<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Policies &amp; Documentation &#8211; DPO Centre</title>
	<atom:link href="https://www.dpocentre.ca/blog/category/policies-documentation/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.dpocentre.ca</link>
	<description>Empowering Compliance, Protecting Data, Ensuring Trust. - DPO Centre</description>
	<lastBuildDate>Wed, 02 Jul 2025 19:59:13 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.dpocentre.ca/wp-content/uploads/2026/07/cropped-DPO-Centre-32x32.png</url>
	<title>Policies &amp; Documentation &#8211; DPO Centre</title>
	<link>https://www.dpocentre.ca</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Data Privacy Day 2025: Navigating privacy in Canada</title>
		<link>https://www.dpocentre.ca/blog/data-privacy-day-2025-canada/</link>
		
		<dc:creator><![CDATA[Taylor Swann]]></dc:creator>
		<pubDate>Tue, 28 Jan 2025 13:39:18 +0000</pubDate>
				<category><![CDATA[Policies & Documentation]]></category>
		<guid isPermaLink="false">https://www.dpocentre.ca/?p=21722</guid>

					<description><![CDATA[<p>As the international privacy community marks Data Privacy Day 2025, the conversation around data protection and regulation takes on heightened significance for Canada. With federal legislative efforts delayed and provinces stepping in to fill critical gaps, organizations face regulatory uncertainty.&#160; To help navigate these developments, we spoke to these leading experts in the field: Constantine [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/data-privacy-day-2025-canada/">Data Privacy Day 2025: Navigating privacy in Canada</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">As the international privacy community marks <strong>Data Privacy Day 2025</strong>, the conversation around data protection and regulation takes on heightened significance for Canada. With federal legislative efforts delayed and provinces stepping in to fill critical gaps, organizations face regulatory uncertainty.&nbsp;</p>



<p class="wp-block-paragraph">To help navigate these developments, we spoke to these leading experts in the field: Constantine Karbaliotis, Counsel for nNovation LLP and  Sylvia Klasovec, Principal Advisor at Trusteva Consulting</p>



<p class="wp-block-paragraph">Together, they provide perspective on the challenges and opportunities facing businesses in 2025, offering insights on how businesses can stay ahead in this evolving landscape.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>What does 2025 hold for data privacy in Canada?</strong></h2>



<p class="wp-block-paragraph">The Office of the Privacy Commissioner of Canada (OPC) has set the tone for 2025, pledging this Data Privacy Week to ‘put privacy first’. But with the delay in federal legislation due to the prorogation of Parliament, how will privacy evolve in Canada this year?&nbsp;</p>



<p class="wp-block-paragraph">Sylvia believes, <em>“It will be a defining year for our country and our privacy landscape. There will be a fragmented approach to privacy, where the provinces may drive their own privacy laws, just as we saw with Quebec’s Law 25</em>, creating dual compliance regimes and more operational complexity.</p>



<p class="wp-block-paragraph"><em>“</em><em>The good news is that our privacy regulators are ahead of the curve, collaborating with international organisations like the Future of Privacy Forum to address emerging challenges, such as children’s privacy, biometrics, and data anonymization.</em>&nbsp;</p>



<p class="wp-block-paragraph"><em>“I predict a heavy focus on data and metadata management for </em><em>AI readiness, emphasizing data quality, integrity, and transparency to support secure and reliable AI governance.”</em>&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>How do Canadian privacy practices compare to the EU?</strong></h2>



<p class="wp-block-paragraph">Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and the EU’s General Data Protection Regulation (GDPR) share foundational similarities but there are key differences in enforcement, scope, and approach.&nbsp;&nbsp;Both adopt a principles-based approach, although the GDPR has stricter requirements, extra-territorial scope and fines tied to global revenue. PIPEDA generally only applies to companies operating in Canada and fines are capped at $100,000 per violation.</p>



<p class="wp-block-paragraph">Constantine acknowledges the influence of EU practices on Canadian privacy regulation, especially in a principles-based legal environment: <em>“We can look to jurisdictions like the EU and UK to interpret and take guidance on new situations, and our commissioner looks to Europe to understand how to apply our legislation.”</em>&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>What are the key aspects businesses should focus on for complying with PIPEDA?</strong></h2>



<p class="wp-block-paragraph">Constantine suggests organizations focus on two key areas: safeguarding data and third-party developments.&nbsp;</p>



<p class="wp-block-paragraph"><em>“First and foremost, always be conscious of the risks and implement the appropriate controls to protect individuals’ data. Secondly, watch what your vendors are doing. As they introduce new features to their services, ask yourself: What does this mean for my business? Are they selling the data, and if so, to whom? And most importantly, is my current risk assessment still valid?”</em></p>



<p class="wp-block-paragraph">To help you comply with PIPEDA, it is advisable to take these essential steps:&nbsp;</p>



<ul class="wp-block-list">
<li>Understand what information your organization collects and processes&nbsp;</li>



<li>Implement appropriate technical and organizational measures&nbsp;</li>



<li>Ensure appropriate consent is obtained and documented for all data collections&nbsp;</li>



<li>Conduct regular training and awareness programmes for employees&nbsp;</li>



<li>Establish comprehensive policies and procedures that include:&nbsp;
<ul class="wp-block-list">
<li>Purpose specificity, data minimisation, and accuracy&nbsp;</li>



<li>Transparency on how information is collected, used, disclosed, retained, and destroyed&nbsp;</li>



<li>Processes for individual access, challenging compliance, and privacy incident management&nbsp;</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading"><br><strong>What does pausing Bill C-27 mean for data privacy in Canada?</strong></h2>



<p class="wp-block-paragraph">After nearly three years of review, Bill-C27 was halted when Parliament was suspended on 6 January 2025. </p>



<h4 class="wp-block-heading"><strong>Key aspects of Bill C-27:</strong></h4>



<ul class="wp-block-list">
<li><strong>Consumer Privacy Protection Act (CPPA)</strong>, which would provide updated privacy protections for individuals&nbsp;</li>



<li><strong>Artificial Intelligence and Data Act (AIDA)</strong>, to establish a risk-based framework to regulate AI&nbsp;</li>
</ul>



<h4 class="wp-block-heading"><strong>Privacy experts raise concerns about the impact of the delay</strong></h4>



<p class="wp-block-paragraph">Constantine notes that the EU’s renewal of Canada’s adequacy status in 2024 was a missed opportunity to push meaningful reform forward.&nbsp;</p>



<p class="wp-block-paragraph"><em>“When the EU renewed our adequacy finding, they took away the one thing that would have put a fire under our parliamentarians&#8217; butts to actually make them pass a law.”</em>&nbsp;</p>



<p class="wp-block-paragraph">Sylvia highlights the gaps in critical areas like children’s privacy, cross-border data transfers, and AI governance. She cautions that, &#8220;<em>Without the regulatory guardrails AIDA provides, it could stifle innovation and lead to risky AI projects.</em><br>&#8220;<em>Consent management will be particularly challenging as global counterparts rely on Legitimate Interests for AI data processing, while Canada follows implied consent rules. This will impact multinational AI companies and market dynamics. Whereas, in the EU, rules require transparency, fairness, and AI risk assessments, to name a few.&#8221;</em></p>



<p class="wp-block-paragraph">She cautions that, <em>&#8220;Without similar regulatory guardrails that AIDA would have offered – though not a perfect solution – innovation may be stifled and AI projects could become more risky.&#8221;</em></p>



<h2 class="wp-block-heading"><br><strong>How can organizations prepare for future regulations in a rapidly evolving environment?</strong></h2>



<p class="wp-block-paragraph">Constantine thinks that as a trading country, we must consider how our business partners are going to interact with us <em>“Look to laws that exist in other countries to provide a structure and build effective governance around these things.”</em></p>



<p class="wp-block-paragraph"> Sylvia advises taking cues from international guidelines, calling the EU a “north star” that sets the world stage on the protection of human rights and freedoms. <em>“We look to international guidelines because they usually indicate the direction in which any enacted laws will take shape. Mature Canadian enterprises have already codified much of this into their data management practices and some have gone as far as complementing our Canadian laws with ISO standards, ethical codes of practice, and certifications.”&nbsp;</em></p>



<h2 class="wp-block-heading"><br><strong>Summary</strong></h2>



<p class="wp-block-paragraph">As we commemorate Data Privacy Day 2025, Canada is at a pivotal juncture. With federal legislation on hold and provinces stepping in to fill regulatory gaps, businesses face both challenges and opportunities.&nbsp;</p>



<p class="wp-block-paragraph">Insights from Constantine and Sylvia underscore the importance of proactive compliance and alignment with global privacy standards. Organizations should prioritize data governance, stay informed on emerging regulations, and implement robust privacy practices.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<h3 class="wp-block-heading"><strong>In case you missed it…</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li><a href="https://www.dpocentre.ca/privacy-in-canada-usa-2024-and-2025-expectations/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/privacy-in-canada-usa-2024-and-2025-expectations/" rel="noreferrer noopener"><strong>Privacy in Canada and USA: 2024 highlights and 2025 expectations</strong>&nbsp;</a></li>



<li><a href="https://www.dpocentre.com/canadian-privacy-laws/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/gdpr-guide-for-saas-companies-eu-uk/" rel="noreferrer noopener"><strong>Canadian privacy laws: PIPEDA and beyond</strong>&nbsp;</a></li>



<li><a href="https://www.dpocentre.ca/quebecs-law-25-a-guide-to-support-privacy-compliance/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/quebecs-law-25-a-guide-to-support-privacy-compliance/" rel="noreferrer noopener"><strong>Quebec’s Law 25: A guide to support privacy compliance</strong>&nbsp;</a></li>
</ul>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<p class="wp-block-paragraph"><strong>For more news and insights about data protection follow The DPO Centre on&nbsp;<a href="https://uk.linkedin.com/company/dpo-centre" target="_blank" rel="noreferrer noopener">LinkedIn</a></strong></p>



<p class="wp-block-paragraph"></p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/data-privacy-day-2025-canada/">Data Privacy Day 2025: Navigating privacy in Canada</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Privacy in Canada &#038; USA: 2024 highlights and 2025 expectations</title>
		<link>https://www.dpocentre.ca/blog/privacy-in-canada-usa-2024-and-2025-expectations/</link>
		
		<dc:creator><![CDATA[Taylor Swann]]></dc:creator>
		<pubDate>Fri, 20 Dec 2024 12:12:12 +0000</pubDate>
				<category><![CDATA[Policies & Documentation]]></category>
		<guid isPermaLink="false">https://www.dpocentre.ca/?p=21636</guid>

					<description><![CDATA[<p>It’s been a busy year for data protection and privacy in Canada and the USA, with significant developments not only across North America, but also globally. As businesses face evolving privacy challenges, understanding the year’s developments and preparing for 2025’s expectations is crucial for maintaining compliance and staying competitive.&#160; In this blog, we highlight some [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/privacy-in-canada-usa-2024-and-2025-expectations/">Privacy in Canada &amp; USA: 2024 highlights and 2025 expectations</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">It’s been a busy year for data protection and privacy in Canada and the USA, with significant developments not only across North America, but also globally. As businesses face evolving privacy challenges, understanding the year’s developments and preparing for 2025’s expectations is crucial for maintaining compliance and staying competitive.&nbsp;</p>



<p class="wp-block-paragraph">In this blog, we highlight some of the key 2024 highlights for privacy in Canada and USA and cast an eye to what we can expect in 2025.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>Privacy in Canada: Challenges and progress</strong></h2>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">2024 has brought notable advancements to privacy in Canada, including the final phase of Quebec’s Law 25 coming into effect and the European Commission&#8217;s decision to uphold Canada&#8217;s Personal Information Protection and Electronic Documents Act (PIPEDA) as adequate under GDPR. This means data can keep moving easily between the EU and Canada, helping to support both trade and data safety.&nbsp;</p>



<p class="wp-block-paragraph">Key areas of focus in 2024 include Ontario’s Bill 194, Quebec’s Law 25, the awaited updates to PIPEDA under the proposed Bill C-27, and the privacy implications of Bill C-65.&nbsp;</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Let’s take a closer look at each:&nbsp;</p>



<h3 class="wp-block-heading"><strong>Quebec’s Law 25</strong>&nbsp;</h3>



<p class="wp-block-paragraph">In September 2024, Quebec completed an overhaul of its privacy regime with Law 25&#8217;s final stage implementation. It requires organizations covered by Law 25 to, among other things, accommodate stricter consent rules, extended privacy rights, and data breach notifications. &nbsp;</p>



<p class="wp-block-paragraph"><strong><a href="https://www.dpocentre.ca/quebecs-law-25-a-guide-to-support-privacy-compliance/" target="_blank" rel="noreferrer noopener">Quebec’s Law 25: A guide to support privacy compliance</a></strong>&nbsp;</p>



<figure class="wp-block-image size-full is-resized"><a href="https://www.dpocentre.ca/quebecs-law-25-a-guide-to-support-privacy-compliance/" target="_blank" rel=" noreferrer noopener"><img fetchpriority="high" decoding="async" width="1002" height="668" src="https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024_rev_header.jpg" alt="Quebec’s Law 25: A guide to support privacy compliance" class="wp-image-20839" style="width:500px" title="Privacy in Canada &amp; USA: 2024 highlights and 2025 expectations 1" srcset="https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024_rev_header.jpg 1002w, https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024_rev_header-300x200.jpg 300w, https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024_rev_header-768x512.jpg 768w" sizes="(max-width: 1002px) 100vw, 1002px" /></a></figure>



<p class="wp-block-paragraph"></p>



<h3 class="wp-block-heading"><strong>Updating PIPEDA: Bill C-27</strong></h3>



<p class="wp-block-paragraph">At the Federal level, the Consumer Privacy Protection Act (Bill C-27) is still under review. A change in government might also mean changes to when the Bill is implemented and in what form.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">While there’s currently no comprehensive legislation in Canada that specifically governs AI systems, Bill C-27 does include within it the Artificial Intelligence and Data Act (AIDA) to establish a risk-based framework to regulate AI. As such, privacy professionals are expecting closer alignment with international frameworks like GDPR that aim to boost both data protection standards and economic competitiveness.&nbsp;</p>



<p class="wp-block-paragraph"></p>



<h3 class="wp-block-heading"><strong>Ontario’s Bill 194</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Ontario&#8217;s Bill 194, <em>Strengthening Cyber Security and Building Trust in the Public Sector Act,</em> has been a major development in Canadian privacy legislation this year. The Bill now obligates public sector&nbsp;organizations to:&nbsp;</p>



<ul class="wp-block-list">
<li>Develop comprehensive cybersecurity programs&nbsp;</li>



<li>Establish clear accountability frameworks for AI systems&nbsp;</li>



<li>Be open and transparent about how digital technology is used&nbsp;</li>



<li>Carry out privacy impact assessments&nbsp;</li>



<li>Notify people quickly if their data is breached&nbsp;</li>
</ul>



<p class="wp-block-paragraph">These obligations may also affect private sector companies working with provincial or municipal governments, as the requirements could extend to them through contractual or operational responsibilities.&nbsp;</p>



<p class="wp-block-paragraph"></p>



<h3 class="wp-block-heading"><strong>Bill C-65</strong>&nbsp;</h3>



<p class="wp-block-paragraph">The Electoral Participation Act (Bill C-65) has sparked considerable debate, with Canadian Privacy Commissioner, Philippe Dufresne highlighting critical gaps in its approach to data protection and that it lacked “basic elements”. He has urged lawmakers to address these shortcomings and recommended the Bill should:&nbsp;</p>



<ul class="wp-block-list">
<li>Require political parties to get consent to use data and limit how they collect and use it&nbsp;</li>



<li>Provide a way for people to access and correct their data&nbsp;</li>



<li>Contain broader obligations about privacy breach notifications to include mandatory reporting&nbsp;</li>



<li>Encourage more formal collaboration between the Office of the Privacy Commissioner, Elections Canada, and the Commissioner of Canada Elections&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The Bill has yet to reach the third reading in the House of Commons.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>United States:</strong> <strong>State-level innovation leads the way</strong></h2>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">The USA has seen much state-level activity, with 19 states now having comprehensive privacy laws. California, New York, and Florida have led the way in AI governance, with each taking a distinctive approach.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Key developments in AI regulations include:</strong>&nbsp;</p>



<p class="wp-block-paragraph"><strong>California</strong> – the <em>Artificial Intelligence Accountability Act</em> proposes to make state-level assessments of generative AI risks mandatory and enforce safety and privacy standards in AI services. California is also planning to establish a centralized AI research hub to collaborate across sectors.&nbsp;</p>



<p class="wp-block-paragraph"><strong>New York</strong> – its focus on algorithm accountability and transparency requires companies to disclose how their AI systems handle customers’ personal data. This fits with consumer protection efforts to maintain human oversight of decisions around AI algorithms.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Florida</strong> – introduced measures on AI transparency in public and educational settings. The state’s also considering regulations that require human oversight of autonomous vehicles.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>Global impact:</strong> <strong>EU data protection regulations affecting Canada and U.S.</strong></h2>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>The EU’s adequacy decision for Canada</strong> under the General Date Protection Regulation (GDPR) has been particularly important for maintaining uninterrupted data flows between the EU and Canada. This decision ensures that Canada’s data protection laws meet the EU’s stringent standards, allowing businesses to transfer personal data across borders without additional safeguards.&nbsp;</p>



<p class="wp-block-paragraph">For the United States, the situation remains more complex. In July 2023, the EU-US Data Privacy Framework (DPF) was established, with the UK’s ‘Data Bridge’ extension to the DPF Framework effective from October 2023. The DPF allows data transfers to organizations participating in the DPF program without the need for further transfer mechanisms. However, the DPF is not accessible for all, and many companies still rely on Standard Contractual Clauses (SCCs) and supplementary measures. &nbsp;</p>



<h2 class="wp-block-heading"><br><strong>Looking ahead to 2025</strong></h2>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Looking to next year, several key trends are emerging that could shape the legislation landscape across North America. <strong>In Canada we could see:</strong></p>



<ul class="wp-block-list">
<li>Updates to privacy laws in Alberta and British Columbia&nbsp;</li>



<li>Introduction of privacy legislation in Ontario&nbsp;</li>



<li>Implementation and enforcement of Bill C-27 (if passed)&nbsp;</li>



<li>More provinces aligning with Quebec&#8217;s Law 25&nbsp;</li>
</ul>



<p class="wp-block-paragraph"><strong>In the U.S. we will see:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>More states beyond the current 19 adopting privacy legislation&nbsp;</li>



<li>More focus on AI regulation and transparency set by California, New York, and Florida&nbsp;</li>



<li>More focus on AI accountability and initiatives regarding how algorithms work&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><br><strong>What it means for businesses</strong></h2>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Organizations across Canada and the United States should prepare for evolving privacy regulations in 2025, with an emphasis on strengthening consent processes and implementing effective data minimization strategies.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">It is essential for businesses to conduct Privacy Impact Assessments (PIAs) on a regular basis and ensure robust data breach plans and policies are in place. As artificial intelligence (AI) continues to shape business operations, organizations must also develop and establish clear guidelines for its responsible use, treating privacy as a key part of building and maintaining customer trust.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Success will ultimately depend on integrating these measures not individually, but as interconnected elements of a comprehensive data protection and privacy management strategy.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>Privacy support and advice for 2025</strong></h2>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">The world of data protection and privacy management is changing fast. And no matter the sector, businesses need to stay updated and flexible, adapting privacy practices to meet new requirements – all while ensuring compliance with current laws.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Effective privacy management in 2025 will require a proactive approach, viewing privacy not just as a compliance obligation but a fundamental element of business strategy. This shift will place even more pressure on Privacy Officers to find trusted, experienced, and reliable sources of professional advice and expert guidance as the year unfolds.&nbsp;</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">If your organization would benefit from additional Privacy Office Support, The DPO Centre offers a range of services, including <strong><a href="https://www.dpocentre.ca/services/consultancy-services/" target="_blank" rel="noreferrer noopener">Privacy Consulting</a></strong>, UK and EU <strong><a href="https://www.dpocentre.ca/services/representation-services/" target="_blank" rel="noreferrer noopener">GDPR Representation</a></strong>, and <strong><a href="https://www.dpocentre.ca/services/outsourced-dpo-services/" target="_blank" rel="noreferrer noopener">Outsourced Privacy Officers</a></strong>.&nbsp;</p>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<h3 class="wp-block-heading"><strong>In case you missed it…</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li><a href="https://www.dpocentre.ca/international-data-transfers-explaining-eu-sccs-uk-addendum-and-uk-idta/" data-type="link" data-id="https://www.dpocentre.ca/international-data-transfers-explaining-eu-sccs-uk-addendum-and-uk-idta/" target="_blank" rel="noreferrer noopener"><strong>International data transfers: Explaining EU SCCs, UK Addendum and UK ITDA</strong>&nbsp;</a></li>



<li><strong><a href="https://www.dpocentre.ca/canadian-privacy-laws-pipeda-and-beyond/" data-type="link" data-id="https://www.dpocentre.ca/canadian-privacy-laws-pipeda-and-beyond/" target="_blank" rel="noreferrer noopener">Canadian privacy laws: PIPEDA and beyond</a></strong>&nbsp;</li>



<li><strong><a href="https://www.dpocentre.ca/gdpr-representative-do-you-need-one/" target="_blank" rel="noreferrer noopener">GDPR Representative: Do you need one?</a></strong>&nbsp;</li>
</ul>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<p class="wp-block-paragraph"><strong>For more news and insights about data protection follow The DPO Centre on&nbsp;<a href="https://uk.linkedin.com/company/dpo-centre" target="_blank" rel="noreferrer noopener">LinkedIn</a></strong></p>



<p class="wp-block-paragraph"></p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/privacy-in-canada-usa-2024-and-2025-expectations/">Privacy in Canada &amp; USA: 2024 highlights and 2025 expectations</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Canadian privacy laws: PIPEDA and beyond</title>
		<link>https://www.dpocentre.ca/canadian-privacy-laws-pipeda-and-beyond/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 27 May 2024 21:35:49 +0000</pubDate>
				<category><![CDATA[Data Privacy Officer]]></category>
		<category><![CDATA[Global data privacy laws]]></category>
		<category><![CDATA[Policies & Documentation]]></category>
		<guid isPermaLink="false">https://dpoca.server.terryh.uk/?p=20841</guid>

					<description><![CDATA[<p>Q&#38;A with Ray Pathak, MD The DPO Centre, Canada The Personal Information Protection and Electronics Act (PIPEDA) was enacted in April 2000. Since then, there have been significant changes in global data protection and technological advancements, necessitating amendments to Canadian federal legislation.&#160; The Digital Charter Implementation Act, 2022 (also known as Bill C-27) is the [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/canadian-privacy-laws-pipeda-and-beyond/">Canadian privacy laws: PIPEDA and beyond</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading"><strong><em>Q&amp;A with Ray Pathak, MD The DPO Centre, Canada</em></strong></h2>



<p class="wp-block-paragraph">The Personal Information Protection and Electronics Act (PIPEDA) was enacted in April 2000. Since then, there have been significant changes in global data protection and technological advancements, necessitating amendments to Canadian federal legislation.&nbsp;</p>



<p class="wp-block-paragraph">The Digital Charter Implementation Act, 2022 (also known as Bill C-27) is the proposed update to PIPEDA. It is currently under consideration in the Senate. If enacted, the new law will require organizations to prepare for stricter regulations and increased enforcements.&nbsp;</p>



<p class="wp-block-paragraph">Here, we talk to Ray Pathak, a former Privacy Officer with over 15 years of Canada privacy experience and MD of The DPO Centre Canada. He sheds light on some of the current challenges faced by Canadian organizations, keeping in mind the potential law changes and the evolving role of privacy professionals. </p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" width="1024" height="409" src="https://www.dpocentre.ca/wp-content/uploads/2024/06/RAY-client-insights-1024x409.jpg" alt="RAY client insights" class="wp-image-20842" style="width:800px" title="Canadian privacy laws: PIPEDA and beyond 2" srcset="https://www.dpocentre.ca/wp-content/uploads/2024/06/RAY-client-insights-1024x409.jpg 1024w, https://www.dpocentre.ca/wp-content/uploads/2024/06/RAY-client-insights-300x120.jpg 300w, https://www.dpocentre.ca/wp-content/uploads/2024/06/RAY-client-insights-768x306.jpg 768w, https://www.dpocentre.ca/wp-content/uploads/2024/06/RAY-client-insights-1536x613.jpg 1536w, https://www.dpocentre.ca/wp-content/uploads/2024/06/RAY-client-insights.jpg 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><strong>Ray, can you tell us a little bit about your background?</strong></h3>



<p class="wp-block-paragraph">I’ve been in the privacy space for almost 20 years. From 2005-2015, I was a Privacy Officer, leading a wide variety of privacy programs. For the last 8 years, I have been leading and developing privacy solutions in the Privacy Tech sector.&nbsp;</p>



<p class="wp-block-paragraph">I’m privileged to now lead The DPO Centre’s Canadian office, where I work with organizations to help guide them through the increasing complexities of local and international privacy regulations.</p>



<h3 class="wp-block-heading"><strong>What&nbsp;are&nbsp;the key&nbsp;privacy challenges&nbsp;currently faced by&nbsp;organizations in Canada?</strong></h3>



<p class="wp-block-paragraph">With so many evolving global privacy laws, organizations operating across multiple jurisdictions face ongoing challenges to keep up with the changes.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Canadian organizations must adapt to new legislation such as Quebec’s Law 25 and the potential federal changes, as and when Bill 27 passes.&nbsp;</p>



<p class="wp-block-paragraph">In addition, emerging technologies like AI have introduced new privacy challenges, including the risk of breach threats with sophisticated attacks, and an increase in state sponsored attacks.&nbsp;</p>



<h3 class="wp-block-heading"><strong>With the upcoming changes in Quebec’s privacy legislation, what should businesses do to prepare for compliance with Law 25?</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Law 25 is being implemented in stages.</p>



<p class="wp-block-paragraph"><strong>Stage 1</strong>&nbsp;came into effect on September 22, 2022, and covered the mandatory designation of a Privacy Officer and Privacy Impact Assessments (PIAs).</p>



<p class="wp-block-paragraph"><strong>Stage 2</strong>&nbsp;came into effect on September 22, 2023, focussing on Accountability, Consent, Transparency, Individual Rights, and other key principals of privacy management.</p>



