Skip to main content

Privacy Impact Assessment and AI System Asessment

Using AI at Ontario Tech?

  1. Find approved tools through IT Services.
  2. Review privacy and governance requirements through the  Privacy Office.
  3. Complete AI training through the Future Ready! AI Training Program.

Privacy Impact Assessment 

Under the Freedom of Information and Protection of Privacy Act (FIPPA), Ontario Tech must complete a Privacy Impact Assessment (PIA) before collecting personal information (PI), or when a substantial change is made to how we intend to collect, use, store or otherwise process personal information. PIAs are normally required when contracting with a vendor to acquire software, whether or not there is a cost associated with the contract.

PIAs consider the following:

Vendor Contract

Safeguards

University Practices

FIPPA Compliance

Limits on vendor use of PI

Rules for sub processors

Data ownership

Data breach protocol

Vendor policies and practices

Technical safeguards

Independent review of Vendor safeguards and practices

Complementary safeguards

User training

Retention and disposal

Data minimization

Necessity of PI

Notice of Collection

Legal Authority

Consistent Usage

The goal is to generate recommendations to better ensure the privacy of our stakeholders, including providing a notice of collection, minimizing the personal information involved, activating security features where available and/or making sure there are adequate contractual protections in place.

PIAs support Ontario Tech’s strategic priority of “Tech with a Conscience”, promoting the ethical use of technology to enhance our academic and administrative service offerings while ensuring that stakeholders’ rights and expectations of privacy are respected and upheld.

To initiate a PIA please fill out our online assessment request form. For more information please contact accessandprivacy@ontariotechu.ca 


Artificial Intelligence System Assessment

The Privacy Office supports the responsible use of Artificial Intelligence (AI) by conducting Algorithmic Impact Assessment (AIA) on proposed new systems or software with AI features, including AI features added to existing systems. The AIA builds on but does not replace the PIA, and many of the requirements for contractual protections and technical security overlap.

The goal of the process is to build tust by ensuring there is a strong AI risk framework in place.

  • A strong AI risk framework ensures ethical, fair, and secure AI system development and deployment.
  • Comprehensive risk assessment helps identify potential AI system vulnerabilities and ethical concerns early.
  • Applying mitigation measures fosters trust and promotes responsible AI adoption by organizations.

AIAs consider the following risk areas:

Algorithm Risk Decision Risk Impact Risk Data Risk

Transparency and Explainability

Human Oversight

Bias and Fairness

Accuracy, Reliability and System Performance

Rights and Freedoms Impact

Reversibility and Duration of Decisions

Intellectual Property

Privacy and Confidentiality

Information Security

An AIA gives requirements for compliance and recommendations to mitigate risk. The conclusion of an AIA will identify areas areas where the university is at risk for non-compliance with applicable laws and residual risks in the use of the system. It will also provide recommendations for best practices to mititage the risks identified in the AIA. An AIA will normally be limited in scope and will identify potential uses that are not permitted and/or will require additional review.

To initiate an AIA please fill out our online assessment request form. For more information please contact accessandprivacy@ontariotechu.ca 

  • What information do I need to provide to start the assessment process?

    We ask that you provide the information listed below as a starting point. Please submit the information to accessandprivacy@ontariotechu.ca.

    1. Vendor agreements and terms of service; (a copy of the draft agreement between the University and Vendor)
    2. Vendor privacy policies;
    3. Vendor information regarding security and privacy;
    4. Information regarding any partners involved in the provision of the service (e.g. any cloud storage platform used for storing personal information)
    5. Audit certificates and reports related to vendor security and privacy (e.g. SOC 2 Report, ISO certification, HECVAT)
    6. A description of the personal information involved and the number of individuals and what constituent groups they come from (e.g. students from a particular faculty, employees, alumni).
    7. A description of the integration with any existing systems, and any personal information transferred to/from those systems (e.g. integration with the LMS or Banner systems.)
    8. A contact at the Vendor in case we have any further questions.
  • What is Personal Information?

    What is Personal Information?

    Personal information is defined under FIPPA. It means recorded information about an identifiable individual. This can include, but is not limited to:

    • an individual’s biographical details (name, sex, age, race)
    • an individual’s biological details (face, fingerprints, blood type, etc.)
    • nationality
    • religion
    • marital status
    • education
    • medical or criminal history
    • financial information
    • identifying numbers, for example, Social Insurance Numbers
    • an individual’s contact details (personal address, phone number, etc.)
    • personal opinions and views.
  • What AI systems am I allowed to use?

    Only University-contracted AI tools should be used. Users should not use their own personal AI tool accounts for University business. This includes paid accounts. Business accounts procured by the Unviersity generally offer enhanced protection and greater restrictions on the vendor's use of data processed by the AI tool.

    IT Services maintains a list of approved AI tools [LINK TBA] that have been procured by the University and reviewed by the Privacy Office. Please review the approved purposes and any restrictions associated with the tools and contact the Privacy Office at accessandprivacy@ontariotechu.ca before using a tool outside of the approved purposes.

  • How can I use AI systems responsibly?

    Human Resources outlines requirements when using AI tools in your work and will make training available on the responsible use of AI tools [LINK TBA]. 


If you have any questions or concerns, please contact the Privacy Office at accessandprivacy@ontariotechu.ca.