<?xml version="1.0"?>
<Bill RHead_reign="62-63 Eliz. II" RHead_ParlYear="2013-2014" DocumentTitle="BILL S-4" Bill_No="S-4" Document_No="90730" xml:lang="EN" Bill_Type="Amending" Stage_Name="First-Reading-Senate" Reprint="No" xml:space="preserve" ChapterNo_E="C. " ChapterNo_F="ch. " Bill-Origin="senate"><Bill_Part Part_Type="Cover" CountLines="No"><Block Align="Yes"><Para Style="CovBillNo">S-4</Para></Block><Block><Para TopMargin="24" Size="9" Leading="10" LeftMargin="0" FirstLineIndent="0" TextAlign="Center">Second Session, Forty-first Parliament,</Para></Block><Block><Para Size="9" Leading="10" LeftMargin="0" FirstLineIndent="0" TextAlign="Center"> 62-63 Elizabeth II,  2013-2014</Para></Block><Block><Para TopMargin="48" LeftMargin="0" FirstLineIndent="0" Bold="Yes" TextAlign="Center">SENATE OF CANADA</Para></Block><Block><Para TopMargin="42" Size="18" Leading="20" LeftMargin="0" FirstLineIndent="0" Bold="Yes" TextAlign="Center">BILL S-4</Para></Block><Block Align="Yes"><Para Style="CovLongTitle">An Act to amend the Personal Information Protection and Electronic Documents Act and to make a consequential amendment to another Act</Para></Block><Block Align="Yes"><Para Style="COV_StageLine"></Para></Block><Block><Para Size="9" AllCaps="Yes" Hyphenate="OFF">first reading, April 8, 2014</Para></Block><Block Align="Yes"><Para Style="COV_StageLine"></Para></Block><Block Align="Yes"><Para Style="Cover_Sponsors">LEADER OF THE GOVERNMENT IN THE SENATE </Para></Block><Block Align="Yes"><Para Style="Cover_DocNo">90730</Para></Block></Bill_Part><Bill_Part CountLines="No" Part_Type="InsideCover"><Block Align="Yes"><Para Style="BPT_InsideCoverE">Available on the Parliament of Canada Web Site at the following address:<br/><B>http://www.parl.gc.ca</B></Para></Block><Block LineCnt="N" Align="Yes" KeepWith="Next"><Para TopMargin="108" BottomMargin="4" Size="10" LeftMargin="0" FirstLineIndent="0" Hyphenate="OFF" TextAlign="Center">SUMMARY</Para></Block><Block LineCnt="N" Align="Yes"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2" Hyphenate="ON" TextAlign="Justify">This enactment amends the <I>Personal Information Protection and Electronic Documents Act</I> to, among other things,</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(<I>a</I>) specify the elements of valid consent for the collection, use or disclosure of personal information;</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(<I>b</I>) permit the disclosure of personal information without the knowledge or consent of an individual for the purposes of</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="4" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(i) identifying an injured, ill or deceased individual and communicating with their next of kin,</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="4" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(ii) preventing, detecting or suppressing fraud, or</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="4" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(iii) protecting victims of financial abuse;</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(<I>c</I>) permit organizations, for certain purposes, to collect, use and disclose, without the knowledge or consent of an individual, personal information</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="4" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(i) contained in witness statements related to insurance claims, or</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="4" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(ii) produced by the individual in the course of their employment, business or profession;</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(<I>d</I>) permit organizations, for certain purposes, to use and disclose, without the knowledge or consent of an individual, personal information related to prospective or completed business transactions;</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(<I>e</I>) permit federal works, undertakings and businesses to collect, use and disclose personal information, without the knowledge or consent of an individual, to establish, manage or terminate their employment relationships with the individual;</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(<I>f</I>) require organizations to notify certain individuals and organizations of certain breaches of security safeguards that create a real risk of significant harm and to report them to the Privacy Commissioner;</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(<I>g</I>) require organizations to keep and maintain a record of every breach of security safeguards involving personal information under their control;</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(<I>h</I>) create offences in relation to the contravention of certain obligations respecting breaches of security safeguards;</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(<I>i</I>) extend the period within which a complainant may apply to the Federal Court for a hearing on matters related to their complaint;</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(<I>j</I>) provide that the Privacy Commissioner may, in certain circumstances, enter into a compliance agreement with an organization to ensure compliance with Part 1 of the Act; and</Para></Block><Block LineCnt="N" Align="No"><Para TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0" Hyphenate="ON" TextAlign="Justify">(<I>k</I>) modify the information that the Privacy Commissioner may make public if he or she considers that it is in the public interest to do so.</Para></Block></Bill_Part><Bill_Part Part_Type="MainText" CountLines="Yes" RunningHead_E="Personal Information Protection and Electronic Documents"><Block Align="Yes"><Para Style="MainText_DocNo">90730</Para></Block><Block LineCnt="N" Align="Yes"><Para Style="Session_Reign">2nd Session, 41st Parliament,</Para></Block><Block LineCnt="N" Align="Yes"><Para Style="Session_Reign"> 62-63 Elizabeth II,  2013-2014</Para></Block><Block LineCnt="N" Align="Yes"><Para Style="MainBillOrigin">senate of canada</Para></Block><Block LineCnt="N" Align="Yes"><Para Bold="Yes" Style="MAIN@BillNo_Title">BILL S-4</Para></Block><Block LineCnt="N" Align="Yes"><Para Style="MAIN@ti;04">An Act to amend the Personal Information Protection and Electronic Documents Act and to make a consequential amendment to another Act</Para></Block><Block LineCnt="Y" Align="Yes"><Para LeftMargin="0" FirstLineIndent="2" Hyphenate="ON" TextAlign="Justify">Her Majesty, by and with the advice and consent of the Senate and House of Commons of Canada, enacts as follows:</Para></Block><Block LineCnt="N" Align="Yes" KeepWith="Next"><!--Heading:SHORT TITLE--><Para TopMargin="10" Hyphenate="OFF" TextAlign="Center">SHORT TITLE</Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Short title<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><B>1.</B> This Act may be cited as the <I>Digital Privacy Act</I>.</Para></Block><Block LineCnt="N" Align="Yes" KeepWith="Next"><!--Heading:PERSONAL INFORMATION PROTECTION AND ELECTRONIC DOCUMENTS ACT--><MarginalNote>2000, c. 5<br/></MarginalNote><Para TopMargin="10" Bold="Yes" Hyphenate="OFF" TextAlign="Center">PERSONAL INFORMATION PROTECTION AND ELECTRONIC DOCUMENTS ACT</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>2.</B> (1) The definition “personal information” in subsection 2(1) of the <I>Personal Information Protection and Electronic Documents Act</I> is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="0" Italic="Yes" Hyphenate="OFF" TextAlign="Center">Personal Information Protection and Electronic Documents Act</Para><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 2</I>: (1) Existing text of the definition:</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0">“personal information” means information about an identifiable individual, but does not include the name, title or business address or telephone number of an employee of an organization.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>“personal information”<br/>« <I>renseignement personnel</I> »<br/></MarginalNote><Para TopMargin="5" LeftMargin="0">“personal information” means information about an identifiable individual.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(2) Paragraph (<I>g</I>) of the definition “federal work, undertaking or business” in subsection 2(1) of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2">(2) Relevant portion of the definition:</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0">“federal work, undertaking or business” means any work, undertaking or business that is within the legislative authority of Parliament. It includes</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>g</I>) a bank;</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0">(<I>g</I>) a bank <change>or an authorized foreign bank as defined in section 2 of the <I>Bank Act</I></change>;</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(3) Subsection 2(1) of the Act is amended by adding the following in alphabetical order:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2">(3) New.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>“breach of security safeguards”<br/>« <I>atteinte aux mesures de sécurité</I> »<br/></MarginalNote><Para TopMargin="5" LeftMargin="0"><change>“breach of security safeguards” means the loss of, unauthorized access to or unauthorized disclosure of personal information resulting from a breach of an organization’s security safeguards that are referred to in clause 4.7 of Schedule 1 or from a failure to establish those safeguards.</change></Para></Block><Block LineCnt="Y" Align="No"><MarginalNote>“business contact information”<br/>« <I>coordonnées d’affaires</I> »<br/></MarginalNote><Para TopMargin="5" LeftMargin="0"><change>“business contact information” means any information that is used for the purpose of communicating or facilitating communication with an individual in relation to their employment, business or profession such as the individual’s name, position name or title, work address, work telephone number, work fax number or work electronic address.</change></Para></Block><Block LineCnt="Y" Align="No"><MarginalNote>“business transaction”<br/>« <I>transaction commerciale</I> »<br/></MarginalNote><Para TopMargin="5" LeftMargin="0"><change>“business transaction” includes</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>a</I>) the purchase, sale or other acquisition or disposition of an organization or a part of an organization, or any of its assets;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b</I>) the merger or amalgamation of two or more organizations;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>c</I>) the making of a loan or provision of other financing to an organization or a part of an organization;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>d</I>) the creating of a charge on, or the taking of a security interest in or a security on, any assets or securities of an organization;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>e</I>) the lease or licensing of any of an organization’s assets; and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>f</I>) any other prescribed arrangement between two or more organizations to conduct a business activity.</change></Para></Block><Block LineCnt="Y" Align="No"><MarginalNote>“prescribed”<br/><I>Version anglaise seulement</I><br/></MarginalNote><Para TopMargin="5" LeftMargin="0"><change>“prescribed” means prescribed by regulation.</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>3.</B> Paragraph 4(1)(<I>b</I>) of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 3</I>: Relevant portion of subsection 4(1):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>4.</B> (1) This Part applies to every organization in respect of personal information that</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>b</I>) is about an employee of the organization and that the organization collects, uses or discloses in connection with the operation of a federal work, undertaking or business.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0">(<I>b</I>) is about an employee of, <change>or an applicant for employment with</change>, the organization and that the organization collects, uses or discloses in connection with the operation of a federal work, undertaking or business.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>4.</B> The Act is amended by adding the following after section 4:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 4</I>: New.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Business contact information<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change><B>4.01</B> This Part does not apply to an organization in respect of the business contact information of an individual that the organization collects, uses or discloses solely for the purpose of communicating or facilitating communication with the individual in relation to their employment, business or profession.</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>5.</B> The Act is amended by adding the following after section 6:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 5</I>: New.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Valid consent<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change><B>6.1</B> For the purposes of clause 4.3 of Schedule 1, the consent of an individual is only valid if it is reasonable to expect that an individual to whom the organization’s activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting.</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>6.</B> (1) The portion of subsection 7(1) of the French version of the Act before paragraph (<I>a</I>) is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 6</I>: (1) to (3) Relevant portion of subsection 7(1):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>7.</B> (1) For the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may collect personal information without the knowledge or consent of the individual only if</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>b</I>) it is reasonable to expect that the collection with the knowledge or consent of the individual would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province;</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Collecte à l’insu de l’intéressé ou sans son consentement<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><AltLang xml:lang="fr"><B>7.</B> (1) Pour l’application de l’article 4.3 de l’annexe 1 et malgré la note afférente, l’organisation ne peut recueillir de renseignement personnel à l’insu de l’intéressé <change>ou</change> sans son consentement que dans les cas suivants :</AltLang></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(2) Paragraph 7(1)(<I>b</I>) of the French version of the Act is replaced by the following:</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><AltLang xml:lang="fr"><I>b</I>) il est raisonnable de s’attendre à ce que la collecte effectuée au su ou avec le consentement de l’intéressé <change>compromette</change> l’exactitude du renseignement ou l’accès à celui-ci, et la collecte est raisonnable à des fins liées à une enquête sur la violation d’un accord ou la contravention <change>au</change> droit fédéral ou provincial;</AltLang></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(3) Subsection 7(1) of the Act is amended by adding the following after paragraph (<I>b</I>):</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b.1</I>) it is contained in a witness statement and the collection is necessary to assess, process or settle an insurance claim;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b.2</I>) it was produced by the individual in the course of their employment, business or profession and the collection is consistent with the purposes for which the information was produced;</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(4) The portion of subsection 7(2) of the French version of the Act before paragraph (<I>a</I>) is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2">(4) and (5) Relevant portion of subsection 7(2):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(2) For the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may, without the knowledge or consent of the individual, use personal information only if</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Utilisation à l’insu de l’intéressé ou sans son consentement<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><AltLang xml:lang="fr">(2) Pour l’application de l’article 4.3 de l’annexe 1 et malgré la note afférente, l’organisation ne peut utiliser de renseignement personnel à l’insu de l’intéressé <change>ou</change> sans son consentement que dans les cas suivants :</AltLang></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(5) Subsection 7(2) of the Act is amended by adding the following after paragraph (<I>b</I>):</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b.1</I>) the information is contained in a witness statement and the use is necessary to assess, process or settle an insurance claim;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b.2</I>) the information was produced by the individual in the course of their employment, business or profession and the use is consistent with the purposes for which the information was produced;</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(6) The portion of subsection 7(3) of the French version of the Act before paragraph (<I>a</I>) is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2">(6) to (12) Relevant portion of subsection 7(3):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(3) For the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may disclose personal information without the knowledge or consent of the individual only if the disclosure is</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>c.1</I>) made to a government institution or part of a government institution that has made a request for the information, identified its lawful authority to obtain the information and indicated that</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>c.2</I>) made to the government institution mentioned in section 7 of the <I>Proceeds of Crime (Money Laundering) Act</I> as required by that section;</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>d</I>) made on the initiative of the organization to an investigative body, a government institution or a part of a government institution and the organization</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="4" FirstLineIndent="0">(i) has reasonable grounds to believe that the information relates to a breach of an agreement or a contravention of the laws of Canada, a province or a foreign jurisdiction that has been, is being or is about to be committed, or</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>h.2</I>) made by an investigative body and the disclosure is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province; or</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Communication à l’insu de l’intéressé ou sans son consentement<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><AltLang xml:lang="fr">(3) Pour l’application de l’article 4.3 de l’annexe 1 et malgré la note afférente, l’organisation ne peut communiquer de renseignement personnel à l’insu de l’intéressé <change>ou</change> sans son consentement que dans les cas suivants :</AltLang></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(7) Paragraph 7(3)(<I>c.1</I>) of the Act is amended by striking out “or” at the end of subparagraph (ii), by adding “or” at the end of subparagraph (iii) and by adding the following after subparagraph (iii):</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(iv) the disclosure is requested for the purpose of communicating with the next of kin or authorized representative of an injured, ill or deceased individual;</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>2000, c. 17, par. 97(1)(<I>a</I>)<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(8) Paragraph 7(3)(<I>c.2</I>) of the Act, as enacted by paragraph 97(1)(<I>a</I>) of chapter 17 of the Statutes of Canada, 2000, is repealed.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(9) The portion of paragraph 7(3)(<I>d</I>) of the Act before subparagraph (ii) is replaced by the following:</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0">(<I>d</I>) made on the initiative of the organization to a government institution or a part of a government institution and the organization</Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0">(i) has reasonable grounds to believe that the information relates to a contravention of the laws of Canada, a province or a foreign jurisdiction that has been, is being or is about to be committed, or</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(10) Subsection 7(3) of the Act is amended by adding the following after paragraph (<I>d</I>):</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>d.1</I>) made to another organization and is reasonable for the purposes of investigating a breach of an agreement or a contravention of the laws of Canada or a province that has been, is being or is about to be committed and it is reasonable to expect that disclosure with the knowledge or consent of the individual would compromise the investigation;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>d.2</I>) made to another organization and is reasonable for the purposes of detecting or suppressing fraud or of preventing fraud that is likely to be committed and it is reasonable to expect that the disclosure with the knowledge or consent of the individual would compromise the ability to prevent, detect or suppress the fraud;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>d.3</I>) made on the initiative of the organization to a government institution, a part of a government institution or the individual’s next of kin or authorized representative and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(i) the organization has reasonable grounds to believe that the individual has been, is or may be the victim of financial abuse,</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(ii) the disclosure is made solely for purposes related to preventing or investigating the abuse, and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(iii) it is reasonable to expect that disclosure with the knowledge or consent of the individual would compromise the ability to prevent or investigate the abuse;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>d.4</I>) necessary to identify the individual who is injured, ill or deceased, made to a government institution, a part of a government institution or the individual’s next of kin or authorized representative and, if the individual is alive, the organization informs that individual in writing without delay of the disclosure;</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(11) Subsection 7(3) of the Act is amended by adding the following after paragraph (<I>e</I>):</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>e.1</I>) of information that is contained in a witness statement and the disclosure is necessary to assess, process or settle an insurance claim;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>e.2</I>) of information that was produced by the individual in the course of their employment, business or profession and the disclosure is consistent with the purposes for which the information was produced;</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(12) Paragraph 7(3)(<I>f</I>) of the French version of the Act is replaced by the following:</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><AltLang xml:lang="fr"><I>f</I>) <change>la communication</change> est faite à des fins statistiques ou à des fins d’étude ou de recherche érudites, ces fins ne peuvent être réalisées sans que le renseignement soit communiqué, le consentement est pratiquement impossible à obtenir et l’organisation informe le commissaire de la communication avant de la faire;</AltLang></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(13) Subsection 7(3) of the Act is amended by adding “or” at the end of paragraph (<I>h.1</I>) and by repealing paragraph (<I>h.2</I>).</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(14) Paragraph 7(3)(<I>i</I>) of the French version of the Act is replaced by the following:</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><AltLang xml:lang="fr"><I>i</I>) <change>la communication</change> est exigée par la loi.</AltLang></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(15) Subsection 7(5) of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2">(13) Existing text of subsection 7(5):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(5) Despite clause 4.5 of Schedule 1, an organization may disclose personal information for purposes other than those for which it was collected in any of the circumstances set out in paragraphs (3)(<I>a</I>) to (<I>h.2</I>).</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Disclosure without consent<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2">(5) Despite clause 4.5 of Schedule 1, an organization may disclose personal information for purposes other than those for which it was collected in any of the circumstances set out in paragraphs (3)(<I>a</I>) to <change>(<I>h.1</I>)</change>.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>7.</B> The Act is amended by adding the following before section 8:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 7</I>: New.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Prospective business transaction<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change><B>7.2</B> (1) In addition to the circumstances set out in subsections 7(2) and (3), for the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, organizations that are parties to a prospective business transaction may use and disclose personal information without the knowledge or consent of the individual if</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>a</I>) the organizations have entered into an agreement that requires the organization that receives the personal information</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(i) to use and disclose that information solely for purposes related to the transaction,</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(ii) to protect that information by security safeguards appropriate to the sensitivity of the information, and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(iii) if the transaction does not proceed, to return that information to the organization that disclosed it, or destroy it, within a reasonable time; and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b</I>) the personal information is necessary</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(i) to determine whether to proceed with the transaction, and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(ii) if the determination is made to proceed with the transaction, to complete it.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Completed business transaction<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(2) In addition to the circumstances set out in subsections 7(2) and (3), for the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, if the business transaction is completed, organizations that are parties to the transaction may use and disclose personal information, which was disclosed under subsection (1), without the knowledge or consent of the individual if</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>a</I>) the organizations have entered into an agreement that requires each of them</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(i) to use and disclose the personal information under its control solely for the purposes for which the personal information was collected, permitted to be used or disclosed before the transaction was completed,</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(ii) to protect that information by security safeguards appropriate to the sensitivity of the information, and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><change>(iii) to give effect to any withdrawal of consent made under clause 4.3.8 of Schedule 1;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b</I>) the personal information is necessary for carrying on the business or activity that was the object of the transaction; and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>c</I>) one of the parties notifies the individual, within a reasonable time after the transaction is completed, that the transaction has been completed and that their personal information has been disclosed under subsection (1).</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Agreements binding<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(3) An organization shall comply with the terms of any agreement into which it enters under paragraph (1)(<I>a</I>) or (2)(<I>a</I>).</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Exception<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(4) Subsections (1) and (2) do not apply to a business transaction of which the primary purpose or result is the purchase, sale or other acquisition or disposition, or lease, of personal information.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Employment relationship<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change><B>7.3</B> In addition to the circumstances set out in section 7, for the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, a federal work, undertaking or business may collect, use and disclose personal information without the consent of the individual if</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>a</I>) the collection, use or disclosure is necessary to establish, manage or terminate an employment relationship between the federal work, undertaking or business and the individual; and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b</I>) the federal work, undertaking or business has informed the individual that the personal information will be or may be collected, used or disclosed for those purposes.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Use without consent<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change><B>7.4</B> (1) Despite clause 4.5 of Schedule 1, an organization may use personal information for purposes other than those for which it was collected in any of the circumstances set out in subsection 7.2(1) or (2) or section 7.3.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Disclosure without consent<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(2) Despite clause 4.5 of Schedule 1, an organization may disclose personal information for purposes other than those for which it was collected in any of the circumstances set out in subsection 7.2(1) or (2) or section 7.3.</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>8.</B> Subsection 8(8) of the French version of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 8</I>: Existing text of subsection 8(8):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(8) Despite clause 4.5 of Schedule 1, an organization that has personal information that is the subject of a request shall retain the information for as long as is necessary to allow the individual to exhaust any recourse under this Part that they may have.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Conservation des renseignements<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><AltLang xml:lang="fr">(8) Malgré l’article 4.5 de l’annexe 1, l’organisation qui détient un renseignement faisant l’objet d’une demande doit le conserver le temps nécessaire pour permettre au demandeur d’épuiser <change>tous les</change> recours <change>qu’il a en vertu de la présente partie</change>.</AltLang></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>2000, c. 17, par. 97(1)(<I>c</I>)<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>9.</B> (1) Paragraph 9(2.3)(<I>a.1</I>) of the Act, as enacted by paragraph 97(1)(<I>c</I>) of chapter 17 of the Statutes of Canada, 2000, is repealed.</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 9</I>: (1) Relevant portion of subsection 9(2.3):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(2.3) Within thirty days after the day on which it is notified under subsection (2.2), the institution or part shall notify the organization whether or not the institution or part objects to the organization complying with the request. The institution or part may object only if the institution or part is of the opinion that compliance with the request could reasonably be expected to be injurious to</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>a.1</I>) the detection, prevention or deterrence of money laundering; or</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(2) Subparagraph 9(2.4)(<I>c</I>)(iii) of the French version of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2">(2) Relevant portion of subsection 9(2.4):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(2.4) Despite clause 4.9 of Schedule 1, if an organization is notified under subsection (2.3) that the institution or part objects to the organization complying with the request, the organization</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>c</I>) shall not disclose to the individual</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="4" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="4" FirstLineIndent="0">(iii) that the institution or part objects.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="4" FirstLineIndent="0"><AltLang xml:lang="fr">(iii) ni le fait que l’institution ou la subdivision s’oppose à ce que l’<change>organisation</change> acquiesce à la demande.</AltLang></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(3) Paragraph 9(3)(<I>a</I>) of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2">(3) Relevant portion of subsection 9(3):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(3) Despite the note that accompanies clause 4.9 of Schedule 1, an organization is not required to give access to personal information only if</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>a</I>) the information is protected by solicitor-client privilege;</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0">(<I>a</I>) the information is protected by solicitor-client privilege <change>or, in civil law, by the professional secrecy of lawyers and notaries</change>;</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>10.</B> The Act is amended by adding the following after section 10:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 10</I>: New.</Para></ExplNote></Block><Block LineCnt="N" Align="Yes" KeepWith="Next"><Para TopMargin="10" SmallCaps="Yes" Hyphenate="OFF" TextAlign="Center"><change>Division 1.1</change></Para></Block><Block LineCnt="N" Align="Yes" KeepWith="Next"><!--Heading:Breaches of Security Safeguards--><Para TopMargin="5" SmallCaps="Yes" Hyphenate="OFF" TextAlign="Center"><change>Breaches of Security Safeguards</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Report to Commissioner<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change><B>10.1</B> (1) An organization shall report to the Commissioner any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Report requirements<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(2) The report shall contain the prescribed information and shall be made in the prescribed form and manner as soon as feasible after the organization determines that the breach has occurred.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Notification to individual<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(3) Unless otherwise prohibited by law, an organization shall notify an individual of any breach of security safeguards involving the individual’s personal information under the organization’s control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to the individual.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Contents of notification<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(4) The notification shall contain sufficient information to allow the individual to understand the significance to them of the breach and to take steps, if any are possible, to reduce the risk of harm that could result from it or to mitigate that harm. It shall also contain any other prescribed information.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Form and manner<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(5) The notification shall be conspicuous and shall be given directly to the individual in the prescribed form and manner, except in prescribed circumstances, in which case it shall be given indirectly in the prescribed form and manner.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Time to give notification<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(6) The notification shall be given as soon as feasible after the organization determines that the breach has occurred. However, if a government institution or part of a government institution requests that the organization delay notification for a criminal investigation relating to the breach, notification shall not be given until the institution or part concerned authorizes the organization to do so.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Definition of “significant harm”<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(7) For the purpose of this section, “significant harm” includes bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record and damage to or loss of property.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Real risk of significant harm — factors<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(8) The factors that are relevant to determining whether a breach of security safeguards creates a real risk of significant harm to the individual include</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>a</I>) the sensitivity of the personal information involved in the breach;</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b</I>) the probability that the personal information has been, is being or will be misused; and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>c</I>) any other prescribed factor.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Notification to organizations<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change><B>10.2</B> (1) An organization that notifies an individual of a breach of security safeguards under subsection 10.1(3) shall notify any other organization, a government institution or a part of a government institution of the breach if the notifying organization believes that the other organization or the government institution or part concerned may be able to reduce the risk of harm that could result from it or mitigate that harm, or if any of the prescribed conditions are satisfied.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Time to give notification<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(2) The notification shall be given as soon as feasible after the organization determines that the breach has occurred.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Disclosure of personal information<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(3) In addition to the circumstances set out in subsection 7(3), for the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may disclose personal information without the knowledge or consent of the individual if</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>a</I>) the disclosure is made to the other organization, the government institution or the part of a government institution that was notified of the breach under subsection (1); and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b</I>) the disclosure is made solely for the purposes of reducing the risk of harm to the individual that could result from the breach or mitigating that harm.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Disclosure without consent<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(4) Despite clause 4.5 of Schedule 1, an organization may disclose personal information for purposes other than those for which it was collected in the circumstance set out in subsection (3).</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Records<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change><B>10.3</B> (1) An organization shall, in accordance with any prescribed requirements, keep and maintain a record of every breach of security safeguards involving personal information under its control.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Provision to Commissioner<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(2) An organization shall, on request, provide the Commissioner with access to, or a copy of, a record.</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>11.</B> Subsection 11(1) of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 11</I>: Existing text of subsection 11(1):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>11.</B> (1) An individual may file with the Commissioner a written complaint against an organization for contravening a provision of Division 1 or for not following a recommendation set out in Schedule 1.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Contravention<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><B>11.</B> (1) An individual may file with the Commissioner a written complaint against an organization for contravening a provision of Division 1 <change>or 1.1</change> or for not following a recommendation set out in Schedule 1.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>12.</B> Subsection 12.2(1) of the Act is amended by adding the following after paragraph (<I>c</I>):</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 12</I>: Relevant portion of subsection 12.2(1).</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>12.2</B> (1) The Commissioner may discontinue the investigation of a complaint if the Commissioner is of the opinion that</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>c.1</I>) the matter is the object of a compliance agreement entered into under subsection 17.1(1);</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>2010, c. 23, s. 85<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>13.</B> Subsections 14(1) and (2) of the Act are replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 13</I>: Existing text of subsections 14(1) and (2):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>14.</B> (1) A complainant may, after receiving the Commissioner’s report or being notified under subsection 12.2(3) that the investigation of the complaint has been discontinued, apply to the Court for a hearing in respect of any matter in respect of which the complaint was made, or that is referred to in the Commissioner’s report, and that is referred to in clause 4.1.3, 4.2, 4.3.3, 4.4, 4.6, 4.7 or 4.8 of Schedule 1, in clause 4.3, 4.5 or 4.9 of that Schedule as modified or clarified by Division 1, in subsection 5(3) or 8(6) or (7) or in section 10.</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(2) A complainant must make an application within 45 days after the report or notification is sent or within any further time that the Court may, either before or after the expiry of those 45 days, allow.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Application<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><B>14.</B> (1) A complainant may, after receiving the Commissioner’s report or being notified under subsection 12.2(3) that the investigation of the complaint has been discontinued, apply to the Court for a hearing in respect of any matter in respect of which the complaint was made, or that is referred to in the Commissioner’s report, and that is referred to in clause 4.1.3, 4.2, 4.3.3, 4.4, 4.6, 4.7 or 4.8 of Schedule 1, in clause 4.3, 4.5 or 4.9 of that Schedule as modified or clarified by Division 1 <change>or 1.1</change>, in subsection 5(3) or 8(6) or (7), in section 10 or <change>in Division 1.1</change>.</Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Time for application<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2">(2) A complainant <change>shall</change> make an application within <change>one year</change> after the report or notification is sent or within any <change>longer period</change> that the Court may, either before or after the expiry of <change>that year</change>, allow.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>14.</B> Paragraph 16(<I>a</I>) of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 14</I>: Relevant portion of section 16:</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>16.</B> The Court may, in addition to any other remedies it may give,</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>a</I>) order an organization to correct its practices in order to comply with sections 5 to 10;</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0">(<I>a</I>) order an organization to correct its practices in order to comply with <change>Divisions 1 and 1.1</change>;</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>15.</B> The Act is amended by adding the following after section 17:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 15</I>: New.</Para></ExplNote></Block><Block LineCnt="N" Align="Yes" KeepWith="Next"><!--Heading:Compliance Agreements--><Para TopMargin="10" Italic="Yes" Hyphenate="OFF" TextAlign="Center"><change>Compliance Agreements</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Compliance agreement<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change><B>17.1</B> (1) If the Commissioner believes on reasonable grounds that an organization has committed, is about to commit or is likely to commit an act or omission that could constitute a contravention of a provision of Division 1 or 1.1 or a failure to follow a recommendation set out in Schedule 1, the Commissioner may enter into a compliance agreement, aimed at ensuring compliance with this Part, with that organization.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Terms<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(2) A compliance agreement may contain any terms that the Commissioner considers necessary to ensure compliance with this Part.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Effect of compliance agreement — no application<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(3) When a compliance agreement is entered into, the Commissioner, in respect of any matter covered under the agreement,</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>a</I>) shall not apply to the Court for a hearing under subsection 14(1) or paragraph 15(<I>a</I>); and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b</I>) shall apply to the court for the suspension of any pending applications that were made by the Commissioner under those provisions.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>For greater certainty<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(4) For greater certainty, a compliance agreement does not preclude</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>a</I>) an individual from applying for a hearing under section 14; or</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b</I>) the prosecution of an offence under the Act.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Agreement complied with<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change><B>17.2</B> (1) If the Commissioner is of the opinion that a compliance agreement has been complied with, the Commissioner shall provide written notice to that effect to the organization and withdraw any applications that were made under subsection 14(1) or paragraph 15(<I>a</I>) in respect of any matter covered under the agreement.</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Agreement not complied with<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(2) If the Commissioner is of the opinion that an organization is not complying with the terms of a compliance agreement, the Commissioner shall notify the organization and may apply to the Court for</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>a</I>) an order requiring the organization to comply with the terms of the agreement, in addition to any other remedies it may give; or</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b</I>) a hearing under subsection 14(1) or paragraph 15(<I>a</I>) or to reinstate proceedings that have been suspended as a result of an application made under paragraph 17.1(3)(<I>b</I>).</change></Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Time for application<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(3) Despite subsection 14(2), the application shall be made within one year after notification is sent or within any longer period that the Court may, either before or after the expiry of that year, allow.</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>16.</B> The portion of subsection 18(1) of the Act before paragraph (<I>a</I>) is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 16</I>: Relevant portion of subsection 18(1):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>18.</B> (1) The Commissioner may, on reasonable notice and at any reasonable time, audit the personal information management practices of an organization if the Commissioner has reasonable grounds to believe that the organization is contravening a provision of Division 1 or is not following a recommendation set out in Schedule 1, and for that purpose may</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>To ensure compliance<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><B>18.</B> (1) The Commissioner may, on reasonable notice and at any reasonable time, audit the personal information management practices of an organization if the Commissioner has reasonable grounds to believe that the organization <change>has contravened</change> a provision of Division 1 <change>or 1.1</change> or is not following a recommendation set out in Schedule 1, and for that purpose may</Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>2010, c. 23, s. 86(1)<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>17.</B> (1) Subsection 20(1) of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 17</I>: (1) and (2) Existing text of subsections 20(1) and (2):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>20.</B> (1) Subject to subsections (2) to (6), 12(3), 12.2(3), 13(3), 19(1), 23(3) and 23.1(1) and section 25, the Commissioner or any person acting on behalf or under the direction of the Commissioner shall not disclose any information that comes to their knowledge as a result of the performance or exercise of any of the Commissioner’s duties or powers under this Part.</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(2) The Commissioner may make public any information relating to the personal information management practices of an organization if the Commissioner considers that it is in the public interest to do so.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Confidentiality<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><B>20.</B> (1) Subject to subsections (2) to (6), 12(3), 12.2(3), 13(3), 19(1), 23(3) and 23.1(1) and section 25, the Commissioner or any person acting on behalf or under the direction of the Commissioner shall not disclose any information that comes to their knowledge as a result of the performance or exercise of any of the Commissioner’s duties or powers under this Part <change>other than those referred to in subsection 10.1(1) or 10.3(2)</change>.</Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Confidentiality — reports and records<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(1.1) Subject to subsections (2) to (6), 12(3), 12.2(3), 13(3), 19(1), 23(3) and 23.1(1) and section 25, the Commissioner or any person acting on behalf or under the direction of the Commissioner shall not disclose any information contained in a report made under subsection 10.1(1) or in a record obtained under subsection 10.3(2).</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(2) Subsection 20(2) of the Act is replaced by the following:</Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Public interest<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2">(2) The Commissioner may, if the Commissioner considers that it is in the public interest to do so, make public any information <change>that comes to his or her knowledge in the performance or exercise of any of his or her duties or powers under this Part</change>.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(3) Subsection 20(4) of the Act is amended by striking out “or” at the end of paragraph (<I>c</I>), by adding “or” at the end of paragraph (<I>d</I>) and by adding the following after that paragraph:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2">(3) Relevant portion of subsection 20(4):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(4) The Commissioner may disclose, or may authorize any person acting on behalf or under the direction of the Commissioner to disclose, information in the course of</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>c</I>) a hearing before the Court under this Part; or</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>d</I>) an appeal from a decision of the Court.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>e</I>) a judicial review in relation to the performance or exercise of any of the Commissioner’s duties or powers under this Part.</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(4) Section 20 of the Act is amended by adding the following after subsection (5):</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2">(4) New.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Disclosure of breach of security safeguards<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(6) The Commissioner may disclose, or may authorize any person acting on behalf or under the direction of the Commissioner to disclose to a government institution or a part of a government institution, any information contained in a report made under subsection 10.1(1) or in a record obtained under subsection 10.3(2) if the Commissioner has reasonable grounds to believe that the information could be useful in the investigation of a contravention of the laws of Canada or a province that has been, is being or is about to be committed.</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>18.</B> (1) The portion of subsection 22(2) of the Act before paragraph (<I>a</I>) is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 18</I>: (1) and (2) Existing text of subsection 22(2):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(2) For the purposes of any law relating to libel or slander,</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>a</I>) anything said, any information supplied or any record or thing produced in good faith in the course of an investigation or audit carried out by or on behalf of the Commissioner under this Part is privileged; and</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>b</I>) any report made in good faith by the Commissioner under this Part and any fair and accurate account of the report made in good faith for the purpose of news reporting is privileged.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Defamation<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><change>(2) No action lies in defamation with respect to</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(2) Paragraphs 22(2)(<I>a</I>) and (<I>b</I>) of the English version of the Act are replaced by the following:</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0">(<I>a</I>) anything said, any information supplied or any record or thing produced in good faith in the course of an investigation or audit carried out by or on behalf of the Commissioner under this Part; and</Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0">(<I>b</I>) any report made in good faith by the Commissioner under this Part and any fair and accurate account of the report made in good faith for the purpose of news reporting.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>19.</B> Paragraph 24(<I>c</I>) of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 19</I>: Relevant portion of section 24:</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>24.</B> The Commissioner shall</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>c</I>) encourage organizations to develop detailed policies and practices, including organizational codes of practice, to comply with sections 5 to 10; and</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0">(<I>c</I>) encourage organizations to develop detailed policies and practices, including organizational codes of practice, to comply with <change>Divisions 1 and 1.1</change>; and</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>20.</B> (1) Subsection 25(1) of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 20</I>: (1) and (2) Existing text of subsection 25(1) and (2):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>25.</B> (1) The Commissioner shall, as soon as practicable after the end of each calendar year, submit to Parliament a report concerning the application of this Part, the extent to which the provinces have enacted legislation that is substantially similar to this Part and the application of any such legislation.</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2">(2) Before preparing the report, the Commissioner shall consult with those persons in the provinces who, in the Commissioner’s opinion, are in a position to assist the Commissioner in reporting respecting personal information that is collected, used or disclosed interprovincially or internationally.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Annual report<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><B>25.</B> (1) The Commissioner shall, <change>within three months after the end of each financial year</change>, submit to Parliament a report concerning the application of this Part, the extent to which the provinces have enacted legislation that is substantially similar to this Part and the application of any such legislation.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(2) Subsection 25(2) of the English version of the Act is replaced by the following:</Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Consultation<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2">(2) Before preparing the report, the Commissioner shall consult with those persons in the provinces who, in the Commissioner’s opinion, are in a position to assist the Commissioner in <change>making a report</change> respecting personal information that is collected, used or disclosed interprovincially or internationally.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>21.</B> (1) The portion of subsection 26(1) of the Act before paragraph (<I>a</I>) is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 21</I>: (1) to (3) Relevant portion of subsection 26(1):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>26.</B> (1) The Governor in Council may make regulations</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>a.01</I>) specifying, by name or by class, what is an investigative body for the purposes of paragraph 7(3)(<I>d</I>) or (<I>h.2</I>);</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">... </Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>b</I>) for carrying out the purposes and provisions of this Part.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Regulations<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><B>26.</B> (1) The Governor in Council may make regulations for carrying out the purposes and provisions of this Part, <change>including regulations</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(2) Paragraph 26(1)(<I>a.01</I>) of the Act is repealed.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(3) Subsection 26(1) of the Act is amended by striking out “and” at the end of paragraph (<I>a.1</I>) and by replacing paragraph (<I>b</I>) with the following:</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>b</I>) specifying information to be kept and maintained under subsection 10.3(1); and</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0"><change>(<I>c</I>) prescribing anything that by this Part is to be prescribed.</change></Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>22.</B> Subsection 27(1) of the Act is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 22</I>: Existing text of subsection 27(1):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>27.</B> (1) Any person who has reasonable grounds to believe that a person has contravened or intends to contravene a provision of Division 1, may notify the Commissioner of the particulars of the matter and may request that their identity be kept confidential with respect to the notification.</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Whistleblowing<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><B>27.</B> (1) Any person who has reasonable grounds to believe that a person has contravened or intends to contravene a provision of Division 1 <change>or 1.1</change> may notify the Commissioner of the particulars of the matter and may request that their identity be kept confidential with respect to the notification.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>23.</B> Paragraphs 27.1(1)(<I>a</I>) to (<I>c</I>) of the Act are replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 23</I>: Relevant portion of subsection 27.1(1):</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>27.1</B> (1) No employer shall dismiss, suspend, demote, discipline, harass or otherwise disadvantage an employee, or deny an employee a benefit of employment, by reason that</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>a</I>) the employee, acting in good faith and on the basis of reasonable belief, has disclosed to the Commissioner that the employer or any other person has contravened or intends to contravene a provision of Division 1;</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>b</I>) the employee, acting in good faith and on the basis of reasonable belief, has refused or stated an intention of refusing to do anything that is a contravention of a provision of Division 1;</Para><Para Align="No" TopMargin="5" Size="8" Leading="9" LeftMargin="2" FirstLineIndent="0">(<I>c</I>) the employee, acting in good faith and on the basis of reasonable belief, has done or stated an intention of doing anything that is required to be done in order that a provision of Division 1 not be contravened; or</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0">(<I>a</I>) the employee, acting in good faith and on the basis of reasonable belief, has disclosed to the Commissioner that the employer or any other person has contravened or intends to contravene a provision of Division 1 <change>or 1.1</change>;</Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0">(<I>b</I>) the employee, acting in good faith and on the basis of reasonable belief, has refused or stated an intention of refusing to do anything that is a contravention of a provision of Division 1 <change>or 1.1</change>;</Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0">(<I>c</I>) the employee, acting in good faith and on the basis of reasonable belief, has done or stated an intention of doing anything that is required to be done in order that a provision of Division 1 <change>or 1.1</change> not be contravened; or</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>24.</B> The portion of section 28 of the Act before paragraph (<I>a</I>) is replaced by the following:</Para><ExplNote><Para Align="Yes" TopMargin="10" LeftMargin="0" FirstLineIndent="2"><I>Clause 24</I>: Relevant portion of section 28:</Para><Para Align="Yes" TopMargin="5" Size="8" Leading="9" LeftMargin="0" FirstLineIndent="2"><B>28.</B> Every person who knowingly contravenes subsection 8(8) or 27.1(1) or who obstructs the Commissioner or the Commissioner’s delegate in the investigation of a complaint or in conducting an audit is guilty of</Para></ExplNote></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Offence and punishment<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><B>28.</B> Every <change>organization that</change> knowingly contravenes subsection 8(8), <change>section 10.1 or subsection 10.3(1)</change> or 27.1(1) or <change>that</change> obstructs the Commissioner or the Commissioner’s delegate in the investigation of a complaint or in conducting an audit is guilty of</Para></Block><Block LineCnt="N" Align="Yes" KeepWith="Next"><!--Heading:CONSEQUENTIAL AMENDMENT--><Para TopMargin="10" Bold="Yes" Hyphenate="OFF" TextAlign="Center">CONSEQUENTIAL AMENDMENT</Para></Block><Block LineCnt="N" Align="Yes" KeepWith="Next"><!--Heading:Access to Information Act--><MarginalNote>R.S., c. A-1<br/></MarginalNote><Para TopMargin="5" Bold="Yes" SmallCaps="Yes" Hyphenate="OFF" TextAlign="Center">Access to Information Act</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>25.</B> Schedule II to the <I>Access to Information Act</I> is amended by adding, in alphabetical order, a reference to</Para></Block><Block LineCnt="Y" Align="Yes" KeepWith="Next"><Para TopMargin="2" LeftMargin="2" FirstLineIndent="-2"><change>Personal Information Protection and Electronic Documents Act</change></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="0" LeftMargin="4" FirstLineIndent="-2" Italic="Yes"><AltLang xml:lang="fr"><change>Loi sur la protection des renseignements personnels et les documents électroniques.</change></AltLang></Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="0" Bold="Yes">and a corresponding reference to “subsection 20(1.1)”.</Para></Block><Block LineCnt="N" Align="Yes" KeepWith="Next"><!--Heading:COORDINATING AMENDMENTS--><Para TopMargin="10" Bold="Yes" Hyphenate="OFF" TextAlign="Center">COORDINATING AMENDMENTS</Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>2010, c. 23<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>26.</B> (1) In this section “other Act” means <I>An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities, and to amend the Canadian Radio-television and Telecommunications Commission Act, the Competition Act, the Personal Information Protection and Electronic Documents Act and the Telecommunications Act</I>, chapter 23 of the Statutes of Canada, 2010.</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(2) On the first day on which both section 82 of the other Act and subsection 6(3) of this Act are in force, the portion of subsection 7.1(2) of the <I>Personal Information Protection and Electronic Documents Act</I> before paragraph (<I>a</I>) is replaced by the following:</Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Collection of electronic addresses, etc.<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2">(2) Paragraphs 7(1)(<I>a</I>) and (<I>b.1</I>) to (<I>d</I>) and (2)(<I>a</I>) to (<I>c.1</I>) and the exception set out in clause 4.3 of Schedule 1 do not apply in respect of</Para></Block><Block LineCnt="Y" Align="Yes"><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes">(3) On the first day on which both subsection 20(6) of the <I>Personal Information Protection and Electronic Documents Act</I>, as enacted by subsection 86(2) of the other Act, and subsection 20(6) of the <I>Personal Information Protection and Electronic Documents Act</I>, as enacted by subsection 17(4) of this Act, are in force,</Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0" Bold="Yes">(<I>a</I>) subsections 20(1) and (1.1) of the <I>Personal Information Protection and Electronic Documents Act</I> are replaced by the following:</Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Confidentiality<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2"><B>20.</B> (1) Subject to subsections (2) to (7), 12(3), 12.2(3), 13(3), 19(1), 23(3) and 23.1(1) and section 25, the Commissioner or any person acting on behalf or under the direction of the Commissioner shall not disclose any information that comes to their knowledge as a result of the performance or exercise of any of the Commissioner’s duties or powers under this Part other than those referred to in subsection 10.1(1) or 10.3(2).</Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Confidentiality — reports and records<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2">(1.1) Subject to subsections (2) to (7), 12(3), 12.2(3), 13(3), 19(1), 23(3) and 23.1(1) and section 25, the Commissioner or any person acting on behalf or under the direction of the Commissioner shall not disclose any information contained in a report made under subsection 10.1(1) or in a record obtained under subsection 10.3(2).</Para></Block><Block LineCnt="Y" Align="No"><Para TopMargin="5" LeftMargin="2" FirstLineIndent="0" Bold="Yes">(<I>b</I>) subsection 20(6) of the <I>Personal Information Protection and Electronic Documents Act</I>, as enacted by subsection 86(2) of the other Act, is renumbered as subsection 20(7) and is repositioned accordingly if required.</Para></Block><Block LineCnt="N" Align="Yes" KeepWith="Next"><!--Heading:COMING INTO FORCE--><Para TopMargin="10" Bold="Yes" Hyphenate="OFF" TextAlign="Center">COMING INTO FORCE</Para></Block><Block LineCnt="Y" Align="Yes"><MarginalNote>Order in council<br/></MarginalNote><Para TopMargin="5" LeftMargin="0" FirstLineIndent="2" Bold="Yes"><B>27.</B> Sections 10, 11 and 14, subsections 17(1) and (4) and sections 19 and 22 to 25 come into force on a day to be fixed by order of the Governor in Council.</Para></Block><Block Align="Yes"><Para Style="BPT_ImprintE"><br/><br/>Published under authority of the Senate of Canada</Para></Block><Block Align="Yes" LineCnt="N"><Para NoLineBreak="Yes" NoHtml="Yes" Leading="0" Size="0" TopMargin="0" BottomMargin="0"></Para></Block></Bill_Part></Bill>
