PIA Questionnaire and Risk Assessment Tool

Privacy Impact Assessment

Submitted by:

Process (System/Manual):

Process Owner:

Date Conducted:

Personal Data Inventory

Personal Data Type (PI/SPI) Collection Use Storage Disclosure Disposal Remarks

Privacy Impact Analysis

Legitimate Purpose

Question Yes No N/A Remarks / Justification
Is there a lawful basis for processing personal data?
Is the processing compatible with a declared and specified purpose?
Are all functionalities aligned to the purpose?

Transparency

Question Yes No N/A Remarks / Justification
Are the information provided prior to the collection? Please specify how in the remarks section.
Does the privacy notice remain accessible any time a data subject wants to know more about the processing system? Please specify how in the remarks section.

Proportionality

Question Yes No N/A Remarks / Justification
Is the processing of personal data adequate, relevant, and not excessive?
Has the necessity of each personal data been assessed?
Is it possible to achieve the purpose by processing fewer personal data?
Will the "need-to-know" principle be adopted when granting access?
Does the processing use the least intrusive & most privacy-preserving method based on industry standards?
Will the processing stop once the purpose is achieved?

Data Subject Rights

Data Subject Right Procedures to Exercise Controls Acceptable (Y/N) Remarks / Justification
Right to be informed
Right to access
Right to object
Right to erasure
Right to damages
Right to file a complaint
Right to rectify
Right to data portability

Risk Table

Vulnerability Threat Risk Impact Probability Risk Rating Mitigation Residual Risk Action Date

Signatories

Drafted By:
Reviewed By:
Recommended By:
Approved By: