Your responsibilities as an executive
You are responsible by default
The person with the highest authority in the organization ensures the protection of personal information and acts as the RPRP (s. 3.1). You may delegate the role in writing, but the delegation must be real: the delegate has the time, access and support needed.
What you must do
| Obligation | In practice |
|---|---|
| Designate the RPRP | Name, written mandate, title and contact details published on the website |
| Adopt governance policies | Written in plain language, published and kept current (s. 3.2) |
| Provide a complaints process | Contact point, deadlines, follow-up |
| Keep an incident register | See crisis management |
| Require PIAs | For new projects and transfers outside Québec |
Why this is a leadership topic: penalties target the organization, and the CAI looks at governance, not only at technology.
Questions to ask your team
- Who is our RPRP, and is it published?
- What are our 5 main sets of personal information, and where are they?
- Do we have an incident register and a tested escalation plan?
- Which suppliers receive personal information?