The Canadian Privacy Law Blog: Developments in privacy law and writings of a Canadian privacy lawyer, containing information related to the Personal Information Protection and Electronic Documents Act (aka PIPEDA) and other Canadian and international laws.
Friday, September 20, 2024
Sunday, April 16, 2023
Privacy Commissioner of Canada Loses in Federal Court against Facebook
Just this past week, the Office of the Privacy Commissioner of Canada was on the receiving end of a Federal Court decision that I would characterize as more than a little embarrassing for the Commissioner.
In a nutshell, the Commissioner took Facebook to court over the Cambridge Analytica incident and lost, big time.
You may recall from 2019, when the Privacy Commissioner of Canada and the Information and Privacy Commissioner of British Columbia released, with as much fanfare as possible, the result of their joint investigation into Facebook related to the Cambridge Analytica incident.
Both of the Commissioners concluded, at that time, that Facebook had violated the federal and British Columbia privacy laws, principally related to transparency and consent.
Because Facebook was not prepared to accept that finding, the Privacy Commissioner of Canada commenced an application in the Federal Court to have the Court make the same determination and issue a whole range of orders against the social media company.
The hearing of that application took place a short time ago and a decision was just released from the federal court this past week. It concluded that the Privacy Commissioner did not prove that Facebook violated our federal privacy law in connection with the Cambridge Analytica incident and made a few other interesting findings and observations.
Just a little bit of additional procedural information: under our current privacy law, the Privacy Commissioner of Canada does not have the ability to issue any orders or to levy any penalties. What can happen after the Commissioner has released his report of findings is that the complainant, or the Commissioner with the complaint’s okay, can commence an application in the federal court of Canada. This is what is called a de novo proceeding.
The finding from the privacy commissioner below can be considered as part of the record, but it is not a decision being appealed from. Instead, the applicant, in this case, the Privacy Commissioner, has the burden of proving to a legal standard that the respondent has violated the federal privacy legislation.
This has to be done with actual evidence, which is where the privacy commissioner fell significantly short in the Facebook case.
It has to be remembered that the events being investigated took place almost 10 years ago, and the Facebook platform is substantially different now compared to what it looked like. Then, if you were a Facebook user from that time, you probably remember a whole bunch of apps running on the Facebook platform. You probably were annoyed by friends who were playing Farmville and sending you invitations and updates. Well, these don't exist anymore. Facebook largely is no longer a platform on which third party apps will run.
In a nutshell, at the time, one of the app developers that used the Facebook platform was a researcher associated with a company called Cambridge Analytica. They had an app running on the platform called “this is your digital life”. It operated for some time in violation of Facebook's terms of use for app developers, hoovering up significant amounts of personal information and then selling and/or using that information for, among other things, profiling and advertising targeting. Here’s how the court described it:
[36] In November 2013, Cambridge professor Dr. Aleksandr Kogan launched an app on the Facebook Platform, the TYDL App. The TYDL App was presented to users as a sort of personality quiz. Prior to launching the TYDL App, Dr. Kogan agreed to Facebook’s Platform Policy and Terms of Service. Through Platform, Dr. Kogan could access the Facebook profile information of every user who installed the TYDL App and agreed to its privacy policy. This included access to information about installing users’ Facebook friends. ...
[38] Media reports in December 2015 revealed that Dr. Kogan (and his firm, Global Science Research Ltd) had sold Facebook user information to Cambridge Analytica and a related entity, SCL Elections Ltd. The reporting claimed that Facebook user data had been used to help SCL’s clients target political messaging to potential voters in the then upcoming US presidential election primaries.
One thing to note is that in 2008-2009, the OPC investigated Facebook and the Granular Data Permissions model that it was employing on their platform. Facebook said that the OPC sanctioned and expressly approved its GDP process after testing it after the conclusion of that investigation. They argued that the Commissioner should not be able to now say that a model it approved is inadequate. The Court didn’t have to go there.
