Updated: 2024-10-01

1. Objective

Groupe Touchette attaches great importance to the protection of personal information. In this regard, Groupe Touchette has developed this policy to provide a framework for its governance of personal information, and to enable its employees and subcontractors to understand the legal requirements and privacy principles inherent in the performance of their duties.

More specifically, this policy aims to ensure compliance with applicable laws and standards, by specifying, among other things: (i) the rules governing the collection and other processing of personal information held by Groupe Touchette; (ii) the management of access to personal information; (iii) the process for handling complaints relating to the protection of personal information; and (iv) the security measures implemented to ensure the confidentiality, integrity and availability of personal information throughout its life cycle.

Groupe Touchette has also implemented various measures in this area in compliance with applicable laws, and in particular with the changes introduced by Bill 25. To this end, Groupe Touchette has: (i) validated and confirmed the roles and responsibilities of its Privacy Officer; (ii) implemented various policies in this area, including the following; (iii) set up a register of confidentiality incidents; (iv) undertook a review and documentation of all governance measures and rules; and (vi) prepared various model contracts and registers.

2. Scope and Policies

This policy applies to:

3. Definitions and Interpretation

In this policy, the following terms have the meanings set out below:

Unless the context otherwise requires, grammatical variations of any defined term have a similar meaning, and the singular includes the plural, and the masculine includes the feminine, and vice versa.

4. Guiding Principles

As part of its mission and activities, Groupe Touchette is called upon to hold and/or process various types of personal information. To this end, Groupe Touchette stresses the importance of ensuring that all processing is carried out in accordance with the following guiding principles:

5. Privacy Officer

The Privacy Officer ensures compliance and implementation of applicable privacy requirements:  

Groupe Touchette Inc.

Privacy Officer

750 Lebeau Blvd., Ville Saint-Laurent, QC, H4N 1S4

personalinformation@grtouchette.com

6. Personal Information Concerning Employees

This section applies to personal information that Groupe Touchette may collect or otherwise process about its employees. Such collection and processing of personal information will be done only to the extent that it is (i) required to manage its employment relationship with its employees; (ii) permitted by law; or (iii) necessary to comply with applicable legal and contractual requirements. Such processing will take place as set out in the Corporate Governance Policy.

COLLECTION AND USE OF PERSONAL INFORMATION BY GROUPE TOUCHETTE

Groupe Touchette collects personal information that is required or optional to manage its employment relationship with its Employees.

Except as provided by law, when Groupe Touchette collects, uses or discloses personal information that is not required to manage the employer-employee relationship, the employee's consent is required. Similarly, when personal information is collected to manage the employer-employee relationship, and Groupe Touchette wishes to use or disclose it for other purposes, consent is also required. When personal information is collected and used to manage the employer-employee relationship, only Groupe Touchette employees whose duties so require will have access to such personal information.

Similarly, Groupe Touchette will only disclose personal information to third parties who need it to fulfill their contractual obligations to Groupe Touchette, who are bound by Groupe Touchette's confidentiality obligations, or when Groupe Touchette honestly believes it is required to do so by law (for example, to tax authorities and law enforcement agencies) or for the protection of Groupe Touchette or its assets or employees. Otherwise, consent to the disclosure of personal information is required.

Groupe Touchette may provide its employees with one or more networks that allow them to: (i) communicate with each other and/or with third parties (including subcontractors or professionals) for business purposes; and (ii) access the Internet and Groupe Touchette information and documentation. Use of the network, information and materials owned by Groupe Touchette is limited to Groupe Touchette's business. However, Groupe Touchette is aware that limited use of the network or technological equipment provided by Groupe Touchette to its employees may be necessary during working hours for personal purposes (e.g., making personal appointments) (collectively, Personal Communications). Employees may not have a reasonable expectation of privacy with respect to Personal Communications made using Groupe Touchette's network or computer equipment.

