Index All entries in the index reference page numbers.

Size: px
Start display at page:

Download "Index All entries in the index reference page numbers."

Transcription

1 Index All entries in the index reference page numbers. A Audit of organizations, 37-38, Access to personal information by individual, 22, 31, B assistance by organization, Biometrics, palm-vein scanning of test- exceptions, 31 takers, Model Code, principles, 180- privacy implications, refusal to provide with reasonable purpose, 124 reasons, 153 voiceprint is personal third party personal information, 123 information, 154 Federal Court appeal held time limit to respond, 153 employee consent required, 124 written request, 152 reasonable purpose, 124 Accountability, 22, Business continuity, see Accuracy, 22, 30, Disaster recovery Anti-spam legislation, see FISA (Fighting Internet and C Wireless Spam Act) CASL, see FISA Applications service provider Canada Evidence Act (ASP) arrangements, 121- certificate, Canada s Anti-Spam Law Asset purchases, see Mergers, (CASL), see FISA (Fighting acquisitions and asset Internet and Wireless Spam purchases Act) 217

2 PIPEDA Quick Reference 2015 Edition Checklists outsourcing, see Outsourcing health care institution privacy purpose of collection program implementation, 86- identified and reasonable, 21, 90 24, 27, 146, outsourcing or transferring ten privacy principles under personal information across Sch. 1 of PIPEDA for, 22-23, borders, PIPEDA compliance for third-party, 26-27, 29, educational institutions, 102- consents needed, due diligence re consents CIBC decision, and contracts, 65 Collection, use, and disclosure without knowledge or consent, of personal information consent, see Consent Commercial activities definition of personal defined, 16-17, 144 information, 145 outsourcing and, disclosure by Privacy Complaints process, 34-43, Commissioner, , 187 to investigative bodies, challenge to compliance, 23, regulation , grandfathering of, court hearing, limitation of, 22, 29 dispute resolution excessive collection, mechanisms, 35-36, 156, 159 Model Code, principles, hearing in Federal Court, see Federal Court reasonable purpose, 24, 27- information to include in, investigation of complaints sensitive information, discontinuance of, 160 use, disclosure and investigator assigned, 35, retention, 22, mergers, acquisitions and notification of complainant, asset purchases, see Mergers, 157 acquisitions and asset powers of Commissioner, purchases

3 Index Complaints process (cont d) publicly available lodge complaint with Federal information, regulation Privacy Commissioner, , letter of findings, 35 response to subpoena, no direct power of warrant, order of court, 149 enforcement, 35 statistical, or scholarly study report with or research, 151 recommendations, 35, 161 exceptions to, 27, within one year, 37 express, Compliance team, implied, privacy officer, 31 methods of giving, Consent opt-out consent, 25, 27 collection without knowledge principle, Model Code, 182- or consent, collection reasonable to third-party use, 26 investigate breach, 148 use without knowledge or disclosure of purposes consent, required by law, 149, 181- emergency threatening life, 182 health, security, 149 interests of individual, 148 investigation of publicly available contravention of laws of information, 148 Canada, 149 solely for journalistic, publicly available artistic or literary purposes, information, statistical, or scholarly study disclosure without knowledge or research, 149 or consent, Cookies case, see under debt collection by Information technology organization, 149 emergency threatening life, D health, security, 150 Damages government request, 150 humiliation, indictable offences, 43, 71 Data breach,

4 PIPEDA Quick Reference 2015 Edition Data mining, signed consent, 98 point-of-sale data includes without consent, 97 personal information, 117 commercial activities, 94-96, Deep packet inspection (DPI), employee information, 100- access personal information 101 sent over Internet, 118 fundraising, Bell advised to disclose to affinity marketing programs, customers the use of DPI, Disaster recovery, commercial activity or not, Disclosure of information, see Collection, use, and disclosure student records, of personal information access to, private schools, E commercial activities, 101, ebay s detailed privacy policy, correction of records, Education sector, private schools, applicability of PIPEDA, 91- tri-council policy statement 94 protocols, universities and private for- Electronic documents profit educational copies, 177 institutions, 94 defined, 172 archives held by educational institutions, 99 evidence or proof, as, 174 checklist, PIPEDA compliance payments, 173 for educational institutions, regulations Canada Labour Code, collection of personal , information for statistical, Federal Real Property and scholarly or research Federal Immovables Act, purposes, , anonymity on collection, 98 Investigative Bodies, implied consent, 97 6,

5 Index Electronic documents (cont d) PIPEDA application, federal Publicly Available works, undertakings or Information, , 210- businesses, 131, retention, F seals, 175 Facebook privacy signatures, secure, 176, 177, investigation, Federal Court statements under oath, 176- hearing on complaint, order compliance, statutory forms and filing, remedies, 162 addresses, personal order damages, 40-42, see information also Damages monitoring by request for hearing to, 40, 42 employer, 134 FISA (Fighting Internet and Employment relationship, 32- Wireless Spam Act), , G labour arbitrator s jurisdiction, 140 Genetic testing, see Healthcare medical information sector collection, Global positioning systems disclosure permitted for (GPS) installation by appeal process, 139 employer, privacy policy needed, 139 Google Buzz privacy violation, reasonable purpose required, Google s Street View security checks, application, employee consent required, 138 Google Wi-Fi privacy concerns, 119 surveillance, , 136, see also Surveillance of Grandfathering of employees information,

6 PIPEDA Quick Reference 2015 Edition H tri-council policy, Health records, see topics personal health information under Healthcare sector defined, 71-72, 145 Health research, see Healthcare employer collected, sector physicians prescribing Healthcare sector, patterns, sale of information, checklist, privacy program implementation, provincial health information privacy statutes, collection, use, and disclosure of personal health statutory reporting obligations, information, consent, 77 when does PIPEDA apply, exceptions, emergency threatening I patient s life, safety, or security, 78 Imaging technology, patient s interest, 78 Google s Street View required by law, 78 application, fax machines and Internet Individual access, concerns, Information technology commercial activities, biometrics, see Biometrics preponderant purpose test, compliance tips, consent obtained custodians in Ontario, electronically, regulation, , 198 disclosure for subpoena, opt-out form, 109 warrant or court order in civil privacy statement, litigation, 82 cookies, information stored is fundraising activities, 75 personal, 111 genetic testing, cookies, advertising, 107 health research, Cookies case, consent exception, 80 Commissioner s finding of research ethics board breach, 106 (REB), cookies, defined,

