Showing posts with label government. Show all posts
Showing posts with label government. Show all posts

Thursday, March 14, 2013

Canadian government's new standard on privacy and web analytics

The CBC is reporting on the Canadian Government's relatively new Standard on Privacy and Web Analytics, which was launched earlier this year. The Treasury Board standard came into effect, but government departments are being given time to adjust contracts with outside providers of website analytic services.
The key provisions related to privacy are set out in Appendix and and Section 3.2 of Appendix A sets out the requirements that government departments must impose on third party service providers:
3.2 That contract must, at a minimum, contain provisions meeting the requirements as set out below.
a. A definition of "personal information" as meaning information collected or generated in the performance of the contract about an individual, including the types of information specifically described in the Privacy Act and also including information that may be linked or is linkable to an individual such as the website visitor's IP address.
b. A requirement that the third party appoint an officer within the organization to act as representative for all matters related to personal information and that the name and contact information for this third-party contact be provided to the government institution within 10 days of the awarding of the contract.
c. A requirement that the third party provide all of its employees, contractors and subcontractors with information on their privacy obligations when dealing with personal information disclosed or transmitted in relation to the work being performed under the contract or subcontract (the "work").
d. A requirement that the third party depersonalize the IP address prior to its storage in order that the full IP address cannot be reconstituted. This must be done through irrevocable truncation of the last octet of the IP address or through some other methodology that offers comparable privacy protection and has been approved by the Chief Information Officer Branch of the Treasury Board of Canada Secretariat.
e. A requirement that the third party not link, or attempt to link, the IP address or some unique identifier associated with a digital marker with the identity of the individual computer user.
f. A requirement that the depersonalized IP address, along with other data disclosed to the third party for Web analytics, be used only in accordance with the work, and that no subsequent uses or reuses of such data for any other purpose be allowed without the institution's express prior written authorization.
g. A requirement that the third party not disclose or transfer the depersonalized IP address or any other data disclosed to it except in accordance with the work, with the express prior written authorization of the institution, or if required to do so by law.
h. A requirement that the third party use only first-party cookies.
i. A requirement that the third party be prohibited from using techniques such as, but not limited to, interlinking, cross-referencing, data mining or data matching from multiple sources on the personal information collected in relation to the work, unless expressly pre-authorized to do so, in writing, by the government institution.
j. A requirement that the third party have security in place for the personal and depersonalized information that is at least commensurate with the Policy on Government Security.
k. A requirement that the third party safeguard the depersonalized IP address and other information disclosed in relation to the work, and that this information be retained for a maximum period of 6 months, after which time that information, including any backup copies, must be destroyed.
l. An audit provision whereby the third party may be audited at least once annually, at a date to be determined by the Government of Canada, to ensure compliance with these requirements.










Friday, January 11, 2013

Government release on the loss of personal information of 583,000 Canadian student loan recipients

Here is the (ironically titled) media release regarding the loss of personal information of more half a million Canadians' personal information. Note that the government has been aware of this breach for over a month and chose to issue the release on a Friday afternoon. Also note that the "new policy" described suggests that storing this information on an unencrypted portable hard-drive was acceptable under the previous policy.

Protecting Canadians' Personal Information at HRSDC

January 11, 2013 13:02 ET

Protecting Canadians' Personal Information at HRSDC

OTTAWA, ONTARIO--(Marketwire - Jan. 11, 2013) - The Honourable Diane Finley, Minister of Human Resources and Skills Development, has issued the following statement regarding the loss of an external hard drive from an HRSDC office in Gatineau, Quebec which contained personal information of 583,000 Canada Student Loans Program borrowers between 2000-2006:

Full details are available in the attached backgrounder.

"I want all Canadians to know that I have expressed my disappointment to departmental officials at this unacceptable and avoidable incident in handling Canadians' personal information. As a result, I have directed that departmental officials take a number of immediate actions to ensure that such an unnecessary situation does not happen again.