<p class="wp-block-paragraph"><strong>Stage 3</strong>&nbsp;will come into effect on September 22, 2024, and deals with data portability rights.&nbsp;</p>



<p class="wp-block-paragraph">Businesses should complete a gap assessment of their current programs and adapt their policies, procedures, and data handling practices to ensure they comply with the stricter obligations under Law 25. Key areas to address will be Consent, PIAs, and cross-border transfers.&nbsp;</p>



<h3 class="wp-block-heading"><strong>Do you think there will be changes to other provincial laws?</strong></h3>



<p class="wp-block-paragraph">With changes already in place in Quebec, and proposed changes to the Federal privacy law, I think it will only be a matter of time before the Alberta and British Columbia laws are amended.&nbsp;</p>



<p class="wp-block-paragraph">Also, the province of Ontario has been talking about introducing their own privacy legislation for some time, and I believe the introduction of this is inevitable in the next two to five years.&nbsp;</p>



<h3 class="wp-block-heading"><strong>How do Canadian laws regulate the use of AI systems?&nbsp;&nbsp;</strong></h3>



<p class="wp-block-paragraph">There is currently no single comprehensive law that deals specifically with AI in Canada.&nbsp;</p>



<p class="wp-block-paragraph">The Artificial Intelligence and Data Act (AIDA) was introduced in June 2022 as part of Bill C-27, which advocates a risk-based approach to AI systems.&nbsp;</p>



<p class="wp-block-paragraph">There are other sector laws that touch on AI within their domains, such as healthcare and finance, and PIPEDA can be applied to cover AI systems that collect, use, or disclose personal information. However, none of these laws are tailored to AI, and they fail to address the unique privacy challenges that come with these technologies.&nbsp;</p>



<h3 class="wp-block-heading"><strong>How do provincial laws&nbsp;like those in&nbsp;Alberta and British Columbia&nbsp;interact with PIPEDA?&nbsp;</strong></h3>



<p class="wp-block-paragraph">PIPEDA is the overarching privacy law for private sector companies that collect, use, or disclose personal information in Canada.&nbsp;</p>



<p class="wp-block-paragraph">However, when processing data in a province with its own privacy law, such as Alberta, British Columbia, or Quebec, the provincial law applies over the federal PIPEDA law.&nbsp;</p>



<p class="wp-block-paragraph">Most organizations operate across multiple provinces and may need to comply with up to four privacy laws – three provincial laws&nbsp;<strong>and</strong>&nbsp;the federal regulation.&nbsp;</p>



<p class="wp-block-paragraph">The good news is that provincial privacy laws have to be substantially similar to the federal privacy law, which ensures a certain amount of consistency for compliance. Although, there are still some significant differences, such as employee privacy, which is covered under provincial privacy laws for most private organizations, but not the current federal PIPEDA law.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>What would you say the greatest challenge is for the privacy industry&nbsp;at the moment?</strong></h3>



<p class="wp-block-paragraph">The limited number of knowledgeable privacy professionals is a big challenge for organizations, especially if they only require part-time support. This can often lead to privacy being managed reactively, and as a secondary priority, by someone fulfilling another role within the company.&nbsp;</p>



<p class="wp-block-paragraph">That’s one of the key reasons why I joined The DPO Centre. We have an incredible pool of talent and a commitment to excellence. We’ve worked with over 900 organizations globally since 2017, and we can offer unparalleled support to organizations, providing in-depth privacy knowledge and expertise.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>What are some common misconceptions about the data protection industry? How do you deal&nbsp;with them?</strong></h3>



<p class="wp-block-paragraph">The biggest misconception is that you can “complete” your privacy program, tick the box, and be done with it.&nbsp;</p>



<p class="wp-block-paragraph">However, if an organisation processes and stores personal data, there is a continual need for ongoing data management. It is one thing to adhere to a set of policies and another to truly safeguard data and ensure practices and processes are monitored and optimised.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Organizations with strong privacy governance and embedded privacy by design practices are better equipped to mitigate risks and build customer trust, loyalty and engagement.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>What range of privacy services does The DPO Centre Canada offer?</strong></h3>



<p class="wp-block-paragraph">Our Canadian team offer the same full-service privacy support that our clients benefit from the UK and EU offices, with the appropriate changes to accommodate Canadian privacy standards.&nbsp;</p>



<p class="wp-block-paragraph">Canadian Data Privacy Officers are available to assess, remediate, and operate your privacy program on an ongoing ‘fractional’ basis, provide ad hoc consulting support as required, and complete mandatory documentation such as Privacy Impact Assessments (PIAs).&nbsp;</p>



<p class="wp-block-paragraph">We also provide EU and UK GDPR representation for Canadian companies operating in the European Economic Area (EEA) and/or the UK. A GDPR Representative is a requirement for organizations that process the personal data of EEA or UK individuals but do not have a physical office in those jurisdictions.&nbsp;&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>With the rise of global data protection laws, how does The DPO Centre Canada ensure multinational compliance?</strong></h3>



<p class="wp-block-paragraph">Many Canadian businesses are aiming for international growth, and privacy can be a significant roadblock as they expand.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">The DPO Centre, has one of the largest teams of privacy experts available. Our DPOs are highly experienced privacy professionals, each with specialist industry sector knowledge and a deep understanding of global privacy laws.&nbsp;</p>



<p class="wp-block-paragraph">Therefore, we help organizations ensure that privacy isn’t a barrier as they grow globally.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>How do you foresee the future of privacy services evolving over the next five years?</strong></h3>



<p class="wp-block-paragraph">I think we’ll see a continuing shift towards regarding privacy, not merely as a legal obligation but also as a key aspect of customer service and relationship management.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">We already work with organizations that understand privacy compliance is only a baseline requirement, especially in business-to-business industries. They recognize the potential for accelerated growth by leveraging excellent privacy practices that build trust, loyalty and engagement with their customers. It is therefore a crucial differentiator, helping them stand out from their competitors.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">As Canada’s privacy regulations evolve, our commitment to delivering top-tier privacy services continues. Supporting and empowering organizations to navigate complex legislation with confidence and integrity.&nbsp;</p>



<h2 class="wp-block-heading"><strong>The DPO Centre Canada</strong></h2>



<p class="wp-block-paragraph">If you would like to discuss how our outsourced privacy services can help support your organization’s privacy governance, please <a href="https://www.dpocentre.ca/contact-us/" target="_blank" rel="noreferrer noopener"><strong>contact The DPO Centre Canada team</strong></a></p>



<p class="wp-block-paragraph">For EU and UK data protection support, please see our range of&nbsp;<a href="https://www.dpocentre.com/services/outsourced-dpo-services/" target="_blank" rel="noreferrer noopener">EU/UK services</a></p>



<p class="wp-block-paragraph">See also our recent blog, offering advice and guidance to support <a href="https://www.dpocentre.ca/2024/05/13/quebecs-law-25-a-guide-to-support-privacy-compliance/" target="_blank" rel="noreferrer noopener">compliance with Quebec’s Law 25</a></p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/canadian-privacy-laws-pipeda-and-beyond/">Canadian privacy laws: PIPEDA and beyond</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Quebec’s Law 25: A guide to support privacy compliance</title>
		<link>https://www.dpocentre.ca/blog/quebecs-law-25-a-guide-to-support-privacy-compliance/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 13 May 2024 21:26:14 +0000</pubDate>
				<category><![CDATA[Data Privacy Officer]]></category>
		<category><![CDATA[Data Sharing]]></category>
		<category><![CDATA[Policies & Documentation]]></category>
		<guid isPermaLink="false">https://dpoca.server.terryh.uk/?p=20828</guid>

					<description><![CDATA[<p>Organizations that collect, process and store the personal information of Quebec individuals must ensure their existing privacy programs are in line with the provisions of Quebec’s Law 25. This new legislation was adopted in September 2021 and has been implemented in stages, with the final stage coming into effect on September 22, 2024.&#160; Law 25 [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/quebecs-law-25-a-guide-to-support-privacy-compliance/">Quebec’s Law 25: A guide to support privacy compliance</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Organizations that collect, process and store the personal information of Quebec individuals must ensure their existing privacy programs are in line with the provisions of Quebec’s Law 25. This new legislation was adopted in September 2021 and has been implemented in stages, with the final stage coming into effect on September 22, 2024.&nbsp;</p>



<p class="wp-block-paragraph">Law 25 represents a milestone for provincial privacy legislation. It marks a complete overhaul of Quebec’s privacy regime, strengthening privacy rights for individuals and updating organisational requirements.&nbsp;</p>



<p class="wp-block-paragraph">In this guide, we provide essential information to help support your journey towards achieving and maintaining compliance. We explain which organizations Law 25 affects and detail what each stage of its provisions include.&nbsp;</p>



<h2 class="wp-block-heading">What is Quebec’s Law 25?</h2>



<p class="wp-block-paragraph">Law 25 introduces several key concepts to modernize data protection practices in Quebec and strengthen privacy rights for individuals.</p>



<p class="wp-block-paragraph">The legislation has been brought into effect in stages, over a three-year period, which has allowed organizations to adapt gradually to the new privacy requirements.&nbsp;By September 2024 organizations should ensure all provisions are fully implemented.&nbsp;</p>



<p class="wp-block-paragraph">Fines for non-compliance can range between CA$15,000 and CA$25,000,000 or 4% of worldwide turnover for the previous year, whichever is greater. </p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" width="1024" height="289" src="https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-1024x289.jpg" alt="Preparing for Quebecs Law 25 changes A guide for Sept 2024" class="wp-image-20829" style="width:800px" title="Quebec’s Law 25: A guide to support privacy compliance 3" srcset="https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-1024x289.jpg 1024w, https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-300x85.jpg 300w, https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-768x217.jpg 768w, https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-1536x434.jpg 1536w, https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-2048x578.jpg 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">Who does Law 25 apply to?</h2>



<p class="wp-block-paragraph">Law 25 applies to all businesses, including non-profits, operating in Quebec that collect, process, use or disclose the data of Quebec residents, regardless of size, revenue or location of the business.&nbsp;</p>



<h2 class="wp-block-heading">Quebec’s Law 25:&nbsp;A guide to support privacy compliance</h2>



<p class="wp-block-paragraph">Law 25 imposes a range of obligations on businesses, with the aim of striking a balance between privacy protection, individual rights, and business accountability.&nbsp;</p>



<p class="wp-block-paragraph">To ensure compliance with the new regulations, you should complete a&nbsp;<strong>gap analysis of your current privacy programs</strong>. This will identify any required updates that need to be made to policies, procedures and data handling practices.&nbsp;</p>



<p class="wp-block-paragraph">If you are operating within the province of Quebec and process personal data, these are the important aspects you should already have in place or need to address by September 22, 2024:&nbsp;</p>



<h3 class="wp-block-heading"><strong>Appoint a Data Privacy Officer&nbsp;</strong></h3>



<p class="wp-block-paragraph">The&nbsp;Data Privacy Officer&nbsp;role shares a similarity with the EU’s requirement for a&nbsp;Data Protection Officer (DPO).&nbsp;However, unlike the GDPR, the Privacy Officer role defaults to the highest-ranking individual in an organization, if one is not otherwise appointed.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Many organizations may not be aware of the defaulting nature of the Privacy Officer role. Where a Privacy Officer is not explicitly appointed, the responsibility falls to the CEO or MD.&nbsp;</strong>&nbsp;</p>



<p class="wp-block-paragraph"><strong>What you need to do:</strong>&nbsp;It is crucial for organizations of any size or industry sector to recognize the importance of this role. A Privacy Officer should have the expertise and specialist knowledge to ensure compliance with privacy laws and understand the complexities of global data protection legislation.&nbsp;</p>



<ul class="wp-block-list">
<li>Appoint an in-house Privacy Officer or outsource to an external professional </li>
</ul>



<p class="wp-block-paragraph">For a comparison between in-house and outsourced options, see this link to download our infographic:</p>



<div class="wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex">
<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://www.dpocentre.ca/resources/in-house-dpo-vs-outsourced-dpo-infographic/">Download Infographic</a></div>
</div>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">The infographic covers these important considerations for choosing between an in-house or outsourced Privacy Officer:</p>



<ul class="wp-block-list">
<li>Speed to hire,</li>



<li>Scalability</li>



<li>Experience and expertise</li>



<li>Risk management</li>



<li>Annual investment</li>
</ul>



<h3 class="wp-block-heading"><strong>Breach reporting&nbsp;</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Organizations must ensure that breach management processes are in place. Data breaches must be reported to the&nbsp;<strong>Commission d’accès à l’information&nbsp;(CAI)</strong><strong>&nbsp;</strong>and all affected individuals as soon as possible.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What you need to do:&nbsp;</strong>Create and test a data breach response protocol. When identifying a potential data breach, you must assess whether an incident poses a “risk of serious injury” based on information sensitivity, anticipated consequences and likelihood of harmful use.&nbsp;</p>



<p class="wp-block-paragraph">Your data breach response protocol should include:&nbsp;</p>



