The Canadian Corporate Counsel Association Magazine (CCCA Magazine) Spring 2014 edition had a strong focus on privacy, "Managing your Privacy Risk: An In-house Guide." The edition included a version of my Cloud Computing and Privacy FAQ, focused at in-house counsel. Click the image (or here) to get the full article:
The Canadian Privacy Law Blog: Developments in privacy law and writings of a Canadian privacy lawyer, containing information related to the Personal Information Protection and Electronic Documents Act (aka PIPEDA) and other Canadian and international laws.
Friday, March 28, 2014
Cloud Computing FAQ for Corporate Counsel
Wednesday, December 19, 2012
Keeping data in Canada provides illusory protection against foreign government access
Here is the presentation, in case it is of interest:
IT World Canada was in attendance and has posted the following article:
Keeping data here no protection against US: Lawyer:
Ottawa may not allow cloud providers to store citizens' data across the border. But a lawyer says a better protection against US law is risk mitigation
By: Howard Solomon
ComputerWorld Canada (19 Dec 2012)
The refusal of some federal government departments to allow outsourcers to store personal data of citizens outside Canada won’t keep foreign governments from getting legal access to it, says a lawyer who specializes in cloud computing.
“Data sovereignty is a bit of an illusion because we’re so interconnected (with law enforcement agencies) and there’s so much data sharing taking place,” David Fraser told an audio conference call Tuesday sponsored by the Canadian Advanced Technology Alliance (CATA).
In particular, fears that the USA Patriot Act acts as a “huge vacuum cleaner” for American law enforcement agencies to get at personal data is baseless, he said.
The Patriot Act is a “boogey man,” he said.
The fact is most developed countries have legal tools that allow their law enforcement agencies to make legal claims on data held in their countries or outside their borders, Fraser said.
Fraser, a partners with the Halifax firm McInnes Cooper, argued the real issue for Ottawa when considering outsourcing that includes storing data in the U.S. should be assessing the risk that data can be lost or unlawfully accessed and taking steps to lower the risk.
The teleconference is part of a campaign by CATA, which represents IT manufacturers, solution providers, system integrators and consultants trying to sell products and services to governments, to get Ottawa to clarify its position on outsourcing data.
In an interview John Reid, CATA chief executive officer, said that since the creation last year of Shared Services Canada, an agency trying to consolidate federal IT services, the government has suggested it may mandate that personal data of citizens must be held in data centres here.
There isn’t a formal federal policy on cross-border data storage, Fraser told the conference call. Nor is there federal law that prohibits it. Instead, it is up to individual departments to do a risk assessment if they decide cross-border data storage is justified and take appropriate privacy measures. Only two provinces, British Columbia and Nova Scotia, have policies forbidding cloud providers from storing provincial data outside Canada.
Shared Services Canada has been trying to create new buying and outsourcing policies, setting up several committees on which CATA and other private sector groups sit. It is those committees, Reid said, that CATA is getting signals of SSC’s only-in-Canada intent.
Earlier this month CATA sent a letter to SSC asking for the department’s intentions, but Reid said he hasn’t had a reply yet.
The department didn’t respond to a request Tuesday from IT World Canada for clarification
One person on the conference call said some government departments already demand in requests for proposals (RPFs) her organization that any outsourced solution has to keep data in Canada.
Reid wants to persuade Ottawa to be more open to cloud solutions where data is stored outside the country in part so his members get opportunities to bid on business, and in part, he said, because the government shouldn’t turn aside possible solutions that will make it more efficient.
Fraser noted that according to international law, U.S. law enforcement authorities have the right to subpoena data even if the data is held outside its borders, as long as there are connecting factors. (The same is true for police here, he added.)
For example, he said, if the data is held in Canada the U.S. could subpoena it through a person working for a company there.
For that reason, he said, a Canadian data centre owner might be able to safeguard data here if none of its executives ever crossed the border.
More practically, he said the Canadian government could take a number of steps to reduce the odds of the personal data of its citizens being misused by U.S. authorities.
The first is to encrypt the data – which should be a standard procedure anyway, he said ---- and make sure control of the encryption keys is held here.
Second, the government could decide that only “low risk” data can be sent out of the country.
Third, the government could demand certain contractual provisions with a service provider, such as clauses that says the data belongs to the customer, not the data centre, that the service provider won’t turn data over unless legally required to so, and that it will notify the customer of any subpoenas.
There could also be a requirement the provider to go a U.S. court to resist a subpoena, although Fraser admitted there’s no guarantee will be successful.
“There isn’t a shortage of ideas of how to mitigate risk,” he said.
Fraser didn’t say, but these risk mitigation options also apply to private sector companies who have been shy about adopting American cloud-based solutions.
Saturday, September 29, 2012
Nova Scotia trade union resurrects the USA Patriot Act boogeyman to prevent outsourcing
For those who have been following this topic in Canada, you'll remember that the first time that the USA Patriot Act appeared on the country's radar in earnest was when the British Columbia government proposed to outsource IT processing to the Canadian subsidiary of a US company. The union, most likely concerned about job losses latched onto the USA Patriot Act as the hook that would get some traction in the media and in the public mind.
That led to the inquiry by BC's Information and Privacy Commissioner, then amendments to that province's Freedom of Information and Protection of Privacy Act and then Nova Scotia's Personal Information International Disclosure Protection Act.
Now, somewhat predictably, the principal Nova Scotia trade union for public employees is resurrecting the boogeyman to try to stop outsourcing of IT services by the provincial government. We'll see how this plays out ...
Data at risk in private-sector deal | The Chronicle HeraldUnion worried Nova Scotian’s records vulnerable
The province’s largest public-sector union is worried about the security of Nova Scotians’ information if the government contracts out information technology work in a deal workers say could total $100 million over 10 years.
Joan Jessome, president of the Nova Scotia Government and General Employees Union, said Thursday that there’s a vast amount and array of data in the SAP computer system. She said it includes everything from payroll numbers to procurement information and data from the Registry of Motor Vehicles.
“There probably isn’t a single Nova Scotian ... that has not been impacted by SAP,” Jessome said.
“(Our members) are telling us that we have reason, no matter what the agreement is, that once that (information) goes to an international company, we should always be concerned about how far that goes and what acts does it cover in different countries across the world.”
She said employees mentioned the Patriot Act in the United States, passed after the 9-11 attacks. It requires U.S. companies to provide records to the American government upon demand.
A 2005 provincial auditor general’s report raised a concern that U.S. companies with Canadian subsidiaries could also be compelled to turn over information. In 2006, the minority Tory government of the day passed the Personal Information International Disclosure Protection Act, meant to prevent U.S. authorities from inappropriately accessing Nova Scotians’ information under the Patriot Act.
Finance Department spokeswoman Michelle Lucas had said Wednesday that ensuring information is secure would be a top priority. She had no further comment on the potential outsourcing Thursday.
On Monday, government officials met with employees who run the system to tell them about the possibility their jobs will be contracted out. There are about 73 unionized workers, and another 35 who aren’t unionized. The non-union workers run the system for district health authorities and the IWK Health Centre.
Jessome said workers told her that the government is considering a 10-year contract for the work, worth $10 million a year.
Lucas had said Wednesday that a multinational firm approached the province last year about setting up a “global delivery centre” in the province. Its main office would be in Halifax, with a smaller one in Sydney.
Sources have said the firm is IBM Canada. Jessome said the government has told her which company, but she agreed to keep it confidential.
IBM Canada spokeswoman Carrie Bendsza said the company, which has employees in Halifax now, doesn’t comment on rumour or speculation. She also said it doesn’t reveal how many employees it has in individual cities or countries.
Jessome said there are currently eight union SAP information technology workers in Sydney, three in Truro, and the rest in Halifax.
Lucas has said that if the province does make a deal with the company, all affected provincial employees would be offered a job. Jessome said many have already indicated they wouldn’t take it.
She said they’d lose the security of being in the union, the work week would likely go up to 40 hours from 35, their pension plan would change to defined contribution from defined benefit, and they could face months-long placements at the company’s other locations, such as China and India.
“They’re certainly concerned about their jobs, no question, but the other thing that they were scared of is the security of information,” Jessome said.
Lucas also said the potential contracting out isn’t being considered as a cost-cutting measure, but as an economic development opportunity in the hope of creating more jobs.
The province has spent many millions on the SAP system since first adopting it in 1996, with some projects going over budget, and the system not always working properly.
Friday, September 21, 2012
Ontario Information Privacy Commissioner blesses cross-border outsourcing of province's hunting and fishing license system
This decision from the Information and Privacy Commissioner of Ontario snuck under my radar this summer while I was on vacation.
This investigation is the result of a complaint brought by a Member of the Provincial Parliament about the Ontario Government's decision to outsource the processing and management of fishing and hunting licenses to a US-based business. The Commissioner did a thorough investigation and I am told they were pleasantly surprised by what they found. With regard to the USA Patriot Act, the Commissioner wrote:
The PATRIOT Act
The complainant has expressed concerns that the personal information of Ontarians will be subject to and accessible under American laws, including the PATRIOT Act. It is important to remember that, in Ontario, there is no legislative prohibition against the storing of personal information outside of the province or Canada. In other words, Ontario law, including the Act, does not speak to this issue. However, the Act and its regulations do require provincial institutions to ensure that reasonable measures are in place to protect the privacy and security of their records containing personal information. This applies regardless of where the records are located. Further, Ontario provincial institutions remain accountable for the actions of their agents or service providers, whether located in Ontario or in other jurisdictions.
I understand the complainant’s concern that the PATRIOT Act may be used by U.S. law enforcement agencies to access Ontarians’ personal information. However, the risk that law enforcement agencies may access personal information is not restricted to information held in the U.S. In fact, Canadian law enforcement agencies have similarly robust legal powers to obtain personal information held in Canada, and similar powers exist throughout most countries in the world. Further, law enforcement agencies in Canada, the U.S. and other countries have the ability to reach across borders to access personal information under various laws and agreements.
In this regard, the federal Privacy Commissioner of Canada has found that the privacy risks posed by the PATRIOT Act are similar to those found in Canada and, therefore, the privacy protection afforded by a U.S. service provider is comparable to that of a Canadian-based provider. In particular, the federal Privacy Commissioner has stated:
The risk of personal information being disclosed to government authorities is not a risk unique to U.S. organizations. In the national security and anti-terrorism context, Canadian organizations are subject to similar types of orders to disclose personal information held in Canada to Canadian authorities.
The federal Privacy Commissioner has also found that prior to the passing of the PATRIOT Act, U.S. authorities were able to access records held by U.S.-based firms relating to foreign intelligence gathering in a number of ways, including through formal bilateral agreements.3
Canadian legal scholars and practitioners have also carefully examined and commented on the privacy implications of the PATRIOT Act. Professor Michael Geist, Canada Research Chair in Internet and E-commerce Law, has written:
Claims that the enactment of the USA Patriot Act has dramatically altered the legal landscape are simply false. The U.S. law enforcement toolkit, which allows for the compelled, secret disclosure of personal information, pre-dates the USA Patriot Act by decades. Suggestions that the problem can be solved by keeping personal information from flowing outside the country are not realistic from a real-world, commercial perspective, where data is transferred and stored instantly on computer servers in other jurisdictions without regard for location.
David T.S. Fraser, a prominent Canadian privacy lawyer, has also been very clear in writing:
Most people are surprised to learn that some of the most “problematic” provisions of the USA Patriot Act are replicated in Canadian law in the Anti-Terrorism Act. We just don’t hear about it as much. People are also surprised to learn of huge amount of information sharing that takes place between agencies in Canada and their counterparts in the US.
The Act does not prohibit provincial institutions from outsourcing services on the basis that foreign law, including the PATRIOT Act, may apply. Similarly, there is no prohibition on the storage of personal information by government institutions outside the province. In fact, as noted by Professor Geist, outsourcing of technology services is a reality, whether by government agencies or private sector companies. Personal information may be subject to disclosure to law enforcement authorities, whether stored in the province or elsewhere. The critical question for institutions which have outsourced their operations across provincial or international borders is whether they have taken reasonable steps to protect the privacy and security of the records in their custody and control. I have always taken the position that you can outsource services, but you cannot outsource accountability. With this in mind, I now turn to consider what measures the Ministry has put into place in the circumstances of this complaint.
The decision is worth reading in its entirety: IPC - Office of the Information and Privacy Commissioner/Ontario | Reviewing the Licensing Automation System of the Ministry of Natural Resources: A Special Investigation Report [PC12-39].
Saturday, May 26, 2012
White paper compares government access to cloud data in ten jurisdictions
In the last week, law firm Hogan Lovells released a very interesting white paper on government access to cloud data across ten jurisdictions, mainly focused on debunking many of the myths associated with the USA Patriot Act. The white paper was released in association with a Round Table on Government Access to Data with European policy makers at the Openforum Academy.
More information is available at the Hogan Lovells Chronicle of Data Protection: Hogan Lovells White Paper on Governmental Access to Data in the Cloud Debunks Faulty Assumption That US Access is Unique : HL Chronicle of Data Protection.
Here's the white paper: A Global Reality: Governmental Access to Data in the Cloud -- A comparative analysis of ten international jurisdictions.
Friday, May 11, 2012
Cloud Computing and the Patriot Act: A Red Herring?
