6.3 Continuous Assessment: PIA, DPIA, TIA, LIA & PTA
Key Takeaways
- The exam tests five distinct assessment types — PIA, DPIA, TIA, LIA, and PTA — each triggered by a different condition, answering a different question, owned by a different role, and reviewed on a different cadence; confusing them is a common exam trap
- PTA (Privacy Threshold Assessment) is the US federal screening tier under E-Government Act §208 and OMB M-03-22 that decides whether a full PIA is required; the PTA answers "do we need a PIA?" and the PIA answers "what are the risks and how do we mitigate them?"
- DPIA is mandatory under GDPR Art. 35 for high-risk processing (systematic monitoring at scale, profiling with significant effects, sensitive data at large scale, innovative technology); if residual risk remains high after mitigation, the controller must consult the supervisory authority under Art. 36 before processing — a fact the exam frequently tests
- TIA (Transfer Impact Assessment) became standard after the CJEU Schrems II judgment (C-311/18, 16 July 2020) which invalidated the EU-US Privacy Shield and confirmed SCCs require case-by-case assessment of whether the third country provides essentially equivalent protection, with supplementary measures (encryption with controller-held keys, pseudonymization) where protection is not equivalent
- LIA (Legitimate Interests Assessment) supports GDPR Art. 6(1)(f) with a three-part test — legitimate purpose, necessity, and balancing of the data subject's interests against the controller's — and must be documented because the controller bears the burden of demonstrating the lawful basis
The Assessment Family
The CIPM Body of Knowledge (V.C) requires the privacy manager to manage continuous assessment of the privacy program by conducting risk assessments on systems, applications, processes, and activities. The exam tests five distinct assessment types — PIA, DPIA, TIA, LIA, and PTA — each triggered by a different condition, answering a different question, owned by a different role, and reviewed on a different cadence. Confusing them is a common exam trap.
Comparison Table — The Five Assessments
| Assessment | Full Name | Trigger | Question Answered | Typical Owner | Review Cadence |
|---|---|---|---|---|---|
| PTA | Privacy Threshold Assessment | New system, process, or data use involving personal information (US federal: E-Government Act §208 / OMB M-03-22 screening) | "Does this processing rise to a level that requires a full PIA?" | Privacy office / privacy analyst | At initiation; re-screened on material change |
| PIA | Privacy Impact Assessment | PTA determines the processing is higher-risk or qualifies under the organization's threshold; US federal: systems of records, SORN, PII | "What are the privacy risks of this system/process, and what controls mitigate them?" | Privacy office with system owner | Before launch; reviewed at major change or every 1–3 years |
| DPIA | Data Protection Impact Assessment | GDPR Art. 35 — "high risk" processing: large-scale systematic monitoring, profiling with significant effects, sensitive data at scale, new tech | "What are the risks to data subjects' rights and freedoms, are they mitigated, and must the DPO/DPA be consulted?" | Controller (often with DPO); DPO advises | Before processing; reviewed when risk changes or roughly every 2 years |
| TIA | Transfer Impact Assessment | Third-country transfer of EU/EEA personal data (post-Schrems II, CJEU C-311/18, July 2020) — required when using SCCs or other Chapter V transfer tools | "Does the third country provide essentially equivalent protection, and what supplementary measures are needed?" | Data exporter (controller/processor) | Before transfer; reviewed when third-country law or transfer mechanism changes |
| LIA | Legitimate Interests Assessment | Reliance on GDPR Art. 6(1)(f) legitimate interests as the lawful basis | "Is the purpose legitimate, is processing necessary, and does the data subject's interest override the controller's interest (the balancing test)?" | Controller (often with DPO) | Before processing; reviewed when purpose or balancing shifts |
PTA vs PIA — The US Federal Tier
The Privacy Threshold Assessment (PTA) is the US federal screening tier established by the E-Government Act of 2002, Section 208, and OMB Memorandum M-03-22. It is a short screening questionnaire completed for every new system or material change. If the PTA shows the system contains personal information in a system of records, creates a new System of Records Notice (SORN), or processes sensitive data, a full PIA is required. The PTA answers "do we need a PIA?"; the PIA answers "what are the risks and how do we mitigate them?" Private-sector organizations adopt similar threshold screening (often called "privacy screening" or "triage") to route only higher-risk processing to a full PIA.
DPIA — The GDPR High-Risk Trigger
The DPIA is mandatory under GDPR Art. 35 for "high risk" processing. The European Data Protection Board (EDPB) criteria for high risk include: evaluation or scoring, automated decision-making with significant effects, systematic monitoring, sensitive data at large scale, large-scale matching or combination of datasets, innovative technology, data subjects unable to easily exercise control, and large-scale processing of data of vulnerable individuals. The DPIA must describe the processing, assess necessity and proportionality, identify risks to data subjects, and identify mitigations. If residual risk remains high after mitigation, the controller must consult the supervisory authority under Art. 36 before processing — a fact the exam frequently tests. The DPO must be consulted for the DPIA under Art. 35(2); where the organization has no DPO, the controller still conducts the DPIA but the consultation duty shifts to the controller's internal advisory process.
TIA — The Schrems II Legacy
The Transfer Impact Assessment became standard practice after the CJEU's Schrems II judgment (Case C-311/18, 16 July 2020), which invalidated the EU-US Privacy Shield and confirmed that Standard Contractual Clauses (SCCs) are valid but require a case-by-case assessment of whether the third country provides essentially equivalent protection. The TIA examines the third country's surveillance laws, access by public authorities, and available legal remedies; where protection is not equivalent, the controller must adopt supplementary measures (encryption with controller-held keys, pseudonymization, contractual transparency, challenge mechanisms). The EDPB's Recommendations 01/2020 provide the structured methodology.
LIA — The Three-Part Balancing Test
The Legitimate Interests Assessment supports reliance on GDPR Art. 6(1)(f). It is a three-part test: (1) Purpose — is the controller's purpose legitimate? (2) Necessity — is the processing necessary to achieve that purpose, or is there a less intrusive means? (3) Balancing — do the data subject's interests, rights, and reasonable expectations override the controller's interest? The LIA must be documented because the controller bears the burden of demonstrating the lawful basis. A LIA is not a one-time document; it is reviewed when the purpose shifts or the data subject's reasonable expectations change.
Review Cadence and Continuous Assessment
"Continuous assessment" does not mean "re-do every assessment every month." It means each assessment is reviewed on a defined cadence and on material change — a new data use, a new vendor, a new third-country legal development, a new processing purpose. The privacy manager maintains an assessment register tracking every assessment, its trigger, its owner, its last review date, and its next review date.
Worked Scenario — A New Employee-Monitoring Tool
A company plans to deploy a workplace-analytics tool that collects system-login telemetry, email metadata, and location data for 5,000 employees across the EU and US. The privacy manager runs a PTA-style screening: high risk — sensitive inferences possible, systematic monitoring, large scale. A PIA is launched for the US deployment. For the EU deployment, a DPIA is mandatory (systematic monitoring at scale is an EDPB high-risk criterion). Because the vendor stores data in the US, a TIA is conducted on the transfer — Schrems II applies, and supplementary measures (encryption with EU-held keys, pseudonymization, vendor transparency report) are required. The controller also runs a LIA if it relies on legitimate interests for the monitoring (employee monitoring rarely fits consent), documenting the three-part balancing test. The DPO is consulted for the DPIA. All four assessments are filed in the register with review dates tied to the annual vendor-review cycle.
The scenario shows that a single new processing activity can trigger multiple assessments simultaneously — the privacy manager's V.C job is to identify every applicable assessment, complete each on its own life cycle, and link them in the assessment register.
A company wants to use GDPR Art. 6(1)(f) legitimate interests as the lawful basis for sending marketing emails to existing customers. Which assessment must it complete and document, and what does that assessment specifically test?
A US federal agency is launching a new case-management system that will store citizens' names, SSNs, and case notes. Staff complete a Privacy Threshold Assessment (PTA) that confirms the system will contain sensitive PII in a system of records. Under OMB M-03-22, what is the immediate next step?