When a BC public body needs a privacy impact assessment

A BC public body needs a privacy impact assessment when it plans a new enactment, system, project, programme or activity, or changes an existing one in a way that alters what personal information is collected, how it is used, who it is disclosed to or where it is stored. Section 69 of FIPPA sets the duty, and the minister’s directions set how the assessment is done.

This page explains the trigger in plain terms. The directions and your own privacy office govern the details.

What FIPPA section 69 requires

Section 69 of the Freedom of Information and Protection of Privacy Act defines a privacy impact assessment as an assessment of whether a current or proposed enactment, system, project, programme or activity meets the requirements of Part 3, the part that governs collection, use, disclosure and protection of personal information.

Section 69 places the duty on the head of a ministry and on the head of a public body that is not a ministry, so public bodies such as health authorities, municipalities and school districts are covered as well as ministries.

What triggers a PIA in practice

The test is simple: is personal information being handled in a way it was not handled before? Common triggers include:

  • buying a new case management or scheduling system;
  • moving records from an on-premises server to a cloud service;
  • starting a joint programme that shares client data with another public body;
  • using existing records for a new purpose, such as analytics or a pilot with an AI tool;
  • switching to a vendor whose support staff can reach the data.

A change to an existing system can trigger one too. If the change alters what personal information is collected, how it is used, who it is disclosed to or where it is stored, the existing assessment no longer describes the system and should be updated. Starting early matters, because a PIA written after the contract is signed can only record risks, not design them out.

What the 2021 amendments changed

FIPPA no longer requires Canadian data residency by statute. The rule that kept personal information stored and accessed in Canada, former section 30.1 of FIPPA, was repealed in 2021. The question did not go away. It moved into the assessment and into the contract. Some public bodies still require Canadian storage by policy or contract, and the PIA is the usual place to weigh storage and access outside Canada.

The amendments also added duties to maintain a privacy management programme (section 36.2) and to notify affected individuals and the commissioner of breaches that could cause significant harm (section 36.3). A current PIA makes both easier, because it already says what data a system holds and who can reach it. The provisions came into force on different dates, so read the current consolidation rather than a 2021 summary.

Who conducts and signs off a PIA

The head of the public body is accountable, usually acting through a delegate. In practice the privacy office drafts with the programme area, and a named approver signs and accepts the residual risk.

Vendors do not write the public body’s PIA, but they supply much of what goes into it. What a supplier should have ready is covered in security for BC public sector vendors.

When the initiative shares personal information with another organization, the PIA usually needs a companion agreement. See information-sharing agreements under FIPPA.

Confirm the current requirements with your privacy office

The minister’s directions, templates and review steps change more often than the Act. Before scoping a PIA, ask your privacy office which template applies, who approves, and whether anything beyond the PIA itself is needed. We are not lawyers, and questions of legal authority belong with your counsel.

Questions we are asked

Does every BC public body have to do PIAs?

Yes. Section 69 places the duty on the head of a ministry and on the head of a public body that is not a ministry, so public bodies such as health authorities, municipalities and school districts are covered as well as ministries.

Does a change to an existing system need a new PIA?

Often, yes. If the change alters what personal information is collected, how it is used, who it is disclosed to or where it is stored, the existing assessment no longer describes the system and should be updated.

Is Canadian data residency still required?

Not by statute. The rule that kept personal information stored and accessed in Canada, former section 30.1 of FIPPA, was repealed in 2021. The question did not go away. It moved into the assessment and into the contract.

Who signs off a PIA in a public body?

The head of the public body is accountable, usually acting through a delegate. In practice the privacy office drafts with the programme area, and a named approver signs and accepts the residual risk.

Getting a PIA written

We prepare PIAs and information-sharing agreements alongside your privacy office and counsel. See privacy impact assessments, or browse more in writing.

Discuss a scope