๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Privacy Impact Assessments

Assess a system, vendor, transfer or AI tool once, against every privacy law you select, and keep the record an auditor or regulator will ask for.

Open Privacy Impact Assessments in your console

Where to find it
Compliance โ€บ Privacy Impact, or Resilience โ€บ Privacy Impact. Also under More in the Compliance bar.
Who can use it
Anyone whose compliance (GRC) role includes viewing; creating and editing, approving, and deleting each need the matching compliance permission
For
Privacy officers, compliance leads, and the people who own a system or vendor
Plan
GRC Compliance Platform (included in Complete), or Resilience: Vendor Risk & Business Impact. Either one opens this page. See pricing

What the page is for

A privacy impact assessment (PIA) records what personal information a project, system, vendor or transfer handles, what could go wrong for the people it is about, and what you will do about it. Quebec Law 25 already requires one before a new information system or a transfer outside Quebec. Bill C-36, the proposed Protecting Privacy and Consumer Data Act (PPCDA), would require one before transferring personal information outside Canada (s. 57) and before relying on legitimate interest (s. 18). Under PIPEDA, the Privacy Commissioner already expects one for new programs.

Each assessment covers every privacy law you select. You answer each question once, and tags show which laws ask for it. One assessment shows compliance with PIPEDA today and readiness for the PPCDA tomorrow, without doing the work twice.

There are six kinds: General privacy impact assessment, Transfer outside Canada, Legitimate interest assessment, AI and automated decisions, Alberta PIA (Health Information Act) and British Columbia PIA (FIPPA). Each kind asks only the questions that apply to it.

An approved assessment counts as evidence for the controls that ask for one, such as PRIV-001 Privacy Impact Assessment and PPCDA-001 Cross-Border Transfer Privacy Impact Assessment, in every framework that maps those controls.

What you see

The Privacy Impact Assessments page with a New assessment button and suggestions under Probably needs an assessment: an AI tool and two transfers of personal information outside Canada.
The Privacy Impact Assessments page before the first assessment. Suggestions come from your vendors and data flows. Example data.
  1. New assessment: opens the two-step wizard.
  2. Probably needs an assessment: suggestions from your Resilience data. Data flows that carry personal information across a border, vendors that hold personal information outside Canada, and vendors marked as using AI features appear here until they have an assessment. SaaS discovery finds the AI apps people are using, so you can add them as vendors and assess them. Select Start to begin one already filled in.
  3. The assessment table: Assessment, Type, Laws covered, Status, Remaining risk, Open risks, Next review and Updated. Select a column heading to sort, and type in Filter to narrow the list.
  4. The assessment: the laws it covers, the questions in sections (Describe it, Necessity and proportionality, Authority and transparency, Sharing and transfers, Safeguards, Individual rights, and sections for the kind you chose), Risks and mitigations, Conclusion, and Controls this assessment evidences.

How to start an assessment

  1. Select New assessment, or Start beside an item under Probably needs an assessment.
  2. Under Kind of assessment, choose the type. Where one of your selected frameworks requires that type, the card says so under Your frameworks.
  3. Enter a Name and, optionally, the Business process, Data flow or Vendor it is about. Each of these lists is searchable: type part of a name to narrow it. To add one that is not there yet, choose + Add a new ... at the bottom of the list (or type the name first and choose + Add "name"). A short form opens over the one you are in; the new item is selected when you save it, and you can fill in the rest later on its own page. Select Next.
  4. Under Which privacy laws should this one assessment cover?, the laws you follow in Compliance are already ticked. Tick any others.
  5. To find laws you might have missed, open Add other privacy laws by location and audience, tick Where are the people? and Who is involved?, and select Tick the laws that apply.
  6. Select Create assessment. The assessment opens as a Draft.
Step 1 of the New privacy impact assessment wizard, with six kinds of assessment. Each card says what your selected frameworks expect, such as the PPCDA requiring a transfer assessment if enacted.
Step 1 of the wizard. Each kind of assessment shows what the frameworks you follow expect of it. Example data.

How to complete an assessment

  1. Answer each question once. The tags under a question show which of the selected laws ask for it and where, for example PIPEDA Principle 4.4 or PPCDA (Bill C-36, proposed) s. 57.
  2. Under Risks and mitigations, select Add a risk, describe What could go wrong, and for whom?, set Likelihood and Impact on people, and record the Mitigation, Owner, Due date and Status. Select Save risk.
  3. Under Conclusion, choose Risk before mitigation, Remaining risk and the Decision (Proceed, Proceed with conditions or Do not proceed), and write the Reasons and conditions.
  4. Enter the Owner and Next review date, and select Save.
  5. When it is ready, select Send for review.

How to approve an assessment

  1. Open the assessment and check the answers, risks and conclusion.
  2. Select Approve. The decision and the remaining risk must be recorded first.
  3. If you wrote the assessment, someone else has to approve it, unless your administrator allows self-approval in Compliance Settings. Then you are asked for a reason of at least ten characters, which auditors can see.
  4. Once approved, the next review date is set to one year from today unless you chose one.

How to print, retire or delete an assessment

  1. Select Report for a printable copy. Use your browser's print dialog to save it as a PDF.
  2. Select Retire when the system or transfer no longer exists. A retired assessment stays on record but no longer counts as evidence. Select Reopen to bring it back as a draft.
  3. Select Delete to remove a draft and its risks permanently. Only drafts can be deleted.

Where else assessments appear

  • Controls: a control that a PIA evidences shows a Privacy impact assessments panel listing yours, with Start an assessment. See Control Detail.
  • Data Flows: a flow that carries personal information across a border has a shield button to start a transfer assessment, or to open the one it has. See Data Flows.

Tips

  • Where two laws set different rules, such as COPPA's under-13 rule and the PPCDA's under-18 definition of a child, record both and design to the stricter one.
  • The PPCDA is a bill, not yet law. Including it now means the same record is ready if it passes, with no second assessment.
  • Link the assessment to the data flow or vendor it is about, so the suggestion disappears and the link shows up on the Data Flows page.
  • Changing an approved assessment, or one of its risks, sends it back to In review. Approve it again once the change is checked.
  • Plan a review at least once a year, and whenever the system, vendor or countries involved change.

Troubleshooting

"Privacy impact assessments are not set up yet."
Your organization's update to this feature has not finished. Ask your administrator, or contact our support team.
"You wrote this, so someone else has to approve it."
Ask a colleague whose compliance role includes approving. An administrator can allow self-approval with a reason in Compliance Settings.
"Record the decision and the remaining risk, and save, before approving."
Fill in Remaining risk and Decision under Conclusion, then select Save.
"Only a draft can be deleted."
Select Retire instead. The record stays for your audit trail.
A law I need is not in the list.
The list shows the privacy laws in the Lavawall framework catalogue. Tell our support team which law you need.

Still need help?

Search the support centre, or contact our support team and tell us which page you were on:

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.