Privacy
Privacy runs through the whole life of a service that handles people's personal information, from the first design sketch to the day the data is destroyed. Personal information is anything that can identify a person: a name, a case number, an address, an IP address. Canada's Privacy Act sets the rules for how a federal institution may collect, use, and share it. The decisions that shape a service's privacy are made early and revisited as it changes: what personal information to collect, how to protect it, and when to reassess the risk.
THE CORE OF PRIVACY
What good looks like
Only the personal information the service genuinely needs is collected, and nothing more.
A Privacy Impact Assessment is done before launch and kept current as the service changes.
Privacy is designed in from the start.
People are told what is collected and why, in a privacy notice.
Personal information is protected with safeguards matched to how sensitive it is.
Personal information is kept only as long as it is needed (administrative information at least two years after its last use), then disposed of.
Staff who handle personal information have privacy training.
A privacy breach has a rehearsed plan: contain, assess the harm, notify the people affected, report it.
Why it matters
When privacy fails, real people are harmed: their information is exposed, used in ways they did not expect, or lost. Trust in the service, and in government, is slow to win back. Most privacy problems are avoidable and trace to the same causes: collecting more than is needed, holding it too long, or never assessing the risk. The Government of Canada's rules for this are the Privacy Act and the Treasury Board Directive on Privacy Practices, which since 2024 folds in the requirement to do a Privacy Impact Assessment. The Digital Privacy Playbook turns those rules into steps a team can follow.
Whose job it is
Privacy is shared across the team, with each role holding a different part:
- The department's privacy or ATIP office reviews the Privacy Impact Assessment and advises on the Privacy Act.
- Developers build the safeguards and collect only what the design calls for.
- The business owner of the application decides what personal information the service needs, makes sure the assessment is done before launch, and accepts the privacy risk that remains.
A closer look
What Privacy looks like in each phase
The privacy work changes shape across the life of a service.
Most privacy is decided before the service exists. The team lists the personal information the service will hold and works out the least it can collect (collecting more than you need is a liability), confirms it has the legal authority to collect it, chooses private defaults, and runs the Privacy Impact Assessment early, while changing the design is still cheap. The privacy notice is drafted, the safeguards and access controls are built, a retention and disposition plan is written, and the staff who will handle the data are trained. If a supplier will hold or handle the personal information, the privacy requirements are written into the contract so the supplier is bound by them. The Digital Privacy Playbook checklist lays out these plan and design steps.
The official instruments behind privacy
Everything official this subject brings with it, and where in a service's life each one comes up. The full detail, including who does the work and what the business owner personally does, is in the table on the home page.
A structured look at what personal information the service collects, why it is allowed to, where it flows, how long it is kept, and what happens to people if it goes wrong. A mandatory checklist comes first and decides whether a full assessment, a lighter privacy protocol, or neither is needed.
- DiscoveryCheck
- AlphaGather
- BetaFillSubmit
- GrowthKeep current
- MaturityKeep current
A questionnaire the department fills in about itself, scoring how much an automated decision could affect people's rights, health, economic interests or the ongoing sustainability of an ecosystem. The score sets obligations for explanation, human involvement, testing and recourse.
- AlphaCheck
- BetaFillSubmit
- GrowthKeep current
- MaturityKeep current
The written consent from Library and Archives Canada without which no government record may be destroyed, plus the department's own schedule saying how long each kind of record is kept. The authority is permission to dispose. It is not an instruction to dispose, and it does not set retention periods.
- AlphaGather
- BetaFill
- MaturityKeep current
- SunsetClose out
- Material privacy breach reportOnly ifFiling
The report a department must make when personal information is lost, accessed or disclosed in a way that could reasonably be expected to cause serious injury. It goes to the Office of the Privacy Commissioner of Canada and to the Treasury Board of Canada Secretariat, and affected people are notified.
- BetaCheck
- StabilizationSubmit
- GrowthKeep current
Further reading
See also
Assumptions this page makes
You are already working to the Government of Canada Digital Standards, design with users, iterate and improve frequently, work in the open, use open standards, address security and privacy, build in accessibility, empower staff, be good data stewards, design ethical services, and collaborate widely, and to the law on privacy, security, official languages, and accessibility. The standards say how the government works in the digital world. The six Government of Canada digital competencies say what every public servant has to be able to do to work that way, and the team page covers them. This guide builds on those.