The CNIL’s PIA methodology — a regulator’s complete DPIA method, in English
A step-by-step method for carrying out a privacy impact assessment, published by the French authority in official English, and the method its free PIA software implements.
- Published by
- Commission Nationale de l’Informatique et des Libertés (CNIL), France.
- Type
- Methodology guide — guide 1 of a three-guide suite (methodology, templates, knowledge bases), plus a separate application to connected objects.
- Versions and language
- February 2018 edition, as stated on the document cover; French and English.
- Jurisdiction
- France / GDPR; the method is usable wherever GDPR-style DPIAs are run.
- Primary audience
- DPOs, privacy teams, risk practitioners, project owners.
- Topic tags
- DPIA · Art. 35 · risk assessment · EBIOS · WP248 rev.01
- Availability
- Free PDF on cnil.fr.
Why it matters
UK GDPR Article 35 requires a DPIA for high-risk processing and, like the EU text it mirrors, says little about how to actually do one. The CNIL suite is one of the few regulator-authored, English-language answers to the “how”: the methodology walks the assessment itself in four steps — study of the context, study of the fundamental principles, study of the risks related to the security of data, and validation — the templates formalise it, and the knowledge bases supply a catalogue of controls to treat the risks. The guide states that its approach is in keeping with the WP29 DPIA guidelines (WP248 rev.01), appends a table showing where each WP29 criterion is covered, and describes itself as compatible with international risk-management standards; it is implemented in the CNIL’s free, open-source PIA software, which means a team can run the method end-to-end without buying anything.
The UK position, plainly: the ICO’s own DPIA guidance governs UK work and this guide has no UK legal status; the CNIL method slots underneath as a working method, not an alternative rulebook. The edition is February 2018 — pre-Brexit and before the Data (Use and Access) Act 2025 — so any UK-specific legal reference is checked against current ICO guidance rather than read across.
