Electronic Transmission of Information Directive

Context

Employees of the Office of the Information and Privacy Commissioner (OIPC) routinely exchange information using electronic means. Risk to information is inherent in the OIPC’s operations, and increases when information is transmitted. The OIPC is obligated to make reasonable security arrangements to protect the confidentiality, availability and integrity of information when it is transmitted.

Purpose

To ensure the privacy of individuals and the confidentiality, integrity and availability of OIPC Information are protected when transmitting information via email, protected file transfer, and fax, and to restrict the use of SMS, MMS and Instant Messaging.

Application

This directive applies to all employees or third-party service providers of the OIPC.

References

Information Risk Management Policy, Collection, Use and Disclosure of Business Information Policy, Office-issued Mobile Communications Device Policy, Breach and IT Security Incident Management Directive, Information Security Classification Directive, OIPC Records Retention and Disposition Schedules

Directive Statements

Transmission of Protected C Information

  1. Prior to any electronic transmission of OIPC Information classified as Protected C, the Director, IM/IT must be notified and transmission may only occur in accordance with any requirements provided by the Director, IM/IT.
  2. In the absence of the Director, IM/IT, the Chief Information Officer may perform this function.

Email Communication

  1. The OIPC email system is for the purpose of supporting OIPC functions.
  2. The use of the OIPC email system must be in compliance with the Information Technology Acceptable Use Directive, the Collection, Use and Disclosure of Business Information Policy and the Code of Conduct and Ethics for the Public Service of Alberta.
  3. Ensure the recipient has approved use of email and has provided an email address for communication purposes.
  4. Email may be used to transmit Public Information and Protected A level information without encryption or additional security measures.
  5. When email is used to transmit content or documents containing Protected B or C level information, the following applies:

a) Limit personal information included in the email to only what is necessary to enable the transmission, such as name and email address.
b) The transmission must be protected, either by encrypting attachments containing Confidential Information, or by using an OIPC-approved protected file transfer system.
c) The password chosen to encrypt attachments must comply with established OIPC Password requirements.
d) The use of an OIPC-approved secure file transfer system must be in accordance with any rules specific to that system.
e) The transmission of passwords that serve to protect Confidential Information in electronic form to an external recipient must, whenever possible, be provided to that recipient using a communication channel that is distinct from the one used to transmit the Confidential Information, e.g. via a phone call to the recipient if the confidential information is to be transmitted via email.
f) Email transmission originating from OIPC email systems must carry a standard disclaimer or confidentiality notice.
g) OIPC Employees must follow any other requirements as set out in OIPC standards from time to time.

  1. When it is necessary for an OIPC Employee to transmit Confidential Information internally, only the required Confidential Information should be transmitted, and it does not require additional security measures to be taken.
  2. Transitory email records should be deleted from OIPC email in accordance with the OIPC Transitory Records Retention and Disposition Schedule.
  3. Email records retention must be in compliance with the OIPC Operational and Administrative Records Retention and Disposition Schedules, OIPC records management policies and procedures, and applicable legislation.

SMS, MMS, RCS and Instant Messaging

  1. Official OIPC transactions must be documented and retained in accordance with the Operational and Administrative Records Retention and Disposition Schedules, OIPC records management policies and procedures, and applicable legislation.
  2. It is prohibited to use SMS, MMS, or RCS to transmit Confidential Information.
  3. Instant Messaging may be used for day-to-day interactions among OIPC employees and other stakeholders. However, instant messages are transitory records and may not be used to request supervisor approval, or to convey decisions, when such decisions must be documented.

Fax Communication Procedure

  1. Since communicating information via fax transmission is inherently unprotected, using fax transmission to communicate Confidential Information must be based on necessity, such as when a recipient is unable to correspond over email.
  2. The use of OIPC fax systems must be in compliance with the Information Technology Acceptable Use Directive, the Collection, Use and Disclosure of Statutory Information Policy and the Collection, Use and Disclosure of Business Information Policy.
  3. The OIPC shall designate one or more employees as responsible for handling fax communications (incoming and outgoing). A backup shall be designated to handle instances in which the primary designate is unable to fulfil his or her role.
  4. OIPC outgoing fax communications must be sent using the OIPC standard cover sheet that contains:

a) The name, title and organization of both the sender and the intended recipient, and the total number of pages being faxed.
b) A check box that allows the sender to indicate (check off) whether the recipient should provide confirmation of successful receipt of the fax transmission. When Protected A or Protected B information is transmitted via fax, the sender must request the recipient to confirm receipt of the information.
c) The information security classification of the information transmitted.
d) A note advising any individual who may receive the fax transmission in error to immediately notify the OIPC and not to disclose the information further.

  1. The sender of a fax communication must confirm the accuracy of a fax number before and after dialing to ensure the fax is transmitted to the intended recipient. For instance, the sender contacts the intended recipient and confirms the fax number before dialing the number and then checks to ensure the correct number has been dialed before pressing the “send” key on the machine.
  2. Prior to initiating a fax communication that contains confidential information, the sender must contact and advise the intended recipient that the information will be transmitted via fax and to confirm if it is acceptable to transmit the information by fax.
  3. The sender of a fax communication must take steps to confirm that the faxed information was successfully transmitted. For instance, the sender prints and reviews activity reports of the fax transmission or contact the intended recipient to confirm that all the documents transmitted have been received.
  4. The OIPC must take steps to notify senders of fax communications received in error by the OIPC and to prevent further unauthorized disclosure of the faxed information.

Roles and Responsibilities

CIO

Implements, maintains and monitors administrative safeguards for electronic transmission channels.

Director, IM/IT

Prescribes security requirements applicable to the transmission of Protected C information by OIPC employees.

Implements, maintains and monitors technical safeguards for electronic transmission channels.

Employees

Exercise reasonable care when transmitting any information electronically.

When transmitting Confidential Information electronically, ensure they make security arrangements that are proportional to the classification level of the information.

Monitoring and review period

This directive will be reviewed and updated every two years or as required.

Approval

This directive was approved by the Information and Privacy Commissioner on September 21, 2026 and is in effect.