GoodRoads.ca
Privacy Policy


Our Commitment to Privacy:

Good Roads/Ontario Good Roads Association is committed to protecting the privacy of the personal information of its members, employees, volunteers, and other stakeholders. This Privacy Policy documents our ongoing commitment to privacy and has been developed in compliance with applicable privacy legislation.

Website: Privacy Policy Update

Revised Cookie Banner/Pop-Up:

Good Roads uses cookies on GoodRoads.ca to improve your experience, understand how the website is used, and provide more relevant content and communications.

We use a simple opt‑in model for cookies:

  • If you accept cookies: We place optional analytics and marketing cookies on your device. These help us understand how visitors use the site, measure the effectiveness of our communications, and support features such as form submissions and contact management.
  • If you decline cookies: Only essential cookies that are required for the consent process and basic site functionality are stored. In this case, we do not set analytics or marketing cookies and do not link your browsing activity to a contact record.

Cookies used on our website fall into two categories:

  • Essential (strictly necessary) cookies: These are required for basic site and consent‑management functions, such as recording your cookie preference and respecting opt‑out requests. They do not require your consent and cannot be disabled through our cookie settings.
  • Non‑essential cookies (analytics and marketing): These include cookies that track visits, sessions, and interactions, and support campaign measurement and more relevant communications. These are only set if you choose to accept cookies via our cookie banner.

You can change your cookie choice at any time by using the “Cookie Preferences” link in the footer of GoodRoads.ca, which will re‑display the cookie banner and allow you to accept or decline cookies again.

 

Privacy Policy
Last updated: August 14, 2026

  1. Our commitment to privacy

Ontario Good Roads Association, operating as Good Roads, respects your privacy and is committed to protecting the personal information entrusted to us.

This Privacy Policy explains how Good Roads collects, uses, discloses, retains and safeguards personal information when you:

  • visit GoodRoads.ca or another Good Roads digital service;
  • create or use a Good Roads account;
  • become a member or corporate partner;
  • register for a course, conference, event or program;
  • subscribe to a newsletter or other communication;
  • complete a survey, application or form;
  • contact us or make an inquiry;
  • serve as a volunteer, instructor, speaker, exhibitor, sponsor or committee member; or
  • otherwise interact with Good Roads.

Good Roads handles personal information in accordance with the Personal Information Protection and Electronic Documents Act, commonly known as PIPEDA, where that legislation applies, and with other applicable privacy requirements.

  1. What is personal information?

Personal information is information about an identifiable individual. Depending on the circumstances, it may include a person’s:

  • name, title and contact information;
  • account or membership information;
  • registration and attendance information;
  • payment and transaction information;
  • accessibility, dietary or accommodation information;
  • correspondence, inquiries and feedback;
  • survey responses;
  • photographs, video or audio recordings;
  • online identifiers, such as an IP address, cookie identifier or device information; and
  • information submitted through applications, nominations, registrations or other forms.

Personal information generally does not include business contact information that is collected, used or disclosed solely for communicating with an individual in relation to their employment, business or professional responsibilities, where permitted by law.

  1. Accountability

Good Roads is responsible for personal information under its control. We have designated a Privacy Officer to oversee our privacy-management practices and respond to privacy questions, concerns and access requests.

Good Roads remains accountable for personal information transferred to service providers for processing on our behalf. We use contractual, administrative and other measures designed to require service providers to protect information and use it only for authorized purposes.

  1. Personal information we collect

The information we collect depends on how you interact with us.

Information you provide

We may collect information when you:

  • create or update an account;
  • purchase a membership, course, event registration, publication or service;
  • register for a conference, webinar, workshop or other event;
  • submit a nomination, application, proposal or survey;
  • subscribe to a newsletter;
  • contact Good Roads;
  • participate in a committee, research project or consultation;
  • apply for a job or volunteer opportunity; or
  • request an accessibility, dietary or other accommodation.

Information collected automatically

When you use GoodRoads.ca, our systems and authorized service providers may automatically collect information such as:

  • IP address;
  • browser and device type;
  • operating system;
  • approximate geographic location;
  • referring website;
  • pages viewed;
  • dates and times of visits;
  • links selected;
  • website interactions;
  • session information; and
  • cookie or similar technology identifiers.

Some of this information may constitute personal information when it identifies an individual or can reasonably be combined with other information to identify an individual.

Information received from others

We may receive personal information from municipalities, employers, event organizers, partners, service providers or other individuals when they register someone for a Good Roads service, identify an organizational contact or otherwise have authority to provide the information.

  1. Why we collect and use personal information

Good Roads may collect and use personal information to:

  • provide memberships, education, events, research, tools and other services;
  • create and administer accounts;
  • process registrations, purchases, invoices and payments;
  • communicate about programs, services, events and organizational activities;
  • respond to questions, requests and complaints;
  • administer memberships and organizational relationships;
  • confirm attendance, credentials, certificates or course completion;
  • plan and operate conferences, courses and events;
  • administer sponsorships, exhibits, awards, committees and volunteer programs;
  • provide requested accessibility, dietary or other accommodations;
  • conduct surveys, consultations, research and service evaluations;
  • improve our website, communications, programs and user experience;
  • understand website performance and audience engagement;
  • maintain the security and integrity of our systems;
  • prevent fraud, misuse and unauthorized activity;
  • maintain appropriate business and financial records;
  • comply with legal, regulatory, insurance and contractual requirements; and
  • carry out another purpose that we explain when the information is collected.

We limit collection to information that is reasonably necessary for the identified purposes.

  1. Consent and your choices

Good Roads obtains consent for the collection, use and disclosure of personal information unless consent is not required or is otherwise permitted by law.

The appropriate form of consent will depend on the sensitivity of the information and the reasonable expectations of the individual. Consent may be express or implied, depending on the circumstances.

When we request consent, we will make reasonable efforts to explain:

  • what information is being collected;
  • why it is being collected;
  • how it will be used;
  • whether it will be disclosed to another organization;
  • any reasonably foreseeable consequences of providing or refusing consent; and
  • how consent may be withdrawn.

You may withdraw consent, subject to legal or contractual restrictions and reasonable notice. Withdrawal may affect our ability to provide a requested service. We will explain the consequences of withdrawal when appropriate.

  1. Cookies and similar technologies

GoodRoads.ca uses cookies and similar technologies to help our website work effectively and to improve the experience for visitors.

Cookies are small files stored on your browser or device. Some cookies are required for the website to function properly, while others help us understand how the site is being used and how we can improve our content, services and communications.

Essential Cookies

Essential cookies help support core website functions such as security, navigation, accessibility, forms, account sessions and privacy preferences. Because these cookies are necessary for the website to operate, they cannot be turned off through our Cookie Preferences settings.

Analytics Cookies

With your consent, we may use analytics cookies to better understand how visitors use GoodRoads.ca. This may include information such as pages visited, referral sources, website interactions, browser or device information and general location information.

We use this information to identify trends, improve website performance and make our content and services more useful to visitors.

Marketing Cookies

With your consent, we may also use cookies to help us understand the effectiveness of promotional campaigns, links and communications.

These cookies may be provided by Good Roads or by third-party service providers we use to support our communications and marketing activities.

Third-Party Services

Some areas of GoodRoads.ca may include services or content provided by third parties, such as videos, maps, social-media features, event services or registration platforms.

These providers may use their own cookies or similar technologies and may collect information in accordance with their own privacy policies.

Where our website technology allows, optional cookies and third-party technologies will only be activated once you have provided consent.

Managing Your Cookie Preferences

You can accept, decline or manage optional cookies through the cookie banner or the Cookie Preferences link available in the website footer.

You can change your preferences at any time. You may also adjust your browser settings to block or delete cookies; however, doing so may affect how some parts of the website function.

  1. Communications and newsletters

Good Roads may send administrative communications that are necessary to provide a membership, registration, account, transaction or requested service.

We may also send newsletters, educational updates, event information and promotional communications where you have consented or where otherwise permitted by law.

You can unsubscribe from promotional electronic communications by using the unsubscribe link in the message or by contacting us. You may continue to receive transactional or service-related communications where necessary.

  1. Payments

Payments may be processed by third-party payment-service providers. Good Roads may receive limited transaction information, such as the payer’s name, contact information, transaction amount, payment status and a payment reference number.

Good Roads does not store complete payment-card numbers. Payment providers handle payment information under their own terms and privacy practices.

  1. Disclosure of personal information

Good Roads does not sell or rent personal information.

We may disclose personal information:

  • to employees, contractors and volunteers who need the information to perform authorized duties;
  • to service providers that host, process, secure or support our website, accounts, payments, communications, surveys, events, courses or business systems;
  • to instructors, venues, event partners or accommodation providers where necessary to deliver a requested service;
  • to a municipality, employer or organization that registered or paid for an individual’s participation, where appropriate and communicated;
  • with an individual’s consent;
  • to collect a debt, investigate fraud or protect Good Roads, its users or others;
  • in connection with a proposed or completed organizational transaction, subject to appropriate protections; or
  • where required or permitted by law.

Service providers may include website hosts, cloud-service providers, registration platforms, learning-management systems, email-distribution services, analytics providers, payment processors, event-technology providers and professional advisers.

We require service providers to use personal information only for authorized purposes and to provide safeguards appropriate to the sensitivity of the information.

  1. Processing outside Canada

Good Roads and its service providers may process or store personal information outside Ontario or outside Canada, including in the United States.

When information is processed in another jurisdiction, it may be subject to the laws of that jurisdiction and may be accessible to courts, law-enforcement agencies, regulators or national-security authorities in accordance with applicable law.

Good Roads uses reasonable contractual, administrative and technical measures to protect personal information handled by service providers, regardless of where it is processed.

You may contact the Privacy Officer for additional information about Good Roads’ use of service providers outside Canada.

  1. Conference and event applications

Good Roads may use mobile applications, online platforms or digital services to support conferences, courses and events.

Depending on the service and your selections, these platforms may process information such as:

  • your name, title, organization and contact details;
  • registration and attendance information;
  • session selections;
  • profile information;
  • messages or networking activity;
  • survey responses;
  • device and usage information; and
  • information you choose to make visible to other participants.

Before using an event application or platform, participants should review the applicable notices and privacy settings. Information made visible through networking or participant-directory features may be seen by other authorized users.

Good Roads retains event-platform information only for as long as reasonably necessary for the identified purposes, subject to legal, operational and contractual requirements.

  1. Photography, video and audio at events

Good Roads may photograph, livestream, film or record activities at conferences, courses and other events for documentation, education, communications, archival and promotional purposes.

We will provide reasonable notice when photography or recording is expected. Where appropriate, we may use signage, registration notices, announcements, designated photography areas or individual consent forms.

Images or recordings may appear on Good Roads websites, social-media accounts, publications, presentations, advertisements or other communications.

Individuals who do not wish to be prominently photographed or recorded should notify Good Roads before or during the event. We will make reasonable efforts to accommodate the request, although we may not be able to prevent incidental inclusion in crowd or background images.

Separate express consent should be obtained for testimonials, featured interviews or uses involving sensitive circumstances.

  1. Safeguards

Good Roads uses physical, administrative and technical safeguards appropriate to the sensitivity of the personal information in its custody or control.

Safeguards may include:

  • access restrictions;
  • account and password controls;
  • secure technology and hosting practices;
  • confidentiality requirements;
  • employee and contractor training;
  • service-provider agreements;
  • records-management procedures;
  • secure disposal practices;
  • security monitoring; and
  • incident-response procedures.

No system or method of electronic transmission is completely secure. Good Roads nevertheless takes reasonable measures to protect personal information against loss, theft, unauthorized access, disclosure, copying, use, modification or disposal.

  1. Privacy breaches

Good Roads maintains procedures for responding to suspected or confirmed privacy and security incidents.

Where a breach of security safeguards creates a real risk of significant harm, Good Roads will notify affected individuals and report the breach to the Office of the Privacy Commissioner of Canada as required by PIPEDA. Good Roads will keep a record of every breach of security safeguards, whether or not it is reportable, for at least 24 months, as required by law.

 

  1. Retention and disposal

Good Roads retains personal information only for as long as reasonably necessary to:

  • fulfill the purposes for which it was collected;
  • provide requested services;
  • satisfy legal, accounting, insurance or reporting requirements;
  • resolve disputes;
  • enforce agreements; and
  • maintain appropriate organizational records.

