Management Response and Action Plan – Privacy Impact Assessment of the Lobbyist Registration System
December 2020
Background
In December of 2019, the Office of the Commissioner of Lobbying (OCL) retained the services of Maxsys Staffing & Consulting to conduct a Privacy Impact Assessment (PIA) of the Lobbyist Registration System (LRS).
Objective
The objective of this document is to present the management response and action plan based on the recommendations made in the PIA of the LRS.
Recommendation #1
Develop and display a context specific notice for the LRS.
Action | Responsible official | Target completion date |
---|---|---|
Develop and deploy a context-specific notice for the LRS. | Director, Corporate Services | March 31, 2021 |
Recommendation #2
Apply retention and disposition to the LRS.
Action | Responsible official | Target completion date |
---|---|---|
1. Review the disposition authority and the retention periods related to registrations and the Monthly Communication Reports in the LRS. | Director, Corporate Services | March 31, 2022 |
2. Apply, if needed, the dispositions to the LRS. | March 31, 2023 |
Recommendation #3
Develop a privacy practice for the non-administrative use of the data collected in the LRS (Example, statistical reports) in accordance with TBS Policy on Privacy Protection.
Action | Responsible official | Target completion date |
---|---|---|
All information in the LRS is collected in compliance with the Lobbying Act, which requires that the Registry be made public and accessible to all Canadians. The OCL does not use information collected in the LRS for non-administrative purposes. It only produces statistical reports based on the information obtained as per the Act requirements. |
Director, Corporate Services | Not applicable |
Recommendation #4
Complete a Threat and Risk Assessment and develop a Statement of Sensitivity for the LRS.
Action | Responsible official | Target completion date |
---|---|---|
Complete a Threat and Risk Assessment and develop a Statement of Sensitivity for the LRS. | Director, Corporate Services | Completed April 30, 2020 |
Recommendation #5
Provide privacy training as part of the OCL’s regular security awareness briefings.
Action | Responsible official | Target completion date |
---|---|---|
Provide, to all OCL staff, privacy awareness training during the OCL’s security awareness training. | Director, Corporate Services | ongoing |
Approval
The Management Response and Action Plan was approved by the members of the Executive Management Committee on December 3rd, 2020.
- Date modified: