Appendix 4: Confidentiality Requirements
The Approved Institution understands that the Ministry is bound by the protection of privacy provisions of the
Freedom of Information and Protection of Privacy Act, that Canada is bound by the protection of privacy
provisions of the Privacy Act, and that the Approved Institution is bound by the Personal Information
Protection and Electronics Document Act. In administering OSAP, the Institution shall protect the privacy of
individuals and abide by the following terms and conditions:
1 The Approved Institution shall use the information in OSAP records solely for the purpose of administering
OSAP as authorized by the Ministry, unless otherwise required by a court of competent jurisdiction or the
Approved Institution has the Ministry's written authorization.
2 The Approved Institution shall designate an informed, and if possible, experienced, officer or employee to be
responsible for ensuring the Approved Institution’s compliance with the privacy provisions of the Performance
Requirements, including section 6.4 and this Appendix, and ensure that the designated individual is aware of
such privacy provisions.
3 The Approved Institution shall only give access to personal information in a form in which the individual to
whom it relates can be identified to its officers and employees if: • the officer or employee needs the
information in the performance of his or her duties and where such disclosure is necessary and proper in the
administration of OSAP by the Institution; • the Approved Institution has obtained a signed agreement from
such officer or employee to ensure that he or she will abide by the terms of these confidentiality provisions
and will not disclose such information to any other person; and• the Approved Institution maintains a file
listing of the persons so authorized, along with an original copy of their signed confidentiality agreement.
4 The Approved Institution shall ensure that only officers and employees authorized by the Ministry to access
the FAO Information Portal through the ONe-Key Portal have access to the Portals using their assigned access
identification numbers or codes and that such officers and employees comply with all conditions imposed or
attached to the allocation and use of such numbers or codes.
5 The Approved Institution shall ensure that all personal information accessed or obtained from OSAP records
or otherwise required pursuant to the Performance Requirements shall be stored, remain in and be accessible
in a physically secure location in Canada to which access is given only to the persons referred to in sections 2
and 3 above. The security of all student and student-related personal information must be accessed and
maintained in accordance with all relevant Ministry guidelines, directives or other Ministry documents relating
to OSAP-related information access and security.45
6 The Approved Institution shall ensure the secure and irreversible destruction of all personal information that
is not needed for the purposes set out in section 1 above, within three years after the student has completed
his or her attendance at the Institution in a manner that is appropriate to the medium on which the personal
information is stored. The Approved Institution shall provide confirmation of the secure destruction to the
Ministry in writing on the request of the Ministry.
7 The Approved Institution shall ensure that no personal information shall be used or disclosed in a form in
which the individual to whom it relates can be identified, except for the purposes set out in section 1 above,
without the written authority of the Ministry, unless required to do so by a court of competent jurisdiction.
8 The Approved Institution shall notify the Ministry in writing immediately upon becoming aware of a
potential or actual breach of any privacy protection provisions of the Performance Requirements.
9 The Approved Institution shall provide the Ministry, on request, with any information the Ministry may need
to confirm that the Approved Institution has complied with the conditions set out in the Performance
Requirements.
10 The Approved Institution shall cooperate with the Ministry and the Ministry’s contractors and auditors, and
with Canada, and Canada’s contractors and auditors, in any audit of or investigation into breach of the privacy
protection provisions of the Performance Requirements or Performance Requirements, 2007.
11 The Approved Institution shall implement, use and maintain other specific privacy or security measures
that in the reasonable opinion of the Ministry would improve the adequacy and effectiveness of the
Institution’s measures to ensure the privacy and security of the information.
12 These confidentiality provisions shall survive the termination of the annual Performance Requirements
Institution Agreement between the Minister and the Approved Institution.
13 These confidentiality provisions apply only to records related to the Approved Institution’s administration
of OSAP on behalf of the Ministry and are not intended to affect the general administration of the Approved
Institution or any of its other records.
CONFIDENTIALITY AGREEMENT
For the purpose of the Administration of the Ontario Student Assistance Program
As an employee of
, I un
derstand that the Ministry is subject to the Freedom of Information and
Protection of the Privacy Act and that it collects and uses relevant personal and tax
information under the authority of the Ministry of Colleges and Universities Act,
R.S.O. 190, c.M. 19, and regulations 773, 774, and 775: The Canada Student
Financial Assistance Act, S.C. 1994, c.28; and the regulation, SOR 95-359, to
administer OSAP.
I agree to comply with the confidentiality provisions appended as appendix 4
(affix initials to the bottom of appendix 4) to this agreement. Compliance with
these provisions will survive termination of this agreement.
____
________________ ____________________ _______________
(Printed Name) (Signature) (Date)