The Good Manager  >  Training modules

100 points to know about...
Inclusive project management

points to know about...
Back to module summary

Notion 23

Conducting a Privacy Impact Assessment

Target skills

Identify the purpose of a Privacy Impact assessment for ensuring data protection

What is a privacy impact assessment?

Privacy Impact Assessment (PIA) is all about analyzing how an entity collects, uses, shares, and maintains personally identifiable information, related to existing risks.

The goals of a PIA

A PIA should accomplish three goals:
1. Ensure conformance with applicable legal, regulatory, and policy requirements for privacy
2. Determine the risks and effects
3. Evaluate protections and alternative processes to mitigate potential privacy risks.

When a PIA is compulsory?

The General Data Protection Regulation (GDPR) specifies the cases where an PIA is necessary and its content, as well as the obligation to check the consistency of the PIA, such as, for example, in the case of a practice which is likely to result in a high risk to the rights and freedoms of natural persons; an action which consists of a systematic and thorough evaluation of personal aspects relating to natural persons, based on automated processing, including profiling, and on the basis of which decisions are taken which have legal effects on a natural person or which significantly affect him or her in a similar way; or the systematic large-scale monitoring of a publicly accessible area...

Key points of a PIA

The Privacy Impact Assessment shall include at least the following points
1 a description of the processing operations and the purposes of the processing, including the legitimate interest pursued by the controller
2 an assessment of the necessity and proportionality of the processing operations in relation to the purposes
3 an assessment of the risks to the rights and freedoms of data subjects;
4 the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation, taking into account the rights and legitimate interests of data subjects and other persons affected.