PRIVACY IMPACT ASSESSMENT FROM A REGULATOR S S POINT OF VIEW
|
|
|
- Dortha Mason
- 10 years ago
- Views:
Transcription
1 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE #
2 PRIVACY IMPACT ASSESSMENT FROM A REGULATOR S S POINT OF VIEW DONALD LEMIEUX EXECUTIVE DIRECTOR INFORMATION AND PRIVACY POLICY BRANCH TREASURY BOARD OF CANADA, SECRETARIAT 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE #
3 Privacy in Canada Canadian Human Rights Act was promulgated - Part IV related to privacy rights 1983 Privacy Act put in place 1989 Policy on SIN and Data Matching Policy on Privacy and Data Protection (SIN / Data Matching requirements integrated) 2001 Personal Information Protection and Electronic Documents Act comes into force 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE #
4 Integrating programs and privacy The Policy (May 2002) was adopted to assure Canadians that their privacy would be taken into account when there are proposals for programs and services that raise privacy risks. A PIA requires federal institutions to consider the privacy issues of programs and services throughout the design, implementation and evolution of those initiatives. PIA is a core component of the federal government s privacy compliance regime. 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE #
5 Federal responsibilities Heads of institutions are responsible for ensuring that their organizations comply with the Privacy Act and by virtue the PIA Policy. Accountability for PIAs rests with departments. Treasury Board Secretariat is responsible for developing and interpreting privacy policy, including the PIA, providing advice to institutions, and monitoring compliance. PIA Policy has links to project approval and government funding for initiatives. 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE #
6 Issues PIAs are not always completed in a timely manner. There is a need to more fully integrate PIAs into the management decision making process of federal institutions. PIA requirements are currently the same for all initiatives regardless of project type, magnitude, or risk. There is a need to streamline the PIA process. The cumulative effects of policies or programs involving personal information may not be apparent. Limited privacy consideration for projects involving multiple programs within institutions, inter-institutional and cross jurisdictional flow of personal information. 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE #
7 Regulatory challenges How do we improve central oversight of the PIA process and ensure greater compliance with the PIA Policy? How do we limit administrative burdens on institutional program and privacy officials with respect to PIA requirements? How can we better assess the cumulative effects of government plans and priorities on an individual s privacy? 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE #
8 Solutions Policy Suite Renewal Strengthening the link between the requirement to conduct a PIA and the law (the Privacy Act). Creating a better awareness and understanding of privacy risks through training and education. Using a risk based approach to streamline the PIA process (in particular for low impact initiatives). Enhancing the public reporting requirements for PIAs so as to improve transparency and oversight. Developing a central repository of PIAs and examining large scale programs (government-wide and across jurisdictions) for cumulative privacy effects. 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE #
9 Office of the Privacy Commissioner of Canada (OPC) OPC has oversight of federal privacy legislation in Canada, that is, the Privacy Act and PIPEDA OPC is also responsible for reviewing PIAs and providing advice and guidance to institutions to mitigate privacy risks Claude Beaulé will now provide greater detail with regard to the OPC s role and responsibilities. 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE #
CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:
CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES: Privacy Responsibilities and Considerations Cloud computing is the delivery of computing services over the Internet, and it offers many potential
Office of the Executive Council. activity plan 2014-17
Office of the Executive Council activity plan 2014-17 Message from the Premier In accordance with my responsibilities under the Transparency and Accountability Act, I am pleased to present the 2014-17
Privacy Policy on the Collection, Use, Disclosure and Retention of Personal Health Information and De-Identified Data, 2010
pic pic Privacy Policy on the Collection, Use, Disclosure and Retention of Personal Health Information and De-Identified Data, 2010 Updated March 2013 Our Vision Better data. Better decisions. Healthier
2008-11 BUSINESS PLAN
