Use this skill when a change introduces or alters personal data processing, user-rights workflows, retention behavior, subprocessors, cross-border transfers, default privacy posture, or third-party data exposure risk.
- feature spec, issue, or diff
- affected data flows and systems
- relevant files in
docs/04-privacy-gdpr/
- vendors or processors involved
Workflow
- Identify the personal-data processing activity affected.
- Check whether the processor or controller role is explicit and whether the processing should appear in the processor RoPA.
- Check whether the data inventory and lawful basis are explicit.
- Check retention, deletion, export, end-of-contract handling, and data-subject-rights impacts.
- Check processor, subprocessor, transfer, and cleartext-access implications.
- Check whether third-party code, tracking, or telemetry could leak personal data.
- Check whether the change may trigger a DPIA.
- Report missing artifacts, unresolved privacy risks, and required updates.
Output