Showing posts with label pipeda damages. Show all posts
Showing posts with label pipeda damages. Show all posts

Wednesday, June 18, 2014

Henry v Bell Mobility: Another Federal Court case shows PIPEDA damages are hardly worth pursuing absent evidence of actual harm

The Federal Court, in the recently issued decision in Henry v Bell Mobility 2014 FC 555 (not yet on CanLII or the Court's site) has awarded a very modest sum of damages to a customer of Bell Mobility whose phone account was accessed by an impostor. At the hearing before the Federal Court, Bell did not contest liability so all the Court had to consider was the appropriate measure of damages. Nevertheless, the facts are relevant: An individual was able to convince a customer service representative employed by the mobile phone company to grant her access to the complainant's account. She was provided with general account information and the last seven numbers dialed. The impostor was also allowed to make changes to the account.

The claimant alleged that he suffered a lost business opportunity as a result of the impostor then contacting an intended business associate of the claimant. However, the claimant did not offer any compelling evidence to support this business opportunity. Instead of the compensatory damages of $35,500.00, punitive damages of $5,000.00, general damages of $5,000.00 and legal costs of $4,000.00, the Court awarded $2,500 in general damages plus $1,000 in costs. The complainant had argued that the Court should follow Chitraker v Bell, but the court was not convinced.

[26] Chitrakar is distinguishable from the current case in that here Bell Mobility has taken responsibility for the breach of Mr. Henry's privacy rights; it has put in place steps to better train CSRs; it has not in any way benefited from the breach; and, has acknowledged that Mr. Henry is entitled to damages in keeping with the jurisprudence of this Court. Bell Mobility argued that damages in the range of $1,500 - $2,000 was more than adequate to compensate Mr. Henry in these circumstances.

[27] Having considered all of the evidence and the jurisprudence and given the circumstances under which the woman cajoled the Bell representative to make the changes to the account and the breadth of the information disclosed it is my view that an award of $2,500.00 is appropriate. Mr. Henry was self-represented at trial although he had counsel on record assisting him earlier in the case. In all of the circumstances, costs in the amount of $1,000.00 will cover disbursements and legal costs.


Interestingly, there is no mention of Jones v Tsige; the court only discusses PIPEDA cases.

What's the moral of this story? Absent any actual, provable harm, PIPEDA damages are hardly worth pursuing.

Saturday, November 02, 2013

Some thoughts on Chitrakar v. Bell TV and damage awards under Canadian privacy law

On Thursday I posted about the new Federal Court case of Chitrakar v. Bell TV (Canadian Privacy Law Blog: Federal Court chastises Bell for accessing customer credit file without consent; $21K in damages) and promised I'd provide some thoughts once I'd had an opportunity to read the decision.

I managed to get a copy of the decision (Chitrakar v. Bell TV, 2013 FC 1103 [Google Doc]) from the Federal Court yesterday and it provides a lot of food for thought and some important questions for practitioners of Canadian privacy law.

In this case, the Court awarded the Applicant $21,000 in total, broken down as $10,000 in general damages, $10,000 in exemplary damages and $1000 in costs. The award of exemplary damages is completely attributable to the Court's view of Bell's handling of the case. They gave him the "royal run-around" and did not even show up in Court to respond to the Applicant's allegations. The Court obviously was not impressed.

But what of the $10,000 in general compensatory damages? What was alleged is that Bell TV had done a credit inquiry on the Applicant without the full knowledge and consent of the Applicant. (The inquiry was made one month BEFORE the customer had signed any agreement with Bell.) The credit inquiry, in and of itself, may have a negative impact upon a consumer's credit rating. The Applicant was subsequently denied a loan, but it was not proved that this was attributable to Bell's credit inquiry. So, in the end, the Court awarded $10,000 for a credit inquiry without consent that may or may not have actually caused any harm or damage to the Applicant.

The Court's discussion of how the damage award was arrived at is interesting:

[24] The fixing of damages for privacy rights’ violations is a difficult matter absent evidence of direct loss. However, there is no reason to require that the violation be egregious before damages will be awarded. To do so would undermine the legislative intent of paragraph 16(c) which provides that damages be awarded for privacy violations including but not limited to damages for humiliation.

[25] Privacy rights are being more broadly recognized as important rights in an era where information on an individual is so readily available even without consent. It is important that violations of those rights be recognized as properly compensable.

