{
  "slug": "dsfa-expose",
  "category": "skill",
  "name": "The DPIA Draft",
  "domaene": "Recht & Compliance",
  "typTags": [
    "strukturierend",
    "analytisch"
  ],
  "teaser": "The DPIA Draft turns a description of a processing activity into a structured Data Protection Impact Assessment draft under Article 35 GDPR, complete with a risk analysis, a measures plan, and a recommendation for your data protection officer.",
  "hat": {
    "schritte": true,
    "beispiel_szenario": true,
    "ausgabebeispiel": false,
    "konfiguration": false,
    "betrieb": false,
    "arbeitsprompts": false,
    "einrichtung": true,
    "umsetzung": true,
    "export": false,
    "staerken": false,
    "ki_funktionen": false,
    "einschraenkungen": false,
    "weniger_geeignet_fuer": false
  },
  "sections": [
    {
      "id": "description",
      "title": "Description",
      "html": "<p>The DPIA Draft produces the structured draft of a Data Protection Impact Assessment under Article 35 GDPR: description of the processing, necessity and proportionality assessment, risk analysis, plan of measures, and recommendation in a single pass. The skill is built for controllers facing a processing activity that is likely to result in high risk, for example the everyday use of AI systems (ChatGPT and comparable tools), profiling, or scoring, who want to hand their data protection officer a solid working basis instead of a blank page.</p>\n<p>The skill works from an implementation perspective, not as an expert opinion: it structures what belongs in a DPIA, consistently separates mandatory measures from recommendations, and explicitly flags missing facts as assumptions instead of silently filling them in. It replaces neither the substantive review by the data protection officer nor a legal assessment.</p>\n<p>Deliberate boundary: the tool makes no legally binding statement on the lawfulness of a processing activity and does not conclusively assess any individual case. It delivers the draft; approval remains with the data protection officer.</p>\n<p>Note: this tool does not replace legal advice. Have any results with legal implications reviewed by a lawyer before you act on them.</p>\n"
    },
    {
      "id": "skill-text",
      "title": "Skill Text",
      "html": "<p>Copy the prompt below in full into your AI tool. As a file: <a href=\"/ai-library/dsfa-expose.en.json\">dsfa-expose.en.json</a></p>\n"
    }
  ],
  "schritte": [
    {
      "nr": 1,
      "titel": "Describe the processing activity",
      "beschreibung": "The data processing, categories of data affected, purpose, and technical systems in use are provided.",
      "rolle": "mensch"
    },
    {
      "nr": 2,
      "titel": "Document the processing",
      "beschreibung": "The nature, scope, context, and purpose of the processing are systematically recorded, the legal basis and proportionality are assessed.",
      "rolle": "automatisch"
    },
    {
      "nr": 3,
      "titel": "Identify and assess risks",
      "beschreibung": "Potential risks to the rights of data subjects are identified and assessed by likelihood and severity.",
      "rolle": "automatisch"
    },
    {
      "nr": 4,
      "titel": "Protective measures and residual risk",
      "beschreibung": "Existing technical and organizational measures are recorded, additional measures are recommended, and the residual risk after the measures are implemented is assessed.",
      "rolle": "automatisch"
    },
    {
      "nr": 5,
      "titel": "Receive the DPIA draft",
      "beschreibung": "The complete draft is ready: description of the processing, risk assessment, plan of measures, and a recommendation of approval, adjustment, or consultation with the supervisory authority.",
      "rolle": "ergebnis"
    }
  ],
  "herausgeber": "Voyage Digital",
  "version": "2.0",
  "stand": "2026-07-26",
  "umsetzung": [
    {
      "titel": "Copy the skill text",
      "text": "The skill text is pasted into the AI tool of choice, and the processing activity is described as specifically as possible."
    },
    {
      "titel": "Add existing measures",
      "text": "Technical and organizational measures already in place are added, which makes the assessment more realistic."
    },
    {
      "titel": "Have the result reviewed",
      "text": "The draft is submitted to the data protection officer for review before the processing is approved."
