Information Security Classification Directive

Context

The Office of the Information and Privacy Commissioner (OIPC) collects, uses, discloses and retains information of varying degrees of sensitivity and criticality in the course of carrying out its duties. It is vital to ensure OIPC Information is appropriately classified and reasonably protected.

Purpose

To protect the privacy of individuals and the confidentiality, integrity and availability of OIPC Information by appropriately classifying and labelling information.

Application

This directive applies to all OIPC Employees and Third-Party Service Providers.

References

POPA, POPR, Information Risk Management Policy, Information Security Directive, Secure Workspace Directive

Directive Statements

Information Security Classification

Public Information

Information that if unavailable, or accessed or disclosed in an unauthorized manner, would cause little or no harm or disruption to the OIPC and its business operations, other public bodies, custodians, organizations or individuals.

For example, news releases are classified as public information once published.

Protected A Information

Information that if unavailable, or if accessed or disclosed in an unauthorized manner, could cause moderate harm to OIPC, other public bodies, custodians, organizations or individuals.

For instance, OIPC internal business process information, or not-yet published news releases are classified as Protected A information.

Protected B Information

Information that if unavailable, or if accessed or disclosed in an unauthorized manner, could cause serious harm to the OIPC, other public bodies, custodians, organizations or individuals. Serious harm to the OIPC and other public bodies includes, but is not limited to, loss of public trust and reputational damage. Serious harm to custodians and organizations includes, but is not limited to, financial loss, loss of competitive advantage and reputational damage. Serious harm to individuals includes, but is not limited to, financial loss, hurt, humiliation, embarrassment, and reputational harm.

For example, any information, including personal and health information, obtained by OIPC employees in performing duties, powers and functions under the Acts and that OIPC employees are restricted from disclosing, is Protected B information.

Protected C Information

Information that if unavailable, or if accessed or disclosed in an unauthorized manner, could cause grave harm to the OIPC, other public bodies, custodians, organizations or individuals. Grave harm includes, but is not limited to, loss of life, loss of public safety, significant financial loss, compromise of legal records, significant damage, sabotage, or terrorism.

For example, administrator-level credentials giving access to OIPC information assets are Protected C information.

Relation to previous Information Security Classification

A table that maps the current information security classification levels in relation to the previous ones

Roles and Responsibilities

Chief Information Officer

Responsible to ensure this directive remains current.

Director IM/IT

Ensures OIPC IT Resources are classified according to OIPC Information Security Classification Directive.

Responsible to implement safeguards that reasonably mitigate risk to OIPC Information Assets, and identify OIPC IT Resources without suitable safeguards (such as legacy systems) for inclusion in the IM/IT Risk Register.

Supervisors

Ensure their direct reports understand and follow OIPC IM/IT policy instruments according to information classification levels when handling OIPC Information.

Employees

Follow OIPC IM/IT policy instruments according to information classification levels when handling OIPC Information.

Responsible to apply safeguards that reasonably mitigate risk to OIPC Information Assets.

Monitoring and review period

This directive will be reviewed and updated every two years or as required.

Approval

This directive was approved by the Information and Privacy Commissioner on September 21, 2026 and is in effect.