repetitiveness, and duration of repetitiveness and duration the offence of the violation • The sensitivity of the personal • The sensitivity of the personal information involved information involved • Whether the offender acted • The number of individuals intentionally or with recklessness affected by the violation and or negligence the risk of harm to those • The foreseeability of the individuals. [...] The PIA must be “proportionate to the sensitivity of the information concerned, the purpose for which it is to be used, the quantity and distribution of the information and the medium on which it is stored” (s. [...] An organization must also inform, on request, the individual of: (i) the personal information collected from them, (ii) the categories of employees who have access to the information within the organization, (iii) the duration of the period of time the information will be kept; and (iv) the contact information of the Privacy Officer (s. [...] • An agreement is reached with the other party, stipulating that the latter undertakes: (i) to use the information only for the purpose of completing the commercial transaction; (ii) not to communicate the information without the individual’s consent; (iii) to take the necessary measures to ensure the protection of the confidentiality of the information; and (iv) to destroy the information if the. [...] The new section 21 states that the information may be communicated if a PIA concludes that: (i) the personal information is needed to achieve the objective; (ii) it is unreasonable to require the requesting person or body to obtain consent from the individual concerned; (iii) the objective of the research outweighs the impact on individual privacy in light of the public interest; (iv) the informat.
Related Organizations
- Pages
- 52
- Published in
- Canada
Table of Contents
- Table of Contents 3
- Coming into force 4
- 1. New enforcement mechanisms 6
- Effective September 22 2023 6
- 1.1. Violation 7
- 1.2. Procedural aspects 8
- 1.3. Penalties 9
- 2.1. Privacy Officer 10
- 2. Accountability and governance 10
- Effective September 22 2022 10
- Steps to compliance 11
- Effective September 22 2023 11
- 2.2. Governance policies and practices regarding the protection 11
- Steps to compliance 12
- Effective September 22 2023 13
- 2.3. Privacy Impact Assessments PIAs 13
- Steps to compliance 14
- Effective September 22 2023 15
- 2.4. Privacy settings and privacy by default 15
- Steps to compliance 15
- 3.1. Transparency and obligation to inform prior to consent 16
- 3. Transparency and consent 16
- Effective September 22 2023 16
- Steps to compliance 18
- 3.2. Consent requirements Form validity and minors 19
- Effective September 22 2023 19
- 3.3. Exceptions to the consent requirement 20
- Steps to compliance 20
- Effective September 22 2023 20
- Steps to compliance 22
- Steps to compliance 23
- 4.1. Consent exception for research 24
- 4. Research internal analytics and 24
- Effective September 22 2022 24
- Steps to compliance 26
- 4.2. Consent exception for internal research and analytics 27
- Effective September 22 2023 27
- Steps to compliance 28
- 4.3. Automated decision-making 29
- Effective September 22 2023 29
- Steps to compliance 31
- 5.1. Right to be forgotten 32
- 5. New individual rights 32
- Effective September 22 2023 32
- 5.2. Right to data portability 34
- Effective September 22 2024 34
- 5.3. Right to be informed of and submit observations regarding 35
- Effective September 22 2023 35
- 5.4. Right to request information about data processing 36
- Effective September 22 2023 36
- Steps to compliance 36
- Steps to compliance 37
- 6.1. Outsourcing 38
- Effective September 22 2023 38
- 6. Outsourcing and transfers 38
- Steps to compliance 39
- 6.2. Transfers outside of Québec 40
- Steps to compliance 40
- Effective September 22 2023 40
- Steps to compliance 42
- Steps to compliance 43
- 7.1. Cybersecurity 44
- Effective September 22 2023 44
- 7. Cybersecurity incident management 44
- Steps to compliance 45
- 7.2. Confidentiality incidents 45
- In force September 22 2022 45
- Steps to compliance 49
- 7.3. Biometrics 50
- In force September 22 2022 50
- Steps to compliance 51