7 Index Information technology (cont d) examples of breach of privacy concern, 106 PIPEDA, data mining, see Data mining radio frequency identification deep packet inspection, see device, see Radio frequency Deep packet inspection (DPI) identification device (RFID) disclosure of on-line social networking, see Social information to police during networking sites an investigation, International transfer of imaging technology, see personal information, see Imaging technology under Outsourcing Internet-based marketing, see Internet-based marketing, Internet-based marketing live video streaming, see Live cookies, information stored is video streaming personal, 111 need for compliance, addresses, personal damage to reputation when information, information use practices spyware, likely breach of disclosed, 110 PIPEDA, Federal Court damage order, Investigation of complaint, see 109 Complaints process Google privacy deficiencies and third-party audit, 109- L 110 Live video streaming, PIPEDA non-compliance privacy policy and passwords may affect ability to protection, contract, 110 webcam service at daycare, outsourcing, see Outsourcing 125 payload data collection, see Payload data collection M PIPEDA compliance tips, Mergers, acquisitions and asset purchases, 65-68, see audit, designate privacy also Outsourcing officer, privacy policy, customers and patients consents, 127 consent,

8 PIPEDA Quick Reference 2015 Edition Mergers, acquisitions and asset comparable level of purchases (cont d) protection, 52 employee information to joint no disclosure, therefore no venture partner, consent needed, employee information to guarantees required by potential purchaser, 67 transferring organization from issues to explore by potential agent, 55 purchase re personal information technology information, services, privacy policy inclusion, 66- applications service provider 67 (ASP) arrangements, 121- sale of customer list, share purchase transaction, 68 disaster recovery, business continuity, 122 O transfer of personal Openness principle, information to third party, Outsourcing, transfer vs disclosure, checklist, CIBC decision by Privacy transfer privacy Commissioner, requirements from affirmed in SWIFT outsourcer, decision, 58 transmission of personal CIBC customer concerns re information to third party, U.S. service provider, CIBC transparent about international transfer of policies on outsourcing, 58 personal information, comparable level of Accusearch case, protection found, 57 disclosure of personal customer consent not information without required, consent, 60 Office of the Superintendent PIPEDA breached, of Financial Institutions Privacy Commissioner (OFSI) approval, and U.S. Federal Trade commercial activities, Commission,

9 Index Outsourcing (cont d) data breach, see Data breach affiliated corporations, 62- defined, 19-21, exclusions, advance notice to customers, identifiable individual, 19, 72 comparable level of data outsourcing, see Outsourcing protection, 63 publicly available, regulation, checklist, , comparable level of reasonable expectation of protection, 59 privacy, see Reasonable expectation of privacy KLM case, safeguards (security), 23, 30- failure to provide 31, applicant access to information, 61 Personal Information transparency re outsourcing, Protection and Electronic 59 Documents Act (PIPEDA) notification of outsourcing activities covered by Act, 16- required, 62 17, 32, privacy policy transparent, 58, collected in course of 59 commercial activities, 16-17, 146 P digital signatures, 17 Payload data collection, 119 federal works, undertakings Google Wi-Fi privacy or businesses, 132, 146 concerns, 119 activities not covered by Act, 18-19, 144 Penalties, see Damages employment related Personal information information collected by access by individual to, 22, 31 private sector employers, 16 accuracy, 22 personal information held collection, use, and disclosure, by government covered by see Collection, use, and Privacy Act, 19 disclosure of personal application, 15-16, 129, 146 information education sector, see compliance team, Education sector 225

10 PIPEDA Quick Reference 2015 Edition Personal Information electronic documents, see Protection and Electronic Electronic documents Documents Act grandfathering clause, none, (PIPEDA) (cont d) employment relationship, Model Code for Protection of see Employment Personal Information relationship (Schedule 1), healthcare sector, see origins of the Act, 9-15 Healthcare sector Bill C-12 proposed changes, information and technology intensive businesses, see digitization of information, Information technology 8-9 definitions, European Union privacy alternative format, 144 directives, 9-10 commercial activity, 144 in force January 2001, 2 commissioner, 144 Internet implications, 8-9 Court, 144 OECD principles re privacy data, 172 protection, 9 electronic document, 172 recommended changes to the Act, electronic signature, 172 personal information, defined, federal law, , 145 federal work, undertaking privacy or business, defined, 7 filing, 174 principles, ten, 22-23, 180- organization, personal health provincial privacy legislation information, 145 and, personal information, 145 purpose of Act, record, 145 regulations, see Electronic responsible authority, documents review of Act every five secure electronic years, 10-12, 171 signature, 172 should,

11 Index Privacy Privacy Commissioner s defined, 7 agreement with provinces, policy sample, Quebec, 14 principles, ten, 22-23, relationship to PIPEDA, challenging compliance to, 23 substantially similar to federal, 14-15, Privacy Commissioner, see also Complaints process R agreements with provinces, Radio frequency identification device (RFID), 117 annual report, 169 Ontario Privacy audit of organizations, Commissioner s guidelines, Commissioner, defined, disclosure of information to personal information may be foreign state, associated with, 117 investigative powers, Privacy Commissioner is studying use in Canada, 117 mediation, 35, 159 no power of enforcement, 35 Reasonable expectation of privacy, 21, protection of, role of, Regulations Governor in Council, made solicitor-client privilege, 35- by, , Privacy policy, S officer, 23, 31 Safeguards (security) of openness of, 23, 30-31, 118, personal information, 23, , sample of, Sample privacy policy, Provincial private sector Security checks, privacy legislation, Social networking sites, 112- Alberta, British Columbia, 14 Facebook privacy Ontario, 14 investigations,

12 PIPEDA Quick Reference 2015 Edition Social networking sites (cont d) Google Buzz privacy violation, 116 Solicitor-client privilege, Spam, see FISA (Fighting Internet and Wireless Spam Act) Spyware, likely breach of PIPEDA, Substantially similar federal for violation of employment contract, 137 video recording of picket line crossing, Third party data collection, United States privacy requirement, legislation, 13 Surveillance of employees, USA Patriot Act, 55, Use of personal information, monitoring, 134 see Collection, use, and global positioning systems disclosure of personal (GPS) installation, information appropriate purpose, 135 V implied consent, 133, 135 justification for surveillance Video surveillance, 54, 128, must be reasonable, Canadian Pacific Railway W video camera case, signs must be posted to Whistle-blowing, 170 alert employees of video protection of, 170 cameras, 133 surreptitious, 136 guidelines issued for covert and non-covert video surveillance, 137 T U 228