DISCLOSURE OF PERSONAL INFORMATION BY GROUPE TOUCHETTE

Groupe Touchette will not provide personal information about its employees to third parties without their consent, except as required by law or in accordance with this Policy, including, if necessary: (i) to manage the employer-employee relationship; (ii) to enable a third party to perform its contractual obligations to an employee or to Groupe Touchette; or (iii) if, in good faith, Groupe Touchette believes that such action is reasonably necessary to comply with legal process or respond to requests or to protect the rights, property or safety of Groupe Touchette, its representatives, employees and customers, or the public. In addition, only Groupe Touchette employees whose duties so require will have access to personal information. The following are examples of the various categories to which the disclosure of personal information may correspond:

Third partiesPurposeInformation Provided
Subcontractors (Suppliers and consultants – group benefit plans)Provide benefits programs to Groupe Touchette employees, administer claims and follow-up and calculate mathematical provisions for benefits.Name, date of birth, home address and telephone number, marital status, dependent information, salary, medical questionnaire, type of coverage, claims information, social insurance number, etc.
Subcontractors (Payroll department)  Provide direct deposit and payroll processing services to Groupe Touchette employees. Name, date of birth, home address and telephone number, salary information, social insurance number, tax information.
Subcontractors (IT services, etc.)Assist Groupe Touchette with certain personnel management tasks.Information required by subcontractors to provide services.
Tax authoritiesComply with Groupe Touchette's obligations under the relevant tax legislation.Income or remuneration, social insurance number, other personal information such as age or residential address required by tax authorities.
References (provided by a candidate)Ensure the veracity of the information received from the candidate and obtain the reference's opinion on his or her abilities.Candidate's name, relevant extracts from the application.
Emergency servicesEnsure the safety of those concerned in the event of an emergency.Names and information required by services.
Law enforcement agencies or government authoritiesWhere necessary, prevent, detect or terminate offences, ensure compliance with the law, and comply with court or tribunal orders.All relevant information for this purpose.

By submitting personal information to Groupe Touchette, employees acknowledge that they have consented to the collection, use and disclosure practices set out in this policy. Employees may withdraw their consent at any time for personal information that is not required to manage the employer-employee relationship, to enable a third party to perform its contractual obligations to them or to Groupe Touchette, or for any other purpose described herein by contacting Groupe Touchette's Privacy Officer in writing. However, by making this choice, the employee may limit Groupe Touchette's ability to serve and provide benefits to the employee or to perform any other applicable duties or functions.

7. Personal Information About Any Other Person

Groupe Touchette may also process personal information about individuals who communicate with Groupe Touchette. Such processing will take place on the basis of consent or in a situation permitted or required by law.

COLLECTION AND USE OF PERSONAL INFORMATION BY GROUPE TOUCHETTE

Various personal information may be processed by Groupe Touchette in its interactions with members of the public. Groupe Touchette collects personal information for the purposes stated at the time of collection.

DISCLOSURE OF PERSONAL INFORMATION BY GROUPE TOUCHETTE

Groupe Touchette will not provide personal information about any individual to third parties without that individual's consent, except as required by law or in accordance with this policy. In addition, only employees whose duties so require will have access to such information. In addition to these disclosures, we may disclose personal information as required or permitted by law.

8. Consent

Groupe Touchette recognizes the importance of obtaining valid consent in connection with the collection or other processing of personal information. Consent must take into account the following requirements:

ConsentCriteria
Personal informationbe manifest (i.e. it must be obvious, certain and indisputable, and must leave no doubt as to the will expressed therein);be free (i.e. given without coercion);be informed (i.e. precise and rigorous, enabling the person concerned to give informed consent);be given for specific purposes (i.e., for each of these purposes. It cannot therefore be general or cover other purposes);be requested for each of the applicable purposes (i.e., the person must be able to confirm his or her intention for each purpose);be requested in clear and simple terms;be presented separately from any other information communicated to the person concerned when the request for consent is made in writing;be valid only for the length of time required to achieve the purposes for which it was requested (i.e., the number of days, months or years required, or until the occurrence or termination of an event).
Sensitive informationbe expressly stated;otherwise comply with the requirements applicable to any consent to the processing of personal information.

