Privacy Impact Assessments

A Privacy Impact Assessment (PIA) is a policy process to identify, assess, and mitigate potential privacy risks before they happen.

When you need one

Privacy tip: Your privacy expert may ask you to answer a few short questions to determine if you need a PIA.

If your initiative doesn’t make decisions about an individual, but does collect and/or use personal information, consult your privacy experts to determine if any privacy assessment, such as a privacy protocol, or other deliverables are needed.

Scenario: Do I need to update my PIA?

Who

Samira, a program advisor, is working on a benefits program that’s moving their traditionally paper-based application process online.

Situation

The new application portal requires people to create an account in order to submit their application to the initiative. Samira needs to know whether she needs to update any of her privacy deliverables.

Outcome

Her privacy officer explains that since there is a significant change to the way information is being collected, she’ll need to update her PIA.

What’s required

All PIAs must include:

General process

When to update and review

Your PIA should be continuously reviewed and updated any time there are changes to your initiative. Always contact your departmental privacy expert to assist you in determining which parts of the PIA need updating.

Related links: