56

Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Embed Size (px)

Citation preview

Page 1: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA
Page 2: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA
Page 3: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Privacy and Confidentiality at Mohawk College

Page 4: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

FOIFIPPAMFIPPA

PHIPA

PIPEDAIPC

PIATRA

Page 5: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Definition of Privacy

“The right to be let alone” Judge Thomas Thomas

CooleyCooley

“The right to exercise control over your personal information.”

Ann Cavoukian, IPC Ann Cavoukian, IPC ComissionerComissioner

Page 6: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Definition of Confidentiality Ensuring that information is accessible

only to those authorized to have access

Page 7: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

How well do you know our rights to privacy? A quiz …

Page 8: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 1 My name, job title and work phone

number is personal information.

TRUE? FALSE?

Page 9: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 1 My name, job title and work phone

number is personal information.

TRUE FALSE

Page 10: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

False Personal information (PI) is:

Factual or subjective Recorded or not …about an identifiable individual

Page 11: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Personal information includes: Home address Home phone number Home email Photo ID SIN Income Marital status Employment history

Employee number Performance appraisals Financial information Educational credentials Medical records Fund raising records Opinions or views on

the person

Page 12: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

…and of course, the “A” word

“… they even know my age!”

Pat MacdonaldAssociate Dean, Continuing Education

Page 13: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 2 A man phones you asking if his wife is

attending your class. You are allowed to tell him.

TRUE? FALSE?

Page 14: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 2 A man phones you asking if his wife is

attending your class. You are allowed to tell him.

TRUE FALSE

Page 15: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 3 A police officer conducting an

investigation phones you asking if a graduate was registered in a C.E. course. You are allowed to tell her.

TRUE? FALSE?

Page 16: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 3 A police officer conducting an

investigation phones you asking if a graduate was registered in a C.E. course. You are allowed to tell her.

TRUE FALSE

Page 17: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 4 A student about to write an exam does

not have an ID card, so the instructor asks for his SIN card as ID. This is illegal.

TRUE? FALSE?

Page 18: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 4 A student about to write an exam does

not have an ID card, so the instructor asks for his SIN card as ID. This is illegal.

TRUE FALSE

Page 19: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 5 A new student does not yet have her

student ID number, or a driver’s licence, and so you note her health card number as proof of identity. You just broke the law.

TRUE? FALSE?

Page 20: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 5 A new student does not yet have her

student ID card, or a driver’s licence, and so you note her health card number as proof of identity. You just broke the law.

TRUE FALSE

Page 21: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 6 Someone hit your car in the parking lot and

you ask Security if you can view the recording to see the incident. Security tells you that is illegal.

TRUE? FALSE?

Page 22: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 6 Someone hit your car in the parking lot and

you ask Security if you can view the recording to see the incident. Security tells you that is illegal.

TRUE FALSE

Page 23: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 7 A family member arrives at the Front Desk saying

that there has been a death in the family. They want to know what classroom their father is in so that they can inform him. The receptionist cannot give them that information.

TRUE? FALSE?

Page 24: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 7 A family member arrives at the Front Desk saying

that there has been a death in the family. They want to know what classroom their father is in so that they can inform him. The receptionist cannot give them that information.

TRUE FALSE

Page 25: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 8 Sears Security department phones the Associate

Dean of your department and says that they suspect that one of your students has been stalking an employee. They ask if the college can provide a photo to confirm this. The Associate Dean could email an ID photo to help in the investigation.

TRUE? FALSE?

Page 26: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 8 Sears Security department phones the Associate

Dean of your department and says that they suspect that one of your students has been stalking an employee. They ask if the college can provide a photo to confirm this. The Associate Dean could email an ID photo to help in the investigation.

TRUE FALSE

Page 27: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 9 An employer sponsoring one of your

students asks if the student passed the course, so that they can reimburse him. It’s OK to confirm.

TRUE? FALSE?

Page 28: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Question 9 An employer sponsoring one of your

students asks if the student passed the course, so that they can reimburse him. It’s OK to confirm.

TRUE FALSE

Page 29: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

How did you do?

Page 30: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Our privacy is protected by Federal and Provincial

legislation

Page 31: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

The Acts …Legislation Sector Date Fed/Prov

Fed Access to Privacy

Gov. Institutions

1980 Fed

FIPPA Provincial 1987 Prov

MFIPPA Municipal 1991 Prov

PIPEDA Commerce 1999 Fed

PHIPA Health 2004 Prov

Page 32: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Freedom of Information and Protection of Privacy Act (FIPPA)

Safety & Corrections WSIB Community & Social Services District Health Councils Consumer & Business Affairs Ontario Human Rights Colleges and universities

Page 33: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Municipal Freedom of Information and Protection of Privacy Act (MFIPPA)

Municipalities Boards of Education Boards of Health Police Services Public utilities (2,500 in total)

Page 34: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

The College gathers personal information from… Students Staff Donors and clients

and is committed to protecting that information

Page 35: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Information is collected by … Human Resources Payroll Financial Services OH&S Health Services Registrar Continuing Education

Page 36: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

So, what is a record? Any record of information, however

recorded, whether in printed form, on film, by electronic means or otherwise.

Page 37: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Records include … Application forms Registration forms OSAP forms Section lists Class lists Exams Address books Memos Draft memos Agendas

Page 38: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Plus … files on your hard drive files on your iPhone files on your Blackberry your email your voice mail

Page 39: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

and even …

Page 40: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Privacy Laws & College policies dictate how information is:

Collected Used Disclosed Retained Destroyed

Page 41: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Collection: We must have legal authority to collect collect it directly from the person provide a notice of collection, stating the

above and provide the title, business address and telephone number of a college official.

Page 42: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

So what do we have to do?

Safeguard our User Name and Passwords Access records only relevant to our duties Do not disclose personal information to any

unauthorized person Protect personal information of staff and

students

Page 43: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Specifically: Do Protect students’ (and employees’)

information Phone numbers Addresses SIN numbers Employee number Student number Grades and marks

Page 44: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Specifically: email/voice mail Don’t leave PI on voice mail - call back Email should be called epostcard! Assume additional copies exist Assume it will be forwarded

Page 45: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

There was a privacy breach…

What do I do?

Page 46: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

What is a privacy breach? A privacy breach occurs when personal

information (PI) is: Collected Retained Used Disclosed

in ways that are not in accordance with FIPPA.

Page 47: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Most common breaches: Unauthorized disclosure of personal

information, contrary to Sect. 42, for example: a file is misplaced a USB flash drive is lost a form is mailed to the wrong person a document is left in the photocopier a fax is sent to the wrong number an email is sent to the wrong address a document is not disposed of correctly a laptop is stolen

Page 48: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Privacy breach protocol

1. Prevention

2. Scope

3. Containment

4. Notification

5. Investigation

6. Remediation

Page 49: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Prevention 1 Know your department’s procedures on;

Collection Retention Use Disclosure Security Disposal

Page 50: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Prevention 2 Know that you are accountable for the PI in

your custody Do not discuss PI in public places Do not leave documents where they can be

seen by the public Do not disclose PI to those who do not need

to know it Turn your monitor away from the public

Page 51: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Prevention 3 Get written consents before disclosing

PI Know the consequences of a privacy

breach Ensure that documents are shredded

when no longer in use Password protect and/or encrypt data

on your laptop, PDA, Flash drive

Page 52: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Notification Immediately inform

Your boss

Page 53: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Consequences … Compliance orders from IPC Penal offences

Fines ($250K) Possible personal liability ($50K!)

Civil liability Loss of Trust

Page 54: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

In summary …

As a new College employee, you are expected to protect the privacy of individuals and the confidentiality of Personal Information under your control!

Page 55: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

Q & A

Have you any questions, additional examples, comments?

Page 56: Privacy and Confidentiality at Mohawk College FOI FIPPA MFIPPA PHIPA PIPEDA IPC PIA TRA

John Guilfoyle

Director, Corporate Services

Ext. 2174