52
VIU Workshop: Creating a Culture of Privacy Awareness June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator Office of the Information & Privacy Commissioner for British Columbia Protecting privacy. Promoting transparency.

VIU Workshop: Creating a Culture of Privacy Awareness

  • Upload
    ata

  • View
    45

  • Download
    0

Embed Size (px)

DESCRIPTION

Office of the Information & Privacy Commissioner for British Columbia. Protecting privacy. Promoting transparency . VIU Workshop: Creating a Culture of Privacy Awareness. June 12, 2013 By Justin Hodkinson OIPC Policy Analyst/Investigator . Agenda. Protection of Privacy60 minutes - PowerPoint PPT Presentation

Citation preview

Page 1: VIU Workshop: Creating a Culture of  Privacy Awareness

VIU Workshop:Creating a Culture of Privacy Awareness

June 12, 2013By Justin Hodkinson

OIPC Policy Analyst/Investigator

Office of theInformation &

PrivacyCommissioner

for British Columbia

Protecting privacy. Promoting transparency.

Page 2: VIU Workshop: Creating a Culture of  Privacy Awareness

Agenda

Protection of Privacy 60 minutesPrivacy Quiz 5 minutesCoffee/Tea Break 10 minutesFIPPA Basics 25 minutesQuestion Period 20 minutesExam 20 minutes

Office of the Information & Privacy Commissioner

for British Columbia

Page 3: VIU Workshop: Creating a Culture of  Privacy Awareness

VIU Privacy Policies

Arriving Soon!

Office of the Information & Privacy Commissioner

for British Columbia

Page 4: VIU Workshop: Creating a Culture of  Privacy Awareness

Privacy Breaches

Not a question of IF But a question of WHEN & HOW BIG

Office of the Information & Privacy Commissioner

for British Columbia

Page 5: VIU Workshop: Creating a Culture of  Privacy Awareness

Common Privacy BreachesStolen laptops or local hard drives

Lost or stolen documentsBlowing out of garbage trucksLost, stolen or misplaced recycling binsFiles on car roofs

Inappropriate or unauthorized behaviourBrowsing databaseBlogs

Inadvertent disclosuresMailing system errorsFaxing errors

Office of the Information & Privacy Commissioner

for British Columbia

Page 6: VIU Workshop: Creating a Culture of  Privacy Awareness

Protecting PI Outside off Campus

Office of the Information & Privacy Commissioner

for British Columbia

Page 7: VIU Workshop: Creating a Culture of  Privacy Awareness

F12-02U of Vic Investigation Report

Importance of a Privacy Management Framework

& Encryption

Office of the Information & Privacy Commissioner

for British Columbia

Page 8: VIU Workshop: Creating a Culture of  Privacy Awareness

Layering Approach to Security

Office of the Information & Privacy Commissioner

for British Columbia

Page 9: VIU Workshop: Creating a Culture of  Privacy Awareness

Social Media Background Checks

Office of the Information & Privacy Commissioner

for British Columbia

Page 10: VIU Workshop: Creating a Culture of  Privacy Awareness

Issues with Social Media Background Checks

• Accuracy• Collecting irrelevant or too

much information• Overreliance on consent• Third party information

Office of the Information & Privacy Commissioner

for British Columbia

Page 11: VIU Workshop: Creating a Culture of  Privacy Awareness

Before you check…remember Personal information you collect is subject to FIPPA

Consider less intrusive ways to meet your purpose

Assess the risks

Ensure you have authority to collect

Develop policies and procedures to address risks

Be prepared to respond to requests for access, correction or for withdrawal of consent

Office of the Information & Privacy Commissioner

for British Columbia

Page 12: VIU Workshop: Creating a Culture of  Privacy Awareness

… don’t

x Wait until after you check to assess the risks

x Assume you are only collecting information about one person

x Assume that the information will be accurate

x Use a personal account to perform the check

x Ask a 3rd party to do the check

x Think the person will not find out

Office of the Information & Privacy Commissioner

for British Columbia

Page 13: VIU Workshop: Creating a Culture of  Privacy Awareness

What is Cloud Computing?

Office of the Information & Privacy Commissioner

for British Columbia

Page 14: VIU Workshop: Creating a Culture of  Privacy Awareness

Weighing Your Options

Office of the Information & Privacy Commissioner

for British Columbia

Page 15: VIU Workshop: Creating a Culture of  Privacy Awareness

Cloud Computing: Issues

Office of the Information & Privacy Commissioner

for British Columbia

Page 16: VIU Workshop: Creating a Culture of  Privacy Awareness

What should you ask your prospective cloud provider?

Office of the Information & Privacy Commissioner

for British Columbia

Page 17: VIU Workshop: Creating a Culture of  Privacy Awareness

What should you ask yourself?

Office of the Information & Privacy Commissioner

for British Columbia

Page 18: VIU Workshop: Creating a Culture of  Privacy Awareness

Privacy Emergency Kit

• What data can VIU share during an emergency?

