What is a Privacy Impact Assessment (PIA)?
A Privacy Impact Assessment (PIA) is an in-depth review of any new or significantly revised
initiative, project, activity or program to ensure that it is compliant with the provisions of
FIPPA, to identify and mitigate risks arising from the initiative and to ensure that the
initiative appropriately protects the privacy of individuals.
Why is a PIA required?
The Freedom of Information and Protection of Privacy Act (“FIPPA”) requires that UFV
conduct a Privacy Impact Assessment (“PIA”) to ensure that all collection, use,
disclosure, protection and processing of Personal Information by UFV is consistent with the
requirements of FIPPA. A PIA helps protect individuals’ personal information and helps
identify privacy concerns early in the process of implementing a new initiative.
Who needs to complete a PIA?
All faculty, staff, researchers, and departments must be aware of the need to complete a
PIA when implementing new systems, processes, or initiatives that involve personal
information. A PIA is also required whenever a new system, process or initiative that
involves personal information is significantly revised.
In practice, the responsibility for completing a PIA will belong with the initiative lead,
the head of an academic department or business unit or other Employee who is
responsible for overseeing an initiative (the “Initiative Lead”).
Who oversees compliance with privacy and access legislation at UFV?
The Office of General Counsel (“OGC”) oversees compliance with FIPPA. As it relates to its
work with respect to access and privacy matters, it is also sometimes referred to as the
Privacy Office.
"For more information please see the resources on the Office of General Counsel’s available here Privacy Impact Assessments
