Authentic statutory obligations decomposed into atomic machine-actionable conditions, actions, and verification standards.
The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate (Schedule 1, 4.3).
Statutory verification and compliance logging required.
{
"no_deceptive_patterns": true,
"express_consent_for_sensitive_data": true
}The purposes for which personal information is collected shall be identified by the organization at or before the time the information is collected (Schedule 1, 4.2).
Statutory verification and compliance logging required.
{
"purpose_identified_at_collection": true
}Personal information shall be protected by security safeguards appropriate to the sensitivity of the information (Schedule 1, 4.7).
Statutory verification and compliance logging required.
{
"physical_organizational_technical_safeguards": true
}An organization must report to the Privacy Commissioner of Canada any breach of security safeguards involving personal information that poses a real risk of significant harm (PIPEDA Section 10.1).
Statutory verification and compliance logging required.
{
"prompt_opc_notification": true,
"rosh_assessment_framework": true
}The collection of personal information shall be limited to that which is necessary for the purposes identified by the organization (Schedule 1, 4.4).
Statutory verification and compliance logging required.
{
"data_collection_boundary_enforced": true
}An organization is responsible for personal information under its control and shall designate an individual or individuals who are accountable for compliance (Schedule 1, 4.1).
Statutory verification and compliance logging required.
{
"published_contact_channel": true,
"privacy_officer_designated": true
}