A NEW GOVERNANCE PARADIGM: Canadian Privacy Law Developments March 11, 2004 Haliburton, Ontario Canada Volunteerism Initiative Arts Council for Haliburton.

Slides:



Advertisements
Similar presentations
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
Advertisements

Information Privacy and Data Protection Lexpert Seminar David YoungDecember 9, 2013 Breach Prevention – Due Diligence and Risk Reduction.
PIPA PRESENTATION PERSONAL INFORMATION PROTECTION ACT.
The Data Protection (Jersey) Law 2005.
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
Quebec City February 2005 PUBLIC SECTOR CIO COUNCIL BC - USA Patriot Act Update.
Data Protection and Records Management
The role of the Office of the Privacy Commissioner in telecommunications Andrew Solomon Director, Policy.
Internet and Information Technology Law September 18 th – Privacy Law Allyson Whyte Nowak UVIC.
1 Office of theCommissariat Privacy Commissionerà la protection de of Canadala vie privée du Canada Personal Information Protection and Electronic Documents.
What if my organization conducts business across borders ? Your footnote Privacy and “Personal Information” have different meanings in different countries;
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Anglican Province of Canada Privacy Policy. Commitment to Privacy The Privacy Policy, including the Web Privacy Statement, is the Anglican Province of.
Taking Steps to Protect Privacy A presentation to Hamilton-area Physiotherapy Managers by Bob Spence Communications Co-ordinator Office of the Ontario.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
Internal Auditing and Outsourcing
Using Technology in Nursing Practice: Part 1: Complying with Policy 1.
Operational Strategies for compliance with the new privacy legislation Excerpted from a Powerpoint presentation by Murray Long, Murray Long & Associates.
Overview of Engagement – Under the terms of this engagement, the Advisor will provide advice in the areas checked below. Investment Management – Develop.
13 July 2006Susan Joseph Health Privacy It’s My Business Health Records Act 2001 (Vic) eReferral Service Co-ordination System.
HIPAA Trading Partners, Legal Relationships October 2, 2001 presented by Peter B. Goldstein, Esq. Cap Gemini Ernst & Young, US LLC.
1-1 Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
6th CACR Information Security Workshop 1st Annual Privacy and Security Workshop (November 10, 2000) Incorporating Privacy into the Security Domain: Issues.
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
Copyright © 2008 by West Legal Studies in Business A Division of Thomson Learning Chapter 39 Regulation of Employment Twomey Jennings Anderson’s Business.
Part 6 – Special Legal Rights and Relationships Chapter 35 – Privacy Law Prepared by Michael Bozzo, Mohawk College © 2015 McGraw-Hill Ryerson Limited 34-1.
Managing Risks Associated With Privacy Alison Baker- Senior Associate Hall & Wilcox 24 November
Data Protection Act AS Module Heathcote Ch. 12.
CORPORATE STRUCTURING AND BASIC TAX CONSIDERATIONS.
Copyright © 2007 Pearson Education Canada 1 Chapter 1: The Demand for Auditing and Assurance Services.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
Copyright © 2007 Pearson Education Canada 1 Chapter 21: Completing the Audit.
PIPEDA and Receivables Management Robin Gould-Soil Receivables Management Association of Canada November 16, 2011.
BC Public Libraries November, 2008 Privacy Principles.
IT Applications Theory Slideshows By Mark Kelly Vceit.com Privacy Laws.
PROTECTION OF PERSONAL DATA. OECD GUIDELINES: BASIC PRINCIPLES OF NATIONAL APPLICATION Collection Limitation Principle There should be limits to the collection.
Session 7 Compliance failure policy. 1 Contents Part 1: COLP and COFA duties Part 2: What do we have to comply with and why does it matter? Part 3: Compliance.
1 Canadian Privacy Policy: Customizing E.U. Standards Remarks by Jennifer Stoddart Privacy Commissioner of Canada Privacy Symposium: Summer 2007 August.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
Fred Carter Senior Policy & Technology Advisor Information and Privacy Commissioner Ontario, Canada MISA Ontario Cloud Computing Transformation Workshop.
Privacy Information for Advisors. Agenda PIPEDA Advisor Required Privacy Program Our MGA Privacy Program Recommendations for Advisors.
Privacy Issues - Watch Out! John D.R. Craig ORIMS Professional Development Day March 19, 2013.
Data protection—training materials [Name and details of speaker]
1 Information Governance (For Dental Practices) Norman Pottinger Information Governance Manager NHS Suffolk.
The Health Information Protection Act. What is the Health Information Protection Act (HIPA)? HIPA is legislation that speaks to access to, and protection.
Privacy Legislation: What Every Funeral Director Needs to Know Julie Maciura March 31 and April 1, 2004.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Commissioning Services: with the DPA in mind South Yorkshire Information and Data Sharing Group Sheffield 14 th August 2014 Lynne Shackley Lead Policy.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
TRANSBORDER DATA FLOWS INA MEIRING. THE PROTECTION OF PERSONAL INFORMATION ACT (“POPI”) > 'personal information' means information relating to an identifiable,
Legal and Compliance Workshop July 28, 2016 Presented by: Lucy Du-Jones, Founder and Managing Director, du-tian.
PRIVACY TRAINING For CAILBA members
Privacy Education Session CMHA-WECB/CCHC Volunteers/Students
Privacy principles Individual written policies
General Data Protection Regulation
Data Protection Legislation
G.D.P.R General Data Protection Regulations
Ethical questions on the use of big data in official statistics
General Data Protection Regulation
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulations 2018
Mandatory Breach Reporting (isn’t *that* bad)
On the Cutting Edge – Update on Privacy Legislation
PRIVACY PRESENTATION TO THE SPRING 2013 CONFERENCE BY HANK MOORLAG
Upcoming PIPEDA Changes
Presentation transcript:

A NEW GOVERNANCE PARADIGM: Canadian Privacy Law Developments March 11, 2004 Haliburton, Ontario Canada Volunteerism Initiative Arts Council for Haliburton County

2 March 11, Presented by Jeffrey H. McCully, B.A., LL.B. PrivacyConsult phone fax

3 March 11, Agenda Overview of private sector privacy legislation in Canada PIPEDA - Application of the law Definitions - what is “personal information”? “governance”? Why privacy protections? Privacy Principles - the heart of PIPEDA Role of Privacy Commissioner & Remedies Privacy Management / Governance Privacy Compliance - Third Party Relations, Employees, Professionals

4 March 11, Agenda (continued) Conclusion Good Governance = Mitigation of Risk = Added Value Question & Answer Session

5 March 11, Overview of Legislation 2 federal privacy laws Privacy Act (1983) & PIPEDA (2001) Privacy Act - imposes obligations on federal departments - gives Canadians protections re collection, use, disclosure, access - covers tax records, military records, security clearances, etc.

6 March 11, Overview of Legislation (continued) PIPEDA - in force in stages from fully in force on January 1, 2004 Provincial laws - only Quebec (1994), BC, Alberta

7 March 11, PIPEDA: Application Jan 1, Federal work, undertaking or business collecting, using, disclosing personal information in the course of commercial activities. - Organizations that trade in information for consideration across a national border or provincial border. Jan 1, All organizations collecting, using or disclosing personal information in the course of commercial activities (excluding those subject to “substantially similar” provincial privacy laws).

8 March 11, Definitions Commercial Activity - means any particular transaction, act or conduct or any regular course of conduct that is of a commercial character, including the selling, bartering or leasing of donor, membership or other fundraising lists. Governance - authoritative care/control over an organization; relates to accountability for the activities of an organization. Organization - association, partnership, person (corporation) and trade union.

9 March 11, Definitions (continued ) Grandfathering (retroactivity) - refers to the treatment of information already in the organization’s possession pre-PIPEDA. Data already there is subject to the same rules. Personal Information - information that relates to an identifiable individual, but does NOT include the name, title and business address or telephone number of an employee of an organization. Privacy - the right of individuals to control the collection, use and disclosure of their own information.

10 March 11, Definitions (continued) Whistleblowing - section 27 of the PIPEDA protects persons who inform the Commissioner that a person or organization has or intends to contravene the Act. Such persons cannot be retaliated against.

11 March 11, Why Privacy Protection? To avoid cost of non-compliance –legal violations and damages/costs flowing from them (unlimited punitive damages; costs of litigation; court fines of $10,000, $100,000) –reputation, goodwill and brand image damage –psychological, economic harm to clients –consumer flight - loss of revenue –public companies - will a violation or a delay in compliance result in a loss of share value?

12 March 11, PIPEDA’S 10 Principles 1. Accountability 2. Identifying purposes 3. Consent 4. Limiting Collection 5. Limiting Use, Disclosure, Retention 6. Accuracy 7. Safeguards 8. Openness 9. Individual access 10. Challenging Compliance Each principle may require organizational changes. The heart of the law. Based on Canadian Standards Association Model Code.

13 March 11, Role of Privacy Commissioner (PC) PC has substantial powers - that of a Superior Court –investigate complaints –summon and question under oath –receive and consider evidence –search business premises –examine records found therein. PC may try to resolve complaints through mediation or conciliation. PC will issue a report, usually within 1 year.

14 March 11, Federal Court Persons may seek a hearing in Federal Court Trial Division if dissatisfied by the PC’s Report. Court may: –order correction of practices –order publication of actions taken –award substantial damages. Obstruction or punishing whistleblowers - up to $100,000 fine.

15 March 11, Privacy Management / Governance Organizations must ask questions: –Does PIPEDA apply? (collect personal information for commercial purposes) –Do we have an individual responsible for compliance (CPO)? –Have we conducted a privacy assessment? An audit periodically? –Have we obtained appropriate consent? –Have we identified use? –Do we have a procedure for access to information? –Have our front line staff and junior managers been educated?

16 March 11, Privacy Management / Governance –Have we reviewed documentation for necessary consents, confidentiality agreements, indemnities, audits? –Have we reviewed the information practices of third party data processors?

17 March 11, Privacy Compliance - Third Parties Liability can result if a business partner or a mere third party outsourcing arrangement violates PIPEDA. Commercial printers, payroll outsourcers, information technology companies (website designers) are a source of liability for you. An organization cannot avoid its privacy obligations by outsourcing. Set out adequate security measures: –confidentiality agreements –encryption technology

18 March 11, Privacy Compliance - Third Parties (continued) –“Chinese walls” and other good practices –proper consents –indemnities –privacy audit rights for you.

19 March 11, Privacy Compliance - Employees PIPEDA applies to employee information in federal works, undertakings and businesses only - NOT to provincially regulated businesses. Balance is required - what does an employer really need to know? (pay, benefits, records, health records, resumes). Question: What about psychological tests, keystroke monitoring, ?

20 March 11, Privacy Compliance - Employees (continued) Collect, use, disclose only with consent (#3). Disclose what information is collected, why, what is done with the information (#2, 4, 5). Collect only what is necessary for stated purpose (#4). Collect by fair/lawful means. Ensure that any consents given by employees are real, and not forced as a condition of employment. Keep information accurate and up to date (#6). Give employees access to it and allow them to challenge or correct it (#6, 9, 10).

21 March 11, Privacy Compliance - Professionals Lawyers, accountants, financial advisors will receive much information on third parties, collected by their clients: –payroll information –rent rolls –life insurance information with respect to claims. In an assurance contract, the professional does not have direct access to third parties. The client has the link to the third party. The client should obtain the appropriate consents.

22 March 11, Privacy Compliance - Professionals Mere transfers of information for processing (eg. preparation of tax returns) are non-assurance contracts. No further consent is necessary. Consent is implied when, for example, a CA is hired to prepare a tax return. Third parties not involved.

23 March 11, Wording in Assurance Contract “It is acknowledged that we will have access to all personal information in your custody that we require to complete our engagement. Our services are provided on the basis that: –you represent to us that you have obtained the required consents for the collection and use of personal information under PIPEDA; and –we will hold all personal information in compliance with our Privacy Policy.”

24 March 11, Conclusion Good privacy practice is good information management. Good information management gives a competitive advantage. Governance is enhanced when an organization’s “directing mind” identifies potential business risks and implements systems to mitigate those risks. Privacy is now key to good governance. Good Governance = Mitigation of Risk = Added Value