Privacy Impact Assessment (PIA) Protocol
Effective Date: 31 July 2026
1. Purpose
The Privacy Impact Assessment (PIA) Protocol defines the methodology for assessing the privacy risks associated with new processing activities, systems, or changes to existing processes at The Payments Club. This ensures that privacy is considered at the design stage and that appropriate controls are implemented before any new processing begins.
2. When to Conduct a PIA
A PIA must be conducted when:
- Introducing a new system that processes personal information
- Changing the purpose of existing processing
- Implementing new technologies that affect privacy
- Sharing personal information with new third parties
- Processing sensitive personal information
- Significant changes to existing processing
- Any processing that poses a high risk to data subjects
3. PIA Process
Step 1: Initiation
- Identify the need for a PIA
- Define the scope of the assessment
- Assign a PIA owner and team
- Set timeline and resources
Step 2: Data Mapping
- Identify what personal information is collected
- Document sources of personal information
- Map data flows within and outside the organization
- Identify storage locations and retention periods
- Document recipients and third parties
Step 3: Purpose and Lawfulness
- Document the purpose of processing
- Identify the lawful basis (contract, consent, legitimate interest, etc.)
- Ensure processing is necessary and proportionate
- Document consent requirements
Step 4: Risk Assessment
- Identify privacy risks and threats
- Assess likelihood and impact of each risk
- Consider risks to data subjects' rights and freedoms
- Identify compliance gaps
- Document risk register
Step 5: Controls and Mitigations
- Identify controls to address identified risks
- Document mitigation measures
- Apply Privacy by Design principles
- Implement data minimization
- Ensure transparency (notice and consent)
Step 6: Review and Approval
- Peer review of PIA documentation
- Information Officer review and sign-off
- Senior management approval where required
- Document decisions and rationale
Step 7: Implementation and Monitoring
- Implement approved controls
- Monitor effectiveness of controls
- Regular review and update of PIA
- Report on compliance
4. PIA Documentation
Each PIA must be documented and include:
- Project or system description
- Data mapping and flow diagrams
- Purpose and lawful basis
- Risk assessment and risk register
- Controls and mitigation measures
- Approval and sign-off
- Review schedule
5. Privacy by Design Principles
The following Privacy by Design principles must be applied in all PIAs:
- Proactive: Privacy is considered from the start
- Default: Privacy is the default setting
- Integrated: Privacy is embedded in design
- End-to-End: Full lifecycle privacy protection
- Visibility: Transparency and accountability
- Respect: Respect for user privacy and rights
6. Roles and Responsibilities
- Information Officer: Overall accountability, review and approval
- Project Owners: Initiating and conducting PIAs
- System Administrators: Technical implementation of controls
- External Assessors: Independent reviews where required
7. PIA Register
The Information Officer maintains a register of all completed PIAs, including:
- Project name and description
- Date of completion
- Key risks identified
- Controls implemented
- Review date
8. Policy Review
This protocol will be reviewed annually and on any material change to processing or systems. The latest version is always published on our website.
Last Updated: 31 July 2026