Service 2 · done for you

PIA and Privacy Support.

MFIPPA will generally require a written PIA before you collect personal information, unless the regulations provide otherwise. Not a template and a training session: Tectonix scopes the assessment, maps the data flows, weighs the risks, and hands you a completed PIA ready for sign-off.

The problem it solves

A PIA is a substantial new workload, and often the hardest to resource in-house.

A PIA is generally triggered when a new collection of personal information is contemplated (new software, a new form, a new program, a new camera), subject to any exceptions the regulations provide, and an existing PIA must be updated before a significant change to the purpose for which the information is used or disclosed. Completing one to the standard the law expects takes a method most small institutions have never had to build. Tectonix works to a consistent PIA process, so a PIA becomes a deliverable you order rather than a project you staff.

Source: MFIPPA, current consolidation, as amended by Bill 97, Schedule 11, in force January 1, 2027. The privacy impact assessment duty is section 28 (3); the safeguards duty is section 30 (5); breach reporting to the Commissioner and notification to the individual are section 30.1. Each is a duty of the institution's head.

Scope

What a PIA engagement covers.

What's included

  • Scoping the assessment: what collection or system is in question and what personal information it touches.
  • Documenting the institution's stated legal authority for the collection, use, and disclosure, and flagging legal questions for its legal services.
  • Mapping the data flows: how information is collected, used, disclosed, retained, and disposed of.
  • Identifying privacy risks, the safeguards in place, and the practical mitigations to close the gaps.
  • A completed, written PIA report covering the statutory elements, suitable for internal sign-off and for the IPC if asked.
  • A quick screening call before anything is scoped, so a full PIA is only quoted when one is actually needed.

What's not included

  • Legal advice or legal opinions. Where a question is legal, the engagement flags it and involves your institution's legal services.
  • Processing freedom-of-information requests. That duty sits with the institution's head under MFIPPA.
  • Building or remediating IT systems. Mitigations are recommended, not implemented.
  • Acting as the statutory "head" under MFIPPA. That designation stays with the institution.

Choose a shape

One assessment, or ongoing support.

Most institutions start with a single PIA engagement. If you expect recurring questions or new collections and have nobody in-house to carry the work between them, choose annual privacy support instead. Each PIA is still scoped and quoted separately.

Single engagement

  • One PIA, fixed scope and fixed price, quoted before the work begins.
  • Everything in the scope above, delivered as a written report you own.
  • No commitment beyond the engagement. Commission the next one when you need it.

Ongoing

  • Practical, non-legal privacy advice during Ontario business hours, as often as you need to ask, based on the facts you provide. Every request is acknowledged within one Ontario business day. Independent research, substantive document review, or a working session is scoped and quoted before it begins.
  • PIA screening before you commission a full assessment, so you only pay for the ones you actually need.
  • An annual review of your readiness gap list, breach-response plan, PIA process, and privacy-policy boilerplate. New policies and material rewrites are quoted before work begins.
  • Support preparing your annual IPC statistical report of breaches reported to the IPC.
  • One staff briefing each year for your designated staff, plus a one-page annual summary for council or the board.
  • The annual fee covers the support listed here. PIAs are scoped and quoted separately, at a rate below the single-engagement price.
  • New to Tectonix? A paid onboarding engagement includes the readiness assessment and readout. After the readout, you may choose a one-year annual arrangement; renewal is by agreement.

Advice means answering your questions. Where the answer needs to become a document, a policy, a contract review, or a PIA, that is quoted as work and you decide before it starts. Breach response is available separately, so institutions that already run incidents through their own IT and legal teams are not paying for something they do not need.

What Tectonix needs from you

Access, not effort.

The program owner

Time with whoever owns the collection or system being assessed, to understand how it really works.

System & vendor detail

Documentation for the software or vendor involved, and any contracts that govern how they handle personal information.

Sign-off authority

The person who will accept the finished PIA on the institution's behalf, so the deliverable lands where it needs to.

Most institutions start with the readiness assessment.

The readiness assessment tells you which collections need a PIA and in what order, so PIA work is targeted rather than guessed at. If you already know what needs assessing, start here.