IT for municipalities and regional districts.
Valley Edge is based in Port Alberni. A local government the size of a mid-Island town runs more distinct systems than a business with ten times its revenue, under rules a business does not have. The records are statutory, the purchasing is public, and the meeting is on the record.
Municipalities, regional districts, and the boards and commissions attached to them.
- Records that survive an FOI request
- Bought the way you are required to buy
- Every account in the local government's name
- No claimed public-sector references
Same size as a mid-market business. Nothing else the same.
Three constraints separate a local government from a company with the same number of desks. None of them is a technology problem on the day it arrives, and all three are decided years earlier by an IT choice nobody flagged as one.
The records are statutory
A business decides how long to keep an email. A local government does not. Records are held to a retention schedule, and under FOIPPA a request arrives with a 30-day limit to respond, counted in working days, with extensions available only in the cases the Act allows. Whether that deadline is survivable is settled long before the request lands. It is settled by whether records are where the schedule says they are, whether anyone can search across mail and file shares in one pass, and whether the last three systems the organisation retired left their contents somewhere findable.
Retention is an IT decision made early.
The purchasing is public
Above the thresholds in the trade agreements BC local governments are bound by, an IT purchase is an open competition, posted publicly, and auditable afterwards by anyone who asks. Below them the organisation's own purchasing policy still applies, and a purchase that was easy is not the same thing as a purchase that was defensible. A vendor who treats that process as friction to be routed around is a vendor who will eventually cost you a complaint, and the complaint lands on staff rather than on the vendor.
Defensible beats convenient.
The meeting is on the record
Council and board meetings are open under the Community Charter and the Local Government Act, closed portions are the exception and have to be justified, and electronic participation is permitted where the procedure bylaw provides for it and the public can still hear, or watch and hear, what happens. That turns a room's microphones, its network path and its recording into part of a statutory obligation. When the stream drops halfway through a public hearing, the problem is not that the audio-visual kit failed. It is that a meeting may now be open to challenge.
The chamber is part of the bylaw.
It is never one network. It is six, across four buildings.
City hall, the public works yard, the arena or the pool, the fire hall, sometimes a water plant or a landfill, and a library that may or may not be yours to support. Different buildings, different links, different hours, different people, and one small IT budget stretched across all of it.
Finance, tax and utilities
The financial system, property tax, utility billing, cash receipting at the front counter, and the card processing behind it. This is the only system on the page whose outage has a public queue standing in front of it, and the only one carrying obligations that come from the payment card industry rather than from any statute. Its upgrade windows are set by the vendor and by the tax cycle, never by when IT happens to be free, which is why finance system work has to be in the calendar a year out rather than fitted around everything else.
Planning, permits and bylaw
Permit intake, inspections, bylaw enforcement files, and the applicant-facing side that increasingly runs online. Mostly a document problem wearing an application's clothes: the drawings, the correspondence and the decision all have to be findable years later by somebody who was not there and who is answering a lawyer.
Public works and the yard
Work orders, fleet, asset management, and the operational systems attached to water and wastewater. Those last ones deserve a separate conversation and a separate answer, because they are not office IT, they do not patch on an office schedule, and running them as though they were is how a utility ends up exposed.
Recreation, facilities and the library
Bookings, memberships, point of sale at the desk, public wifi, and the public access computers. The public-facing network belongs nowhere near the corporate one, and in a great many small local governments it is one flat network that nobody has revisited since the building opened.
Fire, emergency and after hours
Paging, the emergency operations centre, the call-out list, and the plain question of what still works when the power is out, the office is closed and the highway is shut. This is the one part of a local government where an IT failure is not an inconvenience, and it is the part most often left out of a managed agreement because it sits outside the office.
Records, FOI and the clerk's office
The corporate records system, the retention schedule, the agenda and minutes pipeline, and the search that has to work on the day a request arrives. This is the department that finds out first whether the rest of the estate was set up properly, and it finds out with a clock running.
The rule changed in 2021. It did not go away.
This is the question every BC local government is being asked right now, usually by a vendor with a Copilot licence to sell, and it is routinely reported as a relaxation. It is not one. The obligation moved rather than lifted.
Municipalities and regional districts are local public bodies under British Columbia's Freedom of Information and Protection of Privacy Act. Until late 2021 the Act carried a hard data-residency rule: personal information in a public body's custody or under its control had to be stored in Canada and accessed only from Canada, with narrow exceptions. That is the rule most people still have in mind when they say FOIPPA will not let them, and it is the rule that made a straightforward move to a cloud platform difficult for the better part of a decade.
Bill 22 came into force on 25 November 2021 and repealed those provisions. Disclosure of personal information outside Canada is now handled through the Act's ordinary disclosure rules rather than through a blanket prohibition. What replaced the prohibition is an assessment obligation. A privacy impact assessment is required for initiatives that touch personal information, and where sensitive personal information will be stored outside Canada a supplementary assessment forms part of it. The outcome is a documented, risk-based decision taken by the head of the public body.
The practical shift is worth stating plainly. The old rule was a line: inside Canada, or not at all, and the answer was the same for every system. The new rule is a file: you may do it, and you must be able to show afterwards why you decided it was acceptable, for this system, with this data, at this time. For an IT provider that means the deployment and the paperwork are one job rather than two. Configuring a tenant and leaving the assessment to somebody else produces a system in production and a decision nobody made, which is the worst of the available outcomes and the most common.
Two different things also get collapsed into one word here, and the distinction decides the answer. Residency is where the bytes are, and the major platforms operate Canadian regions and publish which of their services keep data inside them. Sovereignty is whose law can compel access, and a Canadian data centre operated by a company headquartered in the United States does not settle that half, because US law reaches data under a US provider's control regardless of where it sits. Both statements are true at once. Neither is a reason to refuse the platform, and neither is a reason to skip the assessment. A vendor who only tells you the first half is not lying to you, but they are answering a smaller question than the one you asked.
