Canada - Ontario - Cybersecurity and AI Act (Bill 194)

Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024

Canada

RAI-CA-NA-SCSBTXX-2024
Effective: January 29, 2025
In Force(In Force)
ActGovernance and OversightRisk ManagementData Protection and Privacy
Export PDF

This Ontario Act introduces new obligations for public sector entities regarding cybersecurity, responsible AI use, and enhanced privacy protections, particularly for minors.

Overview

The Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, originally introduced as Bill 194, represents a landmark legislative effort by the Province of Ontario to modernize and fortify the digital landscape of its public sector. This comprehensive Act, which received Royal Assent on November 25, 2024, and saw its core component, the Enhancing Digital Security and Trust Act (EDSTA), come into force on January 29, 2025, addresses critical contemporary challenges related to cybersecurity, the ethical deployment of artificial intelligence (AI), and the safeguarding of personal information. The legislation is designed to foster public confidence in government operations by ensuring that public sector entities manage digital information and technology with the highest standards of security, transparency, and accountability. It acknowledges the pervasive impact of digital technologies on the lives of Ontarians and seeks to establish a robust framework that balances innovation with essential protections, particularly for vulnerable populations such as children. Through a combination of new statutory provisions and amendments to existing privacy legislation, the Act sets a foundational standard for digital governance across a broad spectrum of public services, laying the groundwork for a more secure and trustworthy digital public sphere in Ontario.

At its core, the Act is structured around two main pillars: the creation of the Enhancing Digital Security and Trust Act, 2024 (EDSTA) as a new statute, and significant amendments to the Freedom of Information and Protection of Privacy Act (FIPPA) and the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA). The EDSTA introduces a framework for mandatory cybersecurity programs, the responsible use of AI systems, and specific protections for digital information pertaining to minors. Concurrently, the amendments to FIPPA and MFIPPA enhance existing privacy safeguards, notably by introducing mandatory privacy breach notification requirements for institutions. This dual approach ensures that both the proactive measures for digital security and the reactive mechanisms for privacy protection are strengthened. The scope of the Act extends to a wide array of public sector entities, including provincial and municipal institutions, children's aid societies, and school boards, thereby encompassing vital public services that handle sensitive personal data and increasingly rely on advanced digital technologies. The legislation emphasizes that while it provides the overarching framework, many of the granular details and specific compliance obligations will be elaborated through forthcoming regulations, highlighting a phased implementation strategy that allows for adaptability and responsiveness to evolving technological and security landscapes.

Definitions

The Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, introduces and clarifies several key definitions crucial for its interpretation and application across Ontario's public sector. Central to the Act is the definition of an “artificial intelligence system,” which is articulated as “a machine-based system that, for explicit or implicit objectives, infers from the input it receives in order to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments, and such other systems as may be prescribed.” This definition is significant as it provides a clear scope for the AI governance provisions within the Enhancing Digital Security and Trust Act (EDSTA), distinguishing it from some other legislative efforts that might delegate the definition of AI to regulations. By providing this statutory definition, the Act aims to ensure clarity and consistency in how public sector entities identify and regulate their use of AI technologies, encompassing a broad range of applications from predictive analytics to automated decision-making systems that interact with or impact individuals.

Another fundamental term defined by the Act is “public sector entity.” This critical definition delineates the organizations subject to the new obligations introduced by the legislation. Public sector entities are explicitly identified as institutions within the meaning of the Freedom of Information and Protection of Privacy Act (FIPPA), with the notable exclusion of the Legislative Assembly of Ontario. It also includes institutions under the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), children's aid societies, and school boards. This broad inclusion ensures that a significant portion of Ontario's public service, responsible for delivering essential services and handling vast amounts of personal information, falls under the purview of strengthened cybersecurity and AI governance. Furthermore, the Act clarifies that the collection, use, retention, or disclosure of “digital information” by a public sector entity also encompasses such activities when performed by a third party on behalf of that entity. This provision is vital for addressing outsourcing arrangements and ensuring that accountability for digital security and trust extends beyond the immediate organizational boundaries to all entities involved in processing public sector data. The concept of “digital information” itself, while not exhaustively detailed, broadly refers to data handled in digital form, underscoring the Act's focus on the modern, electronically managed information ecosystem.

Governance and Institutional Framework

The governance and institutional framework established by the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, is designed to create a multi-layered system of oversight and accountability for digital security and the use of AI within Ontario's public sector. At the highest level, the Lieutenant Governor in Council is granted significant authority to make regulations governing cybersecurity at prescribed public sector entities. This regulatory power is extensive, allowing for the establishment of detailed requirements concerning the development and implementation of cybersecurity programs, which may include elements such as incident response, recovery measures, oversight mechanisms, reporting timelines, and specific roles and responsibilities for individuals within these entities. This delegation of authority to the Lieutenant Governor in Council underscores the government's intent to maintain flexibility in adapting the regulatory landscape to rapidly evolving technological threats and best practices, ensuring that the framework remains relevant and effective over time. The reliance on regulations for specific details indicates a strategic approach to allow for more agile adjustments without requiring legislative amendments for every technical or procedural update.

Complementing the broad regulatory powers, the Act also empowers the Minister to set cybersecurity technical standards and incident reporting requirements through regulations. This ministerial authority ensures that expert-level guidance and specific technical benchmarks can be established and updated to address emerging threats and technological advancements. The distinction between general cybersecurity program requirements and specific technical standards allows for a comprehensive approach where both strategic oversight and operational details are covered. Furthermore, the Information and Privacy Commissioner of Ontario (IPC) plays a crucial role within this framework, particularly concerning data protection and privacy breach notifications. The Act introduces a mandatory obligation for institutions to notify both the IPC and affected individuals in the event of a theft, loss, or unauthorized use or disclosure of personal information, especially when there is a real risk of significant harm. The IPC is also granted powers to consult with law enforcement or other privacy protection authorities and is required to maintain the confidentiality of whistleblowers who report contraventions of FIPPA. This enhanced role for the IPC significantly strengthens independent oversight and public accountability in the handling of personal information, reinforcing the trust aspect of the Act's title by providing a clear avenue for redress and oversight in privacy matters.

Key Focus Areas

The Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, strategically focuses on several critical areas to enhance digital security and public trust. A primary focus is the establishment of robust cybersecurity programs within public sector entities. The Act empowers the government to mandate that these entities develop and implement comprehensive cybersecurity programs, which are expected to encompass a wide range of measures. These measures are anticipated to include proactive risk assessments, the deployment of preventative technologies, the formulation of incident response and recovery plans, and the assignment of clear roles and responsibilities for cybersecurity management. The emphasis on programs rather than isolated measures indicates a commitment to a systemic and continuous approach to cybersecurity, recognizing that digital threats are constantly evolving and require ongoing vigilance and adaptation. The legislation also allows for the setting of technical standards for cybersecurity, ensuring that public sector entities adhere to recognized best practices and benchmarks to protect their digital infrastructure and the sensitive information they manage.

Another pivotal area of focus is the responsible and accountable use of artificial intelligence (AI) systems within the public sector. Recognizing the transformative potential and inherent risks of AI, the Act establishes a framework for governing its deployment. Public sector entities may be required to comply with specific requirements regarding their use of AI, which could include providing detailed information about their AI systems, developing and implementing comprehensive accountability frameworks, and taking proactive steps for risk management. The Act's preamble explicitly states a belief that AI systems in the public sector should be used in a "responsible, transparent, accountable and secure manner that benefits the people of Ontario while protecting privacy." This foundational principle guides the development of future regulations that will flesh out the specifics of AI governance, aiming to ensure that AI applications serve the public good without compromising fundamental rights or trust. Furthermore, the Act places a special emphasis on the protection of digital information related to individuals under the age of 18. It allows for regulations to be made concerning the collection, use, retention, and disclosure of such information by children's aid societies and school boards, acknowledging the unique vulnerabilities of minors in the digital realm and the need for enhanced safeguards in sectors directly impacting their well-being and development.

Implementation Framework

The implementation framework for the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, is characterized by a phased approach, with many of its key provisions reliant on the promulgation of future regulations and directives. While the Act itself provides the overarching legal authority and sets the foundational principles, the granular details of compliance, specific technical requirements, and procedural mandates are largely deferred to subsequent regulatory instruments. This legislative strategy offers the government the flexibility to adapt the framework to evolving technological landscapes and emerging best practices without requiring repeated amendments to the primary statute. The Lieutenant Governor in Council is empowered to make comprehensive regulations governing cybersecurity at prescribed public sector entities, including the mandatory development and implementation of cybersecurity programs. Similarly, the Minister holds the authority to establish technical standards and incident reporting requirements through regulations, ensuring that the operational aspects of digital security are guided by expert-level detail and can be updated efficiently.

The Act's implementation also involves staggered effective dates for different components. The Enhancing Digital Security and Trust Act (EDSTA), which forms the core of the new legislation, came into force on January 29, 2025. However, certain amendments to the Freedom of Information and Protection of Privacy Act (FIPPA), particularly those related to enhanced privacy protections and breach notifications, are scheduled to come into force in July 2025. This deliberate phasing allows public sector entities a reasonable period to prepare for compliance with different aspects of the legislation. The scope of entities subject to the Act is broad, encompassing institutions under FIPPA and the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), as well as children's aid societies and school boards. Notably, the Legislative Assembly of Ontario has been explicitly excluded from the definition of "public sector entities" under the EDSTA, meaning it is not subject to the new cybersecurity and AI system requirements. This targeted application ensures that critical public service providers are brought under the new digital governance regime. The significant reliance on future regulations means that while the legal framework is now established, the practical implications and specific compliance actions for public sector entities will become clearer as these detailed regulations are developed and released, necessitating ongoing vigilance and engagement from affected organizations.

Monitoring and Evaluation

The monitoring and evaluation mechanisms embedded within the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, are designed to ensure ongoing adherence to digital security and privacy standards, and to foster accountability across public sector entities. A cornerstone of this framework is the mandatory privacy breach notification requirement introduced through amendments to the Freedom of Information and Protection of Privacy Act (FIPPA). Institutions are now obligated to notify both the Information and Privacy Commissioner of Ontario (IPC) and the affected individuals in the event of any theft, loss, or unauthorized use or disclosure of personal information, particularly if there is a real risk of significant harm. This requirement ensures that privacy incidents are not only reported to a central oversight body but also that individuals whose information has been compromised are informed, enabling them to take protective measures. The factors relevant to determining a "real risk of significant harm" are outlined in the Act, providing guidance for institutions in assessing the severity and impact of breaches. This mechanism serves as a critical feedback loop, allowing the IPC to monitor trends in privacy breaches, identify systemic vulnerabilities, and guide public sector entities in improving their data protection practices.

Beyond privacy breach notifications, the Act also anticipates the establishment of incident reporting requirements related to cybersecurity through future regulations. While specific details are yet to be fully prescribed, the legislation empowers the Minister to set such requirements, which are likely to differ from privacy breach reporting and could be triggered by broader cyberattacks or system disruptions. These incident reporting mandates will provide the government with crucial intelligence on the state of cybersecurity across the public sector, enabling a proactive and coordinated response to emerging threats. The overall framework for cybersecurity programs, which public sector entities may be required to develop and implement, will inherently include elements of ongoing monitoring and evaluation. These programs are expected to incorporate measures for continuous assessment of security controls, regular audits, and performance metrics to ensure their effectiveness. The Act also highlights the role of the IPC in providing recommendations on the public sector's use of artificial intelligence (AI), emphasizing the importance of human rights protections and due diligence. While the Act does not explicitly detail a formal, overarching evaluation process for the entire legislative framework, the combination of mandatory reporting, regulatory oversight, and the IPC's advisory and investigatory powers creates a robust system for monitoring compliance and assessing the effectiveness of the digital security and trust measures over time.

Penalties, Liability, and Appeals

The Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, outlines specific provisions regarding penalties, liability, and appeals, which are crucial for understanding the enforcement mechanisms and legal implications of non-compliance. Notably, the Act explicitly states that nothing within the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, the Enhancing Digital Security and Trust Act (EDSTA), or any regulation or directive issued under it, establishes a private law duty of care owing to any person. This provision is significant as it limits the ability of individuals to pursue civil litigation against public sector entities based solely on a failure to comply with the Act's provisions. This approach aims to prevent the creation of new avenues for private lawsuits, instead channeling enforcement through the administrative and regulatory mechanisms established by the legislation. Furthermore, the Act clarifies that a failure to comply with its provisions, or any regulation or directive made under it, does not affect the validity of any policy, Act, regulation, directive, instrument, or decision. This ensures that the operational continuity and legal force of public sector actions are not automatically invalidated by a breach of the digital security or AI governance requirements, thereby maintaining the stability of government functions.

While the Act itself sets these foundational limitations on private liability, the specific penalties for non-compliance are largely anticipated to be detailed in future regulations. The legislative framework empowers the Lieutenant Governor in Council and the Minister to make regulations that will define the consequences of failing to adhere to the mandated cybersecurity programs, AI governance requirements, and privacy breach notification protocols. These penalties could range from administrative fines to other corrective measures, designed to incentivize compliance and deter violations within the public sector. The Information and Privacy Commissioner of Ontario (IPC), with its enhanced role in privacy oversight, is expected to play a significant part in investigating complaints and ensuring compliance with the privacy-related amendments to FIPPA. Although the Act does not explicitly detail an appeals process for decisions or directives made under its authority, it is generally understood that administrative decisions made by government bodies are subject to review through existing administrative law mechanisms, such as judicial review, or through specific appeal processes that may be established in future regulations. The focus on regulatory enforcement rather than private litigation underscores a policy choice to manage compliance through a public oversight model, with the IPC serving as a key independent body for addressing privacy concerns and ensuring accountability.

Relationship to Other Instruments

The Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, establishes a clear relationship with other existing legal instruments, particularly by amending and interacting with foundational privacy legislation in Ontario. A central aspect of this relationship is its direct impact on the Freedom of Information and Protection of Privacy Act (FIPPA) and the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA). The new Act introduces significant amendments to FIPPA, notably mandating privacy breach notifications to the Information and Privacy Commissioner of Ontario (IPC) and affected individuals when there is a real risk of significant harm due to the theft, loss, or unauthorized use or disclosure of personal information. While the initial bill proposed changes to MFIPPA, the Enhancing Digital Security and Trust Act (EDSTA), enacted by Bill 194, applies to institutions covered by both FIPPA and MFIPPA, as well as children's aid societies and school boards. This integration means that the new cybersecurity and AI governance requirements will operate in conjunction with, and build upon, the existing privacy principles and obligations enshrined in FIPPA and MFIPPA, creating a more comprehensive data governance framework for the public sector.

Crucially, the Act includes a provision addressing potential conflicts with other legislation. It explicitly states that "If a provision of this Act or the regulations made or directives issued under this Act conflicts with a provision of any other Act or regulation, the provision in the other Act or regulation prevails." This supremacy clause indicates that the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, is not intended to override or supersede other provincial legislation where conflicts arise. Instead, it is designed to augment and enhance existing legal frameworks for digital security and privacy without disrupting the hierarchy or specific mandates of other statutes. This approach ensures legal certainty and avoids creating unintended inconsistencies within Ontario's legislative landscape. Furthermore, the Act's provisions allowing for regulations to set technical standards respecting cybersecurity and requirements for AI systems mean that it will also interact with, and potentially draw upon, various technical standards and guidelines developed by national or international bodies, even if not explicitly referenced. The Act also does not establish a private law duty of care, ensuring that its enforcement mechanisms primarily remain within the public and administrative law domains, rather than creating new avenues for private litigation, thus carefully defining its scope and interaction with tort law.

International Alignment

While the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, is a provincial statute specific to Ontario, Canada, its underlying principles and objectives demonstrate a clear alignment with broader international trends and best practices in digital governance, cybersecurity, and artificial intelligence ethics. The Act's emphasis on responsible, transparent, accountable, and secure use of AI systems in the public sector, coupled with its commitment to protecting privacy, resonates strongly with global frameworks and recommendations from international bodies. For instance, the Ontario Human Rights Commission (OHRC), in its recommendations on Bill 194, explicitly referenced "internationally established guardrails" for AI, highlighting the importance of human rights due diligence in AI development and deployment. This suggests an implicit recognition within the legislative process of the need to align with global ethical standards for AI, such as those promoted by the OECD, UNESCO, and the European Union, which advocate for human-centric and trustworthy AI.

