This section provides some guidance on how you determine whether a privacy impact assessment (PIA) would be recommended for your project and, if so, what level of PIA is required.
This is a fairly short process but provides a basis for the work you will do when it comes to actually completing a PIA or checking legal compliance. It can be very expensive for an organisation to discover too late that a project has substantial privacy impacts. On the other hand, it would be a waste of resources to unnecessarily carry out a PIA, or complete a full-scale PIA where only a small-scale PIA is needed. It is therefore worth doing some preliminary evaluation to determine whether a PIA is necessary and what level of PIA is required.
There are two stages – preparation and a series of screening questions.