The Personal Information Protection and Electronic Documents Act - PIPEDA (2001) sets out ground rules for how private sector organizations may collect, use or disclose personal information in the course of commercial activities.
Zoocheck shall designate an individual who is accountable for the organization's compliance. Accountability for the organization's compliance with the principles rests with the designated individual, even though other individuals within the organization may be responsible for the day-to-day collection and processing of personal information. The identity of the individual designated by the organization to oversee the organization's compliance with the principles shall be made known upon request.
Zoocheck is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. Zoocheck shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.
- implement procedures to protect personal information;
- establish procedures to receive and respond to complaints and inquiries;
- train staff and communicate to them information about the organization's policies and practices;
- develop information to explain the organization's policies and procedures.
Purposes and Type of Information Collected
The purposes for which personal information is collected and the type of information to be collected shall be identified by Zoocheck at or before the time the information is collected.
Zoocheck collects personal information primarily for the purpose of:
- issuing a tax receipt;
- communicating information about our programs, events, and open houses,
- soliciting donations;
- communicating with individual donors about donations we are unable to process, or problems with a donors monthly donation account;
- communicating volunteer opportunities.
In order to fulfill these purposes Zoocheck collects the following information:
- telephone number;
- e-mail address;
- credit card numbers and expiry dates;
- chequing account details, including transit, bank and account number.
Personal information collected by Zoocheck through surveys is used by Zoocheck for marketing purposes and is not disclosed to third parties. The
only information we may share with third parties is aggregated demographic information, which is not linked to any personal information that can identify any individual person.
From time to time, Zoocheck may ask individuals to sign protest cards or petitions. Zoocheck does not record personal information from these sources. Protest card or petitions are forwarded to the intended recipient as outlined on the protest card or petition.
Zoocheck may also collect information when individuals purchase merchandise or tickets, or participate in draws and contests, in
person, by mail or through the internet.
When personal information that has been collected is to be used for a purpose not previously identified, the new purpose shall be identified prior to use. Unless the new purpose is required by law, the consent of the individual is required before information can be used for that purpose.
Information will only be collected from individuals when the individual specifically and knowingly chooses to provide it.
Individuals who fill out a donation coupon and provide personal information are considered to have implied consent. By completing the donation form, the
individual is giving consent to the collection.
will be sought orally when information is collected over the telephone.
When acquiring a mailing list from another organization, it is expected that the organization providing the list has obtain consent as per PIPEDA before disclosing personal information.
An individual may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.
The collection of personal information shall be limited to that which is necessary for the purposes identified by Zoocheck. Information shall be collected by fair and lawful means.
Use, Disclosure, and Retention
Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required by law.
Personal Information will be retained for an indefinite period of time after an individual’s last contact (ie. an individual has sent Zoocheck a donation or has initiated contact with us and has provided personal information) with Zoocheck.
Personal information that is no longer required to fulfil the identified purposes will be destroyed, erased, or made anonymous.
Personal information shall be as accurate, complete, and up-to-date as is necessary for the purposes for which it is to be used.
Personal information shall be protected by security safeguards appropriate to the sensitivity of the information. The security safeguards shall protect personal information against loss or theft, as well as unauthorized access, disclosure, copying, use, or modification.
The methods of protection should include:
- filing cabinets containing personal information will be kept in the Zoocheck office which shall be locked every evening;
- access to personal information will be restricted to employees and volunteers who have signed a confidentiality waiver;
- passwords will be required on all computers and programs that contain personal information;
- files containing personal information sent and received from third parties via the internet will be encrypted using specialized software;
- personal information collected through the Zoocheck website will be protected using encryption software;
- hard copies of personal information will be shredded before disposal.
Zoocheck shall make its employees aware of the importance of maintaining the confidentiality of personal information.
Zoocheck shall make readily available to individuals specific information about its policies and practices relating to the management of personal information.
The information made available shall include
- the name or title, and the address, of the person who is accountable for the organization's policies and practices and to whom complaints or inquiries can be forwarded;
- the means of gaining access to personal information held by the organization;
- a description of the type of personal information held by the organization, including a general account of its use;
- a copy of the Policy Statement explaining the organization's policies.
Upon request and within a reasonable time-frame, an individual shall be informed of the existence, use, and disclosure of his or her personal information and shall be given access to that information. An individual shall be able to challenge the accuracy and completeness of the information and have it amended as appropriate.
Exceptions may include information that is prohibitively costly to provide, information that contains references to other individuals, information that cannot be disclosed for legal, security, or commercial proprietary reasons, and information that is subject to solicitor-client or litigation privilege.
In providing an account of third parties to which it has disclosed personal information about an individual, Zoocheck shall provide a list of organizations to which it may have disclosed information about the individual.
Challenges concerning compliance with the above principles shall be addressed to the designated individual accountable for Zoocheck’s compliance.
Challenges concerning complaints will be investigated and recorded by Zoocheck. If a complaint is found to be justified, Zoocheck shall take appropriate measures, including, if necessary, amending its policies and practices.