white_paper_on_data_protection_in_india_171127_final_v2
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
may take <strong>on</strong>ce pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> <strong>in</strong> their possessi<strong>on</strong> is no l<strong>on</strong>ger required. 702 However, this<br />
guide is not legally b<strong>in</strong>d<strong>in</strong>g <strong>in</strong> nature.<br />
Canada<br />
Accountability <strong>in</strong> relati<strong>on</strong> to privacy is the acceptance of resp<strong>on</strong>sibility for pers<strong>on</strong>al<br />
<strong>in</strong>formati<strong>on</strong> protecti<strong>on</strong>. An organisati<strong>on</strong> which is accountable to <strong>in</strong>dividuals must have <strong>in</strong><br />
place appropriate policies and procedures that promote good privacy practices. 703 The model<br />
code for protecti<strong>on</strong> of pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> c<strong>on</strong>ta<strong>in</strong>ed <strong>in</strong> Schedule 1 of PIPEDA sets out that<br />
an organisati<strong>on</strong> is resp<strong>on</strong>sible for any pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> that is under its c<strong>on</strong>trol. The<br />
organisati<strong>on</strong> must also designate certa<strong>in</strong> <strong>in</strong>dividuals who must be accountable for the<br />
organisati<strong>on</strong>‘s compliance with the <strong>data</strong> protecti<strong>on</strong> obligati<strong>on</strong>s as set out under PIPEDA. 704<br />
PIPEDA also provides that an organisati<strong>on</strong> is not <strong>on</strong>ly resp<strong>on</strong>sible for any pers<strong>on</strong>al<br />
<strong>in</strong>formati<strong>on</strong> that is under its c<strong>on</strong>trol, but is also resp<strong>on</strong>sible for any <strong>in</strong>formati<strong>on</strong> transferred to<br />
a third party for process<strong>in</strong>g. In such situati<strong>on</strong>s, an organisati<strong>on</strong> must ensure that the third party<br />
also provides a comparable level of protecti<strong>on</strong> while process<strong>in</strong>g pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong>. This is<br />
usually ensured by c<strong>on</strong>tractual means. 705<br />
Additi<strong>on</strong>ally, organisati<strong>on</strong>s must implement policies and practices to protect pers<strong>on</strong>al<br />
<strong>in</strong>formati<strong>on</strong>; establish procedures to receive and resp<strong>on</strong>d to compla<strong>in</strong>ts; tra<strong>in</strong> its staff about its<br />
<strong>data</strong> protecti<strong>on</strong> policies and practices. 706 PIPEDA provides that pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> must be<br />
protected by security safeguards appropriate to the sensitivity of the <strong>in</strong>formati<strong>on</strong>. Security<br />
safeguards are <strong>in</strong>tended to protect pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> aga<strong>in</strong>st loss, theft, unauthorised<br />
access, disclosure, copy<strong>in</strong>g, use or modificati<strong>on</strong>. 707 The nature of safeguards, which an<br />
organisati<strong>on</strong> is expected to implement, will be <strong>in</strong> accordance with the nature and sensitivity of<br />
the pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> <strong>in</strong> its possessi<strong>on</strong>. 708 Therefore, it follows that <strong>in</strong>formati<strong>on</strong> of a more<br />
sensitive nature will be safeguarded by a higher level of protecti<strong>on</strong>. PIPEDA also<br />
prescriptively suggests some methods of protecti<strong>on</strong> that may be <strong>in</strong>corporated by an<br />
organisati<strong>on</strong>. For <strong>in</strong>stance, an organisati<strong>on</strong> could utilise physical, organisati<strong>on</strong>al and<br />
technological measures to protect <strong>in</strong>formati<strong>on</strong> <strong>in</strong> its possessi<strong>on</strong>. 709 Organisati<strong>on</strong>s must ensure<br />
that adequate care must be taken while dispos<strong>in</strong>g or destroy<strong>in</strong>g pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong>, <strong>in</strong> order<br />
to prevent unauthorised parties from ga<strong>in</strong><strong>in</strong>g access to the <strong>in</strong>formati<strong>on</strong>. 710 The Office of the<br />
Privacy Commissi<strong>on</strong>er has issued a guidance document to provide organisati<strong>on</strong>s assistance<br />
702 OAIC, ‗Guide to Secur<strong>in</strong>g Pers<strong>on</strong>al Informati<strong>on</strong>: ‗Reas<strong>on</strong>able steps‘ to protect pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong>‘<br />
(January 2015), available at: https://www.oaic.gov.au/resources/agencies-and-organisati<strong>on</strong>s/guides/guide-tosecur<strong>in</strong>g-pers<strong>on</strong>al-<strong>in</strong>formati<strong>on</strong>.pdf,<br />
(last accessed 20 November 2017).<br />
703 Office of the Privacy Commissi<strong>on</strong>er of Canada, ‗Gett<strong>in</strong>g Accountability Right with a Privacy Management<br />
Program‘, available at: https://www.priv.gc.ca/media/2102/gl_acc_201204_e.pdf, (last accessed 20 November<br />
2017).<br />
704 Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />
705 Clause 4.1.3, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />
706 Clause 4.1.4, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />
707 Clause 4.7.1, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />
708 Clause 4.7.2, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />
709 Clause 4.7.3, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />
710 Clause 4.7.5, Pr<strong>in</strong>ciple 1 of Schedule 1, PIPEDA.<br />
154