CTA Management Action Plan on Protection of Personal Information

Please develop a detailed management action plan with actions that are specific, measurable, attainable, relevant and timely Management Action Plans will be tabled at the Small Department Audit Committee with the Final Report.

Audit RecommendationManagement ActionArea ResponsibleExpected Completion Date

 

Departments should ensure that PIAs are considered and conducted appropriately when developing new, or substantially modified, programs and activities

  • CTA ATIP division is developing "PIA Basics" information to be posted on the Intranet.
  • Tools for PIA are under development for employees such as Privacy Impact Questionnaire for Programs to determine if PIA is required, Roadmap/Guide to completing PIA and PIA requirements checklist.
  • CTA is currently undertaking a PIA on the Agency's new online forms for dispute resolution processes. 
  • CTA is planning a PIA for the Shared Case Management System for 2014-2015. 

CTA Programs & ATIP

Sep 30, 2014

Mar 31, 2015

May 2, 2014

Mar 31, 2015

Departments should ensure that privacy notices comply with the Directive on Privacy Practices and the Directive on Social Insurance Number

  • Privacy notices and Personal Information Collection Statements are being revised to comply with Directive on Privacy Practices and the Standard on Web Usability.  This work is being conducted as part of the launch of new online forms for dispute resolution processes. 

ATIP & Communications

May 2, 2014

Date modified: