Privacy code in detail
Principle 1 – Accountability
Universities Canada is responsible for all personal information under its control, including personal information disclosed to third parties for processing. Universities Canada has designated a Privacy Officer who is accountable for the organization’s compliance with this Code. 1.1 The Universities Canada Privacy Officer is responsible for compliance with this Code, even though other individuals within Universities Canada may be responsible for the day to day collection and processing of personal information and may be delegated to act on behalf of the Universities Canada Privacy Officer. 1.2 The identity of the individuals designated by Universities Canada to oversee compliance with this Code will be made known internally and will be made available externally on request. 1.3 Universities Canada will use contractual or other means to protect personal information that has been transferred to service providers for processing, for example, for storage. 1.4 Where Universities Canada acts as a processor of personal information or as a service provider to others, Universities Canada will comply with this Privacy Code and any Privacy Statements issued by the Universities Canada program in question in respect of the personal information it collects, uses, discloses and retains on behalf of third parties or that is transferred to it.
Universities Canada will identify the purposes for which personal information is collected, used, disclosed and retained at or before the time the information is collected. 2.1 Universities Canada programs subject to this Privacy Code will collect, use, disclose and retain personal information for the following purposes:
2.1.1 to process and evaluate scholarship applications, select scholarship recipients and administer the scholarships and scholarship payments once the scholarships are awarded and to assess the efficacy of scholarship programs;
2.1.2 to develop aggregate information and statistics in relation to the scholarship awards program;
2.1.3 to maintain a scholarship or program alumni contact list as well as a scholarship listing client list, and administer subscriptions to University Affairs;
2.1.4 to market our publications program to potential purchasers or subscribers;
2.1.5 to identify and offer information services and products to meet subscriber needs or preferences;
2.1.6 to provide and administer payroll and benefits services to other associations and employers mostly in the higher education sector;
2.1.7 to comply with legal requirements;
2.1.8 to respond to inquiries about publications or our programs received by telephone or by the Universities Canada websites.
2.2 Universities Canada collects and uses primarily business names and addresses of individuals and subscribers for purposes of marketing publications of interest to the higher education sector. Universities Canada collects from and discloses to third parties the names and mailing addresses of potential or existing subscribers to its publications. Universities Canada will require vendors of such information to represent that they have complied with applicable privacy legislation in disclosing this information to Universities Canada. Universities Canada will provide an opportunity to all individuals and subscribers to consent to or opt-out of the collection, use, disclosure and retention of their names and addresses for these purposes. (see Section 3.6 below) 2.3 On occasion, Universities Canada discloses subscriber business contact information to BPA International, for purposes of auditing readership levels. 2.4 Individuals will be advised of the purposes for which the information is collected at the time information is collected, or as soon as practicable thereafter. An individual may, at any time, request or be given an explanation of how their personal information is being used. 2.5 If Universities Canada proposes to use, disclose or retain personal information for a purpose not previously identified, the new purpose will be identified and documented prior to the new use. Unless the new purpose is required or permitted by law, the consent of the individual will be obtained before the information can be used, disclosed or retained for that purpose.
Principle 3 – Obtaining consent
Universities Canada will obtain the consent of individuals before or when it collects, uses, discloses or retains personal information, except where authorized by law. 3.1 In obtaining consent, Universities Canada will use reasonable efforts to ensure that an individual is advised of the identified purposes for which personal information will be used, disclosed and retained. Purposes will be stated in a manner that can be reasonably understood by the individual. 3.2 Generally, Universities Canada will seek consent to use, disclose and retain personal information at the same time it collects the information. However, Universities Canada may seek consent to use and disclose personal information after it has been collected, but before it is used, disclosed or retained for a new purpose. 3.3 Universities Canada will require individuals to consent to the collection, use, disclosure and retention of personal information as a condition of the supply of information or services to the individual only if such collection, use, disclosure and retention is necessary to provide the information or services. 3.4 In determining the appropriate form of consent, Universities Canada will take into account the sensitivity of the personal information and the reasonable expectations of individuals in relation to the purposes for use, disclosure and retention of the information by Universities Canada. 3.5 An individual may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. Individuals may contact Universities Canada for more information regarding the implications of withdrawing consent. 3.6 Individuals may opt-out or refuse to consent to the use, disclosure or retention of their personal information for marketing purposes by contacting Universities Canada at 613-563-1236 or by writing to Privacy Officer, Universities Canada, 1710 – 350 Albert Street, Ottawa, Ontario K1R 1B1.
Principle 4 – Limiting collection of personal information
Universities Canada shall limit the collection of personal information to that which is necessary for the purposes identified by Universities Canada. Universities Canada will collect personal information by fair and lawful means. 4.1 Universities Canada collects personal information primarily from individuals directly. 4.2 Universities Canada may also collect personal information from other sources including:
4.2.1 publishers, list brokers or other associations;
4.2.2 employers using Universities Canada payroll and benefit services who represent that they have the right to disclose the information;
4.2.3 Universities Canada may collect personal information about an individual’s family members or beneficiaries from that individual for purposes of providing benefits administration services to the individual, employer, and will in such circumstances rely on the individual to obtain the consent of these other parties.
