What Is A Privacy Impact Assessment (PIA)? | Teamwire

Privacy Impact Assessment (PIA)

Privacy Impact Assessment (PIA)

Inhalt

A Privacy Impact Assessment (PIA) is a structured process through which an organisation systematically evaluates the risks that a planned data processing activity poses to the rights and freedoms of the individuals concerned, and defines protective measures — before the processing begins. In European law, the Privacy Impact Assessment corresponds to the Data Protection Impact Assessment (DPIA) under Article 35 of the GDPR; internationally, ISO/IEC 29134 describes the methodological framework. The outcome is a documented record that can be presented to supervisory authorities.

 

What is a Privacy Impact Assessment (PIA)?

A Privacy Impact Assessment is an upstream risk evaluation: it examines what effects a planned data processing activity may have on the individuals concerned, before that processing begins. The term originates from the Anglo-American sphere, where it has been established since the 1990s — in the United States, Section 208 of the E-Government Act of 2002 requires federal agencies to carry out such assessments, and comparable administrative requirements exist in Canada, Australia and New Zealand.

The defining feature of a Privacy Impact Assessment is its perspective. What is being assessed is not the risk to the organisation, but the risk to the individuals whose data is being processed. A conventional risk analysis within an Information Security Management System asks what damage an incident would cause to operations, revenue and reputation. A Privacy Impact Assessment asks what harm may befall employees, patients, citizens or customers: discrimination, identity theft, financial loss, reputational damage, a breach of professional secrecy or the loss of control over one’s own data. Recital 75 of the GDPR explicitly lists these types of harm. In practice, this shift in perspective is the most common source of error, because existing risk methods from IT security are adopted without modification.

A Privacy Impact Assessment is also not a one-off opinion but a process with a result document. It accompanies a project from the design phase through the selection of technical and organisational measures to sign-off, and is updated when changes occur. In this way, the Privacy Impact Assessment is the operational counterpart to Privacy by Design under Article 25 of the GDPR: it makes visible which design decisions are relevant to data protection whilst they can still be changed.

 

How does a Privacy Impact Assessment differ from a Data Protection Impact Assessment (DPIA)?

Privacy Impact Assessment and Data Protection Impact Assessment refer to the same fundamental procedure but differ in their binding nature and scope of application. The Data Protection Impact Assessment (DPIA) is the legally defined term under the GDPR, with a prescribed minimum content under Article 35(7). The Privacy Impact Assessment is the broader, methodological umbrella term used outside the European legal framework as well, and can encompass aspects beyond the protection of personal data — such as personality rights or informational self-determination more broadly.

In practical terms: anyone conducting a Privacy Impact Assessment within the DACH region must meet the formal requirements of the DPIA; otherwise the assessment has no regulatory value. Conversely, the methodological toolkit of the Privacy Impact Assessment remains useful even where there is no legal obligation — as a voluntary preliminary review whose outcome is documented.

Procedure Legal basis / source Subject of assessment
Privacy Impact Assessment (PIA) Methodological umbrella term, incl. ISO/IEC 29134 Effects of processing on the privacy of the individuals concerned
Data Protection Impact Assessment (DPIA) Article 35 GDPR Risks to the rights and freedoms of natural persons where high risk is likely
Transfer Impact Assessment (TIA) ECJ ruling “Schrems II” (C-311/18), EDPB Recommendations 01/2020 Legal framework and access rights in a third country for data transfers
Fundamental Rights Impact Assessment (FRIA) Article 27 EU AI Act (EU) 2024/1689 Fundamental rights implications of certain high-risk AI systems; supplements an existing DPIA
Risk analysis within an ISMS ISO/IEC 27001, BSI IT-Grundschutz Risks to confidentiality, integrity and availability from the organisation’s perspective

These procedures overlap but do not replace one another. In particular, the assumption that an existing ISMS risk analysis covers the DPIA requirements does not withstand regulatory scrutiny in practice.

 

When is a Privacy Impact Assessment mandatory?

A Privacy Impact Assessment in the form of a DPIA is mandatory when a processing activity is likely to result in a high risk to the rights and freedoms of natural persons (Article 35(1) GDPR). Article 35(3) sets out three standard examples: the systematic and extensive evaluation of personal aspects including profiling as the basis for automated decisions with legal effect; the large-scale processing of special categories of data under Article 9 or data relating to criminal convictions under Article 10; and the systematic large-scale monitoring of publicly accessible areas.

In addition, supervisory authorities publish under Article 35(4) GDPR so-called “must lists” of processing activities for which a DPIA is always required — in Germany, coordinated through the Data Protection Conference (DSK), which has also addressed the topic in its short paper No. 5. Under paragraph 5, authorities may also maintain lists of processing activities for which no impact assessment is required.

For assessments in grey areas, the nine criteria of the former Article 29 Working Party (Guidelines WP 248 rev.01, adopted by the European Data Protection Board) have become the standard. Where two or more criteria apply, a high risk is generally to be assumed.

Criterion under WP 248 rev.01 Typical examples
Evaluation or scoring (incl. profiling) Credit scoring, performance appraisal, health prognoses
Automated decisions with legal effect Automated rejection of applications or job candidates
Systematic monitoring Video surveillance, location tracking, network and behavioural monitoring
Special categories or highly personal data Health, social, employment and communications data
Large-scale processing Number of data subjects, data volume, duration, geographical scope
Matching or combining datasets Merging separately collected records across different specialist systems
Data of vulnerable individuals Children, patients, employees, asylum seekers
Use of new or innovative technologies Biometrics, AI-based analysis, IoT sensors
Prevention of the exercise of rights or use of services Exclusion from services based on the processing

Whether a DPIA is required is assessed and documented in a threshold analysis. This preliminary check is worthwhile even if the outcome is negative: it is evidence that the question was asked at all, and as such forms part of the accountability obligation under Article 5(2) GDPR. Existing processing activities introduced before the GDPR came into effect are not automatically exempt — where the risk, purpose or technology changes, the obligation arises afresh.

 

How does a Privacy Impact Assessment proceed?

A Privacy Impact Assessment follows a fixed process that is reflected in similar form in ISO/IEC 29134 and in the guidance published by supervisory authorities. Seven steps are common:

Preparation and threshold analysis. The scope of the assessment is defined and it is established whether an obligation exists. A Privacy Impact Assessment may cover several similar processing activities together — for example, an organisation-wide application with a consistent configuration.

Systematic description of the processing. Purposes, legal basis, data categories, groups of data subjects, recipients, retention periods, systems involved, interfaces and third-country transfers are all recorded. The record of processing activities under Article 30 GDPR typically serves as the basis.

Assessment of necessity and proportionality. This step examines whether the purpose could be achieved with less data, shorter retention or a lower level of intervention. This step more often determines the outcome than any subsequent technical measure.

Risk assessment. For each identified threat, the likelihood of occurrence and the severity of the consequences for the individuals concerned are evaluated.

Definition of remedial measures. Technical and organisational measures under Article 32 GDPR are mapped to specific risks — encryption, pseudonymisation, role and permission frameworks, deletion concepts, logging and training.

Assessment of residual risk and sign-off. The remaining risk is re-evaluated and documented as approved. If it remains high despite the measures taken, prior consultation under Article 36 GDPR applies.

Review and update. The Privacy Impact Assessment is updated whenever the processing or risk situation changes.

Two forms of involvement are legally required and are frequently overlooked in practice: the advice of the Data Protection Officer must be sought under Article 35(2) GDPR, and under Article 35(9) the views of data subjects or their representatives should where appropriate be sought — in an employment context, typically via the works council or staff representative body.

 

What content must a Privacy Impact Assessment contain under Article 35(7) GDPR?

Article 35(7) GDPR sets out four minimum components that every Privacy Impact Assessment within the scope of the GDPR must contain: a systematic description of the planned processing operations and their purposes, including any legitimate interest pursued; an assessment of the necessity and proportionality of the processing in relation to the purpose; an assessment of the risks to the rights and freedoms of the data subjects; and the envisaged remedial measures, including safeguards, security measures and mechanisms to demonstrate compliance with the GDPR.

