By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity | Serving organizations across Canada, the US, and beyond | Last updated August 17, 2026
Quick answer: A privacy impact assessment for business is a structured evaluation of the privacy risks associated with a new project, technology, processing activity, or significant change to existing processing. It identifies what personal information will be collected, for what purposes, how it will be handled, and what risks exist for individuals whose information is affected. Under Quebec Law 25, PIAs are legally required before acquiring, developing, or overhauling any information system or service involving personal information, and before communicating personal information outside Quebec. In other jurisdictions, PIAs are best practice that regulators increasingly expect to see as evidence of accountability.
Key Takeaways
- Quebec Law 25 makes PIAs legally mandatory for new or overhauled information systems or services involving personal information and for cross-border transfers of personal information out of Quebec. Failure to conduct a required PIA is a violation subject to penalty regardless of whether a privacy breach occurs.
- A PIA is not a bureaucratic checkbox. It is a risk management tool that identifies privacy risks early, when they are inexpensive to address in design, rather than after deployment, when remediation requires reworking systems that are already in production.
- A PIA program automates the process of determining when a PIA is required and who conducts it. Without a program, PIAs are conducted inconsistently, triggered by whoever remembers to ask rather than by a reliable process embedded in project governance and procurement.
- The PIA must be proportionate to the risk: a PIA for a minor process change affecting a small number of records should be simpler and faster than a PIA for a new AI-based processing system handling sensitive personal information at scale.
- Completed PIAs and their findings must be documented and retained. The documentation is evidence of the organization’s accountability and is reviewed by regulators when complaints are filed or investigations are initiated related to the processing activity assessed.
What a Privacy Impact Assessment Is
A privacy impact assessment is a systematic process for identifying, evaluating, and managing the privacy risks that arise from a new or changed processing activity. The term encompasses a spectrum of activities from a brief structured review of a minor process change to a comprehensive multi-week assessment of a complex new system. What all PIAs share is a structured inquiry into four fundamental questions: what personal information is involved, for what purposes is it being processed, what are the risks to individuals from that processing, and what measures are in place or needed to address those risks.
The PIA is conducted before the processing activity goes live, not after it is deployed. This timing is the source of most of the PIA’s practical value. Privacy risks that are identified at the design stage of a new system can be addressed through design choices: collecting less information, using anonymization or pseudonymization, building in access controls and retention rules, or choosing a different processing approach that achieves the business objective with lower privacy impact. Privacy risks identified after deployment require either accepting the risk, remediating deployed systems at significant cost, or discontinuing a processing activity that the organization has already committed to. The cost of privacy risk management is almost always lowest when it is built into design.
When a PIA Is Legally Required
Quebec Law 25 creates the most explicit PIA obligation under Canadian law, one piece of the broader PIPEDA and Quebec Law 25 business compliance picture. The Act requires that any enterprise subject to it conduct a PIA before acquiring, developing, or overhauling any information technology product or service involving the collection, use, communication, keeping, or destruction of personal information. A PIA is also required before any communication of personal information outside Quebec, to determine whether the information would receive adequate protection in the destination. These are mandatory requirements: the PIA must be conducted, it must be documented, and the risks identified must be addressed before the project proceeds.
PIPEDA does not explicitly require PIAs, but the accountability principle creates a strong expectation that organizations have a systematic way of identifying and managing privacy risks from new processing activities. The Office of the Privacy Commissioner has published guidance recommending PIAs as a best practice and citing the absence of PIAs as a factor in findings of non-compliance where a privacy breach resulted from a processing activity whose risks were not assessed before implementation. The practical effect is that PIPEDA-regulated organizations without a PIA program face regulatory exposure when processing activities result in breaches or complaints that a PIA would have identified and addressed.
