Open navigation
Search
Offices – Austria
Explore all Offices
Global Reach

Apart from offering expert legal consultancy for local jurisdictions, CMS partners up with you to effectively navigate the complexities of global business and legal environments.

Explore our reach
Insights – Austria
Explore all insights
Search
Expertise
Insights

CMS lawyers can provide future-facing advice for your business across a variety of specialisms and industries, worldwide.

Explore topics
Offices
Global Reach

Apart from offering expert legal consultancy for local jurisdictions, CMS partners up with you to effectively navigate the complexities of global business and legal environments.

Explore our reach
CMS Austria
Insights
About CMS

Select your region

GDPR

Privacy Impact Assessment (PIA)

Privacy impact assessment –  yes or no?

The GDPR orders companies to perform a privacy impact assessment (“PIA”) before initiating data applications (that bear a risk for data subjects). Companies must first assess whether their data processing operations will potentially impose a risk to the rights and liberties of data subjects. If there is a high risk, they must then perform a detailed PIA. The most challenging part of a PIA will likely be to assess whether there is a high risk in one’s company. In this context, the GDPR focuses on the perspective of the data subject, i.e. the question whether the rights and liberties of the individual could be affected (in practice, such curtailments of personal rights of the data subject are called “privacy impact”).

In the course of data mapping, all departments in your company should first perform an assessment of said impact and thereby assess risks for the data subjects. The second step should be to describe the processing operations and the measures to be taken (“What exactly do I do and what can I do to reduce the risk?”). The GDPR leaves it up to the data controllers to decide on how they want to realise this process.

In practice, especially companies that use new technologies (such as tracking tools), work with special data categories (e.g., health-related data, crime-related data, etc.) or process data according to a so-called blacklist (a list of particularly high-risk types of data processing that will be published by the Austrian Data Protection Authority in the future) will have to perform PIAs.

Insights on Privacy Impact Assessment (PIA)

Searching for the international perspective?

CMS’ global thought leadership expands to more than 40 countries. Find local insights to your specific matter – locally and globally.

Local market knowledge. Global outlook

We provide future-facing legal advice to help your organisation thrive. Combining local market knowledge and a global perspective, and with lawyers in locations worldwide, your organisation benefits from the expertise it needs, even across borders.

About CMS
People across CMS Find a Lawyer
7,200+ Lawyers
1,300+ Partners
Locations across CMS Find an office
50+ Countries
90+ Offices
21 Member firms
Back to top