Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Public sector & education

Privacy & Security for Public Agencies & Crown Corporations

Privacy Horizon builds privacy and security programs for Crown corporations, provincial agencies, boards and commissions, matched to the government that owns the body: federal Privacy Act institutions with the 7-day material-breach clock, Ontario FIPPA designated agencies under GO-ITS 25.0, BC Schedule 2 public bodies, and Alberta bodies under POPA. Engagements usually start when a statutory deadline lands, a peer agency is breached, or the responsible ministry raises security at MOU-renewal time.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

Federal parent Crown corporations and agencies that qualify as government institutions under the Privacy Act, where the Treasury Board's Policy on Privacy Protection sets a 7-day window to report material breaches to TBS and the OPC and requires PIAs with published summaries.

Ontario provincial agencies designated under FIPPA and governed by the Agencies and Appointments Directive, which expects alignment with GO-ITS 25.0 and compliance with the OPS Procurement Directive, plus municipal boards such as library boards and transit commissions that are MFIPPA institutions in their own right.

BC Crown corporations named in FOIPPA Schedule 2 and Alberta agencies, boards and commissions covered by POPA and the ATIA, each with their own PIA, breach-notification and privacy-management-program obligations.

Bodies of every size, from a ten-person adjudicative tribunal to a utility or insurer with thousands of staff, where a board of directors, a CEO and an ATIP or FOI coordinator share accountability with a responsible minister.

Modern Glass Corner Office Building with Reflective Windows

Services

Privacy & security services for public agencies & crown corporations

Each service below is scoped for how public agencies & crown corporations actually operate — their systems, their regulators and the reviews they face.

What you hold

What a Crown corporation or agency actually holds

Arm's-length bodies concentrate program data, adjudicative records and operational systems that no ministry branch holds in the same mix, and much of it sits outside any central CISO's line of sight.

Program and account records

Insurance claims, licensing files, lottery and gaming accounts, utility billing and transit fare data, each tied to identifiable individuals and often reaching back decades in legacy systems.

Adjudicative and regulatory case files

Tribunals and regulators hold hearing records, investigation files and submissions whose disclosure could prejudice proceedings or expose complainants.

ATIP and FOI request files

Access-request workspaces gather the most sensitive records an institution holds into one queue, along with requester identities that deserve protection in their own right.

Employee HR and payroll data with SINs

The Toronto Zoo ransomware incident exposed employee records going back to 1989, a reminder that agency HR archives accumulate SINs and banking details far beyond current staff.

Board and Cabinet-adjacent records

Business plans, mandate-letter responses, procurement submissions and materials prepared for the responsible ministry carry commercial and governmental sensitivity beyond personal information.

OT and control-system data

Utilities and transit operators run SCADA and operational technology whose availability matters as much as confidentiality, and which shares a boundary with the corporate network.

Regulatory map

The statute depends on which government owns you

Unlike a municipality or a university, an agency's obligations flow from its owner: the federal Privacy Act and TBS policy suite, Ontario's FIPPA and OPS directives, BC's FOIPPA, or Alberta's POPA, with AI directives layered on top.

Federal Privacy Act institutions

Parent Crown corporations and their wholly-owned subsidiaries are government institutions under the Privacy Act, which brings the TBS Policy on Privacy Protection, PIA obligations and material-breach reporting into force for them.

Primary source →

TBS Policy on Privacy Protection

Effective October 9, 2024, the policy defines a material breach as one creating a real risk of significant harm and requires reporting to TBS and the OPC no later than 7 days after materiality is determined.

Primary source →

Ontario FIPPA duties live since July 1, 2025

Designated agencies must complete PIAs before collection, maintain safeguards, notify individuals and report breaches meeting the harm threshold to the IPC, and file annual breach statistics by March 31.

Primary source →

Agencies and Appointments Directive and GO-ITS 25.0

Ontario's directive expects provincial agencies to align with GO-ITS 25.0, the OPS security standard built on ISO/IEC 27002, covering MFA for sensitive processing, TRAs, pre-production security testing and centralized logging.

Primary source →

BC FOIPPA Schedule 2 public bodies

Crown corporations designated in Schedule 2, including BC Hydro, ICBC and BCLC, owe reasonable security under s. 30, privacy management programs, breach notification to the OIPC and PIAs under FOIPPA.

Primary source →

Alberta POPA for agencies, boards and commissions

Since June 11, 2025, Alberta public bodies file PIAs with the OIPC, give breach notice to the Commissioner, affected individuals and the Minister, and needed privacy management programs in place by June 11, 2026.

Primary source →

AI and automated-decision directives

The federal Directive on Automated Decision-Making requires Algorithmic Impact Assessments, with legacy systems brought into compliance by June 24, 2026, while Ontario agencies work under the OPS Responsible Use of AI Directive and the IPC-OHRC principles.

Primary source →

What goes wrong

How Canadian public bodies have actually been breached

The incident record for this niche is unusually well documented, and it points at shared infrastructure, file-transfer tooling and thinly resourced arm's-length IT rather than exotic attacks.

