Difference between revisions of "Freedom of Information and Protection of Privacy"

From Clicklaw Wikibooks
Jump to navigation Jump to search
Line 1: Line 1:
{{REVIEWEDPLS | reviewer = [https://www.oipc.bc.ca Office of the Information and Privacy Commissioner for BC]|date= February 2019}} {{Dial-A-Law TOC|expanded = rights}}
{{REVIEWEDPLS | reviewer = [https://www.ahbl.ca/people/courtenay-catlin/ Courtenay Catlin], Alexander Holburn and [https://pacificlaw.ca/about-our-lawyers/christopher-v-morcom/ Christopher Morcom], Pacific Law Group|date= April 2022}} {{Dial-A-Law TOC|expanded = rights}}
Increasingly, organizations — both private and public — are collecting your personal information. Learn about the laws allowing you to access this information and limiting how it can be used.
Increasingly, organizations — both private and public — are collecting your personal information. Learn about the laws allowing you to access this information and limiting how it can be collected, used, and disclosed.


==What you should know==
==Common questions==
===What laws govern information and privacy rights in British Columbia?===
In BC, your privacy rights are protected by two main laws.
 
The ''[https://canlii.ca/t/8421 Freedom of Information and Protection of Privacy Act]'' applies to public organizations, like local governments, schools, and hospitals. It also applies to bodies that govern professions in the province, like the College of Physicians and Surgeons of BC (which governs doctors) and the Law Society of BC (which governs lawyers). [https://www.canlii.org/en/bc/laws/stat/rsbc-1996-c-165/latest/rsbc-1996-c-165.html#Schedule_3__309308 Here’s a list] of the professional governing bodies this law covers.
 
The second one, the ''[https://canlii.ca/t/84mg Personal Information Protection Act]'', covers data about you collected, used, and disclosed by private organizations, unincorporated associations, trade unions, trusts, or non-profits. This includes stores, hotels, banks, and doctors in private practice.


===You have a right to certain information===
These two laws regulate how your personal information is allowed to be collected, used and disclosed. They also set out your rights around consent to the collection, use, and disclosure of your data, knowing how much of your data is out there, and what’s being done with it.
In British Columbia, your information and privacy rights are protected by two main laws.


The [https://www.canlii.org/en/bc/laws/stat/rsbc-1996-c-165/latest/rsbc-1996-c-165.html ''Freedom of Information and Protection of Privacy Act''] (called FIPPA) gives you the right to see many records kept by the provincial government and other public bodies — including records of your personal information. Public bodies include provincial government ministries, local governments, public schools, hospitals and health authorities, local police forces, and colleges and universities. They also include bodies that govern professions in the province, such as the College of Physicians and Surgeons of BC (which governs doctors) and the Law Society of BC (which governs lawyers).
For a closer look, visit the [https://www.oipc.bc.ca/for-the-public/what-are-my-rights/ BC privacy commissioner’s website].


In addition, the [https://www.canlii.org/en/bc/laws/stat/sbc-2003-c-63/latest/sbc-2003-c-63.html ''Personal Information Protection Act''] (called PIPA) gives you the right to see your personal information held by organizations in the private sector in BC. This includes stores, hotels and restaurants, doctors in private practice, unions, not-for-profit agencies, credit unions (but not chartered banks), professional associations, and many others. Under PIPA, you can ask an organization for access to your personal information that it has, or explain how it has used your personal information and who the organization has given your information to. You can also ask for information on the organization’s privacy policy.
===How do I request access to my personal information?===
In some cases, a simple phone call or email directly to the organization that has your information will work.


===You have a right to privacy===
But if that route proves unsuccessful, you can send a '''written request'''. The organization will have a department or person that handles such queries. If they don’t, you can send your request to the organization’s general address. It’s their responsibility to have a procedure in place to deal with these requests and make a reasonable effort to assist you.
Both FIPPA and PIPA protect your right to privacy by regulating how public bodies and private organizations collect, use, and give out (or disclose) personal information. Public bodies and organizations can use personal information only for the purposes they collect it for, unless they get your consent to use it for another reason. Organizations and public bodies must ensure they don’t give out personal information without proper authorization.


==Common questions==
For example, if you want to see records on an ICBC claim, you could send a written request to the information and privacy branch of ICBC. ICBC offers guidance on [https://icbc.com/claims/disputes-appeals/Pages/Freedom-of-Information-access.aspx how to make such a request].


===How do I request access to information?===
Here's another example. If you want access to information about how your local gym collects, uses, and discloses your personal information, you can send a written request to the gym’s privacy officer, or to the gym’s general contact address.
In some cases, it may be quick and easy to access records held by provincial government ministries or other public bodies, or to access your personal information held by a private organization. An email or a phone call may be enough to get the information.


But if there’s no other way of getting the information you want, you can send a '''written request''' to the organization. The organization might have a department or person that handles information requests. If they do, you can address your request to them. If not, you can just send your request to the organization. It is the responsibility of the organization to have procedures and training in place to handle information requests.
The BC privacy commissioner’s website provides [https://www.oipc.bc.ca/forms/individuals/ template letters you can use]. As well, many organizations have their own templates and internal procedures. If they do, this is a good place to start.


For example, if you want to see records on an ICBC claim, you could send a written request to the information and privacy branch of ICBC. If you want access to information about your gym’s privacy policy, or your personal information it has on file, you could send a written request to the gym’s privacy officer, or just to the gym’s general contact address.
===How long does a public body or organization have to respond to my request for access to information?===
Under the law, public bodies have '''30 business days''' to respond to your request for information. They can’t charge you for a request that relates to your own personal information. But they ''can'' charge you fees for finding, copying, retrieving, and producing records about anything not related to your personal information if it takes more than three hours. (You can ask them to waive the fees if you can’t afford them, or if the information is in the public interest.)


===How long does a public body or an organization have to respond?===
Private organizations also have '''30 business days''' to respond to your request. They can’t charge you a fee for a request that relates to your “employee personal information.” This is personal information collected, used or disclosed to establish, manage or end an employment relationship. But, just like public bodies, they can charge a small fee to access information that isn’t employee personal information.
FIPPA gives public bodies ''30 business days'' to respond to your request for information. They can’t charge you any fees for your own personal information, but they can charge you fees for finding, copying, retrieving, and producing records not related to your personal information. You can ask them to waive the fees if you can’t afford them, or if the information is in the public interest.


Private organizations also have 30 business days to respond to your request. They can’t charge you a fee for your own “employee personal information”. This is personal information collected, used or disclosed for the purposes reasonably required to establish, manage or end an employment relationship. But they can charge a small fee to access your other personal information — information that is not employee personal information.
===What types of information can’t I request access to?===
You may not be able to get certain records, such as Cabinet records, someone else’s personal information, court files, current work files of the Auditor General or Ombudsperson, or certain information if its disclosure would harm private business interests. You may also not be able to see information if its disclosure would harm a law enforcement matter, or harm people or public safety.


===What kind of information isn’t available?===
If you’re asking for information from a public body, you may ask for certain information to be “severed” from the record. This means you can access the information, but the sections you aren’t entitled to see are blacked out (or “redacted”).
Under FIPPA, you may not be able to get certain records, such as Cabinet records, someone else’s personal information, court files, current work files of the Auditor General or Ombudsman, or certain information if its release or disclosure would harm private business interests. You may also not be able to see information if its disclosure would harm a law enforcement matter, or harm people or public safety.


===What can I do if my request for information is refused?===
===What can I do if my request for information is refused?===
If a public body or private organization refuses your request, or if you’re not satisfied with its response, you can ask BC’s Information and Privacy Commissioner to '''review''' the response. There’s a time limit of ''30 business days'' to make this request to the Commissioner.
If either a public body or private organization refuses your request for information — or if you’re not satisfied with its response you can ask BC’s information and privacy commissioner to '''review''' the response. You have up to '''30 business days''' to do this after you receive a response.


The Commissioner is independent of government. The Commissioner reviews the decision and can order a public body or private organization to release information that FIPPA or PIPA gives you the right to see. See the Information and Privacy Commissioner’s website at [https://www.oipc.bc.ca/for-the-public/how-do-i-request-a-review/ oipc.bc.ca] for how to ask for a review.
The commissioner is independent of the government. They review the decision and can order information to be released — so long as it’s information the law gives you the right to see.


===What if an organization’s information about me is wrong?===  
See the privacy commissioner’s website for [https://www.oipc.bc.ca/for-the-public/how-do-i-request-a-review/ how to ask for a review].
An organization must make reasonable efforts to ensure your personal information is accurate and complete. You can ask a public body to correct any factual error or omission (but not opinions or judgments) in your personal information. If the public body refuses your request, FIPPA requires them to mark your information with the correction you requested. You can also ask a private organization to correct any inaccurate personal information. If you are not happy with the decision of the public body or organization, you can ask the Information and Privacy Commissioner to review the decision.
 
===What if someone’s information about me is wrong?===
An organization must make reasonable efforts to ensure your personal information is accurate and complete.
 
You can ask a public body to correct any factual error or omission (but not opinions or judgments). If they refuse your request, the law requires them to mark your information with the correction you requested.
 
You can also ask a private organization to correct any inaccurate personal information. Again, if the organization refuses your request, the law requires them to mark your information with the correction you requested.
 
If you aren’t happy with the decision of the public body or organization upon a correction request, your next step is to ask the privacy commissioner to review the decision.


===What if I’m upset with how my personal information is being handled?===
===What if I’m upset with how my personal information is being handled?===
If you disagree with how your personal information is being managed, you should first complain directly to the public body or organization about how it collects, uses, or discloses your personal information. You should give the public body or organization a reasonable amount of time to respond.
If you disagree with how your personal information is being managed, you should first complain directly to the public body or organization. Give them a reasonable amount of time to respond.


If that doesn’t help, you can file a complaint with the Information and Privacy Commissioner. The Commissioner’s website at [https://www.oipc.bc.ca/for-the-public/how-do-i-make-a-complaint/ oipc.bc.ca] explains the process to make a complaint.
If that doesn’t resolve the issue, you can file a complaint with BC’s privacy commissioner. The commissioner’s website explains the [https://www.oipc.bc.ca/for-the-public/how-do-i-make-a-complaint/ process to make a complaint].


==Who can help==
==Who can help==


===With more information===
===With more information===
The '''Office of the Information & Privacy Commissioner for BC''' oversees and enforces British Columbia's access to information and privacy laws.
:'''Office of the Information and Privacy Commissioner'''
 
:Oversees BC's laws relating to privacy and access to information.
* Call 250-387-5629 in Victoria
:Call 1-800-663-7867
* Call Enquiry BC at 1-800-663-7867 (toll-free)
:Email: info@oipc.bc.ca
* [https://www.oipc.bc.ca/ Visit website]
:[https://www.oipc.bc.ca/ Visit website]
 
The '''BC Freedom of Information and Privacy Association''' (FIPA) is a non-profit organization dedicated to promoting and defending freedom of information and privacy rights.
 
* [https://fipa.bc.ca/ Visit website]


{{Dial-A-Law_Navbox|type=life}}
{{Dial-A-Law_Navbox|type=life}}
{{Dial-A-Law Copyright}}
{{Dial-A-Law Copyright}}

Revision as of 23:19, 2 October 2023

This information applies to British Columbia, Canada. Last reviewed for legal accuracy by Courtenay Catlin, Alexander Holburn and Christopher Morcom, Pacific Law Group in April 2022.

Increasingly, organizations — both private and public — are collecting your personal information. Learn about the laws allowing you to access this information and limiting how it can be collected, used, and disclosed.

Common questions

What laws govern information and privacy rights in British Columbia?

In BC, your privacy rights are protected by two main laws.

The Freedom of Information and Protection of Privacy Act applies to public organizations, like local governments, schools, and hospitals. It also applies to bodies that govern professions in the province, like the College of Physicians and Surgeons of BC (which governs doctors) and the Law Society of BC (which governs lawyers). Here’s a list of the professional governing bodies this law covers.

The second one, the Personal Information Protection Act, covers data about you collected, used, and disclosed by private organizations, unincorporated associations, trade unions, trusts, or non-profits. This includes stores, hotels, banks, and doctors in private practice.

These two laws regulate how your personal information is allowed to be collected, used and disclosed. They also set out your rights around consent to the collection, use, and disclosure of your data, knowing how much of your data is out there, and what’s being done with it.

For a closer look, visit the BC privacy commissioner’s website.

How do I request access to my personal information?

In some cases, a simple phone call or email directly to the organization that has your information will work.

But if that route proves unsuccessful, you can send a written request. The organization will have a department or person that handles such queries. If they don’t, you can send your request to the organization’s general address. It’s their responsibility to have a procedure in place to deal with these requests and make a reasonable effort to assist you.

For example, if you want to see records on an ICBC claim, you could send a written request to the information and privacy branch of ICBC. ICBC offers guidance on how to make such a request.

Here's another example. If you want access to information about how your local gym collects, uses, and discloses your personal information, you can send a written request to the gym’s privacy officer, or to the gym’s general contact address.

The BC privacy commissioner’s website provides template letters you can use. As well, many organizations have their own templates and internal procedures. If they do, this is a good place to start.

How long does a public body or organization have to respond to my request for access to information?

Under the law, public bodies have 30 business days to respond to your request for information. They can’t charge you for a request that relates to your own personal information. But they can charge you fees for finding, copying, retrieving, and producing records about anything not related to your personal information if it takes more than three hours. (You can ask them to waive the fees if you can’t afford them, or if the information is in the public interest.)

Private organizations also have 30 business days to respond to your request. They can’t charge you a fee for a request that relates to your “employee personal information.” This is personal information collected, used or disclosed to establish, manage or end an employment relationship. But, just like public bodies, they can charge a small fee to access information that isn’t employee personal information.

What types of information can’t I request access to?

You may not be able to get certain records, such as Cabinet records, someone else’s personal information, court files, current work files of the Auditor General or Ombudsperson, or certain information if its disclosure would harm private business interests. You may also not be able to see information if its disclosure would harm a law enforcement matter, or harm people or public safety.

If you’re asking for information from a public body, you may ask for certain information to be “severed” from the record. This means you can access the information, but the sections you aren’t entitled to see are blacked out (or “redacted”).

What can I do if my request for information is refused?

If either a public body or private organization refuses your request for information — or if you’re not satisfied with its response — you can ask BC’s information and privacy commissioner to review the response. You have up to 30 business days to do this after you receive a response.

The commissioner is independent of the government. They review the decision and can order information to be released — so long as it’s information the law gives you the right to see.

See the privacy commissioner’s website for how to ask for a review.

What if someone’s information about me is wrong?

An organization must make reasonable efforts to ensure your personal information is accurate and complete.

You can ask a public body to correct any factual error or omission (but not opinions or judgments). If they refuse your request, the law requires them to mark your information with the correction you requested.

You can also ask a private organization to correct any inaccurate personal information. Again, if the organization refuses your request, the law requires them to mark your information with the correction you requested.

If you aren’t happy with the decision of the public body or organization upon a correction request, your next step is to ask the privacy commissioner to review the decision.

What if I’m upset with how my personal information is being handled?

If you disagree with how your personal information is being managed, you should first complain directly to the public body or organization. Give them a reasonable amount of time to respond.

If that doesn’t resolve the issue, you can file a complaint with BC’s privacy commissioner. The commissioner’s website explains the process to make a complaint.

Who can help

With more information

Office of the Information and Privacy Commissioner
Oversees BC's laws relating to privacy and access to information.
Call 1-800-663-7867
Email: info@oipc.bc.ca
Visit website
Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International Licence Dial-A-Law © People's Law School is licensed under a Creative Commons Attribution - NonCommercial - ShareAlike 4.0 International Licence.