Office of the Information & Privacy Commissioner

for British Columbia

Page 19: VIU Workshop: Creating a Culture of  Privacy Awareness

VIU Alumni Association’s Use of PI

Office of the Information & Privacy Commissioner

for British Columbia

Page 20: VIU Workshop: Creating a Culture of  Privacy Awareness

Sharing PI between VIU Departments

Office of the Information & Privacy Commissioner

for British Columbia

Page 21: VIU Workshop: Creating a Culture of  Privacy Awareness

Sharing Health Information

Office of the Information & Privacy Commissioner

for British Columbia

Page 22: VIU Workshop: Creating a Culture of  Privacy Awareness

PIAs & Self-Generated Research

Office of the Information & Privacy Commissioner

for British Columbia

Page 23: VIU Workshop: Creating a Culture of  Privacy Awareness

S. 35 of FIPPA Research Agreements

Office of the Information & Privacy Commissioner

for British Columbia

Page 24: VIU Workshop: Creating a Culture of  Privacy Awareness

Sharing Students’ Email Addresses

Office of the Information & Privacy Commissioner

for British Columbia

Page 25: VIU Workshop: Creating a Culture of  Privacy Awareness

Privacy Quiz Time!

Office of theInformation &

PrivacyCommissioner

for British Columbia

Protecting privacy. Promoting transparency.

Presented by: Justin Hodkinson, Investigator

Page 26: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

1. What does P.I.A. really mean?

Page 27: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

2. Where can you store personal information?

Page 28: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

3. Retention

Page 29: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

4. Who are you gonna call?

Page 30: VIU Workshop: Creating a Culture of  Privacy Awareness

5. Speed Round

The Dean of the Business Department approaches you, the Registrar, & asks for a student’s home address. The Dean explains that she has reason to believe that the student is about to commit suicide & she wants to warn the student’s older sister, who still lives with their parents.

How would you respond to this request for student information?

Page 31: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

Web Cam &Video Surveillance

Page 32: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

More InformationVideo Surveillance:http://www.oipc.bc.ca/news/rlsgen/Video_Surveillance_Guidelines(March2008).pdf

Social Media Background checks:http://www.oipc.bc.ca/pdfs/private/Guidelines-SocialMediaBackgroundChecks.pdf

Cloud Computing: http://www.oipc.bc.ca/pdfs/private/Cloud_computing_for_SMEs_guidance_document.pdf

Page 33: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

Page 34: VIU Workshop: Creating a Culture of  Privacy Awareness

FOI ACCESS

Office of the Information & Privacy Commissioner

for British Columbia

Page 35: VIU Workshop: Creating a Culture of  Privacy Awareness

10 Principles for Privacy Compliance

Be accountableIdentify the purpose

Obtain consentLimit collection, use, disclosure

Limit retentionBe accurate

Use appropriate safeguardsBe open

Give accessChallenging compliance

Page 36: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

About the OIPC…• Independent office of the Legislature

• Oversees privacy and access issues in the public (FIPPA) and private sector (PIPA)

• Power to investigate, mediate & adjudicate

• Guidelines, public education & reports

Page 37: VIU Workshop: Creating a Culture of  Privacy Awareness

Role of the OIPC

Office of the Information & Privacy Commissioner

for British Columbia

Page 38: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

What is “personal information” ?

Information that can identify an individual: name, address, phone number, ID number.

Information about an identifiable individual: physical description, educational qualifications, blood type.

Page 39: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

Access basics• Anyone can ask for their own personal information• Student can ask for exam questions but VIU will not

disclose them• Must remove certain information• May remove other information

Page 40: VIU Workshop: Creating a Culture of  Privacy Awareness

What is purpose of FIPPA?FIPPA passed in 1992 -

Purposes of this Act

2 (1) The purposes of this Act are to make public bodies more accountable to the public and to protect personal privacy by

(a) giving the public a right of access to records,

(b) giving individuals a right of access to, and a right to request correction of, personal information about themselves,

(c) specifying limited exceptions to the rights of access(d) Preventing the unauthorized collection, use or disclosure of

personal information by public bodies, …

Office of the Information & Privacy Commissioner

for British Columbia

Page 41: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

Duty to Assist Applicants

Page 42: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

Access Request Basics

Page 43: VIU Workshop: Creating a Culture of  Privacy Awareness

Employee Records & Investigations

Office of the Information & Privacy Commissioner

for British Columbia

Page 44: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

Time Limits

Page 45: VIU Workshop: Creating a Culture of  Privacy Awareness

Reasons for Extensions

Office of the Information & Privacy Commissioner

for British Columbia

Page 46: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

Safeguarding basics

Security Practices

Retention Practices

Disposal Practices

Page 47: VIU Workshop: Creating a Culture of  Privacy Awareness

Custody & Control

Office of the Information & Privacy Commissioner

for British Columbia

Page 48: VIU Workshop: Creating a Culture of  Privacy Awareness

Clarify Requests & Talk with Applicants

Office of the Information & Privacy Commissioner

for British Columbia

Page 49: VIU Workshop: Creating a Culture of  Privacy Awareness

Fees

Office of the Information & Privacy Commissioner

for British Columbia

Page 50: VIU Workshop: Creating a Culture of  Privacy Awareness

Fee Estimates

Office of the Information & Privacy Commissioner

for British Columbia

Page 51: VIU Workshop: Creating a Culture of  Privacy Awareness

Questions?

Office of the Information & Privacy Commissioner

for British Columbia

Page 52: VIU Workshop: Creating a Culture of  Privacy Awareness

Office of the Information & Privacy Commissioner

for British Columbia

Thank you

Office of the Information and PrivacyCommissioner for British Columbia Telephone: (250) 387-5629 (general) (250) 387-0035 (my direct line)

Toll-free access call Enquiry BC at one of the numbers listed below and request a transfer to (250) 387-5629: Vancouver: (604) 660-2421 Elsewhere in BC: (800) 663-7867

Email: [email protected] or [email protected]: (250) 387-1696