In this application, the Privacy Commissioner alleged that Facebook failed to get adequate consent from users who used apps on Facebook’s platform, and failed to safeguard personal information that was disclosed to third party app developers. The Commissioner failed on both, but for different reasons.
In the court process, both the Commissioner and Facebook had the opportunity to put their best evidence and best arguments forward. Facebook was able to talk about their policies, their practices with respect to third party developers, and the sorts of educational material that they provided as part of their privacy program.
Ultimately, the court concluded that the Commissioner had failed to put forward strong evidence to lead to the conclusion that Facebook had not obtained adequate user consent for the collection, use and disclosure of their personal information when using the app in question, or apps more generally.
It’s interesting to me that the Court notes that the Commissioner did not provide any evidence of what Facebook could have done better, in their view, nor did it offer any expert evidence about what would have been reasonable to do in the circumstances. This is from paragraph 71 of the decision:
[71] In assessing these competing characterizations, aside from evidence consisting of photographs of the relevant webpages from Facebook’s affiant, the Court finds itself in an evidentiary vacuum. There is no expert evidence as to what Facebook could feasibly do differently, nor is there any subjective evidence from Facebook users about their expectations of privacy or evidence that any user did not appreciate the privacy issues at stake when using Facebook. While such evidence may not be strictly necessary, it would have certainly enabled the Court to better assess the reasonableness of meaningful consent in an area where the standard for reasonableness and user expectations may be especially context dependent and are ever evolving.
The Court also seems to be saying that the Commissioner was trying to suck and blow at the same time:
[67] Overall, the Commissioner characterizes Facebook’s privacy measures as opaque and full of deliberate obfuscations, creating an “illusion of control”, containing reassuring statements of Facebook’s commitments to privacy and pictures of padlocks and studious dinosaurs that communicate a false sense of security to users navigating the relevant policies and educational material. On one hand, the Commissioner criticizes Facebook’s resources for being overly complex and full of legalize, rendering those resources as being unreasonable in providing meaningful consent, yet in some instances, the Commissioner criticizes the resources for being overly simplistic and not saying enough.
The judge then found that Facebook was essentially asking the court to make a whole bunch of negative inferences in the absence of evidence, which they did not appear to try to obtain. Here’s the court at paragraph 72 of the decision:
[72] Nor has the Commissioner used the broad powers under section 12.1 of PIPEDA to compel evidence from Facebook. Counsel for the Commissioner explained that they did not use the section 12.1 powers because Facebook would not have complied or would have had nothing to offer. That may be; however, ultimately it is the Commissioner’s burden to establish a breach of PIPEDA on the basis of evidence, not speculation and inferences derived from a paucity of material facts. If Facebook were to refuse disclosure contrary to what is required under PIPEDA, it would have been open to the Commissioner to contest that refusal.
The judge then goes on to say at paragraph 77:
[77] In the absence of evidence, the Commissioner’s submissions are replete with requests for the Court to draw “inferences”, many of which are unsupported in law or by the record. For instance, the Court was asked to draw an adverse inference from an uncontested claim of privilege over certain documents by Facebook’s affiant.
I think there are a couple very important things to note here. The first is that the Privacy Commissioner’s report of findings, which was released with great fanfare and which concluded that Facebook had violated Canada's federal privacy laws, was essentially based on inadequate evidence. The court found it sadly lacking – not enough to convince the Court that it was more likely than not – but apparently this evidentiary record was entirely satisfactory for the purposes of the Commissioner’s investigation and report of findings.
The second thing to note here is that the court application was essentially the privacy commissioner's second kick at the can. More evidence could have been obtained for this hearing had they actually exercised their authorities under the legislation or under the rules of court. If they did that, they came to court with an inadequate evidentiary record.
The second main violation that was alleged by the Privacy Commissioner was that Facebook had failed to adequately safeguard user information that was disclosed to third party app developers. Essentially, the Privacy Commissioner's argument is that Facebook continues to have an obligation to safeguard all of the information even after a user has chosen to disclose that information to a third party app developer. Facebook took the view that the safeguarding obligation transferred to the app developer when the user initiated the disclosure to that app developer.
This is consistent with the scheme of the Act, in my view, because the responsibility to safeguard information and to limit its use falls on the organization that actually controls that information. Once it is given to an app developer for this purpose, it is under the control of that app developer and the obligation to safeguard it would rest with them.
The Court summarized the Commissioner’s argument on this point in paragraph 85:
[85] The Commissioner counters that Facebook maintains control over the information disclosed to third-party applications because it holds a contractual right to request information from apps. The Commissioner maintains that Facebook’s safeguards were inadequate.
[86] I agree with Facebook; its safeguarding obligations end once information is disclosed to third-party applications. The Court of Appeal in Englander observed that the safeguarding principle imposed obligations on organizations with respect to their “internal handling” of information once in their “possession” (para 41).
Very importantly here, though, is the statement from the court that companies can expect good faith and honesty in contractual agreements:
[91] In any event, even if the safeguarding obligations do apply to Facebook after it has disclosed information to third-party applications, there is insufficient evidence to conclude whether Facebook’s contractual agreements and enforcement policies constitute adequate safeguards. Commercial parties reasonably expect honesty and good faith in contractual dealings. For the same reasons as those with respect to meaningful consent, the Commissioner has failed to discharge their burden to show that it was inadequate for Facebook to rely on good faith and honest execution of its contractual agreements with third-party app developers.
This is the conclusion that the court reached. So, in the result, the court did not conclude that Facebook had violated PIPEDA in any way in association with the Cambridge analytica incident.
Another important observation, in my view, is that the Privacy commissioner of Canada did not actually investigate Cambridge Analytica itself, but focused all of its regulatory attention at Facebook. It is common ground that Cambridge Analytica and its principal violated Facebook's policies and developer agreements in taking user data off the platform and using it for secondary, unauthorized purposes. But they did not investigate Cambridge Analytica. They went after Facebook.
So what are the takeaways from this?
I think certain folks at the Office of the Privacy Commissioner should take an opportunity to think deeply about their approach to this entire thing. They should not be issuing flashy press releases and lobbing accusations in the way that they did without evidence that could support the allegations in a court of law.
I also think we need to think carefully about what this says for privacy law reform in Canada. The Commissioner at the time used his finding as an example of why he should be given order making powers and the powers to impose penalties. They even issued a handy-dandy table in which it concluded:
Because “Facebook disputed the validity of the findings and refused to implement the recommendations,” this should lead to the result that:
“The Office of the Privacy Commissioner of Canada’s interpretation of the law should be binding on organizations.
To ensure effective enforcement, the Commissioner should be empowered to make orders and impose fines for non-compliance with the law.”
Almost certainly, if he’d had those powers, he would have imposed orders and fines on Facebook, based on what the Court concluded was inadequate evidence. The Court even disagreed with the Commissioner’s interpretation of the law.
If we are going to have fines and orders under PIPEDA’s replacement, which seems inevitable, the OPC should NOT be in a position to impose them. The OPC should be the prosecutor, recommending any such fines or orders to a tribunal that will not show any deference to the Commissioner.
And finally, this offers some certainty that once information has been disclosed to a third party, it is the third party’s legal obligation to safeguard it. The OPC clearly thought that the obligation remained with the company where it originated, but that view was not shared with the court.
After the OPC filed its application in court, Facebook filed a judicial review application to have the whole thing thrown out. Facebook was not successful on that, mainly because they filed late and were not entitled to an extension. Regardless, there are some very interesting things in that decision, which I’ll discuss in an upcoming episode.
Wednesday, June 08, 2011
Facebook's facial recognition system should help users control their privacy (but doesn't)
Facebook is edging back into the privacy spotlight with the expected global roll-out of assisted tagging of photos using facial recognition. The service scans uploaded photos for faces and suggests tags for the people in them. (See: Facebook's Latest Privacy Settings Shadiness Invades Your Drunk Pics - Gizmodo.)
