Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins.

Apache-2.0Auto-check passedResearch & Science

Install New Tech Pia

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills new-tech-pia --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/new-tech-pia .claude/skills/new-tech-pia && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
new-tech-pia
GitHub stars
301
Token cost
~3.3k tokens
SKILL.md length
1,498 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins.

  • Works in 5 steps: Technology Understanding (Week 1) → Stakeholder Impact Mapping (Week 2) → Proportionality Assessment (Week 3) → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Technology-Specific Privacy…, PIA Methodology for Emerging… and Privacy-by-Design Requirements…, plus 1 more section
  • Runs Python scripts from its folder

What it does

New Tech Pia is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins. Covers risk identification methodology, proportionality assessment, and technology-specific privacy challenges. Activate when evaluating new technology adoption, innovation projects, or emerging tech procurement. Keywords: PIA, emerging technology, IoT, blockchain, AR/VR, quantum computing, digital twins, innovation privacy.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Research & Science, covering Privacy and GDPR, Quantum computing and Vendor and procurement management. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Quantum computing
  • Tasks that involve Vendor and procurement management

Example prompts

  • “Use the new-tech-pia skill to guide privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and…”
  • “/new-tech-pia”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Technology Understanding (Week 1)
  2. Stakeholder Impact Mapping (Week 2)
  3. Proportionality Assessment (Week 3)
  4. Risk Assessment and Mitigation (Week 4-5)
  5. Ongoing Monitoring Framework (Week 5-6)

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

New Tech Pia loads about 3.3k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 118 tokens; SKILL.md has 1,498 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~118
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,498 words, ~3,300 tokens.

Download SKILL.mdSave it as .claude/skills/new-tech-pia/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
new-tech-pia
description
Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins. Covers risk identification methodology, proportionality assessment, and technology-specific privacy challenges. Activate when evaluating new technology adoption, innovation projects, or emerging tech procurement. Keywords: PIA, emerging technology, IoT, blockchain, AR/VR, quantum computing, digital twins, innovation privacy.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-impact-assessment
metadata.tags
pia, emerging-technology, iot, blockchain, ar-vr, quantum-computing

Assessing New Technology Privacy Impact

Overview

Article 35(1) of the GDPR explicitly references new technologies as a factor increasing the likelihood of high risk to data subjects' rights and freedoms. The EDPB in WP248rev.01 identifies innovative use of technology as one of nine criteria triggering a DPIA. This skill provides a structured PIA methodology for emerging technologies where the privacy implications are not yet fully understood, including Internet of Things (IoT), blockchain and distributed ledger technologies, augmented and virtual reality (AR/VR), quantum computing, digital twins, brain-computer interfaces, and ambient computing.

Technology-Specific Privacy Risk Profiles

Internet of Things (IoT)
Risk AreaDescriptionPrivacy Impact
Pervasive data collectionIoT devices continuously collect environmental and behavioural data, often without visible indicatorsData subjects may be unaware of the scope of data collection; transparency obligations under Art. 13-14 are difficult to fulfil on devices without screens
Data minimisation challengesSensors often collect more data than needed for the immediate purpose to enable future analyticsViolation of Art. 5(1)(c) data minimisation; purpose creep through accumulated data
Device-to-device communicationIoT ecosystems share data between devices without user awarenessUnexpected recipients; difficulty identifying all processors and sub-processors
Insecure by defaultMany IoT devices ship with default credentials, unencrypted communications, and no update mechanismArt. 25 data protection by design and Art. 32 security of processing obligations not met
Location and behavioural trackingConnected devices reveal location patterns, daily routines, and behavioural habitsSystematic monitoring (WP248 C3); profiling risk (WP248 C1)
Cross-device correlationData from multiple IoT devices can be combined to create comprehensive behavioural profilesMatching or combining datasets (WP248 C6); disproportionate surveillance

EDPB Guidelines 02/2023 on IoT and Wearable Devices: Emphasized that IoT devices must implement data protection by design, provide clear privacy notices (adapted to device constraints), and enable genuine consent mechanisms.

