Showing posts with label privacy act. Show all posts
Showing posts with label privacy act. Show all posts

Tuesday, February 22, 2022

Video: Cross-border data flows for Canada

New on my YouTube Channel.

In today's video, I am going to talk about the mosaic of privacy laws that we have in Canada and what they have to say about cross border data transfers.

First, I will talk about public sector privacy laws with two particular examples coming from British Columbia and Nova Scotia.

Then I would be talking about Canada’s private sector privacy laws, in particular PIPEDA and the substantially similar laws in Alberta and British Columbia. I will also briefly discuss the new Quebec privacy statute.

Finally, I will touch on various provincial health privacy laws that also have provisions that relate to cross border data flows

What Canadian privacy laws

Canada is a federal country and jurisdiction as it relates to privacy is divided between the provinces and the federal government.

We also have three general varieties of privacy laws:

Those that regulate the collection, use and disclosure of personal information by the public sector – which includes governments, government agencies and other organizations like universities and school boards.

We have a separate category of privacy laws that regulate the private, non-government sector.

Because healthcare in Canada is a mix of public and private, a number of provinces have developed health privacy laws to ensure uniform treatment of personal health information regardless of whether it’s at a doctor’s office or in a hospital.

Public sector privacy laws

One area in Canada that does not have any gaps in privacy regulation is the public sector. Each federal, provincial and territorial jurisdiction has a public sector privacy law that regulates the collection, use and disclosure of personal information by government and government agencies.

One thing that they all have in common is an obligation to protect and safeguard all personal information against a range of risks, including unauthorized disclosure. Very few of them directly address cross border data flows.

Privacy Act

In the federal jurisdiction, we have the privacy act which regulates federal government institutions.

The privacy act does not address cross border transfers or disclosures of personal information.

Instead, the federal treasury board has created guidelines regarding outsourcing that effects personal information.

These guidelines do not prohibit this storage of personal information outside of Canada, but instead impose an assessment to determine whether in the circumstances it is appropriate to use a particular service that may result in personal information being stored outside of Canada or accessed from outside of Canada.

FIPPA (British Columbia)

In 2004, the British Columbia Freedom of Information and Protection of Privacy Act was amended to essentially prohibit the province’s government from allowing personal information to be stored outside of Canada or accessed from outside of Canada.

This was because of a large-scale union campaign that latched onto privacy and fear of the USA PATRIOT Act to oppose government outsourcing of IT services.

These prohibitions were finally removed in 2021, likely driven by the need of governments, universities and school boards to use more modern cloud technologies to support work from home during the pandemic.

The replacement provisions anticipate the government to pass regulations about cross-border data transfers, but we have not seen those yet.

PIIDPA (Nova Scotia)

In 2006, Nova Scotia followed British Columbia in strictly limiting cross-border data flows when it passed the Personal Information International Disclosure Protection Act, also known as “PIIDPA”.

What PIIDPA contains is a general prohibition against storage or access outside of Canada for public bodies in Nova Scotia. This includes public bodies in the health sector.

PIIDPA is not as draconian as the British Columbia law because it does permit the “head of the public body” to authorize the storage or access outside of Canada if it is for the public body’s necessary operations.

The public body also has to make a report of the decision to the minister of justice, which is then made public.

PIIDPA also imposes specific obligations on all service providers of public bodies.

Foreign demands for disclosure

The most significant – but maybe less known – obligation imposed on service providers relates to “foreign demands for disclosure”. These are warrants, subpoenas and court orders by a foreign authority for records, as long as there is a penalty for non-compliance.

It is unlawful for a service provider to provide the data, and the public body or its service provider must give written notice of the demand to the Nova Scotia Minister of Justice.

Then what? I don’t know. Presumably there would be some government-to-government communications.

Foreign demands under other laws

Every privacy law in Canada permits disclosures without consent where the disclosure is required by law. Some include examples like warrants, subpoenas, litigation document discovery and the like.

None of them specify “where required by CANADIAN law”, but that is a reasonable presumption.

These laws, other than PIIDPA, don’t make it an offense but it would still not be permitted.

But at the same time, the Office of the Privacy Commissioner of Canada has been clear that if information is stored outside of Canada, it becomes subject to the laws of the place where it is stored. That’s a risk that needs to be taken into account in any contracting decision.

Private sector privacy laws

For most of the private sector in Canada, there are no rules that prohibit cross-border data transfers but there are rules that come into play.

Each private sector privacy law requires that the original “controller” makes sure that there are adequate safeguards to protect personal information.

The original controller has to use contractual terms to make sure that any contractors implement those safeguards.

Jurisdiction may affect whether safeguards can be adequately assured.

Disclosures by the organization or its contractors in response to a “foreign demand for disclosure” may be unlawful. Any organization dealing with something like this should immediately seek experienced legal advice.

Alberta’s Personal Information Protection Act

Alberta’s Personal Information Protection Act specifically addresses giving people notice about cross-border data transfers.

Specifically, the law requires policies and procedures that include the countries in which the collection, use, disclosure or storage is occurring or may occur, and the purposes for which the service provider has been authorized to collect, use or disclose personal information for or on behalf of the organization.

Because this information has to be made available upon request, it should be included in an organization’s public-facing privacy policy.

The Privacy Commissioner of Canada recommends this as well for PIPEDA

Quebec’s Bill 64

In the past year, Quebec has significantly updated its private sector privacy law, including provisions that specifically address cross-border data transfers.

These new provisions come into effect on September 22, 2023.

When the Quebec provisions come into effect, they will require a process similar to a data transfer impact assessment under the European GDPR.

Before storing personal information outside of Quebec, the organization will need to carry out a privacy impact assessment, sometimes referred to as a PIA.

Then the organization will need to carry out an analysis of whether there will be “adequate” protection of the personal information when transferred outside of the province.

Finally, there needs to be a written agreement with the service provider that mitigates any risk identified in the PIA and ensures that personal information will be adequately protected.

Health privacy laws

Health privacy laws are a specific kind of privacy law in Canada, which cross over the private sector (doctors’ offices, pharmacies and physiotherapists) and the public sector (health authorities and public hospitals).

Most health privacy laws in Canada prohibit disclosures of personal health information outside of Canada unless there is consent from the individual. Some similarly prohibit disclosures outside of the province.

But most people who practice in this space, and some regulators I’ve spoken to, say that a transfer for processing is not a disclosure for the purposes of this prohibition.

What’s the reality on the ground?

Many people still believe that cross-border transfers are prohibited in Canada, which is likely the result of the publicity around the prohibitions added to the British Columbia public sector law years ago.

The only province that significantly limits cross-border transfers is Nova Scotia, for the public sector in that province.

We still see requests for proposals from both the public and the private sectors that require data residency in Canada.

When this happens in the public sector, this is likely in violation of international trade agreements.

Thursday, March 14, 2013

Canadian government's new standard on privacy and web analytics

The CBC is reporting on the Canadian Government's relatively new Standard on Privacy and Web Analytics, which was launched earlier this year. The Treasury Board standard came into effect, but government departments are being given time to adjust contracts with outside providers of website analytic services.
The key provisions related to privacy are set out in Appendix and and Section 3.2 of Appendix A sets out the requirements that government departments must impose on third party service providers:
3.2 That contract must, at a minimum, contain provisions meeting the requirements as set out below.
a. A definition of "personal information" as meaning information collected or generated in the performance of the contract about an individual, including the types of information specifically described in the Privacy Act and also including information that may be linked or is linkable to an individual such as the website visitor's IP address.
b. A requirement that the third party appoint an officer within the organization to act as representative for all matters related to personal information and that the name and contact information for this third-party contact be provided to the government institution within 10 days of the awarding of the contract.
c. A requirement that the third party provide all of its employees, contractors and subcontractors with information on their privacy obligations when dealing with personal information disclosed or transmitted in relation to the work being performed under the contract or subcontract (the "work").
d. A requirement that the third party depersonalize the IP address prior to its storage in order that the full IP address cannot be reconstituted. This must be done through irrevocable truncation of the last octet of the IP address or through some other methodology that offers comparable privacy protection and has been approved by the Chief Information Officer Branch of the Treasury Board of Canada Secretariat.
e. A requirement that the third party not link, or attempt to link, the IP address or some unique identifier associated with a digital marker with the identity of the individual computer user.
f. A requirement that the depersonalized IP address, along with other data disclosed to the third party for Web analytics, be used only in accordance with the work, and that no subsequent uses or reuses of such data for any other purpose be allowed without the institution's express prior written authorization.
g. A requirement that the third party not disclose or transfer the depersonalized IP address or any other data disclosed to it except in accordance with the work, with the express prior written authorization of the institution, or if required to do so by law.
h. A requirement that the third party use only first-party cookies.
i. A requirement that the third party be prohibited from using techniques such as, but not limited to, interlinking, cross-referencing, data mining or data matching from multiple sources on the personal information collected in relation to the work, unless expressly pre-authorized to do so, in writing, by the government institution.
j. A requirement that the third party have security in place for the personal and depersonalized information that is at least commensurate with the Policy on Government Security.
k. A requirement that the third party safeguard the depersonalized IP address and other information disclosed in relation to the work, and that this information be retained for a maximum period of 6 months, after which time that information, including any backup copies, must be destroyed.
l. An audit provision whereby the third party may be audited at least once annually, at a date to be determined by the Government of Canada, to ensure compliance with these requirements.










Monday, December 31, 2012

Privacy commissioner to investigate HRSDC privacy breach

According to a report in the London Free Press, the Office of the Privacy Commissioner of Canada appears to be planning to investigate the appalling privacy breach that was announced last week. The language is not as definitive as I would like, however:

Privacy commissioner to investigate security lapse | Canada | News | The London Free Press

LONDON, Ont. - The federal privacy commissioner is poised to launch a full investigation into a security lapse that lost the private information of about 5,000 Canadians.

“I think you can expect that we will be investigating the matter,” Anne-Marie Hayden, spokesperson for the Privacy Commissioner of Canada, said Monday.

The commissioner’s office has already received 100 calls and several official complaints about the loss of a USB stick that contained private medical, employment and education information, as well as Social Insurance numbers.

It would be gravely disappointing if the OPC does not do a full investigation of this breach along with strong recommendations to prevent it from happening again.

Government needs to be held to an even higher standard than the private sector. People do not have a consensual relationship with government. If you do not like how your bank handles your personal information, you can easily switch to another one. If you're not happy with Instagram's new privacy policy, you can close your account. You cannot do that with government. If Human Resources and Skills Development Canada is incompetent in safeguarding sensitive personal information and cavalier in its response, you can't go looking for another Canada Pension Plan provider.

If this breach involved one of the big California-based internet giants, you can bet there would be a full investigation and further calls for order-making powers and the ability to levy fines.

I hope to see a full and public investigation, followed by calls to amend the Privacy Act to bring it into line with more modern provincial statutes that make it an offense to willfully violate the privacy of Canadians.

Saturday, December 29, 2012

Government "loses" sensitive personal information on thousands of Canadians

Over the past week, Human Resources and Skills Development Canada has been notifying approximately 5000 people that their personal information has been lost. According to reports, the information was on a USB device that has been "misplaced". The information includes Social Insurance Number(SIN); surname; primary and, if applicable, secondary medical condition; birthdate; presence of other payers (e.g., workers' compensation); level of education; occupation type; and, Service Canada processing centre.

This is an ENORMOUS screw up by the Government of Canada. Unencrypted personal information should never be put on these devices as they are notoriously easy to lose. I am also surprised that the Privacy Commissioner's office, at least as quoted in the media, has not yet decided whether to do a formal investigation.
Personal info for thousands lost by federal government - Politics - CBC News

A federal government department says there is no evidence that missing personal information about thousands of Canadians has been used for fraudulent purposes.Human Resources and Skills Development Canada says an employee reported on Nov. 16 that a USB key containing personal information, including Social Insurance Numbers, of about 5,000 Canadians was missing.

The department, which handles a variety of files including pensions, old age security, employment insurance and childcare tax credits, says all those affected have been contacted.

A spokesperson said in an email Friday evening that the affected people have been advised of the incident and informed of the steps they can take to help protect their personal information.

HRSDC notified the privacy commissioner's office on Dec. 21 that the data had been lost.

About 60 people have already called an information line at the privacy commissioner's office expressing concern about the incident and complaints have already been filed.
"It's too early to say whether or not these will turn into official, full, investigations," said Anne-Marie Hayden, a spokeswoman for the privacy commissioner.
"We'd have to look at what we receive first and determine next steps from there."
HRSDC said it has seen no evidence that any of the information contained on the missing USB key has been used for fraudulent purposes.

"Nonetheless, we have advised affected individuals to carefully review and verify bank information, credit card information and other financial transaction statements as a means of safeguarding their personal information as a precautionary measure," the email said.

"We are currently analyzing this incident with the view of preventing a similar occurrence in the future," it added.

The commissioner's office is working with HRSDC in an effort to figure out what happened.

Each year, federal departments are required to report on how well they comply with privacy legislation.

In the 2010-2011 report — the most recent one posted on HRSDC's website — the department noted that it had been the subject of three complaints regarding how it handled personal information.

Thursday, November 17, 2011

Privacy Commissioner of Canada releases annual report on public sector privacy law

Jennifer Stoddart has just tabled her annual report to Parliament on the Privacy Act, Canada's federal public sector privacy law: Annual Report to Parliament 2010-2011 - Report on the Privacy Act.

From her media release on the topic:

Audit of airport security measures flags concerns about over-collection and safeguarding of travellers’ personal information

2010-2011 Annual Report to Parliament on the Privacy Act examines the stewardship of personal information by Canada’s airport security authority, the RCMP and other federal departments and agencies

OTTAWA, November 17, 2011 – The Government of Canada is collecting too much information about some air travellers and is not always safeguarding it properly, Privacy Commissioner Jennifer Stoddart found in an audit published with her annual report today.

The audit of the privacy policies and practices of the Canadian Air Transport Security Authority (CATSA) concluded that the agency was reaching beyond its mandate by completing security reports on incidents which were not related to aviation security.

This was the case even with incidents involving an activity that was legal. For example, CATSA collected information about air passengers who were found to be carrying large sums of cash on domestic flights. CATSA also contacted police in such cases. Since it should not be collecting personal information about legal activities not related to aviation security, the Office of the Privacy Commissioner of Canada recommended that CATSA immediately cease that practice. CATSA agreed.

Moreover, the audit found that such incident reports, and other types of personal information collected by the agency, were not always properly secured.

“Documents containing sensitive personal information were left on open shelves and in plain view in a room where passengers may be taken for security checks,” Commissioner Stoddart reported.

The audit also identified other concerns about procedures not being followed during the screening process. When auditors visited the rooms where CATSA officials screen full-body scans, they discovered a cell phone and a closed-circuit TV camera even though these types of devices are strictly prohibited according to CATSA’s operating procedures.

“Fortunately, these irregularities were uncommon and we were pleased that CATSA moved quickly to correct them by issuing a reminder to staff and conducting inspections to ensure proper procedures were followed,” said Commissioner Stoddart.

Even so, she added, “the Government of Canada is entrusted with highly sensitive personal information, and is obliged to handle it with an uncompromising level of care—not some of the time, or even most of the time, but all of the time.”

The audit was summarized in the 2010-2011 annual report on the Privacy Act, which was tabled in Parliament today.

The annual report also contains a summary of another audit conducted by the Office of the Privacy Commissioner of Canada (OPC). It examined the Royal Canadian Mounted Police’s (RCMP) management of operational databases that are widely shared with other police forces, government institutions and other organizations.

The audit determined that, while the RCMP has policies and procedures to safeguard the sensitive information contained in the databases, there were also some disturbing gaps.

For instance, the Privacy Act, which governs the information-handling practices of federal government departments and agencies, requires that organizations retain personal information no longer than absolutely necessary. And yet, information about offences for which a pardon had been granted, or that resulted in a wrongful conviction, continues to be accessible in a database called the Police Reporting and Occurrence System.

“People who were convicted of an offence they did not commit, or who have been granted a pardon, have a right to go about their lives without information—and especially misinformation—about their past coming to light,” Commissioner Stoddart noted. “Such information must be more tightly controlled.”

The annual report highlights the work of the OPC in 2010-2011 in strengthening the privacy rights of Canadians. It summarizes key investigations into privacy complaints and data breaches that the Office conducted under the Privacy Act. The report also describes several Privacy Impact Assessments that federal institutions submitted to the Office for review during the past fiscal year.

Aimed at assessing the government’s stewardship of personal information, the report has separate chapters devoted to the collection, use and disclosure of data. Given the sensitive nature of the personal information that the state needs to govern, the report warns of grave consequences for its over-collection, misuse or inappropriate disclosure.

