Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Public sector & education

Privacy & Security for Municipalities

Privacy Horizon gives Canadian municipalities privacy and security leadership sized for a public-sector budget. The pressure is concrete: MFIPPA's mandatory PIA, safeguard and breach-reporting duties arrive on January 1, 2027, insurers now test MFA and backup claims before they pay, and ransomware has already shut down city services from Hamilton to Huntsville. We help CAOs, Clerks and IT directors build a program that council can fund and defend.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

Ontario municipalities of every tier fit this work: single-tier towns where the Clerk runs FOI off the corner of a desk, lower-tier townships with two IT staff and an MSP, and upper-tier regions with dozens of departments. All of them are MFIPPA institutions facing the same 2027 deadline, whatever their headcount.

Local governments outside Ontario belong here too. BC municipalities, regional districts and library boards carry FOIPPA's reasonable-security, privacy-management-program and breach-notice duties, while Alberta municipalities moved under POPA and the ATIA in June 2025, with privacy management programs required by June 11, 2026.

It also fits municipalities whose organization chart hides risk: paramedic services, long-term care homes and boards of health that make the corporation a PHIPA custodian; water and transit operations running SCADA and control systems; and library, police or transit boards sitting outside central IT the way Toronto's library and zoo sat outside the city CISO's mandate before their 2023 and 2024 attacks.

Downtown Erin main street view, Town Hall in autumn, Wellington County, Ontario, Canada

Services

Privacy & security services for municipalities

Each service below is scoped for how municipalities actually operate — their systems, their regulators and the reviews they face.

What you hold

The records and systems a municipality has to protect

Municipal data is unusual because residents cannot take their business elsewhere. Taxes, permits, licences and water bills all flow through systems the public is compelled to use, which raises the stakes for every one of them.

Tax rolls and utility billing

Property assessment data derived from MPAC, tax accounts and water billing with pre-authorized debit banking details sit in platforms every household must use. A compromise here touches the whole municipality at once.

Citizen service platforms

311/CRM histories, building-permit and planning files, business and lottery licences, and recreation registrations that capture children's details and medical notes all hold personal information collected under statutory authority.

Water, traffic and transit OT

Water and wastewater SCADA, traffic-signal management and transit systems run beside the corporate network. The Cyber Centre reports attacks on internet-exposed water OT, so these environments need the same governance as any data centre.

Health records in municipal hands

Paramedic electronic patient care records, long-term care resident charts and public-health files are PHI, which places custodian-grade PHIPA duties on parts of the corporation that generic IT policies never contemplated.

Social services case files

Social-assistance, child-care-subsidy and subsidized-housing files concentrate sensitive information about residents in difficult circumstances, held by CMSMs and DSSABs as well as by cities themselves.

Corporate and council records

Closed-session materials, by-law complaints, Provincial Offences files, HR and payroll data with SINs, and CCTV footage each carry their own confidentiality, access and retention obligations.

Regulatory map

The legal map for municipal privacy and security

Municipalities answer to a different rulebook than provincial ministries or school boards, and the most important changes come with hard dates attached.

MFIPPA as it stands today

Cities, towns, transit commissions, library boards, police service boards, boards of health and conservation authorities are all MFIPPA institutions under IPC oversight, and access-request clocks have run in business days since July 1, 2026.

Primary source →

MFIPPA from January 1, 2027

Bill 97 makes privacy impact assessments mandatory before collection, adds an express safeguard duty, and requires reporting real-risk-of-significant-harm breaches to the IPC and affected individuals, with the first annual breach-statistics report due March 31, 2028.

Primary source →

EDSTA covers you; its cyber regulation does not yet

Ontario's Enhancing Digital Security and Trust Act applies to MFIPPA institutions, but O. Reg. 51/26 prescribes only educational institutions, hospitals, children's aid societies and school boards. Municipalities should expect a future regulation rather than assume exemption.

Primary source →

PHIPA inside the corporation

Ambulance services, municipal LTC homes and the medical officer of health are health information custodians, and PHIPA s. 12 already requires notifying individuals when health records are stolen, lost or misused.

Read our guide →

BC and Alberta local government law

BC's FOIPPA imposes reasonable security, a privacy management program and breach notice on local government bodies, while Alberta's POPA brings PIAs filed with the OIPC and mandatory breach reporting for municipalities and municipal police.

Primary source →

Procurement rules with teeth

The Buy Ontario Procurement Directive reached municipalities on April 13, 2026 through O. Reg. 54/26, restricting procurement from US businesses and reshaping how technology contracts get sourced and renewed.