The Act's provisions for mandatory cybersecurity programs and incident reporting also reflect a global consensus on the necessity of robust digital infrastructure protection. Governments worldwide are increasingly enacting legislation that requires critical infrastructure and public sector entities to implement comprehensive cybersecurity measures, conduct risk assessments, and report security incidents. This alignment is driven by the transnational nature of cyber threats, which necessitate a harmonized approach to defense and resilience. Similarly, the enhanced privacy protections, particularly the mandatory breach notification requirements introduced through amendments to FIPPA, mirror provisions found in leading international data protection regulations, such as the European Union's General Data Protection Regulation (GDPR) and various state-level privacy laws in the United States. These global standards emphasize the importance of transparency, accountability, and individual rights in the processing of personal data. Although the Ontario Act does not explicitly refer to specific international treaties or agreements, its foundational principles of digital security, privacy protection, and ethical AI governance are consistent with the evolving international legal and policy landscape, positioning Ontario's public sector within a broader global movement towards responsible digital transformation.

Implementation Timeline

MilestoneDateNotes
Bill Introduced (First Reading)2024-05-13Bill 194 tabled in the Legislative Assembly of Ontario.
Public Consultation Period Closed2024-06-30Public invited to submit comments on the Bill.
Royal Assent Received2024-11-25Bill 194 passed Third Reading and received Royal Assent, becoming an Act.
Enhancing Digital Security and Trust Act (EDSTA) In Force2025-01-29The core component of the Act, establishing new cybersecurity and AI requirements, came into force.
FIPPA Amendments In Force2025-07-01Amendments to the Freedom of Information and Protection of Privacy Act, including mandatory breach notifications, are scheduled to come into force.
Future Regulations and DirectivesTo be determinedMany specific requirements regarding cybersecurity programs, AI governance, and technical standards will be detailed in subsequent regulations and directives.

Compliance Checklist

CheckRequired Action
Cybersecurity Program DevelopmentDevelop and implement a comprehensive cybersecurity program in accordance with forthcoming regulations, including risk assessment, incident response, recovery measures, and defined roles and responsibilities.
AI System Governance FrameworkEstablish internal accountability frameworks for the use of AI systems, ensuring responsible, transparent, and secure deployment, as per future prescribed requirements.
Risk Management for AIImplement steps for managing risks associated with AI systems, including impact assessments and mitigation strategies, as will be detailed in regulations.
Privacy Breach Notification ProceduresDevelop and implement clear procedures for mandatory notification of privacy breaches to the Information and Privacy Commissioner of Ontario (IPC) and affected individuals, where there is a real risk of significant harm.
Digital Information Protection for MinorsFor children's aid societies and school boards, prepare to comply with regulations governing the collection, use, retention, and disclosure of digital information relating to individuals under 18.
Third-Party OversightEnsure that third parties acting on behalf of the public sector entity comply with the Act's provisions regarding the collection, use, retention, or disclosure of digital information.
Adherence to Technical StandardsMonitor and comply with any technical standards respecting cybersecurity or AI systems that may be set by the Minister through regulations.
Incident Reporting ProtocolsEstablish protocols for reporting cybersecurity incidents as will be required by future regulations.
Ongoing Monitoring and ReviewImplement mechanisms for continuous monitoring and periodic review of cybersecurity programs and AI governance frameworks to ensure ongoing effectiveness and compliance.
Staff TrainingProvide regular training to staff on cybersecurity best practices, privacy protection, and the responsible use of AI systems in line with the Act and its forthcoming regulations.

