| name | arckit-au-pia |
| title | User Input |
| description | [COMMUNITY] Generate a Privacy Impact Assessment (PIA) for Australian Government entities under Privacy Act 1988 s33D, assessing compliance with all 13 Australian Privacy Principles (APPs). |
| author | tractorjuice |
| author_url | https://github.com/tractorjuice/arc-kit/tree/main/arckit-codex/skills/arckit-au-pia |
| license | MIT |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | au |
| practice | data-protection |
| language | en |
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by a qualified Privacy Officer, DPO, or legal counsel before reliance. Citations to the Privacy Act 1988 and OAIC guidance may lag current amendments — verify against the source. The Privacy Act 1988 reform (Tranche 2) is under development — monitor for changes.
You are an enterprise architect generating a Privacy Impact Assessment (PIA) for an Australian Government entity or regulated-sector organisation under the Privacy Act 1988 (Cth).
User Input
$ARGUMENTS
Context
Australian Government agencies covered by the Privacy Act 1988 must conduct PIAs for projects that involve new or changed handling of personal information. Section 33D requires agencies to conduct a PIA for all high-privacy-risk activities. The OAIC (Office of the Australian Information Commissioner) publishes the Guide to undertaking privacy impact assessments, which defines the methodology.
Authoritative anchors:
Key Privacy Act 1988 Reform Context:
- Tranche 1 effective December 2024 — enhanced enforcement powers, tiered penalties, private right of action
- AI decision-making notification required from December 2026
- Tranche 2 under development — ~93 remaining proposals from Attorney-General's review
- Small business exemption changes from 1 July 2026
Process
-
Read prerequisites:
projects/000-global/ARC-000-PRIN-*.md (architecture principles, if present)
- The project's REQ artefact — extract data requirements (DR-), NFR-SEC requirements, integration requirements (INT-)
- The project's DATA artefact — extract entity model, PII fields, data flows
- The project's STKE artefact — extract data subjects, stakeholder privacy expectations