24 / 33Privacy Impact Assessment (PIA)

Privacy impact assessment, written to the rule your regulator actually applies

Privacy impact assessment for Canadian institutions and their vendors, scoped to the jurisdiction that will read it.

  • CCIE Security-led team
  • Federal, Ontario, Alberta, BC and Quebec regimes
  • Canadian data residency
THE WORK

Privacy impact assessment, three pillars, one operator.

One Canadian team finds the rule, maps the data, and writes what your regulator accepts. Privacy by design is the part that has to happen before the build, not after the assessment.

  1. 1

    Find the rule first

    Which statute or directive applies decides your template, your threshold and your reader. Ontario institutions have had to produce a written assessment before collecting personal information since 2025-07-01.

  2. 2

    Map the data honestly

    Collection, use, disclosure, retention and destruction, traced to the systems that hold the records rather than to the project's own description of itself.

  3. 3

    Write what gets accepted

    The current form, the named authority, the risks and the mitigations somebody owns. Alberta's commissioner replaced the old template with a new mandatory one on 2026-05-01.

THE PROOF

Built to last. Evidence over promises.

Three Canadian jurisdictions changed their assessment rules since June 2025. Each one wants a different document.

IN PRODUCTION

An Ontario institution that stopped guessing.

Our project was three weeks from launch when someone asked whether we needed an assessment. Nobody could say. SMEnode read the amended statute, told us yes and which form, then mapped the data flows in a fortnight. The commissioner's office had no follow-up questions.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

Privacy impact assessment in Canada, made real.

There isn't one Canadian requirement. There are several, they disagree, and three of them changed in the last fifteen months.

Start with the rule, because the rule sets everything else.

An Ontario institution under the amended access statute has had to produce a written assessment before collecting personal information since 2025-07-01, recorded or not, and update it before a significant change of purpose (IPC Ontario, Bill 194). An Alberta public body works under legislation in force since 2025-06-11 and must use its commissioner's new form, mandatory since 2026-05-01. Federal institutions answer to the Treasury Board Directive on Privacy Practices, which replaced the older assessment-specific directive, and file with both the Secretariat and the federal Privacy Commissioner. Quebec has a different instrument again. Guess wrong and you produce a careful document nobody will accept.

Map the data, not the intentions.

What is collected, under what authority, who sees it, where it lives, how long it stays and what destroys it. The gap we find most often sits between the project's description and its database: a field nobody mentioned, a vendor's analytics on by default, a retention setting left at its factory value. An assessment that describes the plan instead of the system ages badly and gets reopened.

Writing it so a reviewer accepts it.

Reviewers want a named legal authority for each collection, a risk actually characterised rather than labelled medium, a mitigation with an owner and a date, and honesty about residual risk. We'd rather file a document saying one risk stays open, with a plan attached, than one claiming everything is fine. Reviewers have read thousands of these. They can tell.
Control checklist
THE METHOD

How our privacy risk assessment and PIA work runs.

Four steps, and step 01 is a question with a real answer. Which instrument binds you. That depends on whether you're public or private, federal or provincial, which province, whether health information is involved, and whether a contract imposes something extra. It takes hours, not weeks, and it decides the template, the threshold, the reviewer and the deadline. Most of the confusion we're called about is this question left unanswered for months.

  1. Step 01

    Establish the instrument

    Statute, directive, contractual term or all three, named in writing, with the threshold that decides whether an assessment is required at all and which form applies.

  2. Step 02

    Map the initiative

    Data elements, legal authority for each collection, flows to every internal and third-party recipient, storage locations including where a supplier actually holds it, retention and destruction.

  3. Step 03

    Characterise and mitigate

    Real likelihood and real consequence for the people whose information this is, then mitigations with named owners and dates, and residual risk stated rather than buried.

  4. Step 04

    File and keep it alive

    The document in the form your reviewer expects, submitted where submission is required, plus the trigger list that tells you when a change means reopening it.

QUESTIONS

Privacy impact assessment questions, answered straight.

Answers first, including which rule applies to you and when you should do this yourselves instead of hiring us. An architect takes the call, not a salesperson.

Depends on who you are. Ontario institutions under the amended access statute: written, before collection, mandatory since 2025-07-01. Alberta public bodies: under legislation in force since 2025-06-11, on the commissioner's form that became mandatory 2026-05-01. Federal institutions: under the Treasury Board Directive on Privacy Practices, which replaced the older assessment-specific directive, filed with both the Secretariat and the federal Privacy Commissioner. Quebec and BC each have their own. Private companies usually have no statutory duty at all.

For public bodies in several provinces, yes, by statute or directive. For private companies, generally no. What does bind a private company is accountability: PIPEDA holds you responsible for the personal information you hold whether or not anyone made you document the risk. Plenty of private firms do one anyway because a public-sector customer put it in the contract, which is the most common reason we're hired.

Jurisdiction and trigger. A DPIA is the European instrument under the GDPR, required when processing is likely to be high risk, with its own content rules and its own regulator. The Canadian assessment is a public-sector instrument built around legal authority to collect and disclose. The analysis overlaps enough that one can feed the other, and if you serve European users you may genuinely need both documents rather than one bilingual compromise.

Often, yes, and where a regulator publishes one you must. The catch is that templates move: Alberta's became mandatory in a new version on 2026-05-01, so a document on last year's form is now the wrong document. Templates also can't do the two hard parts, which are naming the legal authority for each collection and characterising risk in a way a reviewer accepts. Take the form. The thinking is the work.

When you have a privacy office and the project is small and ordinary, because you'll do it faster than we can and you'll own the result. Call us when the instrument is unclear, when a supplier or a cross-border transfer is in scope, when automated decisions affect people, or when something got launched already and you need an honest assessment rather than a comfortable one.

The assessment on the form your reviewer expects, the data flow map behind it, a legal authority named against every collection, a mitigation register with owners and dates, and the trigger list that says when a change reopens the document. All of it in editable form, in your hands, with no tool to buy from us.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.