Skip to content
SecuriFii

Evidence

When a privacy impact assessment is actually required

Organisations either assess nothing or try to assess everything. Both fail, and the second fails more expensively.

Facts checked2026-09-11

Which processing crosses the threshold?

The requirement is a process, applied where processing is likely to result in high risk: large-scale processing of sensitive data, systematic monitoring, automated decisions with legal or similarly significant effects, novel technology applied to personal data.

The assessment describes the processing and its purpose, assesses necessity and proportionality, identifies risks to individuals — not to the organisation — and sets out the measures that address them. Done at design time it changes decisions; done after launch it documents them.

The bottom line

Run it before the build, not after. An assessment that cannot change the design is a record, not an assessment.

Related insights