<ul class="wp-block-list">
<li>Employee roles and responsibilities </li>



<li>Workflows </li>



<li>Template breach reporting document </li>
</ul>



<h3 class="wp-block-heading"><strong>Biometrics disclosure</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Biometric data collection includes physical features such as fingerprints, facial features and iris patterns.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What you need to do:&nbsp;</strong>&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Express consent requirements</strong> – Obtain express consent from individuals and ensure it is specific to the purpose of collecting and using biometrics </li>



<li><strong>Disclosure requirements</strong> – Inform the Commission d’acc`es ““““`a l’information du Québec (CAI) of your intention to use biometric processes at least 60 days before implementing the biometric system </li>



<li><strong>Privacy by Design</strong> – Implement privacy-enhancing measures when handling biometric data and consider Privacy Impact Assessments (PIAs) to mitigate any potential harms </li>
</ul>



<h3 class="wp-block-heading"><strong>Privacy Policy</strong>&nbsp;</h3>



<p class="wp-block-paragraph">All organizations operating in Quebec must have a comprehensive Privacy Policy that outlines data handling practices.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What you need to do:&nbsp;</strong>Create a Privacy Policy to include these important details:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Purpose</strong> – Clearly state the purpose of your privacy policy and outline how your organization collects, uses, discloses and protects personal information </li>



<li><strong>Scope</strong> – Specify that the policy applies to all individuals whose data you process </li>



<li><strong>Type of information</strong> – For example names, addresses, credit card numbers </li>



<li><strong>Security measures</strong> – For example, encryption, access controls, regular audits, and employee training </li>



<li><strong>Third parties and sharing</strong> – Explain the purpose of any such sharing and ensure transparency </li>



<li><strong>Individual rights</strong> – Inform individuals of their rights and provide instructions on how they can exercise these rights </li>



<li><strong>Contact information</strong> – For inquiries, requests and complaints related to privacy, include details of the designated Data Privacy Officer </li>



<li><strong>Updates and accessibility </strong>– Commit to keeping the Privacy Policy up to date and ensure it is easily accessible and in a prominent place on your website </li>
</ul>



<h3 class="wp-block-heading"><strong>Privacy Impact Assessment (PIA)</strong>&nbsp;</h3>



<p class="wp-block-paragraph">A PIA is a systematic process to evaluate the impact of data processing activities on individuals’ privacy rights&nbsp;</p>



<p class="wp-block-paragraph"><strong>What you need to do:</strong>&nbsp;</p>



<p class="wp-block-paragraph">Under Law 25, organizations must conduct a Privacy Impact Assessment (PIA) for:&nbsp;</p>



<ul class="wp-block-list">
<li>High risk data processing activities (e.g., large-scale data collection, profiling, biometrics) </li>



<li>Data transfers to other provinces, third countries, or international organizations </li>



<li>Implementation of new technologies (e.g., AI, IoT, facial recognition) </li>
</ul>



<h3 class="wp-block-heading"><strong>Cross-border transfers</strong>&nbsp;</h3>



<p class="wp-block-paragraph">These are transfers that involve moving personal data from Quebec to another jurisdiction outside Canada (or to another province).&nbsp;</p>



<p class="wp-block-paragraph"><strong>What you need to do:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>Inform individuals about cross-border transfers in your Privacy Policy </li>



<li>Undertake a PIA (see details in the section above) </li>



<li>Enact contractual safeguards to ensure adequate protection in the jurisdiction of transfer </li>
</ul>



<h3 class="wp-block-heading"><strong>Enhanced Consent</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Law 25 sets stricter rules for acquiring permission before using people’s personal information. Organizations must obtain explicit opt-in consent before collecting, storing, processing, and sharing personal information. Additionally, for children under 14, you will need the parent’s permission first.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What you need to do:&nbsp;</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>Provide comprehensive information about why and how their data will be used </li>



<li>Ensure the consent request is prominant and stands out from general terms and conditions </li>



<li>Use clear and concise language with an opt-in requirement </li>



<li>Inform individuals of their right to withdraw consent at any time </li>



<li>List any non-Quebec third parties that you are sharing the personal information with </li>



<li>Maintain documentation of how and when consent was given </li>
</ul>



<h3 class="wp-block-heading"><strong>Data minimization</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Law 25 emphasises the importance of collecting only the essential data for the intended purpose. Organizations must avoid excessive data collection and retain only relevant information.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What you need to do:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>Clearly define the purpose for which the data will be used in your privacy policy </li>



<li>Then only collect the minimum amount of data required to achieve that purpose  </li>



<li>Define clear retention periods for different types of data </li>
</ul>



<h3 class="wp-block-heading"><strong>Subject rights</strong>&nbsp;</h3>



<p class="wp-block-paragraph">These rights came into effect September 2023, with the right to data portability effective in September 2024 (see below section).&nbsp;</p>



<p class="wp-block-paragraph">Subject rights include:&nbsp;</p>



<ul class="wp-block-list">
<li>Right to be informed </li>



<li>Right to access </li>



<li>Right to rectification </li>



<li>Right to erasure </li>



<li>Right to withdraw consent </li>



<li>Right to restrict processing </li>



<li>Right to data portability </li>
</ul>



<p class="wp-block-paragraph"><strong>What you need to do:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>Ensure individuals are informed about your data practices </li>



<li>Privacy Officers should respond promptly to any access requests, within 30 days, and provide the relevant details (with redactions, as necessary) </li>
</ul>



<h3 class="wp-block-heading"><strong>Data portability rights – comes into effect September 2024</strong>&nbsp;</h3>



<p class="wp-block-paragraph">With this specific area of Law 25, individuals have the right to have their personal data seamlessly transitioned between service providers.&nbsp;</p>



<p class="wp-block-paragraph">What this means is that you are obliged to provide the requested information in a specified format.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What you need to do:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>You must provide the individual’s personal data in a structured, commonly used, and machine-readable format </li>



<li>Share the requested information with any authorized person or organization </li>
</ul>



<h2 class="wp-block-heading"><strong>Summary</strong>&nbsp;</h2>



<p class="wp-block-paragraph">The final stage of Quebec’s Law 25 comes into effect on September 22, 2024.&nbsp;</p>



<p class="wp-block-paragraph">Organizations operating within the province of Quebec must implement the necessary operational and procedural changes by that date to ensure compliance with the new regulations.&nbsp;</p>



<p class="wp-block-paragraph">We covered the key aspects of Law 25 in the above sections, but these are the main elements to consider:&nbsp;</p>



<ul class="wp-block-list">
<li>All organizations must have a Privacy Officer in place </li>



<li>If you don’t specify a Privacy Officer, the CEO/MD will be automatically assigned </li>



<li>Complete a Privacy Impact Assessment (PIA) for all data transfers and new technologies </li>



<li>Implement a robust breach notification protocol with workflows and reporting documents </li>
</ul>



