Showing posts with label pipeda findings. Show all posts
Showing posts with label pipeda findings. Show all posts

Monday, August 08, 2022

Video: OPC Finding: Spam messages sent by COVID testing contractor

The Privacy Commissioner of Canada just released a report of findings about a company contracted by the Airport of Montreal to do on-arrival covid testing. The company added the people tested to their mailing list and sent them unsolicited commercial electronic messages. The investigation was done jointly with the Information Commissioner of Quebec. The finding raises more questions than it answers.

The complainant in this case arrived at Montreal’s Trudeau International Airport. To comply with the Public Health Agency of Canada’s rules, the individual had to undergo on-arrival COVID testing. Conveniently, the Airport had contracted with a company called Biron Health Group to COVID testing directly at the airport. So the complainant went to the Biron site, provided them with his contact information, had this test done, it was negative and they emailed him the results.

A few days after receiving his test results, the complainant received an email from Biron promoting its other services. The complainant unsubscribed using the link in the email, and never received any further unwanted emails from them. The OPC said “he was shocked to receive such an email” and filed a complaint with the OPC.

The information and privacy commissioner of Quebec also investigated, but does not appear to have released a decision on the case. Instead, they just referred to the OPC’s finding.

During the course of the investigation, the company said it had “implied consent” under Canada’s Anti-Spam Law to send commercial electronic messages and was justified in doing so.

The OPC said there was no implied consent under PIPEDA, however. Here’s what they said specifically:

“The OPC is of the opinion that Biron could not reasonably assume that it had the implicit consent of travellers arriving in Canada. Biron was mandated by the government to conduct COVID-19 testing on travellers and paid by the Montreal Trudeau Airport. Biron was the only company offering this service at this airport. Consequently, travellers arriving in Canada had no choice but to do business with Biron to comply with the rules issued by the Public Health Agency. In this situation, these travellers would not normally expect their personal information to be used for reasons other than the mandatory testing.

Biron collected the travellers’ personal information for the purpose of conducting COVID-19 tests and sending them sensitive information related to their health, notably their test results. Biron was acting as a service provider for the airport. The OPC considers that Biron should have taken these circumstances into account before using the personal information for secondary marketing purposes and for its own purposes.”

Because Biron said they’d stop doing this, the OPC closed the file as “settled during the course of the investigation”. Case closed.

So why is this unsatisfying? There are a couple of key questions in the background, of interest to privacy practitioners, that are unaddressed and thus unanswered.

The first question is what law should actually apply to Biron in this case? The Privacy Commissioner refers to PIPEDA, our federal commercial privacy law. But we have a mess of privacy laws in Canada, more than a few of which could have been applicable.

Quebec has a provincial privacy law that applies to all businesses in that province, unless they are “federal works, undertakings or businesses”. Notably, international airports and airlines are “federal works, undertakings or businesses.”

There really is no doubt that if the testing facility had been off the airport property and operating on its own, the federal privacy Law could not have applied at all and instead the Quebec private sector privacy law would have been applicable. That means the federal Commissioner would have had no jurisdiction to investigate and it would have been entirely up to the Quebec Commissioner to do so.

So does that mean that simply being on or operating from airport property makes you a “federal work, undertaking or business”? I don't think that can really be the case.

Was it because the service they were providing is connected to international travel that places them within Federal jurisdiction? That seems dubious to me.

Were they within Federal jurisdiction because they had been engaged by the airport authority to provide this service? The airport authority is certainly a “federal work, undertaking or business”, but does that mean all of its contractors become “federal works, undertakings or businesses”? Again, I don't think that can really be the case. Would a taxi company given a concession to serve the airport automatically come under federal jurisdiction?

They were performing a function that was required by the Public Health Agency of Canada, but PHAC is subject to the federal Privacy Act, which never came up in the commissioner's report of findings.

This would be more tricky in a province like Alberta, where there is a provincial general privacy law that excludes PIPEDA and a health privacy law that does not. (Quebec doesn’t have a health-specific privacy law.)

Now, it may well be that both the federal and the Quebec Commissioners thought they didn't even have to consider jurisdiction because they got the result they were looking for during the course of the investigation: the company said they would change their practices and what might have been problematic under either the Quebec or the federal law has ceased. This seems likely to me, as in my experience the federal Privacy Commissioner's office we'll bend over backwards to avoid making any statements related to their jurisdiction that could come back to haunt them later.

This is not just a privacy nerd question, because other things turn on whether a company is a “federal work, undertaking or business”. If Biron is in that category, then provincial labour and employment laws don’t apply to that workplace. Instead, the Canada Labour Code applies. Other federal laws would also suddenly apply to them, not just our privacy law. If I was this company, I’d be left scratching my head.

The second element of this that is problematic is the interaction between our privacy laws and Canada's anti-spam law, also known as CASL. You will recall that the company said that they were justified in sending commercial electronic messages because they had an “existing business relationship” with the people who underwent testing. The Privacy Commissioner really did not address that, but instead focused on the Personal Information Protection and Electronic Documents Act which requires consent for all collection, use and disclosure of personal information. That consent can be implied, particularly where it would be reasonable for the individual to expect that their information will be used for a particular purpose in light of the overall transaction. The Commissioner found that individuals would not expect to have their personal information used for the secondary purpose and therefore there was no implied consent under PIPEDA.

But that is contrary to the express scheme of Canada's anti-spam law. Under CASL, an organization can only send a commercial electronic message to a recipient where it has consent to do so. That consent either must be express or implied. Implied consent under CASL is very different from implied consent under PIPEDA. CASL doesn't care about what the consumer's expectation might be. Consent can be implied where there is an existing business relationship. One of the possible existing business relationships is the purchase of goods or services from the organization in the previous two years. Presumably, buying a COVID test from a vendor would meet that threshold and there would be implied consent for sending commercial electronic messages. I do agree with the federal Privacy Commissioner that doing so because you are ordered to by the Public Health Agency of Canada would really be contrary to the individual's expectation.

But this really does highlight some of the absurd dissonance between our anti-spam law and our privacy law. Both use the term “implied consent”, but it means radically different things. From this finding from the federal Commissioner, it appears that he is of the view that implied consent under CASL does not lead to deemed implied consent under PIPEDA. CASL expressly permits it, but PIPEDA does not.

When it comes to consent for sending commercial electronic messages, one would think that the piece of legislation that was expressly written and passed by Parliament for that purpose would be the final say, but the OPC certainly does not seem to be of that view.

The Privacy Commissioner carried out this investigation along with the Quebec commissioner, but there is no mention of whether the CRTC, which is the regulator under CASL, was involved.

At the end of the day, I think an existing business relationship was created between the complainant and the company so that there would have been implied consent to send commercial electronic messages, regardless of whether the consumer would have expected it to do so. The Commissioner did highlight that the individual had to be tested under the rules for the Public Health Agency of Canada, leaving room to argue that had the individual gone to the company for a test for other purposes, that might have been a more direct commercial relationship between the parties.

As my friend and tech law colleague Jade Buchanan pointed out on Twitter, “CASL is completely unnecessary when PIPEDA will apply to the use of personal information (name email, etc.) to send commercial electronic messages.” Personally, I think that one of the reasons why we have CASL is because PIPEDA was seldom enforced by the OPC against spammers when clear jurisdiction to do so existed for more than a decade before CASL was created.

And there’s nothing in the pending Consumer Privacy Protection Act that would address this dissonance between our privacy and spam law.

So that is the finding, and we're left scratching our heads a bit or at least have unanswered questions about important matters of jurisdiction and the intersection between our privacy laws and our spam laws.

Tuesday, March 12, 2013

Insurance company inadvertently discloses personal information to complainant’s employer

In PIPEDA Report of Findings # 2012-009, the Office of the Privacy Commissioner of Canada considered a complaint brought by an individual against an insurance company for the disclosure of personal information to the complainant’s employer without her consent. The complainant was employed at a hair salon and was contemplating leaving her employer to set up a competing business. The complainant contacted an insurance company to obtain quotes on insurance for the new business and specifically requested that the company not call her back at her current workplace. Notwithstanding this direction, the company did and left a voice mail in the employer’s general inbox. The contents of a voice mail message were heard by the complainant’s employer, who terminated the complainant’s employment.

The Assistant Commissioner found that there had been a disclosure of personal without her consent, so the complaint was “well founded”. The Assistant Commissioner made specific recommendations to the insurance company, and it ultimately agreed to 1) implement a new procedure that minimizes the amount of information that employees leave in client telephone messages, and 2) amend existing procedures to ensure client contact information and messaging preferences are updated regularly to maintain accuracy. The insurance company also agreed to implement these procedures, so the complaint was also found to be “resolved”.

Privacy Commissioner faults two summer camps for exchanging information about camper

In two related complaints against two summer camps, the Assistant Privacy Commissioner of Canada faulted the camps for exchanging information about a camp applicant without adequate consent. In PIPEDA Report of Findings #2012-007, the parent of a prospective camper complained to the Office of the Privacy Commissioner of Canada because the camp contacted another summer camp that the child had attended previously. The camp in question first stated that they had not contacted the second camp at all, but exchanging such background information was relatively standard in their business and, if they had, they would have had adequate consent by virtue of their privacy policy and privacy statement that was available to the complainant.  

In speaking with the second camp, the Assistant Commissioner determined that the exchange of background information had taken place, notwithstanding the company’s initial statements. With respect to adequate consent, the Assistant Commissioner reviewed the relevant privacy statements and concluded they were too vague and uncertain to result in consent for this sort of information collection. The Assistant Commissioner recommended that the camp obtain better consent for such collections and uses of personal information, and provide privacy training to employees. The recommendations were accepted and the complaint was determined to be “well founded and conditionally resolved”.

With respect to the second summer camp, which had disclosed information to the first summer camp, the Assistant Commissioner found that it violated PIPEDA in PIPEDA Report of Findings # 2012-008.  Specifically, the complainant alleged that it had disclosed the former camper’s personal information without consent. The camp admitted that it had disclosed the information, but stated it was a standard practice and that adequate consent had been obtained. The Assistant Commissioner examined the camp’s privacy statements and concluded the information was minimal and not a sufficient basis for consent.

The Assistant Commissioner concluded that the complaint was “well founded and conditionally resolved”, as the camp agreed to follow her recommendations to implement a better policy and to provide employee privacy training.

Wednesday, January 30, 2013

PIPEDA Finding: In joint investigation with Dutch DPA, Commissioner finds WhatsApp didn't comply with Canadian privacy laws

Earlier this week, the Privacy Commissioner of Canada released its report of findings against the popular, cross-platform instant messaging app. (Commissioner’s Findings - PIPEDA Report of Findings #2013-001: Investigation into the personal information handling practices of WhatsApp Inc.) It's a long and interesting read in and of itself, but it also notable as the first time that the Commissioner has participated in a join investigation with another country's data protection authority. It is also notable that she "named names" and that the investigation was undertaken on her own initiative, rather than as a response to complaints.

Here's the Commissioner's media release, which summarises the investigation:

WhatsApp’s violation of privacy law partly resolved after investigation by data protection authorities

Canadian and Dutch data privacy guardians release findings from investigation of popular mobile app

Ottawa, Canada and The Hague, The Netherlands, January 28, 2013 —The Office of the Privacy Commissioner of Canada (OPC) and the Dutch Data Protection Authority (College bescherming persoonsgegevens, (CBP)) today released their findings from a collaborative investigation into the handling of personal information by WhatsApp Inc., a California-based mobile app developer.

The coordinated investigation is a global first, as two national data protection authorities conducted their work together to examine the privacy practices of a company with hundreds of millions of customers worldwide. This marks a milestone in global privacy protection.

“Our Office is very proud to mark an important world-first along with our Dutch counterparts, especially in light of today’s increasingly online, mobile and borderless world,” said Jennifer Stoddart, Privacy Commissioner of Canada. “Our investigation has led to WhatsApp making and committing to make further changes in order to better protect users’ personal information.”

Jacob Kohnstamm, Chairman of the Dutch Data Protection Authority, adds: “But we are not completely satisfied yet. The investigation revealed that users of WhatsApp – apart from iPhone users who have iOS 6 software – do not have a choice to use the app without granting access to their entire address book. The address book contains phone numbers of both users and non-users. This lack of choice contravenes (Dutch and Canadian) privacy law. Both users and non-users should have control over their personal data and users must be able to freely decide what contact details they wish to share with WhatsApp.”

Key findings and outcomes

  • The investigation focused on WhatsApp’s popular mobile messaging platform, which allows users to send and receive instant messages over the Internet across various mobile platforms. While WhatsApp was found to be in contravention of Canadian and Dutch privacy laws, the organization has taken steps to implement many recommendations to make its product safer from a privacy standpoint. At this time however, outstanding issues remain to be fully addressed.
  • The investigation revealed that WhatsApp was violating certain internationally accepted privacy principles, mainly in relation to the retention, safeguard, and disclosure of personal data. For example:
  • In order to facilitate contact between application users, WhatsApp relies on a user’s address book to populate subscribers’ WhatsApp contacts list. Once users consent to the use of their address book, all phone numbers from the mobile device are transmitted to WhatsApp to assist in the identification of other WhatsApp users. Rather than deleting the mobile numbers of non-users, WhatsApp retains those numbers (in a hash form). This practice contravenes Canadian and Dutch privacy law which holds that information may only be retained for so long as it is required for the fulfilment of an identified purpose. Only iPhone users running iOS6 on their devices have the option of adding contacts manually rather than uploading the mobile address numbers of their address books to company servers automatically.
  • At the time the investigation began, messages sent using WhatsApp’s messenger service were unencrypted, leaving them prone to eavesdropping or interception, especially when sent through unprotected Wi-Fi networks. In September 2012, in partial response to our investigation, WhatsApp introduced encryption to its mobile messaging service.
  • Over the course of the investigation, it was found that WhatsApp was generating passwords for message exchanges using device information that can be relatively easily exposed. This created the risk that a third party may send and receive messages in the name of users without their knowledge. WhatsApp has since strengthened its authentication process in the latest version of its app, using a more secure randomly generated key instead of generating passwords from MAC (Media Acess Control) or IMEI (International Mobile Station Equipment Identity) numbers (which uniquely identify each device on a network) to generate passwords for device to application message exchanges. Anyone who has downloaded WhatsApp, whether they are active users or not, should update to the latest version to benefit from this security upgrade.

Next steps

The OPC and CBP have worked closely together, but have issued separate reports, respecting each country’s data protection law (Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and the Dutch Data Protection Act (Wet bescherming persoonsgegevens (Wbp)). Following the issuance of their respective reports of findings, the OPC and CBP will pursue outstanding matters independently.

Following investigation, the Dutch Data Protection Act provides for a second phase in which the CBP will examine whether the breaches of law continue and will decide whether it will take further enforcement actions. The Dutch legal framework contains the possibility to enforce the Dutch privacy law by imposing sanctions.

Under Canada’s PIPEDA, the OPC will monitor the company’s progress in meeting commitments made in the course of investigation. In most cases, companies are cooperative in meeting their obligations, and WhatsApp has demonstrated a willingness to fully comply with the OPC’s recommendations. Unlike the CBP, the OPC does not have order making powers.

Thursday, December 22, 2011

Privacy Commissioner finding: Laurier Optical inappropriately disclosed customer's information

The Privacy Commissioner of Canada has published its fourth PIPEDA finding of 2011: Commissioner’s Findings - PIPEDA Report of Findings #2011-004: Laurier Optical Improperly Discloses Client’s Personal Information - March 31, 2011. What is most notable is that she "names names", principally because the organization did not respond to her recommendations:

As a result of the circumstances examined in this investigation and the outstanding issues, the Privacy Commissioner was of the view that Laurier Optical’s personal-information handling practices in this case should be made public and exercised her discretion to publicly name the organization.
.

Here is the summary of the investigation and "Lessons Learned":

An individual who was seeking a refund from Laurier Optical because two pairs of prescription eyeglasses didn’t satisfy him, was shocked to discover the company had copied its written response to his request to 10 different parties.

He complained to our Office that the optometry chain, which has locations in Ontario and Quebec, disclosed his personal information without consent and subsequently failed to provide him with access to his personal information.

The man had obtained two prescriptions from Laurier Optical and found that neither satisfied him. As a result, he obtained a prescription from an independent optometrist who worked elsewhere.

After receiving the refund request, Laurier Optical initiated a complaint against the independent optometrist with the Ontario College of Optometrists. The company alleged the optometrist had incorrectly told the complainant that Laurier Optical had not performed a proper eye exam.

In its written response to the refund request, Laurier Optical included the complainant’s home address, telephone number and details of his three prescriptions, as well as a description of the prescription dispute. The complainant felt it contained false statements damaging to his character. The letter also stated that Laurier Optical would ask two other professional bodies and the two biggest lens manufacturing labs in Canada to evaluate the three prescriptions and obtain neutral opinions.

The letter was copied to 10 different parties, including various Laurier Optical officials; the Ontario College of Optometrists; the College of Opticians of Ontario, the independent optometrist; the company that made the complainant’s lenses, as well as another lens manufacturing company.

The complainant also requested access to his personal information held by Laurier Optical, but received no documentation in response.

Following an investigation, our Office found both the disclosure and access complaints to be well founded.

It was not necessary for Laurier Optical to disclose the complainant’s personal information to the College of Opticians or the lens manufacturers in order to demonstrate that the lenses it had provided to the complainant were appropriate. Even if these organizations could provide relevant input, they could have done so without knowing the complainant’s name, address, telephone number or details of the dispute. Similarly, it was not necessary to provide the independent optometrist with this information.

We recommended that Laurier Optical train its staff about PIPEDA’s requirements regarding the protection of clients’ personal information.

The organization did not respond.

As a result of the circumstances examined in this investigation and the outstanding issues, the Privacy Commissioner was of the view that Laurier Optical’s personal-information handling practices in this case should be made public and exercised her discretion to publicly name the organization.

Lessons Learned:

  • If an organization is contemplating the disclosure of a client’s personal information without consent, it must ensure that one of the exceptions to consent under subsection 7(3) applies.
  • The sharing of personal information with other employees or agents of an organization is considered to be a “use” under the Act, rather than a “disclosure.” Therefore, if an organization is contemplating such a use of personal information without the individual’s consent, it must ensure that one of the exceptions to consent under subsection 7(2) applies.
  • When in receipt of a request for access to personal information, organizations must respond in a meaningful way, even if only to indicate that they have already provided the individual with all of their information.

Sunday, August 21, 2011

Federal Court awards minimal damages under PIPEDA

The Federal Court has recently released its second decision in which damages have been awarded for a breach under PIPEDA. Once again, the degree of damages are very low considering the costs associated with seeking redress before the Federal Court, but this very likely turns on the unique facts of the case.

In Landry v. Royal Bank of Canada, 2011 FC 687 (CanLII), the applicant was embroiled in what appears to be a bitter divorce and was hiding certain bank accounts from her spouse. Her bank was served with a subpoena to produce records. It appears that the bank did not follow its prescribed procedures (which would have avoided the entire mess) and ultimately faxed the applicant's bank records to counsel for her spouse. The applicant complained to the Office of the Privacy Commissioner of Canada, who found her complaint to be "well-founded and resolved".

The applicant started an application in the Federal Court, seeking at least $75,000 in damages. Neither party looked good appearing in court: the bank had not followed its procedures and tried to cover it up. The applicant was essentially caught trying to hide assets contrary to her legal obligations in connection with the divorce proceeding.

In the result, the Court concluded:

[32] Taking into account the contributory fault of the applicant, who was partially responsible for her own problems, and the serious breach committed by the respondent’s employee and its subsequent cover-up, the Court finds that the applicant suffered humiliation under paragraph 16(c) of the Act and that the respondent’s negligence warrants the applicant being compensated but does not give rise to exemplary damages as requested. Consequently, we fix an amount of $4,500 with interest and costs to be paid to the applicant by the respondent.

What is interesting is that the Court awarded any damages at all. The records, if they had been properly processed, would have been released to the applicant's husband and the personal result to her would have been the same. The Court could have said "no harm, no foul", but awarded damages (which are at least symbolic). This may hold out some hope for applicants that, in the right case, substantial damages may be awarded.

Friday, July 09, 2010

Important Federal Court decision on "commercial activities" under PIPEDA

Today, the Federal Court of Canada released an important decision on the parameters of "commercial activity" under PIPEDA: State Farm v Privacy Commissioner, 2010 FC 736. Because I was one of the counsel on the case, I can't say much so I'll leave it to Dan Michaluk to provide a full, unbiased summary.

In short, the Court concluded that an insurance company, acting on behalf of its insured in defending a personal injury claim, is not engaged in "commercial activity" so PIPEDA does not apply. Though the case it not specifically followed, this conclusion is consistent with Ferenczy v. MCI Medical Clinics (some commentary here).

Tuesday, July 29, 2008

PIPEDA Finding: Residental property appraisal is the owner's personal information

It's been a while since we've seen a published PIPEDA finding that wasn't from a high-profile case.

In this case, a bank refused to provide a customer with access to the appraisal conducted by the bank of the customer's property. The bank argued it was about the property and not about him. Further, they argued it was confidential commercial information. The Assistant Commissioner did not agree:

Commissioner's Findings - PIPEDA Case Summary #: Residential Property Appraisal Documents are Owners’ Personal Information (May 7, 2008)

The Assistant Commissioner first examined the question of whether the residential property appraisal should be defined as personal information under section 2 of the Act. After considering both the bank’s views and the CBA’s, as well as this Office’s earlier deliberation on the same question in another finding, the Assistant Commissioner remained of the opinion that, since the property was in the complainant’s name, the information relating to the property, including its market value, was his personal information. He therefore had a right of access to it.

Friday, April 18, 2008

Privacy Commissioner Concerned With Ticketmaster's Privacy Practices

The Privacy Commissioner doesn't often "name names", but she's named Ticketmaster in this most recent finding released from her office. Here's the press release:
Privacy Commissioner Concerned With Ticketmaster's Privacy Practices, Encourages Companies to Adopt High Privacy Standards Across Operations

OTTAWA, April 18, 2008 – Privacy Commissioner of Canada Jennifer Stoddart expressed concern with the information collection and privacy practices of a major online ticket vendor. However, following an investigation by her office and that of Alberta Commissioner Frank Work , the privacy practices of Ticketmaster Canada Limited have been brought up to standard.

However, she encourages companies to adopt the highest standard of privacy practices possible, regardless of where they do business.

“Online commerce continues to grow and customers worldwide expect companies to safeguard their personal information in the course of their business,” says Jennifer Stoddart. “It simply makes good business sense for companies to implement excellent privacy practices across their operations. It is also the law in Canada.”

The Commissioner launched an investigation into the information collection practices of Ticketmaster Canada Limited after a private citizen filed a complaint alleging that the company’s policies and practices on the collection, disclosure and use of customers’ personal information did not comply with the Personal Information Protection and Electronic Documents Act (PIPEDA).

The Information and Privacy Commissioner of Alberta, Frank Work, investigated a similar complaint into how Ticketmaster obtained consent to collect its customers’ personal information and released an investigation report late in 2007.

The investigation conducted by the Office of the Privacy Commissioner of Canada examined the issue of consent, but also investigated whether Ticketmaster followed the principles of access, openness and accountability found in PIPEDA.

“I am now satisfied with the measures Ticketmaster undertook to resolve the complaints that were brought to our attention,” says Jennifer Stoddart. “But I am very concerned that, seven years after PIPEDA was enacted, a major online company operating throughout Canada was found to be in violation of the legislation.”

The investigation of Ticketmaster Canada’s privacy practices was led by Assistant Commissioner Elizabeth Denham. It found that although the company had a privacy policy in place, this policy was long, complex and difficult for consumers to read.

The Assistant Commissioner also found that Ticketmaster’s online customers were required to consent to their personal information being used for marketing purposes as a condition of purchasing a ticket – a clear violation of PIPEDA.

Following the two investigations, Ticketmaster has revised its privacy practices to explicitly communicate what personal information is collected, with whom it is shared, and how it is used. The company has also adapted its online notification and call-centre telephone scripts so that customers are provided with a choice of whether to opt in to receive marketing material from Ticketmaster and event providers.

Furthermore, Ticketmaster in the United States has amended its privacy policy to make it more understandable and user-friendly for its customers. However, it did not implement any mechanism to provide customers the choice of opting in to receive marketing material, as it has done for its operations in Canada and the United Kingdom.

The Commissioner will bring this distinction to the attention of her colleagues at the US Federal Trade Commission. As well, she will continue to encourage companies with operations in Canada and elsewhere to adopt the highest standard of information protection practices possible to ensure compliance with Canadian privacy law.

To view the case summary and backgrounder:

Tuesday, July 10, 2007

Commissioner releases pretexting report

You may recall some time ago when pretexting made the headlines in Canada after a MacLean's reporter purchased the Privacy Commissioner's phone records (Canadian Privacy Law Blog: That's a little cheeky: MacLean's Magazine buys Privacy Commissioner's cellphone records off the 'net). Today the Commissioner released a finding into the incident, accompanied by a big media release:

Data broker exploits human error, weak safeguards to access phone records

July 10, 2007

PIPEDA Case summary #372: Disclosures to data brokers expose weaknesses in telecoms’ safeguards

Here's the release:

Data broker exploits human error, weak safeguards to access phone records

OTTAWA, July 10 /CNW Telbec/ - Recent experience has shown Canadian companies must take precautions to ensure personal information and customer data is not vulnerable to data thieves and pretexters. Strong identification and authentication procedures are essential in blocking unauthorized attempts to access the personal information of Canadians.

An investigation by the Office of the Privacy Commissioner of Canada (OPC) has found that human error and weaknesses in the policies and procedures of three telecommunications companies allowed a data broker to gain unauthorized access to personal phone records.

The investigation was prompted by an article in Maclean's alleging the magazine had been able to purchase the telephone records of Privacy Commissioner Jennifer Stoddart and a senior Maclean's editor from US-based data broker Locatecell.com.

The investigation found that Locatecell.com used "social engineering" to trick phone company customer service representatives into divulging confidential information, either in the specific instances alleged and/or subsequent test cases. Social engineering involves manipulating people into divulging personal information, for example, by pretexting, or pretending to be someone authorized to obtain the information.

The OPC looked at improper disclosures of personal information to pretexters seeking to gain unauthorized access to phone records of individuals without their knowledge or consent. The three companies investigated were Bell Canada, Telus Mobility and Fido.

"In each case, we found that customer service representatives had not followed the companies' established authentication procedures. We also found that training of customer service representatives was not comprehensive enough to protect customers' personal information from illegal access by pretexters," says Assistant Commissioner Raymond D'Aoust. "As a result, the three companies failed to meet the requirements of the Protection of Personal Information and Electronic Documents Act (PIPEDA)."

All three companies revised their customer authentication procedures shortly after the disclosures took place. The OPC reviewed those changes and recommended further steps to address weaknesses in their policies and procedures to prevent unauthorized individuals from gaining access to customers' personal information. All three companies have since taken additional steps to further mitigate the risks resulting from pretexting and unauthorized access to personal records. The Office of the Privacy Commissioner is generally satisfied that all three companies have put in place an adequate set of measures to address the problems.

Nonetheless, the Assistant Commissioner says the companies should have been better prepared to deal with social engineering in the first place. The issue of data brokers using social engineering to obtain call records in the United States had been in the news some time before these incidents occurred.

"It's particularly troubling that not enough was done to let call centre employees know about this kind of threat," says Assistant Commissioner D'Aoust.

"Given the prevalence of identity theft, it is absolutely crucial that all companies adopt strong authentication processes to help ensure that they are providing information to someone who is actually authorized to have that information. It is equally vital that companies ensure that their employees are following these processes and are aware of the threats to personal information that pretexting poses."

The OPC has developed Guidelines for Identification and Authentication on its web site.

A summary of findings in the three cases is also available on the web site.

New laws in the US have recently made it an offence to use pretexting to obtain individuals' phone records in an effort to curb the activities of US information brokers, including Locatecell.com. However, this does not mean the problem has gone away either in the US, or elsewhere, particularly in other countries, including Canada, where no similar legislation yet exists.

In an appearance before a Parliamentary committee last month, Commissioner Stoddart called on the federal government to work collaboratively with the provinces and international partners to adopt a range of legislative and policy solutions to address this problem.

The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy and the protection of personal information rights of Canadians.

Monday, April 02, 2007

Federal Commissioner: SWIFT did not violate PIPEDA

Canada's Privacy Commissioner has wrapped up her investigation of the SWIFT information sharing fuss and has concluded that SWIFT is subject to PIPEDA but did not violate the law when it handed over Canadian information in response to US subpoenas.

From the Commissioner:

News Release: Privacy Commissioner concludes investigation of SWIFT (April 2, 2007)

Privacy Commissioner concludes investigation of SWIFT

Ottawa, April 2, 2007 —The Privacy Commissioner of Canada, Jennifer Stoddart, today announced the conclusion of her Office’s investigation of the Society for Worldwide Interbank Financial Telecommunication (SWIFT), a European-based financial cooperative, that supplies messaging services and interface software to a large number of financial institutions in more than 200 countries, including Canada.

In her Report of Findings, made public today, the Commissioner confirmed that SWIFT is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada’s private sector privacy law, and that the organization did not contravene the Act when it complied with lawful subpoenas served outside the country and disclosed personal information about Canadians to foreign authorities. However, she emphasized that making use of existing information-sharing regimes, with built-in privacy protections, would allow for greater transparency for citizens.

Since her appointment, Ms. Stoddart has raised concerns about the personal information of Canadians flowing across borders. In her Report, the Commissioner stressed that organizations operating and connected in a substantial way to Canada are subject to PIPEDA and they must abide by the Act. “Simply because companies might operate in two or more jurisdictions does not relieve them of their obligations to comply with Canadian law,” said Ms. Stoddart.

It was alleged that SWIFT inappropriately disclosed to the US Department of Treasury (UST) personal information originating from or transferred to Canadian financial institutions. Ms. Stoddart launched a commissioner-initiated investigation into the matter to determine if there was a breach of PIPEDA, the federal law which covers the collection, use and disclosure of personal information in the course of commercial activities.

Following September 2001, the UST began issuing subpoenas to SWIFT for certain data held in SWIFT’s US-based operating centre. SWIFT obtained a series of privacy protections for the data it transferred to the UST.

In her Report, the Commissioner explained that PIPEDA allows an organization such as SWIFT to abide by the laws of other countries in which it operates. An organization that is subject to PIPEDA and that has moved personal information outside the country for business reasons may be required at times to disclose it to the legitimate authorities of that country. It is clear that in response to a valid subpoena issued by a court, person or body with jurisdiction to compel the production of information, an organization must disclose personal information and PIPEDA makes it permissible to comply with this obligation. The Commissioner stressed that multi-national organizations must comply with the laws of those jurisdictions in which they operate.

The Commissioner noted, however, that if US authorities need to obtain information about financial transactions that have a Canadian component, they should be encouraged to use existing information mechanisms that have some degree of transparency and built-in privacy protections. Accordingly, she signaled her intent to ask Canadian officials to work with their US counterparts to persuade them to use Canadian anti-money laundering and anti-terrorism financing mechanisms instead of the subpoena route.

“These alternate avenues would allow far greater Canadian involvement in the scrutiny of personal information and would better respect the value we give privacy protection,” said Ms. Stoddart. “Democratic societies must ensure that the fundamental rights and freedoms of the individual are respected to the extent possible, including the right to the protection of personal information.”

In addition to its investigation of SWIFT, the Privacy Commissioner’s Office also received complaints against six Canadian financial institutions and conducted an investigation into their involvement in the matter.

The Office reviewed the contractual documentation that exists between SWIFT and the banks, and concluded that the banks are meeting their obligations under the PIPEDA, noting that when an organization that contracts with a firm that operates both within and outside of Canada, it must respond to lawfully issued subpoenas in other jurisdictions as well as in Canada, and PIPEDA permits this.

Moreover, she found that each of the banks has very clear language in their privacy policies. These policies inform customers that the banks may send their personal information out of the country for certain purposes and that while such information is out of the country, it is subject to the laws of the country in which it is held.

The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of the privacy and protection of personal information rights of Canadians.

View the Executive Summary.

View the Commissioner’s full Report of Findings.

View the PIPEDA case summary relating to the investigations of the banksView the Commissioner’s June 2006 news release and August 2006 news release on this issue.

Monday, February 26, 2007

New findings from the Office of the Privacy Commissioner of Canada

A bunch of new findings have been released on the Privacy Commissioner's website recently:

Commissioner's Findings - Privacy Commissioner of Canada

Wednesday, January 24, 2007

Settled Case summary #27: Clinic discloses client information when trying to collect a debt

The Privacy Commissioner of Canada has released a summary of a recently settled case, in which a dental clinic disclosed the fact that a patient's account was in arrears to another patient who had referred the first:

Settled Case summary #27: Clinic discloses client information when trying to collect a debt (May 16, 2006)

Complaint

An individual complained that her dental clinic disclosed information about her overdue account to the person who had referred her to the clinic.

Outcome

The complainant noted that she had been in hospital and in respite care for several months, and thus did not receive the invoices sent by the dental clinic. When the invoices remained unpaid, the clinic telephoned the client who had made the referral in order to determine the complainant’s whereabouts. The clinic confirmed that it had not only asked the client how it could reach the complainant, but it had also disclosed that her bill was overdue, the amount owing, and that it would be sent to collections unless paid.

The clinic acknowledged that the disclosures went against its privacy policy, and that it should only have requested contact information. In the course of investigating the complaint, the clinic and the complainant agreed to a monetary settlement which also included a letter of apology to the complainant.

The OPC and the complainant agreed that in light of the settlement the matter should be considered settled.

Tuesday, January 16, 2007

Finding: PIPEDA access right exists during litigation

In a finding under PIPEDA published on the OPC website, the Assistant Privacy Commissioner of Canada found that an airline's obligation to provide an individual with access to his information continues to exist even if there is litigation pending between the applicant and the organization. See: Commissioner's Findings - PIPEDA Case Summary #352: Airline delays granting access to personal information, citing ongoing litigation (September 8, 2006).

It is also worth noting that the Commissioner's office had to commence an application before the Federal Court in order to get the airline to follow her recommendation.

Sunday, December 03, 2006

PIPEDA Case Summary #351: Use of personal information collected by Global Positioning System considered

On Thursday, the Office of the Privacy Commissioner of Canada posted a very interesting and detailed finding on the use of GPS tracking of company vehicles. The finding is lengthy and worth a read: Commissioner's Findings - PIPEDA Case Summary #351: Use of personal information collected by Global Positioning System considered (November 9, 2006).

A summary of the summary is in the following media release:

News Release: Privacy Commissioner urges caution before installing GPS in company vehicles (November 30, 2006):

News Release

Privacy Commissioner urges caution before installing GPS in company vehicles

Ottawa, November 30, 2006 – Employers need to carefully consider the privacy rights of their workers before installing Global Positioning Systems (GPS) into their vehicle fleets, according to the Privacy Commissioner of Canada, Jennifer Stoddart.

The Office of the Privacy Commissioner of Canada (OPC) today released a summary of its findings into a case involving the workplace use of GPS, which can track the location of a vehicle in real time. The Commissioner discussed her Office’s findings at a workplace privacy seminar hosted by Ryerson University.

“This is an important issue for employers and employees across Canada. We’re seeing more and more organizations installing GPS in their cars and trucks and it’s unclear whether they are adequately addressing privacy issues,” Ms. Stoddart said.

In the case investigated by the OPC, several workers complained that their employer, a telecommunications company, is using GPS to improperly collect their personal information – specifically their daily movements while on the job.

The company is using GPS in its installation and repair, and construction vehicles to locate, dispatch and route employees to job sites. Some workers worried, however, that GPS is also being used to monitor work performance and that information gleaned from this technology will be used to justify disciplinary action.

The OPC investigation accepted most of the company’s arguments for using GPS. It agreed, for example, that using GPS to dispatch vehicles is likely to lead to better service for the company’s customers and also could help locate missing vehicles.

However, the OPC expressed concern about using GPS as an employee surveillance tool. While using GPS to track a vehicle is not overly privacy invasive, routinely evaluating worker performance based on assumptions drawn from GPS information impinges on individual privacy.

The use of GPS as an employee surveillance tool may be acceptable in certain situations, which are defined and communicated to employees beforehand, according to the OPC findings. However, a company should not routinely use GPS to monitor its workforce.

In this case, the OPC asked the company to clearly explain to its employees how GPS would be used to check up on them, and also to develop a policy outlining an appropriate process of warnings and progressive monitoring. The policy subsequently prepared by the company spelled out situations in which the company will use GPS data to monitor employees. These include an investigation into a complaint – about speeding, for example – from a member of the public; an investigation into concerns raised within the company; or to address productivity problems. The company also made a commitment to train its managers about the appropriate use of the technology.

“Systematically using GPS to check up on workers and try to determine how well they are doing their jobs would be going too far,” said Ms. Stoddart. “Employers do not have carte blanche to use GPS to constantly monitor their workforce.”

The OPC finding also cautions employers about “function creep” – collecting information for one purpose, and then using it for some other unrelated purpose in violation of basic fair information practices.

“Managing workplace privacy is a balancing act. On the one hand, employers have the right to know what workers are up to on company time. On the other, employees have a right to privacy,” the Commissioner said.

“Workers do not check their privacy rights at the factory or office door. Workplace privacy is an important part of the basic autonomy rights of individuals in our society,” she said. “Employers must find ways to weed out the bad employees without shattering the dignity and privacy rights of the good employees – who make up the vast majority of the workforce.”

The OPC is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy rights in Canada.

The summary of the findings in the GPS investigation is available on the OPC Web site:

PIPEDA Case summary #351: Use of personal information collected by Global Positioning System considered

Once again, I am left at a bit of a loss when it comes to using PIPEDA in the workplace. Unlike PIPA in Alberta and BC, PIPEDA has no deemed consent for reasonable collection, use and disclosure in the workplace. To "make do", the practice seems to have been to use s. 5(3) of the Act to say that as long as it's reasonable, you have implied consent (particularly if there is notice). But logically you can't have consent by implication if it is clearly negated by an employee complaint. Hopefully this will become moot if the Parliamentary Committee recommends fixing up that portion of PIPEDA and something is done about it.

Tuesday, September 19, 2006

Finding: Law firms collected credit reports without consent

Yesterday, the Office of the Privacy Commissioner of Canada posted a new finding based on two separate complaints related to a law firm conducting credit checks without consent (Commissioner's Findings - PIPEDA Case Summary #340: Law firms collected credit reports without consent (May 2, 2006)).

The Assistant Commissioner concluded that the complaints were well-founded. This represents a very important finding, not so much on the question of the appropriateness of the credit checks but on important questions of jurisdiction raised. The credit checks were apparently contrary to the agreement between the firms and the credit bureaus in question. However, in my humble opinion and with the greatest respect to the Assistant Commissioner, Complaint A was incorrectly decided.

Complaint A

An individual complained that a law firm collected his personal information, by conducting a credit bureau inquiry, without his knowledge and consent.

Summary of Investigation

The law firm confirmed that it did conduct the credit inquiry. It argued, however, that the OPC did not have jurisdiction in this matter, as the information was collected for personal purposes of a client in relation to possible litigation, and it would therefore not provide the Office with access to its records.

The Office asserted its jurisdiction with respect to the complaint on the basis that the collection occurred during the course of the law firm’s commercial activities.

The complainant had also filed a complaint with the credit bureau regarding the collection of his credit information. The credit bureau requires its member companies, such as the law firm in this case, to obtain express consent for the collection of credit information. Since the law firm failed to provide adequate information or cooperate fully with the credit bureau’s inquiries, the credit bureau concluded that the law firm did not have the complainant’s consent to the collection. As a result, the law firm’s membership privileges were suspended.

Findings

Issued May 2, 2006

Application: Paragraph 4(1)(a) establishes that Part I of the Act applies to every organization in respect of personal information that the organization collects, uses or discloses in the course of commercial activities. Principle 4.3 states that the knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate.

The Assistant Commissioner was satisfied that the collection occurred in the course of the firm’s commercial activities, and noted that as there was no general exclusion for the activities of law firms undertaken on behalf of their clients. The Office therefore found that it had jurisdiction in the matter, pursuant to paragraph 4(1)(a).

As for the collection, the law firm admitted that it had collected the complainant’s personal information, by way of credit inquiry. The complainant had alleged that this was done without his consent, and the law firm did not provide any evidence to the contrary.

The Assistant Commissioner therefore concluded that the information was collected without the complainant’s knowledge or consent, in contravention of Principle 4.3. She recommended that the law firm implement a policy that prohibits conducting credit checks without the individual’s consent, unless one of the exceptions to the requirement for consent, as set out in the Act, is applicable. The law firm responded by continuing to challenge this Office’s jurisdiction, maintaining that the issue did not involve any commercial activity. It stated that it continues to comply with the Act, as it has since the Act came into force. It also maintained that it does not collect the personal information of anyone without their consent. The Assistant Commissioner was not satisfied with this response, noting that the Act requires organizations to be open about their privacy policies and practices. The response from the law firm did not address the specific recommendation of the Office to implement a policy for obtaining consent to conduct credit checks. Nor did the response provide any further evidence that the Act was not contravened in this instance.

Accordingly, she concluded that the complaint was well-founded.

In my humble opinion, and based solely on this little snapshot of the facts provided above, the Assistant Commissioner was without jurisdiction to consider this particular complaint. The basis for the Commissioner's jurisdiction is in s. 4(1)(a) of PIPEDA, which states that Part I of the Act applies with respect to the collection, use and disclosure of personal information in the course of “commercial activities”. Commercial activities is further defined to mean an act or transaction or course of conduct that is of a “commercial character”. It is said that the law firm was acting for a client and that the client was engaged in litigation against the complainant. That the law firm is engaged in its own commercial activities should be irrelevant. It is merely the agent for its client.

This position is supported by the decision of Justice Dawson of the Ontario Superior Court of Justice in Ferenczy v. MCI Medical Clinic, [2004] O.J. No. 1775. Justice Dawson concluded that video surveillance of a medical malpractice plaintiff is not “commercial activity” for the purposes of PIPEDA:

25 The plaintiff submits that the private investigator (an organization) retained by the CMPA (an organization) was collecting and making a record (videotape) of the plaintiff's personal information (images) during the course of commercial activity (while being paid), and that as the plaintiff did not consent to the collection and release of the information, the investigator and the CMPA are in contravention of the Act.

26 For a number of reasons I disagree. I will deal with some specific reasons momentarily, but first I will make a few general comments.

27 The legislation in question is complex and so broadly worded that a reasonable argument could be made to extend its reach so far as to transform both civil and criminal litigation into something very different than it is today. The arguments advanced on behalf of the plaintiff here prove that point. On the basis of the plaintiff's argument, Dr. Weinstein might be permitted to take his own video camera and record surveillance evidence in his own defence, but a licenced private investigator could not do so on his behalf if he was being paid to do so.

28 This argument would extend to an accused in a criminal case. While there are exceptions in the Act that allow law enforcement agencies to investigate and collect information about a suspect or an accused, an accused would arguably be prevented from utilizing a private investigator, or other paid agent, to collect information or conduct surveillance that could be vital to his or her defence. …

30 One way to avoid this result, and I conclude it is the correct interpretation of the Act, is to apply the principles of agency. On this analysis it is the defendant in the civil case who is the person collecting the information for his personal use to defend against the allegations brought by the plaintiff. Those whom he employs, or who are employed on his behalf, are merely his agents. On this analysis s. 4(2)(b) of the Act governs. That section reads as follows:

>4(2) This part does not apply to ...

(b) any individual in respect of personal information that the individual collects, uses or discloses for personal or domestic purposes and does not collect, use or disclose for any other purpose;

The defendant through his representatives was employing and paying an investigator, to collect information for him. It is the defendant's purpose and intended use of the information that one should have regard to in determining the applicability of the Act. On the basis of this analysis I conclude that the defendant is not collecting or recording personal information in the course of commercial activity. He, through his agents, was collecting information to defend himself against the lawsuit brought by the plaintiff. This is a personal purpose in the context of the civil action brought against him by the plaintiff. In my view, this conclusion is consistent with the overall purpose of the Act which is aimed primarily at information collected as a part of commerce. [emphasis added]

The collection, use and disclosure of personal information in connection with private litigation is a private matter and not "commercial activity". Simply put, a claim for damages under the common law or litigation related to such a claim cannot be reasonably said to be a “commercial activity”. The fact that the relationship between the defendant, on one hand, and the law firm, on the other hand, is commercial is not relevant: As PIPEDA requires a “commercial activity” nexus to be applicable, the fact that the law firm is being paid is immaterial, no such nexus would exist and PIPEDA should not apply.

Parliament limited PIPEDA’s application to “commercial activities” (and federal works, undertakings and businesses) because federal jurisdiction is limited by the Constitution Act, 1867. In passing PIPEDA, Parliament relied upon its jurisdiction over the “Regulation of Trade and Commerce” contained in s. 91(2). A private lawsuit between two individual litigants (and all matters ancillary thereto), are a matter of “Property and Civil Rights in a Province”, which is an area of jurisdiction specifically reserved to the Provinces in s. 92 of the Constitution Act, 1867. Simply put, an attempt to enforce PIPEDA between two private individuals, acting in their private capacities (even if one is acting through a paid agent) would be an unconstitutional application of PIPEDA.

If Section 4(1)(a) is going to be read in such an expansive way, virtually all activities fall within "commercial activities". A public hospital will be engaged in commercial activities because it gets paid by medicare and because most attending physicians are actually incorporated contractors. (Even worse: some hospitals charge for casts and splints and private rooms!) All universities are engaged in commercial activity since they collect tuition and charge room and board. All public schools are engaged in commercial activities because students have to pay for field trips. All provincial government departments are engaged in commercial activity because you have to pay to register your car.

At the end of the finding, the following is noted:

For both complaints the Assistant Commissioner also indicated that she would pursue the matter in accordance with the Act and referred the cases to her litigation counsel. Shortly after being contacted by the Commissioner’s counsel, both law firms agreed to implement the recommendations thus avoiding the need to follow through with an Application in the Federal Court.

I can understand why the firms would not want to be drawn into an expensive proceeding in the courts, but it is regrettable that this finding will remain unchallenged.

Wednesday, July 19, 2006

Commissioner releases batch of new findings

The flow of findings posted on the website of the Office of the Privacy Commissioner has slowed to a trickle this year, but the floodgates opened long enough to release seven new findings today. I'll comment on them in greater detail before too long, but here are their titles and links:

Commissioner's Findings - Privacy Commissioner of Canada

In a conversation with the Assistant Commissioner, I've been told that there is no shortage of complaints but only a shortage of complaints that raise novel issues. Astute observers will note that most of these findings deal with novel issues, particularly situations of marital breakdown.