Showing posts with label nova scotia. Show all posts
Showing posts with label nova scotia. Show all posts

Sunday, November 09, 2025

Nova Scotia's new Freedom of Information and Protection of Privacy Act (Bill 150)



In just the past month, kind of unexpectedly, the Nova Scotia government introduced and passed a new public sector privacy and access to information law that completely replaces the existing Freedom of Information and Protection of Privacy Act (known here as “FOIPOP") with a new law that will come into effect in April of 2027.

This isn’t completely out of the blue because the Nova Scotia government has been “reviewing” FOIPOP since 2022, but unlike in most provinces it has been “behind the scenes”. Unlike other provinces, which have public consultations, Nova Scotia’s consultation on transparency was behind closed doors.


I wrote to the then Minister of Justice seeking to participate on behalf of the Nova Scotia branch of the Canadian Bar Association’s Privacy And Access Law Section. The CBA was never invited to chat. I wonder who else commented. We were told that the results of this review would be made public, but they never were. All we got was Bill 150, dropped in the legislature on September 26 and passed on October 3. There was no real opportunity given for privacy and access to information experts to appear in committee with their comments. 


In this episode, I’m going to do a relatively high-level overview of what’s changing with the new FOIPOP that will come into effect in 2027. There’s some good, some bad and some changes that I’m indifferent to. I hope I can provide a relatively unbiased view of it, given that I do legal work for applicants who are seeking access to records, for public bodies who have to comply with the law and third parties whose records held by public bodies are sometimes the subject of access requests. 


There’s a big change to the purposes clause of the law. The original FOIPOP was relatively unique among access to information laws in Canada in that it clearly had as its intent full transparency, accountability and access – as fundamental to how democracy should work. 


The purpose clause in the current act includes:


2. The purpose of this Act is …


(b) to provide for the disclosure of all government information with necessary exemptions, that are limited and specific, in order to

(i) facilitate informed public participation in policy formulation,

(ii) ensure fairness in government decision-making,

(iii) permit the airing and reconciliation of divergent views;


That part is gone. Just removed. The leader of the opposition made a motion to have it returned, but the motion was defeated.


That’s too bad. The purpose clause is important in how regulators and courts approach the law, and future governments will be able to say it was removed for a reason and that should influence how it is interpreted. That’s a real step backward. 


As I said, the new Act fully repeals and replaces the earlier statute. It restructures the entire Act into clear Parts (e.g., Part I – Freedom of Information; Part II – Protection of Privacy; Part III – Reviews and Appeals; Part IV - Information and Privacy Commissioner), and has a number of standardized definitions for consistent terminology (like “access request,” “correction request,” etc.), and procedural timelines are now measured in business days rather than calendar days. This will draw out access requests. Previously, the public body had thirty days; now it’s thirty business days. That’s thirty five percent longer. Easier on the public body, to be sure, but it will mean it takes longer to get requested information from public bodies.


An important change in the new FOIPOP is that it will include municipalities. The Commissioner's jurisdiction is significantly expanded through the consolidation of provincial and municipal regulation. Specifically, the new Act repeals Part XX of the Municipal Government Act and integrates municipalities and municipal bodies into the general FOIPOP framework. Part XX of the MGA was generally a mirror of FOIPOP, but with some significant differences. Bringing municipalities into FOIPOP means the Commissioner now has explicit and uniform jurisdiction to conduct reviews and investigations involving municipal units. The Review Officer's previous roles in handling appeals related to access and correction requests are maintained, but the new Act formalizes two new categories of complaint investigation called Privacy Reviews. These reviews can be initiated by individuals who believe their personal information was collected, used, or disclosed in contravention of the Act, or proactively by the Commissioner if there are reasonable grounds to suspect a contravention.


One of the most important changes is that the former “review officer” is now the Information and Privacy Commissioner of Nova Scotia, and will be an officer of the Nova Scotia House of Assembly. While still appointed by the Governor-in-Council, this position is much more independent of government than under the present Act. A big miss, at least as far as critics are concerned, is that the Commissioner does not have the ability to issue binding orders on public bodies. That position still just issues recommendations, and it’s up to applicants to go to court to get orders.

The 2027 Act introduces or revises numerous definitions, including “Personal information” which now explicitly includes IP addresses, biometric data, and genetic characteristics, while excluding business contact information.


In the part of the Act related to the right of access to public body records, changes clarify that the right of access extends to records in custody or control of a public body, but not to duplicates or exact copies. It says that part of a record that can be withheld and can be reasonably severed, access must be provided to the remainder of the record.


Not surprisingly, the amendments made earlier this year related to frivolous, vexatious and unduly repetitive requests have been continued in the new FOIPOP. The Commissioner must approve a request from a public body to disregard a request, with defined criteria and 14-business-day timelines for both application and decision. It does provide applicants with a right to appeal to the Supreme Court of Nova Scotia if their request is disregarded.


Almost all the timelines in FOIPOP have been extended. All procedural periods are now in business days (such as giving a public body 30 business days to respond to an access request). It also introduces an  explicit suspension of time calculations while fees are being negotiated or reviews are underway (s. 20).

The government gets to set a standard application fee pursuant to the regulations, and also sets  service-based fees but exempts requests for one’s own personal information and provides 3 free hours of work time. Public bodies can charge additional fees if the request will take more than three hours. When presented with a fee estimate, applicants may narrow their requests accordingly. Once the request is being processed, a public body can provide a “revised fee estimate” that the applicant can either accept or revise their request. Fee estimates and revised fee estimates can be referred to the Commissioner. 


There remains a possibility for fee waivers where disclosure serves a public interest (e.g., environment, public health, or safety), or if the applicant can’t afford to pay the fee.


One thing that is interesting and progressive: The new FOIPOP specifically says that public bodies must provide electronic records in “an electronic form that is capable of re-use”. This is positive. If the record is an Excel spreadsheet, the spreadsheet itself should be provided and not just a photocopy of the spreadsheet. (There are few things as useless and opaque as a print-out of an excel spreadsheet full of formulas.)

There are a number of changes that will restrict public and journalistic access to records. The first is an expansion of the definition of “legal privilege” to specifically include settlement privilege. And at section 86(2), the Information and Privacy Commissioner will not be able to inspect a record that is alleged to be privileged to determine if it actually is privileged. Only the Court can do that, and the process to get there can be set out in the regulations.


The second major restriction on the right to know is essentially excluding any right of access to any record that is defined as an “Executive Council record”, going well beyond what was traditionally “cabinet confidences.” To make it worse, in section 32(2), a head of a public body is prohibited from disclosing Executive Council records. There’s no discretion. 


The new Act expands the privacy sections substantially and in a good way, but most of the details will have to wait until we get to see the regulations.

Every public body will have to have a privacy policy and has to publicly disclose its internal privacy-complaint process.


Once the Act comes into effect, every public body will have to carry out a privacy assessment for any new or substantially changed “project, program, system or other activity involving the collection, use or disclosure of personal information”. The details for what must be in a privacy assessment will be determined in regulations. 


The new Act defines “Data-linking” programs – where two or more data sets are combined, either temporarily or permanently, and requires them to be carried out only in accordance with the yet to be seen regulations. 


There are some tweaks to the rules that permit a public body to collect, use or disclose personal information. These public sector privacy laws are generally not based on consent so these rules set the guardrails for public bodies. There are new rules related to inter-agency data sharing, research, and public-interest exceptions.

There’s a new explicit authorization for disclosure to protect individuals from intimate-partner violence or human trafficking.

The new Act introduces obligations to contain, assess, and notify affected individuals and the Commissioner of privacy breaches that pose a real risk of significant harm — aligning Nova Scotia with federal PIPEDA and other provincial models.


There is a weird new provision in s. 79 that authorizes a public body to go to court if “personal information in the custody or under the control of a public body has  been stolen or has been collected by or disclosed to a third party other than as  authorized by this Act”. They can get an order to return or destroy the personal information, or any other order the court considers appropriate to protect the personal information. 


If you’ve been reading or watching my stuff, you may recall that in 2020, the Government of Nova Scotia went to court to try to identify people who may have read unredacted Workers Compensation Appeal Tribunal decisions that were mistakenly given to the Canadian Legal Information Institute, known as CanLII, and they were posted online. I was one of the people they identified, and I was contacted by the government as part of their damage control.  (Here's a video I did on that on my YouTube channel: https://youtu.be/XETVLvkksj0.)


There’s also an interesting, quirky new section that essentially says that a public body is deemed to have not “collected” personal information if it does not relate to a program or activity of the public body, and they either delete it, return it or transfer it to another public body or federal government institution if it’s relevant to the other public body or institution’s programs or activities. 