The law recognizes certain situations in which the consent of the person concerned will not be sought or need not be sought. Please consult the Privacy Officer in this regard. Please note that when a person so requests, assistance is provided to help him or her understand the scope of the consent requested.

9. Retention, Destruction and Anonymization

Subject to a retention period provided by law, when the purposes for which personal information was collected or used have been fulfilled, Groupe Touchette will: (i) destroy such personal information in a secure manner; or (ii) if applicable, anonymize the information for use for serious and legitimate purposes, in accordance with the criteria established by regulation. In order to comply with the above, Groupe Touchette has developed a Retention Policy for documents containing personal information.

10. Procedures and Standards Relating to the Communication of Personal Information Outside Quebec

In order to comply with applicable legal requirements and to ensure the confidentiality and security of any personal information, Groupe Touchette will conduct a privacy impact assessment before disclosing any personal information outside Québec.

This assessment will take into account, among other things: (i) the sensitivity of the personal information; (ii) the purpose for which it is to be used; (iii) the safeguards, including contractual safeguards, from which the personal information would benefit; and (iv) the legal regime applicable in the jurisdiction where the personal information would be disclosed.

For the purposes of this assessment, the Privacy Officer will be consulted at the outset of the project. Groupe Touchette's legal advisors, as well as any other parties deemed necessary/desirable, may also be involved or consulted.

Disclosure may take place if the assessment demonstrates that the personal information would benefit from adequate protection, particularly in light of generally accepted privacy principles. Disclosure will be subject to a written agreement that takes into account, among other things, the results of the assessment and, where applicable, the terms and conditions agreed to in order to mitigate the risks identified during the assessment. The same applies when Groupe Touchette entrusts a person or organization outside Quebec with the task of collecting, using, communicating or storing such information on its behalf.

In order to comply with the foregoing, Groupe Touchette will develop a Privacy Impact Assessment Model in the context of the communication of personal information outside Quebec that complies with the law.

11. Procedures and Standards for Disclosing Personal Information for Study, Research or Statistical Purposes

As required by law, Groupe Touchette may disclose personal information without consent to a person or organization wishing to use the information for study, research or statistical purposes. To do so, Groupe Touchette will first conduct a privacy impact assessment. This assessment will conclude :

Prior to disclosing any personal information, Groupe Touchette will enter into an agreement with the person or organization to whom it discloses such information, in accordance with the requirements of the law.

In order to comply with the foregoing, Groupe Touchette will develop a Privacy Impact Assessment Model in the context of the communication of personal information for study, research or statistical production purposes that complies with the law.

12. Technological Project Involving Personal Information

In order to comply with applicable legal requirements and to ensure the confidentiality and security of personal information, Groupe Touchette will conduct a privacy impact assessment for any project involving the acquisition, development or redesign of an information system or the electronic delivery of services involving the collection, use, disclosure, retention or destruction of personal information. The assessment shall be proportionate to the sensitivity of the personal information concerned, the purpose for which it is to be used, its quantity, distribution and medium.

For the purposes of this assessment, the Privacy Officer will be consulted at the outset of the project. Groupe Touchette's legal advisors, as well as any other parties deemed necessary or desirable, may also be involved or consulted.

Groupe Touchette will ensure that any project allows computerized personal information collected from the person concerned to be communicated to the latter in a structured and commonly used technological format.

In order to comply with the above, Groupe Touchette will develop a Privacy Impact Assessment Model for technology projects involving personal information, in accordance with the law.

13. Use of Information, Location or Profiling Technology

From time to time, Groupe Touchette may use technology that includes functions to identify, locate or profile an individual. Groupe Touchette will comply with legal requirements in this regard.

14. Decision-Making Based on Automated Processing of Personal Information

From time to time, Groupe Touchette may use personal information to make a decision based exclusively on the automated processing of such information. In all cases and in accordance with the law, Groupe Touchette will inform the person concerned of this fact, at the latest at the time Groupe Touchette's decision is communicated to him or her, in addition to complying with other legal requirements in this regard. 

