EPSB.ca » Our Division » Board Policies & Administrative Regulations » C - Division Administration » CN.AR Creation, Use and Maintenance of Division Information

Creation, Use and Maintenance of Division Information

  • Code: CN.AR
    Topic: Creation, Use and Maintenance of Division Information
    Issue Date: 19/08/2026
    Effective Date: 12/12/2006
    Review Year: 2033

Objective

To provide direction and clarity regarding the management of Division information assets in alignment with legislative requirements and industry best practices, balancing accountability and transparency while safeguarding the privacy of students, families and employees.

Definitions

Access Request is a formal application made by an applicant to the Division to view or obtain a copy of information assets that are in the Division’s custody or control.

Automated System, the Government of Alberta defines an "Automated System" as any computer program or process—including AI and data analytics—used to make decisions, process data or interact with the public, excluding basic IT infrastructure. 

Common or Integrated Program or Service (CIPS), in relation to the Division, is defined by the Protection of Privacy Act, as a program or service that is planned, administered, delivered, managed, monitored or evaluated by the Division working collaboratively with one or more other public bodies.

Employee, as set out by the Protection of Privacy Act, includes a person who performs a service for the Division as a staff member, appointee, volunteer or student or under a contract or agency relationship with the Division.

Information, as defined by the Access to Information Act, means content contained in a record.

  1. Information Assets are records, information and data regardless of physical or digital form, created or received by the Division.
  2. Essential Information Assets are irreplaceable information assets necessary to resume Division operations after a disaster or to protect legal and financial responsibilities. Essential information assets must be retrievable after a disaster.

Information Asset Catalogue is a structured, centralized inventory that identifies and documents all information assets owned, processed and managed by the Division.

Personal Information is defined by the Protection of Privacy Act as meaning recorded information about an identifiable individual. Section 1(q) of the Protection of Privacy Act provides a list of the types of information that would be considered personal information.

Privacy Impact Assessment (PIA) is a due diligence process that assists the Division in reviewing the impact(s) that a new, or a substantial change to an existing administrative practice, program, project or service may have on individual privacy if it involves the collection, use or disclosure of personal information.

Privacy Management Program (PMP) is the complete set of standards, procedures and practices the Division uses to promote the safe, legal and respectful handling of personal information by all employees.

Record, as defined by the Access to Information Act, means any electronic record or other record in any form in which information is contained or stored, including information in any written, graphic, electronic, digital, photographic, audio or other medium, but does not include any software or other mechanism used to store or produce the record. Records encompass various types, formats and states, as outlined in the Information Assets Standard.

Security Classification within the context of information management is a framework for assigning sensitivity levels to information, dictating the safeguards required against unauthorized access, alteration or loss.

Responsibility

  1. Each employee is responsible for properly handling and protecting information in their custody and/or control. 

  2. The Superintendent of Schools is designated as the Head of Edmonton Public Schools (Head) for the purposes of the Protection of Privacy Act and Access to Information Act.

  3. The Superintendent of Schools delegates to the Division Access and Privacy Officer the powers and duties of the Head under the Protection of Privacy Act and Access to Information Act necessary for the administration of the PMP and the processing of access requests, excluding the power to delegate and to assess fees to access requests.

  4. The Division Access and Privacy Officer is responsible for the duties as prescribed in the Access to Information Act Delegation Standard for Edmonton Public Schools. This includes, but is not limited to:

    1. Responsibility for the Access and Privacy Office.
    2. Creating standards to ensure legislative requirements are met.
    3. Responsibilities under the legislation are appropriately assigned, including the Division’s Standard for the Use of Personal Information in Artificial Intelligence and Automated Systems.
  5. Information Management is the decision unit responsible for the development and oversight of standards and processes for defining, identifying and protecting essential information assets, creating and maintaining an Information Asset Catalogue as prescribed in the Division’s Information Assets Standard, the Information Security Classification Standard and Information Security Control Standard, and management of the Division’s centralized records storage facility.

  6. Technology and Information Management is responsible for ensuring essential information assets are adequately protected and stored across Division-approved and supported technologies.

