(PIA): DATA COLLECTION RISKS
AND MITIGATION QUESTIONS AND
THEIR CORRECT ANSWERS
What is a Privacy Impact Assessment (PIA)?
A process to identify and minimize data privacy risks
associated with collecting personal information.
Why might an organization collect personal data?
For various business purposes, such as processing payroll
taxes or shipping goods and services.
When should an organization complete a PIA?
Any time it intends to collect a new data element from an
individual.
What types of personal data might require a PIA?
Name, date of birth, age, race, sex, address, biometric
identifiers, or any other personal data element.
What is the first step in completing a PIA?
Clearly specify the data that the organization wishes to
collect from a person.
What should an organization document regarding data
collection?
The reasons for collecting the data.
What aspects of data handling should be described in
a PIA?
How the data will be collected, used, and stored.
What should be documented regarding risks in a PIA?