Showing posts with label Canada's Anti-SPAM Law (CASL). Show all posts
Showing posts with label Canada's Anti-SPAM Law (CASL). Show all posts

Monday, August 08, 2022

Video: OPC Finding: Spam messages sent by COVID testing contractor

The Privacy Commissioner of Canada just released a report of findings about a company contracted by the Airport of Montreal to do on-arrival covid testing. The company added the people tested to their mailing list and sent them unsolicited commercial electronic messages. The investigation was done jointly with the Information Commissioner of Quebec. The finding raises more questions than it answers.

The complainant in this case arrived at Montreal’s Trudeau International Airport. To comply with the Public Health Agency of Canada’s rules, the individual had to undergo on-arrival COVID testing. Conveniently, the Airport had contracted with a company called Biron Health Group to COVID testing directly at the airport. So the complainant went to the Biron site, provided them with his contact information, had this test done, it was negative and they emailed him the results.

A few days after receiving his test results, the complainant received an email from Biron promoting its other services. The complainant unsubscribed using the link in the email, and never received any further unwanted emails from them. The OPC said “he was shocked to receive such an email” and filed a complaint with the OPC.

The information and privacy commissioner of Quebec also investigated, but does not appear to have released a decision on the case. Instead, they just referred to the OPC’s finding.

During the course of the investigation, the company said it had “implied consent” under Canada’s Anti-Spam Law to send commercial electronic messages and was justified in doing so.

The OPC said there was no implied consent under PIPEDA, however. Here’s what they said specifically:

“The OPC is of the opinion that Biron could not reasonably assume that it had the implicit consent of travellers arriving in Canada. Biron was mandated by the government to conduct COVID-19 testing on travellers and paid by the Montreal Trudeau Airport. Biron was the only company offering this service at this airport. Consequently, travellers arriving in Canada had no choice but to do business with Biron to comply with the rules issued by the Public Health Agency. In this situation, these travellers would not normally expect their personal information to be used for reasons other than the mandatory testing.

Biron collected the travellers’ personal information for the purpose of conducting COVID-19 tests and sending them sensitive information related to their health, notably their test results. Biron was acting as a service provider for the airport. The OPC considers that Biron should have taken these circumstances into account before using the personal information for secondary marketing purposes and for its own purposes.”

Because Biron said they’d stop doing this, the OPC closed the file as “settled during the course of the investigation”. Case closed.

So why is this unsatisfying? There are a couple of key questions in the background, of interest to privacy practitioners, that are unaddressed and thus unanswered.

The first question is what law should actually apply to Biron in this case? The Privacy Commissioner refers to PIPEDA, our federal commercial privacy law. But we have a mess of privacy laws in Canada, more than a few of which could have been applicable.

Quebec has a provincial privacy law that applies to all businesses in that province, unless they are “federal works, undertakings or businesses”. Notably, international airports and airlines are “federal works, undertakings or businesses.”

There really is no doubt that if the testing facility had been off the airport property and operating on its own, the federal privacy Law could not have applied at all and instead the Quebec private sector privacy law would have been applicable. That means the federal Commissioner would have had no jurisdiction to investigate and it would have been entirely up to the Quebec Commissioner to do so.

So does that mean that simply being on or operating from airport property makes you a “federal work, undertaking or business”? I don't think that can really be the case.

Was it because the service they were providing is connected to international travel that places them within Federal jurisdiction? That seems dubious to me.

Were they within Federal jurisdiction because they had been engaged by the airport authority to provide this service? The airport authority is certainly a “federal work, undertaking or business”, but does that mean all of its contractors become “federal works, undertakings or businesses”? Again, I don't think that can really be the case. Would a taxi company given a concession to serve the airport automatically come under federal jurisdiction?

They were performing a function that was required by the Public Health Agency of Canada, but PHAC is subject to the federal Privacy Act, which never came up in the commissioner's report of findings.

This would be more tricky in a province like Alberta, where there is a provincial general privacy law that excludes PIPEDA and a health privacy law that does not. (Quebec doesn’t have a health-specific privacy law.)

Now, it may well be that both the federal and the Quebec Commissioners thought they didn't even have to consider jurisdiction because they got the result they were looking for during the course of the investigation: the company said they would change their practices and what might have been problematic under either the Quebec or the federal law has ceased. This seems likely to me, as in my experience the federal Privacy Commissioner's office we'll bend over backwards to avoid making any statements related to their jurisdiction that could come back to haunt them later.

This is not just a privacy nerd question, because other things turn on whether a company is a “federal work, undertaking or business”. If Biron is in that category, then provincial labour and employment laws don’t apply to that workplace. Instead, the Canada Labour Code applies. Other federal laws would also suddenly apply to them, not just our privacy law. If I was this company, I’d be left scratching my head.

The second element of this that is problematic is the interaction between our privacy laws and Canada's anti-spam law, also known as CASL. You will recall that the company said that they were justified in sending commercial electronic messages because they had an “existing business relationship” with the people who underwent testing. The Privacy Commissioner really did not address that, but instead focused on the Personal Information Protection and Electronic Documents Act which requires consent for all collection, use and disclosure of personal information. That consent can be implied, particularly where it would be reasonable for the individual to expect that their information will be used for a particular purpose in light of the overall transaction. The Commissioner found that individuals would not expect to have their personal information used for the secondary purpose and therefore there was no implied consent under PIPEDA.

But that is contrary to the express scheme of Canada's anti-spam law. Under CASL, an organization can only send a commercial electronic message to a recipient where it has consent to do so. That consent either must be express or implied. Implied consent under CASL is very different from implied consent under PIPEDA. CASL doesn't care about what the consumer's expectation might be. Consent can be implied where there is an existing business relationship. One of the possible existing business relationships is the purchase of goods or services from the organization in the previous two years. Presumably, buying a COVID test from a vendor would meet that threshold and there would be implied consent for sending commercial electronic messages. I do agree with the federal Privacy Commissioner that doing so because you are ordered to by the Public Health Agency of Canada would really be contrary to the individual's expectation.

But this really does highlight some of the absurd dissonance between our anti-spam law and our privacy law. Both use the term “implied consent”, but it means radically different things. From this finding from the federal Commissioner, it appears that he is of the view that implied consent under CASL does not lead to deemed implied consent under PIPEDA. CASL expressly permits it, but PIPEDA does not.

When it comes to consent for sending commercial electronic messages, one would think that the piece of legislation that was expressly written and passed by Parliament for that purpose would be the final say, but the OPC certainly does not seem to be of that view.

The Privacy Commissioner carried out this investigation along with the Quebec commissioner, but there is no mention of whether the CRTC, which is the regulator under CASL, was involved.

At the end of the day, I think an existing business relationship was created between the complainant and the company so that there would have been implied consent to send commercial electronic messages, regardless of whether the consumer would have expected it to do so. The Commissioner did highlight that the individual had to be tested under the rules for the Public Health Agency of Canada, leaving room to argue that had the individual gone to the company for a test for other purposes, that might have been a more direct commercial relationship between the parties.

As my friend and tech law colleague Jade Buchanan pointed out on Twitter, “CASL is completely unnecessary when PIPEDA will apply to the use of personal information (name email, etc.) to send commercial electronic messages.” Personally, I think that one of the reasons why we have CASL is because PIPEDA was seldom enforced by the OPC against spammers when clear jurisdiction to do so existed for more than a decade before CASL was created.

And there’s nothing in the pending Consumer Privacy Protection Act that would address this dissonance between our privacy and spam law.

So that is the finding, and we're left scratching our heads a bit or at least have unanswered questions about important matters of jurisdiction and the intersection between our privacy laws and our spam laws.

Monday, April 18, 2022

Video: Canada's Anti-Spam Law and the installation of software

Canada’s anti-spam law is about much more than just spam. It also regulates the installation of software. Like the rest of the law, it is complicated and convoluted and has significant penalties. If you’re a software developer or an IT admin, you definitely need to know about this.

So we’re talking about Canada’s anti-spam law. The official title is much longer, and it also includes two sets of regulations to make it more complicated.

Despite the snappy title that most of us use: Canada’s Anti-Spam Law, it is about more than just spam. It has often-overlooked provisions that make it illegal to install software on another person’s computer – or cause it to be installed – without their consent.

It was clearly put into the law to go after bad stuff like malware, viruses, rootkits, trojans, malware bundled with legitimate software and botnets. But it is not just limited to malevolent software. It potentially affects a huge range of software.

So here is the general rule from Section 8 of the Act:

8. (1) A person must not, in the course of a commercial activity, install or cause to be installed a computer program on any other person’s computer system or, having so installed or caused to be installed a computer program, cause an electronic message to be sent from that computer system, unless

(a) the person has obtained the express consent of the owner or an authorized user of the computer system and complies with subsection 11(5); or

(b) the person is acting in accordance with a court order.

Let’s break that down. The first part is that it has to be part of a commercial activity. I’m not sure they meant to let people off the hook if they’re doing it for fun and giggles. The “commercial activity” part is likely there so that the government can say this is justified under the federal “general trade and commerce power”.

They could have used the federal criminal law jurisdiction, but then they’d be subject to the full due process and fairness requirements of the Canadian Charter of Rights and Freedoms, and the government did not want to do that. They’d rather it be regulatory and subject to much lower scrutiny.

Then it says you can’t install a computer program on another’s computer without the express consent of the owner or authorized user of the computer. (The definition of “computer system” would include desktops, laptops, smartphones, routers and appliances.) or cause to be installed.

The express consent has to be obtained in the manner set out in the Act, and I’ll discuss that later.

It also additionally prohibits installing a computer program on another’s computer and then causing it to send electronic messages. This makes creation of botnets for sending spam extra bad.

The definition of the term “Computer Program” is taken from the Criminal Code of Canada

“computer program” means computer data representing instructions or statements that, when executed in a computer system, causes the computer system to perform a function; (programme d’ordinateur)

In addition to defined terms, there are some key ideas and terms in the Act that are not well-understood.

It talks about “installing” a computer program, but what that is has not been defined in the legislation and the CRTC hasn’t provided any helpful guidance.