  7. Privacy Officers
    1. The following positions are designated Privacy Officers:
      1. Principals
      2. Central decision unit administrators
    2. Principals and central decision unit administrators, serving as Privacy Officers, are responsible for implementing protective measures for essential information assets in their custody. 

    3. Responsibilities of Privacy Officers are as prescribed in the Information Management Responsibilities Standard.

  8. All employees must manage the information assets under their control as defined in the Division’s Information Management Responsibilities Standard. Descriptions of various roles throughout the organization are detailed in the Information Management Responsibilities Standard.

Regulation

  1. DIVISION INFORMATION ASSETS

    The management of all Division information assets must comply with the following directives:

      1. Privacy Officers (principals and central decision unit administrators) who wish to implement a new, or a substantial change to an existing, administrative practice, program, project or service that will involve the collection, use or disclosure of personal information must complete a PIA with support from the Access and Privacy Office.
      2. Central decision units will work with Information Management in the identification and classification of information assets in their area to enable the creation and ongoing maintenance of an Information Asset Catalogue.
      3. Contractual Accountability
        1. Division contracts with vendors that will have access to personal information must include the privacy protections as outlined in the Division's Vendor Management and Oversight Standard (including completing a PIA when required).
        2. Principals or central decision unit administrators who engage with a third party vendor for technology or digital services (including EdTech tools) that involve personal information are required to complete a PIA with support from the Access and Privacy Office.
        3. Specific security provisions must be addressed contractually, including the requirement to notify the Division promptly if the vendor experiences a data breach.

    The Division and any employee of the Division will not sell personal information in any circumstances or for any purpose, including for marketing or advertising purposes.

  2. COLLECTING, CORRECTING AND PROTECTING ALL PERSONAL INFORMATION
    1. Protection of Personal Information
      1. All personal information will be managed by the Division to ensure individual privacy is maintained.
        1. Information Management is responsible for developing and publishing standards and procedures supporting the management of personal information. 
        2. Privacy Officers are responsible for meeting the prescribed standards and procedures for all personal information in their area of responsibility.
      2. The Division will ensure adequate, industry-standard monitoring and response systems are in place to protect Division systems that contain personal information.
        1. Decision units are responsible for the specific systems within their purview that contain personal information.
      3. All personal information will be collected and disclosed based on delivering a Division service or program.
        1.  All information sharing will be limited to:
          1. Only what is needed to complete a task. 
          2. For the reason the information was collected.
          3. To avert imminent danger.
          4. In the best interests of a minor.
        2. All personal information is sensitive; therefore, privacy will be protected during the collection, storage, use, sharing and transmission of personal information by all employees.
      4. The Division must protect personal information, data derived from personal information, and non-personal data by taking reasonable information security actions (administrative, physical and technical safeguards) to mitigate risks such as unauthorized access, collection, use, disclosure or destruction.
      5. The Access and Privacy Office establishes and maintains the Division’s Privacy Breach Standard. 
    2. If the Division will be using an individual’s personal information (staff, student or family) to make a decision that directly affects the individual, including a decision made using an automated system, the Division must:
      1. Make every reasonable effort to ensure that the information is accurate and complete. 
      2. Retain the personal information for at least one year after using it so that the individual has a reasonable opportunity to obtain access to it.
    3. The Access and Privacy Office will maintain the Correction of Personal Information by Division Employee Standard.
  3. PRIVACY IMPACT ASSESSMENTS
    1. The Division must complete and submit a PIA to the Office of the Information and Privacy Commissioner (OIPC) if an initiative meets one or more mandatory conditions set out in legislation. Any initiative must strictly comply with all requirements as set out in the Division’s Privacy Impact Assessment Procedure.
  4. ACCESS TO INFORMATION

    The right of access is the cornerstone of openness and accountability of public bodies. The Access to Information Act is in addition to and does not replace existing procedures for the public to obtain access to information from the Division. Whenever possible, the Division aims to provide information directly without requiring a formal request—this is known as a routine disclosure. The Division will follow all access and privacy requirements.

