A Privacy Impact Assessment (PIA) is a mandatory process which assists organizations in identifying and managing the privacy risks arising from new projects, initiatives, systems, processes, strategies, policies, business relationships etc. PIAs focus on how personal information (PI) will be collected, used, disclosed, stored, retained and protected.
If information security is also at risk, a slightly adapted process called a Privacy and Information Security Impact Assessment is conducted in collaboration with McMaster’s Information Security office.
What is personal information?
Personal information (PI) is recorded information that can be used to identify you.
- It reveals something of a personal nature about you.
- If you can be identified from the information (either alone or by combining it with other information), it is your PI.
How long does a PIA take to complete?
The time needed to complete a PIA can depend on a number of factors, including:
- degree of complexity in the application or service. More complex technology requires more time to assess privacy risks
- the level of vendor transparency. A PIA is more quickly completed when vendors provide excellent depth of detail in their privacy and service policies.
- internal partners are available for consultation, including the PIA requester, and other relevant risk management specialists.
- where there is a previous PIA, we may be able to streamline the process.
- The current capacity of the privacy office may also factor into how quickly we can progress on PIA files.