5.1 Response Protocol
The following five steps shall be initiated as soon as a Privacy Breach or Privacy Incident occurs:
- Report and Assess
- Containment
- Investigate
- Notify
- Closure and Documentation
5.1.1 Step 1: Report and Assess
Report Breach
If you become aware of a possible breach of Personal Information by: 1) an internal source such as a staff member; or 2) an external source such as a third-party contractor, a parent or a student; the suspected breach shall be promptly reported to your Principal or Manager. This shall occur even if the breach is only suspected and not yet confirmed. The following information shall be collected to include in the final documentation in Step 5:
-
- What happened?
- Where?
- When did the Privacy Incident occur?
- How was the Privacy Incident discovered?
- Was any corrective action taken when the Privacy Incident was discovered?
Assess
The Principal or Manager shall assess the information collected to determine whether to take containment steps and notify the Privacy Officer.
If there is a possibility that PI has been collected, used or disclosed without authorization, the Principal or Manager shall take containments steps, per Step 2 below, and shall promptly notify the Supervising Superintendent and Privacy Officer.
5.1.2 Step 2 – Containment
Containment involves taking immediate corrective action to put an end to the unauthorized practice.
For example: recovering the records; shutting down the system; revoking/changing computer access codes; or correcting weaknesses in physical or electronic security. The main goal is to alleviate any consequences for the individual(s) whose PI was involved and for the Board.
5.1.3 Step 3 – Investigate
Once the privacy incident is contained, the Principal or Manager shall consider how best to investigate, with input from the Supervising Superintendent and/or the Privacy Officer as required.
If assistance from an outside expert or investigator is not required, the Principal or Manager shall gather evidence (documentation and statements) to determine the cause and potential impact of the breach by:
-
- identifying and analyzing the events that led to the Privacy Breach;
- evaluating if it was an isolated incident or if there is risk of further exposure to information;
- determining who was affected by the breach, e.g. students or employees, and how many individuals were affected;
- evaluating the effect of containment activities;
- evaluating who had access to what Personal Information;
- evaluating if Personal Information was lost or stolen; and,
- evaluating if the Personal Information has been recovered.
If the privacy incident involved personal information held by one of the Board’s vendors, the Principal or Manager may need to seek all or some of the information above from the vendor.
5.1.4 Step 4 – Notify
Notification helps to ensure that the affected parties can take remedial action, if necessary, and to support a relationship of trust and confidence.
The Principal or Manager shall consult with the Privacy Officer and the Supervising Superintendent (or the Superintendent of Education/Employee Relations for staff breaches, as appropriate) to determine what notifications are required.
Factors in assessing notification
In determining if notification to affected individuals is required, the following factors shall be considered:
a. Reasonable Expectation
The affected individual’s reasonable expectation of notification shall be considered.
b. Statutory Duties
If the information at issue is in a personal counselling or similar record the Board may have a statutory duty to notify affected individuals under the PHIPA. There is also notification duty in the Personal Health Information Protection and Electronic Documents Act that may be triggered in more rare circumstances.
c. Risk of Physical Harm
Does the loss or theft of information place any individual at risk of physical harm, stalking, or harassment?
d. Risk of Identity Theft
Is there a risk of identity theft or other fraud? How reasonable is the risk? Identity theft is a concern if the breach includes unencrypted information such as names in conjunction with social insurance numbers, credit card numbers, drivers’ license numbers, personal
health numbers, debit card numbers with password information, or any other information that can be used for fraud by third parties (e.g., financial). (Appendix 2).
e. Risk of Hurt, Humiliation, or Damage to Reputation
Could the loss or theft of information lead to hurt, humiliation, or damage to an individual’s reputation? This type of harm can occur with the loss or theft of information such as mental health records, medical records, or disciplinary records.
f. Risk of Loss of Business or Employment Opportunities
Could the loss or theft of information result in damage to an individual’s reputation, affecting his/her business or employment opportunities?
Whether notification to authorities or organizations is required
The Privacy Officer shall notify the Information and Privacy Commissioner in accordance with any and all regulatory requirements. The Privacy Officer shall also provide notification to the following, as the Privacy Officer may deem appropriate depending on the circumstances:
-
- police, if theft or other crime is suspected;
- insurers;
- credit card companies and financial institutions;
- third party contractors or other parties that may be affected;
- other DDSB departments or staff; or,
- union or other employee groups.
Notification Timeline
Affected individuals shall be notified promptly after the Board determines that their PI has been collected, used, and disclosed without authorization.
Depending on the circumstances, notification may occur in stages. For example, the Board may choose to notify before completing an investigation if a suspected breach is widely known or if a breach is very likely. In doing so, the Principal or Manager should make clear what the Board knows and does not yet know, and commit to further follow-up.
Method of Notification
The method of notification shall be guided by the nature and scope of the breach and in a manner that reasonably ensures that the affected individual will receive it. Direct notification, e.g., by phone, letter, email or in person is preferable and shall be used where the individuals are identified.
In certain cases, indirect notification may be appropriate. For example, the Board will consider indirect notifications where it is not reasonably possible to ascertain the entire population of affected individuals with precision, where there are a large number of individuals to notify, or where affected individuals are all impactedsimilarly. An indirect notification will be published prominently. The appropriate medium/media for an indirect notification will depend on the circumstances of the
breach. Examples of public notices include posted notices, media releases, and website notices.
Who is Responsible for Notification
Ideally, the individual(s) shall be notified by the department associated with the breach. For example, where the breach is for student information, the Principal of the school shall be responsible for providing notification; where the breach is for staff information, Human Resource Services shall be responsible for providing notification. The Supervising Superintendent or the Superintendent of Education / Employee Relations may be referred to as a contact for questions, as applicable.
Notification shall include:
-
- description of the incident and timing;
- description of the information involved;
- the nature of potential or actual risks or harm;
- what mitigation actions were/are being taken;
- appropriate action for individuals to take in order to protect themselves against harm;
- a contact person for questions or to provide further information; and/or,
- contact information for the Information and Privacy Commissioner of Ontario.
5.1.5 Step 5 – Closure and Documentation: Prevention plan and corrective action
Once the breach has been resolved, the Supervising Superintendent or Associate Director, Corporate Services, as the case may be, shall work with the Principal or Manager to develop a prevention plan or take corrective actions, if required, and in doing so shall consult with the Privacy Officer.
The extent of the prevention plan or corrective actions shall be determined by the significance of the breach and whether it was systemic or isolated. These may include: audits, review of policies, procedures, and practices; employee training; or review of service delivery partners. Consideration shall be given to testing and evaluating a prevention plan or corrective actions to determine if they have been implemented correctly, as well as notifying appropriate stakeholders of any changes or preventative measures that have been implemented.
Privacy Breach Report
The Principal or Manager shall complete a Privacy Breach Report (Appendix 1) in consultation with the Privacy Officer and forward a final copy to the Privacy Officer. If litigation is contemplated, the Privacy Officer may direct that the completion of a Privacy Report be deferred.
Response Protocol – Service Providers
The Board will follow a similar process for responding to breaches and suspected breaches experienced by service providers. The response shall be led by the Privacy Officer delegate, who shall seek appropriate assurances from the service provider about:
-
- The information the service provider will provide to the Board so it can meet its notification and other obligations to individuals;
- The service provider’s plan for communication, which should not create problems or challenges for the Board’s own communication plan; and,
- The final measures taken by the service provider to prevent a recurrence.
Litigation Considerations
These dealings with service providers may be taken in contemplation of litigation (and subject to litigation privilege).