Ontario Young Leaders (ONYL)
Personal Information Protection Policy
At Ontario Young Leaders (“ONYL”), we are committed to providing our members, participants, and partners with high-quality programs, events, and services. As part of these activities, we collect, use, and disclose certain personal information.
Protecting personal information is one of our highest priorities. ONYL is committed to handling personal information in accordance with applicable Canadian privacy laws and best practices, including the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and, where applicable to electronic communications, Canada’s Anti-Spam Legislation (“CASL”). PIPEDA sets out fair information principles including accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. CASL helps reduce unwanted electronic communications by setting rules for certain commercial messages. Where CASL applies to ONYL communications, ONYL will obtain appropriate consent, identify itself, and provide an unsubscribe option.
We will inform individuals of why and how we collect, use, and disclose their personal information, obtain consent where required, and ensure that personal information is handled in a manner that a reasonable person would consider appropriate in the circumstances. Consent will be obtained in a meaningful way so that individuals can reasonably understand the nature, purpose, and consequences of the collection, use, or disclosure of their personal information.
This Personal Information Protection Policy outlines the principles and practices ONYL follows in protecting personal information. Our privacy commitment includes ensuring the accuracy, confidentiality, and security of personal information, maintaining openness about our privacy practices, and allowing individuals to request access to, and correction of, their personal information. A current version of this policy will be made available upon request and through ONYL’s regular communication channels or website, where applicable.
This policy applies to all personal information collected, used, or disclosed by ONYL in the course of its activities, whether such information is held directly by ONYL or by third-party service providers acting on ONYL’s behalf.
Definitions
Personal Information – means information about an identifiable individual. This includes, but is not limited to name, email address, phone number, employer or credit union, job title, age or date of birth, region, pronouns, dietary or accessibility needs, survey responses, event participation, photos, video recordings, social media handles, and similar information.
Contact Information – means business contact details that enable communication with an individual in a professional capacity, including name, title, business email, and business phone number.
Privacy Officer – means the individual designated by ONYL who is responsible for ensuring compliance with this policy and applicable privacy legislation.
Accountability – ONYL’s Board of Directors is ultimately accountable for compliance with this policy and applicable privacy legislation. The Board designates a Privacy Officer to oversee day-to-day privacy compliance, including responding to inquiries, access or correction requests, complaints, and privacy incidents. The Board (or its designate) is responsible for ensuring this policy is implemented, reviewed, and updated as needed.
Policy 1 – Collecting Personal Information
1.1 ONYL will identify the purposes for collecting personal information at or before the time of collection.
1.2 ONYL collects only the personal information necessary to fulfill the following purposes:
● To verify identity and maintain membership records
● To assess eligibility for membership, programs, volunteer, committee, and board participation
● To register individuals for events, conferences, and ONYL programs
● To communicate with members regarding newsletters, events, updates, sponsorship opportunities, partner opportunities, and other ONYL-related activities
● To understand member needs and improve services and offerings
● To conduct surveys and collect feedback
● To administer event registrations and process payments through third-party providers
● To support governance, reporting, risk management, and operational activities
● To comply with legal, financial, regulatory, and contractual requirements
Where personal information is collected from applicants, volunteers, members, or directors, ONYL may collect additional information as reasonably necessary and as permitted by law to support governance, recruitment, eligibility assessment, and accountability obligations.
1.3 Personal information is collected through the following channels:
● Google Forms (membership, surveys, applications, volunteer and board applications)
● Website forms and newsletter signups (e.g., Mailchimp)
● Event registration platforms (e.g., PheedLoop and Eventbrite, where applicable)
● Email and LinkedIn communications
● Sponsorship and partnership forms
● Payment and registration workflows supported by third-party providers
● In-person event sign-ins, attendance lists, or participation records (where applicable)
● Photography, video, or recordings captured at ONYL events or activities (where applicable)
● Information provided to ONYL by sponsors, partners, or other individuals (e.g., referrals or nominations), where appropriate
The channels listed above are examples and may change as ONYL’s tools and service providers evolve.
1.4 ONYL may also collect limited technical data such as browser, and usage data through cookies, pixels, tags, and analytics tools used on its website and digital platforms, including tools such as Google Analytics, Meta Pixel, LinkedIn Insight Tag, and Buffer, where applicable.
1.5 ONYL does not knowingly collect personal information from individuals under the age of 18. If such information is identified, ONYL will take reasonable steps to delete it unless retention is required by law. If ONYL offers programming specifically intended for individuals under the age of 18 in the future, additional consent requirements and safeguards will be implemented in accordance with applicable law.
Policy 2 – Consent
2.1 ONYL will obtain consent to collect, use, or disclose personal information, except where permitted or required by law.
2.2 Consent may be provided in writing, orally, electronically, through an authorized representative or implied where an individual voluntarily provides personal information for a clearly identified purpose.
2.3 Consent may also be implied where individuals are informed and provided with a reasonable opportunity to opt out of communications or specific non-essential uses of their information.
2.4 Individuals may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawal of consent may limit ONYL’s ability to provide certain services, registrations, participation opportunities, or communications.
2.5 ONYL may collect, use, or disclose personal information without consent in limited circumstances, including:
● When required or permitted by law
● In emergency situations affecting health or safety
● For legal or regulatory compliance
● To investigate fraud, policy breaches, or breaches of agreement
● To obtain legal, audit, insurance, or other professional advice
2.6 ONYL may collect and use photos, video recordings, testimonials, and quotes from events and activities for communications and promotional purposes. ONYL will provide notice at or before the time of collection. Individuals may opt out of being photographed or recorded where reasonably practicable or may request removal of specific identifiable content after the event, subject to legal, archival, or operational limitations. Where ONYL intends to use particularly prominent or individually focused identifiable images, recordings, or testimonials outside the ordinary promotion of an ONYL event or activity, ONYL may seek additional express consent as appropriate. This approach is intended to support meaningful consent under PIPEDA.
2.7 Where ONYL sends commercial electronic messages that are subject to CASL, ONYL will obtain and document the required form of consent, whether express or implied, before sending such messages, unless an exemption applies. ONYL may rely on implied consent where permitted, including certain communications with members of an association, club, or voluntary organization, but will still comply with the identification and unsubscribe requirements in each applicable message. ONYL will maintain records of consent where required.
Policy 3 – Using and Disclosing Personal Information
3.1 ONYL will use or disclose personal information only for the purposes identified at the time of collection or for purposes reasonably related to those purposes, unless further consent is obtained or the use or disclosure is otherwise permitted or required by law.
3.2 ONYL may use personal information for delivering programs, events, and communications, managing membership and engagement, conducting surveys, processing registrations and payments, improving services, maintaining governance and operational continuity, and meeting legal or regulatory requirements.
Personal information may be included in internal governance records such as meeting minutes, attendance records, resolutions, reports, and working documents where reasonably necessary to support ONYL’s governance, accountability, and historical record‑keeping obligations.
3.3 ONYL may disclose personal information to third-party service providers supporting its operations, including communication platforms, event registration platforms, payment processors, survey tools, website analytics providers, storage providers, and similar service providers.
3.4 ONYL is committed to protecting personal information against unauthorized access, collection, use, disclosure, or loss. We will implement appropriate safeguards, ensure that personal information is used only for purposes related to ONYL services, and require third-party service providers to maintain a comparable level of protection in accordance with PIPEDA.
ONYL is committed to protecting personal information against unauthorized access, use, disclosure, alteration, or loss. ONYL will apply safeguards that are appropriate to the sensitivity of the information and will limit access to those who need it to carry out ONYL’s identified purposes. Where personal information is handled by third-party service providers, ONYL will take reasonable steps to ensure they use the information only to provide services to ONYL and maintain a comparable level of protection, including through appropriate contractual or other measures and, where appropriate, requiring timely notification of privacy incidents affecting ONYL information.
3.5 ONYL does not sell personal information.
3.6 ONYL may use aggregated and anonymized data for reporting, sponsorship, grant applications, impact measurement, and strategic purposes. ONYL will not disclose identifiable personal information to sponsors, funders, partners, or third parties for those purposes without the individual’s consent unless otherwise permitted or required by law.
3.7 ONYL uses third-party platforms that may store or process personal information outside Canada. Personal information may therefore be accessible to courts, law enforcement, or regulators in those jurisdictions.
3.8 Where ONYL sends electronic communications subject to CASL, each applicable message will include ONYL’s identification information, valid contact information, and a functioning unsubscribe mechanism. Unsubscribe requests will be acted on as soon as feasible and no later than 10 business days after receipt.
Policy 4 – Retaining Personal Information
4.1 If personal information is used to make a decision affecting an individual, it will be retained for at least one (1) year, or longer where required by law or reasonably necessary, to allow the individual a reasonable opportunity to request access and challenge the decision.
4.2 ONYL will retain personal information only as long as necessary to fulfill identified purposes or meet legal, financial, insurance, audit, contractual, governance, or regulatory obligations.
Retention periods will be periodically reviewed to ensure they remain appropriate for ONYL’s changing programs and obligations.
