Showing posts with label biometrics. Show all posts
Showing posts with label biometrics. Show all posts

Monday, September 08, 2025

Ontario privacy finding: Hidden biometrics in on-campus vending machines


On August 27, 2025, the Information and Privacy Commissioner of Ontario released a revised finding against the University of Waterloo. The initial report was issued in June this year and I should have done an episode on it then. The case involved what looked like a pretty ordinary thing on campus — vending machines. Except these weren’t just any vending machines. They were “intelligent vending machines,” installed by a third-party service provider, and they secretly used biometric face detection technology.


That sounds creepy and the University was found to have violated Ontario’s public sector privacy law. It’s not as cut and dried, but there are some interesting takeaways from that decision. 


Nobody on campus was aware that these vending machines use face detection technology until one of the machines malfunctioned and flashed an error message on its screen — basically outing itself as running “FacialRecognition.App.exe.” Understandably, students complained. It got a lot of media coverage and some buzz on Reddit.


Photo of a display showing an error message



The Information and Privacy Commissioner of Ontario investigated.


At the outset, the University of Waterloo challenged whether the Commissioner even had jurisdiction here. The University argued that this wasn’t really about Ontario’s Freedom of Information and Protection of Privacy Act — instead, they said it was governed by the federal Personal Information Protection and Electronic Documents Act or PIPEDA. Their reasoning? Selling snacks through vending machines is a commercial activity. And PIPEDA applies to the collection, use and disclosure of personal information in the course of commercial activity. And that meant the federal law applied, not the provincial law.


They also argued that if the vending machines didn’t actually capture personal information — as the manufacturer claimed — then there was nothing for the Commissioner to investigate. And finally, Waterloo tried to limit its responsibility by pointing out that it never contracted for biometric collection in the first place. In their view, if the vendor went off and deployed face detection technology, that wasn’t for them, they didn’t ask for it and they should not be on the hook for it.


The Commissioner rejected all of those jurisdictional arguments. The decision emphasized that under FIPPA, Ontario institutions like universities are responsible for personal information collected by vendors operating on their behalf — even when those vendors are engaged in activities with a commercial character. The Commissioner leaned on the “double aspect” doctrine in our constitutional jurisprudence: both federal and provincial laws can apply at the same time. In other words, even if PIPEDA could cover some of the activity, that doesn’t oust FIPPA.


So the bottom line on the jurisdiction question was that the University of Waterloo couldn’t escape the Commissioner’s oversight just by pointing to federal law or saying “we didn’t know.” Once personal information was being collected on its campus by machines it authorized, the University was on the hook under FIPPA


On the merits, the Commissioner concluded that the machines were capturing facial images, even if only for milliseconds. Not surprisingly, these facial images qualify as “personal information” under Ontario’s Freedom of Information and Protection of Privacy Act (FIPPA).


The collection wasn’t authorized by law, wasn’t necessary for selling chips and chocolate bars, and no notice was given.


Therefore, in the IPC’s view, Waterloo had violated FIPPA.


In order to find Waterloo at fault, or in violation of FIPPA, the IPC asks and answers three questions:


The IPC asked: “Did Waterloo “collect” personal information?” The Commissioner said yes. Even though the vendor claimed the system only processed images in real time, the machines captured full facial images in memory to estimate age and gender. That’s enough to count as a collection of personal information.


But really? Was it really Waterloo who “collected” personal information? Legally, yes. They had a vendor who was supplying goods and services on their behalf and the University is responsible for that. 


Then the IPC asked: “Was the collection compliant with FIPPA?” No. Section 38(2) of FIPPA says you can only collect personal information if it’s expressly authorized, needed for law enforcement, or necessary to carry out a lawful activity. Selling snacks doesn’t need biometric data. It might be “helpful” for marketing — but helpful isn’t the same as “necessary.” And also, no notice was given that personal information was being collected and why.


Finally, the IPC asked: “Did Waterloo have reasonable measures to protect personal information?” The Commissioner said they had decent contract clauses, but they fell down in procurement. They didn’t do the privacy risk assessment that could have flagged the biometric capability. That failure meant they didn’t exercise enough due diligence, and so they’re responsible.


Here’s where I think the finding is problematic. Waterloo had no knowledge of the biometric functionality. They weren’t using it, they didn’t ask for it, and their contract didn’t mention it. The vendor who responded to the RFP for vending machines apparently wasn’t aware of this functionality in some of the machines they provided. That other supplier embedded this capability, and at the time nobody was aware of it.


