04.05.2014 Views

Personal Information Protection Act - Office of the Information and ...

Personal Information Protection Act - Office of the Information and ...

Personal Information Protection Act - Office of the Information and ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

A G u i d e f o r B u s i n e s s e s a n d O r g a n i z a t i o n s o n t h e P e r s o n a l I n f o r m a t i o n P r o t e c t i o n A c t<br />

What organizations <strong>and</strong> types<br />

<strong>of</strong> information does PIPA regulate?<br />

Organizations under <strong>the</strong> <strong>Act</strong><br />

PIPA applies to all organizations <strong>and</strong> to all personal information held by organizations unless<br />

<strong>the</strong> <strong>Act</strong> says that it does not apply (section 4(1)).<br />

An organization includes:<br />

▲ a corporation,<br />

▲ an association that is not incorporated,<br />

▲ a trade union,<br />

▲ a partnership, <strong>and</strong><br />

▲ an individual acting in a commercial capacity (for example, an individual running a small<br />

renovation business that is not incorporated).<br />

When Organization A hires Organization B under a contract, Organization A is responsible for<br />

<strong>the</strong> personal information related to <strong>the</strong> contract. Organization B is also responsible for making<br />

sure <strong>the</strong>y operate in accordance with <strong>the</strong> <strong>Act</strong>.<br />

An organization does not include a person who is acting in a personal or domestic way, related<br />

solely to family or home activities.<br />

Self-governing pr<strong>of</strong>essional organizations<br />

PIPA allows a pr<strong>of</strong>essional regulatory organization to develop a personal information code that<br />

provides <strong>the</strong> same level <strong>of</strong> privacy protection as <strong>the</strong> <strong>Act</strong> while allowing some latitude in format<br />

<strong>and</strong> wording. The code must be consistent with <strong>the</strong> rights <strong>and</strong> obligations set out in PIPA, <strong>and</strong><br />

<strong>the</strong> Commissioner can still investigate or review <strong>the</strong> decisions or actions <strong>of</strong> a pr<strong>of</strong>essional<br />

regulatory organization with a personal information code.<br />

For guidelines on developing a personal information code, see Guidelines for Developing<br />

a <strong>Personal</strong> <strong>Information</strong> Code for Pr<strong>of</strong>essional Regulatory Organizations, available at<br />

pipa.alberta.ca.<br />

12<br />

Service Alberta <strong>and</strong> <strong>the</strong> <strong>Office</strong> <strong>of</strong> <strong>the</strong> <strong>Information</strong> <strong>and</strong> Privacy Commissioner

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!