Executive Summaries Nov 23, 2023

Demystifying Privacy Impact Assessments (PIAs)

Since September 22, 2023, private businesses have been required to undertake Privacy Impact Assessments (PIAs) in a number of situations provided for by law. The new version of the Act respecting the protection of personal information in the private sector(ARPPIPS) has introduced not only significant penalties for failure to comply with its obligations, but also new concepts such as the PIA that warrant a closer look

What is a PIA?

The PIA plays a key role in the ARPPIPS, as it is an essential tool for businesses, particularly due to its mandatory nature. Despite its incorporation into the ARPPIPS, the Act does not provide a specific definition for PIA.

A PIA is a risk-assessment tool whose chief objective is to identify issues relating to the protection of personal information, thereby enabling mitigating measures to be identified where necessary. As a result, conducting a PIA ensures that businesses:

  • Are aware of the privacy risks that exist within their organization
  • Consider the pros and cons as well as appropriate mitigation measures
  • Monitor the aforementioned risks through practical means

Consequently, while conducting these assessments may appear to be an additional burden, organizations must view PIAs as useful and necessary so as to prevent monetary penalties or reputational harm arising from breaches of the law.

Moreover, the ARPPIPS does not specify how a PIA should be carried out. Nor does it indicate whether it is necessary to document all PIAs or what form such assessments should take. Nevertheless, since assessments must be carried out repeatedly, and since conducting a single PIA may require enlisting help from several parties (including the privacy officer, legal team, security team, and external suppliers), businesses would do well to adopt a basic PIA model tailored to their specific situation, containing all the information they need to document and enabling them to proceed efficiently.

When should a PIA be conducted?

Prior to the enactment of the new requirements in September 2023, PIAs were considered good practice only. The ARPPIPS, however, now makes it compulsory to conduct such an assessment in three instances:

  • Prior to launching any project involving the acquisition, development or restructuring of an information system or electronic service delivery system that involves the collection, use, disclosure, retention or destruction of personal information (including the acquisition of a new payroll management system, development of a mobile application, installation of surveillance cameras, launch of an advertising campaign or use of artificial intelligence)
  • Prior to disclosing personal information outside Québec, which is a common occurrence given how few businesses or their suppliers site their servers exclusively in the province

It is worth noting, however, that the obligation to carry out a PIA is not retroactive. Hence, any project completed as of September 22, 2023 and any disclosure of personal information outside Québec prior to that date are not subject to this assessment.

How should a PIA be conducted?

Faced with this new obligation and in the absence of clear directives from the ARPPIPS on a preferred method, Commission d’accès à l’information (the CAI) released its updated Guide d’accompagnement (the Guide), which is designed primarily as a source of information and which includes a model PIA report. (The Guide is available in French only.)

These documents aim to support organizations that are subject to the ARPPIPS and required to conduct PIAs by means that provide a structure for the assessment and an understanding of various concepts. The steps put forward by the CAI are as follows:

1. Description of the project and its scope: This introductory section provides an overview of the project, its objectives, and so on.

2. Roles and responsibilities: This section identifies the stakeholders involved. Depending on the size of the business, these may vary from regulatory compliance advisors to information security advisors, for example.

3. Personal information involved and scope of the assessment: This section enables the identification of the personal information involved and the categories of people whose information is involved (for example, employees, customers, and so on). In this section, the CAI asks organizations to justify the scope of the PIA being carried out. It should be kept in mind that the ARPPIPS states that the PIA “must be proportionate to the sensitivity of the information concerned, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored.”2

  • While the CAI does not specifically state what criteria should be applied in determining if a PIA is proportionate or not, it is possible that a project involving sensitive personal information (for example, health information, biometric information or information about minors) or linked to artificial intelligence would justify a more detailed assessment. Conversely, a new project involving very little personal information that is not very sensitive (for example, only a few first names, surnames and contact details) should not be the subject of an extensive and exhaustive assessment.

