A privacy impact assessment is how a company figures out what personal data it collects, who can see it, and what could go wrong if that data leaks or gets misused

When a company builds a new product, changes how it handles your information, or buys another company's customer list, it should stop and ask: what personal data will we touch, and what are the risks? A privacy impact assessment (PIA) is the formal process for answering that question. It's not a may provide that your data is safe — it's a checklist that forces someone inside the company to think through the dangers before they're already in trouble.

You won't see a PIA yourself. It's an internal document. But understanding what one is and what it covers helps you know what questions to ask a company if you're trying to get your information removed, or what to look for if you're reading a company's privacy policy and wondering whether they've actually thought through the consequences of what they do with your data.

Key Takeaways

  • A privacy impact assessment forces a company to document what personal data it collects, how long it keeps it, and who inside and outside the company can access it.
  • The assessment identifies specific risks — like data breaches, unauthorized access, or selling information to third parties — before the company launches a new service or changes its practices.
  • Companies are not legally required to do a PIA in most U.S. states, though some industries like healthcare and finance have stricter rules about documenting their data practices.
  • A PIA is only useful if someone actually reads it and the company acts on what it says; many companies complete them as a checkbox exercise and ignore the findings.
  • When you contact a data broker or company asking them to remove your information, knowing that a PIA exists can help you understand whether they've thought through the risks of keeping your data.

What a privacy impact assessment actually contains

A PIA typically starts with a map of the data flow: what personal information does the company collect, where does it come from, where does it go, and how long does it stay? For a data broker, this means documenting that they buy lists from retailers, append additional information from public records, and sell the combined profile to marketers and landlords. For a social media platform, it means tracking that they collect your location, your contacts, your browsing history, and your messages.

The assessment then identifies who can access that data inside the company — customer service reps, engineers, sales teams, executives — and who can access it outside, like advertising partners or law enforcement. It documents what safeguards exist: encryption, password protection, audit logs that track who looked at what. It also lists what could go wrong: a disgruntled employee stealing the database, a hacker breaking in, a contractor losing a laptop, a mistake that exposes data publicly.

Finally, a PIA should recommend steps to reduce those risks. That might mean encrypting data at rest, limiting who can read files, deleting old information instead of keeping it forever, or being more selective about which third parties get access. Whether the company actually implements those recommendations depends on whether leadership cares enough to spend the money.

Why companies are supposed to do them, and when they actually do

In the European Union, a privacy impact assessment (called a Data Protection Impact Assessment, or DPIA) is legally required before a company processes personal data in a way that poses a high risk. That includes large-scale collection, automated decision-making, and systematic monitoring. The requirement is part of the General Data Protection Regulation (GDPR), and companies that operate in Europe or serve European customers often have to comply even if they're based elsewhere.

In the United States, there is no blanket federal requirement. However, certain industries have their own rules. Healthcare providers and health plans must document their data practices under HIPAA. Financial institutions have similar obligations under the Gramm-Leach-Bliley Act. Some states, like California, require companies to describe their data practices in a privacy policy, though that's not quite the same as a formal impact assessment. Federal contractors and agencies have their own requirements.

For most companies in most states — including data brokers — a PIA is optional. Many do one anyway because it reduces legal liability if something goes wrong: they can show a court that they thought about the risks and tried to manage them. Others skip it entirely or treat it as a formality that gets filed away and never read again.

How a privacy impact assessment connects to data removal requests

When you contact a data broker asking them to remove your information, you're essentially asking them to change their data practices. A company that has done a thorough PIA should be able to tell you: we collect this data, we keep it for this long, we sell it to these types of buyers, and here's what happens when you ask us to delete it. They should know whether deletion is actually possible or whether they've sold your information to so many third parties that they can't track it all down.

A company that has not done a PIA — or has done one and ignored it — often cannot answer those questions. They may tell you they'll delete your data and then not actually do it, because they don't have a clear picture of where your information lives in their systems. They may not know which third parties have copies of your data, so they can't contact those parties to request deletion on your behalf.

If you're dealing with a data broker and they're being evasive about what data they hold or how they use it, that's often a sign they haven't done the work to understand their own practices. A company that has genuinely assessed the privacy risks of what it does can usually explain it clearly.

