Data Privacy Policy (Law 25)
Introduction
This policy governs the collection, use, communication, retention, and destruction of personal information within St. Patrick Development Foundation (SPDF). It is created and published in compliance with the Act respecting the protection of personal information in the private sector (Law 25).
Scope
This policy applies to all personal information collected, held, used, or communicated by SPDF during its activities, whether in written, graphic, sound, visual, computerized, or other forms. It concerns all staff, members of the Board of Directors, members, volunteers, and any organization or person acting on behalf of the organization.
Definitions
- Personal Information: Any information that concerns a natural person and allows them to be identified, directly or indirectly. This includes, but is not limited to, name, address, date of birth, contact details, financial information, health information, etc.
- Confidentiality Incident: Any unauthorized access to, unauthorized use of, or unauthorized disclosure of personal information; the loss of personal information or any other breach of the protection of such
Guiding Principles
1. Accountability
SPDF protects the personal information it holds. The board appoints a Data Privacy Officer (DPO) as the Person Responsible for Personal Information Protection. The DPO is responsible for managing compliance, answering privacy inquiries, and addressing complaints
The DPO is Paul Higgins, the designated member of the Board of Directors (dataprivacy@spsquare.ca, mailing address: St. Patrick Square, 6767 Côte-St-Luc Rd., Suite 1, Côte-St-Luc, QC H4V 2Z6).
In accordance with Law 25, the DPO is responsible for specific statutory tasks:
- Policy & Governance Approval: Draft, review, and approve the Corporation’s internal data governance policies, retention schedules, and public-facing privacy notices prior to operational deployment.
- Privacy Impact Assessments (PIAs): Conduct and oversee Privacy Impact Assessments as required by law prior to the acquisition, development, or overhaul of any electronic system involving personal information, or prior to any cross-border data transfer.
- Confidentiality Incident Oversight & Breach Register: Evaluate all suspected security or privacy breaches to assess whether they present a “risk of serious injury” to individuals.
Issue mandatory breach notifications to the Commission d’accès à l’information (CAI) and affected individuals when legally required.
Maintain and regularly update the Corporation’s internal Register of Confidentiality Incidents.
- Management of Individual Rights Requests: Handle and respond to all formal written requests from tenants, applicants, board members or employees regarding access to personal information, correction of files, withdrawal of consent, and data portability within statutory deadlines (30 days).
- Mandatory Public Transparency: Ensure that their title and contact information (specifically a dedicated organizational email address and physical office address) are properly published on the Corporation’s website or displayed in an accessible location within the residence.
- Board Reporting: Deliver a reporting summary (no less than annually) to the Board of Directors regarding the Corporation’s privacy compliance status, policy updates, and any logged confidentiality incidents.
2. Collection of Personal Information
- Purpose: Personal information is collected only for purposes necessary for the organization’s mission, particularly for operating non-profit housing, resident file management, communication with members, supervision of staff, and compliance with legal requirements.
- Consent: The consent of the individual concerned is needed before the collection, use, or communication of their personal information, except as provided by law. Consent must be free, informed, and given for specific purposes.
- Minimization: Only personal information necessary for determined purposes is collected.
3. Use and Communication of Personal Information
- Limited Access: Access to personal information is limited to individuals within the organization whose duties require it.
- Communication: Personal information is only communicated to third parties with the consent of the individual concerned or if required by law. In case of communication outside Quebec, a privacy impact assessment will be conducted.
4. Retention and Destruction of Personal Information
- Duration: Personal information is kept only for the period necessary to achieve the purposes for which it was collected unless a longer retention period is needed or allowed by law.
- Security: Physical, technical, and administrative security measures are implemented to protect personal information against loss, theft, unauthorized access, disclosure, copying, use, or modification.
- Destruction: Personal information is securely destroyed once its retention is no longer necessary.
5. Rights of Concerned Individuals
Concerned individuals have the right to:
- Access and Rectification: Request access to their personal information and request its rectification if it is inaccurate, incomplete, or ambiguous.
- Withdrawal of Consent: Withdraw their consent to the collection, use, or communication of their personal information, subject to legal or contractual restrictions.
- Right to be Forgotten: Request the deletion of their personal information in certain circumstances.
6. Management of Confidentiality Incidents
In case of a confidentiality incident, SPDF shall:
- Take reasonable measures to reduce the risk of harm and prevent new incidents of the same nature from occurring.
- Notify the Commission d’accès à l’information (CAI) and the individuals concerned if the incident presents a risk of serious harm.
7. Training and Awareness
SPDF shall train and raise awareness among its staff and volunteers regarding the requirements of Law 25 and best practices in personal information protection.
Specific Provisions by Stakeholder Group
Residents
SPDF provides affordable housing to autonomous adults aged 55 and over and does not provide medical or food services. Attention is paid to:
- Sensitive Information: Collection and processing of health information, financial status, and family contacts are handled with the care and with adherence to consent requirements.
- Right to Access and Rectification: Procedures are in place to help residents’ requests to access or correct their personal information, ensuring these processes are user-friendly and accessible.
- Communication Preferences: Residents’ preferences are prioritized on how they receive information and how their personal data is used for internal communications or external services.
Employees and Volunteers
Employees and volunteers of SPDF have rights concerning their personal information under Law 25. SPDF shall:
- Purpose-Limited Collection: Collect only personal information necessary for employment, volunteer management, payroll, benefits, and legal obligations.
- Confidentiality Agreements: Ensure all employees and volunteers sign confidentiality agreements and are aware of their responsibilities under Law 25.
- Training: Provide training on personal information protection and the organization’s policies and procedures to all staff and volunteers.
- Access to Information: Upon request, grant employees and volunteers’ access to their personal information held by the organization and allow for rectification.
Suppliers and Partners
When engaging with third-party suppliers and partners who may process personal information on behalf of SPDF, the following requirements apply:
- Written Contracts: All agreements with suppliers and partners shall include clauses ensuring compliance with Law 25, specifying their obligations concerning the protection of personal information.
- Security Measures: Requiring suppliers to implement adequate security measures to protect personal information they handle.
- Limited Use: Ensuring that suppliers only use personal information for the purposes specified in the contract and do not keep it beyond the contract’s term.
- Privacy Impact Assessment (PIA): Conducting a PIA before sharing personal information with new suppliers or partners if data is transferred outside Quebec.
Policy Review
This policy will be reviewed annually to ensure its compliance with applicable laws and regulations and its adequacy with the organization’s practices.
Effective Date: September 17th, 2026
Last Revision: September 17th , 2026
Approved by: Paul Higgins, Data Privacy Officer
