We use cookies to give you the best online experience. By using our website you agree to our use of cookies in accordance with our cookie policy. Learn more here.Close Me
With some exceptions, the Personal Information Protection and
Electronic Documents Act (PIPEDA) requires organizations to provide
individuals with a method of requesting disclosure regarding the
personal information collected about those individuals as well as a
means for correcting that information.
Subject to certain exceptions:
Access requests must be responded to within 30 days.
Individuals must be told what information has been collected,
how it has been used and to whom it has been disclosed.
Individuals must be provided with the opportunity to review the
personal information collected about them at minimal or no
cost.
Records must be corrected if it is factually inaccurate or
incomplete.
It is critically important that staff are trained to recognize
personal information access requests. These requests do not always
come through the "official channels" that have been set
up by organizations, such as an address for the Privacy Officer.
Although the request will be made in writing, it may come to
front-line staff. In addition, organizations should consider
developing a protocol for responding to these requests with a
check-list for ensuring that all relevant sources of data are
reviewed. Access is not limited to documents such as printed
records or electronic word-based files. Personal information can
include photographs and videos as well as electronic information
that is held in multiple locations. A robust records retention
policy can assist organizations in locating records as well as
ensuring that they are appropriately destroyed to limit retention
and, therefore, burdensome access requests.
About Fraser Milner Casgrain LLP (FMC)
FMC is one of Canada's leading business and litigation law
firms with more than 500 lawyers in six full-service offices
located in the country's key business centres. We focus on
providing outstanding service and value to our clients, and we
strive to excel as a workplace of choice for our people. Regardless
of where you choose to do business in Canada, our strong team of
professionals possess knowledge and expertise on regional, national
and cross-border matters. FMC's well-earned reputation for
consistently delivering the highest quality legal services and
counsel to our clients is complemented by an ongoing commitment to
diversity and inclusion to broaden our insight and perspective on
our clients' needs. Visit:
www.fmc-law.com
The content of this article is intended to provide a general
guide to the subject matter. Specialist advice should be sought
about your specific circumstances.
To print this article, all you need is to be registered on Mondaq.com.
Click to Login as an existing user or Register so you can print this article.
A credit union (the "Employer") dismissed a helpdesk analyst (the "Analyst") with cause after discovering the Analyst had, without permission or authorization, remotely accessed another employee’s confidential document stored on the Employer’s network.
With security breaches being on the rise, the requirement to have organizations notify the relevant privacy commissioners and affected individuals upon a security breach taking place is becoming increasingly important.
The Office of the Privacy Commissioner of Canada has announced that the Federal Trade Commission, the UK Information Commissioner’s Office, the OPC and the Office of the Information and Privacy Commissioner for British Columbia and 15 other enforcement authorities worldwide are participating in an "Internet Privacy Sweep".
There are a number of curious features to the Privacy Notice splash page for Canada’s new online tool for making access to information (ATIP) requests.
A ‘massive’ data breach occurred at Hannaford Bros supermarkets over a 3-month period in 2007-08, resulting in the theft of customer financial information.