Privacy Law in Canada

Privacy Law in Canada Privacy Law in Canada Federal and provincial privacy legislation has a profound impact on the way virtually all organizations carry on business across the country. Canada s privacy laws, while likely the

More information

Privacy Law in Canada

Privacy Law in Canada by PATRICIA WILSON & MICHAEL FEKETE Protection of personal information remains at the forefront of public policy debate in. Federal and provincial privacy legislation has a profound impact on the way virtually

More information

Doing Business. A Practical Guide. casselsbrock.com. Canada. Dispute Resolution. Foreign Investment. Aboriginal. Securities and Corporate Finance

Doing Business. A Practical Guide. casselsbrock.com. Canada. Dispute Resolution. Foreign Investment. Aboriginal. Securities and Corporate Finance About Canada Dispute Resolution Forms of Business Organization Aboriginal Law Competition Law Real Estate Securities and Corporate Finance Foreign Investment Public- Private Partnerships Restructuring

More information

Data Management: Considerations for Integrating Compliance Requirements At Home and Abroad. Toronto, Ontario June 14, 2005

Data Management: Considerations for Integrating Compliance Requirements At Home and Abroad. Toronto, Ontario June 14, 2005 Data Management: Considerations for Integrating Compliance Requirements At Home and Abroad Toronto, Ontario June 14, 2005 Outsourcing Update: New Contractual Options and Risks Lisa K. Abe June 14, 2005

More information

Boys and Girls Clubs of Kawartha Lakes B: Administration B4: Information Management & Policy: Privacy & Consent Technology

Boys and Girls Clubs of Kawartha Lakes B: Administration B4: Information Management & Policy: Privacy & Consent Technology Effective: Feb 18, 2015 Executive Director Replaces: 2010 Policy Page 1 of 5 REFERENCE: HIGH FIVE 1.4.3, 2.2.4, 2.5.3, PIDEDA POLICY: Our Commitment Boys and Girls Clubs of Kawartha Lakes (BGCKL) and the

More information

CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:

CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES: CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES: Privacy Responsibilities and Considerations Cloud computing is the delivery of computing services over the Internet, and it offers many potential

More information

PERSONAL INFORMATION PROTECTION ACT

PERSONAL INFORMATION PROTECTION ACT Province of Alberta Statutes of Alberta, Current as of December 17, 2014 Office Consolidation Published by Alberta Queen s Printer Alberta Queen s Printer 7 th Floor, Park Plaza 10611-98 Avenue Edmonton,

More information

PIPEDA and Online Backup White Paper

PIPEDA and Online Backup White Paper PIPEDA and Online Backup White Paper The cloud computing era has seen a phenomenal growth of the data backup service industry. Backup service providers, by nature of their business, are compelled to collect

More information

Is There Such a Thing as Internet Privacy?

Is There Such a Thing as Internet Privacy? Is There Such a Thing as Internet Privacy? April 13, 2015 Danielle Graff & Kristél Kriel Western Canada s Law Firm Click Agenda to edit Master title style What is Internet Privacy? Why does it matter?

More information

Cloud Computing: Trust But Verify

Cloud Computing: Trust But Verify Cloud Computing: Trust But Verify 14th Annual Privacy and Security Conference February 8, 2013, Victoria Martin P.J. Kratz, QC Bennett Jones LLP Cloud Computing Provision of services available on the Internet

More information

INFORMATION SECURITY GUIDE. Cloud Computing Outsourcing. Information Security Unit. Information Technology Services (ITS) July 2013

INFORMATION SECURITY GUIDE. Cloud Computing Outsourcing. Information Security Unit. Information Technology Services (ITS) July 2013 INFORMATION SECURITY GUIDE Cloud Computing Outsourcing Information Security Unit Information Technology Services (ITS) July 2013 CONTENTS 1. Background...2 2. Legislative and Policy Requirements...3 3.

More information

AN INTRO TO. Privacy Laws. An introductory guide to Canadian Privacy Laws and how to be in compliance. Laura Brown

AN INTRO TO. Privacy Laws. An introductory guide to Canadian Privacy Laws and how to be in compliance. Laura Brown AN INTRO TO Privacy Laws An introductory guide to Canadian Privacy Laws and how to be in compliance Laura Brown Air Interactive Media Senior DMS Advisor A Publication of 1 TABLE OF CONTENTS Introduction

More information

Credit Union Code for the Protection of Personal Information

Credit Union Code for the Protection of Personal Information Introduction Canada is part of a global economy based on the creation, processing, and exchange of information. The technology underlying the information economy provides a number of benefits that improve

More information

Taking care of what s important to you

Taking care of what s important to you A v i v a C a n a d a I n c. P r i v a c y P o l i c y Taking care of what s important to you Table of Contents Introduction Privacy in Canada Definition of Personal Information Privacy Policy: the ten

More information

Personal Information Protection Act. Information Sheet 5: 1. Personal Employee Information

Personal Information Protection Act. Information Sheet 5: 1. Personal Employee Information Personal Information Protection Act Information Sheet 5 Introduction The Personal Information Protection Act (PIPA) governs the collection, use, disclosure, retention and protection of personal information

More information

Law Firm Compliance: Key Privacy Considerations for Lawyers and Law Firms in Ontario

Law Firm Compliance: Key Privacy Considerations for Lawyers and Law Firms in Ontario PRIVACY COMPLIANCE ISSUES FOR LAW FIRMS IN ONTARIO By Sara A. Levine 1 Presented at Law Firm Compliance: Key Privacy Considerations for Lawyers and Law Firms in Ontario Ontario Bar Association, May 6,

More information

Credit Union Board of Directors Introduction, Resolution and Code for the Protection of Personal Information

Credit Union Board of Directors Introduction, Resolution and Code for the Protection of Personal Information Credit Union Board of Directors Introduction, Resolution and Code for the Protection of Personal Information INTRODUCTION Privacy legislation establishes legal privacy rights for individuals and sets enforceable

More information

The Manitoba Child Care Association PRIVACY POLICY

The Manitoba Child Care Association PRIVACY POLICY The Manitoba Child Care Association PRIVACY POLICY BACKGROUND The Manitoba Child Care Association is committed to comply with the legal obligations imposed by the federal government's Personal Information

More information

SPECIAL ISSUES IN CANADIAN IT OUTSOURCING BY C. IAN KYER AND JOHN BEARDWOOD

SPECIAL ISSUES IN CANADIAN IT OUTSOURCING BY C. IAN KYER AND JOHN BEARDWOOD SPECIAL ISSUES IN CANADIAN IT OUTSOURCING BY C. IAN KYER AND JOHN BEARDWOOD INTRODUCTION For an American service provider, doing an outsourcing in Canada is like a fan of the National League Chicago Cubs

More information

The Use of Cloud Computing for the Storing and Accessing of Client Information: Some Practical and Ethical Considerations

The Use of Cloud Computing for the Storing and Accessing of Client Information: Some Practical and Ethical Considerations The Use of Cloud Computing for the Storing and Accessing of Client Information: Some Practical and Ethical Considerations Jeffrey D. Scott Jeffrey D. Scott, Legal Professional Corporation Practice Advisors

More information

Cloud Computing: Privacy & Jurisdiction from a Canadian Perspective

Cloud Computing: Privacy & Jurisdiction from a Canadian Perspective Cloud Computing: Privacy & Jurisdiction from a Canadian Perspective Professor Michael Geist Canada Research Chair in Internet and E-commerce Law University of Ottawa, Faculty of Law Cloud Computing - Canada

More information

Cloud Computing Contracts. October 11, 2012

Cloud Computing Contracts. October 11, 2012 Cloud Computing Contracts October 11, 2012 Lorene Novakowski Karam Bayrakal Covering Cloud Computing Cloud Computing Defined Models Manage Cloud Computing Risk Mitigation Strategy Privacy Contracts Best

More information

COUNCIL OF THE EUROPEAN UNION. Brussels, 22 November 2006 15644/06 DATAPROTECT 45 EDPS 3

COUNCIL OF THE EUROPEAN UNION. Brussels, 22 November 2006 15644/06 DATAPROTECT 45 EDPS 3 COUNCIL OF THE EUROPEAN UNION Brussels, 22 November 2006 15644/06 DATAPROTECT 45 EDPS 3 COVER NOTE from: Secretary-General of the European Commission, signed by Mr Jordi AYET PUIGARNAU, Director date of

More information

Central LHIN Governance Manual. Title: Whistleblower Policy Policy Number: GP-003

Central LHIN Governance Manual. Title: Whistleblower Policy Policy Number: GP-003 Central LHIN Governance Manual Title: Whistleblower Policy Policy Number: GP-003 Purpose: Originated: September 25, 2012 Board Approved: September 25, 2012 To set out the LHIN s obligations under the Public

More information

Canada s New Anti-Spam Legislation: Overview and Implications for Businesses

Canada s New Anti-Spam Legislation: Overview and Implications for Businesses dentons.com Focus on Communications Canada s New Anti-Spam Legislation: Overview and Implications for Businesses January, 2011 Contact Margot Patterson Dentons Canada LLP Counsel, Ottawa margot.patterson@dentons.com

More information

Cloud Computing: Privacy and Other Risks

Cloud Computing: Privacy and Other Risks December 2013 Cloud Computing: Privacy and Other Risks by George Waggott, Michael Reid and Mitch Koczerginski, McMillan LLP Introduction While the benefits of outsourcing organizational data storage to

More information

E-COMMERCE GOES MOBILE: SEEKING COMPETITIVENESS THROUGH PRIVACY

E-COMMERCE GOES MOBILE: SEEKING COMPETITIVENESS THROUGH PRIVACY E-COMMERCE GOES MOBILE: SEEKING COMPETITIVENESS THROUGH PRIVACY Oana Dolea 7 th Annual Leg@l.IT Conference March 26th, 2013 Montreal, Canada INTRODUCTION Mobile e-commerce vs. E-commerce Mobile e-commerce:

More information

Cloud Computing: Legal Risks and Best Practices

Cloud Computing: Legal Risks and Best Practices Cloud Computing: Legal Risks and Best Practices A Bennett Jones Presentation Toronto, Ontario Lisa Abe-Oldenburg, Partner Bennett Jones LLP November 7, 2012 Introduction Security and Data Privacy Recent

More information

PROTECTION OF PERSONAL INFORMATION

PROTECTION OF PERSONAL INFORMATION PROTECTION OF PERSONAL INFORMATION Definitions Privacy Officer - The person within the Goderich Community Credit Union Limited (GCCU) who is responsible for ensuring compliance with privacy obligations,

More information

Insurance Journal. Defending Until the End When Does the Duty to. Volume 1, Issue 3 Editor Keoni Norgren. May 1, 2013

Insurance Journal. Defending Until the End When Does the Duty to. Volume 1, Issue 3 Editor Keoni Norgren. May 1, 2013 Insurance Journal May 1, 2013 In this Issue Volume 1, Issue 3 Editor Keoni Norgren Defending Until the End When Does the Duty to Defend End? Cyber Liability Laws in Canada Dolden Wallace Folick Welcomes

More information

3. Consent for the Collection, Use or Disclosure of Personal Information

3. Consent for the Collection, Use or Disclosure of Personal Information PRIVACY POLICY FOR RENNIE MARKETING SYSTEMS Our privacy policy includes provisions of the Personal Information Protection Act (BC) and the Personal Information Protection and Electronic Documents Act (Canada),

More information

Client Alert December 2011

Client Alert December 2011 Client Alert December 2011 In This Issue: Global Recruitment and Social Media Hiring Traps Global Trends The Americas Canada United States Latin America Europe France Germany United Kingdom Asia Pacific

More information

We ask that you contact our Privacy Officer in the event you have any questions or concerns regarding this Code or its implementation.

We ask that you contact our Privacy Officer in the event you have any questions or concerns regarding this Code or its implementation. PRIVACY AND ANTI-SPAM CODE FOR OUR DENTAL OFFICE Please refer to Appendix A for a glossary of defined terms. INTRODUCTION The Personal Health Information Act (PHIA) came into effect on December 11, 1997,

More information

Responsibilities of Custodians and Health Information Act Administration Checklist

Responsibilities of Custodians and Health Information Act Administration Checklist Responsibilities of Custodians and Administration Checklist APPENDIX 3 Responsibilities of Custodians in Administering the Each custodian under the Act must establish internal processes and procedures

More information

Managing Contracts under the FOIP Act. A Guide for Government of Alberta Contract Managers and FOIP Coordinators

Managing Contracts under the FOIP Act. A Guide for Government of Alberta Contract Managers and FOIP Coordinators Managing Contracts under the FOIP Act A Guide for Government of Alberta Contract Managers and FOIP Coordinators ISBN 978-0-7785-6102-6 Produced by Access and Privacy Service Alberta 3rd Floor, 10155 102

More information

ROHIT GROUP OF COMPANIES PRIVACY POLICY This privacy policy is subject to change without notice. It was last updated on July 23, 2014.

ROHIT GROUP OF COMPANIES PRIVACY POLICY This privacy policy is subject to change without notice. It was last updated on July 23, 2014. ROHIT GROUP OF COMPANIES PRIVACY POLICY This privacy policy is subject to change without notice. It was last updated on July 23, 2014. The Rohit Group of Companies ( Rohit Group, Company, our, we ) understands

More information

A Privacy Handbook for Lawyers PIPEDA AND YOUR PRACTICE

A Privacy Handbook for Lawyers PIPEDA AND YOUR PRACTICE A Privacy Handbook for Lawyers PIPEDA AND YOUR PRACTICE Table of Contents Introduction...1 Privacy Issues in Managing a Law Practice...6 Privacy issues in Civil Litigation...16 Conclusion...26 Endnotes...28

More information

Trends in and Tips for Market Conduct Exams. Agenda

Trends in and Tips for Market Conduct Exams. Agenda Trends in and Tips for Market Conduct Exams Elizabeth Tosaris Partner, San Francisco February 10, 2014 Agenda Introduction and Background Types of Exams Recent Trends Practical Advice 1 Who Has Jurisdiction?

More information

CLOUD COMPUTING & THE PATRIOT ACT: A RED HERRING?

CLOUD COMPUTING & THE PATRIOT ACT: A RED HERRING? CLOUD COMPUTING & THE PATRIOT ACT: A RED HERRING? Lindsey Finch Senior Global Privacy Counsel Salesforce.com lfinch@salesforce.com David T.S. Fraser Partner McInnes Cooper David.fraser@mcinnescooper.com

More information

Privacy Guidelines For Landlords and Tenants

Privacy Guidelines For Landlords and Tenants Privacy Guidelines For Landlords and Tenants Purpose of the Guidelines In British Columbia, landlords and property managers acting on their behalf must adhere to the privacy rules contained in the BC Personal

More information

Crawford Chondon &Partners LLP. Is your Business Ready for Canada s Anti Spam Law?

Crawford Chondon &Partners LLP. Is your Business Ready for Canada s Anti Spam Law? Crawford Chondon &Partners LLP Present Is your Business Ready for Canada s Anti Spam Law? By: Michael MacLellan Overview 1. What is Canada s Anti-Spam Legislation, and how will it apply? 2. What does CASL

More information

Taking care of what s important to you

Taking care of what s important to you National Home Warranty Group Inc. Privacy Policy Taking care of what s important to you Table of Contents Introduction Privacy in Canada Definition of Personal Information Privacy Policy: the ten principles

More information

Proudly Presents. Navigating the Cloud Across the US & Canada Border

Proudly Presents. Navigating the Cloud Across the US & Canada Border Proudly Presents Navigating the Cloud Across the US & Canada Border Presenters Rob Groves, B.A., M.B.A., Director, Finance and Business Services, Calgary Catholic School District Rob Groves is the Director,

More information

NORTHWESTEL CODE OF FAIR INFORMATION PRACTICES. Effective January 1, 2001

NORTHWESTEL CODE OF FAIR INFORMATION PRACTICES. Effective January 1, 2001 NORTHWESTEL CODE OF FAIR INFORMATION PRACTICES Effective January 1, 2001 The Northwestel Code of Fair Practices complies fully with the Personal Protection and Electronic Documents Act and incorporates

More information

Privacy and Security Resource Materials for Saskatchewan EMR Physicians: Guidelines, Samples and Templates. Reference Manual

Privacy and Security Resource Materials for Saskatchewan EMR Physicians: Guidelines, Samples and Templates. Reference Manual Privacy and Security Resource Materials for Saskatchewan EMR Physicians: Guidelines, Samples and Templates Guidelines on Requirements and Good Practices For Protecting Personal Health Information Disclaimer

More information

How To Protect Your Privacy Online From Your Company Or Affiliates

How To Protect Your Privacy Online From Your Company Or Affiliates Data Security and Privacy Proposed Threshold Questions and Initial Due Diligence Personal information means any information that can be used to identify a specific individual, for example, such individual

More information

Big Data, Law and Marketing. Roland Hung, Associate, McCarthy Tetrault LLP

Big Data, Law and Marketing. Roland Hung, Associate, McCarthy Tetrault LLP Big Data, Law and Marketing Roland Hung, Associate, McCarthy Tetrault LLP Overview What is Big Data? Overview of the privacy landscape in Canada Collecting information legally Accuracy, Protection and

More information

Online and Mobile Privacy Notice ( Privacy Notice )

Online and Mobile Privacy Notice ( Privacy Notice ) Online and Mobile Privacy Notice ( Privacy Notice ) Introduction This Privacy Notice applies to the operations of Cigna Global Health Benefits and its affiliated companies listed at the end of this Privacy

More information

STATUTORY INSTRUMENTS. S.I. No. 336 of 2011

STATUTORY INSTRUMENTS. S.I. No. 336 of 2011 STATUTORY INSTRUMENTS. S.I. No. 336 of 2011 EUROPEAN COMMUNITIES (ELECTRONIC COMMUNICATIONS NETWORKS AND SERVICES) (PRIVACY AND ELECTRONIC COMMUNICATIONS) REGULATIONS 2011 (Prn. A11/1165) 2 [336] S.I.

