Quick reference
| I need to… | Who handles it | What I do |
|---|---|---|
| Plan the annual privacy training schedule | Technology Department | Follow Section 1; record the annual schedule in the training register (IM-038) by September 30 |
| Onboard a new employee (privacy training) | Technology Department | Follow Section 2; 30-day deadline |
| Deliver enhanced privacy training | Technology Department / Access and Privacy Coordinator | Follow Section 3; annual delivery |
| Check privacy training compliance or generate reports | Technology Department | Follow Section 4; run quarterly reports |
| Escalate non-compliance | Technology Department / Site Coordinator | Follow Section 5 escalation steps |
| Conduct the annual privacy training review | Director of Technology / Access and Privacy Coordinator | Follow Section 6; complete by October 31 |
What’s covered
This guide covers the hands-on process of delivering the Division’s privacy training program as established in A.P. 323 §1, which gives effect to the mandatory training requirements under section 6(1)(d) of the Protection of Privacy (Ministerial) Regulation, Alta Reg 143/2025 ("M-Reg 143/2025"). It applies to all privacy training activities, including annual schedule planning, onboarding, enhanced training, tracking, compliance monitoring, non-compliance escalation, and annual program review. It does not cover privacy training curriculum content, which is defined in A.P. 323 §1.d, or security awareness training delivery, which is governed by IM-018.
Privacy training applies to all Division employees, and to contractors and volunteers who have access to Division information resources. It does not apply to students.
1. Annual privacy training calendar and content development
Annual schedule planning
You will develop an annual privacy training schedule by September 30 of each year, mapping privacy topics to delivery dates, and record it in the training register (IM-038).
You will map topics from the privacy training curriculum in A.P. 323 §1.d to the delivery schedule. The curriculum includes general privacy topics (POPA obligations, privacy breach recognition and reporting, individual rights, data classification, and consent requirements) and enhanced topics for designated roles.
You will coordinate with the Access and Privacy Coordinator to identify priority topics based on complaint trends (per A.P. 323 §2), privacy impact assessment findings (per IM-008), incident trends (per A.P. 321), and legislative changes.
You will coordinate with IM-018 delivery to identify joint delivery opportunities where privacy and security topics overlap. Joint delivery is permitted provided that privacy and security completion are tracked separately (per A.P. 323 §1.h.xvi and A.P. 327 §6).
Content development and review
You will develop privacy training content using plain language appropriate for a general audience. Where possible, use real-world examples relevant to the school division context (e.g., student data scenarios, parent consent situations, privacy complaint examples).
You will incorporate the Access and Privacy Coordinator’s feedback and finalize training content before the scheduled delivery date.
Distribution
You will distribute annual privacy training via the Division’s LMS or email-based training platform.
Staff shall complete annual privacy training within the timeframe specified in the delivery schedule. Training has a 12-month expiry period from the date of completion (per A.P. 323 §1.b.iii).
2. Privacy onboarding training
Trigger and timeline
You will initiate privacy onboarding training upon receiving new hire notification from Human Resources or the hiring site. Onboarding shall be completed within 30 days of the employee’s start date (per A.P. 323 §1.a.i).
The same onboarding requirement applies to contractors and volunteers who are granted access to Division information resources. For these individuals, the 30-day clock starts when their access is provisioned, and the sponsoring department initiates onboarding in place of Human Resources.
Onboarding content
Privacy onboarding training shall cover the general privacy curriculum as established in A.P. 323 §1.a.ii, including:
POPA obligations and the Division’s privacy principles (per Policy 311)
Privacy breach recognition and reporting, how to identify and report a suspected privacy breach (per A.P. 321)
Individual rights, access, correction, and complaint rights under POPA
Data classification, handling requirements for each sensitivity level (per A.P. 313)
Consent requirements, when consent is required and how it is obtained (per A.P. 323 §5)
Collection and notification obligations, what to communicate when collecting personal information (per A.P. 323 §4)
Overview of the Division’s privacy governance framework (per CG-002)
How to contact the Access and Privacy Coordinator
Privacy onboarding may be delivered jointly with security onboarding training under IM-018 §2, provided that privacy and security completion are tracked separately.
System access gate
You will confirm that new employees are not provisioned access to systems classified as Restricted or Confidential under A.P. 313 until privacy onboarding is complete (per A.P. 323 §1.a.i). Access to general Division systems (email, basic productivity applications) is permitted from day one.
3. Enhanced privacy training
Who completes enhanced training
Staff in designated privacy roles shall complete enhanced privacy training annually, in addition to general privacy training, as required by A.P. 323 §1.c.v. These roles are System Owners, Site Coordinators, School Administrative Assistants, and the Division’s privacy office (the Access and Privacy Coordinator and the Director of Technology).
Core enhanced components (System Owners, Site Coordinators, and School Administrative Assistants)
Enhanced training covers privacy responsibilities specific to these roles, including:
Privacy impact assessment participation and System Owner obligations (per IM-008)
Personal Information Bank identification and reporting (per A.P. 323 §7)
Collection notice compliance at the site level (per A.P. 323 §4)
Privacy complaint intake and escalation at the site level (per A.P. 323 §2)
Privacy breach initial response and reporting (per A.P. 321)
These components may be delivered through external professional development, meeting attendance.
Coordination with security training
Enhanced privacy training may overlap with enhanced security training delivered under IM-018. Where topics are delivered jointly, you will track privacy and security completion separately in the training register (per A.P. 323 §1.h.xvi and A.P. 327 §6).
4. Tracking and compliance monitoring
Recording completions
You will record all privacy training completions in the training register (IM-038), maintaining separate records from security awareness training (per A.P. 323 §1.h.xvi).
For each individual, you will record: training module name, training type (onboarding, annual, or enhanced), completion date, and expiry date (12 months from completion per A.P. 323 §1.b.iii).
Compliance reports
You will generate privacy training compliance reports for the Access and Privacy Coordinator as required.
5. Non-compliance escalation
You will follow this escalation process for staff who do not complete required privacy training:
Automated 30-day renewal reminder (annual training) or day-20 reminder (onboarding)
Notification to Site Coordinator.
6. Annual privacy training review
Timeline and scope
You will conduct the annual privacy training review by October 31. This review supports the annual content review the Access and Privacy Coordinator conducts under A.P. 323 §1.g.xv.
Metrics and analysis
You will evaluate the following metrics:
Training completion rates versus the 100% target, by site and training type
Onboarding completion rates.
Enhanced training completion rates
Staff feedback on training quality, relevance, and delivery methods
Content currency, whether training materials reflect current POPA requirements, Division procedures, complaint trends, and PIA findings
Correlation between training activities and privacy complaint or breach trends
Inputs to next year’s program plan
You will document lessons learned and recommendations from the annual review and submit them to the IM-019 – Security Improvement and Lessons Learned improvement register. These inputs shall be available by November 15 to support annual schedule development by September 30 of the following year.
You will incorporate feedback from the Access and Privacy Coordinator’s review (per A.P. 323 §1.g.xv) into the next year’s training schedule and content development plan.
When this gets updated
This guide shall be reviewed annually alongside A.P. 323, or earlier if triggered by:
Changes to POPA, ATIA, M-Reg 143/2025, or OIPC guidance affecting privacy training requirements
Significant privacy complaints or breaches indicating training delivery gaps
Changes to A.P. 323 §1 that affect training delivery procedures
Changes to the Division’s training platform or delivery methods
Direction from the Director of Technology, Access and Privacy Coordinator, or Senior Administration
Document history
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | March 2026 | Director of Technology | Initial release; operationalizes A.P. 323 §1 privacy training delivery |