What is a PIA?
A privacy impact assessment (PIA) is a process that assists public bodies in identifying and managing the privacy risks arising from new or substantially changed projects, initiatives, systems, and processes that collect, use, disclose, secure, or store personal information.
Completing a PIA is a legal requirement for all public bodies under S.69 (5.3) of the Freedom of Information and Protection of Privacy Act (FIPPA). FIPPA requires public bodies to conduct a PIA on any new initiative, or when there is a significant change to an existing initiative, involving the collection, use, disclosure, or security of personal information.
In addition to being a legal requirement, PIAs help to identify deficiencies in privacy protection. It can assist management in making informed decisions and avoid privacy breaches by ensuring that Vancouver Island University (the University) is complying with FIPPA. The PIA demonstrates accountability by including privacy as part of the design of new initiatives or systems.
When to Complete a PIA
PIAs should be completed during the initial development of any new system or program or prior to any significant change being made to an existing system or program.
The PIA must be completed and signed off by the University’s Head or designate, prior to the implementation or launch date of a new initiative or system.
Who is Responsible for a PIA?
PIAs should be drafted by the program manager responsible for the implementation of the initiative, system, or program. The University’s Privacy Officer/Head or delegate is responsible for the approval of the PIA ensuring compliance with FIPPA before implementation. In developing a PIA, the project manager must work closely with the Privacy Officer and, when necessary, the Information Technology Department.
How is the PIA process started?
To start the PIA writing process, please fill out and submit a PIA Needs Analysis Questionnaire. The Privacy Office will then determine whether a full PIA is necessary and will reply with instructions and guidance on how to complete the PIA.
How long does it take to write a PIA?
The PIA process takes four to eight weeks to complete and should be started at as soon as you're contemplating any new program or initiative.
What resources are available for help writing a PIA?
- Privacy and Information Security policies from service providers are should be available on their websites or upon request.
- BC Government's: Guidance for Privacy Impact Assessments. The VIU PIA template mirrors the sections in the guidance document.
- The VIU Privacy Office is also available for questions at pia@viu.ca.