[26] The Court must bear in mind such factors as meaningful compensation, deterrence and vindication (see Vancouver (City) v Ward, 2010 SCC 27, [2010] 2 SCR 28).

[27] In this case, Chitraker had his rights violated in a real sense with potentially adverse consequences. Bell is a large company for whom a small damages award would have little material impact. Chitraker spent a considerable period dealing with the Bell bureaucracy and in pursuing his claim. These factors suggest that a damages award should not be minimalistic.

The Court found his rights were violated and there may have been consequences (but this was unproven). The Court also found that given the size of Bell, a small damage award would have little material consequence. On this basis, the Court awarded $10,000.

Damage awards under PIPEDA have generally been modest, such as $5000 for an inaccurate credit report that resulted in a loan application being denied and $4500 for a bank sending a customer's records to the customer's soon-to-be ex-spouse following receipt of a subpoena. In many other cases, the courts have declined to award damages at all.

This can and should be contrasted to the Jones v Tsige case from the Ontario Court of Appeal. In that case, which was outside of PIPEDA and established the tort of "intrusion upon seclusion" in Ontario, the Court found that general damages for non-pecuniary loss for that tort would range up to $20,000 and fixed the damages payable at the middle of the range.

While these damage awards appear to remain modest in light of the size of the companies involved, one can easily see how this could multiply in connection with a class-action. If a company adopted a procedure under which hard credit inquiries are routinely carried out before the customer signs any contract, each of those customers may be essentially entitled to $10,000 in compensation. Though we have not yet seen a class-action lawyer devise a way to get a class of complainants through a Privacy Commissioner investigation (which is a pre-requisite for getting to the Federal Court), I am sure that day will come and companies should be mindful that a bad practice spread across a customer base may give rise to a very large cumulative liability.

Friday, November 16, 2012

Federal Court awards minimal damages for good faith violation of PIPEDA by bank

The Federal Court of Canada, in Biron v. RBC Royal Bank, 2012 FC 1095, recently had an opportunity to consider a claim for damages under PIPEDA where the disclosure of personal information was made "in good faith". In connection with a separate proceeding, RBC Royal Bank responded to a series of subpoenas by providing information about a client (who had a joint account with one of the litigants). The individual complained to the Office of the Privacy Commissioner of Canada and then proceeded to the Federal Court seeking damages. Her claim was for punitive damages in the amount of $10,000, $5,000 for distress and inconvenience and $10,000 for moral damages. The court awarded only $2500, plus costs.

The Court noted:

[31] RBC’s conduct in the present matter does not justify an award of damages since any violation of the Act resulted from an error in good faith. According to RBC, its representatives acted in good faith when disclosing the personal information before a judge of the Superior Court, in the absence of any challenge of the subpoena. Furthermore, RBC is of the opinion that Mr. Poirier was authorized to represent Ms. Biron and to agree on her behalf to the disclosure of the personal information contained in the statements of their joint credit card. RBC alleges that Ms. Bouchard was misled when Mr. Poirier told her verbally that she could provide Ms. Grassby with all of the private information without obtaining a Court order and without restriction as to any of the information in the statements regarding Ms. Biron.

With respect to the calculation of damages:

[37] In Randall, above, the Court writes as follows about the damages awarded under section 16 of the Act:
[55] Pursuant to section 16 of the PIPEDA [the Act], an award of damages is not be made lightly. Such an award should only be made in the most egregious situations. I do not find the instant case to be an egregious situation.

[56] Damages are awarded where the breach has been one of a very serious and violating nature such as video-taping and phone-line tapping, for example, which are not comparable to the breach in the case at bar: Malcolm v Fleming (BCSC), Nanaimo Registry No S17603, [2000] BCJ No 2400; Srivastava c Hindu Mission of Canada (Québec) Inc. (QCA), [2001] RJQ 1111, [2001] JQ no 1913.

[38] The alleged damages must also result directly from the fault committed (see Stevens v SNF Maritime Metal Inc, 2010 FC 1137 (CanLII), 2010 FC 1137 at paras 28 and 29). The Court notes further that awarding damages under section 16 of the Act is discretionary (see Nammo, above).

