ACCOUNTABLILITY FOR PERSONAL INFORMATION
Goodwill is responsible for personal information under its control
and has designated an individual, the Privacy Officer, who is accountable
for Goodwill’s compliance with the Privacy Legislation of
Canada. At Goodwill, the overall responsibility for ensuring our
compliance with PIPEDA rests with the Vice President, Human Resources,
who is designated as the Chief Privacy Officer.
Goodwill is responsible for Personal Information in our possession
or custody, including Personal Information that we transfer to third
parties for processing. We require that our service providers agree
to contractual requirements that are consistent with our privacy
and security policies. Our service providers are prohibited from
using Personal Information except for the specific purpose for which
we supply it to them.
IDENTIFYING PURPOSES FOR THE COLLECTION OF PERSONAL INFORMATION
Goodwill shall identify the purposes for which Personal Information
is collected at or before the time the information is collected.
Goodwill shall collect only that information necessary for the purposes
that have been identified. Goodwill may advise the purposes orally
or in writing. Unless required by law, Goodwill shall not use Personal
Information for a new purpose without the knowledge and consent
of the individual to whom the information relates. Goodwill shall
train on privacy principles or communicate with employees so that
the persons collecting Personal Information will be able to explain
to individuals the purposes for which the information is being collected.
CONSENT
Goodwill shall seek informed consent for the use or disclosure of
Personal Information at the time of collection. However, Goodwill
may seek consent to use and disclose the Personal Information after
it has been collected but before it is used or disclosed for a new
purpose. Goodwill shall accept consent given by an authorized representative
(such as a legal guardian or a person having power of attorney).
Goodwill shall make reasonable efforts to ensure that the individual
is advised of the identified purposes for which the information
will be used. The purposes shall be stated in a manner that can
be reasonably understood by the individual. Goodwill shall consider
the sensitivity of the Personal Information and the reasonable expectations
of an individual while determining the appropriate form of consent.
Goodwill shall obtain express consent in all cases where the Personal
Information involved is considered highly sensitive.
LIMITING COLLECTION
Goodwill shall limit both the amount and the type of information
collected to that which is necessary to fulfill the purposes identified.
Goodwill shall collect Personal Information by fair and lawful means.
Goodwill shall not collect Personal Information indiscriminately.
LIMITING USE, DISCLOSURE, AND RETENTION
Personal Information shall not be used or disclosed for purposes
other than those for which is was collected, except with the consent
of the individual or as required by law and it shall be retained
only as long as necessary for the fulfillment of those purposes.
ACCURACY
Goodwill shall ensure that Personal Information including information
disclosed to third parties is as accurate, complete and up-to-date
as is necessary for the purposes for which it is to be used. Goodwill
shall update Personal Information as and when necessary to fulfill
the identified purposes or upon notification from the individual.
SAFEGUARDS
Goodwill shall protect Personal Information by security safeguards
appropriate to the sensitivity level of the information. Goodwill
shall protect Personal Information against such risks as lose or
theft, unauthorized access, disclosure, copying, use, or modification
or destruction, through appropriate security measures including
physical, organizational, and technological measures. Goodwill shall
protect Personal Information regardless of the format in which it
is held. Goodwill shall exercise care in the disposal or destruction
of Personal Information to prevent unauthorized parties from gaining
access to the information.
Goodwill shall communicate or provide training on the importance
of maintaining the confidentiality of Personal Information. All
employees of Goodwill shall be required as a condition of employment
to respect and maintain the confidentiality of Personal Information.
Goodwill shall protect Personal Information disclosed to third
parties by contractual agreements stipulating the confidentiality
of the information and the purposes for which it is to be used.
Further, Goodwill requires the third parties to provide a comparable
level of protection to Personal Information that we may supply to
them. Goodwill may conduct third party privacy audit to ensure compliance
with this policy.
OPENNESS
Goodwill shall make readily available to individuals specific information
about its policies and practices relating to the management of Personal
Information. All individuals will be able to acquire information
about Goodwill’s privacy policy procedures and practices without
unreasonable effort.
INDIVIDUAL ACCESS
Upon request, Goodwill shall inform an individual of the existence,
use, and disclosure of his or her personal information and shall
give access to that information. An individual will be able to challenge
the accuracy and completeness of the information and have it amended
as appropriate. Exceptions my include information that contains
references to other individuals, or information that cannot be disclosed
for legal or security reasons. |