Owen Sound: A Four-Year City Business Plan

Home › Information, Privacy and Canadian Digital Independence › Chapter 31

Information, Privacy and Canadian Digital Independence

Chapter 31The Safe Information Program

7,907 words · Mike Seiler · Owen Sound, Ontario

Open in the reader →

Vote on the proposals, hear the audio, read the reviews, search the whole plan.

In this chapter

Information has become basic civic infrastructure.

A resident should be able to find out:

For many people, access to that information now depends upon:

That creates a new kind of municipal accessibility question.

My original Safe Information proposal includes:

Those initiatives should be understood as one system.

The goal is not simply:

More Wi-Fi.

The goal is:

Reliable access to useful information without requiring residents to surrender unnecessary control over their privacy.

The Safe Information Program should be built around five principles:

Access

People can reach information.

Accuracy

People can understand where information came from.

Privacy

Access does not require unnecessary surveillance.

Resilience

Important information remains available when technology fails.

Independence

Residents gain the skills to manage their own information rather than becoming more dependent upon a platform.

The central rule is:

Information should make residents more capable, not more trackable.

31.1Information Is Infrastructure

A road allows a person to move physically.

A reliable information system allows them to move through:

Poor information creates real costs.

A resident may:

Municipal information should therefore be treated with the same seriousness as other operating systems.

31.2Safe Information Does Not Mean Government Decides What People May Believe

The word safe needs to be defined carefully.

Safe Information does not mean:

City Hall decides which political opinions are safe.

It means the City's own information systems should be:

Residents remain free to:

The City should be trustworthy because its information practices are disciplined.

Not because it demands trust.

31.3Official Information Should Look Official

Residents should be able to distinguish between:

Where practical, City information should identify:

Responsible Department

Who owns the information?

Last Updated

When was it checked?

Source

Where does the number or claim come from?

Contact

Who can answer questions?

A screenshot shared on social media should not be the only way to know what City Hall actually said.

31.4One Official Source, Many Channels

For important municipal information, maintain one authoritative record.

Then distribute it through appropriate channels such as:

Update the Source First

If information changes:

  1. correct the authoritative source;
  2. distribute the update;
  3. identify the change where appropriate.

This reduces situations where different City channels say different things.

31.5The Information Owner

Every important public information page should have a responsible internal owner.

Not necessarily a person's name publicly.

A department or role.

Someone should be accountable for knowing:

This information is still correct.

A website full of orphaned pages gradually becomes an archive pretending to be a service.

31.6Information Expiry Dates

Some information rarely changes.

Other information expires quickly.

Examples:

Long-Lived

Medium-Lived

Fast-Changing

Pages should be reviewed according to how quickly the information can become wrong.

31.7Date Every Time-Sensitive Page

A resident should never have to wonder:

Is this information from today or 2019?

For time-sensitive content, show:

Old information may remain useful as an archive.

It should not look current.

31.8Archive Instead of Confuse

When a:

move old information into a clearly marked archive where appropriate.

Do not leave an old application page appearing active simply because nobody removed it.

31.9The Correction Standard

Mistakes will happen.

The City's credibility should depend upon what happens next.

When a material public error is identified:

  1. verify it;
  2. correct it;
  3. identify the correction where appropriate;
  4. update downstream channels;
  5. examine why it happened.

The Rule

Correct quickly. Explain proportionately. Learn permanently.

31.10The Public Correction Log

For significant public-facing errors, maintain a simple correction log.

Possible fields:

Date

Incorrect information

Correction

Source updated

Cause where useful

This should not become a list of every typo.

Focus on errors that could materially affect public understanding or action.

31.11"We Do Not Know" Is Valid Information

Government often damages trust by speaking with certainty before facts are known.

During:

a responsible update may be:

We do not yet know the cause.

or:

The estimated restoration time has not been confirmed.

That is better than speculation dressed as authority.

31.12Estimate Means Estimate

Where a City publishes an estimate:

label it.

Do not allow an estimate to gradually become a fact simply because it appeared in an infographic.

31.13Source the Numbers

The broader campaign already commits to carrying sources behind its numbers.

The City should adopt the same discipline.

For public reports and dashboards, important figures should identify:

A resident should be able to ask:

Where did that number come from?

and receive an answer.

31.14Plain Language

Government often uses specialized language because its work is specialized.

That is sometimes necessary.