Due diligence usually asks the question with reference to what a reasonably prudent person would have done in the same circumstances. Without the benefit of hindsight, I think the University met that standard. But they could have done better, so the University is still on the hook for a privacy violation. It seems to be holding them to a higher standard, based on what we know now. 


It could have been enough to just give them a gentle slap upside the head, saying it’s 2025 and we need to assume that anything that uses electricity – and particularly if it’s a “connected device” – has the potential to collect personal information. You need to check. Even vending machines. 


Think about what this means in practice:


Does every university, hospital, or government office now need to disassemble or reverse-engineer every piece of technology it procures? Almost. 


Do they need to anticipate hidden biometric features in a vending machine?


Or test for surveillance capabilities in every piece of software?


That’s a pretty heavy burden — one that goes far beyond what most organizations reasonably do. I guess the standard for reasonable diligence has to be raised.


Yes, we want institutions to take privacy seriously. Yes, procurement processes should involve risk assessments. But here, it feels like the University is being faulted for not uncovering something that was essentially hidden. I’m not sure we can fault them for not asking at the time whether a vending machine used biometrics. We know now, but I don’t think they should be expected to have known to ask back then. 


While the vendor was not in the cross-hairs of the IPC’s investigation, vendors need to be mindful. If you build a product with biometric capabilities, you should have to disclose it — clearly and up front. If it’s an “internet of things” connected thing, it should be clearly identified as such. There probably is a boilerplate term in contracts that put the vendor on the hook if they cause the customer to violate any applicable law.  


In the end, a finding of having violated FIPPA isn’t like a criminal charge. The IPC issued two recommendations, which the university agreed to implement. First was to review their policies to make sure that future collection of personal information complies with FIPPA. Second was to implement practices to carry out necessary due diligence to identify, assess and mitigate any potential risks to personal information throughout the entire procurement process, including during the planning, tendering, vendor selection, agreement management and termination phases.


There’s a lesson here for everyone: I guess it’s time to update all your procurement and vendor documentation to ask about any connected or biometric features. Ask detailed questions about every bit of gear being installed and fully understand their capabilities. And I’d include reps and warranties in my contacts allowing for the termination of agreements if there has been any misrepresentation about the possible collection of personal information. 


One thing also to note is I think this would have gone differently for the university if the vendor wasn’t the university’s service provider. As I mentioned before, the university is on the hook for all personal information collected by their service providers, whether they wanted the information collected in the first place. But if the university had structured the arrangement differently, they likely would have avoided that direct responsibility. For example, if the agreement was more like the bare rental of space for the placement of vending machines on campus, the element of custody or control of the data likely would not have been there. Imagine the university enters into a lease with Starbucks to put a coffee shop in the library atrium. In such a scenario, you wouldn’t really see the University as being responsible for Starbucks’ collection of personal information as part of the Starbucks Rewards loyalty program.  Or maybe the privacy commissioner would take a different view? I kind of hope not.


In any event, there are more than a few lessons to learn from this finding. 


Monday, May 08, 2023

British Columbia Privacy Commissioner shuts down facial recognition



Recently, the information and privacy commissioner of British Columbia issued a decision that essentially shuts down most use of facial recognition technology in the retail context.

What’s interesting is that the Commissioner undertook this investigation on his own accord. In order to see how prevalent the use of facial recognition was among the province’s retailers, the OIPC surveyed 13 of the province’s largest retailers (including grocery, clothing, electronics, home goods, and hardware stores): 12 responded that they did not use FRT. The remaining retailer, Canadian Tire Corporation, requested that the OIPC contact their 55 independently owned Associate Dealer stores in the province. In the result, 12 stores reported using FRT. Based on these 12 responses, the Commissioner commenced an investigation under s. 36(1)(a) of the Personal Information Protection Act of four of the locations, scattered across the province. 

What’s also interesting is that the stores immediately ceased use of the technology, but the Commissioner determined that doing a full investigation was warranted, so that retailers would be aware of the privacy issues with the use of facial recognition in this context. 

The investigated stores used two different vendors’ systems, but they essentially operated the same way: The systems functioned took pictures or videos of anyone who entered the stores, as they came within range of the FRT cameras. This included customers, staff, delivery personnel, contractors, and minors who might have entered the store. Using software, the facial coordinates from these images or videos were mapped to create a unique biometric template for each face. So everyone was analyzed this way.

The systems then compared the biometrics of new visitors with those stored in a database of previously identified "Persons of Interest," who were allegedly involved in incidents such as theft, vandalism, harassment, or assault. When a new visitor's biometrics matched an existing record in the database, the FRT system sent an automatic alert to store management and security personnel via email or a mobile device application. The alerts contained the newly captured image or video that triggered the match, along with a copy of the previously collected image from the Persons of Interest database and any relevant comments or details about the prior incidents. According to store managers, these alerts were “advisory” until the match was confirmed in person by management or security personnel.

