<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PrivacySense.net</title>
	<atom:link href="http://www.privacysense.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.privacysense.net</link>
	<description>Privacy Resources for Individuals and Businesses</description>
	<lastBuildDate>Mon, 12 Oct 2009 14:36:52 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Clear Screen Policy Templates</title>
		<link>http://www.privacysense.net/clear-screen-policy-templates/</link>
		<comments>http://www.privacysense.net/clear-screen-policy-templates/#comments</comments>
		<pubDate>Mon, 12 Oct 2009 14:36:52 +0000</pubDate>
		<dc:creator>M. G.</dc:creator>
				<category><![CDATA[Privacy Training]]></category>
		<category><![CDATA[clear screen policy]]></category>
		<category><![CDATA[clear screen policy templates]]></category>

		<guid isPermaLink="false">http://www.privacysense.net/?p=2388</guid>
		<description><![CDATA[You already know about the benefits of a Clear Screen Policy — now it’s time to implement one in your organization. Click for free clear screen policy templates.]]></description>
			<content:encoded><![CDATA[<p>You already know about the benefits of a <a href="/clear-screen-policy/">Clear Screen Policy</a> &mdash; now it&#8217;s time to implement one in your organization. </p>
<p>One of the easiest and most inexpensive ways to create a clear screen policy is to use a template or learn and adapt from other policies online.</p>
<p>Below you will find a list of clear screen templates and policies created by other organizations. Feel free to browse them, learn from them, and adapt them to your own organization:</p>
<h2>Clear Screen Policy Templates</h2>
<ul>
<li><img src="/images/small/doc_windows.gif" /> <a href="http://www.desktopauditing.com/files/cleandesk.doc">Clean Desk and Clear Screen Template</a>  (Desktopauditing.com)</li>
<li><img src="/images/small/doc_windows.gif" /> <a href="http://www.six.somerset.gov.uk/som_html_uploads/cms1552006165226/docs/Clear%20desk%20clear%20screen%20procedure.doc">Clear Desk Clear Screen Procedure</a>  (Somerset Gov&#8217;t UK)</li>
<li><img src="/images/small/pdf_small.gif" /> <a href="http://www.emporia.edu/facsen/2008-2009/documents/FSB_08004_final.pdf">Clear Desk and Clear Screen Policy</a> (Emporia University)</li>
<li><img src="/images/small/htm_small.gif" /> <a href="http://www.hantsfire.gov.uk/theservice/policies/infoservices-policies/clear-desk.htm">Clear Desk and Clear Screen Policy</a>  (Hampshire Fire and Rescue Services)</li>
<li><img src="/images/small/pdf_small.gif" /> <a href="http://blogs.mhs.manchester.ac.uk/erg-information-security/files/2009/01/cleardeskclearscreen_policy.pdf">Clear Desk and Clear Screen Policy</a> (University of Mannheim)</li>
<li><img src="/images/small/pdf_small.gif" /> <a href="<br />
http://www.odis.dhr.state.ga.us/1000_adm/1900_OIT/1900/MAN1900/Physical%20and%20Environmental%20Security/Clear%20Desk%20and%20Clear%20Screen.pdf">Clear Desk and Clear Screen Guidelines</a>  (Georgia Department of Human Resources)</li>
<li><img src="/images/small/pdf_small.gif" /> <a href="<br />
http://www.cord.edu/About/Jobs/assets/policyClearDeskClearScreen.pdf">Clear Desk and Clear Screen Policy and Procedure</a>  (Concordia College)</li>
</ul>
<hr />
<p><small>Copyright © 2009 <a href="http://www.privacysense.net">PrivacySense.net</a>. |
<a href="http://www.privacysense.net/clear-screen-policy-templates/">Permalink</a> |
<a href="http://www.privacysense.net/clear-screen-policy-templates/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.privacysense.net/clear-screen-policy-templates/&title=Clear Screen Policy Templates">del.icio.us</a>
<br/>
Tags: <a href="http://www.privacysense.net/tag/clear-screen-policy/" rel="tag">clear screen policy</a>, <a href="http://www.privacysense.net/tag/clear-screen-policy-templates/" rel="tag">clear screen policy templates</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.privacysense.net/clear-screen-policy-templates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clear Desk Policy Templates</title>
		<link>http://www.privacysense.net/clear-desk-policy-templates/</link>
		<comments>http://www.privacysense.net/clear-desk-policy-templates/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 01:57:18 +0000</pubDate>
		<dc:creator>M. G.</dc:creator>
				<category><![CDATA[Privacy Training]]></category>
		<category><![CDATA[clear desk policy]]></category>
		<category><![CDATA[clear desk policy templates]]></category>

		<guid isPermaLink="false">http://www.privacysense.net/?p=2383</guid>
		<description><![CDATA[You already know about the benefits of a Clear Desk Policy &#8212; now it's time to implement one in your organization.  Click for free clear desk policy templates.]]></description>
