EPSB.ca » Our Division » Board Policies & Administrative Regulations » C - Division Administration » CN.AR Creation, Use and Maintenance of Division Information
To provide direction and clarity regarding the management of Division information assets in alignment with legislative requirements and industry best practices, balancing accountability and transparency while safeguarding the privacy of students, families and employees.
Access Request is a formal application made by an applicant to the Division to view or obtain a copy of information assets that are in the Division’s custody or control.
Automated System, the Government of Alberta defines an "Automated System" as any computer program or process—including AI and data analytics—used to make decisions, process data or interact with the public, excluding basic IT infrastructure.
Common or Integrated Program or Service (CIPS), in relation to the Division, is defined by the Protection of Privacy Act, as a program or service that is planned, administered, delivered, managed, monitored or evaluated by the Division working collaboratively with one or more other public bodies.
Employee, as set out by the Protection of Privacy Act, includes a person who performs a service for the Division as a staff member, appointee, volunteer or student or under a contract or agency relationship with the Division.
Information, as defined by the Access to Information Act, means content contained in a record.
Information Asset Catalogue is a structured, centralized inventory that identifies and documents all information assets owned, processed and managed by the Division.
Personal Information is defined by the Protection of Privacy Act as meaning recorded information about an identifiable individual. Section 1(q) of the Protection of Privacy Act provides a list of the types of information that would be considered personal information.
Privacy Impact Assessment (PIA) is a due diligence process that assists the Division in reviewing the impact(s) that a new, or a substantial change to an existing administrative practice, program, project or service may have on individual privacy if it involves the collection, use or disclosure of personal information.
Privacy Management Program (PMP) is the complete set of standards, procedures and practices the Division uses to promote the safe, legal and respectful handling of personal information by all employees.
Record, as defined by the Access to Information Act, means any electronic record or other record in any form in which information is contained or stored, including information in any written, graphic, electronic, digital, photographic, audio or other medium, but does not include any software or other mechanism used to store or produce the record. Records encompass various types, formats and states, as outlined in the Information Assets Standard.
Security Classification within the context of information management is a framework for assigning sensitivity levels to information, dictating the safeguards required against unauthorized access, alteration or loss.
Each employee is responsible for properly handling and protecting information in their custody and/or control.
The Superintendent of Schools is designated as the Head of Edmonton Public Schools (Head) for the purposes of the Protection of Privacy Act and Access to Information Act.
The Superintendent of Schools delegates to the Division Access and Privacy Officer the powers and duties of the Head under the Protection of Privacy Act and Access to Information Act necessary for the administration of the PMP and the processing of access requests, excluding the power to delegate and to assess fees to access requests.
The Division Access and Privacy Officer is responsible for the duties as prescribed in the Access to Information Act Delegation Standard for Edmonton Public Schools. This includes, but is not limited to:
Information Management is the decision unit responsible for the development and oversight of standards and processes for defining, identifying and protecting essential information assets, creating and maintaining an Information Asset Catalogue as prescribed in the Division’s Information Assets Standard, the Information Security Classification Standard and Information Security Control Standard, and management of the Division’s centralized records storage facility.
Technology and Information Management is responsible for ensuring essential information assets are adequately protected and stored across Division-approved and supported technologies.
Principals and central decision unit administrators, serving as Privacy Officers, are responsible for implementing protective measures for essential information assets in their custody.
Responsibilities of Privacy Officers are as prescribed in the Information Management Responsibilities Standard.
All employees must manage the information assets under their control as defined in the Division’s Information Management Responsibilities Standard. Descriptions of various roles throughout the organization are detailed in the Information Management Responsibilities Standard.
The management of all Division information assets must comply with the following directives:
The Division and any employee of the Division will not sell personal information in any circumstances or for any purpose, including for marketing or advertising purposes.
The right of access is the cornerstone of openness and accountability of public bodies. The Access to Information Act is in addition to and does not replace existing procedures for the public to obtain access to information from the Division. Whenever possible, the Division aims to provide information directly without requiring a formal request—this is known as a routine disclosure. The Division will follow all access and privacy requirements.
Internal Division Standards referenced in the regulation
Access to Information Act Delegation Standard for Edmonton Public Schools
Correction of Personal Information by Division Employee Standard
Data De-identification Standard
Information Assets Standard
Information Management Responsibilities Standard under ATIA and POPA
Information Security Classification Standard
Information Security Controls Standard
Privacy Management Program Standard
Privacy Breach Standard
Standard for the Use of Personal Information in Artificial Intelligence and Automated Systems
Vendor Management and Oversight Standard
Internal Division Procedures referenced in the regulation
Data De-identification Procedure
Privacy Impact Assessment Procedure
Privacy Procedures for Front-Line Employees: Collecting and Correcting Personal Information