Skip to content
CDDA My Canadian Freedom

CDDA · Public information

Security, retention & incident response

Proposed operating procedures requiring assigned responsibility.

Proposed policy — not yet adopted

Published for organizational and legal review. This draft does not certify compliance or establish that its proposed procedures are already operating.

Published 18 September 2026 · Version 2026-09-18.2

01Access and handling

Review permissions when a person joins, changes role or leaves. Restrict applicants, requests and membership records to national administrators and legal-restricted projects to authorized roles. Avoid exports unless necessary and approved. Maintain an inventory of providers and data flows before adding new integrations.

02Retention schedule to adopt

Assign a justified retention period and review owner for applications, active-member records, closed requests, research material, audit logs and backups. Apply deletion or anonymization when no longer needed, subject to documented legal holds. Automated expiry is not currently implemented; approving this draft alone would not create it. Keep evidence of completed deletion without retaining the deleted content unnecessarily.

03Incident response

Contain suspected exposure, preserve necessary evidence, identify affected information and assess likely harm. Assign a response lead and record decisions. Where PIPEDA applies, breaches creating a real risk of significant harm require reporting and notification, and records of all breaches must be kept. Assess provincial obligations separately. Do not promise secrecy or delay a required notice while awaiting an internal vote.

04Publication readiness

The organization still needs to designate its accountable privacy lead, approve retention periods, verify provider terms and locations, and adopt applicable governance and payment rules. The published notice describes current functionality; this draft is an implementation plan, not certification that every control exists.

Official references

References explain the legal framework; they do not mean a regulator has approved CDDA or this policy.

A question or concern?

Send a brief request to the national administrator inbox. Please leave out sensitive documents and third-party personal information.

Open request form