An overview of privacy law that regulates private sector businesses in Canada (or those outside of the country who deal with personal information of Canadians): the Personal Information Protection and Electronic Documents Act (PIPEDA).
2:23 Why Canada has a mess of privacy laws
5:43 The Canadian Standards Association Model Code for the protection of personal information
6:40 How was the Personal Information Protection and Electronic Documents Act (PIPEDA) developed?
8:11 Key concepts - "commercial activity"
9:02 Key concepts - "personal information"
10:53 PIPEDA's baseline "reasonableness" requirement at s. 5(3)
12:16 Principle 1 - Accountability
16:09 Principle 2 - Identifying purposes
16:47 Principle 3 - Consent
20:13 Principle 4 - Limiting collection
20:58 Principle 5 - Limiting use, disclosure and retention
22:08 Principle 6 - Accuracy
22:47 Principle 7 - Safeguards
24:23 Principle 8 - Openness
25:49 Principle 9 - Individual access
26:58 Principle 10 - Challenging compliance
27:40 Enforcement under PIPEDA
31:22 Court applications under PIPEDA
34:16 Data breach notification
37:38 Real risk of significant harm (RROSH) analysis
40:25 Data breach record-keeping requirements
► Privacylawyer blog: https://blog.privacylawyer.ca
► My law firm: https://www.mcinnescooper.com/people/david-fraser
► Twitter: https://twitter.com/privacylawyer
► LinkedIn: https://www.linkedin.com/in/davidtsfraser
Disclaimer: This is intended for education and information only and should not be taken as legal advice. If you need advice for your particular situation, you should seek out qualified counsel.
All views expressed are solely those of the creator and should not be attributed to his firm or any of its clients.