OMERS Administration Corporation Privacy Statement

Similar documents
PRIVACY POLICY: INSURANCE OPERATIONS

CBSA PRIVACY POLICY. Canadian Business Strategy Association Page 1

PRIVACY POLICY. Your privacy is critically important to America s Cash Advance, Inc.

PRIVACY POLICY A. SCOPE & INTERPRETATION. Personal Information. What Personal Information is not. B. Consent

Mortgages and Loans Privacy policy

Citi Canada. Privacy of Personal Information Statement

TRAVELTOKENS SALE PRIVACY POLICY Last updated:

PRIVACY POLICY OVERVIEW

SYDNEY METRO AIRPORTS PRIVACY POLICY This Privacy Policy was last updated on 28 June Our privacy commitment This Privacy Policy applies to

Data Processing Appendix

Privacy Policy and. Credit Reporting Policy

ON24 DATA PROCESSING ADDENDUM

Capital Dynamics Privacy Policy

Nova Scotia Health Employees Pension Plan Policy and Guidelines. Protecting the Privacy of Personal Information

This Policy also explains how we collect information through the use of cookies and related technologies which are relevant if you visit our Site.

AMIST Super. Privacy Policy

BERKLEY INSURANCE COMPANY PRIVACY POLICY

What types of personal information is collected and why? Our privacy commitment to you. Personal information. What is personal information?

GT INSURANCE PRIVACY POLICY

PRIVACY POLICY. Last Updated: 06/16/2017

Taking care of what s important to you

MAXETAG MEMBERSHIP TERMS AND CONDITIONS

DATA PROTECTION POLICY

Data Privacy Statement

Privacy Statement v 1.1

IDEXX - DATA PROTECTION AGREEMENT

ASTRAZENECA GLOBAL POLICY DATA PRIVACY

Our Privacy Policy SUPPLEMENTAL INSURANCE. Health Accident Disability Life. combined.ca

Privacy Policy. Effective Date 1 December 2017

Privacy Policy. NESS Super is committed to respecting your right to privacy and protecting your personal information.

PRIVACY NOTICE LAST UPDATED: SEPT. 2018

Linemac Toyota s APP Privacy Policy

HSBC Privacy code. Everything you need to know about the security and privacy of your personal information at HSBC

A copy of Ontario Water Polo Association s Privacy Policy is provided to any member on request to Ontario Water Polo Association.

This policy is also accessible on the Equestrian Australia (EA) website:

BWA Financial Group Pty Ltd Privacy Policy

Client Privacy Policy

Our privacy commitment to you. What types of personal information is collected and why? About us. Personal information. What is personal information?

RAMS Privacy Policy. When you trust us with your personal information, you expect us to protect it and keep it safe.

Taking care of what s important to you

Westpac Privacy Policy.

Where our documents ask for personal information, we will normally state the general purposes for its use and to whom it may be disclosed.

Firefighters Pension Scheme

BDML Connect Ltd Privacy Policy_v1.0_March updated Markerstudy Group 2018 Page 1 of 11

ANNEXURE. Privacy Notice

The EU s General Data Protection Regulation enters into force on 25 May 2018

EQUAL ACCESS FUNDING PTY LTD PRIVACY POLICY

* Unless otherwise indicated, this policy will still apply beyond the review date.

Annual Interest Rates. Standard Rates: Purchases: 11.99% Cash advances (including balance transfers and access cheques):11.

DATA PROCESSING ADDENDUM

ahm Privacy Policy March 2014

SCCCI Personal Data Protection Policy

Data Protection Privacy Notice for people not directly involved in the accident

Quotation/Inception. Renewal. Policy administration. Claims processing PRIVACY POLICY

DATA PROCESSING TERMS DEFINITIONS

JPMorgan recognises the importance of the personal information we hold about individuals and the trust they place in us.

