Albania
IDP · Information and Data Protection Commissioner
Europe · National Supervisory Authority
Global PIA CompositePrimary lawPersonal Data Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Algeria
ANPDP · National Authority for the Protection of Personal Data
Africa · National supervisory authority
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Andorra
APDA · Andorran Data Protection Agency
Europe · National Supervisory Authority
Global PIA CompositePrimary lawOrganic Law on Data Protection
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Angola
APD · Data Protection Agency
Africa · National supervisory authority
Global PIA CompositePrimary lawLDP
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Antigua and Barbuda
Information Commissioner · Information Commissioner
Americas · National supervisory authority
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Argentina
AAIP · Agency of Access to Public Information
Americas · National supervisory authority
Global PIA CompositePrimary lawLGPDP
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Armenia
PDPA Armenia · Personal Data Protection Agency
Europe · National Supervisory Authority
Global PIA CompositePrimary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Australia
OAIC · Office of the Australian Information Commissioner
Asia-Pacific · National privacy authority
OAIC PIAPrimary lawPrivacy Act
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionUse the OAIC risk-proportionate PIA process and verify any Australian Government, state, territory or sector-specific mandatory requirement.
Trigger testNew or changed projects involving personal information, intrusive technology, matching, biometrics, surveillance, AI, significant data sharing or sensitive information.
Required methodThreshold assessment; plan; describe project; identify stakeholders; map information flows; analyse impacts; manage risks; make recommendations; report; implement and review.
Authority escalationEngage privacy, security, legal and affected stakeholders. Check whether an agency, regulator or governance body requires submission or publication.
Review ruleTrack recommendation implementation and repeat when the project or information handling changes.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Austria
DSB · Austrian Data Protection Authority
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Azerbaijan
Authority · Ministry of Digital Development and Transport / competent authority
Europe · No dedicated authority confirmed in the source; verify before reliance
Global PIA CompositePrimary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bahamas
DPC Bahamas · Data Protection Commissioner
Americas · National supervisory authority
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bahrain
PDPA Bahrain · Personal Data Protection Authority
Middle East · National supervisory authority
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bangladesh
Authority · Data Protection Board / competent authority
Asia-Pacific · Operational status should be verified
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Barbados
DPC Barbados · Data Protection Commission
Americas · National supervisory authority
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Belarus
NCPDP · National Center for Personal Data Protection
Europe · National Supervisory Authority
Global PIA CompositePrimary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Belgium
APD-GBA · Belgian Data Protection Authority
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Belize
Authority · Information Commissioner / competent data protection authority
Americas · Current authority details should be verified
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Benin
APDP · Personal Data Protection Authority
Africa · National supervisory authority
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bhutan
Authority · GovTech Agency / competent privacy authority
Asia-Pacific · Current institutional position should be verified
Global PIA CompositePrimary lawPrivacy Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bolivia
Authority · Personal Data Protection Agency / competent authority
Americas · Current institutional position should be verified
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bosnia and Herzegovina
AZLP · Personal Data Protection Agency in Bosnia and Herzegovina
Europe · National Supervisory Authority
Global PIA CompositePrimary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Botswana
Authority · Information and Data Protection Commission / competent authority
Africa · Current institutional position should be verified
Global PIA CompositePrimary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Brazil
ANPD · National Data Protection Authority
Americas · National supervisory authority
Brazil RIPDPrimary lawLGPD
DPIA terminologyRelatório de Impacto à Proteção de Dados Pessoais (RIPD)
Legal positionAssess whether the LGPD, ANPD request, sensitive data, legitimate-interests governance or high-impact processing requires or supports a RIPD.
Trigger testHigh-risk or sensitive processing, profiling, vulnerable people, large scale, legitimate interests, public-sector data sharing or processing identified by the ANPD.
Required methodDescribe data, methodology, safeguards, purposes, necessity, risks, mitigations, responsible persons and evidence.
