Privacy Management Program
PROGRAM OVERVIEW
In accordance with section 25 of Alberta’s Protection of Privacy Act (POPA) and section 6 of the Protection of Privacy (Ministerial) Regulation (Ministerial Regulation), the University of Alberta (U of A) has established a Privacy Management Program (PMP).
To ensure our institutional processes remain consistent and transparent, the Information, Privacy and Records Management Office (IPRMO) has made the PMP publicly available. This framework acts as your direct guide to how the U of A handles and protects personal information.
On this site, you will find direct links to our:
- Institutional Policies: The overarching rules and principles that guide information protection.
- Institutional Procedures: Step-by-step frameworks for handling information securely.
- Resources & Web Pages: In-depth guides to specific privacy topics, rights, and compliance guidelines.
PMP COMPLIANCE FRAMEWORK AND REQUIREMENTS
Privacy Officer
Mary Golab, Director, Information, Privacy and Records Management, in the Office of General Counsel, is designated as the Privacy Officer for the U of A. Please see the U of A’s POPA delegation table. The Privacy Officer can be reached at privacy@ualberta.ca.
Internal Policies and Procedures - Duties under POPA and associated Regulations
- Access to Information and Protection of Privacy Policy
- Access to Information and Protection of Privacy Procedure
- Access to Personal Information for Research and Studies Procedure
- Administrative Information System Access and Maintenance Procedure
- Contract Review Procedure
- Email Forwarding Restriction Procedure
- Encryption Procedure
- Enterprise Risk Management Policy
- Ethical Conduct and Safe Disclosure Policy
- Information Technology Security Policy
- Information Technology Use and Management Policy
- Information Technology Use and Management Policy Appendix A: Examples of Unacceptable Use
- Institutional Data Management and Governance Procedure
- Legal Hold Procedure
- Official Email List Procedure
- Privacy and Information Security Incident Reporting and Response Procedure
- Records Management Policy
- Research Records Stewardship Guidance Procedure
- Student Conduct Policy (French)
- University Campus Network Procedure
Additional website resources of internal processes and procedures:
- ATIA Delegation Table
- POPA Delegation Table
- Information, Privacy and Records Management Office
- IPRMO: Access to Information Act (ATIA)
- Personal ATIA Requests
- IPRMO: Protection of Privacy Act (POPA)
- Personal Information - What is it?
- Collection of Personal Information
- Use of Personal Information
- Disclosure of Personal Information
- Correction of Personal Information
- Consent for Use and Disclosure under POPA
- Access to Information for Studies and Research
- Guidelines on Collection, Use and Disclosure of Photographs, Video and Audio Recordings, and Broadcasting of Live Events
- Disclosure of Personal Information of Employees
- Student Records: Contents, Use, Access and Protection
- Personal Information Banks
- Privacy Impact Assessment
- Privacy and Information Security Incident Reporting
- Safeguards - Privacy Breach Prevention
- Sensitivity of Information
- POPA Notification Statement Template (French)
- Survey Guidelines
- Privacy Highlights and Quick Tips
- Decision Tree - Study or Research Project
- Guidance for Recording Meetings and Discussions
- Records Management
- Retaining + Managing Records: Procedure for Managing Records
- Report an Information Security Incident or Privacy Breach
- Policies, Standards + Codes of Behaviour
Security Classification Systems
- Administrative Information System Access and Maintenance Procedure
- Encryption Procedure
- Enterprise Risk Management Policy
- Information Technology Security Policy
- Information Technology Use and Management Policy
- Information Technology Use and Management Policy Appendix A: Examples of Unacceptable Use
- Institutional Data Management and Governance Procedure
- University Campus Network Procedure
Additional website resources linked to privacy and security classification systems:
- Information Security
- Information Security Policy + Standards
- Multi-Factor Authentication
- Privacy + Security Review Checklist
- Using Artificial Intelligence at the U of A
Mandatory Training - Obligations under POPA
All U of A faculty and staff who access university information technology resources and/or personal information are required to complete the online privacy and security training every three years and an annual acknowledgement between the completion of full training cycles. For additional information, please see Information Services & Technology’s Privacy + Security Awareness Training and Acknowledgement website.
Period Review of the PMP
The responsibility for monitoring the U of A’s PMP is held by the IPRMO. The IPRMO will review the PMP site annually and update the site as needed.
Posted June 11, 2026