105 CMR: Department of Public Health

AonLine Service Agreement Effective July 19, By logging into AonLine, user agrees to these terms and conditions (T&C):

SECURITY SAFEGUARD BREACH GUIDE

SYNCHRO SWIM MANITOBA PRIVACY POLICY

Lexus Asset Protector (GAP Insurance)

Southern Golden Retriever Rescue Data Protection Policy

AmeriHealth Website Privacy Policy and AmeriHealth Website Terms and Conditions of Access

ONTARIO LACROSSE ASSOCIATION INFORMATION PRIVACY POLICY

THE CITY OF EDMONTON PROJECT AGREEMENT VALLEY LINE LRT STAGE 1. Schedule 18. Freedom of Information and Protection of Privacy

DELHAIZE AMERICA PHARMACIES AND WELFARE BENEFIT PLAN HIPAA SECURITY POLICY (9/1/2016 VERSION)

EMPLOYEE PRIVACY STATEMENT

Georgia Health Information Network, Inc. Georgia ConnectedCare Policies

Insurance 4 That Privacy Policy

privacy notice who is responsible for processing your personal data and who you can contact in this regard reasons for processing your data

DATA PROTECTION NOTICE

Coffee time ACCoUNt terms & CoNDitioNS Coffee Time Terms of Use Agreement About Your Gift Card Account: Coffee Time Purchases Only

1A-1084 Kenaston Street tel: (613) Ottawa, ON K1B 3P5 fax: (613)

YOUR PERSONAL INFORMATION AND WHAT WE DO WITH IT

Annex to II.6 MANDATORY PROVIDENT FUND SCHEMES ORDINANCE (CAP. 485) INTERNAL CONTROLS OF REGISTERED SCHEMES

SBI Canada Bank Privacy Policy

CANADIAN AMATEUR SYNCHRONIZED SWIMMING ASSOCIATION, INC. SASKATCHEWAN SECTION PRIVACY POLICY

DATA PROTECTION NOTICE

Data Protection: Fair processing of student personal information Contents

CUSTOMER DATA PROCESSING ADDENDUM

North Simcoe Community Futures Development Corporation (NSCFDC) PRIVACY POLICY 1.0 PURPOSE OF PRIVACY POLICY 3

Designing Privacy Policies and Identifying Privacy Risks for Financial Institutions. June 2016

SILCHESTER INTERNATIONAL INVESTORS DATA PROTECTION POLICY

Principles. Bison Transport will implement policies and procedures to give effect to this policy, including:

Privacy in Canada Federal Legislation: Personal Information Protection and Electronic Documents Act

Client Statement of Disclosure

Mears Terms and Conditions of Use Agreement. Agreement Between Customer and Mears. Use of the Website. Prohibitions on Misuse

DATA PROCESSING AGREEMENT

AAD Policy Manual An overview of the Policies, Strategies and Core Operational Guidelines that AAD uses in its Day-to-Day operations.

Institutional Investment Advisors Limited

Data Privacy Notice of Sumitomo Mitsui Banking Corporation, Brussels Branch ( SMBC )

STEADFAST UNDERWRITING AGENCIES PRIVACY POLICY

AINSLIE BULLION STORAGE ACCOUNT APPLICATION

GROUP POLICY - PRIVACY

DATA PROTECTION POLICY. AtonLine Limited

Record Management & Retention Policy

To: Our Clients and Friends January 25, 2013

HIPAA OMNIBUS RULE. The rule makes it easier for parents and others to give permission to share proof of a child s immunization with a school

INFORMATION AND CYBER SECURITY POLICY V1.1

[Name of Organization] HIPAA Incident/Breach Investigation Procedure 4

Transcription:

OMERS Administration Corporation Privacy Statement Noam Sela privacy@omers.com Effective November 1, 2017 L E G A L OUR COMMITMENT TO YOUR PRIVACY At OMERS Administration Corporation, we are committed to preserving the privacy of your personal information. This Privacy Statement sets out the details of this commitment. The way in which we collect, use and disclose personal information may change from time to time, and we reserve the right to change or clarify our Privacy Statement. You can review our Privacy Statement by visiting our website, http://www.omers.com, or requesting a copy from our Privacy Officer. This Privacy Statement applies to all operations within OMERS Administration Corporation ( OAC ), including pension administration, OMERS Capital Markets and Investment Operations & Applications, but does not apply to the personal information of OAC s employees, prospective employees or contractors. What is personal information? Personal information is any information that identifies a person, that could reasonably be used to identify a person, or that is about an identifiable person. Personal information we collect can include non-sensitive information, such as your name, contact information, and demographic information, or more sensitive personal information, such as your health information. Underlying our commitment to privacy is the protection of personal information information about you or that can identify you. How is my privacy promoted? Under the guidance of our Privacy Officer, OAC monitors and promotes compliance with privacy laws and internal policies and procedures. We have established processes for identifying potential privacy breaches and providing appropriate notification of any breaches that may cause real risk of significant harm to an individual, in order to maintain accountability to the owners of all personal information in our possession and control and allow them to mitigate risk. Such notification will be provided without undue delay, but not later than within 72 hours of the discovery of the breach where feasible. Because your privacy is important to us, we carefully monitor its collection, use and disclosure.

