research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Data Protection Impact Assessment (DPIA) guidance and execution
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/dpiaContext preview
What this command does when you run it.
Data Protection Impact Assessment (DPIA) guidance and execution
description: Data Protection Impact Assessment (DPIA) guidance and execution
Guides the execution of a Data Protection Impact Assessment as required by GDPR Article 35.
Article 35(3) mandates DPIA for processing likely to result in **high risk**, particularly:
1. **Systematic and Extensive Profiling**
2. **Large-Scale Processing of Special Categories**
3. **Systematic Monitoring of Public Areas**
DPIA recommended when processing meets **2+ criteria**:
DPIA **not required** when:
**Determine if DPIA required**:
**Output**: Go/No-Go decision with justification
**Systematic description including**:
**Key Questions**:
**Evaluate**:
**Data Protection by Design and Default** (Article 25):
**Identify Risks to Data Subjects**:
**Risk Categories**:
1. **Illegal access** (data breach, hacking) 2. **Unwanted modification** (data alteration, corruption) 3. **Disappearance** (data loss, deletion) 4. **Disclosure** (unauthorized sharing, surveillance)
**Risk to Rights and Freedoms**:
**Risk Assessment Matrix**:
| Severity | Likelihood | Risk Level | Action Required | |----------|-----------|------------|-----------------| | High | Likely | Critical | Must mitigate before processing | | High | Possible | High | Strong mitigation required | | Medium | Likely | High | Strong mitigation required | | Medium | Possible | Moderate | Mitigation recommended | | Low | Unlikely | Low | Accept or basic mitigation |
**For Each Risk**:
**Identify and Implement Safeguards**:
**Technical Measures**:
**Organizational Measures**:
**Governance Measures**:
**Residual Risk**:
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.