Residents should not need municipal training to understand ordinary services.

Where technical terms must be used:

Example

Instead of only:

Minor variance required pursuant to the applicable zoning framework

also explain:

The project does not meet one or more existing zoning standards, so a separate approval process may be required.

Precision and plain language can coexist.

31.15One-Page First

For major public decisions and services, begin with a plain-language summary.

Then allow residents to go deeper into:

The first page answers:

What is happening?

Why?

What does it cost?

When?

Who is affected?

What happens next?

Complexity can remain underneath.

The resident should not need to begin there.

31.16Information Accessibility

Municipal information should be designed to work with:

A PDF that appears attractive visually can still be extremely difficult for assistive technology.

Accessibility should begin when the document is created.

31.17Accessibility Beyond Disability

Clear information also helps:

Good accessibility is often simply good communication.

31.18Multilingual Information

Owen Sound residents may speak different languages.

Technology can help translate basic public information.

Machine translation should be identified as such where errors may be possible.

For:

professional or authoritative translation may sometimes be required.

Technology Helps

Humans Remain Responsible

31.19Telephone Still Matters

A modern digital City should still answer a telephone.

Some questions are:

The information system should allow someone to say:

I am confused. Can I talk to a person?

The answer should be yes.

31.20In-Person Still Matters

Residents should retain reasonable access to in-person municipal help.

Digital service can reduce:

It should not become an excuse to lock the front door.

31.21Print Still Matters

Important information should remain printable.

Examples:

A resident should not need to purchase a smartphone to participate in civic life.

31.22No App Required

The City should avoid designing essential services around:

Download our app.

An app may be useful.

It should not become the only doorway.

Public information should generally remain available through:

31.23Free Public Wi-Fi

The original Safe Information proposal calls for free public Wi-Fi where people gather.

That is a practical starting point.

Potential locations may include:

The final network should be based on:

Not on a promise to blanket every metre of the City immediately.

31.24Free to the User Does Not Mean Free to Operate

Public Wi-Fi requires:

Publish the full cost.

A sponsorship or grant may reduce municipal cost.

It does not eliminate operating reality.

31.25Why Public Wi-Fi?

The public purpose should be clear.

Possible benefits include access to:

The purpose is not:

People like free internet.

The purpose is reducing reasonable information-access barriers in public places.

31.26Wi-Fi Where People Actually Gather

Before installing equipment, measure:

Do not purchase equipment for a quiet location merely because the site appeared on a campaign map.

Put infrastructure where it solves a real access problem.

31.27Public Wi-Fi Should Be Separate From Internal City Systems

The public network should not be casually connected to systems containing:

Public access and municipal operations should be appropriately separated.

Cybersecurity architecture belongs in the design.

Not as an upgrade after deployment.

31.28No Marketing Captive Portal

A resident should not need to provide:

simply to use basic public Wi-Fi unless a specific necessity can be demonstrated.

The preferred model is:

Connect. Read the necessary terms. Use the network.

No hidden marketing exchange.

31.29No Political Captive Portal

Public Wi-Fi should never ask:

Would you like updates from the Mayor?

as a condition of connection.

Municipal infrastructure must remain politically neutral.

31.30No Wi-Fi Behavioural Advertising

The City should not fund free internet by silently turning user activity into advertising profiles.

If a funding proposal depends upon:

the public should know that before Council decides.

My preference is:

Do not use that model.

31.31Minimum Network Logging

The public network may require some technical information for:

Collect only what is necessary.

Define:

Do not keep identifiable network histories indefinitely because storage is cheap.

31.32No Location Tracking by Default

A public wireless system should not become an invisible map of:

If anonymous aggregate usage can answer the operating question, use anonymous aggregate information.

31.33Network Metrics Without Tracking People

The City may need to know:

It generally does not need to know:

Mike's phone arrived at 10:03 and left at 10:47.

Design measurement around the service.

Not the person.

31.34Content Neutrality

Public internet should not be filtered according to:

Technical security measures may be necessary for:

subject to proper governance.

The City should be extremely cautious about becoming the arbiter of lawful content.

31.35Public Wi-Fi Is Not Private Wi-Fi

Residents should receive clear security education.

A public network does not automatically make every activity private.

Teach basic precautions such as:

The City should not promise privacy that the technology cannot guarantee.

31.36Network Name Verification

One simple risk is connecting to a fake network with a similar name.

Official City Wi-Fi locations should clearly identify:

A small amount of public education can prevent confusion.

31.37Public Wi-Fi Is Not an Emergency Communications Guarantee

A Wi-Fi network may fail during:

It should supplement communication.

Not become the only emergency channel.

The resilience rule remains:

Important public information needs more than one path.

31.38Backup Power

For selected critical public-information locations, examine whether backup power is justified.

The business case should consider:

Not every Wi-Fi access point needs generator support.

Critical sites may.

31.39Low-Income Home Connectivity

The original Safe Information proposal also calls for helping lower-income homes connect.

The first step should not be creating a new municipal internet company.

Start by asking:

Which residents remain disconnected, and why?

Possible reasons:

Different barriers require different solutions.

31.40Existing Programs First

Before creating a City subsidy, map existing:

connectivity programs that are actually current.

Then help residents find them.

No Wrong Government

The City can be the navigator even when it is not the funder.

31.41Connectivity Navigator

A resident should be able to ask:

I cannot afford or obtain home internet. What options exist?

The navigator can identify:

Do not promise eligibility on behalf of another program.

Help the resident find the proper route.

31.42Do Not Confuse Wi-Fi With Home Broadband

Public Wi-Fi may help someone:

It is not equivalent to reliable home internet for:

The Safe Information Program should distinguish:

public access

from

home connectivity.

31.43Community-Owned Connectivity Study

The source plan proposes studying community-owned service supported by broadband funding rather than placing an unplanned burden on property taxes.

That should remain a study, not a predetermined municipal network build.

Possible models to compare include:

The objective is to understand whether a local public-interest model could solve a genuine gap.

31.44Begin With the Gap

Do not begin:

How do we build municipal broadband?

Begin:

What connectivity problem remains unsolved by the existing market and programs?

If existing providers can solve the problem efficiently:

Good.

The City does not need to own the solution.

31.45Community Ownership Is Not Automatically Cheaper

Public ownership can provide benefits.

It can also create:

A community-owned system should have to prove:

Ownership is a tool.

Not a virtue by itself.

31.46Broadband Business Case

Before any municipal capital commitment, publish:

Coverage Problem

What is missing?

Capital Cost

What would construction cost?

Operating Cost

What does the network cost annually?

Revenue

Who pays for service?

Grants

What funding is confirmed rather than merely possible?

Customers

How many users are realistically required?

Competition

How do existing providers respond?

Technology

How does the system remain current?

Exit

What happens if the business model fails?

No hidden liability.

31.47No Grant-Driven Network

A large outside grant can make a project look inexpensive.

The critical question is:

Who pays after the grant is spent?

Do not build a digital utility the City cannot afford to:

The Financial Standard applies fully.

31.48Regional Connectivity

Connectivity does not stop at municipal boundaries.

If a serious broadband gap is regional, Owen Sound should work with:

rather than pretending a municipal border defines the network problem.

31.49Phone in Every Hand

The original proposal also imagines recovering usable phones that would otherwise be replaced or discarded and getting suitable devices into the hands of residents who have none.

The public-purpose idea is strong:

A functioning device can be an access tool.

But the implementation must be much more disciplined than simply collecting old phones in a box.

31.50Reuse Before Purchase

Before purchasing large numbers of devices, explore:

Many households and businesses replace devices that may still have practical life.

The program should determine whether they can be reused safely and economically.

31.51Device Donation Standard

A donated phone should be assessed for:

A ten-year-old phone that can no longer receive necessary security updates may not be a safe donation.

Reuse should not become transfer of obsolete risk.

31.52Data Wiping

Every donated device must have previous user information properly removed before redistribution.

Potential data may include:

A community device program needs a documented secure-wipe process.

"Factory reset" should not be used casually without confirming the appropriate process for the device.

31.53Donor Privacy

The previous owner also deserves protection.

A donation form should explain:

Do not ask donors to trust an informal process with years of personal data.

31.54Recipient Privacy

The recipient should receive a clean device.

They should not be required to give the City unnecessary information about:

The City or partner provides the tool.

It does not gain ownership of the person's digital life.

31.55Device Ownership

Where practical, donated devices distributed permanently should become the recipient's device.

That can simplify:

If a loan model is used, the agreement must explain:

Choose the simplest workable model.

31.56Chargers

A phone without a working charger is not a functioning program.

The device package should consider:

Small practical details determine whether a policy works in real life.

31.57Cases and Protection

A modest protective case may sometimes extend device life substantially.

The business case should compare:

Stewardship applies to donated equipment too.

31.58Emergency Calling Claims Must Be Verified

The source concept includes emergency calling as an important reason to recover usable devices.

Before the final plan states that a donated phone can reliably reach emergency services without active paid service, the City must verify the current technical and regulatory conditions for the specific:

Never Promise Emergency Capability Without Verification

A resident must not be given false confidence that a device is an emergency lifeline if it has not been confirmed to function that way.

31.59Wi-Fi Calling and Messaging

A suitable phone connected to public or home Wi-Fi may support many communication services without a conventional mobile-data plan.

The exact services depend upon:

The program should teach what each phone actually can and cannot do.

Do not advertise one universal capability that does not exist across all devices.

31.60A Phone Is Not a Cellular Plan

Giving someone a device does not automatically provide:

Be explicit about the difference.

The Safe Information Program should never create the impression that:

free phone

means:

free complete cellular service forever.

31.61Device Setup Support

Some recipients may need help with:

Provide basic setup through trained staff or partners.

Teach the Owner

Do not retain their:

31.62Device Accessibility

A refurbished phone may help a resident use features such as:

Digital accessibility training can significantly increase the value of the device.

31.63E-Waste

Not every donated device will be reusable.

Those devices should move into an appropriate electronics-recycling pathway.

A phone collection program should not create a municipal drawer full of hazardous obsolete electronics.

31.64Repair First

Some donated devices may need:

Compare repair cost with:

This can connect with the Repair Economy developed earlier.

31.65Local Repair Partnerships

Qualified local repair businesses may be able to contribute through:

Any municipal purchasing or service arrangement follows normal procurement rules.

The program should not award work informally because a repair shop offered to help once.

31.66Community Device Drives

Businesses and residents could periodically donate suitable devices.

A partner-led drive may be more practical than continuous City collection.

The program should clearly tell donors:

31.67Device Eligibility

If demand exceeds supply, eligibility criteria should be:

Possible priority might be based on genuine lack of a functioning device rather than complicated personal profiling.

The final design should be developed with partner organizations experienced in serving residents who face access barriers.

31.68Do Not Require Public Proof of Poverty

A recipient should not need to publicly demonstrate financial hardship.

Where eligibility verification is necessary, handle it privately through the appropriate organization.

Dignity matters.

31.69Responsible Data Stewardship

The original plan proposes plain-language training so families are less likely to lose:

This should become a major community education program.

Digital independence begins at home.

31.70Your Photos Are Part of Your Family History

Many families now hold decades of memory inside:

A lost password or broken device can erase:

Residents should understand basic backup.

This is practical digital literacy.

31.71The Backup Rule

Teach a simple principle:

If there is only one copy, it is not safely backed up.

Residents can learn to maintain copies appropriate to their own needs.

The City should not prescribe one commercial cloud provider.

Explain choices.

31.72Cloud and Local Copies

Residents may use:

Each has trade-offs.

The public program can explain:

The goal is informed choice.

31.73Password Education

Basic digital education should include:

Avoid turning workshops into advertising for one vendor.

31.74Recovery Planning

Residents should know:

If I lose this phone today, can I still access my email tomorrow?

That means understanding:

Digital resilience should be planned before the device breaks.

31.75Scam Awareness

Safe Information should include practical education about:

Use authoritative information from the appropriate public agencies and police partners.

The City does not need to become a fraud laboratory.

31.76Synthetic Media and Impersonation

As technology improves, residents may encounter convincing:

The basic lesson should remain timeless:

Urgency is not proof. A familiar voice is not proof. Verify through another trusted channel before sending money or sensitive information.

This is modern media literacy.

31.77The Family Verification Word

Families may choose to create their own private verification method for unusual emergency money requests.

The City does not need to know:

It can teach the concept.

The security belongs to the family.

31.78Children and Digital Literacy

Young people should learn:

Schools and families carry major roles.

The City can support community education through:

Do not create a municipal surveillance program in the name of protecting children.

31.79Source Checking

A simple public information lesson:

Who published this?

When?

What evidence is provided?

Is the claim reporting a fact, estimate or opinion?

Can it be confirmed elsewhere?

These questions help residents navigate:

The goal is critical thinking.

Not telling people what conclusion to reach.

31.80Safe Information and AI

AI systems can make information easier to:

They can also produce incorrect answers.

Any City use of AI for resident information should clearly distinguish:

Example

A chatbot may help someone find a permit page.

The official permit rules remain the authoritative source.

31.81AI Should Cite the City Record

Where automated assistants are used, they should be designed to point residents back to:

The answer should not be:

Trust the chatbot.

It should be:

Here is the source the chatbot used.

31.82Human Escalation

A municipal automated service should always provide a clear route to a person for:

issues.

This follows the staffing principle established earlier:

Technology handles repetition. People handle judgement, complexity and care.

31.83AI Errors

If an automated system repeatedly gives incorrect information:

A convenient wrong answer is worse than a slower correct answer.

AI should not independently decide:

simply because automation is possible.

Professional and legal decision-making requirements remain.

Technology can assist.

Humans remain accountable.

31.85Community Calendar

The source plan proposes one community calendar that is:

That is a strong Safe Information model.

The calendar should help residents answer:

What is happening in Owen Sound?

without requiring them to join five social networks.

31.86Calendar Categories

Possible filters:

The organizer supplies:

The basic listing remains neutral.

31.87Calendar Verification

The calendar should distinguish:

City event

Partner event

Community-submitted event

That does not mean one category is better.

It tells the resident who is responsible.

31.88No Calendar Endorsement

A community listing should not imply:

The City endorses every opinion of this organization.

It means the event met the listing rules.

Nothing more.

31.89Calendar Corrections

Organizers should be able to update:

Stale event information quickly destroys trust.

Automated reminders to verify upcoming listings may help.

31.90Emergency Information

Safe Information becomes most important when conditions are uncertain.

Emergency pages should prioritize:

Avoid:

During emergency:

Clarity wins.

31.91Offline Emergency Information

Essential emergency-preparedness information should also exist in:

formats.

Residents should be able to keep a basic household guide without relying on an internet connection during the emergency itself.

31.92Local Media Partnership

Local journalism and broadcasters can be valuable channels during emergencies and ordinary civic life.

The City should provide media with:

Government should not reward favourable coverage with preferred access.

Public information belongs to the public.

31.93Media Is Not the City's Communications Department

Independent media will:

That is their role.

The City provides accurate source information.

It should not expect journalists to reproduce municipal messaging uncritically.

31.94Social Media Is a Distribution Channel

The City may continue to use external social networks where they reach residents.

Those platforms should not become the only location where essential information exists.

A resident should not need an account with a foreign private company to know:

Post to the public source first.

Then share.

31.95Do Not Build Government Around One Platform

Social networks can:

Municipal information should remain portable across channels.

This is the beginning of digital sovereignty.

31.96Email

Email remains useful for residents who choose to receive:

Subscriptions should be:

A resident subscribing to recreation updates should not automatically be enrolled in unrelated political messaging.

31.97SMS and Alerts

Where future alert systems use:

subscriptions should explain:

Do not send every municipal announcement as an emergency alert.

Overuse teaches residents to ignore alerts.

31.98Alert Severity

Develop clear categories such as:

Emergency

Immediate safety action.

Urgent Service

Significant municipal disruption.

Routine Notice

Normal public information.

Different urgency deserves different communication.

31.99Digital Identity

Residents should not be required to create one large municipal identity profile merely to read public information.

Authentication may be necessary for:

Browsing public information should remain open.

31.100Verify Only What Needs Verification

If a service requires proof that:

is authorized, verify appropriately.

Do not verify identity merely because the technology makes it possible.

The Principle

Anonymous where anonymity works. Verified where verification is genuinely required.

31.101Data Minimization

For every new municipal digital form, ask:

Why do we need this field?

If nobody can explain why the City needs:

do not collect it.

A database cannot leak information that was never collected.

31.102Purpose Limitation

If information was collected to:

register for a swimming program,

do not later use it to:

Collect for a defined purpose.

Use for that purpose.

31.103Retention

Keeping information forever is not automatically safer.

Every data category should have an appropriate retention rule based on:

When information no longer needs to be held:

dispose of it properly.

31.104Access Control

Not every City employee needs access to every dataset.

Provide access based on:

Log sensitive administrative access where appropriate.

The human side of cybersecurity matters as much as software.

31.105Privacy Impact Review

Significant new information systems should undergo a privacy review before launch.

Ask:

What information is collected?

Why?

Where is it stored?

Who can access it?

Is it shared?

How long is it kept?

What happens if there is a breach?

Is there a less intrusive design?

Privacy is easiest to protect before the system is built.

31.106Cybersecurity Review

Likewise, significant systems should receive appropriate security review.

Consider:

The details may need to remain confidential.

The governance should not.

31.107Public Security Versus Security Details

Residents deserve to know:

They do not necessarily need publication of:

Open Government does not mean publishing information that would make public systems easier to attack.

31.108No Security by Obscurity Alone

Sensitive technical details may be protected.

The security model should still rely on proper:

Not merely hoping nobody notices a weak system.

31.109Incident Response

Before a major digital system launches, establish:

The middle of a cyber incident is not the time to decide who has authority.

31.110Breach Communication

If resident information is materially compromised, the City should follow applicable legal obligations and communicate appropriately.

Do not hide a breach simply because disclosure is embarrassing.

Trust depends partly upon what government does after failure.

31.111Backups

Critical municipal information should have tested backup and recovery.

A backup that has never been restored is an assumption.

Periodic recovery testing should be part of digital operations.

31.112Offline Continuity

Every essential digital process should ask:

What do we do if the system is unavailable tomorrow?

Possible backup:

Not every service needs a complete paper mirror.

Essential functions need a reasonable continuity path.

31.113Public Information During Cyber Failure

If the main City website is unavailable during a cyber event, residents still need:

Maintain a continuity plan for public communications that does not depend entirely upon the affected system.

31.114Vendor Risk

A system may be secure internally and still depend upon outside vendors.

For major platforms, understand:

The weakest dependency can become the City's vulnerability.

31.115Vendor Exit

The Infrastructure Index principle applies again:

Never buy a system without knowing how we leave it.

Before procurement:

Digital exit planning is financial planning.

31.116Open Formats

Where practical, public information should be stored and exportable using widely usable formats rather than unnecessarily proprietary structures.

This helps:

Open does not mean insecure.

It means portable.

31.117Public Open Data

Some municipal data can create public value when released openly.

Possible examples:

Before publication:

Open Data should mean:

public information made reusable.

Not:

everything the City possesses dumped online.

31.118Student Use of Open Data

Civic Corps participants, schools and residents can use safe public datasets to:

That turns transparency into education.

Students should not need access to internal confidential systems simply to explore civic data.

31.119Application Programming Interfaces

Where future public systems benefit from automated access, the City may consider appropriate open interfaces.

These should be:

Do not build technical complexity before a genuine use case exists.

31.120Resident Data Locker

The source proposal raises the longer-term idea of a resident data locker that could help people preserve important personal information over time.

That concept should not be launched casually.

A system holding:

creates significant:

questions.

The first four-year step should be education and feasibility.

Not immediate mass storage of sensitive resident records.

31.121Teach Before Storing

The City can create major public value simply by teaching residents how to organize and protect information they already control.

That is lower risk than creating a giant municipal personal-data repository.

First Principle

Help people control their own data before asking them to entrust more of it to government.

31.122Portability

If a future public-interest data locker is ever developed, the resident should be able to:

their information subject to lawful record requirements.

The system should not trap someone because:

This connects directly to the broader vision of portable Canadian civic infrastructure.

31.123The Library as Digital Stewardship Partner

Libraries are natural partners for teaching:

Before the City builds a new training department, identify what the library already provides or could provide through partnership.

31.124Schools as Education Partners

Schools may also help students develop:

The City should not dictate curriculum.

It can provide:

Civic learning becomes more real when students use information from their own city.

31.125Service Clubs and Community Organizations

Community groups may provide:

Their role should follow the Community Partners standards.

No organization receives resident data simply because it volunteered to help.

31.126Businesses

Local technology businesses may contribute:

Any paid municipal work follows procurement rules.

Any sponsorship remains transparent.

A company's assistance should not entitle it to resident information.

31.127Public Wi-Fi Sponsorship

If a business offers to sponsor public Wi-Fi:

Good.

Then ask:

What does the sponsor receive?

A sign?

Naming?

Advertising?

Data?

The answer to the last question should generally be:

Not resident browsing data.

Sponsorship should fund the service.

Not purchase the users.

31.128No Hidden Data Economy

The public should not hear:

The Wi-Fi is free

when the actual exchange is:

Your behaviour is the product.

If a system's economics depend upon data exploitation:

say so before adoption.

Prefer a different model.

31.129Children and Public Wi-Fi

Public Wi-Fi will also be used by young people.

Parents and guardians remain responsible for household choices about children's internet use.

The City should provide a secure operating network.

It should not promise to replace:

31.130Public Library Versus Open Public Network

Different facilities may have different legal, institutional and operational needs concerning internet access.

Do not force one technical policy across every partner location without understanding responsibilities.

The Safe Information framework defines principles.

Implementation can vary by environment.

31.131Digital Inclusion Without Digital Compulsion

The ultimate objective is not:

Everyone online all the time.

It is:

Nobody excluded merely because access to information has become digital.

That can mean:

Both are inclusion.

31.132Information Quiet

Government can also communicate too much.

Residents do not need constant notifications about:

Too much information makes important information harder to see.

Prioritize:

31.133Promotional Versus Operational Information

Municipal communications should distinguish:

Operational

What residents need to know.

Promotional

What government wants residents to notice.

Operational information should always win.

A beautiful announcement is not more important than:

This road is closed tomorrow.

31.134Mayor Communications

The Mayor may communicate about:

Official Mayor communications should remain distinct from:

Public communications staff should not become a taxpayer-funded campaign team.

31.135Election Periods

During election periods, municipal information channels should operate under appropriate election-law and municipal policies.

City communication should continue serving residents.

It should not become an incumbent advantage.

The campaign firewall applies to:

31.136map.ca and Safe Information

The source plan also proposes map.ca as possible public infrastructure.

That proposal will be addressed in detail in Section 33.

For this section, one principle is enough:

No privately associated platform becomes municipal infrastructure without independent legal, governance, privacy, security, accessibility, conflict and procurement review.

The information principles must survive regardless of which platform delivers them.

31.137Safe Information Without map.ca

Council should be able to implement:

even if it never adopts map.ca.

Public policy should not be dependent on one founder or one technology.

31.138Private Platforms Remain Private Choices

Residents may continue to use:

The City does not need to replace everything.

The Safe Information Program provides:

31.139The Canadian Question

For important digital public infrastructure, Owen Sound should begin asking:

Where is the data?

Which country governs the provider?

Can we export the data?

Can the service continue if the vendor changes its terms?

Is there a Canadian alternative?

These questions do not always mean:

Choose Canadian regardless of cost or capability.

They mean digital dependency should become visible.

Section 32 will develop this much further.

31.140Information Resilience

A resilient information system uses multiple layers.

Digital

Website, maps, alerts.

Human

Telephone, City staff, partners.

Physical

Print, signs, posted notices.

Media

Local journalism and broadcasting.

If one layer fails, the community still has others.

31.141The Safe Information Audit

Once per year, test important information from the perspective of an ordinary resident.

Choose common questions:

How do I get a building permit?

Where can I skate this weekend?

Who do I call about homelessness?

Where is tonight's Council meeting?

Is this road closed?

Can a resident find the correct answer quickly?

If not:

Fix the system.

31.142Mystery Resident Test

Have people unfamiliar with City Hall try to complete ordinary information tasks.

Do not coach them.

Observe:

This may reveal more than another internal website meeting.

31.143Search Should Work

Residents frequently begin with a search box.

The City's information architecture should support:

A person searching:

basement apartment

should not need to know the official phrase:

additional residential unit

before finding the right page.

Good search bridges public language and municipal language.

31.144No Dead-End Search Results

If an old page is removed, redirect where practical to:

A resident should not follow a search result into a blank error page when the City knows where the information moved.

31.145Information Pages Should End With Next Step

Every service page should answer:

What do I do now?

That may be:

Information without a next step can still leave the resident stranded.

31.146Safe Information Scorecard

The public scorecard should include measures such as:

Access

Connectivity

Devices

Information Quality

Accessibility

Community Calendar

Human Service

Digital Literacy

Privacy

Cybersecurity

Do not publish security information that would weaken the systems being measured.

31.147Measure Wi-Fi Without Following People

Possible operating metrics:

Where feasible, avoid retaining identifiers longer than required to produce those measures.

The scorecard should measure whether the network works.

Not who used it.

31.148Measure Device Program Outcomes

Do not report only:

500 phones collected.

Also report:

A collection drive can look successful while producing mostly unusable devices.

Measure the useful outcome.

31.149Measure Digital Training

Ask participants whether they became more confident doing specific tasks.

Examples:

Do not claim a workshop made someone "digitally safe."

Measure specific skills.

31.150First 100 Days

The first 100 days should establish the information and connectivity baseline.

1. Public Information Audit

Identify:

2. Stale Information Review

Find high-impact pages that are:

Fix them first.

3. Public Wi-Fi Inventory

Identify:

4. Connectivity Gap Review

Work with Grey County, community organizations and providers to understand genuine barriers.

5. Device Reuse Feasibility

Meet:

6. Emergency Calling Verification

Before making any claim about donated handset emergency capability, verify current Canadian network and device conditions.

7. Privacy Standard

Adopt data-minimization and purpose-limitation requirements for new pilots.

8. Cybersecurity Review

Ensure public access systems remain properly separated from operational City networks.

9. Community Calendar Standard

Define:

10. Digital Literacy Partnership

Map existing:

training before creating new programming.

Publish the baseline.

31.151Year One

During Year One:

The objective is useful access.

Not technological spectacle.

31.152Year Two

During Year Two:

31.153Year Three

During Year Three:

Do not build a network merely because three years have passed.

The evidence still decides.

31.154Year Four

By Year Four, publish the Safe Information Report.

Ask:

Can residents find municipal information more easily?

Is important information current?

Can people still access essential information without a smartphone?

Has public Wi-Fi solved real access problems?

What does it cost?

Did the device program put useful equipment into people's hands?

Were donated devices wiped and refurbished safely?

Did digital-literacy programs teach practical skills?

Did we avoid turning public connectivity into a tracking system?

Were resident data and City systems protected?

Did emergency information remain available through multiple channels?

Did any community-connectivity proposal prove financially and technically sustainable?

Did property taxes acquire an unplanned digital liability?

The answer to the last question should be:

No.

31.155What Success Looks Like

Success is not:

Success is a resident being able to say:

I know where to find the answer.

I can reach it.

I know who published it.

I can ask a person if I am confused.

I am not forced to give away unnecessary information to obtain it.

That is safe information.

31.156What This Is Not

The Safe Information Program is not:

It is access infrastructure with boundaries.

The Safe Information Commitment

Modern government increasingly depends upon information.

That creates a new responsibility.

Residents should not become more dependent, more exposed and more confused simply because government became more digital.

The commitment is:

Treat reliable public information as infrastructure.

Maintain one authoritative source and distribute it through many channels.

Date time-sensitive information.

Archive outdated information clearly.

Correct material mistakes openly.

Say "we do not know" when facts are not yet known.

Source important public numbers.

Write in plain language.

Make information accessible.

Keep telephone, print and in-person paths alive.

Never require an app simply to obtain essential public information.

Provide free public Wi-Fi where evidence shows it creates useful access.

Keep public Wi-Fi separate from internal City systems.

Do not require marketing information simply to connect.

Do not sell or commercially exploit browsing behaviour.

Collect the minimum network data required to operate securely.

Do not turn Wi-Fi into a resident movement-tracking system.

Help residents find existing home-connectivity programs before inventing another subsidy.

Study community-owned connectivity only where a real market gap exists.

Require a complete business case before the City builds digital utility infrastructure.

Do not create an unplanned property-tax liability.

Recover and reuse suitable phones before purchasing new ones where practical.

Securely wipe donated devices.

Protect both donor and recipient privacy.

Never promise emergency calling capability unless it has been verified for the actual device and network.

Teach residents how to protect photographs, records, accounts and family history.

Teach source checking, scam awareness and responsible AI use.

Make the community calendar free to list and free to browse under neutral rules.

Do not use municipal information systems for advertising profiles.

Do not use resident information for political targeting.

Collect only the personal information government actually needs.

Know why data is collected, who can see it, how long it stays and how it is deleted.

Complete privacy and cybersecurity review before significant new systems launch.

Maintain offline continuity for essential services.

Know how to leave every major vendor.

Use portable information standards wherever practical.

Teach residents to control their own data before asking them to entrust more of it to government.

Safe information is not information controlled by government.

It is information delivered by government in a way that earns confidence.

Easy to find. Clear about its source. Current enough to use. Available without surrendering unnecessary privacy. Resilient when technology fails. Human when people need help.

← Chapter 30: Civic CorpsChapter 32: Canadian Digital Sovereignty →