2008-11 BUSINESS PLAN FIRE AND EMERGENCY SERVICES - NEWFOUNDLAND AND LABRADOR MESSAGE FROM THE MINISTER As Minister responsible for Fire and Emergency Services Newfoundland and Labrador (FES-NL), I am
Privacy and Security Framework, February 2010
Privacy and Security Framework, February 2010 Updated April 2014 Our Vision Better data. Better decisions. Healthier Canadians. Our Mandate To lead the development and maintenance of comprehensive and
Access to Information and Privacy
Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada Access to Information and Privacy Process and Compliance Manual Prepared by The ATIP Unit April 2008
Status Report of the Auditor General of Canada to the House of Commons
2011 Status Report of the Auditor General of Canada to the House of Commons Chapter 1 Financial Management and Control and Risk Management Office of the Auditor General of Canada The 2011 Status Report
Human Resources and Skills Development Canada Departmental Privacy Policy
Human Resources and Skills Development Canada Departmental Privacy Policy Effective Date: April 2007, Updated October, 2009 CA-579-03-10E You can order this publication by contacting: Publications Services
Cloud Computing: Trust But Verify
Cloud Computing: Trust But Verify 14th Annual Privacy and Security Conference February 8, 2013, Victoria Martin P.J. Kratz, QC Bennett Jones LLP Cloud Computing Provision of services available on the Internet
Strategy for Email Management in Canadian Jurisdictions
Strategy for Email Management in Canadian Jurisdictions Email is a fundamental part of doing business today, and the management of email has become a critical issue across all jurisdictions. All governments
Protecting Saskatchewan data the USA Patriot Act
Protecting Saskatchewan data the USA Patriot Act Main points... 404 Introduction... 405 Standing Committee on Public Accounts motion... 405 Our response to the motion... 405 ITO, its service provider,
Helpful Tips. Privacy Breach Guidelines. September 2010
Helpful Tips Privacy Breach Guidelines September 2010 Office of the Saskatchewan Information and Privacy Commissioner 503 1801 Hamilton Street Regina, Saskatchewan S4P 4B4 Office of the Saskatchewan Information
Cloud Computing: Legal Risks and Best Practices
Cloud Computing: Legal Risks and Best Practices A Bennett Jones Presentation Toronto, Ontario Lisa Abe-Oldenburg, Partner Bennett Jones LLP November 7, 2012 Introduction Security and Data Privacy Recent
Government of Canada Cyber Security Event Management Plan (formerly GC IT Incident Management Plan)
Government of Canada Cyber Security Event Management Plan (formerly GC IT Incident Management Plan) Presentation to PSCIOC March 5 th, 2015 Overview Drivers Current Landscape Proposed Changes Expected
NBC MANAGEMENT ACTION PLAN PLAN D ACTION DE CCBN
NBC MANAGEMENT ACTION PLAN PLAN D ACTION DE CCBN Please develop a detailed management action plan with actions that are specific, measurable, attainable, relevant and timely. Management Action Plans will
The Government of Canada Action Plan to Reform the Administration of Grant and Contribution Programs
The Government of Canada Action Plan to Reform the Administration of Grant and Contribution Programs Her Majesty the Queen in Right of Canada, represented by the President of the Treasury Board, 2008
Self-Assessment of a Comprehensive Privacy Programme: A Tool for Practitioners
Self-Assessment of a Comprehensive Privacy Programme: A Tool for Practitioners The Accountability Project ( the Project ) is pleased to release Self-Assessment of a Comprehensive Privacy Programme: A Tool
Passenger Protect Program Transport Canada
AUDIT REPORT OF THE PRIVACY COMMISSIONER OF CANADA Passenger Protect Program Transport Canada Section 37 of the Privacy Act 2009 AUDIT OF PASSENGER PROTECT PROGRAM, TRANSPORT CANADA The audit work reported
INVESTMENT PLANNING AND PRIORITY SETTING: Management Approaches to Resource Allocation
INVESTMENT PLANNING AND PRIORITY SETTING: Management Approaches to Resource Allocation Treasury Board Secretariat: Mel Thompson : Catherine Ella, P Eng, PMP Speakers Mel Thompson is the Principal Analyst
LEGISLATIVE COUNCIL BRIEF. Insurance Companies Ordinance (Chapter 41) INSURANCE COMPANIES (AMENDMENT) ORDINANCE 2015 (COMMENCEMENT) NOTICE 2015
File Ref.: INS/2/3C(2015) LEGISLATIVE COUNCIL BRIEF Insurance Companies Ordinance (Chapter 41) INSURANCE COMPANIES (AMENDMENT) ORDINANCE 2015 (COMMENCEMENT) NOTICE 2015 INTRODUCTION The Secretary for Financial
Privacy Law in Canada
Privacy Law in Canada Federal and provincial privacy legislation has a profound impact on the way virtually all organizations carry on business across the country. Canada s privacy laws, while likely the
How To Manage Risk At Atb Financial
Guidelines for Financial Institutions Legislative Compliance Management (LCM) Date: July 2004 Introduction Regulatory risk is the risk of non-compliance with applicable regulatory requirements. For the
PIPEDA and Online Backup White Paper
PIPEDA and Online Backup White Paper The cloud computing era has seen a phenomenal growth of the data backup service industry. Backup service providers, by nature of their business, are compelled to collect
Accountability: Data Governance for the Evolving Digital Marketplace 1
Accountability: Data Governance for the Evolving Digital Marketplace 1 1 For the past three years, the Centre for Information Policy Leadership at Hunton & Williams LLP has served as secretariat for the
5581/16 AD/NC/ra DGE 2
Council of the European Union Brussels, 21 April 2016 (OR. en) Interinstitutional File: 2013/0027 (COD) 5581/16 LEGISLATIVE ACTS AND OTHER INSTRUMTS Subject: TELECOM 7 DATAPROTECT 6 CYBER 4 MI 37 CSC 15
The proposed Fourth Money Laundering Directive
The proposed Fourth Money Laundering Directive What the proposed Directive means and how to keep your business safe USING IDENTITY INTELLIGENTLY Money Laundering Directive What the proposed Directive means
Aboriginal Affairs and Northern Development Canada. Internal Audit Report. Audit of Economic Development Programs. Prepared by:
Aboriginal Affairs and Northern Development Canada Internal Audit Report Audit of Economic Development Programs Prepared by: Audit and Assurance Services Branch Project No. 13-44 February 2014 TABLE OF
New Regulations and Mortgage Document Management: What it Means for Mortgage Servicers
New Regulations and Mortgage Document Management: What it Means for Mortgage Servicers CT Representation Services New Regulations and Mortgage Document Management: What it Means for Mortgage Servicers
HEALTH INFORMATION ACT (HIA) BILL QUESTIONS AND ANSWERS
HEALTH INFORMATION ACT (HIA) BILL QUESTIONS AND ANSWERS KEY HIA CONCEPTS AND PROVISIONS Q. What is the purpose of the legislation? To protect clients personal health information. To set rules on the collection,
Issues Paper Managing General Agencies Life Insurance Distribution Model
Issues Paper Managing General Agencies Life Insurance Distribution Model Agencies Regulation Committee February 2011 This document reflects the work of regulators who are members of CCIR. The views expressed
Doing Business in Canada. SCG Legal Annual Meeting Vancouver, British Columbia September 2015
Doing Business in Canada SCG Legal Annual Meeting Vancouver, British Columbia September 2015 Introduction World s second largest country by area As of July 1, 2014 the population was estimated at 35,540,400
Phase II of Compliance to the Policy on Internal Control: Audit of Entity-Level Controls
Phase II of Compliance to the Policy on Internal Control: Audit of Entity-Level Controls Office of the Chief Audit and Evaluation Executive Audit and Assurance Services Directorate November 2013 Cette
DRAFT Report on Office of the Superintendent of Financial Report on Institutions Office of the Superintendent of Financial
DRAFT Report on Office of the Superintendent of Financial Report on Institutions Office of the Superintendent of Financial Institutions Regulation Sector Approvals & Precedents Group Office of the Chief
How To Get A Non-Profit Organization To Support A Caberta Power Plant Plant
VIA EMAIL: [email protected], [email protected] Alberta Securities Commission Autorité des marchés financiers British Columbia Securities Commission Manitoba Securities Commission
Framework for Cooperative Market Conduct Supervision in Canada
Framework for Cooperative Market Conduct Supervision in Canada November 2015 1 Purpose The Framework for Cooperative Market Conduct Supervision in Canada ( Cooperative Framework ) is intended to provide
Info Source. Sources of Federal Government and Employee Information 2015. Vancouver Fraser Port Authority. Table of Contents
Info Source Sources of Federal Government and Employee Information 2015 Vancouver Fraser Port Authority Table of Contents Introduction to Info Source General Information Background Responsibilities Institutional
The Manitoba Child Care Association PRIVACY POLICY
The Manitoba Child Care Association PRIVACY POLICY BACKGROUND The Manitoba Child Care Association is committed to comply with the legal obligations imposed by the federal government's Personal Information
PUBLIC SERVICE COMMISSION AUDIT REPORTS 2012
PUBLIC SERVICE COMMISSION AUDIT REPORTS 2012 All of the audit work in this publication was conducted in accordance with the legislative mandate and audit policies of the Public Service Commission of Canada.
Cloud Computing and Privacy Toolkit. Protecting Privacy Online. May 2016 CLOUD COMPUTING AND PRIVACY TOOLKIT 1
Cloud Computing and Privacy Toolkit Protecting Privacy Online May 2016 CLOUD COMPUTING AND PRIVACY TOOLKIT 1 Table of Contents ABOUT THIS TOOLKIT... 4 What is this Toolkit?... 4 Purpose of this Toolkit...
OFFICE OF THE PRIVACY COMMISSIONER OF CANADA. Audit of Human Resource Management
OFFICE OF THE PRIVACY COMMISSIONER OF CANADA Audit of Human Resource Management May 13, 2010 Prepared by the Centre for Public Management Inc. TABLE OF CONTENTS 1.0 Executive Summary... 2 2.0 Background...
ROLE OF THE AGENCY IN THE DISTRIBUTION OF LIFE/HEALTH INSURANCE PRODUCTS
ROLE OF THE AGENCY IN THE DISTRIBUTION OF LIFE/HEALTH INSURANCE PRODUCTS Independent Financial Brokers of Canada (IFB) is pleased to provide the Canadian Council of Insurance Regulators (CCIR) with input
How To Ensure Health Information Is Protected
pic pic CIHI Submission: 2011 Prescribed Entity Review October 2011 Who We Are Established in 1994, CIHI is an independent, not-for-profit corporation that provides essential information on Canada s health
Insurance Industry Expertise
Insurance Industry Expertise Delivered With High-Level Attention and Service Audit Tax Advisory Risk Performance The Unique Alternative to the Big Four For more than 50 years, clients in all sectors of
Final Audit Report. Audit of the Human Resources Management Information System. December 2013. Canada
Final Audit Report Audit of the Human Resources Management Information System December 2013 Canada Table of Contents Executive summary... i A - Introduction... 1 1. Background... 1 2. Audit objective...
Title V Preventing Fraud and Abuse. Subtitle A- Establishment of New Health and Human Services and Department of Justice Health Care Fraud Positions
Title V Preventing Fraud and Abuse Subtitle A- Establishment of New Health and Human Services and Department of Justice Health Care Fraud Positions Sec. 501. Health and Human Services Senior Advisor There
Legislative Council Panel on Financial Affairs
For information Legislative Council Panel on Financial Affairs Anti-Money Laundering and Counter-Terrorist Financing (Financial Institutions) Ordinance (Amendment of Schedule 2) Notice 2015 PURPOSE This
COUNCIL OF THE EUROPEAN UNION. Brussels, 22 November 2006 15644/06 DATAPROTECT 45 EDPS 3
COUNCIL OF THE EUROPEAN UNION Brussels, 22 November 2006 15644/06 DATAPROTECT 45 EDPS 3 COVER NOTE from: Secretary-General of the European Commission, signed by Mr Jordi AYET PUIGARNAU, Director date of
Code of Conduct for Mobile Money Providers
Code of Conduct for Mobile Money Providers SOUNDNESS OF SERVICES FAIR TREATMENT OF CUSTOMERS SECURITY OF THE MOBILE NETWORK AND CHANNEL VERSION 2 - OCTOBER 2015 Introduction This Code of Conduct identifies
Audit of Financial Reporting Controls
Audit of Financial Reporting Controls WESTERN ECONOMIC DIVERSIFICATION CANADA Audit & Evaluation Branch February 2012 Table of Contents 1.0 Executive Summary 1 2.0 Statement of Assurance 1 3.0 Introduction
Audit of the Policy on Internal Control Implementation
Audit of the Policy on Internal Control Implementation Natural Sciences and Engineering Research Council of Canada Social Sciences and Humanities Research Council of Canada February 18, 2013 1 TABLE OF
How To Write A Listing Policy For A Species At Risk Act
Fisheries and Oceans Canada Species at Risk Act Listing Policy and Directive for Do Not List Advice DFO SARA Listing Policy Preamble The Fisheries and Oceans Canada (DFO) Species at Risk Act (SARA) Listing
UNITED STATES DEPARTMENT OF THE INTERIOR BUREAU OF LAND MANAGEMENT MANUAL TRANSMITTAL SHEET
Form 1221-2 (June 1969) UNITED STATES DEPARTMENT OF THE INTERIOR BUREAU OF LAND MANAGEMENT Release: 1-1718 Date: MANUAL TRANSMITTAL SHEET Subject 1265 Information Technology Investment Management (ITIM)
GAO ELECTRONIC GOVERNMENT ACT. Agencies Have Implemented Most Provisions, but Key Areas of Attention Remain
GAO United States Government Accountability Office Report to the Committee on Homeland Security and Governmental Affairs, U.S. Senate September 2012 ELECTRONIC GOVERNMENT ACT Agencies Have Implemented
Legislative Language
Legislative Language SEC. 1. COORDINATION OF FEDERAL INFORMATION SECURITY POLICY. (a) IN GENERAL. Chapter 35 of title 44, United States Code, is amended by striking subchapters II and III and inserting
Privacy and Cloud Computing for Australian Government Agencies
Privacy and Cloud Computing for Australian Government Agencies Better Practice Guide February 2013 Version 1.1 Introduction Despite common perceptions, cloud computing has the potential to enhance privacy
7.0 Information Security Protections The aggregation and analysis of large collections of data and the development
7.0 Information Security Protections The aggregation and analysis of large collections of data and the development of interconnected information systems designed to facilitate information sharing is revolutionizing
Review of Building the Canadian Advantage: a Corporate Social Responsibility Strategy for the Canadian International Extractive Sector
Review of Building the Canadian Advantage: a Corporate Social Responsibility Strategy for the Canadian International Extractive Sector Submission to the Department of Foreign Affairs, Trade & Development
Red Tape Reduction Action Plan
Red Tape Reduction Action Plan Her Majesty the Queen in Right of Canada, represented by the President of the Treasury Board, 2012 Catalogue No. BT22-132/2012E-PDF ISBN 978-1-100-21308-8 This document is
Taking care of what s important to you
A v i v a C a n a d a I n c. P r i v a c y P o l i c y Taking care of what s important to you Table of Contents Introduction Privacy in Canada Definition of Personal Information Privacy Policy: the ten
Service Alberta BUSINESS PLAN 2010 13
Service Alberta BUSINESS PLAN 2010 13 Service Alberta BUSINESS PLAN 2010-13 ACCOUNTABILITY STATEMENT The business plan for the three years commencing April 1, 2010 was prepared under my direction in accordance
Gaps and Duplicative Requirements, August 30, 2013, available at http://www.cftc.gov/ucm/groups/public/@newsroom/documents/file/odrgreport.pdf.
Report of the OTC Derivatives Regulators Group (ODRG) 1 on Cross-Border Implementation Issues March 2014 At the St. Petersburg summit in September 2013, the G20 leaders welcomed the set of understandings
The USA Patriot Act Government Briefing. Kirsten Tisdale, Chris Norman, Sharon Plater & Alexandra (Gina) Henley September 30, 2004
The USA Patriot Act Government Briefing Kirsten Tisdale, Chris Norman, Sharon Plater & Alexandra (Gina) Henley September 30, 2004 Agenda Background Overview of Government Responses and Approach Mitigation
PROVINCE OF BRITISH COLUMBIA. Summary Review. Anti-Money Laundering Measures at BC Gaming Facilities
PROVINCE OF BRITISH COLUMBIA Summary Review Anti-Money Laundering Measures at BC Gaming Facilities February 2011 2 P a g e EXECUTIVE SUMMARY In early January 2011, a series of news reports ran on cash
Crown Agency Risk Management and Internal Controls
Crown Agency Risk Management and Internal Controls A Good Practices Checklist Crown Agencies Secretariat Board Resourcing and Development Office Introduction Crown Agency Risk Management and Internal
The Use of Cloud Computing for the Storing and Accessing of Client Information: Some Practical and Ethical Considerations
The Use of Cloud Computing for the Storing and Accessing of Client Information: Some Practical and Ethical Considerations Jeffrey D. Scott Jeffrey D. Scott, Legal Professional Corporation Practice Advisors
Workforce planning in the public service : Calculating numbers and compensation costs in the Government of Canada
Workforce planning in the public service : Calculating numbers and compensation costs in the Government of Canada Roger Scott-Douglas 5ème réunion régionale du Groupe de Travail sur la fonction publique
AN INTRO TO. Privacy Laws. An introductory guide to Canadian Privacy Laws and how to be in compliance. Laura Brown
AN INTRO TO Privacy Laws An introductory guide to Canadian Privacy Laws and how to be in compliance Laura Brown Air Interactive Media Senior DMS Advisor A Publication of 1 TABLE OF CONTENTS Introduction
Personal Information Protection Act ( PIPA ) Privacy-Proofing Your Retail Business Tips for Protecting Customers Personal Information 1
Personal Information Protection Act ( PIPA ) Tips for Protecting Customers Personal Information 1 More than ever before, retailers have to be prepared to deal with customers who ask questions about the
Proposed Guidance on Insider Order Marking
Rules Notice Request for Comments UMIR Please distribute internally to: Legal and Compliance Trading Contact: Naomi Solomon Senior Policy Counsel, Market Regulation Policy Telephone: 416.646.7280 Fax:
Regulatory Compliance Management (RCM) (formerly Legislative Compliance Management (LCM))
Guideline Subject: Category: (RCM) (formerly Legislative Compliance Management (LCM)) Sound Business & Financial Practices No: E-13 Date: November 2014 I. Purpose and Scope of the Guideline The purpose
