cds-snc / notification-planning

Project planning for GC Notify Team
5 stars 0 forks source link

Write a Notify Privacy Analysis (PIA-lite) #268

Closed sharlychan-cds closed 2 months ago

sharlychan-cds commented 2 years ago

Give your user story a simple, clear title

Description

We have a draft Privacy Impact Assessment (PIA) for Notify. Work was started with TBS ATIP and we need to incorporate their comments, update and re-evaluate it since it was written. A formal PIA is not needed and we're working with OCIO PDPD on a Notify Privacy Analysis document (a PIA-lite).

The goal is to create a technical Notify Privacy Analysis with a privacy compliance-based govt audience. Will re-evaluate to see if we can adapt it to make it public and plain language.

Acceptance Criteria** (Definition of done)

yaelberger-commits commented 2 years ago

OCIO PDPD is working on this with our policy team

amazingphilippe commented 2 years ago

It changed, so Sharly needs to work on it

sharlychan-cds commented 2 years ago

Working on comments to return back to OCIO PDPD

yaelberger-commits commented 2 years ago

Please add your planning poker estimate with Zenhub @sharlychan-cds

yaelberger-commits commented 2 years ago

Sharly will meet with Kayla soon to accept comments

YedidaZalik commented 1 year ago

@sharlychan-cds working on and will chat OCIO in next day or so.

YedidaZalik commented 1 year ago

Sharly working on and in contact with OCIO

YedidaZalik commented 1 year ago

Meeting OCIO today

YedidaZalik commented 1 year ago

Met with OCIO and some changes accepted, now working on draft and will ask some questions to Yael and Josh early in week

YedidaZalik commented 1 year ago

Sharly is at a meeting with OCIO this morning :)

adriannelee commented 1 year ago

Sharly chatted with Nisa yesterday to get some answers. Blocked time on Friday with her to work on this.

Sharly will continue working a bit on this today.

adriannelee commented 1 year ago

Continued worked on this on Friday. Will be ready for review soon

andrewleith commented 1 year ago
YedidaZalik commented 1 year ago

Moving to Sprint backlog until @sharlychan-cds returns Did some pairing before holidays with table of data we collect, show how collected, stored, use which is one of last pieces of work required.

sharlychan-cds commented 1 year ago

February 16, 2023: Sharly and Nisa (Policy) reviewed and sent back final comments to TBS. Waiting for their final approval. Next steps: Giving PM and Head of Notify a tl;dr review of the the document (and any edits needed) before accepting.

sharlychan-cds commented 1 year ago

Have a meeting with Josh, Yael to brief them today! Agenda here Privacy Analysis Document here

sharlychan-cds commented 1 year ago

Josh and Yael have accepted. Now to dev review for specific sections!

sharlychan-cds commented 1 year ago

Dev review https://docs.google.com/document/d/1oODAdd-O9j1JlzxzdVHiwXk3zRnNZj__/edit# for pages 5,7-11, 18-19

sharlychan-cds commented 1 year ago

@jimleroyer to review to see if the technical descriptions are still accurate https://docs.google.com/document/d/1oODAdd-O9j1JlzxzdVHiwXk3zRnNZj__/edit# for pages 5,7-11, 18-19

Does a deadline of Thursday March 16 work? We're hoping to move this along quickly 🙏

sastels commented 1 year ago

waiting for @jimleroyer / devs to review. Melissa might be reframing slightly.

jimleroyer commented 1 year ago

@mtoutloff @sharlychan-cds I reviewed and that looks great overall. I left a few comments. Please ping me if you have any question!

mtoutloff commented 1 year ago

Thanks @jimleroyer! Will review today and let you know if there are any questions.

yaelberger-commits commented 1 year ago

Melissa still reviewing remaining risks and syncing with Forms team

yaelberger-commits commented 1 year ago

Still with Jimmy for some final reviews

yaelberger-commits commented 1 year ago

Melissa has meeting with Jimmy this aft for remaining risk

yaelberger-commits commented 1 year ago

Melissa and Jimmy met about auditing Met with TBS about risk Melissa documented some key points, will review with Nisa Dependant on ISA signatures issue (PRDD says about Forms)

YedidaZalik commented 1 year ago

Melissa at monthly meeting with Privacy folks today so maybe waiting for info from PRDD or Forms team.

mtoutloff commented 1 year ago

Met with PRDD this morning and they are expecting to provide us their advice on the SIN collection for Forms this week. Once we receive it, I will review to see if it has any impacts on the risks identified in the analysis.

YedidaZalik commented 1 year ago

No update since last week.

YedidaZalik commented 1 year ago

No updates Still waiting on PRDD but majority of their team is out so moving to product backlog

mtoutloff commented 1 year ago

Emailed PRDD about their thoughts on the risks and to get their feedback. Received their response yesterday (June 20) and need to review

mtoutloff commented 1 year ago

Emailed final draft analysis to PRDD on June 27th, once reviewed it will be ready for approval.

adriannelee commented 1 year ago

Heard back from PRDD yesterday - they're good with our changes but taking through their management (approvals). They'll follow up on approval timelines shortly.

mtoutloff commented 1 year ago

Will be following up with PRDD this week for update on the status of their review

mtoutloff commented 1 year ago

PRDD review should be completed this week, next step will be to proceed to sign-off, back by the end of the week?

mtoutloff commented 1 year ago

Received minor comments from PRDD this week and made a few edits to address their comments. With Nisa for review.

mtoutloff commented 1 year ago

Sent back Analysis to PRDD for final review

yaelberger-commits commented 1 year ago

Melissa working on a briefing for Leanne and Josh. PRDD gave the thumbs up

mtoutloff commented 1 year ago

Draft briefing shared with Mohamed and Yael. Meeting set up to brief Leanne and Josh on Aug 9

mtoutloff commented 1 year ago

Will need to make some updates to the Analysis following transfer to ESDC. Waiting for more info from legal.

mtoutloff commented 8 months ago

Decided to finalize the Privacy Analysis with what we know so far following our transition to ESDC and can update it down the road if needed

mtoutloff commented 8 months ago

With Nisa for review. Meeting to brief Ioana set up for tomorrow

mtoutloff commented 8 months ago

Briefed Ioana, she's reviewing and once done will set up meeting with Leanne to brief and finalize.

mtoutloff commented 8 months ago

Ioana reviewed, will be briefing Leanne on Monday, Feb 5

mtoutloff commented 7 months ago

Briefed Leanne: She agrees that we can consider this version of the Privacy Analysis done and dusted: https://docs.google.com/document/d/1L3eLNGW7dJ776XADA7PvEIEbbOx5Uh7BRMicH7KRt4Y/edit#heading=h.1chp7uuqxp8x

mtoutloff commented 7 months ago

Sending to translation

yaelberger-commits commented 7 months ago

Confirm with Melissa next week if this has been sent to translation

mtoutloff commented 6 months ago

Still with translation

mtoutloff commented 3 months ago

Followed up with translation. The doc still needs to be proofread, but there have been many urgent requests, so it's been on hold for now

mtoutloff commented 2 months ago

Followed up with translation and they expect have it finished tomorrow (july 23)