arXiv · 2609.12571
PIA-Bench: Towards Automated Privacy Impact Assessment with Large Language Models
Abstract
Privacy impact assessment (PIA) is a critical instrument for institutions to proactively identify privacy risks and develop mitigation strategies before system deployment. While mandated across regulatory and institutional contexts, executing PIA requires extensive privacy and technical expertise, posing a particular challenge for teams without access to such resources. Prior work shows the potential of leveraging large language models (LLMs) to assist practitioners' privacy decisions, but little is known about how accurately and reliably LLMs can automate PIA. To this end, we develop PIA-Bench, the first open benchmark for evaluating LLMs on real-world PIAs. We first audited 499 expert-authored PIAs published by US federal agencies and curated 73 structured PIAs, comprising a total of 451 privacy risk and 831 mitigation items, to evaluate LLMs' ability to assess privacy risks and propose mitigations of complex systems. Our results show that off-the-shelf LLMs produce meaningful assessments and identify avenues for future improvement. Finally, we call for improving domain-specific workflows for LLM agents, developing accountable LLM infrastructure, and designing new quality standards for PIAs.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Jiamin Zheng, Hao-Ping Lee, Luo Mai, Jingjie Li. 2026-09-11. PIA-Bench: Towards Automated Privacy Impact Assessment with Large Language Models. https://arxiv.org/abs/2609.12571
Cite the original work for its findings. Save a collection to share your selection of sources.