DPIA vs PIA: What Is the Difference? CIPP/US Guide
A PIA is a general privacy risk assessment used across U.S. law and practice. A DPIA is the specific assessment the GDPR requires under Article 35 when processing is likely to create a high risk to individuals. Every DPIA is a kind of PIA; most PIAs are not DPIAs.
Practical example
Before launching sensitive profiling, document the data, purpose, affected people, risks, safeguards and whether the GDPR high-risk threshold triggers a DPIA.
Common mistake
Using PIA and DPIA as interchangeable labels without checking the law, risk threshold and required content that apply to the processing.
A useful assessment starts with the facts. Identify the data, people, purpose, lifecycle, recipients, foreseeable harms and control evidence. The assessment should show why the remaining risk is acceptable or what must change before the activity proceeds.
For CIPP/US study, compare the privacy risk process with the statute or regulator that governs the scenario. A question may test the difference between a governance assessment and a GDPR DPIA requirement.
How this supports CIPP/US study
Use this lesson to connect a privacy programme decision with the relevant regulator, duty or enforcement route. Continue with the CIPP/US study guide.
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.