A Privacy Impact Assessment (PIA) is a risk management tool that evaluates how a system, program, or activity collects, uses, and discloses personal information. It helps you to identify and mitigate potential privacy risks, ensuring compliance with the Freedom of Information and Protection of Privacy Act (FIPPA) and alignment with privacy best practices. The outcome of a PIA should be a practical mitigation plan, not simply a compliance form.
The scope of a PIA includes collection, authority, purpose, consent/notice, access controls, retention, vendor/cloud arrangements, cross-border storage, AI/analytics, and breach response.
Effective July 1, 2025, a PIA is mandatory for any collection of personal information. This requirement applies to all new systems, programs or activities that involve the collection of personal information. A PIA must be completed in advance, and all risk prevention and mitigation measures identified in the assessment must be implemented before collecting personal information – or, if not feasible, within a reasonable timeframe afterward. This requirement covers the collection of any personal information, including but not limited to students, applicants, alumni, donors, etc.
You should start a PIA before purchasing, building, launching or materially changing a system or process. You should do your PIA early, when plans can still change. Do not wait until procurement, configuration or launch is complete.
Please note that an updated PIA is required whenever there is a significant change in the purpose for which personal information is used or disclosed. A PIA is living document that should be regularly reviewed and updated as a project evolves or organizational goals shift, ensuring ongoing alignment with privacy requirements and best practices.
For support, inquiries or clarification on PIAs, contact the Privacy Office.