15. Safety Measures

Groupe Touchette monitors network usage, communications and information, including personal communications. Electronic monitoring includes activities such as logging employee access to the network, communications and information; accessing and recording communications sent or received by e-mail or other electronic messaging methods; and monitoring Internet usage, which may identify servers and sites accessed by Groupe Touchette employees. Groupe Touchette monitors the use of the network, communications and information, including personal communications, for maintenance and security purposes; to ensure that the use of the network, communications and information complies with Groupe Touchette policies and the law; and, when it deems it necessary or useful, to protect the rights, property or safety of Groupe Touchette, its representatives, employees and customers, or the public, but does not limit its ability to use the information collected through electronic monitoring. For these same purposes, it does the following:

Upon leaving Groupe Touchette :

Electronic passes issued to Groupe Touchette employees may record the time and location of their use, and security cameras installed on Groupe Touchette premises videotape key areas of Groupe Touchette facilities. Information from electronic passes and security camera recordings is accessible and usable for security purposes or to comply with Groupe Touchette policies. Depending on the location of your workstation, certain information associated with your electronic pass and security cameras may be collected by the building manager or owners, in which case such information is subject to that owner/manager's privacy policy.

Groupe Touchette implements various security measures to ensure the protection of the personal information it processes, which are reasonable in light of, among other things, the sensitivity of the information, the purpose for which it is used, its quantity, distribution and medium, including the following:

INTERNAL MEASURES

Groupe Touchette deploys various internal safety measures, including the following: 

Separation of roles, responsibilities and tasks

The separation of incompatible functions and accesses is one of the pillars of effective control, designed to prevent or reduce the risk of privacy breaches (for example, by ensuring that the same individual cannot control all phases of a process). To this end, Groupe Touchette ensures that access to personal information is limited to employees and/or subcontractors with a need to know.

Installation of software and equipment

Any installation of software or equipment is carried out exclusively under the supervision or pre-approval of the IT team, to ensure that risks have been validated and understood, that user agreements and rights comply with the intended use, that applications are standardized, and that platforms comply with configuration standards.

Privacy Impact Assessments and Risk Assessments

Privacy Impact Assessments, aimed at better protecting personal information and respecting the privacy of the individuals concerned, are carried out in accordance with the law and as more fully detailed in this Policy.

Training and awareness

Groupe Touchette takes reasonable steps to ensure that all its employees and subcontractors are aware of the privacy rules as set out in applicable laws and standards, as well as in this Policy. Ongoing awareness and training are essential to ensure the protection of personal information. Similarly, the procedure for dealing with confidentiality incidents is known to Groupe Touchette's Privacy Officer, management and relevant technical staff. Finally, Groupe Touchette is committed to providing training in the protection of personal information to employees, insofar as their duties justify the provision of such training.

Protection of information systems

The level of protection afforded to information systems is determined by the outcome of the risk assessment and the security required. In addition, any access to systems must identify the user, and security measures must be applied throughout the life cycle of personal information. Finally, the protection of personal information relies on the ongoing involvement of each employee, who must in particular: (i) use all resources judiciously for their intended purpose and in compliance with applicable laws and standards, as well as Groupe Touchette's instructions; (ii) choose complex passwords; (iii) maintain the security and confidentiality of all passwords and their identifiers; and (iv) not store personal information on technologies other than those specifically authorized by Groupe Touchette.

Transmission of information

Personal information must be transmitted, exchanged or otherwise transferred outside the Groupe Touchette network in a secure manner. Any transfer of personal information to unauthorized external sources is expressly prohibited.

Business continuity

Groupe Touchette has technological and procedural measures in place to ensure that operations deemed essential can be restored within a reasonable timeframe in the event of a disaster (e.g. major cyber-attack, flood, fire, etc.).

