FIPPA and CASL Overview

Slides:



Advertisements
Similar presentations
Bill c CASL Effects of the Canadian Anti-Spam Legislation (CASL) at Skate Canada.
Advertisements

International Telecommunication Union HIPSSA Project Support for Harmonization of the ICT Policies in Sub-Sahara Africa, Meeting with the Tanzanian ICT.
Gaucho Round-Up FAQ’s This presentation covers some of the FAQ’s about campus clean-up day. Presentation #4 2/3/
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
HIPAA Health Insurance Portability and Accountability Act 1.
Legal Framework for Information Sharing in Organ Donation and Transplantation Alexandra K. Glazier, Esq. VP & General Counsel New England Organ Bank.
2014 HIPAA Refresher Omnibus Rule & HIPAA Security.
One university. Many futures. The University of Manitoba FIPPA and PHIA at University of Manitoba Access & Privacy Coordinator’s Office.
Christian Vargas. Also known as Data Privacy or Data Protection Is the relationship between collection and spreading or exposing data and information.
© Information and Privacy Commissioner of Ontario, 2006 Circle of Care Ontario University & College Health Association - May 24, Manuela Di Re Associate.
1 GRAND VALLEY STATE UNIVERSITY FAMILY EDUCATIONAL RIGHTS & PRIVACY ACT (FERPA) TRAINING OFFICES OF THE REGISTRAR AND UNIVERSITY COUNSEL JANUARY 20, 2009.
New Canadian Anti-Spam Legislation Robert Lipson – April 8, 2014.
BC Freedom of Information and Protection of Privacy Act
Taking Steps to Protect Privacy A presentation to Hamilton-area Physiotherapy Managers by Bob Spence Communications Co-ordinator Office of the Ontario.
Canada’s Anti Spam Legislation. What is CASL? CASL was intended to combat negative online behaviour  spam  phishing  malware  spyware  It will create.
Coding Compliance Plan July 12, Benefits of a compliance program  To demonstrate our commitment to honest and responsible conduct, decrease the.
Privacy & Personal Information Prepared by the CBC Law Department CONFIDENTIAL – FALL 2011.
Part 6 – Special Legal Rights and Relationships Chapter 35 – Privacy Law Prepared by Michael Bozzo, Mohawk College © 2015 McGraw-Hill Ryerson Limited 34-1.
Student Data and Confidentiality Parents Rights Schools’ Responsibilities.
IT Applications Theory Slideshows By Mark Kelly Vceit.com Privacy Laws.
IM NETWORK MEETING 20 TH JULY, 2010 CONSULTATION WITH 3 RD PARTIES.
Supervision SICOR Securities, Inc.. Why? NASD 3110 requires the firm to “…establish and maintain a system to supervise the activities of each registered.
The Protection of Personal Information Bill 13 February
Serving the Public. Regulating the Profession. CANADA’S ANTI-SPAM LEGISLATION (CASL) Training for Chapters Based on Guidelines for Chapters First published.
Table of Contents. Lessons 1. Introduction to HIPAA Go Go 2. The Privacy Rule Go Go.
Privacy and Personal Information. WHAT YOU WILL LEARN: What personal information is. General guidelines for the collection of personal information. Your.
Protection of Personal Information Act An Analysis on the impact.
Understanding Privacy An Overview of our Responsibilities.
TRANSBORDER DATA FLOWS INA MEIRING. THE PROTECTION OF PERSONAL INFORMATION ACT (“POPI”) > 'personal information' means information relating to an identifiable,
Effect of Corporate IT Policies on Otherwise Privileged Communication By: Jonathan T. Barton.
Understanding Privacy An Overview of our Responsibilities.
Rights and responsibilities of providers and individuals
PAC Constitution & Bylaws
CANADA’S ANTI-SPAM LEGISLATION (CASL)
Documenting Life in the UK
Privacy Education Session CMHA-WECB/CCHC Volunteers/Students
Data Protection: The Law
2015 Orientation to HIPAA Privacy Rule Compliance
Communication and Cultural Diversity
Patient Encounters and Billing Information Chapter 3
Privacy principles Individual written policies
IT Applications Theory Slideshows
Privacy principles Individual written policies
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
Privacy & Access to Information
2016 Annual CPNI Training CPNI & PI Awareness Beth Slough,
is not secure is not secure..
Current Privacy Issues That May Affect Your Credit Union
2017 College of Medicine Compliance & Privacy R
Welcome to the FERPA training for Faculty and Staff.
Move this to online module slides 11-56
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
Compliance….GlobalSearch……WHAT?!?!
GDPR (General Data Protection Regulation)
Vocabulary and Interview Questions
IMPLICATIONS OF GDPR ROBERT BELL.
MAINTAINING DONORS Grantsmanship and Fundraising
Introduction to Employment and Employee Relations
Equality ……… is the current term for ‘Equal Opportunities’. It is based on the legal obligation to comply with anti-discrimination legislation. Equality.
HIPAA Overview.
PERSONAL INFORMATION BILL
The Health Insurance Portability and Accountability Act
GDPR – General Data Protection Regulation
Good Spirit School Division
BCS Template Presentation February 22, 2018
General Data Protection Regulation Q & A Session
Move this to online module slides 11-56
Ontario’s privacy protective Philadelphia model governance framework
Presentation transcript:

FIPPA and CASL Overview What we need to do to ensure we are in compliance with the Privacy Commissioner of Ontario (IPC) based on FIPPA (Freedom on Information and Protection of Privacy Act) and Electronic Communications

FIPPA Outline The Act requires that government institutions (UofG) protect the privacy of an individual’s personal information existing in our records. It also gives individuals the right to request access to AA&D information, including general records and records containing their own personal information. This includes deceased’s personal information for 30 years.

Personal information “means recorded information about an identifiable individual” a. information relating to the race, national or ethnic origin, colour, religion, age, sex, sexual orientation or marital or family status of the individual, b. information relating to the education or the medical, psychiatric, psychological, criminal or employment history of the individual or information relating to financial transactions in which the individual has been involved, c. any identifying number, symbol or other particular assigned to the individual, d. the address, telephone number, fingerprints or blood type of the individual, e. the personal opinions or views of the individual except where they relate to another individual, f. correspondence sent to an institution by the individual that is implicitly or explicitly of a private or confidential nature, and replies to that correspondence that would reveal the contents of the original correspondence, g. the views or opinions of another individual about the individual, and h. the individual’s name where it appears with other personal information relating to the individual or where the disclosure of the name would reveal other personal information about the individual" Personal information does not include information about an individual who has been dead for more than thirty (30) years.

FIPPA includes: Rules regarding the collection, retention, use, disclosure and disposal of personal information in its custody or control. Collection = We are allowed to collect data through the fundraising effort requirements of the University of Guelph. Use = We must ensure that our usage is for fundraising purposes only. This can be construed as many efforts (reunions, e-news, events, etc) but we must be able to prove this rationale. This is the reason for the mailing component on IRF and ERF form, to ensure we are meeting the acceptable USE clause. Disclosure = We track and document every time we share someone’s information with external entities from AA&D. This is the purpose of the IRF and ERF.

Anti-Spam Legislation in Canada – Bill C28 (CASL) Outline Please adhere to the following: Ensure we are only contacting people whom we have a proven business relationship. This basically includes donors and alumni. We do not have authority to contact other people. All non 1:1 emails (or personal emails) MUST provided simple, immediate and clear unsubscribe mechanisms (ie. manage your subscriptions link). This is why we use a centralized marketing system called Luminate Online (LO) for ALL mass emails. LO is also linked for tracking of interactions within CRM. We need to adhere to individual preferences that have been relayed to us within an appropriate amount of time. DO NOT REUSE any list older than 2 weeks without asking the IS team to re-run for contact restriction updates. Also, all lists requests should include restrictions based on your business usage.