Privacy Impact Assessment
Before you launch the system, migrate the data, or sign the vendor — find out what it does to the people whose information you hold. A PIA documents the personal data flow, tests it against Canadian privacy law, and gives you the findings early enough to change the design.
When a privacy impact assessment is worth doing
Public bodies in several provinces are required to complete one. For private organizations it's usually driven by a project, a contract, or a change that moves personal information somewhere new.
New system or platform
A CRM, HR system, patient portal or customer app that will collect or store personal information.
Cloud migration
Moving records to a hosted service — especially where data may be stored or accessed outside Canada.
New vendor or processor
Any third party that will handle personal data on your behalf, including analytics and support tooling.
New use of existing data
Profiling, automated decisions, AI training, or reusing information collected for a different purpose.
Assessed against the law that applies to you
Canadian privacy obligations depend on your sector and province, and often more than one regime applies at once. We identify which apply before assessing anything:
- PIPEDA — federal private-sector law and the ten fair information principles
- Alberta PIPA · BC PIPA · Quebec Law 25 — provincial private-sector regimes
- FOIP and health information acts — for public bodies and custodians
- GDPR — where you serve or monitor individuals in the EU or UK
- ISO/IEC 27701 — privacy information management as a control framework
We aren't a law firm and don't give legal opinions — where a question turns on legal interpretation, we say so and flag it for your counsel.
The assessment follows the data, from the moment it's collected to the moment it's destroyed:
- Collection — what's gathered, from whom, and whether it's necessary
- Consent and notice — how purpose is communicated and consent recorded
- Use and disclosure — every downstream system, report and recipient
- Storage and residency — where data lives, who can reach it across borders
- Safeguards — encryption, access control, logging, segregation
- Retention and disposal — schedules, and whether deletion actually happens
- Individual rights — access, correction, withdrawal and complaint handling
The report is written to satisfy a regulator or a client's privacy officer without further editing:
- Data flow map — a diagram of personal information through the whole lifecycle
- Compliance analysis — each requirement addressed, with a finding and evidence
- Privacy risk register — risks to individuals, scored, with mitigations
- Recommendations — prioritized, with those that must be done before launch marked clearly
- Residual risk statement — for sign-off by the accountable executive
"The cheapest time to fix a privacy problem is before the system is built. The most expensive is after someone complains." — A & T Global privacy practice
-
Done early, not as a formalityFindings arrive while the design can still change — which is the entire point
-
Data residency addressed head-onCross-border access and hosting analysed against the regime you're bound by
-
Regulator-ready formatStructured the way privacy commissioners and client privacy officers expect to read it
-
Capability you keepGDPR DPO and ISO/IEC 27701 courses in our catalogue if you want the skill in-house
Four steps, two to four weeks
- 01 Threshold & scope We confirm whether a full PIA is warranted, which legislation applies, and where the assessment boundary sits.
- 02 Map the data flow Workshops with process and system owners produce a verified map of personal information end to end.
- 03 Analyse & score Each legal requirement tested against the flow, with privacy risks to individuals scored and documented.
- 04 Report & sign-off Recommendations split into pre-launch and post-launch, ending with a residual risk statement for your executive.
Privacy impact assessment FAQ
It depends on who you are and where you operate. Public bodies in several provinces have statutory obligations; Quebec's Law 25 requires assessments for certain projects; GDPR requires a DPIA for high-risk processing. For most Canadian private-sector organizations it isn't strictly mandated — but it is the accepted way to demonstrate the accountability that PIPEDA does require. We'll confirm your position in the threshold step, and recommend legal advice where the answer is genuinely contested.
Not too late, just more expensive to act on. A retrospective PIA still tells you what you're exposed to and what to fix, and it's far better than discovering the gap through a complaint. We'll be explicit about which recommendations are cheap now and which would have been cheap six months ago.
Not automatically — Canadian private-sector law generally permits cross-border transfer with appropriate safeguards and transparency, though public-sector rules in some provinces are stricter. What matters is contractual protection, comparable safeguards, and telling individuals it happens. The PIA documents exactly that, which is usually what a client or regulator is asking to see.
Yes, and it's efficient — the two share discovery work and interviews. A TRA looks at risk to the organization; a PIA looks at risk to the individual. Running them together typically costs less than running them apart and gives you one consistent set of findings.
Assess it before you launch it
Tell us about the project and the data it touches — we'll confirm whether a full PIA is warranted and scope it with a fixed price. We respond within one business day.