The difference between a privacy impact assessment and a privacy policy

A privacy policy is a public document that tells you, the user, what a company does with your data. A privacy impact assessment is an internal document that tells the company's leadership what risks exist and what they should do about them. They serve different purposes and are written for different audiences.

A privacy policy might say "we collect your location data and share it with advertising partners." A PIA would go deeper: it would identify that location data is particularly sensitive, that sharing it with dozens of ad networks creates a risk of re-identification, that employees in the sales department can read the raw data without logging in, and that the company has no process for deleting old location records. The PIA would then recommend encryption, access controls, and a data retention schedule.

You can sometimes infer whether a company has done a serious PIA by reading its privacy policy. If the policy is vague, contradictory, or doesn't explain how long data is kept or who can access it, that's a sign the company hasn't thought through these questions carefully. If the policy is detailed and specific — naming the types of data, the retention periods, the categories of third parties — that suggests someone has done the work.

What happens when a privacy impact assessment identifies serious risks

A well-done PIA will sometimes recommend that a company not launch a product, or not use a particular data source, because the risks are too high. For example, a PIA might conclude that selling precise location data to debt collectors creates an unacceptable risk of harassment or stalking, and recommend against it. Or it might find that a company's security is too weak to safely store health information, and recommend either improving security or not collecting that data in the first place.

What happens next depends on the company's culture and the strength of its privacy team. In some organizations, the PIA is taken seriously and leadership makes changes. In others, the privacy team raises concerns and gets overruled because the product is profitable or the executive pushing it has more power. In still others, the PIA is completed to satisfy a legal requirement and then shelved.

Data brokers, in particular, often operate in a gray area where the risks identified in a PIA — that selling personal information enables discrimination, fraud, or harassment — are not seen as problems to solve but as features of the business model. A PIA might document these risks clearly, but the company has no incentive to reduce them.

How to think about privacy impact assessments when protecting your own data

You can't demand to see a company's PIA — it's not a public document and most companies won't share it. But you can ask questions that reveal whether the company has done the thinking a PIA would require. When contacting a data broker or company about your information, try asking: How long do you keep my data? Who inside your company can access it? Who do you sell it to or share it with? What happens to my data if I ask you to delete it? Do you have a process for actually removing it from all the places it's been sold?

If a company can answer these questions clearly and specifically, that's a sign they've thought through their data practices. If they're vague, defensive, or say they don't know, that's a sign they haven't — or they have but they're not being honest about what they found.

Understanding that a PIA exists also helps you understand why some companies are better at honoring data removal requests than others. A company with a serious privacy program has documented where your data is, how to find it, and how to delete it. A company without one is just guessing.

Frequently Asked Questions

Can I request to see a company's privacy impact assessment?

No, a PIA is an internal document and companies are not required to share it with the public. However, if you're dealing with a government agency or a contractor working for the government, you may be able to request it under the Freedom of Information Act. For private companies, your best option is to ask specific questions about their data practices and see how clearly they can answer.

Does a privacy impact assessment mean my data is actually safe?

Not necessarily. A PIA identifies risks and recommends solutions, but only if the company actually implements those recommendations. A company can complete a thorough PIA, identify serious security gaps, and then choose not to fix them because it's expensive. The assessment is only as useful as the company's willingness to act on it.

Are data brokers required to do privacy impact assessments?

In most U.S. states, no. Data brokers are not required to do a PIA unless they operate in Europe (where GDPR applies) or handle data in a way that triggers specific state or federal rules. Many data brokers do not do formal PIAs, which is one reason they often struggle to answer questions about what data they hold and how to remove it.

What's the difference between a privacy impact assessment and a security audit?

A PIA focuses on what data a company collects, who can access it, and what could go wrong. A security audit focuses on whether the company's technical safeguards actually work — whether encryption is properly configured, whether passwords are strong, whether systems are patched against known vulnerabilities. A company might have a good PIA but weak security, or vice versa.

If a company says they've done a privacy impact assessment, does that mean I should trust them?

Not automatically. Some companies do serious PIAs and act on them. Others complete them as a checkbox to reduce legal liability and then ignore the findings. The fact that a PIA exists is a good sign that someone has thought about the risks, but it's not a may provide that the company is actually protecting your data.