Privacy impact assessments

A privacy impact assessment (PIA) is a written analysis of how a system, project or programme handles personal information, what could go wrong, and what is done about it, completed before launch rather than after. We write PIAs under BC FIPPA, BC PIPA, PIPEDA and the GDPR, along with the information-sharing agreements that often travel with them, and we bring in specialists where a system or sector calls for it. BC public bodies and their vendors working under FIPPA alone will find that narrower work on BC FIPPA PIAs and information-sharing agreements.

What a privacy impact assessment covers

The format changes by regime. The substance does not:

  • Data flows. What personal information is collected, from whom, where it is stored, who can reach it and where it goes next.
  • Purpose. Why each element is needed, stated narrowly enough to test.
  • Legal authority. The basis for collection, use and disclosure, confirmed with your counsel.
  • Risks and mitigations. Specific ones, such as a support vendor with admin access to case files from outside Canada, each with a control and an owner.
  • Residual risk and sign-off. What is left after the mitigations, and who accepted it.

Which regime your PIA is written under

BC public bodies have a statutory duty to conduct PIAs under section 69 of FIPPA. When that applies is set out in when a BC public body needs a privacy impact assessment.

PIPEDA and BC PIPA do not require a PIA by name. Private-sector organizations still use one as the clearest record that accountability and safeguard duties were considered before launch. Under the GDPR, Article 35 makes the assessment mandatory for high-risk processing. If you are unsure which law reaches you, start with which Canadian privacy law applies.

Information-sharing agreements

When personal information moves between organizations, such as a health authority and a municipality running a joint programme, the PIA usually needs a companion agreement. It records what is shared, why, under what authority, how it is protected, how long it is kept and who to call if something goes wrong. The FIPPA detail is in information-sharing agreements under FIPPA.

How the work runs

We start with the people who run the system, not the policy binder. A data-flow walkthrough with the system owner surfaces most of the real risks in a few sessions. We then draft, review the authority questions with your counsel, and hand you a document your privacy officer can approve without rewriting.

A PIA is not finished at launch. We note which future changes should reopen it, so the next vendor swap or new data field triggers a review instead of a surprise. Wider programme work sits under Canadian privacy readiness.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Do you give legal advice on the PIA?

We are not lawyers. We work alongside your counsel and your privacy officer, who own the legal authority questions and the final sign-off, while we do the mapping, the risk analysis and the drafting.

Is a GDPR DPIA the same as a PIA?

Close, but not identical. The GDPR requires a data protection impact assessment under Article 35 where processing is likely to result in a high risk to the rights and freedoms of individuals, and it sets minimum contents. One piece of work can serve both purposes if it is scoped that way from the start.

How long does a privacy impact assessment take?

A contained change, such as a new vendor tool with a clear data flow, often takes weeks rather than months, though scope decides it. Most of the elapsed time goes into getting accurate answers from the people who run the system.

Who signs off the PIA?

Your organization does. The privacy officer, or the head of a public body or their delegate, approves the assessment and accepts the residual risk in writing.

Start a privacy impact assessment

Tell us what is being built or changed, which regime you think applies and when it needs to launch. See also all compliance and privacy services.

Discuss a scope