The purpose of this policy is to facilitate the Regional District of Central Kootenay’s compliance with the Freedom of Information and Protection of Privacy Act and other relevant privacy law, including but not limited to regulations, statutory guidelines, codes of practice, and other privacy directions in the collection, storage, access, use, and disclosure of personal information.
This policy applies to the overall management of personal information including the collection, storage, access, use and disclosure of personal information. All employees must comply with this policy and other privacy directions as part of the RDCK’s privacy management program.
Collection: Obtaining or compiling personal information directly from the individual the information is about or indirectly by another method of collection
Consent: Agreement by an individual for the RDCK to collect, use, and disclose their personal information
Consistent Purpose: A use or disclosure of personal information which is consistent with the purpose for which the information was obtained or compiled if the use or disclosure has a reasonable and direct connection to that purpose, and it is necessary for performing the statutory duties of, or for operating a legally authorized program or activity of the RDCK
Contact Information: Information to enable an individual to be contacted at a place of business, including the name, position name or title, business telephone number, business address, business email or business fax number of the individual
Employee: Includes all RDCK employees, whether full-time, part-time, permanent, temporary, or volunteer
Disclosure: Communication or transfer of personal information outside the RDCK
FIPPA: Freedom of Information and Protection of Privacy Act
Personal Information: Recorded information about an identifiable individual other than contact information
Privacy: The rights and obligations of individuals and organizations with respect to the collection, use, retention, disclosure, and disposal of personal information
RDCK: Regional District of Central Kootenay
Third Party: In relation to the collection, use, or disclosure of personal information, a third party is any person, group of persons or organizations other than the individual the personal information is about and the RDCK
Use: Communication or handling of personal information within the RDCK
Roles and Responsibilities
It is the responsibility of the Privacy Officer (or designate) to:
It is the responsibility of all employees and RDCK directors to:
Collection of Personal Information
The RDCK will only collect personal information where collection is for a lawful purpose which is directly related to one of its programs or activities and is reasonably necessary for that purpose. The RDCK may also collect personal information if the information is necessary for planning or evaluating one of its programs or activities.
The RDCK will ensure that the personal information being collected is relevant, accurate, complete, and not excessive.
The RDCK will collect personal information directly from the individual concerned unless it is unreasonable or impracticable to do so. The RDCK can collect personal information from a source other than the individual concerned if the indirect method of collection is authorized by the individual the information is about, another enactment authorizes the collection, the information is collected for the purposes of a legal proceeding, collecting a debt or fine, or law enforcement, or the information has been disclosed to the RDCK as authorized by FIPPA.
The RDCK will collect personal information in an open manner, including informing individuals that personal information is being collected, the purpose for the collection, the legal authority for the collection, and who can be contacted to answer questions about the collection.
Use of Personal Information
The RDCK will only use personal information for the purpose for which it was collected, or for a consistent purpose. The RDCK may also use personal information if the individual has provided consent in writing and has specified the personal information for which the individual is providing consent.
Disclosure of Personal Information
The RDCK will only disclose personal information if the disclosure of the personal information is directly related to the primary purpose for which the personal information was collected or for a use consistent with that purpose, the individual has identified the information and consented to its disclosure, or the disclosure is required or authorized by an enactment.
Personal information may be disclosed to an employee of the RDCK if the information is necessary for them to perform their duties as an employee of the RDCK. Any employee of the RDCK or employee of a service provider, who has access, whether authorized or unauthorized, to personal information in the custody or control of a public body, must not disclose that information except as authorized under FIPPA.
Protection of Personal Information
The RDCK will take reasonable steps to ensure that personal information in its custody or control is protected by making reasonable security arrangements against such risks as unauthorized access, collection, use, disclosure or disposal.
When the RDCK retains an external organization to undertake work on its behalf that involves the collection, use, or disclosure of personal information, the RDCK will enter into an agreement with that organization that requires the organization to protect personal information in accordance with FIPPA, including limiting use and disclosure of personal information by the organization to specified contractual purposes, taking reasonable security measures to protect personal information, complying with the RDCK’s privacy policies, and requiring notice to the RDCK in the event of a privacy-related contract breach.
Personal information in the custody or control of the RDCK will be stored and accessed only in Canada unless the individual the information is about has consented to storage or access in another jurisdiction, or it is allowed under FIPPA.
Access, Accuracy and Correction of Personal Information
The RDCK will respond to enquiries from an individual as to whether it holds that individual’s personal information including any rights of access to it. The RDCK will allow an individual to access their own personal information held by the RDCK and make appropriate amendments, corrections or updates to their personal information where necessary. Individuals can request access and correction to their personal information in the custody or under the control of the RDCK by contacting the Privacy Officer.
All reasonable steps will be taken by the RDCK to ensure that personal information it collects, holds, or discloses is accurate, complete, and up to date.
If a correction is requested but no correction is made, the RDCK must annotate the information with the correction that was requested but not made. On correcting or annotating personal information, the RDCK must notify any other public body or third party to whom that information has been disclosed during the one year period before the correction was requested.
Retention and Disposition of Personal Information
The RDCK will retain personal information that has been used to make a decision affecting the individual the information is about for a minimum of one year. All information, including personal information, is still subject to retention schedules based on business, legal, and regulatory needs.
Records containing personal information will be disposed of in accordance with an approved retention schedule. Physical records will be destroyed by confidential shredding and electronic records will be destroyed by an appropriate digital sanitation method such as deletion, degaussing, overwriting, or other method of disposal that ensures complete destruction of the information.
Freedom of Information and Protection of Privacy Act [RSBC 1996]
I agree to allow the Regional District of Central Kootenay to contact me by email or text regarding emergency events. I may withdraw my consent at any time by contacting Fire and Emergency Services at 250.352.8154, firstname.lastname@example.org or RDCK, PO Box 590, 202 Lakeside Drive, Nelson, BC V1L 5R4.
This personal information is being collected under the authority of section 26(c) of the Freedom of Information and Protection of Privacy Act [RSBC 1996]. It will be used to contact you in case of an emergency event occurring in the area in which you live or are visiting. It will be not be used or disclosed for other purposes. If you have any questions about the collection of your personal information, contact the Privacy Officer at 250.352.8166, email@example.com, or RDCK Privacy Officer, Box 590, 202 Lakeside Drive, Nelson, BC V1L 5R4.