More information

THE PERSONAL INFORMATION PROTECTION AND ELECTRONIC DOCUMENTS ACT (PIPEDA) PERSONAL INFORMATION POLICY & PROCEDURE HANDBOOK

THE PERSONAL INFORMATION PROTECTION AND ELECTRONIC DOCUMENTS ACT (PIPEDA) PERSONAL INFORMATION POLICY & PROCEDURE HANDBOOK THE PERSONAL INFORMATION PROTECTION AND ELECTRONIC DOCUMENTS ACT (PIPEDA) PERSONAL INFORMATION POLICY & PROCEDURE HANDBOOK REVISED August 2004 PERSONAL INFORMATION POLICY & PROCEDURE HANDBOOK Introduction

More information

PRIVACY BREACH POLICY

PRIVACY BREACH POLICY Approved By Last Reviewed Responsible Role Responsible Department Executive Management Team March 20, 2014 (next review to be done within two years) Chief Privacy Officer Quality & Customer Service SECTION

More information

PRIVACY POLICY. Consent

PRIVACY POLICY. Consent PRIVACY POLICY car2go N.A. LLC and car2go Canada Ltd. (collectively, car2go ) recognize the importance of protecting your personal information. We take the protection of your personal information seriously

More information

Privacy Policy EMA Online

Privacy Policy EMA Online Privacy Policy EMA Online Thank you for visiting our Privacy Policy. We are committed to respecting the privacy rights of the users of www.emaonline.com ( Website ). We created this privacy policy (the

More information

PHIPA Potpourri. Judith Goldstein, Legal Counsel Information and Privacy Commissioner/Ontario. IPC Mediators April 21, 2015

PHIPA Potpourri. Judith Goldstein, Legal Counsel Information and Privacy Commissioner/Ontario. IPC Mediators April 21, 2015 PHIPA Potpourri Judith Goldstein, Legal Counsel Information and Privacy Commissioner/Ontario IPC Mediators April 21, 2015 Powers of the Commissioner The Powers the Commissioner has to conduct a review

More information

PRIVACY, ANTI-SPAM AND YOUR BUSINESS: WHERE DO WE STAND? Presented by: Cameron Mitchell B.A., LL.B.

PRIVACY, ANTI-SPAM AND YOUR BUSINESS: WHERE DO WE STAND? Presented by: Cameron Mitchell B.A., LL.B. PRIVACY, ANTI-SPAM AND YOUR BUSINESS: WHERE DO WE STAND? Presented by: Cameron Mitchell B.A., LL.B. Privacy The focus of my presentation will be on two thing that have made marketing and contacting clients

More information

CANADIAN PRIVACY AND DATA RESIDENCY REQUIREMENTS. White Paper

CANADIAN PRIVACY AND DATA RESIDENCY REQUIREMENTS. White Paper CANADIAN PRIVACY AND DATA RESIDENCY REQUIREMENTS White Paper Table of Contents Addressing compliance with privacy laws for cloud-based services through persistent encryption and key ownership... Section

More information

PHIA GENERAL INFORMATION

PHIA GENERAL INFORMATION To: From: Researchers Legal Services and Research Services Date: May 21, 2013 Subject: Research and the New Personal Health Information Act On June 1, 2013, the Personal Health Information Act ( PHIA )

More information

Online privacy and identity A regulatory body s perspective

Online privacy and identity A regulatory body s perspective Online privacy and identity A regulatory body s perspective April 21, 2008, Montreal, QC Internet Use and the Norm o $50 million in sales to Canadians o 10 million Canadians use social networking sites

More information

Questions and answers for custodians about the Personal Health Information Privacy and Access Act (PHIPAA)

Questions and answers for custodians about the Personal Health Information Privacy and Access Act (PHIPAA) Questions and answers for custodians about the Personal Health Information Privacy and Access Act (PHIPAA) This document provides answers to some frequently asked questions about the The Personal Health

More information

Privacy Statement. What Personal Information We Collect. Australia

Privacy Statement. What Personal Information We Collect. Australia Privacy Statement Kelly Services, Inc. and its subsidiaries ("Kelly Services" or Kelly ) respect your privacy and we acknowledge that you have certain rights related to any personal information we collect

More information

Your privacy is important to CPABC. This Privacy Policy explains how CPABC collects, uses, discloses and retains your information. Who is CPABC?

Your privacy is important to CPABC. This Privacy Policy explains how CPABC collects, uses, discloses and retains your information. Who is CPABC? CPABC Privacy Policy Your privacy is important to CPABC. This Privacy Policy explains how CPABC collects, uses, discloses and retains your information. Who is CPABC? The Chartered Professional Accountants

More information

LEEDS BECKETT UNIVERSITY. Information Security Policy. 1.0 Introduction

LEEDS BECKETT UNIVERSITY. Information Security Policy. 1.0 Introduction LEEDS BECKETT UNIVERSITY Information Security Policy 1.0 Introduction 1.1 Information in all of its forms is crucial to the effective functioning and good governance of our University. We are committed

More information

INDIVIDUAL CLIENT AGREEMENT AGILITY FOREX LTD INDIVIDUAL CLIENT AGREEMENT

INDIVIDUAL CLIENT AGREEMENT AGILITY FOREX LTD INDIVIDUAL CLIENT AGREEMENT INDIVIDUAL CLIENT AGREEMENT INDIVIDUAL CLIENT AGREEMENT The following terms and conditions apply to individuals who are transacting: for their own account, as a sole proprietor of a business, as a trustee

More information

Hong Leong Asia Ltd.

Hong Leong Asia Ltd. Hong Leong Asia Ltd. Personal Data Protection Policy The protection of your Personal Data is important to us. This Personal Data Protection Policy ( PDP Policy ) outlines how we manage your personal data,

More information

How To Ensure Health Information Is Protected

How To Ensure Health Information Is Protected pic pic CIHI Submission: 2011 Prescribed Entity Review October 2011 Who We Are Established in 1994, CIHI is an independent, not-for-profit corporation that provides essential information on Canada s health

More information

Abilities Centre collects personal information for the following purposes:

Abilities Centre collects personal information for the following purposes: Privacy Policy Accountability Abilities Centre is responsible for your personal information under its control. We have appointed a Privacy Officer who is accountable for our compliance with this Privacy

More information

British Columbia Personal Information Protection Act. Frequently Asked Questions:

British Columbia Personal Information Protection Act. Frequently Asked Questions: British Columbia Personal Information Protection Act Frequently Asked Questions: (Further queries may be sent to Bob Stewart at the B.C. Conference Archives.) (1) What is the Personal Information Protection

More information

THE PHONE RINGS FROM DOWN SOUTH: WHAT ISSUES SHOULD I CONSIDER FOR EXPANDING MY U.S. FRANCHISE INTO CANADA?

