Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Policy development · Public sector & education

Privacy & Security Policy Development for Municipalities

Policy development gives your municipality a council-approved set of privacy and security policies that turn MFIPPA's amended safeguard duty into documented practice, rather than an assumption nobody can point to. Most municipalities start this work when the Clerk maps what January 1, 2027 requires and finds no written safeguards, retention or breach-response policy behind the tax roll, the permit portal or the paramedic service. We draft the set your council can adopt, your insurer can read, and your PHIPA units can actually follow.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The policy gaps most municipal corporations are carrying

Municipalities rarely lack policy entirely; they lack policies that match how the corporation actually operates today, across departments, boards and an MSP contract nobody has reread in years.

A written safeguards policy

Amended MFIPPA s. 30(5) expects reasonable measures to protect personal information, yet many municipalities have never turned that duty into a document naming who is responsible for encryption, access control and vendor oversight.

Records retention tied to the tax roll and FOI file

Property tax, utility billing, permit and licensing records each carry their own retention period, and a schedule that nobody enforces leaves years of resident data sitting in systems long after any purpose remains.

Councillor and staff acceptable use

Personal email, personal devices and closed-session material need a plain rule set, because a councillor's inbox sits outside the corporation's control the moment confidential material lands in it.

PHIPA-specific policies for health units

Paramedic ePCR, long-term care resident charts and board-of-health files need custodian-grade policies distinct from the corporate MFIPPA set, since PHIPA's notification duty already applies today.

Vendor and data-sharing terms

311/CRM platforms, tax-billing software and the MSP holding administrative access all need policy-level requirements for breach notice, data location and access control before a contract is signed, not after.

Regulatory map

Why council-approved policy now protects the municipality later

The safeguard, PIA and breach duties arriving under MFIPPA all assume a documented program behind them, and regulators, auditors and insurers ask for the paper as much as the practice.

The s. 30(5) safeguard duty

From January 1, 2027, MFIPPA requires reasonable measures to protect personal information, and a council-adopted safeguards policy is the clearest evidence a municipality took that duty seriously rather than reacting after an incident.

Primary source →

A policy anchor for the coming PIA duty

Section 28(3)-(6) will require a privacy impact assessment before new collection, and that process needs a policy telling project teams when to trigger one, built before the deadline rather than during a live procurement.

Primary source →

PHIPA duties that do not wait for 2027

Section 12 already places a legal duty on custodians the moment health records fall into the wrong hands through theft, loss, or unauthorized use, so paramedic and LTC policies must be current now, independent of the municipal MFIPPA timeline.

Read our guide →

EDSTA coverage without a prescribed regulation yet

EDSTA reaches every MFIPPA institution in principle, yet its current cyber regulation, O. Reg. 51/26, names hospitals, children's aid societies, school boards, colleges and universities as the prescribed sectors, with municipalities left off the list for now.

Primary source →

BC and Alberta expect programs, not just intentions

FOIPPA's s. 36.2 privacy management program and Alberta's POPA program requirement, due by June 11, 2026, both presume a documented policy set as their visible core, not a single privacy statement.

Primary source →

What goes wrong

What happens when municipal policy is thin or unread

The gaps that show up in Canadian municipal incidents are rarely exotic; they are the plain policy questions nobody had answered before something went wrong.

  • An access rule nobody wrote down

    Hamilton's 2024 attack began at an internet-facing server; a documented safeguards and access policy is the kind of instrument that forces someone to ask whether that server should have been exposed at all.

    Source →

  • A retention schedule that exists only on paper

    Where disposal never actually runs, a breach reaches further than it should; investigators have found government bodies short of reasonable practices largely because written policy and daily operation diverged.

    Source →

  • A board with no policy of its own

    Toronto Public Library's 2023 incident sat inside a board running its own outdated infrastructure for months before anyone caught it, entirely outside the city's core policy program. Boards need named coverage, not an assumption that city hall's rules extend to them.

    Source →

  • A vendor contract silent on breach terms

    When a SaaS or MSP agreement never specifies notification timing or data location, a municipality learns about a vendor incident on the vendor's schedule, not its own, which is precisely what a vendor policy exists to prevent.

Our policy development for municipalities

The policy set we draft for a municipal corporation

Deliverables follow our standard Policy Development discipline, resequenced around MFIPPA, PHIPA and the way a council actually approves documents.

Modern and luxury office
  1. Gap review against Bill 97 and PHIPA

    We compare existing policies, or their absence, against the 2027 MFIPPA amendments and any PHIPA duties your paramedic, LTC or public-health units already carry, and prioritize the set by risk and deadline.

