Lab 02 — Perform a Privacy Impact Assessment (PIA)
Mission Information
Section titled “Mission Information”| Field | Details |
|---|---|
| Lab Type | Privacy / GRC |
| Difficulty | Intermediate |
| Estimated Time | 90–120 Minutes |
| Primary Role | Privacy Analyst / GRC Analyst |
| Environment | Simulated Enterprise Project |
| Primary Deliverable | Completed Privacy Impact Assessment |
| Supporting Deliverables | Screening, Data Inventory, Data Flow, Risk Register, Control Assessment, Remediation Plan & Approval Record |
Mission Scenario
Section titled “Mission Scenario”You are working as a:
Privacy & GRC Analystat:
CloudPay TechnologiesCloudPay is planning to launch a new:
AI-Powered Customer Support PlatformThe business wants the platform to:
Answer Customer Questions
Summarize Support Tickets
Recommend Responses
Identify Customer Sentiment
Retrieve Account Information
Escalate Complex CasesThe proposed solution will integrate with:
Customer Portal
CRM
Support Platform
Order Database
AI Model Provider
Analytics Platform
Cloud StorageThe project team wants to launch within:
8 WeeksThe Privacy team has been asked:
Can this project proceed, and what privacy controls must be implemented before production?
You must perform a complete:
Privacy Impact Assessment
Section titled “Privacy Impact Assessment”Mission Objective
Section titled “Mission Objective”Your objective is to evaluate:
What Personal Data Is Processed?
Why Is It Needed?
Where Does It Go?
Who Can Access It?
Which Vendors Receive It?
Where Is It Stored?
How Long Is It Retained?
Does AI Introduce Additional Risk?
Can Individuals Exercise Their Rights?
What Could Go Wrong?
Which Controls Exist?
What Is the Residual Risk?
Can the Project Be Approved?What You Will Build
Section titled “What You Will Build”Create:
01 Privacy Screening Questionnaire
02 PIA Scope Document
03 Personal Data Inventory
04 Data Flow Map
05 Purpose & Data Minimization Assessment
06 Privacy Requirements Matrix
07 Privacy Risk Register
08 Privacy Control Assessment
09 Privacy Remediation Plan
10 Residual Risk Assessment
11 PIA Approval Record
12 Final Privacy Impact Assessment ReportRecommended Lab Workspace
Section titled “Recommended Lab Workspace”Create:
Lab-02-Privacy-Impact-Assessment/│├── 01-Screening/├── 02-Scope/├── 03-Data-Inventory/├── 04-Data-Flow/├── 05-Minimization/├── 06-Requirements/├── 07-Risk/├── 08-Controls/├── 09-Remediation/├── 10-Residual-Risk/├── 11-Approval/└── 12-Final-Report/Part 1 — Understand the Proposed Project
Section titled “Part 1 — Understand the Proposed Project”Before assessing risk, understand what the business wants to build.
Step 1.1 — Review the Business Objective
Section titled “Step 1.1 — Review the Business Objective”The AI support platform will:
Customer Question ↓AI Assistant ↓Retrieve RelevantAccount / Support Data ↓Generate Response ↓Human Support AgentorCustomerBusiness benefits include:
Faster Support
Reduced Agent Workload
24×7 Assistance
Improved Response Consistency
Automated Ticket SummariesStep 1.2 — Identify Project Stakeholders
Section titled “Step 1.2 — Identify Project Stakeholders”Document:
Business Owner→ Head of Customer Support
Product Owner→ AI Product Manager
Technical Owner→ Engineering
Privacy→ Privacy Team
Security→ Cybersecurity
Legal→ Legal Counsel
Vendor Management→ Procurement
AI Governance→ AI Governance TeamStep 1.3 — Identify Core Technology
Section titled “Step 1.3 — Identify Core Technology”The proposed architecture includes:
Customer Portal
Support SaaS
CRM
Application API
Vector Database
AI Model Provider
Cloud Object Storage
Analytics Platform
Logging PlatformCheckpoint
Section titled “Checkpoint”You should be able to explain:
What does the system do, who owns it, and which systems are involved?