"The department will be making every effort to contact the individuals whose information was lost. This includes direct notification to those for whom we have current contact information. I am releasing all details on the breach publicly and we will be working with a number of external partners to ensure that Canadians are made aware of the data loss. The Department is continuing its investigation. The Office of the Privacy Commissioner has been consulted. My office has engaged the Royal Canadian Mounted Police on this matter, given its serious nature.

"I have requested that HRSDC employees across Canada receive comprehensive communications on the seriousness of these recent incidents and that they participate in mandatory training on a new security policy to ensure that similar situations do not occur again. Further, I have instructed that the new policy contain disciplinary measures that will be implemented for staff, up to and including termination, should the strict codes of privacy and security not be followed.

"On behalf of our Government, I want to reassure Canadians that we are serious about protecting their personal information. As Minister, I will ensure that every effort is taken so that HRSDC meets the expectations of Canadians in keeping their information safe and secure."

This news release is available in alternative formats on request.

BACKGROUNDER

In late 2012, the department of Human Resources and Skills Development Canada (HRSDC) informed the Office of the Privacy Commissioner of the loss of a USB key, which contained the personal information of over 5,000 Canadians.

While reviewing this incident, departmental officials learned of a subsequent serious loss of Canadians' personal information.

Although the search is ongoing, an external hard drive has been deemed lost from an HRSDC office in Gatineau, Quebec.

The Department is continuing its investigation. The Office of the Privacy Commissioner has been consulted. The office of the Minister has engaged the Royal Canadian Mounted Police on this matter, given its serious nature.

Details regarding loss of the hard drive

A hard drive containing personal information on 583,000 Canada Student Loans borrowers dated from 2000-2006 has been deemed lost at an HSRDC office in Gatineau, Quebec, although the search is ongoing.

The file contained information including student names, dates of birth, Social Insurance Numbers, addresses and student loan balances from recipients across the country (except Quebec, Nunavut and the Northwest Territories as they manage their own student loan programs). Personal contact information of 250 HRSDC employees was also on the hard drive.

No banking or medical information was included on the drive.

The client information was saved onto an external hard drive as a back-up storage option.

Timeline of events

November 5, 2012: A HRSDC employee discovered that an external hard drive was missing. Search efforts began.

November 28: The Departmental Security Officer was notified.

December 6: Discovery that personal information of Canada Student Loans Program clients was on the hard drive.

December 14: The Office of the Privacy Commissioner was notified.

January 7: The incident was referred to the Royal Canadian Mounted Police.

January 11: Canadian public was informed of the incident.

Process for inquiries and more information

HRSDC is sending letters to individuals affected, for whom we have current contact information, to advise them of the incident and what steps to take to help protect their personal information.

A toll-free number has been set-up at 1-866-885-1866 (or 416-572-1113 for those outside of North America) for individuals to verify if they are affected by this incident, and to ask additional questions regarding this issue. Hours of operation will be 8:00 a.m.-8:00 p.m. (EST), 7 days a week, starting Monday, January 14, 2013, for as long as needed.

People with a hearing or speech impairment and using a teletypewriter (TTY) can call 1-800-263-5883. Hours of operation will be 8:00 a.m. -8:00 p.m. (EST), 7 days a week, starting Monday, January 14, 2013, for as long as needed.

All details on this incident and how Canadians can protect their personal information are available at http://www.canlearn.ca/eng/main/spotlighton/privacy/index.shtml

New HRSDC policy for storing secure information

The Minister has directed that the overall policy for security and storage of personal information at HRSDC be strengthened and improved. The highlights are:

  • New, stricter protocols to be implemented immediately. Portable hard drives are no longer permitted. Unapproved USB keys are not to be connected to the network;
  • Immediate risk assessments of all portable security devices used in the Department's work environment to ensure that appropriate safeguards are in place; these assessments will continue on a regular, ongoing basis;
  • Mandatory training for all employees regarding the proper handling of sensitive information, including personal information;
  • Implement new data loss prevention technology, which can be configured to control or prevent the transfer of sensitive information;
  • Disciplinary measures that will be implemented for staff, up to and including termination, should the strict codes of privacy and security not be followed.

