Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Policy development · Public sector & education

Privacy & Security Policy Development for School Boards & K-12 Schools

Policy development gives a board the trustee-approved framework its new obligations assume: a retention schedule with teeth, an edtech vetting standard, breach and PIA procedures for the amended MFIPPA, and acceptable-use rules that reflect O. Reg. 52/26. The project usually starts after a gap becomes undeniable, most famously the IPC's finding that boards had kept student records dating to 1965, retention no written schedule would ever have permitted.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The practices board policies have to govern

Board policy has to reach from the boardroom to a school office counter, covering records and decisions that exist nowhere else in the public sector.

OSR retention, transfer and destruction

Rules for how long Ontario Student Record content and SIS data live, how records follow a student between schools and boards, and when destruction actually happens, with the Education Act's OSR framework as the anchor.

Edtech selection and approval

A vetting standard that decides which classroom apps may touch student personal digital information, who approves them, and what privacy terms are non-negotiable before a teacher can deploy one.

Collection notices and transparency

Policy language governing what families are told, folding the O. Reg. 52/26 vendor-disclosure notices into a coherent transparency posture rather than an annual scramble.

Everyday handling in schools

Direction for office administrators, teachers and principals on custody documents, IEP confidentiality, safe-schools reports and CCTV, written at the level a busy school can follow.

Staff and vendor conduct

Acceptable-use rules for staff accounts and devices, and data-handling standards flowed into vendor and consortium agreements so external parties are held to the board's own bar.

Regulatory map

The mandates a 2026-27 board policy suite must satisfy

Each instrument below either requires a policy outright or fails in practice without one, which is the test we apply to every document we draft.

MFIPPA as amended for 2027

The PIA duty in s. 28(3) to (6), s. 30(5) safeguards and s. 30.1 breach obligations each need a written procedure behind them, and IPC review powers under s. 38.1 mean the paperwork will eventually be examined.

Primary source →

O. Reg. 52/26 and under-18 technology

The notice regime only works if policy assigns ownership of the app inventory and requires data elements, purpose and vendor identity to be captured at adoption, before the school year begins.

Primary source →

The Digital Privacy Charter's commitments

The IPC's twelve commitments for Ontario schools, minimization, transparency and vetting among them, translate directly into policy clauses, whether or not the board formally signs.

Primary source →

The BPS Procurement Directive

Since January 1, 2024, boards must run open competitive procurement at $121,200 and up, and consulting services competitively at any value, so edtech-vetting policy has to mesh with procurement policy rather than route around it.

Primary source →

Buy Ontario obligations

The April 13, 2026 directive layers Canadian and Ontario preference rules and US-business restrictions onto board purchasing, another constraint the vendor-selection policy needs to acknowledge.

Primary source →

What goes wrong

Failures that trace back to missing board policy

The K-12 record shows how policy vacuums become findings. These are the ones we design against.

  • Sixty years of retained records

    Peel's PowerSchool exposure reached files from 1965 and TDSB's from 1985 because nothing forced deletion, and the IPC named over-retention as a factor that widened the breach. A schedule that is enforced, not just published, is the fix.

    Source →

  • Contracts signed without privacy terms

    The joint investigation found board agreements missing key privacy and security clauses, the predictable result when no policy prescribes mandatory terms for edtech purchases.

  • Shadow apps in classrooms

    Without a vetting policy that teachers know and principals enforce, free tools spread school by school, each one an unassessed collection and a gap in the fall notice inventory.

  • Thirty schools, thirty practices

    When handling rules live in local custom instead of board policy, identical requests, a custody document, an IEP disclosure, a records transfer, get different answers at different schools, and inconsistency is where complaints start.

Our policy development for school boards & k-12 schools

The policy set we draft for a school board

Following the parent service, custom drafting, compliance alignment, employee and vendor guidance and ongoing updates, packaged for trustee governance.

Modern and luxury office
  1. Records retention and destruction schedule

    A schedule covering the SIS, the OSR framework, CCTV, safe-schools files and staff records, with disposition triggers your IT team can automate against.

  2. Privacy and breach management policies

    The MFIPPA-facing set: collection and notice policy, PIA procedure keyed to the IPC's guide, safeguard standards and the breach-response policy your incident plan operationalizes.