<h2 class="wp-block-heading"><strong>The DPO Centre Canada</strong>&nbsp;</h2>



<p class="wp-block-paragraph">From our offices in Toronto, Ontario, The DPO Centre Canada provides outsourced Canadian Privacy Officers to organizations operating across Quebec and other provinces.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">If you would like to discuss how our range of specialist services can support your organization’s privacy governance, please contact&nbsp;<a href="https://www.dpocentre.ca/contact-us/" target="_blank" rel="noreferrer noopener"><strong>The DPO Centre Canada.</strong></a>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/quebecs-law-25-a-guide-to-support-privacy-compliance/">Quebec’s Law 25: A guide to support privacy compliance</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA</title>
		<link>https://www.dpocentre.ca/blog/international-data-transfers-explaining-eu-sccs-uk-addendum-and-uk-idta/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Sun, 21 Jan 2024 22:23:56 +0000</pubDate>
				<category><![CDATA[Data Sharing]]></category>
		<category><![CDATA[Global data privacy laws]]></category>
		<category><![CDATA[International data transfers]]></category>
		<category><![CDATA[Policies & Documentation]]></category>
		<guid isPermaLink="false">https://dpoca.server.terryh.uk/?p=20824</guid>

					<description><![CDATA[<p>EU and UK-based organisations regularly need to transfer personal data to different countries for a variety of reasons – project collaborations, partnerships, service providers etc.&#160; With the increasing complexity of global privacy legislation, it is vital for organisations to have the appropriate safeguards in place for these transfers. This ensures compliance with data protection laws, [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/international-data-transfers-explaining-eu-sccs-uk-addendum-and-uk-idta/">International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">EU and UK-based organisations regularly need to transfer personal data to different countries for a variety of reasons – project collaborations, partnerships, service providers etc.&nbsp;</p>



<p class="wp-block-paragraph">With the increasing complexity of global privacy legislation, it is vital for organisations to have the appropriate safeguards in place for these transfers. This ensures compliance with data protection laws, mitigates the risk of a data breach, and helps to maintain the trust of customers, stakeholders, and employees.&nbsp;</p>



<p class="wp-block-paragraph">There are several safeguarding options, depending on the nature of the data, where the individuals are located, and where the data is being sent.&nbsp;</p>



<p class="wp-block-paragraph">In this blog, we take a look at the EU Standard Contractual Clauses (EU SCCs), the UK Addendum, and the UK International Data Transfer Agreement (IDTA), explaining the suitability of each mechanism for EU and UK personal data transfers and the factors to consider.&nbsp;</p>



<h2 class="wp-block-heading">EU&nbsp;Standard Contractual Clauses (EU&nbsp;SCCs)&nbsp;</h2>



<p class="wp-block-paragraph">EU SCCs are one of the most commonly used data transfer mechanisms. They are popular because they have pre-approval by the European Commission and a level of assurance for compliance with the General Data Protection Regulation (GDPR).&nbsp;</p>



<p class="wp-block-paragraph">The European Commission published new EU SCCs on 4 June 2021, allowing organisations to use these for data transfers from the European Economic Area (EEA) to third countries from 27 June 2021.&nbsp;</p>



<h2 class="wp-block-heading">UK Addendum</h2>



<p class="wp-block-paragraph">As the UK is no longer part of the EEA, UK organisations cannot rely on the new EU SCCs. Only the old EU SCCs were valid in the UK until the Information Commissioner’s Office (ICO) introduced their own solution in the form of an Addendum, which came into force on 21 March 2022.&nbsp;</p>



<p class="wp-block-paragraph">The UK Addendum allows organisations to use the new EU SCCs for UK personal data transfers, ensuring compliance with both EU and UK data protection laws. A helpful solution for organisations with locations across the EU and the UK.&nbsp;</p>



<p class="wp-block-paragraph"><strong>The old EU SCCs expired on 27 December 2022. Any existing UK contracts have until 21 March 2024 to transition to the new EU SCCs with UK Addendum or the IDTA.</strong>&nbsp;</p>



<h2 class="wp-block-heading">UK&nbsp;International Data Transfer Agreement (IDTA)&nbsp;</h2>



<p class="wp-block-paragraph">The International Data Transfer Agreement (IDTA) was developed by the UK’s Information Commissioner’s Office (ICO) and has been in force since 21 March 2022. It is a legal framework for transferring personal data from the UK to countries outside the European Economic Area (EEA) not covered by adequacy decisions (these are known as UK Restricted Transfers).&nbsp;</p>



<p class="wp-block-paragraph">The IDTA is an alternative to the EU SCCs with the UK Addendum but is only suitable for transferring personal data from the UK.&nbsp;</p>



<p class="wp-block-paragraph">The IDTA sets out contractual obligations for both the data exporter (in the UK) and the data importer (in the third country) to protect the privacy and rights of individuals whose data is being transferred. It includes clauses on data handling, processing, security measures, and the rights of individuals.&nbsp;</p>



<h2 class="wp-block-heading">Should you use&nbsp;EU SCCs, UK IDTA or UK Addendum?&nbsp;</h2>



<p class="wp-block-paragraph">There are fundamental questions you should ask when choosing the most appropriate data transfer mechanism for your organisation. These include understanding the type of data being transferred, the frequency and volumes, and the countries involved.&nbsp;</p>



<p class="wp-block-paragraph">Here’s a helpful list of questions to consider and an overview of which mechanism to use for EU or UK data:&nbsp;&nbsp;</p>



<ul class="wp-block-list">
<li>Where do the individuals reside? EU, UK or both? </li>



<li>Are there any inter-company binding rules in place? If so, further mechanisms may not be required </li>



<li>Are you transferring data to an adequate country? If yes, the transfer can proceed, following the specific adequacy decision frameworks </li>



<li>Are you making a regular transfer to a non-adequate country? If yes, see EU SCCs or UK Addendum or IDTA  </li>
</ul>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="189" src="https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-1024x189.png" alt="SCCs IDTA UK Addendum" class="wp-image-20826" style="width:800px" title="International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA 4" srcset="https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-1024x189.png 1024w, https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-300x55.png 300w, https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-768x142.png 768w, https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum.png 1080w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">The DPO Centre can help with your international data transfer queries </h2>



<ul class="wp-block-list">
<li>One of the largest teams of outsourced Data Protection Officers (DPOs) available </li>



<li>GDPR EU and UK Representatives </li>



<li>Specialist Advice Line offering a rapid response to important data protection queries </li>



<li>Highly cost-effective solutions </li>
</ul>



<p class="wp-block-paragraph">We have worked with over 800 clients globally across the spectrum of industry sectors, supporting their data protection compliance and bringing peace of mind.&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/international-data-transfers-explaining-eu-sccs-uk-addendum-and-uk-idta/">International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
