Showing posts with label Privacy Act (Canada). Show all posts
Showing posts with label Privacy Act (Canada). Show all posts

Friday, March 10, 2017

Privacy and the use of census information for population health research

Professor Teresa Scassa has a very interesting comment on her blog about a recent case from the Federal Court of Canada, O’Grady v. Canada (Attorney General), 2017 FC 167. Her comment is here: Recent Federal Court Decision Examines Privacy and the Census.

The case itself is a judicial review of a decision of the Chief of Statistics to enter into an agreement with McGill University’s Faculty of Medicine to conduct a study examining perinatal outcomes in Canada. This sort of research collaboration and data matching happens all the time, but seldom is it objected-to and the discussions do not often end up in front of the courts.

The context, from the decision:

[3] In 2011, Statistics Canada and McGill entered into a Letter of Agreement to conduct a study that would assess infant mortality and newborn health by examining perinatal outcomes in Canada according to risk factors related to socioeconomic position, ethno-cultural background, and environmental exposure [Study]. In connection with the Study, record linkages were used to link information from the national birth record database and the 1996 and 2006 censuses. In order to minimize the privacy intrusion, the record linkages were performed in accordance with s 6 of the Statistics Act, RSC 1985, c S-19 [Statistics Act] by Statistics Canada employees, or deemed employees, and the composite records were stripped of direct personal identifiers before they were made accessible to McGill. The composite records were also restricted to Statistics Canada’s premises. Additionally, the usage of the record linkages was publicly posted on the Statistics Canada website.

The applicant complained to the Privacy Commissioner of Canada, who concluded that the applicant's personal information had not been improperly used.

[7] The Privacy Commissioner agreed that the Applicant’s census information met the definition of personal information, as defined by s 3 of the Statistics Act. Additionally, the Privacy Commissioner found that usage of census information in the Study was beyond the scope of the purposes for which it was collected, which is prohibited under s 7 of the Statistics Act. However, there was no evidence to suggest that the Applicant’s information had actually been used in the Study as her information had been excluded. Furthermore, even if the Applicant’s information had been used, Statistics Canada had the authority to do so under the Statistics Act. Consequently, the Privacy Commissioner found that the Applicant’s complaint was not well-founded.

The Court, in reviewing the decision by the Chief of Statistics, found that it was lawful as the use of the census data in this manner is consistent with the purpose for which it was originally collected.

[68] There is no doubt that census information is personal information, so the issue in this case is whether it was used “for a use consistent” with the “purpose for which it was obtained or complied….”

[69] The Supreme Court of Canada set out the “consistent use” test in Bernard, above:

[31] A use need not be identical to the purpose for which information was obtained in order to fall under s. 8(2) (a) of the Privacy Act; it must only be consistent with that purpose. As the Federal Court of Appeal held, there need only be a sufficiently direct connection between the purpose and the proposed use, such that an employee would reasonably expect that the information could be used in the manner proposed.

(emphasis in original)


[70] It is clear that Statistics Canada could not have contemplated the Study at the time of either the 1996 census or the 2006 census. Hence, the information collected by those censuses was not obtained specifically for the Study. However, the purpose of the Study is to compile and analyse statistics related to the health and welfare of Canadians, so that it complies with the purpose of the censuses and with Statistics Canada’s mandate.


The application was dismissed, but the Court noted it was premature overall:

[86] The real problem with this application is that it is premature. The Study has not yet been released or used. The Applicant speculates that personal information will be used and disclosed, but has produced no convincing evidence to support that position. Whatever I have said in this application, which is based solely upon the record before me, should not prevent anyone whose personal information is inappropriately used or disclosed from bringing the matter before the Court in the future.

Thursday, December 10, 2015

Privacy Commissioner tables annual report on privacy in the federal government

The Privacy Commissioner of Canada has just tabled his Annual Report on the Privacy Act to Parliament for 2014-2015. The Privacy Act regulates how the federal government and its agencies can collect, use and disclose personal information. The full report is here: Annual Report to Parliament 2014-15 - Protecting personal information and public trust - Report on the Privacy Act.

The highlight of the Annual Report is an audit across government departments regarding the use of portable storage devices. Some might find it ironic, since the Office of the Privacy Commissioner recently lost a portable storage device containing personal information of its employees.

Here's the media release prepared by the Commissioner:

Federal government needs to do more to guard against breaches and privacy violations: Privacy Commissioner

2014-2015 Privacy Act Annual Report to Parliament highlights results of an audit of the government’s management of portable storage devices and reported data breaches

GATINEAU, QC, December 10, 2015 – The Privacy Commissioner of Canada is urging federal departments and agencies to develop and implement more rigorous procedures and safeguards to protect Canadians’ personal information.

This call comes as the Commissioner’s 2014-15 Annual Report on the Privacy Act was tabled today in Parliament, highlighting a record-high number of federal government data breaches reported to his Office and the results of an audit of the government’s management of portable storage devices.

“Many institutions have made some strides to better protect personal information,” says Commissioner Daniel Therrien. “That being said, the breach reports we’ve received, the results of our investigations and our latest audit all suggest there is still much room for improvement.”

Federal institutions reported 256 data breaches in 2014-2015, up from 228 breaches reported the year before—which itself was double the number reported a year earlier. As in previous years, the leading cause of breaches was accidental disclosure, a risk which can often be mitigated by more rigorous procedures.

Last year marked the first time institutions were required to report data breaches to the Privacy Commissioner. Until then, reporting was voluntary.

“Effectively protecting personal information is a challenge we do not want to minimize,” says Commissioner Therrien. “However, given that Canadians are required to provide very sensitive information to federal departments and agencies, the government’s duty of care is paramount.”