Retention periods vary depending on the type of information and the reason it was collected.

When personal information is no longer required, we securely delete, destroy or anonymize it, subject to applicable legal and operational requirements.

  1. Accuracy

Good Roads takes reasonable steps to ensure that personal information is accurate, complete and up to date when it is used to make a decision about an individual or disclosed to another organization.

You are encouraged to update your account information or contact us when your information changes.

  1. Accessing or correcting your information

You may request access to personal information Good Roads holds about you. You may also ask us to correct information that is inaccurate or incomplete.

To process a request, we may need to verify your identity. We will respond within the time required by applicable law.

Access may be limited or refused where permitted or required by law, including where the information:

  • contains personal information about another individual;
  • is protected by solicitor-client privilege;
  • contains confidential commercial information; or
  • cannot be disclosed for legal, security or other permitted reasons.

When access is refused, we will explain the reason, subject to legal restrictions, and advise you of available complaint options.

  1. External websites and social media

GoodRoads.ca may contain links to websites, applications or social-media platforms operated by other organizations.

Good Roads is not responsible for the privacy, security or content practices of third-party services. You should review the privacy policy of a third-party service before providing information to it.

Information posted publicly on social media or other public forums may be viewed, collected and used by others.

  1. Complaints and questions

You may contact the Good Roads Privacy Officer to:

  • ask a question about this Privacy Policy;
  • request access to or correction of your information;
  • withdraw consent;
  • raise a privacy concern; or
  • make a complaint about Good Roads’ information-handling practices.

Good Roads will investigate privacy complaints in a fair and timely manner and will take appropriate steps where a concern is found to be justified.

Privacy Officer

Ontario Good Roads Association
1525 Cornwall Road, Unit 22
Oakville, Ontario L6J 0B2
Canada

Email: Rachel@GoodRoads.ca
Telephone: 905-630-0542

You may also contact the Office of the Privacy Commissioner of Canada regarding a privacy concern.

  1. Changes to this Privacy Policy

Good Roads may update this Privacy Policy to reflect changes to our services, technology, practices or legal obligations.

The current version will be posted on GoodRoads.ca with its effective date. Where a change is significant, we may provide additional notice where required.

Continued use of a service after a policy update does not by itself constitute consent to a new collection, use or disclosure of personal information where additional consent is legally required.


Good Roads Privacy Breach and Crisis Communications Plan

Plan owner: Privacy Officer
Executive lead: Executive Director
Communications lead: Manager, Communications and Marketing
Review cycle: Annually and following any significant incident

  1. Purpose

This plan outlines how Good Roads will respond when personal information is lost, accessed, used, disclosed or altered without authorization.

The priorities are to:

  • protect affected individuals;
  • contain the breach;
  • understand what happened;
  • meet legal and regulatory obligations;
  • communicate accurately and compassionately;
  • protect organizational operations and trust; and
  • prevent a similar incident from happening again.
  1. Examples of a privacy breach

A breach may include:

  • an email sent to the wrong recipient;
  • a lost or stolen computer, phone or document;
  • unauthorized access to an employee or member account;
  • phishing, ransomware or another cyberattack;
  • personal information accidentally posted online;
  • improper access by an employee, contractor or volunteer;
  • compromised membership, education, conference or payment systems; or
  • a breach involving a Good Roads service provider.

All suspected breaches must be reported immediately, even when the full circumstances are not yet known.

  1. Breach Response Team

The following individuals should form the core Breach Response Team:

Privacy Officer

  • Opens and maintains the incident record.
  • Coordinates the response.
  • Leads the privacy-risk assessment.
  • Coordinates regulatory reporting and affected-person notification.
  • Documents decisions and corrective actions.

Executive Director

  • Provides executive oversight.
  • Approves major operational and public communications.
  • Notifies the Board Chair when appropriate.
  • Authorizes legal, technical or forensic support.

Information Technology Lead or Provider

  • Contains and investigates the incident.
  • Secures systems and accounts.
  • Preserves evidence and system logs.
  • Determines what information and systems were affected.
  • Restores secure operations.

Communications Lead

  • Prepares internal and external communications.
  • Develops key messages, notices and media responses.
  • Coordinates website, email and social-media updates.
  • Monitors media and public reaction.
  • Maintains consistency across all communications.

Legal Counsel

  • Advises on notification, reporting and contractual obligations.
  • Reviews communications and regulatory submissions.
  • Helps protect legal privilege where appropriate.

Good Roads may also involve Human Resources, Finance, Membership, Education, Events, insurers and relevant vendors.

  1. Immediate Response

Step 1: Report and activate

Anyone discovering a suspected breach must immediately contact:

  • the Privacy Officer;
  • the Executive Director; and
  • the designated IT contact.

Employees must not independently contact affected individuals, journalists or external parties unless authorized.

Step 2: Contain the breach

Immediate containment may include:

  • disabling compromised accounts;
  • changing passwords;
  • isolating affected systems;
  • removing exposed information;
  • recalling an email;
  • asking an unintended recipient to securely delete information;
  • suspending a vendor connection;
  • recovering lost devices or documents; and
  • preserving logs, emails and other evidence.

Containment should occur without destroying information that may be needed for the investigation.

Step 3: Establish the facts

The Breach Response Team should determine:

  • what happened;
  • when it happened;
  • when it was discovered;
  • whether the breach is continuing;
  • what systems or vendors were involved;
  • what personal information was affected;
  • approximately how many people were affected;
  • whether the information was viewed, copied or misused;
  • who may have accessed it; and
  • what actions have already been taken.

Unconfirmed information should be clearly identified as preliminary.

  1. Assess the Risk

Good Roads should assess:

  • the sensitivity of the information;
  • whether financial, identity, account, health, employment or accommodation information was involved;
  • whether passwords or credentials were exposed;
  • whether the information was encrypted;
  • the number of people affected;
  • how long the information was exposed;
  • who received or accessed it;
  • whether the information was recovered;
  • the likelihood that it will be misused; and
  • the potential for identity theft, fraud, embarrassment, discrimination, reputational harm or other significant harm.

The Privacy Officer, with legal and technical advice, should document whether the breach creates a real risk of significant harm.

Under PIPEDA, the assessment must consider both the sensitivity of the information and the probability that it has been, is being or will be misused.

  1. Reporting and Notification

When a breach creates a real risk of significant harm, Good Roads should, as soon as feasible:

  • report the breach to the Office of the Privacy Commissioner of Canada;
  • notify affected individuals; and
  • notify another organization or government institution when doing so may help reduce the risk of harm.

PIPEDA requires both regulatory reporting and affected-person notification when the real-risk-of-significant-harm threshold is met.

Legal counsel should also determine whether Good Roads has obligations to notify:

  • its cyber insurer;
  • law enforcement;
  • financial institutions;
  • payment processors;
  • employees;
  • municipalities or First Nations;
  • members and partners; or
  • affected vendors and service providers.
  1. Communications Principles

All communications should be:

Timely: Communicate once enough information is available to provide useful and accurate guidance.

Accurate: Use verified facts and clearly identify preliminary information.

Transparent: Explain what happened, what information was involved and what Good Roads is doing.

Empathetic: Recognize the concern and inconvenience experienced by affected people.

Consistent: Ensure employees, executives, Board members and vendors use the same approved information.

Accessible: Use plain language and provide accessible formats upon request.

Privacy-conscious: Do not reveal additional personal information through the response.

Good Roads should not speculate, minimize the incident or assign blame before the investigation is complete.

  1. Communications Escalation

Level 1 — Limited incident

A small and contained incident involving low-sensitivity information.

Possible response:

  • document the incident;
  • contain and correct it;
  • contact affected individuals where appropriate; and
  • provide internal guidance or retraining.

Level 2 — Significant incident

An incident affecting multiple people or involving information that could result in phishing, embarrassment, financial harm or account compromise.

Possible response:

  • notify affected individuals;
  • brief the Executive Director and Board Chair;
  • prepare member and partner communications;
  • create a media holding statement; and
  • increase inquiry and social-media monitoring.

Level 3 — Crisis-level incident

A major cyberattack, ransomware event, widespread system compromise or breach involving highly sensitive information.

