AI tools Require Privacy Impact Assessments
This section now fully incorporates TRU’s official PIA flowchart and PIA form. (References: PIA Flowchart V1, PIA Template August 2024)
AI tools are software services. These services must abide by TRU policies of acceptable use, TRU purchasing policies, legal, and regulatory requirements.
If a staff member wants to use any AI tool other than Copilot, and the tool may collect or process:
- Student personal information.
- Employee personal information.
- Vendor or contractor personal information.
- Any TRU-owned personal information.
Then a Privacy Impact Assessment (PIA) is required.
TRU’s PIA Process Flowchart
Privacy Impact Assessment (PIA) Decision Checklist (Simplified)
(Based on TRU’s PIA Flowchart, attached above)
You must complete a PIA if:
- The AI tool collects or processes Personal Information as defined in Freedom of Information and Protection of Privacy Act (FIPPA).
- The tool is cloud-based (not on-premises).
- You have not verified where data will be stored.
- You have not read or understood the vendor’s Terms of Use.
- Consent is not already collected.
- The tool involves data linking between systems.
- The initiative is a cross-departmental program involving Personal Information.
- The Software stores or transmits information outside of Canada.
- You are unsure whether the collection is authorized under Freedom of Information and Protection of Privacy Act (FIPPA) s.26(c)
If ANY of the above is true -> a PIA is required
This aligns perfectly with TRU’s flowchart instructions. If you are unsure whether your initiative requires a PIA, please contact the Privacy Office at privacy@tru.ca or you can contact the Information Security at InfoSecurity@tru.ca
