Albania
IDP ยท Information and Data Protection Commissioner
Europe ยท National Supervisory Authority
Global PIA CompositePrimary lawPersonal Data Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Algeria
ANPDP ยท National Authority for the Protection of Personal Data
Africa ยท National supervisory authority
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Andorra
APDA ยท Andorran Data Protection Agency
Europe ยท National Supervisory Authority
Global PIA CompositePrimary lawOrganic Law on Data Protection
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Angola
APD ยท Data Protection Agency
Africa ยท National supervisory authority
Global PIA CompositePrimary lawLDP
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Antigua and Barbuda
Information Commissioner ยท Information Commissioner
Americas ยท National supervisory authority
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Argentina
AAIP ยท Agency of Access to Public Information
Americas ยท National supervisory authority
Global PIA CompositePrimary lawLGPDP
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Armenia
PDPA Armenia ยท Personal Data Protection Agency
Europe ยท National Supervisory Authority
Global PIA CompositePrimary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Australia
OAIC ยท Office of the Australian Information Commissioner
Asia-Pacific ยท National privacy authority
OAIC PIAPrimary lawPrivacy Act
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionUse the OAIC risk-proportionate PIA process and verify any Australian Government, state, territory or sector-specific mandatory requirement.
Trigger testNew or changed projects involving personal information, intrusive technology, matching, biometrics, surveillance, AI, significant data sharing or sensitive information.
Required methodThreshold assessment; plan; describe project; identify stakeholders; map information flows; analyse impacts; manage risks; make recommendations; report; implement and review.
Authority escalationEngage privacy, security, legal and affected stakeholders. Check whether an agency, regulator or governance body requires submission or publication.
Review ruleTrack recommendation implementation and repeat when the project or information handling changes.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Austria
DSB ยท Austrian Data Protection Authority
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Azerbaijan
Authority ยท Ministry of Digital Development and Transport / competent authority
Europe ยท No dedicated authority confirmed in the source; verify before reliance
Global PIA CompositePrimary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bahamas
DPC Bahamas ยท Data Protection Commissioner
Americas ยท National supervisory authority
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bahrain
PDPA Bahrain ยท Personal Data Protection Authority
Middle East ยท National supervisory authority
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bangladesh
Authority ยท Data Protection Board / competent authority
Asia-Pacific ยท Operational status should be verified
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Barbados
DPC Barbados ยท Data Protection Commission
Americas ยท National supervisory authority
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Belarus
NCPDP ยท National Center for Personal Data Protection
Europe ยท National Supervisory Authority
Global PIA CompositePrimary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Belgium
APD-GBA ยท Belgian Data Protection Authority
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Belize
Authority ยท Information Commissioner / competent data protection authority
Americas ยท Current authority details should be verified
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Benin
APDP ยท Personal Data Protection Authority
Africa ยท National supervisory authority
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bhutan
Authority ยท GovTech Agency / competent privacy authority
Asia-Pacific ยท Current institutional position should be verified
Global PIA CompositePrimary lawPrivacy Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bolivia
Authority ยท Personal Data Protection Agency / competent authority
Americas ยท Current institutional position should be verified
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bosnia and Herzegovina
AZLP ยท Personal Data Protection Agency in Bosnia and Herzegovina
Europe ยท National Supervisory Authority
Global PIA CompositePrimary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Botswana
Authority ยท Information and Data Protection Commission / competent authority
Africa ยท Current institutional position should be verified
Global PIA CompositePrimary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Brazil
ANPD ยท National Data Protection Authority
Americas ยท National supervisory authority
Brazil RIPDPrimary lawLGPD
DPIA terminologyRelatรณrio de Impacto ร Proteรงรฃo de Dados Pessoais (RIPD)
Legal positionAssess whether the LGPD, ANPD request, sensitive data, legitimate-interests governance or high-impact processing requires or supports a RIPD.
Trigger testHigh-risk or sensitive processing, profiling, vulnerable people, large scale, legitimate interests, public-sector data sharing or processing identified by the ANPD.
Required methodDescribe data, methodology, safeguards, purposes, necessity, risks, mitigations, responsible persons and evidence.
