Nova Scotia's privacy assessments: what the new FOIPOP Act requires from April 1, 2027, and how to be ready before the regulations are
Sections 52, 53 and 78 of the consolidated Act, what they mean for departments, municipalities and other public bodies, the gap the regulations still have to fill, and where each element lives in AccessPoint — for privacy leads, municipal clerks and program managers who will need an assessment before their next new system.
Nova Scotia's new Freedom of Information and Protection of Privacy Act, passed on October 3, 2025, comes into force on April 1, 2027. From that date, every public body — departments, agencies, and the municipalities and other local public bodies the Act now covers — must conduct a privacy assessment before undertaking any project, program, system or other activity that collects, uses or discloses personal information, and before substantially changing one. The Act also requires a privacy policy and public complaint procedures, and it makes breach notification mandatory where an individual could experience significant harm.
For thirty years Nova Scotia's public sector ran on four statutes: the 1993 FOIPOP Act, Part XX of the Municipal Government Act for municipalities and villages, the Privacy Review Officer Act, and the Personal Information International Disclosure Protection Act for information leaving Canada. None of them required a privacy impact assessment, though provincial departments have prepared them under government practice and the Information and Privacy Commissioner has long encouraged them. The new Act replaces all four with one statute, and it turns the assessment from a good practice into a duty. This guide sets out what the Act says, what it leaves to regulation, what the Commissioner has said about implementation, and how to build the assessment program now rather than in the spring of 2027.
What the Act requires
The privacy obligations sit in the Act's Protection of Privacy part, under the heading "Privacy Policies, Privacy-complaint Procedures and Privacy Assessments". Three sections carry the weight.
Section 52: a policy and a complaint route. A public body must establish and maintain a privacy policy that meets the requirements prescribed by regulation, and must make its internal privacy-complaint procedures available to the public. A privacy assessment program without a published complaint route is half a program.
Section 53: the assessment. The core provision reads:
"A public body shall (a) before undertaking or instituting a project, program, system or other activity involving the collection, use or disclosure of personal information, conduct a privacy assessment of the project, program, system or activity; and (b) before substantially changing a project, program, system or other activity involving the collection, use or disclosure of personal information, conduct a privacy assessment of the project, program, system or activity that reflects the anticipated change."
Subsection 53(2) makes the assessment comply with any requirements prescribed by regulation, and subsection 53(3) confirms that the before-undertaking duty does not reach activities undertaken on or before the date the Act comes into force. Two features deserve attention. The trigger is broad: not only a collection, as in Ontario, but any activity involving use or disclosure of personal information, and the phrase "other activity" reaches beyond named projects and systems. And the trigger repeats: a substantial change to an existing activity, including one grandfathered by subsection (3), requires a fresh assessment that reflects the change.
Section 78: breach notification. The Act defines a privacy breach as theft or loss of personal information, or collection, use, disclosure, access or disposal not authorized by the Act, whether intentional or not. Where it is reasonable to believe that an affected individual could experience significant harm as a result, the head must notify; significant harm is defined to include damage to reputation or relationships, loss of employment or business opportunities, financial loss, harm to a credit record, loss of property and effects on insurability, and the Act lists the factors the head must weigh. Section 77 separately requires data-linking programs to comply with any regulation made for them.
What the regulations still have to fill in
The Act names the duty and leaves the contents to regulation. The regulation-making power expressly covers "respecting privacy assessments, including prescribing the requirements with which a privacy assessment must comply", and the privacy-policy requirement in section 52 is likewise regulation-defined. As of September 2026 no such regulation has been published, and the Commissioner's August 26, 2026 letter to the Ministers of Justice and Service Nova Scotia, recommending amendments before the Act takes effect, confirms that implementation details are still moving.
That gap is not a reason to wait. The established structure of a privacy impact assessment in Canada is stable across every regime that has legislated it: the purpose and why the personal information is necessary; the legal authority; the personal information involved and its sources; how it flows, is used and is disclosed; how long it is kept; the safeguards; the risks to individuals; and the steps that address those risks. Ontario wrote exactly that list into its statute in 2025, and a Nova Scotia assessment built to it will meet or exceed whatever the regulation prescribes. The Ontario PIA guide on this site sets the list out paragraph by paragraph.
