Context
Workspaces of the Office of the Information and Privacy Commissioner (OIPC) contain or provide access to OIPC Information. Unprotected OIPC Information in workspaces may lead to a breach of Business Information or Statutory Information, or to an IT security incident where OIPC Information is accessed without authority, including by other employees and service providers.
Purpose
To protect the privacy of personal information contained in Business Information and the confidentiality, integrity and availability of all OIPC information by maintaining appropriate safeguards controls for workspaces.
Application
This directive applies to all employees or third-party service providers of the OIPC.
References
Information Risk Management Policy, Information Security Directive, Breach and IT Security Incident Management Directive, Information Security Classification Directive
Directive Statements
Workspaces
- This directive applies to all workspaces, including worksites, a remote worksite, or a temporary workspace.
- While working in any workspace, reasonable steps must be taken to prevent other individuals from accessing Protected B or Protected C Information, unless the access is authorized.
- If OIPC Information is viewable by others while an OIPC employee is working, the employee must use preventative controls such as a privacy screen or closed door, or re-positioning their monitors as required.
- Anytime an OIPC employee leaves an OIPC-issued laptop or smartphone unattended in their workspace, the employee must ensure that they screen-lock (Windows-L) their laptop or smartphone, and consider if additional physical locks are required.
OIPC Worksites
- OIPC employees must be vigilant and aware of their surroundings when entering and leaving any OIPC worksite and must not allow unknown individuals to enter an OIPC worksite.
- Transitory records containing Protected B and C Information must be placed in locked shredding bins.
- Print jobs containing Protected B and C Information must be sent to printers using secure print and once printed immediately removed.
- Any person accessing an OIPC worksite that is not an OIPC employee must be escorted by and be in the presence of an OIPC employee at all times, unless that person is authorized to be left unaccompanied in an OIPC worksite to perform a specific function for or on behalf of the OIPC. For the latter, the OIPC employee that allows the person to enter an OIPC worksite must provide the person with their name and is accountable for the person while they are in the office and for ensuring that the person leaves at the end of the workday.
- If an OIPC employee sees an unaccompanied person in an OIPC worksite, they must ask the person for the name of the OIPC employee who let them enter the office, then check with that named OIPC employee to verify the information. If the person cannot name an OIPC employee responsible for their presence, the person must be immediately escorted out of the worksite. If an OIPC employee is not comfortable approaching a person they do not recognize, they must seek help from a co-worker or seek further instruction from a member of the senior leadership team about next steps. The safety of OIPC employees is paramount.
- At the end of each workday, the worksite must be clear of Protected B and C Information and steps taken to prevent access to this information by any person, including cleaning staff, such as by locking this Information in filing cabinets or in secure storage and erasing this Information from whiteboards.
- At the end of each workday, the last person leaving the worksite must ensure all perimeter doors are locked and the alarm is set, or scheduled to be set.
- Other than OIPC employees, any person accessing an OIPC worksite after hours must have prior authorization by the OIPC to do so.
Remote worksites
- Any workspace an OIPC Employee routinely uses outside of an OIPC worksite must be authorized by the Commissioner.
- While working at their remote worksite, OIPC employees:
a) Must not print Protected B or Protected C Information, and
b) Must minimize the inclusion of Confidential Information in handwritten notes.
Roles and Responsibilities
Director, IM/IT
Ensures security arrangements are implemented and maintained in accordance with this directive
Employees and third-party service providers
Take reasonable precautions in day-to-day work to ensure the security of their workspace
Report any situation that impacts the security of a workspace or OIPC IT Resource according to the Breach and IT Security Incident Management Directive
Monitoring and review period
This directive will be reviewed and updated every two years or as required.
Approval
This directive was approved by the Information and Privacy Commissioner on September 21, 2026 and is in effect.






