A Personal Information Impact Assessment (PIIA) under POPIA is a process that helps organisations understand and mitigate the data protection risks to data subjects associated with processing personal information. Under South Africa’s Protection of Personal Information Act, 4 of 2013 (POPIA), a PIIA supports the legal duty to process personal information in a way that respects the privacy of data subjects and complies with the law.
A PIIA evaluates a processing activity to determine how it affects the privacy of people, and to identify measures that can mitigate those risks.
Much like a risk assessment in other contexts, a personal information impact assessment is designed to evaluate how a processing activity will affect the privacy of both natural and juristic persons, and to identify measures that can mitigate those risks. The processing activity could be an existing or new project, policy, process, system, app, product or service. A responsible party typically conducts a PIIA when the processing is likely to expose the rights and freedoms of persons to significant risk. The purpose of the PIIA is to assess the impact (or risks) of your processing activities on the privacy or personal information of data subjects.
This assessment is referred to as a Privacy Impact Assessment (PIA) in many countries, a Personal Information Impact Assessment (PIIA) in terms of POPIA in South Africa or a Data Protection Impact Assessment (DPIA) in terms of the GDPR in the EU.
In this article, we are discussing one kind of impact assessment (being a personal information impact assessment). You also get an organisational impact assessment and a regulatory impact assessment. You can read more about legal assessments. It is essential to know which one you are referring to. We can also conduct a gap analysis or a compliance audit, but these are distinct processes. The names of these different things all sound very similar, but they are quite different things.
Why is a PIIA required?
Section 4(1)(b) of POPIA states that the responsible party must process personal information in a “lawful and reasonable manner that does not infringe the privacy of the data subject.” Furthermore, Condition 1 of POPIA (Accountability) places the obligation on responsible parties to ensure all processing complies with POPIA.
A personal information impact assessment is a practical tool for demonstrating compliance with several core POPIA conditions, including:
- Condition 2 (processing limitation) ensures personal data is collected lawfully and minimally.
- Condition 4 (further processing limitation) assesses whether future uses of the data are compatible with the original purpose.
- Condition 7 (security safeguards) identifies technical and organisational security measures needed to protect the data.
- Condition 8 (data subject participation) helps consider how the data subject can access or correct their data.
The law requires responsible parties to conduct Personal Information Impact Assessments
While POPIA does not explicitly use the term “impact assessment”, POPIA Regulation 4(1)(b) says that “an Information Officer must ensure that a personal information impact assessment is done to ensure that adequate measures and standards exist in order to comply with the conditions for the lawful processing of personal information”. This wording is not precise and does not accurately describe the purpose of a PIIA.
Two of the questions in the Information Regulator’s self-assessment relate to PIIAs.
- “Have Personal Information Impact Assessments (PIIAs) been conducted for new projects or processes involving the processing of personal information? [Regulation 4(1)(b)]”
- “Are PIIAs regularly reviewed and updated as necessary?”
From these questions, it is clear the Information Regulator requires responsible parties to conduct multiple PIIAs on an ongoing basis and not just once off. This is one of the reaosn why an impact assessment is not a gap analysis.
Responsible parties to conduct multiple PIIAs on an ongoing basis
When should you conduct a PIIA?
You should conduct a PIIA before starting any new processing activity that is likely to pose a high risk to the privacy rights of individuals. Examples include:
- Deploying surveillance or facial recognition tools
- Launching a new customer management system
- Rolling out biometric attendance tools
- Sharing data with third-party vendors or cloud platforms
- Using AI or algorithmic profiling to make decisions about people
How do you conduct a Personal Information Impact Assessment?
The assessment typically follows a structured process that includes several steps. We have developed a PIIA process that works. At a very high level, it follows the following steps.
- Identify the need: Determine whether the processing activity involves sensitive or large volumes of personal information or uses new technology that may pose a privacy risk.
- Describe the processing: Set out what data will be collected, why, how it will be used, who will have access, and where it will be stored or transferred.
- Assess lawfulness and necessity: Check whether the processing meets one of POPIA’s legal grounds and whether the purpose justifies the means of processing.
- Identify risks: Analyse the potential impact on data subjects, including unauthorised access, misuse, data breaches, or discrimination.
- Mitigate risks: Propose security measures, access controls, training, or policy changes to address the identified risks.
- Document and review: Record the assessment and keep a copy for accountability. Review it periodically, especially when the processing changes.
Conducting personal information impact assessments under POPIA isn’t just a compliance checkbox—it’s a critical tool for protecting privacy, managing risk, and building trust with stakeholders. Embedding PIIAs into your project lifecycle will help ensure your data processing practices remain lawful, fair, and secure. Conducting a PIIA can be a challenging task and requires collaboration among the various teams involved in the project lifecycle.
A PIIA often requires a team effort from the Information Officer, GRC people and people in the business.
Actions to take to comply with the regulatory requirement for PIIAs
- Identify high-risk processing activities that may require a PIIA.
- Develop or adopt a standard PIIA template for internal use by asking the Michalsons team to create one for your organisation.
- Conduct PIIAs by asking Michalson to do them for you.
- Conduct your own PIIAs by asking Michalsons to empower you by providing you with a PIIA template, train you on the methodology of how to do them by
running a workshop and doing one for you as an example. - Train key staff (especially IT, legal, compliance, and data teams) on when and how to carry out a PIIA by asking Michalsons to hold a private workshop for your organisation.
- Empower your people to conduct PIIAs by joining the Michalsons Data Protection Programme and working through the module on conducting PIAs.
- Integrate PIIAs into procurement and system design workflows.
- Involve the Information Officer early in the project planning process to identify whether a PIIA is required.
- Document all assessments you conduct and keep them up to date.
- Be prepared to show the Information Regulator how risks were identified and addressed.