The operating environment for vendors serving Ontario’s education sector has fundamentally and irrevocently changed. The catalyst was a massive 2024 cyberattack on PowerSchool, a major educational technology (EdTech) vendor, which compromised the personal information of approximately 3.86 million Ontarians, including students, parents, and educators. The subsequent investigation by the Information and Privacy Commissioner of Ontario (IPC) has established a new, significantly higher benchmark for privacy, security, and accountability.
Ontario School Boards and the Ministry of Education, now under intense regulatory and public scrutiny, are compelled to enforce stricter standards on their third-party service providers. Vague contractual assurances are obsolete. Vendors must now proactively demonstrate robust, verifiable, and comprehensive privacy and security programs. Failure to meet this new standard will result in exclusion from procurement processes and potential contract termination.
This briefing synthesizes key findings from IPC reports and guidance to provide vendors with a clear understanding of the new requirements and the actions necessary for continued partnership with Ontario’s public education institutions.
Key Takeaways for Vendors:
Heightened Scrutiny and Accountability: The PowerSchool incident has triggered a sector-wide shift. School boards cannot outsource their accountability for protecting personal information and will now rigorously enforce this principle through contractual and oversight mechanisms.
Mandatory Due Diligence: As of July 1, 2025, Privacy Impact Assessments (PIAs) are a legal requirement for provincial institutions under Ontario’s Freedom of Information and Protection of Privacy Act (FIPPA). Vendors must be prepared for deep, formal assessments of their privacy and security practices as a prerequisite for any new project or contract. Ontario’s Municipal Freedom of Information and Protection Privacy Act (MFIPPA), which School Boards fall under, is expected to be updated with the same requirements.
Contractual Rigor is the New Norm: Contracts will move beyond simple compliance clauses to include highly specific, enforceable terms covering data ownership, security controls, subcontractor management, audit rights, data retention and destruction schedules, and strict breach notification timelines.
Technical Safeguards Must Be Demonstrable: Vendors will be required to provide evidence of robust technical controls, including mandatory multi-factor authentication (MFA), adherence to the principle of least privilege for access, extended log retention, and regular third-party security audits (e.g., SOC 2 Type II reports) covering all relevant systems.
Data Governance is a Primary Concern: The over-retention of data is now viewed as a critical liability. Vendors must have and enforce clear policies for data minimization, retention, and secure destruction in alignment with their clients’ legal obligations.
The era of implicit trust has ended. The new paradigm is one of explicit, verifiable compliance. Proactive adaptation is not merely recommended; it is essential for survival and success in this transformed landscape.
In December 2024, a threat actor used compromised credentials from a PowerSchool subcontractor to access the company’s customer support portal, PowerSource. This provided a gateway to the Student Information System (SIS) environments of 20 Ontario school boards and the Ministry of Education, resulting in a massive data exfiltration.
The breach was not an isolated incident; it was the culmination of multiple systemic failures that have since become the blueprint for what Ontario’s public institutions must prevent.
Affected Population: Approximately 3.86 million Ontarians, including current and former students, their parents/guardians, and current and former staff.
Compromised Data: A vast range of personal information was exfiltrated, including names, dates of birth, contact information, student numbers, Ontario Education Numbers, and in some cases, highly sensitive data such as:
Medical information (allergies, medical conditions)
Health Card Numbers and Social Insurance Numbers (SINs)
First Nations, Metis, Inuit status
Disciplinary notes and individualized education program references
Data Over-Retention: The investigation revealed a critical failure in data governance. Compromised data was egregiously old, demonstrating a lack of enforceable retention schedules.
B. The Regulatory Verdict: Key Failures Identified by the IPC
The IPC’s November 2025 Privacy Complaint Report was a scathing indictment of both the institutions and the vendor. It concluded that the school boards did not have reasonable measures in place to prevent unauthorized access to personal information. The findings create a clear roadmap of vendor practices that are no longer tolerable.
Core Failures Attributed to the Vendor (PowerSchool):
Inadequate Technical Safeguards:
Compromised Credentials: The breach originated from the credentials of a subcontractor with elevated privileges.
Lack of Multi-Factor Authentication (MFA): MFA was not required to access the critical PowerSource portal, which was a direct gateway to student data.
“Always On” Remote Access: A remote maintenance feature was left persistently enabled, creating a permanent, unnecessary attack vector.
Insufficient Logging: The threat actor was active in the system for months (August to December 2024) without detection, partly due to limited log retention periods.
Weak Contractual Agreements: The IPC noted that some agreements were outdated (dating back to 2011) and lacked specific, enforceable clauses on key privacy and security requirements.
Insufficient Oversight by Institutions: The report found that school boards failed to regularly monitor PowerSchool’s compliance.
Inadequate Breach Response: PowerSchool discovered the breach on December 28, 2024, but did not notify the affected Ontario institutions until January 7, 2025—a 10-day delay deemed unacceptable.
The IPC Commissioner’s message to the sector was unequivocal: “while institutions may outsource some of their responsibilities to third party service providers, they cannot outsource their accountability.” This principle is now the driving force behind the heightened expectations for all vendors.
In response to the PowerSchool breach and the broader risks of the digital age, Ontario’s public sector has been armed with new legislation and reinforced guidance. These documents are not suggestions; they are the new rules of engagement for vendors.
The IPC’s Guidance: Privacy and Access in Public Sector Contracting with Third Party Service Providers is now the essential operating manual for school boards. Vendors must understand its contents, as it dictates the entire procurement and contract lifecycle.
B. The Legal Mandate: Mandatory Privacy Impact Assessments (PIAs)
With the passage of Bill 194 (Strengthening Cyber Security and Building Trust in the Public Sector Act), PIAs became legally mandatory for provincial institutions under FIPPA as of July 1, 2025.
What this means: Before collecting any personal information for a new or modified project—which includes engaging a vendor—school boards must complete a written PIA.
Impact on Vendors: Vendors are no longer just responding to an RFP; they are participants in a legally mandated risk assessment. They will be required to provide exhaustive details on:
The precise types of personal information to be collected, used, or disclosed.
The legal authority for each data processing activity.
Data flows, sources, and access controls (by position title).
Detailed explanations of all administrative, technical, and physical safeguards.
Retention periods and secure disposal methods.
A summary of risks to individuals in the event of a breach and the vendor’s mitigation strategies.
A vendor’s inability or unwillingness to provide this level of detail will be a disqualifier.
The Digital Privacy Charter for Ontario Schools is a public pledge that operationalizes the principles of the new framework. School boards are committing to, among other things:
Acting in students’ best privacy interests.
Requiring strong privacy protections when engaging third-party providers.
Assessing privacy risks before adopting digital education tools and services.
Strengthening privacy protections in tools, including making privacy-protective settings the default.
This charter transforms internal policy into a public promise, increasing the reputational risk for boards and, by extension, for any vendor that fails to uphold these standards.
The recommendations from the IPC’s PowerSchool report provide a clear and explicit checklist of what school boards will now require from their technology partners. Vendors must be prepared to meet these demands across three critical domains.
To thrive in this new environment, vendors must shift from a reactive to a proactive stance on privacy and security.
Conduct a Gap Analysis: Immediately assess your current technical safeguards, contractual templates, and internal policies against the specific failures and recommendations outlined in the IPC’s PowerSchool report and the Guidance on Public Sector Contracting.
Prepare a PIA Package: Assemble documentation that directly answers the questions required by a PIA. This includes detailed data flow diagrams, inventories of personal information, security architecture documents, retention schedules, and incident response plans. Having this ready will accelerate procurement cycles.
Revise Standard Contracts: Proactively update your standard agreements to include the robust, specific clauses that school boards will now demand. This demonstrates awareness and preparedness, making you a more attractive partner.
Embrace “Verifiable-by-Design”: Structure your operations and documentation to be easily auditable. Ensure you have recent SOC 2 Type II and ISO 27001 certifications and penetration test results ready to share with prospective clients.
Operationalize Data Minimization: Review your products and services to ensure you are only collecting, using, and retaining personal information that is strictly necessary for the provision of the service. Document the rationale and be prepared to defend it during a PIA.
Train Your Team: Ensure your sales, legal, and technical teams are fully briefed on this new landscape. They must be able to speak fluently and accurately about your company’s privacy and security posture.
The PowerSchool breach was a watershed moment for the EdTech sector in Ontario. It exposed systemic vulnerabilities and triggered a powerful regulatory response that has permanently elevated the standards for all third-party service providers. School boards are now mandated—legally and reputationally—to conduct rigorous due diligence and enforce strict accountability.
For vendors, the message is clear: privacy and security are no longer features; they are the foundation of your right to operate in Ontario’s education system. The path forward requires a demonstrable commitment to protecting the sensitive information of children and youth, supported by robust technical controls, transparent practices, and contractually guaranteed accountability. Those who adapt will find themselves trusted partners in a more secure educational ecosystem; those who do not will be left behind.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.