Authority escalationThe ANPD may request the report. Verify current regulations, guidance and sector-specific requirements.
Review ruleUpdate for material changes and maintain evidence for ANPD scrutiny.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
British Virgin Islands
ICO BVI ยท Information Commissioner
Americas ยท National supervisory authority
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Brunei Darussalam
AITI ยท Authority for Info-communications Technology Industry / competent privacy authority
Asia-Pacific ยท Current institutional position should be verified
Global PIA CompositePrimary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Bulgaria
CPDP ยท Commission for Personal Data Protection
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Cambodia
MPTC ยท Ministry of Posts and Telecommunications / competent privacy authority
Asia-Pacific ยท Current institutional position should be verified
Global PIA CompositePrimary lawPersonal Data Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Canada
OPC ยท Office of the Privacy Commissioner of Canada
Americas ยท Federal privacy authority; provincial authorities may also apply
Canada PIAPrimary lawPIPEDA
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionDetermine the applicable federal, provincial and public-sector PIA requirement. Federal institutions should apply the current Treasury Board and OPC process.
Trigger testNew or substantially modified programme, activity, system or service involving personal information, particularly sensitive data, matching, AI, biometrics and cross-border services.
Required methodDescribe authority and programme; map flows; identify privacy risks and compliance gaps; document mitigations, residual risk, approval and submission requirements.
Authority escalationIdentify the correct federal or provincial commissioner and any mandatory review or submission route.
Review ruleUpdate for material programme or technology change and track mitigation implementation.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Chile
CPLT ยท Council for Transparency / competent data protection authority
Americas ยท Institutional allocation should be verified
Global PIA CompositePrimary lawLaw 19628
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Colombia
SIC ยท Superintendence of Industry and Commerce
Americas ยท National data protection authority
Global PIA CompositePrimary lawLaw 1581
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Congo, Democratic Republic of the
ARPTC ยท Post and Telecommunications Regulatory Authority / competent data authority
Africa ยท Current institutional position should be verified
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Cรดte d'Ivoire
ARTCI ยท Telecommunications/ICT Regulatory Authority of Cรดte dโIvoire
Africa ยท Personal data supervisory authority
Global PIA CompositePrimary lawPersonal Data Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Croatia
AZOP ยท Croatian Personal Data Protection Agency
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Cyprus
OCPDP ยท Office of the Commissioner for Personal Data Protection
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Czech Republic
UOOU ยท Office for Personal Data Protection
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Denmark
Datatilsynet ยท Danish Data Protection Agency
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Egypt
PDPC Egypt ยท Personal Data Protection Centre / competent authority
Africa ยท Operational authority details should be verified
Global PIA CompositePrimary lawLaw on Regulated Professions
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Estonia
AKI ยท Estonian Data Protection Inspectorate
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Eswatini
Authority ยท Eswatini Data Protection Authority / competent regulator
Africa ยท Current institutional position should be verified
Global PIA CompositePrimary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Ethiopia
ECA ยท Ethiopian Communications Authority / competent privacy authority
Africa ยท Current institutional position should be verified
Global PIA CompositePrimary lawPrivacy Directive
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Finland
ODPO ยท Office of the Data Protection Ombudsman
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
France
CNIL ยท Commission Nationale de l'Informatique et des Libertรฉs
European Union ยท National Supervisory Authority
CNIL AIPDPrimary lawGDPR
DPIA terminologyAnalyse dโimpact relative ร la protection des donnรฉes (AIPD)
Legal positionApply the CNIL required and non-required lists, GDPR Article 35 and the high-risk criteria before processing.
Trigger testNational mandatory-list activity, GDPR Article 35(3), or processing meeting the CNIL / EDPB high-risk criteria.
Required methodUse the CNIL four-part method: context; fundamental principles including necessity and proportionality; privacy risks; formal validation, action plan and ongoing review.
Authority escalationRecord DPO advice. Consult the CNIL before processing where residual high risk remains after mitigation.
