ONTARIO LACROSSE ASSOCIATION INFORMATION PRIVACY POLICY

Similar documents
MAWA PRIVACY POLICY. Purpose of this Policy

A copy of Ontario Water Polo Association s Privacy Policy is provided to any member on request to Ontario Water Polo Association.

CANADIAN AMATEUR SYNCHRONIZED SWIMMING ASSOCIATION, INC. SASKATCHEWAN SECTION PRIVACY POLICY

1A-1084 Kenaston Street tel: (613) Ottawa, ON K1B 3P5 fax: (613)

SYNCHRO SWIM MANITOBA PRIVACY POLICY

VOLLEYBALL BC Privacy Policy

Model Code for the Protection of Personal Information, CAN/CSA-Q830-96

RICHMOND MINOR HOCKEY ASSOCIATION

Association of Service Providers for Employability and Career Training ( ASPECT ) PRIVACY CODE

CBSA PRIVACY POLICY. Canadian Business Strategy Association Page 1

Prairie Centre Credit Union

Principles. Bison Transport will implement policies and procedures to give effect to this policy, including:

Privacy in Canada Federal Legislation: Personal Information Protection and Electronic Documents Act

Jericho Tennis Club's Privacy Policy

PRIVACY CODE FOR THE PROTECTION OF PERSONAL INFORMATION

Taking care of what s important to you

SBI Canada Bank Privacy Policy

Client Privacy Policy

Our Privacy Policy SUPPLEMENTAL INSURANCE. Health Accident Disability Life. combined.ca

Citi Canada. Privacy of Personal Information Statement

PROTECTION OF PERSONAL INFORMATION POLICY (PoPI)

Taking care of what s important to you

PRIVACY POLICY OVERVIEW

PRIVACY AND INFORMATION MANAGEMENT A Guideline For Alberta Veterinarians

HSBC Privacy code. Everything you need to know about the security and privacy of your personal information at HSBC

North Simcoe Community Futures Development Corporation (NSCFDC) PRIVACY POLICY 1.0 PURPOSE OF PRIVACY POLICY 3

METRO DIRECTION FINANCIAL INC PRIVACY POLICY

Title CIHI Submission: 2014 Prescribed Entity Review

Privacy Guide for Alberta Physiotherapists

American Federation of Musicians and Employers' Pension Welfare Fund (Canada) (the " Fund") PRIVACY POLICY. Effective January 1, 2004

AAD Policy Manual An overview of the Policies, Strategies and Core Operational Guidelines that AAD uses in its Day-to-Day operations.

Privacy Policy. NESS Super is committed to respecting your right to privacy and protecting your personal information.

PRIVACY CODE FOR OUR DENTAL OFFICE

EQUAL ACCESS FUNDING PTY LTD PRIVACY POLICY

Privacy Policy. Football Federation Victoria. Effective March Amended March Mitchell Murphy CEO

GDPR 01 Issue No. 01. GDPR Privacy Policy Issue date: 27/04/2018. Page 1 of 5

SYDNEY METRO AIRPORTS PRIVACY POLICY This Privacy Policy was last updated on 28 June Our privacy commitment This Privacy Policy applies to

Arcare Aged Care APP Privacy Policy

AMIST Super. Privacy Policy

What types of personal information is collected and why? Our privacy commitment to you. Personal information. What is personal information?

Privacy Policy. Amendment History. Trustee Name

This policy is also accessible on the Equestrian Australia (EA) website:

Banks Sheridan Limited Data Protection Privacy Policy 19 May 2018

PRIVACY AND ANTI-SPAM CODE FOR OUR DENTAL OFFICE Please refer to Appendix A for a glossary of defined terms.

All Sorts UK Limited Data Protection Policy 17 th May 2018

Client Statement of Disclosure

YMCA SOUTH AUSTRALIA Privacy Policy

Policies, Procedures and Guidelines

OMERS Administration Corporation Privacy Statement

Our commitment to integrity.

The Allied Group Privacy Shield Policy

PRIVACY NOTICE - GOLFERS/VOLUNTEERS/PLAYERS

GUIDANCE NOTE ON THE DATA PROTECTION ACT Information for clubs & county associations

Annual Report on the Privacy Act

Our privacy commitment to you. What types of personal information is collected and why? About us. Personal information. What is personal information?

We are committed to safeguarding your personal information in accordance with the requirements of the Privacy Act 1988.

