Guide to FOIP-Chapter 6

Office of the Saskatchewan Information and Privacy Commissioner. Guide to FOIP, Chapter 6, Protection of Privacy. Updated 27 February 2023. 122 In addition to what FOIP and the FOIP Regulations require in an information management sharing agreement, there are also some best practices to keep in mind. A well written agreement should also include: • Identities, roles, and responsibilities of the parties. • What information is being disclosed and collected and the purpose(s) of each. • The frequency and duration of information exchanged. • The legal authority to disclose and collect information. • The methods and security measures for transferring and storing the information. • Procedures in the event there is a privacy or security breach. • Limitations for collection, use, disclosure, and retention. • Provisions for accuracy of the information. • Indemnification. • Compliance monitoring.363 An information management service provider must comply with the terms and conditions of the agreement. Comply with means to act in accordance with or fulfil the requirements.364 FOIP does not prohibit the transfer of personal information to outside of Canada. However, any government institution outsourcing personal information outside of Canada still has several obligations under FOIP such as ensuring safeguards are adequate, a detailed contract is in place and other provisions of FOIP are met.365 For more on best practices and developing information sharing agreements, see SK OIPC resource, Best Practices for Information Sharing Agreements. For resources from other jurisdictions on information sharing agreements see: The Office of the Newfoundland and Labrador Information and Privacy Commissioner, Information Sharing Agreements: Essential Administrative Safeguards. The Government of Canada’s Guidance on Preparing Information Sharing Agreements Involving Personal Information. 363 SK OIPC resource, Best Practices for Information Sharing Agreements at p. 4. Originates from the Institute for Citizen-Centered Service resource, Guidelines for Best Practice. 364 British Columbia Government Services, FOIPPA Policy Definitions at https://www2.gov.bc.ca/gov/content/governments/services-for-government/policiesprocedures/foippa-manual/policy-definitions. Accessed April 23, 2020. 365 For more on requirements when outsourcing personal information outside of Canada, see SK OIPC Investigation Report F-2013-001.

RkJQdWJsaXNoZXIy MTgwMjYzOA==