Insight

When Is a PIA Legally Mandatory? GDPR vs LGPD vs PIPEDA vs Quebec Law 25

July 29, 2026


"Is a PIA actually required for this project, or is it just good practice?" is one of the first questions any privacy team has to answer, and the honest answer is: it depends on which law applies to you. The GDPR, Brazil's LGPD, Canada's PIPEDA, and Quebec's Law 25 all converge on the same underlying idea — high risk to people's rights and freedoms is what triggers the obligation — but they draw the actual legal trigger in different places, with very different consequences for getting it wrong.

Brazil: The LGPD and ANPD Resolution No. 2/2022

Under Article 38 of Brazil's LGPD, the national data protection authority — the ANPD — may order a controller to produce a Data Protection Impact Report, the RIPD, including for operations involving sensitive data. ANPD Resolution No. 2/2022 sets out, in Article 4, a cumulative test for when processing counts as "high risk" and therefore requires one: an activity qualifies when it meets at least one general criterion (large-scale processing of personal data, or processing that may significantly affect individuals' rights) together with at least one specific criterion (emerging technologies, large-scale monitoring of public areas, automated decision-making and profiling, or processing sensitive or vulnerable groups' data, such as children, adolescents, or the elderly).

Brazilian case law has already treated a missing or inadequate RIPD as a live liability issue. In February 2025, Brazil's Superior Tribunal de Justiça (STJ), in REsp 2.121.904/SP, ruled that the leakage of sensitive personal data in a life insurance contract — including health and financial records — automatically triggers the controller's objective liability and results in presumed moral damages, even without proof of concrete harm. The exposure itself, the Court held, undermines dignity, reputation, and personal security. Neglecting a RIPD in a high-risk scenario, in other words, is not a technical lapse; it is a direct basis for civil liability.

Canada: PIPEDA Doesn't Say "PIA" — the Case Law Does the Work

Canada's PIPEDA does not expressly require Privacy Impact Assessments in the private sector. What it establishes, in section 10.1, is a breach notification duty whenever there is a "real risk of significant harm" to individuals — a standard that reaches financial loss and identity theft, but also humiliation, reputational damage, and harm to relationships. In the federal public sector, the Treasury Board Secretariat's Directive on Privacy Impact Assessment does make a PIA mandatory whenever a new or substantially modified program involves personal information, and the Office of the Privacy Commissioner reviews those reports while encouraging private entities to adopt similar practices voluntarily.

Three cases show how Canadian courts have filled that gap. In Eastmond v. Canadian Pacific Railway, 2004 FC 852, the Federal Court set out a reasonableness test for workplace surveillance — was the data collection necessary, proportionate, effective, and the least intrusive means available — a framework that remains the standard reference point for privacy practices under PIPEDA. In A.T. v. Globe24h.com, 2017 FC 114, the Federal Court found that a Romanian website's republication of Canadian court decisions online, indexed so they surfaced in search engines, violated PIPEDA; the Court emphasized the reputational harm and lack of consent involved, and confirmed that PIPEDA applies extraterritorially wherever there is a "real and substantial connection" to Canada. And in G.D. v. South Coast British Columbia Transportation Authority, 2024 BCCA 252, the BC Court of Appeal revived a proposed class action after a cyberattack exposed employees' and customers' social insurance numbers and banking data — holding that custodians who fail to safeguard entrusted data can be liable under the provincial Privacy Act and in negligence, even where the breach was carried out by third-party hackers, and expanding the meaning of "wilful" to include reckless omissions.

Together, these cases carry a consistent message: even without a formal statutory PIA obligation, organizations operating in Canada are expected to have already done the risk-identification work a PIA would have produced — and courts are willing to impose liability, including for harms that are reputational rather than purely financial, when they didn't.

Quebec's Law 25: The Only Jurisdiction With a General Private-Sector PIA Mandate

Quebec's 2021 Act to Modernize Legislative Provisions Respecting the Protection of Personal Information — Law 25 — is the first Canadian law to impose a general legal obligation for PIAs on the private sector, applying to "any person carrying on an enterprise." Under section 3.3 of the Private Sector Act as amended by Law 25, an enterprise must conduct a PIA in four specific scenarios: when acquiring or overhauling an information system; when developing or redesigning an electronic service delivery system; before disclosing personal information outside Quebec, whether to another province or internationally; and when communicating personal information without consent for study, research, or statistical purposes.

The law's oversight body, the Commission d'accès à l'information (CAI), can investigate, demand documentation including completed PIAs, and issue corrective orders — including suspending processing until a compliant PIA exists. Its sanctions are among the most severe in North America: administrative monetary penalties can reach $50,000 for individuals and up to $10 million or 2% of worldwide turnover for organizations, while penal provisions go further still, with fines from $5,000 to $100,000 for individuals and up to $25 million or 4% of global turnover for organizations — plus civil liability, with punitive damages available for intentional or grossly negligent violations.

Side by Side

  • GDPR (EU, Art. 35): mandatory whenever processing is likely to result in high risk to individuals' rights and freedoms — large-scale sensitive data, systematic monitoring, or significant profiling — with the threshold spelled out directly in the regulation.
  • LGPD (Brazil, Art. 38 + ANPD Resolution 2/2022): the ANPD can compel a RIPD when a general criterion (scale or significant effect on rights) combines with a specific one (emerging tech, monitoring, automated decisions, or vulnerable-group data); the STJ has already tied a missing report to automatic civil liability.
  • PIPEDA (Canada, federal): no explicit statutory PIA trigger in the private sector — mandatory only for federal institutions under the Treasury Board Directive — but case law (Eastmond, Globe24h.com, G.D. v. South Coast BC) shows courts imposing liability for the risk analysis a PIA would have caught anyway.
  • Law 25 (Quebec): the only general private-sector PIA mandate in Canada, triggered automatically by four defined project types, backed by administrative penalties up to $10 million / 2% of turnover and penal fines up to $25 million / 4% of global turnover.

The Practical Takeaway

High risk, across all four frameworks, is measured from the standpoint of the person affected — the likelihood of financial, reputational, or dignitary harm to them — not the size or intent of the organization processing their data. Organizations only face liability and fines because they failed to protect those individuals in the first place. If your organization operates across more than one of these jurisdictions, the practical floor is Quebec's project-based trigger: treat any new system, service redesign, or cross-border data disclosure as PIA-worthy by default, rather than waiting to see whether the GDPR's "high risk" test or the ANPD's discretionary order would independently require one.

Knowing which law applies to a given project is the first step. Actually running the assessment — in a way a regulator or a court would recognize as diligent and rigorous, not a form filled out after the fact — is the harder part, and it's exactly what the rest of this series, and the book it's drawn from, is built to walk through.


← Back to Privacy Impact Assessment Basics