Privacy Policy
Policy number: 2026-06
Effective date: August 31, 2026
Last revision date: August 31, 2026
On this page
1. Definitions
2. Purpose
3. Scope
4. Principles
4.1 Privacy Protection
4.2 Privacy Breaches
4.3 Privacy Breach Protocol
5. Roles and Responsibilities
5.1 Employees, Council, and Volunteers
5.2 Managers and Supervisors
5.3 The Clerk and Clerks division
5.4 Breach Response Team
Appendix I – Privacy Breach Protocol
1. Definitions
“Collect” means to gather, acquire, receive or obtain the information by any means from any source, and “collection” has a corresponding meaning.
“Consent” means a voluntary and willful agreement in response to a defined proposition. The individual who consents must possess sufficient mental capacity and authority to do so. Consent also requires the absence of coercion, fraud or error.
“Disclose” means to make the information available or to release it to another individual, but does not include to use the information, and “disclosure” has a corresponding meaning.
“Information and Privacy Commissioner of Ontario (IPC)” the Commissioner is an officer of the Legislature who is appointed by, and reports to the Legislative Assembly of Ontario, and is independent of the government of the day. The Commissioner provides oversight of Ontario’s access and privacy laws.
“Personal Information (PI)” as defined by section 2 of MFIPPA.
“Personal Health Information (PHI)” as defined by section 4 of PHIPA.
“Privacy Breach” occurs when personal information and/or personal health information is stolen, lost, collected, retained, used or disclosed in a way that is not in accordance with provincial legislation.
“Real Risk of Significant Harm (RROSH)” means the likelihood that a privacy breach could reasonably result in serious harm to an affected individual, considering the sensitivity of the information involved and the probability of misuse.
“The County” means the Corporation of Haldimand County.
“Use” means to view, handle or otherwise deal with the information, but does not include to disclose the information, and “use”, as a noun, has a corresponding meaning.
2. Purpose
Haldimand County is committed to protecting the privacy, confidentiality, and security of personal information in accordance with the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), the Personal Health Information Protection Act (PHIPA), and recognized privacy principles. This policy reinforces the County’s commitment to accountability and the responsible management of personal information and personal health information across all programs, services, and operations.
MFIPPA establishes rules governing the collection, use, disclosure, retention, security, and disposal of personal information by the County, and sets out requirements for public access to information, subject to limited exemptions. It also provides individuals with the right to request access to their personal information and outlines the process for doing so.
PHIPA governs the confidentiality of personal health information held by the County, requiring that it be protected from unauthorized disclosure. It also provides individuals with the right to access, review, and request corrections to their personal health information.
4. Principles
4.1 Privacy Protection
The County is committed to protecting the privacy, confidentiality, and security of personal information and personal health information in accordance with all applicable privacy legislation.
All personal information (PI) and personal health information (PHI) held by the County shall be treated as confidential and accessed only by authorized staff for legitimate purposes related to their duties. Staff are required to protect this information from unauthorized access, use, or disclosure at all times. Handling of PI and PHI must comply with applicable legislation, County policies, and established privacy and security safeguards.
4.2 Privacy Breaches
A privacy breach occurs when personal information is collected, used, retained, disclosed and/or destroyed in ways that are not in accordance with the privacy provisions of MFIPPA or PHIPA. This would include personal information being shared with, lost, stolen, or accessed by unauthorized persons.
All privacy breaches shall be handled in accordance with the protocol outlined in Appendix I.>
4.3 Privacy Breach Protocol
All known or suspected privacy breaches must be immediately reported to your Manager or Supervisor and the Clerks division. Additional protocol steps will be guided by the Clerks division and/or the Breach Response Team, as required.
5. Roles and Responsibilities
5.1 Employees, Council, and Volunteers
- Maintain records and information in compliance with the County’s Record Retention Schedule, MFIPPA, and PHIPA
- Attend and follow training, as required;
- Immediately report any and all known or suspected privacy breaches, potential or realized, to their respective supervisor and the Clerks division; and
- Cooperate fully with any investigation and/or procedures in relation to the breach.
5.2 Managers and Supervisors
- Ensure employees adhere to the Privacy Policy;
- Ensure the Clerks division is immediately notified of any privacy breach;
- Be accountable for following procedures to address a breach;
- Cooperate with the Clerks division and/or the Breach Response Team to contain, notify, identify and implement measures to prevent future breaches as required; and
- Ensure training is received and followed if recommended.
5.3 The Clerk and Clerks division
Ensure any privacy breach is addressed immediately;
- Effect the Privacy Breach Protocol (Appendix I) with affected division staff and the Breach Response Team if required;
- Provide guidance and direction, as required;
- Inform the IPC and provide necessary reports, as required; and
- Implement and/or update measures to prevent future privacy breaches, as required.
5.4 Breach Response Team
When indicated, the Clerks division and/or the Chief Information Officer will involve a larger Breach Response Team at the Response stage of the protocol. The Team will together be responsible for completing the steps of the Protocol. Members of the team will vary depending on the scope and nature of the breach, but may include the following, as required by the circumstances:
- Clerks
- Insurance / Risk Management
- Innovation and Technology Services
- Customer Experience and Communications
- The CAO and/or Senior Management Team members
- External legal counsel
- The appropriate law enforcement agency
Appendix 1 - Privacy Breach Protocol
Upon learning of any potential privacy breach, the following action(s) must be taken:
Step 1: Response
- When an employee or volunteer learns of a possible privacy breach, the employee must immediately contact their Manager/Supervisor and the Clerks division.
- Depending on the nature of the privacy breach, the Clerks division and/or the Chief Information Officer may involve the following internal divisions, individuals or external organizations:
Clerks- Risk Management
- Innovation and Technology Services
- Customer Experience and Communications
- The CAO and/or Senior Management Team members
- External legal counsel
- The appropriate law enforcement agency
- The IPC
- The Clerks division and/or the Breach Response Team will manage and direct affected staff through the priorities of containment, notification, investigation, remediation and reporting in steps two (2) through five (5) below.
Step 2: Containment
- The following steps should be taken by affected division staff and/or members of the Breach Response Team to contain the breach, as indicated for the specific situation:
- Misdirected Email or Communication
- Attempt to recall the message
- Contact the unintended recipient and request deletion
- Confirm deletion where possible
- Lost or Stolen Device
- Report the incident immediately
- Initiate remote lock or wipe of device, if possible
- Disable access and change passwords as required.
- Unauthorized Access to Records
- Restrict access, where appropriate
- Preserve audit logs and evidence
- Secure any affected information
- Misdirected Paper Records
- Recover the records as soon as possible
- Secure or appropriately dispose of recovered documents
- Confirm no further disclosure occurred
- Cybersecurity Incident
- Notify Innovation and Technology Services immediately
- Isolate affected systems
- Preserve evidence for investigation
- Verbal Disclosure
- Stop the disclosure immediately
- Request confidentiality from unauthorized recipients
- Report the incident for assessment
- Any other containment steps as required
- Misdirected Email or Communication
Objective: Stop the breach, secure the information, and prevent further unauthorized access, use, or disclosure.
2. All actions, dates and times must be documented during containment.
Step 3: Notification
- The information involved in the breach will be reviewed to identify individuals whose personal information was breached.
- Individuals will be notified at the first reasonable opportunity that a privacy breach occurred.
- The method of notification will comply with the IPC’s notification requirements.
Step 4: Investigation and remediation
- The Clerks division and/or the Breach Response Team will work with the affected Manager/Supervisor and employees to conduct an internal investigation into the privacy breach incident and will:
- ensure that the immediate requirements of containment and notification were addressed;
- review the circumstances related to the breach;
- review and determine whether existing policies and procedures related to protecting personal information are adequate;
- review systematic processes to implement changes to reduce the risk of future breaches;
- develop new or updated policies, procedures and/or processes, as required;
- determine if additional or refresher training is required for employees; and
- implement such training, as required.
- Managers, supervisors, and employees must:
- work to implement the recommendations of the Clerks division and the IPC
- ensure privacy related policies are reviewed and followed by employees; and
- ensure training is attended and followed by employees if required.
Step 5: Reporting
- An internal privacy breach report will be completed by the Clerks division and/or by the collective effort of the Breach Response Team to record all of the actions taken in response to the breach.
- The Clerks division will determine whether a situation will be reported to the IPC based on the following criteria:
- Scale – Whether the breach of personal information is limited or significant in scale and/or scope.
- RROSH – Harm may include financial loss, identity theft, reputational damage, loss of employment or business opportunities, physical harm, humiliation, or other adverse effects. In assessing RROSH, consideration should be given to the sensitivity of the information involved and the likelihood that it has been, or will be, misused.
- Assistance – Whether the IPC may be able to provide direction which will assist the County in handling the situation or whether the County has already identified and taken all possible and reasonable steps to handle the situation adequately.
NOTE: The legislation requires that the County notify the IPC if there is a real risk of significant harm to affected individuals.
3. If the IPC has been notified, the Clerks division (in conjunction with the Breach Response Team as required) will provide privacy breach report(s) including the actions taken to contain, notify, and investigate, as well as any changes to be implemented as a result of the. The IPC may conduct an additional investigation and may issue a report with recommendations to minimize future privacy risks.