From arckit-at
Assesses Austrian DSG/DSGVO obligations under DSG 2018, including Datenschutzbehörde enforcement patterns, special provisions (§§12-13), and image processing rules. Run after eu-rgpd for full GDPR coverage.
How this command is triggered — by the user, by Claude, or both
Slash command
/arckit-at:at-dsgvo <project ID or processing description, e.g. '001', 'ministry HR system with CCTV and health data'>The summary Claude sees in its command listing — used to decide when to auto-load this command
> ⚠️ **Community-contributed command** — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified DSB-Beauftragter / DPO / Rechtsabteilung before reliance. Citations to Datenschutzbehörde (DSB) / EU regulations may lag the current text — verify against the source. Some citations are marked `[NEEDS VERIFICATION]` and should be confirmed by an Austrian data protection practitioner before external use. You are helping an enterprise architect generate an **Austrian Data Protection Assessment** — the Austrian-specific GDPR layer applied by the Datenschutzbeh...
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified DSB-Beauftragter / DPO / Rechtsabteilung before reliance. Citations to Datenschutzbehörde (DSB) / EU regulations may lag the current text — verify against the source. Some citations are marked
[NEEDS VERIFICATION]and should be confirmed by an Austrian data protection practitioner before external use.
You are helping an enterprise architect generate an Austrian Data Protection Assessment — the Austrian-specific GDPR layer applied by the Datenschutzbehörde (DSB) under the Datenschutzgesetz (DSG 2018, BGBl. I Nr. 165/1999 as amended). Run this after /arckit:eu-rgpd to add Austrian obligations that go beyond the EU GDPR baseline.
$ARGUMENTS
Note: The ArcKit Project Context hook has already detected all projects, artifacts, external documents, and global policies. Use that context below — no need to scan directories manually.
MANDATORY (warn if missing):
/arckit:at-dsgvo should be run after /arckit:eu-rgpd for best results. Proceed with available data.RECOMMENDED (read if available, note if missing):
OPTIONAL (read if available, skip silently):
external/ — extract previous DSB correspondence, Verarbeitungsverzeichnis (Art. 30 ROPA), existing Auftragsverarbeitungsverträge (DPAs), Betriebsvereinbarungen for employee data000-global/policies/ — extract Datenschutzerklärung, data retention schedule, DSB-Meldungen policyIdentify the target project from the hook context. If the project doesn't exist:
projects/*/ directories and find the highest NNN-* numberprojects/{NNN}-{slug}/README.mdPROJECT_ID and PROJECT_PATHRead all documents from Step 0. Identify:
Read the template (with user override support):
.arckit/templates/at-dsgvo-template.md exists in the project root${CLAUDE_PLUGIN_ROOT}/templates/at-dsgvo-template.mdCRITICAL: Use the Write tool to create the assessment document.
Detect version: Check for existing ARC-{PROJECT_ID}-ATDSG-v*.md files:
Auto-populate Document Control:
ARC-{PROJECT_ID}-ATDSG-v{VERSION}Section 1: AT DSG Regulatory Framework
[NEEDS VERIFICATION: confirm current venue rules]Section 2: §§12–13 DSG — Image and Video Processing (conditional — only if CCTV/imagery detected)
[NEEDS VERIFICATION: confirm current guidance version]Section 3: Health Data and ELGA (conditional — only if health data detected)
/arckit:dpiaSection 4: Employee Data (Arbeitnehmerdatenschutz) (conditional — only if employee data in scope)
[NEEDS VERIFICATION: confirm exact §96a(1) sub-point and threshold]Section 5: Scientific Research (§§7–8 DSG) (conditional — only if research use case)
[NEEDS VERIFICATION: confirm current §2d text and practice]Section 6: Data Subject Rights (Austrian enforcement)
[NEEDS VERIFICATION]Section 7: DSB Reporting and Registration
Section 8: Breach Notification to DSB
[NEEDS VERIFICATION: recent DSB penalty cases]Section 9: International Transfers (AT context)
[NEEDS VERIFICATION]Section 10: DSB Enforcement Priorities and Gap Analysis
[NEEDS VERIFICATION: cite recent DSB annual report][NEEDS VERIFICATION]Before writing the file, read ${CLAUDE_PLUGIN_ROOT}/references/quality-checklist.md and verify all Common Checks pass.
Write the document to:
projects/{project_id}/ARC-{PROJECT_ID}-ATDSG-v{VERSION}.md
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ AT DSG / DSGVO Assessment Generated
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📄 Document: projects/{project_id}/ARC-{PROJECT_ID}-ATDSG-v{VERSION}.md
📋 Document ID: {document_id}
📅 Assessment Date: {date}
🔒 Classification: OFFICIAL-SENSITIVE
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📊 Austrian-Specific Compliance Areas
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
| Area | Status | Gaps |
|---------------------------------|--------------|------|
| §§12–13 Image/Video Processing | {N/A or status} | {N} |
| Health Data / ELGA | {N/A or status} | {N} |
| Employee Data / §96a ArbVG | {N/A or status} | {N} |
| Research Exemptions §§7–8 DSG | {N/A or status} | {N} |
| Age of Consent (14 years) | {N/A or status} | {N} |
| DPO Registration with DSB | {status} | {N} |
| DSB Enforcement Risks | {level} | {N} |
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
⚡ Critical Actions
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
{List 🔴 High priority gaps}
Next steps:
1. {If DPIA required: Run /arckit:dpia}
2. {If employee monitoring: draft Betriebsvereinbarung §96a ArbVG}
3. {If no eu-rgpd baseline: Run /arckit:eu-rgpd first}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
/arckit:eu-rgpd first, then this command.[NEEDS VERIFICATION] must be confirmed against current DSB guidance before external use.projects/{project_id}/ARC-{PROJECT_ID}-ATDSG-v{VERSION}.md/arckit:at-dsgvo Austrian DSG layer for 001 — federal ministry HR system with CCTV at entrances, employee data, and potential monitoring of IT usage
/arckit:at-dsgvo Assess AT DSG obligations for a Vienna regional hospital group integrating with ELGA, processing Gesundheitsdaten, planning mobile patient portal
/arckit:at-dsgvo AT data protection for a research consortium processing pseudonymised health data for a longitudinal cohort study under §§7–8 DSG
npx claudepluginhub tractorjuice/arckit-claude --plugin arckit-at2plugins reuse this command
First indexed Jul 17, 2026
/at-dsgvoAssesses Austrian DSG/DSGVO obligations under DSG 2018, including Datenschutzbehörde enforcement patterns, special provisions (§§12-13), and image processing rules. Run after eu-rgpd for full GDPR coverage.
/eu-rgpdGenerates a GDPR (EU 2016/679) compliance assessment for EU/EEA data processing, covering legal basis mapping, data subject rights, cross-border transfers, DPIA screening, and breach notification.
/evidence-checklistGenerates GDPR evidence checklists for articles or principles, supporting role (controller/processor) and export format (json, csv, markdown). Covers TOMs and data processing activities.
/fr-rgpdAssesses CNIL-specific GDPR obligations for French deployments — cookies, health data (HDS), minors, délibérations CNIL, and French enforcement patterns.
/dpiaGenerates a UK GDPR Article 35 Data Protection Impact Assessment (DPIA) by analyzing project data models, architecture principles, requirements, and external policies to produce a compliance report with risk mitigations.
/au-piaGenerates a Privacy Impact Assessment (PIA) for Australian Government entities under the Privacy Act 1988, assessing compliance with all 13 Australian Privacy Principles (APPs).