Purpose & data minimization
Scope the business purpose first, then assess what data can be reduced, de-identified or simply not collected.
Sources & accuracy
Key answers keep their sources, versions and test evidence wherever possible; when evidence is thin, design refusal or hand-off paths.
Human review & accountability
For high-impact decisions, name an accountable approver and keep the responsibility boundary in the design.
Permissions & isolation
Assess isolation by role, client and task — with least privilege as the design target.
Logs, exceptions & rollback
Keep the operating evidence the risk and contract require; design exception handling, human fallback and rollback paths.
Ongoing review
Re-assess when models, knowledge, vendors or purpose change; one acceptance test is never a permanent guarantee.
Make the important steps explainable and reviewable
Within project scope, record the key input, processing, review and retention steps. Specific vendors, regions, retention periods and training usage must be confirmed per project and contract.
Choose by data, control and operational responsibility
Customer / controlled cloud
Run in a cloud and region the client approves, with identity, logging, keys and vendor responsibility made explicit.
On-premise or offline
Use the word “offline” only when models, hardware, updates, operations and feature limits are all explicit.
Managed service
Make data flow, sub-processors, retention, exit and service responsibility explicit; convenience never replaces scrutiny.
A Privacy Impact Assessment is a living design document
New Zealand’s Privacy Commissioner recommends conducting — and continuously updating — a PIA before using AI on personal information. When the process, fields, vendors or purpose change, so should the assessment.