Alberta Civil Liberties Research Centre
Privacy Handbook Update Centre

| What's New | Publications | Human Rights Ed Program | How Can You Help | Newsletter | Programs | Forum | Other Links | Contact Us | ACLRC Home | 

 


Separator line

Questions A Small Business Should Ask About Privacy

Source: Canadian Institute of Chartered Accountants. For a more comprehensive list of possible questions, please follow the link to the site for the Canadian Institute of Chartered Accountants:

http://www.cica.ca/index.cfm/ci_id/10581/la_id/1.htm

  1. What personal information about customers and employees does your business collect and retain?

  2. What personal information is used in carrying out business transactions (for example, sales, marketing, fundraising)?

  3. What privacy policies has your business established with respect to the collection, use, disclosure and retention of personal information?

  4. What personal information does your business obtain from, or disclose to, affiliates or third parties, for example, in payroll outsourcing?

  5. How does your business plan address the privacy of personal information?

  6. Is the owner/manager able to assign someone the responsibility for compliance with privacy legislation?

  7. If so, has the individual responsible for privacy compliance been given clear authority to oversee the information handling practices of the business; and are adequate resources allocated to facilitating and maintaining such a program?

  8. How are the owner/manager and any employees with access to personal information trained in privacy protection?

  9. To comply with established privacy policies, what objectives are set for the business?

  10. To what extent have appropriate privacy control measures been identified and implemented?

  11. What are the consequences of not meeting the specific privacy objectives?

  12. How is the effectiveness of the privacy control measures monitored and reported?

  13. What mechanisms are in place to deal with contraventions of the privacy policies and procedures?

  14. Has the owner/manager considered the services available from an independent assurance practitioner with respect to online privacy?

For more a more comprehensive list of possible questions, please follow the link to the site for the Canadian Institute of Chartered Accountants:

http://www.cica.ca/index.cfm/ci_id/10581/la_id/1.htm

Alberta Civil Liberties Research Centre

 
 
This web site © 1999-2004 Alberta Civil Liberties Research Centre, Calgary, Alberta, Canada. This page last updated on December 17, 2003 .