  • Compromise through a central provider

    Global Affairs Canada suffered unauthorized access to employees' personal information through a Shared Services Canada-managed VPN, discovered in January 2024, showing how a central provider's compromise cascades into the institutions that depend on it.

    Source →

  • Managed file transfer exploitation

    Nova Scotia's MOVEit breach touched roughly 100,000 people, exposing SINs, banking and health-card data, and the commissioner found the government did not have reasonable security and information practices in place.

    Source →

  • State-sponsored intrusion

    BC government networks were attacked by a suspected state actor in May 2024, and the Cyber Centre reports more than 20 Government of Canada networks compromised by PRC actors over four years.

    Source →

  • Ransomware against arm's-length agencies

    Toronto Public Library ran end-of-life systems and went two months without detecting its attacker, and the Toronto Zoo lost employee data reaching back to 1989; neither body sat under the City CISO's mandate.

    Source →

  • Vendor and subcontractor cascade

    The PowerSchool investigation's findings on contracts and oversight are the template regulators now apply when a public body's vendor or its subcontractor is the point of failure, as the Brookfield Global Relocation Services breach showed for federal personnel.

    Source →

When organisations call us

The moments agencies pick up the phone

Buying in this niche follows statute, incident and oversight calendars more than technology cycles, and the fiscal year running April 1 to March 31 concentrates decisions in Q4 and Q1.

  • A statutory deadline arrives

    Ontario's FIPPA PIA and breach duties took effect July 1, 2025, Alberta privacy management programs were due June 11, 2026, and federal institutions face the 7-day material-breach clock the moment an incident is assessed.

  • A peer body gets breached

    When a library board, a provincial government network or another Crown corporation makes headlines, boards ask their own CEO for an honest answer about whether the same thing could happen here.

  • MOU renewal or business-plan season

    The responsible ministry's oversight staff read agency business plans and MOUs each spring, and questions about cyber posture and privacy compliance increasingly arrive with them.

  • An audit lands

    A value-for-money or IT audit from a legislative auditor, or an internal-audit finding endorsed by the audit and risk committee, turns a known gap into a funded remediation mandate.

  • An AI initiative needs clearance

    Automated decision-making triggers Algorithmic Impact Assessments federally and the OPS AI Directive in Ontario, and program teams discover they need governance before launch, not after.

  • Critical-infrastructure obligations approach

    Bill C-8 received Royal Assent on June 15, 2026, and the Critical Cyber Systems Protection Act will bind designated operators in federally regulated sectors once brought into force, so operators are assessing exposure now.

Public Agencies & Crown Corporations: privacy & security questions, answered

It depends on which government owns the body. Federal parent Crown corporations and scheduled agencies fall under the Privacy Act and the TBS policy suite. Most Ontario provincial agencies are FIPPA institutions, while municipal boards like library boards and transit commissions sit under MFIPPA. BC Crown corporations designated in FOIPPA Schedule 2 follow FOIPPA, and Alberta agencies, boards and commissions follow POPA and the ATIA. Sorting out the correct statute, and the central directives that ride along with it, is the first task in any engagement.

For Ontario provincial agencies, the Agencies and Appointments Directive expects alignment with GO-ITS 25.0 and related OPS standards and compliance with the OPS Procurement Directive. That is a governance obligation flowing through your MOU with the responsible ministry rather than a statute, but ministry oversight staff and auditors treat it as the yardstick, so gaps against it surface at business-plan review and MOU renewal.

Formally, the head of the institution carries the access and privacy obligations, and delegation instruments push day-to-day duties to an ATIP or FOI coordinator. In practice, the board's audit and risk committee owns oversight, the CEO answers to the responsible minister under the MOU, and in Alberta the Minister is even a required breach-notice recipient. A defensible program documents that chain before an incident tests it.

Federally, yes: the Directive on Automated Decision-Making requires Algorithmic Impact Assessments, and legacy systems had to reach compliance by June 24, 2026, so older scoring or triage tools are squarely in scope. Ontario agencies work under the OPS Responsible Use of AI Directive from December 2024, with the IPC and OHRC principles from January 2026 shaping what responsible use means. An inventory of automated decisions is the practical starting point.

Start by accepting that arm's-length status means the risk is yours. Toronto Public Library and the Toronto Zoo were both city agencies outside the City CISO's umbrella when they were hit. A right-sized program begins with knowing your systems and data, a threat and risk assessment against the standard your government applies, and clear ownership at the executive and board level, then builds controls in priority order rather than all at once.

The federal and Ontario fiscal years run April 1 to March 31, and agency business plans are prepared in the spring cycle under the Agencies and Appointments Directive. Audit-committee calendars drive the rest. Most bodies get the best result by scoping work in Q3, securing budget in Q4, and starting early in the new fiscal year, though breach deadlines and audit findings rarely wait for the calendar.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.