Skip to main content

Key insights

  • The PIA label changes by legal regime, and each regime applies a different legal test.
  • A missing assessment can be fined in its own right; a skipped DPIA can be a violation before any breach happens.
  • State assessment triggers converge on targeted advertising, data sales, sensitive data, and profiling. Effective dates shift from state to state.

A client forwards a vendor's security questionnaire: does their credit scoring model have a DPIA on file? The next message, from the same client's California counsel, asks for the risk assessment the state starts requiring in 2026. Same model, two different legal instruments.

More of your SOC 2 clients are landing in exactly this spot. A growing set of state laws now requires documented data protection assessments for everyday processing, on top of the DPIA obligations your European clients already carry. This piece walks through where those instruments diverge, what triggers each, and how to scope an engagement so the workpapers stand up to the legal test they were built to satisfy.

What is a privacy impact assessment (PIA)?

A privacy impact assessment (PIA) is two things at once: the analysis of how a system handles personal information, and the written record of what that analysis found. Skip either half and you don't have a PIA. Think hard about privacy without writing it down and nothing survives scrutiny later. Fill in a template without questioning the collection and you've documented a decision no one actually made.

The analysis half traces back to federal law. OMB guidance names the PIA as an obligation agencies carry when they build or buy IT that handles identifiable information. Strip away the government context and it comes down to two questions. Does the handling meet the rules? Could a less intrusive approach get the same result with less data risk?

Those two questions only work if you ask them early. DHS frames the PIA as a decision tool that runs throughout a system's life cycle, before and during the build. Ask them after shipment and you're documenting a past decision instead of shaping the design.

Outside the federal context the label travels. Commercial teams borrow it for any privacy-risk review, and that's usually fine in conversation. It stops being fine in scoping documents, which is where the next section picks up.

PIA vs. DPIA: What's the difference?

The data protection impact assessment (DPIA) is the GDPR's term of art. It has to be done before processing starts, whenever the processing (new technology especially) is likely to put people's rights at high risk. The DPIA is a specific EU legal instrument. PIA is the broader family it belongs to.

The distinction matters because each name carries a different set of obligations. In US federal law, PIA is an agency obligation. Commercial teams use it as a general privacy-risk exercise. State privacy laws use "data protection assessment" as their own legal instrument, and each is measured against a different rule.

The DPIA brings requirements a generic PIA never does. If your client has a data protection officer (DPO), the controller has to seek the DPO's advice, and the file should show it. If residual risk stays high after mitigation, the client consults the supervisory authority before anything goes live. Miss those steps and the risk analysis can be sharp and the assessment still fails the regulation.

Poland's supervisory authority made this concrete. It fined Toyota Bank Polska S.A. €132,000 in a decision that cited both the DPO's positioning inside the organization and the omission of profiling from the bank's DPIA. No data breach was required to get there. Under ICO guidance, failing to carry out a required DPIA can expose an organization to a fine of up to £8.7 million or 2% of global annual turnover, whichever is higher. The missing assessment is the finding.

When is a privacy impact assessment required?

Because a missing assessment is itself the finding, the first call on any engagement is whether one was required at all. Not every processing activity needs a full assessment. The trick is knowing which is which before the client is already three months into building the thing.

A short threshold analysis does that sorting: a handful of screening questions that decide whether the processing crosses the threshold into a full assessment. Run it before anyone opens a template, and you'll know whether you're scoping the real thing or documenting why you didn't.

When does the GDPR require a DPIA?

Start with a simple question. Will this processing make or shape decisions that matter to people? If profiling or automated evaluation drives legally significant outcomes (a loan approval, an insurance rate, a job screen), Article 35 treats the DPIA as required. Same result if your client processes special-category or criminal-conviction data at large scale, or systematically monitors public spaces at large scale. Those are the bright lines.

Around those bright lines sits a broader set of high-risk indicators endorsed by the EDPB, and they map straight onto the work advisory clients are actually doing. A few common ones:

  • Credit scoring, fraud, and performance models. Hits the evaluation-and-scoring criterion. On its own it rarely forces a DPIA, so the trigger turns on which other criteria are in play.
  • Third-party data enrichment. Hits the dataset-matching criterion. Marketing treats it as plumbing, but the matching itself is what triggers an assessment.
  • Biometric matching and similar systems. Hits the new-technology criterion. The scoping question is what the vendor's model does with the input data.

