Skip to content
Cogio
Compliance· 12 min read· by Alexandre Sauvageau

The privacy impact assessment, demystified: how to assess an AI project before you deploy it

The privacy impact assessment explained step by step: when it is required, who runs it, the concrete stages, and transfers outside Quebec.

Glasses and a calculator resting on analysis reports
Photo: Bia Limova, Pexels

When the assessment is required: almost every AI project

Section 3.3 sets out three triggers: the acquisition, the development and the redesign of an information system or an electronic service delivery system involving personal information. In practice an AI project almost always ticks at least one box.

Take a manufacturer in Granby that wants a quoting assistant: past projects contain client names, email addresses, signatures, sometimes employee data. As soon as a system touches information that makes it possible to identify a person, directly or indirectly, the assessment is required before deployment. And your employees’ data counts every bit as much as your clients’.

  • Acquisition: you sign the company up to an AI tool in SaaS form (writing assistant, meeting transcription, customer service agent).
  • Development: you build an internal assistant, for example a question-and-answer system plugged into your procedures, your quotes or your HR files.
  • Redesign: you add an AI module to an existing system, such as automatic summarization in your CRM or your ERP.

Who runs the assessment, and with whom

The Act names a conductor: the privacy officer, who has to be consulted at the very start of the project. By default that role falls to the person with the highest authority in the business, often without their knowing it. If you have never formally delegated the function, your president is carrying it today.

Around that person, a small team is enough: the project owner on the business side (the one who knows what data actually moves), an IT representative and, if an external supplier is involved, someone tasked with collecting their written answers on hosting, subcontracting and data use. It remains prudent to get legal advice on the complex cases, transfers outside Quebec in particular. But most assessments for internal projects are run in-house, with a rigorous grid and a bit of method.

The four stages of a well-run assessment

Stage one: map the flows. What personal information enters the system, where does it come from, where is it stored, who has access, which third parties does it move to, and how long is it kept? If you already maintain the personal information register Law 25 requires, you have a head start: the assessment is its natural extension, project by project.

Stage two: assess the risks. For each flow, estimate the likelihood and the seriousness of a privacy breach. The typical risks in an AI project: information leaking through the queries sent to a supplier, re-identification of people from poorly de-identified data, an assistant revealing HR information to an employee who should not see it, or your data being reused to train a third party’s model. That last point deserves particular attention: reusing personal information to train a model amounts to a new purpose, which needs its own legal basis.

Stage three: choose the mitigation measures. Minimizing collection, redacting personal information before processing, role-based access control, encryption at rest and in transit, query logging, human sign-off before any action that affects a person. Every risk identified at the previous stage has to find its answer, or be explicitly accepted by management.

Stage four: document. A dated report recording the scope, the flows, the risks, the measures chosen, the residual risks and the final decision. That document is revised whenever the system changes significantly: new supplier, new data source, new feature. It is the one you will produce if the CAI examines your practices.

The simplified grid: eight questions before any deployment

Here is the starting grid we use to frame a first conversation. It does not replace a full assessment, but it has one virtue: if you cannot answer one of these eight questions, you are not ready to deploy.

Simplified assessment grid for an AI project
QuestionWhyExample
What personal information will the system process?To set the scope and apply minimizationAn HR assistant reaches employee names, salaries and reviews
For exactly what purposes?Collection and consent have to target specific purposesAnswering questions about internal policies, nothing more
Where is the data hosted and processed?Any processing outside Quebec triggers the section 17 assessmentA server on your premises or an API in Virginia: two legal worlds
Who will have access, and how?Role-based access control and logging are requiredThe estimator sees the quotes, not the employee files
Is the data used to train a model?A new purpose calls for a new legal basisA SaaS that “improves its services” with your client data
What harm follows an incident?The heart of the assessment: likelihood and seriousnessSalary data leaked, re-identification, a wrong answer given
What measures reduce those risks?Every risk needs a documented mitigationRedaction before processing, encryption, a human in the loop
How long is the data kept?Destruction or anonymization once the purpose is fulfilledPurging meeting transcripts after the period you set

Transfers outside Quebec: section 17 changes the picture

Section 17 adds a separate requirement: before disclosing personal information outside Quebec, a business must carry out an assessment that considers, among other things, the sensitivity of the information, the purpose of its use, the protective measures and the legal regime applicable in the destination state. The disclosure can only take place if the assessment demonstrates adequate protection, and it must be the subject of a written agreement.

