Policy Statement:
The Region of Waterloo is committed to being open, accessible and transparent while maintaining the privacy of personal information, personal health information, and confidential information in its custody and control.
Providing access to records and protecting privacy are legislated obligations under the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA) and Personal Health Information Protection Act (PHIPA).
Regional records are public documents, subject to limited legislative exemptions, and are available for review in accordance with established procedures.
Purpose:
The purpose of this policy is to ensure compliance with the requirements of MFIPPA and PHIPA by establishing policies and procedures that facilitate access to public records while protecting the privacy of personal information, personal health information and confidential information.
This policy is designed to ensure fair and impartial access to corporate records and information in the custody and control of the Region. It also sets out the roles, responsibilities, and operational requirements around how personal information and personal health information are collected, used, disclosed, and disposed of by the Region.
This policy applies to all Regional employees and corporate records, including records and information of members of Council that are created and used for the purpose of carrying out Regional business.
Operating Principles:
Access to Information
The Region of Waterloo recognizes the right of individuals and groups to access information in its custody and control as an essential function of open government, accountability and transparency.
The Region will ensure that personal information and personal health information is as accurate, complete and up-to-date as is necessary for the purpose for which it is to be used. Individuals have a right to challenge the accuracy and completeness of their personal information or personal health information held by the Region and have it corrected as appropriate.
MFIPPA and PHIPA should only be used to supplement regular methods of requesting information. Access to information is provided by one of the four following methods:
- Information request – Most requests received by the Region are for public records and are not submitted under MFIPPA or PHIPA. Staff are encouraged to respond to these information requests unless the records contain another person’s personal information or personal health information; confidential information; or third party information which needs to go through the freedom of information request process.
- Routine disclosure request – Staff will respond to requests from individuals or employees for their own personal information or personal health information where a routine disclosure procedure has been adopted by the program. If a routine disclosure procedure doesn’t exist, the request will go through the freedom of information request process.
- Information corrections request – Personal information or personal health information correction requests are processed by the program area staff that holds the record in accordance with the relevant correction procedure.
- Freedom of information requests – Information Management & Archives is responsible for processing all formal MFIPPA requests. Public Health and Emergency Services Department and Sunnyside Home as health information custodians are responsible for processing all formal PHIPA requests. Delegated staff in those areas provide access, or give a copy of the requested records in accordance to the limited and specific exemptions and exclusions set out in MFIPPA or PHIPA.
See related request procedures for more information on responding to one of these request processes.
In order to facilitate access to records, the Region acknowledges the role that strong information management practices play in preventing records from being lost or inappropriately deleted, reducing search times and fees associated with mishandled information, and reducing the risk of privacy breaches. See the Information Management Accountability Operating Principle and Official Repository for Electronic Documents Operating Principle for more details on the responsibilities of employees to create and maintain accurate records of their activities.
Requesters’ identities are protected and are only disclosed when there is a clear need in order to facilitate a request or as required by legislation. Access decisions in response to requesters exercising their right to access Regional information will be made in a consistent manner regardless of the requesters’ identity.
Staff have a duty to ensure every reasonable effort is made to assist requestors, by providing complete, accurate and timely responses to their request using the appropriate access to information process. This includes working with the MFIPPA or PHIPA delegated staff and responding to requests for records as part of the freedom of information process in a timely manner.
In accordance with MFIPPA and PHIPA, it is an offence to willfully alter, conceal, destroy/delete, or cause any person to do so, with the intension of denying access to a record or information contained in a record.
Protection of Privacy
Maintaining the privacy of personal information, personal health information, and confidential information is an important ethical, professional and legal requirement in the relationship between the Region and individuals/third parties whose information is handled in the course of providing services. The following privacy protection standards are in effect constantly:
- Notice of Collection and Consent Requirements
- Staff may only collect personal information and personal health information with legal authority.
- The purpose for which personal information and personal health information is collected is identified to the individual at or before the time it is collected by way of a Notice of Collection.
- Staff make sure the knowledge and consent of the individual is obtained for the collection, use and disclosure of personal information or personal health information.
- Staff limit the collection of personal information and personal health information to only that which is necessary for the purposes identified and ensure information is collected by fair and lawful means.
- Use of Information Limitations
- Personal information and personal health information collected by the Region will only be used for the purpose for which it was obtained or for a consistent purpose.
- The use of personal information or personal health information for any other purpose must have the consent of the individual to whom the information relates or be required by law enforcement.
- Protection of Information
- All staff share responsibility for the protection and privacy of personal information, personal health information, and confidential information against theft or loss and unauthorized access, collection, use, disclosure, copying, modification, retention and disposal.
- The technical, administrative and physical safeguards in place will be appropriate to the information’s sensitivity, the format in which it is held, and the related privacy risks.
- Physical security measures will be put in place to prevent unauthorized access to personal information, personal health information, and confidential information by staff and external parties.
- Personal information, personal health information, and confidential information will not be left exposed or visible when unattended. Staff will lock computer and mobile device screens with passwords and put physical records in locked locations when not in use.
- System, software and email passwords allowing access to personal information, personal health information, or confidential information are not shared or disclosed to others.
- Security and privacy provisions are included in contracts with outside providers of records and information storage or disposal services.
- Retention of Information
- Personal information and personal health information will be retained only as long as is necessary according to the Corporate Information Retention and Disposal Schedule by-law.
- If not covered by the by-law, personal information and personal health information will be kept for a minimum of one year as prescribed by MFIPPA and PHIPA.
- Privacy Complaints
- The Region will readily make available specific information about its policies and practices related to the management of personal information and personal health information.
- The Region will address complaints concerning its access and privacy practices.
- Privacy Breach
- When discovered, staff will contain the effects of a breach of personal information or personal health information by determining the nature and scope of the incident, and issuing all required notifications through a clear communications and escalation plan according to the Privacy Breach Procedure.
- Where required by MFIPPA or PHIPA, privacy breaches will be reported to the Information & Privacy Commissioner of Ontario.
- Privacy Impact Assessments
- Staff shall work with Information Management & Archives to conduct a privacy impact assessment on every new or changed service, technology or initiative that involves the collection, use or disclosure of personal information or personal health information in accordance with the Privacy impact Assessment Procedure.
Responsibilities:
Head under MFIPPA
The Regional Clerk is accountable to Council for compliance with MFIPPA and will take reasonable steps to ensure that all staff handles personal information in compliance with MFIPPA. As set out in By-Law 04-92, the Regional Clerk is the head for the Region under MFIPPA.
Head under PHIPA
The Medical Officer of Health is accountable to the Board of Health for compliance with PHIPA and will take reasonable steps to ensure that all Public Health and Emergency Services Department staff (ROWPHE) handles personal health information in compliance with PHIPA. The Medical Officer of Health is known as the head for ROWPHE under PHIPA.
The Chief, Paramedic Services is accountable to Council for compliance with PHIPA and will take reasonable steps to ensure that all Paramedic Services staff handles personal health information in compliance with PHIPA. The Chief, Paramedic Services is known as the head for Paramedic Services under PHIPA.
The Director, Seniors’ Services is accountable to Council for compliance with PHIPA and will take reasonable steps to ensure that all Sunnyside Home staff handles personal health information in compliance with PHIPA. The Director, Senior’s Services is known as the head for Sunnyside Home under PHIPA.
Roles
Council approves this policy.
Chief Administrative Officer provides oversight and compliance with this policy by all Regional employees.
Regional Clerk acts as head under MFIPPA and is accountable for overseeing the administration of the legislation.
Manager, Information Management and Archives acts as the Freedom of Information Coordinator and is accountable for responding to formal FOI requests and access and privacy related issues, including privacy complaints.
Medical Officer of Health acts as head for ROWPHE under PHIPA and is accountable for overseeing the administration of the legislation.
Chief, Paramedic Services acts as head for Paramedic Services under PHIPA and is accountable for overseeing the administration of the legislation.
Director, Senior Services acts as head for Sunnyside Home under PHIPA and is accountable for overseeing the administration of the legislation. Supports routine disclosure practices to provide ease of access for clients.
Director, Information Technology Services ensures that the appropriate technological safeguards are implemented in accordance with MFIPPA and PHIPA.
Management takes reasonable steps to ensure that processes and practices for the handling of personal information or personal health information by their staff comply with MFIPPA or PHIPA. Supports routine disclosure practices to provide ease of access for clients.
Employees, Students, Consultants and Volunteers familiarize themselves with and follow any Region or program-specific procedures which direct or affect the handling of personal information or personal health information, as well as adhere to the Corporate Information Retention and Disposal Schedule by-law. Implements routine disclosure practices to provide ease of access for clients.
Definitions:
Consistent purpose means personal information or personal health information collected by the Region is used for the purpose for which it was collected or similar consistent purposes when carrying out Regional business. The individual to whom the information relates might reasonably expect the use or disclosure of their information for the consistent purposes.
Control of a record means the power or authority to make a decision about the use or disclosure of a record.
Custody of a record means the keeping, care, watch, preservation or security of a record for a legitimate business purpose. While physical possession of a record may not always constitute custody, it is the best evidence of custody.
Identifying information means information that directly identifies an individual or for which it is reasonably foreseeable in the circumstances, that the information could be utilized, either alone or with other information, to indirectly identify an individual.
Information & Privacy Commissioner of Ontario hears appeals of decisions made by municipalities, issues binding orders, conducts privacy investigations, and has certain powers relating to the protection of personal privacy as set out in MFIPPA and PHIPA.
Personal information means recorded information about an identifiable individual including, information relating to the race, colour, religion, age, sex, sexual orientation or marital status of the individual; information relating to education, medical, financial or employment history of the individual; any identifying number or symbol assigned to the individual; address, telephone number, fingerprints or blood type of the individual; personal opinions or views of the individual except if they relate to another individual; correspondence sent to an institution by the individual that is implicitly or explicitly of a private nature; views or opinions of another individual about the individual; and individual’s name if it appears with other personal information relating to the individual.
Personal health information includes identifying information about an individual in oral or recorded form, if the information:
- relates to the physical or mental health of the individual, including information that consists of the health history of the individual’s family;
- relates to the providing of health care to the individual, including the identification of a person as a provider of health care to the individual;
- relates to payments or eligibility for health care, or eligibility for coverage for health care, in respect of the individual;
- is the individual’s health card number; or
- identifies an individual’s substitute decision-maker.
Privacy impact assessment is the process for identifying, assessing and mitigating privacy risks. The Region develops and maintains privacy impact assessments for all new or modified programs that involve the collection, use, or disclosure of personal information or personal health information.
Public record is a record that has passed through an open public process, thereby making it a public record that can be provided to a requester without going through a routine disclosure or freedom of information request process.
Record means any information however recorded, whether in printed form, on film, by electronic means or otherwise, and includes the following: correspondence, memorandum, book, plan, map, drawing, diagram, pectoral or graphic work, photograph, film, microfilm, sound recordings, videotape, machine readable record, any other documentary material, regardless of physical form or characteristics, and any copy thereof.
Substitute decision-maker means a person who is authorized under MFIPPA or PHIPA to consent on behalf of the individual to the collection, use or disclosure of personal information or personal health information about the individual or exercise the right to request access to or correction of personal information or personal health information. A substitute decision-maker may include:
- a person legally authorized to make a decision about treatment on behalf of an individual who is not capable;
- a person acting with the written authorization of the affected individual in relation to the individual’s personal information or personal health information;
- a guardian or parent with lawful custody of a child less than 16 years of age;
- the estate trustee or other responsible person in relation to the personal information or personal health information of a deceased individual; or
- other persons authorized under the law of Ontario or Canada to act on behalf of the individual (e.g. the public guardian and trustee or the office of the children’s lawyer).
