Context
The Office of the Information and Privacy Commissioner (OIPC) operates in an environment of evolving threats, technologies, and legal obligations affecting information and information systems. The OIPC makes reasonable security arrangements to protect personal information and maintain the confidentiality of records in its control.
Purpose
To protect the privacy of individuals and the confidentiality, integrity and availability of OIPC Information and OIPC IT Resources.
Application
This directive applies to all employees or third-party service providers of the OIPC.
References
Information Risk Management Policy, Secure Workspace Directive, Electronic Transmission of Information Directive, Information Security Classification Directive, Breach and IT Security Incident Management Directive.
Directive Statements
- This Directive complements the Secure Workspace Directive, which applies to OIPC workspaces, and the Electronic Transmission of Information Directive, which applies to information transmission and the Information Technology Acceptable Use Directive, which establishes acceptable uses of OIPC IT Resources.
Physical safeguards
- Physical access to critical OIPC IT Resources that support OIPC-wide functions must be restricted to OIPC employees or OIPC third-party service providers who require access to perform their work duties.
- When transporting physical records containing OIPC Information, other than solely for records management purposes, the records being transported must be protected with security controls appropriate to the information security classification of the information. The security controls must ensure the risks of loss, destruction, unauthorized disclosure, or unauthorized modification of the OIPC Information while in transit are reduced to acceptable levels (seek guidance from supervisor or from the Director IM/IT, if uncertain). Only security controls authorized by the Director IM/IT are acceptable.
Technical safeguards
- To ensure perimeter security of OIPC IT Resources, a firewall must be set up, maintained and monitored appropriately with the purpose of controlling incoming and outgoing network traffic
- For any connection to OIPC IT Resources that originates from a point outside OIPC offices using an OIPC-issued laptop, a VPN connection must be required to allow the connection. Other OIPC-issued devices, such as smartphones, may be approved for connection to OIPC IT Resources when the Director of IM/IT has ensured security controls are in place.
- The establishment of a VPN connection must be protected by multifactor authentication, which may require the OIPC employee to install an application on their personal smartphone to support that purpose, as directed by the Director, IM/IT.
- Portable computing devices must be protected with a suitable password for the device type:
a) a minimum 6-digit PIN for smartphones, or
b) a password that meets OIPC password requirements for laptops.
- OIPC-issued laptops must have whole-disk encryption enabled and configured according to NIST Cybersecurity Framework specifications and any other industry best practices, as applicable.
Administrative safeguards
- All employees and third-party service providers are expected to remain alert to risks to Information Assets in the course of their day-to-day duties and to report suspected or confirmed risks to their supervisor. This expectation is supported through the requirements of the Information Privacy and Security Training and Awareness Directive.
- The transport of physical records containing Confidential Information outside of OIPC facilities by an OIPC employee or third-party service provider, other than for records management purposes, must be based on valid business needs and must be authorized.
- Only a copy (not the original) of OIPC Information may be transported outside of an OIPC worksite, except where the original copy is required for legal purposes and its transport is approved by the Information and Privacy Commissioner. Only the least amount of OIPC Information necessary to perform a specific job or task may be copied and transported.
- Portable computing devices that contain Confidential Information must be fully powered off prior to leaving worksites or any other OIPC-approved workspace. Putting a portable computing device in hibernation or ‘sleep’ mode does not provide adequate security.
- OIPC-issued portable computing devices must be fully powered off prior to being left unattended inside a temporary accommodation while on OIPC-approved business trips.
- OIPC employees and third-party service providers must seek approval from the Commissioner prior to taking any OIPC IT resource on an international trip. The Commissioner may impose any conditions, or deny approval. If approval is granted and the Commissioner has stipulated any condition, the OIPC employee or third-party service provider must abide by these conditions. In the Commissioner’s absence, the OIPC Chief Privacy Officer may exercise the Commissioner’s authority under this section.
- OIPC Information Assets must not be left unattended while in transit between workspaces. When attending other locations for work purposes, OIPC Information Assets may only be left unattended if there are acceptable physical safeguards in place. No OIPC IT Resources must be left unattended in vehicles.
- When connected to the OIPC network over VPN, OIPC employees must not allow any use of OIPC IT Resources by unauthorized individuals or leave their laptop unattended unless locked.
- OIPC Employees must only gain Internet access for their OIPC-issued portable computing devices through: worksite Wi-Fi network, personal Wi-Fi network at an employee’s residence, or hotspot access set up on an OIPC-issued or personal smartphone. Public Wi-Fi networks must never be used.
- If an OIPC Employee requires mobile connectivity in support of their work duties, they must consult with the Director, IM/IT ahead of time.
- When using a non-OIPC issued information storage device (e.g. a memory stick, disc, or information other storage device received from a third-party) with an OIPC IT resource, a security scan must be completed prior to retrieving data from that device.
- Employees and third-party service providers who use OIPC IT resources must promptly report suspected misuse, loss or a threat to the security or integrity of OIPC IT resources according to the Breach and IT Security Incident Management Directive.
Roles and Responsibilities
Director, IM/IT
Monitors compliance with this directive.
Ensures technical safeguards are implemented and effective.
Consults the Chief Information Officer as needed.
Receives, reviews and responds to employee requests under this directive.
Ensures security arrangements for the physical transport of Confidential Information are implemented and maintained in accordance with applicable OIPC policy instruments
Supervisors
Ensure no practical alternative exists prior to the physical transport of Confidential Information
Provide guidance to their employees according to applicable OIPC policy instruments
Seeks guidance from the Director, IM/IT as needed
Employees and third-party service providers
Take reasonable precautions in day-to-day work to avoid creating vulnerabilities for OIPC IT resources.
Seek guidance from supervisor, contract manager or from the Director IM/IT as applicable
Are responsible to install an application on their personal mobile device to support multifactor authentication, as directed by the Director, IM/IT.
Ensure no practical alternative exists prior to the physical transport of Confidential Information
Promptly report suspected or confirmed breach or IT security incident that involves OIPC Information Assets according to the Breach and IT Security Incident Management Directive.
Monitoring and review period
This directive will be reviewed and updated every two years or as required.
Approval
This directive was approved by the Information and Privacy Commissioner on September 21, 2026 and is in effect.






