Privacy Policy

Purpose

This policy describes and explains how and why OPL collects, uses, protects, and/or shares personal information about clients.

Statement

OPL is committed to protecting the privacy of individuals by protecting personal information in its custody or control. OPL is equally committed to the value of integrity, showing transparency and accountability in its operations and interactions with clients.

Application

This policy applies to all employees when handling client information in both physical and digital formats. This policy does not apply to:

  • Personally identifiable information that is maintained for the purpose of creating a record that is available to the public. For example, cataloguing records for collection items; or,
  • OPL employment files, including employee performance management records and labour relations records.

Definitions

  • Anonymization: The process of removing or altering personal information so that it cannot reasonably be used to identify an individual. Properly anonymized information is not personal information.
  • Anonymous information: Information that does not identify, and cannot reasonably be used, alone or in combination with other information, to identify an individual. Anonymous information is not personal information.
  • Client: An OPL cardholder, visitor to any OPL space (facility, virtual, or mobile), and program attendee.
  • Cookie: A small text file stored on a user’s device by a web browser that may contain information such as preferences, session identifiers, or usage data. Cookies may be used to support website functionality, analytics, and user experience.
  • Identifiable individual: An individual who can be identified directly or indirectly, including using information alone or in combination with other reasonably available information.
  • IP address: A numerical label assigned to a device connected to a network that can be used to identify the device or approximate its location. An IP address is personal information when it can reasonably be linked to an identifiable individual, either alone or in combination with other data.
  • Personal information: Recorded information about an identifiable individual. This includes information that directly identifies an individual (e.g., name) and information that can identify an individual indirectly when combined with other data. Examples include, but are not limited to: address, telephone number, email address, identification numbers, financial transaction information, private correspondence, and online identifiers such as IP addresses where they can be linked to an individual. Information associated with an individual in a professional, business, or official capacity is not personal information, unless it reveals personal characteristics or can identify the individual in a personal capacity. Personal information is used by OPL for the purpose(s) for which it was originally collected or for a purpose consistent with library operations. Access to personal information is restricted to those employees who require it to perform their job duties.
  • Privacy breach: Personal information is stolen, lost, or shared without permission.
  • Third-party service provider: An external organization that provides services to or on behalf of OPL and may have access to personal information (e.g., e-content providers, collections agencies, survey platforms). Where there is any inconsistency between these definitions and applicable legislation, the legislation prevails.

Policy requirements

OPL manages personal information according to responsibilities and requirements set out under the Municipal Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. M.56 (MFIPPA) and other applicable legislation. OPL collects personal information about clients under the authority of the Public Libraries Act, R.S.O. 1990, c.P.44 and uses it for the purposes of delivering library services and programs.

Personal information collected and used by OPL

  • When clients get an OPL card: OPL collects personal information such as name, date of birth, address, and telephone number when a client gets a library card, and when managing their client account. This personal information is used to prevent fraudulent activity and ensure OPL can personally identify clients who borrow material from the library. For clients aged 15 or younger, OPL also collects the name of the client’s parent or guardian. Personal membership information is also linked with information collected as part of requesting or borrowing materials, described in the next section.
  • When clients request or borrow items from OPL: OPL keeps record of items a client has previously borrowed. Specifically, OPL keeps:
    • An indefinite record of all clients and their current checkouts are kept, to help with the recovery of materials or fees for missing and damaged items. This information is kept with the item record and can be retrieved until the item is checked out and returned by another client;
    • A record of items borrowed by Home Services clients for the period during which they are a client of this service, to deliver an efficient experience;
    • A record of items borrowed is retained and can be retrieved for 90 days:
      • If a client asks to OPL to keep it (an “opt in” option via the online catalogue): A record is kept of all items borrowed;
      • All clients, even if they did not choose to “opt in” as above: A record is kept of some items borrowed that are not in the general collection (see the Loan periods and fees web page for more information);
    • A record of items billed to a client is kept indefinitely; and,
    • A record of client requests for material in the collection is kept indefinitely.
  • When clients view OPL’s website: OPL collects IP addresses from visitors to the OPL website. An IP address is personal information when it can reasonably be used, alone or with other information, to identify an individual. No other personal information is collected when a client visits the OPL website, unless the client chooses to use services that need other personal information. IP addresses are collected for security, system administration, fraud prevention, and analytics purposes and are retained only as long as necessary for those purposes. OPL’s web servers keep a log of keyword searches on the OPL website. OPL also keeps statistics to learn more about how people use the library’s website, such as which pages are popular, what times of day people visit the site, and what types of computers or web browsers visitors are using. This information helps improve virtual services. The data OPL obtains is collected from many different visitors and web addresses, and it is kept anonymous; OPL cannot identify any specific client from individual data sets. When a client visits the OPL website, the pages they see, along with a cookie, are saved on their computer, tablet, or phone.
  • When clients fill out a form on OPL’s website: Personal information collected through OPL forms (for programs, equipment, meeting room use, and feedback) is limited to what is necessary to administer services. Information is retained for 7 years in accordance with records management policies. OPL may collect data periodically by way of questionnaires for the purposes of business analysis. Questionnaire data is anonymized to remove direct and indirect identifiers, and OPL takes reasonable steps to prevent re-identification.
  • When clients use the Internet at OPL: Internet access is available at OPL via a Wi-Fi network (accessible via clients’ personal devices or Chromebooks borrowed from OPL) as well as via public computer workstations in branches. Access at OPL is via public Internet networks that filter traffic to block spam, phishing, malicious content, proxy avoidance, and illegal content. Websites visited when using the Internet at OPL may contain separate cookies from these websites. OPL does not control these cookies. OPL does not look at or keep client information, or a history of what pages are visited by clients on the network, either via Wi-Fi or public PC, once they log off. The Terms of use - public network web page provides more information about public network use at OPL.
  • A note about third-party organizations: OPL ensures that agreements with third-party service providers require compliance with privacy obligations and that, when required under MFIPPA, OPL provides appropriate notice to clients when information is collected by or disclosed to third parties. OPL shares information with other (third-party) companies for services, including:
    • Companies that provide e-Content or special collections that are not part of the “General collections” listed on the Loan periods and fees web page;
    • Companies that assist in account collections. For example, OPL may refer clients with outstanding library balances of $50 or more that have been owing for 90 days to an external company.
    • Companies that assist in client services. For example, OPL may engage external companies for client questionnaires; and/or,
    • Organizations providing programming in partnership with OPL.

Accessing or changing personal information

Clients can update some of their own personal information through accessing their online account. Clients can ask staff to review and update personal information. Lastly, they can request a copy of all personal information kept by OPL by completing the form on the OPL website or writing to the OPL MFIPPA Coordinator, 120 Metcalfe Street, Ottawa, ON K1P 5M2 or OPL-MFIPPA@ottawa.ca.

Children's personal information

Parent or guardian access to a child’s personal information is subject to MFIPPA and applicable consent and custody considerations. People with custody of a child under than 16 years of age can decide which type of children’s library card is appropriate for their child, including an option for a card that does not allow Internet access. Parents also have access to the personal information held by the library about their child and can access their child’s account. When an individual turns 16, OPL provides direct access rights to them, subject to MFIPPA and applicable restrictions, and OPL can no longer provide access for parents to their child’s account information without the child’s consent.

Children 16 and older receive a different card type each year until they turn 18, which provides access to different collections in alignment with applicable legislation: for example the Film Content Information Act, 2020 prohibits a person from selling or renting a physical copy of a video game with an ESRB rating of “Mature” to a person who is under 17 years of age and prohibits a person from selling or renting a physical copy of a video game with an ESRB rating of “Adults Only” to a person who is under 18 years of age.

Privacy breaches

Upon discovering a privacy breach, OPL will follow the guidelines of the Information and Privacy Commissioner of Ontario (IPC) on managing privacy breaches and:

  • Investigate the situation, including the scope of the breach;
  • Protect or contain any information possible, make sure no copies of information have been made, and take steps to prevent a further breach;
  • Contact all affected clients;
  • Review the situation to recommend any changes to policies or library operations to prevent a future similar breach;
  • Notify colleagues, as needed, including the Library Senior Management Team;
  • Keep a record of the breach in a centralized breach log, including risk assessment and mitigation steps; and,
  • Report breaches to the IPC where required under IPC guidelines, and notify any other organizations, as applicable.

 

This page was last updated September 21, 2026.