Roger Clarke's 'History of PIAs'

A History of Privacy Impact Assessments

Roger Clarke

Principal, Xamax Consultancy Pty Ltd, Canberra

Visiting Professor, Baker & McKenzie Cyberspace Law & Policy Centre, University of N.S.W.

Visiting Professor, E-Commerce Programme, University of Hong Kong

Visiting Fellow, Department of Computer Science, Australian National University

Draft of 6 February 2004

© Xamax Consultancy Pty Ltd, 2004


This document is at


Privacy Impact Assessment emerged during the 1980s from precursor notions of 'technology assessment' and 'environmental impact statements'. The idea achieved currency through the 1990s, and is increasingly evident in the early years of the new century, as governments and business alike struggle to encourage public acceptance and adoption of quite apparently privacy-invasive technologies.


1. Introduction

The concept of a Privacy Impact Assessment gained currency during the last decade of the old century. An introductory paper on the concept is Clarke (1998). The purpose of the present paper is to trace the origins and development of the meme.

2. Precursors

There would appear to be two primary intellectual threads that gave rise to the concept and term 'PIA'.

One is the idea of 'technology assessment', as practised in the Office of Technology Assessment (OTA) of the U.S. Congress, 1972-1995, and in a range of European contexts. An early treatment of the Office's methods is in OTA (1977). [Later works, which would reflect the OTA's next 15-18 years' experience, have to date eluded me]

The other pregenitor is the concept of an Environmental Impact Statement (EIS). The origins of this idea are to be found in the 'green' movements of the 1960s. The U.S. implemented a requirement for an EIS for major projects in 1970, and few jurisdictions in economically advanced nations would be without some kind of requirement.

There have been great tensions in this area. EIS are costly, and inevitably involve considerable delay. There has accordingly been a great deal of lobbying by powerful corporations, and by development-oriented agencies, resulting in a wide array of compromise to the processes and products.

Of even greater relevance to the history of PIAs has been the cynicism about the EIS notion that has arisen among the people affected by major projects. If the law only requires that an EIS be prepared, then there remain many ways in which inappropriate projects can gain approval. The EIS may be insufficiently audited, or insufficiently auditable, and hence may succeed in glossing over problems. The EIS may gain insufficient media coverage, and hence a development-minded agency or government may be able to ignore illogic, and value public opinion very lightly.

A more substantial notion that counters the weaknesses of an EIS is Environmental Impact Assessment (EIA). This is a more articulated concept, including public consultation, publication and review; and it lifts the focus beyond product alone to include process. Official training materials are provided by UNEP (2002). Links to government sources are available on various sites, including that of the Australian Department of Environment & Heritage.

A professional community exists, the International Association for Impact Assessment (IAIA), which has long since applied the idea to additional areas. The Association's journal, Impact Assessment and Project Appraisal, commenced publication in the early 1980s. IAIA defines impact assessment as "the identification of future consequences of a current or proposed action". IAIA provides guidance on Environmental Impact Assessment (IAIA 1999).

UNEP (2002) includes a segment on Social Impact Assessment, but privacy is not mentioned. IAIA provides guidance on Social Impact Assessment (IOCSIA 1994, (IAIA 2003). See also Becker & Vanclay (2003). But, despite its broad scope, IAIA and its journal do not appear to have recognised a sub-domain of 'privacy impact assessment'.

3. Origins of the Terms

It may prove impracticable, and in any case unprofitable, to search too studiously for the first usage of the relevant terms. It is as well, however, to document that which comes readily to hand.

3.1 Privacy Impact Statements

In keeping with usage in the precursor context of environmental impact, the original concept was of a 'statement' prepared as a condition precedent to approval of a project, or the debate of legislation.

The first literature reference to 'privacy impact statements' that I have located to date is, by way of Stewart (2001), at Flaherty (1989, p.405): "The data protection agency can ... [prepare] its own evaluations of the potential impact on personal privacy of proposed legislation and information systems. ... It is important that small data protection agencies encourage the main government departments to prepare their own initial reviews of the impact of new technology, preferably in the form of 'privacy impact statements' ...".

Further, in respect of the Canadian Federal Privacy Commissioner, he wrote "The Justice Committee recommended ... the submission of a privacy impact statement [by an agency to the Privacy Commissioner] in relevant situations. The Cabinet ... rejects the formal requirement of an impact statement to accompany each piece of legislation [footnoted to Re Ternette and Solicitor General of Canada, Dominion Law Reports 10, 4th ser. (1984): 587]" (p.277-278).

Flaherty's Footnote 26 on p. 413 also states that "The U.S. Privacy Protection Study Commission wisely recommended the preparation of a privacy impact statement for each piece of federal legislation". The final paragraph of PPSC's Chapter 13 states "Perhaps the most significant finding in the Commission's assessment of the Privacy Act arises from its examination of the vehicles available for evaluating and assessing existing record systems, new systems, and agency practices and procedures. Quite simply, there is no vehicle for answering the question: "Should a particular record-keeping policy, practice, or system exist at all?" While the Act takes an important step in establishing a framework by which an individual may obtain and question the contents of his record, it does not purport to establish ethical standards or set limits to the collection or use of certain types of information. Without such standards, however, the principal threat of proliferating records systems is not addressed. Nowhere, other than in the ineffective section requiring the preparation and review of new system notices, does the Act address the question of who is to decide what and how information should be collected, and how it may be used. To deal with this situation, the Congress and the Executive Branch will have to take action" (my emphasis).

It would therefore appear that at least the concept, and perhaps the term, was in use in some quarters as early as 1977. Moreover, the notion was sufficiently well-developed for a national commission to frame one of its 160 recommendations around it (and indeed one that escaped the hatchetry of the Ford Administration, although of course the Recommendation was not taken up).

Interestingly, in one of the formative documents, HEW (1973), the concept can be traced, but not the term. In particular "Each time a new personal data system is proposed (or expansion of an existing system is contemplated) those responsible for the activity the system will serve, as well as those specifically charged with designing and implementing the system, should answer such questions as ..." (p.51).

3.2 Privacy Impact Assessments

The term that has been in currency since at least the second half of the 1990s is the more comprehensive 'PIA'. In addition to resulting in a less unattractive acronym, it is focussed on process as well as product, and encompasses consultation, publication and review.

There are claims of the term 'PIA' being used in the 1970s. [David Flaherty says he can document the use of the term as early as the 1970s (2000, footnote 3), and I look forward to receiving a list of references from him!]

[Lance Hoffman advises that Hoffman (1973) includes a Berkeley, California ordinance requiring a Privacy Impact Assessment, which he helped write]

The term was used in discussions I had with Karl Reed and others in the context of the Australian Computer Society's Economic Legal & Social Implications Committee (ELSIC), in the mid-1980s. We toyed with both 'Social Impact Assessment' and 'Privacy Impact Assessment' at the time, as a means of forcing government agencies and corporations to confront the impacts and implications of applications of advanced information technologies.

Daniel et al. (1990) refers to 'social impact assessment' of traffic management technologies (a predecessor term for what is currently referred to as Intelligent Transportation Systems); but its primary focus is on privacy impacts.

The first documentary usage that I have traced to date is in IPCO (1993), a paper on smart cards by Ann Cavoukian and staff of her Ontario Information and Privacy Commissioner's office. [It appears that this is no longer accessible on the Web, and I have not yet located a printed copy]

4. Early Contributions to the Idea

The concept did not arrive with a pre-determined name. Hence most of the early papers do not mention the term 'PIA'.

The original, pre-OECD Guidelines data protection laws (e.g. those of Hesse 1970, Sweden 1973 and Norway 1978) commonly required registration or licensing. A check was required to ensure that the data controller's behaviour was in compliance with the law. For example, Bygrave (2002) points out that the Norwegian Data Inspectorate was required to assess "whether the establishment and use of the register in question may cause problems for the individual person ..." (s. 10, Norwegian Personal Data Registers Act of 1978, since superseded). Impact Assessment involves a much broader study than merely compliance with a specific law; but interpretations and discretions within those laws would have doubtless enabled Registrars to make some contributions to what we know understand to be a PIA.

The Australian Data-Matching Program (Assistance and Tax) Act 1990 includes in Schedule 1 a requirement for 'program protocols', which are a form of PIA.

Stewart says that the term was used in Longworth (1992). [But that's another reference I haven't seen, and hence I can't enlarge upon the statement]

Early contributions were made by Privacy Commissioners Cavoukian in Toronto (IPCO 1993, 1995) and Flaherty in Vancouver (Flaherty 1995). [But they appear to have disappeared from the Web, and I have yet to locate printed copies of them]

Another important thread is Cost-Benefit Analysis, which was applied to the assessment of computer matching projects in Clarke (1995a). A substantial proposal for a regulatory scheme for computer matching is in Clarke (1995b). An examination of the means whereby an organisation can adopt a strategic approach to privacy is in Clarke (1996).

Early usage of the PIA process was reported on in IPCO (1993, 1995). [I have not yet located copies of these, and hence cannot trace the elements that appeared in them]

As noted in Flaherty (2000), a discussion session on PIAs was organised by Blair Stewart in Christchurch, New Zealand, on 13 June 1996. The considerable New Zealand contributions are summarised in Stewart (1996a, 1996b and 1999).

5. Exemplars

A considerable contribution to progress in the area arose from early applications of the ideas. The earliest exemplars that I have identified to date are:

6. Recipes and Guidelines

Stewart (2001) states that "official guidelines for the preparation of PIAs date from at least 1991 ... See SSNYPSC (1991)". Other early sets of guidelines include 'Suggested Rules for Evaluating the Privacy Impacts of Emerging Technologies', Appendix A to Flaherty (1994), IRS (1996), HealthBC (1997), IPCO/ACTA (1997, 2000) and Uni Alberta (1998).

From the late 1990s onwards, PIAs were recognised by a succession of government agencies as an idea whose time had come. A large number of Guidelines were prepared, which have varying degrees of authority and influence.

It is normal for the routinisation of procedures to result in fairly mindless procedures and documents. Many sets of Guidelines are of the nature of checklists, and can easily lead to the generation of guideline-compliant documents; whereas others are intentionally introductory and designed to stimulate constructive approaches to what are usually complex and multi-dimensional problems.

Recent official documents include Ontario (1999, 2001), USDOJ (2000 - which applies specificially to Justice Information Systems), OIPC-AB (2001) OIPC-AB (2001), OFPC (2001 - for public key infrastructure projects), NZPC (2002), Canada (2002), UKCO (2002) and USDOI (2002).

Guidance is increasingly appearing in commercial documents and books, such as Karol (2001) and Marcella & Stucki (2003, pp. 332-348).

7. Conclusions

Since its emergence in the mid-1960s, privacy protection has been constrained by a mere 'fair information practice' model to a framework that has been more protective of corporate and government interests than of people or even of their data.

The early emphasis was on bodies of principles that could be applied to individual organisations, business processes, and projects. Among the challenges that confronted this approach was the enormous diversity of business and government, and of applications of information technologies.

PIAs have emerged from an early fog, and are now mainstream. The coming years will tell whether they force the surfacing of issues, the involvement of the public, and a multi-stakeholder approach to development initiatives that reflects the privacy interest, and achieves balances among conflicting interests that are less privacy-insensitive than was the case during the last three decades of the twentieth century.


Thanks to the many people who've contributed to the establishment of this document, especially Blair Stewart (NZ), Nigel Waters, Graham Greenleaf, Philip George and Chris Connolly (AU), Ann Cavoukian, David Flaherty, Peter Hope-Tindall, Pierrot Peladeau and Stephanie Perrin (CA), Dave Banisar, Robert Gellman, Lance Hoffman and Willis Ware (US), Herbert Burkert (Germany), and Lee Bygrave (Norway).