    }
  ],
  "zutaten": [
    "Processing activity",
    "Categories of data and data subjects affected",
    "Purpose of the processing",
    "Technical systems"
  ],
  "beispielSzenario": "A company is planning to introduce an AI-supported applicant management system. The skill produces the DPIA from this: a description of the processing covering data categories, data subjects, and systems in use, six identified risks ranging from discrimination to data leaks with an assessment matrix, existing and recommended protective measures, a residual risk assessment at the medium level, and the recommendation to consult the data protection officer.",
  "eingaben": [
    {
      "feld": "Processing activity",
      "pflicht": true
    },
    {
      "feld": "Categories of data and data subjects affected",
      "pflicht": true
    },
    {
      "feld": "Purpose of the processing",
      "pflicht": true
    },
    {
      "feld": "Technical systems and service providers",
      "pflicht": true
    },
    {
      "feld": "Existing protective measures",
      "pflicht": false
    },
    {
      "feld": "Legal basis",
      "pflicht": false
    }
  ],
  "ausgabe": "A complete DPIA draft with a description of the processing, necessity and proportionality assessment, risk identification and assessment, existing and recommended measures, a residual risk assessment, and a clear recommendation of approval, adjustment, or consultation with the supervisory authority.",
  "prompt": "# DESCRIPTION\nProduces the structured draft of a Data Protection Impact Assessment (DPIA) under Article 35 GDPR. Analyzes risks to the rights of data subjects and derives appropriate protective measures from them. Address the user in a professional manner throughout.\n\n# INPUT\n- Processing activity: what is being processed, including the use of AI systems such as ChatGPT, Copilot, or comparable tools, where these play a role in the processing\n- Categories of data and data subjects affected\n- Purpose of the processing\n- Technical systems and service providers\n- Optional: existing protective measures, legal basis\n\n# OUTPUT\nComplete DPIA draft:\n1. Description of the processing: nature, scope, context, purpose\n2. Necessity and proportionality: assessment under Article 35\n3. Risk identification: potential risks to data subjects\n4. Risk assessment: likelihood times severity\n5. Existing measures: technical and organizational measures (TOMs) already in place\n6. Additional measures: recommended protective measures, clearly separated from mandatory measures and optional recommendations\n7. Residual risk assessment: risk remaining after the measures are implemented\n8. Recommendation: approval, adjustment, or consultation with the supervisory authority\n\n# CONTEXT\n- This DPIA does not replace a legal review by the data protection officer (DPO) or legal advice. It provides the professional draft as a starting point.\n- The risk assessment is carried out consistently from the perspective of the data subjects, not the company.\n- TOMs are the core of every risk mitigation effort.\n- Particularly relevant for profiling, video surveillance, scoring, and the use of AI, including everyday use of AI tools such as ChatGPT, where personal data is processed.\n- Where facts about the processing are missing, the assistant explicitly flags its assumptions as an assumption and asks for clarification where needed, instead of silently filling them in.\n\n# WORKING INSTRUCTIONS\n## Step 1: Describe the processing activity\nSystematically document the nature, scope, context, and purpose of the data processing.\n\n## Step 2: Assess necessity and proportionality\nEvaluate the legal basis and proportionality of the processing.\n\n## Step 3: Identify and assess risks\nIdentify potential risks to the rights of data subjects and assess them by likelihood times severity.\n\n## Step 4: Document protective measures\nRecord existing TOMs and recommend additional protective measures, clearly marked as mandatory or recommended.\n\n## Step 5: Assess residual risk and formulate a recommendation\nAssess the risk remaining after the measures are implemented and give a clear recommendation (approval, adjustment, or consultation).\n\n# QUALITY CONTROL\n[ ] Processing fully described\n[ ] All relevant risks identified and assessed\n[ ] Measures concrete, appropriate, and separated into mandatory and recommended\n[ ] Residual risk assessment documented\n[ ] Clear recommendation formulated\n[ ] Note on the boundary to legal advice and the review by the DPO included\n[ ] Missing facts flagged as assumptions\n\n# CONVERSATION START\nWhich processing activity do you need a DPIA for? Describe the data processing, the categories of data affected, and the purpose. I will use this to create a structured impact assessment for you. Note: this draft does not replace a review by your data protection officer.",
  "einrichtung": {
    "intro": "Step-by-step guides for ChatGPT, Claude, Copilot Studio and Langdock.",
    "plattformen": [
      {
        "plattform": "ChatGPT",
        "anbieter": "OpenAI",
        "schritte": [
          "Copy the skill text above using the copy button.",
          "Click your profile picture and select \"Skills\".",
          "Click \"Create skill\" and paste the copied text as the instruction.",
          "Adjust inputs, outputs and format where your case requires it.",
          "Save the skill. It is available in all chats from that point on."
        ],
        "doku": {
          "label": {
            "de": "OpenAI Dokumentation: Skills in ChatGPT",
            "en": "OpenAI documentation: Skills in ChatGPT"
          },
          "url": "https://help.openai.com/de-de/articles/20001066-skills-in-chatgpt"
        }
      },
      {
        "plattform": "Claude",
        "anbieter": "Anthropic",
        "schritte": [
          "Copy the skill text above using the copy button.",
          "Open claude.ai and go to \"Skills\" in your profile.",
          "Create a new skill and paste the copied text as the instruction.",
          "The skill works in claude.ai, in Claude Code and through the API.",
          "Available on the Pro, Max, Team and Enterprise plans."
