Information Privacy and Security Training and Awareness Directive

Context

Information privacy and security training and awareness ensure individuals who access OIPC Information when performing their job functions are able to recognize privacy and security risks and take appropriate actions.

Purpose

To protect the privacy of individuals and the confidentiality, integrity and availability of OIPC Information by ensuring the OIPC provides appropriate information privacy and security training and awareness to its employees and, where required, third-party services providers, in a timely manner.

Application

This directive applies to all employees or third-party service providers of the OIPC.

References

POPA, POPR, Information Governance Policy, Information Risk Management Policy

Directive Statements

  1. All OIPC employees and third-party service providers must receive copies of, or access to, and review the OIPC policy instruments that are relevant to their positions or duties, prior to being given access to OIPC Information Assets.
  2. All OIPC employees must be trained at the start of their employment with the OIPC and regularly retrained on OIPC IM/IT policy instruments, including on changes to IM/IT policy instruments, if applicable. Employee retraining may be provided on an ongoing basis, and a record of attendance for refresher training must be maintained.
  3. All contracts (new or renewed) between the OIPC and third-party service providers must bind the provider to OIPC IM/IT policy instruments. The OIPC contract manager must ensure third-party service providers are trained accordingly, to the extent they collect, use or disclose OIPC Information in delivering the services.

Roles and Responsibilities

Chief Information Officer

Responsible for ensuring that training on OIPC IM/IT policy instruments is provided to new OIPC employees on hire and to third-party service providers on contracting with the OIPC.

Responsible for ensuring that OIPC employees receive ongoing training on OIPC IM/IT policy instruments.

Supervisors

Responsible for arranging training of OIPC employees that report to them and that these OIPC employees understand their responsibility to comply with OIPC IM/IT policy instruments.

Ensure that, for each employee that reports to them, signed acknowledgement(s) and evidence of training on OIPC IM/IT policy instruments are provided to Human Resources to be added to each employee’s file.

Contract managers

Responsible for ensuring that a third-party service provider that they manage complies with the OIPC IM/IT policy instruments relevant to the OIPC Information they collect, use or disclose and receive copies of OIPC IM/IT policy instruments and necessary training on these policy instruments as necessary.

Employees

Upon hire, each new employee shall:

  • When hired under the Public Service Act¸ acknowledge in writing that they have read, understood and will follow the Code of Conduct and Ethics for the Public Service of Alberta.
  • Complete any other privacy and security training as deemed necessary by the Chief Information Officer.
  • Acknowledge in writing that they have read, understood and will follow the OIPC IM/IT policy instruments and have received training on these.
  • Take an oath, administered by the Commissioner, under the Public Service Act and other Acts as determined by the OIPC, to not disclose any OIPC Information unless authorized by law or an OIPC IM/IT policy instrument.

OIPC employees are required to refresh awareness on:

  • the Code of Conduct and Ethics for the Public Service of Alberta at the time specified by the Information and Privacy Commissioner;
  • privacy and security by attending office-coordinated refresher training; and
  • OIPC IM/IT policy instruments, as part of the performance management program regularly conducted by the employee’s supervisor.

Third-party service providers

Third-party service provider are required to:

  • Review OIPC IM/IT policy instruments prior to being given access to OIPC Information Assets and ensure any of the third-party service provider’s employees review the same,
  • Comply with OIPC IM/IT policy instruments and ensure any of the third-party service provider’s employees comply with the same, and
  • Review changes to OIPC IM/IT policy instruments as provided by the OIPC contract manager from time to time.

Monitoring and review period

This directive will be reviewed and updated every two years or as required.

Approval

This directive was approved by the Information and Privacy Commissioner on September 21, 2026 and is in effect.