Appendix 4: Confidentiality Requirements
The Approved Institution understands that the Ministry is bound by the protection of privacy provisions of the
Freedom of Information and Protection of Privacy Act, that Canada is bound by the protection of privacy
provisions of the Privacy Act, and that the Approved Institution is bound by the Personal Information
Protection and Electronics Document Act. In administering OSAP, the Institution shall protect the privacy of
individuals and abide by the following terms and conditions:
1 The Approved Institution shall use the information in OSAP records solely for the purpose of administering
OSAP as authorized by the Ministry, unless otherwise required by a court of competent jurisdiction or the
Approved Institution has the Ministry's written authorization.
2 The Approved Institution shall designate an informed, and if possible, experienced, officer or employee to be
responsible for ensuring the Approved Institution’s compliance with the privacy provisions of the Performance
Requirements, including section 6.4 and this Appendix, and ensure that the designated individual is aware of
such privacy provisions.
3 The Approved Institution shall only give access to personal information in a form in which the individual to
whom it relates can be identified to its officers and employees if: • the officer or employee needs the
information in the performance of his or her duties and where such disclosure is necessary and proper in the
administration of OSAP by the Institution; • the Approved Institution has obtained a signed agreement from
such officer or employee to ensure that he or she will abide by the terms of these confidentiality provisions
and will not disclose such information to any other person; and• the Approved Institution maintains a file
listing of the persons so authorized, along with an original copy of their signed confidentiality agreement.
4 The Approved Institution shall ensure that only officers and employees authorized by the Ministry to access
the FAO Information Portal through the ONe-Key Portal have access to the Portals using their assigned access
identification numbers or codes and that such officers and employees comply with all conditions imposed or
attached to the allocation and use of such numbers or codes.
5 The Approved Institution shall ensure that all personal information accessed or obtained from OSAP records
or otherwise required pursuant to the Performance Requirements shall be stored, remain in and be accessible
in a physically secure location in Canada to which access is given only to the persons referred to in sections 2
and 3 above. The security of all student and student-related personal information must be accessed and
maintained in accordance with all relevant Ministry guidelines, directives or other Ministry documents relating
to OSAP-related information access and security.45
6 The Approved Institution shall ensure the secure and irreversible destruction of all personal information that
is not needed for the purposes set out in section 1 above, within three years after the student has completed
his or her attendance at the Institution in a manner that is appropriate to the medium on which the personal
information is stored. The Approved Institution shall provide confirmation of the secure destruction to the
Ministry in writing on the request of the Ministry.
7 The Approved Institution shall ensure that no personal information shall be used or disclosed in a form in
which the individual to whom it relates can be identified, except for the purposes set out in section 1 above,
without the written authority of the Ministry, unless required to do so by a court of competent jurisdiction.