Solutions · By organization

Access and privacy for provincial and territorial public bodies

Your province's statute, preloaded: FIPPA, Alberta's new ATIA, Québec's Loi sur l'accès, ATIPPA and the rest — with the mandatory PIAs, breach notification, and AI accountability rules now arriving, all running inside your own Microsoft 365 tenant.

For a provincial ministry, agency, or broader-public-sector institution, AccessPoint runs access-to-information requests under your own province's statute — Ontario's FIPPA, Alberta's new Access to Information Act, BC's FIPPA, Québec's Loi sur l'accès, Newfoundland and Labrador's ATIPPA, 2015, and every other province and territory — with the real deadlines, exemption catalogues, and commissioner workflows of each, plus the privacy duties those statutes now impose: privacy impact assessments, breach notification, and AI accountability. It deploys into your own Microsoft 365 and Azure tenant at a flat published price.

The reason to look now is legislative, not technological. Provincial access and privacy law is in its biggest rewrite in a generation: Ontario's Bill 194 has required FIPPA institutions to complete written privacy impact assessments before collecting personal information since July 1, 2025 — alongside mandatory breach reporting to the IPC and Ontario's first public-sector AI accountability rules — and Bill 97 moves FIPPA to a 45-business-day response clock on July 1, 2026. Alberta replaced FOIP outright on June 11, 2025 with two new statutes, the Access to Information Act and the Protection of Privacy Act. BC's Bill 22 reforms made privacy management programs and breach notification mandatory from February 2023, and Québec's Law 25 phased in confidentiality-incident reporting and EFVP privacy assessments with real CAI enforcement behind them.

A request tracker cannot carry that load — the new obligations are assessments, notifications, and governance, not request logging. AccessPoint runs the whole mandate on one platform: the request lifecycle with redaction and exemption tagging, a PIA and AIA engine, a live breach-notification calculator, and commissioner appeals, every action on a hash-chained audit ledger, in English and French.

What provincial institutions need from access and privacy software

The statutes differ province to province, but the load-bearing requirements don't. Whatever you evaluate — including if it isn't AccessPoint — check for these.

Your statute's clock, not a generic reminder Ontario is moving to 45 business days, Alberta and BC run 30 business days, Québec runs 20 days with one 10-day extension, and Newfoundland and Labrador's 20 business days is the tightest in Canada. Due dates should be computed from the statute on the right calendar, with extensions tracked against their legal basis.
A PIA engine, now that PIAs are law Written assessments are a statutory requirement in Ontario since July 1, 2025, and expected under Alberta's Protection of Privacy Act and Québec's Law 25. A fillable template is not an engine — look for screeners, delegated sections, an embedded risk register, and an exportable regulator-ready record.
Breach notification computed, not researched When an incident lands, the system should assess the risk of harm and produce a live checklist of who must be told — commissioner and affected individuals — by when, and with what content, from the incident's legal authority.
Commissioner appeals as first-class work Most provincial commissioners are order-making. Appeals and reviews need their own statutory clocks, an investigation workspace, and a record you can put in front of the IPC, an OIPC, or the CAI without reconstruction.
French and English, properly Québec's regime operates primarily in French, and bilingual service obligations reach well beyond it. The interface, notices, letters, and templates should work natively in both languages.
Data that stays in your control The records under review are the sensitive ones. Processing them in your own Microsoft 365 tenant — no third-party cloud, no cross-border transfers — removes the residency questions before they're asked.

How AccessPoint serves provincial and territorial government

One platform, configured to your province by a jurisdiction pack — statute, calendar, exemptions, fees, letters, and report templates.

A pack for every province and territory

From Ontario FIPPA and MFIPPA to Alberta's new ATIA, BC FIPPA, Québec's Loi sur l'accès, and the territorial ATIPP acts — each pack preloads citations, business-day calendars, exemption catalogues, fee schedules, and correspondence templates with statutory wording.

Mandatory PIAs, operated

The assessment engine runs the written PIAs Bill 194 requires of Ontario institutions and the assessments expected under Alberta's Protection of Privacy Act, Québec's EFVP, and BC's privacy management program — screeners, questionnaires, risk register, review, and export.

