| name | privacy-threat-model |
| description | Threat-model privacy harms including overcollection, linkage, inference, unauthorized secondary use, excessive retention, disclosure, re-identification, and abusive insider/tool access. |
Privacy Threat Model
Use when this procedure is the primary professional method needed for the assignment.
Procedure
- Confirm the decision or outcome this work must support, its scope, owner, constraints, and definition of success.
- Establish the evidence baseline using data flow map, threat actors, analytics/model behavior, access roles, exports, vendors, and product features. Do not fill material gaps with assumptions when they can change the result.
- Identify people/data/purposes, map trust boundaries and powerful joins, enumerate misuse/accidental paths, score harms and detectability, then design minimization and control mitigations.
- Exercise realistic edge, failure, transition, or exception cases that could invalidate the result; record unresolved uncertainty explicitly.
- Validate the output against the original outcome and any neighboring professional contracts so this skill does not silently absorb another specialist's authority.
- Record the resulting artifact, measurements, decisions, provenance, and handoff information needed for another owner to reproduce or continue the work.
Quality gate
Mitigations reduce privacy harm at the data or architecture layer rather than relying only on policy text.