The annual report includes details of a recently completed audit which found that gaps in the federal government’s management of portable storage devices, such as memory sticks, are potentially putting the personal information of Canadians at risk.

The audit concluded that, while federal institutions do have policies, processes and controls related to portable storage devices, there is significant room for improvement in order to reduce the risk of privacy breaches.

Portable storage devices are convenient because they can hold huge amounts of data and are generally small and highly portable. But it is those attributes that also create significant privacy and security risks.

“These devices can be easily lost, misplaced or stolen. Without proper controls, federal institutions are running the risk that the personal information of Canadians will be lost or inappropriately accessed,” says Commissioner Therrien.

The audit was prompted by concerns over a number of federal government data breaches involving portable storage devices, including a 2012 incident in which a portable hard drive containing the personal information of almost 600,000 student loan recipients went missing.

The audit, which included a detailed examination of 17 institutions, identified a number of concerns, including:

  • More than two-thirds (70%) of the institutions had not formally assessed the risks surrounding the use of all types of portable storage devices.
  • More than 90% did not track all portable storage devices throughout their lifecycle.
  • More than 85% did not retain records verifying the secure destruction of data retained on surplus or defective portable storage devices.
  • One-quarter did not enforce the use of encrypted USB storage devices.
  • Two-thirds did not have technical controls in place to prevent the connection of unauthorized portable storage devices (for example, privately owned device) on their networks, and more than half (55%) had not assessed the risk to personal information resulting from the absence of such controls.

There were also weaknesses in the security settings to protect data held on smart phones at some of the audited entities. These included, for example, a lack of encryption, strong password controls, or controls to prevent users from installing unauthorized applications.

The audited institutions have accepted all recommendations made in the audit.

“We hope all federal institutions will take note of the audit and its recommendations with respect to portable storage devices,” says Commissioner Therrien. “The audit highlights some preventive steps that can and must be taken to curtail breaches. There is a need for greater vigilance when it comes to protecting the personal information that Canadians entrust to their federal government.”

About the Office of the Privacy Commissioner of Canada

The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman and guardian of privacy in Canada. The Commissioner enforces two laws for the protection of personal information: the Privacy Act, which applies to the federal public sector; and the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada’s federal private sector privacy law.

Tuesday, July 28, 2015

Privacy breach class action certified against Government of Canada for medical marijuana breach

In a decision issued on July 27, 2015 but not yet published (but available here as a PDF), the Federal Court of Canada has certified a class action against the Government of Canada for disclosing the personal health information of participants in the "Marihuana Medical Access Program" in a botched mailout that was intended to advise program participants about changes to the regulation, which ironically where said to protect privacy and safety.

In November 2013, Health Canada sent notices to over 40,000 participants of the Marihuana Medical Access Program (MMAP) to advise of changes to regulations governing the use of medical marijuana in Canada. The notices were delivered in oversized envelopes that had the words “Health Canada - Marihuana Medical Access Program” on the return address, revealing to anyone who saw the envelope that the recipient was licensed to possess or produce medical marihuana for medical purposes. Previously, Health Canada’s mailings to MMAP members were discreet and made no mention of marijuana on the envelopes. Despite the Government of Canada’s acknowledgement of the error and that it was outside their normal practice, its reaction has consistently been "no harm, no foul".

What's most notable about this decision -- which is consistent with the recent decision in Condon v. Canada -- is that the court certified the plaintiffs' claim under the novel tort of "public disclosure of private facts". This tort is recognized in the United States, but is untested in Canada. It is a part of the four different privacy torts recognized by the Ontario Court of Appeal in Jones v. Tsige.

In March 2015, the Privacy Commissioner of Canada found that Health Canada's breach was a violation of the Privacy Act. At the certification hearing, the Government of Canada argued that the Privacy Commissioner's finding should be enough to satisfy everyone harmed by the breach, but the Court noted that the Commissioner can't award any of the damages sought by the plaintiffs.

Full disclosure: My firm is one of the firms representing the plaintiffs.

From the firms' media release:

Federal Court certifies privacy class action by Medical Marijuana patients against Health Canada


FOR IMMEDIATE RELEASE - July 28, 2015

The Federal Court of Canada has certified a class action commenced on behalf of more than 40,000 medical marijuana licensees alleging that Health Canada violated their privacy.

In November 2013, Health Canada sent notices to over 40,000 participants of the Marihuana Medical Access Program (MMAP) to advise of changes to regulations governing the use of medical marijuana in Canada. The notices were delivered in oversized envelopes that had the words “Health Canada - Marihuana Medical Access Program” on the return address, revealing to anyone who saw the envelope that the recipient was licensed to possess or produce medical marihuana for medical purposes. Previously, Health Canada’s mailings to MMAP members were discreet and made no mention of marijuana on the envelopes. Despite the Government of Canada’s acknowledgement of the error, it insists that no one was harmed by the breach.

In March 2015, the Office of the Privacy Commissioner of Canada concluded that Health Canada violated federal privacy laws. However, in the recent certification decision, the Court found that the class action is necessary to provide access to justice because the Privacy Commissioner cannot order the Government of Canada to compensate class members harmed by the breach. The Government has 30 days to appeal the certification decision.

McInnes Cooper, Branch MacMaster LLP, Charney Lawyers, and Sutts Strosberg LLP are jointly representing the plaintiffs in the medical marijuana privacy breach class action filed in the Federal Court against the Government of Canada. The plaintiffs seek damages for breach of contract, breach of confidence, invasion of privacy and Charter violations.

“We are very glad to see this case moving forward. The certification decision means that the Court has agreed that this is an appropriate case for a class action and that allowing all of the class members to proceed in a group is in the interests of justice,” said Ward Branch of Branch MacMaster LLP. “The Government of Canada has fought us at every turn, but have also lost each motion to date. We are hopeful that they will now see the wisdom of sitting down to resolve the issues created by this error.”

“This is not over yet, but the thousands of affected program members should take some comfort that every legal claim we advanced on their behalf has been approved to go forward,” said David Fraser of McInnes Cooper.

“As citizens of this great country, we rely on our government to protect our sensitive personal information from being disclosed and to protect our privacy during all communications. This decision sends a clear message to the government that our Courts consider privacy to be of the utmost importance and expect our government to take its privacy obligations seriously or face the consequences,” said Ted Charney of Charney Lawyers.

“Over one thousand people have registered on our secure website to tell us how the breach affected them. We will continue to pursue justice for those harmed by the breach,” said David Robins of Sutts, Strosberg LLP.

While it is not necessary to “opt in” to participate in the class action, class members are urged to visit the www.marijuanaclassaction.com website to obtain updates and to register because the information collected on the secured site will assist class counsel in communicating with class members and moving the case forward. Those who have already registered do not need to re-register but should update their information if their circumstances change or to report further harm suffered from the breach.

- 30 -

About Branch MacMaster LLP

Branch MacMaster LLP is a boutique litigation law firm established in 1998 and located in Vancouver, British Columbia. The firm focuses on class actions, health, insurance, and personal injury. The firm provides responsive, flexible, and cost-effective service to their clientele.

About Charney Lawyers

Charney Lawyers is a Toronto, Ontario firm with an established reputation for excellence in advocacy. The firm is experienced in personal injury, class proceedings, commercial litigation, insurance defence, employment law, medical malpractice, food borne illness, construction law and appeals.

About McInnes Cooper

McInnes Cooper is among the top business and litigation law firms in Canada, with more than 200 lawyers in seven Canadian offices, serving clients across North America and abroad. The firm is a market leader in energy and natural resources, business, litigation, employment, tax, real estate and insurance law. McInnes Cooper is the exclusive member firm in Newfoundland, New Brunswick, Nova Scotia and Prince Edward Island for Lex Mundi – the world’s leading network of independent law firms with in-depth experience in 100+ countries worldwide.

About Sutts Strosberg LLP

Sutts, Strosberg LLP is a nationally recognized law firm committed to excellence in litigation, with offices in Windsor and Toronto. The firm has a special interest in class actions, having represented groups or classes of individuals in every province and territory, and in every level of court, and is experienced in complex civil and commercial disputes, corporate, commercial and financial transactions, medical malpractice cases, personal injury cases, family law and criminal law.

For more information or to request an interview, please contact:

Ashley LeCroy
Manager, Marketing & Communications
902.457.5667
media@mcinnescooper.com

For more background, check out these previous posts.

Tuesday, April 01, 2014

Charmaine Borg MP introduces private members bill to add breach notification to the federal Privacy Act

Charmaine Borg, the NDP's digital issues critic and the most activist MP in the area of privacy has tabled Bill C-580 to update the federal Privacy Act to require breach notification and a mandatory 5-year review of the Act. More info here: LEGISinfo - Private Member’s Bill C-580 (41-2).

In the wake of so many privacy breaches by federal government departments, I can get onboard with this.

Tuesday, March 25, 2014

Interim Privacy Commissioner of Canada releases report on HRSDC/Student Loan privacy breach

The Interim Privacy Commissioner of Canada has today tabled in Parliament the report of her investigation into the loss of a portable hard drive that contained personal information more than half a million student loan recipients by Human Resources and Skills Development Canada. (Previous posts can be found here.)

Here's her media release:

News Release: Investigation into hard drive loss highlights important lessons for all organizations to follow - March 25, 2014

Investigation into hard drive loss highlights important lessons for all organizations to follow

OTTAWA, March 25, 2014 - The disappearance of a portable hard drive containing the personal information of 583,000 student loan recipients underscores the need to ensure that formal privacy and security policies are more than simply words on paper, an investigation has found.

The investigation by the Office of the Privacy Commissioner of Canada was launched after the hard drive was reported lost by Employment and Social Development Canada (ESDC), formerly Human Resources and Skills Development Canada.

An investigation report tabled in Parliament today details how the hard drive was left unsecured for extended periods of time; not password protected; and held personal information that was unencrypted. As well, employees handling the device were not aware of the sensitivity of the information stored on the device.

The report concludes that a gap between policies and practices at ESDC led to weaknesses in information management controls, physical security controls, and most importantly, the level of employee awareness of departmental policies and procedures.

“This incident should serve as a lesson for all organizations,” says Interim Privacy Commissioner Chantal Bernier. “Protecting personal information cannot be ensured by having policies on paper. Policies must be put into practice each and every day and monitored regularly.”

“We are pleased that ESDC has accepted all of our recommendations and has started taking the necessary steps to implement them. We hope this investigation will prompt other federal departments and private-sector organizations to review their own privacy policies and practices.”

The Office launched the investigation in January 2013 after ESDC reported that a portable hard drive containing a substantial amount of personal information had been missing for two months.

Despite extensive search efforts, the Department was unable to locate it or determine whether human error or malicious intent was responsible.

Staff of ESDC’s Canada Student Loans Program had used the department-owned, 1 terabyte hard drive to make a backup copy of program information stored in the central computer to ensure its preservation when that data was being transferred between networked drives.

The hard drive contained the Social Insurance Number, name, date of birth, home address, telephone number, loan amounts and balances for 583,000 clients of the loans program. It also included gender, language and marital status for some.

Because of failures in departmental practices, ESDC could not conclusively identify what information was on the portable hard drive or when it had been last updated.