Blockchain and Distributed Ledger Technology
Risk AreaDescriptionPrivacy Impact
Immutability vs right to erasureBlockchain's append-only nature conflicts with Art. 17 right to erasureTechnical inability to delete personal data recorded on-chain
Transparency of transactionsPublic blockchains expose transaction data to all participantsPersonal data potentially accessible to unlimited recipients
Pseudonymity not anonymityBlockchain addresses are pseudonymous but can be linked to real identities through transaction analysisRe-identification risk; Art. 4(5) pseudonymisation does not equal anonymisation
Controller identificationDecentralised governance makes it difficult to identify the data controllerArt. 26 joint controller arrangements may be needed; accountability unclear
Cross-border by designDistributed ledger nodes are typically located across multiple jurisdictionsChapter V international transfer obligations triggered
Smart contract automationSmart contracts execute automatically without human interventionArt. 22 automated decision-making implications when smart contracts affect individuals

CNIL Blockchain Guidance (2018): Recommended storing personal data off-chain with only hashes on-chain; using commitment schemes; designating participants who decide to use blockchain as controllers.

Augmented and Virtual Reality (AR/VR)
Risk AreaDescriptionPrivacy Impact
Biometric data collectionEye tracking, facial expressions, body movements, voice patternsArt. 9 special category data (biometric data for identification); Art. 35(3)(b) trigger
Spatial mappingAR/VR devices scan and map physical environments including private spacesCollection of data about third parties present in the environment without their consent
Behavioural profilingGaze tracking reveals interests, attention patterns, and cognitive stateHighly personal data; evaluation and scoring (WP248 C1)
Immersive manipulationVR environments can influence behaviour through environmental designArt. 5(1)(a) fairness; potential for subliminal manipulation
Persistent identityAvatar and behavioural biometrics create persistent identifiable profilesLong-term tracking across virtual environments
Child safetyMinors using VR platforms face enhanced risksVulnerable data subjects (WP248 C7); Art. 8 child consent requirements
Quantum Computing
Risk AreaDescriptionPrivacy Impact
Cryptographic vulnerabilityQuantum computers may break current encryption standards (RSA, ECC)Art. 32 security measures based on current encryption become insufficient
Retroactive decryptionEncrypted data harvested today can be decrypted when quantum computers mature (harvest now, decrypt later)Data currently protected may become exposed; long-term confidentiality compromised
Enhanced data analyticsQuantum machine learning can process data at scales impossible for classical computersNew forms of profiling and inference; privacy-preserving techniques may be defeated
Post-quantum migrationTransitioning to quantum-resistant cryptography requires significant infrastructure changesInterim vulnerability period during migration

ENISA Post-Quantum Cryptography Report (2024): Recommended organisations begin quantum risk assessment and plan migration to NIST-standardised post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA).

Digital Twins
Risk AreaDescriptionPrivacy Impact
Comprehensive data aggregationDigital twins aggregate data from multiple sources to create a virtual replicaMatching or combining datasets (WP248 C6); comprehensive profiling
Predictive modelling of individualsDigital twins of patients or employees predict future states and behavioursEvaluation and scoring (WP248 C1); Art. 22 implications for predictions affecting individuals
Continuous synchronisationReal-time data feeds maintain the digital twin's accuracySystematic monitoring (WP248 C3); proportionality concerns
Blurred anonymisation boundaryEven without direct identifiers, a sufficiently detailed digital twin may be re-identifiablePseudonymisation vs anonymisation assessment required

PIA Methodology for Emerging Technologies

Phase 1: Technology Understanding (Week 1)
  1. Document the technology's data processing characteristics:
    • What data is collected (categories, volume, frequency)
    • How data flows through the technology stack
    • Where data is stored and processed (geographic locations)
    • Who has access to data at each stage
    • How long data is retained
    • What security measures protect data at each stage
  2. Identify the technology's novel risk characteristics that distinguish it from established technologies.
  3. Map the technology against the EDPB WP248rev.01 nine criteria.
  4. Consult published regulatory guidance specific to the technology (EDPB, CNIL, ICO, ENISA).
Show full SKILL.md (605 more words)Show less
Phase 2: Stakeholder Impact Mapping (Week 2)
  1. Identify all affected data subjects:
    • Direct users of the technology
    • Third parties whose data may be incidentally collected
    • Bystanders (particularly relevant for IoT, AR/VR, spatial computing)
  2. Identify vulnerable data subjects (children, employees, patients, elderly).
  3. Map potential impacts on each stakeholder group:
    • Privacy impacts (loss of control, unexpected processing)
    • Autonomy impacts (manipulation, reduced choice)
    • Equality impacts (discriminatory outcomes, digital exclusion)
    • Safety impacts (physical harm from decisions based on technology)
  4. Document data subject expectations versus actual processing.
Phase 3: Proportionality Assessment (Week 3)

