Office of the Saskatchewan Information and Privacy Commissioner. Guide to LA FOIP, Chapter 6, Protection of Privacy. Updated 27 February 2023. 123 • Misuse of information – e.g., transfer of or sale of personal information in contravention of LA FOIP.341 Local authorities should determine the likelihood (low, medium, or high) of each or any of the above threats occurring. Identify the potential consequences and rate the seriousness (less serious, serious, or very serious) of the events if they were to occur.342 Subsection 23.1(c) Duty of local authority to protect 23.1 Subject to the regulations, a local authority shall establish policies and procedures to maintain administrative, technical and physical safeguards that: … (c) otherwise ensure compliance with this Act by its employees. It is expected that a local authority will have appropriate safeguards in place to protect personal information.343 Local authorities should have written policies and procedures in place to guide employees with what is required by law concerning privacy protection for personal information. Without written policies and procedures, a local authority has not taken reasonable steps to safeguard personal information in its possession or control.344 Local authorities are responsible for taking steps to ensure that its officers and staff comply with the protection of privacy requirements under LA FOIP. This involves: • Ensuring that policies and procedures that safeguard personal information are in place, • That officers and staff are aware and understand the policies and procedures; and 341 Government of Alberta, Health Information Act, Guidelines and Practices Manual, March 2011 at p. 318. Available at https://open.alberta.ca/dataset/50877846-0fba-4dbb-a99feeb651533bc4/resource/3e16d527-2618-48ae-80b8-93f69973878e/download/hia-guidelinespractices-manual.pdf. Accessed June 23, 2020. 342 Government of Alberta, Health Information Act, Guidelines and Practices Manual, March 2011 at p. 318. Available at https://open.alberta.ca/dataset/50877846-0fba-4dbb-a99feeb651533bc4/resource/3e16d527-2618-48ae-80b8-93f69973878e/download/hia-guidelinespractices-manual.pdf. Accessed June 23, 2020. 343 SK OIPC Investigation Report 200-2018 at [34]. 344 SK OIPC Investigation Reports H-2011-001, F-2007-001 at [48] and LA-2013-003 at [54] to 57].
RkJQdWJsaXNoZXIy MTgwMjYzOA==