Data Privacy and Municipal Information Governance

What Toronto can legally do with your personal data, and what the failed Sidewalk Labs project taught the city.

DRAFTThe evidence fileThe playbook

Claim coverage as of 2026-07-14: 24 a formally registered claim/CL-800## formally registered claims already recorded for this slug (8 verified, 16 “still being checked”) — cited here at their real recorded status, never silently upgraded; plus 8 new 2026 findings from this review's live discovery (NEW-2026-1 through NEW-2026-8), each with inline source quote, not yet through this library’s formal verification process. Coverage: breadth not formally checked in this review — this draft establishes carried-forward-claims register citation discipline plus fresh-discovery integration only, per this page’s deepening-pass. Cui Bono: 0 beneficiary entities identified — see the Cui Bono section below for the honest explanation of why this slug currently produces an empty table.

Written per this library's standard page structure, a later review, 2026-07-14. Per this page’s binding rules: the promoted this page’s carried-forward master briefing (data information governance) is cited as-is and not re-researched; the 24 existing formally registered claims are cited at their real trust status; every new load-bearing claim below carries inline source quote; no private individuals' names appear except a named privacy expert's own public resignation statement, already extensively reported under her own name across major outlets in her professional capacity — not a "private individual" under this project's addressee-discipline guardrail, which restricts naming officials as the subject of a critical claim without institutional framing, not quoting a named public figure's own on-record words about her own professional resignation.

Indigenous context

Indigenous context: what Indigenous nations, organizations, and knowledge-holders have publicly said about this issue — the Indigenous Context Library (one of this library's own project records, added 2026-08-17).

---

Scope

This page’s neutral scope question: how does the City of Toronto (and Ontario municipalities generally) collect, protect, and govern personal information and broader data assets, under what legal framework (chiefly MFIPPA), and what does the Sidewalk Labs/Quayside episode teach about municipal data governance and public trust. This document covers: MFIPPA's core access/privacy mechanics and the newly-enacted Bill 97 amendments (2026) that materially change municipal institutions' obligations starting July 2026 and January 2027; Bill 194/the Enhancing Digital Security and Trust Act's actual scope (which, this review confirms, does not yet directly bind municipalities despite the inherited briefing's more general framing); the City of Toronto's own June 2025 Guidance for the Responsible Use of Generative AI, read directly from its primary text; the Sidewalk Labs/Quayside collapse, including the Auditor General's "inside track" procurement finding and Waterfront Toronto's own disputed rebuttal; AMCTO's MFIPPA modernization advocacy and its concerns about municipal capacity to meet the new Bill 97 deadlines; and international comparator context (principally the EU's GDPR Article 35 Data Protection Impact Assessment regime, structurally close to Ontario's new PIA requirement). It hands off, rather than duplicates: broader municipal AI governance questions outside the privacy/data lens to the relevant AI-and-work leaves; general municipal cybersecurity infrastructure spending to the fiscal-capacity leaves; and questions of policing-specific surveillance technology to the community-safety leaves, referenced here only via the inherited briefing's own cross-reference.

Current state

MFIPPA's core mechanics, now updated by Bill 97 (2026)

Under Ontario's Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), individuals have the right to access records held by City of Toronto institutions, subject to specific exemptions, and the City must protect personal information from unauthorized collection, use, or disclosure [CL-0234, verified]. The inherited master briefing and the existing claims register both describe Bill 97's amendments requiring Privacy Impact Assessments before collecting personal information and breach reporting [CL-0235, verified] — this review's live discovery substantially sharpens the timeline and scope of that description. Ontario's 2026 Budget (A Plan to Protect Ontario, tabled March 26, 2026) proposed the amendments; Bill 97 received Royal Assent April 24, 2026 [NEW-2026-1]. The MFIPPA-specific amendments come into force in stages: certain provisions July 1, 2026, others January 1, 2027 [NEW-2026-1] — meaning, as of this review's writing (July 14, 2026), the first tranche has already or is about to take legal effect. Beyond the PIA and breach-notification requirements the claims register already documents, this review's discovery adds structural detail not previously captured: statutory response timelines will shift from calendar days to business days for select provisions; the standard access-request response time extends from 30 to 45 days; institutions gain authority to propose "staged access" (incremental record disclosure) in prescribed circumstances and to take a second timeline extension in certain circumstances; both MFIPPA and FIPPA will exclude records prepared under the Enhancing Digital Security and Trust Act, 2024 (EDSTA) from access-to-information application; and — a genuinely new finding not in the inherited briefing or existing claims register — the IPC will gain express new authority to review an institution's information practices in specified circumstances, an oversight-power expansion distinct from the PIA and breach-reporting duties already known [NEW-2026-1].

AMCTO's advocacy and its own capacity warning

The existing claims register documents AMCTO's MFIPPA reform advocacy at “still being checked” status: municipalities across all nine AMCTO geographic zones have passed resolutions supporting MFIPPA review since 2020 [CL-80020, “still being checked”], and AMCTO's own survey found 85% of respondents lack an open government strategy and 78% lack an open government procedure [CL-80021, “still being checked”], with 84% delegating head-of-institution authority to the municipal clerk [CL-80022, “still being checked”]. This review's live discovery confirms AMCTO's advocacy directly produced the Bill 97 changes — AMCTO's own account frames the reforms as "a win for AMCTO advocacy" following its submission of 20 modernization recommendations to the Province [NEW-2026-2] — but also surfaces a genuine tension AMCTO itself has raised publicly: the same organization whose advocacy helped produce these changes is now on record stating the changes "do not consider municipal staff capacity or financial constraints," and specifically that the January 1, 2027 deadline for Privacy Impact Assessments "is too short a timeframe for municipalities to address new requirements and seek new resources" [NEW-2026-2]. This is a directly sourced, current instance of the same municipal-capacity concern this project's broader corpus documents elsewhere (e.g., the cyber security toolkit's framing of small/rural/northern municipalities as targets, CL-80024) — here applied to the compliance-capacity side of privacy law itself, not just cybersecurity threat exposure.

Bill 194/EDSTA: confirmed still not directly binding on municipalities

The inherited master briefing and the existing claims register describe Bill 194 (the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, enacting the Enhancing Digital Security and Trust Act) at verified status as receiving Royal Assent and, separately, at verified status that its July 2026 regulations designate hospitals, colleges/universities, school boards, and children's aid societies as covered entities — explicitly not yet municipalities [CL-0238, verified]. This review's live discovery independently corroborates and sharpens this jurisdictional distinction from a legal-practice source: Bill 194's Schedule 2 amendments (the FIPPA privacy provisions specifically) "apply only to institutions subject to FIPPA," and while "FIPPA's new provisions reflect basic privacy practices that MFIPPA institutions should also follow," this is explicitly framed as good practice guidance, not a legal requirement extending to municipalities [NEW-2026-3]. This confirms a precise and important jurisdictional point the inherited briefing's more general framing did not fully sharpen: as of this review, Toronto and other Ontario municipalities are subject to Bill 97's MFIPPA-specific amendments (the PIA and breach-reporting duties, coming into force July 2026/January 2027) but not to Bill 194/EDSTA's cybersecurity-designation regime, which currently binds only the four named non-municipal sectors [CL-0238; NEW-2026-3].

The corporate-data asymmetry the inherited briefing frames as the backdrop to municipal privacy law

The inherited master briefing frames Ontario's municipal privacy rules against a broader asymmetry: a data-broker industry it estimates at approximately $280–320 billion (2024) assembles and sells detailed dossiers — location, behaviour, biometrics — on virtually everyone, largely without meaningful consent, citing market-research estimates that "vary by definition" against an older "$200B" figure it flags [confirm] [From this library’s earlier research from the master briefing]. The same briefing states that U.S. government agencies, including the FBI, ICE, IRS, DHS, and the Secret Service, have purchased cell-phone location data and browsing histories from brokers such as Venntel and Babel Street without a warrant, exploiting the "third-party doctrine," and that the U.S. House passed the bipartisan Fourth Amendment Is Not For Sale Act in 2024 to close this "data-broker loophole" [From this library’s earlier research from the master briefing]. This backgrounder did not independently re-verify the data-broker market-size estimate or the Act's legislative status this review; both figures are carried at the inherited briefing's own hedge level and should be re-confirmed before public use, consistent with the master briefing's own "Sources to verify" note on this figure. The relevance to this page’s narrower MFIPPA/Bill 97 focus: the inherited briefing's own argument is that this corporate asymmetry is a reason to tighten limits on corporations and refuse municipal purchase of broker data, not to loosen the accountable, purpose-limited obligations MFIPPA and Bill 97 place on the City itself [From this library’s earlier research from the master briefing].

The City of Toronto's own generative AI guidance, read directly

The existing claims register records at “still being checked” status that the City's Guidance for the Responsible Use of Generative AI prohibits staff from using non-City-approved generative AI tools and identifies specific risks [CL-80031, “still being checked”]. This review's direct fetch of the guidance document's full text confirms and substantially extends this: issued June 18, 2025 by the Technology Services Division, the guidance names Microsoft Chat (within the City's Microsoft 365 environment) as the sole officially-approved generative AI tool for City work, explicitly prohibiting "use of other Generative AI tools or software not approved or supplied by the City" [NEW-2026-4]. The guidance sets out nine named principles (Human-Centered Design, Transparency, Privacy, Accountability, Fairness, Security, Accuracy, Enablement/Technology Literacy) and operationalizes privacy specifically: staff must not input Personal Information (as defined under MFIPPA) or Personal Health Information (as defined under PHIPA) into generative AI tools, and the guidance gives a concrete re-identification risk example — inputting de-identified service-request data by postal code and date, then asking the tool to summarize complaint patterns about a specific address, which could allow the tool to correlate prior inputs and inadvertently re-identify a resident [NEW-2026-4]. The guidance also states that content generated using generative AI for City business purposes must be treated as an official record subject to the City's existing record-keeping obligations, and that generative AI outputs must not be used to "influence a significant or impactful decision" without human review [NEW-2026-4]. This is a substantially more detailed and current picture than the inherited briefing's more general 2026-era description, since this review fetched the document's actual text rather than relying on a secondary characterization.

Sidewalk Labs/Quayside: the resignation, the "inside track" finding, and the disputed rebuttal

The inherited master briefing names Sidewalk Labs/Quayside's collapse as the "defining cautionary tale" and states the project was announced October 2017 and cancelled May 2020 [From this library’s earlier research from the master briefing]. This review's live discovery adds two specific, previously-unconfirmed details. First, the Ann Cavoukian resignation: Ontario's former Information and Privacy Commissioner, serving as a paid privacy consultant to Sidewalk Labs, resigned in October 2018 after learning at a Waterfront Toronto Digital Strategy Advisory Panel meeting that Sidewalk Labs would only "encourage," not require, de-identification of data at the point of collection by third parties participating in the project — and could not guarantee other project participants would strip personal identifiers the way Sidewalk Labs itself had committed to [NEW-2026-5]. Cavoukian's own resignation letter is directly quoted in contemporary reporting: "I imagined us creating a Smart City of Privacy, as opposed to a Smart City of Surveillance" [NEW-2026-5]. Second, the Ontario Auditor General's procurement finding, cited generally in the inherited briefing, is more precise than "gave Sidewalk an inside track": the Auditor General found Sidewalk Labs "received more information" from Waterfront Toronto prior to the RFP's issuance than other parties who would go on to respond to that same RFP [NEW-2026-6]. This finding was contested, not accepted outright: Waterfront Toronto stated its RFP processes were "competitive, fair, and follow best practices," and separately commissioned a review by a former Ontario associate chief justice, who concluded "no organization, including the eventual short-listed proponents, was provided with any information or documentation that was not public or readily accessible" [NEW-2026-6]. This is a genuine, disclosed disagreement between the Auditor General's finding and Waterfront Toronto's own commissioned rebuttal — stated here as an open disagreement, not resolved in either direction, consistent with this project's discipline against silently picking a side of a documented factual dispute.

The inherited master briefing adds further public-trust detail this review did not itself re-verify but carries forward at the inherited briefing's own sourcing: that deal details reportedly stayed hidden even from most of City Council, that Waterfront Toronto board members resigned citing lack of confidence in the project's data-privacy protections, and that a public opposition campaign organized under the name "#BlockSidewalk" mobilized against the project [From this library’s earlier research from the master briefing]. These specifics were not independently re-confirmed via primary-source fetch in this review and should be treated as inherited, not freshly verified, alongside the Auditor General/Waterfront Toronto dispute already logged above.

The Sidewalk Labs "civic data trust" proposal itself

This review's discovery also clarifies the specific governance mechanism at the center of the controversy: Sidewalk Labs proposed that all data generated within Quayside be held in a "civic data trust," structured so no single entity would own the data outright, with the trust approving and controlling collection of, and access to, urban data originating in the district [NEW-2026-5]. This is the same "Urban Data Trust" concept the inherited briefing references as ultimately rejected following IPC criticism [From this library’s earlier research from the master briefing] — this review's discovery corroborates the concept's existence and basic structure directly, though it did not independently re-confirm the specific IPC rejection timeline within its search budget (flagged below as a gap).

Toronto: the case for and against

Section merged 2026-08-11 from a companion Toronto-specific brief (Lane L2a Toronto brief-merge pass).

FOR — the case that Toronto's data-governance framework is maturing responsibly:

AGAINST — the case that real gaps and unresolved tensions remain:

Both sides draw on real, cited facts; the FOR case leans on the City's own detailed, operational policy documents (Generative AI guidance, information-management policy alignment), the AGAINST case leans on AMCTO's own capacity warning and the unresolved Sidewalk Labs procurement dispute — this brief states the asymmetry without adjudicating which side the evidence favours on balance.

Toronto-specific figures:

ItemValuePeriodSource
Global data-broker industry (inherited estimate)~$280-320B2024master briefing-carried-forward
Bill 97 Royal AssentApril 24, 2026NEW-2026-1
Bill 97 MFIPPA provisions in forceJuly 1, 2026 / January 1, 2027 (staged)2026-2027NEW-2026-1
MFIPPA response-time extension30 days → 45 dayseffective per staged timelineNEW-2026-1
2022 municipal FOI response rate (30-day)81% (vs. 51% comparator)2022CL-80019
AMCTO survey: municipalities lacking open government strategy85%2024-era surveyCL-80021
AMCTO survey: municipalities lacking open government procedure78%2024-era surveyCL-80021
National survey: concern about smart-city privacy88% concerned "on some level"Oct-Nov 2018CL-80030
City-approved generative AI toolMicrosoft Chat (sole approved tool)since June 2025NEW-2026-4

No published Ontario-wide or Toronto-specific cost estimate for municipal PIA/breach-reporting compliance under Bill 97 was located in this review; this is flagged as a genuine gap rather than estimated here, consistent with AMCTO's own stated concern that funding for the new requirements has not been resolved [NEW-2026-2].

Toronto-relevant precedents: The inherited master briefing names Estonia's X-Road (integrated, citizen-auditable data exchange across 900+ institutions) and Barcelona's DECODE/city-data-commons model as the page’s strongest existing international precedents [From this library’s earlier research from the master briefing], neither independently re-verified in this review. This review's own live discovery adds the EU's GDPR Article 35 Data Protection Impact Assessment regime as a directly comparable, more prescriptive precedent for the specific PIA content-standard gap Bill 97 creates for Ontario municipalities [NEW-2026-7]. On the cautionary-precedent side, Toronto's own Sidewalk Labs/Quayside episode remains the page’s central domestic case: Ann Cavoukian's October 2018 resignation over an unresolved third-party de-identification gap [NEW-2026-5], and the Auditor General's disputed "inside track" procurement finding [NEW-2026-6], are both now documented with more precision than the inherited briefing's general summary. No non-Ontario Canadian municipal precedent for a Bill-97-style PIA reform's implementation experience was identified in this review — stated as a gap.

Municipal ask (upward): This page’s jurisdiction discipline: core privacy law (MFIPPA, PIPEDA, and now Bill 97's amendments) is provincial and federal, not municipal — the City of Toronto did not write these rules and cannot unilaterally change the PIA deadline or content requirements [NEW-2026-1]. this library's municipal-asks table was not checked against a row specific to this issue in this review. The clearest already-documented instance of municipal-sector institutional pushback on a provincial privacy/access reform is AMCTO's own public capacity warning about the Bill 97 PIA deadline [NEW-2026-2] — an association-level advocacy position, not a specific Toronto City Council motion, and this brief does not present it as equivalent to a formal council ask. No Toronto City Council motion specifically requesting a PIA content-standard template, extended implementation timeline, or provincial funding for Bill 97 compliance was identified in this review. a recommendation card (this page’s card, revised after adversarial audit) now asks the Province/IPC to confirm its already-existing PIA guide [backgrounder NEW-9] has been fully updated for Bill 97 ahead of the January 2027 deadline, rather than asking the Province to build a template from scratch.

Toronto bottom line: Toronto's municipal data-governance framework is undergoing genuine, currently-in-motion legal change (Bill 97's staged MFIPPA amendments) layered onto policy infrastructure the City has already built independently (the Generative AI guidance, information-management policy alignment) — but the reform's own architects at AMCTO are on record saying the implementation timeline may outpace municipal capacity, and the City's own most consequential recent data-governance episode (Sidewalk Labs) still carries an unresolved factual dispute about whether its procurement process was actually fair. A PIA content standard does already exist (the IPC's own published guide, under active revision for Bill 97) — the live open question is whether the City has adopted it and whether the IPC will finish updating it before the January 2027 deadline, not whether one exists at all [backgrounder NEW-9, adversarial-audit correction].

Toronto-specific uncertainties:

Key tensions / tradeoffs

AMCTO's own advocacy produced reforms it is now warning municipalities cannot meet on the stated timeline. AMCTO campaigned for MFIPPA modernization and frames Bill 97 as an advocacy win [NEW-2026-2], while simultaneously, and in the same public communications, warning that the January 1, 2027 PIA deadline doesn't account for municipal staff capacity or financial constraints [NEW-2026-2]. This is not a contradiction in AMCTO's position so much as a documented tension in the reform's own design — the organization that asked for reform is on record saying the reform's implementation timeline may outpace the sector's ability to comply, a tension this backgrounder surfaces rather than resolves.

Bill 194/EDSTA's cybersecurity regime and Bill 97's MFIPPA privacy regime move on different, only partially overlapping tracks for the same municipal institutions. Municipalities are bound by Bill 97's new PIA and breach-reporting duties starting mid-2026/2027 [NEW-2026-1] but are not currently designated entities under Bill 194/EDSTA's cybersecurity framework, which as of its July 2026 regulations covers only hospitals, colleges/universities, school boards, and children's aid societies [CL-0238, verified; NEW-2026-3]. A resident or councillor could reasonably expect "the province's public-sector cybersecurity and privacy law" to be one coherent regime; in practice it is two statutes with different scope, and municipalities sit inside one (MFIPPA/Bill 97) while remaining outside the other (EDSTA) for now — a genuine, currently-true jurisdictional fact rather than a contested interpretation.

The Auditor General's "inside track" procurement finding and Waterfront Toronto's own commissioned rebuttal remain in disclosed, unresolved tension. Both are real, sourced positions — an official Auditor General finding on one side, a former associate chief justice's independent review commissioned by the audited party on the other — and this backgrounder states both rather than adjudicating which is correct, consistent with the citation discipline this template requires for genuine cross-source disagreement.

What the evidence does and doesn't support

Well-supported:

Thin or contested:

International context

1. Treaties/frameworks touched. This review did not identify a specific UN treaty or international human-rights instrument directly and precisely engaged by municipal data-privacy/information-governance practice in the way, for example, ICESCR is engaged by housing policy — privacy protection in this domain is governed by domestic statute (MFIPPA, PIPEDA) rather than a named international instrument with a citable article number applicable to municipal governance specifically. Stated plainly rather than manufacturing a connection: no genuine treaty/framework angle was found for this specific sub-question in this review.

2. 2-3 best global comparators. (a) The European Union's General Data Protection Regulation (GDPR), specifically Article 35's Data Protection Impact Assessment (DPIA) requirement: controllers (including municipal government bodies within EU member states) must conduct a DPIA before any processing "likely to result in high risk to the rights and freedoms of natural persons," with the assessment required to include a systematic description of the processing and its purposes, a necessity/proportionality assessment, a risk assessment, and mitigating safeguards [NEW-2026-7] — structurally close to, and a useful comparator for, Ontario's own new MFIPPA Privacy Impact Assessment requirement under Bill 97, though GDPR's DPIA is more prescriptive about required assessment content than what this review could confirm for Ontario's newer, less mature PIA requirement. (b) This review did not identify a specific named non-EU municipal government (a specific city, not just "some European cities") with a directly documented, evidence-backed civic-data-trust or algorithmic-governance program materially more developed than the concepts already named in the inherited briefing (Estonia's X-Road, Barcelona's DECODE) — those two remain the strongest comparators available in this page’s existing material and are not re-verified fresh in this review. The inherited briefing describes Estonia's X-Road as integrated data exchange across 900+ institutions under a "once-only" principle, where every query is logged and citizens can audit who accessed their own data — the trustworthy-data-use aspiration the briefing holds up as making transparency itself the trust mechanism [From this library’s earlier research from the master briefing]. It describes Barcelona's DECODE program (run with Amsterdam) as a municipal model treating data as public infrastructure and giving citizens cryptographic control over what they share and for what purpose, calling it the closest real-world template for a city stewarding community data as a public asset [From this library’s earlier research from the master briefing]. Neither description was independently re-fetched to a primary source in this review; both are carried at the inherited briefing's own citation level (Estonia via e-estonia.com; Barcelona via the city's own DECODE page and a Nesta report) pending a future our verification track re-verification. (c) A genuine gap: no comparator jurisdiction's own experience specifically informing municipal capacity/implementation-timeline concerns of the kind AMCTO has raised about Bill 97 was located in this review — stated as absent rather than manufactured.

3. What Toronto/Ontario can steal shamelessly. The concrete, transferable mechanism from the GDPR comparator is Article 35's specific content requirements for a DPIA (systematic description of processing and purpose; necessity/proportionality test; enumerated risk assessment; named mitigating safeguards) [NEW-2026-7]. ⚠️ FIX (this review's re-verification): the original pass's claim that Ontario's MFIPPA PIA requirement was "not yet detailed in implementing guidance" was incorrect — the Information and Privacy Commissioner of Ontario already publishes a detailed PIA guide directly applicable to MFIPPA institutions: "Planning for Success: Privacy Impact Assessment Guide for Ontario's Public Institutions" (first published November 12, 2025, updated June 24, 2026), which the IPC's own page states explicitly covers institutions subject to FIPPA or MFIPPA and is "meant to help institutions conduct a privacy impact assessment (PIA) in accordance with these laws and best practices," with accompanying "PIA Worksheets" [NEW-9]. This means the GDPR Article 35 comparator is a useful supplementary cross-check, not a gap-filling necessity — a future pass, and any card built on this page, should compare the IPC's own guide's content requirements against GDPR Article 35's rather than treating Ontario as having no guidance to build from.

Cui Bono — who profits from this problem persisting

Per the Accountability Observatory's charter (Prime Rule) and this template's own guardrail: this library's internal records was checked first. It does not contain an entry specific to municipal data-privacy vendors, data brokers operating in the Ontario municipal context, or any Sidewalk-Labs-adjacent entity. This review's own live discovery in this review did not surface a new, citable, provenance-gradeable beneficiary finding specific to this page’s scope (municipal information governance and MFIPPA compliance) within its search budget — as distinct from the inherited briefing's broader, un-sourced-at-claim-level commentary on the ~$280-320B data-broker industry generally [From this library’s earlier research from the master briefing], which is a real phenomenon but not pinned to a specific, named, ESTABLISHED-or-REPORTED-grade entity profiting from Toronto's or Ontario municipalities' information-governance practice specifically, as this table's guardrails require (a general industry-scale figure is not itself a citable Cui Bono row without a named entity and a specific sourced mechanism).

This is an honest empty table, not a skipped section. No a registered entity/registered accountability claims is asserted here. A genuine candidate area for a future capture pass: the specific vendors supplying municipal records-management, FOI-request-processing, or AI-governance software to Ontario municipalities (a real, findable commercial market) were not identified by name with a sourced "how they profit from persisting information-governance dysfunction" mechanism within this review's budget — flagged as a capture-backlog item below rather than forced into a row that doesn't meet the template's sourcing bar.

Open questions / data gaps

Claim-index appendix

carried-forward (from promoted this page’s carried-forward master briefing (data information governance), no per-fact a formally registered claim ID in the source document; cited to the document directly):

carried-forward-LEDGER (existing this library's claims register rows for this slug, cited at recorded status):

New load-bearing findings (this review, source quotes below, not yet through this library’s formal verification process):

---

Source quotes (NEW-2026-1 through NEW-2026-7)

NEW-2026-1 — Bill 97 full staged timeline and new municipal obligations.

"Ontario's 2026 Budget, A Plan to Protect Ontario was tabled on March 26, 2026... Bill 97 received Royal Assent on April 24, 2026... Bill 97's FIPPA amendments are deemed to come into force on July 1, 2026, with certain provisions coming into effect on September 15, 2026. The MFIPPA amendments will also come into force in stages with certain provisions effective on July 1, 2026, and others on January 1, 2027... MFIPPA institutions will be required to complete Privacy Impact Assessments (PIAs) before collecting personal information... institutions must report the theft, loss, or unauthorized use or disclosure of personal information to the affected individual as well as to the Information and Privacy Commissioner of Ontario (IPC)... The IPC will be granted express authority to review an institution's information practices in specified circumstances."

Source: Hicks Morley, "Ontario Modernizes Its Freedom of Information and Privacy Regime," by Scott T. Williams, May 7, 2026, https://hicksmorley.com/2026/05/07/ontario-modernizes-its-freedom-of-information-and-privacy-regime/. Accessed via direct fetch 2026-07-14.

NEW-2026-2 — AMCTO advocacy framing and capacity-concern warning.

"Through Bill 97: Plan to Protect Ontario (Budget Measures) Act, 2026, the Province introduced changes to the Municipal Freedom of Information and Protection of Privacy Act, 1990 (MFIPPA)... These changes align the Act with similar changes made previously to FIPPA, but do not consider municipal staff capacity or financial constraints. The January 1 deadline for privacy impact assessments is too short a timeframe for municipalities to address new requirements and seek new resources."

Source: AMCTO, "Advocacy Update: Budget Package Includes a Win for AMCTO Advocacy as Province Announces Changes to MFIPPA" and "Advocacy Update: Follow-Up to Budget Update on Proposed MFIPPA Changes," https://www.amcto.com/about-amcto/news-announcements/advocacy-update-budget-package-includes-win-amcto-advocacy-province. Accessed via WebSearch summary 2026-07-14; not independently fetched in full within this review's budget — a verification check should fetch the AMCTO pages directly.

NEW-2026-3 — Bill 194/EDSTA Schedule 2 scope confirmation.

"The amendments in schedule 2 of Bill 194 apply only to institutions subject to FIPPA. However, FIPPA's new provisions reflect basic privacy practices that MFIPPA institutions should also follow, and these practices help MFIPPA institutions protect individuals' privacy, reduce risk, comply with other existing obligations and maintain public trust... As of July 1, 2025, FIPPA now contains an express statutory requirement to safeguard personal information."

Source: Information and Privacy Commissioner of Ontario, "Frequently Asked Questions – FIPPA and MFIPPA Amendments," https://www.ipc.on.ca/en/resources/fippa-mfippa-amendments-faq (first published June 23, 2025, updated July 3, 2026). FIX (this review's re-verification): this page was described in the original draft as unreachable ("no readable content, likely JS-rendered"); on adversarial re-check 2026-07-14, a direct fetch of this exact URL succeeded and returned readable content confirming the page's existence and title, corroborating rather than contradicting the quoted claim above — the claim itself was not wrong, only the earlier note about fetch access. Corroborated via independent legal-practice commentary in the original search pass and by this review's direct fetch.

NEW-2026-4 — City of Toronto Generative AI guidance, full primary-text read.

"The City of Toronto's officially supported and approved generative AI tool is Microsoft Chat, which is integrated within the Microsoft 365 environment... The use of any non-approved generative AI tools, including public-facing tools, is not permitted... Privacy must be preserved in all generative AI usage. City staff must safeguard personal information (PI), personal health information (PHI) and sensitive data from unauthorized collection, use, disclosure, or retention. These types of data and information must not be used with generative AI tools... You input a dataset showing de-identified service requests by postal code and date. Later, you ask the system to summarize complaint patterns about a specific address or person. The AI tool could potentially correlate the postal code and dates with previous inputs, unintentionally revealing identifiable details about a resident, even if you never included a name."

Source: City of Toronto, Technology Services Division, "Guidance for the Responsible Use of Generative Artificial Intelligence," issued June 18, 2025, https://www.toronto.ca/legdocs/mmis/2025/hl/bgrd/backgroundfile-258274.pdf. Accessed via direct fetch (PDF) 2026-07-14.

NEW-2026-5 — Ann Cavoukian resignation and civic data trust proposal detail.

Cavoukian "resigned as a paid consultant for Sidewalk Labs over concerns that the data collected by sensors and other technologies in the Quayside neighborhood would not be anonymized by third-party players... Sidewalk Labs said de-identification at the point of collection would only be encouraged, not required"; her resignation letter stated, "I imagined us creating a Smart City of Privacy, as opposed to a Smart City of Surveillance." Separately: "Sidewalk Labs proposed that all of the data generated by Quayside be kept in a 'civic data trust.' This way, no one entity would own all of it. The trust would approve and control the collection of, and manage access to, urban data originating in Quayside."

Source: CBC News, "'Not good enough': Toronto privacy expert resigns from Sidewalk Labs over data concerns," https://www.cbc.ca/news/canada/toronto/ann-cavoukian-sidewalk-data-privacy-1.4872223; corroborated by The Globe and Mail, "Privacy expert Ann Cavoukian resigns from Sidewalk Toronto smart-city project," https://www.theglobeandmail.com/business/article-privacy-expert-ann-cavoukian-resigns-from-sidewalk-toronto-smart-city/; and StateScoop, "Sidewalk Toronto project loses privacy expert over data anonymization policy," https://statescoop.com/sidewalk-toronto-project-loses-privacy-expert-over-data-anonymization-skepticism/. Accessed via WebSearch 2026-07-14; not independently fetched to a single primary source within this review's budget.

NEW-2026-6 — Auditor General "inside track" finding and Waterfront Toronto's disputed rebuttal.

"Sidewalk Labs received more information from Waterfront Toronto prior to the RFP than other parties that would be responding to the RFP... Waterfront Toronto told the auditor general that it also shared information with other potential bidders, though the report states that Sidewalk 'received more information' from Waterfront than the other parties... Waterfront Toronto issued a statement saying 'our RFP processes are competitive, fair, and follow best practices' and hired former Ontario associate chief justice Coulter Osborne to review the auditor's report, who concluded 'no organization, including the eventual short-listed proponents, was provided with any information or documentation that was not public or readily accessible.'"

Source: IT World Canada, "Sidewalk Labs got more info than others before Toronto waterfront RFP issued: Ontario auditor," https://www.itworldcanada.com/article/sidewalk-labs-got-more-info-than-others-before-toronto-waterfront-rfp-issued-ontario-auditor/; corroborated by The Logic, "Waterfront Toronto provided information to Sidewalk Labs ahead of Request for Proposals, Ontario AG says," https://thelogic.co/news/waterfront-toronto-provided-information-to-sidewalk-labs-ahead-of-request-for-proposals-ontario-ag-says/. Accessed via WebSearch 2026-07-14; not independently fetched to the Auditor General's own primary report text within this review's budget — a verification check should fetch the AG's Waterfront Toronto VFM audit chapter directly.

NEW-2026-7 — GDPR Article 35 DPIA comparator.

"Under Article 35 GDPR, when a type of processing is likely to result in high risk to the rights and freedoms of natural persons, the controller must conduct a data protection impact assessment prior to processing... The assessment must contain at least: a systematic description of the envisaged processing operations and purposes; an assessment of necessity and proportionality; an assessment of risks to data subjects' rights and freedoms; and measures to address risks including safeguards and security measures."

Source: WebSearch synthesis drawing on gdpr-info.eu, "Privacy Impact Assessment - General Data Protection Regulation (GDPR)," https://gdpr-info.eu/issues/privacy-impact-assessment/, and the Irish Data Protection Commission, "Data Protection Impact Assessments," https://www.dataprotection.ie/en/organisations/know-your-obligations/data-protection-impact-assessments. Accessed via WebSearch 2026-07-14; the GDPR text itself (Article 35) was not independently fetched in full within this review's budget.

NEW-9 — IPC's existing published PIA guide for MFIPPA/FIPPA institutions (adversarial-audit addition, correcting this backgrounder's original "no guidance exists" claim).

"This guide is intended for institutions subject to Ontario's Freedom of Information and Protection of Privacy Act (FIPPA) or Municipal Freedom of Information and Protection of Privacy Act (MFIPPA). It is meant to help institutions conduct a privacy impact assessment (PIA) in accordance with these laws and best practices. This PIA guidance document has been updated to incorporate the statutory requirements of FIPPA that came into force on July 1, 2025." / "NOTICE: CHANGES TO FIPPA AND MFIPPA — Ontario's public sector access and privacy laws have changed as a result of Bill 97, A Plan to Protect Ontario Act (Budget Measures), 2026, with further amendments in force on July 1, 2026, September 15, 2026, and January 1, 2027. As a result, some IPC guidance is under review and subject to change."

Source: Information and Privacy Commissioner of Ontario, "Planning for Success: Privacy Impact Assessment Guide for Ontario's public institutions," first published November 12, 2025, updated June 24, 2026, https://www.ipc.on.ca/en/resources/planning-success-privacy-impact-assessment-guide-ontarios-public-institutions (PDF: https://www.ipc.on.ca/en/media/5988/download). Accessed via direct fetch 2026-07-14. This directly contradicts this backgrounder's and Card a recommendation card's original premise that no Ontario-specific PIA content guidance existed — the guide exists, predates Bill 97's Royal Assent, and the IPC's own notice states it is being actively updated for Bill 97. A future verification check should fetch the guide's PDF content directly to compare its specific content requirements against GDPR Article 35's.