HRSDC "loses" sensitive personal information of another half MILLION Canadians

The CBC is reporting tonight that Human Resources and Skills Development Canada has lost a hard drive containing very sensitive personal information on more than five hundred thousand Canadians. This time, it was a portable hard drive and the information is about 583,000 student loan recipients.


Federal agency loses data on 583,000 Canadians - Nova Scotia - CBC News:
A portable hard drive containing personal information about more than half a million people who got student loans has gone missing, the federal government revealed Friday.

Human Resources and Skills Development Canada says the device disappeared from an HRSDC office in Gatineau, Que., in early November.

The hard drive had personal information on 583,000 Canadians who were clients of the Canada Student Loans program from 2000 to 2006. Borrowers from Quebec, Nunavut and the Northwest Territories are not affected.

The information on the missing hard drive includes:

  • Student names, social insurance numbers, dates of birth, contact information and loan balance of Canada Student Loan borrowers. 
  • Personal contact information for 250 HRSDC employees. 
The government says no banking or medical information was on the hard drive.

Letters are going out to everyone affected to tell them what steps to take to protect themselves.  

No evidence of fraud

So far, there's no sign that any of the missing data has been accessed or used for fraudulent purposes, but the government has called in the RCMP and alerted the office of the privacy commissioner.

"I want all Canadians to know that I have expressed my disappointment to departmental officials at this unacceptable and avoidable incident in handling Canadians’ personal information," said Human Resources and Skills Development Minister Diane Finley in a statement.

"I have requested that HRSDC employees across Canada receive comprehensive communications on the seriousness of these recent incidents and that they participate in mandatory training on a new security policy to ensure that similar situations do not occur again."
She says employees who fail to adhere to the new policy could be fired.

This is the second incident involving missing personal information that her department has faced in less than a month.

In late December, HRSDC revealed that a USB key containing personal information on about 5,000 Canadians disappeared in November.

Update: Check out the Government of Canada media release on this breach.

Friday, January 04, 2013

Privacy Commissioner confirms investigation into HRSDC privacy breach

The Canadian Press is reporting that the Office of the Privacy Commissioner will be investigating the huge privacy breach within Human Resources and Skills Development Canada that resulted in the loss of personal information of about 5,000 Canadians.

Very few details have emerged about this breach other than the fact that a USB device was lost that contained names, social insurance numbers, and disability/health information about the affected individuals. Surely HRSDC must know some important details, such as what HRSDC program was the information connected to, was the USB device used to move the data between HRSDC sites or for an employee to take work home? This is the sort of basic information that the victims need to know in order to gauge whether they're at risk of fraud or identity theft.

Hopefully, the investigation will be swift since there are 5,000 people waiting to find out.

From the Canadian Press:

Privacy czar to probe department's loss of USB key containing personal info

OTTAWA - The privacy watchdog will investigate a federal data breach in which the personal information of thousands of Canadians went astray.

The office of privacy commissioner Jennifer Stoddart says it received formal complaints after a Human Resources and Skills Development Canada employee lost a USB key containing the personal information — including social insurance numbers — of about 5,000 Canadians.

Anne-Marie Hayden, a spokeswoman for Stoddart, says the privacy commissioner has also taken close to 200 calls from people expressing concern about the breach.

Human Resources says an extensive search for the key continues.

The department has no evidence that information on the missing key has been used for fraudulent purposes.

A spokeswoman for Human Resources Minister Diane Finley calls the loss of the key a serious and completely unacceptable incident.

Monday, December 31, 2012

Privacy commissioner to investigate HRSDC privacy breach

According to a report in the London Free Press, the Office of the Privacy Commissioner of Canada appears to be planning to investigate the appalling privacy breach that was announced last week. The language is not as definitive as I would like, however:

Privacy commissioner to investigate security lapse | Canada | News | The London Free Press

LONDON, Ont. - The federal privacy commissioner is poised to launch a full investigation into a security lapse that lost the private information of about 5,000 Canadians.

“I think you can expect that we will be investigating the matter,” Anne-Marie Hayden, spokesperson for the Privacy Commissioner of Canada, said Monday.