Review ruleMaintain the AIPD as a living record and reassess material changes, incidents and control failures.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Germany
BfDI ยท Federal Commissioner for Data Protection and Freedom of Information
European Union ยท Federal Supervisory Authority; state authorities also apply
Germany DSK / BfDI DSFAPrimary lawGDPR
DPIA terminologyDatenschutz-Folgenabschรคtzung (DSFA)
Legal positionApply GDPR Article 35 and the applicable BfDI, DSK or state authority mandatory list according to controller type and competence.
Trigger testMandatory-list processing, significant automated evaluation, extensive monitoring, sensitive data at scale and other likely high-risk processing.
Required methodDescribe processing and legal context; test necessity and proportionality; model threats and impacts on people; document safeguards, DPO advice, residual risk and review.
Authority escalationIdentify the competent federal or state authority. Prior consultation is required where high residual risk remains.
Review ruleReview after significant change and where monitoring shows risk assumptions or controls are no longer valid.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Ghana
DPC Ghana ยท Data Protection Commission
Africa ยท National supervisory authority
Global PIA CompositePrimary lawGDPA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Greece
HDPA ยท Hellenic Data Protection Authority
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Hong Kong
PCPD ยท Office of the Privacy Commissioner for Personal Data
Asia-Pacific ยท Privacy regulator
Hong Kong PIAPrimary lawPDPO
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionUse a PIA as accountability and privacy-by-design practice and verify sector or public-body requirements under the PDPO.
Trigger testNew systems, surveillance, biometrics, matching, AI, direct marketing, major sharing or processing that materially changes privacy risk.
Required methodMap data flows, assess Data Protection Principles, identify impacts, controls, owners and residual risks, then monitor implementation.
Authority escalationEngage the Data Protection Officer and consider PCPD guidance or consultation for novel or high-impact processing.
Review ruleReassess material changes and control effectiveness.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Hungary
NAIH ยท Hungarian National Authority for Data Protection and Freedom of Information
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
India
DPB ยท Data Protection Board of India
Asia-Pacific ยท Operational status and contact route should be verified
India DPIAPrimary lawDPDP Act
DPIA terminologyData protection impact / significant data fiduciary assessment
Legal positionVerify current DPDPA rules, significant data fiduciary designation and any sectoral or contractual impact-assessment requirement.
Trigger testHigh-volume or high-risk processing, sensitive sector data, children, profiling, AI, monitoring, cross-border processing and designation-based obligations.
Required methodDescribe purpose and data; test necessity and safeguards; assess harms to data principals; document rights, security, processors, residual risk and approval.
Authority escalationEngage the Data Protection Officer where appointed and verify Data Protection Board or sector regulator expectations.
Review ruleReassess material processing changes and prescribed periodic requirements.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Indonesia
PDP Authority ยท Personal Data Protection supervisory authority
Asia-Pacific ยท Institutional arrangements should be verified
Global PIA CompositePrimary lawPDP Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Ireland
DPC ยท Data Protection Commission
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Israel
PPA Israel ยท Privacy Protection Authority
Middle East ยท National supervisory authority
Global PIA CompositePrimary lawPrivacy Law 1981
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Italy
Garante ยท Garante per la protezione dei dati personali
European Union ยท National Supervisory Authority
Italy Garante DPIAPrimary lawGDPR
DPIA terminologyValutazione dโimpatto sulla protezione dei dati (DPIA)
Legal positionApply GDPR Article 35 and the Garante list of processing subject to DPIA.
Trigger testInnovative technology, systematic monitoring, profiling, vulnerable people, biometric or sensitive data, large scale and other Garante list triggers.
Required methodDocument processing, purposes, necessity, proportionality, rights risks, safeguards, DPO advice, approvals and implementation monitoring.
Authority escalationConsult the Garante before processing where residual high risk cannot be adequately mitigated.
Review ruleUpdate for material processing, technology, vendor, scale or risk changes.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Japan
PPC ยท Personal Information Protection Commission
Asia-Pacific ยท National supervisory authority
Japan PIAPrimary lawAPPI
DPIA terminologyPrivacy impact / personal information risk assessment
Legal positionDetermine whether a PIA is required by sector, public-body rules, procurement or organisational governance and apply APPI accountability.