MEASURES CONCERNING SUBCONTRACTORS

Subject to applicable laws, Groupe Touchette ensures compliance with the following when personal information must be processed by subcontractors in order for them to carry out the mandate/contract entrusted to them: 

In this respect of the above, Groupe Touchette has drawn up model contractual clauses. These models will be adjusted on a case-by-case basis, depending on the co-contractor and the content of the contract to be drawn up with the latter.

CONFIDENTIALITY INCIDENTS

Various situations, including the following, constitute confidentiality incidents:

Groupe Touchette will comply with all legal requirements in the event of a confidentiality incident.

Groupe Touchette keeps a register of confidentiality incidents, and will provide a copy to the Commission d'accès à l'information upon request.

16. Access, Rectification and Other Requests

All requests for access or rectification must be made in writing and addressed to the Privacy Officer. Where the request is not sufficiently precise, or where an individual so requests, the Privacy Officer will assist the individual in identifying the personal information sought. The Privacy Officer's duty to assist includes the following:

In practice, the person in charge will:

  1. provide reasonable assistance throughout the processing of your request;
  2. provide information about the Act, including the processing of a request and the right to complain to the Commission d'accès à l'information;
  3. communicate with the requester if clarification is required about your request, such communication to take place as soon as reasonably possible;
  4. use reasonable efforts to locate and retrieve the requested documents;
  5. ensure that the exceptions invoked (in connection with a refusal to disclose all or part of documents) are precise and limited (to such documents);
  6. provide answers that, to the best of its knowledge, are accurate and complete;
  7. promptly provide the information requested as part of the access process; and
  8. if necessary, provide the documents in the format requested or, as the case may be, provide an appropriate place to examine the documents covered by the request.

Although the duty to assist is not covered by any of the parameters of the Act, the person in charge is obliged to provide it diligently and reasonably. However, this does not oblige the person in charge to provide the same explanations to a person several times. Once the person in charge has provided all the information necessary to help the person understand the decision, he or she may choose to stop providing explanations.

17. Distribution and Updating the Policy

This policy will be made available to all employees when they are hired, and then brought to their attention again on a periodic basis. This policy will also be made available, in whole or in part, to each subcontractor upon entering into any contract if required to ensure adequate protection of personal information, including informing the subcontractor of applicable requirements. This policy shall not be shared with other persons (subject to applicable regulatory authorities) unless Groupe Touchette has given its prior written consent. 

In accordance with applicable legal requirements, Groupe Touchette will undertake, on a periodic basis, a review of this Policy. Such revisions may take place when new requirements under applicable laws come into force, following the publication of guidelines by the Commission d'accès à l'information or otherwise when deemed necessary or desirable. The policy may then be revised or supplemented by other policies.

The updated policy (or any other relevant policy) will be made available. Anyone can find out whether this policy has changed by looking at the effective date.

18. Contact Groupe Touchette

GENERAL

Requests, questions or comments should be forwarded to the Privacy Officer at the address Groupe Touchette Inc.

Privacy Officer

750 Lebeau Blvd., Ville Saint-Laurent, QC, H4N 1S4

personalinformation@grtouchette.com

COMPLAINTS

Any person who wishes to file a complaint regarding the collection, retention, use, disclosure or destruction of personal information by Groupe Touchette may contact the Commission d'accès à l'information; in such a case, the complaint must be made in writing in accordance with the applicable process (detailed in particular on its website available here).

Any person may also file a complaint with Groupe Touchette using the contact information provided in section 5. This will involve the following steps:

  1. Submission of complaint. Basic personal information such as name, telephone number and e-mail or postal address should be provided, as well as general information about the complaint, including: (i) on whose behalf the complaint is made; (ii) the type of complaint; and (iii) any other details deemed relevant to the request (e.g. request number, date of request, relevant facts, etc.).
  2. Review. The complaint will be examined as soon as possible. A communication will be made to obtain any further information required, if applicable. Following the investigation, a communication will be made to the person who filed the complaint. 

APPENDIX 1

Retention policy for documents containing personal information

Groupe Touchette attaches great importance to the protection of Personal Information.

In this regard, and in accordance with the Act, Groupe Touchette has developed this policy in order to confirm in writing: (i) the requirements applicable to the retention of documents containing Personal Information; (ii) the types of documents containing Personal Information that are held by Groupe Touchette; (iii) the levels of confidentiality of the Documents; (iv) the types of media for these Documents in order to associate an appropriate retention method and destruction method; and (v) the document retention schedule in compliance with applicable legal requirements.

This policy applies to all documents held by Groupe Touchette, regardless of their medium (paper, electronic or other), including :

In this Policy, the following terms have the meanings set out below:

Unless the context otherwise requires, grammatical variations of any defined term have a similar meaning, and the singular includes the plural, and the masculine includes the feminine, and vice versa.

In accordance with the law, the Privacy Officer is responsible for ensuring that this policy is respected and kept up to date.

Where applicable, each manager or team leader will ensure that this policy is implemented within his or her respective work team, and will submit any questions or requests relating to the retention of documents (including their destruction) to the Privacy Officer.

Groupe Touchette is called upon to collect and process various documents and personal information in the course of its activities. This personal information is collected and processed and these documents are created/received and processed for serious, legitimate and predetermined purposes (subject to applicable legal exceptions, where applicable). 

During this period, documents and personal information will be stored securely and access will be limited to Groupe Touchette employees and, where applicable, subcontractors or consultants who require access in the course of their employment or mandate.

In order to comply with the foregoing, Groupe Touchette has drawn up a document retention schedule, available below. This schedule indicates the retention period deemed appropriate by Groupe Touchette for the various types of documents (and the personal information contained therein). Accordingly, such Documents will be retained for the period indicated in the retention schedule, unless otherwise instructed in writing in the event that certain Documents (or the Personal Information contained therein) must be retained for an additional period of time, as permitted or required under applicable laws.

When the purposes for which such documents (or the Personal Information contained therein) are to be used are fulfilled, such documents/personal information will be destroyed, unless the law imposes a specific retention period with respect to such personal information or Document.

Periodically, the Privacy Officer, in conjunction with applicable managers and team leaders, will ensure that documents that have reached the retention period prescribed in the Retention Schedule are, depending on the medium of the documents, erased or otherwise securely destroyed.

If you have any questions about this policy, please contact the Privacy Officer :

Privacy Officer

Address: 750 Lebeau Blvd., Saint-Laurent, QC, H4N 1S4

Email : informationpersonnelle@grtouchette.com

Phone : 514-381-1716

This policy will be available to all employees on Groupe Touchette's intranet. In addition, this policy will be brought to the attention of all employees involved in document management, at the time of hiring or at any other time deemed appropriate.

Groupe Touchette reserves the right to update or otherwise modify this policy from time to time. Any substantial change will be brought to the attention of the relevant employees by any means deemed acceptable by the Privacy Officer. Subsequently, the updated policy will be made available and easily accessible on Groupe Touchette's intranet. A new version of this policy will also be published whenever a minor change is made. You can tell whether this policy has changed by looking at the effective date indicated on its first page. Groupe Touchette recommends that this policy be reviewed periodically to ensure that everyone concerned remains aware of and complies with Groupe Touchette's current document retention and destruction practices at all times.

APPENDIX 2

Access, rectification and other requests

Groupe Touchette takes the necessary steps to ensure that individuals can exercise their rights. Groupe Touchette informs the public where and how to access personal information.

Failure to respond to a request for access within the applicable 30-day time limit shall be deemed to constitute a refusal of access to the document. In the case of a written request, this failure gives rise to a right of review under the Private Access Act as if access had been refused.


[1]  At the request of the applicant, computerized personal information must be communicated in the form of a written and intelligible transcript. Unless this raises serious practical difficulties, computerized personal information collected from the applicant - and not created or inferred from personal information concerning him or her - is communicated to him or her in a structured and commonly used technological format at his or her request. This information is also communicated, upon request, to any person or organization authorized by law to collect such information. When the applicant is a disabled person, reasonable accommodation measures are taken upon request.