Skip to main content

Privacy control atlas

Privacy & Data Governance: from risk to evidence

A practical map from Canadian privacy obligations to operating controls, accountable owners, and proof that the controls work.

Privacy programs lose leverage when ownership, inventories, and evidence live in separate places.

PIPEDAQuebec Law 25GDPR readinessPIA / DPIA practice

PRV-01 · Control 1

Accountability

Named owners can make and document risk decisions.

Accountable owner
Privacy or governance lead
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for accountability.
  • Developing: Run accountability consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve accountability through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Privacy governance charter
  • RACI for high-risk processing
  • Decision and exception log

PRV-02 · Control 2

Data inventory

Teams can locate personal information, purposes, processors, and retention rules.

Accountable owner
Data governance lead
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for data inventory.
  • Developing: Run data inventory consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve data inventory through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Record of processing activities
  • System and data-flow inventory
  • Retention schedule

PRV-03 · Control 3

Impact assessment

New processing is assessed before launch, not after an incident.

Accountable owner
Privacy lead with product owner
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for impact assessment.
  • Developing: Run impact assessment consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve impact assessment through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • PIA/DPIA intake
  • Risk acceptance record
  • Remediation tracker

PRV-04 · Control 4

Third-party risk

Vendor decisions are tiered, repeatable, and reviewable.

Accountable owner
Vendor risk or procurement lead
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for third-party risk.
  • Developing: Run third-party risk consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve third-party risk through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Vendor inventory
  • SOC 2/security review
  • Contract and reassessment record

PRV-05 · Control 5

Consent and preference

People receive meaningful choices that match the purposes and data uses the organization actually operates.

Accountable owner
Privacy or product owner
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for consent and preference.
  • Developing: Run consent and preference consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve consent and preference through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Consent and preference design
  • Consent records
  • Withdrawal and change path

PRV-06 · Control 6

Retention and minimization

Personal information is collected, accessed, and retained only for defined purposes and periods.

Accountable owner
Data governance or records lead
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for retention and minimization.
  • Developing: Run retention and minimization consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve retention and minimization through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Retention schedule
  • Deletion or disposal records
  • Data minimization review

PRV-07 · Control 7

Breach readiness

The organization can identify, escalate, assess, and document a privacy incident under time pressure.

Accountable owner
Privacy and security incident lead
Review cadence
Review at least annually and after a material change.

Maturity path

  • Foundational: Establish ownership, a documented workflow, and initial evidence for breach readiness.
  • Developing: Run breach readiness consistently with review cadence, metrics, and exception handling.
  • Advanced: Continuously improve breach readiness through automation, testing, and executive reporting.

Test method: Review current evidence with the accountable owner and record exceptions.

Evidence to look for

  • Incident response playbook
  • Tabletop exercise record
  • Breach decision log

Questions to ask internally

  • Who owns privacy risk decisions?
  • Can you produce a current data inventory?
  • Are PIAs triggered before high-risk launches?
  • Can people change or withdraw preferences?
  • Which data is retained longer than its purpose requires?
  • When did you last test breach escalation?
  • Which vendor reviews are overdue?