The Project Manager must use a privacy impact assessment (PIA) to assess the impact on privacy during the lifecycle of a project. The following must be checked:
Impact | Further action required |
Has no impact on privacy | Where there is no impact on privacy no further action need be taken. |
Has a minor impact on privacy | Where there is a minor impact on privacy the Information Assurance Manager may ask the project manager to complete a privacy questionnaire. The outcome will be determined by the Information Assurance Manager in conjunction with the project manager. Any identified risks and recommendations are to be built into the project plans. |
Has a major impact on privacy | Where there is a major impact then a full Privacy Impact Assessment (PIA) should be undertaken, normally by the Information Assurance Manager, although an external consultant may be used. |
If your project includes handling commercially sensitive information or information supplied under contract, or you have any queries about these documents, please contact the Information Assurance Manager infoman@essex.ac.uk.
The project Business Case should confirm that a checklist has been completed and whether or not the project will have an impact on privacy.
If the Information Assurance Manager has determined that a full PIA is necessary then the resource requirements for the project should include either the Information Assurance Manager’s time (normally five days), if they have capacity, or costs of an external consultant if a PIA is required. Consultancy cost will need to be part of the project budget.
Project reports should report progress against recommendations arising from a PIQ or PIA.
Project risk registers should include risks identified by the PIQ or PIA.
The Information Assurance Manager can be contacted for advice at any stage, infoman@essex.ac.uk