¶¶ÒõAPPµ¼º½

Privacy Management Program

Overview

The Government of Alberta has updated Alberta’s public-sector access to information and privacy legislation by repealing the Freedom of Information and Protection of Privacy Act (FOIP) and replacing it with two new pieces of legislation. These changes took effect on June 11, 2025. The new legislation separates access to information and privacy into two distinct frameworks: the Access to Information Act (ATIA) and the Protection of Privacy Act (POPA)

Under POPA, all Alberta public bodies—including ¶¶ÒõAPPµ¼º½â€”are required to establish and maintain a comprehensive Privacy Management Program (PMP). ¶¶ÒõAPPµ¼º½â€™s PMP is an institution‑wide framework designed to ensure that ¶¶ÒõAPPµ¼º½ is prepared to meet its legal responsibilities under POPA, including protecting privacy, providing appropriate access to personal information, and supporting accountability, transparency, and fairness. It outlines the documented policies, procedures and standards that guide how personal information may be managed across all faculties, departments, and administrative units, and reflects ¶¶ÒõAPPµ¼º½â€™s commitment to protecting personal privacy and maintaining public trust.

Oversight of the PMP is provided by the Office of General Counsel, which publishes the PMP and supports its implementation across campus through the ¶¶ÒõAPPµ¼º½ Access and Privacy Office. While the Access and Privacy Office provides guidance and expertise, privacy is a shared responsibility. Every member of the ¶¶ÒõAPPµ¼º½ community plays an integral role in protecting personal information and upholding the principles of POPA. Through this coordinated approach, ¶¶ÒõAPPµ¼º½ will maintain a modern, transparent, and accountable privacy environment that supports teaching, research, and administrative excellence. 

Additional Resources

Privacy Impact Assessments (PIA)

Learn how to identify and mitigate privacy risks relating to the collection, use, or disclosure of personal information and ensure institutional activities comply with POPA.

Privacy Incident/Breach and Complaint Process

Learn how privacy concerns, incidents, and breaches are reported, assessed, and managed at ¶¶ÒõAPPµ¼º½. 

¶¶ÒõAPPµ¼º½ Notice of Collection

Learn how ¶¶ÒõAPPµ¼º½ collects, uses, discloses and protects the personal information of students, staff, and community members.

Data Matching, De-Identification and the Creation of Non-Personal Data

Learn the requirements for data-matching and ¶¶ÒõAPPµ¼º½'s data quality assurance process for the creation, use and disclosure of de-identified or anonymized non-personal data.

Cybersecurity, Privacy Awareness & Research Security Training

Learn more about ¶¶ÒõAPPµ¼º½'s required training to defend our institution against cyberthreats, protect personal information, and ensure the security of our research assets. 

Use of AI and Automated Systems

Learn how to use AI and automated systems responsibly at ¶¶ÒõAPPµ¼º½.