RSS Amplifier

Chris's Musing · Apr 23, 2026

New Privacy and Cyber Security Rules for Ontario K-12 Schools

0
Sign in to vote or save

Chris R Dale · Chris's Musing

Ontario is changing how K-12 classrooms use digital tools. For years, EdTech vendors worked in a flexible market where data privacy and cyber security were optional competitive edges. New laws have ended that era.

With Bill 97 (Plan to Protect Ontario Act, 2026) and the Enhancing Digital Security and Trust Act, 2024 (EDSTA), the province now mandates specific rules instead of voluntary guidelines. These laws change how school boards buy software and what makes a product “compliant.” As a vendor, you must now prove you can pass audits and ensure your contracts follow the law.

Under Bill 97, school boards must record every app that accesses student data. In the past, competitors could use Freedom of Information (FOI) requests to see these lists and map out a rival’s business.

The government has changed this. Bill 97 and EDSTA now explicitly block “Authorized Software” records from FOI disclosure by amending the Freedom of Information and Protection of Privacy Act (FIPPA) and the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA).

This Act does not apply to... Records containing the names of software applications that have been purchased or otherwise acquired by school boards, that are owned or operated by third parties and that are authorized to access a student’s personal information... [or] any other records the disclosure of which could reasonably be expected to compromise cyber security for a public sector entity.“ (Bill 97, adding Section 65 (22) to FIPPA and Section 52 (7) to MFIPPA).

What this means: Your presence on a school board’s list is now a legal secret to protect provincial cyber security. This makes it harder for competitors to research your market share, but it also means you must meet high technical standards to stay on those lists.

Starting January 1, 2027, school boards cannot collect personal information unless they complete a formal Privacy Impact Assessment (PIA) first. This is required under Bill 97.

To avoid delays when selling your product, your documentation must address these ten statutory categories:

  1. Purpose: Why the personal information is being collected and used.

  2. Necessity: An explanation of why the data is essential to achieve that purpose.

  3. Legal Authority: The statutory basis for the collection.

  4. Data Mapping: Precise types of information collected and how each type is used or disclosed.

  5. Data Sources: Where the information originates.

  6. Access Control: Position titles of officers, employees, or consultants who will have access.

  7. Data Limitations: Any restrictions imposed on the use or disclosure of the data.

  8. Retention: The specific period the information will be retained under subsection 30 (1) of MFIPPA.

  9. Safeguards and Risks: An explanation of administrative, technical, and physical safeguards AND a summary of the risks to individuals in the event of a breach.

  10. Prevention and Mitigation: Explicit steps taken to reduce the likelihood of a breach and measures to mitigate harm if one occurs.

Note: Boards must now document the risks your software creates alongside your safeguards. Providing clear documentation for these ten points will help boards choose your product as the 2027 deadline nears.

The EDSTA gives the Minister power to issue binding rules to all 73 school boards and Children’s Aid Societies. This centralizes decisions that boards used to make individually.

This includes Artificial Intelligence. Boards must create “Accountability Frameworks” for any AI they use, whether they built it or bought it from you. They must also actively manage AI risks.

Vendor Impact: You must provide the technical data for these frameworks. If the Minister sets a new technical standard, non-compliant software could be banned across the whole province with one directive.

On January 1, 2027, boards must begin reporting privacy breaches to the Information and Privacy Commissioner (IPC) if there is a “real risk of significant harm.

The law defines “significant harm” specifically. Your response plans should use this same language to help your clients:

“’Significant harm’ includes bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record and damage to or loss of property.” (MFIPPA, Section 30.1 (10) as added by Bill 97).

Contract Alignment: Update your service level agreements (SLAs) to match the board’s duty to report breaches “as soon as feasible.” If you don’t provide data quickly, you and the board could face regulatory trouble.

The EDSTA turns cyber security into a legal requirement. School boards and Children’s Aid Societies must now run formal cyber security programs that include:

  • Defined roles and responsibilities for security oversight.

  • Mandatory response and recovery measures for incidents.

  • Statutory reporting of cyber security incidents to the Minister.

Vendors are now part of the province’s mandated defence. Boards will demand proof that your product is secure and ready for audits.

Bill 101 updates the Education Act to clarify that “educational materials“ include digital textbooks and learning tools.

This gives the Minister power to set guidelines for how digital tools are used in class. The province will likely standardize how it evaluates software, just like it does with physical textbooks.

These changes move the industry from “trust” to “proof.” With the January 1, 2027 deadline close, you must adjust your technical setup and contracts now.

Ontario boards must now legally assess your product. Success is no longer just about features; it is about whether your security and documentation can withstand provincial scrutiny.

The January 2027 deadline is almost here. Be ready.

Read the original on chrisrdale.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.