[39] As to punitive damages, the Supreme Court of Canada instructs that these “are restricted to advertent wrongful acts that are so malicious and outrageous that they are deserving of punishment on their own” (see Honda Canada Inc v Keays, 2008 SCC 39 (CanLII), 2008 SCC 39 at para 62). In de Montigny, the Supreme Court stated as follows:

[47] While compensatory damages are awarded to compensate for the prejudice resulting from fault, exemplary damages serve a different purpose. An award of such damages aims at expressing special disapproval of a person’s conduct and is tied to the judicial assessment of that conduct, not to the extent of the compensation required for reparation of actual prejudice, whether monetary or not. As Cory J. stated:
Punitive damages may be awarded in situations where the defendant’s misconduct is so malicious, oppressive and high-handed that it offends the court’s sense of decency. Punitive damages bear no relation to [page88] what the plaintiff should receive by way of compensation. Their aim is not to compensate the plaintiff, but rather to punish the defendant. It is the means by which the jury or judge expresses its outrage at the egregious conduct of the defendant.

(Hill v Church of Scientology of Toronto, 1995 CanLII 59 (SCC), [1995] 2 SCR 1130, at para 196)

[40] In the present proceeding, the Court is of the opinion that, in light of the facts of the case, the damages alleged by Ms. Biron can be tied to RBC’s error. The Court is of the opinion, moreover, that it must consider the fact that Ms. Biron asked RBC to stop disclosing her personal information on two occasions. RBC violated its obligations under subsection 7(3) of the Act by failing to properly protect the personal information of one its clients, a disinterested third party in the divorce proceeding between Mr. Poirier and his ex-wife.

[41] Ms. Biron is also claiming punitive damages in the amount of $10,000. There is, however, no evidence on record demonstrating that RBC committed acts against Ms. Biron that were so malicious and outrageous as to warrant an award of punitive damages.

[42] The only evidence submitted by Ms. Biron in support of her total claim for $15,000 in damages, that is, $5,000 for distress and inconvenience and $10,000 for moral damages, is limited to the representations she had to make to the Privacy Commissioner, the letters sent to RBC and the time spent in helping her spouse in defending himself again his ex-wife’s allegations resulting from the review of the money spent using the joint credit card.

[43] The Court therefore concludes that, given that Ms. Biron, as a third party in a divorce proceeding, objected twice to her personal information being disclosed, that she suffered humiliation under paragraph 16(c) of the Act and that the damages sought by Ms. Biron are directly related to RBC’s fault, the Court awards $2,500 plus interest and costs, to be paid to Ms. Biron by RBC.

Monday, July 09, 2012

Federal Court: No damages for trivial privacy breach

Once again, the Federal Court has shown that nominal or no damages will be paid for trivial breaches of PIPEDA. In Townsend v. Sun Life Financial, 2012 FC 550, the Applicant brought an application against Sun Life Financial for having misaddressed a piece of mail (which was returned unopened) and disclosing some medical information to the financial advisor involved in underwriting the policy.

The Applicant sought

(i) Payment of $352.56 for costs associated with the closing of the Investors Group retirement plans;
(ii) Declaration that the Respondent breached the PIPEDA and the fiduciary duties owed to the Applicant;
(iii) Declaration compelling the Respondent to publish notices of measures taken to avoid contravening the PIPEDA;
(iv) An award of $25,000.00 in damages;
(v) Costs before this Court; and
(vi) Any other relief this Court deems appropriate.

Though a (relatively trivial) breach was found, the application was dismissed.

The court noted, in its discussion of damages:

[34] In fact, contrary to the Applicant’s bald assertions, I do not accept that the Respondent has acted in an intentional, callous or egregious manner or in any other way that would indicate a complete disregard for the Applicant’s privacy interests. The fact that the Respondent has never denied having committed the errors is commendable. Plus, there is no evidence that the Respondent acted in bad faith or benefited commercially from the error, as acknowledged by the Applicant. It is also duly noted that the Respondent has apologized to the Applicant on numerous occasions (Respondent’s Record, Affidavit of Rosemary Knez, Exhibit “B”, p 8; Exhibit “D”, pp 11-12; Exhibit “F”, p 14) and even informed the Applicant of the measures implemented to avoid the re-occurrence of such errors (Ibid, Exhibit “D”, p 11). In my opinion, the Respondent promptly and effectively corrected its errors. It may be, as alleged by the Applicant, that the Respondent should have put these measures in place before the error occurred. Nobody should be held to a standard of perfection, and the Respondent already had a detailed protocol before the occurrence of what can only be considered as a human error.

[35] Moreover, the amount of damages sought is greatly out of proportion to the jurisprudence of this Court. Even in cases where the Court has found evidence of bad faith on the part of a respondent, the quantum of damages has been lesser than the order sought by the applicant. ...

[38] Taking into consideration the facts of this case, I am of the view that the disclosure of personal information was minimal and the inaccuracy in the Applicant’s address caused no injury. I accept that medical information is of the utmost sensitivity and should receive the highest degree of protection. In the instant case, and without diminishing the Applicant’s grief, the extent of the disclosure was minimal and was only disclosed to Mr. Townsend’s Advisor, who appeared not to have noticed the personal information and then promptly destroyed the letter upon request. Moreover, the Respondent genuinely apologized for the breach and promptly took steps to correct its policies and procedures. For those reasons, I do not consider it necessary to order the Respondent to correct its practices or to publish a notice of any action taken or proposed to be taken to correct its practices, or to award damages to the Applicant.

[39] Moreover, the Applicant has not provided any arguments or evidence for disbursing $352.56 for costs, associated with the closing of the Investors Group retirement plans. In any event, I see no plain and obvious link between these costs and the Respondent’s conduct. Accordingly, the Court exercises its discretion not to award these costs.

[40] For all of the foregoing reasons, this application is dismissed and each party shall bear its own costs.

Thursday, September 22, 2011

Federal Court slaps law firm for publishing a Privacy Commissioner finding that identified the complainant

The Federal Court of Canada has just issued a decision in Girao v. Zarek Taylor Grossman Hanrahan LLP, 2011 FC 1070 (CanLII), in which it found a law firm liable for having posted on its website a previous report of findings from the Office of the Privacy Commissioner of Canada along with a cover letter that identified the complainant.

As is clear from the decision, this arises from a long-standing string of litigation and privacy complaints involving the complainant and All State Insurance. The firm was counsel to the insurer. The firm had posted the document thinking it would be useful and instructive to its clients.

The complainant said that the firm posted her personal information without her consent and should be liable for $5,000,000 in damages.

The Court agreed that it was a breach of PIPEDA and awarded $1500. Here is the Court's discussion on the appropriate quantum of damages:

[53] Law firms providing advice to clients who deal with the personal information of their customers must be knowledgeable about privacy law and the risks of disclosure. Lawyers also have a public duty to protect the integrity of the legal process. The failure of lawyers to take measures to protect personal information in their possession may justify a higher award than that which would be imposed on others who are less informed about such matters.

[54] Section 16 of PIPEDA provides no guidance as to the quantum of damages that may be granted. Here the applicant is claiming that she suffered mental anguish as a result of the breach. In calculating what might be an appropriate amount to award for such harms, it may be useful to refer to relevant provincial legislation. Section 65 of the Ontario Personal Health Information Act, 2004, SO 2004, c 3, Sch A, may be of assistance in this context as it deals with the protection of medical information. Under that provision, the Superior Court of Justice may award damages, not exceeding $10,000.00 for mental anguish resulting from the willful or reckless contravention of the statute.

[55] In some cases, such as Nammo, a damages award may also be used to compensate a complainant for economic loss and expense incurred in dealing with the consequences of the breach. Here, the respondent points to the lack of any evidence in the applicant’s record that would support a finding that she had suffered any damages as a result of the posting. The respondent submits that the posting of the 2009 Report has not attracted adverse attention to the applicant in any way that would sustain a claim of damages. I agree that the record does not establish that the applicant suffered humiliation as a result of the breach.

[56] The applicant asserts that her mental health was seriously affected. The record before me does not make a connection between the treatment she is presently undergoing and the disclosure of the personal information. The one medical report filed is from a psychiatrist dated April 4, 2008; almost one year before the 2009 Report and letter were posted. The letter speaks to the applicant’s psychological condition and treatment as it related to the car accident, and not in any way to the subsequent disclosure of her personal information.

