The 2027 changes · explainer
What changes for municipalities on January 1, 2027.
A summary of the MFIPPA privacy amendments, written for clerks and CAOs rather than lawyers and privacy professionals. Every claim below is tied to the IPC's own guidance.
The short version
Bill 97, the Plan to Protect Ontario Act (Budget Measures), 2026, received Royal Assent on April 24, 2026. It extends to MFIPPA institutions (municipalities, and library, police services, and conservation authority boards) the privacy regime that provincial ministries have had since 2025. The privacy provisions take effect January 1, 2027, regardless of an institution's size or whether it has any privacy staff.
The obligations are the same as those facing a large city. For a small township, the staffing is not.
The three obligations that create work
- Mandatory breach notification. Where personal information is stolen, lost, or used or disclosed without authorization, the institution must notify the affected individual and the Information and Privacy Commissioner (IPC) if there is a real risk of significant harm.
- Privacy Impact Assessments. Unless the regulations provide otherwise, a written PIA is required before personal information is collected, and an existing assessment must be updated before a significant change to the purpose for which the information is used or disclosed. It should record the legal authority for the collection, the data flows, the risks, and the safeguards. This is an ongoing program obligation, not a one-time filing.
- Safeguards and record-keeping. An express duty to protect personal information with reasonable administrative, technical, and physical safeguards, plus a duty to keep records of breaches and report breach statistics to the IPC each year.
What "real risk of significant harm" means
Not every mishandled record triggers notification. The test asks whether a breach creates a real risk of significant harm to an individual: harm such as identity theft, fraud, financial loss, damage to reputation or relationships, or physical safety concerns. Assessing that risk sensibly, and documenting the reasoning, is part of a working breach-response process. A misdirected email, a lost laptop, or a wrong attachment can all qualify depending on what information was involved.
What that means in practice
Two things need to exist in practice before January 1, 2027 that most municipalities have never had to build: a written PIA process someone can actually run, and a breach-response plan that says who does what, in what order, when something goes wrong. The PIA duty is statutory; the breach-response plan is the practical control that makes the statutory reporting duty survivable. The safeguards duty and the annual breach-statistics report sit on top of both. The readiness assessment exists to tell you exactly how far off you are; the PIA service does the assessments themselves.
Timing
The MFIPPA amendments come into force in waves through 2026 and into 2027. The privacy provisions above are the January 1, 2027 wave. The first annual breach-statistics report covers the 2027 year and is therefore due in 2028.
Primary source: Municipal Freedom of Information and Protection of Privacy Act, ss. 28, 30, 30.1 (as amended by 2026, c. 2, Sched. 11, in force January 1, 2027). Plain-language summary: Information and Privacy Commissioner of Ontario: FIPPA and MFIPPA amendments FAQ. Annual reporting timing: IPC: annual statistical reporting.
General information about pending legislative change, not legal advice.