Top Banner
VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy Commissioner for British Columbia Protecting privacy. Promoting transparency.
52

VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Dec 16, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

VIU Workshop:Creating a Culture of Privacy Awareness

June 12, 2013By Justin Hodkinson

OIPC Policy Analyst/Investigator

Office of theInformation &

PrivacyCommissioner

for British Columbia

Protecting privacy. Promoting transparency.

Page 2: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Agenda

Protection of Privacy 60 minutes

Privacy Quiz 5 minutes

Coffee/Tea Break 10 minutes

FIPPA Basics 25 minutes

Question Period 20 minutes

Exam 20 minutes

Office of the Information & Privacy Commissioner

for British Columbia

Page 3: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

VIU Privacy Policies

Arriving Soon!

Office of the Information & Privacy Commissioner

for British Columbia

Page 4: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Privacy Breaches

Not a question of IF But a question of WHEN & HOW BIG

Office of the Information & Privacy Commissioner

for British Columbia

Page 5: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Common Privacy BreachesStolen laptops or local hard drives

Lost or stolen documentsBlowing out of garbage trucksLost, stolen or misplaced recycling binsFiles on car roofs

Inappropriate or unauthorized behaviourBrowsing databaseBlogs

Inadvertent disclosuresMailing system errorsFaxing errors

Office of the Information & Privacy Commissioner

for British Columbia

Page 6: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Protecting PI Outside off Campus

Office of the Information & Privacy Commissioner

for British Columbia

Page 7: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

F12-02U of Vic Investigation Report

Importance of a Privacy Management Framework

& Encryption

Office of the Information & Privacy Commissioner

for British Columbia

Page 8: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Layering Approach to Security

Office of the Information & Privacy Commissioner

for British Columbia

Page 9: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Social Media Background Checks

Office of the Information & Privacy Commissioner

for British Columbia

Page 10: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Issues with Social Media Background Checks

• Accuracy• Collecting irrelevant or too

much information• Overreliance on consent• Third party information

Office of the Information & Privacy Commissioner

for British Columbia

Page 11: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Before you check…remember Personal information you collect is subject to FIPPA

Consider less intrusive ways to meet your purpose

Assess the risks

Ensure you have authority to collect

Develop policies and procedures to address risks

Be prepared to respond to requests for access, correction or for withdrawal of consent

Office of the Information & Privacy Commissioner

for British Columbia

Page 12: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

… don’tx Wait until after you check to assess the risks

x Assume you are only collecting information about one person

x Assume that the information will be accurate

x Use a personal account to perform the check

x Ask a 3rd party to do the check

x Think the person will not find out

Office of the Information & Privacy Commissioner

for British Columbia

Page 13: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

What is Cloud Computing?

Office of the Information & Privacy Commissioner

for British Columbia

Page 14: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Weighing Your Options

Office of the Information & Privacy Commissioner

for British Columbia

Page 15: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Cloud Computing: Issues

Office of the Information & Privacy Commissioner

for British Columbia

Page 16: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

What should you ask your prospective cloud provider?

Office of the Information & Privacy Commissioner

for British Columbia

Page 17: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

What should you ask yourself?

Office of the Information & Privacy Commissioner

for British Columbia

Page 18: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Privacy Emergency Kit

• What data can VIU share during an emergency?

Office of the Information & Privacy Commissioner

for British Columbia

Page 19: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

VIU Alumni Association’s Use of PI

Office of the Information & Privacy Commissioner

for British Columbia

Page 20: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Sharing PI between VIU Departments

Office of the Information & Privacy Commissioner

for British Columbia

Page 21: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Sharing Health Information

Office of the Information & Privacy Commissioner

for British Columbia

Page 22: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

PIAs & Self-Generated Research

Office of the Information & Privacy Commissioner

for British Columbia

Page 23: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

S. 35 of FIPPA Research Agreements

Office of the Information & Privacy Commissioner

for British Columbia

Page 24: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Sharing Students’ Email Addresses

Office of the Information & Privacy Commissioner

for British Columbia

Page 25: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Privacy Quiz Time!

Office of theInformation &

PrivacyCommissioner

for British Columbia

Protecting privacy. Promoting transparency.

Presented by: Justin Hodkinson, Investigator

Page 26: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

1. What does P.I.A. really mean?

Page 27: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

2. Where can you store personal information?

Page 28: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

3. Retention

Page 29: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

4. Who are you gonna call?

Page 30: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

5. Speed Round

The Dean of the Business Department approaches you, the Registrar, & asks for a student’s home address. The Dean explains that she has reason to believe that the student is about to commit suicide & she wants to warn the student’s older sister, who still lives with their parents.

How would you respond to this request for student information?

Page 31: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

Web Cam &Video Surveillance

Page 32: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

More InformationVideo Surveillance:http://www.oipc.bc.ca/news/rlsgen/Video_Surveillance_Guidelines(March2008).pdf

Social Media Background checks:http://www.oipc.bc.ca/pdfs/private/Guidelines-SocialMediaBackgroundChecks.pdf

Cloud Computing: http://www.oipc.bc.ca/pdfs/private/Cloud_computing_for_SMEs_guidance_document.pdf

Page 33: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

Page 34: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

FOI ACCESS

Office of the Information & Privacy Commissioner

for British Columbia

Page 35: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

10 Principles for Privacy Compliance

Be accountable

Identify the purpose

Obtain consent

Limit collection, use, disclosure

Limit retention

Be accurate

Use appropriate safeguards

Be open

Give access

Challenging compliance

Page 36: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

About the OIPC…• Independent office of the Legislature

• Oversees privacy and access issues in the public (FIPPA) and private sector (PIPA)

• Power to investigate, mediate & adjudicate

• Guidelines, public education & reports

Page 37: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Role of the OIPC

Office of the Information & Privacy Commissioner

for British Columbia

Page 38: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

What is “personal information” ?

Information that can identify an individual: name, address, phone number, ID number.

Information about an identifiable individual: physical description, educational qualifications, blood type.

Page 39: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

Access basics• Anyone can ask for their own personal information

• Student can ask for exam questions but VIU will not disclose them

• Must remove certain information

• May remove other information

Page 40: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

What is purpose of FIPPA?FIPPA passed in 1992 -

Purposes of this Act

2 (1) The purposes of this Act are to make public bodies more accountable to the public and to protect personal privacy by

(a) giving the public a right of access to records,

(b) giving individuals a right of access to, and a right to request correction of, personal information about themselves,

(c) specifying limited exceptions to the rights of access(d) Preventing the unauthorized collection, use or disclosure of

personal information by public bodies, …

Office of the Information & Privacy Commissioner

for British Columbia

Page 41: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

Duty to Assist Applicants

Page 42: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

Access Request Basics

Page 43: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Employee Records & Investigations

Office of the Information & Privacy Commissioner

for British Columbia

Page 44: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

Time Limits

Page 45: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Reasons for Extensions

Office of the Information & Privacy Commissioner

for British Columbia

Page 46: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

Safeguarding basics

Security Practices

Retention Practices

Disposal Practices

Page 47: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Custody & Control

Office of the Information & Privacy Commissioner

for British Columbia

Page 48: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Clarify Requests & Talk with Applicants

Office of the Information & Privacy Commissioner

for British Columbia

Page 49: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Fees

Office of the Information & Privacy Commissioner

for British Columbia

Page 50: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Fee Estimates

Office of the Information & Privacy Commissioner

for British Columbia

Page 51: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Questions?

Office of the Information & Privacy Commissioner

for British Columbia

Page 52: VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy.

Office of the Information & Privacy Commissioner

for British Columbia

Thank you

Office of the Information and PrivacyCommissioner for British Columbia Telephone: (250) 387-5629 (general)

(250) 387-0035 (my direct line)

Toll-free access call Enquiry BC at one of the numbers listed below and request a transfer to (250) 387-5629: Vancouver: (604) 660-2421 Elsewhere in BC: (800) 663-7867

Email: [email protected] or [email protected]: (250) 387-1696