The Value in Conducting a Privacy Impact Assessment Rachael Gallagher Senior Policy Officer 2 December 2014 Introduction • What is a PIA? • What is Privacy? • What are the benefits? • What types of projects? • Who should be responsible? Code of Practice Privacy by design From Handbook to Code of Practice The PIA process Consultation 1 2 3 4 5 6 • Identify need for a PIA • Describe information flows • Identify privacy risks • Identify privacy solutions • Record PIA outcomes, and sign-off • Integrate PIA outcomes into project plan Consultation Internal stakeholders External stakeholders •Project board •Engineers, developers •IT •Procurement •Suppliers / data processors •Comms team •Frontline staff •Corporate Governance •Senior management •End users •Data subjects •Representative groups •Interest groups •General public •Regulators The PIA process 1 • Identify need for a PIA • Establish objectives, outcomes and outputs early • Screening questions • Management support The PIA process 2 • • • • • Describe information flows Types of personal data Use of those data Information asset register Data controller? The PIA process 3 • • • • • Identify privacy risks Risk management tools/methodology ICO guidance Other standards and guidance Types of risk – Individuals – Compliance – Corporate The PIA process 4 • Identify privacy solutions • Accept • Reduce • Eliminate The PIA process 5 • • • • • • Record PIA outcomes, and sign-off Document status of each risk Determine solutions Record reasons Sign-off Publication The PIA process 6 • Integrate PIA outcomes into project plan • Recommendations integrated into project plan • Review PIA at key stages • Final evaluations Conclusions • Way of complying with data protection obligations • Method of Good Practice • Can reduce costs • Publish where appropriate • Promotes trust Keep in touch Information Commissioner’s Office 3rd Floor, 14 Cromac Place, Gasworks, Belfast BT7 2JB. Tel: 028 90278757 / 0303 123 1114 Email: ni@ico.org.uk Subscribe to our e-newsletter at www.ico.org.uk or find us on… www.twitter.com/iconews