Aside from the two audit summaries, here are other highlights of today’s reports:

  • Biometric identifiers: Citizenship and Immigration Canada submitted Privacy Impact Assessments for two initiatives involving the use of fingerprints and other biometric identifiers for immigration control. The OPC recommended ways to strengthen privacy safeguards for vulnerable populations such as refugee claimants.
  • Passenger behaviour observation: A Privacy Impact Assessment for a new pilot project to observe airport travellers for suspicious activity raised several concerns, including the potential for inappropriate risk profiling based on characteristics such as race, age or gender.
  • Personal data breaches: The OPC received a record number of reports of breaches of personal information in 2010-2011. One involved a malfunction of the new My Service Canada Account website, a day after its launch, which allowed an estimated 75 users to see financial and other personal data of previous visitors to the site.
  • Follow-up to past audits: During follow-ups on three audits originally conducted in 2008 and 2009, the entities that we audited indicated that 32 of 34 of the OPC’s recommendations had been fully or substantially implemented. For example, the RCMP reported that it had removed tens of thousands of surplus files from its exempt databanks, in compliance with the Privacy Commissioner’s recommendations.

The full annual report and audit reports on CATSA’s aviation security measures and the RCMP operational databanks are available at www.priv.gc.ca.

The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman and guardian of privacy in Canada.

Tuesday, November 17, 2009

Commissioner tables annual Privacy Act Report for 2008-2009

The Privacy Commissioner of Canada has tabled her annual report on the public sector privacy law, the Privacy Act: Annual Report to Parliament 2008-2009 - Report on the Privacy Act.

At the same time, she has also tabled additional privacy audits, related to FINTRAC and the Canadian no-fly list:

Here's the media release that accompanied the tabling of the reports:

Audits of major national security programs raise concerns for privacy Excessive reporting of personal information to FINTRAC and potential information technology risks with Canada’s “no-fly list” are among concerns identified in audits highlighted in the Privacy Commissioner’s annual report on public sector issues.

OTTAWA, November 17, 2009 — The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) has more personal information in its database than it needs, uses or has the legislative authority to receive.

This was one of the key findings of the Privacy Commissioner of Canada’s in-depth audit of the independent agency mandated to analyze financial transactions and identify suspected money laundering and terrorist financing in Canada.

A separate audit, also published today, examined the Passenger Protect Program – better-known to Canadians as the no-fly list. It identified several concerns, such as the fact that the Deputy Minister ultimately in charge of who is on the list was not provided with complete information to allow for informed decision-making.

“Since the terrorist attacks of 9/11, we’ve seen a proliferation of new national security programs. We fully appreciate the underlying aim of many security programs – protecting Canadians. However, it is critical – a point reinforced by our new audits – for government officials to integrate privacy protections into all of these programs at the outset,” says Privacy Commissioner Jennifer Stoddart.

The findings of the two audits are highlighted in the Commissioner’s 2008-2009 report to Parliament on Canada’s federal public-sector privacy legislation, the Privacy Act.

FINTRAC Audit

Legislative changes passed in 2006 expanded the types of transactions that must be reported to FINTRAC, as well as the number of professionals and organizations that are required to collect information about clients and to report it to FINTRAC. Examples of entities required to report to FINTRAC include financial institutions, life insurance companies, accountants and casinos.

The audit found that FINTRAC needs to do more to ensure that the amount of personal information it acquires is kept to an absolute minimum. A random sample of files examined in the audit turned up several reports that did not clearly demonstrate reasonable grounds to suspect money laundering or terrorist financing. For example:

A reporting entity filed several reports stating it was “taking a conservative approach in reporting this … because there are no grounds for suspecting that this transaction is related to the commission of a money laundering offence, but there is a lack of evidence to prove that the transaction is legitimate.”

An individual deposited a government cheque for an amount less than $300 and then withdrew the entire amount. The financial institution filed a suspicious-transaction report, but did not indicate why the transaction was deemed suspicious.

A financial institution filed a report about an individual who had deposited a cheque from a law firm. The institution was satisfied that the individual had provided legitimate reasons for the source of funds, but decided to notify FINTRAC anyway because of the individual’s ethnic origin and the fact that this person had visited a particular country.

“It is clear that such reports, containing not a shred of evidence of money laundering and terrorist financing, should not be making their way into the FINTRAC database,” says Commissioner Stoddart.

“It is a bedrock privacy principle that you collect only the personal information you need for a specific purpose,” she says. “The federal government needs to have a justifiable need to collect someone’s personal information. Clearly, FINTRAC needs to do more work with organizations to ensure it does not acquire personal information that it has no legislative authority to receive – and that it does not need or use.”

The audit recommended enhanced front-end screening of reports; stronger ongoing monitoring and review to ensure that information holdings are relevant and not excessive, and the permanent deletion of information that FINTRAC did not have the statutory authority to receive.

Under amendments passed in 2006, the Proceeds of Crime (Money Laundering) and Terrorist Financing Act requires the Privacy Commissioner to review FINTRAC every two years and report the results to Parliament.

Passenger Protect Program Audit

The “no-fly list” is a passenger screening tool introduced in 2007 to prevent people named on a “specified persons list” from boarding domestic and international flights from or to Canadian airports.

The program has sparked privacy concerns, in part because it is secretive in that it uses personal information without the knowledge of the individuals concerned. Moreover, the repercussions for a person named on the list being denied boarding on an aircraft can be profound in terms of privacy and other human rights, such as freedom of association and expression and the right to mobility.

The focus of the audit, however, was to determine whether the program has adequate controls and safeguards in place to protect personal information.

“We were concerned to learn that officials did not always provide the Deputy Minister – who is ultimately responsible for adding to or removing people’s names from the ‘specified persons’ list – all the information needed to make these sorts of decisions,” says Assistant Privacy Commissioner Chantal Bernier.

Other concerns identified during the audit included:

Transport Canada has not verified that airlines are complying with federal regulations related to the handling and safeguarding of the “specified persons list.” The risk of this information being inappropriately disclosed is particularly high for the small number of air carriers that rely on paper copies of the list.

There were no requirements that air carriers report to Transport Canada security breaches involving personal information related to the no-fly list.

Transport Canada did not demonstrate that the application used to transmit information to air carriers met government security standards.

The Passenger Protect Program and the FINTRAC audits, as well as the latest Privacy Act annual report, are available at http://www.priv.gc.ca/.

The annual report also includes details of privacy-related complaints against federal departments and agencies investigated during the 2008-2009 fiscal year. The Office received 748 formal complaints in 2008-2009, down slightly from the previous year. The most common complaints related to access to personal information and to the length of time government departments and agencies were taking to respond to access requests.

The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy and the protection of personal information rights of Canadians.

To view the reports:

Friday, June 12, 2009

Privacy Act report released by parliamentary committee

The Parliamentary Standing Committee on Access to Information, Privacy and Ethics has released its long-awaited report on proposed reforms to the Privacy Act. I appeared before the committee on behalf of the Canadian Bar Association and was pleased to see that many of our recommendations to the Committee are also recommendations made by the Committee to the government.

The report is available here.

Friday, January 02, 2009

The Canadian Privacy Law Blog is Five!

Five years ago, on January 2, 2004, a new age of privacy was creeping across Canada and this blog was born. The day before, at the stroke of midnight, the Personal Information Protection and Electronic Documents Act (Canada) had come fully into force. The Alberta and British Columbia Personal Information Protection Acts also became effective on the first day of 2004.

Since then, we have seen dramatic changes in privacy throughout the world: Identity theft is on the rise; there have been literally thousands of data breaches exposing the personal information of millions of people; governments are looking for easier access to personal information; video surveillance is more widespread; more personal information is generated digitally and aggregated in private hands.

And in the past year specifically, things have remained interesting on the privacy front. We've seen debate over changes to PIPEDA without anything definitive coming from the mandatory five year review. We've also seen arguments put forward to reform the public sector Privacy Act. Focus has also been drawn to the increasing practice of examining laptops at US border crossings. Litigation between Viacom and Google has raised awareness of log information that's often retained by internet companies. And Google has also been sued by a couple claiming their privacy has been violated by presenting pictures of their house in Google Street View. But in the last year, the one big privacy story that was supposed to have the largest impact on Canadians was the implementation of the National Do Not Call List. Whether it has, in fact, had an impact is the subject of debate.

I'd like to thank the many thousands of readers of the blog for visiting this site and thanks to those who have contacted me with comments, compliments, suggestions and links to interesting news. It's been a pleasure to write and I plan to keep it going as long as there's interesting privacy news to report.

Birthday cake graphic used under a creative commons license from K. Pierce.

Friday, December 05, 2008

Privacy Commssioner focuses on protection of personal information in accessible tribunal records

Just posted on Slaw, but like of interest to readers of this blog:

Slaw: Privacy Commssioner focuses on protection of personal information in accessible tribunal records

by David T. S. Fraser on December 5th, 2008

Yesterday, the Privacy Commissioner of Canada tabled her annual report on the Privacy Act. While she came down hard on a number of federal bodies such as the passport office, one aspect of the report should be of interest to lawyers generally.

The Commissioner reports on a whole range of complaints against tribunals and quasi-judicial bodies for publishing sensitive personal information about parties and non-parties. Decisions and tribunal records have always contained such information, but now that more of these decisions are readily available online, complainants are not happy that searching for their names online will bring up these decisions in the results.

The Commissioner is hampered by the fact that she can’t order them to change their practices and that many of the disclosures are arguably permissible under the Privacy Act. In any event, she has issued a number of recommendations that have been ignored by many of the tribunals at issue:

  • Reasonably depersonalize future decisions that will be posted on the Internet through the use of randomly assigned initials in place of individuals’ names; or post only a summary of the decision with no identifying personal information.
  • Observe suggested guidelines respecting the exercise of discretion to disclose personal information in any case where an institution proposes to disclose personal information in decisions in electronic form on the Internet.
  • Remove decisions that form the basis of the complaints to the OPC from the Internet on a priority basis until they can be reasonably depersonalized through the use of randomly assigned initials and re-posted in compliance with the Privacy Act.
  • Restrict the indexing by name of past decisions by global search engines through the use of an appropriate “web robot exclusion protocol;” or remove from or reasonably depersonalize all past decisions on the Internet through the use of randomly assigned initials, within a reasonable amount of time.

And in case you were thinking this may sound somewhat familiar, the Canadian Judicial Council tackled this issue in its 2005: Use of Personal Information in Judgments and Recommended Protocol (PDF).

Thursday, December 04, 2008

Federal Commissioner tables annual report on Privacy Act

The Federal Privacy Commissioner has today tabled her annual report on the Privacy Act. And she isn't happy with how certain government departments handle personal information:

News Release: Privacy issues given short shrift in passport operations and tribunal Internet postings, Commissioner says (December 4, 2008) - Privacy Commissioner of Canada

News Release

Privacy Commissioner’s 2007-2008 Annual Report to Parliament on the Privacy Act outlines audit of Passport Canada; investigative findings regarding online posting of personal information by administrative and quasi-judicial bodies

Ottawa, December 4, 2008 — Privacy concerns are not given enough weight in the day-to-day operations of a number of federal government institutions, the Privacy Commissioner of Canada says.

The Commissioner’s latest Annual Report to Parliament on the Privacy Act, which was tabled today, describes how privacy and security problems in Canada’s passport operations added up to a significant risk for Canadians applying for passports.

The annual report also highlights the Commissioner’s concerns that the online posting of personal information by some federal administrative and quasi-judicial bodies does not strike the right balance between the public interest and privacy rights.

Privacy Commissioner Jennifer Stoddart says her Office’s audit of passport operations raised a broad range of concerns about how personal information was handled.

“Given the high sensitivity of the personal information involved in processing passport applications, better privacy and security measures are needed,” says Commissioner Stoddart. “Unfortunately, the shortcomings we found raised the risk that Canadians’ information could wind up in the wrong hands.”

The audit found that passport applications and supporting documents were kept in clear plastic bags on open shelves; documents containing personal information were sometimes tossed into regular garbage and recycling bins; and some documents that were shredded could be easily put back together. Meanwhile, computer systems allowed too many employees to access passport files. The investigation also concluded there was inadequate privacy training for employees – an issue which is a concern across government institutions.The Commissioner is pleased that Passport Canada and the Department of Foreign Affairs and International Trade have indicated they will act on her recommendations and improve privacy and security safeguards.

The annual report also outlines the Commissioner’s concerns about the online posting of federal administrative and quasi-judicial bodies’ decisions which contain highly sensitive personal information.

The OPC investigated 23 complaints regarding the disclosure of personal information on the Internet by seven bodies created by Parliament to adjudicate disputes. The complaints involved: the Canada Appeals Office on Occupational Health and Safety; the Military Police Complaints Commission; the Pension Appeals Board; the Public Service Commission; the Public Service Staff Relations Board; the RCMP Adjudication Board; and Umpire Benefits decisions.

Decisions of these bodies often include highly personal information such as an individual’s financial status, health and personal history.

“This is private information. Law-abiding citizens fighting for a government benefit should not be forced to expose the intimate details of their lives to everyone with an Internet connection,” says Commissioner Stoddart.

The Commissioner agreed that the “open court” principle is an important part of Canada’s legal system, but noted there is a crucial distinction between the courts and the bodies the OPC investigated: The Privacy Act does not apply to the courts, but it does apply to many administrative tribunals and quasi-judicial bodies.

In order to respect their obligations under the Privacy Act, the Commissioner recommended, among other steps, that the bodies reasonably depersonalize decisions posted online by replacing names with random initials. However, the Commissioner noted that, where there is a genuine and compelling public interest in such a disclosure, these bodies have the legal authority under the Act to exercise discretion in disclosing personal information.

Service Canada and Human Resources Development Canada agreed to fully implement the OPC’s recommendations. Other bodies took important but incomplete steps towards compliance with the Commissioner’s recommendations.

Currently, unlike its private-sector counterpart, the Privacy Act does not empower the Privacy Commissioner to enforce her recommendations through legal actions. The OPC has recommended an overhaul of the legislation to address this and other concerns.

The OPC has also asked Treasury Board Secretariat to develop centralized policy guidance on the online posting of personal information by administrative and quasi-judicial bodies.The annual report outlines key activities undertaken by the OPC during 2007-2008, including audits, investigations and policy work. The report notes that new complaints against government institutions dropped slightly to 759 in 2007-2008 from 839 the previous year.

The report is available on the OPC website.

The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy and the protection of personal information rights of Canadians.

Wednesday, December 03, 2008

Privacy Commissioner's 2007-2008 Annual Report to be tabled

The Commissioner is going to be tabling her annual report on the Privacy Act before parliament tomorrow:

CNW Group OFFICE OF THE PRIVACY COMMISSIONER OF CANADA Media Advisory - Privacy Commissioner's 2007-2008 Annual Report to be tabled

OTTAWA, Dec. 3 /CNW Telbec/ - The Privacy Commissioner of Canada's 2007-2008 Annual Report to Parliament on the Privacy Act is expected to be tabled in Parliament on Thursday, December 4, 2008.

The report will highlight:

  • Findings of an audit of Canada's passport operations;
  • Investigative finding related to complaints about several federal administrative tribunals and quasi-judicial bodies posting decisions containing highly sensitive personal information to the Internet;
  • The Commissioner's call for improved privacy training in the federal government; and
  • Other investigations, audits and policy work undertaken by the Office of the Privacy Commissioner.

After the report is tabled, copies will be available to the media through the Parliamentary Press Gallery and on the Privacy Commissioner's website at www.privcom.gc.ca.

Privacy commissioner urged to probe Tory eavesdropping

This may be a legitimate complaint, but a futile one under the Privacy Act:

TheStar.com Canada Privacy commissioner urged to probe Tory eavesdropping

Dec 03, 2008 03:18 PM

OTTAWA — A public interest researcher has filed a formal complaint with Privacy Commissioner Jennifer Stoddart, charging top prime ministerial aides, a parliamentary secretary and an MP with "serious breaches" of the privacy laws.

Ken Rubin is asking Stoddart to investigate the eavesdropping, recording and distribution of a New Democratic conference call by a Conservative MP last weekend about a proposed alternative coalition government.

The office of Prime Minister Stephen Harper claimed that the MP was "invited" to participate by email, but the NDP suggested Conservative MP John Duncan mistakenly received an email intended for their MP Linda Duncan, and should not have participated in the call, let alone tape it.

The party has asked the RCMP to investigate whether an offence under the Criminal Code occurred.

Rubin contends that even if criminal law wasn't broken, there were serious breaches of privacy by a government that has claimed it would fight identity theft with tougher criminal code provisions.

In a letter sent to Stoddart today, Rubin writes that provisions in privacy legislation "mean you cannot collect or share personal information or conversations of others that you are not a legitimate party to."

