HomeKnowledge HubKey Publications & Reports › CNIL PIA guide 1: Methodology

Regulator guidance · Publications

The CNIL’s PIA methodology — a regulator’s complete DPIA method, in English

CNILFebruary 2018 editionFree

A step-by-step method for carrying out a privacy impact assessment, published by the French authority in official English, and the method its free PIA software implements.

Published by
Commission Nationale de l’Informatique et des Libertés (CNIL), France.
Type
Methodology guide — guide 1 of a three-guide suite (methodology, templates, knowledge bases), plus a separate application to connected objects.
Versions and language
February 2018 edition, as stated on the document cover; French and English.
Jurisdiction
France / GDPR; the method is usable wherever GDPR-style DPIAs are run.
Primary audience
DPOs, privacy teams, risk practitioners, project owners.
Topic tags
DPIA · Art. 35 · risk assessment · EBIOS · WP248 rev.01
Availability
Free PDF on cnil.fr.

Why it matters

UK GDPR Article 35 requires a DPIA for high-risk processing and, like the EU text it mirrors, says little about how to actually do one. The CNIL suite is one of the few regulator-authored, English-language answers to the “how”: the methodology walks the assessment itself in four steps — study of the context, study of the fundamental principles, study of the risks related to the security of data, and validation — the templates formalise it, and the knowledge bases supply a catalogue of controls to treat the risks. The guide states that its approach is in keeping with the WP29 DPIA guidelines (WP248 rev.01), appends a table showing where each WP29 criterion is covered, and describes itself as compatible with international risk-management standards; it is implemented in the CNIL’s free, open-source PIA software, which means a team can run the method end-to-end without buying anything.

The UK position, plainly: the ICO’s own DPIA guidance governs UK work and this guide has no UK legal status; the CNIL method slots underneath as a working method, not an alternative rulebook. The edition is February 2018 — pre-Brexit and before the Data (Use and Access) Act 2025 — so any UK-specific legal reference is checked against current ICO guidance rather than read across.

A curated reference entry maintained by VulaPri. We summarise and link to the original; we do not reproduce or host it. Listed since 15 September 2026 · last verified 15 September 2026 — edition verified on the document cover (PDF opened 15 September 2026) and against cnil.fr/en. Suggest a correction.