Saturday, December 11, 2004

Insightful blog-post on the nature of privacy

Bruce Schneider, one of the leading thinkers on security has recently had some interesting things to say about privacy. In my experience, most IT-types usually think about privacy as being primarily a security issue: you keep information private by keeping the baddies out. But privacy is more than that. It's about giving people control over their own personal information....

Schneier on Security: The Digital Person:

"Last week, I stayed at the St. Regis hotel in Washington, DC. It was my first visit, and the management gave me a questionnaire, asking me things like my birthday, my spouse's name and birthday, my anniversary, and my favorite fruits, drinks, and sweets. The purpose was clear; the hotel wanted to be able to offer me a more personalized service the next time I visited. And it was a purpose I agreed with; I wanted more personalized service. But I was very uneasy about filling out the form.

It wasn't that the information was particularly private. I make no secret of my birthday, or anniversary, or food preferences. Much of that information is even floating around the Web somewhere. Secrecy wasn't the issue.

The issue was control. In the United States, information about a person is owned by the person who collects it, not by the person it is about. There are specific exceptions in the law, but they're few and far between. There are no broad data protection laws, as you find in the European Union. There are no Privacy Commissioners, as you find in Canada. Privacy law in the United States is largely about secrecy: if the information is not secret, there's little you can do to control its dissemination...."

If you aren't a regular reader of Schneider on Security, I highly recommend adding it to your blogroll.

SuperPages.ca announces fix for security issues

A few days ago, I posted about a security issues on the SuperPages.ca website that allowed anyone to alter residential telephone listings (see PIPEDA and Canadian Privacy Law: Glitch lets you mess with the phone book). SuperPages has issued a press-release announcing that they have fixed the issues: SuperPages.ca restores People Finder online residential listings service: Changes ensure security for customers:

"BURNABY, BC, Dec. 10 /CNW/ - SuperPages(TM) announced today that it has relaunched the People Finder portion of its SuperPages.ca Web site, following upgrades to the security features of the online residential listings service.

SuperPages(TM) placed its extensive People Finder service back online at 11.00am this morning. SuperPages.ca removed the residential listing service Wednesday afternoon because an updating tool that allowed users to change their address and email information was not fully secure. The Business Finder service, which lists 1.3 million businesses nationally, was not affected by the security issue or loss of service.

In order to ensure that users residential information remains secure, SuperPages.ca has now removed the updating tool from the People Finder service.

'Our customers' privacy and security is of utmost importance to us at SuperPages.ca,' said Todd Millar, the president of SuperPages(TM). 'We took the People Finder service offline after we became aware that the potential to change residential listing information still existed.'

SuperPages.ca's People Finder function provides users with access to 11.7 million residential listings in Canada and 1.5 million residential listings in British Columbia. With several million searches each month on the People Finder Service, SuperPages.ca is Western Canada's premier online directory.

'I can assure all of our SuperPages.ca users that our residential listing information remains both accurate and secure,' said Millar. "

Thursday, December 09, 2004

Authorities give US prisoner detailed personal information on Albertans

Here's a head-scratcher. A prisoner is a US jail, facing deportation to Canada, was given highly sensitive information about a number of Albertans so he could apparently prepare to fight the extradition order. The prisoner may be accused of a savage beating, but at least he knows that he probably should have the info:

Privacy shocker:

"Skinhead Daniel Sims has in his U.S. jail cell the SIN numbers of staff of the Edmonton law firm that sued him after he beat former broadcaster Keith Rutherford so badly he lost an eye. The SIN numbers - including that of high-profile Edmonton lawyer Tom Engel - are included in a 1,000-page immigration file Sims obtained this week from American authorities as he battles deportation back to Canada.

Sims said the documents include financial information such as total income, taxes paid and Canada Pension Plan contributions made by Engel and his wife in 2001 - two years after Rutherford's lawsuit was concluded.

'I got this from the U.S. Attorney's office but because the file is so big they didn't notice,' said Sims, 33, from his Kern County jail cell in Bakersfield, California.

'As far as me and Tom Engel, there's no way I should have this. I don't really want it.' ...."

The Information and Privacy Commissioner of Alberta says he'll investigate if he receives a complaint.

Bank faxes saga continues; involves other banks, too

Perhaps spurred by the coverage of the CIBC faxing incidents, more people are contacting the media to report having received misdirected bank faxes. And it is not just CIBC that is affected as CTV.ca reports: CTV.ca | More people report receiving bank faxes. Also, check out the video of their television reports on the right-hand column of the page.

Everyone would be well advised to read the Alberta Information and Privacy Commissioner's fact sheet on faxing sensitive medical information: "Guidelines on Facsimile Transmission"".

Update: April 18, 2005 - PIPEDA and Canadian Privacy Law: Privacy Commisioner of Canada releases her report on the CIBC faxing incidents

Wednesday, December 08, 2004

Do not call legislation on the way

Both the Toronto Star and CTV are carrying stories predicting that long-awaited "no not call" legislation is on the way, sooner rather than later.

CTV.ca | Canadian do-not-call legislation coming: report:

"By the end of next week, Canadian lawmakers could be considering a bill aimed at ending the scourge of unwanted phone calls from telemarketers.

According to a report in The Toronto Star, legislation to create a national do-not-call registry similar to one already launched in the United States is expected to be tabled before the end of next week.

The bill is expected to bar telemarketers from calling anyone on the list, unless they have established a pre-existing relationship. That means someone who's requested information about a specific service can be contacted.

