Monday, March 29, 2004

Article: Outsourced UCSF notes highlight privacy risk / How one offshore worker sent tremor through medical system

The heated debate over outsourcing in the United States has included some serious dicussion of privacy issues related to the practice of sending personal information overseas. The San Francisco Chronicle has published a series of articles on outsourcing, which includes one that focuses on this issue in particular.

SPECIAL REPORT / Looking Offshore / Outsourced UCSF notes highlight privacy risk / How one offshore worker sent tremor through medical system: "American jobs have been moving offshore for years, primarily manufacturing work seeking out lower-paid workers abroad. The outsourcing of people's personal information, though, is a relatively new phenomenon -- opening the door to identity theft, fraud and other criminal activities.

'We've reached the point where American companies ship personal information outside the country and tell customers to check their privacy at the shore,' said Rep. Edward Markey, D-Mass., one of the leading privacy advocates on Capitol Hill.

Lubna Baloch's run-in with UCSF demonstrates that the safety of outsourced information can never be guaranteed -- no matter how stringent the safeguards -- and offers the most glaring example to date of how a disgruntled overseas worker can violate the privacy rights of U.S. citizens. "

Concerns related to the confidentiality of personal information in outsourcing are, in my view, likely to be among the most compelling arguments in this debate. Most other concerns relate to job losses, but this issue is one of the only ones that speaks to the protection of consumers. Legislators in the US should consider the alternative of "nearshore" outsourcing to Canada, which has been a growth industry for the Atlantic Provinces in Canada. (See, for example, Keane's great growth in Nova Scotia and EDS's expansion in Nova Scotia.) Companies can take advantage of much lower costs, highly-skilled employees and enforceable privacy laws that are actually stronger than those in the United States.

Article: It's a matter of regaining trust in technology

Australia's The Age publication has a very interesting article on trust and customer relationships. Many businesses have sadly let their customers down and have destroyed the trust that is essential to taking advantage of advanced customer relationship management.

It's a matter of regaining trust in technology - Next - theage.com.au:
"It is not only a problem for the paranoid, because according to Longstaff, 'There has been a precipitous decline in trust in everything because of the public perception of the gap between what someone says and what they do. In terms of technology the gap between what technology promises and what is delivered has been apparent. And the gap between a promise and delivery always gives rise to a decline in trust.'

CRM technology has battled one of the biggest such gaps - because the slick marketing promises of vendors were not easily or cheaply delivered, and only now, several years after the first expensive systems went in, are CRM systems delivering on those promises. Julian Beavis, a vice-president of Teradata, which sells data warehousing and CRM tools, acknowledges that, 'The industry is renowned for grossly simplifying what it takes to do this'.

'It has gone some way to regaining its credibility, and people like the National (Australia Bank, which won an award for its database system in 2003) are making it work.

'The fundamental thing to make CRM work is trust, and that has been squandered, and now we have to get it back,' Beavis says. Getting it back, he believes, will require consumers to experience an alluring level of service underpinned by CRM, which will entice them and eventually rebuild their trust."

Sunday, March 28, 2004

White Paper: Privacy and the tourism industry

A couple of weeks ago, I spoke at the Tourism Industry Association of PEI on the impact of PIPEDA on their sector. As a hand-out, I wrote a brief article entitled Privacy and the Tourism Industry. National Privacy Services Inc. has designed a privacy compliance program for the tourism sector, which is, I believe, the first of its kind. It includes:

  • Privacy manual;
  • Multi-media training CD for privacy officers and staff;
  • Complete consent strategy;
  • Model privacy policies; and
  • Model contractor agreeements.

The second-part, which is optional, is also a first of its kind for the industry. For a low monthly fee, NPSi can act as a company's privacy officer. This allows smaller businesses to take advantage of professional privacy support that they would never be able to afford in-house. More information is available at http://www.privlaw.com.

Thursday, March 25, 2004

Incident: Net firm admits leak of data about 1.4 M clients

The Japan Times is reporting about an incident that occurred last year that probably compromised the personal information of approximately 1,400,000 clients:

The Japan Times Online:

"Net firm admits '03 data leak may affect 1.4 million clients

ACCA Networks Co., a high-speed Internet-access wholesaler, confirmed Thursday that information on some of its customers has been leaked, adding that the leak, which apparently occurred about a year ago, may involve data on about 1.4 million people.

ACCA President Yoshio Sakata said the company acknowledges that personal data on at least 201 customers have been leaked to a third party. He did not rule out the possibility that data on all of ACCA's 1.1 million customers have been leaked, as well as data on some 300,000 people who once were subscribers to the company's services."

Article: Don't 'creep out' your customers

This American article talks about the need to be sensitive to customers when you are dealing with their personal information. The example given probaly woudn't fly in Canada under PIPEDA, but the general theme of the article makes sense:

SearchCRM.com | Don't 'creep out' your customers:

"BALTIMORE -- When it comes to customer privacy, marketers have to do more than just obey the law, says Gartner analyst Adam Sarner. They have to avoid the 'creepiness factor.'

Speaking Monday at the Gartner CRM Summit, Sarner described how he was once contacted by a mortgage company that seemed to be almost flaunting the information it had gathered about him.

'[The letter] said: 'Dear Mr. Sarner, we have used your publicly available records and understand that you pay X amount for your house at X percent,'' Sarner said. 'Creepy, right? 'We were digging around in your data, and this is all the stuff that we know about you.' It kind of creeps you out. ... You have to understand that [people] are a little touchy about this.'"

Tuesday, March 23, 2004

Release: Privacy Law Spurs Jump in Shredding Business

This should come as no surprise:

Privacy Law Spurs Jump in Shredding Business:
"Proshred Sees Accelerated Expansion of Its Door-to-Door Shredding Services As Personal Information Protection and Electronic Documents Act Takes Full Effect

TORONTO, March 23 /CNW/ - With the Personal Information Protection and Electronics Act now in full effect in Canada after a three-year phased-in program, Canadian businesses are increasingly turning to shredding services for assistance in complying with the law's prohibition against disclosing personal information collected during the normal course of commercial activities.

Proshred Security International Inc., Canada's largest mobile shredding service with offices in 350 cities across the country, has seen surging interest in the use of its door-to-door document destruction services by companies and organizations wishing to avoid potential liability under the privacy law.

The company's client roster has expanded by 15 percent in the last six months, with a majority of new customers citing the law as a key reason for coming on board. Inquiries have continued to flow in since January 1 as businesses that had delayed changing their document retention and destruction procedures are scrambling to protect themselves.

'We had a number of proposals with large companies that didn't go anywhere for months or even years because there appeared to be no pressing need for a shredding service,' said Ron Campbell, Proshred President and CEO. 'Now we're seeing those proposals being funded because of this privacy legislation.'

Privacy without tears: In addition to helping uphold the law's ban on unauthorized personal information disclosure by ensuring that information is destroyed before it can be used for illicit purposes, shredding can minimize the burden created by the provision of the law that requires companies to supply all information they have on a specific individual upon request."

Monday, March 22, 2004

Article: More on the Equifax breach

Today's Globe and Mail has another article on the Equifax credit report breach, which was widely publicised last week:

The Globe and Mail: Credit breach too easy, consumer group says -- Critics argue Equifax case underscores how simple it is to abuse confidential files:

"VANCOUVER -- A security breach that allowed criminals to gain access to 1,400 confidential credit files at Equifax Canada was a crime waiting to happen, the president of Consumer Federation Canada says.

'This could have been prevented,' said Dan Barnabic, whose non-profit consumer advocacy group is lobbying the government to tighten regulations covering credit-reporting agencies. Mr. Barnabic said that to access the credit reports at a credit-reporting agency such as Equifax, all a criminal needs to do is set up a front operation."

Friday, March 19, 2004

Article: The Hindu Business Line : They still get in!

From India, an article on spam that misunderstands what PIPEDA is supposed to do about spam.

The Hindu Business Line : They still get in!: "In Canada, the PIPEDA (Personal Information Protection and Electronic Documents) Act has been enacted to have a check on and control spamming. Likewise, anyone in Utah receiving banned spam could sue the sender, even if the message originated from out of state. "

Incident: Equifax admits that more than a thousand credit reports have been compromised

In the last week, the Canadian media have been abuzz with news about a huge security breach on the part of Equifax that apparently allowed criminals access to credit reports on 1,400 Canadians. Credit reports are the best starting place for identity thieves, since they contain names, addresses, social insurance number, birth date, employer, banking information, etc.

Some of the coverage includes:

The Globe and Mail: "'If this was done by a couple of kids who had a friend inside at Equifax who started selling passwords, that's one thing. In that case, I'd be watching my credit cards like a hawk. But if it's linked to Eastern European criminal gangs linked to extortion, that's something else again, and I would be a lot more concerned.' Equifax confirmed on Monday that the credit reports of about 1,400 consumers, primarily in British Columbia and Alberta, 'were accessed by criminals posing as legitimate credit grantors.'"

Credit agency reports security breach - Computerworld: "MARCH 17, 2004 - TORONTO - More than 1,400 Canadians, primarily in the provinces of British Columbia and Alberta, have been notified of a major security breach at Equifax Canada Inc., a national consumer-credit reporting agency.

Equifax confirmed yesterday that it discovered the breach in late February and has notified affected consumers via registered mail asking that they contact the agency to review the contents of their respected credit files. "

Albertans on identity theft hit list: "Criminals posing as credit grantors accessed files, including bank account numbers, credit histories and home addresses. Valerie McLean, of Vancouver's Better Business Bureau, says once a criminal gains access to someone's credit file, they can essentially steal that person's identity.

'They have your date of birth. They have your full name. They have your former names. They have your occupations. They have your address. And they know what financial institutions you're doing business with and what credit cards you hold,' she said."

CTV.ca - Personal info stolen from Equifax database- CTV News, Shows and Sports -- Canadian Television: "Though the company only announced the security breach on Monday, the RCMP has been investigating for the past month.

'The RCMP is in fact looking into this matter,' confirms RCMP Sgt. John Ward, but would say no more. It's not the first trouble for Equifax. The company was targeted by criminals two years ago, stealing 2,500 credit reports from mailboxes. Using the information, the thieves applied for new credit cards."

Monday, March 15, 2004

Letter to BC and Alberta Information and Privacy Commissioners - Privacy Commissioner of Canada

Residents of British Columbia and Alberta are caught in a state of jurisdictional overlap with respect to privacy laws. PIPEDA applies to commercial activities, except in those provinces that have enacted legislation that has been declared to be substantially similar. Both BC and Alberta have private sector privacy laws that came into effect on January 1, 2004, but none have been declared by the federal parliament to be "substantially similar". It appears that complainants can go to both the federal and provincial commissioners to complian about a provincially-regulated business.

The federal Privacy Commissioner has just released a letter to the commissioners for BC and Alberta on how to handle this overlap until the federal cabinet makes such a declaration:

The Privacy Commissioner of Canada, Jennifer Stoddart, sent the following letter to Mr. Frank Work, Information and Privacy Commissioner for Alberta, and Mr. David Loukidelis, Information and Privacy Commissioner for British Columbia, regarding the handling of complaints under PIPEDA as of January 1, 2004.

March 11, 2004

Mr. Frank Work
Information and Privacy Commissioner
Office of the Information and Privacy Commissioner
4th floor 9925,109 Street
Edmonton AB T5K 2J8

Mr. David Loukidelis
Information & Privacy Commissioner for British Columbia
Office of the Information and Privacy Commissioner
PO Box 9038, STN Prov Govt
Victoria, BC V8W 9A4

Dear Mr. Work and Mr. Loukidelis:

Handling of complaints under PIPEDA as of January 1, 2004

This letter will serve to confirm the discussions we had in Ottawa on January 21, 2004 concerning our current and future handling of complaints by our Office where the complaint is against an organization in, as the case may be, British Columbia or Alberta.

Our understanding is as follows:

  • Until the BC and Alberta Personal Information Protection Acts (PIPAs) are, respectively, declared to be substantially similar by the Governor in Council;
  1. The Office of the Privacy Commissioner of Canada (OPC) has a legal obligation to apply the Personal Information Protection and Electronic Documents Act (PIPEDA) where appropriate.
  2. OPC will take complaints against private sector organizations in BC and Alberta that are collecting, using or disclosing personal information about their customers in the course of commercial activity. This includes organizations that deal in personal health information such as physicians and dentists’ offices, private laboratories, etc.
  3. OPC will verbally inform complainants of the possibility of complaining directly to the appropriate provincial commissioner and that complaints which fall clearly in provincial rather than federal jurisdiction, after a substantially similar order, will be transferred in any event.
  4. If the complainant wishes nevertheless to proceed federally, OPC will open a complaint file but will inform all parties to the complaint that there will be a transfer of the complaint and all information on the file to the appropriate provincial commissioner if and when a substantially similar order is made.
  • OPC will continue, after any substantially similar order is made, to take complaints concerning federal works, undertakings and businesses (FWUBs), including complaints about employee personal information and information about job applicants to FWUBs.
  • Complaints involving inter-provincial issues will be handled by OPC in accordance with the following principles.
  1. Before the making of a substantially similar order, the complaints will be handled as per (2) above in all cases unless the complaint is substantially about the crossing of inter-provincial boundaries or the issue otherwise falls under OPC’s jurisdiction.
  2. After the making of a substantially similar order, complaints will be handled as per arrangements which we will continue to develop between OPC and your respective offices.
  • Our offices are also currently discussing the following issues:
  1. arrangements to share the contents of complaints files where circumstances warrant and consistent with our respective legal authorities and obligations;
  2. harmonization of statistical reporting and language for such reporting where possible;
  3. development of joint statements, questions and answers, and jurisdictional tools where possible.

The arrangements set out above reflect current practices in our respective offices, but may change over time. In light of that, we have each agreed to name individuals in our respective offices to engage in day-to-day discussions on issues as they arise. We also agree to keep the channels of communication open at the most senior levels and will attempt to meet as frequently as required and possible.

We are pleased that we have been able to reach these understandings and look forward to continuing to work with you to effectively protect the privacy rights of individuals.

Yours sincerely,

Jennifer Stoddart
Privacy Commissioner of Canada

c.c. Provincial Commissioners