Back to privacy assessments

Privacy assessment

Transfer Assessment Evidence Index

Index connecting each TIA conclusion to public evidence or to a classified, controlled evidence record without exposing restricted material.

Status
Draft for external legal and privacy review
Version
0.9
Classification
Public
Last reviewed
12 August 2026
Next review
12 November 2026
Effective date
Pending approval
Owner
Governance administrator - confirmation required
Approval
Privacy and compliance owner - pending
Supersedes
None - initial publication
Download PDF
Document controlValue
Document IDCIC-PIA-TIA-009
Version0.9
Superseded versionNone - initial publication
StatusDraft for external legal and privacy review
Publication classificationPublic
OwnerGovernance administrator - confirmation required
ApproverPrivacy and compliance owner - pending
Effective datePending approval
Last reviewed12 August 2026
Next review12 November 2026 or earlier after a material change

Purpose

This index connects public conclusions to evidence without publishing secrets, account details, personal information, private contracts, detailed security architecture, or restricted operational records. It also exposes where evidence is missing so that external readers do not mistake repository inference for confirmed production fact.

Evidence classifications

ClassificationPublic handling
PublicMay be linked or reproduced where licensing and accuracy permit.
InternalIdentify the record class and conclusion; do not publish operational detail.
ConfidentialIdentify only the evidence ID, owner class, review date, and conclusion where appropriate.
RestrictedDo not publish contents, account identifiers, security detail, secrets, personal data, or request records.

Public evidence

Evidence IDEvidenceSupportsStatus
PUB-01CIC Privacy PolicyTransparency, data use, sharing, rights, retention, and security baselinePublished; reconcile after provider inventory.
PUB-02Data Classification, Privacy, and Retention PolicyClassification, handling, retention, deletion, and evidence expectationsPublished.
PUB-03Third Party Risk Management PolicyVendor classification, diligence, monitoring, evidence, and offboardingPublished.
PUB-04Access Control PolicyLeast privilege, privileged access, support access, service accounts, and reviewsPublished.
PUB-05Incident Response PolicyIncident triage, containment, investigation, communication, and remediationPublished.
PUB-06Information Security PolicySecurity baseline across data, engineering, vendors, incidents, and monitoringPublished.
PUB-07Financial Operations and Reconciliation PolicyWallet, payment, ledger, posting, duplicate-prevention, and reconciliation controlsPublished.
PUB-08Customer Support and Identity Verification PolicyAuthenticated support and purpose-specific access controlsPublished.
PUB-09Secure SDLC and Change Management PolicyRepository, testing, deployment, secret, and change controlsPublished.
PUB-10EDPB Recommendations 01/2020EU transfer assessment and supplementary-measure methodPublic legal guidance.
PUB-11European Commission SCC decisionEU standard contractual clausesPublic legal instrument.
PUB-12ICO transfer risk assessment guidanceUK transfer risk assessment methodPublic regulator guidance.
PUB-13Nigeria Data Protection Act 2023Nigeria privacy and cross-border legal frameworkPublic legislation.
PUB-14Canada OPC cross-border guidanceCanadian accountability and comparable protectionPublic regulator guidance.
PUB-15US Department of Justice CLOUD Act resourcesUnited States lawful-access contextPublic government material.
PUB-16Google Cloud Data Processing and Security TermsProvider contractual frameworkPublic provider material; CIC execution and scope require controlled evidence.
PUB-17Google Cloud subprocessorsProvider onward-recipient referencePublic provider material; CIC subscription and active services require controlled evidence.

