Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

When users upload a CSV of recipients we need to warn them that they must be allowed to use the email for this express purpose in order to be compliant with the Privacy Act #26

Closed
willeybryan opened this issue Jun 27, 2019 · 7 comments
Labels
Ideate wontfix This will not be worked on

Comments

@willeybryan
Copy link
Contributor

willeybryan commented Jun 27, 2019

What?

  • https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-privacy-act/
  • We need a warning message on the page that states users must be compliant with the privacy acts rules around Fair use of the emails of numbers they are uploading
  • We need to figure out how the privacy act applies to SMS and Email notifications and write elements to put in the UI
  • Figure out where in the UI we need them

Why?

  • Legal Requirement
@willeybryan willeybryan transferred this issue from another repository Jul 3, 2019
@willeybryan willeybryan added this to the Discovery 1 milestone Jul 3, 2019
@obrien-j
Copy link

obrien-j commented Jul 8, 2019

Do you have a link to the specific legislative requirement on this?

@YedidaZalik
Copy link

YedidaZalik commented Jul 8, 2019 via email

@willeybryan
Copy link
Contributor Author

https://laws-lois.justice.gc.ca/eng/acts/P-21/page-1.html#h-397235

4 No personal information shall be collected by a government institution unless it relates directly to an operating program or activity of the institution.

(2) A government institution shall inform any individual from whom the institution collects personal information about the individual of the purpose for which the information is being collected.

https://laws-lois.justice.gc.ca/eng/acts/P-21/page-2.html#h-397260

Personal information under the control of a government institution shall not, without the consent of the individual to whom it relates, be used by the institution except

(a) for the purpose for which the information was obtained or compiled by the institution or for a use consistent with that purpose

Any personal information that may be collected is described in the Standard Personal Information Bank entitled Outreach Activities, PSU 938, which can be found in the TBS webpage Information about programs and information holdings.

https://www.canada.ca/en/treasury-board-secretariat/services/access-information-privacy/access-information/information-about-programs-information-holdings/standard-personal-information-banks.html#psu938

https://www.canada.ca/en/treasury-board-secretariat/services/access-information-privacy/access-information/information-about-programs-information-holdings/standard-classes-records.html#prn904

@timarney
Copy link
Member

Any traction on this?

i.e. we need to add X text in a warning box to the UI on page X

@willeybryan
Copy link
Contributor Author

We have some more work to do on this.

@YedidaZalik and @sboots need to have a meeting with TBS privacy and Legal. The current blocker is setting up the meeting.

I don't think we need to get this done this sprint, we can push it back to Alpha.

@willeybryan willeybryan modified the milestones: Discovery 1, Alpha 1 Jul 17, 2019
@willeybryan
Copy link
Contributor Author

I am putting this in discovery to figure out meeting, what we need to write, getting that translated. Then we can integrate in Alpha.

@willeybryan
Copy link
Contributor Author

Still waiting on meeting with TBS Lawyer/Privacy peeps, Pushing this out

@willeybryan willeybryan modified the milestones: Discovery 2, Alpha 2 Jul 30, 2019
@willeybryan willeybryan removed this from the Alpha 2 milestone Aug 27, 2019
@willeybryan willeybryan added the wontfix This will not be worked on label Aug 28, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Ideate wontfix This will not be worked on
Projects
None yet
Development

No branches or pull requests

4 participants