Context
Information Technology (IT) infrastructure of the Office of the Information and Privacy Commissioner (OIPC) is critical to operations and must be protected from misuse. Inappropriate use of OIPC IT Resources may expose OIPC Information to privacy and IT security risks.
Purpose
To protect the privacy of individuals and the confidentiality, integrity and availability of OIPC Information by ensuring OIPC IT resources are appropriately used and secured.
Application
This directive applies to all employees or third-party service providers of the OIPC.
References
Information Risk Management Policy, Office-issued Mobile Communications Device Policy, Breach and IT Security Incident Management Directive, Code of Conduct and Ethics for the Public Service of Alberta
Directive Statements
Acceptable Uses
Unless otherwise specified, the list that follows applies to the use of, and access to, OIPC Information Assets by OIPC employees and third-party service providers:
- Any Business Information or Statutory Information stored on OIPC IT resources is the property of the OIPC.
- Access to and the use of OIPC IT resources must be authorized by the OIPC.
- OIPC IT resources must be used for performing OIPC business functions. IT resources not issued by the OIPC are not to be used for performing OIPC business functions, unless authorized by the OIPC.
- The use of OIPC IT Resources must be in compliance with all OIPC IM/IT policy instruments and the Code of Conduct and Ethics for the Public Service of Alberta.
- The use of an OIPC-issued mobile communications devices must be in accordance with the Office-issued Mobile Communications Device Policy and this directive.
- OIPC Information other than transitory information must be stored within the OIPC network to ensure the information is backed up. Unless authorized by the Director, IM/IT, storing OIPC Information other than transitory information on a local computer hard drive or mobile device is prohibited.
- Employees may utilize OIPC IT resources for limited and reasonable personal purposes provided such use does not conflict or interfere with their job duties and would not harm the reputation of the OIPC. Employees should consult with their supervisors when in doubt about such use.
- Any information that is not Business Information or Statutory Information and in which an employee has a reasonable expectation of privacy should be kept in a separate folder labelled “Personal”. The extent to which employees may have a reasonable expectation of privacy in their personal use of OIPC IT resources is a question of fact and law.
- Streaming media (e.g. videos, music, etc…) from the internet may only be used for work-related purposes.
- Only OIPC-approved software may be installed or used on OIPC IT resources. Approval of software shall be based on business needs.
- Software installations on OIPC computers and network must only be performed by authorized OIPC IM/IT personnel.
- Software applications may require a user to set up an individual account; such accounts should be set up as directed by the Director, IM/IT.
- Where no alternatives exist, only OIPC-approved information storage devices can be used with OIPC computers. No personally-owned information storage device is permitted for use with any OIPC IT resources.
- Employees may only connect non-OIPC issued computer peripherals (e.g. monitors, keyboards, mice, speakers, etc..) to an OIPC IT Resource with prior approval from the Director, IM/IT.
- The Chief Information Officer (CIO) and OIPC Communications Manager are the only employees authorized to represent the OIPC on social media platforms, unless otherwise approved by the Information and Privacy Commissioner.
Unacceptable Uses
The following is a non-exhaustive list of unacceptable uses of OIPC IT resources:
- Sharing system accounts or authentication credentials with any other person, unless authorized by the Commissioner.
- Downloading or installing unauthorized software onto OIPC IT resources.
- Using OIPC IT resources for harassment or violence, or to circulate or access inappropriate materials, such as pornography.
- Visiting internet sites where the visit could harm the reputation of the OIPC. If work duties require visiting a questionable internet site and/or maintaining anonymity, an employee should seek direction from the Director, IM/IT and the CIO.
- Using OIPC IT resources, including the internet, to perform unauthorized download, copying or distribution of materials in violation of applicable protection of the materials, including but not limited to copyright and intellectual property rights laws.
- Using OIPC IT resources to send unsolicited communications, including but not limited to spam.
- Forwarding OIPC email containing Confidential Information to a non-OIPC email account.
- Storing copies of OIPC emails on computing devices or in accounts other than OIPC Information Assets.
- Using OIPC IT resources to spread malicious software, including but not limited to viruses, worms, Trojan horses, spyware, ransomware and other forms of malware.
- Modifying the configuration settings of OIPC IT Resources, including but not limited to technical security controls settings for internet security software and firewall, without authorization.
- Installing, plugging, connecting or otherwise introducing unauthorized hardware within OIPC IT resources.
- Third-party service providers who use OIPC IT resources are prohibited from using OIPC IT resources for personal use.
- Using the OIPC social media account to communicate views contrary to those of the OIPC.
Compliance Monitoring
- The OIPC monitors its IT environment to ensure safeguards are working as expected and to detect and prevent potential information security issues within its information systems.
- The OIPC reserves the right to audit networks and systems on a periodic basis to ensure compliance with this directive or any other OIPC IM/IT policy instruments.
- Any auditing activities undertaken must follow IT auditing procedures established by the OIPC, or instructions given by the Commissioner, if any.
Change requests
- OIPC employees who identify a need to change their access to hardware, software or any other OIPC IT resources, to enable them or others to meet operational needs, shall make such requests to their supervisor or to the Director, IM/IT, as appropriate.
- The Director, IM/IT shall address requests received from employees directly, or bring them to the attention of the OIPC Information Management / Information Technology Governance Committee, as appropriate.
Roles and Responsibilities
Director, IM/IT
Monitors OIPC IT environment and compliance with this directive.
Ensures technical safeguards are implemented and effective.
Consults the Chief Information Officer as needed.
Receives, reviews and responds to employee requests under this directive.
Supervisors
Receive and escalate employee requests under this directive.
Contract managers
Receive and escalate third-party service provider requests under this directive.
Employees
Use OIPC IT resources and manage OIPC Information in compliance with this directive.
Consult with their supervisor or the Director, IM/IT as required by this directive.
Monitoring and review period
This directive will be reviewed and updated every two years or as required.
Approval
This directive was approved by the Information and Privacy Commissioner on September 21, 2026 and is in effect.