AI accountability, ahead of the curve

As provinces introduce public-sector AI rules — Ontario's Bill 194 first among them — the same engine runs Algorithmic Impact Assessments: scored, tiered, reviewed, and audit-trailed.

Breach notification calculators

Log a privacy breach, assess the risk of harm, and get a live obligations checklist computed from your statute — what must be reported to your commissioner and to affected individuals, and by when — with letters generated from the record.

Appeals before order-making commissioners

Track appeals and reviews before the IPC, an OIPC, or the CAI with their own clocks, delegated investigation workstreams, a representations sign-off, and a guided closure that records the disposition and any order.

Your tenant, flat pricing

Everything runs inside your own Microsoft 365 and Azure environment with no vendor runtime access — at a flat annual price with no per-user fees, billed through the Microsoft commercial marketplace.

The Bill 194 era

Provincial privacy law grew teeth. Your tooling has to keep up.

Since July 1, 2025, Ontario FIPPA institutions must complete a written privacy impact assessment before collecting personal information, report breaches to the IPC, and meet the province's first public-sector AI accountability rules — and Ontario is not alone, with Alberta's new two-act regime, BC's mandatory privacy management programs, and Québec's Law 25 all in force. Most offices already track requests. It's everything else the statutes now demand that breaks the spreadsheet.

Mandatory PIAs A running assessment engine with screeners, sections, and sign-off — not a template filed away.
Statutory breach reporting Commissioner and individual notification obligations, computed from the incident itself.
AI rules arriving Assess automated decision systems on the same governed platform before they affect the public.

Provincial & Territorial Government Questions

Does AccessPoint support Ontario's Bill 194 PIA requirement?

Yes. Bill 194 requires FIPPA institutions to complete a written privacy impact assessment before collecting personal information, effective July 1, 2025, alongside breach reporting to the IPC and Ontario's first public-sector AI accountability rules. AccessPoint's assessment engine runs those PIAs end to end — screening, questionnaire, embedded risk register, review, and an exportable regulator-ready summary — with a full audit trail, and the same engine covers the AI side.

What about Alberta's new Access to Information Act replacing FOIP?

Covered. On June 11, 2025 Alberta replaced FOIP with two statutes — the Access to Information Act for access requests and the Protection of Privacy Act for the privacy program, including breach notification and privacy impact assessments. AccessPoint's Alberta pack ships the new citations, the 30-business-day clock, the ATIA exemption catalogue, and both Acts' duties from day one.

Which provinces and territories does AccessPoint cover?

All of them. Jurisdiction packs exist for every Canadian province and territory — Ontario (FIPPA and, separately, municipal MFIPPA), Québec, British Columbia, Alberta, Saskatchewan, Manitoba, New Brunswick, Nova Scotia, Prince Edward Island, Newfoundland and Labrador, Yukon, the Northwest Territories, and Nunavut — plus health-sector privacy statutes such as Ontario's PHIPA. Each pack is a preloaded starting point you can adjust, not a lock-in.

Is AccessPoint available in French?

Yes. The interface ships natively in 11 languages including French, and the Québec configuration operates French-primary, consistent with the Charter of the French language. Notices, letters, and templates work in either language, and case content can additionally be translated per record with the original always one click away.

We already track FOI requests in a spreadsheet or a legacy tool — why change now?

Because the new obligations aren't request tracking. Written PIAs, breach notification with statutory content requirements, and AI assessments are duties a request register cannot carry, and the deadlines themselves are shifting — Ontario's move to a 45-business-day clock takes effect July 1, 2026. AccessPoint runs the requests and the new duties on one platform, and a guided workbook import brings your existing history in so nothing is lost.

Where does our data reside?

Entirely within your own Microsoft 365 and Azure tenant. Requests, documents, assessments, incidents, and audit history never leave your control — no third-party cloud, no cross-border transfers, and no vendor runtime access to your environment.

Your Province Rewrote the Rules. Run Them in One Platform.

Try AccessPoint free for 30 days, pre-configured for your province. No credit card required.

Start Free Trial