The privacy impact assessment (PIA / EFVP)
A PIA (évaluation des facteurs relatifs à la vie privée, EFVP) assesses a project's privacy risks before it is carried out. It is required in particular for any project to acquire, develop or overhaul an information system or electronic service delivery involving personal information (s. 3.3 and 17), and before disclosing information outside Québec (s. 17).
Technical triggers
- a new enterprise system or application;
- a major architecture or database overhaul;
- hosting or access outside Québec (e.g. a US or EU cloud region);
- integrating a new supplier or third-party API (payments, email, analytics, AI);
- a new purpose for existing data.
Your role
You provide what the RPRP cannot guess:
- the data flow map: which data, from where, to where, stored where, for how long;
- the security measures in place (encryption, access, logging);
- the location of data and subprocessors.
Simplified template
| Section | Expected content |
|---|---|
| Description | Goal, scope, data processed |
| Flows | Diagram: source → processing → storage → recipients |
| Risks | Likelihood × severity for individuals |
| Measures | Technical and organizational |
| Outside Québec | Assessment of adequate protection, contract |
| Decision | RPRP validation, date, reassessment |
Detailed legal framework: see the reference guide — The privacy impact assessment.