Privacy Impact Assessments (PIA / DPIA)
Learn when and how to conduct a Privacy Impact Assessment (PIA), aligned with the CAI v3.1 guide.
When is a PIA required?
Law 25 requires a PIA before any project involving personal information that presents a high risk to privacy. Conformaze automatically detects triggering situations: acquisition or development of a new system processing personal information, transfer of data outside Quebec, use of biometric data, or profiling as defined in article 8.1. When a trigger is identified, Conformaze creates a task to remind you to launch the assessment.
Structure of a PIA in Conformaze
The PIA in Conformaze is structured according to the CAI v3.1 guide. You complete the following sections: project and context description, inventory of personal information processed, risk analysis with probability and severity scoring (5x5 matrix), proposed mitigation measures, and final decision (is the project acceptable as-is, with conditions, or unacceptable?). Each section can be completed progressively.
Risk analysis
The risk analysis uses a 5x5 matrix that crosses probability of occurrence and severity of impact. For each identified risk, you assess the initial risk (before measures) and then the residual risk (after mitigation measures). Risks are linked to inventory items (data, systems, actors) for full traceability. Conformaze automatically calculates the risk level and flags high residual risks.
Important
A high residual risk (score ≥ 4×4) blocks approval of the associated ROPA. You must add additional mitigation measures or document a formal risk acceptance by management before proceeding.
Approval and PDF export
Once the PIA is complete, submit it for approval via the RACI workflow. The approver (usually the DPO or executive) can approve, request changes, or reject. The approved PIA is exportable as a watermarked PDF with version number, approval date, and responsible party's signature. This PDF serves as your proof of due diligence in the event of a CAI investigation.
Link to the ROPA registry
PIAs are linked to the corresponding processing activities in your registry. ROPA approval is conditional on the validation of associated PIAs. If a PIA identifies high unmitigated residual risks, Conformaze blocks registry approval and guides you toward the necessary corrective actions.
Qualification questionnaire (phases)
The PIA in Conformaze is completed progressively in four phases, accessible from Assess > Impact assessments > Questionnaire. Phase 1 describes the project and its scope (objectives, systems involved, stakeholders). Phase 2 inventories the personal information processed: data types, volumes, sensitivity, and retention periods. Phase 3 identifies risks for the individuals concerned along three dimensions — confidentiality, integrity, and availability — rated by probability and severity. Phase 4 proposes mitigation measures and calculates the residual risk. Conformaze unlocks each phase sequentially: you cannot move to the next without completing the previous one.
Qualification questionnaire (phases)
Risk matrix — how to use it
The 5x5 matrix crosses two axes: probability of occurrence (1 = unlikely, 5 = almost certain) and severity of impact on individuals (1 = negligible, 5 = catastrophic). The risk score is obtained by multiplying the two values. Concrete example: unauthorized access to health records will receive a probability of 3 and a severity of 5, for a score of 15 — classified as "high risk". Conformaze displays the initial risk (before measures) and the residual risk (after mitigation measures). Any residual risk with a score above 12 blocks approval of the associated ROPA registry until an additional measure or formal risk acceptance is documented.
Risk matrix — how to use it