Authority escalationThe ANPD may request the report. Verify current regulations, guidance and sector-specific requirements.
Review ruleUpdate for material changes and maintain evidence for ANPD scrutiny.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
British Virgin Islands
ICO BVI · Information Commissioner
Americas · National supervisory authority
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Brunei Darussalam
AITI · Authority for Info-communications Technology Industry / competent privacy authority
Asia-Pacific · Current institutional position should be verified
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bulgaria
CPDP · Commission for Personal Data Protection
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Cambodia
MPTC · Ministry of Posts and Telecommunications / competent privacy authority
Asia-Pacific · Current institutional position should be verified
Global PIA CompositePrimary lawPersonal Data Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Canada
OPC · Office of the Privacy Commissioner of Canada
Americas · Federal privacy authority; provincial authorities may also apply
Canada PIAPrimary lawPIPEDA
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionDetermine the applicable federal, provincial and public-sector PIA requirement. Federal institutions should apply the current Treasury Board and OPC process.
Trigger testNew or substantially modified programme, activity, system or service involving personal information, particularly sensitive data, matching, AI, biometrics and cross-border services.
Required methodDescribe authority and programme; map flows; identify privacy risks and compliance gaps; document mitigations, residual risk, approval and submission requirements.
Authority escalationIdentify the correct federal or provincial commissioner and any mandatory review or submission route.
Review ruleUpdate for material programme or technology change and track mitigation implementation.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Chile
CPLT · Council for Transparency / competent data protection authority
Americas · Institutional allocation should be verified
Global PIA CompositePrimary lawLaw 19628
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Colombia
SIC · Superintendence of Industry and Commerce
Americas · National data protection authority
Global PIA CompositePrimary lawLaw 1581
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Congo, Democratic Republic of the
ARPTC · Post and Telecommunications Regulatory Authority / competent data authority
Africa · Current institutional position should be verified
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Côte d'Ivoire
ARTCI · Telecommunications/ICT Regulatory Authority of Côte d’Ivoire
Africa · Personal data supervisory authority
Global PIA CompositePrimary lawPersonal Data Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Croatia
AZOP · Croatian Personal Data Protection Agency
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Cyprus
OCPDP · Office of the Commissioner for Personal Data Protection
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Czech Republic
UOOU · Office for Personal Data Protection
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Denmark
Datatilsynet · Danish Data Protection Agency
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Egypt
PDPC Egypt · Personal Data Protection Centre / competent authority
Africa · Operational authority details should be verified
Global PIA CompositePrimary lawLaw on Regulated Professions
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Estonia
AKI · Estonian Data Protection Inspectorate
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Eswatini
Authority · Eswatini Data Protection Authority / competent regulator
Africa · Current institutional position should be verified
Global PIA CompositePrimary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Ethiopia
ECA · Ethiopian Communications Authority / competent privacy authority
Africa · Current institutional position should be verified
Global PIA CompositePrimary lawPrivacy Directive
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Finland
ODPO · Office of the Data Protection Ombudsman
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
France
CNIL · Commission Nationale de l'Informatique et des Libertés
European Union · National Supervisory Authority
CNIL AIPDPrimary lawGDPR
DPIA terminologyAnalyse d’impact relative à la protection des données (AIPD)
Legal positionApply the CNIL required and non-required lists, GDPR Article 35 and the high-risk criteria before processing.
Trigger testNational mandatory-list activity, GDPR Article 35(3), or processing meeting the CNIL / EDPB high-risk criteria.
Required methodUse the CNIL four-part method: context; fundamental principles including necessity and proportionality; privacy risks; formal validation, action plan and ongoing review.
Authority escalationRecord DPO advice. Consult the CNIL before processing where residual high risk remains after mitigation.
