- Purposes of Collecting Personal Information
- Limiting Collection
- Limiting Use, Disclosure and Retention
- Individual Access
- Accessibility of Facilities
- Service Animals
- Support Persons
- Disruption of Services
- Assistive Devices
- Feedback Process
- Communication About the Accessibility Policy
- Policy Review
HCDC is a federally supported not-for-profit community organization with a volunteer board of directors and professional staff whose purpose is to develop and diversify local economies. HCDC supports community economic development and small business growth by developing and implementing strategic community plans, delivering a range of counselling and information services to small business and operating locally controlled investment funds to provide repayable financing to new and existing businesses.
1.1 The Ten Principles of PIPEDA Summarized
- Accountability: organizations are accountable for the personal information they collect, use, retain and disclose in the course of their commercial activities, including, but not limited to, the appointment of a Chief Privacy Officer;
- Identifying Purposes: organizations are to explain the purposes for which the information is being used at the time of collection and can only be used for those purposes;
- Consent: organizations must obtain an Individual’s express or implied consent when they collect, use, or disclose the individual’s personal information;
- Limiting Collection: the collection of personal information must be limited to only the amount and type that is reasonably necessary for the identified purposes;
- Limiting Use, Disclosure and Retention: personal information must be used for only the identified purposes, and must not be disclosed to third parties unless the Individual consents to the alternative use or disclosure;
- Accuracy: organizations are required to keep personal information in active files accurate and up-to-date;
- Safeguards: organizations are to use physical, organizational, and technological safeguards to protect personal information from unauthorized access or disclosure.
- Openness: organizations must inform their clients and train their employees about their privacy policies and procedures;
- Individual Access: an individual has a right to access personal information held by an organization and to challenge its accuracy if need be; and
- Provide Recourse: organizations are to inform clients and employees of how to bring a request for access, or complaint, to the Chief Privacy Officer, and respond promptly to a request or complaint by the individual.
"Personal information" means any information about an identifiable individual. It includes, without limitation, information relating to identity, nationality, age, gender, address, telephone number, e-mail address, Social Insurance Number, date of birth, marital status, education, employment health history, assets, liabilities, payment records, credit records, loan records, income and information relating to financial transactions as well as certain personal opinions or views of an Individual.
"Business information" means business name, business address, business telephone number, name(s) of owner(s), officer(s) and director(s), job titles, business registration numbers (GST, RST, source deductions), financial status. Although business information is not subject to PIPEDA, confidentiality of business information will be treated with the same security measures by HCDC staff, members and Board members, as is required for individual personal information under PIPEDA.
"Client" means the business that is applying for or has been approved for a loan, (including sole proprietorships and individuals carrying on business in a partnership);
"Individual" means the client’s owner(s) or shareholders, co-signors, and/or any guarantor associated with a client.
"Member" means a person who volunteers on a HCDC committee, but who is not a current or active board member, or chair of the committee.
"Application" means the application form or related forms completed by the individual(s) to request financing for the client through the Investment Fund of HCDC.
"Data base" means the list of names, addresses and telephone numbers of clients and individuals held by HCDC in the forms of, but not limited to, computer files, paper files, and files on computer hard-drives.
"File" means the information collected in the course of processing an application, as well as information collected/updated to maintain /service the account.
"Express consent" means the individual signs the application, or other forms containing personal information, authorizing HCDC to collect, use, and disclose the individual's personal information for the purposes set out in the application and/or forms.
"Implied Consent" means the organization may assume that the individual consents to the information being used, retained and disclosed for the original purposes, unless notified by the individual.
"Third Party" means a person or company that provides services to HCDC support of the programs, benefits, and other services offered by HCDC, such as other lenders, credit bureaus, persons with whom the individual or client does business, but does not include any Government office or department to whom HCDC reports in the delivery of such programs, benefits or services.
2.0 Purposes of Collecting Personal Information
Personal information is collected in order to assess the eligibility of the individual completing an application for financial assistance, as well as to report to FedDev. The individual is the main source of information but HCDC will also ask to obtain information directly from a third source where the individual does not have the required information.
Only that information which is required to make a determination of an individual's eligibility will be collected. Although the individual's Social Insurance Number may be requested in the application for confirming identification of the individual to the credit reporting agency, provision of this personal information is optional. The individual may provide alternative forms of identification, such as date of birth and driver's license number.
An individual’s express, written consent will be obtained before or at the time of collecting personal information. The purposes for the collection, use or disclosure of the personal information will be provided to the individual at the time of seeking his or her consent. Once consent is obtained from the individual to use his or her information for those purposes, HCDC has the individual's implied consent to collect or receive any supplementary information that is necessary to fulfil the same purposes. Express consent will also be obtained if, or when, a new use is identified.
By signing the application and/or other forms, implied consent is granted by the individual to obtain and/or to verify information from third parties such as banks, credit bureaus, other lenders, and insurance companies in the process of assessing the eligibility of an individual or client. Implied consent is also granted by the individual to permit HCDC to report or otherwise disclose information to FedDev, the federal department that administers the Ontario Community Futures Program.
An individual can choose not to provide some or all of the personal information at any time, but if HCDC is unable to collect sufficient information to validate the request for financing, the individual's application for such financing may be turned down.
Express consent will be obtained from the individual prior to disclosing the individual's personal information to other lenders, credit insurers and credit bureaus.
4.0 Limiting Collection
5.0 Limiting Use, Disclosure and Retention
5.1 Use of Personal Information
Personal information will be used for only those purposes to which the individual has consented with the following exceptions, as permitted under PIPEDA:
HCDC will use personal information without the individual's consent, where:
- the organization has reasonable grounds to believe the information could be useful when investigating a contravention of a federal, provincial or foreign law and the information is used for that investigation;
- an emergency exists that threatens an individual’s life, health or security;
- the information is for statistical study or research;
- the information is publicly available;
- the use is clearly in the individual’s interest, and consent is not available in a timely way;
- knowledge and consent would compromise the availability or accuracy of the information, and
- collection is required to investigate a breach of an agreement.
5.2 Disclosure and Transfer of Personal Information
Personal information will be disclosed to only those HCDC employees, members of HCDC committees, and the Board of Directors that need to know the information for the purposes of their work or making an assessment as to the individual's eligibility to the loan program.
Personal information will be disclosed to third parties with the individual's knowledge and consent.
PIPEDA permits HCDC to disclose personal information to third parties, without an individual's knowledge and consent, to:
- a lawyer representing HCDC;
- collect a debt owed to HCDC by the individual or client;
- comply with a subpoena, a warrant or an order made by a court or other body with appropriate jurisdiction;
- a law enforcement agency in the process of a civil or criminal investigation;
- a government agency or department requesting the information; or,
- as required by law.
PIPEDA permits HCDC to transfer personal information to a third party, without the individual's knowledge or consent, if the transfer is simply for processing purposes and the third party only uses the information for the purposes for which it was transferred. HCDC will ensure, by contractual or other means that the third party protects the information and uses it only for the purposes for which it was transferred.
5.3 Retention of Personal Information
Personal information will be retained in client files as long as the file is active and for the length of the Federal Contribution Agreement + seven (7) years from the expiry of the Agreement or its early termination in accordance with the Agreement.
A file will be deemed inactive if the Investment Committee rejects an application, when a loan is repaid in full and securities are discharged, or when a guarantee is terminated. Information contained in an inactive file will be retained for the length of the Federal Contribution Agreement + seven (7) years from the expiry of the Agreement or its early termination in accordance with the Agreement, except in the case where an application is rejected. Where an application has been rejected, the file and all personal information contained in the file will be retained for a period of two (2) years.
HCDC endeavours to ensure that any personal information provided by the individual in his or her active file(s) is accurate, current and complete as is necessary to fulfill the purposes for which the information has been collected, used, retained and disclosed. Individuals are requested to notify HCDC of any change in personal or business information.
Information contained in inactive files is not updated.
Organizational Safeguards: Access to personal information will be limited to the Loans Officer, the Loans & Office Administrator, and/or the Executive Director who have to make a determination as to the individual's eligibility for a business loan. Personal information provided to members of HCDC committee(s) will be limited to only that information required to carry out the mandate of that committee. Members of the HCDC committee(s) and/or Board of Directors are not permitted to copy or retain any personal information on individuals or clients and must return for destruction all such information given to them to review once the purpose for being provided with this information has been fulfilled.
Employees and members of HCDC committee(s) and/or Board of Directors are required to sign a confidentiality agreement binding them to maintaining the confidentiality of all personal information to which they have access.
Physical Safeguards: Active files are stored in locked filing cabinets when not in use. Access to work areas where active files may be in use is restricted to HCDC employees only and authorized third parties.
All inactive files or personal information no longer required are shredded prior to disposal to prevent inadvertent disclosure to unauthorized persons.
Technological Safeguards: Personal information contained in HCDC computers and electronic data bases are password protected in accordance with HCDC's Information Security Policy. Access to any of the HCDC's computers also is password protected. HCDC's Internet router or server has firewall protection sufficient to protect personal and confidential business information against virus attacks and "sniffer" software arising from Internet activity. Personal information is not transferred to volunteer committee members, the Board of Directors, or third parties by e-mail or other unsecured electronic form.
9.0 Individual Access
An Individual who wishes to review or verify what personal information is held by HCDC, or to whom the information has been disclosed (as permitted by the Act), may make the request for access, in writing, to the HCDC's Chief Privacy Officer. Upon verification of the individual's identity, the Chief Privacy Officer will respond within 60 days.
If the individual finds that the information held by HCDC is inaccurate or incomplete, upon the individual providing documentary evidence to verify the correct information, HCDC will make the required changes to the individual's active file(s) promptly.
If an individual has a concern about HCDC's personal information handling practises, a complaint, in writing, may be directed to the HCDC's Chief Privacy Officer.
Upon verification of the individual's identity, HCDC's Chief Privacy Officer will act promptly to investigate the complaint and provide a written report of the investigation's findings to the individual.
Where HCDC's Chief Privacy Officer makes a determination that the individual's complaint is well founded, the Chief Privacy Officer will take the necessary steps to correct the offending information handling practise and/or revise HCDC's privacy policies and procedures.
Where HCDC's Chief Privacy Officer determines that the individual's complaint is not well founded, the individual will be notified in writing.
If the individual is dissatisfied with the finding and corresponding action taken by HCDC's Chief Privacy Officer, the individual may bring a complaint to the Federal Privacy Commissioner at the address below:
The Privacy Commissioner of Canada Tel 1-800-282-1376
30 Victoria Street Fax 1-819-994-5424
Gatineau, Quebec K1A 1H3
11.0 Questions/Access Request/Complaint
Patti Tallman, Chief Privacy Officer
Email address: firstname.lastname@example.org
Haliburton County Development Corporation
235 Highland Street, 2nd Floor
Amendment to HCDC's Privacy Policies
It is the policy of the Haliburton County Development Corporation (HCDC) that persons with disabilities achieve accessibility to the services by the HCDC consistent with the principles of independence, dignity, integration and equality of opportunity as set out in the regulations of the Accessibility for Ontarians With Disabilities Act, 2005.
1. Accessibility of Facilities
HCDC will ensure that its services are accessible to persons with mobility challenges. This will be accomplished by providing accessibility for persons with a disability and their attendant to the HCDC office and/or providing alternative meeting space that provides accessibility and the same level of confidentiality as the main office.
HCDC will, provide facilities that are consistent with the principles of independence, dignity, integration and equality of opportunity.
HCDC will ensure that spaces used for workshops, meetings and forums are accessible to persons with mobility challenges.
2. Service Animals
If a person with a disability is accompanied by a guide dog or other service animal, the HCDC welcomes the person to enter the premises with the animal and keep it with him or her.
'Service Animal' is an animal which is specially trained to assist a person with a disability. A service animal must be readily identifiable as a service animal. If it is not, users of HCDC services may be requested to provide proof.
3. Support Persons
If a person with a disability is accompanied by a support person, they are permitted to enter the premises together and are not prevented from having access to each other while on the premises. HCDC may require a person with a disability to be accompanied by a support person while on its premises, but only if a support person is necessary to protect the health or safety of the person with a disability or the health or safety of others on the premises.
Where HCDC offers workshops or forums that require a fee for entrance, HCDC will waive the fee for the support person.
4. Disruption of Services
If there is a temporary disruption in a particular facility or service used to allow a person with a disability to access HCDC services, HCDC will give notice of the disruption to the public.
5. Assistive Devices
If a person with a disability requires assistive devices to access services of HCDC, the HCDC will attempt to make the accommodations required for the use of these devices.
HCDC will provide training for its staff, contractors and volunteers who interact with the public or other third parties on behalf of HCDC on customer service standards for the provision of services to persons with disabilities.
HCDC will advise applicants for HCDC funding that effective January 1, 2012, they should be in compliance with Accessibility for Ontarians With Disabilities Act, 2005.
HCDC will ensure that its practices allow for the involvement of persons with disabilities on committees and the board of directors.
9. Feedback Process
The HCDC Executive Director will be the contact person for people wishing to give feedback on how HCDC provides services to persons with disabilities. This information will be shared with the Assistant Director and the Executive of the Board of Directors and will be addressed in a timely fashion. The feedback process will be posted on the HCDC website and posted in the HCDC office.
10. Communication About The Accessibility Policy
HCDC will post the HCDC Accessibility Policy on its website, include it in the HCDC policy manual, and have the policy displayed in its office.
11. Policy Review
This policy will be reviewed on an annual basis by the Executive Committee of the Board of Directors of HCDC.