Privacy impact assessment
Also known as: PIA · DPIA · data protection impact assessment
A privacy impact assessment is the analysis run before a project to identify the risks it creates for people's privacy and decide on the measures that reduce them.
It happens before, not after: its whole point is to change the design while that is still possible. An assessment produced after launch is a compliance document, not a decision tool.
The most common triggers are acquiring a system that processes sensitive information, disclosing information outside the originating jurisdiction, and large-scale or systematically monitored processing.
It concludes in a documented decision: proceed, modify, or abandon. That conclusion is what an investigation asks for, more than the detail of the analysis.
What it means for a small business
It does not need to run thirty pages. Two pages that honestly name the risk, the chosen measure and the person who decided beat a template filled in without conviction.
So what actually applies to you?
A definition tells you what a term means, not what your organization must do. The assessment answers the second question — free, no credit card.
Updated September 1, 2026 · Educational definition; not legal advice.