These four elements represent minimum content, not a suggested structure. In practice, additional elements are typically included: linkage to the deletion concept, assessment of processors and sub-processors, documentation of the legal basis for each processing purpose, and an action plan with responsible parties and deadlines. A Privacy Impact Assessment does not need to be published; however, Guidelines WP 248 rev.01 recommend publishing at least a summary to build trust — a particularly effective transparency signal in the public sector.

 

How are risks assessed in a Privacy Impact Assessment?

Risks in a Privacy Impact Assessment are determined by the interplay between the likelihood of occurrence and the severity of the consequences for the individuals concerned. Recital 76 of the GDPR requires an objective assessment based on the nature, scope, context and purposes of the processing. Scales of three to four levels, combined in a risk matrix, are common; what matters is not the granularity of the scale but the traceable justification for each rating.

What is assessed is not limited to security incidents. A Privacy Impact Assessment also considers risks arising from regular, planned processing: unlawful change of purpose, failure to delete, unnoticed profiling through the combination of datasets, or processing that effectively excludes individuals from a service. A data breach is only one of several possible harm pathways.

In German-speaking countries, the Standard Data Protection Model (SDM) of the Data Protection Conference has become established as the framework for structuring this assessment. It translates legal requirements into seven assurance objectives — data minimisation, availability, integrity, confidentiality, unlinkability, transparency and intervenability — and assigns specific measures to each. For a Privacy Impact Assessment, the SDM is particularly valuable because it supplements the security objectives familiar from IT security with the specifically data protection-related objectives of unlinkability, transparency and intervenability. It is precisely these three that go unassessed when an ISMS methodology is adopted without modification.

 

What standards and methods apply to Privacy Impact Assessments?

An international standards framework exists for Privacy Impact Assessments that methodologically supplements the GDPR. ISO/IEC 29134 is the authoritative guide for the process, structure and reporting format of a Privacy Impact Assessment. ISO/IEC 29100 provides the underlying conceptual and principles framework through its Privacy Framework. ISO/IEC 27701 extends ISO/IEC 27001 and ISO/IEC 27002 into a Privacy Information Management System (PIMS) and is the standard route for embedding a Privacy Impact Assessment not as a one-off exercise but as a repeatable process.

At national and regulatory level, additional practical methods are available: the Standard Data Protection Model of the German supervisory authorities; the freely available PIA software of the French supervisory authority CNIL; and the NIST Privacy Framework for the US context. BSI IT-Grundschutz is additionally used for the assessment of technical measures. None of these methods is prescribed — Article 35 GDPR defines required quality and minimum content, not the procedure.

 

Who is responsible for a Privacy Impact Assessment?

Responsibility for conducting the Privacy Impact Assessment rests with the controller under the GDPR — that is, the organisation and therefore its leadership. This obligation cannot be delegated. The Data Protection Officer advises and monitors the process (Articles 35(2) and 39(1)(c) GDPR) but does not conduct the Privacy Impact Assessment themselves — a conflation of roles that is common in practice and which undermines the independence of the advisory function.

The substantive content is provided by the business units responsible for the processing purpose, together with IT and information security for the technical assessment. Processors are required under Article 28(3)(f) GDPR to assist the controller in carrying out the impact assessment; the assessment itself remains the controller’s responsibility. This duty to assist should be specifically described in the processing agreement — otherwise it exists only on paper.

 

What happens if a high residual risk remains after the Privacy Impact Assessment?

If a high risk remains after the Privacy Impact Assessment despite the planned measures, the controller must consult the competent supervisory authority before beginning the processing (Article 36(1) GDPR). The authority provides written recommendations within eight weeks; this period may be extended by a further six weeks. The processing may not commence until the response is received — a time factor that must be factored into project plans.

If a required impact assessment is not carried out, is carried out incompletely or is carried out only retrospectively, this constitutes an independent violation. Article 83(4)(a) GDPR provides for fines of up to €10 million or 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. In addition, supervisory authorities have the power to issue orders up to and including a prohibition on processing.

 

When is a Privacy Impact Assessment required for communication solutions?

