Use when the user asks to "design a new data model that stores personal data", "add a retention policy", "figure out how long to keep guest data", "handle a data deletion request", "design for GDPR compliance", or is adding any field/table that captures a name, email, phone, ID document, or payment detail. Guides applying GDPR's data minimization principle and Ann Cavoukian's Privacy by Design framework at design time, not as a bolt-on compliance pass after launch.