Guides & Tools
Practical resources for ATIP, FOI, and privacy teams — statute explainers, working tools, and playbooks, designed to be genuinely useful before you ever talk to us.
FOI Workflow Quick Check
A seven-question self-assessment that helps FOI teams pinpoint where their workflow has the most room to improve. Takes about two minutes.
Open the quick checkPIA Program Readiness Check
Ten questions that test a privacy impact assessment program the way a commissioner would — trigger, inventory, template, risks, approvals, re-assessment — with a score and where to start.
Open the readiness checkFOI ROI Calculator & Business Case
Model the cost to serve a request today, the levers AccessPoint changes — workflow, video and audio redaction, AI Assist, deadline compliance — and the return against flat-rate pricing. Ends with an executive summary you can forward.
Build the business caseFOI Deadline Calculator
Enter the date a request arrived and your Act; get the statutory due date with weekends and public holidays handled, the maximum-extension date, and the deemed-refusal rule — for more than 100 regimes, each cited to the statute.
Open the calculatorAccessPoint Public Roadmap
Where AccessPoint is heading across three horizons — what we're building now, what's coming through 2026, and what's on the horizon for Canadian access and privacy.
View the roadmapOntario FOI in Transition
What's in force, what's coming, and how Ontario public bodies can prepare for the FIPPA and MFIPPA transition under Bill 194 and Bill 97.
Read the guideManage ATIA with Confidence
A practical guide for Alberta public bodies on the new Access to Information Act — comparing FOIP to ATIA, six priorities, and a readiness check.
Read the guideGet Ready for Bill 150
A guide for Nova Scotia public bodies preparing for Bill 150 — the new FOIPOP Act coming into force April 1, 2027.
Read the guideWashington Public Records Act
The five-business-day rule, penalties up to $100 a day, exemption logs, bot requests, and JLARC reporting — for Washington agencies and local governments.
Read the guideTexas Public Information Act
What the 10-business-day clock actually requires, how attorney general rulings work, and the cost and penalty rules — for Texas public information officers.
Read the guideUK FOI Time Limits
Section 10's 20 working days, the public interest extension, EIR differences, and how the ICO now enforces against FOI backlogs.
Read the guideFOI Backlog Recovery Playbook
Triage the queue by age band, stop the bleeding on new intake, run a disciplined burn-down, and prevent relapse — with real regulator cases cited.
Read the playbookStatutory Deadline Math
Business days vs. calendar days, when the clock starts, what pauses it — one request's due date worked under four regimes.
Read the guideWhat Counts as RROSH?
The real-risk-of-significant-harm threshold in PIPEDA, Alberta PIPA, and Ontario Bill 194 — with worked breach-triage examples.
Read the explainerRedacting Body-Worn Camera & 911 Audio
What regulators have ordered for video and audio releases — obscuring, temporal severance, distorted voices, a citation at the place in the record — and who may charge for the work.
Read the guideTeams Meeting Recordings as Records
Are recordings and transcripts records? Where Microsoft keeps them, the auto-expiration trap, and how to capture, review, and release one.
Read the guideWhat a Reasonable FOI Search Includes
How “reasonable” is judged in Canada, the UK, the US and Australia, a tickable checklist for Outlook, Teams, SharePoint, OneDrive and beyond, and a summary of what to fix.
Open the checklistOntario's Mandatory PIAs
What FIPPA section 38 has required since July 2025 — the ten prescribed contents, the update and Commissioner duties — and the January 2027 extension to municipalities, mapped to AccessPoint.
Read the guideNova Scotia Privacy Assessments
Sections 52, 53 and 78 of the new FOIPOP Act, in force April 1, 2027: the assessment duty, what the regulations still have to fill in, and how to be ready before they land.
Read the guideAlberta POPA Privacy Impact Assessments
When section 26 and the Ministerial Regulation require a PIA, the five factors that force submission to the Commissioner, the OIPC template, and the automated-system notice — mapped to AccessPoint.
Read the guideBC FOIPPA Privacy Impact Assessments
Section 69(5) to (5.4) and the 2021 ministerial directions: when an assessment is due, who reviews it, and the privacy management program and breach rules beside it — mapped to AccessPoint.
Read the guideFederal PIAs: The 2024 Standard
The Directive on Privacy Impact Assessment was rescinded in October 2024. What replaced it, who receives the assessment, the breach procedures, and the automated-decision directive beside it — mapped to AccessPoint.
Read the guideAlgorithmic Impact Assessments
What each regime requires of a public body that uses AI or automated decisions — federal, Ontario, Alberta, Quebec, EU and UK — and what a defensible AIA contains, mapped to AccessPoint.
Read the guideFOI Annual Report Statistics
What Canadian ATIP, Ontario IPC, US FOIA, and UK reporting actually require — and how to make year-end a query, not a project.
Read the guideCalifornia Public Records Act
The CPRA after recodification: the 10-day determination, the 14-day extension, prompt production, direct-cost fees, written denials, and writ-of-mandate attorney-fee exposure.
Read the guideNew York FOIL
New York FOIL: the five-business-day response, the 20-business-day rule, constructive denial, 30-day appeals, 25-cent copies, and Article 78 attorney fees.
Read the guideIllinois FOIA
Illinois FOIA in practice: the five-business-day clock and extension, commercial, recurrent and voluminous requests, PAC review, fees, training, and penalties.
Read the guideFlorida Public Records
Chapter 119 in practice: the limited-reasonable-time standard, custodian duties, cited denials, special service charges, the 2017 fee notice, and penalties.
Read the guidePennsylvania Right-to-Know Law
Pennsylvania's Right-to-Know Law: the five-business-day response, deemed denial, the 30-day extension, OOR appeals, the fee schedule, and civil penalties.
Read the guideEU Access to Documents (Regulation 1049/2001)
Regulation (EC) No 1049/2001 in practice: the 15-working-day clock and how the institutions count it, confirmatory applications, Article 4 exceptions and review.
Read the guideGDPR Data Protection Impact Assessments
When GDPR Article 35 requires a DPIA, what it must contain, the Article 36 eight-week consultation clock, the WP248 criteria and how AccessPoint runs each step.
Read the guideUK DPIAs
UK GDPR Articles 35 and 36 as retained, DPA 2018 section 64 for law enforcement, the ICO's high-risk list and screening checklist, and what the 2025 Act changed.
Read the guideEU Institutions DPIAs (Regulation 2018/1725)
Article 39 DPIAs and Article 40 EDPS prior consultation for EU institutions: the EDPS threshold list, the eight-week clock, Article 31 records, breach rules and the DPO.
Read the guideMichigan FOIA
Michigan FOIA after 2014 PA 563: the five-business-day response, one ten-day extension, itemized fees and deposits, the public summary, appeals and fines.
Read the guidePrivacy Impact Assessments: The Program
How to run a privacy impact assessment program that holds up under any regime: the mandate, the inventory, the screener, the template, delegation, risks, approval, re-assessment, the regulator, and AI.
Read the guideThe Access & Privacy Glossary
Deemed refusal, severing, exemption vs. exclusion, PIA vs. DPIA, RROSH, ROPA — the working vocabulary, defined plainly with jurisdiction differences noted.
Open the glossary