Privacy impact assessment

The Project Manager must use a privacy impact assessment (PIA) to assess the impact on privacy during the lifecycle of a project. The following must be checked:

Impact Further action required 
Has no impact on privacy Where there is no impact on privacy no further action need be taken.
Has a minor impact on privacy Where there is a minor impact on privacy the Information Assurance Manager may ask the project manager to complete a privacy questionnaire. The outcome will be determined by the Information Assurance Manager in conjunction with the project manager. Any identified risks and recommendations are to be built into the project plans.
Has a major impact on privacy Where there is a major impact then a full Privacy Impact Assessment (PIA) should be undertaken, normally by the Information Assurance Manager, although an external consultant may be used.

If your project includes handling commercially sensitive information or information supplied under contract, or you have any queries about these documents, please contact the Information Assurance Manager infoman@essex.ac.uk.

Business case

The project Business Case should confirm that a checklist has been completed and whether or not the project will have an impact on privacy.

If the Information Assurance Manager has determined that a full PIA is necessary then the resource requirements for the project should include either the Information Assurance Manager’s time (normally five days), if they have capacity, or costs of an external consultant if a PIA is required. Consultancy cost will need to be part of the project budget.

Project reports

Project reports should report progress against recommendations arising from a PIQ or PIA.

Project risk registers should include risks identified by the PIQ or PIA.

Documentation

  1. Project Privacy Checklist - seven questions checklist for use by project managers. The outcome of the checklist is determined by the Information Assurance Manager, based on a standard scoring system.
  2. Project Privacy Questionnaire (.docx) - ten questions to be completed by project managers. The outcomes will include a set of risks identified and recommendations for mitigating those risks.
  3. Privacy Impact Assessment - investigative work carried out by the Information Assurance Manager. The outcomes will include a set of risks identified and recommendations for mitigating those risks.

Help and support

The Information Assurance Manager can be contacted for advice at any stage, infoman@essex.ac.uk

Arrow symbol
Contact us
Strategic Projects Office