A Privacy Impact Assessment, or PIA, is a formal written review of how an organization collects, stores, uses, shares, and protects personal information. Federal agencies have been required to complete one since 2002 under Section 208 of the E-Government Act, and a growing number of state privacy laws now impose similar obligations on private businesses. The assessment forces the organization to inventory every piece of personal data it handles, explain why it needs each piece, identify the privacy risks, and document the safeguards in place.1U.S. Government Publishing Office. Public Law 107-347 – E-Government Act of 2002
When a Federal Agency Has to Complete One
Two situations trigger the federal requirement. The first is any time an agency develops or purchases information technology that collects, maintains, or disseminates information in identifiable form.1U.S. Government Publishing Office. Public Law 107-347 – E-Government Act of 2002 Any new IT system, database, or software platform that handles personal data has to go through a PIA before the agency spends money building or buying it.
The second trigger applies when an agency starts a new electronic collection of personal information from ten or more members of the general public, using identical questions or reporting requirements. The information has to be the kind that could be used to physically or digitally contact a specific person.2Electronic Privacy Information Center. E-Government Act of 2002 Federal employees and contractors don’t count toward the ten-person threshold, so internal personnel surveys and interagency data exchanges usually fall outside this trigger.
“Identifiable form” is defined broadly. It reaches any data that lets someone’s identity be reasonably determined, either directly through elements like a name or Social Security number, or indirectly by combining data points that narrow down to a single person.2Electronic Privacy Information Center. E-Government Act of 2002 Biometric records, IP addresses, device identifiers, and location data can all qualify.
Timing is strict: the PIA has to be finished before the agency starts developing the system or collecting the data. Agencies also have to send a copy to the Director of the Office of Management and Budget for any system tied to a funding request.3Office of the Law Revision Counsel. 44 USC 3501 – Purposes That link to the budget gives the requirement teeth. A missing or incomplete PIA can hold up funding for the whole project.
What the Assessment Has to Cover
OMB Memorandum M-03-22 and the statute itself set out the core questions every PIA has to answer:4Office of Management and Budget. OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002
- What information is being collected, down to each data element, and where it comes from.
- Why the agency needs it, tied to a specific programmatic purpose.
- How the agency intends to use it, including any secondary uses beyond the original purpose.
- Who it will be shared with, whether other agencies, contractors, or outside parties.
- What notice and consent the individuals get, whether providing the data is voluntary, and what choices they have.
- How the information will be secured, including access controls, encryption, and training.
- Whether a Privacy Act system of records is being created, which happens when data is retrieved by a personal identifier like a name or SSN.
The assessment also has to document the decisions the agency made as a result of doing the analysis. If the review showed that certain data elements weren’t necessary, or that a sharing arrangement carried too much risk, the PIA records how the agency handled those findings.4Office of Management and Budget. OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002 That written record of trade-offs is what turns the PIA from a checkbox into something that can be reviewed later.
OMB guidance calls for the depth of the analysis to be proportional to the system. A small database tracking public comment submissions does not need the same treatment as a nationwide biometric identification system. Sensitivity of the data and the potential harm from unauthorized release should drive how thorough the review is.3Office of the Law Revision Counsel. 44 USC 3501 – Purposes Retention timelines should also be documented, including what happens to the data at the end of its life cycle.
Who Reviews It and Whether the Public Sees It
A completed PIA goes through internal review led by the agency’s Chief Information Officer or an equivalent official designated by the agency head.3Office of the Law Revision Counsel. 44 USC 3501 – Purposes Many agencies also route the draft through a Senior Agency Official for Privacy. If the reviewer finds gaps or inadequate safeguards, the document goes back for revision. There is no statutory clock on how long that review takes.
