Article 1 General
Purpose - The purpose of this policy is to govern the collection, use and disclosure of personal information in a manner that recognizes the right of privacy of individuals with respect to their personal information and the need of LEISURE INFORMATION NETWORK (LIN) to collect, use or disclose personal information.
Definitions - The following terms have these meanings in this Policy:
Act - Personal Information Protection and Electronic Documents Act
Commercial Activity - any particular transaction, act or conduct that is of a commercial character.
Organization - includes an association, a partnership, a person, an unincorporated association, a trust a not for profit organization, a trade union and a corporation.
Personal Information - any information about an identifiable individual, but does not include an employee's name, title, business address or telephone number.
Personal Health Information - any health information about an identifiable individual.
Representatives - Directors, officers, employees, committees, members, volunteers, coaches, contractors and other decision makes with LEISURE INFORMATION NETWORK (LIN).
Application - This Policy applies to directors, officers, employees, committee members, volunteers, coaches, contractors, and other decision-makers with LEISURE INFORMATION NETWORK (LIN).
Statutory Obligations - LEISURE INFORMATION NETWORK (LIN) is governed by the Personal Information Protection and Electronic Documents Act in matters involving the collection, use and disclosure of personal information.
Additional Obligations - In addition to fulfilling all requirements of the Acts, LEISURE INFORMATION NETWORK (LIN) and its Representatives will also fulfill the additional requirements of this Policy. Representatives of LEISURE INFORMATION NETWORK (LIN) will
Disclose personal information to a third party during any business or transaction unless such business, transaction or other interest is properly consented to in accordance with this policy;
Knowingly place themselves in a position where they are under obligation to any person to disclose personal information;
In the performance of their official duties, disclose personal information to family members, friends or colleagues, or to organizations in which their family members, friend or colleagues have an interest;
Derive personal benefit from personal information that they have acquired during the course of fulfilling their official duties with LEISURE INFORMATION NETWORK (LIN); and
Accept any gift or favor that could be construed as being given in anticipation of, or in recognition for, the disclosure of personal information.
Ruling on Policy - Except as provided in the Acts, the Board of Directors of LEISURE INFORMATION NETWORK (LIN) shall have the authority to interpret any provision of this Policy that is contradictory, ambiguous, or unclear
Article 2 Accountability
Duties - The Privacy Officer shall:
Implement procedures to protect personal information;
Establish procedures to receive and respond to complaints and inquiries;
Train staff and communicate to staff information about the LEISURE INFORMATION NETWORK (LIN)' s policies and practices; and
Develop information to explain LEISURE INFORMATION NETWORK (LIN)'s policies and procedures to members and the public.
Staff Training - The Privacy Officer shall ensure all staff implement the proper procedures to protect personal information.
Identity - The identity of the Privacy' Officer and his/her contact information shall be made known via LEISURE INFORMATION NETWORK (LIN)'s web site and will be publicly accessible.
Inquiries - The Privacy Officer shall be responsible to respond to all requests and inquiries in regards to personal information.
Principles - LEISURE INFORMATION NETWORK (LIN) shall implement policies and practices to secure all personal information during collection, use and disclosure.
Disclosure to Third Parties - A contract made with a third party having access to personal information held by LIFESTYLE INFORMATION NETWORK (LIN) shall include a clause that ensures the third party does not breach LEISURE INFORMATION NETWORK (LIN)'s privacy policies.
Information - Information shall be made available to the public via LEISURE INFORMATION NETWORK (LIN)'s web site explaining privacy policies and procedures.
Annual Review - This Policy shall be reviewed annually by the Privacy Officer and necessary changes shall be made to ensure the protection of personal information and compliance with the law.
Article 3 Identifying Purposes
Collection - LEISURE INFORMATION NETWORK (LIN) shall only collect information reasonably necessary for the identified purposes set out in Article 3.2.
Purpose - Personal information may be collected from prospective members, members, participants, and volunteers ("Individuals") and used by LEISURE INFORMATION NETWORK (LIN) Representatives for purposes that include, but are not limited to, the following:
Name, address, phone number, cell phone number, fax number and e-mail address for the purpose of providing information to LEISURE INFORMATION NETWORK (LIN).
Credit card information for purchasing services and other resources.
Banking information, social insurance number, criminal records check, resume, and
beneficiaries for LEISURE INFORMATION NETWORK (LIN)'s payroll, company insurance and health plan.
Individual measurements for adjusting equipment.
Identity - LEISURE INFORMATION NETWORK (LIN) shall identify in writing the purposes for which personal information is collected at or before the time of collection. The purposes will be stated in a manner that an individual can reasonably understand how the information will be used or disclosed.
Purposes not Identified - LEISURE INFORMATION NETWORK (LIN) shall seek consent from individuals when personal information is used for a purpose not previously identified. This consent shall be documented as to when and how it was received.
Article 4 Consent
Consent - LEISURE INFORMATION NETWORK (LIN) shall obtain consent from individuals at the time of collection prior to the use or disclosure of this information. If consent of the collection, use or disclosure was not obtained upon receipt of the information, consent shall be obtained prior to the use or disclosure of the personal information.
Lawful Means - Consent shall not be obtained by deception.
Requirement - LEISURE INFORMATION NETWORK (LIN) shall not, as a condition of a product or service, require an individual to consent to the collection, use or disclosure of information beyond that required to fulfill the specified purpose.
Form - Consent may be written, oral or implied. In determining the form of consent to use, LEISURE INFORMATION NETWORK (LIN) shall take into account the sensitivity of the information, as well as the individual's reasonable expectations. Individuals may consent to the collection and specified used of personal information in the following ways:
By signing an application form;
By checking a check off box;
By providing written consent either physically or electronically;
By consenting orally in person; or
By consenting orally over the phone.
Withdrawal - An individual may withdraw consent to the collection, use or disclosure of personal information at any time, subject to legal or contractual restrictions, provided the individual gives one week's notice of such withdrawal. LEISURE INFORMATION NETWORK (LIN) shall inform the individual of the implications of such withdrawal.
Legal Guardians - Consent shall not be obtained from individual who are minors, seriously ill, or mentally incapacitated and therefore will be obtained from a parent, legal guardian or person having power of attorney.
Exceptions for Collection - LEISURE INFORMATION NETWORK (LIN) is not required to obtain consent for the collection, of personal information if:
it is clearly in the individual's interests and consent is not available in a timely way;
knowledge and consent would compromise the availability or accuracy of the information and collection is required to investigate a breach of an agreement or contravention of a federal or provincial law;
the information is for journalistic, artistic or literary purposes;
the information is publicly available as specified in the Acts.
Exceptions for Use - LEISURE INFORMATION NETWORK (LIN) may use personal information without the individual's knowledge or consent only:
if LEISURE INFORMATION NETWORK (LIN) has reasonable grounds to believe the information could be useful when investigating a contravention of a federal, provincial or foreign law and the information is used for that investigation;
for an emergency that threatens an individual's life, health or security;
for statistical or scholarly study or research (LEISURE INFORMATION NETWORK (LIN) must notify the Privacy Commissioner before using the information);
if it is publicly available as specified in the Acts;
if the use is clearly in the individual's interest and consent is not available in a timely way; or
if knowledge and consent would compromise the availability or accuracy of the information and collection was required to investigate a breach of an agreement or contravention of a federal or provincial law.