Individuals still have a right to access their own information, and public bodies have an obligation to retain any information that has been used to make a decision directly affecting an individual for at least one year so the individual can exercise their access right. And also in such circumstances, the public body has to make every reasonable effort to make sure the information is accurate and complete.


While the former Privacy Review Officer Act existed separately, the new Act integrates and strengthens the privacy review powers directly within the consolidated statute, giving the Commissioner an explicit mandate to conduct Privacy Reviews. This authority can be used to investigate complaints that personal information has been improperly collected, used, or disclosed, and allows the Commissioner to proactively initiate an investigation if they have reasonable grounds to believe a contravention has occurred.


Finally, on the privacy side, the new FOIPOP revokes and replaces the Personal Information International Disclosure Protection Act or PIIDPA. That law generally prohibits a public body from allowing personal information to be stored outside of Canada or to be accessed from outside of Canada, subject to some exceptions. Under the new FOIPOP, a public body will only be allowed to store or permit access from outside of Canada in accordance with specific regulations, which we haven’t seen yet.

While the new independent Information and Privacy Commissioner is not granted the ability to issue orders or levy penalties in connection with access, correction or privacy reviews, the Commissioner does have broad powers in connection with carrying out such a review. The Commissioner can summon witnesses and compel records (other than records that are claimed to be privileged). The Commissioner can initiate a privacy review without a complaint or request if the “Commissioner has reasonable grounds to believe that a person has contravened or is about to contravene this Part”.


The Commissioner also has an important role to play in requests that a public body thinks is trivial, frivolous, vexatious or abusive. The public body has to seek the approval of the Commissioner to disregard such requests, which is an important check to prevent the overuse of these new provisions.

Individual complainants, exercising access, correction and privacy rights, still have recourse to the Supreme Court of Nova Scotia. In most cases, that will be following a review by the Information and Privacy Commissioner, but individuals do have the right to skip the Commissioner and go straight to the Supreme Court of Nova Scotia. Once you’re in the Court, it is what’s called a “de novo” proceeding meaning that the Court will determine the matter from the very beginning. And the court can issue binding orders.


Finally, the new FOIPOP expands the number and kind of offences that can result in charges and prosecution: this includes (a) willfully collecting, using or disclosing personal information in contravention of the Act, (b) willfully attempting to gain access to personal information in violation of the Act, (c) obstructing the Commissioner and (d) destroys, alters or falsifies a record to evade a request for access to records. 


So this represents a significant change to the privacy and access to information landscape in Nova Scotia. It repeals the old Freedom of Information and Protection of Privacy Act, the Privacy Review Officer Act, the Personal Information International Disclosure Protection Act and Part XX of the Municipal Government Act, replacing all of them with a new Freedom of Information and Protection of Privacy Act. As I said, it comes into effect in April 2027. 


This has been a relatively high-level overview of the new Act. Each time I read it, I find something new. I would encourage folks in Nova Scotia who have an interest in access to information and privacy to review the legislation, and let the government know if it raises any concerns. Though the process to get here has been the opposite of transparent, there is an opportunity before April 2027 to amend it before it comes fully into effect. 

Thursday, October 19, 2017

My comments on Nova Scotia's Intimate Images and Cyber-protection Act

Note: Because of very short notice, I will not be able to appear at the Nova Scotia Legislature's Law Amendments Committee to provide my views on Nova Scotia's new cyberbullying law. Here are my written comments that will be sent to the Committee for their consideration.

Thank you for the opportunity to provide my views on Bill 27, the Intimate Images and Cyber-protection Act.


I am a lawyer with McInnes Cooper whose practice is focused on internet and privacy law matters. I need to emphasise from the outset that these are my own personal and professional comments, and do not necessarily represent the views of my firm, its clients or any other organizations with which I am associated. I have been practicing in this area of law for over fifteen years. In this context, I am perhaps best known as being a vocal critic of the Cyber-Safety Act and being the lawyer who argued in Court that the old Act was unconstitutional.


If I could first comment on a matter of process, I am disappointed that I am not able to appear before the committee and answer any questions you may have. When this bill was first considered on October 16, 2017, I had less than one business day’s notice of the hearing and was out of town. I was advised on Thursday, October 19 that it would be before the committee on Monday, October 23. That’s one and a half day’s notice and I will be out of town on Monday. If the government were serious about getting this right, surely it would make it easier for experts to appear on the Bill. I am sure the Committee would benefit from testimony from Canadian Civil Liberties Association or the Canadian Bar Association, but these organizations can’t just drop tools, consult with their stakeholders and develop a coherent and helpful position with that kind of notice. I can name  at least five people who have immense expertise in the field of civil rights, cyberbullying, restorative justice and youth suicide who this Committee and Nova Scotians should hear from, but none will have a chance to provide their well-informed and expert views. I do not know if this is peculiar to this bill, but it certainly was the case with the original Cyber-Safety Act and Nova Scotians have suffered as a result.