Trigger testSensitive personal information, profiling, AI, large-scale data, cross-border provision, biometrics, location and novel surveillance.
Required methodMap data and third-party provision; identify purpose, notices, consent and security requirements; assess harms; assign safeguards and review.
Authority escalationEngage the privacy lead and relevant sector authority. Verify PPC guidance and notification or consultation requirements.
Review ruleUpdate for new purposes, vendors, transfers, security changes and material risk.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Jordan
PDPC Jordan ยท Personal Data Protection Council / Ministry of Digital Economy and Entrepreneurship
Middle East ยท National privacy authority
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Kenya
ODPC ยท Office of the Data Protection Commissioner
Africa ยท National supervisory authority
Global PIA CompositePrimary lawDPA 2019
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Latvia
DVI ยท Data State Inspectorate
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Lesotho
DPC Lesotho ยท Data Protection Commission
Africa ยท National supervisory authority
Global PIA CompositePrimary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Lithuania
VDAI ยท State Data Protection Inspectorate
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Luxembourg
CNPD ยท National Commission for Data Protection
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Malawi
Authority ยท Data Protection Authority / Malawi Communications Regulatory Authority
Africa ยท Competence should be verified
Global PIA CompositePrimary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Malaysia
JPDP ยท Personal Data Protection Commissioner
Asia-Pacific ยท National supervisory authority
Global PIA CompositePrimary lawPDPA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Malta
IDPC ยท Office of the Information and Data Protection Commissioner
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Mexico
Federal authority ยท Competent federal transparency and personal data authority
Americas ยท Institutional position should be verified for the date of use
Global PIA CompositePrimary lawLGPD
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Moldova
NCPDP ยท National Centre for Personal Data Protection
Europe ยท National Supervisory Authority
Global PIA CompositePrimary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Morocco
CNDP ยท National Commission for the Control of Personal Data Protection
Africa ยท National supervisory authority
Global PIA CompositePrimary lawGDPL
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Mozambique
INTIC ยท National Institute of Information and Communication Technologies / competent authority
Africa ยท Current institutional position should be verified
Global PIA CompositePrimary lawLPDA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Netherlands
AP ยท Dutch Data Protection Authority
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
New Zealand
OPC NZ ยท Office of the Privacy Commissioner
Asia-Pacific ยท National privacy authority
New Zealand OPC PIAPrimary lawPrivacy Act 2020
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionUse a brief or full PIA proportionate to risk and verify sector or public-body requirements.
Trigger testNew or changed collection, use, disclosure, data matching, AI, biometrics, surveillance, sensitive information or material effects on individuals.
Required methodDefine scope, map information flows, consult, identify privacy impacts, rate risks, assign mitigations, approve and review.
Authority escalationUse the privacy officer and seek OPC advice where significant uncertainty or unresolved risk remains.
Review ruleReview implementation and reassess when processing or risks materially change.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Nigeria
NDPC ยท Nigeria Data Protection Commission
Africa ยท National supervisory authority
Global PIA CompositePrimary lawNDPR
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Norway
Datatilsynet ยท Norwegian Data Protection Authority
Europe ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Peru
ANPD ยท National Authority for Personal Data Protection
Americas ยท National supervisory authority
Global PIA CompositePrimary lawLaw 29733
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Philippines
NPC ยท National Privacy Commission
Asia-Pacific ยท National supervisory authority
Global PIA CompositePrimary lawDP Act 2012
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Poland
UODO ยท Personal Data Protection Office
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Portugal
CNPD ยท National Data Protection Commission
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Qatar
NCGAA ยท National Cyber Governance and Assurance Affairs / competent privacy authority
Middle East ยท Current institutional position should be verified
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Romania
ANSPDCP ยท National Supervisory Authority for Personal Data Processing
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Russian Federation
Roskomnadzor ยท Federal Service for Supervision of Communications, Information Technology and Mass Media
Europe ยท Federal supervisory authority
Global PIA CompositePrimary lawFederal Law on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Saudi Arabia
SDAIA/NDMO ยท Saudi Data and Artificial Intelligence Authority / National Data Management Office
Middle East ยท National data governance authority
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Singapore
PDPC ยท Personal Data Protection Commission
Asia-Pacific ยท National regulatory authority
Singapore PDPC DPIAPrimary lawPDPA
DPIA terminologyData Protection Impact Assessment (DPIA)
Legal positionApply a lifecycle-based DPIA as accountability practice and verify any sectoral or contractual mandate.
