APP

General Data Protection Regulation (GDPR) Compliance

APP’s commitment to compliance with the GDPR is reflected in its General Data Protection Regulation Compliance Operating Standard which provides a comprehensive framework to ensure that all personal data processing activities performed by APP that are subject to the GDPR are lawful, transparent and aligned with the GDPR’s requirements.

The standard outlines clear roles and responsibilities including oversight by APP’s Data Protection Officer, and requires:

  • Data Protection Impact Assessments (DPIAs) for high-risk processing activities 
  • Records of Processing Activities (ROPA)
  • Contracts and safeguards for third party processors
  • Controls for international data transfers

Personal data may be processed only where a valid legal basis exists (such as consent, contact, legal obligation or legitimate interest), and all processing activities must be documented through formal records (e.g., Records of Processing Activities or ROPA). This ensures transparency, traceability and regulatory accountability across all operations.

Privacy considerations are embedded into systems, projects and processes from the outset.  This includes limiting data collection to what is necessary, implementing technical and organizational safeguards and conducting risk assessments such as Data Protection Impact Assessments (DPIAs) and technology risk assessments for higher risk activities.

Individuals whose personal data is subject to the GDPR are supported in exercising their rights as data subjects including the right to be informed, access, correct, delete, restrict processing and transfer their personal data. APP maintains processes and timelines for responding to these requests and ensures appropriate coordination when acting as a data processor.  For more information about how to make a data subject rights request, please see the General Data Protection Regulation Compliance Operating Standard or contact the Data Protection Officer

Personal data is protected by appropriate technical and organizational measures, including data classification, access controls, encryption or pseudonymization where appropriate, and ongoing security reviews. There are formal processes for detecting, reporting and responding to personal data breaches, including regulatory notification when required. 

Frequently Asked Questions (FAQs) - GDPR

The General Data Protection Regulation Compliance Operating Standard provides a framework for APP to comply with the GDPR when required under contracts, funding obligations or when engaging with individuals located in the European Economic Area.

The standard can also be used on an indicative basis for complying with the GDPR as it has been retained in the laws of the United Kingdom and the Swiss Federal Act on Data Protection when applicable to APP. 

The GDPR applies to APP when it processes personal data of individuals located in the European Economic Area (EEA) and the activity involves either: 

  • Offering goods or services to those individuals; or
  • Monitoring their behaviour (for example, in research or clinical trials).

GDPR’s requirements may also be contractually imposed on APP when it processes personal data on behalf of a controller located in the EEA.

Personal data is any information that can identify an individual directly or indirectly. This includes information such as names, addresses, telephone numbers, email addresses and photographs or images. Personal data includes expressions of opinion and indications of intentions about individuals such as performance appraisals. It also includes location data, online identifiers such as IP addresses, health information and genetic information.

On the other hand, anonymous information is not considered personal data. Anonymous information is information that does not relate to an identified or identifiable natural person or personal data that has been rendered anonymous in such a manner that the data subject is no longer identifiable. 

Information that does not on its own identify an individual is still considered personal data for purposes of the GDPR if there is a real possibility it can be combined with other information maintained by APP or a third party to identify an individual. In such cases, the data is considered pseudonymized and not anonymized and is still subject to the GDPR’s protections. 

APP follows key GDPR principles when processing personal data:

  • Lawfulness, fairness and transparency;
  • Purpose limitation (personal data is only used for specific, authorized purposes);
  • Data minimization (only what is necessary is used);
  • Accuracy;
  • Storage limitation; and
  • Security and confidentiality.

Processing refers to any activity involving personal data including:

  • Collecting, obtaining, recording, retrieving, consulting or holding it;
  • Using, organizing, adapting or altering it;
  • Disclosing, disseminating or otherwise making it available; and
  • Aligning, blocking, erasing or destroying it.

A Data Controller determines why and how Personal Data is processed.

A Data Processor processes Personal Data on behalf of a Data Controller in accordance with written instructions provided by the Data Controller and subject to contractual guarantees to implement appropriate technical and organizational measures to protect the personal data and to otherwise perform the processing activities in accordance with the Regulation. 

Before personal data is processed, APP must ensure there is a valid legal basis, such as consent, contractual necessity, legal obligation, vital interests, public interest or legitimate interests. The processing of sensitive personal data such as health information must be authorized by an additional legal basis such as explicit consent, employment obligations, vital interests, substantial public interests, public interest in the area of public health, archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, publicly available information, legal rights or health and social care. More information about each of these legal bases is contained in the General Data Protection Regulation Compliance Standard

Personal data is protected in accordance with the APP Information Security Classification Standard by appropriate technical and organizational measures, including data classification, access controls, encryption or pseudonymization where appropriate, and ongoing security reviews. There are formal processes for detecting, reporting and responding to personal data breaches, including regulatory notification when required. 

If you have questions about how APP handles personal data or wish to exercise your GDPR rights, please contact the APP's Data Protection Officer at dpo@ucalgary.ca.