Policy development · Public sector & education
Privacy & Security Policy Development for School Boards & K-12 Schools
Policy development gives a board the trustee-approved framework its new obligations assume: a retention schedule with teeth, an edtech vetting standard, breach and PIA procedures for the amended MFIPPA, and acceptable-use rules that reflect O. Reg. 52/26. The project usually starts after a gap becomes undeniable, most famously the IPC's finding that boards had kept student records dating to 1965, retention no written schedule would ever have permitted.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The practices board policies have to govern
Board policy has to reach from the boardroom to a school office counter, covering records and decisions that exist nowhere else in the public sector.
OSR retention, transfer and destruction
Rules for how long Ontario Student Record content and SIS data live, how records follow a student between schools and boards, and when destruction actually happens, with the Education Act's OSR framework as the anchor.
Edtech selection and approval
A vetting standard that decides which classroom apps may touch student personal digital information, who approves them, and what privacy terms are non-negotiable before a teacher can deploy one.
Collection notices and transparency
Policy language governing what families are told, folding the O. Reg. 52/26 vendor-disclosure notices into a coherent transparency posture rather than an annual scramble.
Everyday handling in schools
Direction for office administrators, teachers and principals on custody documents, IEP confidentiality, safe-schools reports and CCTV, written at the level a busy school can follow.
Staff and vendor conduct
Acceptable-use rules for staff accounts and devices, and data-handling standards flowed into vendor and consortium agreements so external parties are held to the board's own bar.
Regulatory map
The mandates a 2026-27 board policy suite must satisfy
Each instrument below either requires a policy outright or fails in practice without one, which is the test we apply to every document we draft.
MFIPPA as amended for 2027
The PIA duty in s. 28(3) to (6), s. 30(5) safeguards and s. 30.1 breach obligations each need a written procedure behind them, and IPC review powers under s. 38.1 mean the paperwork will eventually be examined.
O. Reg. 52/26 and under-18 technology
The notice regime only works if policy assigns ownership of the app inventory and requires data elements, purpose and vendor identity to be captured at adoption, before the school year begins.
The Digital Privacy Charter's commitments
The IPC's twelve commitments for Ontario schools, minimization, transparency and vetting among them, translate directly into policy clauses, whether or not the board formally signs.
The BPS Procurement Directive
Since January 1, 2024, boards must run open competitive procurement at $121,200 and up, and consulting services competitively at any value, so edtech-vetting policy has to mesh with procurement policy rather than route around it.
Buy Ontario obligations
The April 13, 2026 directive layers Canadian and Ontario preference rules and US-business restrictions onto board purchasing, another constraint the vendor-selection policy needs to acknowledge.
What goes wrong
Failures that trace back to missing board policy
The K-12 record shows how policy vacuums become findings. These are the ones we design against.
Sixty years of retained records
Peel's PowerSchool exposure reached files from 1965 and TDSB's from 1985 because nothing forced deletion, and the IPC named over-retention as a factor that widened the breach. A schedule that is enforced, not just published, is the fix.
Contracts signed without privacy terms
The joint investigation found board agreements missing key privacy and security clauses, the predictable result when no policy prescribes mandatory terms for edtech purchases.
Shadow apps in classrooms
Without a vetting policy that teachers know and principals enforce, free tools spread school by school, each one an unassessed collection and a gap in the fall notice inventory.
Thirty schools, thirty practices
When handling rules live in local custom instead of board policy, identical requests, a custody document, an IEP disclosure, a records transfer, get different answers at different schools, and inconsistency is where complaints start.
Our policy development for school boards & k-12 schools
The policy set we draft for a school board
Following the parent service, custom drafting, compliance alignment, employee and vendor guidance and ongoing updates, packaged for trustee governance.

Records retention and destruction schedule
A schedule covering the SIS, the OSR framework, CCTV, safe-schools files and staff records, with disposition triggers your IT team can automate against.
Privacy and breach management policies
The MFIPPA-facing set: collection and notice policy, PIA procedure keyed to the IPC's guide, safeguard standards and the breach-response policy your incident plan operationalizes.
Edtech vetting and acceptable-use standard
The approval path for classroom software, mandatory contract clauses, the inventory feeding O. Reg. 52/26 notices, and acceptable-use rules for staff and students.
Vendor and consortium data-handling standards
Schedules and clause libraries for agreements with SIS, LMS and transportation partners, aligned with OECM's EDSTA-amended master terms.
Trustee approval package
Board-report drafts, rationale memos citing the IPC's findings and the statutory deadlines, and a staged motion plan matched to your meeting calendar.
Administrative procedures and rollout guides
The school-level procedures under each policy, written for principals and office staff, plus a change summary for existing documents rather than gratuitous rewrites.
How the engagement runs
From policy inventory to trustee vote
Board governance sets the tempo, so we plan the project backward from your trustee meeting schedule.
Step 1
Inventory and gap map
We collect current policies and procedures, compare them against MFIPPA 2027, both EDSTA regulations and the IPC's school-sector guidance, and agree the drafting list with priorities.
Step 2
Draft with your operators
Documents are written with the privacy lead, IT and a principal or superintendent reviewer, so every rule survives contact with a real school office.
Step 3
Governance review
Legal and senior-team review, then the trustee package, timed so approvals land before the deadline each policy serves.
Step 4
Roll out and embed
Procedures distributed to schools, a briefing for administrators, and the retention and vetting processes switched on with owners named.
Step 5
Annual maintenance
A yearly review cycle catches statutory changes and IPC guidance, keeping the suite current without another full project.
What it costs
What board policy projects cost, and why
Price follows the drafting list and the governance load: how many policies and administrative procedures are in scope, whether a usable retention schedule exists or must be built from records inventory upward, how many trustee cycles the approvals need, and whether BC or Alberta operations add statutory variants. Translation of parent-facing documents and school-level rollout sessions are the other variables worth budgeting.
A focused engagement, say retention schedule plus edtech vetting standard, is deliberately affordable for smaller boards, while a full MFIPPA-2027 suite is a term-length project. We scope from your policy inventory and quote fixed per document set.
School Boards & K-12 Schools: Policy development questions, answered
One that pairs every record class with a disposition trigger and an owner, and that your SIS configuration actually enforces. For student records that means retention tied to the OSR framework and to defined periods after a student leaves, not indefinite defaults; for the SIS it means purge routines someone runs and logs. The IPC's finding was not that boards lacked documents, it was that decades of data sat in a vendor's system regardless, so we treat automation and an annual disposition report to the senior team as part of the schedule itself.
At minimum: an updated privacy and collection policy reflecting the PIA duty, a safeguards policy satisfying s. 30(5), a breach-response policy implementing s. 30.1 notification, and the retention schedule that underpins all three. Many boards add the edtech vetting standard to the same package because O. Reg. 52/26 makes it urgent. We stage these across two or three meetings with rationale memos, since a single omnibus motion invites deferral, and deferral is the real deadline risk.
Both need to become inventory-driven. The vetting policy should require that any application receiving student personal digital information is approved centrally, recorded with its vendor, data elements and purpose, and only then deployed, because those fields are exactly what the parent and student notices must contain. Acceptable use shifts from a list of banned sites to a positive rule: staff use approved tools from the register, and requests for new ones go through intake. That single change makes the fall notice cycle a report from the register instead of an investigation.
Trustees approve the policy layer, the board's commitments and accountabilities: privacy policy, retention framework, breach policy, vetting standard. The how-to layer, procedures for office staff, PIA templates, contract clause libraries, sits with administration under the Director's authority so it can be updated without a board motion. Splitting the suite this way keeps trustees governing rather than word-smithing, and it means an IPC guidance change in March does not wait for a June meeting.
Plan on a school term for a focused set and most of a school year for a full suite. Drafting moves quickly; the calendar is consumed by senior-team review, legal sign-off and the monthly rhythm of board meetings, plus any committee stage your governance bylaw requires. Starting in September puts approvals comfortably ahead of a January 1 statutory date; starting in spring means competing with budget season for agenda time, which we plan around explicitly.
More for school boards & k-12 schools
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.