Privacy Notice under the General Data Protection Regulation (GDPR)

Nova Scotia Health Employees Pension Plan Policy and Guidelines. Protecting the Privacy of Personal Information

Schedule A MGA Broker Commission In effect for all Foresters Financial TM business written on or after December 18, 2017

PRIVACY POLICY: INSURANCE OPERATIONS

* Unless otherwise indicated, this policy will still apply beyond the review date.

PRIVACY AND CREDIT REPORTING POLICY

SCCCI Personal Data Protection Policy

Southern Golden Retriever Rescue Data Protection Policy

EMPLOYEE PRIVACY STATEMENT

JPMorgan recognises the importance of the personal information we hold about individuals and the trust they place in us.

GROUP POLICY - PRIVACY

PRIVACY ISSUES IN M&A TRANSACTIONS

ENF/SPAHS (1997) Ltd. APPLICATION FORM

MONASH UNIVERSITY PRIVACY COMPLIANCE MANUAL

DATA PROTECTION POLICY

Claims Made Basis. Underwritten by Underwriters at Lloyd s, London

Voyages Privacy Policy

Man and Machine - Data Protection Policy

DATA PRIVACY I. POLICY DEFINITIONS

AAD Policy Manual An overview of the Policies, Strategies and Core Operational Guidelines that AAD uses in its Day to Day operations.

Item 5 - Policy Approval: Privacy Policy - Board of Directors GCHRCC Public Meeting - December 7, 2017 Report:GCHRCC: Attachment 1

NAPBS BACKGROUND SCREENING AGENCY ACCREDITATION PROGRAM ACCREDITATION STANDARD AND AUDIT CRITERIA Version 2.0. Potential Verification for Onsite Audit

Privacy & Data Protection Procedure-Box Hill Institute Group

BERKLEY INSURANCE COMPANY PRIVACY POLICY

The Controller and Processor Data Protection Binding Corporate Rules of BMC Software

FINANCIAL SERVICES OPPORTUNITIES INVESTMENT FUND LIMITED Company Registration Number: PRIVACY NOTICE

Georgia Power Valdosta Federal credit union Privacy Policy

Sun Life Assurance Company of Canada (U.K.) Limited. Customer Data Protection Notice

DAWSON PUBLIC POWER DISTRICT 300 South Washington Street P. O. Box Lexington, Nebraska Tel. No.- 308/324/2386 Fax No.

March 1. HIPAA Privacy Policy

PRIVACY IMPACT ASSESSMENT

ALBERTA BASKETBALL ASSOCIATION OFFICIAL SANCTIONING POLICY

ANZ PRIVACY POLICY PROTECTING YOUR PRIVACY _ANZ PRIVACY POLICY_77562.indd 1 29/04/2016 9:37 am

May 2, 2018 Page 1 of 8

Fitzwilliam College Data Protection Policy

Creditor and Travel Insurance Print Version 2017 Internal use only 1/16

WHO IS RESPONSIBLE FOR LOOKING AFTER YOUR PERSONAL DATA?

PRIVACY POLICY OF BPO INSOLVENCY LIMITED (COMPANY REGISTRATION NO ) REGISTERED OFFICE 37 WALTER ROAD SWANSEA SA1 5NW

Regenstrief Center for Healthcare Engineering HIPAA Compliance Policy

BINDING CORPORATE RULES

Who are we? Our commitment to protect your privacy

Our Commitment to You Privacy Statement

If you are a business partner, we will collect your business contact details. Gender. Marital Status. Criminal History

o The words "You" and "Your" mean a South Shore Bank Home Banking customer.

Transcription:

ONTARIO LACROSSE ASSOCIATION INFORMATION PRIVACY POLICY Purpose of this Policy Last Updated: January 29, 2017 1. Privacy of personal information is governed in Ontario by the Personal Information Privacy Act ( PIPA ). This policy describes the way that the Ontario Lacrosse Association (OLA) and its Councils and Technical Support Groups, collect, use, retain, safeguard, disclose and dispose of personal information, and states the OLA s commitment to collecting, using and disclosing personal information responsibly. This policy is based on the standards required by PIPA, and the OLA s interpretation of these responsibilities. Background 2. Our organization, the OLA, is the governing body for the support of lacrosse in Ontario, and provides lacrosse programs and services to members and the public. The OLA s mission statement: The Ontario Lacrosse Association is dedicated to the promotion, development, and administration of the sport of lacrosse in Ontario, accountable to its members, constantly striving for excellence, fairness, and continuous improvement with a vision towards being the best. Personal Information 3. Personal information is information about an identifiable individual. Personal information includes information that relates to their personal characteristics (e.g., gender, age, income, home address or phone number, ethnic background, family status), their health (e.g. health history, health conditions, health services received by them) or their activities and views (e.g., religion, politics, opinions expressed by an individual, an opinion or evaluation of an individual). Personal information, however, does not include business information (e.g., an individual s business address and telephone number), which is not protected by privacy legislation. Accountability 4. The OLA President, or Past President and the OLA Executive Director are the Privacy Officers and are responsible for the monitoring information collection and data security, and ensuring that all staff receives appropriate training on privacy issues and their responsibilities. The Privacy Officer also handles personal information access requests and complaints. The Privacy Officer may be contacted at the following address: OLA Privacy Officer, 1 Concorde Gate, Suite 200C Box 51, Toronto, Ontario, M3C 3N6 or by email at info@ontariolacrosse.com 5. Personal information will only be collected by the OLA to meet and maintain the highest standard of organizing and programming the sport of lacrosse. The OLA collects personal information from prospective members, members, coaches, referees, participants, managers and volunteers for purposes that include, but are not limited to the following:

Name, address, phone number, cell phone number, fax number and e-mail address for the purpose of communicating about the OLA s and the OLA partnership programs, events and activities. NCCP number, education, resumes and experience for database entry at the Coaching Association of Canada to determine the level of certification and coaching qualifications. Credit card information for registration at conferences, travel administration, coaching manuals and other products and resources. Date of birth, athlete biography, member club to determine eligibility, age group and appropriate level of play. Banking information, social insurance number, criminal records check, resume, and beneficiaries for the OLA s payroll, company insurance and health plan. Criminal records check and related personal reference information for the purpose of implementing the OLA s volunteer screening program. Personal health information including provincial health card numbers, allergies, emergency contact, and past medical history for use in the case of medical emergency. Athlete information including height, weight, uniform size, shoe size, feedback from coaches, trainers, performance results from athlete registration forms, outfitting uniforms, media relations, and various components of athlete and team selection. Athlete whereabouts information including sport/discipline, training times and venues, training camp dates and locations, travel plans, competition schedule, disability if applicable for the Canadian Centre for Ethics in Sport inquiries for the purposes of out-of-competition drug testing. Body weight, mass, body and fat index to monitor physical response to training and to maintain an appropriate weight for competition. Marketing information including attitudinal and demographic data on individual members to determine membership demographic structure and program wants and needs. Passport numbers and Aeroplan/frequent flyer numbers for the purposes of arranging travel. Name, address, phone number, cell phone number, fax number, e-mail address for the purpose of providing insurance coverage, managing insurance claims and conducting insurance investigations. Players lists and contact information within the OLA Member Associations, National Lacrosse League and/or teams for the purpose of notification of try-outs for other levels of lacrosse. If a purpose has not been identified herein, the OLA will seek consent from individuals when personal information is used for a purpose not already consented to. This consent will be documented as to when and how it was received. Consent 7. Consent is required to be obtained by lawful means from individuals at the time of collection, prior to the use or disclosure of the personal information. If the consent to the collection, use or disclosure was not obtained upon receipt of the information, consent will be obtained prior to the use or disclosure of that information. The OLA may collect personal information without consent where reasonable to do so and where permitted by law. 8. By providing personal information to the OLA, individuals are consenting to the use of the information for the purposes identified in this policy.

