Risk Assessment Directive

Context

The Information Assets of Office of the Information and Privacy Commissioner (OIPC) are subject to varying levels of risk depending on their nature, sensitivity, and use. Effective risk management requires that risk be assessed consistently, using recognized instruments, and that the results of that assessment inform decisions about the treatment and acceptance of risk.

Purpose

This directive establishes the process for assessing risk to Information Assets through Privacy Impact Assessments and Threat Risk Assessments, and to ensure that assessed risk is reflected in the IM/IT Risk Register.

Application

This directive applies to all employees or third-party service providers of the OIPC.

References

POPA, POPR, POPA MReg, Information Governance Policy, Information Risk Management Policy

Directive Statements

  1. Where a Privacy Impact Assessment or Threat Risk Assessment is required under the Information Risk Management Policy, the instrument selected is determined in accordance with that Policy.
  2. Where a substantial change is made to an administrative practice, program, project, or service for which a PIA has already been completed, the existing PIA may be amended to address the change, rather than completing a new PIA, provided the amended PIA continues to meet applicable requirements under POPA and its regulations.
  3. A PIA or TRA is drafted by the owner of the initiative, project, or Information Asset under assessment:
    • A PIA must be prepared in accordance with the requirements of POPA and its regulations. The Privacy Officer supports the drafting of PIAs.
    • A TRA must be prepared in accordance with the Threat Risk Assessment template maintained by the Director, IM/IT, as amended from time to time. The Director, IM/IT supports the drafting of TRAs.
  4. Every completed PIA and TRA must be reviewed and signed off by the Information and Privacy Commissioner to confirm its completion.
  5. Once signed off, the Director, IM/IT logs the PIA or TRA, its identified risks, and any residual risk in the IM/IT Risk Register.
  6. For any PIA completed by the OIPC as a public body and that must be submitted to the Information and Privacy Commissioner under section 7(5) of the Protection of Privacy (Ministerial) Regulation, the Commissioner is responsible to identify a third party to exercise the Commissioner’s function under that section.

Roles and Responsibilities

Information and Privacy Commissioner

Reviews and signs off on every completed PIA and TRA.

Takes the necessary steps to ensure a third party exercises the Commissioner’s PIA review function, as applicable.

Director, IM/IT

Maintains the TRA template.

Supports the drafting of TRAs.

Logs completed PIAs and TRAs, their identified risks, and any residual risk in the IM/IT Risk Register.

Privacy Officer

Supports the drafting of PIAs.

Employees and third-party service providers

Support the drafting of PIAs or TRAs, as applicable.

Monitoring and review period

This directive will be reviewed and updated every two years or as required.

Approval

This directive was approved by the Information and Privacy Commissioner on September 21, 2026 and is in effect.