Sample assessment, fictional organization
ACME Dental does not exist, and neither does the booking system. What is real is the assessment: this is the output ClearBreach produced from those answers, by the same engine a subscriber uses.
← How ClearBreach works·The same clinic’s annual assessment →
ClearBreach Privacy Impact Assessment
Online appointment booking
ACME Dental · A cloud booking system that lets patients request and reschedule appointments themselves, replacing the phone and the paper day book. The vendor hosts it in the United States.
Issued 2026-09-01 · Reference PIA-ACMEDE-20260901 · AB
Why this assessment was required
Bill C-36 (the PPCDA), s.57(1)(a), an assessment is required before personal information is transferred outside Canada. First reading, not in force: the finding is raised on a Bill, and the assessment says so rather than presenting it as settled law.
The clinic did not ask for this. They described a booking system and said where the vendor hosts it. The obligation follows from that, which is the point: a duty that only appears when somebody thinks to tick a box is a duty that gets missed.
What was assessed
The booking system only. Clinical records stay in the practice-management software and are not part of this assessment.
| Flow | Where | Governing Act |
|---|---|---|
| A patient books or reschedules an appointment through the website | ABleaves Canada → United States | AB_PIPA |
| The booking system sends the appointment to the practice-management software | AB | AB_PIPA |
The Act is decided per flow, not per organization. An initiative can fall under an Act the organization mostly does not work under.
The finding nobody was asked for
Shown in full. This is the one the assessment raises on its own.
Could the personal information that "A patient books or reschedules an appointment through the website" sends outside Canada be demanded under the law of the place it reaches?
Bill C-36 (PPCDA) s.57(1)(b), which requires an assessment of a transfer outside Canada to record the mitigations applied to it. Governing Act for this flow: AB_PIPA.
What the clinic actually has
The vendor publishes an SOC 2 report, which the clinic has read, and staff accounts use two-factor authentication. There is no contractual term about a foreign authority compelling disclosure, and no agreement about which country the data rests in.
Residual score 4. The assessment will not complete without that mitigation recorded, scoring a risk and leaving the box empty is unfinished, not accepted.
Risks, scored by the clinic
Shown in full. 5 risks, with the mitigation each one actually rests on.
Could this information be used later for something nobody has thought of yet?
In place · residual 1
The booking system is used only for booking. Nobody has authority to turn on marketing features without the office manager, who is the named privacy officer.
Could this information reach somebody it was not meant to reach?
In progress · residual 4
Confirmations go to the address the patient typed. There is no check that the address belongs to them, and a mistyped address is the way this reaches the wrong person.
Could a breach of the system holding this information expose it?
In place · residual 3
The vendor publishes an SOC 2 report and the clinic has read it. Staff accounts use two-factor authentication.
Could somebody inside the organization open this information without needing to?
In progress · residual 3
Every member of staff has their own login. All of them can see every booking, because the system has one staff role and no way to narrow it.
Could a foreign authority compel the provider to hand this information over?
Not in place · residual 6
None. The contract is the vendor's standard online terms, accepted at sign-up. Nothing in it addresses a foreign authority compelling disclosure, and the clinic has not asked the vendor where the data is stored beyond "the United States".
Compliance findings
Shown in full. 18 findings across ten modules, 8 of them open.
Can you state, in one sentence, why this initiative needs personal information at all?
In place · initiative
Does the description of this initiative say who it affects, and roughly how many people?
In place · initiative
Is every element of personal information this initiative touches written down, one by one?
In place · inventory
Is any of this information required from the person before they can get the product or service, without being needed to provide it?
In progress · inventory
Make any element that is not necessary to provide the product or service optional, or stop collecting it. Requiring consent to more than is necessary is a separate breach from collecting too much.
Are people told the purposes before or at the moment their information is collected?
In place · collection
Where you are relying on the person simply handing information over as their agreement, would the purpose be obvious to them?
In place · collection
If somebody withdraws their consent, is there a way to act on it, and will you tell them what happens as a result?
In progress · collection
Decide who receives a withdrawal, what stops as a result, and what the person is told about the effect on the service.
Are you getting any of this information from another organization rather than from the person themselves?
Not in place · collection
Give the disclosing organization enough about your purpose that they can judge whether disclosing to you is lawful. They cannot make that decision on a request that does not explain itself.
Will the information be used for anything beyond the purposes people were told about?
In place · use
Is every organization that will receive this information named?
In place · disclosure
If somebody asks to see the information this initiative holds about them, can you produce it, say how it has been used, and say who it went to?
In progress · access
Make sure the initiative records where information goes, not only what it holds. Without that the third part of the duty cannot be answered.
Is any of this information used to make a decision about a person, or sent to another organization?
In place · access
When something is corrected, can you tell the organizations you had already sent it to?
Not in place · access
Keep a dated record of what went to whom, so a correction can be pushed to the recipients that fall inside the year.
Is there a decided period after which this information is destroyed or de-identified?
Not in place · retention
Set a period for each kind of information in this initiative, and say what happens at the end of it.
Are the security arrangements for this initiative written down, and do they match how sensitive the information is?
In progress · security
Record the physical, technical and administrative measures for this initiative, against the sensitivity of what it holds.
Is there a named person answerable for privacy in this initiative, and do they know it?
In place · accountability
Do your existing privacy, security, retention and disposal policies actually cover this initiative?
In progress · accountability
Check each policy against this initiative and amend the ones that do not reach it, rather than assuming coverage.
Which countries will the information be in, or be reachable from?
In place · crossBorder
The document this produced
Not shown. One completed assessment, ready to retain or file. The findings above are its substance; the document is the form it takes.
acme_dental_pia_2026-09-01.docx · 15 KB
Where these figures come from
Every finding on this page was produced by the same assessment engine a subscriber uses. Nothing was written by hand or chosen to look good. Issued 2026-09-01, reference PIA-ACMEDE-20260901, the same reference the clinic’s own document carries.