Store management reported that after a positive match was verified, the nature of the prior incident allegedly involving the individual helped determine a course of action. If a prior incident included violence, management or security staff would escort the individual from the store. If the prior incident involved theft, management may have chosen to surveil or remove the person in question

The legal questions posed by the Commissioner were (1) whether consent was required under PIPA for the collection and use of images for this purpose, (2) whether the stores provided notification and obtained the necessary consent (through signage or otherwise) and – most importantly – (3) whether this collection and use is for an “appropriate purpose” under s. 11 and 14 of PIPA.

The first question was easy to answer: Yes, consent is required in this context. PIPA, like PIPEDA, requires organizations to obtain consent, either explicitly or implicitly, before collecting, using, or disclosing personal information unless a specific exception applies. No such exceptions applied in this case. Therefore, the Commissioner concluded it was incumbent on the stores to show that individuals gave consent for the collection of their personal information. 

How would you get that consent? Well the stores had signage at the entrances. Clear signage is usually sufficient for the use of surveillance cameras, but the question would be whether these would be sufficient for this use.

Store number 1 had a sign that stated, in part: “these premises are monitored by video surveillance that may include the use of electronic and/or biometric surveillance technologies.”

The Commissioner said this was inadequate. The notice did not state the purposes for the collection of personal information. Also, stating that biometric surveillance “may” be in use did not reflect that the store continuously employed the technology. The Commissioner said the average person cannot reasonably be expected to understand how their information may be handled by “biometric surveillance technologies,” let alone the implications and risks of this new technology. Consent requires that an individual understands what they are agreeing to – and the posted notification failed to adequately alert the public in this case, according to the Commissioner. This store failed to meet notification requirements under PIPA.

The second store had a notice that stated, in part: “facial recognition technology is being used on these premises to protect our customers and our business.” 

This one was also not satisfactory to the Commissioner. The purpose, as set out, is so  broad that the statement would relay no specific meaning to the average person. Furthermore, the notice does not explain what facial recognition technology entails or the nature of the personal information collected. One cannot reasonably assume that members of the public understand what FRT is, nor its privacy implications, according to the Commissioner.

Stores 3 and 4 had better notices, but they still didn’t satisfy the Commissioner. Their notices stated: “video surveillance cameras and FRT (also known as biometrics) are used on these premises for the protection of our customers and staff. These technologies are also used to support asset protection, loss prevention and to prevent persons of interest from conducting further crime. The images are for internal use only, except as required by law or as part of a legal investigation.” 

It has more detail, but was not that well written. It does not say what “FRT” is. The commissioner noted that the abbreviation is not yet well-known or widely understood. Using the full phrase “facial recognition technology” along with a basic explanation of its workings would have provided a more accurate description of the stores’ data-collection activities. Even so, the Commissioner said that North American society is not yet at the point where it is reasonable to assume that the majority of the population understands what personal information FRT collects, or creates, as well as the technology’s privacy implications. All of this would have to be spelled out. 

While you may be able to rely on implied consent for the use of plain old fashioned surveillance cameras, the Commissioner concluded that you cannot for facial recognition technology, at least in this context. 

The Commissioner said facial biometrics are a highly sensitive, unique, and unchangeable form of personal information. Collecting, using, and sharing this information goes beyond what people would reasonably expect when entering a retail store, and using FRT creates a significant and lasting risk of harm. The Commissioner said the distinctiveness and permanence of this biometric data can make it an attractive target for misuse, potentially becoming a tool to compromise an individual's identity. In the wrong hands, the Commissioner wrote, this information can lead to identity theft, financial loss, and other severe consequences. (I am not entirely sure how…)

As a result, the four stores were required to obtain explicit consent from customers before collecting their facial biometrics. However, they did not make any attempts, either verbally or in writing, to obtain such consent.

So the notices were not adequate and the stores didn’t get the right kind of consent. But the last nail in the coffin for this use of biometrics was the Commissioner’s conclusion about whether the use of facial recognition technology for these purposes is reasonable. 

Reasonableness is determined by looking at the amount of personal information collected, the Sensitivity of the information, the likelihood of being effective and whether less intrusive alternatives had been attempted.

With respect to the Amount of personal information collected, it was vast. The commissioner said a large quantity of personal information was collected from various sources, including customers, staff, contractors, and other visitors. The stores reported that their establishments were visited by hundreds of individuals of all ages, including minors, every day so during a single month, the FRT systems captured images of thousands of people who were simply shopping and not engaging in any harmful activities. The sheer volume of information collected suggests that the collection was unreasonable.