Nonetheless, ESDC says that no evidence has yet emerged that the personal information potentially stored on the hard drive has been accessed or used for fraudulent purposes.

The investigation found that ESDC employees had contravened sections of the Privacy Act — Canada’s federal public sector privacy law — related to the use, disposal and disclosure of personal information.

ESDC has accepted all 10 of the Commissioner’s recommendations and has already made significant steps in implementing some, including:

  • Severely restricting the use of portable storage devices and introducing system software which blocks the use of any such devices on desktop computers without specific authorization;
  • Periodically examining portable storage devices to ensure they are being used solely for the authorized reasons;
  • Reviewing all materiel holdings, disposing of transitory records and classifying remaining records at the appropriate security level; and
  • Instigating a new integrated learning strategy which focuses on the protection of personal privacy and includes mandatory participation for all employees and mandatory testing every two years.

The Office of the Privacy Commissioner of Canada will follow up in one year to confirm ESDC’s progress in implementing the recommendations.

“To effectively mitigate privacy risks, there must be a synergy between privacy and security controls. Implementation of such controls will help ESDC — and all organizations — to properly protect the personal information that Canadians entrust to them,” says Interim Commissioner Bernier. “To further address broader systemic issues, we are conducting an audit of the use of portable storage devices by selected federal organizations, and we have just released some new tips for organizations on this issue.”

About the Office of the Privacy Commissioner of Canada

The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman and guardian of privacy in Canada. The Commissioner enforces two federal laws for the protection of personal information: the Privacy Act, which applies to the federal public sector; and the Personal Information Protection and Electronic Documents Act (PIPEDA), which applies to organizations engaged in commercial activities in the Atlantic provinces, Ontario, Manitoba, Saskatchewan and the Territories. Quebec, Alberta and British Columbia each has its own law covering the private sector. Even in these provinces, PIPEDA continues to apply to the federally regulated private sector and to personal information in interprovincial and international transactions.

See also:

Tuesday, April 23, 2013

Statistics on Federal Government data breaches are staggering

According to documents filed in Parliament in response to a request for information filed by the opposition, the Federal Government has experienced thousands of data breaches over the past decade, affecting the personal information of hundreds of thousands of Canadians. And the vast majority were not reported to the affected individuals.

Government data breached thousands of times in last decade, documents say

OTTAWA — The federal government has seen more than 3,000 data and privacy breaches over the past 10 years, breaches that have affected more than 725,350 Canadians, according to documents tabled in Parliament on Tuesday.

The responses from departments, given to the New Democrats in response to an order paper question, also show that less than 13 per cent of all breaches have been reported, including a handful from the Department of Fisheries and Oceans that affected more than 4,400 individuals.

“There may be issues where Canadians have been put at risk and they haven’t been informed,” said NDP critic Charlie Angus, who submitted the written question. “As a standard, we should involve the privacy commissioner when Canadians’ privacy is breached.”

The list, however, is not a complete accounting of breaches, suggesting that there the number of breaches may be higher than reported. For instance, the Canada Revenue Agency didn’t provide any numbers, saying that a search of the hard copy records of breaches would be too cumbersome to be completed.

The list also turned up at least three instances where the data loss led to criminal activity, including one at the Public Service Commission in the 2007-2008 fiscal year that led to the termination of a contract with the recycling firm JC Fiber. Another data loss at the Department of Finance ended with one worker being charged with breach of trust.

The Department of Foreign Affairs, according to the documents, has 11 ongoing investigations into data breaches that affect at least 42 individuals.

The tabling of the figures prompted the government to release a statement signed by three cabinet ministers, including two whose departments have either come under scrutiny for losing the information of Canadians: Veterans Affairs Minister Steven Blaney, and Human Resources Minister Diane Finley.

“Our Government takes the privacy of Canadians very seriously, especially the critical importance of the proper handling of sensitive personal information,” Treasury Board President Tony Clement said in the statement.

“We will continue to work closely with the Office of the Privacy Commissioner to ensure that the privacy of Canadians is protected.”

Finley’s department has been dealing with fallout from two data breaches. In one incident, the department lost a portable hard drive with the personal information of about 583,000 Canada Student Loan recipients, including their social insurance numbers. In a second incident, a lawyer on loan to HRSDC from the Department of Justice lost a USB key with personal information about more than 5,000 employment insurance recipients.

Both have prompted investigations by the privacy commissioner, Jennifer Stoddardt, who was notified of both incidents.

“This came out of the massive data breach at HRSDC and the fact they spent a number of months keeping it quiet while they searched for it,” Angus said. “Now we see we’ve got well over 3,000 breaches.”

“What we’re seeing here is this about covering the rear-ends of ministers trying to keep their jobs,” Angus said.

Wednesday, April 10, 2013

Missing HRSDC hard drive also contained sensitive investigation reports

The Ottawa Citizen is reporting that the hard drive that went missing from HRSDC not only contained files on five hundred thousand student loan applicants, but also contained sensitive investigation reports and corporate business plans.

This story isn't getting any better: Missing hard drive included business plans, financial information and investigative reports on applicants, emails suggest.

Monday, February 25, 2013

Commissioner expands HRSDC breach investigation to Justice Canada

The Toronto Star is reporting that the Privacy Commissioner's investigation of the loss of a USB device containing the sensitive personal information, health information and financial information of 5000 people has expanded to include Justice Canada. From the Star:

Privacy watchdog expands probe over lost USB key to include justice department | Toronto Star

Marian Ngo, a spokeswoman for the human resources department, said the department notified legal services on Nov. 16 that a USB key containing the personal information of 5,045 Canadians who had applied for CPP disability benefits went missing from an employee’s desk.

