Which Action Requires an Organization to Carry Out a Privacy Impact Assessment?
Collecting personally identifiable information (PII) to store in a new or substantially modified information system requires a Privacy Impact Assessment. Under the E-Government Act of 2002 (Section 208), developing or procuring IT that collects, maintains, or disseminates PII triggers a PIA; de-identified data or paper records generally do not.
The answer
The action that requires an organization to carry out a Privacy Impact Assessment (PIA) is collecting personally identifiable information (PII) to store or process in a new — or substantially changed — information system. Whenever an organization develops, buys, or significantly modifies an IT system that will collect, maintain, or disseminate PII about members of the public, a PIA must be conducted.
The legal basis for federal agencies is Section 208 of the E-Government Act of 2002, which requires agencies to conduct a PIA before developing or procuring IT that handles identifiable information, and before initiating a new electronic collection of PII.
Why the other options are wrong
Typical distractors on this question describe actions that do not trigger a PIA:
- Storing records only on paper. A PIA under the E-Government Act is tied to electronic information systems and IT. Purely paper-based filing, without a supporting IT system, does not by itself require a PIA (though other privacy rules may still apply).
- Working with de-identified or anonymized data. If the data cannot be linked back to an individual, it is not PII, so the core trigger — collecting information about identifiable people — is absent.
- Making a minor cosmetic change to an existing system. The trigger is a new system or a substantial modification that changes how PII is collected, used, or shared. Trivial changes that do not affect privacy risk generally do not require a fresh PIA.
- Publishing already-public, non-personal information. With no PII involved, there is nothing to assess.
The common thread: a PIA is required specifically when the action introduces or changes the collection and handling of PII in an information system.
When is a PIA required — the trigger checklist
An organization should conduct a PIA when it:
- Builds or buys a new information system that collects PII.
- Substantially modifies an existing system in a way that changes privacy risk (new data types, new users, new sharing).
- Begins a new electronic collection of PII from ten or more members of the public.
- Converts paper records to an electronic system that will manage PII.
- Adds a technology (e.g., new tracking, matching, or sharing capability) that changes how PII is used.
A PIA documents what information is collected, why, how it is used, who it is shared with, how it is secured, and what privacy risks exist and how they are mitigated.
PIA vs. DPIA and who is responsible
A PIA is the U.S. federal term under the E-Government Act. A DPIA (Data Protection Impact Assessment) is the closely related requirement under the EU's GDPR (Article 35), mandatory when processing is 'likely to result in a high risk' to individuals' rights. The concepts overlap, but the legal frameworks differ.
Responsibility usually sits with the system or program owner who initiates the data collection, supported and reviewed by the organization's privacy officer (in federal agencies, the Senior Agency Official for Privacy or Chief Privacy Officer). The assessment is completed before the system goes live and is reviewed as the system changes.
- 1
Does the action involve an electronic information system (not just paper)?
PIAs under the E-Government Act apply to IT systems that handle information electronically.
- 2
Will the system collect, maintain, or disseminate PII about identifiable people?
- 3
Is this a new system, a new electronic collection, or a substantial modification affecting privacy?
Frequently asked
What is a Privacy Impact Assessment (PIA)?
A PIA is a documented analysis of how an information system collects, uses, shares, and protects personally identifiable information. It identifies privacy risks and the safeguards used to mitigate them, and is completed before a system that handles PII goes live.
When is a PIA legally required?
Under Section 208 of the E-Government Act of 2002, U.S. federal agencies must conduct a PIA before developing or procuring IT that handles PII, and before starting a new electronic collection of PII from ten or more members of the public.
What is the difference between a PIA and a DPIA?
A PIA is the U.S. federal assessment required by the E-Government Act. A DPIA (Data Protection Impact Assessment) is the equivalent under the EU's GDPR (Article 35), required for processing likely to result in high risk to individuals. They share goals but rest on different laws.
Who is responsible for conducting a PIA?
The system or program owner initiating the data collection typically leads the PIA, with review and oversight from the organization's privacy officer — in federal agencies, the Senior Agency Official for Privacy or Chief Privacy Officer.
What law requires federal agencies to conduct PIAs?
The E-Government Act of 2002, specifically Section 208, requires U.S. federal agencies to conduct Privacy Impact Assessments when developing or procuring IT systems that collect, maintain, or disseminate personally identifiable information.