For each data processing element of the technology:

Assessment QuestionAnalysis Required
Is this processing necessary for the stated purpose?Document why the technology cannot achieve its purpose without this data
Could the purpose be achieved with less data?Evaluate data minimisation alternatives (aggregation, sampling, synthetic data)
Could the purpose be achieved with less identifying data?Evaluate anonymisation, pseudonymisation, and differential privacy options
Could the purpose be achieved with a less invasive technology?Compare the proposed technology against established alternatives
Are the benefits proportionate to the privacy intrusion?Balancing test: public interest vs individual privacy impact
Have data subjects been consulted on the acceptability of the intrusion?Art. 35(9) data subject views; user acceptance research
Phase 4: Risk Assessment and Mitigation (Week 4-5)
  1. For each identified risk, assess likelihood and severity using the standard DPIA risk matrix.
  2. Identify technology-specific mitigation measures:
    • Privacy-enhancing technologies (PETs): differential privacy, homomorphic encryption, secure multi-party computation, federated learning
    • Data protection by design: privacy-preserving defaults, granular consent, purpose-bound processing
    • Transparency mechanisms adapted to technology constraints (audio notices for screenless IoT, visual indicators for AR/VR)
  3. Assess residual risk after mitigation.
  4. If residual risk remains high, consider whether the technology should be deployed at all, not just how to mitigate risks.
Phase 5: Ongoing Monitoring Framework (Week 5-6)
  1. Define monitoring metrics specific to the technology:
    • Data collection volumes (detect scope creep)
    • Access patterns (detect unauthorised use)
    • Accuracy and reliability of technology outputs
    • User complaints and feedback
  2. Establish review triggers:
    • Technology update or version change
    • New use case or feature added
    • Security vulnerability discovered
    • Regulatory guidance issued for the technology
    • Peer data breach involving similar technology
  3. Define a sunset plan: how will personal data be handled if the technology is decommissioned?

Privacy-by-Design Requirements for Emerging Technologies

PrincipleImplementation for Emerging Tech
Proactive not reactiveConduct PIA before technology deployment, not after incidents
Privacy as defaultTechnology must ship with privacy-protective defaults; opt-in for additional data collection
Privacy embedded in designPrivacy requirements must be part of the technology specification, not bolt-on
Full functionalityPrivacy protections should not degrade the technology's core functionality
End-to-end securityData protection from collection through deletion, including inter-device communication
Visibility and transparencyClear indicators when technology is collecting data; accessible privacy notices
Respect for user privacyUser-centric design; genuine choice and control over personal data

Enforcement Precedents

  • Spanish AEPD vs CaixaBank (2021): EUR 6 million fine for deploying new profiling technology (behavioural analytics for targeted financial products) without adequate DPIA for innovative technology use.
  • ICO vs Clearview AI (2022): GBP 7.5 million fine for novel facial recognition technology scraping public images without lawful basis or DPIA.
  • CNIL vs Amazon Europe (2020): EUR 35 million fine for deploying cookie tracking technology without valid consent on the Amazon.fr website.
  • Italian Garante vs Foodinho/Glovo (2021): EUR 2.5 million fine for deploying algorithmic management technology (AI-driven shift allocation for riders) without DPIA.
  • Belgian DPA vs IAB Europe (2022): EUR 250,000 fine for the Transparency and Consent Framework (TCF) used in programmatic advertising technology; found that TCF constituted processing of personal data without adequate controller designation.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/new-tech-pia of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

