MVP program · Nonprofit
Minimum Viable Privacy Program for Member Associations & Professional Regulators
Minimum Viable Privacy packages a working baseline for a newly formed college, a small amalgamated regulator, or a volunteer-run association: a gap review of your AMS and public register, the confidentiality and disclosure basics council needs signed, training for ten people, and twelve hours of coaching, for $5,499 CAD a year. It fits an organization standing up its regulatory function for the first time, replatforming to a new AMS, or facing a cyber-insurance question nobody on a volunteer board can currently answer.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
Where a small regulator's baseline has to start
A newly formed body or a lean association office cannot secure everything on day one, so MVP concentrates on the system and the people that carry the most exposure first.
The AMS or regulatory core as the single highest-value system
Whether you run Thentia, Alinity, iMIS or Member365, this one platform holds registration, complaints and payments together, so its access list and basic settings deliver most of the available protection early.
A public register boundary, even in draft form
Before a full disclosure policy exists, MVP settles the basic question of which fields get published and which stay confidential, so nobody is publishing or withholding by instinct.
A named privacy contact where none exists yet
In most small bodies the Deputy Registrar or Executive Director already carries the function unofficially. MVP formalizes that assignment and gives the person a starting structure to work from.
A basic confidentiality undertaking for council
New council members and committee volunteers need something to sign in their first weeks, even a short form, rather than an assumed understanding of statutory duties nobody explained.
Regulatory map
The compliance floor a small body needs cleared first
Before any policy gets written, MVP answers the question this sector gets wrong most often: which regime, if any, actually governs you.
Whether you are FIPPA, PIPA or neither
A BC governing body is a FIPPA public body; an Alberta professional regulatory organization sits under PIPA; an Ontario college has no general private-sector statute and instead answers to the Procedural Code's s. 36. The baseline documents which of these actually applies to you.
A minimal Law 25 position if you have Quebec members
The private-sector Act reaches professional orders through the Professional Code and any association meeting the enterprise test, starting with naming a person in charge of personal information.
The register content your province actually prescribes
Ontario colleges work from s. 23 and O. Reg. 261/18; other provinces set their own fields. The baseline confirms what your regime requires before you publish anything beyond it.
CASL's two-year window for associations
Membership within the previous two years gives implied consent under the regulations, with no charity-style exemption, so membership staff need this rule stated plainly from the start.
What goes wrong
The predictable failures an unbuilt program invites
Bodies that skip a baseline entirely tend to discover the gap through one of a small number of familiar, avoidable events.
An extortion event with no decision structure
The College of Nurses of Ontario's 2020 ransomware and leak-site event forced decisions about containment and disclosure under a countdown clock. A newly formed body with no baseline would be making those same calls for the first time under identical pressure.
A web breach nobody had prepared to answer for
CPA Canada's 2020 incident exposed contact and employer data for over 329,000 people through its website. A small association with no baseline access controls or incident routine faces the same exposure at a scale that would overwhelm a volunteer board.
A misdirected email with no communications rule
OIPC Alberta decisions record recipients exposed by a single bulk send to the wrong field. A basic BCC and list-hygiene rule, part of MVP's training, closes this gap for a fraction of the effort a full incident costs.
Register disclosure decided case by case, forever
OIPC BC's review of the College of Teachers found publication defensible but written disclosure guidelines missing. A body without even a draft position repeats that same avoidable gap from its very first disclosure decision.
Our mvp program for member associations & professional regulators
What the MVP year delivers for a small regulator or association
The package is fixed and sequenced so the highest-value pieces land first, built around your AMS and governance calendar rather than a generic checklist.

Baseline privacy gap review
A structured look at your AMS or regulatory core, public register practice and council access, benchmarked against the regime that actually applies to you, producing a short, ranked list rather than a lengthy audit.
Prioritized control recommendations
Directional guidance on what to fix first once the which-regime question is answered: typically AMS access limits, a register disclosure position, and a documented consent record for members.
