
Ontario public libraries will have new privacy governance requirements in place effective January 1, 2027.
Earlier this year, Bill 97, the Plan to Protect Ontario Act (Budget Measures), 2026 received Royal Assent. The bill enacted several amendments to the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA).
For public libraries and other institutions subject to MFIPPA, the amendments fall into two key areas:
- Access request processes
- Privacy governance
Together, these amendments require libraries to take a more structured approach to privacy management, including updating access request procedures, conducting Privacy Impact Assessments (PIAs), and implementing formal processes for assessing, managing, and reporting privacy breaches.
Changes to the Access Request Process
In addition to the upcoming privacy governance requirements, libraries should be aware of several important changes to MFIPPA’s access request process, which came into effect on July 1, 2026.
The amendments give libraries more time to process and respond to requests for information.
More Time to Respond
Effective July 1, 2026, institutions now have 45 business days, rather than 30 calendar days, to respond to access requests (s.19).
Expanded Ability to Extend Timelines
The amendments also introduce greater flexibility when dealing with complex requests. In addition to existing extension provisions, institutions may now take a further extension if:
- the request turns out to be significantly larger than initially understood;
- consultations are required; or
- responding within the legislated timeframe would reasonably interfere with the institution’s operations.
The Information and Privacy Commissioner (IPC) has published an FAQ that provides additional guidance on these new extension provisions and may assist libraries in reviewing and updating their internal access request procedures.
Staged Access Plans
In certain circumstances, institutions may now propose a staged access plan, allowing records to be released in phases rather than all at once.
The IPC’s FAQ outlines what a staged access plan must include and explains a requester’s right to appeal a proposed plan.
Privacy Governance: A Major Shift
While the access request changes are important, the most significant changes for many libraries will be the new privacy governance obligations that come into effect on January 1, 2027.
It will mean adopting a more proactive approach to privacy governance that examines the necessity of collecting personal information, assesses risks before collection occurs, and documents the safeguards needed to protect the information of library patrons.
The primary mechanism for meeting these new privacy governance obligations will be the Privacy Impact Assessment (PIA).
Privacy Impact Assessments Become Mandatory
Effective January 1, 2027, institutions will be required to complete a written Privacy Impact Assessment (PIA) before collecting personal information. PIAs must also be reviewed and updated as practices evolve.
The legislation sets out detailed requirements for PIAs, including:
- the purpose of the collection, use, and disclosure of personal information and why the information is necessary;
- the legal authority for collecting, using, and disclosing the information;
- the types of personal information being collected and how each type will be used or disclosed;
- the source of the information;
- who will have access to it;
- any restrictions on collection, use, or disclosure;
- retention periods;
- safeguards used to protect the information;
- potential privacy risks and their impact on individuals; and
- steps the institution will take to prevent, reduce, and mitigate those risks.
(see s. 28(3) for the statutory text that comes into force on January 1, 2027.)
The IPC’s Planning for Success: Privacy Impact Assessment Guide for Ontario’s Public Institutions is an excellent starting point.
The Ministry of Public and Business Service Delivery will release templates, resources, and further guidance for MFIPPA institutions in advance of January 1, 2027. E-learning modules will also be available in the new year.
Expanded Privacy Breach Notification Requirements
The amendments also strengthen breach-reporting obligations.
Where a privacy breach creates a real risk of significant harm to an individual, institutions must now:
- report the breach to the IPC;
- notify affected individuals; and
- inform those individuals of their right to file a complaint with the Information and Privacy Commissioner.
The IPC’s guidance on managing privacy breaches includes helpful information on assessing whether a real risk of significant harm exists.
Annual Breach Reporting
Starting January 1, 2027, MFIPPA institutions must also track and report annual privacy breach statistics to the IPC.
The first reporting deadline will be March 31, 2028. The IPC website has more information available to help guide you through this process.
Start Planning Now
These changes are substantial, particularly the new Privacy Impact Assessment requirements. They reflect a shift from a compliance-based model of privacy management to a governance-based approach that emphasizes accountability, risk assessment, and proactive planning.
Libraries that begin planning now will be in the best position to meet these new obligations when they take effect on January 1, 2027.
Learn More
Freedom of Information and Protection of Privacy Manual | ontario.ca






Written by:












