Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

VPO · Public sector & education

Virtual Privacy Officer for Public Agencies & Crown Corporations

Privacy Horizon's Virtual Privacy Officer runs the privacy operations a public body owes its regulators: PIA pipelines to TBS and the OPC or to the provincial commissioner, breach assessment against the material-breach and RROSH thresholds, and the recurring filings that FIPPA, FOIPPA and POPA now demand. Agencies call when new statutory duties outgrow what an ATIP coordinator can absorb off the side of a desk.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The privacy workload a VPO takes off an agency's desk

Privacy in this niche is operational, with filings, clocks and registers that keep running whether or not anyone is staffed to run them.

PIA pipelines with two recipients

Federal institutions submit privacy impact assessments to both TBS and the OPC and publish summaries; a VPO keeps the intake, drafting and submission flow moving so program launches are not the trigger for a compliance scramble.

Breach triage under statutory clocks

Someone must decide quickly whether an incident is a material breach or meets the real-risk-of-significant-harm threshold, because the federal 7-day report to TBS and the OPC starts once materiality is determined.

ATIP and FOI adjacency

Access requests and privacy duties share files, systems and deadlines; the VPO keeps the two streams consistent so a disclosure decision never contradicts a safeguard commitment.

Personal information banks and Info Source

Federal bodies must keep their descriptions of holdings accurate as programs change, and a designated privacy coach makes those updates routine rather than an annual archaeology project.

Annual and cyclical filings

Ontario institutions owe the IPC breach statistics by March 31 each year, and privacy management programs in BC and Alberta need documented upkeep, all of which a VPO calendars and executes.

Regulatory map

Privacy obligations by owner government, in force now

The last two years rewrote this niche's privacy rulebook in three jurisdictions at once, and the duties below are the ones a VPO engagement is built around.

TBS Policy on Privacy Protection reporting

In effect since October 9, 2024, it requires federal institutions to report material breaches, defined by real risk of significant harm, to TBS and the OPC no later than 7 days after determining materiality.

Primary source →

Directive on Privacy Practices PIA triggers

The directive requires PIAs for new or modified programs using personal information for administrative purposes, submitted to TBS and the OPC, and its Appendix B carries the breach procedures; the standalone PIA directive was rescinded October 9, 2024.

Primary source →

FIPPA's post-July 2025 regime in Ontario

Designated agencies must complete PIAs before collection under s. 38(3), maintain safeguards, notify affected individuals and report qualifying breaches to the IPC, with whistleblower protections in force since January 29, 2025 and a 45-business-day access clock since July 1, 2026.

Primary source →

IPC annual breach statistics

Provincial institutions report privacy-breach statistics to the Commissioner annually by March 31, which requires a working breach log from day one, not a year-end reconstruction.

Primary source →

FOIPPA duties for Schedule 2 Crowns

BC Crown corporations owe privacy management programs under s. 36.2, breach notification to individuals and the OIPC under s. 36.3, and PIAs under s. 69(5.3), alongside the s. 30 security standard.

Primary source →

Alberta's POPA and ATIA

Since June 11, 2025, Alberta agencies, boards and commissions file PIAs with the OIPC and give RROSH breach notice to the Commissioner, individuals and the Minister, with privacy management programs required from June 11, 2026.

Primary source →

What goes wrong

The privacy failures that put agencies in front of regulators

Commissioners' public findings in this sector consistently fault process and oversight rather than technology alone, which is precisely what a VPO exists to fix.

  • Breach response without a materiality decision

    When nobody is assigned to assess harm, the 7-day federal clock or a provincial RROSH duty can lapse while an agency is still debating severity, converting a security incident into a compliance failure.

  • Programs launched without PIAs

    Ontario's s. 38(3) makes the assessment a precondition of collection, and federal directives tie PIAs to program approval; retrofitting one after launch invites exactly the review powers the IPC gained in 2025.

  • Reasonable-practices findings after the fact

    Nova Scotia's commissioner concluded the province lacked reasonable security and information practices after MOVEit exposed data on roughly 100,000 people, a finding template any Canadian commissioner can now reach for.

    Source →

  • Old data nobody owned

    The Toronto Zoo breach reached employee records dating to 1989, and Toronto Public Library's incident affected 8,018 staff and their dependants, showing how unmanaged retention multiplies the population a breach touches.

    Source →

Our vpo for public agencies & crown corporations

What the VPO retainer covers for a public body

The service adapts our standing VPO offering to the instruments and regulators your body answers to.

Business performance checklist, Businessman using laptop online survey filling out check digital form task, business performance monitoring and evaluation. online survey question f
  1. Designated privacy coach

    A named advisor who learns your programs, holdings and governance, and acts as the standing resource for your ATIP or FOI coordinator, counsel and executives.