Microsoft 365 Copilot is where all of this lands in practice, because it is switched on per licence and it reads whatever the person prompting it can already reach. That last part is the real exposure and it is not a privacy-law problem, it is a permissions problem. An assistant that can search everything a user can search will surface the HR folder somebody shared with the whole organisation in 2019, and it will do it in front of whoever asked. The order of work is therefore permissions first, assessment second, licences third. Done in the other order it produces the incident that ends up in the local paper, and the assessment gets written afterwards to explain it.
Underneath all of it is ordinary managed IT: monitored and patched machines, Microsoft 365 administration, endpoint protection, backup with a restore somebody has actually run, and a network that reaches every site. That is the same work described on the managed IT page. What is different here is not the technology. It is that every one of those decisions has to be written down in a form that survives an audit, a change of council, and a request from a member of the public.
Buy it the way you are required to buy it. We will not ask you not to.
Small vendors lose public work by treating procurement as an obstacle, and staff pay for it afterwards. These are the commitments that go in writing, and none of them costs anything to make.
- Quoted in writing, with scope, exclusions and term stated on the page
- Priced in the same units as the other quotes, so a comparison is possible
- No bundle assembled to make a like-for-like comparison impossible
- No pressure to treat it as a sole source when it plainly is not one
- Posted openly, which for BC local government means BC Bid, and covered notices carry through to CanadaBuys
- Questions answered in the open, to every bidder, not privately to us
- A response written to your format rather than replacing it with ours
- No certification, clearance, reference or experience claimed that cannot be checked
- Which systems are covered, and what is quoted separately
- Who owns the tenant, the domain and the data, which is always the local government
- What happens at the end of the term, including who performs the export
- The record of what was changed and when, held by you rather than only by us
Councils change. The estate does not.
A general local election every four years resets the council or the board, and with it the appetite for a capital request that has already been deferred twice. The systems do not reset, and neither does the year the switches stop being supported. The way to survive that is unglamorous: a written inventory of what exists and what it costs to keep, a replacement schedule with dates in it rather than intentions, and a one-page answer to what stops if a given system stops. A new council can read those three documents in an evening. It cannot read an IT department's institutional memory, and in a small local government that memory is usually one retirement away from gone.
Whoever provides the service.
Three things a local government should be able to produce on request, no matter who runs its IT. If any of them takes a phone call to a vendor to answer, that is not an inconvenience. That is the finding.
- The tenant and the domain Registered to the local government, with your own staff holding the top administrator accounts.
- The retention record What is kept, where it lives, for how long, and who can search it on the day a request arrives.
- The exit A written process for taking everything back, rehearsed at least once, not drafted at the end.
Before anything is procured
The six questions staff ask first, answered the same way here as in a meeting.
Does FOIPPA still stop us using cloud services?
No, and it has not since late 2021. The Act used to carry a hard rule that personal information in a public body's custody or control had to be stored in and accessed only from Canada. Bill 22 repealed that. What replaced it is not permission, it is an assessment obligation: disclosure outside Canada runs through the Act's general disclosure rules, a privacy impact assessment is required, and where sensitive personal information will be stored outside Canada a supplementary assessment goes into it. The outcome is a documented risk-based decision by the head of the public body. The old rule was a line. The new rule is a file.
Who is responsible for the privacy impact assessment?
The public body. That responsibility does not transfer to a vendor and no vendor should tell you it does. What a provider contributes is the technical detail the assessment needs and cannot invent: which service holds which data, where each one stores it, who can reach it, what is logged, how long it is kept, and how access ends. The decision and the signature stay with the head of the public body, which is exactly where the Act puts them.
Can you help with an FOI request?
With the search and the extraction, yes. Finding every record matching a request across mail, file shares, a records system and whatever else the request touches is a technical job, and it is the part that runs out of clock. What is released and what is severed is not a vendor decision. That belongs to the head of the public body and to whoever they have delegated it to, and it stays there.
Our council meetings are streamed and it keeps failing. Is that IT?
Yes, and it is worth treating as a statutory system rather than as audio-visual kit. Open meeting requirements sit in the Community Charter and the Local Government Act, and where a procedure bylaw allows electronic participation the public still has to be able to hear, or watch and hear, the proceedings. That makes the microphones, the encoder, the network path and the recording a compliance dependency rather than a convenience. The fix is usually boring: one documented signal path, a tested fallback, and somebody who knows what to do in the first two minutes.
We already have internal IT. What would you actually do?
Work to it rather than around it. The common shape is that internal staff hold the counter and the departments, and an outside provider covers what is unreasonable to carry in a small team: after-hours cover, a second pair of hands during a project, the systems nobody has had time to learn properly, and a straight second opinion on a vendor proposal. What that split is gets written into the agreement, so it is not being rediscovered during an incident at eleven at night.
Do you work with regional districts as well as municipalities?
Yes, and the difference is real rather than cosmetic. A regional district is a federation. It delivers different services to different electoral areas and member municipalities, its budget is assembled from separate service areas rather than one levy, and its board is made of representatives who each answer somewhere else. In the Alberni-Clayoquot Regional District, four treaty First Nations sit on the board as full voting members alongside the three member municipalities. A composition like that changes how a shared system has to handle access and records, and it is a design question rather than an administrative detail.
Tell us what the estate actually looks like.
Which systems, which buildings, and which of them nobody wants to touch. We will tell you what shape it is in and what it would take to fix, in writing, before anyone talks about a term.
info@valleyedgeconsulting.io · 778-488-8618