Safeguarding Personal Information
Blackfalds Food Bank Society (BFBS) is committed to protecting the personal information of clients, donors, volunteers, staff, and partners. In accordance with applicable privacy legislation and our ethical responsibility, BFBS has implemented a combination of physical, technical, and procedural safeguards to prevent unauthorized access, loss, misuse, or disclosure of personal data.
1. Physical Safeguards
- Personal information stored in paper format is kept in locked cabinets or secure offices accessible only to authorized personnel.
- Access to BFBS facilities is restricted to authorized staff, volunteers, clients, and scheduled visitors. All clients and visitors to be accompanied while on the premises.
- Any physical documents containing sensitive information are disposed of using a cross-cut shredder or a certified document destruction service.
2. Technical Safeguards
- Electronic personal information is stored on secure, encrypted servers or cloudbased platforms with role-based access controls.
- Password-protected user accounts are used for accessing systems containing personal data. Passwords are changed regularly and must meet strong password requirements.
- All devices (computers, tablets, phones) used to access personal information are protected with up-to-date antivirus software and firewalls.
- Backups of sensitive data are performed regularly and stored in secure, off-site or cloud-based locations.
3. Procedural Safeguards
- Staff and volunteers receive mandatory privacy and confidentiality training during onboarding and on a regular basis.
- Access to personal information is granted only on a need-to-know basis, based on an individual’s role within the organization.
- All staff and volunteers are required to sign a confidentiality agreement acknowledging their responsibility to protect personal data.
- Any data breaches or suspected breaches must be reported immediately to the Executive Director, who will follow a predefined incident response plan.
- Personal information is not shared with external parties without express consent from the individual, unless required by law.
4. Retention and Disposal
- Personal information is retained only for as long as necessary to fulfill the purposes for which it was collected or as required by law.
- When no longer needed, personal data is securely deleted from digital systems and physically destroyed if in paper form.
5. Regular Review
- BFBS will review this policy annually and revise it as needed to ensure continued compliance with evolving best practices and legislation.
