Privacy Management Program

The Protection of Privacy Act (POPA) requires the City of Beaumont (and other public bodies) to establish and implement a privacy management program.

The City of Beaumont’s Privacy Management Program (PMP) is an evolving set of policies, procedures and tools developed to protect privacy and align internal policies and procedures with POPA.

The City is committed to protecting personal information and managing it in a responsible, transparent and accountable manner. The City’s Privacy Management and Access to Information Policy establishes the governance framework and guiding principles for the City’s Privacy Management Program.

Compliance with the legislation is a legal obligation and an organizational priority. Through its Privacy Management Program, the City promotes:

  • strong privacy practices,
  • supporting public trust,
  • reducing the risk of privacy incidents and
  • management of personal information in accordance with legislative requirements.

The lifecycle of personal information management follows it through its:

  • collection,
  • use,
  • disclosure,
  • protection,
  • retention and
  • disposal.

Designating the Access and Privacy Officer

The City has designated the Access and Privacy Officer position to comply with legislation.

Position title: Access and Privacy Officer
Department: Legal & Legislative Services
Contact: access.privacy@beaumont.ab.ca

The Access and Privacy Officer is responsible for administering and supporting the City’s privacy management framework, including:

  • Monitoring and supporting compliance with the legislation and the PMP,
  • Providing guidance and recommendations to departments regarding privacy obligations and requirements,
  • Reviewing Privacy Impact Assessments (PIAs) and identifying measures to address privacy risks,
  • Coordinating the management and response to privacy incidents,
  • Overseeing privacy education and awareness initiatives across the organization,
  • Acting as the City’s primary contact with the Office of the Information and Privacy Commissioner of Alberta and
  • Maintaining, evaluating and updating the Privacy Management Program.

Review, assessment and update

The PMP is reviewed on a regular basis and updated as necessary to reflect legislative changes, operational requirements and privacy best practices. At a minimum, the PMP will be formally reviewed every two years.

Administrative directives and procedures

The City maintains policies, procedures, standards and other administrative documents to provide direction for the appropriate management and protection of personal information throughout its operations.

Public availability

The City makes its PMP available to the public in accordance with the legislation.

Privacy incident response

The City has established processes and procedures to help staff respond to privacy incidents promptly and consistently.

Access and correction rights

Individuals have the right to request access to records containing their personal information and to request correction of personal information that they believe is inaccurate or incomplete, subject to applicable legislative requirements.

Complaint response

Individuals who have concerns regarding the collection, use, disclosure, retention, or protection of their personal information may submit a privacy complaint to the City.

Go to Protecting Your Privacy

Automated systems using personal information

Where automated systems involve the collection, use, or disclosure of personal information, the City implements appropriate privacy and security measures to support compliance with the legislation. Information relating to specific technical safeguards may be withheld where permitted under the legislation to protect system security.

Information security classification

The City maintains an information classification framework that applies to personal information, data derived from personal information, and non-personal data that is in the custody or under the control of the City.

Safeguards

The City employs a combination of administrative, technical, and physical safeguards to protect personal information, data derived from personal information, and non-personal data against unauthorized access, use, disclosure, alteration, loss, or destruction.

Certain details regarding security controls and technical measures may be excluded from public documentation where permitted by the legislation and where necessary to maintain the security of information systems.

The City maintains policies governing the acceptable use of technology resources and information assets to support the secure handling of information.

All employees are required to complete privacy awareness training.

The training is intended to give employees an understanding of their responsibilities for safeguarding personal information and complying with the legislation. Topics include:

  • An overview of privacy legislation and employee responsibilities
  • Requirements for the collection, use, disclosure and protection of personal information
  • Individual rights relating to access and correction of personal information
  • Identifying, reporting and responding to privacy incidents
  • The City’s privacy policies, procedures and expectations

Privacy training is provided to new employees, and refresher training is delivered periodically to reinforce privacy awareness and compliance obligations. Records of training completion are maintained by the City.

Privacy Impact Assessments (PIAs)

Privacy Impact Assessments are used to identify, evaluate and mitigate privacy risks associated with new or substantially modified programs, services, technologies, business processes or information-sharing arrangements.

Consent

The City has procedures governing the collection and management of consent. Where consent is required, employees must obtain consent in a manner that complies with the legislation.

Proactive monitoring of information systems

The City conducts monitoring activities relating to information systems that contain personal information, data derived from personal information and non-personal data. These activities support the protection of information assets, the identification of potential risks, and compliance with legislative and organizational requirements.

Information regarding specific monitoring practices or technical controls may be withheld where permitted under the legislation to protect the security of information systems.