The commissioner’s office has already received 100 calls and several official complaints about the loss of a USB stick that contained private medical, employment and education information, as well as Social Insurance numbers.

It would be gravely disappointing if the OPC does not do a full investigation of this breach along with strong recommendations to prevent it from happening again.

Government needs to be held to an even higher standard than the private sector. People do not have a consensual relationship with government. If you do not like how your bank handles your personal information, you can easily switch to another one. If you're not happy with Instagram's new privacy policy, you can close your account. You cannot do that with government. If Human Resources and Skills Development Canada is incompetent in safeguarding sensitive personal information and cavalier in its response, you can't go looking for another Canada Pension Plan provider.

If this breach involved one of the big California-based internet giants, you can bet there would be a full investigation and further calls for order-making powers and the ability to levy fines.

I hope to see a full and public investigation, followed by calls to amend the Privacy Act to bring it into line with more modern provincial statutes that make it an offense to willfully violate the privacy of Canadians.

Saturday, December 29, 2012

Government "loses" sensitive personal information on thousands of Canadians

Over the past week, Human Resources and Skills Development Canada has been notifying approximately 5000 people that their personal information has been lost. According to reports, the information was on a USB device that has been "misplaced". The information includes Social Insurance Number(SIN); surname; primary and, if applicable, secondary medical condition; birthdate; presence of other payers (e.g., workers' compensation); level of education; occupation type; and, Service Canada processing centre.

This is an ENORMOUS screw up by the Government of Canada. Unencrypted personal information should never be put on these devices as they are notoriously easy to lose. I am also surprised that the Privacy Commissioner's office, at least as quoted in the media, has not yet decided whether to do a formal investigation.
Personal info for thousands lost by federal government - Politics - CBC News

A federal government department says there is no evidence that missing personal information about thousands of Canadians has been used for fraudulent purposes.Human Resources and Skills Development Canada says an employee reported on Nov. 16 that a USB key containing personal information, including Social Insurance Numbers, of about 5,000 Canadians was missing.

The department, which handles a variety of files including pensions, old age security, employment insurance and childcare tax credits, says all those affected have been contacted.

A spokesperson said in an email Friday evening that the affected people have been advised of the incident and informed of the steps they can take to help protect their personal information.

HRSDC notified the privacy commissioner's office on Dec. 21 that the data had been lost.

About 60 people have already called an information line at the privacy commissioner's office expressing concern about the incident and complaints have already been filed.
"It's too early to say whether or not these will turn into official, full, investigations," said Anne-Marie Hayden, a spokeswoman for the privacy commissioner.
"We'd have to look at what we receive first and determine next steps from there."
HRSDC said it has seen no evidence that any of the information contained on the missing USB key has been used for fraudulent purposes.

"Nonetheless, we have advised affected individuals to carefully review and verify bank information, credit card information and other financial transaction statements as a means of safeguarding their personal information as a precautionary measure," the email said.

"We are currently analyzing this incident with the view of preventing a similar occurrence in the future," it added.

The commissioner's office is working with HRSDC in an effort to figure out what happened.

Each year, federal departments are required to report on how well they comply with privacy legislation.

In the 2010-2011 report — the most recent one posted on HRSDC's website — the department noted that it had been the subject of three complaints regarding how it handled personal information.

Friday, September 21, 2012

Ontario Information Privacy Commissioner blesses cross-border outsourcing of province's hunting and fishing license system

This decision from the Information and Privacy Commissioner of Ontario snuck under my radar this summer while I was on vacation.



This investigation is the result of a complaint brought by a Member of the Provincial Parliament about the Ontario Government's decision to outsource the processing and management of fishing and hunting licenses to a US-based business. The Commissioner did a thorough investigation and I am told they were pleasantly surprised by what they found. With regard to the USA Patriot Act, the Commissioner wrote:



The PATRIOT Act



The complainant has expressed concerns that the personal information of Ontarians will be subject to and accessible under American laws, including the PATRIOT Act. It is important to remember that, in Ontario, there is no legislative prohibition against the storing of personal information outside of the province or Canada. In other words, Ontario law, including the Act, does not speak to this issue. However, the Act and its regulations do require provincial institutions to ensure that reasonable measures are in place to protect the privacy and security of their records containing personal information. This applies regardless of where the records are located. Further, Ontario provincial institutions remain accountable for the actions of their agents or service providers, whether located in Ontario or in other jurisdictions.