What I'd like to see is the service being used in reverse: alert me if someone posts a photo of me on Facebook. If it can help someone tag me, it can surely recognize me in untagged photos and give me a heads' up. Just a thought of using the technology to let users control (or at least know about) others posting photos of them.
Friday, April 08, 2011
Presentation: Social media and the multi-generational workplace
I just gave a professional development presentation for the Canadian Bar Association on Social Media and the Multi-Generational Workplace. Since there's a definite privacy angle, I thought it might be of interest to readers of this blog.
Here's the link in case the embedded presentation isn't showing up for you: https://docs.google.com/present/view?id=ddpx56cg_444ffh725f3&interval=30.
Wednesday, April 06, 2011
Quebec court sends Facebook class-action packing to California
The Quebec Superior Court has just declined jurisdiction over a proposed class-action lawsuit against Facebook over its privacy policies and practices by upholding the choice of law and forum selection clause in the Facebook Terms of Use. Check out: St-Arnaud c. Facebook Inc., 2011 QCCS 1506 (CanLII)
Saturday, March 05, 2011
BC NDP demanding social media login credentials
In the last week, there have been reports that the British Columbia New Democratic Party has been demanding the social media login credentials from candidates for the leadership of the party (see: B.C. NDP candidate in social-media standoff with party bosses - The Globe and Mail). All of the candidates have provided this info, except for one who -- quite rightly -- challenges this an an invasion of privacy.
We've heard in the past about employers asking for this sort of information and then backing off when facing a fire-storm of criticism. I can appreciate that the party is hoping to avoid any surprises, but this, in my view, seriously crosses the line. People use their Facebook accounts not only as a trove of embarrassing photos and journals of indiscretions, but also as a primary means of communicating with friends and family. I have close friends who I exclusively communicate with via Facebook. Would it be reasonable for an employer or a political party to ask for my GMail login? Phone records? All my photo albums? My journals? Crappy poetry written in high school (for the record: that was hypothetical; I wrote no poetry in high school)? The notes my mother left me in my lunchbox?
Come on, people. Just because it's easy and just because some people relent and hand it over, does not make it reasonable. It is not reasonable to ask and it is not reasonable to provide it.
It should also be noted that handing over your Facebook login credentials is a violation of the site's terms of use, which could not be more clear:
4.8 You will not share your password, (or in the case of developers, your secret key), let anyone else access your account, or do anything else that might jeopardize the security of your account.
The Information and Privacy Commissioner of BC is on the case and it will be interesting to see what she concludes.
My personal conclusion: any political party that demands this sort of information doesn't care at all about privacy and doesn't deserve to govern. Any candidate who acquiesces to this doesn't deserve to be elected.
Nova Scotia Court of Appeal favours open courts over youth privacy in Facebook defamation case
Yesterday, the Nova Scotia Court of Appeal issued a decision (AB v Bragg Communications Inc, 2011 NSCA 26) denying a child-plaintiff's application to proceed in a defamation action under a pseudonym and to impose a publication ban on the defamatory materials. The case involves a fake Facebook profile created by an unknown person and the dissemination of defamatory messages via that profile. The plaintiff sought the court's assistance in tracking town the intended defendant based on the IP address. At the original hearing, the judge denied the application to proceed under a pseudonym, which was upheld by the Court of Appeal. In short, the open courts principle trumps her concerns.
Since I was one of the lawyers working for the young girl who sought the application, you should read Dan Michaluk's summary for an unbiased view: Nova Scotia CA Favours Open Courts Over Youth Privacy in Facebook Defamation Case « All About Information.
Monday, February 21, 2011
Court Grants Ex Parte Order to Preserve Facebook
Last month, one of my partners made an application before the New Brunswick Court of Queens bench for an unusual ex parte order for the preservation and production of the contents of plaintiff's Facebook account. The order and reasons are here: Sparks v. Dubé, 2011 NBQB 40 (CanLII).
It's an unusual situation, which is well summarized by Dan Michaluk: Court Grants Ex Parte Order to Preserve Facebook « All About Information.
