Skip to content

Lab 02 — Perform a Privacy Impact Assessment (PIA)

Field Details
Lab Type Privacy / GRC
Difficulty Intermediate
Estimated Time 90–120 Minutes
Primary Role Privacy Analyst / GRC Analyst
Environment Simulated Enterprise Project
Primary Deliverable Completed Privacy Impact Assessment
Supporting Deliverables Screening, Data Inventory, Data Flow, Risk Register, Control Assessment, Remediation Plan & Approval Record

You are working as a:

Privacy & GRC Analyst

at:

CloudPay Technologies

CloudPay is planning to launch a new:

AI-Powered Customer Support Platform

The business wants the platform to:

Answer Customer Questions
Summarize Support Tickets
Recommend Responses
Identify Customer Sentiment
Retrieve Account Information
Escalate Complex Cases

The proposed solution will integrate with:

Customer Portal
CRM
Support Platform
Order Database
AI Model Provider
Analytics Platform
Cloud Storage

The project team wants to launch within:

8 Weeks

The Privacy team has been asked:

Can this project proceed, and what privacy controls must be implemented before production?

You must perform a complete:

Your objective is to evaluate:

What Personal Data Is Processed?
Why Is It Needed?
Where Does It Go?
Who Can Access It?
Which Vendors Receive It?
Where Is It Stored?
How Long Is It Retained?
Does AI Introduce Additional Risk?
Can Individuals Exercise Their Rights?
What Could Go Wrong?
Which Controls Exist?
What Is the Residual Risk?
Can the Project Be Approved?

Create:

01 Privacy Screening Questionnaire
02 PIA Scope Document
03 Personal Data Inventory
04 Data Flow Map
05 Purpose & Data Minimization Assessment
06 Privacy Requirements Matrix
07 Privacy Risk Register
08 Privacy Control Assessment
09 Privacy Remediation Plan
10 Residual Risk Assessment
11 PIA Approval Record
12 Final Privacy Impact Assessment Report

Create:

Lab-02-Privacy-Impact-Assessment/
├── 01-Screening/
├── 02-Scope/
├── 03-Data-Inventory/
├── 04-Data-Flow/
├── 05-Minimization/
├── 06-Requirements/
├── 07-Risk/
├── 08-Controls/
├── 09-Remediation/
├── 10-Residual-Risk/
├── 11-Approval/
└── 12-Final-Report/

Part 1 — Understand the Proposed Project

Section titled “Part 1 — Understand the Proposed Project”

Before assessing risk, understand what the business wants to build.

Step 1.1 — Review the Business Objective

Section titled “Step 1.1 — Review the Business Objective”

The AI support platform will:

Customer Question
AI Assistant
Retrieve Relevant
Account / Support Data
Generate Response
Human Support Agent
or
Customer

Business benefits include:

Faster Support
Reduced Agent Workload
24×7 Assistance
Improved Response Consistency
Automated Ticket Summaries

Step 1.2 — Identify Project Stakeholders

Section titled “Step 1.2 — Identify Project Stakeholders”

Document:

Business Owner
→ Head of Customer Support
Product Owner
→ AI Product Manager
Technical Owner
→ Engineering
Privacy
→ Privacy Team
Security
→ Cybersecurity
Legal
→ Legal Counsel
Vendor Management
→ Procurement
AI Governance
→ AI Governance Team

The proposed architecture includes:

Customer Portal
Support SaaS
CRM
Application API
Vector Database
AI Model Provider
Cloud Object Storage
Analytics Platform
Logging Platform

You should be able to explain:

What does the system do, who owns it, and which systems are involved?

Create:

01 Privacy Screening Questionnaire

Use:

Question Answer
Does project process personal data? Yes
Sensitive data possible? Yes
New processing purpose? Yes
AI involved? Yes
External vendor involved? Yes
Profiling involved? Possible
Automated decision-making? Limited / Assess
Data transferred internationally? Possible
Large-scale processing? Yes
Customer monitoring? Possible
Data retained by vendor? To be confirmed
New technology? Yes

Result:

Multiple High-Risk Indicators
Full PIA Required

Depending on applicable law, the processing may also require:

DPIA
or
Equivalent Enhanced
Privacy Assessment

Document:

PIA Required:
YES
Reason:
AI + Personal Data +
Vendor Processing +
Profiling +
Large-Scale Processing

Create:

02 PIA Scope Document

Include:

Customer Conversations
Support Tickets
Account Information
Order Information
AI Prompt Processing
AI Output
Vector Search
Conversation History
Analytics
Logging
Customer Portal
CRM
Support Platform
AI Gateway
Vector Database
AI Provider
Analytics
Cloud Storage
Logging
Customers
Prospective Customers
Support Agents

Potentially:

Other Individuals
Mentioned in Support
Conversations

The PIA will evaluate:

Collection
Use
Storage
Sharing
AI Processing
Vendor Processing
Retention
Deletion
Security
Data Subject Rights
Cross-Border Transfers

Part 4 — Build the Personal Data Inventory

Section titled “Part 4 — Build the Personal Data Inventory”

Create:

03 Personal Data Inventory

Start with:

Name
Email
Phone
Customer ID
Account Number
Order History
Support Tickets
Conversation Content
Device Information
IP Address
Location
Authentication Information

Potentially:

Payment Information
Health Information
Identity Documents
Sensitive Customer Messages

because customers may voluntarily include these in support conversations.

Example:

Data Category Classification
Name Personal Data Confidential
Email Personal Data Confidential
Customer ID Personal Data Confidential
Support Conversation Personal Data Confidential
Authentication Secret Sensitive Restricted
Payment Credential Sensitive Restricted
Data Source
Name CRM
Email CRM
Order history Order DB
Support history Support Platform
Conversation Customer
Account information Customer Portal

Extend:

Data Source AI Used? Stored? Vendor?
Name CRM Yes Yes Yes
Order history Order DB Yes Maybe Yes
Ticket text Support Yes Yes Yes
Authentication data Portal Should not No No

Identify data that should not enter the AI system.

Example:

Passwords
Authentication Tokens
Full Payment Credentials
Private Security Secrets

Recommended:

BLOCK
or
REDACT
Before AI Processing

Create:

04 Data Flow Map
Customer
Customer Portal
AI Gateway
Context Retrieval
CRM / Support /
Order Database
Prompt Construction
AI Provider
Response
Customer / Agent
Support Documents
Chunking
Embedding Model
Vector Database
Retrieval
AI Prompt
Customer Conversation
Application Log
Central Logging
Security / Analytics
CloudPay
AI Provider
Provider Infrastructure
Potential Subprocessors

Capture:

Customer Location
Cloud Region
AI Provider Region
Support SaaS Region
Backup Region
Subprocessor Locations

Part 6 — Assess Purpose & Data Minimization

Section titled “Part 6 — Assess Purpose & Data Minimization”

Create:

05 Purpose & Data Minimization Assessment
Data Purpose
Customer ID Retrieve correct account
Order history Answer order queries
Support history Provide context
Conversation Generate response
Sentiment Prioritize support

Ask:

Is this data necessary for the stated purpose?

Example:

Purpose:
Answer Shipping Question

Required:

Order Number
Delivery Status

Potentially unnecessary:

Full Payment History
Date of Birth
Full Profile
Data Purpose Necessary? Recommendation
Order number Support Yes Allow
Delivery status Support Yes Allow
Password None No Block
Full card number None No Block
Customer address Some cases Conditional Limit
Full support history Context Maybe Retrieve only relevant records

Review existing privacy notices.

Ask:

Do Customers Know
Their Data Will Be
Processed by AI?

Existing notice states:

Customer Data
Used for
Customer Support

But proposed processing includes:

AI Processing
Sentiment Analysis
Third-Party Model Provider
Automated Summarization

Potential:

Transparency Gap

Update applicable notice to clearly explain, where required:

AI Processing
Purpose
Data Categories
Third-Party Processing
Retention
Rights

Create:

06 Privacy Requirements Matrix

For each relevant jurisdiction determine:

Applicable Privacy Framework
Processing Requirement
Consent Requirement
Notice Requirement
Rights
Transfer Requirement
Retention Requirement

Do not automatically use:

Consent

for every processing activity.

Document the actual legal or organizational basis applicable to each purpose.

Ask whether the system can support:

Access
Correction
Deletion
Restriction
Objection
Consent Withdrawal

where applicable.

Can CloudPay find:

Customer Conversations?
AI Interaction History?
Stored Prompt Data?
Vector Metadata?

Can CloudPay delete:

Conversation History
AI Logs
Uploaded Files
Vector Embeddings
Provider Copies?

If:

Customer Profile
Is Incorrect

will corrected information propagate to:

CRM
Support
AI Retrieval

If the AI provider cannot support deletion of customer prompt history:

Privacy Rights
Capability Gap

Document all retention periods.

Create:

Data System Proposed Retention
Customer conversation Support Existing schedule
AI prompt AI gateway 30 days
AI provider log Vendor 90 days
Vector data Vector DB Account lifecycle
Analytics Analytics platform 12 months

These are scenario values for this lab, not universal requirements.

Step 10.1 — Challenge Provider Retention

Section titled “Step 10.1 — Challenge Provider Retention”

Business wants:

AI Provider
90-Day Prompt Retention

Ask:

Why?

If only needed for troubleshooting:

90 Days
May Be Excessive

Potential recommendation:

Disable Provider Retention
or
Reduce to Minimum
Supported Period

The AI provider receives personal information.

Evaluate:

Processor Role
Contract
Security
Retention
Training Use
Subprocessors
Locations
Incident Notification
Deletion
Audit Evidence

Ask:

Is Customer Data
Used for Provider
Model Training?
Can Training
Be Disabled?
How Long Are
Prompts Retained?
Which Subprocessors
Receive Data?
Where Is Data
Processed?
How Is Data
Deleted?

Provider terms permit:

Customer Content
to Improve Services

without an enterprise opt-out.

Risk:

Secondary Use
of Personal Data

Recommended:

Do Not Approve
Until Enterprise Terms
Prohibit Model Training
Using CloudPay Data

Part 12 — Assess Cross-Border Processing

Section titled “Part 12 — Assess Cross-Border Processing”

Suppose:

CloudPay Customer:
EU
CloudPay Application:
India
AI Provider:
USA

Map:

EU
India
USA

Evaluate applicable transfer requirements.

Create:

Cross-Border Transfer Assessment

Capture:

Transfer Data Destination Requirement Safeguard

Create:

07 Privacy Risk Register

But first identify security controls supporting privacy.

Review:

IAM
MFA
Encryption
Network Security
Logging
Monitoring
Secrets Management
DLP
Incident Response

AI support data should be accessible only to:

Authorized Support Staff
Approved Administrators
Required Technical Services

Require:

TLS in Transit
Encryption at Rest
Encrypted Backups

Introduce:

Input DLP / Redaction

to detect:

Payment Credentials
Passwords
Tokens
Sensitive Identifiers

before AI processing.

Assess:

Could the AI
Expose Another
Customer's Data?

Implement:

Tenant Isolation
Authorization
Retrieval Filtering
Output Validation

Now populate the:

07 Privacy Risk Register

Use:

Risk Likelihood Impact Inherent Risk
Excessive data sent to AI 4 4 16
Sensitive data in prompts 4 5 20
Provider uses data for training 3 5 15
Cross-customer disclosure 3 5 15
Excessive provider retention 4 4 16
DSR deletion incomplete 3 4 12
Cross-border compliance gap 3 5 15
Inaccurate AI output 4 3 12
Shadow logging of PI 4 4 16
Excessive support-agent access 3 4 12

Create:

08 Privacy Control Assessment

Use:

Risk Existing Control Design Operating Gap
Sensitive prompts Basic validation Weak Partial Yes
Cross-customer disclosure Account auth Medium Unknown Yes
Provider training Contract Weak N/A Yes
Retention Vendor default Weak Yes Yes
Excess access RBAC Strong Unknown Test

Part 16 — Determine Control Design Effectiveness

Section titled “Part 16 — Determine Control Design Effectiveness”

For each control ask:

If this control works exactly as designed, will it sufficiently reduce the privacy risk?

Example:

Risk:
Sensitive Data
Entered in Prompt

Existing control:

Employee Training

Assessment:

Weak Design

because training alone does not prevent technical submission.

Better:

Training
+
Input Filtering
+
DLP
+
Blocked Data Types

Create:

09 Privacy Remediation Plan

Use:

ID Risk Action Owner Due Priority
PA-01 Sensitive prompts Implement DLP/redaction Engineering Pre-launch Critical
PA-02 Provider training Negotiate no-training terms Legal Pre-launch Critical
PA-03 Retention Disable/reduce provider logs Engineering Pre-launch High
PA-04 Rights Implement AI deletion workflow Product Pre-launch High
PA-05 Notice Update privacy notice Privacy Pre-launch High
PA-06 Tenant exposure Test authorization isolation Security Pre-launch Critical
PA-07 Transfers Complete transfer assessment Privacy/Legal Pre-launch High

Part 18 — Define Mandatory Pre-Launch Controls

Section titled “Part 18 — Define Mandatory Pre-Launch Controls”

Classify actions as:

Must Fix Before Launch
Can Fix After Launch
Monitor

For this scenario, mark as Must Fix Before Launch:

Provider No-Training Terms
Sensitive Prompt Filtering
Tenant Isolation Testing
Appropriate Transfer Controls
Privacy Notice Update
Defined Retention
DSR Deletion Capability

Create:

10 Residual Risk Assessment

After remediation, reassess.

Example:

Risk Inherent Control Residual
Sensitive prompts 20 DLP + filtering 8
Provider training 15 Contract prohibition 5
Tenant disclosure 15 Authorization + testing 5
Excess retention 16 Reduced retention 6
DSR deletion 12 Deletion workflow 6

Use the organization’s actual scoring methodology in production.

Suppose one issue remains:

Provider Backup
Deletion
Cannot Be Immediate

Residual risk:

Medium

Document:

Technical Limitation
Backup Expiration
Restricted Restore Process
Contractual Control
Monitoring

Possible decisions:

APPROVED
APPROVED WITH CONDITIONS
REMEDIATION REQUIRED
ESCALATED
REJECTED

For this lab:

APPROVED
WITH CONDITIONS

provided all critical pre-launch actions are completed.

Create:

11 PIA Approval Record

Use:

Field Decision
Overall Risk High before controls
Residual Risk Medium
Decision Approved with conditions
Business Owner Support
Privacy Approval Required
Security Approval Required
Legal Review Required
Reassessment 6 months / material change
1. AI provider must not train on CloudPay customer data.
2. Sensitive-data filtering must be enabled.
3. Cross-customer data isolation must be validated.
4. Provider retention must be reduced.
5. Privacy notice must be updated.
6. DSR deletion workflow must include AI data.
7. Cross-border transfer controls must be completed.

Create:

12 Final Privacy Impact Assessment Report

Use this structure:

Example:

CloudPay proposes deploying an AI-powered customer-support platform that will process customer identity, account, order, and support information. The assessment identified material privacy risks involving excessive data exposure to the AI model, potential secondary use by the AI provider, prompt retention, cross-border processing, data subject rights, and cross-customer information disclosure. The project may proceed only after mandatory privacy and security controls are implemented and validated.

Document:

Purpose
Business Owner
Architecture
Users
Vendors
Launch Date

Summarize:

Data Subjects
Personal Data
Sensitive Data
Sources
Systems
Classification

Include:

Internal Flows
Cloud Flows
Vendor Flows
AI Flows
Cross-Border Flows

Explain:

Why Each Major
Data Category
Is Needed

and identify unnecessary data removed from scope.

Document:

Transparency
Processing Basis
Rights
Retention
Transfers
Vendor Obligations
Security

Summarize:

Inherent Risk
Existing Controls
Control Gaps
Residual Risk

Include:

Action
Owner
Priority
Deadline
Evidence
APPROVED
WITH CONDITIONS

Define:

New AI Model
New Vendor
New Subprocessor
New Data Category
New Processing Purpose
New Country
Automated Decision-Making
Major Security Incident
Material Architecture Change

Create an evidence folder:

PIA-Evidence/
├── Screening/
├── Architecture/
├── Data-Inventory/
├── Data-Flow/
├── Vendor-Documents/
├── Contracts/
├── Security-Controls/
├── Retention/
├── Rights-Assessment/
├── Risk/
├── Remediation/
└── Approval/

Before launch, do not accept:

"Engineering Says
It Is Fixed"

Test it.

Enter controlled test data resembling:

Payment Credential
Password
Security Token

Expected:

Blocked / Redacted
Before AI Provider

User A asks:

Show My Orders

Verify the AI can retrieve:

User A Orders

but cannot retrieve:

User B Orders

Create test customer:

Customer-Test-001

Generate:

Conversation
Prompt
Vector Record
Support Ticket

Run deletion workflow.

Verify applicable removal from:

Application
Conversation Store
Vector DB
Analytics
Vendor

Check:

AI Provider Configuration

matches the approved retention requirement.

Verify contractual and technical settings confirm:

CloudPay Customer Data
Not Used
to Train Provider Models
  • privacy screening completed.

  • high-risk indicators identified.

  • full PIA decision documented.

  • processing defined.

  • systems identified.

  • data subjects identified.

  • vendors identified.

  • boundaries documented.

  • personal data identified.

  • sensitive data identified.

  • data sources mapped.

  • classifications assigned.

  • prohibited AI data identified.

  • internal flow mapped.

  • AI flow mapped.

  • vendor flow mapped.

  • vector flow mapped.

  • logging flow mapped.

  • countries identified.

  • each data element challenged.

  • unnecessary data removed.

  • contextual retrieval limited.

  • sensitive data filtered.

  • existing notice reviewed.

  • AI processing addressed.

  • third-party processing addressed.

  • required updates identified.

  • access capability assessed.

  • correction assessed.

  • deletion assessed.

  • vector data considered.

  • provider data considered.

  • application retention defined.

  • AI provider retention reviewed.

  • vector retention defined.

  • logs reviewed.

  • deletion workflow documented.

  • AI provider assessed.

  • processor role reviewed.

  • contract reviewed.

  • model training use assessed.

  • subprocessors assessed.

  • data locations assessed.

  • data-transfer paths mapped.

  • applicable requirements identified.

  • safeguards documented.

  • IAM reviewed.

  • encryption reviewed.

  • DLP assessed.

  • prompt filtering assessed.

  • output controls assessed.

  • tenant isolation assessed.

  • logging reviewed.

  • inherent risks scored.

  • existing controls assessed.

  • control gaps identified.

  • remediation defined.

  • residual risks scored.

  • mandatory pre-launch actions identified.

  • residual risk reviewed.

  • approval decision documented.

  • conditions assigned.

  • reassessment triggers defined.

  • screening retained.

  • diagrams retained.

  • inventory retained.

  • vendor evidence retained.

  • security evidence retained.

  • risk assessment retained.

  • remediation evidence retained.

  • approval retained.

Your completed assessment should identify at least the following potential issues:

ID Finding Severity
PIA-01 Sensitive information may enter AI prompts Critical
PIA-02 Provider model-training terms unclear Critical
PIA-03 AI provider retention excessive High
PIA-04 Privacy notice does not clearly address AI High
PIA-05 AI deletion workflow incomplete High
PIA-06 Cross-border transfer assessment incomplete High
PIA-07 Tenant isolation requires validation Critical
PIA-08 AI and application logs may retain unnecessary PI Medium/High

You have successfully completed the lab when you can answer:

Does This Project
Process Personal Data?
What Data?
Why Is It Needed?
Can We Reduce It?
Where Does It Go?
Does It Reach
an AI Provider?
Does the Provider
Retain It?
Is It Used
for Training?
Which Countries
Process It?
Can Customers
Exercise Their Rights?
Can Data
Be Deleted?
Could One Customer
See Another's Data?
Which Risks Exist?
Which Controls
Reduce Them?
What Is the
Residual Risk?
Can the Project
Be Approved?
What Must Be Fixed
Before Launch?
Can We Prove
Those Fixes Work?

By completing this lab, you practiced:

  • Privacy screening

  • PIA scoping

  • Personal-data inventory

  • Data-flow mapping

  • Data minimization

  • Purpose limitation

  • Privacy-notice assessment

  • Data subject rights analysis

  • Data-retention assessment

  • Vendor privacy due diligence

  • AI privacy assessment

  • Cross-border transfer analysis

  • Privacy security-control assessment

  • Privacy risk scoring

  • Residual-risk assessment

  • Corrective-action planning

  • Approval governance

  • Remediation validation

  • Privacy evidence management

  • Privacy-by-design thinking

These are practical skills used by:

Privacy Analysts
GRC Analysts
Privacy Engineers
Data Protection Officers
Privacy Consultants
Security GRC Professionals
AI Governance Professionals

Before completing the lab, make sure you can answer:

  1. Why did the CloudPay AI project require a full PIA?

  2. What should be included in PIA scope?

  3. Why should personal data be classified?

  4. Why must sensitive data be prevented from entering AI prompts?

  5. Why is data-flow mapping critical?

  6. What is the purpose of a minimization assessment?

  7. Why might full support history be unnecessary for every AI interaction?

  8. Why should the privacy notice be reassessed?

  9. Why is consent not automatically the correct basis for AI processing?

  10. How should privacy rights be assessed for AI systems?

  11. Why are vector databases relevant to deletion?

  12. Why should provider prompt retention be challenged?

  13. Why must model-training terms be reviewed?

  14. How can subprocessors affect privacy risk?

  15. Why must cross-border flows be documented?

  16. How can DLP reduce AI privacy risk?

  17. What is inherent privacy risk?

  18. What is residual privacy risk?

  19. What is the difference between an existing control and a remediation action?

  20. Why should some controls be mandatory before production?

  21. What does Approved With Conditions mean?

  22. Why should remediation be technically validated?

  23. What should trigger PIA reassessment?

  24. What evidence should be retained?

  25. How does this lab demonstrate Privacy by Design?

You have completed:

Lab 02 — Perform a Privacy Impact Assessment (PIA)

Section titled “Lab 02 — Perform a Privacy Impact Assessment (PIA)”

You started with:

New AI Project

and transformed it into:

Privacy Screening
PIA Scope
Data Inventory
Data Flow
Purpose & Minimization
Privacy Requirements
Rights Assessment
Retention
Vendor Assessment
AI Privacy Review
Cross-Border Assessment
Risk Register
Control Assessment
Remediation
Residual Risk
Formal Approval
Validated Evidence

That is how a Privacy or GRC professional turns:

"Can We Launch This?"

into a defensible:

Privacy Risk Decision

➡️ Next: Runbook 01 — Privacy Impact Assessment & Data Subject Request Operations

In the next section, you will move from performing individual privacy labs to operating a repeatable enterprise privacy workflow for:

New Project
Privacy Screening
PIA / DPIA
Privacy Approval

and:

Data Subject Request
Identity Verification
Data Discovery
Rights Fulfilment
Secure Response
Evidence

The runbook will provide the operational steps a Privacy Analyst or GRC Analyst can follow repeatedly in a real enterprise environment.