Privacy Law Is Changing:
What Bill 97 Means for Your Organization
- July 06, 2026
- 3 min read
Privacy Compliance Is About to Get More Serious in Ontario
Ontario’s privacy landscape is undergoing significant change. With the passage of Bill 97, many of the privacy modernization measures previously introduced under Ontario’s Freedom of Information and Protection of Privacy Act (FIPPA) are now being extended to the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA). These changes create new obligations for municipalities and other organizations subject to MFIPPA, while also increasing oversight and accountability.
For organizations that have already invested in privacy governance, these changes may feel like a natural progression. For others, the time to begin preparing is now.
What's Changing Under Bill 97?
Bill 97 introduces several important privacy and information management requirements that will directly impact organizations governed by MFIPPA.
Mandatory Privacy Impact Assessments (PIAs)
Organizations will be required to conduct Privacy Impact Assessments before collecting personal information. These assessments must examine:
- The purpose of collection
- Legal authority
- Information retention requirements
- Security safeguards
- Privacy risks and mitigation strategies
This formalizes a practice long recommended by privacy professionals and the Information and Privacy Commissioner of Ontario.
Mandatory Privacy Breach Reporting
Organizations will need documented processes for identifying, assessing, and reporting privacy breaches where there is a real risk of significant harm. This means privacy incidents can no longer be handled informally or inconsistently.
Enhanced Privacy Safeguards
Bill 97 strengthens requirements for protecting personal information and expects organizations to implement reasonable safeguards appropriate to their risks and operations.
Expanded Powers for the Information and Privacy Commissioner
The Information and Privacy Commissioner (IPC) will receive broader oversight authority, including the ability to review information practices and issue binding orders.
New Whistleblower Protections
Individuals will have mechanisms to confidentially report suspected privacy violations to the Commissioner, adding another layer of accountability for organizations handling personal information.
Why These Changes Matter
While some headlines focused on the controversy surrounding Bill 97’s access-to-information provisions, the privacy-related amendments may ultimately have the greatest operational impact for municipal institutions and public-sector organizations.
Many organizations still rely on informal privacy practices, fragmented policies, or undocumented procedures. Under the new framework, privacy governance will need to be intentional, measurable, and demonstrable.
Organizations that cannot show how privacy risks were assessed, how breaches are managed, or how personal information is protected may face increased scrutiny from regulators and stakeholders alike.
The Compliance Deadline Is Closer Than It Appears
While some Bill 97 provisions take effect earlier, many of the privacy-related MFIPPA requirements are scheduled to come into force on January 1, 2027.
That may seem distant, but building a mature privacy program takes time.
Organizations should begin preparing by:
- Reviewing privacy policies and procedures
- Establishing a formal Privacy Impact Assessment process
- Creating breach response and notification procedures
- Assessing privacy risks associated with technology and AI systems
- Training staff on privacy obligations
- Strengthening governance and accountability structures
- Evaluating vendor and third-party service provider risks
Starting now allows organizations to address gaps methodically rather than rushing toward compliance as deadlines approach.
The Opportunity Behind Compliance
The most successful organizations will view Bill 97 as more than a regulatory requirement. Strong privacy governance can:
- Increase stakeholder trust
- Improve decision-making
- Reduce cybersecurity and privacy risks
- Clarify accountability
- Support digital transformation initiatives
- Enable responsible AI adoption
In many cases, better privacy practices lead to better business practices.
How Garabyte Can Help
Navigating evolving privacy requirements can be challenging, especially for organizations balancing limited resources with growing compliance expectations.
Garabyte helps organizations build practical privacy programs that support both compliance and operational goals. Our services include:
- Privacy Impact Assessments (PIAs)
- Privacy governance program development
- Privacy-by-design implementation
- Breach response planning
- Privacy and security risk assessments
- Compliance readiness reviews
- AI and emerging technology privacy assessments
As Ontario’s privacy framework continues to evolve, organizations that prepare early will be best positioned to reduce risk, demonstrate accountability, and maintain public trust.
Ready for 2027?
Bill 97 is more than a legislative update. It is a signal that privacy governance is becoming a core organizational responsibility. Garabyte can help you turn compliance requirements into practical action. Contact us to learn how.