CHINOOK CREDIT UNION LTD.

Section 2000: CORPORATE GOVERNANCE

Policy 2003: PRIVACY & CONFIDENTIALITY OF MEMBER INFORMATION

Original Approval Date: October 2002, Revision #: 1 Date: November 2003

Contact Privacy Officer : Email


PURPOSE

To protect the interests of those who do business with the Credit Union from any unauthorized use of personal information, which members have made available in the course of conducting their business with the Credit Union.

POLICY STATEMENTS

  1. The Credit Union enforces strict compliance with the confidentiality requirements of its standards of professional conduct policy.
  2. In addition, the Credit Union subscribes to the Code for the Protection of Personal Information as adopted by the Board of Directors (November 2003) for the privacy, protection and confidentiality of member information:

RESPONSIBILITY

  1. Ultimate accountability for the Credit Union's compliance with the policy statements rests with the Credit Union's Board of Directors.
  2. Management, through the Privacy Officer, is responsible for the day to day accountability, implementation of, and compliance with this policy, including, but not limited to:
    1. ensuring policy and procedures remain relevant;
    2. on-going compliance monitoring;
    3. on-going staff training and mentoring;
    4. on-going member communication;
    5. complaints processing and dispute resolution;
    6. required reporting;
    7. review of Service Provider and third party contracts
    8. review of Credit Union facilities and other access points such as data systems, computers, internet, and waste disposal
    9. recommend changes to policy.
  3. The Board will review this policy at least annually at the meeting at which compliance observations are reported by management.
  4. Nothing in this policy is intended to prohibit the proper and responsible use of information given with consent, for the purposes of enhancing services or delivering services to members. This policy does not diminish the Credit Union's need to make fully informed decisions about the services it provides or persons to whom services may be provided. This policy does not authorize the taking of any business risks without all information needed to support prudent decisions.

MONITORING AND REPORTING

  1. The Privacy Officer will maintain a record of any member complaints and the resolution of such complaints.
  2. The Privacy Officer will report to Management any concerns relating to compliance of the Code principles or policies, and if necessary, such issues may be forwarded on to the Board.
  3. On a frequency no less than annual, Management, through the Privacy Officer, will report to the Board on compliance with this policy.

Chinook Credit Union Ltd.
Code for the Protection of Personal Information


1. Accountability


The Credit Union is accountable for all personal information in their control. The Credit Union will designate one or more persons to be accountable for compliance with this privacy code.

1.1 Ultimate accountability for the Credit Unions compliance with the principles rests with the Chinook Credit Union Ltd. Board of Directors, who delegates day-to-day accountability to a Privacy Officer. Other persons within the Credit Union may be accountable for the day-to-day collection and processing of personal information, or to act on behalf of the designated individual.

1.2 The Credit Union will identify to staff and to members the person (persons) who is (are) responsible for the day-to-day procedures of compliance (see also 8.2).

1.3 The Credit Union accepts responsibility for personal information that has been disclosed to a third party in order to deliver a product or service. The Credit Union will safeguard the privacy of this personal information through a contract or other means with the third party.

1.4 To practice the principles of this privacy code, the Credit Union will:


2. Identifying Purposes


The Credit Union will identify the purposes of collecting personal information, before or when the member provides it.

2.1 The Credit Union will document the purposes for which personal information is collected prior to the information being collected.

2.2 The Credit Union will ensure that the member information is readily available to the member (see 2.4) disclosing the purposes for which personal information is collected, including use by third parties.

2.3 The Credit Union will collect and use personal information for the following purposes:

2.4 The identified purpose should be communicated directly to the member from whom personal information is being collected. This can be done orally, electronically, or in writing.

2.5 When personal information that has been collected is to be used for a purpose not previously identified, the new purpose shall be identified and the member's consent will be received before the information is used. If the new use is required by law the member's consent will not be required.


3. Consent


The knowledge and consent of the member is required for the collection, use, or disclosure of personal information except where inappropriate.

Note: In certain circumstances personal information may be collected, used, or disclosed without the knowledge or consent of the Member. These circumstances include, but are not limited to:

3.1 At the time the Credit Union collects personal information, the member's consent will be required before or when the personal information is collected, used, or disclosed.

Sometimes, the Credit Union may seek consent to use and disclose personal information after it has been collected. This can happen when the Credit Union wants to use the information for a purpose that was not previously identified to the member.

The Credit Union may choose to collect, use, or disclose personal information without the member's consent for the collection of overdue accounts, legal or security reasons.

3.2 The Credit Union will make a reasonable effort to communicate the purpose for collecting, using and disclosing information in a clear and understandable way so as not to deceive. The Credit Union will explain to members how personal information will be used or disclosed before consent is received.

3.3 The Credit Union may not, as a condition of the supply of a product or service, require a member to consent to the collection, use, or disclosure of information beyond that required to fulfill explicitly specified and legitimate purposes.

3.4 In determining the form of consent to use, the Credit Union will take into account the sensitivity of the information. Although some information (for example, medical and financial records) is almost always considered to be sensitive, any information can be sensitive depending on the context.

Members can give consent:

in writing, such as when completing and signing an application;

3.5 The Credit Union may collect, use, or disclose personal information without the knowledge and consent of the member when legal, security, or certain processing reasons make it impossible or impractical to get this consent.

For example:

3.6 Subject to legal and contractual restrictions on the Credit Union, members can withdraw consent to the use or disclosure of information for a particular purpose at any time as long as:


4. Limiting Collection


The Credit Union will limit the amount and type of personal information that is collected to the purposes already identified to the member. The Credit Union will collect personal information using procedures that are fair and lawful.

4.1 The Credit Union will collect only the amount and type of information needed for the purposes identified to the member, in accordance with the Credit Union's policies and procedures.

4.2 The Credit Union will collect personal information by fair and lawful means, and not by misleading or deceiving members about the purpose for which information is being collected.


5. Limiting Use, Disclosure, and Retention


The Credit Union will use or disclose personal information only for the purposes it was collected, unless a member gives consent to use or disclose it for another purpose or as required by law.

The Credit Union will keep personal information only as long as necessary for the identified purposes or as required by law.

5.1 The Credit Union may disclose personal information without consent when required by law. For example:

5.2 In these circumstances, the Credit Union will protect the interests of members by taking precautionary steps to ensure that:

The Credit Union may notify members that an order has been received, if the law allows it. (Notification may be by telephone or by letter to the member's address on file or any other means that the Credit Union deems appropriate in the given circumstance).

5.3 Health records will only be collected to verify authority of trust representatives (account Management), for credit application purposes and credit related insurance sales. Health records will not be disclosed to, or received from any other unrelated organization.

5.4 Credit Union policies and procedures will specify the shortest and longest periods of time it will keep personal information. Some of these time periods may be determined by legislation. If personal information has been used to make a decision about a member, the personal information will be kept long enough for the member to have access to it after the decision has been made.

5.5 The Credit Union will destroy, erase, or make anonymous any personal information no longer needed for its identified purposes or for legal requirements. The Credit Union will develop guidelines and implement procedures to govern the destruction of personal information.


6. Accuracy


The Credit Union will keep personal information as accurate, complete, and up-to-date as necessary for the purposes for which it is to be used.

6.1 The extent to which personal information will be accurate, complete, and up-to-date will depend upon the use of the information taking into account the interests of the member. The Credit Union will rely on the member to keep certain personal information accurate, complete and current, such as name and address.

6.2 The Credit Union will not routinely/automatically update personal information unless updating is necessary for the purposes for which the information is used.

6.3 Personal information that is used on an ongoing basis, including information that is disclosed to third parties, will generally be accurate and up-to-date.


7. Safeguard Personal Information


The Credit Union will protect member's personal information with safeguards appropriate to the sensitivity of the information.

7.1 The Credit Union will safeguard personal information from loss or theft and from unauthorized access, disclosure, copying, use or modification. Appropriate safeguards will be applied regardless of the format in which that information is held.

7.2 Credit Union safeguards will vary depending on the sensitivity, amount, distribution, format, and storage of the personal information. The highest level of protection will be given to the most sensitive personal information.

7.3 Personal information will be safeguarded through appropriate security measures. For example:

7.4 Employees, directors and officers will be regularly informed about the Credit Union's policies and procedures for protecting member personal information and will emphasize the importance of complying with them. Employees and directors will be required to sign an oath of ethical conduct annually including commitment to keep member's personal information in strict confidence.

7.5 The Credit Union may disclose personal information to third parties for example; printing cheques, data processing services, collection, credit bureau reports, or for the supply of other goods and services. The Credit Union will require that these third parties safeguard all personal information in a way that is consistent with safeguards the Credit Union would apply to personal information in their control.

7.6 The Credit Union will use care when disposing of, or destroying personal information, to prevent unauthorized access to the information.


8. Openness


The Credit Union will make the policies and procedures used to manage personal information readily available.

8.1 The Credit Union will make available to members information about the policies and procedures used to protect privacy in accordance with this code. The Credit Union will make available copies of this privacy code.

8.2 The privacy information made available will include:

8.3 The Credit Union may make information about its privacy policies and procedures available in a variety of ways, depending on the nature of the service members are using and the sensitivity of the personal information. For example, a Credit Union may make brochures available in its branches, mail information to its members, establish a toll-free telephone service, or provide on-line access.


9. Individual Access


When members request it, the Credit Union will tell them what personal information the Credit Union has, what it is being used for, and to whom it has been disclosed.

Members may challenge the accuracy and completeness of personal information in the Credit Union's control and have it amended as appropriate.

When members request it, the Credit Union will give them access to theirpersonal information.

Note: Exceptions to the access requirement will be limited and specific.

9.1 A member has the right to know, by request, what personal information the Credit Union has in its control and to obtain access to that information.

9.2 Members may be requested to assist the Credit Union in locating information by providing information required for the search. Information provided will only be used for the purpose of assisting in a search.

9.3 The Credit Union will be as specific as possible in identifying the type of information and the identity of third parties to which information has been disclosed including a list of organizations that may receive personal information.

9.4 The Credit Union will respond to member requests within a reasonable time. The information will be made available at a cost that will vary with the type and amount of information requested. The requested information shall be provided or made available in a form that is easy to understand. For example, if the Credit Union uses abbreviations or codes to record information, an explanation will be provided.

9.5 In some cases, the Credit Union may not be able to provide the personal information that is in its control. Each Credit Union will seek to limit these cases, and make them specific in policies and procedures. For example, some personal information may not be provided, or not provided in full, because:

9.6 When a member successfully demonstrates the inaccuracy or incompleteness of personal information, the Credit Union shall amend the information as required. Depending upon the nature of the information challenged, amendment involves the correction, deletion, or addition of information. Where appropriate, the amended information shall be forwarded to third parties having access to the information in question.

9.7 If the Credit Union denies the member's request for access to personal information, the member must be told why. The member may then question the decision under the procedures in this privacy code. When a challenge is not resolved to the satisfaction of the member, the substance of the unresolved challenge will be recorded by the Credit Union. When appropriate, the existence of the unresolved challenge will be transmitted to third parties having access to the information in question.


10. Compliance


Members are welcome to question the Credit Union concerning compliance with this privacy code. The Credit Union will have policies and procedures for responding to member questions.

10.1 The Credit Union will have policies and procedures to receive, investigate, and respond to member's questions and concerns relating to personal information.

The process will be easily accessible and simple to use.

It will be clear whom members must contact with a question or concern. The designated individual accountable for the Credit Union's compliance will be known to staff and identified to the membership periodically.

10.2 All members will have the right to take concerns that are not satisfactorily resolved to the Board for final arbitration. The Credit Union will inform members who make inquiries or lodge complaints of the existence of relevant complaint mechanisms.

10.3 The Credit Union will investigate all concerns. If the Credit Union finds a concern justified, the Credit Union will have an appropriate resolve, including changing policies and procedures to ensure other members will not experience the same situation.

If You have any questions about the policy, please contact our privacy officer by clicking here.

Back to Top

		
Click Here for a demo
of our new banking system.