You won’t be surprised that the Commissioner concluded that the personal information at issue was super-duper sensitive. 

With respect to the likelihood of being effective, they didn’t really have in place any system to measure it. The commissioner concluded it really wasn’t that effective. 

The Commissioner wrote that before implementing new technology that collects personal information, organizations should establish a reliable method to measure the technology's effectiveness. This typically involves comparing relevant metrics before and after the technology's implementation. 

However, in this case, the stores did not provide any systematic evidence of measuring their FRT system's effectiveness. Instead, they only gave anecdotal evidence of incidents before and after installation. Without a clear way to measure the technology's effectiveness, it is challenging to analyze this factor, particularly when collecting highly sensitive personal information.

The accuracy of FRT technology is also a related issue. Systems such as these have been reported widely to falsely match facial biometrics of people of colour and women. 

The store managers acknowledged that the alerts could be inaccurate and relied on staff to compare database images to a visual observation of the individual. This manual check by staff suggests that the FRT system may not be effective. False identification can have harmful consequences when innocent shoppers are followed or confronted based on an inaccurate match.

Besides the system's accuracy, its effectiveness can also be judged against the existing methods used by the stores to identify potential suspects. The store managers stated that their security guards and managers typically knew the "bad actors" and could recognize them without FRT alerts. The persons of interest were often professional thieves who repeatedly returned to the store.

Moreover, there is little evidence that FRT enhanced customer and employee safety. Whether a person of interest was identified by FRT or by the visual recognition of an employee, the stores' next steps were the same. These involved deciding whether to observe the suspected person or interact with them directly, including escorting them from the premises. In either case, store managers rarely reported contacting the police for assistance.

As for whether less intrusive alternatives had been attempted, the less intrusive measures were what they were doing before. The Commissioner concluded that the use of FRT didn’t add a lot to solving the stores problems, but collected a completely disproportionate amount of sensitive personal information. The less intrusive means – without biometrics – largely did the trick. 

In the end, the Commissioner made three main recommendations. 

The first was that the stores should build and maintain robust privacy management programs that guide internal practices and contracted services. – presumably so they wouldn’t implement practices such as these that are offside the legislation. 

This report also makes two recommendations for the BC government: The BC Government should amend the Security Services Act or similar enactments to explicitly regulate the sale or installation of technologies that capture biometric Information. 

Finally, the BC Government should amend PIPA to create additional obligations for organizations that collect, use, or disclose biometric information, including requiring notification to the OIPC. This would be similar to what’s in place in Quebec where biometric databases need to be disclosed to the province’s privacy commissioner. 

I think, for all intents and purposes, this shuts down the use of facial recognition technology in the retail context, where it is being used to identify “bad guys”. 


Tuesday, July 26, 2011

Globe & Mail series on facial recognition

This week, the Globe & Mail is running a series of articles and opinion pieces on the use of facial recognition technologies. They're worth a read:

Wednesday, June 22, 2011

The Current on facial recognition technology to identify Vancouver rioters

I was invited to participate in a discussion on CBC's The Current about the proposed use of ICBC's facial recognition software to identify people who participated in the Vancouver riots following the loss of the Stanley Cup playoffs. The segment is here as an MP3 file for your listening pleasure: http://podcast.cbc.ca/mp3/podcasts/current_20110622_72805.mp3 or embedded on their site.

First up was Adam Grossman of ICBC, followed by me, then Marc Rotenberg of EPIC, then Gil Hirsch of Face.com.

The CBC's summary of the segment is here.

Sunday, June 19, 2011

ICBC offers up its drivers' license database (with facial recognition) to ID Vancouver rioters

The Insurance Corporation of British Columbia is offering up its massive database of drivers' license photos, accompanied by the biometric measurements of those photos, to the police to help identify those involved in the recent Stanley Cup riot. (See: Insurance corporation offers to help ID rioters - British Columbia - CBC News.)

They are saying they'd need a court order to do so, but nevertheless I think this is a serious issue that hopefully any judge considering such an application will think long and hard about. Yes the riot was appalling and yes there are many, many photos available of people who were involved. I am greatly concerned that information collected for one purpose, namely identifying licensed drivers, will be reused for a completely unrelated purpose without adequate debate about what this means in the big picture.

