44,"tag":62,"props":209,"children":211},{"className":210},[],[212],{"type":49,"value":213},"on",{"type":49,"value":215},".",{"type":44,"tag":117,"props":217,"children":218},{},[],{"type":44,"tag":127,"props":220,"children":222},{"id":221},"destination-check",[223],{"type":49,"value":224},"Destination check",{"type":44,"tag":134,"props":226,"children":227},{},[228,230,236],{"type":49,"value":229},"Before producing output, check where it's going. If the user has named a destination (a channel, a distribution list, a counterparty, \"everyone\"), ask whether it's inside the privilege circle. Public channels, company-wide lists, counterparty\u002Fopposing counsel, vendors, and clients (for work product) waive the protection. When the destination looks outside the circle, flag it and offer (a) the privileged version for legal only, (b) a sanitized version for the broader channel, or (c) both — don't silently apply a privileged header and then help paste it somewhere the header won't protect it. See the canonical ",{"type":44,"tag":62,"props":231,"children":233},{"className":232},[],[234],{"type":49,"value":235},"## Shared guardrails → Destination check",{"type":49,"value":237}," in this plugin's CLAUDE.md.",{"type":44,"tag":127,"props":239,"children":241},{"id":240},"purpose",[242],{"type":49,"value":243},"Purpose",{"type":44,"tag":134,"props":245,"children":246},{},[247],{"type":49,"value":248},"A PIA is a conversation with the product team, captured. It asks: what data, why, how long, who sees it, what could go wrong. This skill structures that conversation and writes the output in this team's format — the one learned from the seed PIA during cold-start.",{"type":44,"tag":127,"props":250,"children":252},{"id":251},"jurisdiction-assumption",[253],{"type":49,"value":254},"Jurisdiction assumption",{"type":44,"tag":134,"props":256,"children":257},{},[258],{"type":49,"value":259},"This assessment assumes the jurisdictional scope specified in your configuration. Privacy rules, assessment triggers, and lawful bases vary materially by jurisdiction (GDPR vs. state consumer privacy laws vs. sectoral). If the processing activity, controller, or affected data subjects fall under a different jurisdiction, this analysis may not apply as written.",{"type":44,"tag":127,"props":261,"children":263},{"id":262},"load-prior-context-on-this-feature-activity",[264],{"type":49,"value":265},"Load prior context on this feature \u002F activity",{"type":44,"tag":134,"props":267,"children":268},{},[269,271,276,278,284],{"type":49,"value":270},"Before writing a new PIA, check the outputs folder for prior work on the same feature, processing activity, or counterparty. Read ",{"type":44,"tag":62,"props":272,"children":274},{"className":273},[],[275],{"type":49,"value":67},{"type":49,"value":277}," → ",{"type":44,"tag":62,"props":279,"children":281},{"className":280},[],[282],{"type":49,"value":283},"## Outputs",{"type":49,"value":285}," for the path. Scan for:",{"type":44,"tag":287,"props":288,"children":289},"ul",{},[290,308,324],{"type":44,"tag":56,"props":291,"children":292},{},[293,306],{"type":44,"tag":138,"props":294,"children":295},{},[296,298,304],{"type":49,"value":297},"Prior ",{"type":44,"tag":62,"props":299,"children":301},{"className":300},[],[302],{"type":49,"value":303},"use-case-triage",{"type":49,"value":305}," results",{"type":49,"value":307}," covering this activity — the triage's risk rating, mandatory conditions, and called-out concerns are the entry point for the PIA.",{"type":44,"tag":56,"props":309,"children":310},{},[311,322],{"type":44,"tag":138,"props":312,"children":313},{},[314,315,320],{"type":49,"value":297},{"type":44,"tag":62,"props":316,"children":318},{"className":317},[],[319],{"type":49,"value":4},{"type":49,"value":321}," outputs",{"type":49,"value":323}," for the same or an overlapping activity — a superseding PIA should reconcile (what changed, what carried over). A PIA that silently produces different conclusions than a prior PIA on the same activity is a contradiction a reviewing attorney cannot see.",{"type":44,"tag":56,"props":325,"children":326},{},[327,338],{"type":44,"tag":138,"props":328,"children":329},{},[330,331,337],{"type":49,"value":297},{"type":44,"tag":62,"props":332,"children":334},{"className":333},[],[335],{"type":49,"value":336},"dpa-review",{"type":49,"value":321},{"type":49,"value":339}," for vendors in scope — the DPA review's findings inform the PIA's analysis of subprocessor \u002F cross-border \u002F retention risk.",{"type":44,"tag":134,"props":341,"children":342},{},[343],{"type":49,"value":344},"If a prior output is found, cite it in the PIA:",{"type":44,"tag":346,"props":347,"children":348},"blockquote",{},[349],{"type":44,"tag":134,"props":350,"children":351},{},[352,354,360,362,367,369,374,376,381],{"type":49,"value":353},"\"Prior triage (",{"type":44,"tag":355,"props":356,"children":357},"span",{},[358],{"type":49,"value":359},"date",{"type":49,"value":361},") rated this ",{"type":44,"tag":355,"props":363,"children":364},{},[365],{"type":49,"value":366},"risk level",{"type":49,"value":368}," and required ",{"type":44,"tag":355,"props":370,"children":371},{},[372],{"type":49,"value":373},"conditions",{"type":49,"value":375},". This PIA builds on that finding — ",{"type":44,"tag":355,"props":377,"children":378},{},[379],{"type":49,"value":380},"which conditions are satisfied, which remain, which are re-scoped",{"type":49,"value":382},".\"",{"type":44,"tag":134,"props":384,"children":385},{},[386],{"type":49,"value":387},"If a prior PIA exists:",{"type":44,"tag":346,"props":389,"children":390},{},[391],{"type":44,"tag":134,"props":392,"children":393},{},[394,396,400,402,407,409,414,416,421],{"type":49,"value":395},"\"This PIA supersedes the ",{"type":44,"tag":355,"props":397,"children":398},{},[399],{"type":49,"value":359},{"type":49,"value":401}," PIA because ",{"type":44,"tag":355,"props":403,"children":404},{},[405],{"type":49,"value":406},"reason — scope change, new data category, vendor change, regulatory change",{"type":49,"value":408},". Conclusions carried over: ",{"type":44,"tag":355,"props":410,"children":411},{},[412],{"type":49,"value":413},"X",{"type":49,"value":415},". Conclusions revised: ",{"type":44,"tag":355,"props":417,"children":418},{},[419],{"type":49,"value":420},"Y, because Z",{"type":49,"value":382},{"type":44,"tag":134,"props":423,"children":424},{},[425,430,432,437,438,444],{"type":44,"tag":138,"props":426,"children":427},{},[428],{"type":49,"value":429},"Carry severity from upstream as a floor",{"type":49,"value":431}," per the cross-skill severity floor rule in ",{"type":44,"tag":62,"props":433,"children":435},{"className":434},[],[436],{"type":49,"value":67},{"type":49,"value":277},{"type":44,"tag":62,"props":439,"children":441},{"className":440},[],[442],{"type":49,"value":443},"## Shared guardrails",{"type":49,"value":445},". A use-case-triage that rated the activity high-risk cannot become a PIA that concludes low-risk without stating why and what changed.",{"type":44,"tag":134,"props":447,"children":448},{},[449],{"type":49,"value":450},"If no prior output is found, say so explicitly — \"No prior triage or PIA on this activity in outputs folder; this is a cold start\" — so the reviewing attorney knows the check ran and didn't find anything to reconcile.",{"type":44,"tag":127,"props":452,"children":454},{"id":453},"load-house-style",[455],{"type":49,"value":456},"Load house style",{"type":44,"tag":134,"props":458,"children":459},{},[460,462,467,468,474],{"type":49,"value":461},"Read ",{"type":44,"tag":62,"props":463,"children":465},{"className":464},[],[466],{"type":49,"value":67},{"type":49,"value":277},{"type":44,"tag":62,"props":469,"children":471},{"className":470},[],[472],{"type":49,"value":473},"## PIA house style",{"type":49,"value":475},". That has:",{"type":44,"tag":287,"props":477,"children":478},{},[479,484,489,494],{"type":44,"tag":56,"props":480,"children":481},{},[482],{"type":49,"value":483},"What triggers a PIA here (may not match regulatory DPIA triggers — some teams PIA everything, some only high-risk)",{"type":44,"tag":56,"props":485,"children":486},{},[487],{"type":49,"value":488},"The structure template extracted from the seed PIA",{"type":44,"tag":56,"props":490,"children":491},{},[492],{"type":49,"value":493},"Typical depth",{"type":44,"tag":56,"props":495,"children":496},{},[497],{"type":49,"value":498},"Who signs off",{"type":44,"tag":134,"props":500,"children":501},{},[502,504,509],{"type":49,"value":503},"If the seed PIA structure is in the config CLAUDE.md, ",{"type":44,"tag":138,"props":505,"children":506},{},[507],{"type":49,"value":508},"use it",{"type":49,"value":510},". The point is that this PIA looks like the other PIAs this team produces, not like a generic one.",{"type":44,"tag":127,"props":512,"children":514},{"id":513},"step-0-is-a-pia-needed",[515],{"type":49,"value":516},"Step 0: Is a PIA needed?",{"type":44,"tag":134,"props":518,"children":519},{},[520,522,527],{"type":49,"value":521},"Check the trigger criteria in ",{"type":44,"tag":62,"props":523,"children":525},{"className":524},[],[526],{"type":49,"value":67},{"type":49,"value":528},". That is the team's house answer.",{"type":44,"tag":134,"props":530,"children":531},{},[532,534,539],{"type":49,"value":533},"In addition, ",{"type":44,"tag":138,"props":535,"children":536},{},[537],{"type":49,"value":538},"research the currently operative mandatory-assessment triggers",{"type":49,"value":540}," for each regime in the regulatory footprint (GDPR\u002FUK GDPR DPIA triggers, CCPA\u002FCPRA risk-assessment triggers, other US state data-protection assessment triggers, sectoral regimes). Cite the controlling statute, regulation, or regulator guidance with pinpoint references. Verify currency — assessment thresholds and definitions shift through new state laws, rulemaking, and enforcement guidance. Flag uncertainty rather than guess.",{"type":44,"tag":346,"props":542,"children":543},{},[544,583],{"type":44,"tag":134,"props":545,"children":546},{},[547,552,554,559,561,566,568,573,575,581],{"type":44,"tag":138,"props":548,"children":549},{},[550],{"type":49,"value":551},"No silent supplement.",{"type":49,"value":553}," If a research query to the configured legal research tool returns few or no results for a regime's DPIA \u002F risk-assessment triggers or lawful-basis rules, report what was found and stop. Do NOT fill the gap from web search or model knowledge without asking. Say: \"The search returned ",{"type":44,"tag":355,"props":555,"children":556},{},[557],{"type":49,"value":558},"N",{"type":49,"value":560}," results from ",{"type":44,"tag":355,"props":562,"children":563},{},[564],{"type":49,"value":565},"tool",{"type":49,"value":567},". Coverage appears thin for ",{"type":44,"tag":355,"props":569,"children":570},{},[571],{"type":49,"value":572},"regime \u002F question",{"type":49,"value":574},". Options: (1) broaden the search query, (2) try a different research tool, (3) search the web — results will be tagged ",{"type":44,"tag":62,"props":576,"children":578},{"className":577},[],[579],{"type":49,"value":580},"[web search — verify]",{"type":49,"value":582}," and should be checked against a primary source before relying, or (4) flag as unverified and stop. Which would you like?