The CNIL PIA knowledge bases — the control catalogue behind the method
The third guide in the CNIL’s PIA suite: a catalogue of measures for treating privacy risks, from encryption and access control to organisational safeguards.
- Published by
- Commission Nationale de l’Informatique et des Libertés (CNIL), France.
- Type
- Control catalogue / knowledge base — guide 3 of the PIA suite.
- Versions and language
- February 2018 edition, as stated on the document cover; French and English.
- Jurisdiction
- France / GDPR; the content is largely jurisdiction-neutral.
- Primary audience
- DPOs, CISOs, privacy engineers.
- Topic tags
- DPIA · controls · Art. 32 · security measures · risk treatment
- Availability
- Free PDF on cnil.fr.
Why it matters
Most DPIA templates leave a blank where the mitigations go. This guide is a regulator’s answer to what belongs in that blank: a structured catalogue of technical and organisational measures mapped to the risks a PIA surfaces. In practice it earns a second use outside the DPIA workflow entirely — as a reference when reviewing an Article 32 UK GDPR security position, alongside the CNIL’s separate personal-data security guide. It pairs with the methodology guide (the approach) and the templates (the formalisation); the CNIL’s free PIA software carries the same base.
The UK position is as for the methodology: no UK legal status, checked against current ICO guidance where legal references appear; the 2018 edition’s control families remain the working content.
