Privacy Impact Assessment
What is a Privacy Impact Assessment (PIA)?
The Protection of Privacy Act (POPA) establishes that public bodies are required to prepare privacy impact assessments (PIA) under prescribed circumstances outlined in the Protection of Privacy (Ministerial) Regulation (Ministerial Regulation). PIAs help public bodies identify and mitigate privacy risks around the collection, use and disclosure of personal information for new administrative practices or information systems (or significant changes to existing systems).
A PIA is a process intended to help you identify and manage privacy and security risks before they arise. Think of a PIA as a proactive roadmap for your project.
When is a PIA required?
A PIA is required for a new, or a substantial change to an existing, administrative practice, program, project or service that will involve the collection, use or disclosure of personal information if one or more of the following apply (see section 7 of the Protection of Privacy (Ministerial) Regulation):
- if the loss of, unauthorized access to or unauthorized disclosure of the personal information could result in significant harm;
- a practice, program, project or service will collect, use or disclose personal information considered to be of high sensitivity,
- a practice, program, project or service will involve the personal information of a significant percentage of the population the public body serves;
- a practice, program, project or service will involve data matching between 2 or more public bodies;
- a practice, program, project or service is part of a common or integrated program or service;
- a practice, program, project or service involves the development or use of innovative technology.
In relation to the collection, use and/or disclosure of personal information, a PIA must:
- include a summary of the purpose of the collection, use or disclosure of personal information;
- identify the types of personal information;
- identify the legal authority;
- Identify any privacy risks and mitigation strategies;
- identify any administrative, physical or technical safeguards in place to protect the personal information;
- if applicable, include how the personal information will be securely transmitted, matched or linked by the public body;
- describe implemented accuracy, correction and retention procedures ensuring the personal information is accurate and complete; and
- if two or more public bodies are engaging in a common or integrated program or service or if a public body is collecting personal information from another public body for the purpose of carrying out data matching, establish a clear governance structure respecting the responsibilities and accountability of each public body.
If you believe you are required to complete a PIA or have questions regarding the requirements for PIAs under POPA, please contact our office at privacy@ualberta.ca. The IPRMO is here to guide you through this process, ensuring your work meets Alberta’s legal standards of privacy and security and aligns with the University of Alberta’s privacy policies and procedures.
FACTS AND FRAMEWORKS:
- Public bodies can prepare a PIA for any initiative that involves collecting, using, or disclosing personal information.
- PIAs enhance privacy and transparency by mapping how personal information is collected, used, disclosed, and retained.
- PIAs mitigate risks associated with managing personal information.
- Some PIAs must be submitted to the Office of the Information and Privacy Commissioner (OIPC). Additional information is available on the OIPC’s website.
DEFINITIONS:
- Common or Integrated Program or Service means a program or service planned, administered, delivered, managed, monitored or evaluated by the public body working collaboratively with one or more other public bodies, or another public body working on behalf of the public body, or the public body and one or more other public bodies.
- Data Matching means linking personal information between two or more databases or other electronic sources of information.
- Personal Information means recorded information about an identifiable individual, including but not limited to: name, home address, personal email address, age, and an identifying number assigned to the individual.
- Examples of public bodies include post-secondary institutions, Government departments, municipalities, and health authorities.
Health Information Act (HIA)
Although the University is not a custodian of health information and is not responsible for preparing HIA PIAs, the university does employ custodians of health information. Section 64 of the HIA states:
…each custodian must prepare a privacy impact assessment that describes how proposed administrative practices and information systems relating to the collection, use and disclosure of individually identifying health information may affect the privacy of the individual who is the subject of the information.
Custodians wishing to learn more about preparing a PIA under HIA should visit the OIPC PIA webpage.Contact Us
Information, Privacy and Records Management Office
University of Alberta
7-20 University Terrace
8303 - 112 Street NW
Edmonton, Alberta, Canada T6G 1K4