skills/arckit-ca-pia/SKILL.md
[COMMUNITY] Generate a Canada Privacy Impact Assessment per the Privacy Act and TBS Directive on Privacy Impact Assessment — personal-information inventory, lawful authority, necessity and proportionality, OPC notification trigger, and mitigation tracker.
npx skillsauth add tractorjuice/arckit-codex arckit-ca-piaInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified Canadian counsel and the relevant departmental authority (ATIP coordinator, ITSEC officer, OCHRO language lead, CIO branch) before reliance. Citations may lag current text — verify against the Justice Laws Website and the issuing TBS / CSE / OPC source.
$ARGUMENTS
You are an enterprise architect generating a Canada Privacy Impact Assessment (PIA) for a federal entity.
projects/000-global/ARC-000-PRIN-*.md (federal principles, if present).arckit/templates/_partials/RENDERING.md.arckit/templates-custom/ca-pia-template.md (user override).arckit/templates-custom/ca-pia-template.md.arckit/templates/ca-pia-template.mdscripts/bash/generate-document-id.sh <PROJECT_ID> PIA --filename for the artefact filename.<!-- DOC-CONTROL-HEADER --> marker per RENDERING.md. Use the Canadian classification scheme (UNCLASSIFIED / Protected A / Protected B / Protected C / CONFIDENTIAL / SECRET / TOP SECRET) — replace the standard UK line in the header.<TBC> and flag as a blocker for OPC notification — collection without statutory authority is not lawful.risk for the project-level register continuation.ca-cloud-residency..arckit/references/citation-instructions.md. The Privacy Act and the TBS Directive on Privacy Impact Assessment MUST appear in the Document Register with their primary URLs and verification dates.projects/<project-id>/<filename>.Privacy Act (R.S.C., 1985, c. P-21) and the TBS Directive on Privacy Impact Assessment (current version). Authority: Office of the Privacy Commissioner of Canada (OPC) for consultation and review; Treasury Board Secretariat for the Directive. Primary URL for the Privacy Act: https://laws-lois.justice.gc.ca/eng/acts/P-21/.
After completing this command, consider running:
$arckit-risk -- PIA findings feed the privacy and regulatory entries in the risk register.$arckit-ca-atip -- Personal-information disclosure register continues into the Access to Information / Privacy Act reconciliation.$arckit-ca-aia -- Required when automated decision-making touches personal information; the AIA inherits the PIA personal-information inventory.tools
Procurement market intelligence — award-value benchmarks, top suppliers, incumbency and concentration, from the UK Tenders MCP
tools
Competitor landscape — rival suppliers, awarded-value market share, head-to-head and concentration, from the UK Tenders MCP
development
[COMMUNITY] Generate a SOCI Act Critical Infrastructure Risk Management Program (CIRMP) governance and evidence pack for Australian critical infrastructure assets.
development
[COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments.