PIA program readiness check.
Ten questions on the parts of a privacy impact assessment program that a commissioner, an auditor or a new statute will test first: the trigger, the inventory, the template, the risks, the approvals and the re-assessment. Score yourself honestly; the value is in the gaps it names, not the number.
Readiness assessment
Pick one option per question. "In place" means it is written down, followed, and you could show the evidence today.
The mandate
Do you know which statute or directive requires a privacy impact assessment for your organization, and what triggers it — a new collection, a project, or a substantial change?
What good looks like: The trigger and the required contents are written down for your regime and reviewed against the statute each year. Which regimes require a PIA →
The inventory
Do you keep an inventory of the programs, systems and activities that collect, use or disclose personal information, each with a named owner?
What good looks like: A durable subject record per program with its owner, personal-information categories, retention and vendors, updated as part of the assessment itself. Privacy subjects and the ROPA register →
The screener
Does every new initiative or change pass through a written threshold screener that records whether a full assessment is needed, and why not when it is not?
What good looks like: A preliminary screener whose answers instantiate the full assessment or a lightweight compliance record, with the determination stored. Documenting the decision to assess →
Template coverage
Does your template cover purpose and necessity, legal authority, the information inventory, sources, who has access, limits, retention, safeguards, risks to individuals, and mitigation steps?
What good looks like: A pack-maintained template built on your regulator's own methodology, versioned when the regulation changes. What every template must contain →
Program-area input
Do program areas answer the sections only they can — flows, retention practice, real safeguards — rather than the privacy office guessing?
What good looks like: Section delegation to the people who run the program, with autosave, hours and documents, and coordinator approval. Section delegation →
Risks and mitigations
Are risks to individuals scored on likelihood and impact, with every mitigation assigned an owner and a date and tracked to completion?
What good looks like: A risk register with a harm-to-individuals determination, controls from a library, and commitments tracked to done. Risks that outlive the assessment →
Approval and freeze
Is every approved assessment signed off, read-only afterwards, and versioned when the program changes?
What good looks like: A review workflow that moves the assessment to In Effect, freezes it, and routes change through Re-assess on the same subject. Approval and re-assessment →
Re-assessment triggers
Do you have a defined trigger that reopens an assessment when purpose, data or vendors change, or when a substantial change occurs?
What good looks like: A change-of-purpose trigger that pulls the reassessment date forward and surfaces it on the day view. The substantial-change trigger →
Regulator readiness
Could you produce any assessment, with its approvals, risks and evidence, for a commissioner within a day?
What good looks like: A regulator summary generated as a document and an export of the assessment, its documents, approvals and activity trail. Submitting to the Commissioner →
AI and automated decisions
Are AI and automated decision systems in your inventory, with an algorithmic impact assessment beside the PIA wherever they affect people?
What good looks like: An AI systems register, an AIA on the same engine as the PIA, and a compliance profile that flags a system deployed without one. Algorithmic impact assessments →
What your score means
Three bands. Ontario, Alberta, British Columbia and the federal government now test these elements in statute or directive; Nova Scotia joins them on April 1, 2027.
Exposed
Assessments happen ad hoc, if at all. A commissioner's request or a new collection would be answered from scratch, and the mandate may already apply to you.
Building
The pieces exist — a template, some assessments, a person who owns it — but the trigger, the risk follow-through or the re-assessment is not yet systematic.
Defensible
A program, not a document: screened intake, delegated sections, tracked mitigations, frozen approvals, and an export a regulator can read on demand.