Your responsibilities as an executive

You are responsible by default

The person with the highest authority in the organization ensures the protection of personal information and acts as the RPRP (s. 3.1). You may delegate the role in writing, but the delegation must be real: the delegate has the time, access and support needed.

What you must do

Obligation In practice
Designate the RPRP Name, written mandate, title and contact details published on the website
Adopt governance policies Written in plain language, published and kept current (s. 3.2)
Provide a complaints process Contact point, deadlines, follow-up
Keep an incident register See crisis management
Require PIAs For new projects and transfers outside Québec

Why this is a leadership topic: penalties target the organization, and the CAI looks at governance, not only at technology.

Questions to ask your team

  1. Who is our RPRP, and is it published?
  2. What are our 5 main sets of personal information, and where are they?
  3. Do we have an incident register and a tested escalation plan?
  4. Which suppliers receive personal information?