25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

may take <strong>on</strong>ce pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> <strong>in</strong> their possessi<strong>on</strong> is no l<strong>on</strong>ger required. 702 However, this<br />

guide is not legally b<strong>in</strong>d<strong>in</strong>g <strong>in</strong> nature.<br />

Canada<br />

Accountability <strong>in</strong> relati<strong>on</strong> to privacy is the acceptance of resp<strong>on</strong>sibility for pers<strong>on</strong>al<br />

<strong>in</strong>formati<strong>on</strong> protecti<strong>on</strong>. An organisati<strong>on</strong> which is accountable to <strong>in</strong>dividuals must have <strong>in</strong><br />

place appropriate policies and procedures that promote good privacy practices. 703 The model<br />

code for protecti<strong>on</strong> of pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> c<strong>on</strong>ta<strong>in</strong>ed <strong>in</strong> Schedule 1 of PIPEDA sets out that<br />

an organisati<strong>on</strong> is resp<strong>on</strong>sible for any pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> that is under its c<strong>on</strong>trol. The<br />

organisati<strong>on</strong> must also designate certa<strong>in</strong> <strong>in</strong>dividuals who must be accountable for the<br />

organisati<strong>on</strong>‘s compliance with the <strong>data</strong> protecti<strong>on</strong> obligati<strong>on</strong>s as set out under PIPEDA. 704<br />

PIPEDA also provides that an organisati<strong>on</strong> is not <strong>on</strong>ly resp<strong>on</strong>sible for any pers<strong>on</strong>al<br />

<strong>in</strong>formati<strong>on</strong> that is under its c<strong>on</strong>trol, but is also resp<strong>on</strong>sible for any <strong>in</strong>formati<strong>on</strong> transferred to<br />

a third party for process<strong>in</strong>g. In such situati<strong>on</strong>s, an organisati<strong>on</strong> must ensure that the third party<br />

also provides a comparable level of protecti<strong>on</strong> while process<strong>in</strong>g pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong>. This is<br />

usually ensured by c<strong>on</strong>tractual means. 705<br />

Additi<strong>on</strong>ally, organisati<strong>on</strong>s must implement policies and practices to protect pers<strong>on</strong>al<br />

<strong>in</strong>formati<strong>on</strong>; establish procedures to receive and resp<strong>on</strong>d to compla<strong>in</strong>ts; tra<strong>in</strong> its staff about its<br />

<strong>data</strong> protecti<strong>on</strong> policies and practices. 706 PIPEDA provides that pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> must be<br />

protected by security safeguards appropriate to the sensitivity of the <strong>in</strong>formati<strong>on</strong>. Security<br />

safeguards are <strong>in</strong>tended to protect pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> aga<strong>in</strong>st loss, theft, unauthorised<br />

access, disclosure, copy<strong>in</strong>g, use or modificati<strong>on</strong>. 707 The nature of safeguards, which an<br />

organisati<strong>on</strong> is expected to implement, will be <strong>in</strong> accordance with the nature and sensitivity of<br />

the pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> <strong>in</strong> its possessi<strong>on</strong>. 708 Therefore, it follows that <strong>in</strong>formati<strong>on</strong> of a more<br />

sensitive nature will be safeguarded by a higher level of protecti<strong>on</strong>. PIPEDA also<br />

prescriptively suggests some methods of protecti<strong>on</strong> that may be <strong>in</strong>corporated by an<br />

organisati<strong>on</strong>. For <strong>in</strong>stance, an organisati<strong>on</strong> could utilise physical, organisati<strong>on</strong>al and<br />

technological measures to protect <strong>in</strong>formati<strong>on</strong> <strong>in</strong> its possessi<strong>on</strong>. 709 Organisati<strong>on</strong>s must ensure<br />

that adequate care must be taken while dispos<strong>in</strong>g or destroy<strong>in</strong>g pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong>, <strong>in</strong> order<br />

to prevent unauthorised parties from ga<strong>in</strong><strong>in</strong>g access to the <strong>in</strong>formati<strong>on</strong>. 710 The Office of the<br />

Privacy Commissi<strong>on</strong>er has issued a guidance document to provide organisati<strong>on</strong>s assistance<br />

702 OAIC, ‗Guide to Secur<strong>in</strong>g Pers<strong>on</strong>al Informati<strong>on</strong>: ‗Reas<strong>on</strong>able steps‘ to protect pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong>‘<br />

(January 2015), available at: https://www.oaic.gov.au/resources/agencies-and-organisati<strong>on</strong>s/guides/guide-tosecur<strong>in</strong>g-pers<strong>on</strong>al-<strong>in</strong>formati<strong>on</strong>.pdf,<br />

(last accessed 20 November 2017).<br />

703 Office of the Privacy Commissi<strong>on</strong>er of Canada, ‗Gett<strong>in</strong>g Accountability Right with a Privacy Management<br />

Program‘, available at: https://www.priv.gc.ca/media/2102/gl_acc_201204_e.pdf, (last accessed 20 November<br />

2017).<br />

704 Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />

705 Clause 4.1.3, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />

706 Clause 4.1.4, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />

707 Clause 4.7.1, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />

708 Clause 4.7.2, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />

709 Clause 4.7.3, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />

710 Clause 4.7.5, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />

154

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!