New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Public sector & education
Privacy & Security for School Boards & K-12 Schools
School boards hold minors' personal information at population scale, and three regimes now converge on how they protect it: MFIPPA's new duties arriving January 1, 2027, O. Reg. 51/26's cyber security program and maturity-assessment obligations, and O. Reg. 52/26's parent and student notices about data disclosed to software vendors. Privacy Horizon helps Directors of Education, Superintendents of Business and board IT leaders build the program those regimes expect, shaped by what the IPC found when it investigated the PowerSchool breach.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
For Directors of Education and Superintendents of Business & Finance who answer to elected trustees for privacy and cyber spending. Trustees approve the policies and the budgets, budgets are set in the spring, and everything operational runs on the September-to-June school year, so a compliance plan that ignores the school calendar fails on contact.
For CIOs, IT managers and privacy or FOI leads in Corporate Services who run the student information system, the learning platform, parent-communication and school-cash tools, and hundreds of classroom apps, often with shared-service support from ECNO and purchasing through OECM master agreements.
For boards outside Ontario too: BC boards of education carry FOIPPA's reasonable-security, privacy-management-program and breach-notification sections, and Alberta divisions moved under POPA and ATIA in June 2025, with PIAs filed to the OIPC. The PowerSchool investigation was a joint Ontario-Alberta exercise, and its lessons travel.

Services
Privacy & security services for school boards & k-12 schools
Each service below is scoped for how school boards & k-12 schools actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for School Boards & K-12 Schools
vCISO for school boards: senior security leadership for your O. Reg. 51/26 cyber program, the 2027 maturity assessment and 72-hour Ministry reporting.
Virtual Privacy Officer
Virtual Privacy Officer for School Boards & K-12 Schools
Virtual Privacy Officer for school boards: a standing privacy office for MFIPPA's January 2027 duties, O. Reg. 52/26 parent notices and PIAs on new edtech.
Penetration Testing
Penetration Testing for School Boards & K-12 Schools
Penetration testing for school boards: summer-window tests of your SIS, parent portal, payment flows and vendor remote access, with reports trustees can read.
Incident Response Planning
Incident Response Planning for School Boards & K-12 Schools
Incident response plan for school boards: rehearsed playbooks for student-data breaches, 72-hour Ministry reports, IPC notification and parent communication.
Privacy & Security Policy Development
Privacy & Security Policy Development for School Boards & K-12 Schools
Privacy policy development for school boards: trustee-ready retention schedules, edtech vetting standards and MFIPPA 2027 policy sets grounded in IPC findings.
Privacy & Security Training
Privacy & Security Training for School Boards & K-12 Schools
Privacy and security training for school boards: role-specific sessions for teachers, office admins and trustees, timed to K-12 Cyber Awareness Month.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for School Boards & K-12 Schools
Vendor security review for school boards: vet SIS and edtech vendors against the PowerSchool findings, with O. Reg. 52/26-ready contract terms.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for School Boards & K-12 Schools
AI-PIAs for school boards: classroom and administrative AI tools reviewed against MFIPPA's 2027 PIA duty and the IPC-OHRC AI principles.
What you hold
The student records only a school board holds
A board's data estate is unlike any other public body's: nearly every data subject is a minor, and the most sensitive files follow a child for years.
The OSR and the OEN
Ontario Student Records carry report cards, suspensions and expulsions, and IPRC decisions, keyed to the Ontario Education Number. OSR content is governed under the Education Act, which is why retention and transfer practices need real discipline.
Special-education files
IEPs and special-education assessments often include psychological reports, among the most sensitive records any public institution holds about a child, and a fixture of what attackers exfiltrate.
Health and custody information
Medical and allergy alerts, immunization-linked correspondence, and registration and custody documents that determine who may pick a child up, all held at every school office.
Where students physically are
Attendance, transportation addresses and bus stops, and school bus GPS feeds managed with transportation consortia describe the daily location of children, which raises the safety stakes of any exposure.
Money and staff data
School-cash payment data from parents plus board HR and payroll records. The WRDSB incident touched employee payroll-type data, a reminder that staff files ride on the same systems as student ones.
Cameras and safe-schools reports
CCTV footage and incident and safe-schools reports combine discipline, security and personal information in ways that demand clear access rules and retention limits.
Regulatory map
The regimes converging on boards through 2026 and 2027
Boards are prescribed entities under Ontario's new cyber regulation, institutions under MFIPPA, and the direct audience of an edtech-specific notice rule, a combination no neighbouring sector faces.
MFIPPA, amended by Bill 97
Mandatory privacy impact assessments, s. 30(5) safeguards, breach reporting and notification under s. 30.1, and IPC review powers all take effect January 1, 2027; access requests moved to business-day clocks on July 1, 2026. First annual breach statistics are due March 31, 2028.
O. Reg. 51/26 cyber security
In force July 1, 2026: a cyber security program, a senior-management point of contact, a maturity assessment within one year and then at least every two years with summaries to the Ministry, and 72-hour reporting of critical incidents.
O. Reg. 52/26 edtech notices
Written notice to parents or guardians of students under 16, or to students aged 16 and 17, identifying the specific data elements disclosed to each software vendor, the purpose, the application and vendor name, and complaint routes, as early in the school year as operationally feasible.
IPC soft law for schools
The Digital Privacy Charter for Ontario Schools sets out twelve signable commitments, and the IPC's Planning for Success guide shapes how the regulator expects PIAs to be done.
BC FOIPPA for boards of education
Section 30 reasonable security, s. 36.2 privacy management programs per ministerial direction, s. 36.3 breach notification on the significant-harm test, and PIA directions for non-ministry public bodies.
