In Indian practice a DPIA is the assessment contemplated by the DPDP Act as an obligation of Significant Data Fiduciaries, while PIA is the older, general term for any privacy impact assessment an organisation chooses to run. The substance — identifying risks to individuals from a processing activity and the measures managing them — is the same; the difference is whether it is a statutory duty or good practice.
Because the terms are used loosely by vendors, ask what a product actually produces rather than which acronym it uses: a record tied to a specific processing activity, with the risks, the mitigations, the named approver and a version history.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Dinkar Singh — Dinkar covers privacy engineering at ProtectComply — discovery, consent propagation and the evidence trail behind them.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →