CSA PLUS 8300-1996 Making the CSA Privacy Code Work for You (Includes Plus 8830-95).pdf
《CSA PLUS 8300-1996 Making the CSA Privacy Code Work for You (Includes Plus 8830-95).pdf》由会员分享,可在线阅读,更多相关《CSA PLUS 8300-1996 Making the CSA Privacy Code Work for You (Includes Plus 8830-95).pdf(259页珍藏版)》请在麦多课文档分享上搜索。
1、PLUS 8300 Making the CSA Privacy Code Work for You A workbook on applying the CSA Model Code for the Protection of Personal Information to your organization (CAN/CSA-Q830) PLUS 8300 Making the CSA Privacy Code Work for You A workbook on applying the CSA Model Code for the Protection of Personal Info
2、rmation (CAN/CSA-Q830) to your organization Published in December 7 996 by Canadian Standards Asssociation 7 78 Rexdale Boulevard, ftobicoke, Ontario, Canada M9 W 7 R3 Acknowledgments This Publication was developed under the guidance of the Technical Committee on Privacy and, in particular, the foll
3、owing individuals: M. Long - Ottawa - Publication Coordinator and Prime Author C. Bennett - Victoria - Associate Professor, University of Victoria T. Campbell - Toronto - Contributor A. Coles - Edmonton - Contributor D. McKendry - Ottawa - Contributor R. Roy - Ottawa - Contributor Note on tailoring
4、the Code Organizations may choose to develop an organization-specific code based on the CIA Code. The commentaries which accompany each of the Code principles may be tailored to provide organization-specific examples. The principles themselves are interrelated and must be applied in their entirety a
5、nd without alteration (see CSA Code, General Requirements, Clauses 3.7.7 and 3.7 -2, and Appendix D of this Publication). Note on registering with the Quality Management Institute - a division of CSA A separate publication is attached which gives details of tbe steps to be undertaken should you wish
6、 to register your organizations adoption of the Code with the Quality Management Institute (OW. ISBN 0-921 347-57-X 0 Canadian Standards Association - 1996 All rights reserved. No part of this Publication, other than sections indicated bejow, may be reproduced in any form, in an electronic retrieval
7、 system or otherwise, without express prior permission of the publisher. This workbook contains forms which may be used to document personal information management practices and procedures. These forms are clearly identified and may be reproduced without perm iss ion. Technical Editor: Robin Haighto
8、n Managing L ditor: Gary Burford Making the CSA Privacy Code Work for You Contents Introduction The purpose of this workbook Chapter 1 The importance of u national voluntary informa tion protection code Chapter 2 Significonce of the ten prhciples Chapter 3 How to implement the CSA Code in your orgun
9、lzution Stage 1: Establishing an implementation ream and plan Stage 2: Assessing your current information use policies and practices Stage 3: Bringing poIicies and practices in line with the CSA Code Step 7. Step 2. How to identify information purposes Ways to explain purposes and obtain consent Ste
10、p 3. What to do when you want to use information for new purposes Step 4. Step 5. How long you should keep information How to make sure personal information is secure Step 6. How to address individuol concerns about personal information use Stage 4: Documenting policies and procedures Stage 5: Truin
11、ing employees and implementing Q communications plan Stage 6: Periodic review and auditing Appendices A - Privacy publications and information sources B - QMI recognition program C - Information on safeguards and security D - Tailoring the Code: report to CSA Technical Committee on Privacy Page V 1
12、7 21 23 26 34 34 37 42 45 48 54 61 64 69 75 ai 83 87 E - Health information December 1996 89 PLUS 8300 iV December 7 996 In trod u ction The purpose o this workboo k HE PUBLICATION CAN/CSA-Q830, A Mode/ Code for the Protection of Personal information, T referred to as the CSA Code, (a) provides the
13、principles for the management of personal information; (b) specifies the minimum requirements for the adequate protection of personal information held by pa rtic i pati n g organizations; (c) makes the Canadian public aware of how personal information should be protected; and (d) provides standards
14、by which the international community can measure the protection of personal information in Canada. This workbook is designed to provide practical, useful advice to help organizations understand and apply CSAs Model Code for the protection of personal information. The workbook is intended to be used
15、in conjunction with the CSA Code, but it is not a replacement. The text of the CSA Code in its entirety should be referred to, when required, as the final authority on matters of.interpretation. The workbook was developed and reviewed by the CSA Technical Committee on Privacy, to provide guidance on
16、 how to apply the CSA Code effectively, Organizations will find it a valuable tool, particularly for those individuals directly responsible for implementing the CSA Code. However, the use of the workbook is not mandatory. The CSA Code can be applied in all types of organizations, from small sole pro
17、prietorships to large corporate enterprises; from service clubs and charities to universities and hospitals; from organizations that hold very little personal information to those that specialize in information collection and use. While CSA has produced only one workbook to cover this vast range of
18、information users, the principles of the CSA Code are universal and can, accordingly, be applied to all types of organizations whether they are large or small, locally based or multinational, and whether they use the simplest of information management methods or are at the leading edge of electronic
19、 information use. What differs principally between organizations is the amount and variety of information collected, its sensitivity, and its relative value, both to the individuals providing it and the organizations using it. The workbook addresses these differences with examples drawn from a range
20、 of organizational experiences and with practical, commonsense solutions. Whatever type of organization you are involved with, this workbook will provide you with basic information you need to implement the CSA Code in an appropriate way. December 7 996 V PLUS 8300 The CSA Code was developed as a na
21、tional voluntary standard for personal information protection. As you apply the CSA Code, remember that its ultimate success depends upon an underlying commitment to integrity and fairness in the use of personal information. Organizations must always balance their need for information collection, us
22、e, and disclosure with the privacy rights of the i nd ivid u a I. Implementing the CSA Code may be a time-consuming task; however, once implemented, the ongoing maintenance of systems and procedures to meet the Standard should become a routine operation. In support of the CSA Code, the Quality Manag
23、ement Institute (QMI) is offering three levels or tiers of recognition as follows: Tier 1 - Declaration of the organizations intent to apply the CSA Code. Tier 2 - Verification by QMI that the CSA Code has been implemented to an acceptable standard. Tier 3 - Registration with QMI. For more details o
24、n these tiers and the role of the Quality Management Institute, see Appendix 8. CSA has also published (August 7 995) the background research report, Implementing Privacy Codes of Practice: A Report to the Canadian Standards Association (PLUS 8830), written by Colin Bennett of the University of Vict
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- CSAPLUS83001996MAKINGTHECSAPRIVACYCODEWORKFORYOUINCLUDESPLUS883095PDF

链接地址:http://www.mydoc123.com/p-621592.html