New Tech Pia next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

New Tech Pia compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
New Tech Pia this skillmukul975/Privacy-Data-Protection-Skills301—~3.3kAutomated safety check: PassApache-2.0
Tech Contract Negotiation Patrick Munrolawve-ai/awesome-legal-skills847—~4.9kAutomated safety check: PassAGPL-3.0
Operational Designmagnus919/agent-skills115—~1.4kAutomated safety check: PassMIT
Regulatory Deal Card Generator Patrick Munrolawve-ai/awesome-legal-skills847—~2.1kAutomated safety check: PassAGPL-3.0
AI Governance Reviewer Carl Ditzlerlawve-ai/awesome-legal-skills847—~4.6kAutomated safety check: PassApache-2.0
Operational Designmagnus919/hermes-profiles289—~1.3kAutomated safety check: PassMIT

Similar skills

  • Tech Contract Negotiation Patrick Munro

    lawve-ai/awesome-legal-skills

    Systematic contract negotiation strategies for technology services agreements with German/EU law specificity.

    847 GitHub stars~4.9k tokensUpdated 7 days ago
    Legal & ComplianceAuto-check passed
  • Operational Design

    magnus919/agent-skills

    Design and improve operational processes, controls, metrics, vendors, and scaling models through bounded pilots and evidence.

    115 GitHub stars~1.4k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Generates standalone interactive HTML "deal cards" that translate complex regulations into negotiation-ready reference tools, systematically distinguishing mandatory obligations from negotiable…

    847 GitHub stars~2.1k tokensUpdated 7 days ago
    Legal & ComplianceAuto-check passed
  • AI Governance Reviewer Carl Ditzler

    lawve-ai/awesome-legal-skills

    A skill your agent uses when the user wants an AI governance, legal-risk, privacy, compliance, procurement, or vendor-risk review of an internal AI use case, an AI product feature, an LLM workflow…

    847 GitHub stars~4.6k tokensUpdated 7 days ago
    Legal & ComplianceAuto-check passed
  • Operational Design

    magnus919/hermes-profiles

    COO methodology for process design, organizational scaling, operational metrics, compliance and audit, vendor management, and team topology.

    289 GitHub stars~1.3k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed
  • Qiskit 2.x Quantum ML Reference

    aiming-lab/AutoResearchClaw

    Reference patterns for writing qiskit 2.x code for variational quantum machine learning: feature maps, VQC training, VQE for chemistry, MPS circuits and noise models.

    15k GitHub stars~4.7k tokensUpdated 1 mo ago
    Research & ScienceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about New Tech Pia

What does New Tech Pia do?

Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins. New Tech Pia is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides privacy impact assessment for emerging technologies including IoT, blockchain, AR/VR, quantum computing, and digital twins.

When should I use New Tech Pia?

New Tech Pia fits situations like: tasks that involve Privacy and GDPR; tasks that involve Quantum computing; tasks that involve Vendor and procurement management.

How do I install New Tech Pia in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a claude-code`. Or copy the skill folder (skills/privacy/new-tech-pia in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/new-tech-pia in your project. Claude Code loads it when a task matches its description.

How do I install New Tech Pia in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a codex`. Or copy the skill folder (skills/privacy/new-tech-pia in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/new-tech-pia in your project. Codex loads it when a task matches its description.

Can I use New Tech Pia in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill new-tech-pia -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/new-tech-pia, .gemini/skills/new-tech-pia, .github/skills/new-tech-pia and .opencode/skills/new-tech-pia in your project.

What does New Tech Pia need to run?

Going by SKILL.md and its folder, New Tech Pia needs Python for the scripts in its folder. Our summary lists: Python 3.

Does New Tech Pia access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is New Tech Pia safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does New Tech Pia use?

New Tech Pia is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does New Tech Pia use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.

What are the alternatives to New Tech Pia?

Skills that share tags, products or a category with New Tech Pia: Tech Contract Negotiation Patrick Munro (lawve-ai/awesome-legal-skills, 847 stars), Operational Design (magnus919/agent-skills, 115 stars), Regulatory Deal Card Generator Patrick Munro (lawve-ai/awesome-legal-skills, 847 stars) and AI Governance Reviewer Carl Ditzler (lawve-ai/awesome-legal-skills, 847 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains New Tech Pia?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.