Skip to content

Privacy practice tune-up – getting ready for the Consumer Privacy Protection Act

Rob Aske

As we wrote about earlier, Canada’s federal government has proposed a replacement to our national privacy law for commercial transactions known as the Personal Information Protection and Electronic Documents Act (“PIPEDA”).

The new bill is the Digital Charter Implementation Act, and this bill in turn would create a new Consumer Privacy Protection Act (“CPPA”) which would replace the privacy portion of PIPEDA.

The CPPA will likely not come into force for a year or more, while consultations and the drafting of regulations proceed.

However, the proposed CPPA does restate and expand on the existing privacy law requirements of PIPEDA, and if your business needs a privacy tune-up then CPPA can provide a useful guide, with better detail than PIPEDA offers now.

Privacy management program

For example, CPPA requires all organizations (including businesses) to implement a “privacy management program” including policies, practices and procedures for protection of personal information, complaints handling, training of personnel and for explaining these practices to the public. This program must take into account the “volume and sensitivity of the personal information” under the organization’s control.

CPPA also obliges an organization to provide the federal Privacy Commissioner with access to all policies, practices and procedures of its privacy management program, merely upon request, which of course could give the Commissioner a good look into any program gaps. If the Commissioner has reasonable grounds to believe that a breach of privacy obligations has occurred, then the Commissioner may choose to “audit” these practices.

Further detail on consent

The required consent for use of personal information is also described in CPPA in greater detail, and states that consent is only valid if at or before the time that the organization seeks the individual’s consent, it provides the following information in “plain language”:

(a) the purposes for the collection, use or disclosure;

(b) the way in which the personal information is to be collected, used or disclosed;

(c) any reasonably foreseeable consequences of the collection, use or disclosure of the personal information;

(d) the specific type of personal information that is to be collected, used or disclosed; and

(e) the names of any third parties or types of third parties to which the organization may disclose the personal information.

Consent must be obtained at or before collection, and must be express unless it is appropriate to rely on implied consent, taking into account the reasonable expectations of the individual and the sensitivity of the personal information.

Plain language privacy policies

CPPA also gives clearer guidance on privacy policies to be made available to customers and others providing personal information, which must again be in “plain language” and include at least the following:

(a) a description of the type of personal information under the organization’s control;

(b) a general account of how the organization makes use of personal information, including how the organization applies any permitted exceptions;

(c) a general account of the organization’s use of any automated decision system (e.g. AI systems) to make predictions, recommendations or decisions about individuals that could have significant impacts on them;

(d) whether or not the organization carries out any international or interprovincial transfer or disclosure of personal information that may have reasonably foreseeable privacy implications;

(e) how an individual may make a request for disposal or access; and

(f) the business contact information for your privacy officer.

While the policy requirements above about automated decision systems and international and interprovincial transfers are part of many policies now, they are new as express requirements of the law.

Therefore, all businesses that may be considering a tune-up of their privacy practices and policies should review the standards as outlined in the proposed CPPA, including those above.


This article is provided for general information only. If you have any questions about the above, please contact a member of our Privacy group.

Click here to subscribe to Stewart McKelvey Thought Leadership articles and updates.

SHARE

Archive

Search Archive


 
 

Nova Scotia offers new pension option to private sector employers

November 24, 2023

By Level Chan When proclaimed in force, the Nova Scotia Private Sector Pension Plan Transfer Act (the “Transfer Act”) enacted by Bill 339, Financial Measures (Fall 2023) Act will allow the transfer of private sector…

Read More

Bill C-365 calls for plan for implementation of open banking in Canada

November 17, 2023

By Kevin Landry On November 9 2023, Bill C-365, An Act respecting the implementation of a consumer-led banking system for Canadians (“C-365”), short titled as the ‘Consumer-led Banking Act’ was read in the House of…

Read More

More limits: NSCA tightens the test for disallowing a limitations defence

November 15, 2023

By Jennifer Taylor The Nova Scotia Court of Appeal (“NSCA”) has issued an important decision clarifying the test to disallow a limitations defence. The decision, Halifax (Regional Municipality) v Carvery (“Carvery”), has real implications for personal…

Read More

Anticipating changes to the Competition Act: what businesses need to know

November 1, 2023

By Deanne MacLeod, K.C., Burtley Francis & David Slipp On September 21, 2023, the Federal Government introduced Bill C-56: An Act to amend the Excise Tax Act and the Competition Act (“Bill C-56”), with the…

Read More

Powering the future: Green choice program regulations

September 22, 2023

By Nancy Rubin, K.C. and Lauren Agnew The long-awaited Green Choice Program Regulations (N.S. Reg. 155/2023) were released by the provincial government on September 8, 2023, offering some clarity into the practical implementation of Nova…

Read More

Privilege protected: Court of Appeal rules NL’s Information and Privacy Commissioner barred from reviewing solicitor-client privileged information

September 20, 2023

By Koren Thomson, John Samms, and Matthew Raske The Newfoundland and Labrador Court of Appeal has held that the Information and Privacy Commissioner for this province (the “Commissioner”) does not have the authority to order…

Read More

Amendments required for Prince Edward Island code of conduct bylaws

September 18, 2023

By Perlene Morrison, K.C. Municipalities are required to pass code of conduct bylaws in accordance with section 107 of the Municipal Government Act (the “MGA”). Subsection 107(1) of the MGA specifically states that a municipality’s…

Read More

Professionally speaking: Ontario Superior Court upholds professional regulators’ right to moderate speech

September 14, 2023

By Sheila Mecking and Kathleen Starke On August 23, 2023, the Ontario Superior Court (“ONSC”) upheld a complaints decision which ordered a psychologist to complete a continuing education or remedial program regarding professionalism in public…

Read More

One-year reminder for federal employers: Pay equity plans due September 3, 2024

September 5, 2023

By Dante Manna As we advised in a previous podcast, all federal employers with at least ten employees[1] have been subject to the Pay Equity Act [2] (“PEA”) and Pay Equity Regulations [3] (“Regulations”) since…

Read More

Charging to net-zero: Government releases draft Clean Electricity Regulations

August 23, 2023

By Nancy Rubin, K.C. Environment and Climate Change Canada (ECCC) recently published a draft of the Clean Electricity Regulations (CER). The proposed Regulations work toward achieving a net-zero electricity-generating sector, helping Canada become a net-zero…

Read More

Search Archive


Scroll To Top