Exceptions for Disclosure - LEISURE INFORMATION NETWORK (LIN) may disclose personal information without the individual's knowledge or consent only:
to a lawyer representing LEISURE INFORMATION NETWORK (LIN);
to collect a debt the individual owes to LEISURE INFORMATION NETWORK (LIN);
to comply with a subpoena, a warrant or an order made by a court or other body with appropriate jurisdiction;
to a government institution that has requested the information, identified its lawful authority, and indicated that disclosure is for the purpose of enforcing, carrying out an investigation, or gathering intelligence relating to any federal, provincial or foreign law; or that suspects that the information relates to national security or the conduct of international affairs; or is for the purpose of administering any federal or provincial law;
to an investigative body named in the Acts or government institution on LEISURE INFORMATION NETWORK (LIN)'s initiative when LEISURE INFORMATION NETWORK (LIN) believes the information concerns a breach of an agreement, or a contravention of a federal, provincial, or foreign law, or suspects the information relates to national security or the conduct of international affairs;
to an investigative body for the purposes related to the investigation of a breach of an agreement or a contravention of a federal or provincial law;
in an emergency threatening an individual's life, health, or security (LEISURE INFORMATION NETWORK (LIN) must inform the individual of the disclosure);
for statistical, scholarly study or research (LEISURE INFORMATION NETWORK LIN) must notify the Privacy Commissioner before disclosing the information);
to an archival institution;
20 years after the individual's death or 100 years after the record was created;
if it is publicly available as specified in the regulations; or
if otherwise required by law.
Article 5 Limiting Collection
Limiting Collection - LEISURE INFORMATION NETWORK (LIN) shall not collect personal information indiscriminately. Information collected shall be for the purposes specified in Article 3.2.
Method of Collection - Information shall be collected by fair and lawful means.
Article 6 Limiting Use, Disclosure and Retention
Limiting Use - Personal information shall not be used or disclosed for purposes other than those
for which it was collected as described in Article 3.2, except with the consent of the individual or as required by law.
Retention Periods - Personal information shall be retained for certain periods of time in accordance with the following:
Employee information shall be retained for a period of seven years in accordance with Canada Customs and Revenue Agency requirements.
Marketing information shall be immediately destroyed upon compilation and analysis of
As otherwise may be stipulated in federal or provincial legislation.
Destruction of Information - Documents shall be destroyed by way of shredding and electronic files shall be deleted in their entirety.
Exception - Personal information that is used to make a decision about an individual shall be maintained for a minimum of one year of time to allow the individual access to the information after the decision has been made.
Third Parties - Information which has been consented to be disclosed to a third party shall be protected by a third party agreement to limit use and disclosure.
Article 7 Accuracy
Accuracy - Personal information shall be accurate, complete and up to date as is necessary for the purposes for which it is to be used to minimize the possibility that inappropriate information may be used to make a decision about the individual.
Update - Personal information shall only be updated if it is necessary to fulfill the purposes for which the information was collected unless the personal information is used on an ongoing basis.
Third Parties - Personal information disclosed to a third party shall be accurate and up-to-date.
Article 8 Safeguards
Safeguards - Personal information shall be protected by security safeguards appropriate to the sensitivity of the information against loss or theft, unauthorized access, disclosure, copying, use or modification.
Sensitivity - The nature of the safeguards shall be directly related to the level of sensitivity of the personal information collected. The more sensitive the information, the higher the level of security employed.
Methods of Protection - Methods of protection and safeguards include, but are not limited to, locked filing cabinets, restricted access to offices, security clearances, need-to-know access and technological measures including the use of passwords, encryption, and firewalls.
Employees - Employees shall be made aware of the importance of maintaining personal information confidential and may be required to sign confidentiality agreements.
Financial Information - Personal information of employees shall be secured in a locked filing cabinet and on a password protected computer accessed only by the Finance Officer and office staff with permission for the Finance Officer.
Marketing Information - Marketing information shall be secured in a locked filing cabinet and on a password protected computer, both of which will only be accessed by the Marketing Director.
Article 9 Openness
Openness - LEISURE INFORMATION NETWORK (LIN) shall make publicly available information about its policies and practices relating to the management of personal information. This information shall be in a form that is generally understandable.
