Privacy Impact Assessment 3
Data Analysis and IT
21st Jun 2025
2
Privacy Impact Assessment 3
Task
Prepare a 1600 – 1800-word report evaluating the consequences and key ethical, legal, regulatory and privacy considerations of a data project on key stakeholders.
Instructions
Choose a data-related situation with which you are familiar. It can relate to any aspect of the data supply chain: acquire, store, aggregate, analyse, use, share/sell or dispose.
Revisit Building Digital Trust
Conduct a Privacy Impact Assessment of this situation using the guidelines on page 2-3
You will need to consider the following elements:
Purpose of data collection, use or storage
Information flows, upstream and downstream considerations
Stakeholders including data subjects and their relative power, agency and vulnerabilities
Analysis of the impacts (including unintended or unwanted impacts) on stakeholders including data subjects
Ethical concerns
Relevant regulatory considerations
Public interest concerns
Risk profile
Strategies for risk mitigation
Overall recommendation.
Assessment 3 guidelines Privacy Impact Assessment
This assessment task requires you to conduct a Privacy Impact Assessment (PIA) examining the potential consequences of a data project on key stakeholders, particularly data subjects.
Imagine you are the ‘owner’ of the process/situation being considered.
Task
Prepare a 1600-1800 word report evaluating the consequences and key legal, regulatory and privacy considerations of a data project on key stakeholders. You should include additional data (e.g. tables or diagrams) in appendices to allow you to do a detailed analysis and then draw the most relevant insights into your report.
Note: The purpose of appendices is to provide content that can support your analysis. Using appendices will allow you to demonstrate that you have applied a range of ethical, legal and regulatory frameworks, and have written up your comprehensive analysis and recommendations based on this application.
Words in appendices are excluded from the word count. Appendices should be no more than 4 pages.
Instructions
Choose a data-related situation with which you are familiar. It can relate to any aspect of the data supply chain. You will need to consider the following elements:
Background
In this section you should:
1. Clearly and succinctly outline the purpose of data collection, use or storage.
2. State why you need this data.
3. You should also outline the data supply chain/process including information flows, upstream and downstream considerations. CRICOS Provider Code 00098G
4. How will the data be collected, stored, used and deleted?
5. Who are the key stakeholders including data subjects? Include their relative power, agency (include control of their data) and vulnerabilities (you can use a table for this); also include your relationship.
6. Consider the volume, variety and sensitivity of the data.
7. Why is a data impact assessment needed?
Impacts
1. What are the main impacts of this data collection, use or storage?
2. Include unintended or unwanted impacts on key stakeholders including data subjects.
3. In considering the impacts, apply ethical decision-making frameworks we covered in weeks 2 and 3 and draw relevant insights from your analysis.
Legal and regulatory concerns
Here you should consider any legal and regulatory concerns. For example:
What are the privacy implications?
Are there any issues of public concern/interest?
What regulatory considerations apply?
Risk profile
Construct table(s) showing the identified risks and affected stakeholders. Explain your reasoning for each risk identified. Assess Likelihood of Harm (remote/possible/probable); Severity of Harm (minor/moderate/significant/severe) and Overall Risk (low/medium/high).
See below for a possible configuration.
Focusing particularly on high-risk areas, what are some possible strategies for risk mitigation? Will they reduce or eliminate risks?
Any residual risks?
Overall recommendations
What are your overall recommendations? The recommendations need to include what you might propose to mitigate high risks.
Any implementation considerations?
How do you intend to ensure ongoing compliance with regulations and privacy principles?
Assessment criteria
The following criteria will be used to assess your submission:
Clarity of description of situation, purpose of data use
Depth, breadth and appropriateness of discussion of context, scope, and affected stakeholders including data subjects (Apply ethical and regulatory frameworks to the discussion)
Ǫuality of risk analysis and proposed mitigation strategies
Structure, written expression, clarity, Harvard referencing