APPENDIX I
TEN PRINCIPLES OF PRIVACY PROTECTION
- Be accountable
Establish policies and responsibilities
- Identify Purposes
Explain why information is collected and used
- Obtain consent
for information collection, use and disclosure
- Limit collection
Only gather information required for identified purposes
- Limit use, disclosure and retention
Destroy data when no longer required
- Ensure Accuracy
Keep frequently use information up-to-date
- Safeguard security
Keep sensitive information secure, control access
- Be open
Communicate policies and practices
- Provide access
Enable member/employee access to their records
- Challenge Compliance
Invite feedback, quickly investigate and resolve complaints