I understand the complainant’s concern that the PATRIOT Act may be used by U.S. law enforcement agencies to access Ontarians’ personal information. However, the risk that law enforcement agencies may access personal information is not restricted to information held in the U.S. In fact, Canadian law enforcement agencies have similarly robust legal powers to obtain personal information held in Canada, and similar powers exist throughout most countries in the world. Further, law enforcement agencies in Canada, the U.S. and other countries have the ability to reach across borders to access personal information under various laws and agreements.



In this regard, the federal Privacy Commissioner of Canada has found that the privacy risks posed by the PATRIOT Act are similar to those found in Canada and, therefore, the privacy protection afforded by a U.S. service provider is comparable to that of a Canadian-based provider. In particular, the federal Privacy Commissioner has stated:



The risk of personal information being disclosed to government authorities is not a risk unique to U.S. organizations. In the national security and anti-terrorism context, Canadian organizations are subject to similar types of orders to disclose personal information held in Canada to Canadian authorities.


The federal Privacy Commissioner has also found that prior to the passing of the PATRIOT Act, U.S. authorities were able to access records held by U.S.-based firms relating to foreign intelligence gathering in a number of ways, including through formal bilateral agreements.3



Canadian legal scholars and practitioners have also carefully examined and commented on the privacy implications of the PATRIOT Act. Professor Michael Geist, Canada Research Chair in Internet and E-commerce Law, has written:



Claims that the enactment of the USA Patriot Act has dramatically altered the legal landscape are simply false. The U.S. law enforcement toolkit, which allows for the compelled, secret disclosure of personal information, pre-dates the USA Patriot Act by decades. Suggestions that the problem can be solved by keeping personal information from flowing outside the country are not realistic from a real-world, commercial perspective, where data is transferred and stored instantly on computer servers in other jurisdictions without regard for location.


David T.S. Fraser, a prominent Canadian privacy lawyer, has also been very clear in writing:



Most people are surprised to learn that some of the most “problematic” provisions of the USA Patriot Act are replicated in Canadian law in the Anti-Terrorism Act. We just don’t hear about it as much. People are also surprised to learn of huge amount of information sharing that takes place between agencies in Canada and their counterparts in the US.


The Act does not prohibit provincial institutions from outsourcing services on the basis that foreign law, including the PATRIOT Act, may apply. Similarly, there is no prohibition on the storage of personal information by government institutions outside the province. In fact, as noted by Professor Geist, outsourcing of technology services is a reality, whether by government agencies or private sector companies. Personal information may be subject to disclosure to law enforcement authorities, whether stored in the province or elsewhere. The critical question for institutions which have outsourced their operations across provincial or international borders is whether they have taken reasonable steps to protect the privacy and security of the records in their custody and control. I have always taken the position that you can outsource services, but you cannot outsource accountability. With this in mind, I now turn to consider what measures the Ministry has put into place in the circumstances of this complaint.





The decision is worth reading in its entirety: IPC - Office of the Information and Privacy Commissioner/Ontario | Reviewing the Licensing Automation System of the Ministry of Natural Resources: A Special Investigation Report [PC12-39].

Wednesday, September 29, 2004

Canadian government proposes regulations to require disclosure of employee data without consent for policing employment insurance program

Human Resources and Skills Development Canada has proposed amendments to the Employment Insurance Regulations to ensure that HRSDC has access to employee payroll information to detect fraud and abuse of the Employment Insurance Program. The National Post has a large front page story on this, saying that the fraud detection program has been on hold for nine months because of fears of transgressing federal and provincial privacy laws. I would have suggested that this information collection without consent was already allowed under PIPEDA, the Alberta Personal Information Protection Act and BC's Personal Information Protection Act. Better to be safe than sorry ...

