privacy-impact-assessment-review

Run privacy impact assessments for new features, data collection, analytics, AI processing, profiling, vendors, retention, consent, legal basis, minimization, sensitive data, children/regulated users, DSAR, cross-border transfer, security controls, mitigations, launch gates, and record keeping. Use when product changes may affect personal data or user trust.

sylphxai/skills38 installsMITSynced Aug 26

Works with

Claude CodeCursorCodex CLIGitHub CopilotGemini CLI
---
name: privacy-impact-assessment-review
description: Run privacy impact assessments for new features, data collection, analytics, AI processing, profiling, vendors, retention, consent, legal basis, minimization, sensitive data, children/regulated users, DSAR, cross-border transfer, security controls, mitigations, launch gates, and record keeping. Use when product changes may affect personal data or user trust.
license: MIT
---

# Privacy Impact Assessment Review

Use this skill to convert privacy impact assessment, data processing, minimization, legal basis, vendor, retention, and mitigation questions into a concrete artifact with owners, gates, metrics, and recovery paths.

## Workflow

1. Identify feature scope, user groups, data collected, purpose, legal basis, vendors, AI/analytics use, retention, sharing, region, sensitive data, and user controls.
2. Read `references/privacy-impact-assessment-patterns.md`.
3. Classify processing as low-risk routine, consent-sensitive, vendor/subprocessor, AI/profiling, cross-border transfer, sensitive data, child/regulated, or high-risk DPIA-needed.
4. Define data map, minimization, notice/consent, access controls, retention/deletion, DSAR path, risk mitigations, launch gate, and record of decision.
5. Produce PIA report, state machine, decision table, event schema, risk checklist, and mitigation plan.

## When not to use

- Do not use for generic advice the base model already handles without this skill's specific artifact contract.

## Guardrails

- Do not collect personal data because it is convenient; tie each field to purpose, retention, and user value.
- Do not rely on consent, legitimate interest, or contract language without jurisdiction and context review.
- Do not ship AI/profiling, sensitive-data, or child/regulated-user processing without elevated review.
- Do not treat privacy review as a one-time launch checkbox when data flows, vendors, or purposes change.

## Output format

```text
PIA context:
Audience / source of truth / risk boundary:

Privacy assessment plan:
| Area | Decision | Evidence | Risk | Owner |
| --- | --- | --- | --- | --- |

Risks, mitigations, and launch gates:
- <trigger> -> <policy, metric, edge case, support note>
```

More Performance skills

seo-audit

coreyhaines31/marketingskills

When the user wants to audit, review, or diagnose SEO issues on their site. Also use when the user mentions "SEO audit," "technical SEO," "why am I not ranking," "SEO issues," "on-page SEO," "meta tags review," "SEO health check," "my traffic dropped," "lost rankings," "not showing up in Google," "site isn't ranking," "Google update hit me," "page speed," "core web vitals," "crawl errors," or "indexing issues." Use this even if the user just says something vague like "my SEO is bad" or "help with SEO" — start with an audit. For building pages at scale to target keywords, see programmatic-seo. For adding structured data, see schema. For AI search optimization, see ai-seo.

195.1k

competitor-profiling

coreyhaines31/marketingskills

When the user wants to research, profile, or analyze competitors from their URLs. Also use when the user mentions 'competitor profile,' 'competitor research,' 'competitor analysis,' 'profile this competitor,' 'analyze competitor,' 'competitive intelligence,' 'competitor deep dive,' 'who are my competitors,' 'competitor landscape,' 'competitor dossier,' 'competitive audit,' or 'research these competitors.' Input is a list of competitor URLs. Output is structured competitor profile markdown files. For creating comparison/alternative pages from profiles, see competitors. For sales-specific battle cards, see sales-enablement.

65.8k

vercel-optimize

vercel-labs/agent-skills

Use for Vercel cost and performance optimization on deployed projects, especially Next.js, SvelteKit, Nuxt, and limited Astro apps. Collect Vercel metrics, usage, project config, and code scan results first; investigate only metric-backed candidates; produce ranked recommendations grounded in verified files and version-aware Vercel/framework docs. Trigger for Vercel bill reduction, slow or expensive routes, caching opportunities, Function Invocations, Build Minutes, Fast Data Transfer, Core Web Vitals, Bot Management, Fluid compute, or cost breakdown requests.

59.3k

← All Performance skills

Check your AI visibility

One URL in, a 0–100 score and the exact fixes out.

RUN THE CHECK

Browse all the tools

15 tools across six categories
13 of them never send your data anywhere

Free · No signup · No trial clock

SEE THE DIRECTORY