GDPR Article 35 requires data protection impact assessments (DPIAs, which are functionally equivalent to PIAs) for processing activities that are likely to result in high risks to individuals, including large-scale processing of sensitive personal data, systematic profiling, and use of new technologies. Organizations subject to GDPR due to their processing of EU resident data must conduct DPIAs for in-scope processing activities regardless of where they are headquartered. The specific triggers, documentation requirements, and consultation obligations under GDPR differ from those under Quebec Law 25, but the underlying purpose and methodology are consistent.
What a PIA Covers
Project and processing description
The PIA begins with a description of the project or processing activity being assessed: the business purpose, the personal information involved including categories, sources, volume, and sensitivity, the systems and technologies being used, the internal teams and external parties involved in processing, the jurisdictions in which processing occurs, and the retention period for the information. This description provides the factual foundation for the risk assessment that follows and serves as the documentation of what was assessed if the PIA is reviewed by a regulator or auditor.
Legal basis and necessity review
A PIA evaluates whether the processing has a valid legal basis under applicable privacy law: consent, performance of a contract, legal obligation, or another recognized basis. It also evaluates the necessity and proportionality of the processing: is the personal information being collected limited to what is necessary for the identified purpose, and is the processing approach proportionate to the business benefit? Processing that lacks a clear legal basis or that is disproportionate in its collection scope should be redesigned before deployment rather than documented as a known risk.
Risk identification and rating
The risk assessment identifies the specific PIA privacy risks to individuals that the processing activity creates: risks of unauthorized access or disclosure, risks of inaccurate processing that affects decisions about individuals, risks of function creep in which information collected for one purpose is used for another, risks arising from cross-border transfers to jurisdictions with different legal protections, and risks specific to sensitive categories of personal information including health, financial, biometric, and information about children. Each risk is rated by likelihood and potential impact to individuals, which produces the priority order for the mitigation measures that follow.
Mitigation measures
For each identified risk, the PIA documents the mitigation measures that will be implemented: technical controls such as encryption, access restrictions, and audit logging; organizational controls such as data handling procedures, training, and vendor contractual requirements; and design choices such as data minimization, pseudonymization, or avoiding collection of specific data categories. The PIA documents both the residual risk that remains after mitigation and the decision to accept that residual risk, which is typically made by the designated privacy officer or a privacy governance committee with appropriate authority.
Cross-border transfer assessment
Where the processing activity involves communication of personal information outside Quebec, or outside Canada, the PIA must assess whether the information would receive protection comparable to that required at home, taking into account the sensitivity of the information, the purposes of its use, the protection measures including contractual terms, and the legal framework of the destination jurisdiction. Under Quebec Law 25, where those factors do not support adequate protection, additional contractual safeguards are required before the transfer can proceed. The transfer assessment documents the jurisdiction, the applicable legal framework, the adequacy determination, and any additional contractual measures required, and it overlaps directly with vendor and supplier risk management.
Building a PIA Program That Runs Without Expert Intervention on Every Request
The value of a PIA program over ad hoc assessments is that the program makes privacy risk assessment a routine operational process rather than a special project. A PIA program has four components: trigger criteria that define when a PIA is required and who initiates it, an intake process that captures the information needed to assess whether the activity requires a full PIA or a lighter-touch review, assessment templates and methodology that guide the assessor through the risk identification and mitigation process, and an approval workflow that routes the completed PIA for review by the privacy officer and documents the go-ahead decision.
Trigger criteria are the most important component because they determine whether PIAs happen consistently or only when someone remembers. Triggers should be embedded in the procurement process for new vendors, in the project governance process for new or changed systems, in the product development process for new features involving personal information, and in the change management process for significant changes to existing processing. The trigger does not require that every new project complete a full PIA; a screening intake questionnaire determines whether the project involves personal information and at what scale and sensitivity, and routes it to the appropriate level of assessment. Run well, a PIA program is one of the clearest signs of an operational privacy function, which is the difference explained in why a privacy policy is not a privacy risk management program.
