<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Pandemic &#8211; Office of the Information and Privacy Commissioner of Alberta</title>
	<atom:link href="https://oipc.ab.ca/resources/pandemic/feed/" rel="self" type="application/rss+xml" />
	<link>https://oipc.ab.ca</link>
	<description>Office of the Information and Privacy Commissioner of Alberta</description>
	<lastBuildDate>Tue, 01 Mar 2022 18:33:12 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://oipc.ab.ca/wp-content/uploads/2022/01/cropped-OIPC-Icon-32x32.png</url>
	<title>Pandemic &#8211; Office of the Information and Privacy Commissioner of Alberta</title>
	<link>https://oipc.ab.ca</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>COVID-19 Pandemic: Privacy in a Pandemic</title>
		<link>https://oipc.ab.ca/resource/pandemic-privacy/</link>
		
		<dc:creator><![CDATA[ssibbald]]></dc:creator>
		<pubDate>Tue, 01 Mar 2022 18:33:12 +0000</pubDate>
				<guid isPermaLink="false">https://staging.oipc.ab.ca?post_type=resource&#038;p=2466</guid>

					<description><![CDATA[Privacy laws are not a barrier to appropriate information sharing in a pandemic or emergency situation. It is important that&#8230;]]></description>
										<content:encoded><![CDATA[<div class="nine small-12 medium-9 columns">
<div class="row">
<div>
<p>Privacy laws are not a barrier to appropriate information sharing in a pandemic or emergency situation.</p>
<p>It is important that public bodies, health custodians and private sector organizations know how personal or health information may be shared during a pandemic or emergency situation.</p>
<h4>How Information May Be Shared under Alberta’s Privacy Laws</h4>
<p>Alberta has three privacy laws:</p>
<ul>
<li>Freedom of Information and Protection of Privacy Act for the public sector</li>
<li>Health Information Act for the health sector</li>
<li>Personal Information Protection Act for the private sector</li>
</ul>
<p>These Acts govern the collection, use and disclosure of personal or health information.</p>
<p>Each Act contains provisions to allow for the sharing of personal or health information in the event of an emergency.</p>
<p>All three Acts require that any collection, use or disclosure of personal information or health information be limited to that which is needed to achieve the purpose of the collection, use or disclosure.</p>
<h4><strong>Freedom of Information and Protection of Privacy Act (FOIP Act)</strong></h4>
<p>The FOIP Act applies to “public bodies”, which include provincial government ministries and municipalities.</p>
<p>The FOIP Act permits public bodies to collect personal information if the collection is expressly authorized by an enactment (section 33(a)) or if the collection relates directly to and is necessary for an operating program or activity of the public body (section 33(c)). For example, a municipality may have a bylaw specifically authorizing the collection of personal information in emergency situations. As a bylaw is an “enactment”, the collection would be authorized under section 33(a). Section 33(c) would permit a municipality to collect personal information necessary for the management and delivery of its emergency services.</p>
<p>The FOIP Act generally requires public bodies to collect personal information directly from the individual the information is about. Public bodies may collect information about an individual from other sources with the individual’s consent, or without consent in specific circumstances, such as when the collection is authorized by law or the individual is not able to provide the information directly in a health or safety emergency (section 34(1)).</p>
<p>Public bodies may disclose personal information in emergency situations with the consent of the individual, or without consent in certain circumstances, including:</p>
<ul>
<li>if the disclosure is authorized by an enactment of Alberta or Canada (sections 40(1)(e), (f))</li>
<li>to avert or minimize an imminent danger to the health or safety of any person (section 40(1)(ee))</li>
<li>if the disclosure is not an unreasonable invasion of the individual’s privacy (section 40(1)(b))</li>
<li>so that a spouse, adult interdependent partner, relative or friend of an injured, ill or deceased individual may be contacted (section 40(1)(s))</li>
</ul>
<h4><strong>Health Information Act (HIA)</strong></h4>
<p>The HIA applies to health information in the custody or control of custodians. Custodians include Alberta Health, Alberta Health Services, Covenant Health, nursing homes, ambulance operators, physicians, pharmacists, registered nurses and certain other health professionals. The HIA authorizes custodians to collect and use health information for the purposes of providing health services.</p>
<p>The HIA allows custodians to disclose (Part 5) health information with the consent of the individual, or without consent in specific circumstances, including:</p>
<ul>
<li>if the disclosure is authorized or required by an enactment of Canada or Alberta (section 35(1)(p))</li>
<li>to avert or minimize an imminent danger to the health or safety of any person (section 35(1)(m))</li>
<li>to family members or another individual in a close relationship with the individual so they may be notified that the individual is ill, injured or deceased, providing the disclosure is not contrary to the expressed wishes of the individual (section 35(1)(d))</li>
<li>to another custodian for the provision of health services (section 35(1)(a))</li>
<li>to a person responsible for continuing treatment and care for the individual (section 35(1)(b))</li>
<li>to law enforcement officials where the custodian reasonably believes the information relates to a possible offence and the disclosure will protect the health and safety of Albertans (section 37.3(1) – limited health information may be disclosed in this circumstance (section 37.3(2))</li>
</ul>
<h4><strong>Personal Information Protection Act (PIPA)</strong></h4>
<p>PIPA applies to personal information collected, used and disclosed by private sector organizations.</p>
<p>Organizations are required by PIPA to collect, use and disclose personal information only for purposes that are reasonable (sections 11, 16 and 19). The term “reasonable” means “what a reasonable person would consider appropriate in the circumstances” (section 2).</p>
<p>Except in limited, specific circumstances, PIPA requires organization have the individual’s consent when collecting, using or disclosing personal information about that individual (section 7). Some of the circumstances where consent is not required include:</p>
<ul>
<li>if the collection, use or disclosure is authorized by an enactment of Alberta or Canada, including a bylaw (sections 14 (b), 17(b) and 20(b))</li>
<li>a reasonable person would consider that the collection, use or disclosure of the information is clearly in the interests of the individual and consent of the individual cannot be obtained in a timely way or the individual would not reasonably be expected to withhold consent (sections 14(a), 17(a) and 20(a))</li>
<li>the use or disclosure of the information is necessary to respond to an emergency that threatens the life, health or security of an individual or the public (sections 17(i) and 20(g))</li>
<li>the disclosure is for the purposes of contacting the next of kin or a friend of an injured, ill or deceased individual (section 20(h))</li>
</ul>
<h4>Declaration of a Public Health Emergency</h4>
<p>Privacy legislation would not impede the work of public health officials if a public health emergency is declared.</p>
<p>If an outbreak is declared to be a public emergency, the powers to collect, use and disclose personal or health information to protect the public health may be very broad.</p>
<p>In the event that a public health or general emergency is declared, orders issued under public health legislation could require the collection, use and disclosure of certain personal information relating to employees and customers.</p>
<p>If you need to collect, use or disclose employee personal information in an emergency, you should communicate to your employees the specific legislative authority that is engaged to do so.</p>
<p><em>March 2020</em></p>
</div>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>COVID-19 Pandemic: Proof of Vaccination</title>
		<link>https://oipc.ab.ca/resource/proof-of-vaccination/</link>
		
		<dc:creator><![CDATA[ssibbald]]></dc:creator>
		<pubDate>Mon, 28 Feb 2022 22:27:21 +0000</pubDate>
				<guid isPermaLink="false">https://staging.oipc.ab.ca?post_type=resource&#038;p=2438</guid>

					<description><![CDATA[As more individuals receive COVID-19 vaccinations, some organizations may be considering asking customers to provide proof of vaccination in order&#8230;]]></description>
										<content:encoded><![CDATA[<p>As more individuals receive COVID-19 vaccinations, some organizations may be considering asking customers to provide proof of vaccination in order to receive discounts, access goods or services, or enter a store.</p>
<p>This advisory provides guidance for organizations subject to the Personal Information Protection Act (PIPA) that are considering asking for or requiring proof of vaccination from customers for these or similar purposes.</p>
<p><strong>Note: </strong>This advisory does not provide guidance for employers who may be considering requiring proof of vaccination from employees, and it does not address proof of vaccination for the purpose of international travel or domestic air travel as border services and airlines are subject to federal laws and oversight.</p>
<h4>Proof of Vaccination</h4>
<p>Proof of vaccination is information about an individual’s health history, and is personal information as defined in PIPA. Proof of vaccination may include much more information than just an individual’s vaccine status, including their name, date of birth, address, phone number and personal health number.</p>
<p>Proof of vaccination may be in paper or digital format. For example, an individual may receive a paper or digital record from Alberta Health Services or their pharmacist at the time of vaccination. Individuals may also access their immunization history online (for example, My Health Records accounts for registered users provide immunization history).</p>
<h4>Reasonable Purpose and Reasonable Extent</h4>
<p>Organizations that wish to collect proof of vaccination must ensure they have a reasonable purpose for doing so (section 11).  In some cases, this may be relatively straightforward. For example, it may be reasonable for an organization to offer a customer a discount, or even complimentary goods and services, if the customer can show they have been vaccinated.</p>
<p>In other cases, the assessment of whether an organization has a reasonable purpose for asking for proof of vaccination may be more complex. For example, if an organization wants to collect proof of vaccination for “health and safety purposes” before allowing a customer to enter a store, it may need to consider a range of factors in determining whether this purpose is reasonable, including:</p>
<ul>
<li>The likelihood customers will be able to provide proof of vaccination on request</li>
<li>The effectiveness of other measures to achieve the purpose, such as physical distancing, wearing a mask and other common public health practices</li>
<li>The type of services offered, and whether customers and employees are in close contact for extended periods of time</li>
<li>The implications for people who may be denied access, such as those who choose not to be vaccinated for medical reasons or religious beliefs</li>
<li>Laws that authorize or prohibit requiring individuals to provide proof of vaccination, which may be based on industry, type of service, or in specific and limited circumstances</li>
</ul>
<p>If an organization can establish that it has a reasonable purpose for collecting proof of vaccination, it will also need to consider the extent of collection (section 11(2)), and specifically whether it needs to record information or if viewing proof of vaccination is sufficient.</p>
<p>Personal information does not need to be recorded or written down in order for PIPA to apply; viewing a certificate or proof of vaccination is a collection of personal information that is subject to PIPA. An organization may be able to accomplish its purpose reasonably by viewing proof of vaccination, and may not need to make a record of the customer’s vaccination.</p>
<h4>Notice</h4>
<p>Before or at the time of collecting personal information, such as proof of vaccination, from an individual, an organization is required to provide notice of its purpose for collecting the information. The organization must also be prepared to provide a customer with the name or position of a person who is able to answer questions the individual may have about the collection of personal information (section 13).</p>
<p>Businesses can make customers aware of their personal information collection practices and the purpose for collection through websites, social media pages, or posters at entrances or other highly visible locations. Another option may be to provide a staff member with a script to describe the personal information collection practice and the reason for the collection at the time of the collection.</p>
<h4>Consent and Denial of Service</h4>
<p>In addition to the above obligations with respect to reasonable purpose and notice, organizations will generally require an individual’s consent to collect proof of vaccination (section 7).</p>
<p>Consent under PIPA can be written or oral, and can take many forms (section 8) including an express statement (for example, “I consent to the collection of my personal information for the purpose of&#8230;”).</p>
<p>Consent can also be deemed where the purposes for collection are obvious and the individual voluntarily provides their information, or opt-out where an individual is told an organization will collect their personal information for a particular purpose and the individual has a reasonable opportunity to decline or object to the collection.</p>
<p>Organizations should note that <strong>PIPA prohibits requiring an individual to consent to the collection of personal information beyond what is necessary to provide the product or service</strong> (section 7(2)).</p>
<p>This means an organization <strong>cannot</strong> require an individual to provide proof of vaccination in order to enter a store or to eat in a restaurant, unless collecting proof of vaccination is <strong>necessary</strong> to meet the organization’s purpose. The threshold for an organization to establish that it is necessary to collect proof of vaccination for a particular purpose, such as store entry, is higher than establishing that it is reasonable. If it is not necessary to collect personal information to provide the service, then the organization cannot require the individual to provide the information and cannot deny the service if the individual refuses to consent.</p>
<h4>Other Privacy Considerations</h4>
<p>PIPA prohibits an organization from retaining personal information longer than is required to meet legal or business purposes (section 35). If an organization does not require a record of vaccination for its purposes, it should not create and retain one. If it does record proof of vaccination, it must securely destroy this information once its business purpose has been achieved. It is unlikely that an organization collecting proof of vaccination in order to offer a discount will need to create a record, or retain it for any length of time.</p>
<p>Organizations are also cautioned that if personal information, such as proof of vaccination, is collected for a specific purpose, the information cannot be used for any other purpose, unless the organization obtains the individual’s consent. For example, an organization cannot collect proof of vaccination to offer a free drink or meal, and then add a customer to a mailing list to receive promotional or marketing materials, unless the organization obtains consent and advises individuals of this new purpose.</p>
<h4>Customer Rights</h4>
<p>Customers may make a complaint to the OIPC if they believe that their personal information was improperly collected, used or disclosed.</p>
<p><em>May 2021</em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>COVID-19 Pandemic: Customer Lists for Contact Tracing</title>
		<link>https://oipc.ab.ca/resource/customer-lists/</link>
		
		<dc:creator><![CDATA[ssibbald]]></dc:creator>
		<pubDate>Mon, 28 Feb 2022 22:26:14 +0000</pubDate>
				<guid isPermaLink="false">https://staging.oipc.ab.ca?post_type=resource&#038;p=2419</guid>

					<description><![CDATA[The Office of the Information and Privacy Commissioner (OIPC) has received several questions from organizations and individuals about keeping a&#8230;]]></description>
										<content:encoded><![CDATA[<p>The Office of the Information and Privacy Commissioner (OIPC) has received several questions from organizations and individuals about keeping a customer list or contact log during the COVID-19 pandemic, particularly in retail locations and at restaurants.</p>
<p>The following are some considerations to ensure that organizations comply with Alberta’s Personal Information Protection Act (PIPA) when making and keeping lists of customers and their contact information.</p>
<h4>Consent and Notice</h4>
<p>Organizations must generally obtain an individual’s consent to collect that individual’s personal information (sections 7 and 8). An organization must also notify an individual about why the personal information is being collected – before or at the time of the collection (section 13). Both consent and notification can be done in writing or orally.</p>