Controlled evidence requirements

Evidence IDControlled evidence classSupportsCurrent state
CTL-01CIC legal-entity, establishment, registration, and role matrixApplicable law, exporter, controller/processor, contract selectionConfirmation required.
CTL-02Named governance owner and delegate registerAccountability and approvalsConfirmation required.
CTL-03Active provider and product reconciliation exportComplete transfer inventoryConfirmation required.
CTL-04Cloud service, project, storage, backup, region, support, and access exportT-01, T-02, T-15 and TR-03Confirmation required.
CTL-05Database provider, cluster, region, backup, encryption, access, DPA, and subprocessor packT-03 and TR-02Confirmation required.
CTL-06Executed provider contract, DPA, security exhibit, and deletion termsContractual safeguardsConfirmation required per active provider.
CTL-07Completed SCC, UK IDTA/Addendum, Nigerian safeguard, Canadian protection, or adequacy/certification recordLawful transfer mechanismConfirmation required per transfer.
CTL-08Provider and subprocessor location inventory with retrieval datesJurisdiction and onward-transfer analysisConfirmation required.
CTL-09Financial and identity product field maps and activation decisionsT-06 to T-10 and TR-04Confirmation required.
CTL-10Communications provider/channel map and template minimization reviewT-05 and TR-06Confirmation required.
CTL-11Video, voice, screen, recording, consent, routing, storage, retention, and deletion exportT-12 and TR-05Confirmation required.
CTL-12Workforce/contractor location, role, contract, training, device, and access inventoryT-16 and TR-07Confirmation required.
CTL-13Restricted-field encryption, key, rotation, recovery, and plaintext-necessity matrixTR-10 and technical safeguardsPartial implementation evidenced; controlled verification required.
CTL-14Privileged and Restricted-data access certificationAccess-control effectivenessOperating evidence required.
CTL-15Audit, masked reveal, correction, appeal, compliance-reporting, and notification test evidenceApplication privacy controlsImplementation evidence exists; production effectiveness review required.
CTL-16Retention schedule, dry-run, authorized deletion, provider deletion, and backup evidenceTR-11Partial design evidenced; approval and operating record required.
CTL-17Subprocessor change subscriptions, notices, deadlines, assessments, and decisionsTR-08Confirmation required.
CTL-18Government-request policy, provider transparency material, request history, and CIC case recordsTR-12Provider evidence required; case records remain Restricted.
CTL-19Integration suspension and fallback runbooksTR-14Documented process required; technical feasibility confirmation required.
CTL-20Credential rotation attestations and relevant access/log reviewTR-18Open; values must never be included.
CTL-21Privacy, security, business, executive risk, and counsel approvalsFinal decisionPending.

Source-code evidence boundary

Repository evidence can establish that:

  • a service is deployed through a named cloud platform;
  • a dependency, route, workflow, model, environment-variable name, or adapter exists;
  • selected application controls and tests have been implemented;
  • governance documents and deployment workflows exist.

Repository evidence cannot by itself establish that:

  • an optional integration is active in production;
  • a named provider is the contracting legal entity;
  • a provider account uses a particular storage or support region;
  • current DPA, SCC, IDTA, certification, or subprocessor terms are executed and applicable;
  • production controls operate effectively over time;
  • no government request, incident, exception, or out-of-band disclosure occurred.

Evidence integrity and access

Controlled records must be stored in an access-restricted governance location. Record retrieval or test date, source, owner, classification, retention, linked risk/action, and review date. Integrity hashes may be retained where proportionate, but they must not be used to expose secret material. Access to Restricted evidence must be least privilege and audited.

Publication review checklist

Before publishing any revision:

  • scan report content and deployment configuration for credentials, tokens, private keys, credential-bearing URIs, private endpoints, personal data, account identifiers, and restricted architecture;
  • verify every internal governance link resolves;
  • verify public external legal and provider sources resolve;
  • verify document IDs, versions, statuses, dates, owners, and approval posture agree;
  • verify browser and PDF rendering on desktop and mobile widths;
  • verify no Integration evidenced statement became a production-use claim without controlled evidence;
  • obtain security, privacy, governance, accessibility, and counsel review appropriate to the change.

Current evidence conclusion

The public and repository evidence supports publication of a transparent draft assessment. It does not support a final legal approval or certification. CTL-01 through CTL-21 define the evidence needed to close the remaining gaps.

Limitation

This index was prepared with AI assistance. Controlled evidence owners must confirm existence, integrity, access, retention, conclusions, and completion.