12. An organization is updating its information security policies in order to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). What should this organization expect to be required to do under this legislation?
Answer: C
Securely dispose of personal identifiable information
Organizations must implement processes to securely dispose of personal identifiable information to comply with PIPEDA. This legislation emphasizes the importance of protecting personal data throughout its lifecycle, including its final disposal.
A) Compensate individuals for revenue from the sale of their information
This option is incorrect as PIPEDA does not require organizations to compensate individuals for revenue generated from their personal information. Instead, the act focuses on the protection and proper handling of personal data rather than financial remuneration for its use.
B) Disclose the software used to protect personal data
While transparency in data protection practices is important, PIPEDA does not mandate organizations to disclose the specific software they use to secure personal data. Organizations are required to implement adequate security measures, but the specific tools and technologies are not required to be publicly disclosed.
C) Securely dispose of personal identifiable information
This option is correct as PIPEDA explicitly requires organizations to securely dispose of personal identifiable information when it is no longer needed for the purposes for which it was collected. This helps ensure that personal data does not remain vulnerable to unauthorized access after its intended use has ended.
D) Notify individuals each time their personal information is viewed
This option is incorrect because PIPEDA does not require organizations to notify individuals every time their personal information is accessed. While organizations must inform individuals about the collection and use of their data, real-time notifications for each access event are not stipulated by the legislation.
Conclusion
The requirement to securely dispose of personal identifiable information is a critical aspect of PIPEDA, aimed at protecting individuals' privacy and ensuring data security. Other options presented either misinterpret the requirements of the legislation or focus on aspects that are not mandated, reinforcing that C is the only correct choice in this context.