4. Compliance with obligations and principles relating to the protection of personal information: While the CAI states that the purpose of this section is to assess compliance with the applicable provisions, unlike its counterpart in France, Commission nationale de l’informatique et des libertés, it does not provide a specific list of applicable obligations or privacy factors to be complied with in its recommended assessment model. Hence, in this third section of the assessment, it would be up to businesses to raise the legal obligations to which they are subject and assess the compliance of the activities in question:

  • Does the project comply with applicable legislation on the protection of personal information?
  • Is the business able to identify potential threats and the consequences of such threats for the people concerned?
  • Can the business introduce mitigation measures to reduce the probability or impact of a previously identified risk?

It is primarily at this stage that support from a member of our team may be required. While the CAI Guide delves into many of the other steps, as far as legal insight is concerned, seeking the help of legal professionals may well be worthwhile.

5. Identifying risks and mitigation strategies: This section should describe the project’s privacy risks and identify suggested mitigation measures. This is also where risk matrices, such as the one below, may prove useful. This matrix qualifies the level of risk in accordance with the probability of occurrence and the severity of the potential consequences.

graohique-gravity-probability

6. Action plan: In this section, the CAI sets out the concrete actions to be implemented, based on the strategies identified in the preceding stages. For instance, if the use of an unsafe tool or software is only temporary, pending the negotiation of a new contract, a person must be appointed to ensure that this part of the action plan is implemented within the set timeframe.

7. Approval of the report and versions: This section allows a senior officer of the organization to approve the content of the PIA. The risks to privacy and the protection of personal information are significant and may result in considerable harm if they occur. Consequently, it is essential that the key players in the organization be aware of them, for more informed decision-making.

In its Guide, the CAI states that while it is possible to carry out a PIA without formally documenting it, one should be able to explain and justify one’s PIA approach. With this final step, the CAI reminds businesses of the importance of documenting their PIA. The assessment report is important when businesses are required to account for or demonstrate their compliance, for example, in response to requests from regulators.

It is also important to remember that these assessments need to be updated and need to evolve over time.

If you have any questions about conducting PIAs, whether to help you in undertaking an assessment or provide you with the tools you need to conduct it yourself, or if you have any other questions about the impact of the new privacy requirements on your business, please contact our team.

[1] Act respecting the protection of personal information in the private sector, CQLR c P-39.1.

[2] ARPPIPS, Article 3.3 p. 4.

You would also like

Data-Privacy

Bill 82: One Step Closer to a National Digital Identity (and Modifications to Other Provisions!)

Entrepreneurship forum

Entrepreneurship Forum: Vision 2025

Athlete

Protecting Privacy in Sports – Don’t Wait to be Caught Flat-Footed!

data-protection

Obligation to Report Information Security Incidents: The Autorité des Marchés Financiers Catches the Wave and Publishes a New Regulation

Right to Data Portability: Is your Organization Ready?

Tech Forum 360

Tech 360 Forum: Growth and Inflection Points

Prospera: Québec’s Economic Barometer

Canada's Best Managed Companies: BCF Recognized for 17th Consecutive Year

paul et misha

BCF Strengthens its Expertise in Artificial Intelligence

new-partners-2024

BCF Has Appointed Three New Partners

Who’s Who Legal : 5 BCF Professionals Stand Out

BCF extends its Partnership with the Canadian Association of Black Lawyers to a Third Year

The Data Processing Agreement: An Essential Resource to Implement

camera-on-a-wall

The Incident Response Plan: the Cornerstone of Effective Crisis Management

forum-privacy-en

Strategic Forum on Enterprise Data Protection

Chambers Canada Ranking: Five of our Lawyers Recognized

Photo of Julie Doré

Julie Doré Takes Over Management of The BCF Business Law Firm

Prospera – Quebec Economic Barometer

Julien Tricart, Member of the Meritas Sports Law Group

Pride Month: Let’s Create an Inclusive Future

Canada’s Best Managed Companies: BCF Recognized for 16th Consecutive Year

New Privacy Requirements: Is Your Business Compliant?