THE PHONE RINGS FROM DOWN SOUTH: WHAT ISSUES SHOULD I CONSIDER FOR EXPANDING MY U.S. FRANCHISE INTO CANADA? THE PHONE RINGS FROM DOWN SOUTH: WHAT ISSUES SHOULD I CONSIDER FOR EXPANDING MY U.S. FRANCHISE INTO CANADA? By Leonard H. Polsky Gowling Lafleur Henderson LLP Vancouver, British Columbia SYNOPSIS Canadian

More information

Best Practices in Data Management - A Guide for Marketers -

Best Practices in Data Management - A Guide for Marketers - Best Practices in Data Management - A Guide for Marketers - Prepared with support from the Office of the Privacy Commissioner of Canada s Contributions Program INTRODUCTION As consumers personal information

More information

The Credit Reporting Act

The Credit Reporting Act 1 CREDIT REPORTING c. C-43.2 The Credit Reporting Act being Chapter C-43.2 of The Statutes of Saskatchewan, 2004 (effective March 1, 2005). NOTE: This consolidation is not official. Amendments have been

More information

The HR Skinny: Effectively managing international employee data flows

The HR Skinny: Effectively managing international employee data flows The HR Skinny: Effectively managing international employee data flows Topics we will cover today Laws affecting HR data flows HR international data protection challenges and strategic solutions Case study

More information

Personal Information Protection and Electronic Documents Act

Personal Information Protection and Electronic Documents Act PIPEDA Self-Assessment Tool Personal Information Protection and Electronic Documents Act table of contents Why this tool is needed... 3 How to use this tool... 4 PART 1: Compliance Assessment Guide Principle

More information

Transferring Personal Information about Canadians Across Borders Implications of the USA PATRIOT Act

Transferring Personal Information about Canadians Across Borders Implications of the USA PATRIOT Act Office of the Commissariat Privacy Commissioner à la protection de of Canada la vie privée du Canada Transferring Personal Information about Canadians Across Borders Implications of the USA PATRIOT Act

More information

The USA Patriot Act Government Briefing. Kirsten Tisdale, Chris Norman, Sharon Plater & Alexandra (Gina) Henley September 30, 2004

The USA Patriot Act Government Briefing. Kirsten Tisdale, Chris Norman, Sharon Plater & Alexandra (Gina) Henley September 30, 2004 The USA Patriot Act Government Briefing Kirsten Tisdale, Chris Norman, Sharon Plater & Alexandra (Gina) Henley September 30, 2004 Agenda Background Overview of Government Responses and Approach Mitigation

More information

Troy Cablevision, Inc. Subscriber Privacy Policy

Troy Cablevision, Inc. Subscriber Privacy Policy Troy Cablevision, Inc. Subscriber Privacy Policy Troy Cablevision, Inc. ( Troy Cable ) is committed to protecting and securely maintaining our customers privacy. The following privacy policy applies to

More information

GENOA, a QoL HEALTHCARE COMPANY, LLC WEBSITE PRIVACY POLICY

GENOA, a QoL HEALTHCARE COMPANY, LLC WEBSITE PRIVACY POLICY GENOA, a QoL HEALTHCARE COMPANY, LLC WEBSITE PRIVACY POLICY PLEASE READ THIS WEBSITE PRIVACY POLICY CAREFULLY BEFORE USING THIS WEBSITE, OR SUBMITTING ANY PROTECTED HEALTH INFORMATION OR PERSONALLY IDENTIFIABLE

More information

SURVEILLANCE AND PRIVACY

SURVEILLANCE AND PRIVACY info sheet 03.12 SURVEILLANCE AND PRIVACY Info Sheet 03.12 March 2012 This Information Sheet applies to Victorian state and local government organisations that are bound by the Information Privacy Act

More information

Protecting your privacy

Protecting your privacy Protecting your privacy Table of Contents Answering your questions about privacy Your privacy... 1 Your consent... 1 Answering your questions about privacy... 2 About cookies... 9 Behavioural Advertising/Online

More information

Privacy Breach Protocol

Privacy Breach Protocol & Privacy Breach Protocol Guidelines for Government Organizations www.ipc.on.ca Table of Contents What is a privacy breach? 1 Guidelines on what government organizations should do 2 What happens when the

More information

Privacy in the Workplace Update What You Don t Know May Hurt You

Privacy in the Workplace Update What You Don t Know May Hurt You McCarthy Tétrault Advance Building Capabilities for Growth Privacy in the Workplace Update What You Don t Know May Hurt You Rosalie Cress Will Cascadden Employees Rights to Privacy in the Workplace 2 Federal

More information

HEALTH INFORMATION ACT

HEALTH INFORMATION ACT Province of Alberta HEALTH INFORMATION ACT Revised Statutes of Alberta 2000 Current as of June 17, 2014 Office Consolidation Published by Alberta Queen s Printer Alberta Queen s Printer 7 th Floor, Park

More information

MICROSOFT OFFICE 365 PRIVACY IMPACT ASSESSMENT. Western Student E-Communications Outsourcing

MICROSOFT OFFICE 365 PRIVACY IMPACT ASSESSMENT. Western Student E-Communications Outsourcing MICROSOFT OFFICE 365 PRIVACY IMPACT ASSESSMENT Western Student E-Communications Outsourcing Paul Eluchok - University Privacy Officer David Ghantous - Associate Director of Technical Services Dated: August

More information

PORTFOLIO MANAGEMENT ASSOCIATION OF CANADA

PORTFOLIO MANAGEMENT ASSOCIATION OF CANADA PORTFOLIO MANAGEMENT ASSOCIATION OF CANADA REFERENCE GUIDE TO POLICIES AND PROCEDURES FOR PORTFOLIO MANAGERS December 2010 Introduction Compliance Systems for Portfolio Managers Regulatory Expectations

More information

Updated February 15, 2008 MINISTRY OF HEALTH SOFTWARE SUPPORT ORGANIZATION SERVICE LEVEL AGREEMENT

Updated February 15, 2008 MINISTRY OF HEALTH SOFTWARE SUPPORT ORGANIZATION SERVICE LEVEL AGREEMENT BETWEEN: HER MAJESTY THE QUEEN IN RIGHT OF THE PROVINCE OF BRITISH COLUMBIA, represented by the Minister of Health ( the Ministry as the Province as applicable) at the following address: Assistant Deputy

More information

Policy Brief: Protecting Privacy in Cloud-Based Genomic Research

Policy Brief: Protecting Privacy in Cloud-Based Genomic Research Policy Brief: Protecting Privacy in Cloud-Based Genomic Research Version 1.0 July 21 st, 2015 Suggested Citation: Adrian Thorogood, Howard Simkevitz, Mark Phillips, Edward S Dove & Yann Joly, Policy Brief:

More information

5.00 Employee in relation to the university, includes a volunteer and a service provider.

5.00 Employee in relation to the university, includes a volunteer and a service provider. PROTECTION OF PRIVACY POLICY University Policy No: GV0235 Classification: Governance Approving Authority: Board of Governors Effective Date: January 1, 2010 Supersedes: June 2008 Last Editorial Change:

More information

Personal Information Protection Act ( PIPA ) Privacy-Proofing Your Retail Business Tips for Protecting Customers Personal Information 1

Personal Information Protection Act ( PIPA ) Privacy-Proofing Your Retail Business Tips for Protecting Customers Personal Information 1 Personal Information Protection Act ( PIPA ) Tips for Protecting Customers Personal Information 1 More than ever before, retailers have to be prepared to deal with customers who ask questions about the

More information

Personal Information Protection Act (PIPA) Privacy & Landlord - Tenant Matters Frequently Asked Questions

Personal Information Protection Act (PIPA) Privacy & Landlord - Tenant Matters Frequently Asked Questions Personal Information Protection Act (PIPA) Privacy & Landlord - Tenant Matters Frequently Asked Questions Are landlords in Alberta bound by privacy law? Yes. The Personal Information Protection Act (PIPA)

More information

KEY ISSUES IN PRIVACY AND INFORMATION MANAGEMENT

KEY ISSUES IN PRIVACY AND INFORMATION MANAGEMENT OSGOODE PROFESSIONAL DEVELOPMENT The OsgoodePD Webinar Series KEY ISSUES IN PRIVACY AND INFORMATION MANAGEMENT 8 focused webinars for the latest legal developments, including: Session 1: September 16,

More information

We will not collect, use or disclose your personal information without your consent, except where required or permitted by law.

We will not collect, use or disclose your personal information without your consent, except where required or permitted by law. HSBC Privacy Notice HSBC's Privacy Principles HSBC Bank Canada is a subsidiary of HSBC Holdings plc which, together with its subsidiaries and affiliates, is one of the world s largest banking and financial

More information

2. A Note about Children. We do not intentionally gather Personal Data from visitors who are under the age of 13.

2. A Note about Children. We do not intentionally gather Personal Data from visitors who are under the age of 13. PRIVACY POLICY Macromeasures Inc. ("Macromeasures") is committed to protecting your privacy. We have prepared this Privacy Policy to describe to you our practices regarding the Personal Data (as defined

More information

POLICE RECORD CHECKS IN EMPLOYMENT AND VOLUNTEERING

POLICE RECORD CHECKS IN EMPLOYMENT AND VOLUNTEERING POLICE RECORD CHECKS IN EMPLOYMENT AND VOLUNTEERING Know your rights A wide range of organizations are requiring employees and volunteers to provide police record checks. Privacy, human rights and employment

More information

Casino, Liquor and Gaming Control Authority Act 2007 No 91

Casino, Liquor and Gaming Control Authority Act 2007 No 91 New South Wales Casino, Liquor and Gaming Control Authority Act 2007 No 91 Contents Part 1 Part 2 Preliminary Page 1 Name of Act 2 2 Commencement 2 3 Definitions 2 4 Meaning of gaming and liquor legislation

More information

PERSONAL HEALTH INFORMATION PROTECTION ACT, 2004: AN OVERVIEW FOR HEALTH INFORMATION CUSTODIANS

PERSONAL HEALTH INFORMATION PROTECTION ACT, 2004: AN OVERVIEW FOR HEALTH INFORMATION CUSTODIANS PERSONAL HEALTH INFORMATION PROTECTION ACT, 2004: AN OVERVIEW FOR HEALTH INFORMATION CUSTODIANS Note: This document provides a general overview of the Personal Health Information Protection Act, 2004,

More information

Doing Business in Canada. SCG Legal Annual Meeting Vancouver, British Columbia September 2015

Doing Business in Canada. SCG Legal Annual Meeting Vancouver, British Columbia September 2015 Doing Business in Canada SCG Legal Annual Meeting Vancouver, British Columbia September 2015 Introduction World s second largest country by area As of July 1, 2014 the population was estimated at 35,540,400

More information

Zinc Recruitment Pty Ltd Privacy Policy

Zinc Recruitment Pty Ltd Privacy Policy 1. Introduction Zinc Recruitment Pty Ltd Privacy Policy We manage personal information in accordance with the Privacy Act 1988 and Australian Privacy Principles. This policy applies to information collected

More information

Table of Contents. Acknowledgement

Table of Contents. Acknowledgement OPA Communications and Member Services Committee February 2015 Table of Contents Preamble... 3 General Information... 3 Risks of Using Email... 4 Use of Smartphones and Other Mobile Devices... 5 Guidelines...

More information

Personal Information Protection and Electronic Documents Act (PIPEDA)

Personal Information Protection and Electronic Documents Act (PIPEDA) Introduction Personal Information Protection and Electronic Documents Act (PIPEDA) Policy and The Insurance Brokers Association of Alberta is committed to respect the privacy rights of individuals by ensuring

More information

NOTE: SERVICE AGREEMENTS WILL BE DRAFTED BY RISK SERVICES SERVICE AGREEMENT

NOTE: SERVICE AGREEMENTS WILL BE DRAFTED BY RISK SERVICES SERVICE AGREEMENT NOTE: SERVICE AGREEMENTS WILL BE DRAFTED BY RISK SERVICES SERVICE AGREEMENT Between: And: XXXXXX (the Contractor") Langara College 100 West 49 th Avenue Vancouver, BC V5Y 2Z6 (the College") The College

More information

VIDEO SURVEILLANCE GUIDELINES

VIDEO SURVEILLANCE GUIDELINES VIDEO SURVEILLANCE GUIDELINES Introduction Surveillance of public spaces has increased rapidly over recent years. This growth is largely attributed to the significant advances in surveillance technology

More information