Compliance & Regulatory Updates

Ontario’s Privacy Rules Just Changed Again — And the IPC Says Its Own Guidance Isn’t Finished Yet

TITLE: Ontario’s Privacy Rules Shifted Twice in 2026 — But the IPC Says Its Own Guidance Isn’t Finished Yet

FROM AN INFRASTRUCTURE STANDPOINT, Ontario’s privacy rulebook shifted twice in 2026 — but the regulator enforcing it posted a public notice saying its own guidance isn’t finished yet. That disconnect matters if you’re managing institutional systems or compliance controls under Ontario’s Freedom of Information and Protection of Privacy Act (FIPPA) or the municipal equivalent (MFIPPA). You’re potentially implementing amended statutory obligations while the Information and Privacy Commissioner (IPC) is still writing the rulebook.

• Bill 97 (Plan to Protect Ontario Act (Budget Measures), 2026) received Royal Assent on April 24, 2026 ([Ontario Legislative Assembly + McMillan LLP legal analysis](https://www.ola.org/en/legislative-business/bills/parliament-44/session-1/bill-97))
• First tranche of FIPPA and MFIPPA amendments came into force on July 1, 2026 ([Information and Privacy Commissioner of Ontario (IPC); Multiple Ontario law firms (Weirfoulds, Hicks Morley, Blakes, Lerners); Ontario.ca](https://www.ipc.on.ca/en/resources/fippa-mfippa-amendments-faq))
• The ‘second tranche’ of Bill 194 amendments (Schedule 2 / FIPPA amendments, including mandatory PIAs, breach notification, and annual reporting) came into force on July 1, 2025. The first tranche — housekeeping, whistleblower, and joint investigation amendments — came into force on January 29, 2025. The parent Act (EDSTA, Schedule 1) also came into force on January 29, 2025. ([Information and Privacy Commissioner of Ontario (IPC) — FAQ on Schedule 2 of Bill 194/FIPPA Amendments](https://www.ipc.on.ca/en/resources/bill-194-strengthening-cyber-security-and-building-trust-public-sector-act/frequently-asked-questions-schedule-2-bill-194fippa-amendments))

WHY THIS MATTERS FOR YOUR INFRASTRUCTURE

If you’re responsible for systems handling personal information in Ontario public or municipal institutions, this layered amendment process creates a compliance timing problem. The PECB ISO 27001 course taught me that regulatory implementation requires three simultaneous moving parts: statutory language, organizational controls, and auditor/regulator guidance. When the third piece isn’t ready, you’re interpreting the first piece without a safety net.

That’s your current state.

THE DUAL OBLIGATION MOST ORGANIZATIONS MISS

Here’s where it gets complicated from a sysadmin standpoint: if your organization operates in Ontario but also collects personal information federally or across provinces, you’re tracking PIPEDA (federal Personal Information Protection and Electronic Documents Act) and FIPPA/MFIPPA (provincial). Most compliance programs don’t distinguish between them. The infrastructure you’ve already deployed likely handles both under a single privacy framework. These amendments apply only to Ontario provincial/municipal institutions — not your PIPEDA obligations.

But if you’re a public body? You need to track both separately.

WHAT THE IPC ACTUALLY SAID

THE CPA CANADA ANGLE YOU HAVEN’T CONSIDERED

CPA Canada’s guidance on governance and risk management notes that regulatory lag — the gap between statutory change and implementation guidance — creates material control gaps. From a sysadmin standpoint, that means: your Privacy Impact Assessment (PIA) templates, which may have been built against the previous statutory language, now sit in a state of technical non-alignment with amended law, while the regulator is still writing what “alignment” actually means.

This is a documented governance risk.

WHAT TO DO THIS WEEK

1. Inventory your FIPPA/MFIPPA systems. Which institutional systems actually fall under Ontario provincial privacy law vs. federal PIPEDA? Document the boundary.

