StructureClerk

Privacy impact assessment

Also known as: PIA · DPIA · data protection impact assessment

A privacy impact assessment is the analysis run before a project to identify the risks it creates for people's privacy and decide on the measures that reduce them.

It happens before, not after: its whole point is to change the design while that is still possible. An assessment produced after launch is a compliance document, not a decision tool.

The most common triggers are acquiring a system that processes sensitive information, disclosing information outside the originating jurisdiction, and large-scale or systematically monitored processing.

It concludes in a documented decision: proceed, modify, or abandon. That conclusion is what an investigation asks for, more than the detail of the analysis.

What it means for a small business

It does not need to run thirty pages. Two pages that honestly name the risk, the chosen measure and the person who decided beat a template filled in without conviction.

So what actually applies to you?

A definition tells you what a term means, not what your organization must do. The assessment answers the second question — free, no credit card.

Updated September 1, 2026 · Educational definition; not legal advice.