Saturday, July 31, 2004

Article: Suit charges Prozac privacy violations -

Over the years, there have been a series of stories like this one ..

Suit charges Prozac privacy violations - (United Press International):

"Fort Lauderdale, FL, Jul. 15 (UPI) -- Court papers filed this week in Fort Lauderdale, Fla., show pharmaceutical companies mailed unsolicited doses of Prozac to potential customers.

A deposition filed in a privacy suit brought by some of the recipients of the anti-depressant said the companies got the names and addresses from physicians, the South Florida Sun-Sentinel reported Thursday.

In one case, Dr. Ken Burke admitted supplying his signature on a blank piece of office stationery that a company representative, a frequent fishing companion, attached to the free drugs. Two other doctors from the same office also said they provided their signatures.

The trial packages of a new weekly form of Prozac were sent mostly to users of the standard medication but at least one recipient -- a 16-year-old boy -- had never used anti-depressants.

The suit has also prompted a criminal investigation by the state and criticism from consumer advocates who say it is an example of the improper relationship between doctors and drug companies.

Thanks to Privacy.Org for the pointer to this article.

Article: Privacy Expert To Publishers: Don't Bury It In The Privacy Policy

Here's an interesting article, reporting on a speech given by D. Reed Freeman, chief privacy officer, vice president-legislative and regulatory affairs, Claria Corp. He formerly worked with the US Federal Trade Commission. In short, if the customer would be surprised at what you propose to do with his/her personal information, you need to bring the practice to his/her attention.

Privacy Expert To Publishers: Don't Bury It In The Privacy Policy

Publishers that think their privacy policies are sufficient should think again. Claria Corp.'s chief privacy officer told attendees at the Jupiter Advertising Forum to expect more enforcement where privacy issues surrounding behavioral marketing are concerned. Freeman argued that anything a consumer is likely to be surprised by must be extracted from a privacy policy and made plain. "Ask yourself," Freeman told the crowd, "Is there something going on here that would surprise your mother or a sick uncle?"

Full text of the article here ...

Article: U.S. laws put Canadian privacy at risk

You can always count on Michael Geist to provide good commentary on privacy issues. His latest LawBytes article in the Toronto Star adds to the debate about the collision between the USA Patriot Act (among others) and Canadian privacy laws:

TheStar.com - U.S. laws put Canadian privacy at risk:

"Although it has garnered only limited attention in the rest of the country, for the past few months the British Columbia privacy and information technology communities have been embroiled in a high-stakes issue that raises difficult questions about the effectiveness of Canadian privacy law and the potential threat posed by data outsourcing to the United States. "

One thing that we shouldn't forget is that PIPEDA gives Canadian law enforcement access to Canadian personal information without consent and without notice to the individual concerned.

7(3) For the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may disclose personal information without the knowledge or consent of the individual only if the disclosure is

(c) required to comply with a subpoena or warrant issued or an order made by a court, person or body with jurisdiction to compel the production of information, or to comply with rules of court relating to the production of records;

(c.1) made to a government institution or part of a government institution that has made a request for the information, identified its lawful authority to obtain the information and indicated that

(i) it suspects that the information relates to national security, the defence of Canada or the conduct of international affairs,

(ii) the disclosure is requested for the purpose of enforcing any law of Canada, a province or a foreign jurisdiction, carrying out an investigation relating to the enforcement of any such law or gathering intelligence for the purpose of enforcing any such law, or

(iii) the disclosure is requested for the purpose of administering any law of Canada or a province;

(c.2) made to the government institution mentioned in section 7 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act as required by that section;

*(c.2) made to the government institution mentioned in section 7 of the Proceeds of Crime (Money Laundering) Act as required by that section; *[Note: Paragraph 7(3)(c.2), as enacted by paragraph 97(1)(a) of chapter 17 of the Statutes of Canada, 2000, will be repealed at a later date.]

(d) made on the initiative of the organization to an investigative body, a government institution or a part of a government institution and the organization

(i) has reasonable grounds to believe that the information relates to a breach of an agreement or a contravention of the laws of Canada, a province or a foreign jurisdiction that has been, is being or is about to be committed, or

(ii) suspects that the information relates to national security, the defence of Canada or the conduct of international affairs;

Thursday, July 29, 2004

Not for me, thanks: Under-the-skin ID chips move toward U.S. hospitals

File this under "c" for creepy:

Under-the-skin ID chips move toward U.S. hospitals - News - ZDNet:

"VeriChip, the company that makes radio frequency identification--RFID--tags for humans, has moved one step closer to getting its technology into hospitals.

The Federal Drug Administration issued a ruling Tuesday that essentially begins a final review process that will determine whether hospitals can use RFID systems from the Palm Beach, Fla.-based company to identify patients and/or permit relevant hospital staff to access medical records, said Angela Fulcher, vice president of marketing and sales at VeriChip.

VeriChip sells 11-millimeter RFID tags that get implanted in the fatty tissue below the right tricep. When near one of Verichip's scanners, the chip wakes up and radios an ID number to the scanner. If the number matches an ID number in a database, a person with the chip under his or her skin can enter a secured room or complete a financial transaction."

Full text is available here ...

UK Big Brother Awards

A followup to my previous post. Privacy International announced the awarding of their annual Big Brother Awards last night:

Privacy International:

"Privacy International Announces Winners of 6th Annual Big Brother Awards

28/07/2004

PRIVACY INTERNATIONAL ANNOUNCES WINNERS OF
THE 6th ANNUAL BIG BROTHER AWARDS

WINNERS INCLUDE MARGARET HODGE MP AND BRITISH GAS.

28th July 2004

On July 28th, the human rights watchdog Privacy International will present the 6th annual 'Big Brother awards' to name and shame the government and private sector organisations that have done the most to invade personal privacy in Britain.

The awards will be bestowed at a special event at the London School of Economics. Awards will also be given to individuals and organisations that have made an outstanding contribution to the protection of privacy. "

Full text of the announcement and info on the winners is available here: http://pi.gn.apc.org/article.shtml?cmd[347]=x-347-63280

Wednesday, July 28, 2004

Video: ACLU - Pizza

This entry represents a first ... I've never linked to a video before, but the ACLU has released an interesting and eye-opening flash animation, illustrating a bit of a worst-case scenario for linked databases. Check it out:

ACLU - Pizza:

"The government and corporations are aggressively collecting information about your personal life and your habits. They want to track your purchases, your medical records, and even your relationships. The Bush Administration's policies, coupled with invasive new technologies, could eliminate your right to privacy completely. Please help us protect our privacy rights and prevent the Total Surveillance Society.

Government programs such as MATRIX and Carnivore are destroying our privacy. We live in a democratic society and government-controlled data systems are a dangerous step toward establishing a 24-hour surveillance society.

Recently Northwest Airlines provided the names, addresses, travel plans and credit card numbers of its customers to a NASA project in complete violation of its own privacy policy. In another example, JetBlue provided information from over a million of its customers to the Transportation Security Administration, also in violation of its own privacy policy."

Tuesday, July 27, 2004

Oops: Sentech Confidentiality Breach

Watch those attachments!

allAfrica.com: South Africa: Sentech Confidentiality Breach:

"Sentech has e-mailed a database of MyWireless users to some of its clients, in what one user described as a 'serious breach of confidentiality'.

Astonished MyWireless clients forwarded copies of the database to ITWeb this morning, saying it had been attached to an e-mail they received from Sentech at the weekend. The e-mail purported to contain an attachment outlining Acceptable Use Policy. The Excel database includes names, addresses and contact numbers of around 1 500 users.

User groups who have campaigned to get Sentech to improve its MyWireless service said this morning that they were hoping to arrange a meeting with Sentech soon. 'We don't want to fight with Sentech over things like this,' one said. 'We just want the service to work properly.'"

Monday, July 26, 2004

Labor groups raise outsourcing privacy concerns | CNET News.com

More coverage on the BC outsourcing privacy debate. This time, American CNET News.Com has a report that hightlights a submission co-written by Michael Geist, one of the leading Canadian academics on privacy and technology law:

Labor groups raise outsourcing privacy concerns | CNET News.com A 34-page legal analysis released Monday suggests that the Canadian unions are exaggerating the impact of the Patriot Act. A section of the law enacted after the Sept. 11, 2001 terrorist attacks lets police obtain records from any company with a U.S. branch if the information is said to be "relevant" to a terrorism investigation. The request is made to a secret court that meets behind closed doors in Washington, D.C.

The report, written by Michael Geist and Milana Homsi and filed with the BC Privacy Commissioner, says that current rules granting police the power to review data are "not significantly different than that which was available in a pre-Patriot Act era through grand jury subpoenas and national security letters." (National security letters are a type of administrative subpoena that doesn't require a judge's prior approval.)

The report also says that a Canadian law called the Personal Information Protection and Electronic Documents Act authorizes companies to secretly disclose data to government officials--a definition that could include U.S. police.

Saturday, July 24, 2004

Release: B.C. leads Canada in privacy protection

An earlier blog entry mentioned that BC is planning to strenthen their public sector privacy legislation to prevent access to British Columbians' data by foreign governments. (See the entry here.) The B.C. government's press release is available here: "B.C. LEADS CANADA IN PRIVACY PROTECTION". Also of interest is the BC Government's submission to the BC Privacy Commissioner's study on the impact of the USA Patriot Act on the privacy of Lotuslanders: http://www.gov.bc.ca/mser/down/submission.pdf

Friday, July 23, 2004

CBC News: P.E.I. to track prescription drug abuse

Prescription drug abuse has consistently presented one of the greatest challenges to the privacy of patient prescriptions. Health Canada has recently required many pharmacists to report prescriptions of certain drugs. Now it looks like the government of Prince Edward Island is proposing to introduce a province-wide computer system to drack prescriptions. Privacy is obviously an issue. Pharmacists and private practice physicians are subject to PIPEDA and are unable to disclose personal information without consent.

CBC News: P.E.I. to track prescription drug abuse:

"Last Updated Fri, 23 Jul 2004 15:22:45 EDT

The government's software could let doctors, hospitals and pharmacists share information on what prescriptions their patients are pocketing, but it's unlikely they will have access when the system launches in the fall.

Under the privacy act, doctors and pharmacists are not allowed to trade information about a patient without that person's consent."

One thing to remember is that PIPEDA has a catch-all exception to the consent principle buried in the end of section 7:

(3) For the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may disclose personal information without the knowledge or consent of the individual only if the disclosure is ...

(c.1) made to a government institution or part of a government institution that has made a request for the information, identified its lawful authority to obtain the information and indicated that ...

(iii) the disclosure is requested for the purpose of administering any law of Canada or a province;

...

(i) required by law.

If the pharmacist is "required by law" to disclose the information, the pharmacist arguably may dispense with consent.