  3. Edtech vetting and acceptable-use standard

    The approval path for classroom software, mandatory contract clauses, the inventory feeding O. Reg. 52/26 notices, and acceptable-use rules for staff and students.

  4. Vendor and consortium data-handling standards

    Schedules and clause libraries for agreements with SIS, LMS and transportation partners, aligned with OECM's EDSTA-amended master terms.

  5. Trustee approval package

    Board-report drafts, rationale memos citing the IPC's findings and the statutory deadlines, and a staged motion plan matched to your meeting calendar.

  6. Administrative procedures and rollout guides

    The school-level procedures under each policy, written for principals and office staff, plus a change summary for existing documents rather than gratuitous rewrites.

How the engagement runs

From policy inventory to trustee vote

Board governance sets the tempo, so we plan the project backward from your trustee meeting schedule.

  1. Step 1

    Inventory and gap map

    We collect current policies and procedures, compare them against MFIPPA 2027, both EDSTA regulations and the IPC's school-sector guidance, and agree the drafting list with priorities.

  2. Step 2

    Draft with your operators

    Documents are written with the privacy lead, IT and a principal or superintendent reviewer, so every rule survives contact with a real school office.

  3. Step 3

    Governance review

    Legal and senior-team review, then the trustee package, timed so approvals land before the deadline each policy serves.

  4. Step 4

    Roll out and embed

    Procedures distributed to schools, a briefing for administrators, and the retention and vetting processes switched on with owners named.

  5. Step 5

    Annual maintenance

    A yearly review cycle catches statutory changes and IPC guidance, keeping the suite current without another full project.

What it costs

What board policy projects cost, and why

Price follows the drafting list and the governance load: how many policies and administrative procedures are in scope, whether a usable retention schedule exists or must be built from records inventory upward, how many trustee cycles the approvals need, and whether BC or Alberta operations add statutory variants. Translation of parent-facing documents and school-level rollout sessions are the other variables worth budgeting.

A focused engagement, say retention schedule plus edtech vetting standard, is deliberately affordable for smaller boards, while a full MFIPPA-2027 suite is a term-length project. We scope from your policy inventory and quote fixed per document set.

School Boards & K-12 Schools: Policy development questions, answered

One that pairs every record class with a disposition trigger and an owner, and that your SIS configuration actually enforces. For student records that means retention tied to the OSR framework and to defined periods after a student leaves, not indefinite defaults; for the SIS it means purge routines someone runs and logs. The IPC's finding was not that boards lacked documents, it was that decades of data sat in a vendor's system regardless, so we treat automation and an annual disposition report to the senior team as part of the schedule itself.

At minimum: an updated privacy and collection policy reflecting the PIA duty, a safeguards policy satisfying s. 30(5), a breach-response policy implementing s. 30.1 notification, and the retention schedule that underpins all three. Many boards add the edtech vetting standard to the same package because O. Reg. 52/26 makes it urgent. We stage these across two or three meetings with rationale memos, since a single omnibus motion invites deferral, and deferral is the real deadline risk.

Both need to become inventory-driven. The vetting policy should require that any application receiving student personal digital information is approved centrally, recorded with its vendor, data elements and purpose, and only then deployed, because those fields are exactly what the parent and student notices must contain. Acceptable use shifts from a list of banned sites to a positive rule: staff use approved tools from the register, and requests for new ones go through intake. That single change makes the fall notice cycle a report from the register instead of an investigation.

Trustees approve the policy layer, the board's commitments and accountabilities: privacy policy, retention framework, breach policy, vetting standard. The how-to layer, procedures for office staff, PIA templates, contract clause libraries, sits with administration under the Director's authority so it can be updated without a board motion. Splitting the suite this way keeps trustees governing rather than word-smithing, and it means an IPC guidance change in March does not wait for a June meeting.

Plan on a school term for a focused set and most of a school year for a full suite. Drafting moves quickly; the calendar is consumed by senior-team review, legal sign-off and the monthly rhythm of board meetings, plus any committee stage your governance bylaw requires. Starting in September puts approvals comfortably ahead of a January 1 statutory date; starting in spring means competing with budget season for agenda time, which we plan around explicitly.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.