We can do a Privacy Impact Assessment (PIA) for you. Some people, especially in the EU where the GDPR applies, call it a Data Protection Impact Assessment (DPIA). The POPIA regulations in South Africa require personal information impact assessments (PIIAs). They are essentially flavours of the same thing, although there are differences. Generally speaking, a DPIA or PIIA is a specialised, high-risk subset of a PIA. While many people use the terms interchangeably in casual conversation, a PIA is a broad, proactive planning tool, whereas a DPIA or PIIA is a strict, legally triggered exercise focused on severe risks to data subjects.
We have studied International trends and best practices regarding impact assessments and have conducted many for our clients.
In this article, we discuss one kind of impact assessment (a privacy impact assessment). You also get an organisational impact assessment and a regulatory impact assessment. You can read more about legal assessments. It is important to know which one you are referring to. We can also do a gap analysis or a compliance audit, but those are something different. The names of these different things all sound very similar, but they are quite different things. You can also do a privacy impact assessment yourself with our guidance by joining our data protection programme and working through the Conducting Privacy Impact Assessments module.
How you benefit from a privacy impact assessment
- Ensure that adequate measures and standards exist
- Know where the biggest impact will be
- Know where to focus your efforts
- Know the scope of the remedial work that needs to be done and how best to do it
- Reduce your legal compliance workload
An assessment focuses on where your organisation is at a point in time.
When should I do a PIA?
Your organisation should conduct a PIA before starting a project or beginning to process personal data in terms of a particular processing activity, when there is an opportunity to affect the outcome. You can still do it during or afterwards, but it won’t be nearly as effective. You will do PIAs many times in the future and at different points in time. Doing PIAs is part of protecting personal data and is an ongoing exercise. For example, you might do one once a year, and it might take you two weeks each time. You should also do a PIA if you are going to launch a new product or service that involves the processing of personal data.
Sometimes, we recommend conducting a privacy impact assessment for just one of your activities or processes.
Actions you can take
- Conduct a privacy impact assessment by asking Michalsons to do one for you.
- Attend our next workshop on PIAs.
- Conduct a privacy impact assessment yourself with our guidance by joining a Data Protection Programme and working through the Conducting Privacy Impact Assessments module.
- Understand the impact of data protection on your organisation by doing a quick complimentary organisational impact assessment (to assess the high-level impact of applicable data protection laws on your organisation and evaluate the best way forward).
- Check that you are conducting impact assessments correctly by asking us to review your process and outcomes.
What do you assess?
We assess:
- what laws you must comply with,
- the impact the applicable privacy laws or issues will have on your organisation or on a specific activity, process, or application,
- your current privacy practices,
- your current state of compliance with data protection laws,
- where the biggest impact will be, and
- what you should focus on.
