Privacy + Security Awareness Training and Acknowledgement

Information is one of the university's greatest assets, and our ability to safeguard it is vitally important. The responsibility to protect the personal information that the university holds is one that is shared among the university and its employees. A key component of this protection is ensuring university employees are adequately trained in how to safeguard the personal or confidential information under their control.

All university faculty and staff who access university information technology resources and/or personal information are required to complete the online privacy and security training and acknowledgement.

Training is mandatory and is required to be retaken every three years. The acknowledgement is an annual requirement, which expires each year on June 30.

All university faculty and staff should receive an email directing them to go through this process, but can also start the process at any time by clicking on the green button below. Employees should then receive automated reminders beginning on April 1 each year.

Please do your part to help us to stay strong and stay protected.

For additional information:

Questions & Answers 

Start the Online Privacy and Security Training and Acknowledgement


Questions and Answers for Employees

Do Faculty members have to do the online training and acknowledgement?

Yes, Faculty members are university employees who handle personal information in the course of their employment, including student information. They also generally access university information technology resources. Faculty participation is important to the success of this initiative.

Do sessional instructors have to do the online training and acknowledgement?

If a sessional instructor is a university employee and accesses either personal information in the course of their employment (e.g. student information), or accesses university information technology resources, then they are required to do the training and acknowledgement.

Do contractors have to do the online training and acknowledgement?

This initiative is focused on university employees, and there is no general requirement for contractors to do the online training and acknowledgement at this time. However, some units may wish to have their contractors complete the training and acknowledgement. Any contractor with a CCID can access and complete the training and acknowledgement.

Alternatively, a contractor may be provided with a hard copy of the training and acknowledgement, or the unit may organize a session for contractors to view and listen to the online training with a university employee, using the employee’s CCID to access it.

Do I have to do the training and acknowledgement in one sitting?

No, you can complete the acknowledgement and different portions of the training at different times, if this is easier than completing everything in one sitting.

Is this initiative imposing a lot of new responsibilities on me?

No - it’s important to remember that you already have an obligation to comply with privacy legislation and with the university’s existing security and privacy policies and procedures. This training is meant to help you understand what those obligations are, and how to fulfill them.

What if I don’t feel comfortable signing the Acknowledgement because I still have questions about what I should be doing after I take the training and look at the policies and procedures?

Questions can be directed to your supervisor, your unit’s Access and Privacy Liaison (APL), the Information, Privacy and Records Management Office (IPRMO) or the Chief Information Security Officer (CISO).

What legislative changes occurred in 2025?

  • New access and privacy legislation — the Access to Information Act (ATIA) and the Protection of Privacy Act (POPA) — were introduced in 2025 and replaced the Freedom of Information and Protection of Privacy Act (FOIP).
  • The Security and Privacy Employee Declaration (SPED) has been updated to reflect these changes and as required in accordance with section 25 of POPA.

How will compliance be monitored?

  • Each employee’s completion of the training and the acknowledgement will be recorded electronically.
  • Reports about the completion status of individuals within a Department ID will be generated and provided monthly to the designated contacts for this initiative within a Faculty or unit.
  • Deans, Chairs, Directors and other supervisors are responsible for ensuring that the employees who report to them complete this process.

What are the consequences if I don’t comply?

  • Failure to complete the training—either as a new hire or by the established deadline—will result in a loss of PeopleSoft access. Should access be revoked due to non-compliance, it will only be restored once the training is finished.
  • Regardless of whether or not you complete the training and/or the Acknowledgement, all employees of the U of A are bound by the university’s policies and procedures. Non-compliance with those policies and procedures constitutes misconduct and may be pursued under the applicable collective agreements, university policy, or law.
  • Remember also that if you refuse to comply with the direction to take these steps and in future you cause a privacy or security breach (intentionally or unintentionally), your refusal to go through this education process may be a factor that is considered in the university’s response to the incident.

I’m a researcher. If I accidentally lose a research participant’s information or get hacked, isn’t that really just my problem to deal with? It’s my data, right? Why should I have to do this?

  • Apart from the impact on the research participants, if you have a privacy or security breach involving your research data, it doesn’t just impact your reputation; it can impact the reputation of other researchers at the university, and the university as a whole.
  • The Tri-Council Policy Statement on Ethical Conduct for Research Involving Humans states that researchers shall safeguard information entrusted to them, and institutions shall support their researchers in maintaining promises of confidentiality. The online training and acknowledgement are one of the ways in which both you and the university fulfill these responsibilities.

Contact Information

Questions About How To Complete The Process

Please contact the Staff Service Centre.

Questions About the Initiative As a Whole

Information, Privacy and Records Management Office
privacy@ualberta.ca

Office of the Vice-Provost & Associate Vice-President (Information Services & Technology)
Chief Information Security Officer
ciso@ualberta.ca