PIAs are a tool or process that is implemented to assess risk in relation to the collection, use and disclosure of personal information; information relating to the identity of an individual.
Concerned mainly with protection and privacy, PIAs can help organisations embed policies that prevent risk, law breaches and non-compliance with upcoming regulations like the EU General Data Protection Regulation (GDPR). By 2018, when the EU GDPR is in place, businesses should look to have PIAs embedded as part of a business approval or procurement process, including when existing processes are redesigned or otherwise changed.
In the UK, the Information Commissioner (ICO) provides a code of practice for Privacy Impact Assessments, and this is considered necessary reading for all organisations that deal with Personal Data.
Download our latest research with Data IQ to help benchmark yourself against other organisations for GDPR preparedness.