        ],
        "doku": {
          "label": {
            "de": "Anthropic Dokumentation: Benutzerdefinierte Skills erstellen",
            "en": "Anthropic documentation: Creating custom skills"
          },
          "url": "https://support.claude.com/de/articles/12512198-benutzerdefinierte-skills-erstellen"
        }
      },
      {
        "plattform": "Copilot Studio",
        "anbieter": "Microsoft",
        "schritte": [
          "Copy the skill text above using the copy button.",
          "Open Copilot Studio and create a new agent.",
          "Paste the copied text as the instruction.",
          "Connect knowledge sources and tools where needed.",
          "Publish the agent for yourself or for your organisation."
        ],
        "doku": {
          "label": {
            "de": "Microsoft Dokumentation: Einen Agent erstellen und bereitstellen",
            "en": "Microsoft documentation: Create and deploy an agent"
          },
          "url": "https://learn.microsoft.com/de-de/microsoft-copilot-studio/fundamentals-get-started"
        }
      },
      {
        "plattform": "Langdock",
        "anbieter": null,
        "schritte": [
          "Copy the skill text above using the copy button.",
          "Open the sidebar and click \"Add skill\".",
          "Paste the copied text directly as the instruction.",
          "Connect the skill to integrations such as Gmail or Slack where needed.",
          "Save the skill and release it for yourself or your team."
        ],
        "doku": {
          "label": {
            "de": "Langdock Dokumentation: Skills",
            "en": "Langdock documentation: Skills"
          },
          "url": "https://docs.langdock.com/de/product/chat/skills"
        }
      }
    ]
  },
  "itemIcon": "shield-alert",
  "recommended": [
    {
      "slug": "vertrags-sichter",
      "category": "assistent",
      "name": "The Contract Screener",
      "teaser": "The Contract Screener reviews a contract before signing, ranks its key clauses by risk, and gives executives a structured basis for the decision and the negotiation.",
      "domaene": "Recht & Compliance",
      "itemIcon": "file-signature"
    },
    {
      "slug": "compliance-regelwerk",
      "category": "skill",
      "name": "The Compliance Rulebook",
      "teaser": "The Compliance Rulebook turns regulatory requirements into a structured, plain-language compliance policy complete with rules, responsibilities and reporting channels, ready for legal review before it takes effect.",
      "domaene": "Recht & Compliance",
      "itemIcon": "gavel"
    },
    {
      "slug": "vertragsrisiko-kette",
      "category": "workflow",
      "name": "The Contract Risk Chain",
      "teaser": "An automation workflow that reads new contracts on arrival, extracts key terms, and files a structured high, medium and low risk assessment for the responsible team to review.",
      "domaene": "Recht & Compliance",
      "itemIcon": "file-warning"
    },
    {
      "slug": "datenschutz-pruefer",
      "category": "assistent",
      "name": "The Data Protection Reviewer",
      "teaser": "Checks vendor and AI tool data protection documents against GDPR, rates risks with a traffic light system, and delivers concrete renegotiation points.",
      "domaene": "Recht & Compliance",
      "itemIcon": "shield-check"
    },
    {
      "slug": "eu-ai-act-lotse",
      "category": "assistent",
      "name": "The EU AI Act Navigator",
      "teaser": "Classifies AI use cases under the EU AI Act into the appropriate risk category and shows small and mid-sized companies the obligations and next steps that follow, while clearly separating settled law from interpretation.",
      "domaene": "Recht & Compliance",
      "itemIcon": "landmark"
    },
    {
      "slug": "vertragsrisiko-pruefer",
      "category": "assistent",
      "name": "The Contract Risk Reviewer",
      "teaser": "Reviews contract texts before signing, flags the five most critical risks, and gives a concrete recommended action for each.",
      "domaene": "Recht & Compliance",
      "itemIcon": "file-warning"
    },
    {
      "slug": "kundentermin-protokoll",
      "category": "skill",
      "name": "The Client Meeting Protocol",
      "teaser": "Turns notes or a transcript from a client meeting into a structured protocol with a BANT or MEDDIC opportunity analysis, action items, and a follow-up email draft.",
      "domaene": "Vertrieb & Outreach",
      "itemIcon": "notebook-pen"
    },
    {
      "slug": "pipeline-protokoll",
      "category": "skill",
      "name": "The Pipeline Protocol",
      "teaser": "Systematically checks your CRM pipeline, flags deals that need action, and delivers a compact report with metrics and prioritized next steps.",
      "domaene": "Vertrieb & Outreach",
      "itemIcon": "git-branch"
    },
    {
      "slug": "call-analyst",
      "category": "assistent",
      "name": "The Call Analyst",
      "teaser": "Turns call notes or a sales call transcript into a CRM-ready follow-up document with needs analysis, BANT assessment and a scheduled follow-up plan.",
      "domaene": "Vertrieb & Outreach",
      "itemIcon": "phone-call"
    },
    {
      "slug": "claude-video",
      "category": "tool",
      "name": "claude-video",
      "teaser": "claude-video is a video analysis pipeline that downloads videos, extracts frames, and produces transcripts so Claude can answer targeted questions about individual scenes.",
      "domaene": "Medienproduktion"
    }
  ]
}