Skip to content
Sidecrowd Technologies
3 min read

A POPA Compliance Checklist for Alberta Municipalities

A practical, IT-focused checklist to help Alberta municipalities protect residents' personal information under the Protection of Privacy Act (POPA), which replaced FOIP in 2025.

By Damin Massicotte

Since Alberta replaced the FOIP Act with the Protection of Privacy Act (POPA) and the Access to Information Act (ATIA) on June 11, 2025, municipalities have a clearer — and in places higher — bar for protecting residents' personal information. POPA governs how public bodies collect, use, protect, and disclose that information. This checklist focuses on the practical, IT-side safeguards that support compliance.

This is general information, not legal advice. Work with your municipality's privacy officer or legal counsel on your specific obligations. For background, see our overview of POPA and ATIA for Alberta municipalities.

1. Know where personal information lives

You can't protect what you can't find. Map out where residents' and staff personal information is stored — servers, cloud services, email, spreadsheets, paper files, and any third-party systems (utility billing, permits, payroll).

  • Inventory all systems and locations holding personal information
  • Identify who has access to each
  • Note any information shared with third parties or contractors

2. Control who can access it

POPA expects personal information to be protected against unauthorized access. Access control is foundational.

  • Individual accounts for every staff member (no shared logins)
  • Least-privilege access — people can only reach what their role requires
  • Multi-factor authentication on email and key systems
  • Prompt removal of access when staff or contractors leave

3. Encrypt and secure the data

  • Encryption for laptops and mobile devices
  • Secure, encrypted email and file sharing for sensitive information
  • Endpoint protection and email filtering on all devices
  • A properly configured firewall and secured network

4. Back it up — and be able to recover

Protecting information includes being able to recover it after ransomware, hardware failure, or accidental deletion.

  • Automatic, verified backups of critical records
  • Backups tested by actually performing a restore
  • Ransomware-resistant retention

5. Prepare for incidents

  • A basic incident-response plan: who to call, what to do
  • Audit logging so you can see who accessed what, and when
  • A process for reporting and responding to a privacy breach

6. Train your people

Most incidents start with a person, not a system.

  • Regular, practical staff security awareness (recognizing phishing, handling data)
  • Clear internal policies for handling personal information
  • Updated forms, notices, and procedures that reference POPA and ATIA (not FOIP)

7. Review regularly

  • Periodic review of access, backups, and security posture
  • Reassess when systems, staff, or services change

The bottom line

POPA doesn't require a massive budget — it requires disciplined, well-run IT: know where personal information is, control who can reach it, encrypt and back it up, prepare for incidents, and train your people. Work through this checklist and you'll close the gaps that matter most.

We help Alberta municipalities put these safeguards in place with dependable, public-sector-ready IT. Learn more about our IT support for municipalities, or book a free evaluation and we'll review your current setup against this list.

Sources: Government of Alberta — Protection of Privacy Act and Access to Information Act; Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca).

MunicipalitiesComplianceCybersecurity

Start spending smarter on your IT.

Schedule a quick call to explore cost-effective support that keeps your tech running right — no pressure, no jargon.