Skip to main content

Current Chapter

Current chapter – Section 11: Privacy Impact Assessments


A Privacy Impact Assessment (PIA) is a process which helps assess privacy risks to individuals in the collection, use and disclosure of information. PIAs help identify privacy risks, foresee problems and bring forward solutions. They help to

  • identify privacy risks to individuals
  • identify confidentiality, privacy and Data Protection compliance liabilities for an organisation
  • protect an organisation’s reputation
  • instil public trust and confidence in an organisation’s project/product
  • avoid expensive, inadequate “bolt- on” solutions
  • inform an organisation’s communications strategy; and
  • represent enlightened self-interest

PIAs are most effective when they are started at an early stage of a project, when

  • the project is being designed
  • organisations know what they want to do
  • organisations know how they want to do it
  • and organisations know who else is involved

But ideally they should be started before

  • decisions are set in stone
  • organisations have procured systems
  • organisations have signed contracts, Memorandum Of Understandings (MOUs) or agreements; and
  • while organisations can still change their mind

Guidance on Privacy Impact Assessments (Privacy Impact Assessments – An Overview) is provided by the Information Commissioner.


Last edited: 17 January 2022 1:03 pm