comparing-pia-methodologies

Installation
SKILL.md

Comparing PIA Methodologies

Overview

Multiple established methodologies exist for conducting Privacy Impact Assessments: the CNIL PIA tool, ICO DPIA template, NIST Privacy Framework, and ISO/IEC 29134:2017. Each methodology reflects its originating regulatory context, organisational assumptions, and privacy philosophy. Selecting the appropriate methodology — or combining elements from several — is critical for producing assessments that satisfy regulatory expectations, align with organisational maturity, and address the actual risks of the processing activity. This skill provides a structured comparison framework for methodology selection.

Methodology Profiles

1. CNIL PIA Tool (France)

Origin: Commission Nationale de l'Informatique et des Libertes (CNIL), first published 2015, updated 2018 for GDPR alignment.

Structure:

  • Step 1: Context — Describe the processing, its purposes, the data processed, and the actors involved.
  • Step 2: Fundamental Principles — Assess compliance with necessity, proportionality, data subject rights, and obligations (Art. 5, 6, 9, 12-22, 28, 44).
  • Step 3: Risks — Identify feared events (illegitimate access, unwanted modification, disappearance of data), assess severity and likelihood.
  • Step 4: Validation — Map risks against controls. Decide whether to accept residual risk, implement additional measures, or consult the supervisory authority.
Installs
24
GitHub Stars
239
First Seen
Jun 9, 2026
comparing-pia-methodologies — mukul975/privacy-data-protection-skills