Privacy & Access to Information

Slides:



Advertisements
Similar presentations
The Role of the IRB An Institutional Review Board (IRB) is a review committee established to help protect the rights and welfare of human research subjects.
Advertisements

University Data Classification Table* Level 5Level 4 Information that would cause severe harm to individuals or the University if disclosed. Level 5 information.
Data Protection Information Management / Jody McKenzie.
Confidentiality and HIPAA
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
NAU HIPAA Awareness Training
PIPA PRESENTATION PERSONAL INFORMATION PROTECTION ACT.
The Data Protection (Jersey) Law 2005.
VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.
Complying with Privacy to Enable Innovation & Research
 Freedom of Information Act General Background. Access to Army Records. Exemptions. Exclusions. Procedural Rules for Processing FOIA Requests for Army.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
Presentation by Mark Grady Vancouver Island University June 13, 2012.
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
The Family Educational Rights and Privacy Act (FERPA) The Importance of Protecting Student Records This session will help you better understand the law.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
HIPAA PRIVACY AND SECURITY AWARENESS.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
707 KAR 1:360 Confidentiality of Information. Section 1: Access Rights 1) An LEA shall permit a parent to inspect and review any education records relating.
Privacy and Security Laws for Health Care Organizations Presented by Robert J. Scott Scott & Scott, LLP
Part 6 – Special Legal Rights and Relationships Chapter 35 – Privacy Law Prepared by Michael Bozzo, Mohawk College © 2015 McGraw-Hill Ryerson Limited 34-1.
Family Educational Rights and Privacy Act. From the moment a child enters the school system, sensitive information is collected about the child (and even.
FERPA: What you Need to Know The Family Educational Rights and Privacy Act & SEI.
The Family Educational Rights and Privacy Act FERPA.
LeToia Crozier, Esq., CHC Vice President, Compliance & Regulatory Affairs Corey Wilson Director of Technical Services & Security Officer Interactive Think.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
The right item, right place, right time. DLA Privacy Act Code of Fair Information Principles.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
1 CONFIDENTIALITY. 2 Requirement Under IDEA 34 CFR Sec (c) All staff collecting or using personally identifiable information in public education.
Data Practices in Minnesota December Outline for this presentation Minnesota data practices laws Classification of government data Government entity.
1 PARCC Data Privacy & Security Policy December 2013.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
FERPA Guidelines for Cooperating Teacher and University Supervisors.
Indiana’s Access to Public Records Act Heather Willis Neal Indiana Public Access Counselor Presented to Indiana State Department of Health August 21, 2008.
Privacy Information for Advisors. Agenda PIPEDA Advisor Required Privacy Program Our MGA Privacy Program Recommendations for Advisors.
The Freedom of Information Act and UCL Compliance Rosamund Cummings UCL FOI Officer
CONFIDENTIALITY. Three Confidentiality Laws 1.FERPA-Family Education Rights and Privacy Act (State Policy 4350: Procedures for the Collection, Maintenance.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Data protection—training materials [Name and details of speaker]
The Health Information Protection Act. What is the Health Information Protection Act (HIPA)? HIPA is legislation that speaks to access to, and protection.
Taylor County Schools FERPA (Confidentiality) Training August 17, 2010.
SEMINAR: Copyright 2012 All rights reserved. This presentation and/or any part thereof is intended for personal use and may not be reproduced or distributed.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Laws and Regulations. Family Educational Rights and Privacy Act Children’s Online Privacy Protection Act Protection of Pupil Rights Amendment Health Insurance.
Nassau Association of School Technologists
The Data Protection Act 1998
Protecting PHI & PII 12/30/2017 6:45 AM
PRIVACY TRAINING For CAILBA members
Privacy principles Individual written policies
Obligations of Educational Agencies: Parents’ Bill of Rights
General Data Protection Regulation
The Data Protection Act 1998
Move this to online module slides 11-56
Disability Services Agencies Briefing On HIPAA
CONTRACTS PRIVILEGED COMMUNICATION PRIVACY ACT
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulations 2018
Mandatory Breach Reporting (isn’t *that* bad)
Confidentiality Agreement
Good Spirit School Division
Move this to online module slides 11-56
Student Data Privacy: National Trends and Wyoming’s Role
Colorado “Protections For Consumer Data Privacy” Law
Presentation transcript:

Privacy & Access to Information ICT Support Services February 2018 Rayelle Johnston, Access and Privacy Officer

Legislation and Policy The Local Authority Freedom of Information and Protection of Privacy Act (LA FOIP) Policies Freedom of Information and Protection of Privacy Data Management Computer Use E-mail Management of University Records Information Security

Other Compliance Legislated reporting requirements Funding agency requirements Contractual requirements Confidentiality Reporting

Access to Information Any person Any record Limited exemptions With application form and fee Any record Limited exemptions Others’ personal information (including child or family member), certain financial and third party information Time limits Informal/formal processes

Privacy Protection of personal information Any information in our custody or control about an identifiable individual is protected Except – certain employment information about university employees; the degrees awarded by the university Can only be used and disclosed in accordance with the Act Rules around collection, use, and disclosure Consent – express or implied Without consent in very limited circumstances

Privacy Limited collection Shall not collect personal information unless the information is collected for a purpose that relates to an existing or proposed program or activity of the university Personal information should generally be collected from the individual to whom it relates, with informed consent Need to ensure personal information is accurate and complete Need to know vs. nice to know

Privacy Use and disclosure Shall not use or disclose personal information without express consent, except: With implied consent - “for the purpose for which the information was obtained or compiled by the university or for a use that is consistent with that purpose” Without consent in very limited circumstances As required or permitted by law Protection of mental or physical health or safety Public interest outweighs invasion of privacy or a clear benefit to the individual – high bar and rarely relied on Where the information is otherwise publicly available

Privacy Steps to considering use and disclosure of PI Should we be collecting the information in the first place? Do we have express consent to use or disclose the information in the manner or for the purpose proposed? Do we have implied consent? Can we do it without consent? If we can use or disclose, what it the best way to do so? Best practices, other laws (eg. CASL), university policy and other compliance requirements (contracts, etc.)

Privacy Breach Improper collection Improper use or disclosure intentional or unintentional, malicious or not Privacy breach response guidelines Contain Notify Investigate Mitigate Report

Important Changes Duty to Protect Outsourcing – IMSPs Mandatory Breach Notification Penalties

Duty to Protect Administrative safeguards Technical safeguards Policies, procedures, guidelines Appropriate contracts with service providers Technical safeguards Encryption, role-based access, secured connections, password protected mobile devices Physical safeguards Lock doors, filing cabinets, don’t leave files/laptops in car

Penalties Institution: 1 year in prison and/or $50,000 fine New – Individuals who wilfully access or use personal information that is not reasonably required to carry out an authorized purpose (snooping): 1 year in prison and/or $50,000 fine

Contact & Other Resources Access and Privacy Office privacy@usask.ca www.privacy.usask.ca Rayelle Johnston rayelle.johnston@usask.ca 966-8596 Saskatchewan Information and Privacy Commissioner www.oipc.sk.ca

Contact & Other Resources Internal Resources Access and Privacy Officer FOIP Liaisons (coming soon!) University Archives – records management policy and records retention schedules Research Services and Ethics Office Legal Services Data Classification, Data Stewards and Data Dictionary Technology Assessment Team

Questions?