Skip to main content

Platform Modules

Privacy Impact Assessment (PIA) - Unicis.Tech OÜ Docs

Evaluate and manage privacy risks related to personal data processing, with GDPR-aligned risk matrices.

The Privacy Impact Assessment (PIA) module helps organizations evaluate and manage privacy risks related to personal data processing. It supports compliance with GDPR and other privacy regulations by ensuring that risks to individuals’ rights and freedoms are identified and mitigated.

To create a Privacy Impact Assessment:

  1. Navigate to All Tasks
  2. Select an existing task or create a new one
  3. Navigate to the Privacy Impact Assessment tab
  4. Click Register Privacy Impact Assessment
  5. Follow the guided steps

Probability of Risk

The Probability of Risk refers to the likelihood that a specific risk will materialize:

LevelDescription
RareHighly unlikely; requires an unusual combination of events to materialize
UnlikelyNot expected under normal conditions; low probability
PossibleModerate likelihood; neither rare nor frequent
ProbableLikely to occur in most circumstances; predictable and regularly occurring
SevereAlmost certain to occur; highly predictable and frequent

Security of Risk (Impact)

The Security of Risk refers to the potential impact or severity in relation to data privacy — specifically the consequences of a loss of confidentiality, integrity, or availability of personal data:

LevelDescription
InsignificantMinimal operational impact; negligible costs; does not notably affect the data subject’s business or finances
MinorNoticeable but limited impact; some costs; minor financial impact for the data subject; unlikely to significantly affect rights
ModerateSubstantial operational impact; very costly; considerable harm to the data subject; does not involve special categories
MajorSevere disruption; highly damaging and extremely costly; may involve special categories (e.g., criminal history or sensitive data); significant impact on rights and freedoms
ExtremeComplete operational failure; potentially unsurvivable; may have life-threatening consequences or severe impacts on personal freedoms

Risk Levels

Risk Levels are calculated by combining Probability and Security of Risk (Impact):

LevelRangeIndicatorDescription
Low1–3 (1%–12%)GreenRare or unlikely with insignificant or minor impact; minimal action required
Medium4–9 (16%–36%)YellowPossible with moderate impact; monitor and address with reasonable measures
High10–16 (40%–64%)OrangeProbable with major impact; prompt and proactive management required
Extreme20–25 (80%–100%)RedSevere in both probability and impact; immediate action required

Dashboard

The PIA dashboard provides an overview of all assessments:

ColumnDescription
RegisterAssessment identifier
StatusTo Do / In Progress / Completed
Confidentiality & Integrity riskRisk percentage
Availability riskRisk percentage
Transparency & data minimization riskRisk percentage
ActionsEdit / Delete

Add a PIA

A Privacy Impact Assessment can only be added via a Task in the Privacy Impact Assessment tab.

  1. Open a task and navigate to the Privacy Impact Assessment tab
  2. Click Register Privacy Impact Assessment
  3. Follow the guided steps (required fields are marked with a red star)
  4. Click Next to proceed through each step

Steps:

  1. Data processing
  2. Confidentiality and Integrity
  3. Availability
  4. Transparency and data minimization
  5. Results
  6. Corrective measures

Edit

Edit an existing assessment from the dashboard by clicking Actions → Edit.

Delete

Delete an assessment from the dashboard by clicking the Delete button.

Activity Logs

Access audit logs by opening the associated task and navigating to Audit Logs → Privacy Impact Assessment Audit Logs.

Logged events:

  • Created
  • Updated
  • Deleted