Help us improve
Share bugs, ideas, or general feedback.
From privacy-impact-assessment-skills
Compares PIA/DPIA methodologies: CNIL tool, ICO template, NIST Privacy Framework, ISO 29134. Guides selection by regulatory jurisdiction, org maturity, processing complexity, resources.
npx claudepluginhub mukul975/privacy-data-protection-skills --plugin privacy-impact-assessment-skillsHow this skill is triggered — by the user, by Claude, or both
Slash command
/privacy-impact-assessment-skills:comparing-pia-methodologiesThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Multiple established methodologies exist for conducting Privacy Impact Assessments: the CNIL PIA tool, ICO DPIA template, NIST Privacy Framework, and ISO/IEC 29134:2017. Each methodology reflects its originating regulatory context, organisational assumptions, and privacy philosophy. Selecting the appropriate methodology — or combining elements from several — is critical for producing assessment...
Compares PIA/DPIA methodologies: CNIL tool, ICO template, NIST Privacy Framework, ISO 29134. Guides selection by regulatory jurisdiction, org maturity, processing complexity, resources.
Automates privacy impact assessments: data flow mapping, privacy risk scoring, GDPR/CCPA compliance checks, data inventory cataloging, and remediation tracking. Implements NIST Privacy Framework PRAM and ICO DPIA guidance.
Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, risk scoring, GDPR/CCPA alignment checks, and remediation tracking.
Share bugs, ideas, or general feedback.
Multiple established methodologies exist for conducting Privacy Impact Assessments: the CNIL PIA tool, ICO DPIA template, NIST Privacy Framework, and ISO/IEC 29134:2017. Each methodology reflects its originating regulatory context, organisational assumptions, and privacy philosophy. Selecting the appropriate methodology — or combining elements from several — is critical for producing assessments that satisfy regulatory expectations, align with organisational maturity, and address the actual risks of the processing activity. This skill provides a structured comparison framework for methodology selection.
Origin: Commission Nationale de l'Informatique et des Libertes (CNIL), first published 2015, updated 2018 for GDPR alignment.
Structure:
Key Features:
Regulatory Acceptance:
Origin: Information Commissioner's Office (ICO), UK. Published as part of ICO GDPR guidance, updated for UK GDPR post-Brexit.
Structure:
Key Features:
Regulatory Acceptance:
Origin: National Institute of Standards and Technology (NIST), Version 1.0 published January 2020. Voluntary framework.
Structure:
Key Features:
Regulatory Acceptance:
Origin: International Organization for Standardization, published 2017. International standard.
Structure:
Key Features:
Regulatory Acceptance:
| Dimension | CNIL PIA | ICO DPIA | NIST PF | ISO 29134 |
|---|---|---|---|---|
| Regulatory origin | French DPA (CNIL) | UK DPA (ICO) | US NIST | International (ISO/IEC) |
| Legal framework | GDPR | UK GDPR | Sector-agnostic | International |
| Risk model | 3 feared events (CIA-adapted) | Harm to individuals | Organisation-defined | ISO 31000-based |
| Risk scale | 4x4 (Negligible to Maximum) | Qualitative (Low/Medium/High) | Organisation-defined tiers | Likelihood x Consequence |
| Steps/phases | 4 steps | 7 steps | 5 functions | 3 clauses (prep/execute/follow-up) |
| Data subject consultation | Recommended | Explicitly required (Step 3) | COMMUNICATE function | Required (Clause 6.4) |
| DPO involvement | Required | Required with advice recording | N/A (no DPO concept) | Recommended |
| Tool availability | Open-source software | Word template | Excel self-assessment | No official tool |
| Cost | Free | Free | Free | Standard purchase required (~CHF 166) |
| Certification alignment | None | None | NIST CSF alignment | ISO 27701, ISO 27001 |
| Typical completion time | 2-4 weeks | 1-3 weeks | Ongoing (framework) | 4-8 weeks |
| Best suited for | EU/GDPR processing, French-regulated entities | UK processing, practical quick-start | US organisations, framework-based programs | Multinational, auditable, certification-seeking |
| Factor | Weight | Considerations |
|---|---|---|
| Regulatory jurisdiction | High | Which supervisory authority will review the assessment? Use their preferred methodology. |
| Organisational maturity | Medium | Low maturity → ICO (simplest). Medium → CNIL. High → ISO 29134. |
| Processing complexity | Medium | Simple processing → ICO. Complex/high-risk → CNIL or ISO 29134. |
| International scope | High | Single jurisdiction → local DPA methodology. Multi-jurisdiction → ISO 29134. |
| Certification goals | Medium | Seeking ISO 27701 or Art. 42 certification → ISO 29134. |
| Resource availability | Medium | Limited resources → ICO. Dedicated privacy team → ISO 29134. |
| Existing framework | Low | Already using NIST CSF → add NIST PF. Already ISO 27001 → ISO 29134. |
| CNIL Step | ICO Step | NIST PF Function | ISO 29134 Clause |
|---|---|---|---|
| Step 1: Context | Step 2: Describe processing | ID.IM (Inventory & Mapping) | Clause 6: Preparation |
| — | Step 1: Identify need | — | Clause 6.1: Determine necessity |
| — | Step 3: Consultation | CT.PO (Communication Policies) | Clause 6.4: Stakeholder engagement |
| Step 2: Fundamental Principles | Step 4: Necessity & proportionality | GV.PO (Governance Policies) | Clause 7.3: Privacy safeguard analysis |
| Step 3: Risks | Step 5: Identify & assess risks | ID.RA (Risk Assessment) | Clause 7.4: Risk analysis |
| Step 4: Validation | Step 6: Mitigation measures | CT.DM (Data Processing Management) | Clause 7.5: Risk treatment |
| — | Step 7: Sign off & record | GV.AT (Awareness & Training) | Clause 8: Follow-up |