The 2012 International Association of Privacy Professionals Canada Symposium has just wrapped up. I had the pleasure of giving a presentation on cloud computing and the USA PATRIOT Act with Lindsey Finch, the Senior Global Privacy Counsel with salesforce.com. Our presentation is here:
Cloud Computing and the Patriot Act: A Red Herring?Cloud computing is revolutionizing the information technology industry by providing cost savings, flexibility and innovation. But many Canadian companies are concerned that use of cloud computing services may cause them to violate Canadian privacy laws, particularly because of potential non-Canadian government access to data stored in the cloud. Join our expert panel as they address persistent Canadian myths regarding cloud computing and privacy, discuss how cloud computing services can be used in compliance with Canadian privacy laws and the real impact of the Patriot Act, and provide tips to use during RFP cycles and contractual negotiations.
Lindsey Finch, CIPP/US, Senior Global Privacy Counsel, salesforce.com David T.S. Fraser, Partner, McInnes Cooper, Halifax
What you’ll take away:
- Learn how to manage privacy risk and legal compliance in cloud computing decisions, including both public and private sector privacy laws
- Understand the similarities and differences between U.S. and Canadian government powers to access data in the course of a terrorism investigation and how the two governments share data to assist each other in such investigations
- Learn when Canadian privacy law permits the transfer of personal information outside of country for processing purposes
- Leave with a checklist, based on established best practices, to facilitate decisions about moving information to the cloud and a checklist to use in a RFP or contract with a cloud provider
Most of the other conference presentations are here.
Friday, December 02, 2011
Smartphones are equivalent to computers for purposes of police search, says Nova Scotia court
Notably, the Court characterized the phone as a computer and observed that the same considerations come into play as with a search of a personal computer:
[39] The Crown acknowledges that the accused had a reasonable expectation of privacy in the contents of his cellphone and that the three occasions when the police examined and retrieved information from the cellphone constituted a warrantless search which constituted a prima facie unreasonable search[30] for the purposes of s. 8 of the Charter. Having said that, in my opinion it is important to characterize the degree or level of privacy in the smart phone information and how that information is stored because, in my opinion, it is a factor in deciding the scope of the police authority to search a cellphone incident to arrest.
[40] Here the cellphone which was seized was described as a “regular smart phone, a Blackberry sort of phone”. Phones of this sort have been described as “mini computers”[31]. These phones are capable of storing dozens of gigabytes of data not unlike personal or home computers. There is a high level of privacy associated with personal computers[32]. In R. v. Morelli, supra Justice Fish said at para. 2 “It is difficult to imagine a search more intrusive, extensive, or invasive of one's privacy than the search and seizure of a personal computer”. He continues at para. 3 :
First, police officers enter your home, take possession of your computer, and carry it off for examination in a place unknown and inaccessible to you. There, without supervision or constraint, they scour the entire contents of your hard drive: your emails sent and received; accompanying attachments; your personal notes and correspondence; your meetings and appointments; your medical and financial records; and all other saved documents that you have downloaded, copied, scanned, or created. The police scrutinize as well the electronic roadmap of your cybernetic peregrinations, where you have been and what you appear to have seen on the Internet -- generally by design, but sometimes by accident.[41] Later at para. 105 he describes the nature of information computers contain:
Computers often contain our most intimate correspondence. They contain the details of our financial, medical, and personal situations. They even reveal our specific interests, likes, and propensities, recording in the browsing history and cache files the information we seek out and read, watch, or listen to on the Internet.Blackberrys and other smart phones function in the same way as personal computers[33].
[42] Other case authorities[34] are consistent in their conclusions that smartphone devices have the capacity to store vast amounts of sensitive and personal and private information including emails, text messages, contact lists, diaries, medical information and personal photographs as well as internet browsing histories.
[43] Given the advances in technology, these types of devices allow individuals to carry their entire personal information library with them. In my opinion, it is difficult to compare a smartphone with a notebook or briefcase one might carry or have for a specific purpose. Smartphones have several gigabytes of data storage which can store literally thousands of documents, photographs, messages or hundreds of thousands of filed data[35]. This, of course, does not take into account current technological advances regarding Cloud[36] storage and electronic and computer device sharing features which could increase the information available from a hand-held electronic device.
[44] While the accused did not testify as to the level of privacy – the Crown has admitted the accused had a reasonable expectation of privacy in the cell phone. I agree with the conclusion reached by Fuerst, J in R. v. Little, supra, at para. 120, that the subjective expectation of privacy can be presumed. This subjective expectation of privacy is objectively reasonable for the reasons I expressed above. Furthermore, the high level of privacy which I described can be inferred as well. In my opinion this privacy level exists irrespective of whether the phone is password protected. The lack of a password is not an invitation to view the personal contents contained in the device especially from the prying eyes of the state.
[45] Finally, I would add that like other computers, cellphones are organized in a way that separates voice messages, text messages, documents, photographs, browser history and other information. The information is not stored in one big container to use perhaps a poor analogy. It is possible to look at text messages without looking at photographs, for example. It is not necessary to examine ones voice memos to read text messages or documents.
Thursday, December 01, 2011
Never mind the Patriot Act, watch your thumb drives
Earlier this week, I spoke on a panel at Reboot's Privacy and Security conference in Ottawa about privacy and security in cloud computing. I didn't have a powerpoint, but IT World Canada has a pretty good write-up of the presentation ...
Never mind the Patriot Act, watch your thumb drives - Page 1 - SecurityBy: Grant Buckler
On: 01 Dec 2011
For: ComputerWorld CanadaBusinesses that think storing their cloud-based data north of the border protects them from government intrusion are wrong, a panel says. Why thumb drives are the real threat to info security
OTTAWA – Businesses contemplating cloud computing should worry less about the U.S. Patriot Act and more about thumb drives and border crossings, panelists at the Privacy and Information Security Congress said here Monday.
David Fraser, partner with the Atlantic Canadian law firm McInnes Cooper, said many people believe it is illegal to put data in the cloud if that means it will be stored south of the border because of provisions in the U.S. Patriot Act that allow the American security establishment to seize information without a conventional warrant or any notification to the data’s owners.
Whether or not many people believe it is illegal (it is not, though some provinces put limits on where certain data such as health records may be stored), comments from the audience showed there are concerns about the Patriot Act, particularly the fact that the law expressly forbids a cloud service provider from notifying a data owner when data is seized under the act.
But Fraser argued that Canada has similar legislation and that U.S. law applies to any company with a substantial connection to that country anyway, so insulating oneself from such government intrusion is not as simple as ensuring data stays north of the border.
And he said other risks are more significant – like thumb drives that plug into Universal Serial Bus (USB) ports. These are the No. 1 source of data breaches, according to Fraser.
“Go to the front desk of a hotel and say that you’ve lost your thumb drive,” he said, “and they’ll probably pull out a box of them.”
And if you’re concerned about governments snooping into your data, he added, “any time you cross the border … they can open up your laptop and they can clone your hard drive.”
Cloud computing could actually be a solution to both those problems by allowing computer users secure access to data from anywhere so they need not carry sensitive data on laptop hard drives or USB thumb drives, said Fraser.
Omkhar Arasaratnam, cloud security lead architect for SmartCloud Enterprise at IBM Canada Ltd., agreed with Fraser that keeping data at home is no panacea. And he said cloud security is not much different from information security in general, which is mainly about risk management and education.
Putting too many restrictions on what people can do won’t work, said Arasaratnam. “If you as an IT department are too restrictive, your end user community, your executives or their children will find ways around it.”
The best hope, he said, is to educate people so they understand why some behavior is risky, and look for ways to ensure security without restricting people’s use of technology too much.
The fact that cloud computing is new doesn’t necessarily mean it is insecure, said Arasaratnam. But Winn Schwartau, moderator of the panel, well-known speaker and author of several books on security, observed that IT has swung back and forth between centralization and decentralization several times since the 1950s, and asked the panelists what businesses should do to ensure they can get off the cloud should the pendulum swing again.
Fraser advised making sure contracts are clear about ownership of data and the client’s right to have it returned. Arasaratnam added that it’s important to ensure the data comes back in usable form, not as paper printouts or files in incomprehensible formats.
Tuesday, November 22, 2011
Current issues in privacy: Social media and cloud computing
Thursday, November 10, 2011
Cloud computing session at Privacy and Information Security Congress 2011
I'm going to be on a panel discussion at the Reboot conference "Privacy and Information Security Congress 2011" on November 28/29 in Ottawa.
The session is entitled Borderless Cloud Computing – "Hey You, Get Off My Cloud!"
Moderator: Winn Schwartau, President, Interpact, Inc. Author of Information Warfare, Cyber Shock, Time Based Security and Internet & Computer Ethics for Kids
Speakers:
- David Fraser, Partner, McInnes Cooper
- Omkhar Arasaratnam, Lead Security Architect, SmartCloud Enterprise+, IBM
- Ibrahim Gedeon*, Chief Technology Officer, TELUS
For more info, check out the agenda here: http://www.rebootconference.com/ottawaPS2011/agenda.php
Friday, October 14, 2011
Cloudlaw: Law and Policy in the Cloud
I'm spending the day today at a conference being hosted by the University of Toronto's Faculty of Law and the Centre for Innovation Law and Policy focused on cloud computing. The full agenda is at cloudlaw.ca and it looks like it will be a very interesting day.
I'm speaking at 1:00 on a panel that includes Patricia Kosseim (General Counsel to the Office of the Privacy Commissioner of Canada) and Professor Christopher Millard (Professor of Privacy and Information Law at the University of London). The topic is, not surprisingly, "Privacy and Security".
Here is my presentation, in case it's of interest:
Saturday, September 24, 2011
Upcoming conference: Cloudlaw: Law and Policy in the Cloud
If you'll be in Toronto on October 14 and have an interest in law and policy related to the cloud, you should sign up for a full day conference on the topic organized by The Centre for Innovation Law and Policy at the University of Toronto Faculty of Law. Registration is free, but you have to sign up in advance.
More info is here: Welcome to Cloud Computing Blog | The Fall 2011 Cloud Computing Conference.
Friday, July 15, 2011
Cloud computing and privacy
Today, I will be giving a presentation during a "Town Hall" meeting at the University of New Brunswick as part of their roll-out of cloud computing services for students. I've been asked to address privacy and security aspects of cloud computing.
Here's the presentation, if you're interested:
The video of the presentation is posted on YouTube.
Friday, June 10, 2011
Canadian Cloud Law Blog: Legal issues in cloud computing contracts
Just posted on my Canadian Cloud Law Blog:
Canadian Cloud Law Blog: Legal issues in cloud computing contractsYesterday, IT World Canada published a very lengthy article on the manifold legal issues that need to be considered when a company moves its data to the cloud, including a lengthy interview with me given a little while ago.
Here's the first part ...
Canadian cloud contracts: Liabilities and limitations - Page 1 - LeadershipMore companies in Canada are turning to the cloud — or, at least, thinking about it — for flexibility, agility and cost savings. But there is often the perception that using cloud-computing services could compromise corporate and customer data, or may even be against the law.
But there’s no law that prevents most Canadian businesses from exporting personal information, said David Fraser, partner with McInnis Cooper, president of the Canadian IT Law Association and chair of the National Privacy and Access Law Section of the Canadian Bar Association.
“Once you move into a real cloud computing model, all of a sudden you don’t know where your data is — where in Canada or where in the world — and we’ve seen a big privacy-related backlash against cloud computing,” he said. So a large part of his job is telling people they’re wrong, since there’s a huge amount of misinformation out there.
Private-sector privacy laws require that you ensure a comparable level of security for personal information, regardless of whether you permit it to be managed by a Canadian company or a non-Canadian company. And some highly regulated industries, such as banking, have special rules that may include additional regulation for outsourced services.
“The Patriot Act is the big thing that people freak out about,” he said, “but we have a Canadian version of the Patriot Act, which is just as offensive.”
Here’s the deal: In 2001, the U.S. Congress passed the USA Patriot Act, which expanded the powers of law enforcement and national security agencies to carry out investigations and obtain intelligence in connection with anti-terrorism investigations.
But the provisions that have attracted the most criticism, said Fraser, have equivalents under Canadian law. Regardless of where information resides, it will always be subject to lawful disclosure to law enforcement or national security bodies. In Canada, he said, this includes search warrants under the Criminal Code of Canada and the Canadian Security Intelligence Service Act. Many European countries also permit broader law enforcement and national security access to information than in both the U.S. and Canada.
Of course, where the data sits can have an impact on that data. If it’s in North Korea or China, it’s at high risk, said Fraser. In the U.S., it may in some cases be significant, but in most cases it won’t be. “How interested would the FBI be in getting their hands on that data and would they be able to justify getting a subpoena? In most cases no,” he said. “And if it’s a person of interest they can get it in Canada.”
Many people are surprised to learn there’s a secret court in the U.S. where judges hear applications made by Department of Justice lawyers for search warrants (and other such things) and there’s nobody on the other side to oppose those applications.
“We have a secret court in Canada,” said Fraser. “We have a bunker in Ottawa where judges hear lawyers from the Department of Justice and CSIS for warrants to do things as potentially offensive as break into your house and install wiretapping equipment. These orders can specifically provide for authorities to go back in and change the batteries. So people don’t often think that Canada is engaged in these types of cloak and dagger things, and we are. Our definition of anti-terrorism is as broad and offensive as the U.S.”
Canadian authorities have virtually identical powers under the Canadian Security Intelligence Service Act, he said, which permits secret court orders that authorize CSIS to intercept communications or to obtain anything named in the warrant.
On top of that, Canada has a mutual legal assistance treaty with the U.S. (as well as informal agreements), so if the FBI wants data and it’s in the hands of a Canadian company, the FBI calls the RCMP or CSIS. “So when you dig into it, that cross-border issue, at least in most cases, really is not the large issue that many people are led to believe it is,” he said, adding that the Patriot Act has become shorthand for just saying no.
Only British Columbia and Nova Scotia have laws strictly regulating the export of personal information from Canada by public bodies, said Fraser. For all other jurisdictions, including the federal jurisdiction, export is permitted, but the public body must ensure a comparable level of security for personal information, regardless of whether it’s managed by a Canadian or non-Canadian company.
What businesses need to do is benchmark their existing privacy infrastructure and compare it to the privacy infrastructure of the proposed cloud provider. What are the real risks to the data, and to privacy and security? A lot of businesses have significant existing vulnerabilities — from insecure desktops, to playing catch-up with security patches, to mobile employees running around with laptops. Or thumb drives. “Nothing is more stupid or dangerous,” said Fraser. “In a cloud model if the computer is lost you lose nothing.”
Very often, this benchmark leans heavily in favour of the cloud provider that has squadrons of security people. Small businesses, in particular, are vulnerable to power outages and basic continuity issues. A reputable large-scale cloud provider will have multiple data centres, so things will stay up and running.
Tuesday, May 17, 2011
Senator Leahy introduces much-needed update to Electronic Communications Privacy Act
Today, May 17, 2011, Patrick Leahy introduced a bill to amend and substantially fix the Electronic Communications Privacy Act (ECPA). The bill made sense at the time it was first authored by Leahy a quarter century ago, but it has needed a substantial re-write in this cloud computing age. The most problematic provision allows obtaining stored communications that are more than 180 days old with just a subpoena, rather than a warrant based on probable cause. Twenty-five years ago, you might consider an un-downloaded e-mail message to have been abandoned, but that is no longer the case when millions of users are keeping all of their e-mails and documents in the cloud.
The Digital Due Process Coalition has been heavily lobbying for this change for some time.
For more info: Patrick Leahy introduces update to electronic privacy law - Post Tech - The Washington Post
Friday, May 06, 2011
Canadian Privacy Commissioner releases consultation report on cloud computing and online profiling
The Privacy Commissioner of Canada has just today released her report that resulted from last year's consumer consultations, which focused on cloud computing, online tracking/profiling. The report is here: Report on the 2010 Office of the Privacy Commissioner of Canada's Consultations on Online Tracking, Profiling and Targeting, and Cloud Computing.
The summary is:
In the spring of 2010, the Office of the Privacy Commissioner of Canada (OPC) held consultations on online tracking, profiling and targeting, and cloud computing. The OPC received in total 32 written submissions and held public events in Toronto, Montreal and Calgary, attended by representatives of other privacy commissioner offices and industry, as well as academics, advocates and members of the public. On October 25, 2010, the OPC released a draft report on the consultations, seeking further comments on a range of issues, from the public/private divide to cloud computing. Twelve responses were received, addressing some of these issues.With respect to online tracking, profiling and targeting, we heard primarily about the privacy issues related to behavioural advertising: what it is, what the benefits are, what risks to privacy exist, and what self-regulatory measures are in place. In terms of general privacy concerns, the blurring of the public/private divide and its effects on reputation was seen as a significant issue that arises from online tracking, profiling and targeting. Children's activities online and the need to incorporate privacy into digital citizenship programs were also items that were raised.
The consultations were an opportunity to examine the practices of online tracking, profiling and targeting through the lens of the Personal Information Protection and Electronic Documents Act (PIPEDA). While most industry participants were of the view that PIPEDA can handle the evolving technological environment, certain challenges with respect to applying the law were raised by many respondents and participants. Defining what is (or is not) personal information, determining the appropriate form of consent, limiting the use of personal information, implementing reasonable safeguards, providing access and correction to online information, and ensuring accountability were cited as PIPEDA-related issues that need careful attention. Online tracking, profiling and targeting are still largely invisible to most individuals, and most respondents and participants agreed that greater transparency is needed for the benefit of individuals and to ensure innovation.
With respect to cloud computing, the OPC learned about the different characteristics and models of cloud computing. We heard about its benefits and risks to enterprises and consumers. Again, most respondents and participants were of the view that PIPEDA can address issues that arise from cloud computing while others suggested that more should be done. Most of the PIPEDA-related issues concerned jurisdiction and availability of personal information to third parties; safeguards; new uses for the personal information and retention; and access.
The OPC is proposing to undertake specific activities in relation to online tracking, profiling and targeting, specifically in terms of research and outreach activities, as well as policy development. The OPC also intends to reach out to individuals and small and medium-sized enterprises with respect to privacy issues related to cloud computing. The comments related to PIPEDA compliance will also be considered in any review of the legislation.
Monday, April 18, 2011
Cloud Computing and Privacy FAQ
Is it illegal for a Canadian business to outsource services, such as cloud computing, to a non-Canadian company?
Is it illegal for a Canadian public sector or government body to outsource services, such as cloud computing, to a non-Canadian company?
What is all the fuss about privacy and cloud computing?
What does British Columbia’s anti-export law say?
What does Nova Scotia’s anti-export law say?
Is information better protected from law enforcement and national security access in Canada than in the United States?
Does keeping data in Canada keep it away from American law enforcement and national security agencies?
If we go with a cloud solution, should we give notice of this to our customers/users?
What are the legal security requirements for Canadian companies considering cloud computing?
What role should jurisdiction play in a decision about whether to adopt cloud computing?
What should I be looking for in the contract with my service provider?
What are the best practices for decision-making around cloud computing?
About the author
Wednesday, April 13, 2011
Join the discussion about Dalhousie University and Cloud Computing
Dalhousie University, like many other Canadian post-secondary institutions, is engaging in a deep conversation with students, faculty and staff about the possibility of moving e-mail and other IT services to the cloud. As part of that conversation, the university is hosting a special forum on privacy and the cloud. Here's the details:
“A Forum on Privacy Laws, Cloud Computing and Impact to IT Strategy”Presentation Date: Monday, April 18th, 2011 2:00-5:00 (Rowe Potter Auditorium)
Information Technology Services at Dalhousie University is exploring a number of opportunities with emerging “Software-as-a-Service” or “Cloud Computing” initiatives. Cloud computing introduces a number of potential concerns around security, privacy, data ownership and data stewardship.
In an effort to address concerns and increase awareness around the legal, policy and academic implications, Dalhousie has invited professionals in a number of areas to speak and take part in a panel discussion on these topics.
David Fraser, Partner, McInnes Cooper
Mr. Fraser will speak to Canadian and American laws in relation to cross border data transfer, privacy and access to information.
Dwight Fischer, CIO, Dalhousie University
Mr. Fischer will speak to the technology challenges and changes taking place and the impact on Dalhousie.
Paul Jones, Policy & Education Officer, Canadian Association of University Teachers
Mr. Jones will speak to the concerns around privacy and academic freedom, specifically how it relates to faculty.
Come and take part in the discussion on April 18th from 2:00 to 5:00 p.m!
Join in the online conversations now at blogs.dal.ca/connectedU
Wednesday, March 02, 2011
Is university faculty e-mail subject to access and privacy laws?
Dan Michaluk has just blogged about an interesting case out of Alberta (University of Alberta v. Alberta (Information and Privacy Commissioner), 2011 ABQB 100) that may have a significant impact on freedom of information law, particularly in universities. It will also have an impact on cloud computing decisions by universities. The Canadian Association of University Teachers takes the position that faculty e-mail are not under the "custody and control" of the educational institution. If this is found to be the case, faculty e-mail is not within the ambit of access to information laws at all and the privacy protection provisions of those laws. And, if that's the case, such e-mails are not covered by laws that are meant to regulate the export of personal information (out of fear of the USA Patriot Act). Stay tuned ....
See Dan's post: Alberta Court set to Hear Faculty E-mail Case « All About Information
Thursday, February 24, 2011
Ryerson University looks to the cloud
Today, I had the great pleasure of being one of the speakers at Ryerson University's broad consultation on the possibility of adopting cloud computing at the university. It was an incredibly high-quality event with a packed auditorium (in the middle of reading week, no less) and a very engaged audience.
The agenda is here: E-mail and Collaboration Tools Consultation | Email & Collaboration Tools Consultation.
My presentation is here:
If you can't see the embedded presentation, try this link: https://docs.google.com/present/view?id=ddpx56cg_415c4c8k5g5&interval=60
The full symposium was webcast live and will be available here:
- Morning session, including introductions, Ontario Commissioner Anne Cavoukian and me.
- Afternoon session, including presentations by Google, Microsoft, James Turk (Executive Director, Canadian Association of University Teachers), panel discussion and next steps by the University
If you want to see the many, many tweets which were sent out, search Twitter for #ryeprivacy.
UPDATE: Over at Slaw.ca, Dan Michaluk, who was at the symposium, has posted a few of his observations on the day: Commissioner Cavoukian says the Patriot Act is nothing.