[57] According to an exhibit attached to Mrs. Girao’s affidavit, her husband became aware of the ZTGH posting as early as May 2009. Mrs. Girao referred to it in a letter to a PCC investigator in August 2009, presumably while the first complaint was under review. No steps were taken to inform ZTGH of this prior to the PCC’s call to Mr. Grossman in February, 2010. The information thus remained on the ZTGH website for a much longer period than might have been the case if the firm had been notified in a timely manner. It is not clear when it first appeared on the US website.

[58] The evidence is that 247 persons accessed the information on the ZTGH site prior to the filing of the complaint, including members of the firm itself. I expect that most of those persons would have been interested in the legal issues arising from the case and not in Mrs. Girao’s personal information. While the 2009 Report may still be accessed at the U.S. site and could be disseminated further by visitors to that site, the evidence indicates that the traffic to that page was minimal. In any event, there is nothing before me to indicate that there would be any broader interest in the applicant’s personal information or that it has been used in any way to cause any adverse effects to her health and welfare.

[59] There is no evidence before me that the respondent posted the information for economic gain. Mr. Grossman saw the 2009 Report to be an important precedent in the domain of insurance defence litigation and posted it on his firm’s website to inform their clients and others about the development of the law in that field. It is a common business practice for law firms to post such information. Success achieved by the firm in litigation may help to retain or attract clients. But there is no basis in law upon which Mrs. Girao would be entitled to an accounting of any benefits that may have flowed to ZTGH from the publication of the 2009 Report even if the value of such benefits could be calculated, which is unlikely.

[60] The nature of this breach fits somewhere at the low end between the breach committed in Randall: “the result of an unfortunate misunderstanding”; and that which was committed in Nammo: a “serious breach involving financial information of high personal and professional importance”. That is not the case here. While the information related to her claim for increased benefits, there was no disclosure of her financial status. The applicant submitted evidence of her current limited income on this application, but there is no evidence that this is due to the disclosure of her personal information or that she has missed opportunities to earn income as a result.

[61] The respondent was careless in posting but did not act in bad faith. ZTGH deleted from its website all references to the applicant as soon as it became aware that there was a concern. The law firm was negligent in not taking steps to ensure that any personal information about an identifiable complainant was removed before it posted the report. In the result I consider it appropriate to make an award of $1500.00.

Sunday, August 21, 2011

Federal Court awards minimal damages under PIPEDA

The Federal Court has recently released its second decision in which damages have been awarded for a breach under PIPEDA. Once again, the degree of damages are very low considering the costs associated with seeking redress before the Federal Court, but this very likely turns on the unique facts of the case.

In Landry v. Royal Bank of Canada, 2011 FC 687 (CanLII), the applicant was embroiled in what appears to be a bitter divorce and was hiding certain bank accounts from her spouse. Her bank was served with a subpoena to produce records. It appears that the bank did not follow its prescribed procedures (which would have avoided the entire mess) and ultimately faxed the applicant's bank records to counsel for her spouse. The applicant complained to the Office of the Privacy Commissioner of Canada, who found her complaint to be "well-founded and resolved".

The applicant started an application in the Federal Court, seeking at least $75,000 in damages. Neither party looked good appearing in court: the bank had not followed its procedures and tried to cover it up. The applicant was essentially caught trying to hide assets contrary to her legal obligations in connection with the divorce proceeding.

In the result, the Court concluded:

[32] Taking into account the contributory fault of the applicant, who was partially responsible for her own problems, and the serious breach committed by the respondent’s employee and its subsequent cover-up, the Court finds that the applicant suffered humiliation under paragraph 16(c) of the Act and that the respondent’s negligence warrants the applicant being compensated but does not give rise to exemplary damages as requested. Consequently, we fix an amount of $4,500 with interest and costs to be paid to the applicant by the respondent.

What is interesting is that the Court awarded any damages at all. The records, if they had been properly processed, would have been released to the applicant's husband and the personal result to her would have been the same. The Court could have said "no harm, no foul", but awarded damages (which are at least symbolic). This may hold out some hope for applicants that, in the right case, substantial damages may be awarded.

Tuesday, December 21, 2010

Federal Court awards PIPEDA damages due to inaccurate credit report

In what appears to be a break from the recent cases that have declined to award damages to applicants under PIPEDA, the Federal Court in Nammo v. Transunion of Canada Inc., 2010 FC 1284 has just recently awarded damages to an individual whose loan application was declined due to inaccurate information provided by a credit bureau.

The court awarded $5000 in damages after considering the principles to be applied by the court in awarding damages under the statute. It is really worth noting how cases such as Randall v Nubody's is distinguished.

[71] As indicated, PIPEDA provides the Court broad remedial powers and, in my view, s. 16 of PIPEDA permits the Court, in an appropriate case, to award damages even when no actual financial loss has been proven. In Randall v Nubodys Fitness Centres, 2010 FC 681, Justice Mosley found that an award of damages under s. 16 is not to be made lightly and that such an award should only be made “in the most egregious situations.” This is such a situation. In Randall, which involved the disclosure of how often the applicant used his gym membership to his former employer, Justice Mosley determined that the impugned disclosure of personal information was “minimal,” that there had been no injury to the applicant sufficient to justify an award of damages, that the respondent did not benefit commercially from the breach of PIPEDA, that the respondent did not act in bad faith, and, perhaps most importantly, that there was no link between the disclosure and the employer’s alleged retaliation against the applicant. The same cannot be said here. Not only was the disclosure of inaccurate information directly linked to the refusal of the loan and the associated injury to the applicant, but the respondent also profited from the disclosure and acted in bad faith in failing to take responsibility for its error and failing to rectify the problem in a timely manner. The violation of Mr. Nammo’s rights under PIPEDA was not “the result of an unfortunate misunderstanding,” as was the case in Randall. It was a serious breach involving financial information of high personal and professional importance. The fact that there is no precedent for an award of damages under PIPEDA should not impact the Court from making an award of damages where the circumstances and justice demands it. In my view, for the reasons that follow, this is such a case.

...

[74] The Supreme Court found that “to be ‘appropriate and just’, an award of damages must represent a meaningful response to the seriousness of the breach and the objectives of compensation, upholding Charter values, and deterring future breaches.” In my view, the same reasoning applies to a breach of PIPEDA, which is quasi-constitutional legislation.

[75] In Lavigne v Canada (Office of the Commissioner of Official Languages), 2002 SCC 53, the Supreme Court held that the Privacy Act, R.S.C.1985, c. P-21, was quasi-constitutional legislation that must be interpreted with its special purposes in mind. In Eastmond v Canadian Pacific Railway, 2004 FC 852, at para. 100, Justice Lemieux confirmed that PIPEDA also enjoys quasi-constitutional status:

I have no hesitation in classifying PIPEDA as a fundamental law of Canada just as the Supreme Court of Canada ruled the federal Privacy Act enjoyed quasi-constitutional status (see Justice Gonthier's reasons for judgment in Lavigne v. Canada (Office of the Commissioner of Official Languages, [2002] 2 S.C.R. 773 at paragraphs 24 and 25).

[76] Applying the Supreme Court’s reasoning in Ward to PIPEDA applications before this Court indicates that both the question of whether damages should be awarded and the question of the quantum of damages should be answered with regard to whether awarding damages would further the general objects of PIPEDA and uphold the values it embodies. Furthermore, deterring future breaches and the seriousness or egregiousness of the breach would be factors to consider.

[77] One of the central objects of PIPEDA is to encourage those who collect, use and disclose personal information to do so with a degree of accuracy appropriate to the use to which the information is to be put and to correct errors quickly and effectively. I have found that TransUnion failed to collect accurate information on the applicant. Further, when apprised of its error, it failed to address the complaint quickly and effectively. It further failed to quickly and effectively correct the inaccurate information it had disseminated. Lastly, it failed to take responsibility for its error, first blaming CBV, and then in this action attempting to attribute some blame to the applicant. In my judgment, these are circumstances that warrant an award of damages based on the considerations of vindication and deterrence.

Check out the following commentary:

Friday, November 19, 2010

Federal Court dismisses damages claims, considers what is compensable under PIPEDA

Dan Michaluk has a good summary of a very recent case from the Federal Court in Stevens v. SNF Maritime Metal Inc., 2010 FC 1137, where a claim for damages was dismissed as essentially an end-run around other potential causes of action. In this case, for wrongful termination. The applicant had apparently defrauded his employer and another company breached PIPEDA by disclosing the applicant's information to the employer. The employee was terminated and claimed damages for the resulting loss.

See: Case Report – Federal Court dismisses application, articulates what damages are compensable under PIPEDA « All About Information.

Friday, July 09, 2010