This is where many AI projects stumble. Sending extracts of client files to an AI API hosted in the United States is a disclosure outside Quebec. Using an American SaaS with no prior assessment is among the most common non-compliances found in Quebec businesses. And physical location does not settle it: under the CLOUD Act, a 2018 American statute, an American-owned provider can be compelled to hand over data even when it is stored in Canada. What counts is the owner’s jurisdiction, not the data centre’s address.

What a sovereign architecture changes about the exercise

Every flow that leaves your perimeter adds a layer to the assessment: a processor to govern by contract (s. 18.3), a foreign legal regime to analyze, a written agreement to negotiate. Conversely, when the AI model runs on a server on your premises or with a Quebec host under your control, whole sections of the assessment fall away on their own: no transfer outside Quebec, so no analysis under section 17; no model provider receiving your data; and a verifiable guarantee that your information is never used to train a third party’s model.

To be clear: the assessment stays mandatory, and hosting on your own premises exempts you from nothing. But the nature of the exercise changes. You document measures you control (redacting personal information before processing, role-based access, an audit log of queries) rather than weighing the contractual promises of a supplier you cannot verify. For an SME with no in-house lawyer, that is often the difference between a few days of structured work and weeks of contractual back-and-forth.

Where to start this week

Three concrete moves to get going. First, confirm who your privacy officer is and publish their title and contact details on your site: that obligation has been in force since September 2022, and this is the person who will carry the assessment. Next, inventory the AI projects underway, including the tools your employees use without approval: each one is a potential section 3.3 trigger. Finally, take the most advanced project and run it through the eight-question grid above; the holes you find are your work plan.

To place the assessment within the wider effort, see our complete guide to Law 25 compliance and our 12-step checklist. And if you would rather have support, our approach always starts with an audit that includes mapping personal information flows: exactly the first stage of an assessment.

Frequently asked questions

Is a privacy impact assessment required for a small business?

Yes. Law 25 applies to every business that holds personal information in Quebec, with no size or revenue threshold. The assessment is proportionate, though: for a small project handling data of low sensitivity, a documented assessment of a few pages can be enough.

Is an assessment required for a pilot or a proof of concept?

As soon as the pilot handles real personal information, yes, because section 3.3 covers the development of the system, not only putting it into production. A prudent practice is to run the pilot with redacted or fictitious data, then carry out the assessment before opening access to real data.

Do we have to send the assessment to the Commission d’accès à l’information?

No, the Act requires no systematic filing with the CAI. The business must, however, be able to show that the assessment was carried out if the Commission examines its practices or investigates after an incident. Hence the importance of a dated report, kept on file.

How long does an assessment take for an AI project?

It depends on the scope. For an internal assistant hosted in Quebec whose flows are well mapped, a few days of structured work is often enough. A project involving transfers outside Quebec or sensitive data calls for more analysis, in particular the review of the destination state’s legal regime that section 17 requires.

Does using an American AI tool such as a public chatbot trigger section 17?

If personal information is typed into it, yes: that is a disclosure outside Quebec, which requires a prior assessment demonstrating adequate protection, along with a written agreement. It is one of the most common non-compliances seen in Quebec businesses.

What does a business risk by deploying without an assessment?

The absence of an assessment is a failure the CAI can target directly with an administrative monetary penalty of up to $10M or 2% of worldwide revenue. If an incident involving personal information occurs, the absence of a prior assessment will also weigh in the analysis of fault, including for the private right of action available to the people concerned.

Sources and references

This article is a plain-language summary, accurate as of the date shown. It is not legal advice: for your own situation, consult a legal adviser or contact the Commission d’accès à l’information.