A data privacy impact assessment (DPIA/PIA) is an internal evaluation of how personally identifiable information is handled for a given data processing activity. A PIA is conducted to ensure compliance with regulations, outline potential privacy risks, and potential ways of reducing those risks.
In this way, a PIA is both an analysis as well as a formal document outlining the data collection process and the findings of the analysis.
To know whether or not you need to conduct a PIA, you’ll need to evaluate your data collection activity against two sets of criteria (international and national). The international criteria has 10 conditions as per the G29. The national criteria is based on where you are conducting the data collection.
We carry out a risk analysis against three criteria: the potential for loss of data, disclosure of data, and alteration of data. We assess the risks on the privacy of the data subjects and how they are currently being mitigated by the security measures implemented.