Information found on the USB stick included social insurance numbers, surnames, occupations, birth dates, medical conditions, level of education, whether there are other payers, such as workers’ compensation, and which Service Canada processing centre was dealing with their applications.

The USB key was not encrypted or protected by a password. Ngo said the memory stick had been delivered by hand two days earlier to legal services for work on a project dealing with transitioning files to the Social Security Tribunal, which opens Apr. 1.

Officials from both HRSDC and Justice Canada searched for USB key extensively on Nov. 16, including at the home of the employee, but could not find it and it was considered lost Nov. 27.

Friday, February 15, 2013

HRSDC appears before Parliamentary Committee to account for massive data breaches

Representatives of Human Resources and Skills Development Canada appeared before the House of Commons Standing Committee on Human Resources, Skills and Social Development and the Status of Persons with Disabilities (HUMA) to account for HRSDC's data loss. The testimony will appear here, when the transcript is prepared: House of Commons Committees - HUMA (41-1) - Study Home - Ensuring the protection of personal information held by HRSDC. You can watch the testimony by clicking on the Webaast icon here.

Though the HUMA committee has oversight of HRSDC, they should also be dragged in front of the Standing Committee on Access to Information, Privacy and Ethics (ETHI), which has oversight of privacy more generally.

Here is the Toronto Star's coverage of the appearance: Ottawa sorry for losing data on 500,000 Canadians.

Despite the Silicon Valley boogeymen, the Canadian government is the greatest threat to your privacy

Jesse Brown at Macleans.ca has had a great series of four posts on his blog there, which highlight that despite all the attention being lavished on Facebook, Google, WhatsApp and other American internet companies, the most ignored threat to the privacy of Canadians is the Government.

Government information security practices are laughable, fear of the cloud means that public servants have to use insecure USB storage devices to move data, the regulatory regime is antiquated and not up to the task, and the Privacy Commissioner spends a disproportionate amount of time chasing Silicon Valley companies. It's a perfect storm that's not getting adequate attention.

The Privacy Act is completely not up to the task. If the Commissioner needs order-making powers and the ability to levy fines, that power should be directed to the government where her sensible advice is sorely needed and often ignored.

Privacy is generally about choice: you get to choose with whom you share your information, what they can do with it and with whom it can be disclosed. But personal information protection by governments is dramatically different from the private sector. If I don't like my bank's practices, I can go to another bank. If I don't like how Twitter or Facebook work, I can shut down my accounts or go somewhere else. Individuals do not have any choice about their governments. If you are disabled and want benefits you paid for, you have no choice but to go to HRSDC, which is -- by all appearances -- contemptuous of your privacy. In my view, governments have a much higher duty to protect your privacy because choice has been completely removed from the equation. It's time that government starts living by the same rules they impose on your bank and the Internet boogeymen.

Check Jesse's posts out:

Friday, January 25, 2013

HRSDC to provide credit protection for those affected by missing hard drive

HRSDC has decided to do the right thing -- which it should have done one day one: provide credit protection services to the more than half a million individuals affected by the HRSDC missing hard drive fiasco. The department's release only refers to this breach, which leaves me wondering why they are not providing the same protection to people whose information was compromised with the missing USB thumb drive full of equally sensitive information.

I expect this really takes the wind out of the sails of the many class actions against the government.

Canada News Centre - Department to provide credit protection for clients with information on missing hard drive

Ottawa, Ontario, January 25, 2013 — The Department of Human Resources and Skills Development (HRSDC) is responding to the concerns of Canadians and providing credit protection at no cost to Canada Student Loans Program (CSLP) clients whose personal information was contained in a missing hard drive.

In addition to the strong measures that the Minister recently directed the Department to implement, the Department has contracted with Equifax, a credit bureau, to provide the affected clients with credit and identity protection services for a period of up to six years.

“While there is no evidence that information has been fraudulently accessed or used, I want to reassure Canadians that we are serious about protecting their personal information,” said Minister Finley. “That is why we will provide potentially affected individuals with credit protection at no cost, which will flag their credit files and help detect any potential compromise of their personal information.”

While HRSDC has no evidence that any of the information has been accessed or used for fraudulent purposes, those clients who could potentially have been affected by this incident have the choice to request the credit protection services, and can contact the HRSDC call centre at 1-866-885-1866 within North America. For calls from outside of North America, affected citizens can call 1-416-572-1113 and dial 0 to speak to an operator in order to reverse the charges. Callers with a hearing or speech impairment and who use a teletypewriter (TTY) can call at 1-800-263-5883.

To protect privacy, the Department is asking that affected individuals call to provide their consent for their information to be shared with Equifax. The process will be simple and efficient.

A hard drive containing personal information on approximately 583,000 individuals who were Canada Student Loans clients from 2000-2006 has been deemed missing from an HRSDC office in Gatineau, Quebec, although the search is ongoing.

Credit protection services will be arranged once clients make contact with the HRSDC call centre.

HRSDC continues to take all efforts to reassure Canadians that rigorous new protocols are in place to protect their data.

With respect to the last sentence, shouldn't they be reassuring Canadians that they are taking all efforts to protect data rather than taking all efforts to reassure Canadians?

Tuesday, January 15, 2013

Massive BC privacy breach involves millions of health records

The Canadian Press, via the CBC, is reporting on a series of new data breaches from British Columbia that likely involved millions of health records. And, as with the HRSDC breaches, portable electronic USB storage devices are involved.

It appears that the province is not planning to notify everyone involved.

B.C. privacy breach shows millions affected - British Columbia - CBC News:

Ministry notifying more than 38,000 people about shared data

The personal-health data of millions of British Columbians has been accessed without proper authorization, and in the most serious cases, the provincial government says it will notify 38,486 individuals of the breaches by letter.
Health Minister Margaret MacDiarmid made the announcement as part of an ongoing investigation into research-grant practices between ministry employees and researchers at the universities of B.C. and Victoria.

MacDiarmid said that during three separate instances in October 2010 and June 2012, the health information was saved on USB sticks and shared with researchers or contractors without the proper permission or protocols.

McDiarmid said the data did not include names, addresses or financial information, but it wasn't supposed to be shared with other health researchers.

Also included was data from Statistics Canada's Canadian Community Health Survey, including information on the mental, physical and sexual health of individuals, as well as their lifestyles and the use of health services.

“We don't have any evidence at all that any of this information was used for any purpose other than health research. There is minimal if any risk that this information that would be used in a way that would be harmful to these individuals.”
MacDiarmid said her ministry decided to write the letters following discussions with the Office of the Information and Privacy Commissioner.

Elizabeth Denham, the information and privacy commissioner, also said Monday her independent investigation should be complete in the coming weeks, and she will then issue a public report with findings and recommendations.

Seven ministry workers have already been fired, sparking two separate lawsuits.

Monday, January 14, 2013

Note to HRSDC: Cloud computing and remote access dramatically reduces the risk of portable device data breaches

I posted this, this morning, on the Canadian Cloud Law Blog but it should be equally of interest to readers of this blog:
Canadian Cloud Law Blog: Note to HRSDC: Cloud computing and remote access dramatically reduces the risk of portable device data breachesNote to HRSDC: Cloud computing and remote access dramatically reduces the risk of portable device data breaches

The Canadian news has been full of reports related to two significant privacy breaches emanating from the federal ministry of Human Resources and Skills Development Canada. The first to be reported was the loss of a USB thumb drive containing the personal information (including personal health information) of more than 5,000 disabled Canadians who were receiving benefits under programs administered by HRSDC. In the course of investigating that first breach, a second came to light. Apparently someone at HRSDC thought it would be wise to backup the data of over half a million student loan recipients onto a portable USB hard-drive, which could be easily lost or misplaced. Guess what happened ... it was lost or misplaced.

Problems with storing sensitive personal information on USB storage devices are not unknown. The Information and Privacy Commissioner of Ontario, Ann Cavoukian, has recently been on a tear over a USB-related breach by Elections Ontario resulting from poorly understood policies, bad training and a lack of accountability. In fact, she's published reams of reports on the breach, its root causes and what should be done to prevent it from happening again. (The TL;DR version: Employees were engaged in a project where they had to clean up electoral lists at an off-site location. They decided to transfer the data using USB thumb drives and didn't even do that well.)

The HRSDC Minister's media release says that, as a response to the second breach, employees will be given training on a new information security policy. That suggests to me that the reckless practice of placing unencrypted personal information on portable storage devices was A-OK. Well, it's not. Never has been and never will be.

The full facts of the HRSDC breaches are still very sparse, but we know that the second breach was caused by an employee or employees who wanted to make a backup of data (probably a good idea) and put the backup on a small portable device (a very bad idea). It may be that the first breach was caused by an employee who either needed to work offsite with the data or needed to move it from one computer to another. Both are reasonable things to want to do. And in some computing environments, can only be accomplished by making a copy of the data and USB devices are a handy way of accomplishing that.

A large part of my practice is advising clients on cloud computing. And I also often get invited to speak to groups of IT professionals and fellow lawyers on legal issues related to cloud computing. For the past few years, the majority of questions about the risk of cloud computing have focused on the fact that the data may be outside of Canada and that the customer is trusting someone else to secure the data. Those are both important questions to ponder, but few turn their minds to the fact that, in most cases, cloud computing is much safer for the data and significantly lowers the risk to data.

If Elections Ontario or HRSDC were using a cloud computing model, none of these breaches would have happened in any of the scenarios outlined above. Cloud computing keeps the data on a server or series of servers in highly secured data centres. There's no need to copy or move the data to get access to it remotely. This is accomplished through secured connections between an authorized computer or browser and the data centre. If you want it backed up, that's usually done on tapes in the data center and the data seldom has to leave the secured premises. In any data centre worth its salt, disk inventory is carefully controlled and audit tools are used to keep track of who has accessed what data. If tapes are moved offsite for redundancy's sake, there is usually a much higher level of diligence exercised as it follows documented processes.

When questions are being asked about how this happened and what can be done to prevent such breaches from happening again, the government should carefully consider how cloud computing or other remote access models dramatically reduce the risk of such breaches.

Friday, January 11, 2013

Government release on the loss of personal information of 583,000 Canadian student loan recipients

Here is the (ironically titled) media release regarding the loss of personal information of more half a million Canadians' personal information. Note that the government has been aware of this breach for over a month and chose to issue the release on a Friday afternoon. Also note that the "new policy" described suggests that storing this information on an unencrypted portable hard-drive was acceptable under the previous policy.

Protecting Canadians' Personal Information at HRSDC

January 11, 2013 13:02 ET

Protecting Canadians' Personal Information at HRSDC

OTTAWA, ONTARIO--(Marketwire - Jan. 11, 2013) - The Honourable Diane Finley, Minister of Human Resources and Skills Development, has issued the following statement regarding the loss of an external hard drive from an HRSDC office in Gatineau, Quebec which contained personal information of 583,000 Canada Student Loans Program borrowers between 2000-2006:

Full details are available in the attached backgrounder.

"I want all Canadians to know that I have expressed my disappointment to departmental officials at this unacceptable and avoidable incident in handling Canadians' personal information. As a result, I have directed that departmental officials take a number of immediate actions to ensure that such an unnecessary situation does not happen again.

