Data Protection Policy 
Our approach
 
British Columbia's Personal Information Protection Act requires an organization to protect personal information in its custody or control by making reasonable security arrangements, and to develop and follow the policies and practices needed to meet its obligations. This page describes how we go about that.
 
What we do not claim. We are not certified to ISO/IEC 27001 or any comparable standard, and we do not hold a SOC 2 report. An earlier version of this page said we operated an information security management system developed in line with ISO/IEC 27001:2013. That was not accurate, and we have removed it.
 
How our security is governed
 
We maintain a written Information Security Safeguards Procedure. It is owned by our Chief Technology Officer, approved by our Chief Executive Officer, and reviewed at least once every twelve months — and sooner after a security incident, a change of hosting or endpoint protection provider, the addition of a system holding personal information, or any question from a client or insurer we cannot answer from our records.
 
It sets a minimum baseline rather than a ceiling. At each review the Chief Technology Officer must propose further safeguards, and what was proposed and decided is recorded.
 
The procedure gives every requirement to a named role and states the record that shows it was done. Where a requirement cannot be met, a written exception must be approved, is limited in time, and is kept on a list. An unapproved departure is a breach of the procedure.
 
What the procedure covers
 
The procedure covers the following areas. Each carries specific requirements, and we would rather describe the scope here and give you the detail on request than publish a control list that ages badly.
 
Area What it covers
Accounts and authentication Individual named accounts with no sharing, multi-factor authentication, password standards and a company password manager.
Granting and removing access Access granted only on a manager's request and only to what the role requires; accounts disabled promptly when an engagement ends; administrative rights restricted and kept separate from day-to-day accounts.
Devices Full disk encryption, automatic locking, supported software versions, defined patching windows, and endpoint protection on laptops and servers.
Where information may be kept Approved systems only, never a personal cloud or email account; encrypted channels for confidential information; no administrative console, remote desktop service or file share exposed directly to the internet.
Backup and recovery Daily backups of systems holding data we cannot afford to lose, including hosted client data, with at least one copy held where a compromise of the source system would not reach it, and a restore tested and recorded at least annually.
Security incidents A single reporting route, immediate containment, evidence preserved, and a written record kept for seven years.
 
Service providers and staff
 
We use a small number of service providers, listed in full with their location at Service Providers. A written agreement covering the purpose, the protection required, and notice to us of any breach must be in place before we disclose personal information to a provider. We remain accountable for that information while it is with them.
 
Access to personal information is limited to the people whose work requires it, and staff and contractors are told what the procedure requires before they are given access, and again each year.
 
If something goes wrong
 
Anyone at Inchol who becomes aware of a suspected security incident must report it by telephone, promptly, on a single reporting route. Reporting in good faith carries no adverse consequence, including for the person who caused the incident; failing to report is the breach.
 
We then open a written record, contain the incident, preserve the evidence, and decide who must be told.
 
Who we tell, and when
  • If the information is a client's, we notify their privacy contact within 24 hours of the first report, or sooner where the contract requires. We do not report to a regulator or contact individuals unless the client instructs us in writing or the law places a duty on us directly.
  • Where PIPEDA governs the activity, we determine in writing whether the breach creates a real risk of significant harm. If it does, we report to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible. We keep a record of every breach for at least 24 months, whatever the determination.
  • Where BC PIPA governs the activity, that Act places no duty to report to the Commissioner or to notify individuals. Reporting is voluntary and the Commissioner encourages it. We decide case by case, record the decision and the reason either way, and will not decide against telling people about a breach likely to cause them significant harm without our Chief Executive Officer's written agreement.
  • Where the GDPR applies and we are the controller, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk. Where it is likely to result in a high risk, we notify affected individuals too. Where we act as a processor, we notify the controller without undue delay.
Asking for more detail
 
Clients and prospective clients carrying out a security or procurement review should contact our Privacy Officer at dpo@inchol.com. We can share our internal security documentation under a confidentiality agreement, and we answer questions about the current state of our systems from evidence rather than from a policy document.