CareNucleus — Privacy operations playbook
Not legal advice. Use with your Privacy Officer and counsel. Last updated March 23, 2026.
1. Data subject access requests (DSAR)
- Intake — Record type, patient ID, date received, identity verification.
- Route — Custodian is primary; CareNucleus assists as processor where applicable.
- Timeline — Target 30 days (PIPEDA) unless lawfully extended.
- Fulfillment — Export/redact; minimize disclosure.
- Close — Record in Privacy Dashboard and retain audit trail.
2. Breach of security safeguards
- Contain — Stop exposure; preserve evidence.
- Assess — Scope, sensitivity, RROSH.
- Notify — OPC / provincial commissioner / individuals as required.
- Record — Breach record in Privacy Dashboard.
- Remediate — Root cause and controls.
3. Complaints
Acknowledge within 5 business days; investigate; respond with recourse to OPC/IPC.
Compliance · Subprocessors