Evolve FM is now Zenith. We’ve brought the product under our company name. Same software, same team — new name as of September 1, 2026.

If you run the workplace side of a municipality, a library board or a school board, a deadline lands in January that changes how you buy a municipal space booking system. From 1 January 2027, institutions covered by MFIPPA have to complete a privacy impact assessment before collecting personal information — and a desk booking record is personal information.

This guide covers who is caught, what changes in January, why booking data counts, what the assessment should actually examine, and how municipal procurement differs from the rest of the broader public sector.

Who the municipal space booking rules cover

MFIPPA — Ontario’s Municipal Freedom of Information and Protection of Privacy Act — applies to municipal institutions. The Information and Privacy Commissioner lists municipal government, school boards, police services boards and public library boards among them.

That is a wider net than people expect. A library board runs study-room bookings. A police services board runs shift desks. Both sit inside MFIPPA, and both collect the same kind of record.

What changes on 1 January 2027

Three MFIPPA obligations arriving on 1 January 2027 for municipal space booking: privacy impact assessments, breach reporting and annual reports
Three obligations, one date. The first one has to happen before you collect anything.

The Information and Privacy Commissioner sets out three new obligations for MFIPPA institutions from that date:

  • Privacy impact assessments before collecting personal information.
  • Breach reporting to the IPC, and notification to affected individuals, where there is a real risk of significant harm.
  • Annual reports covering breaches that meet the specified thresholds.

The first one reshapes a purchase. An assessment before collection means before go-live, which in practice means during procurement.

Why municipal space booking data is personal information

It is easy to think of municipal space booking as furniture logistics. It is not. A booking record names a person, a building and a day — often a floor and a desk too.

Three parts of the record deserve particular attention.

  • Attendance patterns. Bookings plus check-ins reconstruct who came in and when, across months.
  • Guests and visitors. A guest captured against a booking is a third party whose information you now hold, and who never agreed to your employment terms.
  • Accommodation context. A desk assigned for health or disability reasons can reveal something sensitive by implication, even when no medical detail is stored. Keep those desks outside the bookable pool, as our hot desking policy template sets out.

One consequence is peculiar to municipalities. Records the institution holds can be subject to access requests. So design the reporting to make aggregate answers easy, and to keep individual timelines off the default view.

What a privacy impact assessment for municipal space booking should examine

An eight-point privacy impact assessment checklist for a municipal space booking system, covering collection, purpose, access, retention and breach response
Eight questions. Your privacy office will have more; none of these should be missing.
  1. What is collected — name, booking, check-in, guest details, and anything a free-text field invites people to add.
  2. Why — the stated purpose, written narrowly enough to exclude uses you have not agreed to.
  3. Whether it feeds attendance management. Answer this explicitly. Staff will assume it does unless you say otherwise.
  4. Who can see what — roles, and whether anyone can view an individual’s history rather than an aggregate.
  5. Where it is stored — the hosting region, and which sub-processors touch it.
  6. How long it is kept — a retention period that matches your records schedule, enforced rather than aspirational.
  7. What happens in a breach — who decides whether the harm threshold is met, who notifies the IPC, on what timeline.
  8. What the vendor can see — support access to production data, and whether it is logged.

A vendor’s documentation answers most of these. Three usually need asking in writing before you sign: retention enforcement, individual-level visibility, and support access to production data.

Municipal procurement is its own regime

Municipal space booking purchases sit outside Ontario’s BPS Procurement Directive. Municipalities follow their own council-approved by-laws instead. Thresholds, approval levels and posting requirements vary, and a neighbouring city’s rules are not yours. That directive, and the thresholds it sets for hospitals, school boards and colleges, is covered in our guide to the BPS Procurement Directive.

Library boards and school boards may fall under different rules again. The practical advice is the same in every case: confirm the route with your own procurement office before you shape the purchase, because the classification decides the process and the process decides the timeline.

Other obligations that land on a municipal space booking purchase

  • Accessibility. Designated public sector organisations must meet WCAG 2.0 Level AA under the AODA. Ask for a dated conformance report, then run your own keyboard test. Our guide to accessible booking systems covers the eight checks.
  • French language services. Obligations vary by designation and region, but if you serve in both languages, the refusal messages and notifications have to work in both.
  • Records retention. Booking data has to fit your existing records schedule, not sit outside it in a vendor’s database with a different clock.
  • Council transparency. A utilisation figure that reaches a council report needs a divisor somebody can defend in public. How to calculate space utilisation covers what makes that number hold up.

Questions people actually ask

Does a municipal space booking system really need a privacy impact assessment?

From 1 January 2027, MFIPPA institutions must complete one before collecting personal information, and booking records are personal information. Treat it as required rather than optional, and start it during procurement — an assessment that arrives after go-live has missed its own deadline.

Does this apply to library boards?

The IPC lists public library boards among MFIPPA institutions. If your board takes bookings for study rooms, meeting rooms or staff desks, the same analysis applies.

Are booking records subject to freedom of information requests?

Records held by the institution can be, subject to the exemptions in the Act. That is a reason to be deliberate about what you collect and how long you keep it, and to make aggregate reporting the easy path. Your FOI coordinator should see the system before it goes live, not after the first request. A visitor log raises the same questions; our guide to visitor management software works through them.

Can we use booking data for attendance management?

That is a policy decision with legal and labour dimensions, not a software setting — and if you intend to, the purpose has to be stated up front rather than added later. Repurposing collected information without saying so is exactly what these rules exist to prevent.

Do municipalities follow the BPS Procurement Directive?

No. Municipalities follow their own procurement by-laws. The evaluation questions overlap heavily, but the thresholds and approvals are your council’s.

How long should we keep booking records?

Long enough to support the reporting you actually do — usually a year or two for trend analysis — and no longer. Fit it to your records schedule and enforce it in the system rather than by intention.

Where to start

Bring your privacy officer into the municipal space booking procurement now, not at implementation. Give them the eight questions above. Let them tell you which answers they need from a vendor in writing. If you are buying before January, the assessment is part of the project either way, and doing it early costs less than doing it twice.

If a Canadian-owned, Canadian-hosted option belongs on the list, Zenith Workplace reports by floor, team and space type rather than by individual, keeps the register and the bookings in one place, and is built to WCAG 2.2 AA with both languages first-class.

Published by Zenith Software Corp., Victoria, British Columbia · September 2026. Practical guidance, not legal advice — confirm every obligation with your own privacy officer, FOI coordinator and procurement office. We verified the external references in September 2026.