Safeguards - Privacy Breach Prevention
Reasonable Security Arrangements
The Protection of Privacy Act (POPA) requires a public body to protect personal information by making reasonable security arrangements against such risks as unauthorized access, collection, use, disclosure or destruction.
Making reasonable security arrangements means guarding against reasonably foreseeable risks to the privacy of personal information held by the University of Alberta. The University has an obligation to implement deliberate, prudent and functional measures that demonstrate that it considered and mitigated such risks. The nature of the safeguards and measures required to be undertaken will vary according to the sensitivity of the personal information.
Guidance on Implementing Reasonable Security Arrangements or Safeguards can be found at the website of the Office of the Information and Privacy Commissioner, by clicking on the link below:
Securing Personal Information: A Self-Assessment Tool for Organizations
Information about information technology security can be found at the University's Information Information Services & Technology (IST) website, located here:
Chief Information Security Officer
Safeguarding Information on Mobile Devices
One of the most common sources of privacy breaches is the loss or theft of mobile devices containing personal information. If this happens, the first question we ask is whether the device was encrypted. Several privacy commissioners have stated that organizations fail to meet their duties under privacy legislation if they fail to encrypt mobile devices.
For this reason, the Encryption Procedure states that any mobile computing device that is used to store personal information under the custody or control of the university must be encrypted and protected in accordance with standards developed by the Office of the Chief Information Officer and Associate Vice-President (IST). This applies regardless of whether the device is owned by the university or the individual.
Procedures and guidance on how personal information on mobile devices is to be protected can be found here:
Chief Information Security Officer: Mobile Security
Privacy Highlights + Quick Tips
Check out some quick tips on our Privacy Highlights and Quick Tips document.
Misdirected E-mails
Did you know that misdirected emails to individuals who have the same or a similar name as the intended recipient is one of the most common causes of privacy breaches? Before sending personal information by e-mail, please consider the risks of sending this information by e-mail, and consider whether you can use a more secure method of sending the information (e.g. by sharing the personal information on Google Drive).
Read more information about Email Management.
Encryption
For information regarding encryption, visit IST’s website: Encryption.For additional information, please see the Access to Information and Protection of Privacy Procedure and the Privacy and Information Security Incident Reporting and Response Procedure.