Guide to LA FOIP-Chapter 6

Office of the Saskatchewan Information and Privacy Commissioner. Guide to LA FOIP, Chapter 6, Protection of Privacy. Updated 27 February 2023. 129 In addition to what LA FOIP and the LA FOIP Regulations require in an information management sharing agreement, there are also some best practices to keep in mind. A well written agreement should also include: • Identities, roles, and responsibilities of the parties. • What information is being disclosed and collected and the purpose(s) of each. • The frequency and duration of information exchanged. • The legal authority to disclose and collect information. • The methods and security measures for transferring and storing the information. • Procedures in the event there is a privacy or security breach. • Limitations for collection, use, disclosure, and retention. • Provisions for accuracy of the information. • Indemnification. • Compliance monitoring.353 An information management service provider must comply with the terms and conditions of the agreement. Comply with means to act in accordance with or fulfil the requirements.354 LA FOIP does not prohibit the transfer of personal information to outside of Canada. However, any local authority outsourcing personal information outside of Canada still has several obligations under LA FOIP such as ensuring safeguards are adequate, a detailed contract is in place and other provisions of LA FOIP are met.355 For more on best practices and developing information sharing agreements, see SK OIPC resource, Best Practices for Information Sharing Agreements. For resources from other jurisdictions on information sharing agreements see: The Office of the Newfoundland and Labrador Information and Privacy Commissioner, Information Sharing Agreements: Essential Administrative Safeguards. The Government of Canada’s Guidance on Preparing Information Sharing Agreements Involving Personal Information. 353 SK OIPC resource, Best Practices for Information Sharing Agreements at p. 4. Originates from the Institute for Citizen-Centered Service resource, Guidelines for Best Practice. 354 British Columbia Government Services, FOIPPA Policy Definitions at https://www2.gov.bc.ca/gov/content/governments/services-for-government/policiesprocedures/foippa-manual/policy-definitions. Accessed April 23, 2020. 355 For more on requirements when outsourcing personal information outside of Canada, see SK OIPC Investigation Report F-2013-001.

RkJQdWJsaXNoZXIy MTgwMjYzOA==