He alleges several breaches, all related to the "wrongful" and wide distribution to the media of the contents of the conference call "by a government entity (who receives significant taxpayers' monies)."

He suggests it is a case of potential "identity theft" when a person (in this case one elected MP) "allegedly assumes the identity of another elected MP with the same last name, whether there was a mix up in the communications sent or not."

Rubin described himself as "both a privacy and access to information advocate with no partisan axe to grind."

He urged an investigation by Stoddart, the Ethics Commissioner, and a Parliamentary committee, reminding Stoddart of her advocacy for stronger protections against identity theft.

"No public official should be seen to be or partake in any such activity."

"These privacy breaches are all the more onimous when they are carried out by the central state and with the Prime Minister's Office in the lead. This is the very institution whose elected head and parliamentary secretary (Pierre Poilievre, who commented on the call) are supposed to be leaders in upholding Canadians' privacy protections."

Rubin acknowledged the PMO is not "directly covered under either privacy or access legislation."

But he reminded Stoddart that Ontario ministers have had to resign in the past when they misused personal data derived from government institutions.

"Someone in this case needs to be held accountable and to offer Parliament and the appropriate parliamentary committee an explanation."

"It is disturbing too to see that on one hand, the government denies public access to much of its key operations, including the PMO. But it then feels it can gain intelligence on the operations of others by using deceptive means."

Dimitri Soudas, a spokesman for the Prime Minister's Office, said "no comment" in response to a request from the Star.

Meantime, Rubin's complaint my reach a dead end.

Valerie Lawton, a spokesperson for Stddart, said in an emailed: "The Privacy Act does not cover political parties or members of Parliament."

The privacy commissioner also does not have jurisdiction over either political parties or MPs.

Monday, August 18, 2008

CBA urges Government to reform Privacy Act

I am currently in Quebec City attending the Canadian Bar Association's annual Canadian Legal Conference. On behalf of the CBA's National Privacy and Access Law Section, I had the honour of presenting a resolution to the National Council calling for reforms to the Privacy Act. The resolution passed with one contrary vote (I wanted to speak with the fellow who voted against it, but didn't get the chance and then lost him in the crowd). This is the third time the CBA has formally called upon the government to look at the antiquated 1982 Act. The Privacy Commissioner, Jennifer Stoddart, is here and spoke to the Council on the following day. Her office has issued the following press release about the resolution:
News Release: Commissioner welcomes legal community’s call for privacy law reform (August 18, 2008) - Privacy Commissioner of Canada

Commissioner welcomes legal community’s call for privacy law reform

Quebec City, August 18, 2008 — A Canadian Bar Association (CBA) resolution once again highlights the urgent need for reform of Canada’s federal public sector privacy legislation, says the Privacy Commissioner of Canada, Jennifer Stoddart.

“With this resolution, lawyers from across the country are urging the government to strengthen privacy protection for Canadians. Canada’s federal sector privacy legislation, the Privacy Act, is unbelievably inadequate,” says Commissioner Stoddart. “I hope the federal government will heed the CBA’s call for modernization of the Act. This is the latest in a string of appeals from privacy experts about the need to update legislation which has been far outpaced by technological and societal changes.”

The CBA, which is holding its 2008 Legal Conference in Quebec City, passed the resolution calling for comprehensive revision of the Privacy Act on the weekend.

In particular, it proposes changes to the legislation to ensure that:

  • Federal government departments only collect personal information when demonstrably necessary for clear and articulated state goals;
  • Once collected, personal information is rigorously protected with stringent safeguards and accountability requirements, including a breach notification requirement; and
  • Personal information is not shared within or beyond Canada’s borders unless those safeguards and requirements can be guaranteed.

The Office of the Privacy Commissioner of Canada (OPC) has long been advocating for reform of the Privacy Act, which is a quarter-century old and has never been substantially updated.

Last spring, the House of Commons Standing Committee on Access to Information, Privacy and Ethics began a study of the Privacy Act and possible amendments. The OPC reform proposals to the committee are posted at http://www.privcom.gc.ca/keyIssues/ki-qc/mc-ki-pa_e.asp. The OPC looks forward to the Committee’s recommendations.The CBA resolution is available at www.cba.org/cba/resolutions/pdf/08-06-a-pdf.pdf. The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy and the protection of personal information rights of Canadians.

Thursday, February 14, 2008

No need for RCMP to keep files secret, privacy Commissioner says

The Privacy Commissioner of Canada has completed a review of the exempt databanks maintained by the RCMP and has concluded that many of the records should not be there in the first place. She calls it "disturbing":

News Release: Large number of files mistakenly held in RCMP exempt data banks "disturbing," says Privacy Commissioner (February 13, 2008) - Privacy Commissioner of Canada

Large number of files mistakenly held in RCMP exempt data banks "disturbing," says Privacy Commissioner

Commissioner tables first special report to Parliament; raises serious concerns about data banks containing documents Canadians can’t access

February 13, 2008 — An audit has found that many of the national security and criminal operational intelligence files sheltered from public access in the RCMP’s exempt data banks did not belong there, says the Privacy Commissioner of Canada in a special report to Parliament.

"These data banks have been crowded with tens of thousands of files that should not have been there," says Commissioner Jennifer Stoddart.

"Government transparency and accountability are fundamental concepts in democratic countries like Canada. Being named in a national security exempt bank file could have a harmful impact, particularly in a post 9-11 environment. For example, it could potentially affect someone trying to obtain an employment security clearance, or impede an individual’s ability to cross the border."

Exempt data banks serve to withhold the most sensitive national security and criminal intelligence information. Government departments and agencies which control these records will consistently refuse to confirm or deny the existence of information in response to an individual’s request for access.

Canadians should be able to see their personal information – except under limited circumstances, such as where the disclosure could threaten national security, international affairs or lawful investigations.

"The large number of documents held in these exempt banks when their inclusion was unwarranted is disturbing – particularly given the RCMP was advised of compliance problems 20 years ago and made a commitment to properly manage such banks " says Commissioner Stoddart.

"More than half of the files examined as part of our audit should not have been there."

The Privacy Commissioner announced during her appearance before the Maher Arar inquiry – where the sharing of personal information by police became a central issue – that her Office would audit exempt data banks held by federal government departments and agencies.

The audit findings are detailed in a special report tabled today in Parliament. This is the first time the Privacy Commissioner has used her powers under the Privacy Act to issue a special report.

RCMP’s Exempt Banks

The RCMP has two exempt banks: Criminal Operational Intelligence Records and National Security Investigations Records.

Of the files the Office of the Privacy Commissioner (OPC) tested, more than half of the national security files and over 60 per cent of criminal operational intelligence files did not warrant exempt bank status. Exempt banks are designed to hold only the most sensitive of such information. These files did not meet the threshold for inclusion in an exempt bank as set out in the Privacy Act and/or the RCMP’s own policy.

These findings are of particular concern given that, with few exceptions, the audit was conducted on files already examined by the RCMP as part of a recent internal review.

To illustrate, one seven-year-old file in the national security exempt bank detailed a resident’s tip that a man had gone into a rooming house and drugs might be involved. Police investigated, but found the man had simply dropped his daughter off at a nearby school and stepped out of his car to smoke.

RCMP Internal Review

While the OPC audit was proceeding, the RCMP conducted its own internal review, which has so far resulted in the removal of more than 45,000 records from the criminal operational intelligence exempt data bank. This review found varying rates of compliance:

  • Almost 99 per cent of criminal intelligence exempt data bank holdings – more than 2,700 documents – at RCMP headquarters should not have been there.
  • At B Division in Newfoundland and Labrador, roughly two-thirds of documents – close to 37,000 records – were incorrectly kept in the criminal intelligence exempt bank.

An internal review of the national security exempt data bank holdings at 13 divisions resulted in the removal of more than 1,400 files – more than 40 per cent of the files examined.

Notwithstanding the large number of records removed from the exempt data bank holdings as a result of the internal review, the OPC audit concluded both banks remain overpopulated.

"The problems are largely due to a general lack of awareness within the force of exempt bank policy and the absence of ongoing monitoring," says Commissioner Stoddart.

Past History of the RCMP Exempt Bank

In the late 1980s, the RCMP’s criminal operational intelligence exempt bank order was rescinded for non-compliance following another OPC review.

"That exempt bank order was reinstated with an understanding that the RCMP would adhere to guidelines for managing exempt bank holdings. Unfortunately, the RCMP has not met this commitment," the Commissioner says.

"While there is a clear need for exempt data banks to ensure highly sensitive information related to security and intelligence work is protected, privacy concerns must also be considered. Greater care must be taken to ensure that personal information is concealed in an exempt data bank only when absolutely necessary."

Results

The Privacy Commissioner is satisfied that the RCMP is taking the audit observations and recommendations seriously and will take action to ensure its exempt banks comply with the Privacy Act and RCMP policy.

The OPC will examine how the RCMP has followed through on its plans to improve how the exempt banks are managed within the next two years.

The special report and a backgrounder are available at http://www.privcom.gc.ca/.

The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy and the protection of personal information rights of Canadians.

From the Globe & Mail:

globeandmail.com: No need for RCMP to keep files secret, privacy czar says

No need for RCMP to keep files secret, privacy czar says

OMAR EL AKKAD

February 14, 2008

OTTAWA -- More than half the files in the RCMP's secret data banks should not be there, the federal Privacy Commissioner said yesterday in a report that is likely to renew calls for an overhaul of the national police force.

An audit by the commissioner's office found that tens of thousands of files in the RCMP's two "exempt" banks - which are designed to hold the most sensitive national security and criminal intelligence information - should not be secret, and many should have been removed years ago.

"These finds are particularly concerning given that, with few exceptions, the audit was conducted on randomly selected files already examined by the RCMP as part of an internal review," Privacy Commissioner Jennifer Stoddart said in a news release accompanying the report.

Ms. Stoddart said the large number of files kept secret was not only unjustifiable, but illegal.

In one case, a man on a Canada-U.S. bus tour, exasperated with a delay by the tour guide, joked that he should hijack the bus, Ms. Stoddart said. The bus driver told U.S. customs officials, and the RCMP were called. Even though it was deemed that the incident was clearly not a serious hijacking attempt, a file was kept in one of the secret banks for more than five years.

Ms. Stoddart said Canadians should be concerned about the large number of unnecessarily secret files because they can have a serious impact on someone looking to cross the border or obtain security clearance for a job.

Because the files are part of the secret data banks, she said, the RCMP will neither confirm or deny they exist when individuals ask the police force if they have any files on them.

Ms. Stoddart said her findings were especially surprising because a previous audit 20 years ago also discovered serious compliance problems with the data banks - problems the RCMP undertook to fix at the time.

The RCMP made the same pledge again yesterday."We will be implementing every one of this report's recommendations," Chief Superintendent Dan Killam said in a news release. He said that the force will re-examine files retained in banks known as Criminal Operational Intelligence Records and National Security Investigation Records.

"The end result will be a new accountability structure that will see responsibility for these banks shared between operational areas of the force and experts from our Access to Information and Privacy Branch," Mr. Killam said. "Based on our reading of Ms. Stoddart's report, we believe this increased oversight of the exempt banks is what she and other Canadians want."

Ms. Stoddart's report, which marks the first time the commissioner has used her powers under the Privacy Act to issue a special report to Parliament, is more bad news for a police force already under intense public scrutiny.

Liberal MP Ujjal Dosanjh said the new findings are a clear indication that the government should adopt the recommendations of a federal task force last year that proposed a new civilian board of management for the force.

"It is absolutely shocking that the RCMP would show such reckless disregard for information about individuals of which 99 per cent did not deserve to be there in the first place," Mr. Dosanjh said. "That should send shivers down every Canadian's spine."

Ms. Stoddart said she believes the large number of unnecessarily secret files are the product of negligence rather than malice.

"I think it just fell by the wayside."

Friday, December 28, 2007

Privacy resolutions from the PCC

Privacy resolutions from the Privacy Commissioner of Canada:

News Release: Do you resolve to protect your privacy in 2008? (December 27, 2007) - Privacy Commissioner of Canada

Do you resolve to protect your privacy in 2008?

OTTAWA, December 27, 2007 – Threats to the privacy rights of Canadians will intensify in 2008 unless organizations resolve to do more to protect personal information, warns Privacy Commissioner of Canada Jennifer Stoddart.

“Heightened national security concerns, the growing business appetite for personal information and technological advances are all potent – and growing – threats to privacy rights,” says Commissioner Stoddart.

“The coming year will be another challenging one for privacy in Canada.”

With that prediction in mind, Commissioner Stoddart today released her 2008 list of top 10 suggested New Year’s resolutions for businesses, individuals and government.

Resolutions for businesses in Canada:

1. Protect personal information with strong security.

More than 162 million records were compromised by theft or loss in 2007, triple the number of data losses for the previous year, according to a USA Today analysis of breaches in the US, Canada and other countries. This alarming trend can be reversed if businesses begin to recognize the value of personal information. The disastrous breach involving Winner’s and HomeSense stores is an example of what can go wrong if businesses don’t invest in the latest security.

2. Use encryption to protect personal information on mobile devices such as laptops.

We are seeing too many headlines about personal information at risk because a laptop has been lost or stolen. Organizations must ensure personal information on a mobile device is encrypted – protecting information stored on a laptop with a password is simply not enough.

3. Ensure credit card processing equipment masks complete card numbers on receipts.

Complete credit card numbers should not be printed on receipts for electronically processed transactions. Businesses were supposed to switch to electronic processing equipment that masks card numbers – for example, by printing Xes – by the end of 2007. Printing complete card numbers exposes customers to the risk of identity theft. (Some very small businesses may still be manually taking imprints of cards because it is not economically feasible for them to purchase electronic equipment. They should still take all steps necessary to protect the information they collect.)

Resolutions for Canadians:

4. Think twice before posting personal information on social networking sites.

Many Facebook and Myspace users think of these sites as private, when, in reality, the information they post can often be seen by just about anyone. Before posting something, ask questions such as: How would I feel defending this comment or photo during a job interview five years from now? Am I harming someone else or invading someone’s privacy by posting this comment, photo or video? We like this simple rule of thumb: If Grandma shouldn't know, it shouldn't be posted.

5. Ask questions when someone asks for personal information.

It’s a good idea to understand why information such as your phone number or postal code, or driver’s licence is being requested and how it will be used. If you are concerned about receiving junk mail or telemarketing calls, decline to provide the information. Canada’s privacy laws offer you a choice about providing personal information that is not necessary for a transaction.

6. Take steps to protect your personal information.

Invest in a good shredder or burn all documents that include your name, address, SIN, financial information or other sensitive personal information. Papers containing personal information don’t belong in the recycling bin.

Resolutions for the federal government:

7. Overhaul the no-fly list to ensure strong privacy protections for Canadians.

The no-fly list involves the secretive use of personal information in a way that has very serious impact on privacy and other human rights. Innocent Canadians face the very real risk they will be stopped from flying because they’ve been incorrectly listed or share the name of someone on the list.

8. Move forward with proposed reforms to Canada’s privacy laws.

The federal government is currently holding consultations on important amendments to the Personal Information Protection and Electronic Documents Act (PIPEDA). These proposed changes include mandatory breach notification, a step that would encourage businesses to take security more seriously and protect Canadians against identity theft.

We also urge the federal government to open a review of the Privacy Act, which will be celebrating its 25th anniversary in 2008. Canadians should be offered the same level of legal protection under the Privacy Act as they have, as consumers, under PIPEDA.

9. Ensure that identity theft legislation is swiftly passed.

The government has introduced Criminal Code amendments to help police stop identity thieves or fraudsters before Canadians suffer actual financial harm. The changes include explicit penalties for collecting, possessing and trafficking in personal information.

10. Develop anti-spam legislation.

Canada remains the only G-8 country without anti-spam legislation, raising the danger that we will become a harbour for spammers. Halting the proliferation of spam is another important measure necessary to address identity theft.

The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy and the protection of personal information rights of Canadians.

Saturday, November 10, 2007

Privacy laws and general cluelessness

Karen Selick, a lawyer from Belleville, has an opinion piece in a recent National Post going on a tirade against privacy laws. I can certainly see her point. But the problem is not the privacy laws themselves, but the general cluelessness of the people who cite them to avoid doing something they can and likely should do.

The examples raised by Ms. Selick are general bureaucratic nonsense, but I do agree that privacy laws are increasingly and incorrectly cited by people who should know better:

The CRA vs. Canadian men

Wednesday, November 07, 2007

It appears that the Canada Revenue Agency (CRA) has recently established a policy of ripping off divorced or separated men on the flimsiest of pretexts. Within the past month, two of my legal clients have had their spousal support deductions disallowed, despite having filed copies of the documents (court order or separation agreement) proving that they have to pay.