Review ruleMaintain the AIPD as a living record and reassess material changes, incidents and control failures.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Germany
BfDI · Federal Commissioner for Data Protection and Freedom of Information
European Union · Federal Supervisory Authority; state authorities also apply
Germany DSK / BfDI DSFAPrimary lawGDPR
DPIA terminologyDatenschutz-Folgenabschätzung (DSFA)
Legal positionApply GDPR Article 35 and the applicable BfDI, DSK or state authority mandatory list according to controller type and competence.
Trigger testMandatory-list processing, significant automated evaluation, extensive monitoring, sensitive data at scale and other likely high-risk processing.
Required methodDescribe processing and legal context; test necessity and proportionality; model threats and impacts on people; document safeguards, DPO advice, residual risk and review.
Authority escalationIdentify the competent federal or state authority. Prior consultation is required where high residual risk remains.
Review ruleReview after significant change and where monitoring shows risk assumptions or controls are no longer valid.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Ghana
DPC Ghana · Data Protection Commission
Africa · National supervisory authority
Global PIA CompositePrimary lawGDPA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Greece
HDPA · Hellenic Data Protection Authority
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Hong Kong
PCPD · Office of the Privacy Commissioner for Personal Data
Asia-Pacific · Privacy regulator
Hong Kong PIAPrimary lawPDPO
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionUse a PIA as accountability and privacy-by-design practice and verify sector or public-body requirements under the PDPO.
Trigger testNew systems, surveillance, biometrics, matching, AI, direct marketing, major sharing or processing that materially changes privacy risk.
Required methodMap data flows, assess Data Protection Principles, identify impacts, controls, owners and residual risks, then monitor implementation.
Authority escalationEngage the Data Protection Officer and consider PCPD guidance or consultation for novel or high-impact processing.
Review ruleReassess material changes and control effectiveness.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Hungary
NAIH · Hungarian National Authority for Data Protection and Freedom of Information
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
India
DPB · Data Protection Board of India
Asia-Pacific · Operational status and contact route should be verified
India DPIAPrimary lawDPDP Act
DPIA terminologyData protection impact / significant data fiduciary assessment
Legal positionVerify current DPDPA rules, significant data fiduciary designation and any sectoral or contractual impact-assessment requirement.
Trigger testHigh-volume or high-risk processing, sensitive sector data, children, profiling, AI, monitoring, cross-border processing and designation-based obligations.
Required methodDescribe purpose and data; test necessity and safeguards; assess harms to data principals; document rights, security, processors, residual risk and approval.
Authority escalationEngage the Data Protection Officer where appointed and verify Data Protection Board or sector regulator expectations.
Review ruleReassess material processing changes and prescribed periodic requirements.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Indonesia
PDP Authority · Personal Data Protection supervisory authority
Asia-Pacific · Institutional arrangements should be verified
Global PIA CompositePrimary lawPDP Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Ireland
DPC · Data Protection Commission
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Israel
PPA Israel · Privacy Protection Authority
Middle East · National supervisory authority
Global PIA CompositePrimary lawPrivacy Law 1981
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Italy
Garante · Garante per la protezione dei dati personali
European Union · National Supervisory Authority
Italy Garante DPIAPrimary lawGDPR
DPIA terminologyValutazione d’impatto sulla protezione dei dati (DPIA)
Legal positionApply GDPR Article 35 and the Garante list of processing subject to DPIA.
Trigger testInnovative technology, systematic monitoring, profiling, vulnerable people, biometric or sensitive data, large scale and other Garante list triggers.
Required methodDocument processing, purposes, necessity, proportionality, rights risks, safeguards, DPO advice, approvals and implementation monitoring.
Authority escalationConsult the Garante before processing where residual high risk cannot be adequately mitigated.
Review ruleUpdate for material processing, technology, vendor, scale or risk changes.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Japan
PPC · Personal Information Protection Commission
Asia-Pacific · National supervisory authority
Japan PIAPrimary lawAPPI
DPIA terminologyPrivacy impact / personal information risk assessment
Legal positionDetermine whether a PIA is required by sector, public-body rules, procurement or organisational governance and apply APPI accountability.
