Qortora · Search · Indexed page

www.tbs-sct.canada.caFetched 2026-08-15T10:57:07Z

Policy on Privacy Protection- Canada.ca

Policy on Privacy Protection- Canada.ca Privacy Act."> Privacy Act."> Skip to main content Skip to "About this site" Policy on Privacy Protection This policy provides direction to government institutions to ensure compliance with the Privacy Act. Date modified: 2024-11-08 Support…

Open original source · Full cached text

Policy on Privacy Protection- Canada.ca Privacy Act."> Privacy Act."> Skip to main content Skip to "About this site" Policy on Privacy Protection This policy provides direction to government institutions to ensure compliance with the Privacy Act. Date modified: 2024-11-08 Supporting tools Directive: Personal Information Requests and Correction of Personal Information, Directive on Privacy Practices, Directive on Social Insurance Number, Directive on More information Terminology: Glossary Topic: Access to information and privacy Hierarchy Foundation Framework for Treasury Board Policies Policy on Privacy Protection Personal Information Requests and Correction of Personal Information, Directive on Privacy Practices, Directive on Social Insurance Number, Directive on View complete hierarchy Archives This policy replaces: Privacy Protection, Policy on [2022-07-22] Privacy Protection, Policy on [2022-10-26] View all inactive instruments Print-friendly XML Expand all Collapse all 1. Effective date 1.1This policy takes effect on October 9, 2024. 1.2This policy replaces the Policy on Privacy Protection dated October 26, 2022. 2. Authorities 2.1This policy is issued pursuant to paragraph 71(1)(d) of the Privacy Act (the Act). This policy also contains elements that relate to paragraphs 71(1)(b) and (e) of the Act. 2.2The President of the Treasury Board, as designated Minister for the paragraphs of the Act referenced in section 2.1 above, is responsible for establishing policies and prescribing forms concerning the operation of the Act and its Regulations. 3. Objectives and expected results 3.1The objectives of this policy are as follows: 3.1.1Canadians have confidence that the government is protecting their privacy with regard to their personal information; 3.1.2Canadians have confidence that they can access their personal information that is under the control of government institutions; 3.1.3Personal information under the control of government institutions is effectively protected and managed through identifying, assessing, monitoring and mitigating privacy risks in programs and activities involving the collection, creation, retention, use, disclosure and disposal of personal information; 3.1.4Government institutions are accountable and transparent in the protection and management of personal information and in their response to privacy breaches; and 3.1.5Privacy considerations are incorporated into programs or activities at the design stage and are integrated into the governance and administration of programs involving the creation, collection, retention, use, disclosure and disposal of personal information. 3.2The expected results of this policy are as follows: 3.2.1Government institutions have appropriate processes and tools to support the administration of the Act; 3.2.2Government institutions offer requesters easily accessible mechanisms to make personal information requests; 3.2.3Government institutions provide complete, accurate and timely responses to requests for personal information or correction of personal information; 3.2.4Employees understand their obligations under the Act; and 3.2.5Performance is measured, and compliance issues are identified and addressed. 4. Requirements 4.1Heads of government institutions are responsible for the following: 4.1.1Deciding whether to delegate, pursuant to section 73 of the Act, any of the powers, duties or functions under the Act that are listed in Appendix B: Powers That Can Be Delegated; 4.1.2When signing a delegation order, giving careful consideration to the delegation of any powers, duties or functions pursuant to section 73 of the Act and ensuring that: 4.1.2.1Powers, duties and functions are: 4.1.2.1.1Delegated only to officers and employees of their government institution or of another government institution within the same ministerial portfolio when there is a service-sharing agreement between the two government institutions; 4.1.2.1.2Not delegated to consultants, members of a Minister’s exempt staff, employees of other government institutions with which there is no service-sharing agreement, or to individuals from the private sector; and 4.1.2.1.3Delegated to positions identified by title, not to individuals identified by name; 4.1.2.2Delegates understand that they are accountable for any decisions they make but that ultimate responsibility remains with the head of the government institution; 4.1.2.3Delegates are at the appropriate level to be able to fulfill the duties of their delegated authorities and are well informed of their responsibilities; 4.1.2.4Delegates cannot further delegate powers, duties and functions that have been delegated to them, although employees and consultants may perform tasks in support of delegates’ responsibilities; and 4.1.2.5Delegation orders are reviewed when the circumstances surrounding the delegations have changed. A delegation order remains in force until it is replaced. 4.2Heads of government institutions or their delegates are responsible for the following: 4.2.1Ensuring that employees of the government institution are aware of policies, procedures and legal responsibilities under the Act; 4.2.2Notifying the Treasury Board of Canada Secretariat (TBS) and the Office of the Privacy Commissioner of Canada (OPC) of any planned initiatives (legislation, regulations, policies or programs) that could relate to the Act or to any of its provisions, or that may have an impact on the privacy of individuals. This notification is to take place at a sufficiently early stage to permit TBS and the OPC to review and discuss the issues involved while respecting Cabinet confidences; 4.2.3Ensuring compliance with the specific terms and conditions related to the use of the Social Insurance Number and the specific restrictions regarding its collection, use and disclosure as set out in the Directive on Social Insurance Number; 4.2.4Ensuring that personal information banks (PIBs) are prepared and updated, as required by section 10 of the Act; 4.2.5Obtaining the approval of the President of the Treasury Board to establish, modify or terminate a PIB, unless otherwise specified in the terms and conditions of a delegation under subsection 71(6) of the Act; 4.2.6Ensuring that TBS is consulted on any proposal to establish or terminate an exempt bank; and 4.2.7Ensuring that the TBS-prescribed repository of PIBs is updated for new, modified or terminated PIBs; 5.1This section identifies other key government organizations in relation to this policy. In and of itself, this section does not confer any authority. 5.2TBS is responsible for supporting the President of the Treasury Board in: 5.2.1Issuing direction and guidance to government institutions with respect to the administration of the Act and the interpretation of this policy and its supporting instruments; 5.2.2Approving exceptions to any requirement in this policy or its supporting instruments; 5.2.2.1Advising the OPC of any exceptions to any requirement in this policy or its supporting instruments that have been granted that could relate to the Act or to any of its provisions, or that may have an impact on the privacy of Canadians; 5.2.3Prescribing forms and platforms to be used in the administration of the Act, as well as the form and content of the annual report to Parliament; 5.2.4Reviewing regularly, or at least every five years, this policy and its related directives, guidelines, forms and prescribed platforms to assess their continued effectiveness and accuracy. When substantiated by risk analysis, TBS will also ensure that an evaluation is conducted; 5.2.5Overseeing compliance with this policy and its supporting instruments across government institutions, leveraging existing reporting mechanisms as appropriate; 5.2.6Receiving and reviewing material privacy breach reports; 5.2.7Advising institutions on the management of multi-institutional privacy breaches that require a coordinated response; 5.2.8Designating the repository for PIBs for all new or modified PIBs; 5.2.9Publishing annually an index of personal information under the control of government institutions that is confirmed to be up to date; 5.2.10Reviewing new and modified PIBs and assigning a registration number to new PIBs; and 5.2.11Working with the Canada School of Public Service to integrate knowledge elements related to the Act and associated policy instruments into training courses, programs and knowledge assessment instruments. 5.3The Privacy Commissioner of Canada is an Agent of Parliament with the duty of protecting and promoting privacy rights and is responsible for the following: 5.3.1Receiving and independently investigating complaints from individuals or self-initiated complaints on any matter related to the handling of personal information by federal government institutions; 5.3.2Issuing findings and any recommendations that the Commissioner considers appropriate, in relation to investigations where a complaint is well founded, to the head of the government institution; 5.3.3Communicating the outcomes of investigations to the complainant; 5.3.4Receiving and reviewing material privacy breach reports; 5.3.5Conducting compliance reviews of the privacy practices of government institutions as the practices relate to the collection, retention, accuracy, use, disclosure and disposal of personal information by government institutions subject to the Act; and 5.3.6Reporting to Parliament on activities annually. The Privacy Commissioner can also report at any time on any important matter within the scope of the Commissioner’s powers, duties and functions. 5.4The Clerk of the Privy Council Office is responsible for ensuring the integrity of the Cabinet process and the stewardship of the documents that support this process. As custodian of the confidences of the King’s Privy Council for Canada of the current and previous ministries, the Clerk is responsible for policies on the administration of these confidences and for the ultimate determination of what constitutes such confidences and must be consulted in a manner consistent with the guidance in the Personal Information Request Manual. 5.5The Department of Justice Canada is responsible for supporting the Minister of Justice in the role of designated Minister for certain provisions of the Act, specifically: 5.5.1Designating, by order-in-council, the head of a government institution for the purposes of the Act; 5.5.2Recommending extensions of the right of access by order-in-council; 5.5.3Specifying in regulations the government institutions or part of a government institution for the purpose of paragraph (e) of the definition of personal information in section 3 of the Act; 5.5.4Specifying investigative bodies and classes of investigations; 5.5.5Specifying persons or bodies for the purposes of paragraph 8(2)(h); 5.5.6Specifying classes of investigations for the purpose of paragraph 22(3)(c); and 5.5.7Amending the Schedule of the Act. 6. Application 6.1This policy and its supporting instruments apply to government institutions as defined in section 3 of the Act, including departments, ministries of state, any parent Crown corporations and any wholly owned subsidiary of these corporations. 6.2This policy does not apply to the Bank of Canada. 7. Consequences of non-compliance 7.1For government institutions that do not comply with this policy and its related instruments, there may be a requirement to provide additional information on the development and implementation of compliance strategies in their annual report to Parliament or to TBS directly. This reporting may be in addition to other reporting requirements. 7.2TBS will work collaboratively with heads of institutions or their delegates to restore compliance. 7.3On the basis of analysis of monitoring and information received, the President of the Treasury Board may make recommendations to the head of the government institution. Such recommendations could include that t…