Part 2 — Perform Privacy Screening
Section titled “Part 2 — Perform Privacy Screening”Create:
01 Privacy Screening QuestionnaireStep 2.1 — Answer Screening Questions
Section titled “Step 2.1 — Answer Screening Questions”Use:
| Question | Answer |
|---|---|
| Does project process personal data? | Yes |
| Sensitive data possible? | Yes |
| New processing purpose? | Yes |
| AI involved? | Yes |
| External vendor involved? | Yes |
| Profiling involved? | Possible |
| Automated decision-making? | Limited / Assess |
| Data transferred internationally? | Possible |
| Large-scale processing? | Yes |
| Customer monitoring? | Possible |
| Data retained by vendor? | To be confirmed |
| New technology? | Yes |
Step 2.2 — Determine Assessment Level
Section titled “Step 2.2 — Determine Assessment Level”Result:
Multiple High-Risk Indicators ↓Full PIA RequiredDepending on applicable law, the processing may also require:
DPIAorEquivalent EnhancedPrivacy AssessmentStep 2.3 — Record Screening Decision
Section titled “Step 2.3 — Record Screening Decision”Document:
PIA Required:YES
Reason:AI + Personal Data +Vendor Processing +Profiling +Large-Scale ProcessingPart 3 — Define PIA Scope
Section titled “Part 3 — Define PIA Scope”Create:
02 PIA Scope DocumentStep 3.1 — Define In-Scope Processing
Section titled “Step 3.1 — Define In-Scope Processing”Include:
Customer Conversations
Support Tickets
Account Information
Order Information
AI Prompt Processing
AI Output
Vector Search
Conversation History
Analytics
LoggingStep 3.2 — Define Systems in Scope
Section titled “Step 3.2 — Define Systems in Scope”Customer Portal
CRM
Support Platform
AI Gateway
Vector Database
AI Provider
Analytics
Cloud Storage
LoggingStep 3.3 — Define Data Subjects
Section titled “Step 3.3 — Define Data Subjects”Customers
Prospective Customers
Support AgentsPotentially:
Other IndividualsMentioned in SupportConversationsStep 3.4 — Define Assessment Boundaries
Section titled “Step 3.4 — Define Assessment Boundaries”The PIA will evaluate:
Collection
Use
Storage
Sharing
AI Processing
Vendor Processing
Retention
Deletion
Security
Data Subject Rights
Cross-Border TransfersPart 4 — Build the Personal Data Inventory
Section titled “Part 4 — Build the Personal Data Inventory”Create:
03 Personal Data InventoryStep 4.1 — Identify Data Elements
Section titled “Step 4.1 — Identify Data Elements”Start with:
Name
Email
Phone
Customer ID
Account Number
Order History
Support Tickets
Conversation Content
Device Information
IP Address
Location
Authentication InformationPotentially:
Payment Information
Health Information
Identity Documents
Sensitive Customer Messagesbecause customers may voluntarily include these in support conversations.
Step 4.2 — Classify Data
Section titled “Step 4.2 — Classify Data”Example:
| Data | Category | Classification |
|---|---|---|
| Name | Personal Data | Confidential |
| Personal Data | Confidential | |
| Customer ID | Personal Data | Confidential |
| Support Conversation | Personal Data | Confidential |
| Authentication Secret | Sensitive | Restricted |
| Payment Credential | Sensitive | Restricted |
Step 4.3 — Identify Data Sources
Section titled “Step 4.3 — Identify Data Sources”| Data | Source |
|---|---|
| Name | CRM |
| CRM | |
| Order history | Order DB |
| Support history | Support Platform |
| Conversation | Customer |
| Account information | Customer Portal |
Step 4.4 — Identify Processing Systems
Section titled “Step 4.4 — Identify Processing Systems”Extend:
| Data | Source | AI Used? | Stored? | Vendor? |
|---|---|---|---|---|
| Name | CRM | Yes | Yes | Yes |
| Order history | Order DB | Yes | Maybe | Yes |
| Ticket text | Support | Yes | Yes | Yes |
| Authentication data | Portal | Should not | No | No |
Key Finding
Section titled “Key Finding”Identify data that should not enter the AI system.
Example:
Passwords
Authentication Tokens
Full Payment Credentials
Private Security SecretsRecommended:
BLOCKorREDACTBefore AI ProcessingPart 5 — Build the Data Flow Map
Section titled “Part 5 — Build the Data Flow Map”Create:
04 Data Flow MapStep 5.1 — Map Main Flow
Section titled “Step 5.1 — Map Main Flow”Customer ↓Customer Portal ↓AI Gateway ↓Context Retrieval ↓CRM / Support /Order Database ↓Prompt Construction ↓AI Provider ↓Response ↓Customer / AgentStep 5.2 — Map Vector Flow
Section titled “Step 5.2 — Map Vector Flow”Support Documents ↓Chunking ↓Embedding Model ↓Vector Database ↓Retrieval ↓AI PromptStep 5.3 — Map Logging Flow
Section titled “Step 5.3 — Map Logging Flow”Customer Conversation ↓Application Log ↓Central Logging ↓Security / AnalyticsStep 5.4 — Map Vendor Flow
Section titled “Step 5.4 — Map Vendor Flow”CloudPay ↓AI Provider ↓Provider Infrastructure ↓Potential SubprocessorsStep 5.5 — Identify Countries
Section titled “Step 5.5 — Identify Countries”Capture:
Customer Location
Cloud Region
AI Provider Region
Support SaaS Region
Backup Region
Subprocessor LocationsPart 6 — Assess Purpose & Data Minimization
Section titled “Part 6 — Assess Purpose & Data Minimization”Create:
05 Purpose & Data Minimization AssessmentStep 6.1 — Document Primary Purposes
Section titled “Step 6.1 — Document Primary Purposes”| Data | Purpose |
|---|---|
| Customer ID | Retrieve correct account |
| Order history | Answer order queries |
| Support history | Provide context |
| Conversation | Generate response |
| Sentiment | Prioritize support |
Step 6.2 — Challenge Every Data Element
Section titled “Step 6.2 — Challenge Every Data Element”Ask:
Is this data necessary for the stated purpose?
Example:
Purpose:Answer Shipping QuestionRequired:
Order Number
Delivery StatusPotentially unnecessary:
Full Payment History
Date of Birth
Full ProfileStep 6.3 — Build Minimization Matrix
Section titled “Step 6.3 — Build Minimization Matrix”| Data | Purpose | Necessary? | Recommendation |
|---|---|---|---|
| Order number | Support | Yes | Allow |
| Delivery status | Support | Yes | Allow |
| Password | None | No | Block |
| Full card number | None | No | Block |
| Customer address | Some cases | Conditional | Limit |
| Full support history | Context | Maybe | Retrieve only relevant records |
Part 7 — Assess Transparency & Notice
Section titled “Part 7 — Assess Transparency & Notice”Review existing privacy notices.
Ask:
Do Customers KnowTheir Data Will BeProcessed by AI?Step 7.1 — Compare Existing Notice
Section titled “Step 7.1 — Compare Existing Notice”Existing notice states:
Customer DataUsed forCustomer SupportBut proposed processing includes:
AI Processing
Sentiment Analysis
Third-Party Model Provider
Automated SummarizationPotential:
Transparency GapStep 7.2 — Required Action
Section titled “Step 7.2 — Required Action”Update applicable notice to clearly explain, where required:
AI Processing
Purpose
Data Categories
Third-Party Processing
Retention
RightsPart 8 — Assess Processing Basis
Section titled “Part 8 — Assess Processing Basis”Create:
06 Privacy Requirements MatrixFor each relevant jurisdiction determine:
Applicable Privacy Framework
Processing Requirement
Consent Requirement
Notice Requirement
Rights
Transfer Requirement
Retention RequirementDo not automatically use:
Consentfor every processing activity.
Document the actual legal or organizational basis applicable to each purpose.