Trigger testSensitive personal information, profiling, AI, large-scale data, cross-border provision, biometrics, location and novel surveillance.
Required methodMap data and third-party provision; identify purpose, notices, consent and security requirements; assess harms; assign safeguards and review.
Authority escalationEngage the privacy lead and relevant sector authority. Verify PPC guidance and notification or consultation requirements.
Review ruleUpdate for new purposes, vendors, transfers, security changes and material risk.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Jordan
PDPC Jordan · Personal Data Protection Council / Ministry of Digital Economy and Entrepreneurship
Middle East · National privacy authority
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Kenya
ODPC · Office of the Data Protection Commissioner
Africa · National supervisory authority
Global PIA CompositePrimary lawDPA 2019
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Latvia
DVI · Data State Inspectorate
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Lesotho
DPC Lesotho · Data Protection Commission
Africa · National supervisory authority
Global PIA CompositePrimary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Lithuania
VDAI · State Data Protection Inspectorate
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Luxembourg
CNPD · National Commission for Data Protection
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Malawi
Authority · Data Protection Authority / Malawi Communications Regulatory Authority
Africa · Competence should be verified
Global PIA CompositePrimary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Malaysia
JPDP · Personal Data Protection Commissioner
Asia-Pacific · National supervisory authority
Global PIA CompositePrimary lawPDPA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Malta
IDPC · Office of the Information and Data Protection Commissioner
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Mexico
Federal authority · Competent federal transparency and personal data authority
Americas · Institutional position should be verified for the date of use
Global PIA CompositePrimary lawLGPD
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Moldova
NCPDP · National Centre for Personal Data Protection
Europe · National Supervisory Authority
Global PIA CompositePrimary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Morocco
CNDP · National Commission for the Control of Personal Data Protection
Africa · National supervisory authority
Global PIA CompositePrimary lawGDPL
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Mozambique
INTIC · National Institute of Information and Communication Technologies / competent authority
Africa · Current institutional position should be verified
Global PIA CompositePrimary lawLPDA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Netherlands
AP · Dutch Data Protection Authority
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
New Zealand
OPC NZ · Office of the Privacy Commissioner
Asia-Pacific · National privacy authority
New Zealand OPC PIAPrimary lawPrivacy Act 2020
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionUse a brief or full PIA proportionate to risk and verify sector or public-body requirements.
Trigger testNew or changed collection, use, disclosure, data matching, AI, biometrics, surveillance, sensitive information or material effects on individuals.
Required methodDefine scope, map information flows, consult, identify privacy impacts, rate risks, assign mitigations, approve and review.
Authority escalationUse the privacy officer and seek OPC advice where significant uncertainty or unresolved risk remains.
Review ruleReview implementation and reassess when processing or risks materially change.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Nigeria
NDPC · Nigeria Data Protection Commission
Africa · National supervisory authority
Global PIA CompositePrimary lawNDPR
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Norway
Datatilsynet · Norwegian Data Protection Authority
Europe · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Peru
ANPD · National Authority for Personal Data Protection
Americas · National supervisory authority
Global PIA CompositePrimary lawLaw 29733
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Philippines
NPC · National Privacy Commission
Asia-Pacific · National supervisory authority
Global PIA CompositePrimary lawDP Act 2012
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Poland
UODO · Personal Data Protection Office
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Portugal
CNPD · National Data Protection Commission
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Qatar
NCGAA · National Cyber Governance and Assurance Affairs / competent privacy authority
Middle East · Current institutional position should be verified
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Romania
ANSPDCP · National Supervisory Authority for Personal Data Processing
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Russian Federation
Roskomnadzor · Federal Service for Supervision of Communications, Information Technology and Mass Media
Europe · Federal supervisory authority
Global PIA CompositePrimary lawFederal Law on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Saudi Arabia
SDAIA/NDMO · Saudi Data and Artificial Intelligence Authority / National Data Management Office
Middle East · National data governance authority
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Singapore
PDPC · Personal Data Protection Commission
Asia-Pacific · National regulatory authority
Singapore PDPC DPIAPrimary lawPDPA
DPIA terminologyData Protection Impact Assessment (DPIA)
Legal positionApply a lifecycle-based DPIA as accountability practice and verify any sectoral or contractual mandate.