4.3 Personal information relating to membership or participation will generally be deleted or anonymized within one (1) year after an individual no longer meets membership or participation criteria, unless a longer retention period is required or justified under Policy 4.1 or 4.2.
4.4 Financial, accounting, tax, governance, insurance, incident, dispute, and contractual records may be retained longer where required by law, by prudent nonprofit governance practices, or for the establishment, exercise, or defense of legal claims.
4.5 Individuals who opt out of communications will be removed from applicable mailing lists in accordance with CASL and other applicable requirements. Unsubscribe requests will be processed no later than 10 business days after receipt.
4.6 Where a breach of security safeguards occurs, ONYL will maintain records of the breach in accordance with applicable law. Under PIPEDA, records of all breaches of security safeguards must be retained for at least two (2) years.
Policy 5 – Ensuring Accuracy of Personal Information
5.1 ONYL will make reasonable efforts to ensure that personal information is accurate, complete, and as up to date as necessary for the purposes for which it is used.
5.2 Individuals may request corrections to their personal information by submitting a written request to the Privacy Officer with sufficient detail to identify the information and the requested correction.
5.3 Where appropriate, ONYL will correct the information and, where feasible and appropriate, notify third parties to whom the information was disclosed.
5.4 Where ONYL does not agree to make a requested correction, it will note the request on file where appropriate and advise the individual of the reasons and available recourse.
Policy 6 – Securing Personal Information
6.1 ONYL is committed to protecting personal information against unauthorized access, collection, use, disclosure, or loss and we will take appropriate measures to safeguard personal information.
6.2 Security measures include:
● Restricted and role-based access to personal information, limited to ONYL directors and other authorized individuals who require the information for approved ONYL purposes
● Secure storage using approved platforms such as Google Workspace, Mailchimp, PheedLoop, and other approved systems
● Password protection, multi-factor authentication where available, and access controls
● Use of secure third-party tools and systems
● Regular review of access permissions and system controls
● Reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption or similar protections where available and appropriate
6.3 ONYL requires service providers to maintain comparable security safeguards and to process personal information only in accordance with ONYL’s instructions and applicable agreements.
6.4 Personal information will be securely destroyed, deleted, or anonymized when no longer required, using methods appropriate to the sensitivity of the information.
6.5 ONYL will investigate suspected privacy incidents and security breaches. Where a breach of security safeguards involving personal information creates a real risk of significant harm, ONYL will comply with applicable PIPEDA breach reporting, notification, and record-keeping requirements, including notification to affected individuals and the Office of the Privacy Commissioner of Canada where required.
6.6 ONYL will review and update its privacy and security practices from time to time as technology, organizational needs, and legal requirements evolve.This policy will be reviewed periodically and at least every two (2) years, or sooner if there are material changes to ONYL’s programs, technology, or legal obligations.
Policy 7 – Providing Access to Personal Information
7.1 Individuals have the right to request access to their personal information, subject to limited exceptions permitted or required by law.
7.2 Requests must be submitted in writing and include sufficient detail to identify the information being requested.
7.3 ONYL will respond within thirty (30) days or provide written notice if an extension is permitted or required.
7.4 Upon request, ONYL will provide information on how personal information has been used and, where available and appropriate, to whom it has been disclosed.
7.5 If access is denied in whole or in part, ONYL will provide reasons in writing, together with information about available recourse.
7.6 ONYL may require verification of identity before providing access or making corrections, in order to protect personal information from unauthorized disclosure.
Policy 8 – Questions and Complaints
8.1 The Privacy Officer is responsible for ensuring ONYL’s compliance with this policy and applicable privacy legislation, including overseeing privacy inquiries, access requests, correction requests, complaints, breach response, and privacy-related training or guidance as appropriate.
The Privacy Officer may recommend updates to this policy; however, any material changes to this policy must be reviewed and approved by ONYL’s Board of Directors (or its designate) in accordance with ONYL’s governance processes.
8.2 Individuals may submit questions, concerns, or complaints regarding ONYL’s privacy practices in writing to the Privacy Officer.
8.3 ONYL will investigate privacy complaints in a fair and reasonable manner and will document the complaint, review, findings, and outcome. ONYL may request additional information where reasonably necessary to assess the matter.
8.4 ONYL will respond within a reasonable timeframe and, where appropriate, advise the individual of corrective actions taken or proposed.
8.5 If a concern is not resolved, individuals may contact the Office of the Privacy Commissioner of Canada.
Contact Information
Privacy Officer
Email: privacy@ontarioyoungleaders.ca
Policy Information
Approved by: ONYL Board of Directors
Effective date: May 27, 2026
Last reviewed: May 27, 2026
Cookies
If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.