\" A lawyer decides whether to accept lower-confidence sources.",{"type":44,"tag":134,"props":584,"children":585},{},[586,591,593,599,601,607,609,614,616,622,624,630,632,638],{"type":44,"tag":138,"props":587,"children":588},{},[589],{"type":49,"value":590},"Source attribution.",{"type":49,"value":592}," Tag every citation in the PIA with where it came from: ",{"type":44,"tag":62,"props":594,"children":596},{"className":595},[],[597],{"type":49,"value":598},"[Westlaw]",{"type":49,"value":600},", ",{"type":44,"tag":62,"props":602,"children":604},{"className":603},[],[605],{"type":49,"value":606},"[regulator site]",{"type":49,"value":608},", or the MCP tool name for citations retrieved from a legal research connector; ",{"type":44,"tag":62,"props":610,"children":612},{"className":611},[],[613],{"type":49,"value":580},{"type":49,"value":615}," for web-search citations; ",{"type":44,"tag":62,"props":617,"children":619},{"className":618},[],[620],{"type":49,"value":621},"[model knowledge — verify]",{"type":49,"value":623}," for citations recalled from training data; ",{"type":44,"tag":62,"props":625,"children":627},{"className":626},[],[628],{"type":49,"value":629},"[user provided]",{"type":49,"value":631}," for citations the user supplied. Citations tagged ",{"type":44,"tag":62,"props":633,"children":635},{"className":634},[],[636],{"type":49,"value":637},"verify",{"type":49,"value":639}," carry higher fabrication risk and should be checked first. Never strip or collapse the tags.",{"type":44,"tag":134,"props":641,"children":642},{},[643,645,650],{"type":49,"value":644},"Beyond statutory mandates, treat these as ",{"type":44,"tag":138,"props":646,"children":647},{},[648],{"type":49,"value":649},"strong indicators",{"type":49,"value":651}," that a PIA is worth doing even if not strictly mandatory (research whether any of them independently triggers a mandatory assessment under the applicable regime):",{"type":44,"tag":287,"props":653,"children":654},{},[655,660,665,670,675],{"type":44,"tag":56,"props":656,"children":657},{},[658],{"type":49,"value":659},"New technology or novel use of existing tech",{"type":44,"tag":56,"props":661,"children":662},{},[663],{"type":49,"value":664},"Children's data",{"type":44,"tag":56,"props":666,"children":667},{},[668],{"type":49,"value":669},"Combining datasets that weren't collected together",{"type":44,"tag":56,"props":671,"children":672},{},[673],{"type":49,"value":674},"Data that could enable discrimination",{"type":44,"tag":56,"props":676,"children":677},{},[678],{"type":49,"value":679},"Processing that users wouldn't expect",{"type":44,"tag":134,"props":681,"children":682},{},[683],{"type":49,"value":684},"If no statutory trigger applies and the house trigger also isn't met → \"Doesn't look like this needs a PIA. Here's a one-paragraph note for the file explaining why, in case anyone asks.\"",{"type":44,"tag":127,"props":686,"children":688},{"id":687},"the-intake",[689],{"type":49,"value":690},"The intake",{"type":44,"tag":134,"props":692,"children":693},{},[694],{"type":49,"value":695},"Before writing anything, get answers to these from the product team. Conversational is fine — this isn't a form to send them.",{"type":44,"tag":697,"props":698,"children":700},"h3",{"id":699},"what-and-why",[701],{"type":49,"value":702},"What and why",{"type":44,"tag":287,"props":704,"children":705},{},[706,711,716,721,726],{"type":44,"tag":56,"props":707,"children":708},{},[709],{"type":49,"value":710},"What's the feature\u002Fproduct\u002Fchange?",{"type":44,"tag":56,"props":712,"children":713},{},[714],{"type":49,"value":715},"What problem does it solve for users?",{"type":44,"tag":56,"props":717,"children":718},{},[719],{"type":49,"value":720},"What personal data does it touch? Be specific — \"user data\" is not an answer. Which fields?",{"type":44,"tag":56,"props":722,"children":723},{},[724],{"type":49,"value":725},"Is any of it new collection, or is it all data you already have?",{"type":44,"tag":56,"props":727,"children":728},{},[729],{"type":49,"value":730},"What's the processing — storage, analysis, sharing, automated decisions?",{"type":44,"tag":697,"props":732,"children":734},{"id":733},"legal-basis-regime-specific-checks",[735],{"type":49,"value":736},"Legal basis \u002F regime-specific checks",{"type":44,"tag":134,"props":738,"children":739},{},[740,742,747],{"type":49,"value":741},"For each applicable regime, ",{"type":44,"tag":138,"props":743,"children":744},{},[745],{"type":49,"value":746},"research the currently operative framework",{"type":49,"value":748}," for the question below and cite primary sources:",{"type":44,"tag":287,"props":750,"children":751},{},[752,757,762],{"type":44,"tag":56,"props":753,"children":754},{},[755],{"type":49,"value":756},"Under regimes that require an identified lawful basis for processing (e.g., GDPR, UK GDPR), identify the basis for each purpose (contract \u002F legitimate interest \u002F consent \u002F legal obligation \u002F vital interests \u002F public task \u002F other). Research the specific requirements and any balancing-test or consent-standard expectations; cite controlling authority.",{"type":44,"tag":56,"props":758,"children":759},{},[760],{"type":49,"value":761},"Under regimes that regulate disclosures (e.g., CCPA\u002FCPRA and other US state privacy laws), check whether any flow looks like a \"sale,\" \"share,\" or other regulated disclosure under the currently operative statutory definitions. Third-party advertising is a recurring trap — research whether it falls within the regulated category for the applicable regime.",{"type":44,"tag":56,"props":763,"children":764},{},[765],{"type":49,"value":766},"Under sectoral regimes (HIPAA, GLBA, COPPA, FERPA, etc.), research any regime-specific basis or disclosure rules.",{"type":44,"tag":134,"props":768,"children":769},{},[770],{"type":49,"value":771},"Verify currency; statutory definitions and bases are amended often. Flag uncertainty for attorney verification.",{"type":44,"tag":697,"props":773,"children":775},{"id":774},"who-and-where",[776],{"type":49,"value":777},"Who and where",{"type":44,"tag":287,"props":779,"children":780},{},[781,786,791,796],{"type":44,"tag":56,"props":782,"children":783},{},[784],{"type":49,"value":785},"Who inside the company can see this data? Engineers? Support? Analysts?",{"type":44,"tag":56,"props":787,"children":788},{},[789],{"type":49,"value":790},"Any third parties? Vendors, partners, analytics?",{"type":44,"tag":56,"props":792,"children":793},{},[794],{"type":49,"value":795},"Where is it stored? Which region? New infrastructure or existing?",{"type":44,"tag":56,"props":797,"children":798},{},[799],{"type":49,"value":800},"How long is it kept? Is there a deletion schedule or does it live forever?",{"type":44,"tag":697,"props":802,"children":804},{"id":803},"what-could-go-wrong",[805],{"type":49,"value":806},"What could go wrong",{"type":44,"tag":287,"props":808,"children":809},{},[810,815,820,825],{"type":44,"tag":56,"props":811,"children":812},{},[813],{"type":49,"value":814},"If this data leaked, what's the harm to the person?",{"type":44,"tag":56,"props":816,"children":817},{},[818],{"type":49,"value":819},"Could this data be used to discriminate, even accidentally?",{"type":44,"tag":56,"props":821,"children":822},{},[823],{"type":49,"value":824},"Would users be surprised this is happening? (The \"creepy test\" — not a legal standard but a useful one.)",{"type":44,"tag":56,"props":826,"children":827},{},[828],{"type":49,"value":829},"Is there an opt-out? Should there be?",{"type":44,"tag":127,"props":831,"children":833},{"id":832},"writing-the-pia",[834],{"type":49,"value":835},"Writing the PIA",{"type":44,"tag":134,"props":837,"children":838},{},[839,844,846,851,853,858,860,866],{"type":44,"tag":138,"props":840,"children":841},{},[842],{"type":49,"value":843},"Use the seed PIA structure from the config CLAUDE.md.",{"type":49,"value":845}," If none was captured, use this default. Prepend the work-product header from ",{"type":44,"tag":62,"props":847,"children":849},{"className":848},[],[850],{"type":49,"value":67},{"type":49,"value":852}," ",{"type":44,"tag":62,"props":854,"children":856},{"className":855},[],[857],{"type":49,"value":283},{"type":49,"value":859}," (it differs by user role — see ",{"type":44,"tag":62,"props":861,"children":863},{"className":862},[],[864],{"type":49,"value":865},"## Who's using this",{"type":49,"value":867},").",{"type":44,"tag":96,"props":869,"children":873},{"className":870,"code":871,"language":872,"meta":104,"style":104},"language-markdown shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","[WORK-PRODUCT HEADER — per plugin config ## Outputs]\n\n# Privacy Impact Assessment: [Feature\u002FProduct Name]\n\n**Prepared by:** [name] | **Date:** [date] | **Status:** DRAFT \u002F APPROVED\n**Product owner:** [name] | **Privacy reviewer:** [name]\n\n---\n\n## Executive summary\n\n[Two sentences: what this is, whether it's okay. E.g., \"Feature X collects\nlocation data to provide Y. Processing is consistent with existing privacy\npolicy commitments and uses consent as lawful basis. Two mitigations\nrecommended below; no blockers identified.\"]\n\n**Overall risk:** [Reviewer to set: 🟢 Low \u002F 🟡 Medium \u002F 🟠 High \u002F 🔴 Very high]\n\n---\n\n## 1. Description of processing\n\n**What:** [the feature, in plain English]\n**Data categories:** [specific fields — not \"user data\"]\n**Data subjects:** [customers \u002F end users \u002F employees \u002F etc.]\n**Purpose:** [why — tie to user benefit]\n**New collection?** [yes — these fields are new \u002F no — reusing existing data]\n\n---\n\n## 2. Lawful basis\n\n| Purpose | Basis | Notes |\n|---|---|---|\n| [purpose 1] | [Contract \u002F LI \u002F Consent \u002F etc.] | [if LI: balancing test summary; if consent: how obtained] |\n\n---\n\n## 3. Data flow\n\n**Collection:** [how\u002Fwhere data enters]\n**Storage:** [system, region, encryption]\n**Access:** [who, via what controls]\n**Sharing:** [third parties, purpose, governed by which DPA]\n**Retention:** [how long, deletion mechanism]\n\n---\n\n## 4. Privacy policy consistency\n\n| Policy commitment | Consistent? | Notes |\n|---|---|---|\n| [commitment from config CLAUDE.md privacy policy section] | 🟢 \u002F 🟡 | |\n\n[If any 🟡: policy update needed before launch, or processing needs to change]\n\n---\n\n## 5. Risks and mitigations\n\n| # | Risk | Likelihood | Impact | Mitigation | Status | Owner |\n|---|---|---|---|---|---|---|\n| 1 | [specific risk, tied to the design — not \"data breach\" generically] | L\u002FM\u002FH | L\u002FM\u002FH | [specific control] | Done \u002F Planned \u002F Gap | [name] |\n\n**Residual risk after mitigations:** [assessment]\n\n---\n\n## 6. Data subject rights\n\n| Right | Can be exercised? | How |\n|---|---|---|\n| Access | | |\n| Deletion | | |\n| Correction | | |\n| Portability | | |\n| Objection | | |\n\n---\n\n## 7. Recommendation\n\n[APPROVED \u002F APPROVED WITH CONDITIONS \u002F CHANGES REQUIRED \u002F NOT APPROVED]\n\n**Conditions (if any):**\n- [ ] [specific thing that has to happen before launch]\n\n**Sign-off:** [name, date]\n","markdown",[874],{"type":44,"tag":62,"props":875,"children":876},{"__ignoreMap":104},[877,888,898,914,922,1010,1069,1077,1086,1094,1108,1116,1125,1134,1143,1152,1160,1182,1190,1198,1206,1219,1227,1249,1271,1293,1315,1337,1345,1353,1361,1374,1382,1419,1428,1463,1471,1479,1487,1500,1508,1530,1552,1574,1596,1618,1626,1634,1642,1655,1663,1697,1705,1736,1744,1753,1761,1769,1777,1790,1798,1869,1878,1955,1963,1993,2001,2009,2017,2030,2038,2073,2081,2107,2132,2157,2182,2207,2215,2223,2231,2244,2252,2261,2269,2287,2301,2309],{"type":44,"tag":355,"props":878,"children":881},{"class":879,"line":880},"line",1,[882],{"type":44,"tag":355,"props":883,"children":885},{"style":884},"--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8",[886],{"type":49,"value":887},"[WORK-PRODUCT HEADER — per plugin config ## Outputs]\n",{"type":44,"tag":355,"props":889,"children":891},{"class":879,"line":890},2,[892],{"type":44,"tag":355,"props":893,"children":895},{"emptyLinePlaceholder":894},true,[896],{"type":49,"value":897},"\n",{"type":44,"tag":355,"props":899,"children":901},{"class":879,"line":900},3,[902,908],{"type":44,"tag":355,"props":903,"children":905},{"style":904},"--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF",[906],{"type":49,"value":907},"# ",{"type":44,"tag":355,"props":909,"children":911},{"style":910},"--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B",[912],{"type":49,"value":913},"Privacy Impact Assessment: [Feature\u002FProduct Name]\n",{"type":44,"tag":355,"props":915,"children":917},{"class":879,"line":916},4,[918],{"type":44,"tag":355,"props":919,"children":920},{"emptyLinePlaceholder":894},[921],{"type":49,"value":897},{"type":44,"tag":355,"props":923,"children":925},{"class":879,"line":924},5,[926,932,938,942,947,953,958,963,967,972,976,980,984,988,992,996,1001,1005],{"type":44,"tag":355,"props":927,"children":929},{"style":928},"--shiki-light:#39ADB5;--shiki-light-font-weight:bold;--shiki-default:#89DDFF;--shiki-default-font-weight:bold;--shiki-dark:#89DDFF;--shiki-dark-font-weight:bold",[930],{"type":49,"value":931},"**",{"type":44,"tag":355,"props":933,"children":935},{"style":934},"--shiki-light:#E53935;--shiki-light-font-weight:bold;--shiki-default:#F07178;--shiki-default-font-weight:bold;--shiki-dark:#F07178;--shiki-dark-font-weight:bold",[936],{"type":49,"value":937},"Prepared by:",{"type":44,"tag":355,"props":939,"children":940},{"style":928},[941],{"type":49,"value":931},{"type":44,"tag":355,"props":943,"children":944},{"style":904},[945],{"type":49,"value":946}," [",{"type":44,"tag":355,"props":948,"children":950},{"style":949},"--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D",[951],{"type":49,"value":952},"name",{"type":44,"tag":355,"props":954,"children":955},{"style":904},[956],{"type":49,"value":957},"]",{"type":44,"tag":355,"props":959,"children":960},{"style":884},[961],{"type":49,"value":962}," | ",{"type":44,"tag":355,"props":964,"children":965},{"style":928},[966],{"type":49,"value":931},{"type":44,"tag":355,"props":968,"children":969},{"style":934},[970],{"type":49,"value":971},"Date:",{"type":44,"tag":355,"props":973,"children":974},{"style":928},[975],{"type":49,"value":931},{"type":44,"tag":355,"props":977,"children":978},{"style":904},[979],{"type":49,"value":946},{"type":44,"tag":355,"props":981,"children":982},{"style":949},[983],{"type":49,"value":359},{"type":44,"tag":355,"props":985,"children":986},{"style":904},[987],{"type":49,"value":957},{"type":44,"tag":355,"props":989,"children":990},{"style":884},[991],{"type":49,"value":962},{"type":44,"tag":355,"props":993,"children":994},{"style":928},[995],{"type":49,"value":931},{"type":44,"tag":355,"props":997,"children":998},{"style":934},[999],{"type":49,"value":1000},"Status:",{"type":44,"tag":355,"props":1002,"children":1003},{"style":928},[1004],{"type":49,"value":931},{"type":44,"tag":355,"props":1006,"children":1007},{"style":884},[1008],{"type":49,"value":1009}," DRAFT \u002F APPROVED\n",{"type":44,"tag":355,"props":1011,"children":1013},{"class":879,"line":1012},6,[1014,1018,1023,1027,1031,1035,1039,1043,1047,1052,1056,1060,1064],{"type":44,"tag":355,"props":1015,"children":1016},{"style":928},[1017],{"type":49,"value":931},{"type":44,"tag":355,"props":1019,"children":1020},{"style":934},[1021],{"type":49,"value":1022},"Product owner:",{"type":44,"tag":355,"props":1024,"children":1025},{"style":928},[1026],{"type":49,"value":931},{"type":44,"tag":355,"props":1028,"children":1029},{"style":904},[1030],{"type":49,"value":946},{"type":44,"tag":355,"props":1032,"children":1033},{"style":949},[1034],{"type":49,"value":952},{"type":44,"tag":355,"props":1036,"children":1037},{"style":904},[1038],{"type":49,"value":957},{"type":44,"tag":355,"props":1040,"children":1041},{"style":884},[1042],{"type":49,"value":962},{"type":44,"tag":355,"props":1044,"children":1045},{"style":928},[1046],{"type":49,"value":931},{"type":44,"tag":355,"props":1048,"children":1049},{"style":934},[1050],{"type":49,"value":1051},"Privacy reviewer:",{"type":44,"tag":355,"props":1053,"children":1054},{"style":928},[1055],{"type":49,"value":931},{"type":44,"tag":355,"props":1057,"children":1058},{"style":904},[1059],{"type":49,"value":946},{"type":44,"tag":355,"props":1061,"children":1062},{"style":949},[1063],{"type":49,"value":952},{"type":44,"tag":355,"props":1065,"children":1066},{"style":904},[1067],{"type":49,"value":1068},"]\n",{"type":44,"tag":355,"props":1070,"children":1072},{"class":879,"line":1071},7,[1073],{"type":44,"tag":355,"props":1074,"children":1075},{"emptyLinePlaceholder":894},[1076],{"type":49,"value":897},{"type":44,"tag":355,"props":1078,"children":1080},{"class":879,"line":1079},8,[1081],{"type":44,"tag":355,"props":1082,"children":1083},{"style":904},[1084],{"type":49,"value":1085},"---\n",{"type":44,"tag":355,"props":1087,"children":1089},{"class":879,"line":1088},9,[1090],{"type":44,"tag":355,"props":1091,"children":1092},{"emptyLinePlaceholder":894},[1093],{"type":49,"value":897},{"type":44,"tag":355,"props":1095,"children":1097},{"class":879,"line":1096},10,[1098,1103],{"type":44,"tag":355,"props":1099,"children":1100},{"style":904},[1101],{"type":49,"value":1102},"## ",{"type":44,"tag":355,"props":1104,"children":1105},{"style":910},[1106],{"type":49,"value":1107},"Executive summary\n",{"type":44,"tag":355,"props":1109,"children":1111},{"class":879,"line":1110},11,[1112],{"type":44,"tag":355,"props":1113,"children":1114},{"emptyLinePlaceholder":894},[1115],{"type":49,"value":897},{"type":44,"tag":355,"props":1117,"children":1119},{"class":879,"line":1118},12,[1120],{"type":44,"tag":355,"props":1121,"children":1122},{"style":884},[1123],{"type":49,"value":1124},"[Two sentences: what this is, whether it's okay. E.g., \"Feature X collects\n",{"type":44,"tag":355,"props":1126,"children":1128},{"class":879,"line":1127},13,[1129],{"type":44,"tag":355,"props":1130,"children":1131},{"style":884},[1132],{"type":49,"value":1133},"location data to provide Y. Processing is consistent with existing privacy\n",{"type":44,"tag":355,"props":1135,"children":1137},{"class":879,"line":1136},14,[1138],{"type":44,"tag":355,"props":1139,"children":1140},{"style":884},[1141],{"type":49,"value":1142},"policy commitments and uses consent as lawful basis. Two mitigations\n",{"type":44,"tag":355,"props":1144,"children":1146},{"class":879,"line":1145},15,[1147],{"type":44,"tag":355,"props":1148,"children":1149},{"style":884},[1150],{"type":49,"value":1151},"recommended below; no blockers identified.\"]\n",{"type":44,"tag":355,"props":1153,"children":1155},{"class":879,"line":1154},16,[1156],{"type":44,"tag":355,"props":1157,"children":1158},{"emptyLinePlaceholder":894},[1159],{"type":49,"value":897},{"type":44,"tag":355,"props":1161,"children":1163},{"class":879,"line":1162},17,[1164,1168,1173,1177],{"type":44,"tag":355,"props":1165,"children":1166},{"style":928},[1167],{"type":49,"value":931},{"type":44,"tag":355,"props":1169,"children":1170},{"style":934},[1171],{"type":49,"value":1172},"Overall risk:",{"type":44,"tag":355,"props":1174,"children":1175},{"style":928},[1176],{"type":49,"value":931},{"type":44,"tag":355,"props":1178,"children":1179},{"style":884},[1180],{"type":49,"value":1181}," [Reviewer to set: 🟢 Low \u002F 🟡 Medium \u002F 🟠 High \u002F 🔴 Very high]\n",{"type":44,"tag":355,"props":1183,"children":1185},{"class":879,"line":1184},18,[1186],{"type":44,"tag":355,"props":1187,"children":1188},{"emptyLinePlaceholder":894},[1189],{"type":49,"value":897},{"type":44,"tag":355,"props":1191,"children":1193},{"class":879,"line":1192},19,[1194],{"type":44,"tag":355,"props":1195,"children":1196},{"style":904},[1197],{"type":49,"value":1085},{"type":44,"tag":355,"props":1199,"children":1201},{"class":879,"line":1200},20,[1202],{"type":44,"tag":355,"props":1203,"children":1204},{"emptyLinePlaceholder":894},[1205],{"type":49,"value":897},{"type":44,"tag":355,"props":1207,"children":1209},{"class":879,"line":1208},21,[1210,1214],{"type":44,"tag":355,"props":1211,"children":1212},{"style":904},[1213],{"type":49,"value":1102},{"type":44,"tag":355,"props":1215,"children":1216},{"style":910},[1217],{"type":49,"value":1218},"1. Description of processing\n",{"type":44,"tag":355,"props":1220,"children":1222},{"class":879,"line":1221},22,[1223],{"type":44,"tag":355,"props":1224,"children":1225},{"emptyLinePlaceholder":894},[1226],{"type":49,"value":897},{"type":44,"tag":355,"props":1228,"children":1230},{"class":879,"line":1229},23,[1231,1235,1240,1244],{"type":44,"tag":355,"props":1232,"children":1233},{"style":928},[1234],{"type":49,"value":931},{"type":44,"tag":355,"props":1236,"children":1237},{"style":934},[1238],{"type":49,"value":1239},"What:",{"type":44,"tag":355,"props":1241,"children":1242},{"style":928},[1243],{"type":49,"value":931},{"type":44,"tag":355,"props":1245,"children":1246},{"style":884},[1247],{"type":49,"value":1248}," [the feature, in plain English]\n",{"type":44,"tag":355,"props":1250,"children":1252},{"class":879,"line":1251},24,[1253,1257,1262,1266],{"type":44,"tag":355,"props":1254,"children":1255},{"style":928},[1256],{"type":49,"value":931},{"type":44,"tag":355,"props":1258,"children":1259},{"style":934},[1260],{"type":49,"value":1261},"Data categories:",{"type":44,"tag":355,"props":1263,"children":1264},{"style":928},[1265],{"type":49,"value":931},{"type":44,"tag":355,"props":1267,"children":1268},{"style":884},[1269],{"type":49,"value":1270}," [specific fields — not \"user data\"]\n",{"type":44,"tag":355,"props":1272,"children":1274},{"class":879,"line":1273},25,[1275,1279,1284,1288],{"type":44,"tag":355,"props":1276,"children":1277},{"style":928},[1278],{"type":49,"value":931},{"type":44,"tag":355,"props":1280,"children":1281},{"style":934},[1282],{"type":49,"value":1283},"Data subjects:",{"type":44,"tag":355,"props":1285,"children":1286},{"style":928},[1287],{"type":49,"value":931},{"type":44,"tag":355,"props":1289,"children":1290},{"style":884},[1291],{"type":49,"value":1292}," [customers \u002F end users \u002F employees \u002F etc.]\n",{"type":44,"tag":355,"props":1294,"children":1296},{"class":879,"line":1295},26,[1297,1301,1306,1310],{"type":44,"tag":355,"props":1298,"children":1299},{"style":928},[1300],{"type":49,"value":931},{"type":44,"tag":355,"props":1302,"children":1303},{"style":934},[1304],{"type":49,"value":1305},"Purpose:",{"type":44,"tag":355,"props":1307,"children":1308},{"style":928},[1309],{"type":49,"value":931},{"type":44,"tag":355,"props":1311,"children":1312},{"style":884},[1313],{"type":49,"value":1314}," [why — tie to user benefit]\n",{"type":44,"tag":355,"props":1316,"children":1318},{"class":879,"line":1317},27,[1319,1323,1328,1332],{"type":44,"tag":355,"props":1320,"children":1321},{"style":928},[1322],{"type":49,"value":931},{"type":44,"tag":355,"props":1324,"children":1325},{"style":934},[1326],{"type":49,"value":1327},"New collection?",{"type":44,"tag":355,"props":1329,"children":1330},{"style":928},[1331],{"type":49,"value":931},{"type":44,"tag":355,"props":1333,"children":1334},{"style":884},[1335],{"type":49,"value":1336}," [yes — these fields are new \u002F no — reusing existing data]\n",{"type":44,"tag":355,"props":1338,"children":1340},{"class":879,"line":1339},28,[1341],{"type":44,"tag":355,"props":1342,"children":1343},{"emptyLinePlaceholder":894},[1344],{"type":49,"value":897},{"type":44,"tag":355,"props":1346,"children":1348},{"class":879,"line":1347},29,[1349],{"type":44,"tag":355,"props":1350,"children":1351},{"style":904},[1352],{"type":49,"value":1085},{"type":44,"tag":355,"props":1354,"children":1356},{"class":879,"line":1355},30,[1357],{"type":44,"tag":355,"props":1358,"children":1359},{"emptyLinePlaceholder":894},[1360],{"type":49,"value":897},{"type":44,"tag":355,"props":1362,"children":1364},{"class":879,"line":1363},31,[1365,1369],{"type":44,"tag":355,"props":1366,"children":1367},{"style":904},[1368],{"type":49,"value":1102},{"type":44,"tag":355,"props":1370,"children":1371},{"style":910},[1372],{"type":49,"value":1373},"2. Lawful basis\n",{"type":44,"tag":355,"props":1375,"children":1377},{"class":879,"line":1376},32,[1378],{"type":44,"tag":355,"props":1379,"children":1380},{"emptyLinePlaceholder":894},[1381],{"type":49,"value":897},{"type":44,"tag":355,"props":1383,"children":1385},{"class":879,"line":1384},33,[1386,1391,1396,1400,1405,1409,1414],{"type":44,"tag":355,"props":1387,"children":1388},{"style":904},[1389],{"type":49,"value":1390},"|",{"type":44,"tag":355,"props":1392,"children":1393},{"style":884},[1394],{"type":49,"value":1395}," Purpose ",{"type":44,"tag":355,"props":1397,"children":1398},{"style":904},[1399],{"type":49,"value":1390},{"type":44,"tag":355,"props":1401,"children":1402},{"style":884},[1403],{"type":49,"value":1404}," Basis ",{"type":44,"tag":355,"props":1406,"children":1407},{"style":904},[1408],{"type":49,"value":1390},{"type":44,"tag":355,"props":1410,"children":1411},{"style":884},[1412],{"type":49,"value":1413}," Notes ",{"type":44,"tag":355,"props":1415,"children":1416},{"style":904},[1417],{"type":49,"value":1418},"|\n",{"type":44,"tag":355,"props":1420,"children":1422},{"class":879,"line":1421},34,[1423],{"type":44,"tag":355,"props":1424,"children":1425},{"style":904},[1426],{"type":49,"value":1427},"|---|---|---|\n",{"type":44,"tag":355,"props":1429,"children":1431},{"class":879,"line":1430},35,[1432,1436,1441,1445,1450,1454,1459],{"type":44,"tag":355,"props":1433,"children":1434},{"style":904},[1435],{"type":49,"value":1390},{"type":44,"tag":355,"props":1437,"children":1438},{"style":884},[1439],{"type":49,"value":1440}," [purpose 1] ",{"type":44,"tag":355,"props":1442,"children":1443},{"style":904},[1444],{"type":49,"value":1390},{"type":44,"tag":355,"props":1446,"children":1447},{"style":884},[1448],{"type":49,"value":1449}," [Contract \u002F LI \u002F Consent \u002F etc.] ",{"type":44,"tag":355,"props":1451,"children":1452},{"style":904},[1453],{"type":49,"value":1390},{"type":44,"tag":355,"props":1455,"children":1456},{"style":884},[1457],{"type":49,"value":1458}," [if LI: balancing test summary; if consent: how obtained] ",{"type":44,"tag":355,"props":1460,"children":1461},{"style":904},[1462],{"type":49,"value":1418},{"type":44,"tag":355,"props":1464,"children":1466},{"class":879,"line":1465},36,[1467],{"type":44,"tag":355,"props":1468,"children":1469},{"emptyLinePlaceholder":894},[1470],{"type":49,"value":897},{"type":44,"tag":355,"props":1472,"children":1474},{"class":879,"line":1473},37,[1475],{"type":44,"tag":355,"props":1476,"children":1477},{"style":884},[1478],{"type":49,"value":1085},{"type":44,"tag":355,"props":1480,"children":1482},{"class":879,"line":1481},38,[1483],{"type":44,"tag":355,"props":1484,"children":1485},{"emptyLinePlaceholder":894},[1486],{"type":49,"value":897},{"type":44,"tag":355,"props":1488,"children":1490},{"class":879,"line":1489},39,[1491,1495],{"type":44,"tag":355,"props":1492,"children":1493},{"style":904},[1494],{"type":49,"value":1102},{"type":44,"tag":355,"props":1496,"children":1497},{"style":910},[1498],{"type":49,"value":1499},"3. Data flow\n",{"type":44,"tag":355,"props":1501,"children":1503},{"class":879,"line":1502},40,[1504],{"type":44,"tag":355,"props":1505,"children":1506},{"emptyLinePlaceholder":894},[1507],{"type":49,"value":897},{"type":44,"tag":355,"props":1509,"children":1511},{"class":879,"line":1510},41,[1512,1516,1521,1525],{"type":44,"tag":355,"props":1513,"children":1514},{"style":928},[1515],{"type":49,"value":931},{"type":44,"tag":355,"props":1517,"children":1518},{"style":934},[1519],{"type":49,"value":1520},"Collection:",{"type":44,"tag":355,"props":1522,"children":1523},{"style":928},[1524],{"type":49,"value":931},{"type":44,"tag":355,"props":1526,"children":1527},{"style":884},[1528],{"type":49,"value":1529}," [how\u002Fwhere data enters]\n",{"type":44,"tag":355,"props":1531,"children":1533},{"class":879,"line":1532},42,[1534,1538,1543,1547],{"type":44,"tag":355,"props":1535,"children":1536},{"style":928},[1537],{"type":49,"value":931},{"type":44,"tag":355,"props":1539,"children":1540},{"style":934},[1541],{"type":49,"value":1542},"Storage:",{"type":44,"tag":355,"props":1544,"children":1545},{"style":928},[1546],{"type":49,"value":931},{"type":44,"tag":355,"props":1548,"children":1549},{"style":884},[1550],{"type":49,"value":1551}," [system, region, encryption]\n",{"type":44,"tag":355,"props":1553,"children":1555},{"class":879,"line":1554},43,[1556,1560,1565,1569],{"type":44,"tag":355,"props":1557,"children":1558},{"style":928},[1559],{"type":49,"value":931},{"type":44,"tag":355,"props":1561,"children":1562},{"style":934},[1563],{"type":49,"value":1564},"Access:",{"type":44,"tag":355,"props":1566,"children":1567},{"style":928},[1568],{"type":49,"value":931},{"type":44,"tag":355,"props":1570,"children":1571},{"style":884},[1572],{"type":49,"value":1573}," [who, via what controls]\n",{"type":44,"tag":355,"props":1575,"children":1577},{"class":879,"line":1576},44,[1578,1582,1587,1591],{"type":44,"tag":355,"props":1579,"children":1580},{"style":928},[1581],{"type":49,"value":931},{"type":44,"tag":355,"props":1583,"children":1584},{"style":934},[1585],{"type":49,"value":1586},"Sharing:",{"type":44,"tag":355,"props":1588,"children":1589},{"style":928},[1590],{"type":49,"value":931},{"type":44,"tag":355,"props":1592,"children":1593},{"style":884},[1594],{"type":49,"value":1595}," [third parties, purpose, governed by which DPA]\n",{"type":44,"tag":355,"props":1597,"children":1599},{"class":879,"line":1598},45,[1600,1604,1609,1613],{"type":44,"tag":355,"props":1601,"children":1602},{"style":928},[1603],{"type":49,"value":931},{"type":44,"tag":355,"props":1605,"children":1606},{"style":934},[1607],{"type":49,"value":1608},"Retention:",{"type":44,"tag":355,"props":1610,"children":1611},{"style":928},[1612],{"type":49,"value":931},{"type":44,"tag":355,"props":1614,"children":1615},{"style":884},[1616],{"type":49,"value":1617}," [how long, deletion mechanism]\n",{"type":44,"tag":355,"props":1619,"children":1621},{"class":879,"line":1620},46,[1622],{"type":44,"tag":355,"props":1623,"children":1624},{"emptyLinePlaceholder":894},[1625],{"type":49,"value":897},{"type":44,"tag":355,"props":1627,"children":1629},{"class":879,"line":1628},47,[1630],{"type":44,"tag":355,"props":1631,"children":1632},{"style":904},[1633],{"type":49,"value":1085},{"type":44,"tag":355,"props":1635,"children":1637},{"class":879,"line":1636},48,[1638],{"type":44,"tag":355,"props":1639,"children":1640},{"emptyLinePlaceholder":894},[1641],{"type":49,"value":897},{"type":44,"tag":355,"props":1643,"children":1645},{"class":879,"line":1644},49,[1646,1650],{"type":44,"tag":355,"props":1647,"children":1648},{"style":904},[1649],{"type":49,"value":1102},{"type":44,"tag":355,"props":1651,"children":1652},{"style":910},[1653],{"type":49,"value":1654},"4. Privacy policy consistency\n",{"type":44,"tag":355,"props":1656,"children":1658},{"class":879,"line":1657},50,[1659],{"type":44,"tag":355,"props":1660,"children":1661},{"emptyLinePlaceholder":894},[1662],{"type":49,"value":897},{"type":44,"tag":355,"props":1664,"children":1666},{"class":879,"line":1665},51,[1667,1671,1676,1680,1685,1689,1693],{"type":44,"tag":355,"props":1668,"children":1669},{"style":904},[1670],{"type":49,"value":1390},{"type":44,"tag":355,"props":1672,"children":1673},{"style":884},[1674],{"type":49,"value":1675}," Policy commitment ",{"type":44,"tag":355,"props":1677,"children":1678},{"style":904},[1679],{"type":49,"value":1390},{"type":44,"tag":355,"props":1681,"children":1682},{"style":884},[1683],{"type":49,"value":1684}," Consistent? ",{"type":44,"tag":355,"props":1686,"children":1687},{"style":904},[1688],{"type":49,"value":1390},{"type":44,"tag":355,"props":1690,"children":1691},{"style":884},[1692],{"type":49,"value":1413},{"type":44,"tag":355,"props":1694,"children":1695},{"style":904},[1696],{"type":49,"value":1418},{"type":44,"tag":355,"props":1698,"children":1700},{"class":879,"line":1699},52,[1701],{"type":44,"tag":355,"props":1702,"children":1703},{"style":904},[1704],{"type":49,"value":1427},{"type":44,"tag":355,"props":1706,"children":1708},{"class":879,"line":1707},53,[1709,1713,1718,1722,1727,1731],{"type":44,"tag":355,"props":1710,"children":1711},{"style":904},[1712],{"type":49,"value":1390},{"type":44,"tag":355,"props":1714,"children":1715},{"style":884},[1716],{"type":49,"value":1717}," [commitment from config CLAUDE.md privacy policy section] ",{"type":44,"tag":355,"props":1719,"children":1720},{"style":904},[1721],{"type":49,"value":1390},{"type":44,"tag":355,"props":1723,"children":1724},{"style":884},[1725],{"type":49,"value":1726}," 🟢 \u002F 🟡 ",{"type":44,"tag":355,"props":1728,"children":1729},{"style":904},[1730],{"type":49,"value":1390},{"type":44,"tag":355,"props":1732,"children":1733},{"style":904},[1734],{"type":49,"value":1735}," |\n",{"type":44,"tag":355,"props":1737,"children":1739},{"class":879,"line":1738},54,[1740],{"type":44,"tag":355,"props":1741,"children":1742},{"emptyLinePlaceholder":894},[1743],{"type":49,"value":897},{"type":44,"tag":355,"props":1745,"children":1747},{"class":879,"line":1746},55,[1748],{"type":44,"tag":355,"props":1749,"children":1750},{"style":884},[1751],{"type":49,"value":1752},"[If any 🟡: policy update needed before launch, or processing needs to change]\n",{"type":44,"tag":355,"props":1754,"children":1756},{"class":879,"line":1755},56,[1757],{"type":44,"tag":355,"props":1758,"children":1759},{"emptyLinePlaceholder":894},[1760],{"type":49,"value":897},{"type":44,"tag":355,"props":1762,"children":1764},{"class":879,"line":1763},57,[1765],{"type":44,"tag":355,"props":1766,"children":1767},{"style":904},[1768],{"type":49,"value":1085},{"type":44,"tag":355,"props":1770,"children":1772},{"class":879,"line":1771},58,[1773],{"type":44,"tag":355,"props":1774,"children":1775},{"emptyLinePlaceholder":894},[1776],{"type":49,"value":897},{"type":44,"tag":355,"props":1778,"children":1780},{"class":879,"line":1779},59,[1781,1785],{"type":44,"tag":355,"props":1782,"children":1783},{"style":904},[1784],{"type":49,"value":1102},{"type":44,"tag":355,"props":1786,"children":1787},{"style":910},[1788],{"type":49,"value":1789},"5. Risks and mitigations\n",{"type":44,"tag":355,"props":1791,"children":1793},{"class":879,"line":1792},60,[1794],{"type":44,"tag":355,"props":1795,"children":1796},{"emptyLinePlaceholder":894},[1797],{"type":49,"value":897},{"type":44,"tag":355,"props":1799,"children":1801},{"class":879,"line":1800},61,[1802,1806,1811,1815,1820,1824,1829,1833,1838,1842,1847,1851,1856,1860,1865],{"type":44,"tag":355,"props":1803,"children":1804},{"style":904},[1805],{"type":49,"value":1390},{"type":44,"tag":355,"props":1807,"children":1808},{"style":884},[1809],{"type":49,"value":1810}," # ",{"type":44,"tag":355,"props":1812,"children":1813},{"style":904},[1814],{"type":49,"value":1390},{"type":44,"tag":355,"props":1816,"children":1817},{"style":884},[1818],{"type":49,"value":1819}," Risk ",{"type":44,"tag":355,"props":1821,"children":1822},{"style":904},[1823],{"type":49,"value":1390},{"type":44,"tag":355,"props":1825,"children":1826},{"style":884},[1827],{"type":49,"value":1828}," Likelihood ",{"type":44,"tag":355,"props":1830,"children":1831},{"style":904},[1832],{"type":49,"value":1390},{"type":44,"tag":355,"props":1834,"children":1835},{"style":884},[1836],{"type":49,"value":1837}," Impact ",{"type":44,"tag":355,"props":1839,"children":1840},{"style":904},[1841],{"type":49,"value":1390},{"type":44,"tag":355,"props":1843,"children":1844},{"style":884},[1845],{"type":49,"value":1846}," Mitigation ",{"type":44,"tag":355,"props":1848,"children":1849},{"style":904},[1850],{"type":49,"value":1390},{"type":44,"tag":355,"props":1852,"children":1853},{"style":884},[1854],{"type":49,"value":1855}," Status ",{"type":44,"tag":355,"props":1857,"children":1858},{"style":904},[1859],{"type":49,"value":1390},{"type":44,"tag":355,"props":1861,"children":1862},{"style":884},[1863],{"type":49,"value":1864}," Owner ",{"type":44,"tag":355,"props":1866,"children":1867},{"style":904},[1868],{"type":49,"value":1418},{"type":44,"tag":355,"props":1870,"children":1872},{"class":879,"line":1871},62,[1873],{"type":44,"tag":355,"props":1874,"children":1875},{"style":904},[1876],{"type":49,"value":1877},"|---|---|---|---|---|---|---|\n",{"type":44,"tag":355,"props":1879,"children":1881},{"class":879,"line":1880},63,[1882,1886,1891,1895,1900,1904,1909,1913,1917,1921,1926,1930,1935,1939,1943,1947,1951],{"type":44,"tag":355,"props":1883,"children":1884},{"style":904},[1885],{"type":49,"value":1390},{"type":44,"tag":355,"props":1887,"children":1888},{"style":884},[1889],{"type":49,"value":1890}," 1 ",{"type":44,"tag":355,"props":1892,"children":1893},{"style":904},[1894],{"type":49,"value":1390},{"type":44,"tag":355,"props":1896,"children":1897},{"style":884},[1898],{"type":49,"value":1899}," [specific risk, tied to the design — not \"data breach\" generically] ",{"type":44,"tag":355,"props":1901,"children":1902},{"style":904},[1903],{"type":49,"value":1390},{"type":44,"tag":355,"props":1905,"children":1906},{"style":884},[1907],{"type":49,"value":1908}," L\u002FM\u002FH ",{"type":44,"tag":355,"props":1910,"children":1911},{"style":904},[1912],{"type":49,"value":1390},{"type":44,"tag":355,"props":1914,"children":1915},{"style":884},[1916],{"type":49,"value":1908},{"type":44,"tag":355,"props":1918,"children":1919},{"style":904},[1920],{"type":49,"value":1390},{"type":44,"tag":355,"props":1922,"children":1923},{"style":884},[1924],{"type":49,"value":1925}," [specific control] ",{"type":44,"tag":355,"props":1927,"children":1928},{"style":904},[1929],{"type":49,"value":1390},{"type":44,"tag":355,"props":1931,"children":1932},{"style":884},[1933],{"type":49,"value":1934}," Done \u002F Planned \u002F Gap ",{"type":44,"tag":355,"props":1936,"children":1937},{"style":904},[1938],{"type":49,"value":1390},{"type":44,"tag":355,"props":1940,"children":1941},{"style":904},[1942],{"type":49,"value":946},{"type":44,"tag":355,"props":1944,"children":1945},{"style":949},[1946],{"type":49,"value":952},{"type":44,"tag":355,"props":1948,"children":1949},{"style":904},[1950],{"type":49,"value":957},{"type":44,"tag":355,"props":1952,"children":1953},{"style":904},[1954],{"type":49,"value":1735},{"type":44,"tag":355,"props":1956,"children":1958},{"class":879,"line":1957},64,[1959],{"type":44,"tag":355,"props":1960,"children":1961},{"emptyLinePlaceholder":894},[1962],{"type":49,"value":897},{"type":44,"tag":355,"props":1964,"children":1966},{"class":879,"line":1965},65,[1967,1971,1976,1980,1984,1989],{"type":44,"tag":355,"props":1968,"children":1969},{"style":928},[1970],{"type":49,"value":931},{"type":44,"tag":355,"props":1972,"children":1973},{"style":934},[1974],{"type":49,"value":1975},"Residual risk after mitigations:",{"type":44,"tag":355,"props":1977,"children":1978},{"style":928},[1979],{"type":49,"value":931},{"type":44,"tag":355,"props":1981,"children":1982},{"style":904},[1983],{"type":49,"value":946},{"type":44,"tag":355,"props":1985,"children":1986},{"style":949},[1987],{"type":49,"value":1988},"assessment",{"type":44,"tag":355,"props":1990,"children":1991},{"style":904},[1992],{"type":49,"value":1068},{"type":44,"tag":355,"props":1994,"children":1996},{"class":879,"line":1995},66,[1997],{"type":44,"tag":355,"props":1998,"children":1999},{"emptyLinePlaceholder":894},[2000],{"type":49,"value":897},{"type":44,"tag":355,"props":2002,"children":2004},{"class":879,"line":2003},67,[2005],{"type":44,"tag":355,"props":2006,"children":2007},{"style":904},[2008],{"type":49,"value":1085},{"type":44,"tag":355,"props":2010,"children":2012},{"class":879,"line":2011},68,[2013],{"type":44,"tag":355,"props":2014,"children":2015},{"emptyLinePlaceholder":894},[2016],{"type":49,"value":897},{"type":44,"tag":355,"props":2018,"children":2020},{"class":879,"line":2019},69,[2021,2025],{"type":44,"tag":355,"props":2022,"children":2023},{"style":904},[2024],{"type":49,"value":1102},{"type":44,"tag":355,"props":2026,"children":2027},{"style":910},[2028],{"type":49,"value":2029},"6. Data subject rights\n",{"type":44,"tag":355,"props":2031,"children":2033},{"class":879,"line":2032},70,[2034],{"type":44,"tag":355,"props":2035,"children":2036},{"emptyLinePlaceholder":894},[2037],{"type":49,"value":897},{"type":44,"tag":355,"props":2039,"children":2041},{"class":879,"line":2040},71,[2042,2046,2051,2055,2060,2064,2069],{"type":44,"tag":355,"props":2043,"children":2044},{"style":904},[2045],{"type":49,"value":1390},{"type":44,"tag":355,"props":2047,"children":2048},{"style":884},[2049],{"type":49,"value":2050}," Right ",{"type":44,"tag":355,"props":2052,"children":2053},{"style":904},[2054],{"type":49,"value":1390},{"type":44,"tag":355,"props":2056,"children":2057},{"style":884},[2058],{"type":49,"value":2059}," Can be exercised? ",{"type":44,"tag":355,"props":2061,"children":2062},{"style":904},[2063],{"type":49,"value":1390},{"type":44,"tag":355,"props":2065,"children":2066},{"style":884},[2067],{"type":49,"value":2068}," How ",{"type":44,"tag":355,"props":2070,"children":2071},{"style":904},[2072],{"type":49,"value":1418},{"type":44,"tag":355,"props":2074,"children":2076},{"class":879,"line":2075},72,[2077],{"type":44,"tag":355,"props":2078,"children":2079},{"style":904},[2080],{"type":49,"value":1427},{"type":44,"tag":355,"props":2082,"children":2084},{"class":879,"line":2083},73,[2085,2089,2094,2098,2103],{"type":44,"tag":355,"props":2086,"children":2087},{"style":904},[2088],{"type":49,"value":1390},{"type":44,"tag":355,"props":2090,"children":2091},{"style":884},[2092],{"type":49,"value":2093}," Access ",{"type":44,"tag":355,"props":2095,"children":2096},{"style":904},[2097],{"type":49,"value":1390},{"type":44,"tag":355,"props":2099,"children":2100},{"style":904},[2101],{"type":49,"value":2102}," |",{"type":44,"tag":355,"props":2104,"children":2105},{"style":904},[2106],{"type":49,"value":1735},{"type":44,"tag":355,"props":2108,"children":2110},{"class":879,"line":2109},74,[2111,2115,2120,2124,2128],{"type":44,"tag":355,"props":2112,"children":2113},{"style":904},[2114],{"type":49,"value":1390},{"type":44,"tag":355,"props":2116,"children":2117},{"style":884},[2118],{"type":49,"value":2119}," Deletion ",{"type":44,"tag":355,"props":2121,"children":2122},{"style":904},[2123],{"type":49,"value":1390},{"type":44,"tag":355,"props":2125,"children":2126},{"style":904},[2127],{"type":49,"value":2102},{"type":44,"tag":355,"props":2129,"children":2130},{"style":904},[2131],{"type":49,"value":1735},{"type":44,"tag":355,"props":2133,"children":2135},{"class":879,"line":2134},75,[2136,2140,2145,2149,2153],{"type":44,"tag":355,"props":2137,"children":2138},{"style":904},[2139],{"type":49,"value":1390},{"type":44,"tag":355,"props":2141,"children":2142},{"style":884},[2143],{"type":49,"value":2144}," Correction ",{"type":44,"tag":355,"props":2146,"children":2147},{"style":904},[2148],{"type":49,"value":1390},{"type":44,"tag":355,"props":2150,"children":2151},{"style":904},[2152],{"type":49,"value":2102},{"type":44,"tag":355,"props":2154,"children":2155},{"style":904},[2156],{"type":49,"value":1735},{"type":44,"tag":355,"props":2158,"children":2160},{"class":879,"line":2159},76,[2161,2165,2170,2174,2178],{"type":44,"tag":355,"props":2162,"children":2163},{"style":904},[2164],{"type":49,"value":1390},{"type":44,"tag":355,"props":2166,"children":2167},{"style":884},[2168],{"type":49,"value":2169}," Portability ",{"type":44,"tag":355,"props":2171,"children":2172},{"style":904},[2173],{"type":49,"value":1390},{"type":44,"tag":355,"props":2175,"children":2176},{"style":904},[2177],{"type":49,"value":2102},{"type":44,"tag":355,"props":2179,"children":2180},{"style":904},[2181],{"type":49,"value":1735},{"type":44,"tag":355,"props":2183,"children":2185},{"class":879,"line":2184},77,[2186,2190,2195,2199,2203],{"type":44,"tag":355,"props":2187,"children":2188},{"style":904},[2189],{"type":49,"value":1390},{"type":44,"tag":355,"props":2191,"children":2192},{"style":884},[2193],{"type":49,"value":2194}," Objection ",{"type":44,"tag":355,"props":2196,"children":2197},{"style":904},[2198],{"type":49,"value":1390},{"type":44,"tag":355,"props":2200,"children":2201},{"style":904},[2202],{"type":49,"value":2102},{"type":44,"tag":355,"props":2204,"children":2205},{"style":904},[2206],{"type":49,"value":1735},{"type":44,"tag":355,"props":2208,"children":2210},{"class":879,"line":2209},78,[2211],{"type":44,"tag":355,"props":2212,"children":2213},{"emptyLinePlaceholder":894},[2214],{"type":49,"value":897},{"type":44,"tag":355,"props":2216,"children":2218},{"class":879,"line":2217},79,[2219],{"type":44,"tag":355,"props":2220,"children":2221},{"style":884},[2222],{"type":49,"value":1085},{"type":44,"tag":355,"props":2224,"children":2226},{"class":879,"line":2225},80,[2227],{"type":44,"tag":355,"props":2228,"children":2229},{"emptyLinePlaceholder":894},[2230],{"type":49,"value":897},{"type":44,"tag":355,"props":2232,"children":2234},{"class":879,"line":2233},81,[2235,2239],{"type":44,"tag":355,"props":2236,"children":2237},{"style":904},[2238],{"type":49,"value":1102},{"type":44,"tag":355,"props":2240,"children":2241},{"style":910},[2242],{"type":49,"value":2243},"7. Recommendation\n",{"type":44,"tag":355,"props":2245,"children":2247},{"class":879,"line":2246},82,[2248],{"type":44,"tag":355,"props":2249,"children":2250},{"emptyLinePlaceholder":894},[2251],{"type":49,"value":897},{"type":44,"tag":355,"props":2253,"children":2255},{"class":879,"line":2254},83,[2256],{"type":44,"tag":355,"props":2257,"children":2258},{"style":884},[2259],{"type":49,"value":2260},"[APPROVED \u002F APPROVED WITH CONDITIONS \u002F CHANGES REQUIRED \u002F NOT APPROVED]\n",{"type":44,"tag":355,"props":2262,"children":2264},{"class":879,"line":2263},84,[2265],{"type":44,"tag":355,"props":2266,"children":2267},{"emptyLinePlaceholder":894},[2268],{"type":49,"value":897},{"type":44,"tag":355,"props":2270,"children":2272},{"class":879,"line":2271},85,[2273,2277,2282],{"type":44,"tag":355,"props":2274,"children":2275},{"style":928},[2276],{"type":49,"value":931},{"type":44,"tag":355,"props":2278,"children":2279},{"style":934},[2280],{"type":49,"value":2281},"Conditions (if any):",{"type":44,"tag":355,"props":2283,"children":2284},{"style":928},[2285],{"type":49,"value":2286},"**\n",{"type":44,"tag":355,"props":2288,"children":2290},{"class":879,"line":2289},86,[2291,2296],{"type":44,"tag":355,"props":2292,"children":2293},{"style":904},[2294],{"type":49,"value":2295},"-",{"type":44,"tag":355,"props":2297,"children":2298},{"style":884},[2299],{"type":49,"value":2300}," [ ] [specific thing that has to happen before launch]\n",{"type":44,"tag":355,"props":2302,"children":2304},{"class":879,"line":2303},87,[2305],{"type":44,"tag":355,"props":2306,"children":2307},{"emptyLinePlaceholder":894},[2308],{"type":49,"value":897},{"type":44,"tag":355,"props":2310,"children":2312},{"class":879,"line":2311},88,[2313,2317,2322,2326],{"type":44,"tag":355,"props":2314,"children":2315},{"style":928},[2316],{"type":49,"value":931},{"type":44,"tag":355,"props":2318,"children":2319},{"style":934},[2320],{"type":49,"value":2321},"Sign-off:",{"type":44,"tag":355,"props":2323,"children":2324},{"style":928},[2325],{"type":49,"value":931},{"type":44,"tag":355,"props":2327,"children":2328},{"style":884},[2329],{"type":49,"value":2330}," [name, date]\n",{"type":44,"tag":127,"props":2332,"children":2334},{"id":2333},"risk-quality-standards",[2335],{"type":49,"value":2336},"Risk quality standards",{"type":44,"tag":134,"props":2338,"children":2339},{},[2340,2342,2347],{"type":49,"value":2341},"Risks in a PIA should be ",{"type":44,"tag":138,"props":2343,"children":2344},{},[2345],{"type":49,"value":2346},"specific and tied to the design",{"type":49,"value":2348},", not generic. Bad risks pad the document and train readers to skim.",{"type":44,"tag":2350,"props":2351,"children":2352},"table",{},[2353,2377],{"type":44,"tag":2354,"props":2355,"children":2356},"thead",{},[2357],{"type":44,"tag":2358,"props":2359,"children":2360},"tr",{},[2361,2367,2372],{"type":44,"tag":2362,"props":2363,"children":2364},"th",{},[2365],{"type":49,"value":2366},"Bad risk",{"type":44,"tag":2362,"props":2368,"children":2369},{},[2370],{"type":49,"value":2371},"Why bad",{"type":44,"tag":2362,"props":2373,"children":2374},{},[2375],{"type":49,"value":2376},"Better",{"type":44,"tag":2378,"props":2379,"children":2380},"tbody",{},[2381,2400,2426],{"type":44,"tag":2358,"props":2382,"children":2383},{},[2384,2390,2395],{"type":44,"tag":2385,"props":2386,"children":2387},"td",{},[2388],{"type":49,"value":2389},"\"Data breach\"",{"type":44,"tag":2385,"props":2391,"children":2392},{},[2393],{"type":49,"value":2394},"Applies to everything; says nothing",{"type":44,"tag":2385,"props":2396,"children":2397},{},[2398],{"type":49,"value":2399},"\"Location history accessible by support staff via the admin panel without audit logging — a malicious insider could track a user undetected\"",{"type":44,"tag":2358,"props":2401,"children":2402},{},[2403,2408,2421],{"type":44,"tag":2385,"props":2404,"children":2405},{},[2406],{"type":49,"value":2407},"\"Non-compliance with GDPR\"",{"type":44,"tag":2385,"props":2409,"children":2410},{},[2411,2413,2419],{"type":49,"value":2412},"Circular — the PIA is supposed to ",{"type":44,"tag":2414,"props":2415,"children":2416},"em",{},[2417],{"type":49,"value":2418},"assess",{"type":49,"value":2420}," compliance",{"type":44,"tag":2385,"props":2422,"children":2423},{},[2424],{"type":49,"value":2425},"Name the specific article and the gap",{"type":44,"tag":2358,"props":2427,"children":2428},{},[2429,2434,2439],{"type":44,"tag":2385,"props":2430,"children":2431},{},[2432],{"type":49,"value":2433},"\"Users might not like it\"",{"type":44,"tag":2385,"props":2435,"children":2436},{},[2437],{"type":49,"value":2438},"Vague",{"type":44,"tag":2385,"props":2440,"children":2441},{},[2442],{"type":49,"value":2443},"\"Users who opted out of marketing may still receive this because the opt-out flag isn't checked in this flow\"",{"type":44,"tag":134,"props":2445,"children":2446},{},[2447],{"type":49,"value":2448},"Aim for 2-5 real risks, not 15 padded ones.",{"type":44,"tag":127,"props":2450,"children":2452},{"id":2451},"privacy-policy-diff",[2453],{"type":49,"value":2454},"Privacy policy diff",{"type":44,"tag":134,"props":2456,"children":2457},{},[2458,2460,2465],{"type":49,"value":2459},"Every PIA should cross-check against the privacy policy commitments in ",{"type":44,"tag":62,"props":2461,"children":2463},{"className":2462},[],[2464],{"type":49,"value":67},{"type":49,"value":2466},". The common drift:",{"type":44,"tag":287,"props":2468,"children":2469},{},[2470,2475,2480],{"type":44,"tag":56,"props":2471,"children":2472},{},[2473],{"type":49,"value":2474},"Policy says \"we collect X, Y, Z\" — new feature collects W. Policy needs updating, or stop collecting W.",{"type":44,"tag":56,"props":2476,"children":2477},{},[2478],{"type":49,"value":2479},"Policy says \"we don't sell data\" — new feature shares with an ad partner. That might be a CCPA sale.",{"type":44,"tag":56,"props":2481,"children":2482},{},[2483],{"type":49,"value":2484},"Policy says retention is \"as long as your account is active\" — new feature keeps data post-deletion.",{"type":44,"tag":134,"props":2486,"children":2487},{},[2488],{"type":49,"value":2489},"Flag every mismatch. One of them has to change before launch.",{"type":44,"tag":127,"props":2491,"children":2493},{"id":2492},"handoff",[2494],{"type":49,"value":2495},"Handoff",{"type":44,"tag":287,"props":2497,"children":2498},{},[2499,2516,2526],{"type":44,"tag":56,"props":2500,"children":2501},{},[2502,2507,2509,2514],{"type":44,"tag":138,"props":2503,"children":2504},{},[2505],{"type":49,"value":2506},"To product team:",{"type":49,"value":2508}," Conditions list with owners and deadlines. Not \"improve security\" — \"add audit logging to the admin panel's location lookup, owner: ",{"type":44,"tag":355,"props":2510,"children":2511},{},[2512],{"type":49,"value":2513},"eng lead",{"type":49,"value":2515},", before launch.