Principle 5 – Limiting use, disclosure and retention of personal information
Universities Canada will not use, disclose or retain personal information for purposes other than those for which it was collected, except with the consent of the individual, or as required or authorized by law. Personal information will be retained only as long as necessary for the fulfilment of those purposes. 5.1 Universities Canada may disclose personal information about an individual to the following for the purposes set out in Section 2:
5.1.1 a person who, on the basis of a written authorization from a scholarship applicant or recipient, is seeking the information as an agent of the applicant or recipient;
5.1.2 to the employers using Universities Canada payroll and benefit services in relation to their employees;
5.1.3 to third parties, for marketing or readership audit purposes (see Sections 2.2 and 2.3);
5.1.4 to a third party, where the individual consents to disclosure or where disclosure is required or authorized by law.
5.2 Universities Canada has a records retention policy that specifies the length of time that records are maintained. All personal information is accessible only by Universities Canada’s personnel, or service providers, who need access to that information for the performance of their duties or services.
Principle 6 – Keeping personal information accurate
Universities Canada will keep personal information as accurate, complete and up to date as necessary for the purposes for which it is to be used. 6.1 Information will be sufficiently accurate, complete and up to date so as to minimize the possibility that inappropriate information may be used to make a decision about an individual. 6.2 Universities Canada will update personal information about individuals on an on-going basis, only when necessary to fulfill the purposes identified in this Code, or upon notification by the individual.
Principle 7 – Safeguarding personal information
Universities Canada will protect personal information with security safeguards appropriate to the sensitivity of the information. 7.1 Universities Canada will protect personal information against loss or theft as well as unauthorized access, disclosure, copying, use or modification, regardless of the format in which the information is held and will restrict internal access to personnel who require such access to perform their duties. 7.2 Universities Canada shall protect personal information transferred to third parties providing services to Universities Canada through contractual measures or other arrangements stipulating the confidentiality of the information, restricting the purposes for which the information is to be used and prohibiting its disclosure to third parties upon direction from Universities Canada in accordance with this Privacy Code. 7.3 In the event of a suspected security breach, Universities Canada’s staff will immediately undertake an investigation to assess the severity of the breach, including an assessment of which information may have been compromised. Should a security breach be confirmed, Universities Canada will notify all potentially affected users and the Privacy Commissioner of Canada within 72 hours of discovering the breach. Universities Canada will then review the incident and ensure appropriate action is taken to prevent future breaches.
Principle 8 – Being open about policies and procedures
Universities Canada will make readily available to individuals specific information about Universities Canada policies and procedures relating to the management of personal information. 8.1 Universities Canada will be open about its policies and procedures with respect to the management of personal information. Individuals will be able to acquire information about our policies and procedures at minimal or no cost and without unreasonable effort. This information will be made available in a form that is generally understandable.
Principle 9 – Providing access to personal information
On written request, and subject to the exemptions stipulated by law, Universities Canada will inform individuals of the existence, use, disclosure and retention of their personal information and provide access to that information. An individual will be able to challenge the accuracy and completeness of the information and have it amended where inaccuracies exist. 9.1 In certain situations, Universities Canada may not be able to provide access to all of the personal information that it holds about an individual. These situations shall be limited to those required or stipulated by law. 9.2 When an individual successfully challenges the accuracy or completeness of personal information, the Universities Canada will correct, delete or add information as required. When appropriate, the amended information will be transmitted to any third parties having access to the information in question.
Principle 10 – Challenging compliance
An individual will be able to address a challenge concerning compliance by Universities Canada with this Code to the Universities Canada Privacy Officer. 10.1 Universities Canada will investigate all complaints. If a complaint is found to be justified, Universities Canada will take appropriate measures, including amending its policies and procedures if necessary. 10.2 Individuals will be able to obtain more information on Universities Canada’s privacy practices, or make a complaint, by contacting: Privacy Officer Universities Canada 1710 – 350 Albert Street Ottawa, Ontario K1R 1B1 Phone: 613-563-1236 E-mail: email@example.com 10.3 Individuals also have recourse to the Office of the Privacy Commissioner of Canada if they consider that Universities Canada has not responded satisfactorily to their complaint or inquiry. Privacy Commissioner of Canada 30 Victoria Street Gatineau, Quebec K1A 1H3 Phone: 819-994-5444 Toll-free: 1-800-282-1376 Website: https://www.priv.gc.ca/en/ For a copy of the Personal Information Protection and Electronic Documents Act, please access the website of the Privacy Commissioner of Canada. The CSA Model Code is Schedule 1 to the Personal Information Protection and Electronic Documents Act. For copies of the CSA Model Code for the Protection of Personal Information, please contact the Canadian Standards Association, 178 Rexdale Blvd., Etobicoke, Ontario M9W 1R3.