Grasslands Public Schools Policy Handbook Grasslands Public Schools
Home
live
Grasslands Public Schools

IM-020 — Privacy Training Delivery

Working Instruction
Functional Area: Information Management · IM-020
Document Owner: Director of Technology
Effective: June 10, 2026 Last Reviewed:

Quick reference

I need to… Who handles it What I do
Plan the annual privacy training schedule Technology Department Follow Section 1; record the annual schedule in the training register (IM-038) by September 30
Onboard a new employee (privacy training) Technology Department Follow Section 2; 30-day deadline
Deliver enhanced privacy training Technology Department / Access and Privacy Coordinator Follow Section 3; annual delivery
Check privacy training compliance or generate reports Technology Department Follow Section 4; run quarterly reports
Escalate non-compliance Technology Department / Site Coordinator Follow Section 5 escalation steps
Conduct the annual privacy training review Director of Technology / Access and Privacy Coordinator Follow Section 6; complete by October 31

What’s covered

This guide covers the hands-on process of delivering the Division’s privacy training program as established in A.P. 323 §1, which gives effect to the mandatory training requirements under section 6(1)(d) of the Protection of Privacy (Ministerial) Regulation, Alta Reg 143/2025 ("M-Reg 143/2025"). It applies to all privacy training activities, including annual schedule planning, onboarding, enhanced training, tracking, compliance monitoring, non-compliance escalation, and annual program review. It does not cover privacy training curriculum content, which is defined in A.P. 323 §1.d, or security awareness training delivery, which is governed by IM-018.

Privacy training applies to all Division employees, and to contractors and volunteers who have access to Division information resources. It does not apply to students.

1. Annual privacy training calendar and content development

Annual schedule planning

You will develop an annual privacy training schedule by September 30 of each year, mapping privacy topics to delivery dates, and record it in the training register (IM-038).

You will map topics from the privacy training curriculum in A.P. 323 §1.d to the delivery schedule. The curriculum includes general privacy topics (POPA obligations, privacy breach recognition and reporting, individual rights, data classification, and consent requirements) and enhanced topics for designated roles.

You will coordinate with the Access and Privacy Coordinator to identify priority topics based on complaint trends (per A.P. 323 §2), privacy impact assessment findings (per IM-008), incident trends (per A.P. 321), and legislative changes.

You will coordinate with IM-018 delivery to identify joint delivery opportunities where privacy and security topics overlap. Joint delivery is permitted provided that privacy and security completion are tracked separately (per A.P. 323 §1.h.xvi and A.P. 327 §6).

Content development and review

You will develop privacy training content using plain language appropriate for a general audience. Where possible, use real-world examples relevant to the school division context (e.g., student data scenarios, parent consent situations, privacy complaint examples).

You will incorporate the Access and Privacy Coordinator’s feedback and finalize training content before the scheduled delivery date.

Distribution

You will distribute annual privacy training via the Division’s LMS or email-based training platform.

Staff shall complete annual privacy training within the timeframe specified in the delivery schedule. Training has a 12-month expiry period from the date of completion (per A.P. 323 §1.b.iii).

2. Privacy onboarding training

Trigger and timeline

You will initiate privacy onboarding training upon receiving new hire notification from Human Resources or the hiring site. Onboarding shall be completed within 30 days of the employee’s start date (per A.P. 323 §1.a.i).

The same onboarding requirement applies to contractors and volunteers who are granted access to Division information resources. For these individuals, the 30-day clock starts when their access is provisioned, and the sponsoring department initiates onboarding in place of Human Resources.

Onboarding content

Privacy onboarding training shall cover the general privacy curriculum as established in A.P. 323 §1.a.ii, including:

Privacy onboarding may be delivered jointly with security onboarding training under IM-018 §2, provided that privacy and security completion are tracked separately.

System access gate

You will confirm that new employees are not provisioned access to systems classified as Restricted or Confidential under A.P. 313 until privacy onboarding is complete (per A.P. 323 §1.a.i). Access to general Division systems (email, basic productivity applications) is permitted from day one.

3. Enhanced privacy training

Who completes enhanced training

Staff in designated privacy roles shall complete enhanced privacy training annually, in addition to general privacy training, as required by A.P. 323 §1.c.v. These roles are System Owners, Site Coordinators, School Administrative Assistants, and the Division’s privacy office (the Access and Privacy Coordinator and the Director of Technology).

Core enhanced components (System Owners, Site Coordinators, and School Administrative Assistants)

Enhanced training covers privacy responsibilities specific to these roles, including:

These components may be delivered through external professional development, meeting attendance.

Coordination with security training

Enhanced privacy training may overlap with enhanced security training delivered under IM-018. Where topics are delivered jointly, you will track privacy and security completion separately in the training register (per A.P. 323 §1.h.xvi and A.P. 327 §6).

4. Tracking and compliance monitoring

Recording completions

You will record all privacy training completions in the training register (IM-038), maintaining separate records from security awareness training (per A.P. 323 §1.h.xvi).

For each individual, you will record: training module name, training type (onboarding, annual, or enhanced), completion date, and expiry date (12 months from completion per A.P. 323 §1.b.iii).

Compliance reports

You will generate privacy training compliance reports for the Access and Privacy Coordinator as required.

5. Non-compliance escalation

You will follow this escalation process for staff who do not complete required privacy training:

6. Annual privacy training review

Timeline and scope

You will conduct the annual privacy training review by October 31. This review supports the annual content review the Access and Privacy Coordinator conducts under A.P. 323 §1.g.xv.

Metrics and analysis

You will evaluate the following metrics:

Inputs to next year’s program plan

You will document lessons learned and recommendations from the annual review and submit them to the IM-019 – Security Improvement and Lessons Learned improvement register. These inputs shall be available by November 15 to support annual schedule development by September 30 of the following year.

You will incorporate feedback from the Access and Privacy Coordinator’s review (per A.P. 323 §1.g.xv) into the next year’s training schedule and content development plan.

When this gets updated

This guide shall be reviewed annually alongside A.P. 323, or earlier if triggered by:

Document history

Version Date Author Changes
1.0 March 2026 Director of Technology Initial release; operationalizes A.P. 323 §1 privacy training delivery