Tuesday, December 28, 2010
Class action lawsuit? There’s an app for that
Just posted over at slaw.ca:
Class action lawsuit? There’s an app for that — SlawYou may have seen the recent Wall Street Journal article on the privacy implications of certain iPhone, iPod Touch and Android apps that disclose information to advertising networks without the explicit knowledge of the user. It didn't take long, but now a class action lawsuit filed in California against Apple for allowing this to happen. See: Apple sued over privacy in iPhone, iPad apps | Apple - CNET News.
I think that this lawsuit is directed at the wrong party (Apple Computer Inc.) and, if it is at all successful, will be harmful to the internet.
This is similar to going after Facebook for everything that their app developers do. Where on party provides a platform (in this case, a mobile device) and another party builds applications on that platform, the key issue that needs to be addressed where privacy is concerned is “where should accountability for privacy lie?” Getting it wrong will stifle innovation in this currently burgeoning area of the Internet ecosystem. Placing all the responsibility on the platform provider will discourage innovators from making new technologies available to the public, to the detriment of those users who are supposed to be protected by privacy rules. Instead, third-party service and application providers should be responsible to users (and to the courts) for their collection, use and disclosure of personal information.
Just imagine what might happen if the already restrictive Apple is found liable for providing app developers too much latitude in structuring their apps. Would this encourage innovation in applications for users? Nope.
Thursday, December 16, 2010
Facebook implements facial recognition, silent on privacy
Facebook has just announced that it is implementing facial recognition software to "make it easier to tag your friends" in photos. It will make tagging the same person over and over in an album much easier, but their blog post (Making Photo Tagging Easier) doesn't address privacy at all. I'm surprised by this, given that Facebook has been much more vocal and upfront about privacy as of late.
Wednesday, December 08, 2010
South Korea investigates Facebook for allegedly breaching privacy laws
Facebook is facing scrutiny and an investigation by data protection authorities in South Korea for allegedly not getting user consent before collecting personal information, though the site's terms and conditions do a standard job of covering the topic. See: South Korea: Facebook Doesn't Comply With Our Privacy Laws
Tuesday, November 30, 2010
Facebook sued for HAVING privacy controls
TechCrunch is reporting that Facebook is facing a patent infringement lawsuit in the US for having privacy controls. Yup, you heard that right. The plaintiff is alleging that Facebook's privacy controls infringe a prior patent.
You simply can't win in this world.
Here's a blurb:
Facebook Sued For Having Privacy Controls In Place. Yes, Seriously.... In short, because Facebook enables people to have some control over their privacy on the popular social networking sites by effectively letting users decide which information you share with whom, Walker Digital believes the company infringes one of its “inventions”.
Provided I’ve understood the complaint correctly and the whole thing isn’t an early April Fools joke, this whole suit is just plain laughable.
In a reaction to the Bloomberg piece, a Facebook spokesperson said they would fight the suit vigorously, calling it “completely frivolous”. This time, I can’t help but agree with them.
You can read the full docket over at Justia.
Monday, November 29, 2010
Ottawa Citizen: On guard for privacy
The Privacy Commissioner, Jennifer Stoddart, is the subject of a very complimentary editorial in today's Ottawa Citizen.
On guard for privacyOTTAWA CITIZEN NOVEMBER 29, 2010 7:55 AM
The rule for political survival under Stephen Harper's government seems to be: smile and nod, and hope no one notices you. So it's a nice surprise that the prime minister has nominated Canada's high-profile privacy commissioner for re-appointment.
Jennifer Stoddart is no sycophant. And she seems to have avoided the administrative and budgetary pitfalls that claimed the careers or marred the work of other officers of Parliament. Seven years ago, she took over an office in disarray, and turned it into an internationally recognized storehouse of expertise. Her office deals with a large workload. She often has to pronounce on questions while they are in the headlines. There's an urgency to every matter she takes on, because when an individual's privacy is under threat, a remedy delayed is a remedy denied.
