Skip to content
CyberTECTDigital operations control
All resources

Ontario MFIPPA Breach Reporting Starts January 1, 2027

Municipal institutions need the systems, access, vendor and incident evidence required for MFIPPA privacy-breach reporting starting January 1, 2027.

January 1, 2027 is not just a reporting date.

For municipal institutions subject to MFIPPA, the new privacy-breach, privacy-impact-assessment and recordkeeping obligations mean the organization will need operational facts before an incident—not after it.

On January 1, 2027, mandatory MFIPPA requirements take effect for privacy impact assessments, privacy-breach assessment using the real risk of significant harm threshold, notification and reporting of qualifying breaches, and breach-record retention. The first annual MFIPPA privacy-breach statistical report is due in 2028.

These are privacy obligations, but a defensible assessment depends on the people who operate the systems: what data was involved, where it was stored, who could access it, how the service was configured, whether access occurred, what safeguards were active and what was done to contain the event.

General information only. Reviewed September 4, 2026. This is not legal or privacy advice and does not determine whether an incident requires notification or reporting. Municipal institutions should use current IPC guidance and obtain advice from their privacy, legal and governance advisors.

What changes on January 1, 2027

Obligation What the institution must be able to do Operational dependency
Privacy impact assessments Complete a written PIA before collecting personal information and update it before significant changes. Know the information, systems, users, vendors, safeguards, retention and risks involved.
RROSH assessment Assess a privacy breach against the real risk of significant harm threshold. Collect reliable facts about information, exposure, access, misuse risk and available mitigation.
Notification and IPC reporting Notify people and report qualifying breaches as soon as feasible, subject to the legal rules. Coordinate privacy, IT, leadership, communications and providers without waiting for basic facts.
Records and annual statistics Keep breach records and submit annual statistics starting in 2028. Maintain a repeatable incident record instead of reconstructing events from emails months later.

RROSH is not an IT severity rating

RROSH means real risk of significant harm. The IPC says the assessment considers sensitivity of the personal information, probability of misuse and whether affected people can take steps to prevent or mitigate harm, among other factors. A technically small event can expose sensitive information; a disruptive event may not expose personal information at all.

The privacy team needs to know Where evidence usually comes from
What information was involved and how sensitive was it? Records owners, system owners, configuration, file locations and the PIA or information inventory.
Was information accessed, copied, changed or made available? Identity and application logs, email-security findings, vendor reports, device status and investigation notes.
Who may have had access? Administrator lists, permissions, file-sharing records, vendor-access records and account activity.
What was done to reduce risk? Containment, password resets, access revocation, recovery actions, user guidance and documented decisions.

Build the facts before the breach

The first hours after an incident are a poor time to discover nobody knows who owns the email tenant, how long a vendor keeps logs, which shared drive holds a program’s records, or whether a former contractor still has access. MFIPPA readiness begins with a short, current operating record.

  • critical systems and the personal-information types they hold;
  • business and technical owners for each system;
  • privileged accounts and how access is protected and reviewed;
  • third-party services, integrations and support accounts;
  • backup, retention and recovery arrangements for important records;
  • incident contacts for privacy, cyber, legal, communications and executive decisions; and
  • the locations and retention periods for relevant logs.
What a written PIA needs from operations

IPC Ontario explains that a PIA generally needs the purpose and legal authority for collection, use or disclosure; information types and sources; who will access them; restrictions; retention; safeguards; risks to individuals; and measures to prevent or mitigate those risks. The privacy office may own the PIA, but system and service owners must supply the underlying facts accurately.

Set one breach-triage route

  1. Report and preserve: capture the time, reporter, systems and concern; preserve evidence without delaying urgent containment.
  2. Contain safely: revoke access, isolate systems, pause sharing or engage a provider while maintaining an action log.
  3. Establish facts: identify information, systems, accounts, possible exposure and available logs.
  4. Escalate: bring in privacy, IT/security, leadership, legal, communications and necessary providers.
  5. Assess, notify, report and record: complete the appropriate assessment and retain evidence and decisions for follow-up.
The minimum incident record to keep
  • When and how the concern was identified.
  • The systems, accounts, information categories and third parties involved.
  • Containment, investigation and recovery actions with timestamps.
  • Material decisions and the information they were based on.
  • Relevant logs, provider communications and technical findings.
  • The resulting assessment, notifications, report and corrective actions, as applicable.

Vendors and municipal partners should prepare too

MFIPPA does not turn every local business into a municipal institution. It will, however, change the standard of conversation between institutions and the people who support them. Expect questions about who can access information, how quickly access can be removed, what logs exist, when an incident will be reported, where information and backups are held, and who is available after hours.

Where CyberTECT fits

CyberTECT is Ontario’s Rural & Small Business Digital Risk Partner. We do not provide legal advice, determine RROSH, complete an institution’s legal privacy assessment or certify MFIPPA compliance. We help establish the operational record behind those decisions: systems, accounts, vendors, backup evidence, incident contacts and practical response steps.

Relevant starting points include the Digital Operations Checkup, Break-Glass Readiness Review and Backup and Recovery Validation.

Official sources

Using this guidance

CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.

Discover more from Cybertect

Subscribe now to keep reading and get access to the full archive.

Continue reading