Showing posts with label universities. Show all posts
Showing posts with label universities. Show all posts

Monday, September 08, 2025

Ontario privacy finding: Hidden biometrics in on-campus vending machines


On August 27, 2025, the Information and Privacy Commissioner of Ontario released a revised finding against the University of Waterloo. The initial report was issued in June this year and I should have done an episode on it then. The case involved what looked like a pretty ordinary thing on campus — vending machines. Except these weren’t just any vending machines. They were “intelligent vending machines,” installed by a third-party service provider, and they secretly used biometric face detection technology.


That sounds creepy and the University was found to have violated Ontario’s public sector privacy law. It’s not as cut and dried, but there are some interesting takeaways from that decision. 


Nobody on campus was aware that these vending machines use face detection technology until one of the machines malfunctioned and flashed an error message on its screen — basically outing itself as running “FacialRecognition.App.exe.” Understandably, students complained. It got a lot of media coverage and some buzz on Reddit.


Photo of a display showing an error message



The Information and Privacy Commissioner of Ontario investigated.


At the outset, the University of Waterloo challenged whether the Commissioner even had jurisdiction here. The University argued that this wasn’t really about Ontario’s Freedom of Information and Protection of Privacy Act — instead, they said it was governed by the federal Personal Information Protection and Electronic Documents Act or PIPEDA. Their reasoning? Selling snacks through vending machines is a commercial activity. And PIPEDA applies to the collection, use and disclosure of personal information in the course of commercial activity. And that meant the federal law applied, not the provincial law.


They also argued that if the vending machines didn’t actually capture personal information — as the manufacturer claimed — then there was nothing for the Commissioner to investigate. And finally, Waterloo tried to limit its responsibility by pointing out that it never contracted for biometric collection in the first place. In their view, if the vendor went off and deployed face detection technology, that wasn’t for them, they didn’t ask for it and they should not be on the hook for it.


The Commissioner rejected all of those jurisdictional arguments. The decision emphasized that under FIPPA, Ontario institutions like universities are responsible for personal information collected by vendors operating on their behalf — even when those vendors are engaged in activities with a commercial character. The Commissioner leaned on the “double aspect” doctrine in our constitutional jurisprudence: both federal and provincial laws can apply at the same time. In other words, even if PIPEDA could cover some of the activity, that doesn’t oust FIPPA.


So the bottom line on the jurisdiction question was that the University of Waterloo couldn’t escape the Commissioner’s oversight just by pointing to federal law or saying “we didn’t know.” Once personal information was being collected on its campus by machines it authorized, the University was on the hook under FIPPA


On the merits, the Commissioner concluded that the machines were capturing facial images, even if only for milliseconds. Not surprisingly, these facial images qualify as “personal information” under Ontario’s Freedom of Information and Protection of Privacy Act (FIPPA).


The collection wasn’t authorized by law, wasn’t necessary for selling chips and chocolate bars, and no notice was given.


Therefore, in the IPC’s view, Waterloo had violated FIPPA.


In order to find Waterloo at fault, or in violation of FIPPA, the IPC asks and answers three questions:


The IPC asked: “Did Waterloo “collect” personal information?” The Commissioner said yes. Even though the vendor claimed the system only processed images in real time, the machines captured full facial images in memory to estimate age and gender. That’s enough to count as a collection of personal information.


But really? Was it really Waterloo who “collected” personal information? Legally, yes. They had a vendor who was supplying goods and services on their behalf and the University is responsible for that. 


Then the IPC asked: “Was the collection compliant with FIPPA?” No. Section 38(2) of FIPPA says you can only collect personal information if it’s expressly authorized, needed for law enforcement, or necessary to carry out a lawful activity. Selling snacks doesn’t need biometric data. It might be “helpful” for marketing — but helpful isn’t the same as “necessary.” And also, no notice was given that personal information was being collected and why.


Finally, the IPC asked: “Did Waterloo have reasonable measures to protect personal information?” The Commissioner said they had decent contract clauses, but they fell down in procurement. They didn’t do the privacy risk assessment that could have flagged the biometric capability. That failure meant they didn’t exercise enough due diligence, and so they’re responsible.


Here’s where I think the finding is problematic. Waterloo had no knowledge of the biometric functionality. They weren’t using it, they didn’t ask for it, and their contract didn’t mention it. The vendor who responded to the RFP for vending machines apparently wasn’t aware of this functionality in some of the machines they provided. That other supplier embedded this capability, and at the time nobody was aware of it.


Due diligence usually asks the question with reference to what a reasonably prudent person would have done in the same circumstances. Without the benefit of hindsight, I think the University met that standard. But they could have done better, so the University is still on the hook for a privacy violation. It seems to be holding them to a higher standard, based on what we know now. 


It could have been enough to just give them a gentle slap upside the head, saying it’s 2025 and we need to assume that anything that uses electricity – and particularly if it’s a “connected device” – has the potential to collect personal information. You need to check. Even vending machines. 


Think about what this means in practice:


Does every university, hospital, or government office now need to disassemble or reverse-engineer every piece of technology it procures? Almost. 


Do they need to anticipate hidden biometric features in a vending machine?


Or test for surveillance capabilities in every piece of software?


That’s a pretty heavy burden — one that goes far beyond what most organizations reasonably do. I guess the standard for reasonable diligence has to be raised.


Yes, we want institutions to take privacy seriously. Yes, procurement processes should involve risk assessments. But here, it feels like the University is being faulted for not uncovering something that was essentially hidden. I’m not sure we can fault them for not asking at the time whether a vending machine used biometrics. We know now, but I don’t think they should be expected to have known to ask back then. 


While the vendor was not in the cross-hairs of the IPC’s investigation, vendors need to be mindful. If you build a product with biometric capabilities, you should have to disclose it — clearly and up front. If it’s an “internet of things” connected thing, it should be clearly identified as such. There probably is a boilerplate term in contracts that put the vendor on the hook if they cause the customer to violate any applicable law.  


In the end, a finding of having violated FIPPA isn’t like a criminal charge. The IPC issued two recommendations, which the university agreed to implement. First was to review their policies to make sure that future collection of personal information complies with FIPPA. Second was to implement practices to carry out necessary due diligence to identify, assess and mitigate any potential risks to personal information throughout the entire procurement process, including during the planning, tendering, vendor selection, agreement management and termination phases.


There’s a lesson here for everyone: I guess it’s time to update all your procurement and vendor documentation to ask about any connected or biometric features. Ask detailed questions about every bit of gear being installed and fully understand their capabilities. And I’d include reps and warranties in my contacts allowing for the termination of agreements if there has been any misrepresentation about the possible collection of personal information. 


One thing also to note is I think this would have gone differently for the university if the vendor wasn’t the university’s service provider. As I mentioned before, the university is on the hook for all personal information collected by their service providers, whether they wanted the information collected in the first place. But if the university had structured the arrangement differently, they likely would have avoided that direct responsibility. For example, if the agreement was more like the bare rental of space for the placement of vending machines on campus, the element of custody or control of the data likely would not have been there. Imagine the university enters into a lease with Starbucks to put a coffee shop in the library atrium. In such a scenario, you wouldn’t really see the University as being responsible for Starbucks’ collection of personal information as part of the Starbucks Rewards loyalty program.  Or maybe the privacy commissioner would take a different view? I kind of hope not.


In any event, there are more than a few lessons to learn from this finding. 


Wednesday, April 13, 2011

Join the discussion about Dalhousie University and Cloud Computing

Dalhousie University, like many other Canadian post-secondary institutions, is engaging in a deep conversation with students, faculty and staff about the possibility of moving e-mail and other IT services to the cloud. As part of that conversation, the university is hosting a special forum on privacy and the cloud. Here's the details:

“A Forum on Privacy Laws, Cloud Computing and Impact to IT Strategy”

Presentation Date: Monday, April 18th, 2011 2:00-5:00 (Rowe Potter Auditorium)

Information Technology Services at Dalhousie University is exploring a number of opportunities with emerging “Software-as-a-Service” or “Cloud Computing” initiatives. Cloud computing introduces a number of potential concerns around security, privacy, data ownership and data stewardship.

In an effort to address concerns and increase awareness around the legal, policy and academic implications, Dalhousie has invited professionals in a number of areas to speak and take part in a panel discussion on these topics.

David Fraser, Partner, McInnes Cooper

Mr. Fraser will speak to Canadian and American laws in relation to cross border data transfer, privacy and access to information.

Dwight Fischer, CIO, Dalhousie University

Mr. Fischer will speak to the technology challenges and changes taking place and the impact on Dalhousie.

Paul Jones, Policy & Education Officer, Canadian Association of University Teachers

Mr. Jones will speak to the concerns around privacy and academic freedom, specifically how it relates to faculty.

Come and take part in the discussion on April 18th from 2:00 to 5:00 p.m!

Join in the online conversations now at blogs.dal.ca/connectedU

Wednesday, March 02, 2011

Is university faculty e-mail subject to access and privacy laws?

Dan Michaluk has just blogged about an interesting case out of Alberta (University of Alberta v. Alberta (Information and Privacy Commissioner), 2011 ABQB 100) that may have a significant impact on freedom of information law, particularly in universities. It will also have an impact on cloud computing decisions by universities. The Canadian Association of University Teachers takes the position that faculty e-mail are not under the "custody and control" of the educational institution. If this is found to be the case, faculty e-mail is not within the ambit of access to information laws at all and the privacy protection provisions of those laws. And, if that's the case, such e-mails are not covered by laws that are meant to regulate the export of personal information (out of fear of the USA Patriot Act). Stay tuned ....

See Dan's post: Alberta Court set to Hear Faculty E-mail Case « All About Information

Thursday, February 24, 2011

Ryerson University looks to the cloud

Today, I had the great pleasure of being one of the speakers at Ryerson University's broad consultation on the possibility of adopting cloud computing at the university. It was an incredibly high-quality event with a packed auditorium (in the middle of reading week, no less) and a very engaged audience.

The agenda is here: E-mail and Collaboration Tools Consultation | Email & Collaboration Tools Consultation.

My presentation is here:

If you can't see the embedded presentation, try this link: https://docs.google.com/present/view?id=ddpx56cg_415c4c8k5g5&interval=60

The full symposium was webcast live and will be available here:

If you want to see the many, many tweets which were sent out, search Twitter for #ryeprivacy.

UPDATE: Over at Slaw.ca, Dan Michaluk, who was at the symposium, has posted a few of his observations on the day: Commissioner Cavoukian says the Patriot Act is nothing.

Saturday, December 11, 2010

University of Alberta signs on to Gmail

Interesting development, from the Edmonton Journal:

University of Alberta signs on to Gmail

EDMONTON — The University of Alberta and Google concluded legal negotiations this week, preparing the way for better e-mail service for students and entry into the Canadian university market for the Internet giant.

The contract makes legally binding Google’s promises not to data mine university Gmails or share data with a third party. University staff and students get all of Google’s Gmail applications for free, and get to retain their @ualberta.ca tags.

The contract is the first of its kind in Canada and expected to be adopted other Canadian universities now that Alberta has paved the way, University of Alberta vice-provost Jonathan Schaeffer said.

The University of Alberta currently uses more than 30 different e-mail systems across campus.

Using Gmail could save the university $2 million a year, allow a common calendar and improve the emergency response system. But when the idea was first touted publicly last January, many staff and students had privacy concerns.

Signing the contract to ease those concerns means increased legal risks for Google, which sees the free services as a way to build market loyalty but can’t otherwise profit from the deal.

“That, in part, is why it took so long,” Schaeffer said. Now, “we have a legal contract that would allow us to go after them.”

The contract took 15 months to negotiate, which was much longer than the university expected, Schaeffer said. But a legally binding framework was also needed to meet the requirements of the Alberta Freedom of Information and Protection of Privacy Act.

The shift to Gmail will begin in January.

More than 20 Canadian universities, as well as the Canadian University Council of Chief Information Officers, sent Google letters of support during a low point in negotiations last July, indicating it would also be interested in accepting Gmail if a legal framework like the one the U of A wanted was in place.

Sunday, November 28, 2010

Privacy in the cloud for Canadian universities

This past week, I was invited to speak at the annual get-together of The Canadian University Council of CIOs (CUCCIO) in Toronto on the topic of cloud computing. Many universities in Canada are struggling with the legal and privacy issues of adopting cloud computing, particularly when Google and Microsoft are both offering very attractive (and free!) offerings that would relieve universities of the costs and burdens of administering student and alumni e-mail.

Universities in Alberta, British Columbia and Nova Scotia are particularly hampered by legislation that was designed to thwart the boogeyman represented by the USA Patriot Act.

BC and Nova Scotia have each adopted legislation that either categorically prohibits the "export" of personal information by public bodies, or put in place administrative hurdles. Alberta joins this pack by making it an offense under their public sector privacy law to disclose personal information in response to a "foreign demand for disclosure".

Part of the problem is that the legal framework is not particularly nuanced, as each decision about whether to outsource a service should be guided by a detailed risk assessment and privacy impact assessment instead of ham-fisted categorical rules that don't take particular circumstances into account.

Here is my presentation, which was well received.

If the embedded slideshow isn't showing you the love, click here: https://docs.google.com/present/view?id=ddpx56cg_320fx7rkbhh&interval=30

Thursday, October 29, 2009

University of Akron may demand DNA from job applicants

Wow. All I can say is wow.
Want A Job In Akron? Hand Over Your DNA - Taking Liberties - CBS News It's not unusual for employers to conduct criminal background checks during the hiring process. But the University of Akron has taken this to a surprising new level.

The Ohio school now reserves the right to require any prospective faculty, staff, or contractor to submit a DNA sample, which genetic-testing experts say makes it the first employer in the nation to take such an extreme and potentially intrusive step.

The new policy, which says a "DNA sample for purpose of a federal criminal background check" may be collected, took the campus by surprise after it was announced last week. An adjunct faculty member has resigned in protest and is contemplating a lawsuit, and the local chapter of the American Association of University Professors says that genetic testing violates a collective bargaining agreement. ...

Wednesday, May 13, 2009

Ontario Commissioner releases 2008 annual report and prepares for battle with Victoria University

The Information and Privacy Commissioner of Ontario has released her 2008 Annual Report, which makes broad recommendations for changes to the laws in Ontario and calls for the adoption of better practices:

IPC - Office of the Information and Privacy Commissioner/Ontario Commissioner Cavoukian lays out path for increased privacy protection & accountability – doing battle with Victoria University

Commissioner Cavoukian lays out path for increased privacy protection & accountability – doing battle with Victoria University

TORONTO – Ontario’s Information and Privacy Commissioner, Dr. Ann Cavoukian, is urging the provincial government to make specific legislative changes and take additional steps to protect privacy and ensure greater accountability.

In her 2008 Annual Report, released today, the Commissioner cites how her sweeping recommendations from her seminal investigation into a privacy complaint against the video surveillance program of Toronto’s mass transit system have been hailed in the United States as a model that cities around the world can build upon, and in Canada as “a road map for the most privacy-protective approach to CCTV.”

Among the recommendations she is making in her 2008 Annual Report, are:

Amend the law to make it clear that all Ontario universities fall under FIPPA

The Commissioner is calling on the government to fix a potential omission in the Freedom of Information and Protection of Privacy Act related to which organizations are covered under the Act.

Under amendments that came into force in mid-2006, publicly funded universities were brought under the Act. Due to the wording of an amended regulation, the University of Toronto, in response to a freedom of information request received under the Act, argued that Victoria University, an affiliated university, was not covered under the Act.

“An IPC adjudicator determined that, based on the financial and academic relationship between the two, Victoria was part of the University of Toronto for the purposes of FIPPA,” said Commissioner Cavoukian. “The University of Toronto has not accepted our ruling and is now appealing it – having it ‘judicially reviewed.’ They have chosen to fight openness and transparency, expending valuable public resources in the process. We find this completely unacceptable, which is why we are prepared to go to battle on this issue, in our effort to defend public sector accountability. We should add that this is contrary to our normal process of working co-operatively with organizations to mediate appeals and resolve complaints informally. In this case, however, the university, having thrown down the gauntlet, left us no choice but to respond in kind and aggressively defend our Order in the courts.”

There are more than 20 other affiliated universities in Ontario that may have a different relationship with the university they are affiliated with, says Commissioner Cavoukian. “I am calling on the government to ensure that all affiliated universities are covered by the Act. There is no rationale for these publicly funded institutions to fall outside of the law.”

The government needs to set specific fees for requests for patients’ health records under PHIPA

The IPC has received a number of inquiries and formal complaints from the public regarding the fees charged by some health information custodians when patients ask for copies of their own medical records.

Ontario’s Personal Health Information Protection Act (PHIPA) provides that when an individual seeks copies of his or her own personal health information, the fee charged by a health information custodian shall not exceed the amount set out in the regulation under the Act or the amount of reasonable cost recovery, if no amount is provided in the regulation. No such regulation has been passed.

Commissioner Cavoukian, in her August 2008 submission to the Standing Committee on Social Policy, which conducted a statutorily mandated review of PHIPA, again raised the need for a fee regulation. Two months later, in its report to the Speaker of the Assembly, the Standing Committee indicated its agreement with the Commissioner’s recommendation, stating that the determination of what constitutes “reasonable cost recovery” should not be left to the discretion of individual health information custodians and their agents.

“The Minister of Health,” said the Commissioner, “should make the creation of a fee regulation a priority.”

Ontario’s enhanced driver’s licence (EDL) needs a higher level of protection

The Commissioner is calling on the Minister of Transportation to provide better privacy protection for the EDL. “The radio frequency identity (RFID) tag that will be embedded into the card can be read not only by authorized readers, but just as easily by unauthorized readers,” said Commissioner Cavoukian. “Over time, these tags could be used to track or covertly survey one’s activities and movements.”

The electronically opaque protective sleeve that will come with these enhanced licences – which drivers without a passport will need as of June 1 to drive across the U.S. border – “only provides protection when the driver’s licence is actually encased in the sleeve,” said Commissioner Cavoukian. “But individuals who voluntarily sign up for these enhanced driver’s licences will not only be required to produce them at the border, but will still have to do so in other circumstances where a driver’s licence or ID card is presently required, including in many commercial contexts. The reality is that most drivers will abandon the use of the protective sleeve.”

“An on-off device on the RFID tag would provide greatly enhanced protection,” said the Commissioner. “The default position would be off since drivers don’t need the RFID to be ‘on’ when routinely taking their licence in and out of their wallets, unless they are actually crossing the border. I am urging the government to pursue adding a privacy-enhancing on-off device for RFID tags embedded in the EDLs.”

FOI REQUESTS

The number of freedom of information requests filed across Ontario in 2008 was the second highest ever – 37, 933, trailing only the 38,584 filed in 2007. Nearly two-thirds of the 2008 requests were filed under the Municipal Freedom of Information and Protection of Privacy Act (24,482), to such organizations as police service boards, municipalities, school boards and health boards. In fact, there were more requests filed to police service boards (13,598) than there were for all organizations under the provincial Act (13,451).

FOI requests may be filed for either personal information or general records (which encompasses all information held by government organizations except personal information). And, the majority of requests each year have been for general records. In 2008 – for the second year in a row – the average cost of obtaining general records under the provincial Act dropped – this time, to $42.74 from $50.54, continuing a reversal of what had been a lengthy trend. The average cost of general records under the municipal Act was $23.54, up only a nickel from the previous year.

Among other key statistics released by the Commissioner:

· Since the IPC began emphasizing in 1999 the importance of quickly responding to FOI requests, in compliance with the response requirements set out in the Acts, the provincial 30-day compliance rate has more than doubled, climbing to 85 per cent from 42 per cent. After achieving a record 30-day compliance rate in 2007 of 84.4 per cent, provincial ministries, agencies and other provincial institutions promptly broke the record in 2008, producing an overall 30-day compliance rate of 85 per cent.

· The Commissioner also reported that her office received 507 complaints in 2008 under Ontario’s three privacy Acts, and 919 appeals from requesters who were not satisfied with the response they received after filing an FOI request with a provincial or local government organization. Overall, the IPC resolved 966 appeals and 534 complaints in 2008. The Information and Privacy Commissioner is appointed by and reports to the Ontario Legislative Assembly, and is independent of the government of the day. The Commissioner's mandate includes overseeing the access and privacy provisions of the Freedom of Information and Protection of Privacy Act and the Municipal Freedom of Information and Protection of Privacy Act, as well as the Personal Health Information Protection Act, which applies to both public and private sector health information custodians, in addition to educating the public about access and privacy issues.

Thursday, May 22, 2008

Ontario Commissioner releases 2007 annual report

The Information and Privacy Commissioner of Ontario tabled her Annual Report 2007 this past week. Apparently it was a good year:

IPC - Office of the Information and Privacy Commissioner/Ontario Major advances made in Access and Privacy, says Commissioner Ann Cavoukian

Major advances made in Access and Privacy, says Commissioner Ann Cavoukian

Court rulings, key decisions by her office and other developments all helped to make 2007 a year of significant progress in advancing both freedom of information and protection of privacy, Ontario Information and Privacy Commissioner Ann Cavoukian said today, as she released her 2007 Annual Report.

“I have never felt as positive about the future of privacy in Ontario as I do right now,” said the Commissioner. “And there have been some very important advances related to access to government-held information.”

PRIVACY PROTECTION

Among the positive developments she cites related to privacy protection:

  • A key court ruling and subsequent ground-breaking order the Commissioner issued that addressed the same core issue – that the collection of extensive personal information from individuals whose only wish was to sell one or more second-hand items to a used-goods store should not end up in police files.
  • In July, the Ontario Court of Appeal struck down a City of Oshawa bylaw that had required used-goods retailers to collect extensive personal information from people who wanted to sell second-hand items to used-goods stores. This personal information was then to be transmitted to, and stored centrally in, a police database – without any restrictions on its use or any judicial oversight.
  • Two months later, following an investigation into a privacy complaint received by her office, the Commissioner invoked – for the first time in the 20-year history of her office – the power to order an institution to cease the collection of personal information and to destroy collections of information collected previously. She ordered the City of Ottawa and the Ottawa Police to stop collecting extensive personal information from individuals selling used goods to second-hand stores and to destroy personal information already collected (with limited exceptions).
  • A ruling by Justice Edward Belobaba of the Ontario Superior Court of Justice that sections of the Adoption Information Disclosure Act breached the Canadian Charter of Rights and Freedoms. “As the Court noted,” said the Commissioner, “the Charter, ‘… is intended primarily to protect individuals and minorities against the excesses of the majority,’ and, accordingly, in this case, the Charter protected the minority who wished to preserve their privacy. I want to emphasize the significance of one of the statements in that Court decision:

    ‘People expect, and are entitled to expect, that the government will not share their confidential or personal information without their consent. The protection of privacy is undeniably a fundamental value in Canadian society.’”

    “It is of critical importance,” said the Commissioner, “that we never forget the Court’s words, ‘… privacy is undeniably a fundamental value in Canadian society,’ because privacy forms the very underpinning of liberty – the very foundation upon which our freedoms are built.”

  • Positive steps were also taken in the development of “transformative technologies” – a new term for privacy-enhancing technologies applied to technologies of surveillance. For example, the Ontario Lottery and Gaming Corporation is evaluating facial biometrics for its “self-exclusion” program, under which some gamblers seek the OLG’s assistance in barring them from gambling in casinos operated by the OLG. Under a contract with the OLG, a University of Toronto team has been researching novel Biometric Encryption (BE) solutions. The system attempts to identify the subjects in the self-exclusion program while protecting the privacy of stored personal information. This information can be accessed only if a correct biometric, i.e. the facial image of a self-excluded person, is presented. In other words, the personal information is in effect “encrypted” with the person’s biometric – extremely privacy protective.

ACCESS IMPLICATIONS

Among the positive developments in 2007 related to freedom of information were several pivotal court rulings. These included:

  • A very significant ruling by Ontario’s Divisional Court which upheld two decisions made by the Commissioner’s office on the application of the solicitor-client exemption to legal fees. “This ruling was a strong endorsement of our approach to the disclosure of legal fee information and underscores our consistent message that governments should actively disclose information about the expenditure of public funds,” said the Commissioner.
  • Another key ruling, which applied the Canadian Charter of Rights and Freedoms, expanded the circumstances under which the public interest may override certain exemptions to accessing information under the Freedom of Information and Protection of Privacy Act (FIPPA). The Ontario Court of Appeal, in effect, amended FIPPA in a way that the IPC had been advocating since 1994, but did not have the authority to change. Section 23 of FIPPA states that where a “compelling public interest” in disclosure “clearly outweighs” the purpose of certain exemptions from the right of access, those exemptions do not apply. As a result of this decision, the IPC (subject to an appeal the Supreme Court of Canada will hear this fall) now has the ability to decide independently whether records subject to the law enforcement and solicitor-client privilege exemptions should be disclosed in the public interest.

