Why Care About Privacy
Public confidence in the responsible management of personal information is crucial to building and maintaining residents' trust. To achieve this, each city must adopt a data governance framework that maintains integrity, security and trustworthiness.
The Government of British Columbia enacted Bill 22 to amend the Freedom of Information and Protection of Privacy Act. A few of the amendment highlights include:
- Requiring public bodies to have a privacy management program.
- Implementing mandatory privacy breach reporting.
- Increasing penalties for offences and adding new offences for evading FOI.
Enforcement of these changes is expected to begin on February 1st, 2023. In future investigations and audits, the Office of Information & Privacy Commissioner for British Columbia will look for evidence of a privacy program.
The Role of a Privacy Officer
What are the duties of a privacy officer?
Let’s take a closer look...
A privacy officer is the first point of contact when privacy issues arise. They are responsible for developing and communicating a privacy policy, monitoring compliance, and handling complaints.
They must also be knowledgeable about new privacy regulations and updates as they happen.
Each municipality must have, at a minimum, strong privacy and data breach policies to comply with regulations. Bring policies to life by ensuring employees receive the appropriate privacy and security training.
Finally, be prepared to work with the Information and Privacy Commissioner in the event of an investigation
Everyone in City Hall is busier than ever. We want to help your privacy program succeed.
Recipe For Success

Recipe:
As you might imagine, there isn’t a one-size-fits-all approach to building a good privacy program. There are, however, key principles and actions that are essential for every municipality.
By following these steps, you’ll create a program that helps protect from data privacy risks and lets you collect, manage, and process data in a way that respects data privacy regulations.
Whichever step you're on, we can help!
- Start by designating a Privacy Officer and develop or confirm a privacy policy.
- Next conduct an organizational review to see what needs to be addressed for your municipality to become privacy compliant.
- Examine all Forms (paper and digital), subscription forms, surveys, application forms, newsletter lists, etc.
- Start with Senior Management, Managers/Supervisors and then follow with Staff to best gain buy-in support.
- Release promotional material about privacy policies and protocols.
- Use online quizzes and contests to drive awareness and engagement.
- Start with Senior Management, Managers/Supervisors and then follow with Staff to best gain buy-in support.
- Utilize ready-made on-demand courses, or customize your own!
The following courses were developed in conjunction with the City of Surrey, a leading municipality in the knowledge and application of the BC Provincial Freedom of Information and Protection of Personal Information Act, (FIPPA or FOIPPA), one of the most comprehensive pieces of privacy legislation in Canada.

Privacy Awareness: This 20-minute, four-module course begins with a real-life case study and explores the fundamental concepts of privacy, personal information and responsibilities; the management of access and freedom of information, (FOIPPA); the collection, use and sharing of personal information; and how to protect personal information in the Municipal environment. Brief quizzes are presented with opportunities to review and retry after each module with the objective of reaching a 100% pass.
Canadian Anti-Spam Legislation (CASL) Awareness: This 20 minute, interactive course reviews the definition and purpose of the legislation; what actions are prohibited; guidance related to commercial electronic messages, (CEM) including affirmative action in consent; and the implications both legally and monetarily to organizations who do not maintain a rigorous list, message and consent practices. One quiz is presented with the opportunity to review and retry with the objective of reaching 100%.
Records Management: This 20-minute, four-module course is intended to help staff understand their obligations related to records management. It covers why records management is important; what effective record keeping is; and key concepts such as a corporate file plan, filing and naming conventions; and the management of the various phases and types of a record. Each module is followed by a brief quiz and the opportunity to review and retry with the objective of reaching 100%.
- Use Privacy Assessment results as a work plan to bring materials into compliance.
- Require PIA’s to be completed for all new activities involving ‘personal information’.
- Ensure a FOIPPA Compliance Statement is on every form and survey.
- Monitor activities with regular reporting and audits.
- Refresh awareness and reinforce behaviour by using events, quizzes and contests.
- Update privacy awareness training – annually or bi-annually for all staff (and onboarding for new staff).
Get Started
Free Consultation Offer
Kent Waugh, Managing Partner
Founder and Managing Partner, Kent Waugh, has 40 years of experience conducting public consultation on behalf of dozens of communities.
Kent works exclusively with municipalities and has provided ongoing FOIPPA & CASL legislation support to the City of Surrey for the past 10 years
With the right partner by your side, you can rest assured that your privacy program is on the best path to success.
The W Group Services
Good privacy practice starts here. Our expertise in the following areas can help bring your privacy program to life.
Simplify data collection. Improve user experience and ease data entry costs. Move beyond paper-based forms or fillable PDFs to leverage dynamic data flow.
Turn your subject into a vibrant and interactive online learning experience. For less than you think. Options range from per-seat, to full-custom, with or without an LMS.
Get the insights you need to be confident in your report. Great research delivers meaningful, actionable, and accurate results.
Secure your audience, and build your community. Take engagement to the next level with measurable, direct communications.
Gain clear insights required to improve facilities, programs, and services. Manage issues in near real-time and deliver a great customer experience.
Leverage turn-key, affordable project pages to maximize awareness, understanding, and participation. No code. No login. No-fuss.