Information - The information made available shall include:
the name or title, and the address, of the person who is accountable for the organization's policies and practices and to whom complaints or inquiries can be forwarded;
the means of gaining access to personal information held by the organization;
a description of the type of personal information held by the organization, including a general account of its use;
a copy of any brochures or other information that explain the organization's policies, standards, or codes.
Article 10 Individual Access
Individual Access - Upon written request, and assistance from LEISURE INFORMATION NETWORK (LIN), an individual shall be informed of the existence, use, and disclosure of his or her personal information and shall be given access to that information.
Amendment - An individual shall be able to challenge the accuracy and completeness of the information and have it amended as appropriate.
Denial - An individual may be denied access to his or her personal information and provided a
written explanation as to why if:
the information is prohibitively costly to provide;
the information contains references to other individuals;
the information cannot be disclosed for legal, security, or commercial proprietary reasons, and
the information is subject to solicitor-client or litigation privilege.
Contents of Refusal - If LEISURE INFORMATION NETWORK (LIN) determines that the disclosure of personal information should be refused, LEISURE INFORMATION NETWORK (LIN) must inform an individual the following:
the reasons for the refusal and the provisions of the Act on which the refusal is based;
the name, position title, business address and business telephone number of the Privacy Officer who can answer the applicant's questions; and
that the individual may ask for a review within thirty (30) days of being notified of the
Source - Upon request, the source of personal information shall be disclosed along with an account of third parties to whom the information may have been disclosed.
Identity - Sufficient information may be required to confirm an individual's identity prior to providing that individual an account of the existence, use, and disclosure of personal information.
Response - Requested information shall be disclosed within 30 days of receipt of the request at minimal expense for copying or no cost to the individual, unless there are reasonable grounds to extend the time limit. The requested information shall be provided in a form that is generally understandable.
Costs - Costs may only be levied if an individual is informed in writing in advance of the approximate cost and has agreed to proceed with the request.
Inaccuracies - If personal information is inaccurate or incomplete, it shall be amended as required and the amended information shall be transmitted to third parties in due course.
Unresolved Complaints - An unresolved complaint from an individual in regards to the accuracy of personal information shall be recorded and transmitted to third parties having access to the information in question.
Article 11 Challenging Compliance
Challenges - An individual shall be able to challenge compliance with this Policy and the Act to the designated individual accountable for compliance.
Procedures - Upon receipt of a complaint LEISURE INFORMATION NETWORK (LIN) shall:
Record the date the complaint is received;
Notify the Privacy Officer who will serve in a neutral, unbiased capacity to resolve the complaint;
Acknowledge receipt of the complaint by way of telephone conversation and clarify the nature of the complaint within three (3) days of receipt of the complaint;
Appoint an investigator using LEISURE INFORMATION NETWORK (LIN) personnel or an independent investigator, who will have the skills necessary to conduct a fair and impartial investigation and will have unfettered access to all file and personnel, within ten (10) days of receipt of the complaint.
Upon completion of the investigation and within twenty-five (25) days of receipt of the complaint, the investigator shall submit a written report to LEISURE INFORMATION NETWORK (LIN).
Notify the complainant the outcome of the investigation and any relevant steps taken to rectify the complaint, including any amendments to policies and procedures within thirty (30) days of receipt of the complaint.
Assistance - LEISURE INFORMATION NETWORK (LIN) shall assist an individual in preparing a request for information.
Whistleblowing - LEISURE INFORMATION NETWORK (LIN) must not dismiss, suspend, demote, discipline, harass or otherwise disadvantage an employee of LEISURE INFORMATION NETWORK (LIN), or deny that employee a benefit because the employee, acting in good faith and on the basis of reasonable belief:
has disclosed to the commissioner that LEISURE INFORMATION NETWORK (LIN) has contravened or is about to contravene the Acts;
has done or stated an intention of doing anything that is required to be done in order to avoid having any person contravene these Acts;
has refused to do or stated an intention of refusing to do anything that is in contravention of these Acts.