Privacy laws are not a barrier to appropriate information sharing in a pandemic or emergency situation.
It is important that public bodies, health custodians and private sector organizations know how personal or health information may be shared during a pandemic or emergency situation.
Alberta has three privacy laws:
These Acts govern the collection, use and disclosure of personal or health information.
Each Act contains provisions to allow for the sharing of personal or health information in the event of an emergency.
All three Acts require that any collection, use or disclosure of personal information or health information be limited to that which is needed to achieve the purpose of the collection, use or disclosure.
The FOIP Act applies to “public bodies”, which include provincial government ministries and municipalities.
The FOIP Act permits public bodies to collect personal information if the collection is expressly authorized by an enactment (section 33(a)) or if the collection relates directly to and is necessary for an operating program or activity of the public body (section 33(c)). For example, a municipality may have a bylaw specifically authorizing the collection of personal information in emergency situations. As a bylaw is an “enactment”, the collection would be authorized under section 33(a). Section 33(c) would permit a municipality to collect personal information necessary for the management and delivery of its emergency services.
The FOIP Act generally requires public bodies to collect personal information directly from the individual the information is about. Public bodies may collect information about an individual from other sources with the individual’s consent, or without consent in specific circumstances, such as when the collection is authorized by law or the individual is not able to provide the information directly in a health or safety emergency (section 34(1)).
Public bodies may disclose personal information in emergency situations with the consent of the individual, or without consent in certain circumstances, including:
The HIA applies to health information in the custody or control of custodians. Custodians include Alberta Health, Alberta Health Services, Covenant Health, nursing homes, ambulance operators, physicians, pharmacists, registered nurses and certain other health professionals. The HIA authorizes custodians to collect and use health information for the purposes of providing health services.
The HIA allows custodians to disclose (Part 5) health information with the consent of the individual, or without consent in specific circumstances, including:
PIPA applies to personal information collected, used and disclosed by private sector organizations.
Organizations are required by PIPA to collect, use and disclose personal information only for purposes that are reasonable (sections 11, 16 and 19). The term “reasonable” means “what a reasonable person would consider appropriate in the circumstances” (section 2).
Except in limited, specific circumstances, PIPA requires organization have the individual’s consent when collecting, using or disclosing personal information about that individual (section 7). Some of the circumstances where consent is not required include:
Privacy legislation would not impede the work of public health officials if a public health emergency is declared.
If an outbreak is declared to be a public emergency, the powers to collect, use and disclose personal or health information to protect the public health may be very broad.
In the event that a public health or general emergency is declared, orders issued under public health legislation could require the collection, use and disclosure of certain personal information relating to employees and customers.
If you need to collect, use or disclose employee personal information in an emergency, you should communicate to your employees the specific legislative authority that is engaged to do so.
Copyright 2020 OIPC. All rights reserved.