\"",{"type":44,"tag":56,"props":2517,"children":2518},{},[2519,2524],{"type":44,"tag":138,"props":2520,"children":2521},{},[2522],{"type":49,"value":2523},"To reg-gap-analysis skill:",{"type":49,"value":2525}," If the PIA uncovered a policy inconsistency, that skill tracks the policy update.",{"type":44,"tag":56,"props":2527,"children":2528},{},[2529,2534,2536,2541],{"type":44,"tag":138,"props":2530,"children":2531},{},[2532],{"type":49,"value":2533},"To the sign-off process:",{"type":49,"value":2535}," Per ",{"type":44,"tag":62,"props":2537,"children":2539},{"className":2538},[],[2540],{"type":49,"value":67},{"type":49,"value":2542}," → who approves PIAs.",{"type":44,"tag":127,"props":2544,"children":2546},{"id":2545},"gate-submitting-a-dpia-to-a-regulator",[2547],{"type":49,"value":2548},"Gate: submitting a DPIA to a regulator",{"type":44,"tag":134,"props":2550,"children":2551},{},[2552,2554,2559],{"type":49,"value":2553},"Producing an internal PIA is research and documentation. ",{"type":44,"tag":2414,"props":2555,"children":2556},{},[2557],{"type":49,"value":2558},"Submitting a DPIA to a supervisory authority",{"type":49,"value":2560}," — or voluntarily disclosing one to a regulator in response to an inquiry — is the consequential act.",{"type":44,"tag":134,"props":2562,"children":2563},{},[2564,2569,2571,2576,2578,2583],{"type":44,"tag":138,"props":2565,"children":2566},{},[2567],{"type":49,"value":2568},"Before proceeding to submit a DPIA (or any equivalent impact assessment) to a regulator, supervisory authority, or enforcement body:",{"type":49,"value":2570}," Read ",{"type":44,"tag":62,"props":2572,"children":2574},{"className":2573},[],[2575],{"type":49,"value":865},{"type":49,"value":2577}," in ",{"type":44,"tag":62,"props":2579,"children":2581},{"className":2580},[],[2582],{"type":49,"value":67},{"type":49,"value":2584},". If the Role is Non-lawyer:",{"type":44,"tag":346,"props":2586,"children":2587},{},[2588,2593,2601],{"type":44,"tag":134,"props":2589,"children":2590},{},[2591],{"type":49,"value":2592},"Submitting to a regulator has legal consequences — the document becomes part of the supervisory record and any material omission or error becomes enforcement exposure. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:",{"type":44,"tag":134,"props":2594,"children":2595},{},[2596],{"type":44,"tag":355,"props":2597,"children":2598},{},[2599],{"type":49,"value":2600},"Generate a 1-page summary: regime and regulator, why a submission is being made (mandatory trigger or voluntary), the risks identified, residual risk after mitigations, any flagged uncertainty, and the three things to ask the attorney before filing.",{"type":44,"tag":134,"props":2602,"children":2603},{},[2604],{"type":49,"value":2605},"If you need to find a licensed attorney, solicitor, barrister, or other authorised legal professional in your jurisdiction: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA\u002FBar Standards Board in England & Wales, Law Society in Scotland\u002FNI\u002FIreland\u002FCanada\u002FAustralia, or your jurisdiction's equivalent).",{"type":44,"tag":134,"props":2607,"children":2608},{},[2609],{"type":49,"value":2610},"Do not proceed past this gate without an explicit yes.",{"type":44,"tag":127,"props":2612,"children":2614},{"id":2613},"close-with-the-next-steps-decision-tree",[2615],{"type":49,"value":2616},"Close with the next-steps decision tree",{"type":44,"tag":134,"props":2618,"children":2619},{},[2620,2622,2627],{"type":49,"value":2621},"End with the next-steps decision tree per CLAUDE.md ",{"type":44,"tag":62,"props":2623,"children":2625},{"className":2624},[],[2626],{"type":49,"value":283},{"type":49,"value":2628},". Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.",{"type":44,"tag":127,"props":2630,"children":2632},{"id":2631},"what-this-skill-does-not-do",[2633],{"type":49,"value":2634},"What this skill does not do",{"type":44,"tag":287,"props":2636,"children":2637},{},[2638,2643,2648],{"type":44,"tag":56,"props":2639,"children":2640},{},[2641],{"type":49,"value":2642},"It doesn't approve the processing. A human signs the PIA.",{"type":44,"tag":56,"props":2644,"children":2645},{},[2646],{"type":49,"value":2647},"It doesn't write a DPIA for a supervisory authority — that's a more formal document with specific regulatory requirements. This is the internal assessment.",{"type":44,"tag":56,"props":2649,"children":2650},{},[2651],{"type":49,"value":2652},"It doesn't design the mitigation. It describes what needs mitigating; engineering designs the fix.",{"type":44,"tag":2654,"props":2655,"children":2656},"style",{},[2657],{"type":49,"value":2658},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"items":2660,"total":2754},[2661,2673,2690,2707,2719,2730,2741],{"slug":2662,"name":2662,"fn":2663,"description":2664,"org":2665,"tags":2666,"stars":26,"repoUrl":27,"updatedAt":2672},"ai-inventory","track AI systems for EU AI Act","EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer, distributor, authorized representative, product manufacturer) and risk tier (prohibited, high-risk, limited, minimal, GPAI, GPAI+systemic). Role and tier are assessed per system, not per company. Use when the user says \"ai inventory\", \"add an ai system\", \"what systems do we have\", \"classify this ai system\", \"eu ai act register\", or \"ai system registry\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2667,2668,2671],{"name":14,"slug":15,"type":16},{"name":2669,"slug":2670,"type":16},"Governance","governance",{"name":21,"slug":22,"type":16},"2026-05-14T06:02:19.677579",{"slug":2674,"name":2674,"fn":2675,"description":2676,"org":2677,"tags":2678,"stars":26,"repoUrl":27,"updatedAt":2689},"ai-tool-handoff","manage handoff to bulk legal review tools","Detects when Luminance, Kira, or a similar bulk-review tool is in use, hands off the high-volume clause extraction to it, and QAs its output per the trust level in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fcorporate-legal\u002FCLAUDE.md`. Use when user says \"send to Luminance\", \"bulk review\", \"AI extraction\", or when diligence-issue-extraction hits a high-volume category.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2679,2682,2685,2686],{"name":2680,"slug":2681,"type":16},"Automation","automation",{"name":2683,"slug":2684,"type":16},"Contracts","contracts",{"name":21,"slug":22,"type":16},{"name":2687,"slug":2688,"type":16},"QA","qa","2026-05-14T06:01:31.00555",{"slug":2691,"name":2691,"fn":2692,"description":2693,"org":2694,"tags":2695,"stars":26,"repoUrl":27,"updatedAt":2706},"aia-generation","run AI impact assessments","Run an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommendation with conditions. Uses the house-style structure learned from the seed impact assessment in `~\u002F.claude\u002Fplugins\u002Fconfig\u002Fclaude-for-legal\u002Fai-governance-legal\u002FCLAUDE.md`. Use when user says \"impact assessment for\", \"assess this AI use case\", \"run an AIA\", \"generate an AIA\", \"we need to document this AI system\", \"AI risk assessment for X\", or follows a conditional triage result.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2696,2697,2700,2703],{"name":21,"slug":22,"type":16},{"name":2698,"slug":2699,"type":16},"Policy","policy",{"name":2701,"slug":2702,"type":16},"Regulatory Compliance","regulatory-compliance",{"name":2704,"slug":2705,"type":16},"Risk Assessment","risk-assessment","2026-05-13T06:03:19.61029",{"slug":2708,"name":2708,"fn":2709,"description":2710,"org":2711,"tags":2712,"stars":26,"repoUrl":27,"updatedAt":2718},"amendment-history","trace contract amendment history","Trace how a contract has changed across its base agreement and all amendments — either a summary of all changes over time, or a provision trace for a specific clause. Use when the user says \"what changed in this contract over time\", \"show me the amendment history\", \"where's the latest [clause]\", \"how has [provision] evolved\", or uploads multiple versions of an agreement.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2713,2714,2717],{"name":2683,"slug":2684,"type":16},{"name":2715,"slug":2716,"type":16},"Documents","documents",{"name":21,"slug":22,"type":16},"2026-05-13T06:03:34.070339",{"slug":2720,"name":2720,"fn":2721,"description":2722,"org":2723,"tags":2724,"stars":26,"repoUrl":27,"updatedAt":2729},"auto-updater","check for community skill updates","Check installed community skills for updates. Shows a diff and requires explicit approval before applying. Use when the user says \"check for updates\", \"update my skills\", \"anything new for my installed skills\", or when invoked from the registry-sync agent.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2725,2726],{"name":2680,"slug":2681,"type":16},{"name":2727,"slug":2728,"type":16},"Plugin Development","plugin-development","2026-05-13T06:02:55.642269",{"slug":2731,"name":2731,"fn":2732,"description":2733,"org":2734,"tags":2735,"stars":26,"repoUrl":27,"updatedAt":2740},"bar-prep-questions","provide bar exam practice questions","Bar prep questions — MBE or essay, targeted at your weak subjects and bar jurisdiction. Tracks misses and comes back to patterns. Use when the user says \"bar prep\", \"MBE questions\", \"practice essay\", or \"test me for the bar\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2736,2739],{"name":2737,"slug":2738,"type":16},"Education","education",{"name":21,"slug":22,"type":16},"2026-07-24T05:41:43.01243",{"slug":2742,"name":2742,"fn":2743,"description":2744,"org":2745,"tags":2746,"stars":26,"repoUrl":27,"updatedAt":2753},"board-minutes","draft board and committee meeting minutes","Drafts board or committee meeting minutes in your house format. Auto-detects upcoming board and committee meetings from your calendar, asks for the agenda and any slides or pre-read materials, and produces a complete draft in the format learned from your seed minutes. Also handles written consents in lieu of meetings. Trigger: \"board minutes\", \"draft minutes\", \"upcoming board meeting\", \"committee minutes\", \"written consent\", or calendar detection of an upcoming board or committee event.