What is the difference between a DPIA and a PIA?

In Indian practice a DPIA is the assessment contemplated by the DPDP Act as an obligation of Significant Data Fiduciaries, while PIA is the older, general term for any privacy impact assessment an organisation chooses to run. The substance — identifying risks to individuals from a processing activity and the measures managing them — is the same; the difference is whether it is a statutory duty or good practice.

Dinkar Singh

Because the terms are used loosely by vendors, ask what a product actually produces rather than which acronym it uses: a record tied to a specific processing activity, with the risks, the mitigations, the named approver and a version history.

General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.

Dinkar SinghDinkar covers privacy engineering at ProtectComply — discovery, consent propagation and the evidence trail behind them.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →