Kelowna City Privacy Impact Assessment Process

Technology and Data British Columbia 3 Minutes Read · published May 26, 2026 Flag of British Columbia · By Daniel Roy

In Kelowna, British Columbia, municipal projects that collect, use or disclose personal information should follow a formal Privacy Impact Assessment (PIA) process to identify and reduce privacy risks under provincial privacy rules and City policies. A PIA helps project teams, IT, planning and the City Clerk assess data flows, retention, access controls and legal bases before deployment. This article explains roles, step-by-step actions, enforcement pathways and where to find official City and provincial guidance for PIAs on municipal projects.

Carry out a PIA early to reduce rework and legal risk.

Overview of the PIA process

A PIA documents the personal information a project will handle, the purposes for collection, risk assessment, mitigation measures and accountability assignments. Typical stages are scoping, mapping data flows, identifying legal authorities, assessing privacy risks, documenting mitigations and recording approvals. The City Clerk and Information Technology Services typically coordinate PIAs for Kelowna city projects, with input from the project manager, legal counsel and records management.

When to do a PIA

  • New systems or services that collect personal data from residents or employees.
  • Significant changes to how existing systems store, share or disclose personal information.
  • Projects involving third-party service providers or cloud hosting.
  • Public-facing analytic tools, CCTV expansions or IoT deployments.

Penalties & Enforcement

Enforcement for privacy matters affecting municipal records involves both internal City processes and the provincial regulator. The Office of the Information and Privacy Commissioner for British Columbia (OIPC) provides orders and guidance; criminal or monetary penalty amounts are not specified on the cited pages for municipal PIAs and depend on statutory provisions and case outcomes.[2] Internally, the City Clerk and Information Services investigate complaints, implement corrective measures and may notify affected individuals where required by law.[1]

If a privacy breach occurs, prompt internal reporting speeds corrective action and notification.
  • Typical enforcement actions: written orders to change practices, mandated data disposal, audits and public reports.
  • Monetary fines: not specified on the cited pages; consult the OIPC and FIPPA text for statutory penalties.
  • Complaint pathways: submit to City Clerk's Access & Privacy contact or to the OIPC for review.
  • Appeals/reviews: avenues and time limits are governed by provincial statute and OIPC procedures; specific time limits are not specified on the cited pages.

Applications & Forms

The City publishes Access to Information and Privacy contact information and processes; specific PIA forms or templates used by the City are not specified on the cited City page, though the OIPC offers guidance and tools useful for municipal PIAs.[1][2]

How to conduct a PIA for a Kelowna city project

  1. Define scope and stakeholders: identify the project lead, data owners and the City Clerk or Information Services contact.
  2. Map data flows: list data collected, sources, purposes, recipients and retention periods.
  3. Assess risks and mitigations: evaluate risks to individuals and document technical and administrative safeguards.
  4. Record legal authority: identify the municipal purpose and legal basis to collect and use the information under BC law.
  5. Approve and document: obtain approvals from the City Clerk or delegated authority and retain the PIA record with the project file.
  6. Review and update: revisit the PIA on material changes or periodically per City policy.
Retain PIA documentation with the project record to support accountability and later review.

Action steps for project teams

  • Contact the City Clerk's Access & Privacy lead at project start to confirm requirements and templates.[1]
  • Use OIPC PIA guidance to structure assessments and mitigation plans.[2]
  • Budget for privacy controls and potential audit actions.
  • Report suspected breaches immediately to the City Clerk and Information Services.

FAQ

Do all city projects need a PIA?
Not all projects require a formal PIA, but any project collecting or using personal information should assess privacy risk and consult the City Clerk to determine whether a full PIA is required.
Who within the City approves a PIA?
The City Clerk, often with Information Technology Services and legal counsel, is typically responsible for approval and oversight of privacy assessments for municipal projects.
Where can I find PIA templates or guidance?
The OIPC publishes PIA guidance and tools; the City Clerk provides local procedures and contact details on Kelowna's Access & Privacy pages.[2][1]

How-To

  1. Notify the City Clerk and request PIA requirements for your project.
  2. Complete or draft the PIA: scope, data map, risk assessment and mitigation plan.
  3. Implement technical and administrative controls identified in the PIA.
  4. Submit the PIA to the City Clerk for review and approval, and retain the approved record.
  5. Schedule periodic reviews or update the PIA for major project changes.

Key Takeaways

  • Start PIAs early—before procurement or public launch.
  • Coordinate with the City Clerk and IT to ensure legal and technical controls.
  • Document mitigations and approvals to demonstrate accountability.

Help and Support / Resources


  1. [1] City of Kelowna - Access to Information & Privacy
  2. [2] Office of the Information and Privacy Commissioner for BC - Guidance
Daniel Roy

Daniel Roy

Municipal Bylaw Analyst

Daniel analyses municipal bylaws across Canadian provinces and territories. He checks every guide against official municipal and provincial sources.