All learning

Beta

Assessing Privacy and Security

Create your Privacy Impact Assessment (PIA) and Security and Threat Risk Assessment

Pre-requisites

  • A defined service and working architecture
  • An inventory of information and system integrations
  • Access to privacy and security officials

What you'll get

  • A draft Privacy Impact Assessment
  • A draft security threat-risk assessment
  • Privacy and security mitigations added to the delivery roadmap

Mentors

Developer agent
Code for Canada Coach
Start activity

Why assess privacy before launch?

Privacy starts with whether the service needs personal information at all. Security cannot justify unnecessary collection or an inappropriate use.

A late privacy review can expose problems that require new consent, different data flows, shorter retention, or a redesigned service.

Why assess security throughout the service lifecycle?

Security protects the confidentiality, integrity, and availability of the service and its information. Those needs depend on business impact, system design, and current threats.

Controls need evidence, not promises. Residual risks also need a named authority who understands and accepts their possible impact.

Why keep privacy and security connected?

Privacy and security risks often share systems and controls, but they ask different questions. Treating them together exposes gaps without collapsing one into the other.

Both assessments change as the service, data, vendors, and threats change. They remain living records instead of one-time launch paperwork.

What you leave with

The Privacy Impact Assessment explains the personal information, its purpose, its handling, and the risks to affected people.

The security threat-risk assessment records assets, threats, controls, evidence, and residual risks. Required mitigations become prioritized roadmap work with clear owners.

Further Reading

  • - Complete privacy and security assessments early, then update them throughout the service lifecycle.
  • - Establish threats, legal duties, controls, accountable leaders, and lifecycle security funding.
  • - Identify assets and threats, prioritize risks, select controls, and document residual risk.
  • - Minimize collection and retention while explaining purpose and legal basis clearly.
  • - Combine threat modelling, risk assessment, security controls, and privacy impact assessment.
  • - Apply privacy guidance and required deliverables across every initiative stage.
  • - Determine when a PIA applies and document risks, mitigations, and approvals.
  • - Collect only necessary personal information under clear authority and notice.
  • - Manage privacy risk through a reusable enterprise framework and shared outcomes.
  • - Model systems, identify threats, plan mitigations, and review security decisions throughout development.
NextTraining and Change Management