2. Request the IPC’s in-draft guidance. The IPC maintains draft guidance documents on its website. Download current versions. These may not be final, but they represent the regulator’s current interpretation.

3. Audit your PIA templates. Pull your existing Privacy Impact Assessment templates used for new systems. Map each question against the amended statutory definitions. Where do they no longer align?

4. Flag for legal review. Your in-house legal or privacy counsel should review which amended obligations affect your current control infrastructure. This isn’t optional compliance work — it’s evidence of control management.

FOOTNOTES

– Ontario Legislative Assembly (Bill 97 status)
– Ontario Gazette (both proclamation dates)
– Office of the Information and Privacy Commissioner (IPC) — current guidance status
– Office of the Privacy Commissioner of Canada 2024–2025 Annual Report (if available)
– CPA Canada Governance & Risk resources

{
“@context”: “https://schema.org”,
“@type”: “Person”,
“name”: “[Author Name]”,
“jobTitle”: “Systems Engineer & PECB ISO 27001 Provisional Auditor”,
“description”: “PECB ISO 27001 Provisional Auditor. No consulting clients. Writing from sysadmin and infrastructure perspective.”,
“url”: “[Author URL]”
}

Sources

– [Legislative Assembly of Ontario (Official Government Record)](https://www.ola.org/en/legislative-business/bills/parliament-44/session-1/bill-97)
– [Information and Privacy Commissioner of Ontario (IPC) & Ontario Legislature](https://www.ipc.on.ca/en/resources/fippa-mfippa-amendments-faq)
– [Ontario Gazette / O. Reg. 51/26 and O. Reg. 52/26](https://www.ontario.ca/laws/regulation/260051)
– [Information and Privacy Commissioner of Ontario (IPC) – Official Website](https://www.ipc.on.ca)
– [Information and Privacy Commissioner of Ontario (IPC)](https://www.ipc.on.ca/en/fippa-mfippa-privacy-organizations)

1. All legislative dates verified against Ontario Legislative Assembly and Ontario Gazette
2. OPC statistic verified or replaced with hedged language + named source
3. IPC current guidance status confirmed
4. All hyperlinks tested and valid
5. Legal review completed for PIPEDA/FIPPA intersection claims

Sources

– [Information and Privacy Commissioner of Ontario (IPC)](https://www.ipc.on.ca/en/resources/advice-and-submissions/ipc-urges-removal-bill-97-changes-weaken-access-and-privacy-rights)
– [Ontario Legislative Assembly + McMillan LLP legal analysis](https://www.ola.org/en/legislative-business/bills/parliament-44/session-1/bill-97)
– [Information and Privacy Commissioner of Ontario (IPC); Multiple Ontario law firms (Weirfoulds, Hicks Morley, Blakes, Lerners); Ontario.ca](https://www.ipc.on.ca/en/resources/fippa-mfippa-amendments-faq)
– [Information and Privacy Commissioner of Ontario (IPC) — FAQ on Schedule 2 of Bill 194/FIPPA Amendments](https://www.ipc.on.ca/en/resources/bill-194-strengthening-cyber-security-and-building-trust-public-sector-act/frequently-asked-questions-schedule-2-bill-194fippa-amendments)
– [Information and Privacy Commissioner of Ontario (IPC)](https://www.ipc.on.ca/en/resources/guidance)

FREE RESOURCE

How Exposed Is Your Business Right Now?

Take the free 7-minute scorecard and find out exactly where your cybersecurity gaps are — before an insurer or attacker does.

Get My Free Risk Score →

No email required to start. Takes 7 minutes.

← Back to all resources

Have Questions About Your IT Setup?

Book a free 15-minute fit call. We'll help you figure out the best path forward for your business — no pressure.

Book a Free Consultation

📍 Toronto · GTA · Ontario · Across Canada  |  ⏰ 1 business day response

Discover more from Secrecy Evolution

Subscribe now to keep reading and get access to the full archive.

Continue reading