Part 9 — Assess Data Subject Rights
Section titled “Part 9 — Assess Data Subject Rights”Ask whether the system can support:
Access
Correction
Deletion
Restriction
Objection
Consent Withdrawalwhere applicable.
Step 9.1 — Access
Section titled “Step 9.1 — Access”Can CloudPay find:
Customer Conversations?
AI Interaction History?
Stored Prompt Data?
Vector Metadata?Step 9.2 — Deletion
Section titled “Step 9.2 — Deletion”Can CloudPay delete:
Conversation History
AI Logs
Uploaded Files
Vector Embeddings
Provider Copies?Step 9.3 — Correction
Section titled “Step 9.3 — Correction”If:
Customer ProfileIs Incorrectwill corrected information propagate to:
CRM
Support
AI RetrievalStep 9.4 — Finding
Section titled “Step 9.4 — Finding”If the AI provider cannot support deletion of customer prompt history:
Privacy RightsCapability GapPart 10 — Assess Retention
Section titled “Part 10 — Assess Retention”Document all retention periods.
Create:
| Data | System | Proposed Retention |
|---|---|---|
| Customer conversation | Support | Existing schedule |
| AI prompt | AI gateway | 30 days |
| AI provider log | Vendor | 90 days |
| Vector data | Vector DB | Account lifecycle |
| Analytics | Analytics platform | 12 months |
These are scenario values for this lab, not universal requirements.
Step 10.1 — Challenge Provider Retention
Section titled “Step 10.1 — Challenge Provider Retention”Business wants:
AI Provider90-Day Prompt RetentionAsk:
Why?If only needed for troubleshooting:
90 DaysMay Be ExcessivePotential recommendation:
Disable Provider RetentionorReduce to MinimumSupported PeriodPart 11 — Assess Third-Party Risk
Section titled “Part 11 — Assess Third-Party Risk”The AI provider receives personal information.
Evaluate:
Processor Role
Contract
Security
Retention
Training Use
Subprocessors
Locations
Incident Notification
Deletion
Audit EvidenceStep 11.1 — Vendor Questions
Section titled “Step 11.1 — Vendor Questions”Ask:
Is Customer DataUsed for ProviderModel Training?
Can TrainingBe Disabled?
How Long ArePrompts Retained?
Which SubprocessorsReceive Data?
Where Is DataProcessed?
How Is DataDeleted?Step 11.2 — Vendor Finding Example
Section titled “Step 11.2 — Vendor Finding Example”Provider terms permit:
Customer Contentto Improve Serviceswithout an enterprise opt-out.
Risk:
Secondary Useof Personal DataRecommended:
Do Not ApproveUntil Enterprise TermsProhibit Model TrainingUsing CloudPay DataPart 12 — Assess Cross-Border Processing
Section titled “Part 12 — Assess Cross-Border Processing”Suppose:
CloudPay Customer:EU
CloudPay Application:India
AI Provider:USAMap:
EU ↓India ↓USAEvaluate applicable transfer requirements.
Create:
Cross-Border Transfer AssessmentCapture:
| Transfer | Data | Destination | Requirement | Safeguard |
|---|
Part 13 — Assess Security Controls
Section titled “Part 13 — Assess Security Controls”Create:
07 Privacy Risk RegisterBut first identify security controls supporting privacy.
Review:
IAM
MFA
Encryption
Network Security
Logging
Monitoring
Secrets Management
DLP
Incident ResponseStep 13.1 — Access
Section titled “Step 13.1 — Access”AI support data should be accessible only to:
Authorized Support Staff
Approved Administrators
Required Technical ServicesStep 13.2 — Encryption
Section titled “Step 13.2 — Encryption”Require:
TLS in Transit
Encryption at Rest
Encrypted BackupsStep 13.3 — Prompt Filtering
Section titled “Step 13.3 — Prompt Filtering”Introduce:
Input DLP / Redactionto detect:
Payment Credentials
Passwords
Tokens
Sensitive Identifiersbefore AI processing.
