ITBusiness.ca

The essential elements of protecting personal data

Image of lock on keyboard


When it comes to personal data protection, some companies are having difficulty fulfilling their obligations properly. Here are a few ideas and some advice to enable you to properly manage sensitive information.

by François Daigle Director, Professional services and trainingOkiok Data


When it comes to personal data protection, some companies are having difficulty fulfilling their obligations properly. Here are a few ideas and some advice to enable you to properly manage sensitive information.

by François Daigle Director, Professional services and trainingOkiok Data


Advice no. 1: control the inventory

Collecting customer’s personal information is easily accomplished through Web forms, but you should be aware of the potential pitfalls of maintaining these records.


Rule no. 2: someone in charge

Choose a person within the organization to coordinate data collection, even if it’s not a full-time job. That person should know the disclosure laws and be familiar with legislation like PIPEDA (Personal Information Protection and Electronic Documents Act)


Advice no. 2: choose your data manager wisely

Some organizations will prefer outsourcing those responsibilities. They should make sure they choose a partner who fully understands their privacy compliance and management issues.


Rule no. 3: write a policy

It’s important to create a privacy policy for information management that includes protection of personal data. The precise wording depends on the industry and the relationship the company has with its customers.


Advice no. 3: write a policy that is simple

A privacy policy doesn’t need to be long and complex. The longer it is, the less it will be read and the more difficult it will be to implement and follow.


Rule no. 4: make sure you have consent

A corporation always needs to have the consent of its customers (or employees) before using their personal data. The consent must be explicit and explicitly given.


Advice no. 4: the consent is limited

Keep in mind that the consent a customer gives to collect his/her information is limited in scope and can only be used for a specific purpose. Personal data given by someone to participate in a contest cannot be used later to invite that person to a seminar.


The fifth element: a golden rule

Personal data disclosed by someone who doesn’t belong to the company cannot be shared without that person’s consent. The company receiving the data has the right of use but not the right of property. The person/customer disclosing the information, on the other hand, holds absolute rights.


Read more

For more information on this topic, please refer to the following articles:

PIPEDA by the numbers

E-mail compliance

Compliance comes calling



Exit mobile version