Sensitivity of Information

Not all personal information carries the same risks. The more sensitive the personal information, the greater the impact a privacy breach will have. While no data disclosure is risk-free, general identifying information carries a lower and more manageable risk than sensitive information. For this reason, the Access to Information Act (ATIA) and Protection of Privacy Act (POPA) provide a framework on how personal information is collected, used and disclosed.

Examples of general identifying information include: job title and business address, publications listed in an academic staff member's annual report and publicly available information. Examples of highly sensitive information include: credit card information, social insurance numbers, and health information of an individual. A privacy breach involving credit card information or social insurance number could result in a real risk of significant harm, such as identity theft. Similarly, a breach of an individual’s health information could cause a risk of significant harm, including humiliation.

For additional information regarding privacy incidents and breaches, please visit the Information, Privacy and Records Management Office’s Privacy and Information Security Incident Reporting web page and the Privacy and Information Security Incident Reporting and Response Procedure

The University is required to make reasonable safeguards to protect personal information that it holds. In general, the higher the sensitivity of the information, the stronger the safeguards must be to protect it. For additional information, please see the Institutional Data Management and Governance Procedure.

For more information about how to safeguard personal information, please see Information Services & Technology’s Information Security web page.