Description
The DPIA Draft produces the structured draft of a Data Protection Impact Assessment under Article 35 GDPR: description of the processing, necessity and proportionality assessment, risk analysis, plan of measures, and recommendation in a single pass. The skill is built for controllers facing a processing activity that is likely to result in high risk, for example the everyday use of AI systems (ChatGPT and comparable tools), profiling, or scoring, who want to hand their data protection officer a solid working basis instead of a blank page.
The skill works from an implementation perspective, not as an expert opinion: it structures what belongs in a DPIA, consistently separates mandatory measures from recommendations, and explicitly flags missing facts as assumptions instead of silently filling them in. It replaces neither the substantive review by the data protection officer nor a legal assessment.
Deliberate boundary: the tool makes no legally binding statement on the lawfulness of a processing activity and does not conclusively assess any individual case. It delivers the draft; approval remains with the data protection officer.
Note: this tool does not replace legal advice. Have any results with legal implications reviewed by a lawyer before you act on them.




