Information Governance Policy

Context

Information and information systems are important and valuable assets of the Office of the Information and Privacy Commissioner (OIPC). As such, the OIPC must manage its information management (IM) and information technology (IT) functions to ensure the confidentiality, integrity and availability of OIPC Information Assets.

Purpose

This policy identifies the guiding principles for IM/IT functions, decisions and activities at the OIPC.

Application

This policy applies to all employees of the OIPC.

References

ATIA, POPA, HIA, PIPA, IM/IT Policy Framework, Breach and IT Security Incident Management Directive

Policy Statement

The OIPC manages its Information Assets responsibly to ensure legal compliance and that these Information Assets support operational objectives.

Roles and Responsibilities

There are five key roles or components relevant to information governance at the OIPC:

  • Information and Privacy Commissioner
  • Chief Information Officer
  • Director, IM/IT
  • IM/IT Governance Committee
  • Access/Privacy Coordinator

Information and Privacy Commissioner

The Information and Privacy Commissioner (“the Commissioner”) has overall accountability for confidentiality, integrity and availability of Information Assets at the OIPC. The Commissioner sets out day-to-day responsibility for OIPC access, privacy and information security functions in the job descriptions of OIPC Employees and in contracts, as applicable.

Chief Information Officer

The Assistant Commissioner, Strategic Initiatives and Information Management, who is the OIPC’s Chief Information Officer (“CIO”), is designated as the OIPC’s Privacy Officer. The CIO is responsible for the confidentiality, integrity and availability of Information Assets at the OIPC, including to:

  • ensure that IM/IT policy instruments remain current,
  • investigate and respond to Breaches, and
  • ensure OIPC’s compliance with POPA and its regulations.

Director, IM/IT

The Director, IM/IT is responsible for making reasonable security arrangements to protect OIPC Information Assets. This includes:

  • Ensuring appropriate administrative, physical and technical safeguards are developed, implemented and maintained
  • Investigating and responding to IT security incidents
  • Supporting the Access/Privacy Coordinator in responding to Breaches

IM/IT Governance Committee

The IM/IT Governance Committee (IM/IT GC) is comprised of the Commissioner, CIO, and Director, IM/IT.

The IM/IT GC makes decisions concerning the operations within the OIPC and IM/IT needs and is responsible for approving the IM/IT administrative policies. Additionally, the IM/IT GC is tasked with ensuring that there is alignment between IM/IT and operations within the OIPC, that risks to OIPC Information Assets are appropriately managed, and that records management policies and practices are developed, implemented and maintained.

The IM/IT GC meets monthly together with the IM/IT Operations Subcommittee (IM/IT OS).  Minutes are taken at each meeting.

The IM/IT OS is made up of team leads (or designate) from each OIPC team.  Its purpose is to advise the IM/IT GC on the IM/IT needs of operations and to provide feedback on IM/IT related matters.

Formal decisions are made by the IM/IT GC as needed at the end of each monthly meetings or ad hoc as is needed. All decisions are recorded in minutes of the meetings.

Access/Privacy Coordinator

The Director, Legal Services, is designated as the OIPC’s Access/Privacy Coordinator. The Access/Privacy Coordinator is responsible to ensure the OIPC complies with specific legislated requirements, including but not limited to:

  • Responding to access to information requests, privacy complaints or correction requests submitted under the ATIA or POPA, as applicable,
  • Responding to consultation requests from other public bodies regarding access to information requests, and
  • Supporting the Director, IM/IT in investigating and responding to IT security incidents.

Monitoring and review period

This policy will be reviewed and updated every two years or as required.

Approval

This policy was approved by the IM/IT Governance Committee on September 21, 2026 and is in effect.