Why is my personal information collected? Knowing you helps us understand your needs, allows us to communicate effectively, and to provide high quality service. Reasons we collect your personal information include the following purposes (the identified purposes ): administering the OMERS Pension Plans; facilitating business transactions, including evaluating, effecting, monitoring and managing investments; establishing and maintaining member and stakeholder relationships; paying pensions and other benefits to members, spouses, survivors and others; providing you with the services you have requested or that you may be interested in; communicating with stakeholders, including employers; researching, developing, managing, protecting and improving our services, including conducting surveys that provide us with feedback on our service standards; tracking website usage, transaction history and patterns, for the purposes of market research and/or providing tailored messages; investigating specific transactions or patterns of transactions to detect unauthorized or illegal activities; maintaining appropriate records, and generally managing and administering our business; evaluating, establishing and maintaining commercial relationships and fulfilling contractual obligations; facilitating safety and security; performing functions required or authorized by law, including meeting our statutory objects; and for any other purpose to which you consent. We only collect and use your personal information as reasonably necessary for the identified purposes. We collect, use and disclose personal information to serve you better. The type of personal information we collect about you will depend on how you interact with us. Is consent needed for collection, use and disclosure of my personal information? In most cases, your consent will be needed for OAC to collect, use or disclose your personal information. However, your consent can be expressly provided or implied, where it is reasonable in the circumstances. Subject to legal requirements, your consent can be refused or withdrawn for OAC s collection, use or disclosure of your personal information by notifying our Privacy Officer in writing. Your consent can be express or implied where it is reasonable in the circumstances. The following are examples of consent, collection, use and disclosure. Information You Provide To Us: When you disclose personal information to OAC or to our service providers and agents, you are consenting to our collection, use and disclosure of your personal information in order to fulfill the identified purposes. This may include the sharing of information with our service providers (for example, financial institutions, actuaries, consultants, auditors, legal advisors, etc.). Page 2 of 5

We may verify your personal information (for example, contact information), or obtain additional personal information about you by checking with third-parties to assist us in the identified purposes. If you provide us, our service providers, or our agents with personal information about another person, you represent that you have all necessary authority and/or have obtained all necessary consents from that individual to enable us to collect, use and disclose that personal information. Pension Plan Administration: When you enroll in the OMERS Pension Plans, you are consenting to our collection, use and disclosure of your personal information for the identified purposes. As we rely on your employer and other third-parties in administration of the OMERS Pension Plans, we may share your personal information for this purpose. We imply your consent for pension plan administration. As an example, if we are trying to locate you due to out-of-date contact information, we may share your name, date of birth, last known address and other out-of-date contact information with third-parties who provide locator services. When dealing with government entities (such as the Canada Revenue Agency) we may also share your Social Insurance Number, which they will use in order to identify you. We may also share information with other pension plan administrators to facilitate transfer of assets and to determine eligibility for transfer. Disclosure of Information to Employers for Other Purposes The OMERS Pension Plans form part of your overall employment relationship with your employer. Unlike most private sector pension plans, employers who participate in the OMERS Pension Plans do not always have information about member pension accruals, and benefit entitlements that they may require for workforce and succession planning purposes, and for the purpose of other employment related benefit plans such as long term disability plans and insurance plans. As such, in addition to sharing information for the purposes of pension plan administration, we may share information about a member s hire date, enrolment date, total accrued service, unreduced early retirement date, and pension amounts after retirement (including disability pensions), solely for workforce and succession planning purposes and for the purposes of administering other employer benefit programs in which the member is enrolled. Members who prefer that this information not be shared may send a written opt out request to our Privacy Officer at the address below. Website(s): Use of our website(s) is subject to our policies and procedures. By using our website(s), you are providing us with consent to collect, use and disclose any information that may be provided to us through its use. Through our website(s), we may place a text file called a cookie in the browser directory of your computer s hard drive. A cookie is a small piece of information that a website can store on a web browser and later retrieve. The cookie cannot be read by any website other than the one that set up the cookie. Most browsers can be set to reject all cookies. If you choose to modify your browser in this manner, some pages of our website may not function optimally and you may not be able to use all features of our website in the future. When you use our websites, your personal information may be collected, used, or disclosed. Our website(s) often provides links to websites that are operated by third-parties not under our control. This Privacy Statement does not describe the privacy policies of any third-party websites or their privacy practices. OAC is not responsible for how such third-parties collect, use or disclose your personal information, so it is important to familiarize yourself with their privacy policies before providing them with your personal information. Page 3 of 5

Secondary Marketing: From time to time we may use your personal information to send you material that we believe may be of interest to you. Examples of such information include offers from our portfolio companies, our stakeholders, and charitable causes. We will not disclose your personal information to these parties without your consent. Video Surveillance: For safety and security reasons, we may use video surveillance technologies at our properties to monitor public areas of those properties (for example, parking lots, public areas in malls and lobby areas) as well as internal meeting rooms and offices. By entering our premises, you are consenting to the use of your personal information for these purposes. For questions about our use of video surveillance at our properties, please contact our Privacy Officer. For security purposes, we use video surveillance on our properties. We may disclose video surveillance footage to law enforcement or other government agencies where we believe such disclosure is (i) permitted or required by law; (ii) necessary to protect our properties, visitors, customers or employees; or (iii) reasonable in connection with a law enforcement investigation. Business Transactions: In addition, to day-to-day administration of the OMERS Pension Plans, we also invest the assets of the funds. We try to limit collection, use and disclosure of personal information in the course of transactions, and do not exchange client lists as a matter of course. However, where reasonably necessary for business transactions, we may collect personal information from, or disclose personal information to third-parties. This may include for background checks (including criminal and credit checks), proposed or actual purchase, sale (including a liquidation, realization, foreclosure or repossession), lease, merger, amalgamation or any other type of acquisition, disposal, transfer, conveyance, financing or investment. In these cases, consent is implied, unless express consent is legally required. Regulated Disclosures: Where permitted by the law, we may disclose your personal information to government agencies in accordance with their statutory authority. Where is my personal information stored, and how long is it retained? Usually your personal information is stored in the jurisdiction in which it was collected. However, OAC or our service providers and agents may store or access your personal information outside of the jurisdiction in which it has previously been collected, used or disclosed. For example, personal information collected in Ontario may be transferred outside of Ontario and/or Canada. Similarly, personal information collected within the European Economic Area ( EEA ) may be transferred to, and stored at, a destination within or outside of that area. When such transfer takes place, it may also be processed by staff operating outside of the jurisdiction who work for us or for one of our service providers. Your personal information may be stored in, transferred to, and accessed from, a variety of jurisdictions. By providing your personal information to us, you agree to the transfer and storage of your personal information, and accept that your personal information may be subject to the laws of those other jurisdictions, and in certain circumstances that the courts, law enforcement agencies, regulatory agencies or security authorities in those other jurisdictions may be entitled to access your personal information. We retain personal information for only as long as it is needed or as may be required to comply with applicable laws. We keep your personal information only as long as it is needed. Page 4 of 5

How is my personal information kept safe? Whether in electronic or paper-based format, we use industry standard technology and efforts to safeguard your personal information from loss, theft and unauthorized access, use or disclosure. These include secure servers and firewalls. Physical access to those areas where information is gathered, processed or stored is restricted to authorized employees who require the information to perform a specific function. Appropriate controls are in place over computer systems and data processing procedures and these controls are reviewed on an ongoing basis to ensure compliance with our security and privacy requirements. When your personal information is no longer necessary, we permanently destroy or erase it. We use a variety of mechanisms including physical, technological, and organizational ones to help keep your personal information secure. We require our service providers and agents to protect personal information collected by them on our behalf, or disclosed to them by us. How can I access or correct my personal information? We try to ensure that the personal information we collect about you is accurate, complete and up-to-date. However, we rely on you to provide accurate information in the first instance, and to notify us when there is a change in your personal information. While we will not routinely update your personal information, we may do so when such updates are necessary to fulfill the identified purposes. As such, in certain circumstances we may verify personal information, or obtain additional personal information through third-parties. You have a right, subject to certain exceptions, to access and correct your personal information in our possession or control. You may access and correct your personal information by writing or emailing our Privacy Officer as described below. There may be an administrative charge for retrieving this information. We rely on you to help us keep our records accurate, but may occasionally seek external verification. You can access your personal information by making a written request to our Privacy Officer. Who can I contact with questions or concerns? If you have any comments or questions about our Privacy Statement, or if you believe that we have not complied with our Privacy Statement, please contact our Privacy Officer as follows: Noam Sela Privacy Officer 900-100 Adelaide Street West Toronto ON M5H 0E2 Our Privacy Officer is ready to respond to your questions and concerns. e-mail: privacy@omers.com Page 5 of 5