- What a privacy impact assessment is, in plain English
- The two parts of every PIA
- When a PIA is done
- Is a PIA compulsory in Australia?
- A worked example: a physiotherapy clinic launches a booking app
- Common misconceptions about DPIAs and PIAs
- When a privacy lawyer should be involved
- The question to ask before your next project
DPIA stands for Data Protection Impact Assessment, and in Australia the same idea usually travels under a simpler name: a privacy impact assessment, or PIA. In short, it is a structured, written review of how a project will affect people's privacy, done before the project goes live, so that problems can be designed out rather than patched up after launch.
This article explains what a PIA actually involves, when one is required or simply worth doing for a small business, how it works in practice through a worked example, and the misconceptions that trip business owners up. If you are collecting customer data, building an app, introducing AI features or changing how you share information with suppliers, this is the concept to understand before you start.
What a privacy impact assessment is, in plain English
The Office of the Australian Information Commissioner (OAIC) defines a privacy impact assessment as a systematic assessment of a project that identifies the impact the project might have on the privacy of individuals, and sets out recommendations for managing, minimising or eliminating that impact. The same definition appears in s 33D of the Privacy Act 1988 (Cth), which is the provision the Commissioner can use to require one from a government agency.
A PIA is not a privacy policy, although the two are often confused. A privacy policy is a document that tells the public what you do with their information. A PIA is the analysis that happens first, working out what information the project will collect, why, who will see it, what could go wrong with it, and what controls should be built in. The policy, collection notices and supplier contracts come afterwards, once the analysis has told you what they need to say.
The DPIA and the PIA are close cousins rather than the same thing. A DPIA is the term used by the European Union's General Data Protection Regulation (GDPR), and it carries specific legal triggers and content requirements under European law. A PIA is the broader Australian practice that the OAIC recommends to any organisation handling personal information. For most small businesses the two can be treated as one exercise: a structured risk assessment that asks the right questions and records the answers. If your business deals with people in the EU or UK, you need to make sure the assessment also ticks the GDPR boxes.
The two parts of every PIA
Every worthwhile privacy impact assessment has two halves, and it helps to think of them separately.
The first half is the impact analysis. You map what the project will do with personal information: what is collected, from whom, where it is stored, who can access it, and who it is shared with. Then you work through what could go wrong for the individuals involved. Common problems include a data breach or weak access controls, collecting more information than needed or keeping it too long, using information in ways people did not expect or understand, producing unfair or inaccurate outcomes through automated decisions, and sending information to overseas suppliers without adequate safeguards.
The second half is the recommendations. For each risk you identified, you set out what you will do to manage, minimise or eliminate it. The OAIC is explicit that this second half is not optional decoration: an assessment that lists problems without solutions is only half an assessment. Realistic controls include collecting less data in the first place, pseudonymising or de-identifying information where possible, encrypting it, restricting who inside the business can see it, giving customers opt-outs, and doing proper due diligence on third-party providers. Each recommendation should name who is responsible for it and when it will be done, so the document produces action rather than good intentions.
When a PIA is done
The timing of a privacy impact assessment is part of what makes it work. The OAIC's guidance is that a PIA should be an integral part of the project planning process, not a formality bolted on after the build is finished. Run early, the assessment shapes the design: you discover that you do not need the customer's date of birth, or that the app does not need location access at all, while those choices are still cheap to make. Run at the end, you find out about problems when fixing them means rebuilding, renegotiating or relaunching.
The OAIC links the PIA to privacy by design, the idea that privacy should be built into a product from the start rather than added afterwards. It also publishes a free privacy impact assessment tool and an e-learning course that walk through the steps, so a small business does not need to invent the process from scratch.
Is a PIA compulsory in Australia?
For most private businesses, no. The Privacy Act 1988 (Cth) does not generally require organisations to conduct a privacy impact assessment before a project. The one compulsory direction power, in s 33D of the Act, lets the Information Commissioner require an assessment where a government agency proposes an activity that might have a significant impact on privacy. Australian Government agencies are also bound by the Privacy (Australian Government Agencies – Governance) APP Code 2017 to conduct a PIA for every high privacy risk project. Private companies are not under that obligation.
What is compulsory for an organisation that is covered by the Privacy Act is APP 1, the principle requiring open and transparent management of personal information. Under APP 1.2, an entity must take such steps as are reasonable in the circumstances to implement practices, procedures and systems that will ensure it complies with the Australian Privacy Principles. A documented PIA is one of the most practical ways to show those reasonable steps were taken, which matters if a complaint is made or a regulator asks questions later.
Two further points decide whether your small business should treat a PIA as more than good practice.
The first is the small business exemption. Under s 6D of the Privacy Act, a business with an annual turnover of $3 million or less is generally exempt from the Australian Privacy Principles, but the OAIC's small business guidance lists important exceptions. Regardless of turnover, the Act covers health service providers, businesses that trade in personal information, contractors providing services under Commonwealth contracts, operators of residential tenancy databases, credit reporting bodies and several other categories. A physiotherapy clinic or private school is a health service provider and is covered even with turnover well under $3 million.
The second is that the exemption is ending. The Privacy and Other Legislation Amendment Act 2024 (Cth) removes the small business exemption, and the change is scheduled to commence on 10 December 2026, two years after royal assent. From that date most small businesses will fall within the Privacy Act and will need to comply with all 13 Australian Privacy Principles, including APP 1. The businesses that will feel this most sharply are those that have never had to think about privacy law because of their size.
There is also the GDPR dimension. Under Article 35 of the GDPR, a DPIA is required before any type of processing that is likely to result in a high risk to the rights and freedoms of individuals. The GDPR can apply to an Australian business even though it is not based in Europe, where the business offers goods or services to people in the EU or monitors their behaviour. If you run an online store that ships to Europe, or an app that tracks the behaviour of European users, a DPIA may be legally required for high-risk processing regardless of your turnover. In that situation your PIA needs to follow the GDPR's structure, including the requirement to consult the supervisory authority if high risks remain after mitigation.
A worked example: a physiotherapy clinic launches a booking app
Coastal Health Physio is a three-clinic business with an annual turnover of about $1.8 million. It is a health service provider, so despite its size it is already covered by the Privacy Act and must comply with the Australian Privacy Principles. It decides to launch a patient app that lets clients book appointments, message their physiotherapist and store their treatment history, including notes about injuries and health conditions.
Before commissioning the app, Coastal Health runs a privacy impact assessment. The team maps the data flows: the app will collect names, contact details, appointment history, health information typed into forms, and location data if the client uses the app to find the nearest clinic. The app is being built by a developer in India, so client data will leave Australia. The impact analysis identifies the significant risks: a breach of sensitive health information, an overseas developer with access to client data, staff logging into the app with weak passwords, and health information being kept on phones longer than needed.
The recommendations half of the assessment decides what to do about each risk. Coastal Health removes location tracking except when a client actively requests clinic directions. It instructs the developer to build the app so health information is encrypted in transit and at rest, and access is limited to the treating physiotherapist and the practice manager. It signs a data processing agreement with the developer covering security, sub-processors and breach notification, and reviews where the developer's servers are located. It sets a retention rule that treatment notes are kept only as long as the practice needs them under its clinical record-keeping obligations, and it updates its privacy policy and adds a collection notice at the point of sign-up. Each control is assigned to a named staff member with a completion date, and the assessment is signed off by the practice manager.
The result is a project that launches with privacy built in, and a document that Coastal Health can produce if a client complains or the OAIC ever asks how it manages health information. The exercise took a few days of staff time and no external cost, and it changed several design decisions that would have been expensive to reverse after launch.
Common misconceptions about DPIAs and PIAs
Five misconceptions recur whenever small business owners first encounter the concept:
-
A PIA is just another name for a privacy policy: It is the opposite. The policy is a public document; the PIA is the internal analysis that tells you what the policy should say. Businesses that skip the analysis and write a generic policy copied from a template miss exactly the risks that are specific to their project.
-
Small businesses do not need to think about privacy law: Many do already, because they are health service providers, trade in personal information or fall into another exception to the small business exemption. And from 10 December 2026 the exemption disappears altogether. The businesses that will be caught out are the ones that assumed their size protected them.
-
A PIA is only for big companies rolling out AI: AI features are a common trigger because they can make decisions about individuals, but the trigger in Australia is simpler than that: any project that touches personal information in a new or expanded way is a candidate. A loyalty app, new CCTV with facial recognition, or a switch to an overseas cloud provider all justify one.
-
Once a PIA is signed off, the work is done: Projects change: new features are added, suppliers change, markets expand. Each change can alter the privacy risk. The OAIC's guidance treats the PIA as part of project planning and risk management, which means it should be revisited when the project materially changes.
-
If nothing is legally required, there is no point: A PIA is the documented record of the reasonable steps APP 1 contemplates, and it is one of the few documents that shows good faith after something has gone wrong. Businesses that can point to a genuine pre-launch assessment are in a much stronger position with the OAIC, and with their customers, than businesses that cannot.
When a privacy lawyer should be involved
A small business can run a straightforward PIA itself using the OAIC's tool and guidance, but there are situations where a privacy lawyer earns their fee. The first is scoping: working out whether your business is covered by the Privacy Act now, whether it falls within an exception to the small business exemption, and whether the GDPR applies to your customer base. Getting that analysis wrong means either over-investing in compliance you do not need or, more dangerously, assuming you are exempt when you are not.
The second is the assessment itself when the stakes are higher. If a project involves sensitive information such as health data, children's data, biometrics, large-scale profiling or automated decisions about individuals, a lawyer can help determine whether the processing is likely to result in high risk, structure the assessment to meet both Australian and GDPR requirements, and advise on whether residual risks after mitigation are acceptable. They can also negotiate the supplier contracts the assessment will call for, such as data processing agreements with overseas developers and cloud providers, and draft the policies, collection notices and breach response procedures that turn the assessment's recommendations into day-to-day practice.
Finally, a lawyer is the right person when things go wrong. The Privacy Act's notifiable data breaches scheme in Part IIIC requires an entity to notify the OAIC and affected individuals when there are reasonable grounds to believe an eligible data breach has occurred, meaning unauthorised access to, disclosure of, or loss of personal information that is likely to result in serious harm. A lawyer can assess whether a breach crosses that threshold and manage the notification. Penalties for serious interference with privacy under s 13G of the Act reach $50 million for a body corporate, so the assessment that prevents a breach, and the documentation that shows reasonable steps were taken, are inexpensive insurance by comparison.
The question to ask before your next project
Before you build the app, sign the supplier contract or switch platforms, ask one question: what personal information will this project touch, and what is the worst thing that could happen to it? If you cannot answer confidently, or the answer makes you uncomfortable, that is the signal to run a privacy impact assessment.
For most Australian small businesses the decision to run one is not driven by a legal mandate today, but by the combination of the health service provider and other exceptions that already apply, the GDPR's reach if you deal with Europe, and the removal of the small business exemption on 10 December 2026. The businesses that build the PIA habit now, while it is still voluntary, will be the ones for whom privacy compliance in 2027 is routine rather than a scramble. The assessment does not need to be elaborate. It needs to be honest, written down, and done early enough to change the design.