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2747,2748,2749,2750],{"name":18,"slug":19,"type":16},{"name":2669,"slug":2670,"type":16},{"name":21,"slug":22,"type":16},{"name":2751,"slug":2752,"type":16},"Meetings","meetings","2026-05-14T06:01:29.792942",118,{"items":2756,"total":2939},[2757,2778,2792,2804,2823,2834,2853,2873,2887,2902,2910,2923],{"slug":2758,"name":2758,"fn":2759,"description":2760,"org":2761,"tags":2762,"stars":2775,"repoUrl":2776,"updatedAt":2777},"algorithmic-art","create algorithmic art with p5.js","Creating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems. Create original algorithmic art rather than copying existing artists' work to avoid copyright violations.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2763,2766,2769,2772],{"name":2764,"slug":2765,"type":16},"Creative","creative",{"name":2767,"slug":2768,"type":16},"Design","design",{"name":2770,"slug":2771,"type":16},"Generative Art","generative-art",{"name":2773,"slug":2774,"type":16},"JavaScript","javascript",161831,"https:\u002F\u002Fgithub.com\u002Fanthropics\u002Fskills","2026-04-06T17:56:15.455818",{"slug":2779,"name":2779,"fn":2780,"description":2781,"org":2782,"tags":2783,"stars":2775,"repoUrl":2776,"updatedAt":2791},"brand-guidelines","apply Anthropic brand colors and typography","Applies Anthropic's official brand colors and typography to any sort of artifact that may benefit from having Anthropic's look-and-feel. Use it when brand colors or style guidelines, visual formatting, or company design standards apply.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2784,2787,2788],{"name":2785,"slug":2786,"type":16},"Branding","branding",{"name":2767,"slug":2768,"type":16},{"name":2789,"slug":2790,"type":16},"Typography","typography","2026-04-06T17:56:05.042852",{"slug":2793,"name":2793,"fn":2794,"description":2795,"org":2796,"tags":2797,"stars":2775,"repoUrl":2776,"updatedAt":2803},"canvas-design","create posters and visual art as PNG or PDF","Create beautiful visual art in .png and .pdf documents using design philosophy. You should use this skill when the user asks to create a poster, piece of art, design, or other static piece. Create original visual designs, never copying existing artists' work to avoid copyright violations.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2798,2799,2800],{"name":2764,"slug":2765,"type":16},{"name":2767,"slug":2768,"type":16},{"name":2801,"slug":2802,"type":16},"PDF","pdf","2026-04-06T17:56:03.794732",{"slug":2805,"name":2805,"fn":2806,"description":2807,"org":2808,"tags":2809,"stars":2775,"repoUrl":2776,"updatedAt":2822},"claude-api","build apps with the Claude API","Reference for the Claude API \u002F Anthropic SDK — model ids, pricing, params, streaming, tool use, MCP, agents, caching, token counting, model migration.\nTRIGGER — read BEFORE opening the target file; don't skip because it \"looks like a one-liner\" — whenever: the prompt names Claude\u002FAnthropic in any form (Claude, Anthropic, Fable, Opus, Sonnet, Haiku, `anthropic`, `@anthropic-ai`, `claude-*`, `us.anthropic.*`, `[1m]`); the user asks about an LLM (pricing\u002Fmodel choice\u002Flimits\u002Fcaching) — never answer from memory; OR the task is LLM-shaped with provider unstated (agent\u002FMCP\u002Ftool-definition\u002Fmulti-agent\u002FRAG\u002FLLM-judge\u002Fcomputer-use; generate\u002Fsummarize\u002Fextract\u002Fclassify\u002Frewrite\u002Fconverse over NL; debugging refusals\u002Fcutoffs\u002Fstreaming\u002Ftool-calls\u002Ftokens).\nSKIP only when another provider is being worked on (overrides all triggers): OpenAI\u002FGPT\u002FGemini\u002FLlama\u002FMistral\u002FCohere\u002FOllama named in the query; OR `grep -rE 'openai|langchain_openai|google.generativeai|genai|mistralai|cohere|ollama'` over the project hits (run this grep FIRST if no provider named — don't Read the file).",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2810,2813,2814,2817,2819],{"name":2811,"slug":2812,"type":16},"Agents","agents",{"name":9,"slug":8,"type":16},{"name":2815,"slug":2816,"type":16},"Anthropic SDK","anthropic-sdk",{"name":2818,"slug":2805,"type":16},"Claude API",{"name":2820,"slug":2821,"type":16},"LLM","llm","2026-07-28T05:36:08.213335",{"slug":2824,"name":2824,"fn":2825,"description":2826,"org":2827,"tags":2828,"stars":2775,"repoUrl":2776,"updatedAt":2833},"doc-coauthoring","co-author documentation and technical specs","Guide users through a structured workflow for co-authoring documentation. Use when user wants to write documentation, proposals, technical specs, decision docs, or similar structured content. This workflow helps users efficiently transfer context, refine content through iteration, and verify the doc works for readers. Trigger when user mentions writing docs, creating proposals, drafting specs, or similar documentation tasks.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2829,2830],{"name":18,"slug":19,"type":16},{"name":2831,"slug":2832,"type":16},"Technical Writing","technical-writing","2026-04-06T17:56:14.18897",{"slug":2835,"name":2835,"fn":2836,"description":2837,"org":2838,"tags":2839,"stars":2775,"repoUrl":2776,"updatedAt":2852},"docx","create and edit Word documents","Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when extracting or reorganizing content from .docx or .dotx files, inserting or replacing images in documents, performing find-and-replace in Word files, working with tracked changes or comments, or converting content into a polished Word document. If the user asks for a 'report', 'memo', 'letter', 'template', or similar deliverable as a Word or .docx file, use this skill. Do NOT use for PDFs, spreadsheets, Google Docs, or general coding tasks unrelated to document generation.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2840,2841,2843,2846,2849],{"name":2715,"slug":2716,"type":16},{"name":2842,"slug":2835,"type":16},"DOCX",{"name":2844,"slug":2845,"type":16},"Office","office",{"name":2847,"slug":2848,"type":16},"Templates","templates",{"name":2850,"slug":2851,"type":16},"Word","word","2026-07-18T05:16:23.136271",{"slug":2854,"name":2854,"fn":2855,"description":2856,"org":2857,"tags":2858,"stars":2775,"repoUrl":2776,"updatedAt":2872},"frontend-design","design production-grade frontend interfaces","Guidance for distinctive, intentional visual design when building new UI or reshaping an existing one. Helps with aesthetic direction, typography, and making choices that don't read as templated defaults.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2859,2860,2863,2866,2869],{"name":2767,"slug":2768,"type":16},{"name":2861,"slug":2862,"type":16},"Frontend","frontend",{"name":2864,"slug":2865,"type":16},"React","react",{"name":2867,"slug":2868,"type":16},"Tailwind CSS","tailwind-css",{"name":2870,"slug":2871,"type":16},"UI Components","ui-components","2026-04-06T17:56:16.723469",{"slug":2874,"name":2874,"fn":2875,"description":2876,"org":2877,"tags":2878,"stars":2775,"repoUrl":2776,"updatedAt":2886},"internal-comms","write internal company communications","A set of resources to help me write all kinds of internal communications, using the formats that my company likes to use. Claude should use this skill whenever asked to write some sort of internal communications (status reports, leadership updates, 3P updates, company newsletters, FAQs, incident reports, project updates, etc.).",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2879,2882,2883],{"name":2880,"slug":2881,"type":16},"Communications","communications",{"name":2847,"slug":2848,"type":16},{"name":2884,"slug":2885,"type":16},"Writing","writing","2026-04-06T17:56:20.695522",{"slug":2888,"name":2888,"fn":2889,"description":2890,"org":2891,"tags":2892,"stars":2775,"repoUrl":2776,"updatedAt":2901},"mcp-builder","build MCP servers","Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node\u002FTypeScript (MCP SDK).",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2893,2894,2897,2898],{"name":2811,"slug":2812,"type":16},{"name":2895,"slug":2896,"type":16},"API Development","api-development",{"name":2820,"slug":2821,"type":16},{"name":2899,"slug":2900,"type":16},"MCP","mcp","2026-04-06T17:56:10.357665",{"slug":2802,"name":2802,"fn":2903,"description":2904,"org":2905,"tags":2906,"stars":2775,"repoUrl":2776,"updatedAt":2909},"read edit and manipulate PDF files","Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text\u002Ftables from PDFs, combining or merging multiple PDFs into one, splitting PDFs apart, rotating pages, adding watermarks, creating new PDFs, filling PDF forms, encrypting\u002Fdecrypting PDFs, extracting images, and OCR on scanned PDFs to make them searchable. If the user mentions a .pdf file or asks to produce one, use this skill.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2907,2908],{"name":2715,"slug":2716,"type":16},{"name":2801,"slug":2802,"type":16},"2026-04-06T17:56:02.483316",{"slug":2911,"name":2911,"fn":2912,"description":2913,"org":2914,"tags":2915,"stars":2775,"repoUrl":2776,"updatedAt":2922},"pptx","create and edit PowerPoint presentations","Use this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an email or summary); editing, modifying, or updating existing presentations; combining or splitting slide files; working with templates (.potx), layouts, speaker notes, or comments. Trigger whenever the user mentions \"deck,\" \"slides,\" \"presentation,\" or references a .pptx or .potx filename, regardless of what they plan to do with the content afterward. If a .pptx or .potx file needs to be opened, created, or touched, use this skill.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2916,2919],{"name":2917,"slug":2918,"type":16},"PowerPoint","powerpoint",{"name":2920,"slug":2921,"type":16},"Presentations","presentations","2026-07-18T05:16:24.1471",{"slug":2924,"name":2924,"fn":2925,"description":2926,"org":2927,"tags":2928,"stars":2775,"repoUrl":2776,"updatedAt":2938},"skill-creator","create and optimize agent skills","Create new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with variance analysis, or optimize a skill's description for better triggering accuracy.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2929,2930,2931,2934,2937],{"name":2811,"slug":2812,"type":16},{"name":18,"slug":19,"type":16},{"name":2932,"slug":2933,"type":16},"Evals","evals",{"name":2935,"slug":2936,"type":16},"Performance","performance",{"name":2831,"slug":2832,"type":16},"2026-04-19T06:45:40.804",490]