Privacy protocol for non-administrative purposes

Last update: February 2025

Purpose

This privacy protocol outlines the policies and procedures that National Film Board of Canada (NFB) will follow to ensure the protection of personal information for non-administrative purposes in our possession or control. This protocol applies to all employees, contractors, and third-party service providers who may have access to personal information in the course of their work for NFB.

Definition of Personal Information

For the purposes of this protocol, personal information refers to any information relating to an identified or identifiable individual, including but not limited to name, address, email address, phone number, date of birth, social security number, financial information, and health information.

Collection and Use of Personal Information

NFB will collect, use, and disclose personal information only for purposes that are necessary, reasonable, and consented to by the individual to whom this information relates. We will take appropriate measures to ensure that personal data is accurate, complete, and up to date.

Access Controls

NFB will implement access controls to ensure that personal information is accessible only to authorized individuals on a need-to-know basis. Access controls will include the use of strong passwords, multi-factor authentication, and permission-based access to data.

Encryption and Anonymization

NFB will use encryption and anonymization techniques to protect personal data in our possession or control. We will ensure that personal data is encrypted during transmission and at rest, and that any data that is anonymized cannot be re-identified.

Data Minimization

NFB will practice data minimization by limiting the collection and retention of personal information to only what is necessary for a particular purpose. We will regularly review and delete personal data that is no longer necessary for the purposes for which it was collected (the NFB Information Classification Plan with Retention Schedule).

Privacy Policies

NFB will provide clear and transparent privacy policies that outline how personal information is collected, used, and protected. We will ensure that individuals are informed of their rights regarding their personal data, including the right to access, correct, and delete their data.

Data Protection Training

NFB will provide training to employees on how to handle personal data, how to spot and report breaches, and how to adhere to this privacy protocol.Breach NotificationIn the event of a breach of personal information, NFB will notify affected individuals and any relevant regulatory authorities. We will take appropriate steps to mitigate the effects of the breach and to prevent future breaches.

Review and Update

NFB will regularly review and update this privacy protocol to ensure that it remains effective in protecting the privacy of individuals.

Page details

2025-03-21