Alberta POPA and ATIA
In force June 11, 2025 for school boards and charter schools: PIAs submitted to the OIPC, breach reporting on the real-risk-of-significant-harm standard to the Commissioner, individuals and the Minister, and privacy management programs required by June 11, 2026.
What goes wrong
What has already happened to Canadian boards
The threat picture here is not hypothetical. Every pattern below comes from a named incident at a Canadian school board or its dominant vendor.
The PowerSchool breach
Between December 22 and 28, 2024, an attacker used a subcontractor's credentials on the PowerSource support portal, which had no MFA, to take records of roughly 5.2 million Canadians, including about 3.86 million Ontarians. The IPC's November 17, 2025 report found missing contract terms, always-on remote access, short log retention and decades of over-retained data.
Ransom paid, extortion anyway
PowerSchool paid the attacker, yet in May 2025 boards including TDSB and PDSB received fresh extortion demands over the same data, proof that payment settles nothing for the boards downstream.
Ransomware inside a board
TDSB reported ransomware in its technology testing environment in June 2024, exposing 2023/24 student records and triggering IPC notification, a direct hit rather than a vendor one.
Network intrusion and bulk theft
WRDSB's July 2022 intrusion took records of tens of thousands of students spanning several school years, including names, birthdates, OENs and IEP status, along with employee data reported by CBC.
Outage-first incidents
YRDSB's November 2023 cyber incident was contained, but individuals were only notified the following June, showing how long the tail of even a controlled event runs.
A hostile background environment
The Cyber Centre's national assessment tracks state-adjacent and commodity threats against the broader public sector, the backdrop against which under-resourced board IT teams operate.
When organisations call us
The moments that start privacy projects at boards
Board privacy and security work rarely starts from abstract ambition. It starts from a deadline, a regulator's direction or a neighbour's bad month.
IPC directions after PowerSchool
The Commissioner's report covering twenty boards and the Ministry of Education directs boards to renegotiate contracts, run PIAs, monitor vendors, restrict remote access and build breach-response plans, a to-do list many boards cannot staff internally.
The July 1, 2027 maturity assessment
The first O. Reg. 51/26 cyber maturity assessment lands within a year of the regulation applying, and a summary goes to the Ministry, so boards want a defensible program in place well before assessors arrive.
MFIPPA's January 1, 2027 duties
PIA obligations before collection, statutory safeguards and mandatory breach reporting arrive together, and most boards' privacy functions were built for FOI processing, not this.
The late-summer notice crunch
O. Reg. 52/26 notices must go out as early in the school year as operationally feasible, which turns August and September into an annual sprint to inventory every app and the data elements it receives.
An incident nearby
When TDSB, WRDSB or YRDSB makes the news, neighbouring Directors of Education ask their own teams the same questions, and gaps surface fast.
Insurance renewal and October awareness season
Cyber insurers ask harder questions each renewal, and Ministry and ECNO programming around K-12 Cyber Awareness Month each October puts board readiness in front of trustees.
School Boards & K-12 Schools: privacy & security questions, answered
School boards are institutions under MFIPPA, the municipal statute, while universities fall under FIPPA. The distinction matters less than it used to: Bill 97 brings MFIPPA duties much closer to the provincial standard from January 1, 2027, and the IPC has publicly urged that boards be held to FIPPA-level expectations. The regulator for both is the Information and Privacy Commissioner of Ontario.
The Enhancing Digital Security and Trust Act (Bill 194, given royal assent November 25, 2024) names school boards as public sector entities and authorized the two regulations boards now live with: O. Reg. 51/26 on cyber security and O. Reg. 52/26 on digital technology affecting people under 18. Both took effect July 1, 2026, which is why cyber programs, maturity assessments, Ministry incident reports and vendor-disclosure notices all arrived on board agendas at once.
The Ontario and Alberta commissioners investigated jointly and published findings in November 2025. On the vendor side: no MFA protecting the PowerSource support portal, always-on remote access and short log retention. On the board side: contracts missing key privacy and security terms, weak vendor monitoring, and student records retained as far back as 1965 at Peel and 1985 at TDSB, which widened the breach. Boards were directed to fix contracts, run PIAs, monitor vendors and build breach-response plans.
Yes, under different statutes. BC boards of education are local public bodies under FOIPPA, with reasonable-security duties, privacy management programs under ministerial direction, breach notification on the significant-harm test, and PIA requirements; the province-wide SIS is MyEducation BC. Alberta boards came under POPA and ATIA on June 11, 2025, submit PIAs to the OIPC, and needed privacy management programs by June 11, 2026. Alberta's commissioner issued its own PowerSchool findings, with roughly 700,000 Albertans affected.
A full school year out. MFIPPA's PIA, safeguard and breach duties bite on January 1, 2027, in the middle of the school year, and the first O. Reg. 51/26 maturity assessment is due by July 1, 2027 with a summary to the Ministry. Working backwards through trustee approval cycles, spring budget setting and the September start-up crunch leaves little slack, and remediation found by an assessment takes months on its own.
The Director of Education owns the accountability, the Superintendent of Business & Finance typically holds the budget and the insurance relationship, and the CIO or IT manager runs delivery alongside the privacy or FOI lead in Corporate Services. Trustees approve policy and spending, and principals and Superintendents of Education drive the edtech demand that creates much of the risk, so all of them end up involved.
Related industries
Answers & guides
- What's the difference between data privacy and cybersecurity?
- What should I do after a data breach?
- What is a cybersecurity risk assessment, and how often should we do one?
- PIA vs TRA: which assessment do you need (or do you need both)?
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
- Building a Third-Party Vendor Risk Assessment Program That Scales
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.