The Privacy Impact Assessment (PIA) is a systematic process for identifying and assessing privacy risks posed by a project or development.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Executable approach: can be applied and produces an outcome.
What organizes, connects, or makes decisions possible.
A privacy impact assessment identifies early which privacy risks a project may create for people and how those risks can be mitigated.
The approach grew from privacy assessments for information-intensive projects and became binding in Europe through Article 35 of the General Data Protection Regulation. Authorities such as the EDPB and the BfDI refine its criteria and process.
Before launch, the data flow is viewed like a building plan: purpose, participants, risks, and safeguards become visible. If high risk remains, the project must change or receive additional supervisory consultation.
The assessment records where data goes and why.
Severity and likelihood of possible harm are assessed.
Technical and organizational controls reduce risk.
A PIA turns privacy into a testable design decision and documents safeguards. It fits high-risk processing; a document lowers risk only when measures are implemented and maintained.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.