BC FIPPA privacy assessments and information-sharing agreements
We help BC public bodies and their vendors with the privacy work FIPPA requires: privacy impact assessments, information-sharing agreements, and systems that can actually produce records when a freedom of information request arrives.
What a FIPPA privacy impact assessment is
FIPPA defines a privacy impact assessment as an assessment a public body conducts to determine whether a current or proposed enactment, system, project, programme or activity meets the requirements of Part 3 of the Act. Part 3 covers how personal information is collected, used, disclosed, protected and retained. The definition and the duty sit in section 69.
In practice the hard part is the facts. Which fields does the system collect? Who at the vendor can see them? Where are the backups? A PIA built on a sales brochure fails the first question the privacy office asks. We get those answers from the people and the configuration, not from marketing copy.
The general method is on privacy impact assessments, and the triggers are covered in when a BC public body needs a PIA.
What goes into a FIPPA information-sharing agreement
An information-sharing agreement sets the conditions on how personal information is collected, used or disclosed when a public body shares it with another party, such as a second public body, a federal institution or a private organization. We draft the operational content: the data elements, the purpose, the safeguards, retention, breach notification and the review date. Your counsel settles the legal authority. What a good ISA contains is set out in information-sharing agreements under BC FIPPA.
FOI-readiness: can you find and produce the records?
FIPPA requires a public body to make every reasonable effort to assist an applicant and to respond openly, accurately and completely (section 6). That duty fails quietly when records live in places nobody can search: a messaging tool with no export, a vendor platform the public body cannot query, personal drives.
We test whether a realistic request could be answered from each system, and we write down what would be missed. Keeping records long enough, and no longer, is covered on records management and retention.
Privacy terms vendors to public bodies are asked to meet
FIPPA binds the public body, and it also applies directly to a service provider’s people: section 25.1 prohibits an employee or associate of a service provider from collecting, using or disclosing personal information except as Part 3 of the Act authorizes. Most of the detailed obligations still reach the vendor through the contract. Expect a privacy protection schedule, a security questionnaire, questions about where data is stored and accessed, and a breach notice clause with short timelines. We help vendors answer those accurately and close the gaps before the contract is signed. More on the bid itself is in security for BC public sector vendors.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Who is responsible for a FIPPA privacy impact assessment?
The public body does. FIPPA places the duty to conduct a privacy impact assessment on the head of the public body, so our work is to help its privacy office, or a vendor supplying it, produce an assessment that is accurate and finished on time.
Do you work with vendors as well as public bodies?
Yes. Most of the vendor work is answering the public body’s PIA questions correctly, meeting the privacy and security schedule in the contract, and showing where your system stores and sends personal information.
What does FOI-ready mean for a system?
It means that when an access request arrives, the records it covers can be found, searched and produced in full, including those held in chat tools, shared drives and a vendor’s platform, without anyone rebuilding them by hand.
Is this legal advice?
No. We are not lawyers and we do not give legal advice. We work alongside your counsel and your privacy office, and the legal calls in an assessment or an agreement stay with them.
Start with the system or the agreement in front of you
Tell us what is being assessed or shared, who the parties are, and the deadline. The reply says what the work would cover. Related services are on compliance and privacy.