APPENDIX I
TEN PRINCIPLES OF PRIVACY PROTECTION
- Be accountable
Establish policies and responsibilities - Identify Purposes
Explain why information is collected and used - Obtain consent
for information collection, use and disclosure - Limit collection
Only gather information required for identified purposes - Limit use, disclosure and retention
Destroy data when no longer required - Ensure Accuracy
Keep frequently use information up-to-date - Safeguard security
Keep sensitive information secure, control access - Be open
Communicate policies and practices - Provide access
Enable member/employee access to their records - Challenge Compliance
Invite feedback, quickly investigate and resolve complaints