Office of the Saskatchewan Information and Privacy Commissioner. Guide to FOIP, Chapter 6, Protection of Privacy. Updated 27 February 2023. 345 • Company name. • A unique serialized transaction number. • The transfer of custody. • A reference to the terms and conditions. • The acceptance of fiduciary responsibility. • The date and time the information ceased to exist. • The location of the destruction. • The witness to the destruction. • The method of destruction. • A reference to compliance with the contract (if employing a secure destruction service provider). • Signature. Organizations creating internally generated Certificates of Destruction may also wish to include fields such as: who the destruction was conducted by (name, title, contact information, department, etc.); when collection of the information to be destroyed began (if using a centralized model of internal destruction); the type of media collected and from which specific containers; and the time at which the collection was completed. Regarding the destruction event itself, the internally generated Certificate of Destruction may detail the start time, location, equipment used, quantity destroyed, and destruction completion time. An organization may develop a process to certify the destruction of batches of records or media. (iii) Logs In addition, creating a log for the destruction of records not subject to the organization’s retention schedule, such as incidental and duplicate records, organizations may also include a provision in their secure destruction policy to create a record documenting the destination and disposal of the media particles following the destruction. In addition, the results of random sampling audits following the degaussing and sanitization process for electronic media should be logged. E. Considerations Prior to Employing a Service Provider (i) Criteria for choosing a service provider Organizations should develop criteria for choosing a secure destruction service provider and include it in their secure destruction policy. For example, organizations may wish to
RkJQdWJsaXNoZXIy MTgwMjYzOA==