Conducting a PIA Flashcards
What’s a Privacy Impact Assessment ?
A detailed assessment of the actual or potential effects that a proposed program, project or activity of a government institution will have on the privacy of citizens, clients and employees
Why is Privacy so Important?
Public trust in government institutions
International obligations of Canada
Privacy protection is legislated
Privacy compliance audits by the OPC
Liability for government institutions
Need to incorporate the “Human Values” in all programs and activities of government institutions
Why Conduct a PIA?
Ensure compliance with the Privacy Act and the generally accepted privacy principles
Mitigate the identifiable privacy risks and the identifiable security risks related to privacy
Identify and address the privacy and the security risks that cannot be mitigated – residual risks
what’s the Main Objectives of a PIA ?
Can the initiative successfully pass the “privacy test”?
- ensure that it will be designed and operated in compliance with the terms and spirit of the Privacy Act, the generally accepted privacy principles as well as the internationally recognized privacy standards
- ensuring that privacy is fully integrated into the design, implementation and operations of the initiative, including the activities supported by, and supporting it
- Ensuring that we can adequately answer questions from interested parties about the impact that the initiative and related processes may have on the privacy of the targeted and other individuals
When to Conduct a PIA ?
Increased use of personal information
A broader target population
A shift from direct to indirect collection of personal information
Using personal information for purposes for which it was not originally collected
Greater sharing of personal information with other programs, institutions, governments or sectors
Contracting out or devolution of a program or service to other levels of government or the private sector
Creation of a common personal identifier
An anticipated negative public response
When a program or activity initiated or sponsored by the institution may bring individuals to:
Expose their personal information or elements of their private life to others without properly assessing the risks
Adopt a type of behaviour that presents risks to their safety or well-being or to act against their best interests without properly assessing the risks
Personal Information Bank (PIB)
A collection or grouping of personal information that:
Has been used, is being used or is available for use for an administrative purpose; or
Is organized or intended to be retrieved by the name of an individual or by an identifying number, symbol or other particular assigned to an individual
Assess Privacy Implications
Privacy and security issues already identified (results of the TRA)
Interviews and on-site inspections
Other jurisdictions
Precedents
Could the institution achieve the same or acceptable objectives without any privacy risks?