Primary source →

What goes wrong

How Canadian municipalities actually get hit

The incident record in this sector is public and unusually specific, which makes it a planning tool rather than a scare story.

  • Ransomware through the perimeter

    Hamilton's February 25, 2024 attack came through an internet-facing server, took down systems from business licensing to traffic-signal management, and carried a demand of roughly $18.5 million that the city refused, restoring from backups instead.

    Source →

  • Small towns forced to decide

    Wasaga Beach paid $35,000 in 2018 and Midland paid an undisclosed sum the same year; Stratford was hit in 2019 and Huntsville closed its offices in March 2024. Size is no protection when the whole administration runs on a handful of servers.

    Source →

  • The insurance surprise

    Hamilton's insurer refused its claim because multi-factor authentication had not been fully implemented, leaving an $18.3 million bill. Renewal questionnaires are underwriting tests now, not paperwork.

    Source →

  • Local boards outside the fence

    Toronto Public Library's 2023 breach affected 8,018 staff plus dependants and others, running undetected for two months on end-of-life systems; the Toronto Zoo lost employee SINs and earnings data going back to 1989. Neither fell within the city CISO's coverage.

    Source →

  • Espionage and supply-chain compromise

    The Cyber Centre reports PRC-linked espionage against municipal networks alongside ransomware as the top critical-infrastructure threat, and Nova Scotia's MOVEit file-transfer breach shows how one vendor tool can expose about 100,000 people.

    Source →

When organisations call us

When municipalities pick up the phone

Most engagements start with a date, a demand or a headline rather than a strategy exercise, and each trigger has its own clock.

  • The January 1, 2027 countdown

    Clerks need PIA templates, a breach protocol and statistics tracking in place before the MFIPPA amendments take effect, and the work has to clear committee agendas and a budget cycle first.

  • A cyber-insurance renewal

    A questionnaire asks whether MFA covers all remote access and whether backups are tested. The Treasurer needs answers that will hold up if a claim is ever filed, because Hamilton's did not.

  • A peer municipality in the news

    After each publicized attack, councillors ask whether it could happen here and direct staff to report back. That report needs an honest assessment behind it, not reassurance.

  • A new system going live

    An ERP replacement, a tax-billing migration, a 311 upgrade or an AI chatbot pilot will require a privacy impact assessment from 2027 onward, and assessing during procurement is far cheaper than retrofitting.

  • Audit findings or council direction

    Internal audit reports and post-incident reviews land on public agendas and create deadlines that outlast the news cycle, the way Hamilton's recovery reporting went through committee.

Municipalities: privacy & security questions, answered

Yes. MFIPPA's definition of institution reaches municipal service boards, public library boards, transit commissions, police service boards, boards of health, conservation authorities and DSSABs, so the new PIA, safeguard and breach-reporting duties arrive for them on the same January 1, 2027 date. The hard part is practical: many boards run their own IT outside the municipal environment, as Toronto's library and zoo did before their attacks, so your program has to name who assesses, who reports and who tracks statistics for each board.

Not yet. EDSTA itself applies to MFIPPA institutions, but O. Reg. 51/26, in force July 1, 2026, prescribes only educational institutions, hospitals, children's aid societies and school boards. No cyber-program or maturity-assessment mandate binds municipalities today. The sensible reading is a grace period rather than an exemption: a municipal regulation is expected eventually, and building toward it now avoids a scramble later.

Start with the failure modes that have actually hurt towns your size: an internet-facing server without MFA, untested backups, and nobody assigned to call the insurer and the IPC. Wasaga Beach and Midland were small organizations when they were forced to negotiate with attackers in 2018. A short assessment, a council-endorsed roadmap and a handful of high-impact controls beat a thick framework binder, and fractional support means you are not funding a full-time hire.

Those units make the municipality a health information custodian under PHIPA, layered on top of its MFIPPA duties. PHIPA is not waiting for 2027: section 12 already requires notifying affected individuals when health information is stolen, lost, or used or disclosed without authority, with IPC notification in prescribed cases. In practice, ePCR and resident-chart systems need their own safeguards, policies and breach procedures rather than inheriting generic corporate ones.

Underwriters increasingly set your priorities for you. AMO's municipal cyber toolkit warns that insurers evaluate security practices and can decline coverage, and Hamilton's claim was refused because MFA was incomplete when its attack began. Treat the renewal questionnaire as a forcing function: MFA everywhere it is promised, backups proven by restore tests, and an incident plan you can evidence. Answer it accurately, because those answers get tested when money is on the table.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.