PIPEDA and Receivables Management Robin Gould-Soil Receivables Management Association of Canada November 16, 2011
Source: Chris Slane ( 1
OPC oversees the Personal Information Protection and Electronic Documents Act (PIPEDA) Governs federally regulated private sector “Substantially similar” legislation in Quebec, Alberta and BC, and in Ontario for health information First decade of PIPEDA has passed, expectations for compliance are high Privacy Protection Framework in Canada 2
OPC proactive on several fronts: Investigations Research and monitoring Outreach Collaboration Regulator Vigilance: More Vital Than Ever 3
Privacy Principles 1.Accountability 2.Identifying Purposes 3.Consent 4.Limiting Collection 5.Limiting Use, Disclosure and Retention 6.Accuracy 7.Safeguards 8.Openness 9.Individual Access 10.Challenging Compliance 4
Exceptions to Knowledge or Consent Collection Use Disclosure 5
Over-sharing Third party accountability Over-collection Privacy & Receivables Mgmt: Issues & Challenges 6
Over-sharing Third party accountability Over-collection Information Accuracy Access requests Cross border transfers Privacy & Receivables Mgmt: Issues & Challenges Consent 7
Privacy should not be viewed as a restriction that negatively impacts the way you do business While extending credit and collecting from current and delinquent customers, their personal information must still be protected Need to find right balance of business needs and privacy rights Wide range of collection activities can be implemented in a privacy-sensitive way Finding the Right Balance 8
→Tools and guidelines: – Securing Personal Information: Self-Assessment Tool – Privacy for Small Business Online Tool – Privacy Handbook for Lawyers – PIPEDA Self-Assessment Tool – And more Support for Business 9
→Tools and guidelines: – Securing Personal Information: Self-Assessment Tool – Privacy for Small Business Online Tool – Privacy Handbook for Lawyers – PIPEDA Self-Assessment Tool – Etc. →New Toronto office →Technology Analysis Branch Support for Business (cont’d) 10
On the Legislative Front 11 Bill C-12
On the Legislative Front (cont’d) 12 Bill C-12 PIPEDA Review II
1)Leadership on priority issues o Online privacy o Public safety 2)Supporting informed privacy decisions 3)Service delivery to individual Canadians OPC Priorities for
Ensure your privacy protection standards are high Employee training is key Don’t over-collect Implement data de-identification applications for system administration and analytics Continually review policies and practices Engage with OPC/other regulators, take advantage of guidance tools Closing Words 14