Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Privacy & security assessments

Do you need a TRA before moving sensitive data to a new cloud provider?

Reviewed by the Privacy Horizon team · Last reviewed

Quick answer

In most cases, yes — complete a threat and risk assessment (TRA) before moving sensitive or personal data to a new cloud provider. A TRA identifies the threats, vulnerabilities, and residual risks the migration introduces, then defines the safeguards to manage them. It is best practice for any organization and is often contractually or legally expected in healthcare, public-sector, and enterprise settings, especially when data crosses borders or its storage location changes.

On this page

When is a TRA actually required before a cloud migration?

A TRA is required, or strongly expected, before a cloud migration whenever the move changes who can access sensitive data, where it is stored, or what could go wrong. For most organizations a TRA is best practice rather than a hard legal mandate, but several situations push it from advisable to effectively non-negotiable.

Treat the migration as a material change to your risk posture. A new provider means new infrastructure, new access paths, new shared-responsibility boundaries, and often a new storage jurisdiction — each of which should be assessed before, not after, your data lands there.

  • You handle health information or other sensitive personal data — health-sector buyers and regulators (for example under PHIPA in Ontario) routinely expect a documented risk assessment before custodians or their service providers move data.
  • You sell to or operate as a public body — provincial and federal public-sector rules often require assessing privacy and security risk before launching or changing a system; in BC, public bodies must complete privacy impact assessments before launch under FOIPPA, and security risk work typically accompanies them.
  • Data will be stored or processed in a new country — cross-border transfers raise lawful-access, residency, and contractual concerns that a TRA is designed to surface.
  • An enterprise customer's vendor security review or contract requires evidence of a risk assessment before you can store their data in a new environment.
  • The data is highly sensitive (financial, biometric, credentials) or the system is business-critical, so the impact of a failure is high.

What does a TRA for a cloud migration actually cover?

A TRA for a cloud migration systematically examines the assets you are moving, the threats and vulnerabilities that apply to the new environment, the likelihood and impact of each risk, and the controls that bring residual risk to an acceptable level. The goal is a clear, documented decision: migrate as planned, migrate with added safeguards, or change the approach.

Unlike a generic security checklist, a TRA is contextual — it weighs the specific data, the specific provider, and your own risk tolerance, so you invest in controls where the risk genuinely is rather than everywhere at once.

  • Asset and data classification — what is moving, how sensitive it is, and the volume involved.
  • Threat identification — who or what could compromise the data (external attackers, insiders, misconfiguration, provider outages, lawful-access requests).
  • Vulnerability and configuration review of the target environment, including identity and access management, encryption in transit and at rest, logging, and network exposure.
  • Shared-responsibility analysis — exactly which controls the provider owns versus which you must configure and operate.
  • Data residency and cross-border exposure, plus the contractual and legal terms that govern lawful access.
  • Likelihood and impact rating for each risk, with recommended safeguards and a documented residual-risk decision.

TRA or PIA — do you need one or both before migrating?

You often need both, because a TRA and a PIA answer different questions. A TRA is a security exercise: it asks how data could be compromised and what controls reduce that risk. A privacy impact assessment (PIA) is a privacy exercise: it asks how the program affects individuals' privacy and whether you are meeting privacy principles and obligations.

The Office of the Privacy Commissioner of Canada describes a PIA as a risk-management process that helps institutions meet legislative requirements and identify the impacts their programs and activities have on individuals' privacy; its risk analysis covers principles such as accountability, limiting collection, retention, safeguards, and limiting use and disclosure. Moving personal data to a new cloud provider can touch several of those principles at once, so the safeguards finding in your PIA and the controls in your TRA should reinforce each other.

For a routine lift-and-shift of non-personal data, a TRA alone may suffice. When personal or health information is involved — or when storage location, access, or use changes — pairing the TRA with a PIA gives you both the security and the privacy view that sophisticated buyers and regulators expect.

What happens if you skip the TRA and migrate anyway?

Skipping the TRA means accepting risks you have not measured. The most common consequences are misconfigured cloud storage, weak access controls, encryption gaps, and overlooked data-residency obligations — all far cheaper to fix before migration than after a breach or a failed customer audit.

There are commercial costs too. Enterprise and healthcare buyers increasingly ask for evidence of a risk assessment during vendor security reviews; without it, deals stall. And if an incident occurs, regulators and customers will ask what due diligence you performed before placing their data in a new environment — a documented TRA is the record that you assessed and managed the risk responsibly.

  • Undetected misconfigurations that expose data publicly or to the wrong tenants.
  • Encryption or key-management gaps discovered only after data is already migrated.
  • Data-residency or cross-border violations that breach contracts or sector rules.
  • Stalled sales when buyers ask for assessment evidence you cannot produce.
  • Higher remediation cost and reputational damage if a preventable incident follows.

How do you scope and cost a TRA for a cloud move?

Cost and timeline for a TRA depend on scope, not a fixed price, so the honest answer is that they vary with the complexity of what you are moving. A single application with one data type and a well-documented provider is a far smaller exercise than a multi-system migration spanning several jurisdictions and integrations.

Rather than quoting a number sight unseen, Privacy Horizon scopes a TRA to your actual environment and provides a tailored estimate after a short consultation.

  • Number and sensitivity of systems and data types being migrated.
  • Complexity of the target architecture, including integrations and identity setup.
  • Whether data crosses borders and how many jurisdictions are involved.
  • Whether you also need a paired PIA, policy updates, or penetration testing of the new environment.
  • Whether the engagement is a one-time pre-migration assessment or part of ongoing oversight, such as a Virtual Privacy Officer or vCISO arrangement.

Frequently asked questions

Before. The purpose of a TRA is to inform the migration decision and to specify safeguards while they can still be built in. Doing it after data has moved turns the assessment into incident clean-up rather than risk management, and any gaps it finds are more expensive to remediate.

No. A provider's SOC 2 or ISO 27001 report only covers the controls the provider operates. Under the shared-responsibility model, you still own configuration, access management, encryption choices, and how you use the service. A TRA assesses your side of that boundary, which no provider report or certification can do for you.

A Canadian provider can simplify data-residency concerns, but it does not remove the need to assess threats, misconfiguration risk, access controls, and shared-responsibility gaps. The residency analysis is one part of a TRA, not the whole of it, so an assessment is still advisable for sensitive data.

A TRA reflects your environment at a point in time. Revisit it when the architecture, data types, provider terms, or threat landscape change materially, and review it periodically as part of routine risk management — annually is a common cadence for sensitive systems.

Privacy & security assessments

PIA vs TRA: which assessment do you need (or do you need both)?

PIA vs TRA: a PIA assesses privacy risk to individuals; a TRA assesses security threats to systems. Learn which assessment you need, or whether you need both.

Read
Compliance & regulations

What is a cybersecurity risk assessment, and how often should we do one?

A cybersecurity risk assessment identifies threats to your data and systems and how to manage them. Do one at least annually and after any significant change.

Read
Compliance & regulations

How do we prepare for a customer security questionnaire?

Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.

Read
Cybersecurity basics

What's the difference between data privacy and cybersecurity?

Data privacy governs how personal information is collected, used, and shared; cybersecurity protects information and systems from threats. Here's how they differ and overlap.

Read
Privacy & security assessments

What's involved in a Privacy Impact Assessment: inputs, timeline, and cost?

What's involved in a Privacy Impact Assessment — the inputs, timeline, and cost drivers of a PIA, and how to scope one for your project or product.

Read
Privacy & security assessments

When should you do a Privacy Impact Assessment in the product development lifecycle?

When should you do a Privacy Impact Assessment in the product development lifecycle? Start at design, finish before launch, and refresh when data handling changes.

Read

How Privacy Horizon can help

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.