In the meantime, the government has had a number of targeted consultations. I did meet with Justice officials twice to provide my views, with the final meeting commenting on a draft of the bill. I had some misgivings then which I’ll share with you today.


As I mentioned, I was the lawyer in the case that resulted in the Cyber-Safety Act being declared unconstitutional. I was previously very critical of the law and the former Premier said he “could not disagree with me more”. When that quote was posted by the CBC on their website, that cyberbullied me according to the law’s definition.


While the law was declared unconstitutional on December 10, 2015, it was unconstitutional on the day it was introduced on April 25, 2013, fewer than three weeks after the tragic death of Rehtaeh Parsons.


I stood up in court and called the Cyber-Safety Act a “dumpster fire”. Justice McDougall called it, much more politely, a “colossal failure” as far as the Charter is concerned.  


I argued, and the Court agreed, that the law had two principal failures. The first was that the definition of “cyberbullying” was far, far too broad and would include anything that could hurt someone’s feelings (including legitimate, political speech). The second failure was that a complainant could get a protection order without the alleged cyberbullying ever having an opportunity to defend themselves. The justice of the peace would make a decision on the basis of only hearing one side of the case. And the first that the respondent would hear of it would be when a police officer would show up at their house -- usually at night -- and serve them with the order.


I think both of these issues have been addressed in the new Bill. The definition of “cyberbullying” raises the bar much, much higher. It may be too high, by requiring “malice”, but it does capture communications that are intended to harm the victim. The issue of procedural fairness has certainly been addressed, but I am afraid the pendulum may have swung too far the other way.


The way the Bill sets it out, a victim of cyberbullying has only one option: to commence an application in the Supreme Court of Nova Scotia following the Nova Scotia Civil Procedure Rules. I have 100% confidence in the fairness of a judge of the Supreme Court. But forcing a victim of cyberbullying to start a conventional lawsuit will represent a huge barrier to access to justice.


What I am saying is completely contrary to my own pecuniary self interests. I am a lawyer who practices law in this area. My law partners much prefer that I charge clients for my time and for my services. We have a great pro bono program -- I think it’s one of the best in the country of any law firm that I am familiar with -- but I am not able to take the cases of all victims of cyberbullying. Going to the Supreme Court requires that a victim understand and follow Civil Procedure Rules. They’ll have to read and understand Rules 5, 4, 5, and 6. They have to prepare a notice of application in court and an affidavit, all according to the rules. They’ll have to hire a process server to serve the documents on the respondent. They likely have to be in court across from their tormentor to schedule the next steps and the court hearing. They get a written affidavit from the respondent. They can then maybe file another response affidavit. They can maybe cross-examine the respondent outside of Court, assuming they are in a position to pay a court reporting service to transcribe the cross-examination on an expedited basis. Then they have to file their brief. And then they have their day in Court, except they never get to directly tell a judge their story. They don’t get to testify on their own behalf, since their testimony is only in their affidavit.


I would expect it would cost at least $10,000 for me to represent an applicant in this process. That is daunting. But what’s equally daunting is the prospect of a traumatized cyberbullying victim having to find, let alone understand and precisely follow, the civil procedure rules. That greatly troubles me and I think it should trouble you.


The legislature should seriously consider a different approach. I do not think I have all the answers, but I would suggest that the legislature should consider a less formal approach that still preserves the procedural fairness that was lacking in the old Cyber-safety Act. While the procedure for a peace bond is not without its shortcomings, there should be a procedure through which an applicant can go to court and tell their story. The respondent has the same right to know what is being alleged, to appear, to present their story and possible justification. If neither adduced evidence about some of the essential factors to be considered under the Act, the judge can ask them questions. And a decision follows. This can be before the Supreme Court of Nova Scotia or a judge of the Provincial Court.
I do agree with sidelining the CyberSCAN unit from enforcement of the law. In my experience and in my opinion, they were the wrong tool for the job. While perhaps not representative of all the people with whom they interacted, I consistently heard from and about people whose political or legitimate Charter-protected speech was removed from the internet because they bullied the people into removing it under threat of unspecified “legal action” that could include removing their internet access. It may have been a matter of who they hired for the role or how they were led, but the CyberSCAN unit was part and parcel of the speech suppression that the law represented. When I asked Roger Merrick how the CyberSCAN unit took the Charter into account in doing their jobs, I was told that the legislature took it into account when the bill was passed by this House. That was clearly incorrect.