This would set a precedent in Canada that might permit the use of Foreign Affairs' massive passport photo database and each provincial drivers' license database to (supposedly) finger people in what is essentially a property crime investigation. If police are allowed access in this case, they'll be looking for access in many, many more. The "slippery slope" argument is a pretty compelling one, since once the pandora's box is opened it's very hard to put the lid on it.

Wednesday, June 08, 2011

Facebook's facial recognition system should help users control their privacy (but doesn't)

Facebook is edging back into the privacy spotlight with the expected global roll-out of assisted tagging of photos using facial recognition. The service scans uploaded photos for faces and suggests tags for the people in them. (See: Facebook's Latest Privacy Settings Shadiness Invades Your Drunk Pics - Gizmodo.)

What I'd like to see is the service being used in reverse: alert me if someone posts a photo of me on Facebook. If it can help someone tag me, it can surely recognize me in untagged photos and give me a heads' up. Just a thought of using the technology to let users control (or at least know about) others posting photos of them.

Tuesday, May 17, 2011

Ontario Information and Privacy Commissioner tables annual report for 2010

The Information and Privacy Commissioner of Ontario, Anne Cavoukian, has tabled her annual report for 2010 with the Ontario legislature. The report is here and below is her press release:

OFFICE OF THE INFORMATION AND PRIVACY COMMISSIONER/ONTARIO | We must Be Proactive in our pursuit of Access and Privacy: Commissioner Cavoukian

We must Be Proactive in our pursuit of Access and Privacy: Commissioner Cavoukian 2010 Annual Report cites benchmark ruling to lower costs for Ontarians to access their own health records

TORONTO, May 17 /CNW/ - Ontario's Information and Privacy Commissioner, Dr. Ann Cavoukian, today issued a challenge for public organizations to "Be Proactive" with access and privacy initiatives, as she released her 2010 Annual Report.

Her call to action follows a year in which more Freedom of Information (FOI) requests were filed with government organizations in Ontario than ever before. In 2010, the Commissioner's office (IPC) also posted a new record for the number of privacy complaints closed.

The Commissioner's core concepts of Privacy by Design (PbD) and Access by Design (AbD) provide guiding principles for embedding default privacy and access within processes and technologies from the outset - avoiding many of the inefficiencies, costs and "harm" related to privacy breaches and requests for government-held information.

Rolling back fees for access to Ontarians' health records

Within her Annual Report, the Commissioner also stressed the importance of a benchmark ruling from her office in 2010. Following an Ontario citizen's complaint, a medical professional was ordered to significantly reduce a charge for access to health records. This followed an IPC review of fee structures in order to determine "reasonable cost recovery" - the amount that health care providers are permitted to charge.

"We have consistently urged the government to bring in a regulation that would set specific fees that health care providers can charge individuals," says Commissioner Cavoukian. "The fees vary dramatically across the health sector, and my office has received numerous complaints about excessive fees. This health order will now serve as a solid benchmark for decisions from my Office, until a regulation is officially introduced."

Celebrating Innovation in Privacy and Access

The Commissioner's Privacy by Design approach was officially centre-stage in 2010, as her made-in-Ontario solution was adopted as an "essential component of fundamental privacy protection" by International Data Protection Commissioners. Now an International Privacy Standard, Privacy by Design has been embraced by The U.S. Federal Trade Commission and European Union. The international acclaim in 2010 paved the way for continued innovation closer to home, to ensure that citizens' personal information is protected - by default.

The Commissioner praised Ontario organizations that stood out in their commitment to proactive privacy in 2010. They include Hydro One and Toronto Hydro for their work to embed privacy into Ontario's emerging Smart Grid, and The Ontario Lottery and Gaming Corporation, for a new privacy-protective biometric facial recognition system to support its voluntary self-exclusion program, for patrons who want to be kept out of gambling sites.

On the issue of access to information, the cities of Toronto and Ottawa earned special recognition for their leading open government initiatives - the proactive release of pertinent government-held information in open, usable formats.

Key Statistics: New records set for Privacy Complaints and FOI requests

  • Overall, the IPC closed 267 privacy complaints in 2010 under the two public sector information and privacy Acts, the highest number ever. The disclosure of personal information was the most cited reason for filing a privacy complaint;
  • The number of FOI requests filed across Ontario in 2010 climbed to 38,903, breaking the record of 38,584 set in 2007.
  • The total number of privacy complaints filed with the IPC (under the two public sector Acts and the Personal Health Information Protection Act) climbed to 440 in 2010
  • In 2010, 977 appeals (of decisions issued by individual government organizations related to FOI requests) were submitted to the IPC, the second highest number in 15 years.

