A Privacy Impact Assessment (PIA) is a risk management tool used to identify and mitigate privacy risks. The purpose of a PIA is to analyze how an organization handles information to ensure it satisfies requirements and to determine whether information must be protected as Personally Identifiable Information (PII) . A PIA helps to develop and advance strategy by identifying gaps in privacy coverage and determining how to address them. In summary, the purpose of a Privacy Impact Assessment is to identify and mitigate privacy risks, analyze how an organization handles information, and determine whether information must be protected as PII.