RECOMMENDATIONS

Among the recommendations the Commissioner makes in her Annual Report:

  • She is urging Ontario to make a privacy-protective electronic health record a priority.
  • She is calling on the Premier and John Wilkinson, the Minister of Research and Innovation, to advance the development of transformative technologies (privacy-enhancing technologies applied to technologies of surveillance), not only in the area of research, but particularly in the commercialization of such research to facilitate its entry into the marketplace.
  • She is urging all police services in Ontario to abide by the law and give a broad and generous interpretation to recent amendments to the provincial and municipal freedom of information and protection of privacy Acts that now allow police to disclose – in compassionate circumstances – the personal information of someone who has died to his or her family members.
  • Rather than require individual provinces to build their own extensive databases of citizenship information from scratch, she is urging the federal government to make citizenship information available to provinces that want to provide an enhanced drivers’ licence (EDL) that citizens could use as an alternative to a passport, for the purpose of crossing the U.S. border.

FOI REQUESTS SET ANOTHER RECORD

Among the statistical information released by the Commissioner:

  • The number of freedom of information requests filed with provincial or municipal government organizations across Ontario in 2007 – 38,584 – set an all-time high, surpassing the previous record of 36,739, set in 2006. Much of this increase is due to a jump in the number of requests filed with municipalities and police services.
  • The number of privacy complaint files opened under the two public sector privacy Acts – 213 – was the highest in 11 years. (There were 170 privacy complaints in 2006.)
  • And, the number of complaint files opened under the Personal Health Information Protection Act – 338 – set a record. (The old record was 269 in 2006.) Of the 338 complaint files, 227 were privacy complaints and 111 were access or correction complaints.

Commissioner Cavoukian’s 2007 annual report is available on the IPC’s website, www.ipc.on.ca.

The Information and Privacy Commissioner is appointed by and reports to the Ontario Legislative Assembly, and is independent of the government of the day. The Commissioner's mandate includes overseeing the access and privacy provisions of the Freedom of Information and Protection of Privacy Act, the Municipal Freedom of Information and Protection of Privacy Act, and the Personal Health Information Protection Act, and helping to educate the public about access and privacy issues.

Monday, September 03, 2007

BC Commissioner: Student records can be shared to protect public safety

Proably not a surprise for those who regularly work with the provincial public sector privacy laws in Canada, which usually contain a public interest and "health and safety" override:

Records of troubled B.C. students can be shared: privacy commissioner

Universities in British Columbia can share confidential medical records about troubled students if there's a perceived a threat to public safety, the province's privacy commissioner says.

Responding to a U.S. government report issued June 13 on the April 16 massacre at Virginia Tech that left 33 people dead — including the student who fired the gun — David Loukidelis said a university student's confidential medical records can be shared — regardless of the student's age.

"The laws in B.C. fully enable university and college officials to take steps to protect individual and indeed public safety," Loukidelis told CBC News on Monday.

The U.S. report says schools, doctors and police often do not share information about potentially dangerous students because they can't figure out complicated and overlapping privacy laws.

Loukidelis said there's a long list of exemptions in B.C.'s privacy laws that allow a student's private information to be shared for the good of public safety.

Tim Rahilly, senior director of student and community life at Simon Fraser University in Vancouver, said he often noticed the beginning of problems with students and wondered whether that information could be shared.

He said the university would ask the student whether it can talk to the student's parents about the concerns.

"The student can say no and if they are above the age of majority we are a little bit hamstrung," Rahilly said.

Loukidelis said if a student denies a request to share personal information with their parents or school officials, an assessment can be made.

Video

Nil Koksal reports for CBC-TV (Runs: 2:28)

Play: QuickTime »

Play: Real Media »

Tuesday, December 12, 2006

Incident: UCLA database with 800K SSNs hacked

I stopped reporting on information breaches some time ago as they have become too routine. But this one bears commenting upon:

It appears that a database at UCLA containing over eight hundred thousand social security numbers has been hacked. Repeatedly. For over a year. What is most remarkable about this is that a large portion the affected individuals have never been students or employees of the university. Many simply applied for admission, in some cases years before.

Repeat after me: Only collect the information you need (actually, really need) and then only keep it for as long as you actually, really need it.

Personal information is like an underground oil tank. If you need one, they're good to have. Heck, if you need two, have two. But oil tanks are inherently risky. If you don't need an oil tank, for goodness' sake don't put one on your property. If you no longer need it, get rid of it. If you just leave it on your property, the risks leaks (and the ensuing cleanup cost) is too high. It doesn't matter if oil tanks and personal information appear free.

See: Boing Boing: Major identity leak: UCLA database with 800K SSNs hacked