This document gives guidelines for:
a process on privacy impact assessments, and
a structure and content of a PIA report.
It is applicable to all types and sizes of organizations, including public companies, private companies, government entities and not-for-profit organizations.
This document is relevant to those involved in designing or implementing projects, including the parties operating data processing systems and services that process PII.
BSI recommends this version of standard for organisations operating in or with the UK. The ISO edition is available here if required.