As an input to the PIA, the organization should provide a description of the information system or
other initiative. The information flow should be described in as detailed a manner as possible, to help
to identify potential privacy risks. The assessor should consider the impacts not only on information
privacy, but also compliance with privacy related regulations e.g. Telecommunications acts. The whole
PII life cycle should be considered.
This step could be taken immediately after 6.3.3 and concurrently with 6.3.4