Most recently, she's expressed concern about how governments will manage the information they gather on airline passengers. Notably, though, she doesn't rail against the whole concept of data collection. She's not a slavish defender of privacy at the cost of every other consideration. Her advice on airline security, as in all matters, is balanced and sensible. If a policy has an unwarranted or unnecessary effect on privacy, Stoddart will point out ways the government can mitigate those effects. When there is a clear breach, though, she doesn't mince words. She recently said Veterans Affairs' treatment of veteran Sean Bruyea was "alarming" and might be an indicator of a systemic problem. Stoddart's office has been pushing Facebook to make changes for several years, and has criticized a careless mistake Google Inc. made in collecting information for its Street View application.
In any era, Canadians would be lucky to have a privacy commissioner ready to denounce and recommend fixes for an egregious but conventional breach of an individual's rights, as happened in the Bruyea case. Stoddart, though, is particularly suited for this age, when new kinds of co-operation between states, new global business models and new territories in cyberspace are forcing privacy advocates to keep one step ahead.
Technology is changing fast. One gets the sense, though, that Stoddart finds that exciting, as well as challenging. She's no Luddite. She wants to improve the world of social media, not sneer at it. She treats privacy as an essential living element of 21st-century citizenship. That's important, because when privacy advocates buy into a binary world view that sees privacy and engagement as opposing principles, that encourages the developers of new technology to dismiss privacy as the concern of a bygone era.
There will be a lot of work to do in the next few years, as governments continue to refine their security protocols and as cyberspace takes on new forms. No public servant should develop a sense of entitlement, but Stoddart shows no signs of doing so. She's working hard, getting results and is eminently qualified to keep leading this fight for the next few years.
Stoddart has been nothing but fair to this government, and has given it no reason to punish her. It's quite possible, though, that her independent spirit and sharp mind will prove inconvenient to any government on the receiving end of one of her reports. The Harper government, to its credit, has shown itself willing to take that political risk for the good of the country.
Sunday, October 24, 2010
Privacy for Sale: The Real Cost of Social Networking
This month's edition of The National magazine (National (English) - October/November 2010) has a significant multi-page article on privacy and social networking, featuring interviews with me, Michael Geist, Ariane Siegel and Jennifer Stoddart.
You can download the entire article in PDF here.
Tuesday, October 19, 2010
Commissioner to initiate new investigation of Facebook, perhaps?
It appears that another investigation of Facebook by the Privacy Commissioner may be in the offing as it is revealed that the site passed -- perhaps unwittingly -- user info to advertisers and applications. See: Personal info slips through Facebook into advertisers’ hands - The Globe and Mail.
Wednesday, October 06, 2010
Facebook offers additional privacy features
Today, in what has been speculated to be phase one of significant announcements in the coming days, Facebook has revealed some important new features to increase user control over personal information. First, the company has unveiled a completely redesigned "groups" feature that allows you to more easily share information with smaller groups of friends, rather than all your "friends" or the world at large. The second is the ability to download the information that Facebook has about you. Read: Gawker: New Facebook Offers Cliques for Privacy, Techcrunch: This Was Just Phase One Of Facebook’s “Lockdown” — Redesign Still Coming and the Official Facebook Blog: Giving You More Control.
Sunday, September 26, 2010
Facebook now anticipating and responding to privacy questions in Canada
CTV News is reporting that when Facebook launched their location-based service "Places" in Canada, the company did more than just have a teleconference with reporters to gush about how cool it is. Much of the call was spent talking about privacy, which is key to managing the inevitable privacy questions that any such product will raise in Canada. That's simply the new reality and good on Facebook for anticipating the questions and dealing with them up front. See: CTV News | Facebook tries to head privacy critics off at the pass.
Thursday, September 23, 2010
Queensland Privacy Commissioner calls Facebook suspect because of its profit motive
A day after the Canadian Privacy Commissioner stated that Facebook had gotten its house in order, the Privacy Commissioner of Queensland, Australia, has piled on the social networking site.