They've both received letters from CRA bureaucrats saying they must provide signed receipts from their estranged wives. Fat chance. The wives have no obligation to provide receipts. Many women in these circumstances would withhold receipts either as a bargaining tactic to exact some other concession, or from sheer malice.

...

I phoned the CRA and spoke to a "pre-assessment review officer." She told me that it was within an officer's discretion to accept other evidence of support having been paid, without insisting that a man approach a hostile wife for receipts, and that she herself would have accepted the copy of the wife's tax return. I suspected that her apparent reasonableness may have arisen because she was talking to an irate lawyer, so I pressed on, asking why the CRA would not, on its own initiative, simply compare the two tax returns and allow the husband's deduction so long as the wife had reported the same amount of income.

Oh no, she said, that would violate the privacy laws. If they allowed the man's deduction so easily, that would be tantamount to spilling some confidential information that the wife had provided on her return.

My mind boggled. The CRA would choose to overtax a man by thousands of dollars rather than have him infer, from the fact that his deduction was allowed, that his wife had complied with the Income Tax Act and reported the money he already knew he had given her.

Could anyone really believe that this is what the Privacy Act requires? What nonsense. Men wouldn't necessarily assume that the CRA had cross-checked their wives' returns. They'd just assume the deduction was allowed because they're legally entitled to it.

The Privacy Act and its private sector counterpart, the Personal Information Protection and Electronic Documents Act (PIPEDA), now loom up unexpectedly and absurdly in many situations, I've observed. Few people know what they really require, so they've become a bogeyman, lurking ominously in the background, waiting to trip up some insufficiently vigilant flunky. It's like being a kid again, worrying that Santa's always watching and will know if you'd been bad or good. When in doubt, don't stick your neck out by saying anything about anything, no matter how absurd and inconvenient the consequences may be to anyone else.

Here's another example: Last year, I spent nine hours at a hospital emergency ward with a relative, who ultimately died there following a stroke. Days later, I wrote a letter praising the three doctors and one nurse who had attended her for their diligence and compassion. I didn't know their names but asked the hospital to pass my letter on to them. Astonishingly, the hospital replied that doing so would violate the privacy laws, unless the deceased's executor consented. Huh? I was there. I watched them doing their jobs. They discussed things with me. I observed their competence and kindness. I wanted them to know that. How on Earth could it violate anybody's "privacy" for the hospital to pass along my letter?

Aah, PIPEDA -- I've pondered this farce before. Every divorce lawyer in the country collects and uses personal information about their clients' spouses. We couldn't do our jobs otherwise. Theoretically, PIPEDA says we're supposed to seek the opposing party's consent to collecting and using information about their incomes, their adultery, their alcoholism, their bankruptcies, etc. Never yet has another lawyer contacted a client of mine seeking consent, so I assume my colleagues are as mystified as I am over how we're supposed to comply. Legislation like this, applied in the ridiculous way in which it is so often applied, undermines respect for the law. And the law could sure stand a little respect these days.

The only thing that I'd add is the last paragraph is likely incorrect. The case between the spouses is not a "commercial activity" so PIPEDA would not apply to that, even if it is facilitated by a lawyer. No PIPEDA, no consent required.

Thursday, October 18, 2007

Privacy Commissioner tables report on public sector Privacy Act

The Privacy Commissioner of Canada has tabled her annual report on the Privacy Act in parliament today. The Commissioner notes that the Privacy Act became law when the Commodore 64 was new on the shelves and is getting long in the tooth.

Canadians continue to think personal information not well protected: Tabling of Privacy Commissioner of Canada’s Annual Report on the Privacy Act

October 17, 2007

Canadians continue to think personal information not well protected: Tabling of Privacy Commissioner of Canada’s Annual Report on the Privacy Act

Ottawa, October 17, 2007 — Canadians overwhelmingly feel their personal information is less well protected than it was a decade ago, and they are right to be worried, says the Privacy Commissioner of Canada, Jennifer Stoddart.

Commissioner Stoddart’s 2006-2007 Annual Report on the Privacy Act was tabled today in Parliament. At the same time, the Privacy Commissioner’s Office released new research confirming that Canadians are unsure of how their personal information is protected, and by whom.

Increasingly, Canadians’ personal information is being exchanged with law enforcement and security agencies in other countries. The government has claimed that this transborder flow of information will improve transportation safety and enhance our national security. “We are particularly concerned about the number of travel-related security programs that have been put in place,” says Commissioner Stoddart. “Parliament may not be sufficiently informed about how these programs work and their individual and collective impact on the privacy rights of Canadians.”

The increased collection of personal information under these programs increases the risk that Canadians will be the victims of inappropriate data matching, intrusive data mining, or the unintended consequences of the disclosure of personal information. This increases the risk of surveillance, rendition and unwarranted attention from law and security enforcement both at home and abroad.

These concerns could be addressed, in part, by a review and modernization of the Privacy Act. As the Annual Report notes, “Parliament passed Canada’s public sector privacy law back in 1982 – the same year the Commodore 64 computer hit the market. At the time, both were considered pioneering.”

The Privacy Act, unfortunately, is not equipped to deal with the pressures imposed by tremendous technological change. In fact, Canada’s private sector privacy law, the Personal Information Protection and Electronic Documents Act, provides more protection for Canadians.

As the results of an audit of the government’s Privacy Impact Assessment (PIA) Policy confirm, government departments are not doing enough to protect Canadians’ personal information as they plan new programs or redesign existing programs.

“While we did not identify cases of pervasive non-compliance, many institutions are not fully meeting their commitments under the policy and, by extension, the intent or spirit of the Privacy Act,” says Commissioner Stoddart.

Under the PIA policy, federal institutions are required to assess the potential privacy risks of programs before they are implemented. These institutions must also identify the measures in place to protect personal information as it is collected, stored, used, disclosed and ultimately destroyed.

The Office of the Privacy Commissioner audit found that some institutions made serious efforts to apply the PIA policy but many are lagging behind. PIAs are sometimes completed well after the program has been implemented and, in some cases, not done even when potential privacy issues are evident.

“Privacy protection should be a key consideration in the initial framing of a program or service,” says Commissioner Stoddart. “Current PIA reports offer little assurance to Canadians who want to understand how a government service or program will affect their privacy.”

Canadians not only want to be reassured that their personal information is being protected; they also want to be informed when it is disclosed inappropriately.

Research conducted for the OPC shows that a majority of Canadians (seven in ten) expect to be informed if a security breach leads to the disclosure of information – whether that information is sensitive or not.

That research, a survey of 2,001 Canadians conducted by EKOS Research Associates earlier this year but released for the first time today, also found that:

  • Seven in ten Canadians feel their personal information is less protected than it was ten years ago.
  • A bare majority of Canadians agree that they have enough information to know how new technologies might affect their personal privacy.
  • About seven in ten Canadians believe that they are doing a relatively good job of protecting their own personal information.
  • Despite this, almost half of Canadians (46 per cent) carry a Social Insurance Number (SIN) card in their wallet, although this number is a key piece of information used by identity thieves.

“These survey results underline that we – my Office, privacy advocates, regulators and consumer protection authorities – have to work harder to reassure Canadians that their privacy rights are protected,” says Commissioner Stoddart. “We also have to give them the information and tools so they can better protect their own information.”The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of the privacy and protection of personal information rights of Canadians.

To view the reports:

Wednesday, January 17, 2007

Taxman moves to protect privacy

I was interviewed today for Global National's most recent report on privacy problems at the Canada Revenue Agency (our IRS, for my American readers). Since earlier reports on misdirected tax information, many more people have come out to report they have also been the unwitting recipients of information about other taxpayers. See: Taxman moves to protect privacy and also note the many comments in which others relate receiving others' personal information.

I think you can get the video of the feature here: http://video.canada.com/VideoContent.aspx?13750&vc=1&popup=1, but it seems hit and miss to me.

Monday, January 08, 2007

More on privacy and the Canada Revenue Agency

The Canada Revenue Agency continues to be in the news as of late.

The Canadian Press has found that the CRA official leading the investigation into the disclosure of information about high profile taxpayers, including MP and former hockey star Ken Dryden, once faced the wrath of George Radwanski:

CRA commissioner probing Dryden tax leak once dismissed privacy breach finding

Gregory Bonnell

Canadian Press

Monday, January 08, 2007

TORONTO (CP) - The senior public servant leading a probe into the leak of Ken Dryden's confidential tax information once dismissed a scathing ruling by the federal privacy commission that found Canada Revenue Agency employees had violated the Privacy Act.