Step 13.4 — Output Filtering
Section titled “Step 13.4 — Output Filtering”Assess:
Could the AIExpose AnotherCustomer's Data?Implement:
Tenant Isolation
Authorization
Retrieval Filtering
Output ValidationPart 14 — Identify Privacy Risks
Section titled “Part 14 — Identify Privacy Risks”Now populate the:
07 Privacy Risk RegisterUse:
| Risk | Likelihood | Impact | Inherent Risk |
|---|---|---|---|
| Excessive data sent to AI | 4 | 4 | 16 |
| Sensitive data in prompts | 4 | 5 | 20 |
| Provider uses data for training | 3 | 5 | 15 |
| Cross-customer disclosure | 3 | 5 | 15 |
| Excessive provider retention | 4 | 4 | 16 |
| DSR deletion incomplete | 3 | 4 | 12 |
| Cross-border compliance gap | 3 | 5 | 15 |
| Inaccurate AI output | 4 | 3 | 12 |
| Shadow logging of PI | 4 | 4 | 16 |
| Excessive support-agent access | 3 | 4 | 12 |
Part 15 — Assess Existing Controls
Section titled “Part 15 — Assess Existing Controls”Create:
08 Privacy Control AssessmentUse:
| Risk | Existing Control | Design | Operating | Gap |
|---|---|---|---|---|
| Sensitive prompts | Basic validation | Weak | Partial | Yes |
| Cross-customer disclosure | Account auth | Medium | Unknown | Yes |
| Provider training | Contract | Weak | N/A | Yes |
| Retention | Vendor default | Weak | Yes | Yes |
| Excess access | RBAC | Strong | Unknown | Test |
Part 16 — Determine Control Design Effectiveness
Section titled “Part 16 — Determine Control Design Effectiveness”For each control ask:
If this control works exactly as designed, will it sufficiently reduce the privacy risk?
Example:
Risk:Sensitive DataEntered in PromptExisting control:
Employee TrainingAssessment:
Weak Designbecause training alone does not prevent technical submission.
Better:
Training+Input Filtering+DLP+Blocked Data TypesPart 17 — Build the Remediation Plan
Section titled “Part 17 — Build the Remediation Plan”Create:
09 Privacy Remediation PlanUse:
| ID | Risk | Action | Owner | Due | Priority |
|---|---|---|---|---|---|
| PA-01 | Sensitive prompts | Implement DLP/redaction | Engineering | Pre-launch | Critical |
| PA-02 | Provider training | Negotiate no-training terms | Legal | Pre-launch | Critical |
| PA-03 | Retention | Disable/reduce provider logs | Engineering | Pre-launch | High |
| PA-04 | Rights | Implement AI deletion workflow | Product | Pre-launch | High |
| PA-05 | Notice | Update privacy notice | Privacy | Pre-launch | High |
| PA-06 | Tenant exposure | Test authorization isolation | Security | Pre-launch | Critical |
| PA-07 | Transfers | Complete transfer assessment | Privacy/Legal | Pre-launch | High |
Part 18 — Define Mandatory Pre-Launch Controls
Section titled “Part 18 — Define Mandatory Pre-Launch Controls”Classify actions as:
Must Fix Before Launch
Can Fix After Launch
MonitorFor this scenario, mark as Must Fix Before Launch:
Provider No-Training Terms
Sensitive Prompt Filtering
Tenant Isolation Testing
Appropriate Transfer Controls
Privacy Notice Update
Defined Retention
DSR Deletion CapabilityPart 19 — Calculate Residual Risk
Section titled “Part 19 — Calculate Residual Risk”Create:
10 Residual Risk AssessmentAfter remediation, reassess.
Example:
| Risk | Inherent | Control | Residual |
|---|---|---|---|
| Sensitive prompts | 20 | DLP + filtering | 8 |
| Provider training | 15 | Contract prohibition | 5 |
| Tenant disclosure | 15 | Authorization + testing | 5 |
| Excess retention | 16 | Reduced retention | 6 |
| DSR deletion | 12 | Deletion workflow | 6 |
Use the organization’s actual scoring methodology in production.
Part 20 — Identify Residual High Risk
Section titled “Part 20 — Identify Residual High Risk”Suppose one issue remains:
Provider BackupDeletionCannot Be ImmediateResidual risk:
MediumDocument:
Technical Limitation
Backup Expiration
Restricted Restore Process
Contractual Control
MonitoringPart 21 — Determine PIA Outcome
Section titled “Part 21 — Determine PIA Outcome”Possible decisions:
APPROVED
APPROVED WITH CONDITIONS
REMEDIATION REQUIRED
ESCALATED
REJECTEDFor this lab:
APPROVEDWITH CONDITIONSprovided all critical pre-launch actions are completed.
Part 22 — Build the Approval Record
Section titled “Part 22 — Build the Approval Record”Create:
11 PIA Approval RecordUse:
| Field | Decision |
|---|---|
| Overall Risk | High before controls |
| Residual Risk | Medium |
| Decision | Approved with conditions |
| Business Owner | Support |
| Privacy Approval | Required |
| Security Approval | Required |
| Legal Review | Required |
| Reassessment | 6 months / material change |
Approval Conditions
Section titled “Approval Conditions”1. AI provider must not train on CloudPay customer data.
2. Sensitive-data filtering must be enabled.
3. Cross-customer data isolation must be validated.
4. Provider retention must be reduced.
5. Privacy notice must be updated.
6. DSR deletion workflow must include AI data.
7. Cross-border transfer controls must be completed.Part 23 — Build the Final PIA Report
Section titled “Part 23 — Build the Final PIA Report”Create:
12 Final Privacy Impact Assessment ReportUse this structure:
Executive Summary
Section titled “Executive Summary”Example:
CloudPay proposes deploying an AI-powered customer-support platform that will process customer identity, account, order, and support information. The assessment identified material privacy risks involving excessive data exposure to the AI model, potential secondary use by the AI provider, prompt retention, cross-border processing, data subject rights, and cross-customer information disclosure. The project may proceed only after mandatory privacy and security controls are implemented and validated.
Project Description
Section titled “Project Description”Document:
Purpose
Business Owner
Architecture
Users
Vendors
Launch DatePersonal Data
Section titled “Personal Data”Summarize:
Data Subjects
Personal Data
Sensitive Data
Sources
Systems
ClassificationData Flow
Section titled “Data Flow”Include:
Internal Flows
Cloud Flows
Vendor Flows
AI Flows
Cross-Border FlowsPurpose & Necessity
Section titled “Purpose & Necessity”Explain:
Why Each MajorData CategoryIs Neededand identify unnecessary data removed from scope.
Privacy Requirements
Section titled “Privacy Requirements”Document:
Transparency
Processing Basis
Rights
Retention
Transfers
Vendor Obligations
SecurityRisk Assessment
Section titled “Risk Assessment”Summarize:
Inherent Risk
Existing Controls
Control Gaps
Residual RiskRemediation
Section titled “Remediation”Include:
Action
Owner
Priority
Deadline
EvidenceFinal Decision
Section titled “Final Decision”APPROVEDWITH CONDITIONSReassessment Triggers
Section titled “Reassessment Triggers”Define:
New AI Model
New Vendor
New Subprocessor
New Data Category
New Processing Purpose
New Country
Automated Decision-Making
Major Security Incident
Material Architecture ChangePart 24 — Build Evidence Package
Section titled “Part 24 — Build Evidence Package”Create an evidence folder:
PIA-Evidence/│├── Screening/├── Architecture/├── Data-Inventory/├── Data-Flow/├── Vendor-Documents/├── Contracts/├── Security-Controls/├── Retention/├── Rights-Assessment/├── Risk/├── Remediation/└── Approval/Part 25 — Validate Remediation
Section titled “Part 25 — Validate Remediation”Before launch, do not accept:
"Engineering SaysIt Is Fixed"Test it.