Get Your Local Perspective - In-depth Statistics Available

A more detailed look at FOI compliance rates, requests, appeals and privacy statistics is available in the online section of the Commissioner's Annual Report. This lists specific 2010 statistics for Ontario's ministries, agencies and local government institutions covered under the Acts, such as municipalities, universities, health units and police services. Find it all at www.ipc.on.ca

Thursday, December 16, 2010

Facebook implements facial recognition, silent on privacy

Facebook has just announced that it is implementing facial recognition software to "make it easier to tag your friends" in photos. It will make tagging the same person over and over in an album much easier, but their blog post (Making Photo Tagging Easier) doesn't address privacy at all. I'm surprised by this, given that Facebook has been much more vocal and upfront about privacy as of late.

Sunday, April 27, 2008

California takes lead on DNA crime-fighting technique

In an effort to fully exploit DNA databases, investigators in California are planning to look for partial matches from crime scenes. If a forensic sample partially matches a sample on file, it likely means that it was left by a relative of the person on file. Although the "match" isn't for a suspect, they'll be investigated to try to find the suspect in their family tree.

Critics are concerned about the privacy implications of this.

California takes lead on DNA crime-fighting technique - Los Angeles Times

Civil libertarians oppose using DNA databases to search for relatives of unknown offenders, saying it puts family members under "genetic surveillance" for crimes they did not commit. For now, all the people in the state's database are convicted offenders, but the state plans to expand the database next year to include arrestees, heightening concerns over privacy.

Critics say familial searching could expose sensitive and secret genetic relationships. A son, for example, could learn that his father was not his biological parent. DNA databases also reflect the racial and ethnic biases of the justice system, exposing minority communities to more surveillance than others, critics maintain.

FBI officials in charge of the national database network have also expressed concerns, making them unlikely allies of civil libertarians on familial searching. They urge a cautious approach, worrying that the courts will balk at this type of sleuthing. No law specifically authorizes it, and some legal scholars consider it unconstitutional because they say it amounts to an unreasonable search.

Brown called such objections hypothetical. The policy forbids the release of the names of relatives until genetic tests and analysis convince the state that the person is indeed a relative.

"It is still not going to be a fail-safe system, and we are going to make mistakes," said Simoncelli, the ACLU science advisor. "We are opening the door to using the database in such a fundamentally different way than the purpose for which it was established."

Wacky Canadians Still Believe in Privacy

Washtington Post columnist Al Kamen has picked up on the Canadian Privacy Commissioner's response to the Secretary of Homeland Security's statement that fingerprits are not "personal" (see: Canadian Privacy Law Blog: Privacy Commissioner's response to US Homeland Security Secretary's statement on biometrics). It's not clear whether he's being serious, but we certainly are wacky compared to the Americans.

Al Kamen - Wacky Canadians Still Believe in Privacy - washingtonpost.com

Wacky Canadians Still Believe in Privacy

By Al Kamen

Friday, April 25, 2008; A21

Homeland Security chief Michael Chertoff caused a little ruckus up north a couple weeks ago as he was pushing his plan to share databases of international air travelers' fingerprints with the Canadians, Brits and Aussies.

In an interview with an excessively squeamish Canadian reporter, Chertoff was told: "Some are raising that the privacy aspects of this thing, you know, sharing of that kind of data, very personal data, among four countries is quite a scary thing."

Nonsense, Chertoff responded. "Well, first of all, a fingerprint is hardly personal data because you leave it on glasses and silverware and articles all over the world. They're like footprints. They're not particularly private," he said, according to Canadian news reports and privacy lawyer Peter Swire, a senior fellow and guest blogger at the Center for American Progress.

Absolutely. But the old-fashioned Canadians seem to think otherwise. They even have someone who monitors privacy issues, Privacy Commissioner Jennifer Stoddart, who promptly wrote the minister of public safety and preparedness to object, noting that Canadian law "defines fingerprints as personal information" and that "fingerprints constitute extremely personal information for which there is clearly a high expectation of privacy." That's why, she wrote with a hint of huffiness, "Canadians rightly expect their government to respect their civil liberties and personal information from abuse."

Oh yeah? Well, our Supreme Court ruled in 1985 that you have to have probable cause before you haul someone off and fingerprint them. Justice Byron R. White wrote the opinion, joined by Warren E. Burger and William H. Rehnquist, no less.

But in wartime, maybe we have different expectations, okay? As Chertoff, who after all was recently a federal appeals judge, knows quite well, no one should expect privacy in a restaurant or anywhere else where a fingerprint might be left.

And we don't. That's why many diners here are beginning to use gloves when they eat at restaurants and some even wear those hospital booties. Others prefer just a discreet swipe of utensils and glassware with a Wet-Nap to ensure against DNA retrieval from saliva. (There is a growing -- and deplorable -- trend to bring personal cutlery, but that really seems excessive and, in finer establishments, downright disrespectful, especially if it's plastic.)

Is it possible the Canadians thought those signs at beachfront eateries -- "No shirt, no shoes, no service" -- were an effort to maintain appropriate attire? Everyone down here knows the restaurants just wanted to prevent the feds from trying to collect toe prints.

Canadians probably still go to barbershops -- where a single hair in the right hands can provide DNA, general health info, recent drug use data and other information. Our cousins probably haven't read about the growing in-home trim movement here.

And there's an easy way to guard against theft of your secret mattress Sleep Number. Just change the setting every morning before you leave.

Saturday, April 12, 2008

Toronto Police Chief calls for DNA samples regardless of conviction

CityNews in Toronto is reporting that the city's chief of police is calling for forced DNA samples for a national database even before an individual is convicted, and the retention of those samples even if the individual is acquitted. See: CityNews: Toronto Police Chief Calls For Forced DNA Samples.

Friday, April 11, 2008

Privacy Commissioner's response to US Homeland Security Secretary's statement on biometrics

Jennifer Stoddart has released a letter addressed to Minister of Public Safety Stockwell Day in response to remarks made by the U.S. Secretary of Homeland Security suggesting fingerprints are not “personal data”.

Letter to the Minister of Public Safety and Emergency Preparedness Canada

The Honourable Stockwell Day, P.C., M.P. Minister of Public Safety and Emergency Preparedness Canada Public Safety Canada Room: 19A-7400 269 Laurier Avenue West Ottawa, ON K1A 0P8

Dear Minister,

I am writing to express my concern about remarks U.S. Secretary of Homeland Security Michael Chertoff made yesterday while in Ottawa, suggesting fingerprints are not “personal data”.

As you know, Canadian privacy legislation defines fingerprints as personal information. In Canada, we have traditionally taken a more restrained approach to the collection of fingerprints, largely restricted to cases were individuals are charged with or convicted of certain criminal behaviour.

In contrast, the U.S. has increasingly relied upon the collection of biometric data, including fingerprints, from a broad range of individuals for border control purposes and in order to identify and track suspected terrorists. Fingerprints constitute extremely personal information for which there is clearly a high expectation of privacy. Canadian courts have held that, absent lawful authority, compelling persons to provide fingerprints may violate their rights under the Charter of Rights and Freedoms.

No one doubts the need to strengthen information-sharing among nations. We all share a common goal of ensuring our national security. However, as Privacy Commissioner, I strongly urge the Government of Canada to ensure that the privacy rights of individuals are respected and protected at all times.

Canadians rightly expect their government to respect their civil liberties and safeguard their personal information from abuse. The challenge lies in finding the balance between the protection of civil liberties and the need for national security.

As Privacy Commissioner, I certainly expect to be consulted if the Government of Canada is considering new programs to share biometric information – or any personal information – with foreign governments.

I expect your assurance that adequate oversight and control mechanisms are built into the collection, use and safeguarding of personal information that may be shared with other governments, and I expect the opportunity to review these mechanisms.

I know that our respective staffs have built a solid working relationship in matters of security and privacy, and expect that the concerns identified above will be addressed as programs are expanded or new programs are considered.

Sincerely,

Original signed by

Jennifer Stoddart Privacy Commissioner of Canada

Thursday, March 27, 2008

Tuesday, March 18, 2008

UK police urge that young children be added to already enormous DNA list

Just in case you were starting to wonder about the benefits of a written constitution and bill of rights, the UK steps up to the plate: Authorities in England are proposing to collect the DNA of five year olds in case they grow up to be terrorists, thugs, or ne'er do wells. And if you have a transit card, your movements will be analyzed by the sercurity services in case you are a terrorist, thug or ne'er do well. See: Put young children on DNA list, urge police Society The Observer. Via Boing Boing.

Wednesday, January 02, 2008

New US passport cards for North American travel can be read at a distance

Over the holidays, the US government published information about a new passport card to facilitate travel by Americans in North America. One "feature" is causing a lot of concern: the technology (presumably RFID) built into the card means they can be read over a distance of up to eight metres. The cards will be issued with protective sleeves for those who want to use them, but this doesn't assuage privacy advocates who think the technology is inherently flawed. See: globeandmail.com: U.S. 'vicinity-read' cards assailed by privacy experts.