I wouldn’t think that running malware once on someone’s system for a malevolent purpose would be captured in the definition of “install”, though it likely is the criminal offence of mischief in relation to data.

What about downloading source code that is not yet compiled? Or then compiling it?

It is certainly possible to load up software and have it ready to execute without being conventionally “installed”. Does it have to be permanent? Or show up in your installed applications directory?

I don’t know.

There’s also the question of who is an owner or an authorized user of a computer system.

If it is leased, the leasing company likely owns the computer and we’ve certainly seen reports and investigations of spyware and intrusive software installed on rented and leased laptops.

My internet service provider owns my cable modem, so it’s apparently ok if they install malware on it.

For authorized users, it means any person who is authorized by the owner to use the computer system. Interestingly, it is not limited by the scope of the authorization. It seems to be binary. Either you are authorized or you are not.

There are some scenarios to think about when considering owners and authorized users.

For example, if a company pre-installs software on a device at the factory or before ownership transfers to the end customer, that company is the owner of the device and can install whatever they like on it.

Many companies issue devices like laptops and smartphones to employees. Those employers own the devices and can install any software on them.

But increasingly, employees are using devices that they own for work-related purposes, and employers may have a legitimate interest in installing mobile device management and security software on those devices. Unless there’s a clear agreement that the employer gets to do so, they may find themselves to be offside the law.

So, in short, it is prohibited to do any of these things without the express consent of the owner or authorized user:

  • (a) install a computer program of any kind;
  • (b) cause a computer program of any kind to be installed, such as hiding or bundling additional software in an installer that the owner or authorized user has installed. We sometimes see this when downloading freeware or shareware, and the installer includes other software that the user didn’t ask for;
  • (c) or cause such a program that has been installed to send electronic messages after installation.

Of course, someone who is the owner or authorized user of the particular device can put whatever software they want on the device. This only covers installation by people who are not the owner or the authorized user of the device.

There are some exceptions that people should be aware of.

It is common to install software and to have it automatically update. This is ok if the user consents to the auto updates. But that probably doesn't apply if the update results in software that does very different things compared to when it was first installed.

There are some cases where consent is deemed or implied.

CASL deems users to consent to the installation of the following list of computer programs if the user’s conduct shows it is reasonable to believe they consented to it. It is a weird list.

At the top of the list are “cookies”. To start with, anyone who knows what cookies are knows they are not computer programs. They are text files, and including them on this list tells me that the people who wrote this law may not know as much as you may hope about this subject.

It then includes HTML code. HTML is hypertext markup language. I suppose it is data that represents instructions to a computer on how to display text and other elements. I guess the next question is whether this includes the variations of HTML like XHTML? I don’t know. But if HTML is a computer program, then so are fonts and Unicode character codes.

Next it refers to “Java Scripts”. Yup. That’s what it says. We are told by industry Canada that this is meant to refer to JavaScript, which is different from a Java script. Not only could have have maybe not made such a stupid mistake, but maybe they could have been clear about whether they were referring to JavaScript run in a browser (with its attendant sandbox) or something else.

Next on the list are “operating systems”, which seems very perverse to include. The operating system is the mostly invisible layer that lies between the computer hardware and the software that runs on top of it. Changes to the operating system can have a huge impact on the security and privacy of the user, and much of it happens below the system. And there is no clarity about whether an “operating system” on this list includes the software that often comes bundled with it. When I replace the operating system on my Windows PC, I get a new version of a whole bunch of standard software that comes with it like the file explorer and notepad. It would make sense that a user who upgrades from one version of MacOS or Windows to another. But I can make an open source operating system distro that’s full of appalling stuff, in addition to the operating system.

Finally, it says any program executable only through use of another computer program for which the user has already consented to installation. Does this include macros embedded in word documents? Not sure.

It makes sense to have deemed consent situations or implied consent, but we could have used a LOT more clarity.

There are some exceptions to the general rule of getting consent, two of which are exclusively reserved to telecommunications service providers, and a final one that related to programs that exclusively correct failures in a computer system or a computer program.

This is understandable, but this would mean that a telco can install software on my computer without my knowledge or consent if it’s to upgrade their network.

So how do you get express consent. It’s like the cumbersome express consent for commercial electronic messages, but with more.

When seeking express consent, the installer has to identify

  • the reason;
  • Their full business name;
  • Their mailing address, and one of: telephone number, email address, or web address;
  • if consent is sought on behalf of another person, a statement indicating who is seeking consent and on whose behalf consent is being sought;
  • a statement that the user may withdraw consent for the computer program’s installation at any time; and
  • a clear and simple description, in general terms, of the computer program’s function and purposes.

But if an installer “knows and intends” that a computer program will cause a computer system to operate in a way its owner doesn’t reasonably expect, the installer must provide a higher level of disclosure and acknowledgement to get the user’s express consent.

This specifically includes the following functions, all of which largely make sense:

  • collecting personal information stored on the computer system;
  • interfering with the user’s control of the computer system;
  • changing or interfering with settings, preferences, or commands already installed or stored on the computer system without the user’s knowledge;
  • changing or interfering with data stored on the computer system in a way that obstructs, interrupts or interferes with lawful access to or use of that data by the user;
  • causing the computer system to communicate with another computer system, or other device, without the user’s authorization;
  • installing a computer program that may be activated by a third party without the user’s knowledge; and
  • performing any other function CASL specifies (there are none as yet).

Like the unsubscribe for commercial electronic messages, anyone who installs software that meets this higher threshold has to include an electronic address that is valid for at least one year to the user can ask the installer to remove or disable the program.

A user can make this request if she believes the installer didn’t accurately describe the “function, purpose, or impact” of the computer program when the installer requested consent to install it. If the installer gets a removal request within one year of installation, and consent was based on an inaccurate description of the program’s material elements, then the installer must assist the user in removing or disabling the program as soon as feasible – and at no cost to the user.

So how is this enforced? CASL is largely overseen by the enforcement team at the Canadian Radio-television and Telecommunications Commission.

Overall, I see them at least making more noise about their enforcement activities in the software arena than the spam arena.

In doing this work, the CRTC has some pretty gnarly enforcement tools.

First of all, they can issue “notices to produce” which are essentially similar to Criminal Code production orders except they do not require judicial authorization. These can require the recipient of the order to hand over just about any records or information, and unlike Criminal Code production orders, they can be issued without any suspicion of unlawful conduct. They can be issued just to check compliance. I should do a whole episode on these things, since they really are something else in the whole panoply of law enforcement tools.

They can also seek and obtain search warrants, which at least are overseen and have to be approved by a judge.

Before CASL, I imagine the CRTC was entirely populated by guys in suits and now they get to put on raid jackets, tactical boots and a badge.

I mentioned before that there can be some significant penalties for infractions of CASL’s software rules.

It needs to be noted that contraventions involve “administrative monetary penalties” - not a “punishment” but intended to ensure compliance. These are not fines per se and are not criminal penalties. That’s because if they were criminal or truly quasi-criminal, they’d have to follow the Charter’s much stricter standards for criminal offences.

The maximum for these administrative monetary penalties are steep. Up to $1M for an individual offender and $10M for a corporation.

The legislation sets out a bunch of factors to be considered in determining the amount of penalty, including the ability of the offender to pay.

There is a mechanism similar to a US consent decree where the offender can give an “undertaking” that halts enforcement, but likely imposes a whole bunch of conditions that will last for a while.

Officers and directors of companies need to know they may be personally liable for penalties and of course the CRTC can name and shame violators.

There is a due diligence defence, but this is a pretty high bar to reach.

We have seen at least three reported enforcement actions under the software provisions of CASL.

The first was involving two companies called Datablocks and Sunlight Media in 2018. They were found by the CRTC to be providing a service to others to inject exploits onto users’ computers through online ads. They were hit with penalties amount to $100K and $150K, respectively.

The second was in 2019 and involved a company called Orcus Technologies, which was said to be marketing a remote access trojan. They marketed it as a legitimate tool, but the CRTC concluded this was to give a veneer of respectability to a shady undertaking. They were hit with a penalty of $115K.

The most recent one, in 2020, involved a company called Notesolution Inc. doing business as OneClass. They were involved in a shady installation of a Chrome extension that collected personal information on users’ systems without their knowledge or expectation. They entered into an undertaking, and agreed to pay $100K.

I hope this has been of interest. The discussion was obviously at a pretty high level, and there is a lot that it unknown about how some of the key terms and concepts are being interpreted by the regulator.

If you have any questions or comments, please feel free to leave them below. I read them all and try to reply to them all as well. If your company needs help in this area, please reach out. My contact info is in the notes, as well.

Friday, October 20, 2017

CRTC finds CASL to be constitutional in CompuFinder challenge

On October 19, 2017, the CRTC issued its decision in a constitutional challenge to CASL brought by CompuFinder. You may recall that in 2015, the CRTC levied the largest penalty to date -- $1.1 million -- against CompuFinder. (My previous blog post.) The company challenged the constitutionality of the legislation, primarily on the grounds that it is ultra vires federal jurisdiction (outside of powers granted to the federal parliament under the constitution) and that it violated s. 2(b) of the Charter and could not be saved by s. 1.

For the non-lawyers out there, a law can violate Charter rights but can still be upheld if the infringement is justifiable using s. 1:

1. The Canadian Charter of Rights and Freedoms guarantees the rights and freedoms set out in it subject only to such reasonable limits prescribed by law as can be demonstrably justified in a free and democratic society.

The framework for s. 1 analysis set by the Supreme Court requires all of the following to be met for a limitation on a constitutionally-guaranteed right to be upheld:

1. The limit must be prescribed by law

2. There must be a pressing and substantial objective

3. The means must be proportional
a. The means must be rationally connected to the objective

b. There must be minimal impairment of rights

c. There must be proportionality between the infringement and objective

In my personal view, the decision is incorrect in a number of ways. I think the Commission suffered the same issue that plagues much of the discussion of CASL: the use of the word "spam" in its colloquial sense when the focus really needs to be on what the law really regulates: commercial electronic messages. It is comparing apples to oranges, and statistics like "spam is down in Canada" is only slightly useful in the discussion.

I think the Commission was dramatically wrong in finding that there was a minimal impairment of constitutional rights. This generally asks whether the restriction unduly limits speech or expression that is outside of the scope of the "pressing and substantial objective."

In its decision (Compliance and Enforcement Decision CRTC 2017-367 | CRTC), the CRTC agreed with the government regarding the law's objective:

108. The government’s objective in enacting CASL is revealed within the title of the Act: “to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities….”

109. The Act is clearly focused on e-commerce in Canada as a whole. This is expanded on in the objective clause of the Act (section 3).

110. In the Commission’s view, it is clear that the government’s objective is pressing and substantial. The factual evidence put forward by the Attorney General is detailed and convincingly supports this conclusion. There is an abundance of literature, analyses, reports, and statistical evidence that demonstrate the existence of spam and other electronic threats, the impact that they have on Canadian businesses and consumers, and how countries around the world have been compelled to introduce legislation to address these threats.


Note again the use of the word "spam". The law regulates and generally prohibits "commercial electronic message" and its main defect -- in my view -- is that it goes after "spam" by limiting legitimate expression that is not "spam" and that has little if anything to do with harming confidence in electronic commerce.

However, the Commission did not follow CompuFinder's argument that the law is not minimally impairing.

152. CompuFinder’s argument at this stage is essentially that CASL’s CEM prohibition regime is overbroad, capturing more forms of expression than are necessary to achieve the statute’s purpose.

153. The Attorney General did not directly respond to each specific allegation of the law’s overreach. Instead, its main response to the overbreadth arguments raised by CompuFinder is that the Act does not impose a total ban on the sending of CEMs. Persons wishing to send commercial messages are not barred from using the Internet or email to advertise. In addition, the exceptions and exemptions to the general prohibition contained in section 6 of CASL act as levers that further limit the infringement of freedom of expression.

154. The Commission notes that, as indicated by the Supreme Court in JTI-Macdonald Corp., when interpreting these exceptions and exemptions, specific words should not be considered in isolation; rather, the interpretation must be guided by Parliament’s objective and its global intention sought.

155. In the case of CASL, Parliament’s concern was to combat a multitude of electronic threats that could have deleterious effects on Canada’s e-economy, Canadian businesses, and Canadian Internet users. In pursuing its objectives, Parliament has deliberately narrowed, and empowered the Governor in Council to make regulations narrowing, the applicability of the Act to certain commercial activities (as defined in subsection 1(1) of the Act), and enacted a long series of exceptions, exclusions, and limitations to the application of prohibitions on the sending of CEMs.

156. Examples of these exceptions can be found in subsections 6(5) and 6(6) of CASL and in the provisions regarding excluded messages in section 3 of the Governor in Council regulations. As a result of these and other exceptions and exemptions, the prohibition in section 6 of CASL does not apply to numerous types of CEMs, including those sent by or on behalf of an individual who has a personal or family relationship with the recipient, those consisting of an inquiry relating to a commercial activity engaged in by the recipient, certain notice-giving or transactional messages, and certain intra-organizational and inter-organizational messages.

157. Further, given that, in cases of ambiguity, claims of overbreadth may be resolved by appropriate interpretation, where the application of these exceptions and exclusions are potentially ambiguous, and such ambiguity could potentially lead to overbreadth of the provisions in question, they must be interpreted in the manner that would result in the least possible intrusion upon protected expression, while also respecting the intention of Parliament.

158. Accordingly, the Commission agrees with the Attorney General that the expression limited by CASL is substantially lessened as a result of its exceptions and exemptions. These exceptions, when taken as a whole, significantly narrow the application of section 6 and, as a result, on a balance of probabilities, the impugned provisions do not impair free expression more than necessary to achieve the objectives of CASL. In these circumstances, the limitations on the sending of CEMs, are not unreasonable in light of their legislative purpose.

I disagree with this overall, but I am particularly concerned with what the Commission said in paragraph 157. It essentially said that the law can be made constitutional in some cases by erring on the side of a constitutional interpretation in the event of any ambiguity. That essentially says that the law can remain constitutional because the CRTC enforcement folks can interpret in a manner that scales back its overbreadth. I don't think I know anyone who practices in this area who thinks that the CRTC enforcement folks can be counted on to do that.

I remain of the view that CASL is overbroad and unduly limits protected expression that has nothing to do with protecting consumer confidence in e-commerce. The Commission's decision doesn't change my mind on that at all, and it will be interesting to see if this particular case goes any further.

Wednesday, June 07, 2017

Canadian government pulls the plug on the Canadian Anti-Spam Law private right of action

It's official ... the ability to sue for damages under Canada's Anti-Spam Law (CASL) has been put on ice. An order-in-council dated June 2, 2017 repealed the provision of a previous cabinet order that set the commencement of the private right of action as July 1, 2017. Without that provision, the private right of action will not come into effect.

PC Number: 2017-0580

Date: 2017-06-02

His Excellency the Governor General in Council, on the recommendation of the Minister of Industry, pursuant to section 91 of An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities, and to amend the Canadian Radio-television and Telecommunications Commission Act, the Competition Act, the Personal Information Protection and Electronic Documents Act and the Telecommunications Act, chapter 23 of the Statutes of Canada, 2010, amends Order in Council P.C. 2013-1323 of December 3, 2013 by repealing paragraph (c).


The Precis sets out the rationale:

Order Amending Order in Council P.C. 2013-1323 of December 3, 2013 in order to delay the Coming into Force date of sections 47 to 51 and 55 of Canada's Anti-spam Law, which provides for a private right of action, in order to promote legal certainty for numerous stakeholders claiming to experience difficulties in interpreting several provisions of the Act while being exposed to litigation risk.


This gives Canadian business, government and consumers the chance to take a breath and figure out whether this dumpster fire of a law is the right tool for the job.

CASL's civil right of action to be delayed?

I am hearing from reliable sources that the government has agreed to postpone the civil right of action under Canada's Anti-spam Law. The provisions, that were planned to come into effect on July 1, 2017, would mean a person or corporation affected by a CASL contravention can bring a civil lawsuit against the offending person or entity – and seek remedies including monetary compensation and expenses. The maximum penalties are $200 for each commercial electronic message contravention (to a maximum of $1M/day), and $1M for each day on which a software contravention occurs (CASL’s software sections come into force on January 1, 2015).




Very few people in the legal community and in business are in favour of these provisions, and it would appear that the government has been convinced. When the order in council is published, it will appear in the Canada Gazette.

Thursday, March 05, 2015

CRTC issues first CASL penalty: $1.1 million levied against Compu-Finder

The CRTC has levied its first penalty under Canada's Anti-spam Law (CASL): a whopping $1.1 million against Compu-Finder for sending commercial electronic messages without consent and for not meeting the unsubscribe requirements under the law.

It would appear that Compu-Finder got the CRTC's attention quite vividly thanks to a huge number of complaints made to the CRTC's anti-spam reporting centre. Apparently 26% complaints received for this industry segment related to this company.

Here's the CRTC's media release:

CRTC Chief Compliance and Enforcement Officer issues $1.1 million penalty to Compu-Finder for spamming Canadians - Canada News Centre

March 5, 2015 – Ottawa-Gatineau - The Canadian Radio-television and Telecommunications Commission’s (CRTC’s) Chief Compliance and Enforcement Officer today issued a Notice of Violation to Compu-Finder, which includes a penalty of $1.1 million, for breaking Canada’s anti-spam law. Compu-Finder has 30 days to submit written representations to the CRTC or pay the penalty. It also has the option of requesting an undertaking with the CRTC on this matter.

Further to an investigation, the Chief Compliance and Enforcement Officer finds that Compu-Finder sent commercial electronic messages without the recipient’s consent as well as emails in which the unsubscribe mechanisms did not function properly. The emails sent by Compu-Finder promoted various training courses to businesses, often related to topics such as management, social media and professional development. The four alleged violations occurred between July 2, 2014 and September 16, 2014. Furthermore, an analysis of the complaints made to the Spam Reporting Centre of this industry sector shows that Compu-Finder accounts for 26% of all complaints submitted.

The CRTC is assessing complaints submitted to the Spam Reporting Centre that are under its legislative mandate and a number of investigations are currently underway. The CRTC is working with its partners, both within Canada and internationally, to protect Canadians from online threats and contribute to a more secure online environment.

The CRTC can discuss corrective actions with individuals, firms or organizations, which may lead to an undertaking that includes an amount to be paid and other corrective measures. As part of its powers, the CRTC can also issue warning letters, preservation demands, notices to produce, restraining orders and notices of violation.

Canadians are encouraged to report spam to the Spam Reporting Centre. The information sent to the Centre is used by the CRTC, the Competition Bureau, and the Office of the Privacy Commissioner to enforce Canada’s anti-spam law.

Quick Facts

  • The CRTC’s Chief Compliance Officer has issued Compu-Finder a Notice of Violation, which includes a penalty of $1.1 million, for four violations of Canada’s anti-spam law.
  • Compu-Finder had sent commercial emails without consent, as well as messages in which the unsubscribe mechanisms did not function properly.
  • To help Canadian businesses comply with the law, the CRTC has provided numerous information sessions across the country and made guidance materials available on its website.
  • The CRTC is working with its partners, both within Canada and internationally, to protect Canadians from online threats and contribute to a more secure online environment.
  • Canada’s anti-spam law protects Canadians while ensuring that businesses can continue to compete in the global marketplace.
  • Canada’s anti-spam legislation was adopted by Parliament in December 2010 and came into force on July 1, 2014.
  • Penalty amounts are calculated using the factors outlined in section 20 of Canada’s anti-spam legislation.

Quote

“Prior to the coming into force of the anti-spam law, the CRTC conducted numerous outreach initiatives to increase the awareness of businesses on the new requirements. Creating a secure online environment for Canadians is also the responsibility of industry. Despite the CRTC’s efforts, Compu-Finder flagrantly violated the basic principles of the law by continuing to send unsolicited commercial electronic messages after the law came into force to email addresses it found by scouring websites. Complaints submitted to the Spam Reporting Centre clearly indicate that consumers didn’t find Compu-Finder’s offerings relevant to them. By issuing this Notice of Violation, my goal is to encourage a change of behaviour on the part of Compu-Finder such that it adapts its business practices to the modern reality of electronic commerce and the requirements of the anti-spam law. We take violations to the law very seriously and expect businesses to be in compliance.”

Manon Bombardier, Chief Compliance and Enforcement Officer, Canadian Radio-television and Telecommunications Commission

Edit: Corrected/clarified the information in italics above.

Thursday, February 19, 2015

Pre-installed adware may be kosher under Canadian anti-spyware provisions of CASL

The Next Web is reporting that Lenovo has been shipping consumer laptops pre-equipped with adware (see: Lenovo Caught Installing Adware On New Computers). This raises an interesting question for Canadians: would something like this be ok under the anti-spyware provisions of Canada's Anti-Spam Law (CASL)?

In true lawyerly style, the answer is "it depends". But maybe this highlights one of the many problems with the law.

The owner or authorized user of a computer system can install whatever he or she wants on the device, but this may not be the ultimate end-user. So if a manufacturer installs adware software on the device before title to it passed to the end user, that may be just fine under the law (but likely problematic from the point of view of the end user). Also, if it is embedded in the operating system of the device, that may be OK because there's deemed consent for the installation of operating systems by third parties.

I think most consumers would say that adware, crapware, bloatware, etc. should not be on their devices without their consent and the company that put it there should be required to remove it on request. However, if the software was installed when the manufacturer owned the device, the law may not meet consumers' expectations.

For more information on the software installation provisions of CASL, check out my firm's FAQ on the subject.

Wednesday, January 28, 2015

Presentation on the new software installation rules in Canada's Anti-spam Law

I was pleased to deliver an online Hangout On Air about CASL's new software installation rules on behalf of both Digital Nova Scotia and McInnes Cooper. The full presentation is here and you can get your mitts on the slides here. As I mentioned in the video, feel free to ask any questions or make any observations in the comments below. Though I can't provide legal advice through comments (and you should not provide any confidential information), I'm happy to discuss this law.

Tuesday, October 14, 2014

Two weeks until the Canadian Bar Association 5th Annual Privacy and Access Law Symposium

Only a short time until the Canadian Bar Association's 5th Annual Privacy and Access Law Symposium in Ottawa at the end of the month. The conference is uniformly excellent with great speakers.

Topics include:

  • Implementing Canada's new Anti-Spam Legislation (CASL) under existing privacy frameworks
  • Key developments in international law which will affect Canadian compliance
  • Mobile tracking, consumer online scoring and user-generated health data
  • Records management and challenges to access
  • Significant provincial changes regarding police information checks, PIPEDA, Ontario's FIPPA “advice and recommendations” exemption, and IPC Ontario's “Crossing the Line” investigation report
  • Trends in access including shared services arrangements which include NGOs
  • Privacy in public places – protectable personal information

You can get the agenda [PDF] here and register here.

Friday, October 03, 2014

Presentation: Canada's Anti-spam Law and School Boards

Later today, I'll be giving a presentation to the Nova Scotia School Boards Association on Canada's Anti-Spam Law (CASL) and how it affects their operations. There has been a huge amount of confusion about the impact of this law on organizations like school boards, which are generally not engaged in commercial activity and can't really take advantage of some of the implied consent provisions are are available to other organizations.

Here's the presentation, in case it is of interest or useful:

Wednesday, October 01, 2014

Presentation: Canada's Anti-spam Law and non-profits/charities

I just had the pleasure of speaking at a joint meeting of the Canadian Bar Association (Nova Scotia)'s privacy and charities sections on the impact of Canada's Anti-Spam Law (CASL) on charities and not for profits.

Here's the presentation, in case it may be of interest:

Presentation: Canada's Anti-spam law and University Conference Services

I had the pleasure of giving a presentation at the annual conference of the Canadian University and College Conference Organizers Association about the impact of Canada's Anti-Spam law on how they carry on their operations. The good news is that universities and colleges are not as affected by this law as most organizations. The bad news is that the conference and accommodation services folks are perhaps the most affected at their institutions.

Here is my presentation, in case it is of interest:

Monday, June 23, 2014

The New Canadian Anti-SPAM Law and Your Business

This morning, I hosted an online webinar entitled The New Canadian Anti-SPAM Law and Your Business. We did it using Google's Hangout On Air feature that allows virtually unlimited numbers of people to attend live and it creates a handy YouTube video of the entire session for future reference.

You'll see from the presentation that I'm not a big fan of the law, but it's going to be the law on July 1, 2014 and businesses need to get their ducks in a row if they haven't already.

If you're looking for specific advice about compliance, feel free to contact me at david.fraser@mcinnescooper.com.


Monday, April 28, 2014

Presentation on Canada's new Anti-Spam law

For the lawyers who read this blog, this topic may be getting tired but I'm regularly confronted by business folks who have heard very little about Canada's new Anti-SPAM law (CASL). I was asked to give a presentation on the topic on behalf of Digital Nova Scotia as part of its Business 101 seminar series.

For anyone who may benefit, here is my presentation:

Friday, April 04, 2014

PIPEDA amendments coming next week to a Parliament near you

In a speech at the Digital Canada 150 Launch, Industry Minister James Moore hinted very strongly that amendments to Canada's private sector privacy law is just around the corner. From his speaking notes:

Digital Canada 150 Launch - Canada News Centre

Digital Canada 150 will protect Canadians online.

As we encourage even more individuals and businesses to get online, Canadians need to have confidence that their online transactions are secure, their privacy is protected and their families are safe from cyberbullying and other online threats.

So what's new?

  • Next week I will table new legislation in Parliament to strengthen our laws to better protect the online privacy of Canadians.
  • New cyberbullying legislation will protect our families from invasion of privacy, intimidation and personal abuse.
  • We will make sure the communications networks and devices that connect Canadians will be secure from threats, protecting the privacy of families, business and governments.
  • The anti-spam laws coming into force on July 1 this year will protect Canadians from malicious online attacks.

Watch this space ...

Wednesday, January 11, 2012

Geist: Are Canada’s digital laws unconstitutional?

Michael Geist's regular column in the Toronto Star is very interesting this week. It highlights that the recent decision of the Canadian Supreme Court regarding a single, national securities regulator throws into question the constitutionality of other federal laws that depend on the "general trade and commerce" power of the Canadian constitution, such as PIPEDA and the new anti-spam law. Geist predicts, rightly I think, that the Privacy Commissioner of Canada will likely face a constitutional challenge to her jurisdiction if she proceeds aggressively for order-making powers.

Check it out: Geist: Are Canada’s digital laws unconstitutional?.

Saturday, April 16, 2011

Political parties can spam you as much as they want

I was contacted this week by a reporter from the Toronto Star inquiring about the legality of Members of Parliament adding constituents' names to the databases of the parties with which they are affiliated. The answer is, either intentionally or unintentionally, politicians have exempted themselves from Canada's privacy laws and Canada's anti-spam law. While it flies in the face of fair information practices, MPs and political parties are free to spam you all they want.

Email to MP lands woman in campaign database - thestar.com

Brendan Kennedy

Staff Reporter

Mary Krohnert wrote her MP earlier this year to voice her concerns about changes to CRTC regulations. The act of civic engagement also appears to have signed her up to receive Conservative attack ads in her email.

The 36-year-old Oshawa resident says she had Tory campaign literature sent to her inbox this week, though she has never signed up for anything to do with the party.

When she called the Conservative party’s Ottawa headquarters to inquire, she says she was told her email address was added to a national campaign database after she wrote her MP — Conservative incumbent Colin Carrie — on a number of different issues in recent years.

“As far as I know I’ve never given consent for my email address to be shared,” said Krohnert, an actor who is studying to become an art therapist. “I was just communicating with my MP.”

Carrie refused to be interviewed for this story through his campaign manager, Judy Pati.

What apparently happened to Krohnert is perfectly legal because political parties are exempt from Canada’s privacy rules, said David Fraser, a privacy lawyer with Halifax-based McInnes Cooper.

“They can collect, use and disclose your personal information without your consent and they can use it for whatever purpose they want.”

Ryan Sparrow, a spokesman for the Conservatives, refused to comment on whether it was common practice for the party’s elected politicians to use constituents’ personal information when campaigning, saying he could not speak on behalf of MPs. He also three-times repeated a statement saying the party is “more than happy” to remove someone’s name “from any distribution list that we have” when requested.

Thursday, December 16, 2010

Canada's anti-spam act passes and receives royal assent

Bill C-28, Fighting Internet and Wireless Spam Act, also known as the anti-spam act, has passed through the sentate and received royal assent on December 15, 2010. It comes into force on the day or days set by the Governor in Council.

Check it out: LEGISINFO - The Library of Parliament's research tool for finding information on legislation.

Monday, September 27, 2010

Canada's Anti-Spam Act back on the order paper

Bill C-28, called the Fighting Internet and Wireless Spam Act (or, more formally: An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities, and to amend the Canadian Radio-television and Telecommunications Commission Act, the Competition Act, the Personal Information Protection and Electronic Documents Act and the Telecommunications Act) is back on the order paper in Parliament today. Here's the bill's status and a link to the full-text: LEGISINFO - The Library of Parliament's research tool for finding information on legislation.

Via @kaplanmyrth.

Wednesday, June 09, 2010

What's new in the anti-spam bill?

Since my redline of the PIPEDA amendments seemed to be of interest to readers of the blog, I thought readers may also be interested to see what has changed between the anti-Spam bill that fell off the order paper last parliamentary session (the Electronic Commerce Protection Act or ECPA) and the new Bill C-28, also known as the Fighting Internet and Wireless Spam Act or FISA.

Here is a redline comparing the old ECPA to the new FISA, via Google docs.