Assess and manage privacy risk

We help you identify how personal information is collected, stored and shared across your organisation, and provide practical steps to manage privacy risk.
Talk to an expert
Privacy Impact Assessment

Why partner with Bastion for your Privacy Impact Assessment

Understand how your organisation handles personal information, meet legal obligations, and build trust through expert, outcome-focused privacy advice.

  • In-depth, actionable privacy risk analysis
  • Clear reporting aligned to the Privacy Act 2020
  • Tailored advice for both legacy systems and AI

Service detail

What is a Privacy Impact Assessment?

Understand your information and do privacy well

A Privacy Impact Assessment analyses your initiative’s privacy practices across all stages of the information life cycle, against best practice and legal requirements including the 13 Information Privacy Principles of the Privacy Act (2020). The result is a comprehensive and accessible document that guides you through where privacy risk exists, and the steps you can take to manage it. We go beyond interpreting the law, providing advice that is informed by the latest in local and international privacy thought, tailored to your unique requirements.

Our delivery process

Delivery of a Privacy Impact Assessment

We begin by understanding you – your work, your situation, and the people whose information you hold. We combine this with our extensive privacy and security knowledge to highlight where risk exists.
Workshops and Reviews
We glean insights from your team, establishing a comprehensive understanding of how you work.
Assess Risk
We apply our expertise in across your processes and systems, identifying where risks are present.
PIA Delivery
We deliver a report that clearly provides the steps needed to do privacy well.
Benefits

Why work with us

We combine privacy, security and AI expertise to deliver assessments that uncover risk and provide practical, tailored steps to manage it effectively.
Depth of knowledge
Our team has hands-on experience across public and private sectors, delivering local and global projects that balance compliance and practicality
Accessible content
Our reports are clear, concise and ready to use. They’re written to support decision-making and sharing with stakeholders
Tailored solutions
We engage with you directly to understand your work and context, delivering advice that fits your people, processes and systems
What comes next

Take the next step in your privacy journey

Meeting customer and regulator expectations starts with confidence in your systems. We help you strengthen privacy governance and maturity through clear, practical reviews aligned to legal requirements and best practice.

Talk to an expert
Compliance Management Programme
We help you design, embed and manage compliance programmes that support your legal, contractual and governance obligations.
Privacy Impact Assessment
We help you identify how personal information is collected, stored and shared across your organisation, and provide practical steps to manage privacy risk.
Frequently asked questions

Frequently asked questions

From risk assessment to rapid response - we’re with you every step of the way.

What is a Privacy Impact Assessment (PIA)?

A Bastion Privacy Impact Assessment is a process that assesses an initiative against the 13 Information Privacy Principles of the Privacy Act (2020) throughout all stages of the information life cycle. The PIA identifies privacy risks and provides practical advice on how to prevent harm occurring, while offering a competitive advantage by highlighting opportunities to do privacy well.

What is an AI PIA (Artificial Intelligence Privacy Impact Assessment)?

An AI PIA is a specialist Privacy Impact Assessment offered by Bastion, assessing Privacy Act compliance with a particular focus on the ethical and technological implications of AI use. The result is a comprehensive risk assessment, informed by the latest research and thought, that identifies risks and provides guidance on how AI can be leveraged in a privacy-protective manner.

What does completing a PIA involve?

We will start by ensuring that your business context and initiative are fully understood, typically by conducting workshops and reviewing any relevant documentation. Bastion will then perform an expert analysis across that information, providing you with a document that gives actionable insights on protecting your customers’ data.

When should I start a PIA?

Ideally as early in the development of your initiative as possible. This allows for a Privacy by Design approach to be used, identifying privacy risks and the controls against them that prevent them from becoming reality early in the piece. Do not worry if you’re further down the track though – a PIA can be completed at any point, even retroactively.

What are the outcomes of a PIA?

A PIA completed by Bastion will consist of a report that thoroughly analyses how your initiative performs against data protection law and latest privacy thought. The PIA will guide the reader through a thorough analysis of your initiative’s risks and the recommendations we make to manage them.

My customers are outside of New Zealand, does Bastion perform analyses using international privacy law?

Yes. Our team of experts are active within the international privacy community and have experience working with international legislation such as General Data Protection Regulations, the Australian Privacy Act, and the California Online Privacy Protection Act.

Contact us

Talk to an expert

Please call our office number during normal business hours or submit a form below
Where to find us
If you experience a security breach outside normal working hours, please complete the form and we will respond as soon as possible.