Trigger testNew or changed high-impact processing, sensitive information, profiling, monitoring, AI, large-scale sharing or cross-border processing.
Required methodScope and describe processing; assess compliance, necessity, proportionality and risks; identify safeguards; approve; implement; monitor and review.
Authority escalationEngage the Data Protection Officer and sector regulator where applicable. Verify whether notification or consultation is required for the particular processing.
Review ruleMaintain throughout the system and data lifecycle.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Slovakia
UOOU SR · Office for Personal Data Protection of the Slovak Republic
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Slovenia
IP-RS · Information Commissioner of the Republic of Slovenia
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
South Africa
IR · Information Regulator
Africa · National supervisory authority
South Africa PIAPrimary lawPOPIA
DPIA terminologyPrivacy impact and risk assessment under POPIA accountability
Legal positionUse a documented assessment to demonstrate responsible-party accountability and verify current Information Regulator guidance and sector rules.
Trigger testSpecial personal information, children, biometrics, profiling, surveillance, extensive matching, cross-border processing or material risk to data subjects.
Required methodDocument purpose, lawful justification, minimality, openness, security safeguards, participation rights, operators, cross-border conditions, risks and controls.
Authority escalationEngage the Information Officer and determine whether prior authorisation or regulator engagement applies to the processing.
Review ruleReview on material change, incident, complaint or control failure.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Spain
AEPD · Spanish Data Protection Agency
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Sweden
IMY · Swedish Authority for Privacy Protection
European Union · National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Switzerland
FDPIC · Federal Data Protection and Information Commissioner
Europe · Federal Supervisory Authority
Switzerland DPIAPrimary lawFederal Data Protection Act
DPIA terminologyData protection impact assessment under the Federal Act on Data Protection
Legal positionAssess planned processing likely to result in high risk to personality or fundamental rights and verify current federal guidance.
Trigger testSensitive personal data at scale, systematic monitoring, profiling with high risk, innovative or extensive processing and other circumstances creating likely high risk.
Required methodDescribe processing; assess risks to affected people; document measures; consult the data protection adviser where appointed; record residual risk and decision.
Authority escalationDetermine whether consultation with the FDPIC is required where high residual risk remains and is not resolved through the statutory adviser route.
Review ruleUpdate where risk or processing changes materially.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Tanzania
PDPC Tanzania · Personal Data Protection Commission
Africa · National supervisory authority
Global PIA CompositePrimary lawDPA 2022
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Thailand
PDPC · Personal Data Protection Committee / Office of the PDPC
Asia-Pacific · National supervisory authority
Global PIA CompositePrimary lawPDPA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Uganda
PDPO · Personal Data Protection Office
Africa · National supervisory authority
Global PIA CompositePrimary lawDPA 2019
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United Arab Emirates
UAE Data Office · UAE Data Office
Middle East · Federal privacy authority; free-zone regulators may also apply
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United Kingdom
ICO · Information Commissioner's Office
Europe · National Supervisory Authority
UK ICO DPIAPrimary lawUK GDPR
DPIA terminologyUK GDPR Data Protection Impact Assessment
Legal positionComplete a DPIA before high-risk processing. Apply UK GDPR Article 35, the ICO high-risk processing list and current UK guidance.
Trigger testSystematic evaluation with significant effects, large-scale special-category or criminal data, systematic public monitoring and other processing identified by the ICO as likely high risk.
