The Modernization of Privacy Laws and What This Means for Your Business

In a digital world where personal information is so easily collected and may easily be used for malicious intent, concerns about privacy and the protection of personal information has become an important topic. Globally, governments have implemented or are implementing privacy laws to reflect today’s realities.   

The European Union’s General Data Protection Regulation (GDPR) which regulates personally identifiable data was one of the first modernized privacy legislations to be adopted. Other governments have followed suit or have tabled reforms to current privacy laws that they are looking to adopt.  

In Canada, on the federal level, there is Personal Information Protection and Electronic Documents Act (PIPEDA). As recently as 2020, legislation was tabled to maintain, modernize, and extend existing rules and to impose new rules on private sector organizations for the protection of personal information. Ultimately, Bill C-11 did not become law, but they are working on tabling a new bill that would reform the current protection of personal information legislation. BC is looking at reforming their Personal Information Protection Act (PIPA) and Ontario has tabled a reform document as well. Most recently, Quebec passed into law Bill 64 which experts say, will be a template for the Canadian government as well as other provincial governments for reforming the protection of personal information legislation. 

Reforms 

A few of the areas of focus of the privacy reforms include: 

  1. Privacy by Default  

An approach to systems development that requires data protection to be taken into account throughout the system development process when collecting, retaining, using, accessing, sharing or any otherwise managing a person’s personal information. This includes deactivating profiling, tracking or identification technology, and giving individuals the opportunity to expressly opt for such features in accordance with their preferences. 

  1. Greater control of personal information  

The person whose personal information is being requested has more control over the information they provide. This includes: 

  • Transparency and accountability when it comes to consent, use, access, retention and with who and when it may be shared 
  • They have the right to de-indexation (requesting that personal information ceases to be disseminated) 
  • The anonymization (person cannot be identified) of personal information once the purpose for which it was collected has been achieved 
  • Data portability which gives a person the right to access their personal information as well as the right to ask that the information be communicated or transferred to themselves or a third party  
  1. Development, implementation and publication of detailed privacy policies and practices by businesses and organizations 
  1. Reporting and notification of breaches affecting personal information 
  1. Stringent enforcement mechanisms and heavy administrative penalties and fines by privacy commission of the jurisdiction for violations and offences in addition to, the ability for private action against the violators 

What does this mean for businesses? 

The reforms that have been tabled or already enacted by various government bodies in Canada and globally include more stringent requirements and enforcement mechanism. Additionally, penalties and fines for non-compliance are much more impactful.  

If not already done, organizations will have to develop, implement, communicate internally, and make public their privacy policies and practices. I order to do this they will need to have someone within the organization responsible for privacy. The privacy will need to understand how they collect personal information. What information they are collecting. The purpose of information. Who will have access. How it will be shared. Who it will be shared with. Where it will be shared. The interaction between the data and different applications and tools. How and where it will be stored. The retention period. How the data will be protected. What the breach protocols will be. What the incident response plan will be.  

IT Service Providers, like MicroAge, can help with the security, storage, backup, and recovery of the data. To understand the impact of the privacy laws on your organization, we recommend engaging with a legal expert with specific expertise in privacy laws. 

Get the most from your IT

As service providers to more than 300 companies, the dedicated professionals at MicroAge are second to none when it comes to managed services. By improving efficiency, cutting costs and reducing downtime, we can help you achieve your business goals!

Most commented posts

10 Keyboard Shortcuts That Work in Chrome, Edge, and Firefox Browsers

You can use many of the same keyboard shortcuts when working in Google Chrome, Microsoft Edge, and Mozilla Firefox web browsers. Here are 10 keyboard shortcuts that are handy as well as easy to remember.

Read More

Disinfect Your Devices

How to disinfect your devices and maintain a healthy work environment. MicroAge is dedicated to providing our clients with market-leading business solutions that help them…

Read More
remote-work-it-security

Rethinking Your IT With A Decentralized Workforce – Chapter 1 : Security

With an increasingly remote or hybrid workforce, we must rethink the way you look at your IT. Let’s first examine network security and how to…

Read More
8 actions to avoid ransomware

8 Actions Your Business Can Take Now to Avoid Paying a Ransom Later

The number of ransomware attacks have exploded in 2021. The month of July started out with a big bang when cybercriminals encrypted the data in…

Read More
Microsoft365-vs-AzureVirtualDesktop

Azure Virtual Desktop vs Windows 365: What is the Difference?

As we mentioned in a previous blog Desktop as a Service (DaaS) is a cloud-based offering where the backend is hosted by a third party….

Read More