Armour Cybersecurity builds complete PIA programs as part of the privacy risk management engagement: trigger criteria, intake questionnaires, assessment templates, risk rating methodology, approval workflow, and integration guidance for procurement, project governance, and change management. The program is designed for independent operation by your privacy and legal teams after implementation.

Frequently Asked Questions
Who conducts a PIA in our organization?
PIAs are typically conducted by the privacy officer or a privacy team member, with input from the project team, IT, legal, and any other functions whose work is affected by the processing activity. For organizations without a dedicated privacy officer, the PIA may be conducted by a senior manager with privacy responsibility, supported by external privacy advisory when the complexity of the assessment warrants it. The person conducting the PIA should understand both the business context of the project and the applicable privacy law requirements, which is why role-based privacy training for project managers, product owners, and procurement staff is a component of a mature privacy program.
How long does a PIA take?
A PIA for a minor change to an existing processing activity with low privacy impact may take a few hours using a structured template. A PIA for a new AI-based processing system handling sensitive personal information at scale may take several weeks, including multiple stakeholder interviews, technical documentation review, vendor assessment, and legal consultation. The PIA program should establish proportionality criteria that match the depth of assessment to the scale and sensitivity of the processing activity, so that limited privacy resources are focused on the highest-risk processing rather than applied uniformly to all activities.
What happens if we skip a PIA that was required under Quebec Law 25?
Failure to conduct a required PIA under Quebec Law 25 is a violation of the Act independent of whether a privacy breach occurs. The Commission d’acces a l’information can impose administrative monetary penalties for failure to conduct PIAs as required. If a breach subsequently occurs in connection with a processing activity for which no PIA was conducted, the absence of the PIA is an aggravating factor in the regulatory assessment of the organization’s accountability practices. The absence of PIAs for high-risk processing activities is also a finding that can support a determination of inadequate organizational accountability under PIPEDA’s accountability principle.
Can a PIA be used to justify processing that has privacy risks?
The purpose of a PIA is not to provide approval for risky processing but to ensure that privacy risks are identified and addressed. A completed PIA documents the risks, the mitigation measures implemented, and the residual risk. The decision to proceed with processing that carries residual risk after mitigation is a governance decision made by the privacy officer or a designated committee with appropriate authority, and it must be documented. Some residual risk is acceptable when it is proportionate to the business benefit, when the mitigation measures are robust, and when the affected individuals would find the processing reasonable given its purpose. Processing with high residual risk that cannot be adequately mitigated should be redesigned or discontinued, not approved on the basis of a completed PIA.
Do we need to publish our PIAs?
Quebec Law 25 does not require the publication of PIAs, but it does require that PIAs be documented and available for review. The Commission d’acces a l’information can request PIA documentation in the context of an investigation. GDPR requires that DPIAs be retained and, in some cases, shared with the supervisory authority. Internal PIAs are typically confidential business documents and are not published, though the privacy governance policy that the organization is required to publish under Quebec Law 25 should describe the PIA program and its triggers, giving individuals and regulators visibility into the organization’s practice without disclosing the specific findings of individual assessments.
The Bottom Line
A privacy impact assessment for business is how you find and fix privacy risk while it is still cheap to fix, at the design stage, rather than after a system is in production or after a regulator asks why it was never assessed. Under Quebec Law 25 the PIA is mandatory for new and overhauled systems and for transfers out of the province; under PIPEDA and GDPR it is the accountability practice regulators expect. The way to do it reliably is not heroics on each request but a PIA program with clear triggers, proportionate templates, and a documented approval workflow. A structured privacy risk management engagement builds that program so your team can run it without expert help on every request.
About the author
David Chernitzky is Co-Founder and CEO of Armour Cybersecurity, a Toronto-based cybersecurity firm founded by military intelligence veterans and advised by senior leaders from PwC, KPMG, Deloitte, EY, and Mandiant. Armour serves more than 260 organizations across 52-plus industries, including finance, healthcare, technology, energy, legal, and government, with a 97 percent client retention rate.