The working rule: two or more indicators normally require a DPIA. One can be enough depending on context.

For clients outside the GDPR's reach, the trigger analysis doesn't go away. It just moves to state law, where the penalty for guessing wrong lands on the same workpapers.

When do US state laws require a data protection assessment?

State privacy laws converge on a familiar short list. If any of these describe your client's processing, an assessment is on the table:

  • Targeted advertising
  • Selling personal data
  • Processing sensitive data (the definition varies, but health, precise location, and children's data show up almost everywhere)
  • Profiling with legal or similarly significant effects on the consumer
  • Any processing that presents a heightened risk of consumer harm

The last one is the catch-all that keeps the analysis from turning into a checkbox exercise.

The timelines don't line up. California's are the nearest: its risk assessment regulations take effect January 1, 2026, and they spell out what the file must contain in more detail than most states.

What does a privacy impact assessment include?

Prescriptive or not, every regime judges the file on the same thing. Regulators don't fail a file because the writing is bad. They fail it because the necessity and proportionality analysis is thin.

Describing what a system does is easy. Answering whether the same purpose could be achieved with less data, or through a less intrusive method, is where drafts usually break down. It's also where the assessment stops being paperwork and starts changing the design.

The GDPR file wants the judgment visible:

  • What your client is doing
  • Why it's necessary and proportionate
  • Where people could be harmed
  • Which measures the client chose to reduce that risk

A US-style PIA wants the same judgment through different evidence:

  • Authority for the collection
  • A clear description of the data
  • The use case
  • The notice individuals receive
  • The retention period
  • The parties that receive the information

Different regimes, same underlying story. A reviewer should be able to follow the personal information from collection to deletion, connect the purpose and lawful basis to the people affected, and see which harms could reach them. Then the file ties that story back to notice, choice, retention, security, chosen mitigations, ownership, and a refresh point for when processing changes.

The practical implication: most of the core file travels. Build the common risk story once, then layer in the legal steps each regime requires on top.

What are the benefits of a privacy impact assessment?

The file is real work to build, and firms tend to book it as pure compliance cost. The data says the opposite.

PwC's 2025 customer experience survey found 53% of consumers think sharing personal information is worth it for a smoother experience, and 93% say a brand loses their trust if it mishandles data. HBS research on privacy laws points the same way: stricter rules can increase people's willingness to share, because they feel more protected. Privacy work doesn't shrink the dataset. It's part of what earns the dataset in the first place.

Assessments also front-load the questions that get expensive later. Forrester's review of 2025 counted over 10.6 billion records exposed and nearly $2.8 billion in penalties among the year's most notable incidents. An assessment forces purpose, retention, sharing, and safeguards onto the table before launch. That's not a guarantee against a breach, but it's a very different starting position when one happens.

For firms, there's a delivery angle worth naming. California's regulations turn privacy assessments into a recurring cycle rather than a one-off: predictable, forecastable, repeatable. That's more than most new statutes give a practice leader to plan around. The evidence collection, workpapers, and control documentation the cycle runs on are already core to a compliance practice.

Run privacy assessments without the manual grind

Here's the good news for firms already doing SOC 2: you've built most of the muscle. Different rulebook, same delivery motion. The hard part isn't the first assessment. It's the tenth, and the fiftieth after that, once state laws and the GDPR each start asking for their own version on a recurring cycle. That's where delivery capacity becomes the constraint.

Fieldguide runs the whole lifecycle in one place: requests, evidence, workpapers, and reporting. Practitioners direct the engagement and own the judgment, while Agent Workforce executes the evidence review and documentation underneath, every output reviewed and approved by a practitioner. Refreshing the same file next cycle instead of rebuilding it from scratch changes the economics: the first assessment carries the build cost, and each one after runs on a fraction of the hours.

If your firm is looking at growing assessment demand across state privacy laws and the GDPR, request a demo and we'll show you how it fits your practice.

Amanda Waldmann

Amanda Waldmann

Increasing trust with AI for audit and advisory firms.

fg-gradient-light