10.07.2015 Views

1E9Ct5D

1E9Ct5D

1E9Ct5D

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

an employee of an organization. UnderPIPEDA, organizations are required tocomply with the key principles set out in theModel Code for the Protection of PersonalInformation, which include the following:Accountability: Organizations areresponsible for personal informationunder their control and mustdesignate an individual or individualswho are accountable for theorganization’s compliance with theprinciples set out in PIPEDA.Identifying Purposes: The purposesfor which personal information iscollected must be identified by theorganization at or before the time theinformation is collected.Consent: The knowledge andconsent of the individual arerequired for the collection, use, ordisclosure of personal information,except where inappropriate.Limiting Collection: The collection ofpersonal information must be limitedto that which is necessary for thepurposes identified by theorganization. Information must becollected by fair and lawful means.Limiting Use, Disclosure, andRetention: Personal informationmust not be used or disclosed forpurposes other than those for whichit was collected, except with theconsent of the individual or asrequired by law. Personalinformation must be retained only aslong as necessary for the fulfilmentof those purposes.Accuracy: Personal information mustbe as accurate, complete and up-todateas is necessary for thepurposes for which it is to be used.Safeguards: Personal informationmust be protected by securitysafeguards appropriate to thesensitivity of the information.Openness: Organizations mustmake readily available to individualsspecific information about theirpolicies and practices relating to themanagement of personalinformation.Individual Access: Upon request, anindividual must be informed of theexistence, use, and disclosure of hisor her personal information and mustbe given access to that information.An individual must be able tochallenge the accuracy andcompleteness of the information andhave it amended as appropriate.Challenging Compliance: Anindividual must be able to address achallenge concerning theorganization’s compliance with theabove principles to the designatedindividual or individuals accountablefor the organization’s compliance.The Privacy Commissioner of Canada isresponsible for overseeing theadministration of the legislation andinvestigating and adjudicating complaints.Complaints regarding an organization’scompliance can be filed by any person or bythe Privacy Commissioner. The PrivacyCommissioner has broad powers, includingthe right to conduct audits, undertakeinvestigations, issue subpoenas, compelpersons to give evidence, and enter thepremises of an organization and examine orobtain copies of records relevant to aninvestigation. There is an offence provisionunder PIPEDA with fines for obstructing thePrivacy Commissioner in an investigation orPrivacy Law 84

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!