Queen鈥檚 introduces two new privacy policies
August 10, 2018
Share
Queen University has introduced two new policies focused on access to information and the protection of personal and health information.
The policies 鈥 Access to Information and Protection of Privacy Policy and Policy on the Handling of Personal Health Information 鈥 were recently approved by the Vice Principals鈥 Operations Committee (VPOC).
Both policies apply to the whole Queen鈥檚 community and are a response to recent audit reviews that highlighted the need to clearly define the expectations and responsibilities of the university and its employees in providing access to information and protecting the privacy of personal information and personal health information the university collects and uses, explains Carolyn Heald, Director, University Records Management and Chief Privacy Officer.
As a public institution Queen鈥檚 must comply with the requirements of the Freedom of Information and Protection of Privacy Act (FIPPA). FIPPA gives people a right to make an access to information request for university records, and requires the university to protect the privacy of the personal information it collects and uses. The Records Management and Privacy Office advises on the implications of access and privacy legislation and implements mechanisms to ensure compliance with the law.
鈥淲e collect a lot of personal information here at Queen鈥檚, whether it鈥檚 for students, parents, or even summer campers, and we need to make sure that this information is protected appropriately as per the legislation,鈥 Heald says.
The Access to Information and Protection of Privacy Policy aligns with FIPPA and sets out the expectations for the Queen鈥檚 community.
鈥淭his includes the university鈥檚 use of third-party providers 鈥 such as cloud service providers,鈥 Heald says. 鈥淭he policy addresses the need to ensure that personal information is handled in the appropriate way by providers, through contractual or other means.鈥
The Policy on the Handling of Personal Health Information focuses specifically on personal health information that is gathered by the university鈥檚 Health Information Custodians 鈥 Queen鈥檚 Family Health Team; Student Wellness Services; Athletic Therapy Services; Physical Therapy Clinic; Psychology Clinic; and the Regional Assessment and Resource Centre (RARC) 鈥 that provide health care to the Queen鈥檚 and Kingston communities.
Once again, Queen鈥檚 must follow the requirements of the Personal Health Information Protection Act (PHIPA) and the new policy clearly defines the expectations and requirements for employees when dealing with personal health information.
The importance of protecting personal information has been highlighted internationally in the past year with a number of prominent breaches, as well as the use of social media platforms to create profiles of potential voters without their knowledge or consent.
鈥淭here has been so much more public awareness lately in terms of all the personal information we, as individuals, are giving out to private sector interests through apps and social media. I think the case involving Facebook and Cambridge Analytica has focused people鈥檚 attention and made them realize how much information is being collected for purposes that perhaps we don鈥檛 always know about, whether it鈥檚 for political profiling or adtech or whatnot,鈥 Heald says 鈥淪ocietal expectations are shifting and we also see that in decisions the courts are making about people鈥檚 reasonable expectations of privacy.鈥
The European Union strengthened its privacy legislation in May with the introduction of the General Data Protection Regulation (GDPR). The GDPR affects Queen鈥檚 to some extent and the new policies were developed with an eye to that legislation as well.
All Queen鈥檚 University policies are available on the University Secretariat and Legal Counsel website.