Most organizations do not fail at privacy because they lack reports. They fail because no one paused to ask six simple questions before launching a project. A full Privacy Impact Assessment can take weeks — but deciding whether you need one shouldn't. The Quick Check is a one-page diagnostic that shows, in minutes, whether a project appears low risk and just needs a short accountability note, or high risk and needs a full PIA.
The Six Questions That Define High-Risk Processing
Before deciding whether a full PIA is needed, run the project through this quick filter. These six questions are the risk gateway: if all answers are "No," just record a short accountability note and move forward. If any answer is "Yes," the project involves high-risk processing and requires a full Privacy Impact Assessment.
- Sensitive or potentially sensitive data? Both the GDPR (Art. 9) and Brazil's LGPD (Art. 5, II) list categories always treated as sensitive — racial or ethnic origin, religious or philosophical belief, political opinion, union affiliation, health data, sexual life or orientation, and genetic or biometric data tied to an identifiable person. Canada's PIPEDA has no fixed list but treats health information as inherently sensitive and applies a contextual test to everything else: financial records, consumption habits, or online activity can become sensitive if their misuse could cause financial loss, reputational damage, or employment discrimination.
- Large-scale processing? None of the three frameworks sets a magic number. Regulators like the European Data Protection Board, Brazil's ANPD, and the UK's ICO look at context instead — the number of people affected, the amount of data per person, how long the activity runs, and how broad its geographic reach is. A hospital network handling patient records daily is clearly large-scale; a solo clinic with fifty patients is not.
- Automated decisions or profiling? Will an algorithm or automated system decide something that affects people's lives? The GDPR's Article 22 restricts solely automated decisions that create legal or significant effects, and regulators worldwide flag automation as a risk precisely because it can be opaque, biased, and hard to challenge — a credit-scoring algorithm or an AI recruiting tool that filters résumés is high risk because it shapes access to money or jobs.
- Public exposure or broad sharing? Whenever personal information leaves the controlled environment of your organization, risk rises sharply. Under the GDPR (Art. 35(3)(c)), the LGPD (Art. 33), and ANPD Resolution 2/2022, the logic is the same: once data is public, it can be copied, misused, or combined without limits — a municipality publishing property tax records with names and addresses is high risk for exactly this reason.
- Potential harm to individuals? This is the heart of a PIA: not the technology, but the impact on people. The GDPR (Recital 75), the LGPD (Art. 5, XVII), and PIPEDA (s. 10.1(7)) all recognize that a project becomes high risk when misuse or a breach could cause real harm — financial, reputational, discriminatory, psychological, or exclusionary. A recruitment algorithm that consistently ranks women or minorities lower is a harm question just as much as a database breach is.
- Transfer of personal data outside Quebec? Under Quebec's Law 25, a PIA is mandatory whenever personal information leaves the province, to another Canadian province or another country — even a startup sending customer data to its own branch in Toronto triggers the obligation, and the analysis has to cover the sensitivity of the data, the purpose of the transfer, the safeguards in place, and the legal framework of the destination.
The Rule of Thumb Behind Every Question
Each of the six questions carries its own rule of thumb, and they all point the same direction: when in doubt, treat the project as high risk and perform a full PIA. If misuse of the data could lead to discrimination, exclusion, financial harm, or reputational damage, treat it as sensitive. If a project involves thousands of people, continuous flows of data, or systematic handling of sensitive categories, treat it as large-scale. If a system decides for or about people without meaningful human review, treat it as high risk. None of these thresholds are about giving an organization the benefit of the doubt — they're about catching the project before it ships, not explaining it after a complaint.
When the Answer Is "No" Across the Board
A low-risk finding isn't a free pass to skip documentation — it's still worth a short accountability note recording that the six questions were asked and answered. A survey collecting names and emails from two hundred people for internal use only, with no automated decisions and no external sharing, is a textbook example: sensitive data, no; large-scale, no; automated decisions, no; public exposure, no; potential harm, no. The project doesn't need a full PIA, but the note itself is what proves, later, that someone actually checked.
Why This Matters More Than the Full PIA Template
A comprehensive PIA template is only useful once you already know you need one. The gap most organizations fall into isn't a bad template — it's never running the six-question filter in the first place, so a high-risk project ships without anyone ever having paused to ask. The Quick Check exists to close exactly that gap: a diagnostic simple enough to run before a project launches, not complex enough that teams skip it under deadline pressure.
This is the second article in a series drawn from Privacy Impact Assessment Basics. The next piece in this series walks through how to turn a completed Quick Check into a record regulators actually respect — signed, timestamped, and ready to produce on request. If you want to see how these six questions apply to a project on your desk right now, the book's full Quick Check chapter walks through each one with worked examples, and it's the same judgment PIA Studio is being built to support at scale.