What the Commissioner has said
The Office of the Information and Privacy Commissioner has been explicit about its role. Since November 21, 2025 it no longer provides on-request consultations to public bodies and health custodians, to concentrate on reviews and privacy complaints. At the same time it has begun proactively reaching out to public bodies and custodians to offer advice on significant privacy impact assessments — new programs involving particularly sensitive personal information such as health information, or significant changes to how existing programs manage personal information. On the new Act, the Commissioner has said the OIPC hopes to take part in briefings and training for municipalities on their new responsibilities but will not lead implementation, which sits with Information Access and Privacy Services in the Department of Justice.
The practical reading for a public body: expect the Commissioner to ask about the significant assessments rather than to help write the routine ones, and expect municipalities to be learning the duty for the first time in the same year the Act arrives.
Who is covered
The Act's definition of public body includes departments, boards, commissions, agencies and other bodies whose members are appointed by the Governor in Council or serve as public officers, the Public Archives, any body designated by regulation, and local public bodies. The municipal regime that Part XX of the Municipal Government Act carried for three decades is folded into the same statute, which is why the Commissioner describes the Act as creating new privacy-related obligations for municipalities. Health custodians remain under the Personal Health Information Act, and the two regimes will need to be read together wherever a program touches both.
Building the program before April 2027
- Inventory the activities. Section 53 attaches to projects, programs, systems and other activities. List them with their owners, note which will be undertaken after April 1, 2027, and rank the existing ones by how likely they are to change substantially.
- Adopt a template now and version it later. Build to the full Canadian structure; when the regulation prescribes contents, add or rename sections rather than starting again.
- Define "substantial change" for your organization. The Act does not. A written threshold — new categories of personal information, a new use or disclosure, a new vendor, a new jurisdiction, a new automated decision — turns a judgment call into a screener.
- Delegate the program-area sections. Sources, flows, retention practice and real safeguards come from the people who run the activity. Send them the sections; keep the privacy analysis with the privacy lead.
- Register the risks and the commitments. Each risk to individuals with its likelihood, impact and the safeguard that addresses it; each step still owed with an owner and a date.
- Publish the complaint route and align the breach procedure. Section 52 requires the procedures to be public; section 78 sets the harm test. Both should exist as documented procedures before April 1, 2027, with the breach procedure written around the Act's definition and factors.
- Municipalities: start with the systems you already know are coming. A new permitting platform, a body-worn camera program, a resident portal: anything launching after April 1, 2027 needs its assessment finished before launch.
How AccessPoint runs it
AccessPoint's Nova Scotia jurisdiction pack covers the provincial FOIPOP regime and the municipal regime together, with the Review Officer's oversight model, and a separate pack covers PHIPA for health custodians. Each pack that carries a PIA practice ships an assessment template built on the regime's own material, versioned and pack-maintained, so the contents a regulation prescribes arrive as a template version rather than a rebuild. The assessment machinery underneath is the same engine the Ontario and federal packs use.
Assessment types and templates with legal authority
A Nova Scotia assessment starts from the pack's template with the governing Act attached; the type decides whether scoring and the harm-to-individuals lens apply.
A screener for the "substantial change" question
Templates can carry a preliminary screener whose answers decide whether a full assessment is instantiated or a lightweight compliance record is kept — the written threshold from step 3, enforced.
Durable subjects and re-assessment
Every activity is a reusable privacy subject with its assessment history; a change goes forward through Re-assess on the same subject, and when a subject's recorded purpose changes the reassessment date is pulled forward and surfaced on My Day.
Typed questions that populate the register
The personal-information inventory is a table question, and retention, categories of personal data and the international-transfer flag bind to the subject's record of processing on approval — useful in a province that has just moved its cross-border rules into the main Act.
Section delegation
Program experts answer only their sections, with autosave, hours and documents; the privacy lead approves or requests changes.
Risks, controls and commitments
A likelihood-and-impact risk register with a harm-to-individuals determination, controls linked from the controls library, and a commitments card that tracks every undertaking to completion.