Larry Hillier, the agency's assistant commissioner for the Ontario region, launched an "immediate investigation" last month after a published report that employees had violated the Income Tax Act, the Privacy Act and possibly criminal law by leaking Dryden's information.

In an internal e-mail sent to CRA employees, Hillier also warned of possible disciplinary action, including dismissal.

"When one employee breaches confidentiality, as is currently alleged, each and every one of us is impacted," he wrote.

Hillier, however, had a decidedly different response in 2003, when the federal privacy commissioner found CRA employees committed a "serious violation" of the Privacy Act by accessing and disclosing the tax information of former employee Lillian Shneidman while investigating allegations that she had violated a taxpayer's privacy rights.

In an October 2003 letter obtained by The Canadian Press, Hillier defended the actions of his employees, despite the privacy commissioner's findings.

"I offer the following regarding the above-referenced report, which concludes that we inappropriately accessed Ms. Shneidman's tax information," Hillier writes in a letter to then-CRA human resources branch assistant commissioner Dan Tucker.

"It is felt that this particular investigation warranted the accessing of Ms. Shneidman's tax information, as a taxpayer raised serious allegations."

CRA employees who are found guilty of disclosing confidential tax information - a violation of the Income Tax Act - face fines of up to $5,000 or jail time of up to 12 months. Under the Criminal Code of Canada, breach of trust by a public officer is punishable by a maximum prison sentence of five years.

Shneidman, who was fired from the CRA in 2001, had been assured in a July 2003 letter from Tucker that the agency viewed "any breach in privacy as a very serious matter."

The CRA "will ensure that appropriate corrective action will be taken," Tucker wrote.

At least one of the employees involved in the incident has been promoted, said Shneidman - who continues to fight her termination, with cases pending before the Public Service Labour Relations Board and the Federal Court of Appeal.

Former privacy commissioner George Radwanski was unequivocal in his condemnation of the CRA's treatment of Shneidman.

"Accessing that information . . . for the sole purpose of confirming your status as a (CRA) employee was, in my view, totally unnecessary and a gross misuse of taxpayer information," wrote Radwanski, who faces charges of fraud and breach of trust after resigning that same year amid an expense-abuse scandal.

"I consider the use of your (tax) information in this instance to constitute a serious violation of the confidentiality rights afforded you under . . . the Privacy Act."

...

Thursday, January 04, 2007

Incident: CRA misdirects taxpayer information

A Halifax resident was more than slightly surprised when he went to the Canada Revenue Agency to pick up his requested notice of assessment. While the notice was conspicuously absent from the envelope, he did find a raft of information about ten complete strangers. Apparently, the CRA stuffed the wrong envelopes and handed over confidential and sensitive information to the wrong person.

When the individual who received the information was not satisfied with the CRA's reaction, he called the other taxpayers and went to the media. The story is on the front page of the Halifax Chronicle Herald.

To make matters worse, the notice of assessment was mailed but nobody knows who to.

CTV is doing a piece for the supper hour news here in Halifax, for which I was interviewed earlier today. They are hoping to get some comment from the unshuffled Minister responsible for CRA.

From today's paper:

More than he wanted to know

Government mistakenly mails other people’s tax papers to Whites Lake man

By JOHN GILLIS Staff Reporter

Andrew Doiron of Whites Lake just wanted to find out his RRSP contribution limit for the year. But what he got was a raft of personal information about 10 strangers from as far away as British Columbia.

The Canada Revenue Agency is now investigating how the confidential tax documents landed in Mr. Doiron’s mailbox and where the information he requested ended up.

"It looks like somebody just picked a handful of paper off a printer and just slipped it in an envelope with my (address) page on top," Mr. Doiron said Wednesday. "But of course they didn’t put my papers in there."

The confusion began Dec. 20 when Mr. Doiron went to the Canada Revenue Agency’s Halifax office in person to ask for a copy of his notice of assessment. He was told he had to call a toll-free number to ask for the document. Staff let him use a phone in the building.

Mr. Doiron was surprised Tuesday when he found an envelope from the agency in his mailbox, and it contained about 35 pages. The documents bore the names, addresses, social insurance numbers, income, marital status and other personal information for 10 other people. His own notice of assessment was not included.

He immediately called a toll-free Canada Revenue Agency number again but said it was tough to persuade the person who answered to let him speak to a supervisor. When he finally did, he said he was asked to mail the documents back to the agency and advised he could claim the price of the postage stamp on his tax return next year.

Mr. Doiron also called as many of the people whose tax information he’d been sent as possible.

One, Sandra Ambersley of Brampton, Ont., told CTV she was very concerned about what might have happened if someone had wanted to use that information.

"I was totally shocked yesterday when I received a call from Halifax, this man saying that he’d received all my personal information," she said Wednesday.

Mr. Doiron noted that on the same online telephone directory he used to find people’s telephone numbers, there was an ad pointing to a Capital One credit card application that required only an address and a social insurance number.

He personally returned all the strangers’ documents to the Halifax office Wednesday.

Mr. Doiron said he felt he did not get a serious response from the agency until after he began contacting the media.

Jack Lee, acting director of the Nova Scotia office, called to apologize and had a copy of the notice of assessment Mr. Doiron requested sent to him. It arrived safely.

The notice had been mailed previously, but not to him.

"Mine’s out there somewhere, floating around," Mr. Doiron said. "I hope somebody threw it away."

Canada Revenue Agency spokesman Roy Jamieson said security is the No. 1 priority for the service, but mistakes happen.

"We’re certainly scrambling to try and piece together what took place," he said. "There’s quite an active and quite an intense investigation going on right now."

He said a call to a toll-free number could be answered at any one of a number of call centres across the country, depending in part on the nature of the request. A requested document could be printed at the appropriate location and mailed from there.

The agency sends about 90 million pieces of mail per year and it’s rare that something gets mixed up, he said.

"To be misdirected in the magnitude of this case, it’s certainly unusual," Mr. Jamieson said.

He said the agency will contact all of the people whose documents were involved and will keep Mr. Doiron abreast of its investigation into the mix-up.

"There’s no question that any kind of breach of security and compromising of an individual’s privacy and confidentiality is our most significant issue in this agency," Mr. Jamieson said.

Mr. Doiron has little confidence that anything will change.

"My gut feeling is, this is government, nothing’s going to happen," he said.

Update: From CTV:

Canada Revenue investigates botched mailout

The Canada Revenue Agency is scrambling to restore public trust and has launched an internal investigation after confidential information on several Canadians was sent to a Halifax-area man.

Documents that Andy Doiron of White's Lake, N.S., were mistakenly sent include social insurance numbers, income, addresses and the marital status of 10 Canadians, including some from as far west as Edmonton.

Doiron said he called most of the people to tell them what happened, and returned the documents to Revenue Canada.

With the trust of Canadians potentially on the line and tax time just around the corner, the agency is promising tough action if necessary.

Revenue Canada spokesperson Roy Jamieson called the incident a rare case of misdirected mail, but admitted somebody in the department made a mistake.

"Certainly if we identify breaches of policy process and procedure, there are disciplinary measures that can be taken and I expect they will be looked at quite seriously," he told CTV Atlantic.

Federal Minister of National Revenue Carol Skelton said she was "disturbed" by the security breach.

"The instant that I found out about it we had launched an investigation," she told CTV News in Saskatoon. "I really can't say much more about it than that. The incident is being looked into."

The agency is still trying to determine which one of five locations was responsible for the botched mail out.

David Fraser, a legal expert in security matters, told CTV Halifax that if such information were to fall in the wrong hands, it could easily be used to commit fraud.

"There really does need to be something done in order to make sure the trust is always there. Accidents happen but so often trust is won or lost in the aftermath of how they decide to deal with it," he said.

Sandra Ambersley of Brampton, Ont. was one of the people Dorion called.

"I was totally shocked when I received the call (on Tuesday) from Halifax," Ambersley told CTV Toronto.

"This man (was) telling me that he received all my personal information. As a joke he did say 'I could duplicate you right now.'"

The confusion began when Doiron called the revenue agency on Dec. 20 requesting a copy of his notice of assessment.

On Tuesday, an envelope from the agency arrived in his mailbox, containing over 30 pages of documents with all the information. His own assessment wasn't included.

Doiron said he immediately called the toll-free Canada Revenue Agency number again and he was asked to mail the documents immediately.

With a report from CTV Atlantic reporter Marc Patrone.