• About
  • Offices
  • Careers
  • News
  • Students
  • Alumni
  • Payments
  • EN | FR
Background Image
Bennett Jones Logo
  • People
  • Expertise
  • Knowledge
  • Search
  • FR Menu
  • Search Mobile
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
View all
Practices
Corporate Litigation Regulatory Tax View all
Industries
Energy Infrastructure Mining Private Equity & Investment Funds View all
Advisory
Crisis & Risk Management Public Policy
View Client Work
International Experience
Insights News Events Subscribe
Arbitration Angle Artificial Intelligence Insights Business Law Talks Podcast Class Actions: Looking Forward Class Action Quick Takes
Economic Outlook New Energy Economy Series Quarterly Fintech Insights Quarterly M&A Insights Sustainability & the CIO
People
Offices
About
Practices
Industries
Advisory Services
Client Work
Insights
News
Events
Careers
Law Students
Alumni
Payments
Search
Subscribe

Stay informed on the latest business and legal insights and events.

LinkedIn LinkedIn Twitter Twitter Vimeo Vimeo
 

Four Key Steps For Privacy Compliance

April 02, 2005

Written By Stephen D. Burns

As your organization works towards compliance with Canada's private sector privacy legislation, consider undertaking these four key steps and their component activities.

Step One: Getting Started

  • Develop support within your organization's leadership. Privacy compliance is a corporate governance issue and the support of the Board of Directors and Senior Management Team is essential to a successful privacy compliance program.
  • Appoint a Privacy Officer/Manager. This individual should possess the leadership skills necessary to develop and implement the privacy compliance program.
  • Determine which law applies: international, federal or provincial/territorial privacy legislation.

Step Two: Understanding the Organization's Privacy Activities

  • Understand the existing information practices of the organization. Investigate how the organization collects, uses, discloses, retains, destroys and secures personal information. Consider if an individual's consent is obtained when the personal information is collected for the purpose for which the information is collected, used or disclosed.
  • Assess the 'gaps' between practices and legislative requirements. Compare the organization's current activities and practices against the requirements of the applicable privacy legislation and identify the 'gaps' that exist between the organization's practices and the legislative requirements.

Step Three: Developing & Implementing Policies and Practices

  • Develop privacy policies and practices. The organization's policies and practices will govern its privacy activities and provide a basis for training its employees and communicating its privacy activities to its customers and third parties.
  • Develop an implementation plan. The implementation plan should establish how the organization will: obtain consent from individuals for the collection, use and disclosure of their personal information; manage the exchange of personal information with third party service providers and business associates; manage the changes to its processes and activities required to address the 'gaps' identified above and implement the organization's privacy policies and practices; and, communicate its privacy policies and practices to internal and external parties.
  • Train your employees, volunteers and independent contractors. Ensure that your organization is ready for the introduction of the privacy legislation and understands your organization's privacy policies and practices.
  • Review or initiate third party service provider or business associate agreements. Ensure that the agreements governing the exchange of personal information contain the necessary privacy representations, warranties, covenants and indemnities to protect the organization.

Step Four: Ongoing Compliance Activities

  • Manage access to personal information. Implement mechanisms to ensure that the organization is compliant with the privacy legislation's requirement that an individual be able to access and challenge the accuracy of its personal information. Develop reports to record such activities. Ensure that applicable timelines are met.
  • Manage complaints in respect of personal information. Implement mechanisms to ensure that the organization manages complaints from point of receipt to resolution. Ensure that applicable time-lines are met.
  • Enforce the organization's privacy policies and practices. Implement mechanisms to ensure that the organization's privacy policies and practices are consistently applied, and develop sanctions where necessary for failure to comply.
  • Undertake periodic reviews. Develop a plan for periodic review of documentation, policies, procedures and systems to ensure their timeliness and accuracy.

Please note that this publication presents an overview of notable legal trends and related updates. It is intended for informational purposes and not as a replacement for detailed legal advice. If you need guidance tailored to your specific circumstances, please contact one of the authors to explore how we can help you navigate your legal needs.

For permission to republish this or any other publication, contact Amrita Kochhar at kochhara@bennettjones.com.

Key Contact

  • Stephen D. Burns Stephen D. Burns, Partner, Trademark Agent

Related Links

  • Insights
  • Media
  • Subscribe

Related Expertise

  • Privacy & Data Protection

Recent Posts

Announcements

Bennett Jones Wins Big at Benchmark Litigation Awards

May 09, 2025
       

In The News

Managing Risk Amid Tariff Chaos

May 09, 2025
       

Speaking Engagements

Insights on Tariff Strategy and Cross-Border Trade Compliance

May 08, 2025
       

In The News

John Manley on NPR’s Morning Edition on Mark Carney’s White House Visit

May 06, 2025
       

Speaking Engagements

Brendan Sigalet on Clean Investment Tax Credits

May 05, 2025
       

Speaking Engagements

Due Diligence for Tenants at ICSC CANADIAN LAW

May 02, 2025
       

Announcements

Bennett Jones Lawyers Named Among Canada’s Top Litigators By Benchmark Canada

May 01, 2025
       

Announcements

Twenty-Six Bennett Jones Lawyers Ranked in Lexpert's Special Edition on Infrastructure

April 30, 2025
       

Announcements

Jesslyn Maurier Appointed to Ontario Chamber of Commerce’s Board of Directors

April 29, 2025
       
Bennett Jones Centennial Footer
Bennett Jones Centennial Footer
About
  • Leadership
  • Diversity
  • Community
  • Innovation
  • Security
Offices
  • Calgary
  • Edmonton
  • Montréal
  • Ottawa
  • Toronto
  • Vancouver
  • New York
Connect
  • Insights
  • News
  • Events
  • Careers
  • Students
  • Alumni
Subscribe

Stay informed on the latest business and legal insights and events.

LinkedIn LinkedIn Twitter Twitter Vimeo Vimeo
© Bennett Jones LLP 2025. All rights reserved.
  • Privacy Policy
  • Disclaimer
  • Terms of Use
Logo Bennett Jones