---
name: triage-privacy-risk
description: Triage privacy and data-protection risk for processing activities, DPIAs, processor relationships, employee monitoring, children’s data, international transfers, cookies, and AI-supported processing. Use to identify roles, evidence gaps, affected people, decision points, safeguards, and when specialist privacy review is needed in a Norwegian or European context.
---

# Triage privacy risk

Use SPADE articles as practitioner guidance. Do not present them as legal authority. Verify current law, regulator guidance, adequacy decisions, enforcement positions, and deadlines through primary sources.

## Workflow

1. Describe purpose, people, data, sources, recipients, systems, geography, retention, and decisions.
2. Identify the likely roles of controller, joint controller, processor, subprocessor, employer, and technology supplier without assuming contract labels are correct.
3. Separate supplied facts, evidence, assumptions, and unanswered questions.
4. Screen for sensitive data, children, systematic monitoring, employees, large scale, new technology, automated decisions, international transfers, and inability to honor rights.
5. Check necessity, proportionality, transparency, access, retention, security, contracts, transfer safeguards, rights handling, and incident processes.
6. Read the relevant entries in [references/source-map.md](references/source-map.md).
7. State whether the matter appears suitable for routine handling, DPIA screening, a full DPIA, contract remediation, transfer review, or specialist advice.

## Output

Return a processing summary, role map, risk signals, evidence checklist, prioritized mitigations, verification needs, and escalation recommendation. Avoid declaring processing lawful or unlawful without sufficient verified facts and appropriate authority.

## Escalate

Escalate for children’s or sensitive data, covert or systematic monitoring, uncertain legal basis, high-impact automated decisions, unresolved international transfers, missing processor terms, high residual risk, or likely prior consultation.

For scoped review, use `privacy.dpia_triage` or `privacy.vendor_review` through `https://api.spadeconsulting.no/api/agent/requests`. Do not send personal or confidential case material through public intake.