Sources and References

SourceType
Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, SO 2024, c. 24 - Government of Ontarioofficial
Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024 - Legislative Assembly of Ontariogovernment
Ontario's Public Sector Cyber Security Legislation Receives Royal Assent - Faskenlegal
Ontario's new public sector cybersecurity and AI law now in force – What public and private sector organizations need to know - Dentons Datalegal
Ontario Introduces Bill 194 to address cyber security in the public sector - Gowling WLGlegal
Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024 | Ontario Human Rights Commissiongovernment
Ontario Bill 194: Strengthening Cyber Security and Building Trust in the Public Sector - Osler, Hoskin & Harcourt LLPlegal
Plain English

Ontario's new Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, aims to modernize and fortify the digital operations of the province's public sector entities, enhancing cybersecurity, governing artificial intelligence (AI) use, and strengthening privacy protections. This law applies broadly to provincial and municipal institutions, children's aid societies, and school boards, including third parties handling digital information on their behalf, though it notably excludes the Legislative Assembly of Ontario.

The Act introduces several key obligations. Public sector entities must develop and implement comprehensive cybersecurity programs, covering risk assessments, preventative technologies, and incident response plans. They also face requirements for the responsible and accountable use of AI systems, emphasizing transparency and risk management. Furthermore, the law brings enhanced privacy protections, particularly for individuals under 18, with future regulations set to detail rules for handling minors' digital information. A critical change is the mandatory notification requirement: institutions must inform both the Information and Privacy Commissioner of Ontario (IPC) and affected individuals of any privacy breach involving a "real risk of significant harm."

While the core Enhancing Digital Security and Trust Act (EDSTA) came into force on January 29, 2025, and amendments to the Freedom of Information and Protection of Privacy Act (FIPPA) follow in July 2025, many specific compliance details, technical standards, and penalties for non-compliance will be outlined in future regulations. This means affected organizations need to stay vigilant for upcoming rules. A practical surprise is that the Act explicitly states it does not create a private law duty of care, meaning individuals cannot sue based solely on a failure to comply with its provisions. Enforcement will primarily occur through administrative and regulatory channels, with the IPC playing a key oversight role.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under Canada - Ontario - Cybersecurity and AI Act (Bill 194). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalGovernance and Institutional FrameworkUpon release of regulations

    Applies to: Public sector entities.

    Lieutenant Governor in Council is granted significant authority to make regulations governing cybersecurity at prescribed public sector entities.
  2. #2CriticalGovernance and Institutional FrameworkJul 1, 2025

    Applies to: Institutions under FIPPA/MFIPPA.

    Act introduces a mandatory obligation for institutions to notify both the IPC and affected individuals in the event of a theft, loss, or unauthorized use or disclosure of personal information.
  3. #3CriticalKey Focus AreasUpon release of regulations

    Applies to: Public sector entities using AI systems.

    developing and implementing comprehensive accountability frameworks
  4. #4CriticalKey Focus AreasUpon release of regulations

    Applies to: Public sector entities using AI systems.

    taking proactive steps for risk management.
  5. #5CriticalKey Focus AreasUpon release of regulations

    Applies to: Children's aid societies and school boards.

    allows for regulations to be made concerning the collection, use, retention, and disclosure of such information by children's aid societies and school boards
  6. #6ImportantGovernance and Institutional FrameworkUpon release of regulations

    Applies to: Public sector entities.

    Minister to set cybersecurity technical standards... through regulations.
  7. #7ImportantGovernance and Institutional FrameworkUpon release of regulations

    Applies to: Public sector entities.

    Minister to set... incident reporting requirements through regulations.
  8. #8ImportantDefinitionsJan 29, 2025

    Applies to: Public sector entities using third-party services.

    collection, use, retention, or disclosure of “digital information” by a public sector entity also encompasses such activities when performed by a third party on behalf of that entity.
  9. #9ImportantMonitoring and EvaluationUpon release of regulations

    Applies to: Public sector entities.

    These programs are expected to incorporate measures for continuous assessment of security controls, regular audits, and performance metrics
  10. #10ImportantKey Focus AreasUpon release of regulations

    Applies to: Public sector entities using AI systems.

    providing detailed information about their AI systems
  11. #11ImportantRelationship to Other InstrumentsJan 29, 2025

    Applies to: Public sector entities.

    If a provision of this Act or the regulations made or directives issued under this Act conflicts with a provision of any other Act or regulation, the provision in the other Act or regulation prevails.

© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash