Bylaw Privacy Impact Assessment - Saguenay

Technology and Data Quebec 3 Minutes Read · published May 26, 2026 Flag of Quebec · By Daniel Roy

Saguenay, Quebec project teams that design or operate municipal services must assess privacy risks early. This guide explains when a privacy impact assessment (PIA) is recommended for city-run projects, the practical steps municipal staff and contractors should follow, and how to document decisions so they align with municipal practice and provincial requirements. Use this article to plan assessments for IT systems, service delivery changes, sensors or cameras, and data-sharing arrangements with vendors or other public bodies.

When to perform a PIA

Conduct a PIA when a project will collect, use, retain, disclose or centralize personal information in a new way, when introducing new surveillance or sensor technology, or when a vendor will process personal data on behalf of the City.

Start PIAs at the project design phase, not after deployment.

Step-by-step PIA process (municipal focus)

  • Inventory data: list categories of personal information, purpose and data flows.
  • Assess necessity and proportionality: confirm legal basis and minimize data collected.
  • Identify risks: threats to confidentiality, integrity and availability and risks to individuals.
  • Design mitigations: technical, organizational and contractual controls with vendors.
  • Approve and budget: include ongoing operational costs for security and retention.
  • Document and review: keep the PIA report with the project file and review after major changes.
Keep a short executive summary of the PIA suitable for council or public posting.

Penalties & Enforcement

Municipal PIA practice is enforced through the City administration and applicable provincial legislation. Specific municipal fines or monetary penalties for failure to complete a PIA or for privacy breaches are not specified on the City pages commonly used for public procedures; provincial enforcement and fines are defined by Quebec law and provincial authorities for public bodies when applicable, current as of May 2026.

  • Fine amounts: not specified on the cited page.
  • Escalation: first, repeat or continuing offence ranges are not specified on the cited page.
  • Non-monetary sanctions: orders to cease processing, directions to correct practices, administrative reviews and potential court actions may apply under provincial authority.
  • Enforcer: the City administration (responsible service) handles municipal compliance and the provincial oversight body handles statutory enforcement and appeals.
  • Inspection and complaints: file complaints with the municipal contact or the provincial access and privacy authority; timelines and forms are not specified on the cited municipal pages.
If a breach occurs, notify the municipal privacy contact and follow provincial breach reporting obligations without delay.

Applications & Forms

The City does not publish a standardized municipal PIA form on its general public pages; project teams should contact the City service responsible for information technology or by-law administration to confirm local requirements or to obtain internal PIA templates.

Common violations

  • Collecting unnecessary personal data without documented purpose.
  • Failure to include privacy terms in vendor contracts or data-sharing agreements.
  • Deploying surveillance or cameras without an impact assessment or signage.

Action steps for municipal teams

  • Start a PIA checklist during project initiation.
  • Contact the City IT or privacy lead to request any internal template.
  • Document decisions and retain PIA records with procurement files.

FAQ

When does a municipal project need a PIA?
A PIA is recommended when personal information is collected, when new surveillance is introduced, or when data processing by a vendor is required.
Who approves a PIA within the City?
The responsible service or departmental head approves PIAs; consult the municipal IT or legal service for local approval routes.
Are PIA reports public?
Publication depends on municipal policy and confidentiality concerns; check with the City’s records or communications service.

How-To

  1. Identify whether the project handles personal information and the categories involved.
  2. Perform a risk assessment focusing on likely harms to individuals and data flows.
  3. Design controls and update contracts with vendors to include privacy obligations.
  4. Document the PIA outcome and submit to the designated City contact for the project file.

Key Takeaways

  • Do PIAs early in project design to reduce legal and operational risk.
  • Keep concise records of findings and mitigations with procurement files.

Help and Support / Resources


Daniel Roy

Daniel Roy

Municipal Bylaw Analyst

Daniel analyses municipal bylaws across Canadian provinces and territories. He checks every guide against official municipal and provincial sources.