Test 1 — Sensitive Prompt
Section titled “Test 1 — Sensitive Prompt”Enter controlled test data resembling:
Payment Credential
Password
Security TokenExpected:
Blocked / RedactedBefore AI ProviderTest 2 — Tenant Isolation
Section titled “Test 2 — Tenant Isolation”User A asks:
Show My OrdersVerify the AI can retrieve:
User A Ordersbut cannot retrieve:
User B OrdersTest 3 — Deletion
Section titled “Test 3 — Deletion”Create test customer:
Customer-Test-001Generate:
Conversation
Prompt
Vector Record
Support TicketRun deletion workflow.
Verify applicable removal from:
Application
Conversation Store
Vector DB
Analytics
VendorTest 4 — Retention
Section titled “Test 4 — Retention”Check:
AI Provider Configurationmatches the approved retention requirement.
Test 5 — Training Usage
Section titled “Test 5 — Training Usage”Verify contractual and technical settings confirm:
CloudPay Customer DataNot Usedto Train Provider ModelsPIA Mission Checklist
Section titled “PIA Mission Checklist”Screening
Section titled “Screening”-
privacy screening completed.
-
high-risk indicators identified.
-
full PIA decision documented.
-
processing defined.
-
systems identified.
-
data subjects identified.
-
vendors identified.
-
boundaries documented.
Data Inventory
Section titled “Data Inventory”-
personal data identified.
-
sensitive data identified.
-
data sources mapped.
-
classifications assigned.
-
prohibited AI data identified.
Data Flow
Section titled “Data Flow”-
internal flow mapped.
-
AI flow mapped.
-
vendor flow mapped.
-
vector flow mapped.
-
logging flow mapped.
-
countries identified.
Minimization
Section titled “Minimization”-
each data element challenged.
-
unnecessary data removed.
-
contextual retrieval limited.
-
sensitive data filtered.
Transparency
Section titled “Transparency”-
existing notice reviewed.
-
AI processing addressed.
-
third-party processing addressed.
-
required updates identified.
Rights
Section titled “Rights”-
access capability assessed.
-
correction assessed.
-
deletion assessed.
-
vector data considered.
-
provider data considered.
Retention
Section titled “Retention”-
application retention defined.
-
AI provider retention reviewed.
-
vector retention defined.
-
logs reviewed.
-
deletion workflow documented.
Vendors
Section titled “Vendors”-
AI provider assessed.
-
processor role reviewed.
-
contract reviewed.
-
model training use assessed.
-
subprocessors assessed.
-
data locations assessed.
Cross-Border
Section titled “Cross-Border”-
data-transfer paths mapped.
-
applicable requirements identified.
-
safeguards documented.
Security
Section titled “Security”-
IAM reviewed.
-
encryption reviewed.
-
DLP assessed.
-
prompt filtering assessed.
-
output controls assessed.
-
tenant isolation assessed.
-
logging reviewed.
-
inherent risks scored.
-
existing controls assessed.
-
control gaps identified.
-
remediation defined.
-
residual risks scored.
Approval
Section titled “Approval”-
mandatory pre-launch actions identified.
-
residual risk reviewed.
-
approval decision documented.
-
conditions assigned.
-
reassessment triggers defined.
Evidence
Section titled “Evidence”-
screening retained.
-
diagrams retained.
-
inventory retained.
-
vendor evidence retained.
-
security evidence retained.
-
risk assessment retained.
-
remediation evidence retained.
-
approval retained.
Final Lab Findings
Section titled “Final Lab Findings”Your completed assessment should identify at least the following potential issues:
| ID | Finding | Severity |
|---|---|---|
| PIA-01 | Sensitive information may enter AI prompts | Critical |
| PIA-02 | Provider model-training terms unclear | Critical |
| PIA-03 | AI provider retention excessive | High |
| PIA-04 | Privacy notice does not clearly address AI | High |
| PIA-05 | AI deletion workflow incomplete | High |
| PIA-06 | Cross-border transfer assessment incomplete | High |
| PIA-07 | Tenant isolation requires validation | Critical |
| PIA-08 | AI and application logs may retain unnecessary PI | Medium/High |
Mission Success Criteria
Section titled “Mission Success Criteria”You have successfully completed the lab when you can answer:
Does This ProjectProcess Personal Data?
↓
What Data?
