Conducting a PIA Flashcards

1
Q

What’s a Privacy Impact Assessment ?

A

A detailed assessment of the actual or potential effects that a proposed program, project or activity of a government institution will have on the privacy of citizens, clients and employees

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why is Privacy so Important?

A

Public trust in government institutions

International obligations of Canada

Privacy protection is legislated

Privacy compliance audits by the OPC

Liability for government institutions

Need to incorporate the “Human Values” in all programs and activities of government institutions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why Conduct a PIA?

A

Ensure compliance with the Privacy Act and the generally accepted privacy principles

Mitigate the identifiable privacy risks and the identifiable security risks related to privacy

Identify and address the privacy and the security risks that cannot be mitigated – residual risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what’s the Main Objectives of a PIA ?

A

Can the initiative successfully pass the “privacy test”?

  1. ensure that it will be designed and operated in compliance with the terms and spirit of the Privacy Act, the generally accepted privacy principles as well as the internationally recognized privacy standards
  2. ensuring that privacy is fully integrated into the design, implementation and operations of the initiative, including the activities supported by, and supporting it
  3. Ensuring that we can adequately answer questions from interested parties about the impact that the initiative and related processes may have on the privacy of the targeted and other individuals
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

When to Conduct a PIA ?

A

Increased use of personal information

A broader target population

A shift from direct to indirect collection of personal information

Using personal information for purposes for which it was not originally collected

Greater sharing of personal information with other programs, institutions, governments or sectors

Contracting out or devolution of a program or service to other levels of government or the private sector

Creation of a common personal identifier
An anticipated negative public response

When a program or activity initiated or sponsored by the institution may bring individuals to:

Expose their personal information or elements of their private life to others without properly assessing the risks

Adopt a type of behaviour that presents risks to their safety or well-being or to act against their best interests without properly assessing the risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Personal Information Bank (PIB)

A

A collection or grouping of personal information that:

Has been used, is being used or is available for use for an administrative purpose; or

Is organized or intended to be retrieved by the name of an individual or by an identifying number, symbol or other particular assigned to an individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Assess Privacy Implications

A

Privacy and security issues already identified (results of the TRA)

Interviews and on-site inspections

Other jurisdictions

Precedents

Could the institution achieve the same or acceptable objectives without any privacy risks?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly