Why data integration units exist
Ontario’s Freedom of Information and Protection of Privacy Act was amended to enable prescribed data integration units (DIUs) to collect personal information for linking, so government can create and use de-identified datasets for analysis. On paper, this is the adult version of evidence-based policy: stop guessing with siloed spreadsheets; start measuring outcomes across programs.
The IPC’s materials on the review and approval process under FIPPA Part III.1 make the bargain explicit. Integration is allowed, but not as a free-for-all. There are process gates, standards, and oversight expectations. Ontario has also published data integration data standards aimed at protecting confidentiality when personal information is handled for linking and de-identification. Start from ipc.on.ca rather than vendor white papers when you brief executives.
I do not treat those gates as anti-innovation theatre. I treat them as load-bearing walls.
Predictive governance is seductive
Once linked data exists, the analytical questions escalate:
- Which interventions reduce emergency visits?
- Which students are at risk of disengaging?
- Where should inspectors go first?
- Which households will need support next winter?
Those questions can improve services. They can also slide into scoring people. The technical path from de-identified population models to re-identification risk, function creep, and front-line use of “risk flags” is shorter than most project charters admit.
I have been in meetings where someone said “it’s de-identified, so privacy is done.” That sentence should set off alarms. De-identification is a risk management method, not a moral reset. Quasi-identifiers, small cells, longitudinal links, and external datasets all reopen risk. If a model output can be applied to an individual at the point of service, you are no longer only doing statistics. You are doing decisioning.
Where privacy friction should show up
Healthy friction looks like this:
- Purpose binding. Linking for program evaluation is not permission for enforcement targeting.
- Minimum necessary sources. Every additional registry multiplies both insight and harm potential.
- Separation of roles. Analysts who build de-identified products should not casually become operational scorers for front-line staff.
- Independent oversight. IPC approval and periodic assessment are features. Attempts to weaken independent review should be read as risk concentration, not “streamlining.”
- Public transparency. People deserve to know that integration units exist, what they link, and what they do not do.
- Challenge paths. When models affect benefits or burdens, people need a way to question errors without navigating a maze.
When political timelines compress, friction is the first budget cut. That is when privacy professionals earn their keep.
A practical control set for DIU-adjacent work
If you advise a ministry, hospital partner, or vendor touching integrated government data, I would insist on:
- A living register of datasets in and derived products out.
- Documented linkage keys and destruction or isolation rules for identifiers after linking.
- Re-identification testing that matches modern attack methods, not 2012 checkbox methods.
- Ethics and equity review for models that could allocate benefits or burdens.
- Contracts that ban silent secondary use by service providers.
- Incident playbooks for mislinkage and mistaken identity — because integration errors hurt real people.
- Clear answers to “can a front-line worker see a risk score derived from this?” If yes, privacy analysis starts over.
- Logging of who requested which analytical product and for which statutory purpose.
Predictive value vs democratic restraint
I am not anti-analytics. I am anti-magical thinking. Governments will keep wanting earlier warning and tighter targeting. Climate response, health system strain, and fiscal pressure all push that way. The adult response is not to pretend prediction is impossible. It is to force a design choice: population learning with hard barriers, or personal prediction with explicit legal authority, notice, and challenge rights.
If you cannot explain the difference in plain language to the public, you are not ready to link the data.
Vendors selling “insights platforms” to the public sector should hear the same message. If your demo ends with a map of households ranked by risk, you are not selling neutral tooling. You are selling a decision system that needs legal authority, equity analysis, and a challenge process. Procurement language should require those artifacts before go-live, not after a newspaper story.
How this connects to the wider Canadian privacy floor
Public-sector integration in Ontario sits beside private-sector reform debates after Bill C-27 and beside health privacy enforcement under PHIPA. The common lesson is accountability with evidence. Whether the actor is a DIU, a hospital, or a platform, “trust us, it’s for good” is not a control. Document purpose, minimize identifiers, test re-identification, and keep independent oversight meaningful. For health-adjacent links, remember that PHIPA still polices personal health information in custodian hands even when analytics stories sound whole-of-government.
Actionable takeaway
Ontario’s FIPPA data integration framework is a test of whether the public sector can do large-scale analytics without quietly building a parallel profiling infrastructure. The legal pathway exists. The privacy friction — standards, approvals, de-identification discipline, purpose limits — is what keeps predictive governance from becoming personal surveillance. Protect the friction. Improve the analytics inside it. Read the IPC Part III.1 materials before you approve the next linkage. If your organization uses integrated public data, can you show — today — that outputs cannot be re-applied to individuals without a fresh legal basis?