I do think the CyberSCAN unit or some replacement of it could go good things. Education and awareness is important. Providing support to victims is important. I am sure that victims will need a lot of help in figuring out how to have their day in court, and they can be a resource for that.

One final concern that I have is that the legislation says that if the victim is a minor, their parent or guardian has to commence the application on their behalf. There should be a mechanism by which a minor can do this on their own. First of all, there may be a case where the case relates to intimate images and the minor does not want to tell their parents. Secondly, I can imagine a scenario where the parent is either the perpetrator or is unwilling to help the child. Some safeguard needs to be in place to give a child direct access to the courts.


I do want to take the opportunity to praise the manner in which the non-consensual distribution of intimate images is treated in the statute. By separating this from the definition of cyberbullying, it will effectively shield this from being struck down if the conventional cyberbullying aspect is found to be unconstitutional.


Again, I regret that there was not enough notice for me to appear in person and answer any questions by the Committee. However, I am easy to find and I would be pleased to discuss this important matter with any Committee members or their staffers.

Thursday, December 17, 2015

Nova Scotia's cyberbullying law declared to be unconstitutional and a "colossal failure"

Full disclosure: I was counsel to the applicant respondent in this case. (The party seeking to have the order set aside and to have the statute found to be unconstitutional.)

The Nova Scotia Supreme Court has just released its decision in Crouch v Snell, 2015 NSCC 340 (PDF).

In the decision, the Supreme Court of Nova Scotia has declared the province’s cyberbullying law to be unconstitutional, from start to finish. The law has been found to violate the Canadian Charter of Rights and Freedoms' guarantees of freedom of expression and “life, liberty and security of the person” rights, in a manner that cannot be upheld as a reasonable limit on those rights that can be justified in a free and democratic society. In short, the law is a dramatic failure.

The case related to two adults, former business partners, who had a falling out. Mr. Crouch sought and obtained an ex parte cybersafety protection order before a justice of the peace in December 2014. The respondent (I was his counsel) challenged the order and the legislation.

I have not been known as a fan of the Cyber-safety Act. I've blogged about it, written Op-Eds about it and I've called it a dumpster fire. It was passed unanimously by the Nova Scotia legislature in the immediate aftermath of the tragic death of Rehtaeh Parsons. In my view, it was created in haste in the immediate, emotional aftermath of the tragic death of a young woman who had been sexually assaulted and had photos of the assault circulated around the community. The government of the day -- which was heading for an election -- was not willing to throw the police and the prosecution service under the bus for no charges being laid, so instead created the appearance of doing something by creating and passing a very poorly executed law. In the process, they trampled on the Charter rights of all Nova Scotians and created a distraction from the important discussion about sexual assault and consent.

Among other things, the Act allows an alleged victim of cyberbullying to appear before a justice of the peace to obtain a cybersafety protection order. These orders can go so far as to result in the confiscation of electronic devices and being barred from using the internet. An alleged cyberbully never has any notice of this hearing and has no right to give his side before the order is made. In this case, the order of the justice of the peace even ordered the respondent to delete all of his social media postings that didn’t refer to anyone in particular, as they may have referred to the complainant.

The case mainly focused on two aspects: the definition of "cyberbullying" at the heart of the Act and the scheme that permits applications and orders without notice to the other side. The Court found the Act violates freedom of expression rights and cannot be saved. The definition is overbroad and encompasses a range of expression that is constitutionally protected:

[115] The Act restricts "any electronic communication through the use of technology ... that is intended or ought reasonably be expected to cause fear, intimidation, humiliation, distress or other damage or harm to another person's health, emotional well-being, self-esteem or reputation, and includes assisting or encouraging such communication in any way". It is not difficult to come up with examples of expressive activity that falls within this definition, and at the same time promotes one of the core freedom of expression values. Moir J. did just that in Self, supra at para. 25:
A neighbour who calls to warn that smoke is coming from your upstairs windows causes fear. A lawyer who sends a demand letter by fax or e-mail causes intimidation. I expect Bob Dylan caused humiliation to P.F. Sloan when he released "Positively 4th Street", just as a local on-line newspaper causes humiliation when it reports that someone has been charged with a vile offence. Each is a cyberbully, according to the literal meaning of the definitions, no matter the good intentions of the neighbour, the just demand of the lawyer, or the truthfulness of Mr. Dylan or the newspaper.

[116] In conclusion, I find that the Act has both the purpose and effect of controlling or restricting freedom of expression.



Once any limitation on a Charter protected right is found, it can only be justified if (i) it is prescribed by law, (ii) it relates to a pressing and substantial objective, (iii) the impugned provision must be rationally connected to the objective, (iv) it must impair the Charter right "minimally" and (v) the effects must be proportional. In this case, remarkably, the Court found that it is not even "prescribed by law" as it is not sufficient intelligible:

[137] In this regard, I find that the Act provides no intelligible standard according to which Justices of the Peace and the judiciary must do their work. It does not provide sufficiently clear standards to avoid arbitrary and discriminatory applications. The Legislature has given a plenary discretion to do whatever seems best in a wide set of circumstances. There is no "limit prescribed by law" and the impugned provisions of the Act cannot be justified under s. 1. In the event I am wrong, I will perform the balance of the Oakes analysis.

The Court also found that the ex parte procedure is not rationally connected to the mischief to be addressed:

[156] ... Section 5(1) must be read as requiring protection order applications to be made without notice to the respondent. I also agree with the Respondent's submission that even if s. 5(1) did give applicants a choice in the matter, it would be a rare case indeed where an applicant would choose to give notice.

[157] Finally, with respect to the Attorney General's reliance on the various procedural safeguards set out in the Act, the reality is that while the respondent waits for the opportunity to be heard at a de novo hearing, his or her Charter-protected rights and freedoms will continue to be infringed upon. This will be on the basis of a proceeding that most likely occurred without notice to the respondent, and without the respondent having had an opportunity to be heard.

[158] I find the process set out in s. 5(1) of the Act is not rationally connected to the legislative objectives. The process does not specifically address a targeted mischief.


On "minimal impairment", the Court called the Act a "colossal failure":

[165] I need to consider all of the types of expression that may be caught in the net of the Cyber-safety Act, and determine whether the Act unnecessarily catches
material that has little or nothing to do with the prevention of cyberbullying: R. v. Sharpe, 2001 SCC 2, [2001] S.C.J. No. 3 at para. 95. In this regard, the Cyber-safety Act, and the definition of cyberbullying in particular, is a colossal failure. The Attorney General submits that the Act does not pertain to private communication between individuals, but rather, deals with "cyber messages or public communications". With respect, I find that the Act restricts both public and private communications. Furthermore, the Act provides no defences, and proof of harm is not required. These factors all culminate in a legislative scheme that infringes on s. 2(b) of the Charter much more than is necessary to meet the legislative objectives. The procedural safeguards, such as automatic review by this Court and the respondent's right to request a hearing, do nothing to address the fact that the definition of cyberbullying is far too broad, even if a requirement for malice was read in. Moir J.'s comments in Self supra at para. 25, are instructive:
The next thing to note is the absence of conditions or qualifications ordinarily part of the meaning of bullying. Truth does not appear to matter. Motive does not appear to matter. Repetition or continuation might ("repeated or with continuing effect") or might not ("typically") matter.

[166] In conclusion, the Cyber-safety Act fails the "minimum impairment" branch of the Oakes test.
Emphasis added


The Court also found that the Act fails on the final proportionality test:

[174] The Attorney General submits that the Act strikes an appropriate balance because it only restricts expression that is malicious, and therefore low-value. The
Respondent says this Court must instead balance an individual's right to express any sort of speech captured in the definition of "cyberbullying" against the objectives of the Act. The Respondent says the Act prevents an individual from telling the truth if it hurts another person's feelings or harms their self-esteem, and it does not provide any defences. The Act does not accommodate expression that relates to individual self-fulfillment, truth-finding or political discourse. The Respondent submits that the Act can therefore "limit speech that cuts to the core of Charter values". The Respondent distinguishes Lucas on the basis that the libel provisions in the Criminal Code were upheld because they prohibit only falsehoods that are known by the defendant to be false.

[175] It is clear that many types of expression that go to the core of freedom of expression values might be caught in the definition of cyberbullying. These deleterious effects have not been outweighed by the presumed salutary effects.


In the end, the Court found that the Cyber-safety Act offends sections 2(b) and 7 of the Charter and cannot be justified.

Interestingly, the Attorney General asked that if the Act were declared to be unconstitutional, the Court should suspend the declaration of invalidity so that the legislature could go back to the drawing board. In court, we agreed that it could be suspended with respect to anyone but my client. The Court declared the entire Act to be unconstitutional but refused to suspend the order:

[220] Both parties confined their submissions to the definition of cyberbullying and Part I of the Act. I have identified a number of problems with both components. The remaining parts of the Act cannot survive on their own. They are inextricably connected to the offending provisions, in particular the definition of cyberbullying. Severance would not be appropriate. The Act being over-inclusive rather than underinclusive, reading in also would not be an appropriate remedy. I have already explained why reading in a requirement for malice is not, in my view, appropriate or sufficient. The Act must be struck down in its entirety. The Attorney General has not persuaded me that a temporary suspension is warranted. To temporarily suspend the declaration of validity would be to condone further infringements of Charter protected rights and freedoms. Further, the fact that the Act was enacted to fill a "gap" in the legislation does not mean that victims of cyberbullying will be completely without redress in the time it takes to enact new cyberbullying legislation. They will have the usual albeit imperfect civil and criminal avenues available to them.
Emphasis added

So far, the government of Nova Scotia has not commented on the case and it remains to be seen whether they will appeal the case or go back to the drawing board, or both.

If they do go back to the drawing board, I really hope they will do it with very careful deliberation and full consultation with experts. But if nothing else, they have a good example of how not to do it.

Friday, November 28, 2014

Nova Scotia FOIPOP Review Officer annual report for 2013

Nova Scotia's new Freedom of Information and Protection of Privacy Review Officer, Catherine Tully, has just tabled the annual report for 2013 [PDF]. Former review officer Dulcie McCallum was at the helm for the period covered by the report.

From the media release that accompanied the report:

Proactive protection of personal information and disclosure of government data highlight FOIPOP Review Officer’s annual report

Halifax – Privacy breaches were front and centre across the country in 2013. In Nova Scotia, at least two of those breaches sparked class-action lawsuits against health care organizations. Today Catherine Tully, Nova Scotia’s Freedom of Information and Protection of Privacy Review Officer, released her office’s annual report for 2013. In the report, Tully highlighted the need for government departments and health care organizations to have strong privacy management frameworks in place to help mitigate the risks from privacy breaches.

“In determining whether or not damages will be awarded the court will no doubt look to the adequacy of the security arrangements and the steps the health authorities took to both prevent and detect the unauthorized viewing of medical records,” said Tully. “Equally important are the steps public bodies take to manage a breach once it occurs.”

The Review Officer said that assisting public bodies and health care custodians to develop privacy management frameworks would be a focus of her office going forward.

Tully also highlighted the importance of government finding ways to be transparent through proactive disclosures of information. Two examples that helped citizens understand how their tax dollars were spent were Halifax’s open data pilot project and the Department of Health and Wellness’ reporting on patient safety indicators. 2013 also saw calls for modernization of access and privacy legislation across the country, including in Nova Scotia. Going forward Tully plans to continue meeting with stakeholders to assess the need for modernization of Nova Scotia’s set of access and privacy laws.

“Transparency and accountability are at the heart of access and privacy legislation. A key element of such legislation is independent oversight that both public bodies and citizens can have confidence in,” said Tully. “Over the course of the coming months I will meet with stakeholders, and review complaints to develop an informed opinion about how well our legislation is working for Nova Scotians.” The annual report noted the backlog of case files that has built up at the Review Office. Tully committed that the backlog will be a priority for her office in the immediate future.

Tully also noted that 2013 saw the Personal Health Information Act (PHIA) come into force, though the Review Office received less contact from the public and custodians under that Act than expected. Tully plans to increase public education efforts around PHIA in the near future.

Thursday, April 03, 2014

U.S. (correctly) identifies some Canadian privacy laws as trade barriers

The United States Trade Representative has released its latest Report on Foreign Trade Barriers [PDF] which specifically identifies certain Canadian provincial privacy laws as non-tariff trade barriers. It points to the public sector privacy laws in British Columbia and Nova Scotia and singles out Canadian federal government procurement of cloud services:

Cross-Border Data Flows

The strong growth of cross-border data flows resulting from widespread adoption of broadband-based services in Canada and the United States has refocused attention on the restrictive effects of privacy rules in two Canadian provinces, British Columbia, and Nova Scotia. These provinces mandate that personal information in the custody of a public body must be stored and accessed only in Canada unless one of a few limited exceptions applies. These laws prevent public bodies such as primary and secondary schools, universities, hospitals, government-owned utilities, and public agencies from using U.S. services when personal information could be accessed from or stored in the United States.

The Canadian federal government is consolidating information technology services across 63 email systems under a single platform. The request for proposals for this project includes a national security exemption which prohibits the contracted company from allowing data to go outside of Canada. This policy precludes some new technologies such as “cloud” computing providers from participating in the procurement process. The public sector represents approximately one-third of the Canadian economy, and is a major consumer of U.S. services. In today’s information-based economy, particularly where a broad range of services are moving to “cloud” based delivery where U.S. firms are market leaders; this law hinders U.S. exports of a wide array of products and services.

This has prompted Daniel Tencer to write in the Huffington Post that "U.S. Pushes Canada To Loosen Privacy Laws". These laws were designed to thwart the USA Patriot Act by requiring public bodies in those jurisdictions to only allow personal information to be stored in Canada and only accessed from within Canada.

As a practitioner of privacy law who has to deal with these statutes on a regular basis, I tend to agree and think the fine citizens of Nova Scotia and British Columbia would be better off without them. I have seen, on many occasions, government functionaries simply say "no" to non-Canadian vendors because of privacy risks they do not understand, denying their citizens access to leading-edge, cost saving technology. It is much simpler and easier to say "no"

The BC law came into being as a result of a public sector trade union objecting to the possible outsourcing of medicare claims processing to the Canadian subsidiary of a US corporation. When the union realized it would not get public support for their jobs, they might be able to create a spectre of the US government getting their mitts on sensitive information under the Patriot Act. The result was the BC legislation. (Ironically, the outsourcing still took place after a very convoluted corporate structure was put in place.)

Similarly, a back-bench NDP politician stood up in the legislature and raised the exact same spectre. A short while later, Nova Scotia passed the Personal Information International Disclosure Protection Act. While the Nova Scotia law is much more flexible than the B.C. statute, both are a ham-fisted response to a really nuanced issue. Instead of asking the question about the real risk to data, the default answer is always "no" when a non-Canadian vendor puts forward a cloud computing solution to a government agency.

If these laws were designed to prevent non-Canadian vendors from getting a piece of government business, they've done that quite well. But they do not actually accomplish the objective of keeping personal information out of the hands of U.S. authorities under all circumstances. To begin with, if the Americans want data that's in Canada, they are likely to get it. Canada, the United States and most western democracies engage in a very high level of cooperation that includes mutual legal assistance treaties and ad hoc information sharing. If US agencies are interested in an individual who has ties to Canada, the Federal Bureau of Investigation can make a formal request of the Royal Canadian Mounted Police or CSIS to obtain the relevant information on their behalf. (Most Canadian privacy laws actually permit this sort of information sharing under treaties or informal arrangements.) And if you are concerned about covert access to this sort of data, American laws do not prohibit federal agencies from infiltrating computers and networks outside of the United States. Some have suggested that information is safer from U.S. authorities in the U.S. because of this.

In addition, any person or corporation with sufficient ties to the United States can be compelled to hand over data regardless of where it is. This can include fully Canadian corporations with assets in the U.S. This can also take place if handing over the data would violate Canadian laws. The Huffington Post article refers to the Canadian federal government's decision to give a massive cloud "shared services" contract to Bell Canada when U.S. vendors were disqualified from even submitting a proposal. Does this make the data "safe" from the Americans? Not really, since the parent company of Bell Canada is publicly traded on the New York stock exchange. They simply can't ignore a U.S. court order.

So what's the solution to this "problem"? It would be the policy that the federal government purports to have, but does not seem to have followed in the shared services contracting. That is to do a full privacy impact assessment in all cases which fully evaluates all of the risks to privacy associated with the project, including what risks that cross-border data flows might introduce. And when I saw all the risks, I mean with a fully-informed understanding of the circumstances under which non-Canadian governments might get their hands on the data. In some cases, the risk introduced by crossing the border may be unpalatable, but at least it is an informed decision.

The current practice of simply saying no to non-Canadian vendors is a non-tariff trade barrier.