After internal approval, the agency generally has to make the PIA publicly available, typically by posting it on the agency website or publishing a summary in the Federal Register.3Office of the Law Revision Counsel. 44 USC 3501 – Purposes
There is an exception. The public disclosure requirement can be modified or waived when publishing the PIA would raise security concerns, reveal classified national security information, or expose sensitive law enforcement or competitive business details.3Office of the Law Revision Counsel. 44 USC 3501 – Purposes The exception applies only to publication. The agency still has to do the PIA. A classified intelligence system does not get to skip the privacy analysis simply because the document will not be posted online. Withheld PIAs are handled consistently with the Freedom of Information Act.5Department of Justice. E-Government Act of 2002
How Often It Has to Be Redone
A PIA is a living document. OMB Circular A-130 requires it to be updated whenever changes to the system or data practices alter the privacy risks involved.6Office of Management and Budget. Managing Information as a Strategic Resource – OMB Circular A-130 For existing systems that collect personal information from ten or more members of the public, the PIA has to be reviewed and re-approved at least every three years. Major changes, such as adding new data elements, integrating a new external database, or migrating to a different platform, trigger an updated PIA regardless of when the last review happened.7CMS Information Security and Privacy Program. Privacy Impact Assessment (PIA)
An expired or incomplete PIA can block an agency from receiving its Authority to Operate, the formal security authorization required before an IT system can go live. A system sitting idle because its privacy paperwork lapsed is a problem an agency can avoid with a calendar reminder.
When Private Companies Have to Do One
The E-Government Act reaches only federal agencies, but the private sector increasingly faces its own version of the requirement. As of early 2026, eighteen state privacy laws impose some form of mandatory privacy or data protection assessment on businesses that process personal information in ways that create elevated risk to consumers. The formats differ, but the purpose is the same: force the company to evaluate privacy risks before the processing starts.
Common triggers across state laws include selling or sharing personal data, processing sensitive categories like biometric or health data, and using automated decision-making for consequential decisions such as credit approvals, insurance underwriting, or employment screening. Some states specifically target profiling based on location tracking or systematic monitoring in sensitive settings like schools and workplaces. Assessments generally have to be finished before the risky processing begins and updated when material changes occur, with some state frameworks requiring a full review every three years regardless of change.
For companies not covered by a specific mandate, the NIST Privacy Framework offers a voluntary structure for identifying and managing privacy risk, with resources aimed at small and medium businesses building a privacy program for the first time.8National Institute of Standards and Technology. Privacy Framework Even where no law compels a PIA, completing one is increasingly treated as a baseline expectation during vendor due diligence and regulatory inquiries.
How the EU’s DPIA Differs
Organizations that process personal data of people in the European Union face a related but distinct requirement called a Data Protection Impact Assessment, or DPIA, under Article 35 of the General Data Protection Regulation. A DPIA is mandatory whenever a type of processing is likely to result in a high risk to individuals’ rights and freedoms, particularly when new technologies are involved.9UK Legislation. Regulation (EU) 2016/679 of the European Parliament and of the Council – Article 35
Three situations specifically require a DPIA:
- Systematic automated evaluation of personal characteristics where the results feed into decisions with legal or similarly significant effects on the individual.
- Large-scale processing of sensitive categories like health records, racial or ethnic origin, criminal history, or biometric data.
- Large-scale systematic monitoring of publicly accessible areas, such as citywide camera networks or transit surveillance.
National data protection authorities can publish additional lists of processing activities that require a DPIA in their jurisdictions.10European Commission. When Is a Data Protection Impact Assessment (DPIA) Required?
The content overlaps with a federal PIA but adds an explicit proportionality analysis. The DPIA has to describe the planned processing and its purposes, evaluate whether the processing is necessary and proportionate to those purposes, assess the risks to individuals, and document the safeguards and mitigation measures planned.9UK Legislation. Regulation (EU) 2016/679 of the European Parliament and of the Council – Article 35 If the DPIA shows high residual risk that the organization cannot adequately mitigate, it has to consult the relevant data protection authority before the processing starts.10European Commission. When Is a Data Protection Impact Assessment (DPIA) Required? That prior-consultation obligation has no direct equivalent in U.S. federal PIA law. Organizations subject to both regimes often run a single assessment that satisfies each, so long as the GDPR’s proportionality analysis and consultation duty are addressed on their own terms.