Trigger testNew or changed high-impact processing, sensitive information, profiling, monitoring, AI, large-scale sharing or cross-border processing.
Required methodScope and describe processing; assess compliance, necessity, proportionality and risks; identify safeguards; approve; implement; monitor and review.
Authority escalationEngage the Data Protection Officer and sector regulator where applicable. Verify whether notification or consultation is required for the particular processing.
Review ruleMaintain throughout the system and data lifecycle.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Slovakia
UOOU SR ยท Office for Personal Data Protection of the Slovak Republic
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Slovenia
IP-RS ยท Information Commissioner of the Republic of Slovenia
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
South Africa
IR ยท Information Regulator
Africa ยท National supervisory authority
South Africa PIAPrimary lawPOPIA
DPIA terminologyPrivacy impact and risk assessment under POPIA accountability
Legal positionUse a documented assessment to demonstrate responsible-party accountability and verify current Information Regulator guidance and sector rules.
Trigger testSpecial personal information, children, biometrics, profiling, surveillance, extensive matching, cross-border processing or material risk to data subjects.
Required methodDocument purpose, lawful justification, minimality, openness, security safeguards, participation rights, operators, cross-border conditions, risks and controls.
Authority escalationEngage the Information Officer and determine whether prior authorisation or regulator engagement applies to the processing.
Review ruleReview on material change, incident, complaint or control failure.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Spain
AEPD ยท Spanish Data Protection Agency
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Sweden
IMY ยท Swedish Authority for Privacy Protection
European Union ยท National Supervisory Authority
EU / EEA DPIAPrimary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Switzerland
FDPIC ยท Federal Data Protection and Information Commissioner
Europe ยท Federal Supervisory Authority
Switzerland DPIAPrimary lawFederal Data Protection Act
DPIA terminologyData protection impact assessment under the Federal Act on Data Protection
Legal positionAssess planned processing likely to result in high risk to personality or fundamental rights and verify current federal guidance.
Trigger testSensitive personal data at scale, systematic monitoring, profiling with high risk, innovative or extensive processing and other circumstances creating likely high risk.
Required methodDescribe processing; assess risks to affected people; document measures; consult the data protection adviser where appointed; record residual risk and decision.
Authority escalationDetermine whether consultation with the FDPIC is required where high residual risk remains and is not resolved through the statutory adviser route.
Review ruleUpdate where risk or processing changes materially.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Tanzania
PDPC Tanzania ยท Personal Data Protection Commission
Africa ยท National supervisory authority
Global PIA CompositePrimary lawDPA 2022
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Thailand
PDPC ยท Personal Data Protection Committee / Office of the PDPC
Asia-Pacific ยท National supervisory authority
Global PIA CompositePrimary lawPDPA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Uganda
PDPO ยท Personal Data Protection Office
Africa ยท National supervisory authority
Global PIA CompositePrimary lawDPA 2019
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United Arab Emirates
UAE Data Office ยท UAE Data Office
Middle East ยท Federal privacy authority; free-zone regulators may also apply
Global PIA CompositePrimary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United Kingdom
ICO ยท Information Commissioner's Office
Europe ยท National Supervisory Authority
UK ICO DPIAPrimary lawUK GDPR
DPIA terminologyUK GDPR Data Protection Impact Assessment
Legal positionComplete a DPIA before high-risk processing. Apply UK GDPR Article 35, the ICO high-risk processing list and current UK guidance.
Trigger testSystematic evaluation with significant effects, large-scale special-category or criminal data, systematic public monitoring and other processing identified by the ICO as likely high risk.
Required methodDescribe processing and consultation; assess necessity and proportionality; identify and assess risks to rights and freedoms; identify measures and safeguards; record DPO advice and sign-off.
Authority escalationConsult the DPO. Submit a prior-consultation request to the ICO before processing where identified high residual risk cannot be reduced.
Review ruleKeep the DPIA under review and update it when the nature, scope, context, purposes, technology or risk changes.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Alabama
AL AG ยท Alabama Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Alaska
AK AG ยท Alaska Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Arizona
AZ AG ยท Arizona Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Arkansas
AR AG ยท Arkansas Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawACDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - California
CPPA ยท California Privacy Protection Agency
United States ยท State privacy regulator; Attorney General also has enforcement functions
California CPPA Risk AssessmentPrimary lawCCPA/CPRA
DPIA terminologyCalifornia privacy risk assessment
Legal positionApply California risk-assessment requirements and rules to covered processing that presents significant risk to consumersโ privacy.
Trigger testCovered processing identified by current CCPA regulations, including relevant sale or sharing, sensitive data, profiling or automated decision-making and other significant-risk activity.
Required methodDocument purpose, benefits, data categories, affected consumers, safeguards, negative impacts, necessity, alternatives, responsible persons and certification or submission requirements.
Authority escalationIdentify CPPA and Attorney General competence. Verify filing, certification, timing and record-retention requirements in the current regulations.
Review ruleUpdate when processing materially changes and at any required periodic interval.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Colorado
CO AG ยท Colorado Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawCPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Connecticut
CT AG ยท Connecticut Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawCTDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Delaware
DE AG ยท Delaware Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawDPDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - District of Columbia
DC AG ยท District of Columbia Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Florida
FL AG ยท Florida Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFDBR
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Georgia
GA AG ยท Georgia Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Hawaii
HI AG ยท Hawaii Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Idaho
ID AG ยท Idaho Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Illinois
IL AG ยท Illinois Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Indiana
IN AG ยท Indiana Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawICDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Iowa
IA AG ยท Iowa Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawICDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Kansas
KS AG ยท Kansas Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Kentucky
KY AG ยท Kentucky Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawKCDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Louisiana
LA AG ยท Louisiana Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Maine
ME AG ยท Maine Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Maryland
MD AG ยท Maryland Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawMODPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Massachusetts
MA AG ยท Massachusetts Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Michigan
MI AG ยท Michigan Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Minnesota
MN AG ยท Minnesota Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawMNDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Mississippi
MS AG ยท Mississippi Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Missouri
MO AG ยท Missouri Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Montana
MT AG ยท Montana Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawMCDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Nebraska
NE AG ยท Nebraska Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawNDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Nevada
NV AG ยท Nevada Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawNDPP
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - New Hampshire
NH AG ยท New Hampshire Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawNHDPP
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - New Jersey
NJ AG ยท New Jersey Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawNJDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - New Mexico
NM AG ยท New Mexico Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - New York
NY AG ยท New York Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawNYDSA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - North Carolina
NC AG ยท North Carolina Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - North Dakota
ND AG ยท North Dakota Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Ohio
OH AG ยท Ohio Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Oklahoma
OK AG ยท Oklahoma Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Oregon
OR AG ยท Oregon Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawOCPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Pennsylvania
PA AG ยท Pennsylvania Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Rhode Island
RI AG ยท Rhode Island Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - South Carolina
SC AG ยท South Carolina Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - South Dakota
SD AG ยท South Dakota Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Tennessee
TN AG ยท Tennessee Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawTIPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Texas
TX AG ยท Texas Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawTDPSA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Utah
UT AG ยท Utah Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawUCPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Vermont
VT AG ยท Vermont Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawVDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Virginia
VA AG ยท Virginia Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawVCDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Washington
WA AG ยท Washington Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - West Virginia
WV AG ยท West Virginia Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Wisconsin
WI AG ยท Wisconsin Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
United States - Wyoming
WY AG ยท Wyoming Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection AssessmentPrimary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Vietnam
MPS ยท Ministry of Public Security / competent personal data authority
Asia-Pacific ยท National competent authority
Global PIA CompositePrimary lawLaw on Info Security
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Zambia
DPA Zambia ยท Data Protection Commissioner / Data Protection Authority
Africa ยท National supervisory authority
Global PIA CompositePrimary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.