Required methodDescribe processing and consultation; assess necessity and proportionality; identify and assess risks to rights and freedoms; identify measures and safeguards; record DPO advice and sign-off.
Authority escalationConsult the DPO. Submit a prior-consultation request to the ICO before processing where identified high residual risk cannot be reduced.
Review ruleKeep the DPIA under review and update it when the nature, scope, context, purposes, technology or risk changes.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Alabama
AL AG · Alabama Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Alaska
AK AG · Alaska Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Arizona
AZ AG · Arizona Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Arkansas
AR AG · Arkansas Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawACDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - California
CPPA · California Privacy Protection Agency
United States · State privacy regulator; Attorney General also has enforcement functions
California CPPA Risk AssessmentPrimary lawCCPA/CPRA
DPIA terminologyCalifornia privacy risk assessment
Legal positionApply California risk-assessment requirements and rules to covered processing that presents significant risk to consumers’ privacy.
Trigger testCovered processing identified by current CCPA regulations, including relevant sale or sharing, sensitive data, profiling or automated decision-making and other significant-risk activity.
Required methodDocument purpose, benefits, data categories, affected consumers, safeguards, negative impacts, necessity, alternatives, responsible persons and certification or submission requirements.
Authority escalationIdentify CPPA and Attorney General competence. Verify filing, certification, timing and record-retention requirements in the current regulations.
Review ruleUpdate when processing materially changes and at any required periodic interval.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Colorado
CO AG · Colorado Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawCPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Connecticut
CT AG · Connecticut Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawCTDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Delaware
DE AG · Delaware Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawDPDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - District of Columbia
DC AG · District of Columbia Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Florida
FL AG · Florida Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFDBR
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Georgia
GA AG · Georgia Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Hawaii
HI AG · Hawaii Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Idaho
ID AG · Idaho Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Illinois
IL AG · Illinois Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Indiana
IN AG · Indiana Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawICDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Iowa
IA AG · Iowa Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawICDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Kansas
KS AG · Kansas Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Kentucky
KY AG · Kentucky Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawKCDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Louisiana
LA AG · Louisiana Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Maine
ME AG · Maine Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Maryland
MD AG · Maryland Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawMODPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Massachusetts
MA AG · Massachusetts Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Michigan
MI AG · Michigan Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Minnesota
MN AG · Minnesota Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawMNDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Mississippi
MS AG · Mississippi Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Missouri
MO AG · Missouri Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Montana
MT AG · Montana Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawMCDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Nebraska
NE AG · Nebraska Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawNDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Nevada
NV AG · Nevada Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawNDPP
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - New Hampshire
NH AG · New Hampshire Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawNHDPP
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - New Jersey
NJ AG · New Jersey Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawNJDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - New Mexico
NM AG · New Mexico Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - New York
NY AG · New York Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawNYDSA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - North Carolina
NC AG · North Carolina Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - North Dakota
ND AG · North Dakota Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Ohio
OH AG · Ohio Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Oklahoma
OK AG · Oklahoma Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Oregon
OR AG · Oregon Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawOCPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Pennsylvania
PA AG · Pennsylvania Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Rhode Island
RI AG · Rhode Island Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - South Carolina
SC AG · South Carolina Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - South Dakota
SD AG · South Dakota Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Tennessee
TN AG · Tennessee Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawTIPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Texas
TX AG · Texas Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawTDPSA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Utah
UT AG · Utah Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawUCPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Vermont
VT AG · Vermont Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawVDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Virginia
VA AG · Virginia Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawVCDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Washington
WA AG · Washington Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - West Virginia
WV AG · West Virginia Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Wisconsin
WI AG · Wisconsin Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Wyoming
WY AG · Wyoming Attorney General
United States · State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Vietnam
MPS · Ministry of Public Security / competent personal data authority
Asia-Pacific · National competent authority
Global PIA CompositePrimary lawLaw on Info Security
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Zambia
DPA Zambia · Data Protection Commissioner / Data Protection Authority
Africa · National supervisory authority
Global PIA CompositePrimary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.