I have to take issue with some of her comments. She claims that Facebook is deceptive because it bills itself as a site for users to share and connect with friends, while its motives are to make money.
Give me a break. I've had issues with Facebook and their policies, but the suggestion that somehow they are suspect simply because it's a for-profit venture does nothing to move the privacy discussion forward. This is a notion I've been hearing more and more from speakers at conferences. Feel free to criticize them for for what they do or how they do it. Even be suspicious of their motives, but never lose sight of the fact that the service is what it is only because they make money.
Facebook is free to all of its users, paid for by advertisers. The company operates multi-million dollar data centres loaded with expensive servers. Bandwidth isn't cheap, either. Would they have 500,000,000 users if they required each of them to pony up cash? Nope. Most of the internet is advertising supported and users are used to online services being free.
Part of the implicit contract that users have with almost all free services (broadcast TV included) is that it is paid for by ads. If the ads don't generate enough revenue, the users either have to pay or the service goes away. Often, if the users have to pay, they go away and the service goes away. This, in and of itself, is really a non-issue and Facebook is not at all unique in this.
Feel free to criticize Facebook for its privacy policies, its privacy practices and how it manages user information, but don't confuse the issue by pointing to the simple fact that they make their money from advertising.
Here is the full article from iTnews.com.au:
Facebook slammed for ‘deceptive’ approach - Security - Technology - News - iTnews.com.auQueensland Privacy Commissioner Linda Matthews has criticised Facebook for deceiving potential users about its purpose.
Speaking on a panel at the World Computer Congress in Brisbane, Matthews highlighted the "enormous power" wielded by the social network with more than 500 million users.
Facebook promoted itself as a community; a place to share and connect with other human beings. But like most companies, its goal was to make money, she said.
"There's nothing wrong with making money; what's wrong is that it deceives potential users about that," Matthews said.
"There's a big difference [to users] between choosing to share your personal information to make friends, and sharing your personal information to make someone lots of money."
Corporate advisory lawyer Anna Sharpe, who was also on the panel, described her work on brand networks, which companies used to build rapport with their customers.
Rather than the vague, oft-used statement, "we will use your information for marketing", Sharpe said companies should disclose the information stored, its use and the parties that may access it.
"Given the complexity, I think the onus is on organisations to be a lot clearer on their privacy wordings," she said.
Although companies like Facebook, Google and Sun Microsystems have previously claimed that privacy was a thing of the past, panellists said the case for privacy still could be won.
"The auction is in full swing," said Goethe University professor Kai Rannenberg, addressing the session's theme: "Privacy ... going, going, gone?"
Rannenberg highlighted "privacy gateway infrastructure components" used by mobile telcos T-mobile Germany and Deutche Telekom that allowed users to determine how their information was used and with whom it was shared.
Personal information, he said, was an asset, and privacy required: the minimisation and decentralisation of data; empowering users; user-controlled identity management; privacy by design; and privacy standards.
Fellow panellist and Australian Privacy Foundation chair Roger Clarke observed that privacy would become more of a concern for those born after 1995, the i-Generation.
He observed that as Generation Y - those born between 1980 and 1995 - faced the impact of having their information stored and published online, 'iGen' would become more careful.
"Youth have always been risk-talkers," Clarke said. "The big thing that's changed is not the behaviour; it's the impact of the behaviour, how long that data exists and how many people have access to it."
"iGens are already absorbing those messages ... What will actually happen is that the young generation of right now will be more privacy conscious and more privacy demanding than their predecessors were."
Former Australian Privacy Commissioner Malcolm Crompton noted, "privacy is a cloudy term", highlighting linked elements of control, trust, risk and accountability.
He said users could exercise "people power" by deciding whether or not to use Facebook, and any other consumer services that came with privacy risks.
Wednesday, September 22, 2010
Social media and the courts
I was honoured to speak on a panel this afternoon with Assistant Privacy Commissioner Chantal Benier and Professor Pierre Trudel at the Canadian Forum for Court Technology put on by the Canadian Centre for Court Technology. The panel was on the topic of the Ethical Implications of Technology. My presentation focused on social media and the courts.
