Not legal advice. This post explains PIPEDA in plain language for teachers. For guidance specific to your board or institution, consult your privacy officer or legal counsel.

Canadian teachers increasingly rely on third-party tools (Chrome extensions, messaging apps, Google integrations) to fill gaps in their school's LMS. But every time a tool touches student data, a question arises: does this comply with PIPEDA?

The honest answer for most teachers is: you probably don't know, and your board might not either. This post explains what PIPEDA actually requires, how it applies to classroom tools, and what ClassWatcher does specifically to address it.

What is PIPEDA?

PIPEDA, the Personal Information Protection and Electronic Documents Act, is Canada's federal private-sector privacy law. It governs how organizations collect, use, and disclose personal information in the course of commercial activity.

PIPEDA is built around 10 fair information principles. The ones most relevant to classroom tools are:

Principle 1
Accountability
An organization is responsible for personal information it collects, including information handled by third parties on its behalf.
Principle 2
Identifying purposes
The purpose for collecting personal information must be identified before or at the time of collection.
Principle 3
Consent
Knowledge and consent of the individual is required for collection, use, or disclosure, with some exceptions.
Principle 4
Limiting collection
Only collect information necessary for the identified purpose. Not more.
Principle 5
Limiting use & disclosure
Personal information can't be used for purposes other than those for which it was collected.
Principle 8
Openness
Organizations must make their privacy policies and practices readily available.

Does PIPEDA apply to teachers?

This is where it gets nuanced. PIPEDA technically applies to commercial activity. Public schools are generally exempt from PIPEDA at the federal level. They fall under provincial legislation (like Ontario's Municipal Freedom of Information and Protection of Privacy Act, MFIPPA, or Alberta's Freedom of Information and Protection of Privacy Act, FOIPPA).

However, when a teacher uses a third-party commercial tool that processes student data, that tool is subject to PIPEDA even if the school isn't. The tool operator (ClassWatcher in this case) has obligations under PIPEDA for any personal information it handles.

The practical implication: your school board's privacy obligations are governed by provincial law. But the tools you use are governed by federal law (PIPEDA). Both matter. Your IT department will ask about both.

What student data does a classroom tool actually touch?

Not all tools are equal. Before adopting any third-party tool, it's worth asking what personal information it actually processes:

The less a tool collects, the lower the privacy risk. A tool that reads student names from a page you already have open is very different from one that scrapes your full gradebook and sends it to a US server for processing.

How ClassWatcher is designed around PIPEDA

ClassWatcher was built by a Canadian teacher and designed with PIPEDA in mind from the start. Here's how each relevant principle maps to what the tool actually does:

PIPEDA Principle What ClassWatcher does
Accountability โœ“ Privacy Policy published at classwatcher.com/privacy.html. IT documentation at classwatcher.com/it.html. Operated by a named individual (David W Cooper).
Identifying purposes โœ“ Data is collected solely to support the missing-assignment tracking and parent/student messaging features the teacher explicitly uses. No other purpose.
Consent โœ“ Teachers enter parent contact information themselves, with no automatic scraping of contact details. Parents can opt out of further messages at any time by texting STOP.
Limiting collection โœ“ ClassWatcher reads only the submission page currently open in the teacher's browser. It does not access grades, course content, other tabs, or any page the teacher hasn't explicitly opened.
Limiting use & disclosure โœ“ Student data is never sold, shared with third parties, or used for advertising. Message logs are automatically deleted after 365 days.
Safeguards โœ“ All data in transit encrypted via HTTPS/TLS. Passwords hashed with bcrypt. Session tokens cryptographically random. Extension only runs on Brightspace pages.
Openness โœ“ Privacy Policy, Terms of Service, and IT/Security overview all publicly available.

What about provincial privacy laws?

Ontario teachers are most often subject to MFIPPA and their board's own acceptable use policies. Alberta uses FOIPPA. BC has PIPA. These laws share similar principles to PIPEDA (consent, limiting collection, safeguards) but apply to the board rather than the tool vendor.

In practice, this means your board's IT or privacy officer may ask: "Where is the data stored? Who can access it? How long is it retained? Is it stored outside Canada?"

ClassWatcher's answers: data is hosted on DreamHost servers in the United States. Most student-identifying data (class lists, submission status) is stored locally in the teacher's browser, not on ClassWatcher servers. Message logs are retained for 365 days then deleted. Only the teacher who entered the data can access it.

Note on US hosting: Some Ontario school boards have policies requiring data to be stored in Canada. If your board has such a requirement, check with your privacy officer before using any US-hosted tool, including ClassWatcher.

What to tell your board or IT department

If you're asked to justify using ClassWatcher, here's a concise summary you can share: