11.05.2016 Views

Consent and privacy

consent_201605_e

consent_201605_e

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

In order for consent to be considered meaningful under PIPEDA, individuals should have a clear underst<strong>and</strong>ing<br />

of what will be collected, how their personal information will be used, <strong>and</strong> with whom it will be shared.<br />

<strong>Consent</strong> is only valid if it is reasonable to expect that an individual to whom the organization’s activities are<br />

directed would underst<strong>and</strong> the nature, purpose <strong>and</strong> consequences of the collection, use or disclosure of the<br />

personal information to which they are consenting. 11<br />

Recognizing organizations’ need to collect, use <strong>and</strong> disclose personal information for reasonable purposes,<br />

PIPEDA also contains a number of exceptions to the requirement for knowledge <strong>and</strong> consent, based on the<br />

reality that obtaining individuals’ consent may not be appropriate in every circumstance. For example,<br />

information may be used or disclosed without consent in an emergency that threatens the life, health or<br />

security of an individual. Some other exceptions include investigating a breach of an agreement or<br />

contravention of a law where seeking consent might compromise an ongoing investigation. Such exceptions<br />

recognize that individual consent, <strong>and</strong> the autonomy it protects, do not override all other interests, but rather<br />

that there needs to be a balance between <strong>privacy</strong> <strong>and</strong> competing values which individual consent might<br />

undermine. 12 In this sense, as is discussed below, PIPEDA already recognizes, <strong>and</strong> accommodates, both<br />

limitations inherent in the consent principle. Certain statutory obligations apply even if consent is not<br />

required. For example, subsection 5(3) of PIPEDA limits the purposes for which an organization may collect,<br />

use or disclose personal information to those that “a reasonable person would consider are appropriate in the<br />

circumstances.” This helps ensure that individuals remain protected from inappropriate collection, use <strong>and</strong><br />

disclosure of their personal information even if an individual consents or where consent is not required. 13 All<br />

other PIPEDA principles, such as safeguards <strong>and</strong> accountability, also continue to apply even where consent is<br />

not required.<br />

PIPEDA requires that the purposes for which an individual’s information is to be collected, used or disclosed be<br />

explained in a clear <strong>and</strong> transparent manner. <strong>Consent</strong> must be obtained before or at the time of collection, or<br />

when a new use of personal information has been identified. Organizations may not deny a product or service<br />

to an individual who fails to consent to the collection, use or disclosure of information beyond that required to<br />

fulfill an explicitly specified <strong>and</strong> legitimate purpose. At the same time, individuals should be informed of the<br />

consequences of withdrawing consent, particularly if they are withdrawing consent to a collection, use or<br />

disclosure of their personal information that is essential to the service they are signing up for.<br />

PIPEDA recognizes that the form of consent can vary, taking into account the sensitivity of the information <strong>and</strong><br />

the reasonable expectations of the individual. Express consent is the most appropriate <strong>and</strong> respectful form of<br />

consent to use generally, <strong>and</strong> is required when sensitive 14 information is at issue. Implied consent can be<br />

acceptable in strictly defined circumstances. 15<br />

_____________________________________________________________________________________________________<br />

30 Victoria Street – 1st Floor, Gatineau, QC K1A 1H3 • Toll-free: 1-800-282-1376 • Fax: (819) 994-5424 • TDD (819) 994-6591<br />

www.priv.gc.ca • Follow us on Twitter: @<strong>privacy</strong>privee<br />

3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!