Monday, May 31, 2004

Resource: Organizations' Guide to Complaint Investigations under PIPEDA

The Office of the Privacy Commissioner has just published a handy guide for organizations facing investigations under PIPEDA. For companies in this unhappy position and the lawyers who advise them, this brief guide will probably be very useful:

Fact Sheet: Organizations' Guide to Complaint Investigations under the Personal Information Protection and Electronic Documents Act - Privacy Commissioner of Canada:

An individual has filed a complaint against your organization with the Office of the Privacy Commissioner of Canada.

What happens now?

Our Investigations and Inquiries Branch will review the complaint and an investigator will be assigned to the case.

What is the investigator's role?

The investigator's job is to gather the facts related to the complaint and make recommendations to the Commissioner. These recommendations are based on an analysis of the facts within the framework of the Personal Information Protection and Electronic Documents Act. ..."

Saturday, May 29, 2004

Presentation: PIPEDA and Physicians - MSNS AGM 2004

I was recently invited to give a presentation to the Annual General Meeting of the Medical Society of Nova Scotia on the impact of PIPEDA on physicians. (See presentation: PIPEDA and Physicians - MSNS AGM 2004.)

Since last year, I have been working with National Privacy Services and the Medical Society to design an easy-to implement solution for busy physicians. In our experience, most physicians don't have the time or the inclination to design their own compliance program. And as small business people with tightening revenue, physicians don't have the resources to engage a privacy lawyer to assist them. (Perhaps as important, most doctors don't know about the law, let alone what they need to do to address it.)

The final product is the Physician's Privacy Manual, which includes a complete suite of products that a physician can implement in his or her practice. The Manual includes:

  • Privacy training manual (the only one of its kind designed from the ground up to address privacy in the private practice;
  • Policies and procedures to adopt in the practice;
  • Consent form for affirmative, opt-in consent;
  • Educational tools, including a privacy statement for patients and poster; and
  • Multi-media CD with a one-hour overview of PIPEDA and its requirements.

The procedures and tools contained in the Physician's Privacy Manual have been extensively field tested in private practices and subjected to review by a wide range of physician focus groups. For more information, contact National Privacy Services at http://www.privlaw.com or (toll free) at 1-877-PRIVLAW.

BC privacy watchdog seeks US government, FBI input in Patriot Act

The British Columbia Privacy Commissioner has released a statementthat he will begin an inquiry into the impact of the US Patriot Act on the privacy of British Columbians. Specifically, he is concerned that US federal authorities will have access to personal information of British Columbians if a US company is used as the outsourced service provider for various public services.

Here are links to articles from Google News:

Pending inquiry, government should halt its plan to give private ...
BCGEU, Canada - 11 hours ago
The provincial government should immediately halt plans that would put private information on every British Columbians into the hands of US firms, pending a ...

BC privacy watchdog seeks US government, FBI input in Patriot Act ...
Canada East, Canada - 14 hours ago
VICTORIA (CP) - The FBI and US Attorney General John Ashcroft are being asked to contribute to a British Columbia study of the US Patriot Act. ...

Patriot Act probe begins
CBC British Columbia, Canada - 14 hours ago
VICTORIA - BC's Privacy Commissioner has launched a review of the impact of the US Patriot Act on government plans to contract out the Medical Services Plan to ...

BC privacy czar to study US Patriot Act
CTV, Canada - 12 hours ago
VICTORIA — The FBI and US Attorney General John Ashcroft are being asked to contribute to a British Columbia study of the US Patriot Act. ...

Friday, May 28, 2004

Article: ID Theft from Medical Records

A recent story from Baltimore, MD, highlights the vulnerability of personal information and the need for vigilance. People trust their doctors to maintain their confidentiality, but this trust can be betrayed by unscrupulous employees.

Making Medical Records Identity-Theft Proof

POSTED: 8:47 am EDT May 27, 2004

BALTIMORE -- You trust your doctor to maintain your health but what about your privacy?

Patients from one doctor's office thought their personal information was protected. They were wrong.

WBAL-TV 11 News I-Team reporter Barry Simms discovers how easily your security can be breeched.

Anne Knoeller thought her personal information was secure until an unusual phone call...

Knoeller: "He said check your credit report."

The caller -- a Baltimore County police detective. He told her, "your information's been taken out of a doctor's office."

She was shocked. The alleged thief -- a medical assistant trusted with private patient information. 21-year-old Chanell Cole of Baltimore worked at Hunt Manor Medical Associates in Phoenix. The practice is affiliated with the Greater Baltimore Medical Center....

Full text here ...

Wednesday, May 26, 2004

Article: Google's GMail faces fight on privacy

Privacy International has filed a complaint against GMail, Google's new web-based e-mail service that offers 1GB of storage. The complaint has been filed in a number of jurisdictions, including Canada.

Privacy International: "PI intensifies pressure on Google's Gmail service

Privacy International has filed a complaint asking the privacy and data protection commissions in France,Germany, the Netherlands, Greece, Italy, Spain, Czech Republic, Belgium, Denmark, Sweden, Ireland, Portugal, Poland, Austria,Australia and Canada along with the European Commission and the EU Commissioners internal Article 29 Data Protection Working Group to investigate the serious privacy problems that Google's Gmail service poses."

The most reported aspect of the privacy concerns revolve around Google's intention of serving ads that are based on the content of e-mails. There is also a concern related to the amount of storage offered and the risks that may be associated with it.

See the following media coverage:

London Free Press: Business Section - Google faces fight on privacy: "Google's free e-mail service, Gmail, has come under attack by privacy rights groups that claim it violates privacy laws in many countries. Many Internet service providers (ISPs) offer free e-mail with a limited amount of space to store messages. Gmail's generous 1GB storage capacity comes at a price -- the user's exposure to targeted advertisements based on the contents of their e-mails.

Google's free e-mail storage capacity is more than 100 times that offered by established rivals such as Yahoo and Hotmail. The service is promoted as a means for a user to create a centralized and permanent e-mail archive.

Privacy International filed complaints against Gmail with privacy regulators in Australia, Canada and 15 countries in Europe. "

SignOnSanDiego.com > News > Technology -- Google's free Gmail service comes under fire overseas: "Google's free e-mail service Gmail is under fresh fire from an international privacy rights group that said the soon-to-be-launched service violated privacy laws across Europe and elsewhere.

Privacy International, which has offices in the United States and Europe, said it filed complaints with privacy and data-protection regulators in Europe, Canada and Australia. It had already filed an initial complaint in Britain. "

Bits & Bytes for April 22, 2004: "Google Pressured On Privacy

Yet more Google news: the search giant's plans to include contextually targeted ads in its still-in-beta free e-mail service, Gmail, have drawn more fire.

The search giant intends to have its technology scan the content of e-mail messages, and target ads accordingly. The plan has generated privacy concerns and widespread criticism.

The free consumer service comes with 1 gigabyte of storage and the ability to easily search through old messages. The price of that is letting the company apply its highly successful keyword-advertising infrastructure to the content of the messages. Privacy International is the latest group to protest on grounds of privacy. The group filed a complaint Monday asking privacy and data protection commissions in sixteen countries to investigate potential invasion of consumers' privacy.

The international electronic privacy watchdog complained that the proposed service violates several statutes of the European Union's Data Protection law.

Google says what's drawing concern is what computers are capable of doing, not what the company does in reality. 'We pride ourselves in protecting users' data and holding ourselves to the highest standard,' said Wayne Rosing, VP of engineering for Google.

'We do not keep that data in correlated form, it's separated in various ways and we have policies inside the company that do not allow that kind of correlation to happen. We consider any program or programming that correlates user data with user identity to be a violation of trust and we do not do that,' said Rosing."

Monday, May 24, 2004

Thanks: This blog named "website of the month"

Thanks to the Canada/BC Business Services Society and eBusiness Connection for naming this blog "website of the month".

eNews: "Website of the Month

Looking for more details about how recent privacy legislation changes are affecting how you do business? Be sure to bookmark David Fraser�s Canadian Privacy Law blog. This online journal presents the writings of a Canadian privacy lawyer. Here, Fraser outlines the developments in privacy law containing information related to the Personal Information Protection and Electronic Documents Act (aka PIPEDA) and other Canadian and international laws. www.pipeda.blogspot.com."

Article: Public supportive of strict rules for telemarkers

From today's Toronto Star:

"TheStar.com - Public supportive of strict rules for telemarkers

How to make `do not call' list work

TYLER HAMILTON

Telemarketing.

Doesn't just the sight of the word make your blood boil? Not that all telemarketers are bad, it's just that the very word conjures up the image of dinner-time interruption and an uncomfortable phone conversation that usually ends with the handset crashing to its base.

To its credit, the Canadian Marketing Association is trying its best to separate itself from insensitive, rogue marketers who insist on bothering us at the worst of times and, despite our pleas, call back over and over again, or worse, defiantly challenge us when we say, 'Sorry, not interested.'

The problem is, the CMA only has 800 members - all big, respectable companies with reputations to protect and enough sense to listen when we ask to be removed from their respective calling lists."

Full text here ...

Article: U.S., Canadian firms worlds apart on privacy

Today's Toronto Star reports the results of a study comparing the privacy practices of Canadian and US companies:

"TheStar.com - U.S., Canadian firms worlds apart on privacy:

Compliance, security are aims in states
In Canada, privacy seen as good business

TYLER HAMILTON
TECHNOLOGY REPORTER

Canadian and U.S. companies have vastly different attitudes and motivations when it comes to protecting the privacy of their customers, according to a cross-national study to be released this week.

The study, the first to compare the corporate privacy practices of comparable Canadian and U.S. firms, found that Canadian businesses see their privacy practices as an opportunity to improve relations with customers, while their U.S. counterparts viewed privacy measures more as a way of complying with legislation and avoiding civil lawsuits.

Indeed, 61 per cent of surveyed Canadian companies linked 'good privacy practices' to customer trust and brand loyalty, compared to only 17 per cent of U.S. companies."

Full article here ...

Saturday, May 22, 2004

Privacy Officer Training: Toronto, Ottawa, London

National Privacy Services Inc. will be offering its unique privacy officer training course in London, Toronto and Ottawa, Ontario in the month of June.

Unlike most "privacy seminars" (which I have found to be rambling, too theoretical and disjointed), NPSi's offering is very practical, hands-on and leaves attendees with solid skills and tools to either begin the compliance process for their organizations or to increase their competence in critical skills.

For more information, check out NPSi's training schedule or the links to the individual sessions above.

Friday, May 21, 2004

Thanks for the link! beSpacific: Blog on Canadian Privacy Law Issues

Thanks to Sabrina I. Pacifici for the link from her very useful and frequenly updated beSpacific blog. I never knew until yesterday that Sabrina is also the creator of the fantastic LLRX.

beSpacific: Blog on Canadian Privacy Law Issues
Attorney David T.S. Fraser's blog on the Personal Information Protection and Electronic Documents Act and Canadian privacy law issues provides a wealth of resources, commentary and links, frequently updated, from his home base in the wonderful city of Halifax.