Possible response:

  • immediately activate the full response team;
  • notify the Board and insurer;
  • engage legal counsel and forensic experts;
  • report to regulators;
  • directly notify affected individuals;
  • publish a website update;
  • issue member, media and partner communications;
  • establish a dedicated email address or telephone line; and
  • provide scheduled updates until the situation stabilizes.

The response level may change as more information becomes available.

  1. Key Audiences

Depending on the incident, communications may be required for:

  • affected individuals;
  • employees;
  • the Board of Directors;
  • municipal and First Nations members;
  • corporate partners;
  • course and event participants;
  • instructors, speakers, sponsors and exhibitors;
  • service providers;
  • regulators;
  • insurers;
  • law enforcement;
  • media; and
  • the public.

Affected individuals should generally hear directly from Good Roads before, or at the same time as, a broader public announcement.

  1. Core Message Framework

Every breach communication should answer:

  1. What happened?
  2. What information was involved?
  3. What has Good Roads done to contain it?
  4. What risks may affected individuals face?
  5. What should affected individuals do now?
  6. Where can people obtain additional information or assistance?
  1. Initial Holding Statement

“Good Roads recently identified a privacy and security incident involving one of our systems or services. Upon discovering the incident, we took immediate steps to contain it and began an investigation with appropriate technical and privacy advisers.

Our priority is protecting the individuals who may be affected and determining the nature and scope of the incident. We will communicate directly with affected individuals and notify the appropriate authorities where required.

The investigation is ongoing. We will provide further information when confirmed. Questions may be directed to Rachel Swiednicki, at Rachel@GoodRoads.ca.”

This statement must be adapted to the circumstances and approved before release.

  1. Affected-Person Notice

A notice to affected individuals should explain:

  • what happened;
  • when the breach occurred and was discovered;
  • what personal information was involved;
  • the potential risks;
  • what Good Roads has done;
  • what the individual should do;
  • whether authorities were notified;
  • what assistance is available; and
  • how to contact Good Roads and the Privacy Commissioner.

The notice should use direct language and avoid vague expressions such as “some information may have been affected.”

  1. Employee and Media Protocol

Employees should be instructed not to speculate or provide independent comments.

All media inquiries should be directed to the Communications Lead. The Executive Director or another designated spokesperson should provide public comments.

A standard employee response may be:

“Good Roads is actively reviewing the matter. To ensure you receive accurate and current information, please direct your inquiry to Rachel Swiednicki, Rachel@GoodRoads.ca.”

The Communications Lead should maintain:

  • approved key messages;
  • a frequently asked questions document;
  • a media-inquiry log;
  • an affected-person inquiry log; and
  • copies of every public statement and update.
  1. Documentation and Record-Keeping

Good Roads must create a record of every breach, including incidents that do not require notification.

The record should document:

  • what happened;
  • dates of occurrence and discovery;
  • information and systems involved;
  • affected individuals;
  • containment measures;
  • the risk assessment;
  • the decision about reporting and notification;
  • communications issued;
  • corrective actions; and
  • final outcomes.

PIPEDA regulations require breach records to be retained for 24 months after Good Roads determines that the breach occurred.

  1. Recovery and Follow-Up

Following the incident, Good Roads should complete a formal review addressing:

  • the root cause;
  • whether policies and procedures were followed;
  • technical or vendor weaknesses;
  • the effectiveness of communications;
  • whether safeguards should be strengthened;
  • whether contracts need to be updated;
  • additional employee training;
  • required privacy-policy changes; and
  • lessons for future incidents.

Each corrective action should have an assigned owner and completion date.

Significant incidents should be reported to the Board, including the cause, impact, response, cost, lessons learned and corrective measures.

  1. Preparedness Checklist

Before a breach occurs, Good Roads should maintain:

  • a formally designated Privacy Officer and alternate;
  • an up-to-date emergency contact list;
  • a current inventory of systems, vendors and personal information;
  • cyber-insurance contact information;
  • access to privacy counsel and cybersecurity support;
  • contract clauses requiring vendors to promptly report breaches;
  • approved notice and holding-statement templates;
  • multi-factor authentication on critical accounts;
  • secure and tested backups;
  • annual privacy and cybersecurity training; and
  • an annual tabletop breach-response exercise.