Canada Gazette:

"REGULATORY IMPACT ANALYSIS STATEMENT

Description

The purpose of the proposed amendment to the Employment Insurance Regulations is to ensure that earnings verification programs conducted by Human Resources and Skills Development Canada (HRSDC), formerly Human Resources Development Canada, in cooperation with employers, satisfy the requirements of federal and provincial legislation pertaining to the disclosure of personal information.

As of January 1, 2004, subsection 7(3) of the federal Personal Information Protection and Electronic Documents Act (PIPEDA), applies to employers who fall under federal jurisdiction (i.e. airlines, banks, interprovincial transportation, radio and television broadcasting or telecommunications industries). Under the Act, these employers may not disclose personal information about an employee to HRSDC without the employee's consent unless HRSDC can demonstrate that it has the lawful authority to obtain this information. In addition, Quebec, British Columbia and Alberta have enacted privacy protection legislation requiring HRSDC to have lawful authority before it can obtain employee information from private sector employers in those provinces without employee consent. Similar legislation is being developed in other provinces.

With the implementation of the above-mentioned privacy legislation, regulatory clarification is required to ensure the ongoing functions of two verification programs administered by the Employment Insurance (EI) program: the Automated Earnings Reporting System (AERS) and the Report on Hirings (ROH) Program. These voluntary programs involve the comparison of EI claim files with current employee information provided to HRSDC by employers. HRSDC's lawful authority to obtain this information needs to be made explicit as a result of PIPEDA implementation. The AERS and ROH programs are currently under suspension (since January 1, 2004) and will be reinstated once the Regulations comes into effect.

Both the AERS and the ROH programs were developed in the late 1970s following recommendations made by stakeholders representing employers and employees. The level of participation has been considerable among employers because these programs are cost-effective and they help to alleviate the significant paper burden of requests for payroll information employers would otherwise receive.

Employees working for participants of AERS and the ROH benefit because the overpayment of EI benefits is minimized keeping financial hardship for the claimant to a minimum if repayments are required. This also means that subsequent administrative penalties or prosecutions are less likely because HRSDC is aware of the problem at the outset. As well, deterrence is achieved by encouraging participating employers to advise their employees that they participate in the AERS or ROH program. HRSDC provides employers with posters and inserts for use in informing employees that they share payroll and hiring information with HRSDC.

The proposed Regulations safeguards the privacy of Canadian workers and at the same time, it reduces the potential for making EI payments to claimants who are not lawfully entitled to receive them. The only information available to HRSDC that is collected from the verification programs, is information matching employees subject to an overpayment.

AERS and ROH are early intervention measures and serve as major deterrents to fraud and abuse of the EI program. HRSDC considers the use of regular and ongoing verification programs as crucial control mechanisms that assist HRSDC in meeting its obligations with respect to sound management practices and its fiduciary responsibility under the Employment Insurance Act.

To support the continuation of these voluntary verification programs, it is proposed that section 55.1 of the Employment Insurance Regulations be added to make explicit that HRSDC has the lawful authority to obtain employee information on a continuing basis. The information to be collected will include information in respect of the date of commencement of employment, duration of employment, amounts earned and reasons for separation from employment. It will apply to employers who (a) hired or recalled ten or more employees in a twelve-month period or expect to do so in the upcoming twelve months or (b) were required to issue ten or more records of employment in a twelve-month period or expect to do so in the upcoming twelve months.

...

Consultation

This proposed regulatory amendment was prepared by Human Resources and Skills Development Canada's Employment Program Policy and Design in consultation with Insurance Program Services, Investigation and Control, Legal Services and Privacy and Access to Information. External consultations have taken place with Industry Canada which is responsible for PIPEDA and the Department of Justice which agreed to the intent of the Regulations and drafted the wording. The Office of the Privacy Commissioner was also consulted during the developmental stages. The Employment Insurance Commission (including the Commissioners for Workers and the Employers) approved the Regulations in principle on November 14, 2003.

Compliance and enforcement

Existing compliance mechanisms contained in HRSDC's adjudication and control procedures will ensure that these changes are properly implemented. ..."