Context
The Office of the Information and Privacy Commissioner (OIPC) collects, uses and discloses Business Information as a public body subject to the Protection of Privacy Act (POPA) in order to conduct business and manage personnel.
Purpose
To ensure the collection, use and disclosure of Business Information by the OIPC occurs in accordance with POPA.
Application
This policy applies to all employees of the OIPC.
References
POPA, Information Security Classification Directive
Policy Statements
Business Information is classified as Protected B Information.
Collection of Business Information
All Business Information must be collected for a specified purpose and only as permitted by POPA. The purpose for collection must be identified prior to collecting the Business Information.
The least amount of Business Information must be collected to perform a specific job or task.
When collecting Business Information, steps must be taken to ensure the Business Information is protected with controls appropriate to the information security classification of the Business Information during the collection.
Use of Business Information
Business Information may only be used:
- for the purpose for which the Business Information was collected or compiled or for a use consistent with that purpose;
- if the individual the information is about has identified the Business Information and consented, in the prescribed manner, to the use; or
- for a purpose for which the Business Information may be disclosed, as set out in POPA.
The use of Business Information must be limited to the extent necessary to enable the OIPC to carry out its purpose in a reasonable manner.
When using Business Information, steps must be taken to ensure the Business Information is protected with controls appropriate to the information security classification of the Business Information during the use.
Disclosure of Business Information
Business Information may only be disclosed:
- for the purpose for which it was collected or compiled or for a use consistent with that purpose;
- if the individual the information is about has identified the Business Information and consented, in the prescribed manner, to the disclosure; or
- otherwise, if authorized by POPA.
The disclosure of Business Information must only be to the extent necessary to enable the OIPC to carry out the purposes described by POPA, in a reasonable manner.
When disclosing Business Information, steps must be taken to ensure the Business Information is protected with controls appropriate to the information security classification of the business information during the disclosure.
Roles and Responsibilities
Director IM/IT
The Director IM/IT is responsible for making reasonable security arrangements to protect OIPC Information Assets.
Access/Privacy Coordinator
The Access/Privacy Coordinator is responsible to ensure the OIPC complies with specific legislated requirements applicable to Business Information, including but not limited to responding to privacy complaints or correction requests submitted under POPA.
Supervisors
Supervisors are responsible to:
- determine what Business Information is needed and for what specified purpose(s) in accordance with POPA, and
- ensure their direct reports limit collection, use or disclosure to these purposes in form and manner.
Supervisors are responsible to ensure their staff are aware of and follow this policy.
Supervisors must forward any formal requests for correction of Business Information, or privacy complaints they may receive to the Access/Privacy Coordinator.
Employees
Employees are responsible to:
- abide by the collection, use and disclosure restrictions established by their supervisor when carrying out their job duties,
- work with their supervisor to define necessary collection, use or disclosure of Business Information for operational purposes, and
promptly notify their supervisor of any formal requests for correction of Business Information, or about any privacy complaints they may receive..
Monitoring and review period
This policy will be reviewed and updated every two years or as required.
Approval
This policy was approved by the IM/IT Governance Committee on September 21, 2026 and is in effect.






