This parallels a recommendation I have been making, and it has been reflected in the government's consultation. There have been many exchanges between my office and Treasury Board, and I spoke to the minister. Those recommendations are largely reflected in the consultation.
I've advocated that privacy impact assessments be a legal requirement because, currently, it's a requirement in the Treasury Board policy and directive. It's the same as the algorithmic impact assessment you're referring to. That's good, but it's not enough.
When something is required by policy, we see more instances of it not being complied with because the consequence is less than if you were to break the law. Raising this to the level of a legal obligation makes it more transparent. It's more visible when it's in the law. It focuses and gives it a higher priority, so I support both the privacy impact and the algorithmic impact assessments being legal requirements.
