We offer independent, privileged privacy impact assessments for large and mid-size enterprises.
We are retained by internal privacy, legal, and security teams that need a third-party assessment, whether to satisfy a regulatory obligation, answer a customer requirement, or add qualified capacity to a program that is already fully committed.
Business Case
- 01A proactive privacy impact assessment (PIA) or data protection impact assessment (DPIA) is a compliance prerequisite in a growing number of jurisdictions.
- 02Enterprise customers and procurement teams increasingly require documented evidence of a privacy risk assessment before new software handling sensitive information goes into production.
- 03Independence is often required, either because a regulator or customer expects an arm’s-length assessor, or because the internal privacy team is at capacity and needs the work done without adding headcount.
- 04Running privacy, security, and AI risk assessments as separate exercises duplicates effort. A single assessor qualified in both privacy and security removes that overlap.
A custodian must prepare a privacy impact assessment and submit the privacy impact assessment to the Commissioner for review and comment (a) before introducing a new administrative practice or information system relating to the collection, use and disclosure of individually identifying health information; (b) before changing an existing administrative practice or information system relating to the collection, use and disclosure of individually identifying health information, or (c) as otherwise required under this Act.Representative requirement — Alberta Health Information Act, s.64
Background
Risk management has moved from a vague corporate buzzword to a prescriptive regulatory and contractual requirement. Participation in modern supply chains now assumes that privacy risks are identified proactively, by trained professionals, and that the resulting treatment decisions are documented. Privacy impact assessments have become standard assurance documentation for handling sensitive data. Assess your risks. Show your work.
Services
We deliver assessments as a privileged legal opinion, supported by risk-based privacy and security expertise rather than a formulaic questionnaire. We select frameworks and reporting models to match the laws that apply to you and the requirements your customers have put in writing.
- Statutory Privacy Impact Assessments (PIAs) Assessment against the statutory requirements that apply in your jurisdiction, mapped to your existing privacy program so findings arrive in a form your team can action and file.
- Article 35 GDPR Data Protection Impact Assessments (DPIAs) Article 35 GDPR assessments for processing likely to result in a high risk to data subjects, including the necessity, proportionality, and consultation record a supervisory authority expects.
- Automated decisions Algorithmic Impact Assessments (AIAs) Assessment of automated decision-making systems, covering model and training data provenance, human oversight, transparency obligations, and the AI-specific harms a conventional PIA does not reach.
- One engagement, one report Converged Privacy & Security Assessments One engagement covering both domains. We hold both privacy (CIPP/C) and security (CISSP) credentials, so overlapping controls are assessed once, in a single report, rather than twice by two providers.
Threat Risk Assessments (TRAs) are covered on a separate page. Where privacy and security are both in scope, the converged assessment above delivers them as a single engagement and a single report.
Qualifications & Experience
Qualifications
- Certified Information Privacy Professional / Canada (CIPP/C) — International Association of Privacy Professionals, 2020
- Fundamentals of OCAP Certification (Indigenous Data Sovereignty) — First Nations Information Governance Centre, 2026
- Certified Information Systems Security Professional (CISSP) — ISC2, 2026
- Certificate of Cloud Security Knowledge (CCSK) — Cloud Security Alliance, 2021
- Practising Lawyer — Law Society of British Columbia, 2009
- Degrees in computer science (Queen’s University) and management information systems (LSE)
Experience
- 18+ years of professional services experience with technology companies. Six years in internal roles and twelve as a third-party service provider.
- Completed internal and external PIAs ranging from targeted assessments of a single system to comprehensive cross-organization reviews.
- Specific focus on regulated industries including healthtech, fintech, and legal tech.
- Agile engagement model. You work directly with the assessor from scoping through final report, with no junior staff layered in and no internal review queue between you and an answer.
Pricing
Project-based pricing reflects the professional services time an engagement requires. Considerations include:
- Scoping complexity
- On-site requirements & travel
- Applicable frameworks
- Reporting requirements
- StructureWe quote a fixed fee following completion of a short scoping exercise, so the cost is known before work begins. We also respond to formal requests for proposals.
- BudgetsOur pricing is not prohibitive for an in-house team working to a set number. Where a budget has already been approved, we can generally tailor scope, framework depth, and reporting format to fit it without compromising the defensibility of the assessment.
Getting Started
Send us the system, project, or vendor you need assessed and any deadline you are working to. A short scoping call is usually enough to confirm the applicable framework, the level of assessment required, and a fixed fee.
Assessments sit where three practices meet. The same lawyer who negotiates your data processing terms and advises on your AI governance program runs the assessment — drawing on Privacy Law, Information Security, and AI Governance.