You want to understand a system’s implications before choosing its configuration. Collection, sharing and retention options need to be discussed with the teams involved.
- Home
- Our services
- Privacy impact and vendor assessments
Privacy impact and vendor assessments
Scope a privacy impact or vendor assessment with Loupe Technologies: information flows, risks, evidence gaps and safeguards to consider.
Are you preparing a new system, integration or service that handles personal information? Loupe Technologies helps you scope a privacy impact assessment and examine the information supplied by your vendors.
The proposed work brings together the facts needed for a decision: information involved, intended uses, access, responsibilities and safeguards. A privacy impact assessment and a vendor assessment can support one another while keeping their own defined scope.
Examine the project while choices are still open
Sales responses do not clearly explain the service’s information handling. You need structured questions, supporting documents and a way to track incomplete answers.
The project combines a model, documents and sometimes tools that can take action. You want to identify the uses and transfers to examine before deciding how a trial should proceed.
Two assessment streams supporting an informed decision
For the privacy impact assessment, we propose defining the project, describing information flows and examining risks to individuals. The work identifies proposed safeguards, choices still open and reviews to obtain. The regulatory scope is established with the responsible people.
For the vendor assessment, we examine available responses and documents against your intended use: access, declared processing locations, subcontractors, retention, deletion, incident handling and exit arrangements. Vendor claims are distinguished from what the documentation actually supports.
The engagement defines which streams are included and the depth of verification. It does not assume technical testing of the vendor or legal approval of its contracts. Questions requiring those activities are identified so that complementary work can be scoped.
A working record for decisions and project follow-up
Depending on the agreed engagement, deliverables may include the following.
Scope and information flows
A description of the project, information and participants, including assumptions and facts still to confirm.
Assessment and proposed safeguards
A summary of risks and possible safeguards, connected to design choices and decisions to be made.
Vendor questions and follow-up
A record of responses, clarification requests and points for the responsible people to review before deciding or continuing the project.
Build the assessment with the right people
-
Define the decision
We identify the project, its owners and the decision stage to prepare. Privacy impact and vendor assessment scopes are defined separately.
-
Gather useful information
We work from flow descriptions, planned configurations and available documentation, recording where information comes from and what remains uncertain.
-
Examine the options
We discuss risks and possible safeguards with your teams, identifying technical and legal questions that require separate review.
-
Present findings and plan updates
The assessment records findings, decisions still needed and changes that should trigger a review of the work.
Questions before you get started
When should a privacy impact assessment begin?
The CAI describes a PIA as a process undertaken before a project and as it develops. Starting early allows choices to be examined while they can still change. The assessment need and scope must be established for your situation.
Does a vendor assessment replace a privacy impact assessment?
No. Vendor assessment examines the supplier’s responses and proposed service arrangements. A privacy impact assessment looks more broadly at the project and its effects on privacy. Findings from the first stream can inform the second.
Is Canadian hosting enough to approve a vendor?
We propose also examining access, subcontractors, permitted uses and exit arrangements. Declared hosting location is one part of the record; the assessment should reflect how the service actually works and your circumstances.
What can we prepare for the first conversation?
A project description, the tools and information categories involved, responsible contacts and the vendor’s public documentation are useful. Real personal information is not needed to describe the initial requirement.
Sources and references
- Responsabilité des entreprises — gouvernance et EFVP — Commission d’accès à l’information du Québec
Which project or vendor do you need to assess?
Tell us about the project, its stage and the decision you are preparing. We can clarify the information to gather, the people to involve and the assessment scope to consider.