Actually, if I could add a gloss to that, I would say it's typically the decision of the organization at first instance, but it's ultimately a determination to be made by the Privacy Commissioner of Canada.
On February 1st, 2007. See this statement in context.