Private Sector Flashcards

1
Q

What is PIPDEA

A

Federal privacy law that governs the collection, use, and disclosure of personal information by private sector for commercial purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the situations where the PIPDEA does not apply

A

Government institutions
Personal or domestic purpose
Journalist, artistic or literary purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

PIPEDA does not apply to Quebec, Alberta, and BC unless when ?

A

It is a federal work (banks, telecom)
The personal information crosses provincial borders in the course of commercial activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When a province has a legislation that matches PIPEDA, what does it have to do?

A

Communicate with the industry Canada (innovation, science, and economic development Canada). They may consult with OPC to access the alignment between PIPEDA and provincial law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PIPEDA does not apply to what type of info?

A

Does not apply to information that is publicly available and can be found is publications.

Information for the purpose of communication with the individual in relation to their employment, business, or profession

Certain organizations, such as investigative bodies and organizations in regulated professions

Collection of personal information for the purpose of establishing, managing, or terminating an employment,

Collection of personal information if it is part of business transaction.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the privacy principles under PIPEDA

A

Accountability,
Consent
Identifying purpose
Limiting collection of information
Limting use, disclosure and retention
Accuracy
Safeguard
Openness
Individual access
Challenging compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the legal grounds in Alberta’s Personal Information Protection Act (PIPA) for use, disposal and retention of personal data

A

Vital interest, legal obligation, and performance of labor contract as consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What type of consent is required in BC’s PIPA ?

A

Explicit or implied before data collection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Does BC’s PIPA differ to PIPEDA where federal jurisdictions prevail

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Can organizations outsource their privacy obligations

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Does BC’s PIPA presides over conflicting provincial law

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What province’s health privacy laws are similar to PIPEDA

A

Ontario
New foundland and Labrador
New Brunswick
Nova Scotia

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does PIPEDA Accountability principle mean

A

Ensuring there is a designated position handling matters
Responsible for 3rd party processing
Implementation of policies and practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is PIPEDA’s identifying purpose

A

The identifying purpose for which the information is collected must be identified by the organization at/before the time to data collection

Purposes must be documented, identified at collection, new purpose identified, and explanation of collection purpose.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the principles of PIPEDA Consent

A

Freely given
Consent at the time of collection
Informed and knowledgeable
Withdrawal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Under PIPEDA, when can personal information be collected, used, or disclosed without the knowledge and consent of the individual

A

Emergencies
Detection and prevention of fraud or law enforcement
Minor or mentally incapacitated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the fine amount for PIPEDA

A

10k for summary conviction or 100k for indictable offenses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Risk associated with non compliance

A

Complaints and investigation
Public disclosure
Legal remedies
Financial loss
Risk of class action lawsuits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What are the three types of breach notification

A

Notification to OPC, individual and other organizations

20
Q

What provinces health legislation is similar to PIPEDA

A

New Brunswick
Ontario
Newfoundland and Labrador
Nova Scotia

21
Q

What provinces refer to entities managing personal health info as Custodians

A

Alberta
Nova Scotia
Newfoundland and Labrador
New Brunswick

22
Q

What provinces refer to entities managing personal health info as trustee

A

Manitoba
Saskatchewan

23
Q

Ontario PHIPA applies to what

A

Gathering of personal health data by custodians
Usage and sharing of data
Handling of a health number by any custodians

24
Q

Is Timeframe of when the info is received relevant under ON PHIPA

A

Timeframe of when the information was received is irrelevant under ON PHIPA

25
Does PHIPA and its regulation take precedence over other legislative acts and regulations
Yes
26
What is the information Commissioner of Canada responsible for ?
Overseeing compliance with the Access to Information Act ensure transaperacy and accountability within the federal government by investigating complaints from individuals who have been denied access to government records or information
27
The privacy commissioner is responsible for administering what Acts?
PIPDEA and Privacy Act
28
is the privacy commissioner an administrative tribunal ?
no, it is an agent of Parliament embodying independence and accountability
29
Who is governed by the Privacy Act
Federal government entities handling the collection, use, and sharing of personal information of individuals
30
what organizations are excluded from the privacy Act
political parties, private organizations, and court
31
what type of personal information are excluded as personal information in the privacy act
20 years old information on deceased individuals, ministerial advisers, government employee, contractors, and discretionary financial benefits
32
What are the parameters for consent under the Privacy Act
original purpose of collection, consistent use, and nonconsensual disclosure
33
Under the Privacy Act, what is the process for requesting access to personal information
A request has to be made in writing and attended to within 30 days
34
What are the 13 exemptions key areas to access information under the a Privacy Act.
solicitor-client privilege; national security and law enforcement; federal-provincial harm; less than 20 years of info related to law enforcement; 3rd party or individual harm
35
In what scenarios can govt disclose personal info
original purpose; internal audits; lib archives; court subpoena/warrents; act of parliament purpose/investigative body; parliament; statistical purpose if the head of govt approves; aboriginal govt; debt owing to the crown
36
What is the CASL
An act to promote the efficiency and adaptability of the Canadian economy by and revolves around a range of electronic communication
37
Who is binded by the CASL
Corporations operating as an agent of the Her Majesty for commercial activities and non-profit organizations and registered charities.
38
What is the territorial scope of the CASL
It is inclusive of any CEM that is either dispatched from or received by the a system in Canada
39
What is a commercial electronic message according to the CASL
Any electronic message with content that encourages participation in a commercial activity. This includes offer to sell, advertise and promote business, persons or images
40
What are the exceptions to CEM
Electronic messages sent for the purpose of law enforcement, public safety, international affairs/defense of Canada, and protection of Canada.
41
What are the content requirement of a message under CASL
1) Contact information of the sender or entity on whose behalf the message was sent. It has to be valid for a minimum of 60 days 2) conform to prescribed requirement under the legislation. 3) identification of the sender and the entity on whose behalf it was sent. 4) unsubscribe link valid for at least 60 days . request to unsubscribe must be acted on within 10 days and the unsubscribe process must be straightforward
42
The CASL rules does not apply to
personal/ family business information specific classes or circumstances
43
who is responsible for enforcing the CASL
Competition Breau, Office of Privacy Commissioner, the Canadian radio-television and Telecommunication Commission (CRTC)
44
What are the penalties to non-compliance under the CASL
1 Million for individual and up to 10Million for businesses
45
Under the Privacy Act what is considered personal information
identifying number, race name address, biometric O
46
What province have similar privacy laws to PIPEDA
Bc, Alberta, Quebec