For anyone who may be interested but wasn't there, here is my presentation:
Canadian Privacy Commissioner satisfied with Facebook resolution
This just posted on the OPC website:
News Release: Privacy Commissioner completes Facebook review - September 22, 2010Privacy Commissioner completes Facebook review
OTTAWA, September 22, 2010 – The Privacy Commissioner of Canada has finished reviewing the changes that Facebook implemented as a result of her investigation of the social networking site and has concluded that the issues raised in the complaint have been resolved to her satisfaction.
Privacy Commissioner Jennifer Stoddart today issued the following statement:
The changes Facebook has put in place in response to concerns we raised as part of our investigation last year are reasonable and meet the expectations set out under Canadian privacy law.
The investigation has resulted in many significant changes. Facebook has put in place measures to limit the sharing of personal information with third-party application developers and is now providing users with clear information about its privacy practices.
A major concern during our investigation was that third-party developers of games and other applications on the site had virtually unrestricted access to Facebook users’ personal information. Facebook has since rolled out a permissions model that is a vast improvement. Applications must now inform users of the categories of data they require to run and seek consent to access and use this data. Technical controls ensure that applications can only access user information that they specifically request.
We’re also pleased that Facebook has developed simplified privacy settings and has implemented a tool that allows users to apply a privacy setting to each photo or comment they post.
It has been a long road in arriving at this point. These changes are the result of extensive and often intense discussions with Facebook. Our follow-up work was complicated by the fact that we were dealing with a site that was continually changing.
Overall, Facebook has implemented the changes it promised following our investigation.
The issues related to the investigation – and, to be clear, I am only speaking about those issues rather than the site as a whole – have been resolved to my satisfaction.
However, our work with Facebook is not over.
While we are satisfied that the changes address the concerns raised during our investigation, there is still room for improvement in some areas. We’ve asked Facebook to continue to improve its oversight of application developers and to better educate them about their privacy responsibilities. We have also cautioned Facebook against expanding the categories of user information made available to everyone on the Internet – and over which users cannot control through privacy settings. As well, we had recommended that Facebook make its default settings for photo albums more restrictive than “everyone on the Internet” – though this concern has been mitigated to a large extent by Facebook’s per-object privacy tool.
Facebook is constantly evolving and we are actively following the changes there – as well as on other social networking sites. We will take action if we feel there are potential new violations of Canadian privacy law.
As well, we have received several further complaints about issues that were not part of our first investigation and we are now examining those. The new complaints deal with Facebook’s invitation feature and Facebook “Like” buttons on other websites.
Our ongoing work does not take away from the improvements Facebook has already made. Indeed, I would like to express my sincere appreciation to Facebook for the cooperation it has provided throughout our discussions. We recognize that some of the changes needed in order for Facebook to meet its legal obligations in Canada were complex and time-consuming to implement. Ultimately, Facebook has made several privacy improvements that will benefit its users around the globe. I believe we have also demonstrated that privacy protection does not stand in the way of innovation.
I would also like to offer my gratitude to the Canadian Internet Policy and Public Interest Clinic for bringing these important issues forward. CIPPIC recognizes how much Canadians value their privacy and has become an important voice for privacy rights in Canada.
A large focus of our work with Facebook related to third-party applications. It is our expectation that application developers will take note of our investigation. Like Facebook, many of them have an obligation to respect Canadian privacy law.
Finally, Facebook users also have a responsibility here. They need to inform themselves about how their personal information is going to be used and shared. The investigation has led to more privacy information and improved privacy tools – Facebook users should take advantage of those changes.
A backgrounder with detailed information about the investigation is available on the Office of the Privacy Commissioner of Canada’s website, www.priv.gc.ca.
The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy and the protection of personal information rights of Canadians.
The Commissioner's "backgrounder" is here: http://priv.gc.ca/media/nr-c/2010/bg_100922_e.cfm .