A privacy impact assessment is how a company figures out what personal data it collects, where that data goes, and what could go wrong
When a company builds a new product, changes how it handles your information, or buys data from a broker, it should run a privacy impact assessment — a document that maps out what personal data flows through the system and identifies the risks. The assessment asks: What information are we collecting? Who can see it? How long do we keep it? What happens if it gets breached or misused?
You won't see these assessments yourself — they're internal documents. But they matter to you because they're supposed to catch problems before your data gets exposed. If a company skips the assessment or ignores what it finds, that's often when data brokers end up with your information, your address gets sold to marketers, or your details leak in a breach. Understanding what a PIA is helps you recognize when a company may not have thought through the privacy consequences of what it's doing.
Key Takeaways
- A privacy impact assessment documents what personal data a company collects, stores, and shares, and identifies the risks at each step.
- Companies use PIAs when launching new products, changing data practices, or integrating data from outside sources like data brokers.
- A PIA should identify who has access to your data, how long it's kept, and what safeguards protect it from theft or misuse.
- If a company conducts a PIA and publishes the results, that's a sign it took privacy seriously — though many companies keep assessments private.
The three main sections of a privacy impact assessment
A typical PIA starts with a description of the system or change. If a company is launching a new app, the assessment describes what the app does, what data it collects (location, contacts, payment info), and where that data goes. If a data broker is integrating a new source of records, the PIA explains what records those are and how they'll be used.
The second part is the risk analysis. This is where the company identifies what could go wrong: Could an employee steal the data? Could a hacker break in? Could the data be sold to a third party without consent? Could it be used to discriminate against someone? The assessment rates each risk as high, medium, or low based on how likely it is and how much harm it would cause.
The third part lists safeguards and controls. These are the steps the company will take to reduce risk — encryption, access limits, employee training, audit logs, deletion schedules. A good PIA explains not just what safeguards exist, but whether they're actually strong enough to address the risks identified.
Why companies conduct privacy impact assessments
Some companies do PIAs because the law requires it. The European Union's General Data Protection Regulation (GDPR) mandates a PIA — called a Data Protection Impact Assessment — before any processing that poses a high risk to people's rights. California's Consumer Privacy Act (CCPA) doesn't explicitly require a PIA, but regulators expect companies to show they've thought through privacy consequences.
Other companies do PIAs because they're buying or selling data and need to understand the legal and reputational risk. If a company acquires records from a data broker without assessing where those records came from or how they'll be used, and then someone's data is misused, the company can be held liable. A PIA creates a paper trail showing the company did due diligence.
Some companies do PIAs because their customers or business partners demand it. If you're a healthcare provider and you want to use a new patient management system, you might ask the vendor for a PIA to confirm they've thought through how they'll protect medical records.
What a privacy impact assessment should tell you about data brokers
If a company is integrating data from a broker — buying lists of names, addresses, phone numbers, or purchase history — a PIA should answer: Where did the broker get this data? Was it collected with consent? How accurate is it? What will the company do if someone asks for it to be deleted?
A thorough PIA would also identify the risk that the data is outdated or wrong, which is common with broker data. If a company uses broker data to make decisions about you — whether to offer you credit, insurance, or a job — a PIA should flag that risk and describe how the company will handle disputes or corrections.
The assessment should also address whether the company will share the broker data with other parties, sell it onward, or combine it with other information about you. If the PIA doesn't address these questions, that's a sign the company may not have fully thought through the privacy implications of using broker data.
When a company publishes its privacy impact assessment
Most companies keep PIAs private. But some — particularly government agencies, nonprofits, and companies that handle sensitive data — publish them or summaries of them. When a company publishes a PIA, it's usually a sign that privacy was a serious consideration, not an afterthought.
If you're trying to understand whether a company that holds your data has thought through privacy risks, you can look for a published PIA on their website or ask them directly whether they've conducted one. Some companies will share a summary even if they don't publish the full document. The fact that they've done the assessment at all — and can describe it — is more reassuring than silence.
The difference between a privacy impact assessment and a privacy policy
A privacy policy is what a company publishes for you to read. It explains what data they collect, how they use it, and your rights. A privacy impact assessment is an internal analysis of risks and safeguards. They serve different purposes.
A privacy policy might say "we encrypt your data in transit and at rest." A PIA would go deeper: it would identify the specific encryption standard, who has the decryption keys, how often the encryption is tested, and what happens if the keys are compromised. A privacy policy might say "we don't sell your data." A PIA would identify the risk that a data broker could scrape the data anyway, or that an employee could leak it, and describe what controls prevent that.
You can't always tell from a privacy policy whether a company actually conducted a thorough PIA. A company with a vague privacy policy might have done a rigorous internal assessment, or it might have done neither. But if a company publishes a detailed PIA or references one in its privacy documentation, that's a stronger signal that it took privacy seriously.
How privacy impact assessments connect to data removal requests
If you're trying to remove your information from data broker websites, understanding PIAs helps you know what to look for. When you contact a data broker and ask them to delete your data, they should have a process for it — and that process should have been identified in their PIA. If a broker has no clear deletion process, that's a sign they may not have conducted a thorough assessment.
Some data brokers claim they can't delete data because they don't know where it came from or how it's being used. That's a red flag that they skipped the PIA step. A company that did a proper assessment would know exactly what data it holds, where it came from, and what it's used for — which means it should be able to delete it if you ask.
Frequently Asked Questions
Can I request to see a company's privacy impact assessment?
You can ask, but most companies won't share it. PIAs are internal documents. Some government agencies and nonprofits publish them or summaries. If a company refuses to share one, you can try asking what safeguards they use to protect your data — that's the same information a PIA would contain.
Does a privacy impact assessment mean my data is safe?
A PIA identifies risks and describes safeguards, but it doesn't may provide safety. A company could conduct a thorough assessment and then ignore its own recommendations. The assessment is only as good as the company's commitment to actually implementing the safeguards it describes.
Are privacy impact assessments required by law?
GDPR in Europe requires them for high-risk data processing. U.S. laws like CCPA don't explicitly mandate them, but regulators expect companies to show they've assessed privacy risks. Many companies do them voluntarily to reduce legal liability.
What should I do if a company won't tell me whether they've conducted a PIA?
Ask them directly what safeguards protect your data, how long they keep it, and who has access to it. Those are the core questions a PIA answers. If they can't or won't answer, that's a sign they may not have thought through privacy carefully.
How does a privacy impact assessment help me remove my data from brokers?
A broker that conducted a proper PIA knows exactly what data it holds and where it came from, which means it should be able to delete your information when you request it. If a broker claims it can't delete your data, that suggests it skipped the assessment step.