<p>In addition to notifying customers about the purpose for collecting personal information, an organization must also be prepared to provide a customer with the name or position of a person who is able to answer questions on behalf of the organization about the collection of personal information.</p>
<p>Businesses can make customers aware of their personal information collection practices and the purpose for the collection through websites, social media pages, or posters at entrances or other highly visible locations. Another option may be to provide a staff member with a script to describe the personal information collection practice and the reason for the collection at the time of the collection. Other options may be available to a business.</p>
<p>If an organization decides to collect customer information during the COVID-19 pandemic, they are advised to understand their authority to collect personal information and be able to cite their authority under PIPA.</p>
<p>Further, section 7(2) of PIPA says that an organization shall not, as a condition of supplying a product or service, require an individual to consent to the collection of personal information beyond what is necessary to provide the product or service. Organizations should determine whether it is necessary for a customer to provide contact details in order to shop in a store or eat at a restaurant. If it is not necessary, then the organization cannot require the individual to provide the information.</p>
<p>There are circumstances in which consent may not be required, such as if a public health order requires the collection of personal information. Organizations are advised to keep up to date on public health orders, which may require that personal information of customers be collected by some businesses or in certain circumstances. In such a scenario, organizations should also be prepared to notify customers why they are required to collect personal information.</p>
<h4>Reasonable Purpose and Extent</h4>
<p>PIPA requires that organizations collect personal information only for purposes that are reasonable and only to the extent reasonable for meeting those purposes (section 11).</p>
<p>For example, an organization may decide as a health and safety measure for employees and customers to collect personal information in order to assist contact-tracing efforts during the COVID-19 pandemic. The organization can only collect personal information that would be reasonably required to meet the purpose. For example, it might be reasonable to collect an individual’s name, cellphone number or email address, and the date and time the customer attended the store or restaurant. It is unlikely that it would be reasonable to collect other types of personal information that are not required for the purposes of contact tracing.</p>
<h4>Secondary Use Restrictions</h4>
<p>Organizations cannot use information collected for one purpose for another, different purpose, unless the individual consents to the new use, or the new use is otherwise authorized by PIPA (section 17). This means, for example, that an organization cannot use personal information collected to contact a customer in the event of exposure to COVID-19 to add them to a mailing or subscription list. The organization would have to obtain consent for this additional purpose.</p>
<p>Another example may be a restaurant that uses an online platform for booking reservations. If the restaurant intends to use the information collected for booking reservations to assist with contact tracing in certain circumstances, they may have to get consent and notify customers before or at the time of the collection that the information may also be used to assist contact tracing efforts during the COVID-19 pandemic. The business may also need to get consent for this new use of information prior to disclosing the customer’s contact information.</p>
<h4>Retention</h4>
<p>If an organization collects a list of customers and associated personal information, it will need to consider how long to retain the information. The organization might want to consider factors such as the period of time public health authorities say it takes for COVID-19 virus to present itself in individuals and how long it might take for someone to be tested and diagnosed with COVID-19 (e.g. Alberta Health’s contact-tracing app retains contact logs for 21 days). PIPA prohibits an organization from retaining the information longer than is necessary for legal or business purposes.</p>
<p>When the information is no longer required for those legal or business purposes, the organization is required to destroy the information or render it non-identifying (section 35).</p>
<h4>Safeguarding</h4>
<p>Organizations subject to PIPA are required to make reasonable security arrangements to protect personal information against unauthorized access, collection, use, disclosure, copying, modification, disposal or destruction (section 34).</p>
<p>Using a single customer sign-in sheet can disclose personal information about one customer to others.</p>
<p>Organizations should consider how they can collect and retain the customer’s personal information in a manner that does not disclose it to others, and ensure that access to this information is strictly controlled by certain employees (e.g. not all employees have access to the information).</p>
<h4>Customer Rights</h4>
<p>If a customer is unclear about why they are being asked to provide personal information, they can ask in what circumstances their information will be used and disclosed. Customers also have a right under PIPA to request access to their own personal information. They may also make a complaint to the OIPC if they believe that their personal information was improperly collected, used or disclosed.</p>
<p><em>June 2020</em></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
