Insight

PIA Laws, Standards, and Templates: The Practical Index by Country

September 7, 2026


A Privacy Impact Assessment is only as strong as the framework that supports it. Knowing when a PIA is legally required, and how to avoid the seven mistakes that sink one, only gets an organization so far without a curated map of where to find official rules, regulatory guidance, and working templates. This is that map — a country-by-country and standard-by-standard index of the resources that turn PIA theory into practice.

Regulatory and Supervisory Guidance

  • ANPD (Brazil) — Brazil's data protection authority offers FAQs on the Relatório de Impacto à Proteção de Dados (RIPD), confirming that controllers, per LGPD Article 38, must prepare a RIPD when required and specifying its mandatory contents. The FAQs are in Portuguese, on gov.br.
  • CAI (Quebec) — Quebec's Commission d'accès à l'information provides a Guide to Conducting a PIA under Law 25 (April 2024, v3.1). It sets out the steps of an évaluation des facteurs relatifs à la vie privée and the criteria for when a PIA is mandatory. A companion template is also available, in French.
  • CNIL (France) — CNIL's PIA resources include a full methodology, a knowledge base with case studies, a downloadable template, and an online DPIA tool (beta). CNIL emphasizes that "where processing is likely to result in a high risk... the controller shall carry out a PIA."
  • EDPB (European Union) — The official DPIA guidelines, originally issued by the Article 29 Working Party and now endorsed by the European Data Protection Board, explain when a DPIA is required and how to conduct one step by step.
  • ICO (United Kingdom) — The UK's Information Commissioner's Office provides a comprehensive DPIA guide with an "at a glance" checklist and a free template. It defines a DPIA as a process to identify and minimize risks, listing the required elements: processing description, necessity/proportionality, risk analysis, and mitigations.
  • OPC (Canada) — The Office of the Privacy Commissioner publishes a Guide to the PIA Process for federal public-sector institutions. It clarifies how to scope and document PIAs under Canadian law; while PIPEDA does not explicitly require PIAs for the private sector, the accountability principle encourages similar assessments.

Data Protection Laws and Frameworks

  • Brazil (LGPD) — Article 38 allows the ANPD to require a RIPD from controllers. The law states that "the national authority may determine that the controller must prepare a data protection impact assessment," with its sole paragraph specifying required contents, including data types, methodology, security measures, and mitigation steps.
  • California (CCPA/CPRA) — California's original CCPA (2020) contained no formal PIA requirement. Under the newer CPRA and California Privacy Protection Agency regulations, risk assessments are mandated for automated decision-making. In July 2025, the CPPA finalized rules requiring businesses, in certain cases, to conduct an Automated Decisionmaking Technology risk assessment weighing the privacy risks of ADMT against its benefits — these rules implement CPRA obligations for algorithmic impact assessments.
  • Canada (PIPEDA and Quebec's Law 25) — Canada's federal PIPEDA mandates accountability under Schedule 1 but does not explicitly require PIAs. "Privacy by design," now codified in law, implies risk reviews, and the OPC publishes a detailed guide for practical guidance. Separately, Quebec's modernized private-sector Law 25 explicitly requires PIAs in certain cases, such as new IT systems and research projects, with the CAI's official guide and template providing implementation details.
  • European Union (GDPR) — Under Article 35, a DPIA is mandatory for any processing "likely to result in a high risk" to rights and freedoms. Member State authorities also publish blacklists and whitelists of processing types under Article 35(4). Article 35(7) specifies the minimum elements: description of processing, necessity and proportionality, risk analysis, and mitigation measures.
  • Japan (APPI) — The Act on the Protection of Personal Information, amended in 2022, emphasizes data security and privacy management. While it does not formally mandate a PIA, the Personal Information Protection Commission expects organizations to adopt "necessary and appropriate measures." In practice, Japanese companies incorporate risk reviews into privacy programs such as PrivacyMark or FSA guidance, often applying internationally recognized methodologies like ISO or NIST as best practice.

International Standards and Methodologies

  • ISO/IEC 27701 (2019) — Extends ISO/IEC 27001 and 27002 with privacy-specific controls for a Privacy Information Management System (PIMS). Provides guidance on risk assessment and can be used to embed PIA logic into a broader privacy management framework.
  • ISO/IEC 29134 (2023) — Offers global guidelines for conducting PIAs, covering structure, process, and report contents. A core reference when designing a PIA process, and complementary to privacy-by-design requirements in data protection laws.
  • NIST and OMB Guidance — NIST defines a PIA as "an analysis of how information is handled... and a formal document detailing the process and outcome." U.S. federal agencies follow OMB Memo M-03-22 and the NIST SP 800 series; SP 800-37 (Risk Management) and SP 800-53 privacy controls support integrating PIAs into overall security assessments.
  • NIST Privacy Framework (2020, v1.1) — A voluntary U.S. tool for managing privacy risk within enterprise risk management. Maps outcomes across five functions — Identify, Govern, Control, Communicate, Protect — and can guide PIA activities.
  • OECD and APEC — The OECD Privacy Guidelines and the APEC Privacy Framework set out high-level principles widely adopted internationally. Many jurisdictions align their PIA expectations with these frameworks, which emphasize accountability and data minimization.

Tools, Templates, and Professional Guides

  • Consultancy and industry publications — Major firms publish privacy guides and whitepapers. PwC's Data Privacy Handbook (2023) defines a DPIA as "a tool used to identify privacy risks... assess their impact and design controls." Deloitte's privacy reports highlight that DPIAs are required for high-risk processing such as profiling, health data, and monitoring, while noting common pitfalls in implementation.
  • IAPP and NGOs — The International Association of Privacy Professionals offers resources including DPIA templates and articles. For example, a Family Links Network DPIA template hosted on the IAPP site lists privacy questions tailored for non-profits. The IAPP Global Privacy Resource Center and sites like GDPR.eu also collect templates and examples adaptable across sectors.
  • Privacy assessment tools — Commercial solutions such as OneTrust and TrustArc can automate parts of a PIA process. Even simple risk registers or incident-management systems can be adapted for privacy risk assessment; the key is ensuring any tool aligns with the chosen methodology, whether ISO, GDPR, LGPD, or local law requirements.
  • Regulatory templates — Several data protection authorities publish templates and tools directly: the UK ICO provides a free DPIA template and checklist, Quebec's CAI publishes a French-language template alongside its Law 25 guide, and the French CNIL offers an online DPIA tool (beta) plus a detailed methodology and downloadable templates.

Where to Start

Regulators look for diligence, not perfection, and no single resource above is a substitute for judgment about your own project's risk. But a PIA built without reference to any of these frameworks will read, to an auditor, like exactly what it is — improvised. Start with your primary jurisdiction's official guide, adopt ISO/IEC 29134 or the NIST Privacy Framework as your underlying methodology if you operate across borders, and use the regulator-published templates as a starting point to adapt, never a finish line.

This is the sixth article in a series drawn from Privacy Impact Assessment Basics. If you're building a PIA process that needs to speak to more than one of these regulators at once, that's exactly the cross-jurisdictional discipline PIA Studio is being built to support at scale.


← All insights