↓
Why Is It Needed?
↓
Can We Reduce It?
↓
Where Does It Go?
↓
Does It Reachan AI Provider?
↓
Does the ProviderRetain It?
↓
Is It Usedfor Training?
↓
Which CountriesProcess It?
↓
Can CustomersExercise Their Rights?
↓
Can DataBe Deleted?
↓
Could One CustomerSee Another's Data?
↓
Which Risks Exist?
↓
Which ControlsReduce Them?
↓
What Is theResidual Risk?
↓
Can the ProjectBe Approved?
↓
What Must Be FixedBefore Launch?
↓
Can We ProveThose Fixes Work?Skills You Practiced
Section titled “Skills You Practiced”By completing this lab, you practiced:
-
Privacy screening
-
PIA scoping
-
Personal-data inventory
-
Data-flow mapping
-
Data minimization
-
Purpose limitation
-
Privacy-notice assessment
-
Data subject rights analysis
-
Data-retention assessment
-
Vendor privacy due diligence
-
AI privacy assessment
-
Cross-border transfer analysis
-
Privacy security-control assessment
-
Privacy risk scoring
-
Residual-risk assessment
-
Corrective-action planning
-
Approval governance
-
Remediation validation
-
Privacy evidence management
-
Privacy-by-design thinking
These are practical skills used by:
Privacy Analysts
GRC Analysts
Privacy Engineers
Data Protection Officers
Privacy Consultants
Security GRC Professionals
AI Governance ProfessionalsKnowledge Check
Section titled “Knowledge Check”Before completing the lab, make sure you can answer:
-
Why did the CloudPay AI project require a full PIA?
-
What should be included in PIA scope?
-
Why should personal data be classified?
-
Why must sensitive data be prevented from entering AI prompts?
-
Why is data-flow mapping critical?
-
What is the purpose of a minimization assessment?
-
Why might full support history be unnecessary for every AI interaction?
-
Why should the privacy notice be reassessed?
-
Why is consent not automatically the correct basis for AI processing?
-
How should privacy rights be assessed for AI systems?
-
Why are vector databases relevant to deletion?
-
Why should provider prompt retention be challenged?
-
Why must model-training terms be reviewed?
-
How can subprocessors affect privacy risk?
-
Why must cross-border flows be documented?
-
How can DLP reduce AI privacy risk?
-
What is inherent privacy risk?
-
What is residual privacy risk?
-
What is the difference between an existing control and a remediation action?
-
Why should some controls be mandatory before production?
-
What does Approved With Conditions mean?
-
Why should remediation be technically validated?
-
What should trigger PIA reassessment?
-
What evidence should be retained?
-
How does this lab demonstrate Privacy by Design?
Lab Complete
Section titled “Lab Complete”You have completed:
Lab 02 — Perform a Privacy Impact Assessment (PIA)
Section titled “Lab 02 — Perform a Privacy Impact Assessment (PIA)”You started with:
New AI Projectand transformed it into:
Privacy Screening ↓PIA Scope ↓Data Inventory ↓Data Flow ↓Purpose & Minimization ↓Privacy Requirements ↓Rights Assessment ↓Retention ↓Vendor Assessment ↓AI Privacy Review ↓Cross-Border Assessment ↓Risk Register ↓Control Assessment ↓Remediation ↓Residual Risk ↓Formal Approval ↓Validated EvidenceThat is how a Privacy or GRC professional turns:
"Can We Launch This?"into a defensible:
Privacy Risk DecisionWhat’s Next?
Section titled “What’s Next?”➡️ Next: Runbook 01 — Privacy Impact Assessment & Data Subject Request Operations
In the next section, you will move from performing individual privacy labs to operating a repeatable enterprise privacy workflow for:
New Project ↓Privacy Screening ↓PIA / DPIA ↓Privacy Approvaland:
Data Subject Request ↓Identity Verification ↓Data Discovery ↓Rights Fulfilment ↓Secure Response ↓EvidenceThe runbook will provide the operational steps a Privacy Analyst or GRC Analyst can follow repeatedly in a real enterprise environment.