9. The OLA will not, as a condition of product or service, require an individual to consent to the collection, use or disclosure of information beyond that required to fulfill the specified purpose. 10. An individual may withdraw consent; use or disclosure of personal information at any time, subject to legal or contractual restrictions, provided the individual gives one week s notice of such withdrawal to the OLA. The Privacy Officer will advise the individual of the implications of such withdrawal. Limiting Collection 11. All personal information will be collected fairly, by lawful means and for the purposes as specified in this policy. The OLA will not use any form of deception to obtain personal information. Limiting Use, Disclosure and Retention 12. Personal information will not be used or disclosed by the OLA for purposes other than those for which it was collected as described herein, except with the consent of the individual or as required by law. 13. Personal information will be retained for certain periods of time in accordance with the following: Registration data and athlete information will be retained after an individual has left a program of the OLA, in the event that the individual chooses to return to the program. Parental/family information will be retained after an individual has left a program of the OLA, in the event that the individual choose to return to the program. Information collected by coaches will be retained after an individual has left a program of the OLA, in the event the individual chooses to return to the program. Employee information will be retained for a period of seven years in accordance with Canada Customs and Revenue Agency Requirements. Personal health information will be immediately destroyed when an individual chooses to leave a program of the OLA. Marketing information will be destroyed upon completion and analysis of collected information. As otherwise may be stipulated in Provincial legislation. 14. Personal information that is used to make a decision about an individual will be maintained for a minimum of one year of time to allow the individual access to the information after the decision has been made. 15. The OLA may disclose personal information to a government authority that has asserted its lawful authority to obtain the information or where the OLA has reasonable grounds to believe the information could be useful in the investigation of an unlawful activity, or to comply with a subpoena or warrant or an order made by the court or otherwise as permitted by applicable law.

16. Documents will be destroyed by way of shredding and electronic files will be deleted in their entirety. When hardware is discarded, the OLA will ensure that the hard drive is reformatted. Accuracy 17. The OLA will use accurate and up-to-date information as is necessary for the purposes for which it is to be used, to minimize the possibility that inappropriate information may be used to make a decision about an individual. Safeguards 18. Personal information is protected by security safeguards appropriate to the sensitivity of the information against loss or theft, unauthorized access, disclousure, copying, use or modification. 19. Methods of protection and safeguards include, but are not limited to, locked filing cabinets, restricted access to offices, security clearances, need-to-know access and technological measures including the use of passwords, encryption and firewalls. 20. The following steps will be taken to ensure security: Paper information is either under supervision or secured in a locked or restricted area. Electronic hardware is either under supervision or secured in a locked or restricted area at all times. In addition, passwords are used on computers. Paper information is transmitted through sealed, addressed envelopes or in boxes by reputable courier/delivery companies. Electronic information is transmitted either through a direct line or is encrypted. External consultants and agencies with access to personal information will provide the OLA with appropriate privacy assurances. Openness 21. The OLA will publicize information about its policies and practices relating to the management of personal information. This information is available through this policy, on the OLA s web site or upon request by contacting the Privacy Officer. 22. The information available to the public includes: The name or title, address and telephone number of the OLA s Privacy Officer. A description of the type of personal information held by the OLA, including a statement of its approved uses. Individual Access 23. Upon written request, and with assistance from the OLA, an individual may be informed of the existence, use and disclosure of his or her personal information and will be given access to

that information. As well, an individual is entitled to be informed of the source of the personal information along with an account of third parties to whom the information has been disclosed. 24. Requested information will be disclosed to the individual within thirty days of receipt of the written request at no cost to the individual, or at nominal cost relating to photocopying expenses, unless there are reasonable grounds to extend the time limit. 25. If personal information is inaccurate or incomplete, it will be amended as required. 26. An individual may be denied access to his or her personal information if: This information is prohibitively costly to provide; The information contains references to other individuals; The information cannot be disclosed for legal, security or commercial proprietary purposes; The information is subject to solicitor-client or litigation privilege. 27. Upon refusal, the OLA will inform the individual the reasons for the refusal and the associated provisions of PIPA. Challenging Compliance 28. An individual may challenge the OLA s compliance with this policy and PIPA, by submitting a challenge in writing. 29. Upon receipt of a written complaint, the OLA will: Record the date the complaint is received; Notify the Privacy Officer who will serve in a neutral, unbiased capacity to resolve the complaint; Acknowledge receipt of the complaint by way of telephone conversation and clarify the nature of the complaint within three business days of receipt of the complaint; Appoint an investigator using OLA personnel or an independent investigator, who will have the skills necessary to conduct a fair and impartial investigation, and who will have unfettered access to all files and personnel, within ten business days of receipt of the complaint. Upon completion of the investigation and within 25 days of receipt of the complaint, the investigator will submit a written report to the OLA. Notify the complainant of the outcome of the investigation and any relevant steps taken to rectify the complaint, including any amendments to policies and procedures, within 30 days of receipt of complaint. 30. An individual may appeal a decision made by the OLA under this policy, in accordance with the OLA s policies for appeals.