  2. Core privacy and security policies

    Drafting of a safeguards policy, an information security policy, an access and correction procedure, and a breach-response policy naming roles for the Clerk, IT and the head, written in language your departments will actually use.

  3. Records retention and disposition

    A schedule by record class, from the tax roll to recreation registrations, with disposal mechanics and an owner assigned to each category so the document drives action rather than sitting in a binder.

  4. PHIPA-specific policies

    Separate, custodian-grade policies for paramedic ePCR, LTC resident records and board-of-health files, aligned with the corporate set but written to PHIPA's own notification and consent rules.

  5. Vendor and data-sharing policy

    Standard requirements for SaaS, MSP and data-sharing agreements covering breach notice, data location, access control and Buy Ontario considerations, ready to attach to the next procurement.

How the engagement runs

How we build the policy set with your departments

Drafting happens with the people who will follow the policies daily, and the package ends on a council or committee agenda rather than a shared drive.

  1. Step 1

    Discovery with the Clerk and departments

    Interviews with the Clerk, IT, Treasurer, paramedic and LTC leadership and any board contacts establish what already exists, what the MSP contract actually says, and where the biggest gaps sit.

  2. Step 2

    Draft the set

    We produce the core, PHIPA-specific and vendor policies together, so cross-references stay consistent and nothing contradicts the retention schedule or breach protocol.

  3. Step 3

    Review with legal and the insurer's conditions in view

    Drafts are checked against your insurer's questionnaire commitments and any legal counsel input, so the adopted policy supports the coverage rather than exposing a gap between promise and practice.

  4. Step 4

    Council or committee adoption

    We prepare the approval package and briefing note, present where useful, and finalize the set once council or committee has adopted it.

  5. Step 5

    Annual refresh

    A yearly review folds in MFIPPA and PHIPA developments, staffing changes and any incidents from the sector, timed to land ahead of budget season so updates are funded rather than deferred.

What it costs

What shapes policy development pricing for a municipality

Effort tracks the size of the policy set and the number of distinct units it must cover: a single-tier township drafting a core MFIPPA set is a smaller project than a regional government adding paramedic, LTC and board-of-health policies alongside it. The number of local boards in scope and how much existing material can be revised rather than written from scratch both move the estimate.

Policy Development is one of the inclusions in our Minimum Viable Privacy plan, priced at $5,499 CAD per year, which suits a smaller municipality building its first documented program. Larger or multi-board corporations typically need a broader engagement; tell us your structure and we will return a fixed quote.

Municipalities: Policy development questions, answered

The safeguard duty points to a small set of documents rather than one omnibus policy: an information security policy naming technical and administrative controls, an access-control policy for who can reach personal information and how, a retention and disposal schedule, and a breach-response policy with defined roles. Together they let the municipality show a reviewer that reasonable measures were planned and followed, not assembled after the fact. We map each clause of s. 30(5) to the document that answers it, so nothing is assumed covered that was never actually written.

Yes. Paramedic services and municipal long-term care homes carry health-information-custodian status under PHIPA that the rest of the corporation does not hold, and that status already triggers a notification duty today, well ahead of MFIPPA's 2027 date. Folding paramedic and LTC data into a generic MFIPPA policy usually gets the consent, access and breach-notification rules wrong, because PHIPA's tests differ from MFIPPA's. We draft these as distinct, PHIPA-aligned documents that still reference the corporate policy set where the two overlap, such as vendor management.

Enough to be usable during an incident, not a restatement of best practice. At minimum: roles and authority for approving security spending and declaring an incident, expected controls such as MFA on remote access, a breach-response procedure naming who contacts the IPC and residents, an acceptable-use standard for staff and councillors, and a review cycle tied to the budget calendar. We write it so a councillor without a technical background can read it and still understand what the corporation has committed to.

Yes. Many municipalities start with a defined policy set rather than an ongoing engagement, and our Minimum Viable Privacy plan bundles that drafting work with coaching hours, readiness workshops and training seats at a fixed annual price. Municipalities that later need continuous support, such as an ongoing PIA pipeline or monthly incident handling, typically move that work into a Virtual Privacy Office retainer once the core policy set is in place.

Each board is a separate MFIPPA institution and usually operates its own IT, so it needs named coverage rather than an assumption that municipal policy reaches it automatically. Toronto's 2023 library breach and 2024 zoo incident both happened inside bodies nobody's central program actually reached. The practical model most municipalities use is a shared core policy framework with a short board-specific annex covering that board's systems, contacts and any variations its board of directors must approve separately.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.