Risk Area |
Level of Risk |
Details |
A) Type of program or activity |
4 |
The information associated with a learner can be used to make decisions that directly affect the individual.
Data collected in Brightspace is then in turn stored in the Synapse Analytics data warehouse and reported using the Power Bi application.
Information collected in Brightspace, stored in Synapse Analytics and reported in Power BI is used for compliance and could be used for investigations and enforcement. |
B) Type of personal information involved and context |
2 |
Brightspace, Synapse Analytics and Power BI link this personal information with information on courses and events that the learner has taken namely:
-
what training will take place
- when the training will take place
- how the training will be delivered
- who will deliver the training
- attendance at the training
- the results of any tests that are associated with the course
- if the training has been completed
- learner activities associated with the training
|
C) Program or activity partners and private sector involvement |
2 |
The program and activity participants are as follows:
- CSPS management and staff that are involved in the delivery, management and reporting on training and events
- Management and staff of client organizations with whom the School has signed data-sharing agreements that are involved in reporting on training and events
- Central agency representatives working on compliance or policy activities
- GoC learners who get to see their training
The private sector organizations are D2L, as the vendor of Brightspace, and Microsoft, as the vendor of Synapse Analytics and Power BI. |
D) Duration of the program or activity |
3 |
The management of training and events at CSPS has a long history and Brightspace is an upgrade of technology that will provide better, more efficient and effective training and events operations to the GoC learners.
Providing better business intelligence to business lines and client organizations is a key goal driving the adoption of Synapse Analytics as a data warehousing tool and Power BI as a reporting tool. |
E) Program population |
2 |
The program affects various GoC Learners including indeterminate, term, students, casual and consultants engaged in mandatory and optional external training and events. |
F) Technology & privacy |
1. Does the new or modified program or activity involve the implementation of a new electronic system, software or application program including collaborative software (or groupware) that is implemented to support the program or activity in terms of the creation, collection or handling of personal information?
|
Yes |
Once Power BI is fully implemented, Cognos (legacy data visualization tool) will be switched off and all reports and dashboards will be developed and distributed through Power BI.
D2L is fully implemented, SABA (legacy LMS) is discontinued.
Once Synapse Analytics is fully implemented, the legacy data warehouse will continue to remain in use until SABA (legacy LMS) is fully replaced by D2L. Once SABA is fully replaced by D2L, the legacy data warehouse will be shut down, and all required legacy data will be migrated in a one-time export into Synapse Analytics.
Brightspace uses an audit trail to track unauthorized access, modification and deletion.
Synapse Analytics uses an audit trail to track when Azure resources are used (e.g. a database is paused or resumed), when files are created or modified, and when changes are made to the code base.
Power BI uses an audit trail to track which users viewed reports and dashboards. |
2. Does the new or modified program or activity require any modifications to IT legacy systems and / or services? |
Yes |
3. Does the new or modified program or activity involve the implementation of one or more of the following technologies:
- Enhanced identification methods
- Use of surveillance
- Use of automated personal information analysis, personal information matching and knowledge discovery techniques
|
No |
Yes |
No |
G) Personal information transmission |
4 |
Data collected in Brightspace is then in turn stored in the Synapse Analytics data warehouse and reported using the Power BI application.
Brightspace, Synapse Analytics and Power BI are web-based platforms accessed via the HTTPS protocol.
The platforms allow printing of the information that the person has access to.
It is also important to note that the platforms assign roles to the various classes of users. It is through these roles that the platforms’ administrators regulate the amount of information that a user is allowed to view. As web-based platforms, personal information may be transmitted using wireless technologies. |
H) Potential risk impact to the individual or employee in the event of a privacy breach |
3 |
The potential harm associated with a privacy breach would be the knowledge of:
- whether or not an employee had the required training associated with the performance of their job;
- the results of any testing associated with a completed course.
|
I) Potential risk impact to the institution in the event of a privacy breach |
4 |
The potential risk impact to the institution in the event of a privacy breach to CSPS would be whether or not an employee had the mandatory training associated with the performance of their job. This may also incur reputation harm, embarrassment and/or loss of credibility to the department. |