Complaints and breaches on the same platform
The complaints module runs the privacy-complaint procedure section 52 requires you to publish, and the incidents module runs breach response with a risk-of-harm register and a notification checklist computed from the governing legislation.
Reporting for the Commissioner and for council
Assessment throughput, outstanding commitments and the PIA findings report, plus Report Studio for the questions specific to your program; the closure tab generates the regulator summary as a document, in English or French.
Everything runs inside your own Microsoft 365 and Azure tenant, in Canada, beside the access requests the same office already handles.
A readiness checklist
- Confirm the Act binds you as a public body or local public body, and whether PHIPA also applies.
- Inventory projects, programs, systems and activities involving personal information, with owners and expected change dates.
- Adopt a template covering the full Canadian PIA structure; plan to version it when the regulation is made.
- Write and adopt a "substantial change" threshold and put it in a screener.
- Draft the privacy policy against the section 52 requirement and publish the complaint procedures.
- Rewrite the breach procedure around section 78's definition, harm test and factors.
- Complete assessments for anything launching on or after April 1, 2027 before it launches.
- Watch for the regulations and the Commissioner's guidance, and record the date each assessment was reviewed against them.
Sources
- Bill 150, Freedom of Information and Protection of Privacy Act (third reading text), ss. 52, 53, 77, 78 and the transitional provisions — Nova Scotia Legislature (accessed September 4, 2026).
- Office of the Information and Privacy Commissioner for Nova Scotia — statements on the new Act's April 1, 2027 commencement, the end of on-request consultations (November 21, 2025) and proactive outreach on significant PIAs (accessed September 4, 2026).
- Recommendations of the Information and Privacy Commissioner on the new FOIPOP Act — letter to the Ministers of Justice and Service Nova Scotia, August 26, 2026 (records the October 3, 2025 passage and the April 1, 2027 commencement).
- Notes on Nova Scotia's FOIPOP Reform Bill — All About Information, September 29, 2025.
- Ontario FIPPA s. 38(3) — the statutory list used above as the reference structure for assessment contents.
Related reading on this site: Get ready for Bill 150, AccessPoint for Nova Scotia public bodies, privacy impact assessment software, breach and incident management, the companion guide on Ontario's mandatory PIAs, or book a demo to see a Nova Scotia assessment run end to end.
Nova Scotia Privacy Assessment Questions
When does Nova Scotia's new Freedom of Information and Protection of Privacy Act take effect?
April 1, 2027. The consolidated Act, introduced as Bill 150, was passed on October 3, 2025 and received Royal Assent that month. It replaces the 1993 FOIPOP Act, Part XX of the Municipal Government Act, the Privacy Review Officer Act and the Personal Information International Disclosure Protection Act with one statute.
Are privacy impact assessments mandatory in Nova Scotia?
They will be, from April 1, 2027. Section 53 of the new Act requires a public body to conduct a privacy assessment before undertaking or instituting a project, program, system or other activity that involves collecting, using or disclosing personal information, and again before substantially changing one. The Act calls it a privacy assessment rather than a privacy impact assessment; the obligation is the same.
What must a Nova Scotia privacy assessment contain?
The Act leaves the contents to regulation: section 53(2) says an assessment must comply with any requirements the regulations prescribe, and the regulation-making power expressly covers privacy assessments. Until a regulation is made, the established PIA structure applies: purpose and necessity, legal authority, the personal information involved and its sources, flows and disclosures, retention, safeguards, the risks to individuals and the steps that address them.
Do municipalities have to conduct privacy assessments?
Yes. The new Act folds the municipal regime of Part XX of the Municipal Government Act into one statute, and its definition of public body includes local public bodies. The Information and Privacy Commissioner has said the new law creates new privacy obligations for municipalities and that the OIPC will support briefings, but will not lead implementation.
Does a program that already exists need a privacy assessment?
Not on day one. Section 53(3) says the before-undertaking duty does not apply to a project, program, system or activity undertaken on or before the date the Act comes into force. The duty to assess before a substantial change does apply to existing programs, so any change after April 1, 2027 that alters how personal information is collected, used or disclosed triggers an assessment.