Federal privacy impact assessments after October 2024: the Standard on PIA, the OPC process, and the automated-decision directive beside it
The 2010 directive is gone; the duty is not. Where the federal PIA requirement now sits, what the 2024 standard changed, who receives the assessment, what the breach procedures and the Directive on Automated Decision-Making add, and where each element lives in AccessPoint — for ATIP directors, privacy officers and the program executives who sign.
On October 9, 2024 the Treasury Board rescinded the Directive on Privacy Impact Assessment and moved the requirement into the Directive on Privacy Practices, whose Appendix C: Standard on Privacy Impact Assessment took effect the same day, with a grace period to October 10, 2025 for two of its subsections. Institutions must complete PIAs for new or substantially modified programs and activities that use personal information for an administrative purpose, provide approved PIAs to TBS and the Office of the Privacy Commissioner, publish summaries, and document every decision to prepare or update one. The Directive on Automated Decision-Making separately requires an algorithmic impact assessment before an automated system makes or assists an administrative decision.
Federal PIAs have never been a statutory duty under the Privacy Act; they are a Treasury Board requirement, which is why the Privacy Commissioner has recommended to Parliament that the Act be amended to make them one. What changed in 2024 is the instrument. For fourteen years institutions worked from a stand-alone directive with its own core PIA elements; that directive is now marked rescinded, and the requirement lives inside the broader privacy-practices directive as a standard, next to the breach procedures and the personal information bank rules it was always entangled with. This guide sets out the current text, the process the OPC expects, and the automated-decision regime that increasingly sits beside a federal PIA.
Where the requirement lives now
The Directive on Privacy Practices took effect on October 9, 2024 and expressly replaces the Directive on Privacy Impact Assessment dated April 1, 2010. Its expected result is stated in section 3.2.3: PIAs are completed so that the privacy risks associated with programs and activities that use personal information for administrative purposes are identified, reviewed and updated, and appropriate mitigation measures implemented. The head of the institution, or the official responsible for section 10 of the Privacy Act, carries the duties; the standard in Appendix C carries the detail.
The duties in section 4.2 of the directive are the ones a privacy office plans around:
- Complete PIAs in accordance with Appendix C and in collaboration with the section 10 official (4.2.11).
- Provide approved PIAs to TBS and the OPC, respecting Cabinet confidences (4.2.12.1), and notify both in accordance with the standard (4.2.13.2).
- Document decisions to prepare or update PIAs (4.2.14) — the decision not to assess is a record too.
- Publish summaries of approved PIAs (4.2.15).
- Prepare privacy protocols where the standard calls for them, and document decisions to establish or update them (4.2.16 to 4.2.18).
- Keep personal information banks aligned: PIBs are prepared, updated, terminated and submitted to TBS under the same standard (4.2.10), and the development of new or substantially modified PIBs is aligned with the PIA and privacy-protocol process (4.1.7).
The standard's scope test in C.2.2.1 is the familiar one: personal information used for an administrative purpose, or organized and retrievable by the name of an individual or by an identifying number, symbol or other particular. Institutions had until October 10, 2025 to meet subsections C.2.2.1.2 and C.2.2.9.4; everything else applied from day one.
The breach procedures beside it
Appendix B of the same directive, the Mandatory Procedures for Privacy Breaches, took effect on March 1, 2024 and replaced the October 2022 procedures. They require prompt notification of the controlling institution when a breach affects information held for another institution, and they list the minimum information to report to the OPC and TBS for a material breach. A PIA's risk section, written in the same vocabulary as the breach report, is the document a breach response reaches for first.
What the Privacy Commissioner expects
The OPC's Guide to the Privacy Impact Assessment Process sets out the office's role and its expectations of the reports it receives under the Directive on Privacy Practices: a PIA that is proportionate to the risk, that maps the flows and identifies the legal authority, that assesses risks and commits to mitigations, and that is accompanied by the relevant supporting documents such as information-sharing agreements and summaries of security assessments. The OPC may ask for supplementary documents, meetings or site visits. Submissions go through the OPC's online form. The office has also told Parliament it wants the Privacy Act amended to require institutions to submit PIA reports before implementing a program; until that happens, the directive is the obligation and the OPC's guide is the standard of review.
The automated-decision directive
The Directive on Automated Decision-Making applies to any automated decision system in production that is used to make an administrative decision or a related assessment about a client, across every institution subject to the Policy on Service and Digital. It took effect on April 1, 2019; the current version extends to systems developed or procured after April 1, 2020, and existing systems developed or procured before June 24, 2025 have until June 24, 2026 to comply with the updated requirements. Section 6.1 requires an algorithmic impact assessment to be completed, approved and published before production, the requirements of Appendix C applied according to the impact level it produces, and the assessment reviewed and updated on a schedule and whenever the system's functionality or scope changes. Sections 6.2 to 6.5 add notice before decisions, explanations after them, access to components, testing and monitoring, data quality and governance, peer review, Gender-based Analysis Plus, employee training, security and legal review, human involvement, recourse, and reporting.
The AIA tool itself is a questionnaire that scores raw impact across 65 questions to a maximum of 169 and mitigation across 41 questions to a maximum of 77; where the mitigation score reaches 80 percent of its maximum, 15 percent is deducted from the raw impact score. The result places the system in one of four impact levels, from Level I (little impact) to Level IV (very high impact), and the level sets the obligations. A federal system that processes personal information to make decisions therefore needs two assessments describing one system: the PIA under the privacy-practices standard and the AIA under the automated-decision directive. The algorithmic impact assessment guide on this site covers the second in depth.
Building the program
- Re-map your process to the new instrument. Policies, templates and training that cite the 2010 directive cite a rescinded document. Update the references to the Directive on Privacy Practices and its Appendix C.
- Document the decision either way. Section 4.2.14 requires the decision to prepare or update a PIA to be documented; a screener at intake that records "no PIA required, because" is the cheapest compliance record in the program.
- Run the PIB and the PIA together. A new or substantially modified PIB should not reach TBS without the PIA that justifies it, and the retention, sources and uses in both should match.
- Plan the two submissions and the summary. TBS, the OPC and the published summary each need a version; write the summary as you go rather than redacting the report at the end.
- Pair the AIA with the PIA for any system that automates or assists decisions about clients, and align the two on data sources, human involvement and recourse.
- Register risks and commitments with owners and dates, because the standard expects mitigations to be implemented, not listed.
How AccessPoint runs it
AccessPoint's federal jurisdiction pack carries the Treasury Board's 2024 PIA form as its questionnaire and the Privacy Checklist as a preliminary screener, versioned and pack-maintained, with the Privacy Act attached as governing legal authority; the same pack carries the compliance rules for the Directive on Automated Decision-Making.
The checklist as a screener
The screener step records the threshold decision with the assessment, so section 4.2.14's documented decision exists whether or not a full PIA follows.
The TBS form as typed questions
: the personal-information inventory as a table, a flow diagram question, and answers bound to the subject's record of processing on approval, so the PIB fields and the PIA cannot disagree.
Section delegation
to the program's own people, with autosave, hours and documents, and coordinator approval.
Risks, controls and commitments
: a likelihood-and-impact register with a harm-to-individuals determination, controls from the controls library, and undertakings tracked to completion with owners and dates.
AIAs on the same engine
An automated-decision subject carries its AI/ADM register, and the federal pack's compliance profile evaluates the directive's requirements: an assessment before production, the notice, and documented human involvement.
Review, freeze and re-assess
A configurable review carries the approval; approved assessments are read-only, and updates go forward through Re-assess on the same subject, with the reassessment date pulled forward when a purpose changes.
Three outputs from one record
The closure tab generates the regulator summary, the executive summary and a publication summary that deliberately excludes personal data, each in English or French, and the assessment's documents, approvals and activity trail export together for TBS and the OPC.
Breach response beside it
, with a risk-of-harm register and a notification checklist aligned to the mandatory procedures.
Everything runs in your own Microsoft 365 and Azure tenant, in Canada, beside the ATIP requests the same office handles.
A readiness checklist
- Replace every reference to the 2010 directive with the Directive on Privacy Practices, Appendix C.
- Confirm the two subsections with the October 10, 2025 deadline are met.
- Put a documented threshold decision at intake.
- Align the PIB process with the PIA process and the privacy-protocol process.
- Define the TBS submission, the OPC submission and the published summary as three outputs of one record.
- Inventory automated decision systems and confirm each has a current AIA before June 24, 2026.
- Write the breach procedure to Appendix B and use its harm vocabulary in every PIA.
Sources
- Directive on Privacy Practices (effective October 9, 2024; Appendix B Mandatory Procedures for Privacy Breaches effective March 1, 2024; Appendix C Standard on Privacy Impact Assessment effective October 9, 2024) — Treasury Board of Canada Secretariat (accessed September 4, 2026).
- Directive on Privacy Impact Assessment (rescinded October 9, 2024) — Treasury Board of Canada Secretariat.
- Directive on Automated Decision-Making and Algorithmic Impact Assessment tool — Treasury Board of Canada Secretariat (accessed September 4, 2026).
- OPC's Guide to the Privacy Impact Assessment Process — Office of the Privacy Commissioner of Canada (accessed September 4, 2026).
Related reading on this site: AccessPoint for federal institutions, privacy impact assessment software, AI governance and AIA software, the companion guides on algorithmic impact assessments, Ontario's mandatory PIAs and British Columbia's section 69 PIAs, or book a demo.
Federal PIA Questions
Is the Directive on Privacy Impact Assessment still in force?
No. The Treasury Board directive dated April 1, 2010 was rescinded on October 9, 2024. The requirement now lives in the Directive on Privacy Practices, effective the same day, whose Appendix C is the Standard on Privacy Impact Assessment. Institutions had until October 10, 2025 to meet two of the standard's subsections.
When does a federal institution need a PIA?
When personal information is used for an administrative purpose, or is organized and retrievable by a name or an identifying number, symbol or other particular, in a new or substantially modified program or activity. The standard requires the decision to prepare or update a PIA to be documented, so a decision not to assess needs a record too.
Who receives a federal PIA?
Approved PIAs are provided to the Treasury Board of Canada Secretariat and to the Office of the Privacy Commissioner, respecting Cabinet confidences, and both are notified in accordance with the standard. Summaries of approved PIAs are published. The OPC's guide sets out what it expects in the report it receives.
What is the connection between a PIA and a personal information bank?
The Directive on Privacy Practices ties them together: new or substantially modified personal information banks are developed in alignment with the PIA and privacy-protocol process, and PIBs are prepared, updated, terminated and submitted to TBS under the same Appendix C standard.
Does a federal automated decision system need its own assessment?
Yes. The Directive on Automated Decision-Making requires an algorithmic impact assessment to be completed, approved and published before an automated decision system is used to make or assist an administrative decision about a client, with the requirements scaling by impact level. Existing systems developed or procured before June 24, 2025 have until June 24, 2026 to comply with the updated requirements. The PIA and the AIA are separate instruments that describe the same system.