			<content:encoded><![CDATA[<p>You already know about the benefits of a <a href="/clear-desk-policy/">Clear Desk Policy</a> &mdash; now it&#8217;s time to implement one in your organization. </p>
<p>One of the easiest and most inexpensive ways to create a clear desk policy is to use a template or learn and adapt from other policies online.</p>
<p>Below you will find a list of clear desk templates and policies created by other organizations. Feel free to browse them, learn from them, and adapt them to your own organization:</p>
<h2>Clear Desk Policy Templates</h2>
<ul>
<li><img src="/images/small/doc_windows.gif" /> <a href="http://www.desktopauditing.com/files/cleandesk.doc">Clean Desk and Clear Screen Template</a>  (Desktopauditing.com)</li>
<li><img src="/images/small/doc_windows.gif" /> <a href="http://www.six.somerset.gov.uk/som_html_uploads/cms1552006165226/docs/Clear%20desk%20clear%20screen%20procedure.doc">Clear Desk Clear Screen Procedure</a>  (Somerset Gov&#8217;t UK)</li>
<li><img src="/images/small/doc_windows.gif" /> <a href="http://www.sans.edu/resources/student_projects/200808_01.doc">Clean Desk Policy</a> (sans.edu)</li>
<li><img src="/images/small/htm_small.gif" /> <a href="http://www.hantsfire.gov.uk/theservice/policies/infoservices-policies/clear-desk.htm">Clear Desk and Clear Screen Policy</a>  (Hampshire Fire and Rescue Services)</li>
<li><img src="/images/small/pdf_small.gif" /> <a href="http://www.emporia.edu/facsen/2008-2009/documents/FSB_08004_final.pdf">Clear Desk and Clear Screen Policy</a> (Emporia University)</li>
<li><img src="/images/small/pdf_small.gif" /> <a href="http://www.uc.edu/infosec/documents/Policy_Clean_Desk_Policy.pdf">Clean Desk Policy</a>  (University of Cincinatti)</li>
<li><img src="/images/small/pdf_small.gif" /> <a href="http://www.toronto.ca/legdocs/2009/agendas/committees/gm/CleanDesk.pdf">Clean Desk Policy and Guidelines</a>  (City of Toronto)</li>
<li><img src="/images/small/pdf_small.gif" /> <a href="http://www.bankersonline.com/tools/clean_desk_pol.pdf">Clean Desk Policy</a>  (BankersOnline.com)</li>
<li><img src="/images/small/pdf_small.gif" /> <a href="http://blogs.mhs.manchester.ac.uk/erg-information-security/files/2009/01/cleardeskclearscreen_policy.pdf">Clear Desk and Clear Screen Policy</a> (University of Mannheim)</li>
<li><img src="/images/small/pdf_small.gif" /> <a href="<br />
http://www.odis.dhr.state.ga.us/1000_adm/1900_OIT/1900/MAN1900/Physical%20and%20Environmental%20Security/Clear%20Desk%20and%20Clear%20Screen.pdf">Clear Desk and Clear Screen Guidelines</a>  (Georgia Department of Human Resources)</li>
<li><img src="/images/small/pdf_small.gif" /> <a href="<br />
http://www.cord.edu/About/Jobs/assets/policyClearDeskClearScreen.pdf">Clear Desk and Clear Screen Policy and Procedure</a>  (Concordia College)</li>
</ul>
<hr />
<p><small>Copyright © 2009 <a href="http://www.privacysense.net">PrivacySense.net</a>. |
<a href="http://www.privacysense.net/clear-desk-policy-templates/">Permalink</a> |
<a href="http://www.privacysense.net/clear-desk-policy-templates/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.privacysense.net/clear-desk-policy-templates/&title=Clear Desk Policy Templates">del.icio.us</a>
<br/>
Tags: <a href="http://www.privacysense.net/tag/clear-desk-policy/" rel="tag">clear desk policy</a>, <a href="http://www.privacysense.net/tag/clear-desk-policy-templates/" rel="tag">clear desk policy templates</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.privacysense.net/clear-desk-policy-templates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Cost of a Privacy Breach</title>
		<link>http://www.privacysense.net/cost-privacy-breach/</link>
		<comments>http://www.privacysense.net/cost-privacy-breach/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 22:36:32 +0000</pubDate>
		<dc:creator>M. G.</dc:creator>
				<category><![CDATA[Personal Information]]></category>
		<category><![CDATA[Privacy News]]></category>
		<category><![CDATA[Privacy Breach]]></category>

		<guid isPermaLink="false">http://www.privacysense.net/?p=2363</guid>
		<description><![CDATA[A new study released by TELUS in partnership with The Rotman School of Management puts a hefty dollar value on the cost of an IT security breach.]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://www.rotman.utoronto.ca/news/detail.asp?ID=490">new study</a> released by TELUS in partnership with The Rotman School of Management puts a hefty dollar value on the cost of an IT security breach:</p>
<blockquote><p>According to the study which surveyed more than 600 IT security professionals across the country:</p>
<p>IT security breaches cost the average Canadian organization an estimated <b>$834,000</b> in 2009 &#8211; a 97 per cent increase from the $423,000 reported by the study last year (<a href="http://www.rotman.utoronto.ca/news/detail.asp?ID=490">source</a>).
</p></blockquote>
<p>IT security breaches happen when systems get compromised or sensitive information voluntary or involuntarily leaks from the system, often due to carelessness or dishonest employees. When a security breach involves the loss of people&#8217;s personal information it is commonly referred to as a <em>privacy breach</em>.</p>
<p>Many organizations are bound by privacy legislation to properly secure their systems with respect to the sensitivity of personal information collected but many still fail to do so. </p>
<p>Can we attribute these numbers to the state of the economy?</p>
<p>Not necessarily:</p>
<blockquote><p>
&#8220;Canadian organizations are finding it difficult to improve their security posture within the current economic climate. </p>
<p>However, we found several organizations that performed well despite the adversity. Those organizations tended to review whether or not they were focusing on the right threats and conducted regular assessments of their capabilities to prevent, detect and respond to security concerns,&#8221; said Alan Lefort, managing director, TELUS Security Labs.
</p></blockquote>
<p>While some organizations will not place a priority on <a href="/personal-information-safe-weak-economy/">keeping your personal information safe in a weak economy</a>, many still do, so it is not an excuse.</p>
<p>Businesses must remember that <a href="/personal-information-organizations-liability/">personal information is a liability</a> and it must take appropriate measures to secure it and properly train staff to handle it.</p>
<h2>Advice for Organizations</h2>
<p>Here&#8217;s some advice for organizations wanting to minimize the possibilities of a privacy breach:</p>
<ul>
<li><b><a href="/hiring-privacy-officer/">Hire a Privacy Officer</a></b>. This will ensure that you have someone responsible for privacy compliance in the office. The privacy officer will need to work closely with security personnel from IT to secure systems containing personal information.</li>
<li><b><a href="/introductory-refresher-privacy-training/">Conduct Privacy Training Regularly</a></b>. Employees need to be constantly reminded about the proper way to handle sensitive information (e.g. A <a href="/document-destruction-policy/">document destruction</a> and <a href="/data-destruction-policy/">data destruction</a> policy) so that it does not carelessly slip into the wrong hands.</li>
<li><b><a href="/hiring-privacy-lawyer/">Hire Professional Help</a></b>. If your organization realizes it has suffered a privacy breach, <a href="/privacy-lawyer-directory/">finding</a> and <a href="/hiring-privacy-lawyer/">hiring</a> a privacy lawyer can be one of the smartest moves to make.</li>
</ul>
<hr />
<p><small>Copyright © 2009 <a href="http://www.privacysense.net">PrivacySense.net</a>. |
<a href="http://www.privacysense.net/cost-privacy-breach/">Permalink</a> |
<a href="http://www.privacysense.net/cost-privacy-breach/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.privacysense.net/cost-privacy-breach/&title=The Cost of a Privacy Breach">del.icio.us</a>
<br/>
Tags: <a href="http://www.privacysense.net/tag/privacy-breach/" rel="tag">Privacy Breach</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.privacysense.net/cost-privacy-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New! Find Privacy Lawyers Online</title>
		<link>http://www.privacysense.net/find-privacy-lawyers-online/</link>
		<comments>http://www.privacysense.net/find-privacy-lawyers-online/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 21:56:10 +0000</pubDate>
		<dc:creator>M. G.</dc:creator>
				<category><![CDATA[Privacy News]]></category>

		<guid isPermaLink="false">http://www.privacysense.net/?p=2334</guid>
		<description><![CDATA[PrivacySense is pleased to present a new Privacy Lawyer Directory where you can browse for law firms practicing privacy law in your area.]]></description>
			<content:encoded><![CDATA[<p>PrivacySense is pleased to present a new <a href="/privacy-lawyer-directory/">Privacy Lawyer Directory</a> where you can browse for law firms practicing privacy law all over Canada.</p>
<p>If you&#8217;re unfamiliar with the services of a privacy lawyer and the benefit they can bring to your organization, read the article on <a href="/hiring-privacy-lawyer/">hiring a privacy lawyer</a>. </p>
<p>In addition to hiring a privacy lawyer, you may also want to read the article on <a href="/hiring-privacy-officer/">hiring a privacy officer</a> &mdash; especially if your organization has not made an effort to become privacy compliant yet.</p>
<hr />
<p><small>Copyright © 2009 <a href="http://www.privacysense.net">PrivacySense.net</a>. |
<a href="http://www.privacysense.net/find-privacy-lawyers-online/">Permalink</a> |
<a href="http://www.privacysense.net/find-privacy-lawyers-online/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.privacysense.net/find-privacy-lawyers-online/&title=New! Find Privacy Lawyers Online">del.icio.us</a>
<br/>
Tags: <br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.privacysense.net/find-privacy-lawyers-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hiring a Privacy Lawyer</title>
		<link>http://www.privacysense.net/hiring-privacy-lawyer/</link>
		<comments>http://www.privacysense.net/hiring-privacy-lawyer/#comments</comments>
		<pubDate>Thu, 24 Sep 2009 04:23:27 +0000</pubDate>
		<dc:creator>M. G.</dc:creator>
				<category><![CDATA[Privacy Training]]></category>

		<guid isPermaLink="false">http://www.privacysense.net/?p=2307</guid>
		<description><![CDATA[Does the thought of making your organization privacy complaint seem like the last item on your priority list? Becoming privacy compliant is not an option for most organizations &#8212; <b>it's the law</b>.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.privacysense.net/wp-content/uploads/2009/09/lawyers.jpg" alt="lawyers" title="lawyers" width="150" height="115" class="alignright" />Does the thought of making your organization privacy complaint seem like the last item on your priority list?</p>
<p>Becoming privacy compliant is not an option for most organizations &mdash; <b>it&#8217;s the law</b>.</p>
<p>Not being prepared with the appropriate policies and procedures to handle your customers&#8217; and clients&#8217; <a href="/personal-information/">personal information</a> can cost your organization dearly later on in the form of legal services, deteriorating company image, and loss of business revenue.</p>
<p>One of the quickest and most surest ways of becoming privacy complaint is by <strong>hiring a privacy lawyer</strong>.</p>
<h2>The Benefits of Hiring a Privacy Lawyer</h2>
<p>Your organization has other options for ensuring privacy compliance. For example, you can <a href="/hiring-privacy-officer/">hire a privacy officer</a>. However, there are numerous <em>immediate</em> benefits by hiring the services of an experienced legal professional.</p>
<h3>Get it Done Right &#8212; Right Away</h3>
<p>Hiring a privacy lawyer means expertise immediately within your reach. Sure, they may cost more initially, but your organization will benefit by having results that you can count on <em>now</em>.</p>
<h3>Developing Policies and Procedures</h3>
<p>A privacy lawyer is able to create policies and procedures for the collection, usage, disclosure, and management of personal information that is consistent with your organization&#8217;s business processes. </p>
<p>You can rest assured that your organization&#8217;s policies and procedures are developed using best practices and backed by a professional.</p>
<h3>Understanding Tricky, Cross-Border Issues</h3>
<p>Many organizations are large, diverse, and have offices scattered throughout the globe. </p>
<p>For example, your organization may collect personal information from people in Canada, process that information in India where labour is cheap, and finally store the information in a data warehouse in the US.</p>
<p>When personal information crosses borders and is subject to difference privacy legislation, it is vital to have a privacy lawyer review your situation to ensure you are aware of your risks and responsibilities and are compliant in each area.</p>
<h3>Responding to Access Requests and Complaints</h3>
<p>What happens when you receive a <em>nightmare access request</em>?</p>
<p> A customer who seemingly knows privacy legislation better than the back of his hand is demanding volumes of records containing personal information and is demanding information about how his data is collected, used, stored, and deleted. </p>
<p>On top of that, he&#8217;s also threatening to make a complaint with the privacy commissioner if you do not provide a satisfactory response within thirty days.</p>
<p>Are you prepared to handle difficult privacy access requests and complaints?</p>
<h3>Mitigating a Privacy Breach</h3>
<p>Everyone knows about the financial damage that TJX corporation suffered when it failed to provide adequate security measures to protect the personal information it had collected. </p>
<p>A privacy lawyer can mitigate the chances of a privacy breach which has the power to cripple your organization. If your organization has already suffered a privacy breach, a privacy lawyer can help minimize its impact.</p>
<h3>Privacy Training</h3>
<p>For larger and more specialized organizations, training privacy officers, employees, and creating educational materials needs to be done properly. Some organizations can simply not afford to make mistakes. </p>
<p>Privacy training done properly will create knowledgeable, trained employees and reduce the risks of an employee making a careless mistake with your organization&#8217;s sensitive information.</p>
<h3>Contracts</h3>
<p>Perhaps the most important, a privacy lawyer can assess, create, or modify your legal contracts to ensure that your organization is legally covered in its business activities when collecting, using, and disclosing personal information.</p>
<h2>Finding a Privacy Lawyer</h2>
<p>PrivacySense offers a free <a href="/privacy-lawyer-directory/">Privacy Lawyer Directory</a> where you can search for law firms practicing privacy law in Canada. Take a look at the law firms in your area and see what services they have to offer.</p>
<h2>Conclusion</h2>
<p>Privacy law is relatively young and not fully understood by a majority of businesses. Although hiring a privacy lawyer can seem expensive on the onset, your organization will save valuable time and costs in the long-run and will get started on the right foot by having dependable professional resources from an experienced law firm. </p>
<p>Once your organization has employed the use of a privacy lawyer, continuing to use one can be an ongoing, costly expense. Consider using the resources of a privacy lawyer to properly train a <a href="/hiring-privacy-officer/">privacy officer you hire</a> to handle the management of personal information in your organization.</p>
<hr />
<p><small>Copyright © 2009 <a href="http://www.privacysense.net">PrivacySense.net</a>. |
<a href="http://www.privacysense.net/hiring-privacy-lawyer/">Permalink</a> |
<a href="http://www.privacysense.net/hiring-privacy-lawyer/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.privacysense.net/hiring-privacy-lawyer/&title=Hiring a Privacy Lawyer">del.icio.us</a>
<br/>
Tags: <br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.privacysense.net/hiring-privacy-lawyer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ideas to Foster Privacy Awareness</title>
		<link>http://www.privacysense.net/ideas-to-foster-privacy-awareness/</link>
		<comments>http://www.privacysense.net/ideas-to-foster-privacy-awareness/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 00:17:53 +0000</pubDate>
		<dc:creator>M. G.</dc:creator>
				<category><![CDATA[Privacy Officers]]></category>
		<category><![CDATA[privacy awareness]]></category>

		<guid isPermaLink="false">http://www.privacysense.net/?p=2185</guid>
		<description><![CDATA[All it takes is a careless slip by an employee to cause a massive privacy breach. Read this article to find creative ideas for your privacy officer to foster privacy awareness in the office.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.privacysense.net/wp-content/uploads/2009/09/bulb.jpg" alt="bulb" title="bulb" width="103" height="150" class="alignright" />One thing every privacy officer should be concerned about is the proper handling of personal information in an organization. </p>
<p>Your organization can spend thousands of dollars on high-tech solutions to protect personal information but all it takes is a careless slip by an employee to cause a massive privacy breach. </p>
<p>This is why employees need constant reminders about the importance of handling personal information properly and why privacy officers need solid ideas to foster privacy awareness in their organization.</p>
<p>Here are some creative ideas for privacy officers:</p>
<h2>Write for the Company Newsletter</h2>
<p>Most medium-to-large sized organizations have a company newsletter that gets circulated through the office. This is a great opportunity for privacy officers to have a presence and deliver privacy-related information to employees at regular intervals.</p>
<h3>Provide Practical Tips</h3>
<p>Chances are, many of the employees in your organization manage online profiles such as Facebook. Use this opportunity to show employees how to keep their profiles private and show them what type of personal information they should <em>not</em> share with the entire world.</p>
<h3>Show Consequences for Failing to Comply with Policies and Procedures</h3>
<p>Policies and procedures are easier to comply with if employees know <em>why</em> they should be following them. </p>
<p>For example, if your organization uses a <a href="/document-destruction-policy/">document destruction policy</a> to instruct employees to shred all paperwork containing sensitive information, you can refer to news stories where employees have <a href="http://www.ctv.ca/servlet/ArticleNews/story/CTVNews/20080406/BC_information_dumpster_080406/20080406?hub=TopStories">contributed to a privacy breach</a> by throwing personal information into a dumpster rather than using the shredder.</p>
<h3>Report on Privacy News</h3>
<p>Privacy news, especially if it is relevant to your industry, may interest many of your employees. You may choose to provide snippets from articles or rewrite and summarize news stories for your audience.</p>
<h3>Mention Changes in Policies and Procedures</h3>
<p>A &#8220;what&#8217;s new&#8221; section may be an effective place to remind employees about changes to policies and procedures.</p>
<h2>Make Privacy Officers Open and Accessible</h2>
<p>Consider publishing the names and contact information of all privacy officers in the organization. </p>
<p>Depending on the size of your organization, you may also consider posting a picture and location of the privacy officers in the office. Employees will feel more comfortable approaching privacy officers if they know who they are, where they are located, and if they are open to questions, comments, and suggestions.</p>
<p>Another thing to consider is having your organization create an email specifically designated for privacy related inquiries (e.g. <b>privacy</b>@yourbusiness.com). This will ensure that employees always remember where to send inquiries via email.</p>
<h2>Deliver Introductory and Refresher Privacy Training</h2>
<p>Whenever possible, deliver <a href="/introductory-refresher-privacy-training/">introductory and refresher privacy training</a> in person. This will allow you to meet employees and promote privacy awareness on a personal level.</p>
<h2>Write an F.A.Q. Document</h2>
<p>After a few years there will be numerous questions that will be frequently asked by employees. Consider creating a Frequently Asked Questions document and putting it online or making it available in hard-copy.</p>
<hr />
<p><small>Copyright © 2009 <a href="http://www.privacysense.net">PrivacySense.net</a>. |
<a href="http://www.privacysense.net/ideas-to-foster-privacy-awareness/">Permalink</a> |
<a href="http://www.privacysense.net/ideas-to-foster-privacy-awareness/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.privacysense.net/ideas-to-foster-privacy-awareness/&title=Ideas to Foster Privacy Awareness">del.icio.us</a>
<br/>
Tags: <a href="http://www.privacysense.net/tag/privacy-awareness/" rel="tag">privacy awareness</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.privacysense.net/ideas-to-foster-privacy-awareness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Requests to Correct Personal Information</title>
		<link>http://www.privacysense.net/requests-correct-personal-information/</link>
		<comments>http://www.privacysense.net/requests-correct-personal-information/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 04:37:05 +0000</pubDate>
		<dc:creator>M. G.</dc:creator>
				<category><![CDATA[Privacy Officers]]></category>

		<guid isPermaLink="false">http://www.privacysense.net/?p=2144</guid>
		<description><![CDATA[An individual should expect that the information your organization has collected is complete, factual, and current. If an individual requests records of his/her personal information and believes that it is not, a request can be made to have your organization correct it.]]></description>
			<content:encoded><![CDATA[<p>In addition to responding to <a href="/personal-information-access-requests/">personal information access requests</a> a privacy officer will also need to respond to <strong>requests to correct personal information</strong>.</p>
<p>An individual should expect that the information your organization has collected is complete, factual, and current. If an individual requests records of his/her personal information and believes that it is not, a request can be made to have your organization correct it.</p>
<p>If your organization corrects any errors or omissions it should, whenever appropriate, notify all other organizations to which the individual&#8217;s personal information was originally disclosed.</p>
<p>If there are no errors or omissions the organization should annotate the individual&#8217;s file with the unsuccessful request.</p>
<hr />
<p><small>Copyright © 2009 <a href="http://www.privacysense.net">PrivacySense.net</a>. |
<a href="http://www.privacysense.net/requests-correct-personal-information/">Permalink</a> |
<a href="http://www.privacysense.net/requests-correct-personal-information/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.privacysense.net/requests-correct-personal-information/&title=Requests to Correct Personal Information">del.icio.us</a>
<br/>
Tags: <br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.privacysense.net/requests-correct-personal-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Responding to Personal Information Access Requests</title>
		<link>http://www.privacysense.net/personal-information-access-requests/</link>
		<comments>http://www.privacysense.net/personal-information-access-requests/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 02:17:31 +0000</pubDate>
		<dc:creator>M. G.</dc:creator>
				<category><![CDATA[Privacy Officers]]></category>
		<category><![CDATA[Personal Information]]></category>

		<guid isPermaLink="false">http://www.privacysense.net/?p=2129</guid>
		<description><![CDATA[A personal information access request allows an individual the right to view or obtain a copy of some types of personal information that your organization has collected. ]]></description>
			<content:encoded><![CDATA[<p>One of a privacy officer&#8217;s main responsibilities is to respond to personal information access requests. </p>
<p>A <strong>personal information access request</strong> allows an individual the right to view or obtain a copy of some types of <a href="/personal-information/">personal information</a> that your organization has collected. Before releasing personal information, it is important to verify the identity of the individual and only charge nominal fees whenever acceptable.</p>
<h2>Policies and Procedures</h2>
<p>Your organization may already have policies and procedures in place to ensure that personal information access requests are dealt with appropriately. If not, it will be your privacy officer&#8217;s responsibility to create and follow them in accordance with privacy legislation. </p>
<h2>Verifying an Individual&#8217;s Identity</h2>
<p>It is important to have strong identity verification procedures before releasing personal information. Releasing personal information to the wrong individual is a privacy breach and can cause dire consequences for your organization.</p>
<p>It is important to follow industry best practices <em>at a bare minimum</em> when releasing personal information, especially if it sensitive. </p>
<p>Personal information usually used for verification purposes (e.g. name, date of birth, address, maiden name, SIN/SSN number) can usually be obtained easily. Your organization should show due diligence verifying an individual&#8217;s identity in relation to the sensitivity of personal information being released. </p>
<h2>Fees</h2>
<p>Depending on the scope and time required to produce personal information, your organization may choose to charge individuals for an access request.</p>
<p>Some legislation &mdash; such as Canada&#8217;s PIPEDA &mdash; suggests that fees must be minimal or at no cost to the individual making the request. An organization cannot use fees as a way to make profit. </p>
<p>It is important to consult privacy legislation or any available regulations when deciding to charge fees for access requests.</p>
<hr />
<p><small>Copyright © 2009 <a href="http://www.privacysense.net">PrivacySense.net</a>. |
<a href="http://www.privacysense.net/personal-information-access-requests/">Permalink</a> |
<a href="http://www.privacysense.net/personal-information-access-requests/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.privacysense.net/personal-information-access-requests/&title=Responding to Personal Information Access Requests">del.icio.us</a>
<br/>
Tags: <a href="http://www.privacysense.net/tag/personal-information/" rel="tag">Personal Information</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.privacysense.net/personal-information-access-requests/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Introductory and Refresher Privacy Training</title>
		<link>http://www.privacysense.net/introductory-refresher-privacy-training/</link>
		<comments>http://www.privacysense.net/introductory-refresher-privacy-training/#comments</comments>
		<pubDate>Sat, 11 Jul 2009 04:16:26 +0000</pubDate>
		<dc:creator>M. G.</dc:creator>
				<category><![CDATA[Privacy Officers]]></category>
		<category><![CDATA[Privacy Training]]></category>

		<guid isPermaLink="false">http://www.privacysense.net/?p=2118</guid>
		<description><![CDATA[Whenever your organization hires any new staff, such as a general employee, volunteer, or contractor, a privacy officer will usually be responsible for conducting, monitoring, or performing introductory and refresher privacy training.]]></description>
			<content:encoded><![CDATA[<p>Whenever your organization hires any new staff, such as a general employee, volunteer, or contractor, a privacy officer will usually be responsible for conducting, monitoring, or performing introductory and refresher privacy training. Privacy training is vital to ensuring your organization&#8217;s overall compliance with privacy legislation.</p>
<p>During introductory privacy training a privacy officer will usually explain:</p>
<ul>
<li>Who the privacy officers in the organization are</li>
<li>How and when to contact a privacy officer</li>
<li>How to protect <a href="/personal-information/">personal information</a> and reduce the risk of a privacy breach</li>
<li>The organization&#8217;s privacy policy and where to find it</li>
<li>The organization&#8217;s policies and procedures with respect to the collection, usage, and disclosure of personal information (e.g. What personal information does the organization collect? Why? By what methods?)</li>
<li>How to answer general inquiries about the collection, usage, and disclosure of personal information and when to recognize and direct inquiries to a privacy officer</li>
</ul>
<p>In addition, a privacy officer will usually be responsible for providing ongoing privacy training to all staff members. This can be done in the form of meetings, presentations, or training documents.</p>
<hr />
<p><small>Copyright © 2009 <a href="http://www.privacysense.net">PrivacySense.net</a>. |
<a href="http://www.privacysense.net/introductory-refresher-privacy-training/">Permalink</a> |
<a href="http://www.privacysense.net/introductory-refresher-privacy-training/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.privacysense.net/introductory-refresher-privacy-training/&title=Introductory and Refresher Privacy Training">del.icio.us</a>
<br/>
Tags: <br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.privacysense.net/introductory-refresher-privacy-training/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Importance of Understanding Privacy Legislation</title>
		<link>http://www.privacysense.net/importance-understanding-privacy-legislation/</link>
		<comments>http://www.privacysense.net/importance-understanding-privacy-legislation/#comments</comments>
		<pubDate>Thu, 21 May 2009 02:50:27 +0000</pubDate>
		<dc:creator>M. G.</dc:creator>
				<category><![CDATA[Privacy Legislation]]></category>
		<category><![CDATA[Privacy Training]]></category>

		<guid isPermaLink="false">http://www.privacysense.net/?p=2065</guid>
		<description><![CDATA[This can seem like a daunting task for new privacy officers, especially if the role of the privacy officer is new in your organization and there is no ...]]></description>
			<content:encoded><![CDATA[<p>As a privacy officer in your organization it is your responsibility to ensure organizational compliance with privacy legislation. </p>
<p>This means that you should have a thorough understanding of which privacy legislation applies to your organization and how it applies. Not only that, but you should also understand what privacy legislation applies to your key stakeholders, including your suppliers, service providers and clients.
<div style="float: right">
<div class="ds1">
<div class="ds2"><img src="/wp-content/uploads/2009/05/privacylegislation.jpg" alt="privacy legislation" title="privacy legislation" width="175" height="131"  /></div>
</div>
</div>
<p>This can seem like a daunting task for new privacy officers, especially if the role of the privacy officer is new in your organization and there is no training material to help you get started.</p>
<p>Depending on the privacy legislation that applies to your organization, there may already be free privacy resources online that can help your organization with compliance. For example, <a href="http://www.priv.gc.ca/">The Office of the Privacy Commissioner of Canada</a>, UK&#8217;s <a href="http://www.ico.gov.uk/">Information Commissioner&#8217;s Office</a>, and <a href="http://www.privacysense.net">PrivacySense</a> all offer free privacy resources.</p>
<p>But while these resources are helpful for summarizing key points of privacy legislation, it does not mean you can avoid reading privacy legislation in full. On the contrary, because you are responsible and accountable for privacy compliance within your organization, it is to your benefit to read and understand privacy legislation line-by-line. After all — it&#8217;s your job!</p>
<h2>Know What Privacy Legislation Applies to Your Organization</h2>
<p>Depending on your organization&#8217;s line of business, where it is located, whether it operates in the <a href="/difference-between-private-public-sector/">private or public sector</a> and its flow of personal information, different privacy legislation may apply. With some basic online research you should be able to quickly find out what privacy legislation applies to your organization.</p>
<p>If your organization has a wide geographic presence, multiple offices around the world, or collects, uses, or discloses <a href="/personal-information/">personal information</a> across borders, it may be subject to different pieces of privacy legislation. In these more difficult scenarios, it may be wise to consult with a privacy lawyer.</p>
<h2>Know What Privacy Legislation Applies to Your Key Stakeholders</h2>
<p>In addition to understanding what privacy legislation applies to your organization, it is also equally important to understand what privacy legislation applies to your key stakeholders, including your suppliers, service providers and clients.</p>
<h3>Your Suppliers</h3>
<p>If your suppliers transfer personal information to your organization, you may be required to sign a contract agreeing to provide a comparable level of privacy protection or dispose of the personal information after a certain time period. You should not be caught off guard.</p>
<h3>Your Service Providers</h3>
<p>If you transfer personal information to a third party service provider, most privacy legislation will require that your provider have a comparable level of privacy protection. </p>
<p>Your organization can be fully compliant and have a top-notch privacy policy but transferring personal information to a service provider without adequate privacy protection undoes all your efforts and can also make your organization <a href="/personal-information-organizations-liability/">liable for personal information</a> in the event of a privacy breach.</p>
<h3>Your Clients</h3>
<p>If your clients entrust you with personal information, many will require proof that your organization is compliant with privacy legislation. A privacy policy or evidence of other policies and procedures may be required.</p>
<p>Furthermore, some of your clients may be governed by different privacy legislation that can impose certain obligations on your organization. </p>
<p>As a privacy officer, it is your responsibility to be knowledgeable and answer any client inquiries that may come your way. Understanding your clients&#8217; privacy legislation, at least on a basic level, will let your clients know that your organization is serious about privacy.</p>
<h2>How to Understand Privacy Legislation</h2>
<p>Now that you understand the importance of knowing what privacy legislation applies to your organization and its key stakeholders, it&#8217;s time to finally read it.</p>
<p>Privacy legislation can be found online by doing a simple Google search or by visiting the website of the privacy authority if one exists in your geographic area. For example, you can Google for Canada&#8217;s <a href="http://www.google.ca/search?q=pipeda">PIPEDA</a> or UK&#8217;s <a href="http://www.google.ca/search?q=data+protection+act">Data Protection Act</a>.</p>
<p>Start by printing out the privacy legislation — you will want a hard-copy to store later for easy access. Grab a highlighter, a pen, and start going through legislation slowly, highlighting relevant sections, making notes, and ensuring you understand everything.</p>
<p>After going through the legislation you may realize that your organization is not compliant in certain areas. As a privacy officer, it is your responsibility to look into any areas of non-compliance, document them, and work towards total organizational compliance.</p>
<p>Whenever possible, supplement your reading with online privacy resources such as those available at <a href="http://www.privacysense.net">PrivacySense</a> and other websites specific to your industry. This will help reinforce both your learning and memory retention.</p>
<p>As months pass, you may find that details from your memory slip. Review legislation, your notes, and online privacy resources whenever possible to ensure that your knowledge and proficiency does not fade away with time.	</p>
<hr />
<p><small>Copyright © 2009 <a href="http://www.privacysense.net">PrivacySense.net</a>. |
<a href="http://www.privacysense.net/importance-understanding-privacy-legislation/">Permalink</a> |
<a href="http://www.privacysense.net/importance-understanding-privacy-legislation/#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.privacysense.net/importance-understanding-privacy-legislation/&title=The Importance of Understanding Privacy Legislation">del.icio.us</a>
<br/>
Tags: <br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.privacysense.net/importance-understanding-privacy-legislation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