Every Woman Counts

Strategic Forum on the Role Played by Businesses in the Fight Against Climate Change

BCF Partners with the Canadian Association of Black Lawyers to Promote Diversity in Québec Law Faculties

BCF's More Inclusive Approach: Improved Parental Leave

Shaun E. Finn Appointed to the Superior Court of Québec

How to Ensure a Business Succession?

Business black folders on table

Adoption of Bill 78 on Transparency Business: Are You Ready?

Strategic Forum on Market Consolidation and Business Succession

BCF Partners with the Clinique Juridique de Saint-Michel to Promote Access to Legal Studies for Young People from Diverse Communities

What Are the Best Practices for Managing Privacy Incidents?

Shaun E. Finn, Co-Author of In the Public Eye: Privacy, Personal Information, and High Stakes Litigation in the Canadian Public Sector

Should Using Personal Information Obtained Without Consent Be Grounds for Class Action Authorization?

Five of our Lawyers Stand out in the 2023 Edition of the Chambers Canada Ranking

Cybersecurity and Privacy in Canada: What You Need to Know About Bill C-27

Is the Loss of Personal Information Sufficient to Justify the Success of a Class Action on the Merits?

Bill C-26: The Federal Government Takes a Closer Look at Cybersecurity and Privacy

Jocelyn Poirier, BCF’s Chief Privacy Officer

43 BCF Professionals Stand Out with 78 Nominations in the 2023 Editions of Best Lawyers in Canada and Ones to Watch

Seven New Lawyers Join BCF

Adoption of Bill 96: Be Ready

Pride Month: The Value of Diversity

BCF, the 3rd Largest Law Firm in Québec

Canada’s Best Managed Companies: BCF Recognized for 15th Consecutive Year

BCF Recognized by the Globe and Mail as one of Canada’s top Law Firms

Chambers Canada 2022: BCF Earned Band 1 Ranking in Québec for Corporate and Commercial Law

Seven New Lawyers Join BCF

Privacy and Data Protection Class Actions: Trends, Challenges and Best Practices

A First in Canada: Privacy Class Action Dismissed on the Merits

escalier

BCF Welcomes Seven New Lawyers

Collaboration in the Time of COVID-19: Legal Considerations for Successful AI and Healthcare Partnerships

Shaun E. Finn and Danielle Miller Olofsson Publish a Unique Practical Handbook on Privacy and Data-Protection Class Actions

What Are the Implications of the End of EU-U.S. Privacy Shield Framework for Your Business?

Investigation on Tim Hortons’ Application

Québec’s Bill 64 to Amend Data Protection Legislation: A Bill with Teeth?

Does the Use of Thermal Imaging Cameras in Stores Comply with Privacy Laws?

COVID-19: Solutions to Address this Situation

COVID-19: Finally a Toolbox for Developers of Geolocalisation Applications

Tracking the COVID-19 Pandemic with Cellphones

COVID-19: Don’t Forget Data Protection When Designing a Response Strategy

BCF once again ranks as one of Montreal's Top Employers

BCF Names 16 New Partners for Its 25th Anniversary

Joint Controllership or the Risks of using Website Plugins

Are You a Leader or a Follower?Results of the Innovation Survey

Chambers Canada 2020: BCF Recognised in Corporate and Commercial Law

Strategic Forum on Innovation

Different Legislative Approaches to 5G

Innovating to Survive: Are You a Leader or a Follower?

Is Your Company Implementing a New Technology System? Remember to Protect Your Data

5G Technology Is Coming: Legal Questions Abound

Legal Issues Surrounding the Industrial Revolution 4.0

Where Does Québec Stand in Terms of Privacy Class Actions?

De-fogging the Cloud Act

fenetres

Google and CNIL: a Case of Inappropriately Obtained Consent

Best Practices for Québec Companies Receiving European Data

Anonymization? Think Again

The Deep Web and Dark Web Demystified for Businesses

The GDPR is Coming: How to Get Ready

Protection of Personal Data: New Measures Put in Place by the European Union

Is Your Organisation Collecting Too Much Data and Is It Well Protected?

Get the latest thought leadership