    1. Right of Access
      1. The public has the right of access to records held by public bodies, subject to limited and specific exceptions as set out in the Access to Information Act.
      2. An individual’s right of access to their own information is significant. Any exceptions to access should be interpreted in a way that provides an individual with as much access as possible to their own personal information.
      3. Any disclosure of personal information must be in compliance with the privacy provisions of the Protection of Privacy Act and the Access to Information Act.
      4. The Division must fulfill an applicant’s request for information if it can be done using the Division’s existing computer hardware, software, and technical expertise and if it would not unreasonably interfere with the operations of the Division.
    2. Access Requests
      1. A formal request for information under the Access to Information Act must be made in writing and sent to the attention of the Division Access and Privacy Officer. The request may be made by completing a Request to Access Information Form or by writing a letter requesting specific records, providing a timeframe for when the records were created, and referencing the Access to Information Act.
      2. An applicant may make an oral access request to the Division Access and Privacy Office if their ability to read or write English is limited, or if they have a physical disability or condition that impacts their ability to make a written request.
      3. Employees must not reveal the identity of an applicant in any communication, formal or informal, with any other individual unless the other individual requires the identity of the applicant to search for records that are responsive to an access request.
    3. Fees for processing an Access Request
      1. The Division is authorized to charge fees for services related to requests under the Access to Information Act. Fees payable will be in accordance with and will not exceed the fees as provided in the Access to Information Act Regulation, Alta. Reg. 133/2025, as amended from time to time, or a successor regulation that sets fees for an access request for information.
    4. Right of Review
      1. Individuals may request a review or submit a privacy concern to the OIPC. However, before going to the OIPC, the individual must make a complaint to the Division Access and Privacy Office regarding the matter.
  5. DISCLOSURE FOR RESEARCH OR STATISTICAL PURPOSES
    1. Access may be granted to personal information if:
      1. The research proposal is of educational benefit to the Division and meets Division criteria for acceptable research practices in accordance with Administrative Regulation IQ.AR Conducting Research Within the Division.
      2. The disclosure otherwise conforms to the requirements of Section 15 of the Protection of Privacy Act.
    2. The Access and Privacy Office provides the Division’s De-identification Standard and Privacy Impact Assessment Procedure to assist with the disclosure of personal information for research or statistical purposes.
  6. DATA DERIVED FROM PERSONAL INFORMATION
    1. The Access and Privacy Office establishes and updates standards to de-identify data derived from personal information, non-personal data, data matching and synthetic data. The Division standards and de-identification procedure will ensure that appropriate governance is in place to protect the identity of any individual whose personal data was used in these processes.
  7. ARTIFICIAL INTELLIGENCE AND AUTOMATED SYSTEMS
    1. The Access and Privacy Office will establish and maintain the Division’s Standard for the Use of Personal Information in Artificial Intelligence and Automated Systems. The standard governs the use of personal information in an automated system, including artificial intelligence, to generate content or make decisions, recommendations or predictions. It will dictate how the automated systems will use the personal information, including the mandatory safeguards, human oversight requirements, and the mandatory notification to individuals.

 

References

CN.BP Managing Division Information
IQ.AR Conducting Research Within the District
Access to Information Act
Access to Information Act Regulation
Division Privacy Management Program (PMP) Request Process
Fact Sheet: Artificial Intelligence and Automated Systems
Office of the Information and Privacy Commissioner of Alberta Website
Protection of Privacy Act
Protection of Privacy (Ministerial) Regulation
Records Management Regulation

 

Internal Division Standards referenced in the regulation
Access to Information Act Delegation Standard for Edmonton Public Schools
Correction of Personal Information by Division Employee Standard
Data De-identification Standard
Information Assets Standard
Information Management Responsibilities Standard under ATIA and POPA
Information Security Classification Standard
Information Security Controls Standard
Privacy Management Program Standard
Privacy Breach Standard
Standard for the Use of Personal Information in Artificial Intelligence and Automated Systems 
Vendor Management and Oversight Standard

Internal Division Procedures referenced in the regulation
Data De-identification Procedure
Privacy Impact Assessment Procedure
Privacy Procedures for Front-Line Employees: Collecting and Correcting Personal Information