POPA & ATIA Readiness Check

How ready is your municipality?

FOIP is gone. Alberta's Protection of Privacy Act and Access to Information Act are now in force, with penalties reaching $1 million. Tick what's already true — and see where you stand.

Two minutes. Eighteen questions. No email required.
1 Privacy Governance POPA s.5
CivicShift assigns the Privacy Officer as a system role and keeps the program documented and current by design — not by memory.
2 Breach Readiness POPA s.34.1
CivicShift captures the breach, walks the harm assessment, and time-stamps every step — so "we reported on time" is a record, not a memory.
3 Records & Audit Trail POPA s.27
CivicShift writes a signed, tamper-evident access trail at the data layer — every view of a confidential record logged automatically, and impossible to rewrite.
4 Access Requests ATIA · Duty to Assist
CivicShift turns the Duty to Assist into a tracked workflow — responsive records surfaced, deadlines watched, every effort logged as proof.
5 Active Disclosure ATIA s.7
CivicShift flags what belongs in active disclosure and keeps it current — so proactive publishing becomes a routine the system drives, not a task that slips.
6 Staff Awareness & Use The human layer
CivicShift makes the compliant path the path of least resistance — so the rules hold whether or not anyone's thinking about them. Let the computer do the computer stuff.
0 / 18
Items ready
Tick what's already true
Work down the list above. Your readiness verdict appears here as you go — and the unchecked items show you exactly where the risk lives.

See the gaps close — on realistic data.

Book a short walkthrough on a live sample municipality. Watch CivicShift produce a record, with its audit trail, on demand — the proof behind every line above.

Book a discovery conversation

This self-assessment is a readiness aid, not legal advice. Statute references reflect Alberta's Protection of Privacy Act and Access to Information Act; confirm current obligations against the legislation or your own counsel.