Saturday, December 22, 2007

FBI aims for world's largest biometrics database

This sort of stuff no longer surprises me, but this bit of the story on Yahoo! News is interesting:
FBI aims for world's largest biometrics database - Yahoo! News

... At an employer's request, the FBI will also retain the fingerprints of employees who have undergone criminal background checks, the paper said....

Sunday, September 16, 2007

British commentator looks to Canadian example for privacy

A comment in the Guardian by Henry Porter decries preceived intrusions into the private lives of the British and suggests that Canada is a good model to follow. He agrees strongly with what Pierre Trudeau said, that the Government has no business in the bedrooms of the nation.

Our sex lives are our own business Comment Guardian Unlimited Politics

... A few years ago, this sentence appeared at the beginning of a bill: 'Her Majesty by and with the advice of the House of Commons enacts as follows: rules to govern the collection, use and disclosure of personal information in a manner that recognises the right of privacy of individuals with respect to their personal information.'

The only words I have missed out are the 'senate' and 'of Canada'. Same queen, but different country and one which has placed the respect for privacy at the heart of its national life. It seems extraordinary that two countries which used to share so many political values have taken such different directions. There's a lot that Canada can teach the Mother of Parliaments, especially the opposition, which has lost the habit of thinking outside the terms that Labour has set for the national agenda.

There are two important acts which serve as good templates for the sorts of reforms Liberty calls for. The first is the Privacy Act which took effect in 1983 and which imposes obligations on some 150 government and federal departments and agencies to respect the privacy rights by limiting the collection, use and disclosure of personal information. It gives the individual a right to access and correction of personal information held by agencies. The second act is the Personal Information Protection and Electronic Documents Act (Pipeda), a law which means a company like Tesco, which accumulates enormous amounts of personal data, must have consent from its customers. Underlying these is the Canadian charter of rights and freedoms which states: 'Everyone has the right to be secure against unreasonable search and seizure', a guarantee which I would like to see in a British bill of rights.

It is argued that we have the Data Protection Act and the information commissioner, but despite the latter's agitation, nothing has stopped the 500,000 interceptions of private communication each year, the total surveillance of motorways, the building of the ID card data base, the creepy children's database and expansion of the police DNA database.

The Canadian system hasn't worked perfectly, especially since 9/11, but Canadians shudder at what is happening in the UK, at the abandon with which we allow government more and more control over our lives and our futures....

Sunday, July 01, 2007

OPC finds LSAT fingerprinting violates PIPEDA

In a preliminary letter to the complainant, the Office of the Privacy Commissioner of Canada has concluded that the Law School Admissions Council violates PIPEDA by requiring candidates to submit to fingerprinting at the time the LSAT test is taken:

CIPPIC News « CIPPIC

In a decision released earlier this month, the Privacy Commissioner of Canada found that the requirement for Canadian students to provide a finger/thumb print in order to take the Law School Admission Test (LSAT) is an unnecessary infringement of privacy.

Copy of letter decision sent to Complainant

One of the most interesting aspects of the letter is the conclusion that the non-profit LSAC is engaged in commercial activities sufficient to have PIPEDA apply in the first place.

Also, the Assistant Commissioner's conclusion turned on the four point test applied in the past to video surveillance:

  • Is the measure demonstrably necessary to meet a specific need?
  • Is it likely to be effective in meeting that need?
  • Is the loss of privacy proportional to the benefit gained?
  • Is there a less privacy-invasive way of achieving the same end?

Saturday, February 17, 2007

Mining drivers' licence databases raises privacy concerns

Yesterday's New York Times ran an interesting article on the increasing application of biometrics to drivers' licenses in the United States, and the collateral use of this technology. For example, photos from state databases are run against the rest of the database to identify those who have multiple licenses (to try to thwart a license suspension) or against photos of wanted felons. This practice has privacy advocates upset:

Driver’s License Emerges as Crime-Fighting Tool, but Privacy Advocates Worry - New York Times

“What is the D.M.V.?” asked Lee Tien, a lawyer with the Electronic Frontier Foundation and a privacy advocate. “Does it license motor vehicles and drivers? Or is it really an identification arm of law enforcement?”

Anne L. Collins, the Massachusetts registrar of motor vehicles, said that people seeking a driver’s license at least implicitly consent to allowing their images to be used for other purposes.

“One of the things a driver’s license has become,” Ms. Collins said, “is evidence that you are who you say you are.”

Monday, February 05, 2007

VeriChip goes public

Applied Digital Solutions, the creator of VeriChip, is planning an IPO shortly. It'll be interesting to see how investors feel about this controversial company and its technology. See: A Medical ID Business, Much Criticized, Plans a Stock Offering - New York Times.