"The department will be making every effort to contact the individuals whose information was lost. This includes direct notification to those for whom we have current contact information. I am releasing all details on the breach publicly and we will be working with a number of external partners to ensure that Canadians are made aware of the data loss. The Department is continuing its investigation. The Office of the Privacy Commissioner has been consulted. My office has engaged the Royal Canadian Mounted Police on this matter, given its serious nature.

"I have requested that HRSDC employees across Canada receive comprehensive communications on the seriousness of these recent incidents and that they participate in mandatory training on a new security policy to ensure that similar situations do not occur again. Further, I have instructed that the new policy contain disciplinary measures that will be implemented for staff, up to and including termination, should the strict codes of privacy and security not be followed.

"On behalf of our Government, I want to reassure Canadians that we are serious about protecting their personal information. As Minister, I will ensure that every effort is taken so that HRSDC meets the expectations of Canadians in keeping their information safe and secure."

This news release is available in alternative formats on request.

BACKGROUNDER

In late 2012, the department of Human Resources and Skills Development Canada (HRSDC) informed the Office of the Privacy Commissioner of the loss of a USB key, which contained the personal information of over 5,000 Canadians.

While reviewing this incident, departmental officials learned of a subsequent serious loss of Canadians' personal information.

Although the search is ongoing, an external hard drive has been deemed lost from an HRSDC office in Gatineau, Quebec.

The Department is continuing its investigation. The Office of the Privacy Commissioner has been consulted. The office of the Minister has engaged the Royal Canadian Mounted Police on this matter, given its serious nature.

Details regarding loss of the hard drive

A hard drive containing personal information on 583,000 Canada Student Loans borrowers dated from 2000-2006 has been deemed lost at an HSRDC office in Gatineau, Quebec, although the search is ongoing.

The file contained information including student names, dates of birth, Social Insurance Numbers, addresses and student loan balances from recipients across the country (except Quebec, Nunavut and the Northwest Territories as they manage their own student loan programs). Personal contact information of 250 HRSDC employees was also on the hard drive.

No banking or medical information was included on the drive.

The client information was saved onto an external hard drive as a back-up storage option.

Timeline of events

November 5, 2012: A HRSDC employee discovered that an external hard drive was missing. Search efforts began.

November 28: The Departmental Security Officer was notified.

December 6: Discovery that personal information of Canada Student Loans Program clients was on the hard drive.

December 14: The Office of the Privacy Commissioner was notified.

January 7: The incident was referred to the Royal Canadian Mounted Police.

January 11: Canadian public was informed of the incident.

Process for inquiries and more information

HRSDC is sending letters to individuals affected, for whom we have current contact information, to advise them of the incident and what steps to take to help protect their personal information.

A toll-free number has been set-up at 1-866-885-1866 (or 416-572-1113 for those outside of North America) for individuals to verify if they are affected by this incident, and to ask additional questions regarding this issue. Hours of operation will be 8:00 a.m.-8:00 p.m. (EST), 7 days a week, starting Monday, January 14, 2013, for as long as needed.

People with a hearing or speech impairment and using a teletypewriter (TTY) can call 1-800-263-5883. Hours of operation will be 8:00 a.m. -8:00 p.m. (EST), 7 days a week, starting Monday, January 14, 2013, for as long as needed.

All details on this incident and how Canadians can protect their personal information are available at http://www.canlearn.ca/eng/main/spotlighton/privacy/index.shtml

New HRSDC policy for storing secure information

The Minister has directed that the overall policy for security and storage of personal information at HRSDC be strengthened and improved. The highlights are:

  • New, stricter protocols to be implemented immediately. Portable hard drives are no longer permitted. Unapproved USB keys are not to be connected to the network;
  • Immediate risk assessments of all portable security devices used in the Department's work environment to ensure that appropriate safeguards are in place; these assessments will continue on a regular, ongoing basis;
  • Mandatory training for all employees regarding the proper handling of sensitive information, including personal information;
  • Implement new data loss prevention technology, which can be configured to control or prevent the transfer of sensitive information;
  • Disciplinary measures that will be implemented for staff, up to and including termination, should the strict codes of privacy and security not be followed.

HRSDC "loses" sensitive personal information of another half MILLION Canadians

The CBC is reporting tonight that Human Resources and Skills Development Canada has lost a hard drive containing very sensitive personal information on more than five hundred thousand Canadians. This time, it was a portable hard drive and the information is about 583,000 student loan recipients.


Federal agency loses data on 583,000 Canadians - Nova Scotia - CBC News:
A portable hard drive containing personal information about more than half a million people who got student loans has gone missing, the federal government revealed Friday.

Human Resources and Skills Development Canada says the device disappeared from an HRSDC office in Gatineau, Que., in early November.

The hard drive had personal information on 583,000 Canadians who were clients of the Canada Student Loans program from 2000 to 2006. Borrowers from Quebec, Nunavut and the Northwest Territories are not affected.

The information on the missing hard drive includes:

  • Student names, social insurance numbers, dates of birth, contact information and loan balance of Canada Student Loan borrowers. 
  • Personal contact information for 250 HRSDC employees. 
The government says no banking or medical information was on the hard drive.

Letters are going out to everyone affected to tell them what steps to take to protect themselves.  

No evidence of fraud

So far, there's no sign that any of the missing data has been accessed or used for fraudulent purposes, but the government has called in the RCMP and alerted the office of the privacy commissioner.

"I want all Canadians to know that I have expressed my disappointment to departmental officials at this unacceptable and avoidable incident in handling Canadians’ personal information," said Human Resources and Skills Development Minister Diane Finley in a statement.

"I have requested that HRSDC employees across Canada receive comprehensive communications on the seriousness of these recent incidents and that they participate in mandatory training on a new security policy to ensure that similar situations do not occur again."
She says employees who fail to adhere to the new policy could be fired.

This is the second incident involving missing personal information that her department has faced in less than a month.

In late December, HRSDC revealed that a USB key containing personal information on about 5,000 Canadians disappeared in November.

Update: Check out the Government of Canada media release on this breach.

Friday, January 04, 2013

Privacy Commissioner confirms investigation into HRSDC privacy breach

The Canadian Press is reporting that the Office of the Privacy Commissioner will be investigating the huge privacy breach within Human Resources and Skills Development Canada that resulted in the loss of personal information of about 5,000 Canadians.

Very few details have emerged about this breach other than the fact that a USB device was lost that contained names, social insurance numbers, and disability/health information about the affected individuals. Surely HRSDC must know some important details, such as what HRSDC program was the information connected to, was the USB device used to move the data between HRSDC sites or for an employee to take work home? This is the sort of basic information that the victims need to know in order to gauge whether they're at risk of fraud or identity theft.

Hopefully, the investigation will be swift since there are 5,000 people waiting to find out.

From the Canadian Press:

Privacy czar to probe department's loss of USB key containing personal info

OTTAWA - The privacy watchdog will investigate a federal data breach in which the personal information of thousands of Canadians went astray.

The office of privacy commissioner Jennifer Stoddart says it received formal complaints after a Human Resources and Skills Development Canada employee lost a USB key containing the personal information — including social insurance numbers — of about 5,000 Canadians.

Anne-Marie Hayden, a spokeswoman for Stoddart, says the privacy commissioner has also taken close to 200 calls from people expressing concern about the breach.

Human Resources says an extensive search for the key continues.

The department has no evidence that information on the missing key has been used for fraudulent purposes.

A spokeswoman for Human Resources Minister Diane Finley calls the loss of the key a serious and completely unacceptable incident.

Monday, December 31, 2012

Privacy commissioner to investigate HRSDC privacy breach

According to a report in the London Free Press, the Office of the Privacy Commissioner of Canada appears to be planning to investigate the appalling privacy breach that was announced last week. The language is not as definitive as I would like, however:

Privacy commissioner to investigate security lapse | Canada | News | The London Free Press

LONDON, Ont. - The federal privacy commissioner is poised to launch a full investigation into a security lapse that lost the private information of about 5,000 Canadians.

“I think you can expect that we will be investigating the matter,” Anne-Marie Hayden, spokesperson for the Privacy Commissioner of Canada, said Monday.

The commissioner’s office has already received 100 calls and several official complaints about the loss of a USB stick that contained private medical, employment and education information, as well as Social Insurance numbers.

It would be gravely disappointing if the OPC does not do a full investigation of this breach along with strong recommendations to prevent it from happening again.

Government needs to be held to an even higher standard than the private sector. People do not have a consensual relationship with government. If you do not like how your bank handles your personal information, you can easily switch to another one. If you're not happy with Instagram's new privacy policy, you can close your account. You cannot do that with government. If Human Resources and Skills Development Canada is incompetent in safeguarding sensitive personal information and cavalier in its response, you can't go looking for another Canada Pension Plan provider.

If this breach involved one of the big California-based internet giants, you can bet there would be a full investigation and further calls for order-making powers and the ability to levy fines.

I hope to see a full and public investigation, followed by calls to amend the Privacy Act to bring it into line with more modern provincial statutes that make it an offense to willfully violate the privacy of Canadians.

Saturday, December 29, 2012

Government "loses" sensitive personal information on thousands of Canadians

Over the past week, Human Resources and Skills Development Canada has been notifying approximately 5000 people that their personal information has been lost. According to reports, the information was on a USB device that has been "misplaced". The information includes Social Insurance Number(SIN); surname; primary and, if applicable, secondary medical condition; birthdate; presence of other payers (e.g., workers' compensation); level of education; occupation type; and, Service Canada processing centre.

This is an ENORMOUS screw up by the Government of Canada. Unencrypted personal information should never be put on these devices as they are notoriously easy to lose. I am also surprised that the Privacy Commissioner's office, at least as quoted in the media, has not yet decided whether to do a formal investigation.
Personal info for thousands lost by federal government - Politics - CBC News

A federal government department says there is no evidence that missing personal information about thousands of Canadians has been used for fraudulent purposes.Human Resources and Skills Development Canada says an employee reported on Nov. 16 that a USB key containing personal information, including Social Insurance Numbers, of about 5,000 Canadians was missing.

The department, which handles a variety of files including pensions, old age security, employment insurance and childcare tax credits, says all those affected have been contacted.

A spokesperson said in an email Friday evening that the affected people have been advised of the incident and informed of the steps they can take to help protect their personal information.

HRSDC notified the privacy commissioner's office on Dec. 21 that the data had been lost.

About 60 people have already called an information line at the privacy commissioner's office expressing concern about the incident and complaints have already been filed.
"It's too early to say whether or not these will turn into official, full, investigations," said Anne-Marie Hayden, a spokeswoman for the privacy commissioner.
"We'd have to look at what we receive first and determine next steps from there."
HRSDC said it has seen no evidence that any of the information contained on the missing USB key has been used for fraudulent purposes.

"Nonetheless, we have advised affected individuals to carefully review and verify bank information, credit card information and other financial transaction statements as a means of safeguarding their personal information as a precautionary measure," the email said.

"We are currently analyzing this incident with the view of preventing a similar occurrence in the future," it added.

The commissioner's office is working with HRSDC in an effort to figure out what happened.

Each year, federal departments are required to report on how well they comply with privacy legislation.

In the 2010-2011 report — the most recent one posted on HRSDC's website — the department noted that it had been the subject of three complaints regarding how it handled personal information.