Put Privacy First – Privacy Commissioner of Canada speaks about privacy risk mitigation.

Learn more about The Power of PETs: Privacy Enhancing Technologies during a panel discussion hosted by The Information and Privacy Commissioner of Ontario.

BC Commissioner issues report on how municipalities make records available. For more information check out the full news release, fact sheet, guidance document and video.

Thank you to our 800 registrants who registered for the Top of Mind webinar hosted on Jan 31. For those of you who missed the session, you can access both an English and French version of the recording here under “Top of Mind” Data Privacy Webinar 2025. Enjoy!

Blog

Risk Management and Privacy Protection

May 12, 2016 - Ron Kruzeniski, Information and Privacy Commissioner

Most organizations today have addressed the issue of risk management. Many have gone through a process of identifying the risks and the ways of mitigating those risks. They will have a document with the risks and the mitigating factors. Some will report to the CEO, a board council or minister on a regular basis.

When you hear the reports from around the world of hacking into systems and data being copied and or released on the web, when you hear of the costs to prevent future breaches, when you hear of the damage to reputation and brand, or security of data (personal information and or personal health information) these are undoubtedly risks that an organization faces. It is a significant risk and managers need to find ways of lessening that risk. Can you eliminate the risk? Probably not, but you can lessen the risk in the future.

This blog is to encourage all organizations to identify as a high risk the security of their data and to regularly discuss and report the level of risk and the steps they are taking to mitigate that risk. As to how to lessen that risk, there are many resources out there on best practices to protect your data including The Personal Information Protection Act, PIPA Advisory #8, Implementing Reasonable Safeguards from the Alberta IPC or Securing Personal Information: A Self-Assessment Tool for Organizations available on the Privacy Commissioner of Canada’s website.

Another way to identify and mitigate risk is by conducting a privacy impact assessment. More is available on my office’s website our publication Privacy Impact Assessment Guidance Document.

I encourage all organizations to put into practice ways of reducing the risks.

Categories: BlogTags:

Back to Blog