Information-sharing agreements under BC FIPPA
An information-sharing agreement is a written agreement between a BC public body and another party that sets the conditions on how personal information is collected, used or disclosed between them. FIPPA defines the term in section 69, and the other party can be another public body, a federal institution, a private organization or an individual. The agreement turns a legal permission into operating rules both sides can follow.
When does a BC public body need an ISA?
An ISA is the usual instrument when personal information will flow regularly between a public body and another organization, in either direction, as part of an ongoing programme rather than a single disclosure. Typical cases: a health authority sending referral data to a community agency, a municipality exchanging enforcement records with the police, a university sharing student data with a scholarship funder.
For ministries, FIPPA says ISAs are prepared in accordance with the minister’s directions, and ministry agreements are summarized in the government’s personal information directory. Other public bodies often set the same expectation in their own privacy policy.
What an information-sharing agreement should contain
- Parties. Legal names, and a named contact at each for questions and incidents.
- Authority. The provision that permits each party to collect and disclose. Your counsel settles this, and it should be specific, not “as permitted by law”.
- Purpose. One clear purpose. Any use beyond it needs a fresh look.
- Data elements. A field-by-field list. “Client file” is not a data element.
- Safeguards. How data moves, who can access it, and the reasonable security arrangements FIPPA requires (section 30).
- Retention and disposal. How long each party keeps it, and how disposal is confirmed.
- Breach notification. Who tells whom, and how fast, if something goes wrong on either side.
- Review date. A fixed date to confirm the sharing is still needed and still matches the text.
How an ISA differs from a service contract
A service contract governs a vendor processing information on the public body’s behalf. An ISA governs two parties who each use the information for their own purposes, which is why it needs its own authority, purpose and limits. Using a vendor contract template for a sharing arrangement leaves out the authority and purpose clauses, which are the ones a reviewer checks first.
Common mistakes
- The data list is vague. Without it, nobody can tell whether a new field is in scope, so everything ends up in scope.
- Nobody owns the review date. The agreement expires on paper and the data keeps flowing.
- The safeguards describe a system that changed. The secure file transfer named in the ISA was replaced by email two years ago.
- Onward disclosure is silent. The receiving party passes the data to its own vendor, and nothing in the agreement addresses it.
- The PIA and the ISA disagree. They were written by different people at different times.
How the PIA and the ISA fit together
Most sharing programmes need both documents. The PIA tests whether the sharing complies with FIPPA, and the ISA records the conditions the parties agree to, so each document should reference the other. The triggers for an assessment are in when a BC public body needs a PIA. Retention terms should match your records retention schedule, and vendors on either side will recognize the obligations described in security for BC public sector vendors.
Questions we are asked
What is an information-sharing agreement?
An information-sharing agreement is a written agreement between a BC public body and another party that sets the conditions on how personal information is collected, used or disclosed between them.
When does a BC public body need an ISA?
An ISA is the usual instrument when personal information will flow regularly between a public body and another organization, in either direction, as part of an ongoing programme rather than a single disclosure.
How is an ISA different from a service contract?
A service contract governs a vendor processing information on the public body’s behalf. An ISA governs two parties who each use the information for their own purposes, which is why it needs its own authority, purpose and limits.
Do we need a PIA as well as an ISA?
Usually both. The PIA tests whether the sharing complies with FIPPA, and the ISA records the conditions the parties agree to, so each document should reference the other.
Getting an agreement drafted or reviewed
We draft and review the operational content of ISAs and work alongside your counsel, who settles the legal authority. We are not lawyers. See FIPPA PIAs and information-sharing agreements, or browse all writing.