← Rohas Legal AI: PrivacyCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Rohas Legal AI: Privacy
Snapshot Sep 30, 2026 · 23:14 UTC · version 0.2.2
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Screen, conduct, and document data-protection or privacy impact assessments for new or changed processing. Use when evaluating necessity, proportionality, high-risk triggers, risks to people, automated decisions, sensitive data, children, monitoring, new technology, safeguards, and residual-risk approval.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 326
}
],
"name": "dpia-documenter",
"skill_md_contents": "---\nname: dpia-documenter\ndescription: >-\n Screen, conduct, and document data-protection or privacy impact assessments\n for new or changed processing. Use when evaluating necessity, proportionality,\n high-risk triggers, risks to people, automated decisions, sensitive data,\n children, monitoring, new technology, safeguards, and residual-risk approval.\n---\n\n# DPIA Documenter\n\nComplete the assessment before high-risk processing begins and revisit it when\npurpose, data, technology, scale, recipients, threat, law, or safeguards change.\n\n## Intake\n\nObtain the proposal and decision owner, jurisdictions, processing purpose,\nbusiness outcome, data-flow and architecture, parties and roles, data and people,\nsources, scale, frequency, matching, monitoring, profiling, automated decisions,\nAI models, biometrics, children, locations, transfers, retention, security,\nalternatives, prior assessments, incidents, and stakeholder views.\n\n## Assessment method\n\n1. Record the screening decision against current law, regulator lists, sector\n rules, and organisation thresholds. Explain both required and not-required outcomes.\n2. Describe the full lifecycle: collect, generate, infer, combine, use, access,\n disclose, transfer, retain, archive, delete, and train or evaluate models.\n3. Identify roles, legal bases or permissions, notices, consent, rights, contracts,\n secrecy, localisation, and governance dependencies.\n4. Test necessity: connect each data element and operation to a specific outcome\n and identify less intrusive means.\n5. Test proportionality: purpose compatibility, minimisation, accuracy, access,\n retention, transparency, choice, contestability, human review, and fairness.\n6. Assess risk from the individual's perspective, including surveillance,\n exclusion, bias, denial of opportunity, manipulation, exposure, identity harm,\n financial loss, safety, confidentiality, autonomy, and chilling effects.\n7. Score likelihood and severity before controls using explained criteria, not\n unsupported arithmetic.\n8. Document existing and proposed technical, contractual, organisational, and\n product safeguards, evidence, owner, due date, and test method.\n9. Reassess residual risk, record accepted assumptions and dissent, consult the\n DPO, security, legal, affected groups, representatives, or regulator as required.\n10. Obtain accountable approval, conditions, launch gates, monitoring metrics,\n incident triggers, review date, and stop or reassessment criteria.\n\n## Output\n\nProvide the screening record, processing and data-flow description, stakeholder\nconsultation, necessity and proportionality analysis, risk register, safeguard\nplan, residual-risk decision, approval record, and monitoring schedule.\n\n## Guardrails\n\nDo not use a DPIA to legitimise unlawful processing, hide unresolved high risk,\nor substitute organisational impact for harm to people. Do not claim\nanonymisation without technical evidence. Escalate residual high risk and obtain\nrequired prior consultation before launch.\n"
}SHA-256 of public snapshot: fec529526688d11d10e9e56772afdd04321c3f8f2897472bf5898941c8b0f4ad