  2. Compliance monitoring and risk assessments

    Structured reviews against the TBS privacy instruments, FIPPA, FOIPPA or POPA, with practical remediation steps ranked by regulatory exposure.

  3. Incident management protocol

    A documented breach-handling procedure tuned to your notification map, whether that ends at TBS and the OPC, the IPC, the BC OIPC, or Alberta's Commissioner and Minister.

  4. Audits, reporting and filings

    Recurring privacy audits, board and ministry reporting, breach-log upkeep and the March 31 statistics submission where FIPPA applies.

  5. Policy and agreement review

    Ongoing review of privacy policies, information-sharing agreements and vendor terms so documents keep pace with directive changes.

  6. Training and human-risk assessments

    Seats for staff awareness work are included in the retainer, focused on the handling errors that generate reportable incidents in program and case-file environments.

How the engagement runs

Standing up a VPO inside an agency

  1. Step 1

    Map your obligations

    We confirm your status under the Privacy Act, FIPPA, FOIPPA or POPA, inventory holdings and personal information banks, and identify every filing and clock your body owes.

  2. Step 2

    Baseline the program

    An initial assessment scores current practices against your applicable instruments and produces a prioritized privacy workplan endorsed by your executive team.

  3. Step 3

    Run the operations

    The monthly retainer delivers PIA support, breach triage readiness, policy upkeep, training and regulator correspondence, with your designated coach as the single point of contact.

  4. Step 4

    Report and adjust

    Monthly privacy updates and periodic audits show the board and ministry what has improved, and the workplan shifts as directives, programs and AI initiatives evolve.

What it costs

VPO pricing for agencies and Crown corporations

For the Virtual Privacy Office, the starting rate is $2,200 CAD per month with a one-year commitment, including ten hours of monthly coaching, a designated privacy coach, an incident management protocol, inquiries and complaints handling, policy and agreement review, monthly privacy updates and training seats for 25 staff.

Where the fit varies is scope: a federal institution with active PIA submissions to TBS and the OPC, or a FIPPA agency clearing a backlog before its March 31 statistics filing, may need additional hours in early months. We confirm the right level after reviewing your obligations map, and the retainer scales down once the program is in steady state.

Public Agencies & Crown Corporations: VPO questions, answered

The Privacy Act's s. 3 definition captures the bodies listed in its schedule plus parent Crown corporations and their wholly-owned subsidiaries, so most federal Crowns are covered. The report itself is the institution's responsibility, normally executed by the ATIP or privacy office on behalf of the head of the institution, and it must reach TBS and the OPC no later than 7 days after your body determines the breach is material. Your VPO builds the assessment record that makes that determination defensible and drafts the report.

Four things changed for designated agencies on that date: privacy impact assessments before collecting personal information under s. 38(3), a statutory safeguards duty, notification to affected individuals and reporting to the IPC when a breach creates a real risk of significant harm, and IPC review powers behind it all. Whistleblower protections arrived earlier, in January 2025, and the 45-business-day access clock followed on July 1, 2026. Most agencies find the PIA-before-collection rule the hardest to operationalize.

It follows your statute. Federal institutions submit PIAs to both TBS and the OPC under the Directive on Privacy Practices and publish summaries. Ontario FIPPA agencies conduct PIAs before collection but the statute does not route them through a central filing the way the federal regime does; the IPC can review your practices. BC Schedule 2 bodies conduct PIAs under s. 69(5.3), and Alberta public bodies file theirs with the OIPC. The VPO owns whichever pipeline applies and keeps the submission record audit-ready.

Ontario provincial institutions must give the IPC annual statistics on privacy breaches by March 31, which only works if every incident all year was logged with consistent categories: what happened, what data, how many individuals, whether the RROSH threshold was met, and whether notification occurred. We set up the log, embed it in your incident procedure, and prepare the filing, so year-end is an export rather than an investigation of your own inbox.

No, and it should not. The coordinator role carries delegated statutory authority and institutional knowledge that belongs in-house. The VPO backstops that person with specialist depth: harm assessments during a breach, PIA methodology, regulator correspondence, directive interpretation and program development. For small tribunals where one person juggles access, privacy and records, the retainer effectively gives that person a department behind them.

Both provinces now require one by law: FOIPPA s. 36.2 for Schedule 2 Crown corporations and POPA's requirement for Alberta public bodies as of June 11, 2026. In practice it means designated accountability, documented policies and procedures, training, a breach process, service-provider oversight and regular review, all proportionate to your size and holdings. The VPO builds the program document and then, more importantly, generates the ongoing evidence that it is actually operating.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.