Core policy development
A starter register disclosure position, a council and committee confidentiality undertaking, and, for associations, a membership and CASL policy, drafted for your own systems and governance structure.
Readiness assessment workshops
Working sessions with the Registrar or Executive Director and, where useful, council itself, rehearsing the situation that prompted the purchase: a new AMS, an amalgamation, or an insurer's first questionnaire.
Training with ten seats
Role-appropriate training and human-risk assessment for up to ten people, enough to cover core staff plus council leadership or membership staff at this size of organization.
Twelve hours of coaching
Expert time spent wherever the year takes you: an AMS vendor's contract clause, a council question about the confidentiality duty, or a first cyber-insurance renewal question.
How the engagement runs
How the term is sequenced from intake to close-out
Setup is deliberately light on a volunteer board or a small staff team, and nothing structural is scheduled during a live exam sitting or renewal window.
Step 1
Intake and the which-regime determination
We confirm whether FIPPA, a provincial PIPA, Law 25 or only your own procedural code applies, so every later decision starts from a documented answer instead of a guess.
Step 2
Gap review and a ranked plan
The AMS, register practice and council access are reviewed against that determination, and the findings become a short list the Registrar or ED can approve in one meeting.
Step 3
Policy drafting and readiness workshops
Core policies are drafted and refined live with your team, then rehearsed in a workshop built around the AMS migration, amalgamation or insurer deadline that started the engagement.
Step 4
Training rollout and coaching close-out
Core staff, council leadership and membership staff each complete their track, and the leftover coaching hours are spent on whatever question the year actually raised, closing with a clear sense of what a bigger program would add.
What it costs
What MVP costs and what a small regulator gets for it
The MVP fee is $5,499 CAD annually on a twelve-month term. Across that term you get the baseline gap review, core policy drafting, readiness workshops, twelve coaching hours and training for ten people, priced as one package a Registrar or volunteer board can approve without a procurement process.
Bodies that outgrow it, typically by adding an exam and proctoring program, expanding into a second province with a different regime, or facing recurring council or oversight reporting demands, usually move to the Virtual Privacy Office retainer once the MVP year ends, and everything built during MVP carries forward into it.
Member Associations & Professional Regulators: MVP program questions, answered
Five things, sized to a volunteer-run organization: a named contact, usually the Executive Director; a documented answer to whether PIPEDA or a provincial statute governs your membership data; a short policy covering membership consent, CASL and basic confidentiality; access limits on your AMS; and a trained staff team plus board orientation. MVP delivers that set without asking the board to hire anyone.
The gap review and core policy drafting are sequenced to land early for situations like this: access roles, integrations and public-facing fields on the new platform get reviewed first, a starter disclosure position and confidentiality undertaking follow, and the readiness workshop rehearses the questions a council member or insurer is likely to ask about the migration.
MFA on every account touching the regulatory core; a documented answer to which privacy regime applies provincially; a written position on what the public register does and does not show; a signed confidentiality undertaking for every council and committee member; and a named contact for privacy and security questions. These five sit at the centre of MVP's baseline, sequenced earliest in the term.
Yes, FIPPA status does not supply a working program on its own. It sets the legal framework, freedom-of-information obligations and OIPC BC oversight, but someone still has to build the register disclosure position, the AMS access controls and the confidentiality undertakings that make that framework real day to day. MVP's gap review is written to your FIPPA status, not a generic template.
A starter position stating which fields your regime requires or permits publishing, how discipline entries are handled, and who decides a borderline case, drafted against your province's specific rule such as O. Reg. 261/18 in Ontario. It is a working baseline rather than the full disclosure policy a mature body would eventually want, but it stops decisions being made ad hoc from your first case.
It covers the baseline: a documented position on candidate consent expectations and a first look at the vendor's contract terms. A full exam-candidate notice and biometric data-flow review, matched to the OPC's 2025 guidance, is deeper work than the MVP term is built for, and bodies standing up a new exam program often add a focused vendor review once the sitting date is set.
More for member associations & professional regulators
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.