Evidence
When a privacy impact assessment is actually required
Organisations either assess nothing or try to assess everything. Both fail, and the second fails more expensively.
Facts checked — 2026-09-11
Which processing crosses the threshold?
The requirement is a process, applied where processing is likely to result in high risk: large-scale processing of sensitive data, systematic monitoring, automated decisions with legal or similarly significant effects, novel technology applied to personal data.
The assessment describes the processing and its purpose, assesses necessity and proportionality, identifies risks to individuals — not to the organisation — and sets out the measures that address them. Done at design time it changes decisions; done after launch it documents them.
The bottom line
Run it before the build, not after. An assessment that cannot change the design is a record, not an assessment.
Related services
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.