For communication and messaging solutions, a Privacy Impact Assessment is required wherever personal data with a high protection requirement is exchanged — health and social care data, operational data of public safety authorities and organisations, employee data or location data. Typically, several WP 248 criteria apply simultaneously: special categories of data, groups of vulnerable individuals and, where live location features or analytics are involved, a surveillance dimension.

Four points are particularly relevant to the assessment: the confidentiality of content, typically addressed through end-to-end encryption; the processing of metadata such as contact relationships, timestamps and device data, which is frequently underestimated; storage locations and transfers to third countries, together with the question of data sovereignty and appropriate safeguards under Chapter V of the GDPR; and control over end devices — for example through Mobile Device Management and the separation of business from personal data.

A recurring finding in practice: the use of personal consumer messaging apps for business communications can rarely be justified in a Privacy Impact Assessment, because neither retention periods, nor the scope of recipients, nor access to the address book can be controlled.

Organisations typically address these requirements through approved communication solutions whose data processing, retention periods and permissions can be centrally administered and documented — features that can be demonstrated as concrete remedial measures within the Privacy Impact Assessment.

Teamwire can demonstrate how retention periods, permissions and logging can be centrally managed — in a demo or a free trial.

 

How often must a Privacy Impact Assessment be reviewed?

A Privacy Impact Assessment must be reviewed whenever the risk associated with the processing changes; Article 35(11) GDPR requires this explicitly. Triggers include new processing purposes, additional data categories or recipients, a change of processor, changes to storage locations, new features involving personal data, and data protection breaches that have occurred.

Independently of event-driven triggers, a regular review cycle has proven effective — typically annual or biennial. Without such a cycle, a Privacy Impact Assessment becomes silently outdated: the document continues to exist but describes a processing activity that no longer exists in that form, thereby losing precisely the evidential function for which it was created. GDPR compliance of a processing activity is assessed against actual operations, not against the state of the documentation.

 

What mistakes are most common in Privacy Impact Assessments?

The most common mistake in a Privacy Impact Assessment is poor timing: the assessment is only created once the selection decision has already been made and the system configured. At that point, it merely documents the status quo rather than influencing it. Further typical weaknesses include:

  • Risks are assessed from the organisation’s perspective rather than that of the individuals concerned
  • The threshold analysis is not carried out or is not documented with justification
  • Necessity and proportionality are skipped and replaced by a list of measures
  • Metadata, log data and backups are left out of scope
  • Measures are formulated in general terms and not mapped to specific risks
  • The Data Protection Officer is only consulted at the sign-off stage rather than during the advisory process
  • The outcome is not updated after the project is completed

 

Key takeaways

  • A Privacy Impact Assessment (PIA) is a structured process that evaluates the risks of a processing activity to the rights and freedoms of the individuals concerned, and defines protective measures — before processing begins.
  • In European law, the Privacy Impact Assessment corresponds to the Data Protection Impact Assessment (DPIA) under Article 35 GDPR.
  • A Privacy Impact Assessment assesses risk to the individuals concerned, not to the organisation — this distinguishes it from the risk analysis of an Information Security Management System.
  • It is mandatory where high risk is likely — particularly for profiling with legal effect, large-scale processing of special categories of data, and systematic monitoring of publicly accessible areas (Article 35(3) GDPR).
  • The nine criteria of Guidelines WP 248 rev.01 serve as a screening framework; where two or more criteria apply, a high risk is generally to be assumed.
  • The minimum content under Article 35(7) GDPR comprises a description of the processing, an assessment of necessity and proportionality, a risk assessment and remedial measures.
  • Methodological foundations are provided by ISO/IEC 29134, ISO/IEC 27701 and the Standard Data Protection Model (SDM) with its seven assurance objectives.
  • Responsibility rests with the organisation’s leadership; the Data Protection Officer advises under Article 35(2) GDPR, and processors support the process under Article 28(3)(f) GDPR.
  • If a high residual risk remains, the supervisory authority must be consulted before processing begins (Article 36 GDPR; response period: eight weeks, extendable by six weeks).
  • A missing or inadequate impact assessment may be subject to fines of up to €10 million or 2% of total worldwide annual turnover (Article 83(4)(a) GDPR).