Privacy Hub by Wrangu –
Solution for PIPEDA and PPIPS
Your go-to solution for Implementing Canada’s PIPEDA and PPIPS into your organisation
Quick Look: Canada’s PIPEDA
The Personal Information Protection and Electronic Documents Act (PIPEDA) passed into Law in Canada in 2000 places specific regulatory requirements on private sector organisations who process personal data of individuals located in Canada. For most organisations, these requirements have led to the introduction of new processes, systems and personnel to enable them to meet their obligations. Privacy Hub by Wrangu, is a data privacy management solution that automates and harmonises the disparate activities of various teams into one seamless outcome ensuring ongoing compliance.
A look into the details of the PIPEDA articles immediately reveals several requirements of interest such as the rights of data subjects which organisations are required to fulfil within 30 days. Organisations are also required to maintain a record of processing activities, send personal data breach notifications to supervisory authorities and impacted data subjects, conduct data protection impact assessments and process personal data with appropriate safeguards.
Privacy Hub by Wrangu – Solution for PIPEDA
The data subject rights module provides the ability for data privacy teams and data subjects to raise and manage data subject rights requests allowing organisations:
- Capture DSR request details.
- Validate the data subjects, agents and data subject rights requests.
- Manage 30 days SLA duration.
- Have a consolidated view of all open and closed data subject requests received from a particular data subject over a given period of time to manage excessive request.
- Indicate whether a DSR request should be fulfilled based on the lawful basis of processing the information and possible reasons to decline requests.
- Request approval from a data controller to process a DSR request.
- Confirm with data subjects how they would like to receive information in response to right to access requests
- Dynamically create action tasks for the notification of third parties when fulfilling a right to erasure or right to rectification request
Relevant PIPEDA Articles:
Part 1, Section 1, Articles 8, 9, 10, Schedule 1, Section 5, Principle 9
The DPIA module provides the ability to perform an initial DPIA screening questionnaire to determine if a new processing is likely to result in a high risk to the rights and freedoms of data subjects and, if required, conduct a full assessment for new projects, ensuring adherence to privacy by design principles. The DPIA module also provides:
- Automatic evaluation of DPIA responses with possible concerns raised for consideration.
- Built-in configurable risk calculation engine with risk ratings displays based on responses.
- Configurable approval levels throughout the lifecycle of an assessment including facility to capture and monitor advice from data protection officers.
Relevant PIPEDA Articles:
Schedule 1, Section 5, Principles 3, 4, 5, 6, 7
Comprehensive engine enabling the robust documentation of processing activities with the ability to relate a ROPA directly to services, processes or configuration items within the ServiceNow CMDB. The ROPA module also supports:
- Capture of all data sets required to fulfil the principles of the regulation on the treatment of personal data. These principles include accountability, identifying purposes of processing, consent, limiting collection, and limiting use, disclosure and retention.
- Maintain version history for each ROPA record to support auditing and complaints management activities.
- Flag changes in the CMDB and other sources that would suggest a need to update the ROPA including provision of adequate technical and organisational measures for the security of personal data.
- Generate and update a ROPA from a DPIA utilising the same data set from the DPIA.
- Automatically indicate what rights data subjects can exercise against the data collected as part of this processing.
Relevant PIPEDA Article:
Part 1, Section 1, Articles 6, 7, Schedule 1, Section 5, Principles 1, 2, 3, 4, 5, 8.
Acts as a register of all data breach incidents as they relate to personal data and facilitate the automatic determination of whether a report or notification should be sent to the Privacy Commissioner or affected data subjects. This module also provides:
- Standard process to support data gathering to determine if the personal data breach is likely to cause relevant risk or damage to the data subjects.
- Automated data breach SLA calculator to ensure regulatory stated reporting timelines are monitored and complied with.
- Generate and assign dynamic tasks to relevant parties in addressing data breach reporting requirements.
- Support report creation for notification to the Privacy Commissioner or communication to affected data subjects.
- Ready integration with ServiceNow Security Incident Response module.
Relevant PIPEDA Article:
Part 1, Division 1.1 Articles 10.1, 10.2 and 10.3
Quick Look: Quebec’s PPIPS
The Act Respecting the Protection of Personal Information in the Private Sector (PPIPS) passed into Law in Quebec, Canada in 1994, places specific regulatory requirements on private sector organisations who process personal data of individuals located in Quebec, Canada. For most organisations, these requirements have led to the introduction of new processes, systems and personnel to enable them to meet their obligations. Privacy Hub by Wrangu, is a data privacy management solution that automates and harmonises the disparate activities of various teams into one seamless outcome ensuring ongoing compliance.
A look into the details of the PPIPS articles immediately reveals several requirements of interest such as the rights of data subjects which organisations are required to fulfill within 30 days. Organisations are also required to maintain a record of processing activities, send personal data breach notifications to supervisory authorities and impacted data subjects, conduct data protection impact assessments and process personal data with appropriate safeguards.
Privacy Hub by Wrangu – Solution for PPIPS
The data subject rights module provides the ability for data privacy teams and data subjects to raise and manage data subject rights requests allowing organisations:
- Capture DSR request details.
- Validate the data subjects, agents and data subject rights requests.
- Manage 30 days SLA duration.
- Have a consolidated view of all open and closed data subject requests received from a particular data subject over a given period of time to manage excessive request.
- Indicate whether a DSR request should be fulfilled based on the lawful basis of processing the information and possible reasons to decline requests.
- Confirm with data subjects how they would like to receive information in response to right to access requests
- Dynamically create action tasks for the notification of third parties when fulfilling a right to erasure or right to rectification request
Relevant PPIPS Articles:
Article 16, 19, 25 – 46
The DPIA module provides the ability to perform an initial DPIA screening questionnaire to determine if a new processing is likely to result in a high risk to the rights and freedoms of data subjects and, if required, conduct a full assessment for new projects, ensuring adherence to privacy by design principles. The DPIA module also provides:
- Automatic evaluation of DPIA responses with possible concerns raised for consideration.
- Built-in configurable risk calculation engine with risk ratings displays based on responses.
- Configurable approval levels throughout the lifecycle of an assessment including facility to capture and monitor advice from data protection officers.
Relevant PPIPS Articles:
Article 10, 11, 12, 17, 20, 21.
Comprehensive engine enabling the robust documentation of processing activities with the ability to relate a ROPA directly to services, processes or configuration items within the ServiceNow CMDB. The ROPA module also supports:
- Capture of all data sets required to fulfil the requirements of the regulation such as bi-annual publication of purposes of processing.
- Maintain version history for each ROPA record to support auditing and complaints management activities.
- Flag changes in the CMDB and other sources that would suggest a need to update the ROPA including provision of adequate technical and organisational measures for the security of personal data.
- Generate and update a ROPA from a DPIA utilising the same data set from the DPIA.
- Automatically indicate what rights data subjects can exercise against the data collected as part of this processing.
Relevant PPIPS Article:
Article 8, 12, 14, 15, 17, 19, 20 – 24, 79.
Acts as a register of all data breach incidents as they relate to personal data and facilitate the automatic determination of whether a report or notification should be sent to the Privacy Commissioner or affected data subjects. This module also provides:
- Standard process to support data gathering to determine if the personal data breach is likely to cause relevant risk or damage to the data subjects.
- Automated data breach SLA calculator to ensure regulatory stated reporting timelines are monitored and complied with.
- Generate and assign dynamic tasks to relevant parties in addressing data breach reporting requirements.
- Support report creation for notification to the Privacy Commissioner or communication to affected data subjects.
- Ready integration with ServiceNow Security Incident Response module.