Previous legislation that would have allowed Canadians to register with such a list died with the last federal election call.

Under current Canadian Radio-television and Telecommunications Commission regulations, telemarketing agencies must maintain their own registry of people not wishing to be called. Numbers appearing on those lists can't be faxed or phoned for three years....."

And from the Toronto Star:

TheStar.com - National 'do-not-call' registry likely:

"The Liberal government is widely expected to introduce legislation next week that would create a national do-not-call registry, giving Canadian households the option of shielding themselves from unwanted telemarketing calls.

A similar registry was introduced with great fanfare last year in the United States and has already attracted more than 66 million households. Government and industry sources said a bill is likely to be tabled before the House of Commons breaks next week for the holidays, but could be delayed until it sits again in late January.

'I am convinced now that they have every intent of doing it, and doing it very soon,' said John Gustavson, president of the Canadian Marketing Association, which has supported a national registry since 2001. 'We think it's the right way to go, and we think it will be valuable information for marketers and valuable relief for consumers.'...."

As a complete aside, I find it interesting that Canadian marketing organizations, unlike their US counterparts, favour DNC laws and privacy laws.

Red cross employee implicated in ID theft of blood donors

Even if the organization is 100% benevolent and trustworthy, you still need to be concerned about the employees. Case in point: three (former -- hopefully!) employees the Red Cross have been indicted for stealing the identities of 40 blood donors, using information collected during corporate blood drives:

Three indicted in identity theft scheme victimizing blood donors:

"A Red Cross employee and two other people were accused Friday of stealing the identities of about 40 blood donors and using the information to obtain about $268,000 in cash and merchandise.... "

More on biometrics and the workplace

The last month has been rich pickings for observers of privacy in Canada. The country's leading media outlets have had an abundance of coverage of privacy issues. Today, it is the Globe and Mail with an article on biometrics in the workplace, focusing on the use of fingerprint devices to authenticate and log users onto their systems. Or, in this case, their cash registers:

The Globe and Mail: Print scans: retail tool or invasion of privacy?:

"When Carly Johannesson takes her post at the IDA drugstore's cash register in Medicine Hat, Alta., she places her finger on a small pad that reads the fingerprint and electronically gives her access to the system.

With that simple tap, she finds herself on the front lines of one of the more contentious retailing issues: whether employers' use of fingerprint scans is another smart business tool or a move by Big Brother to gather data that some believe should remain private.

'It has tremendous potential, especially in terms of speeding up processes and internal security,' says Gary Joachim, co-owner of the Medicine Hat pharmacy, which implemented the system a few months ago. 'As employers, we're tied to a lot of confidential information from our employees, like social insurance numbers. This is just one more thing that's added to the kettle of confidential information.'

Computer users are tapping into fingerprint identification more frequently to log on to their terminals, but now the technology is arriving in the retail sector, opening up new opportunities and issues for those in the field....."

CIBC faxes reportedly misdirected to another person

The newswires are carrying a report that CIBC's fax problems weren't only with a junkyard in West Virgina.

Report:2nd Man Received Confidential CIBC Data -CP :

"Wednesday December 8, 3:34 AM EST

NEW YORK (Dow Jones)--A second businessman says the Canadian Imperial Bank of Commerce (CM.T) has been faxing him confidential customer information for several years -the second such privacy breach revealed in less than two weeks, the Montreal Gazette reported on Wednesday, according to the Canadian Press.

Local businessman Stephen Oakes told the Gazette the CIBC has been sending private information about its customers to his toll-free number for four years, CP reported.

Oakes estimates he has received 24 CIBC faxes since 2000, containing names, home addresses, social insurance numbers and bank plan account numbers, CP reported. ..."

For the background to this story, see "PIPEDA and Canadian Privacy Law: Misdirected fax saga continues" and the news reports it links to.

Update: April 18, 2005 - PIPEDA and Canadian Privacy Law: Privacy Commisioner of Canada releases her report on the CIBC faxing incidents

Article: Privacy issues of receipts and the OPC's resources issues

Full points to the Toronto Star for its very strong coverage of privacy issues.

A column in today's edition discusses the privacy problems associated with companies that continue to print the full debit and credit card numbers on receipts and, more importantly, the huge lack of resources hampering the responsiveness of the Office of the Privacy Commissioner. The OPC, under PIPEDA, has up to a year to issue a finding and it appears to be taking about that long. Michael Geist's complaint, blogged about in "Privacy Commissioner issues first spam decision under the Personal Information Protection and Electronic Documents Act (PIPEDA)", was filed in February of this year and took about ten months to result in a finding. See the Star's column:

TheStar.com - It's up to the public to enforce privacy law: "

When Denise Ranger ordered Chinese food recently, she was shocked to see her credit card number and expiry date printed in large type on the receipt � along with her address and telephone number.

'Any person could take my telephone number, go to the Internet, find my full name and shop to their heart's content, or even take my identity,' she says.

When she called the office of the Privacy Commissioner of Canada, she found something equally shocking: It would take up to a year to investigate her complaint.

The privacy commissioner's office is short-staffed. It has only one person handling calls from the public.

Renee Couturier, a privacy commission spokeswoman, didn't realize the call centre was down to one full-time staff member until I asked her to double-check.

'We had five inquiry officers at our peak,' she says. 'When we have critical periods, we have to pull people from other areas to assist.' ...."

Privacy the 'Hot' Topic of 2004?

As soon as it came to my attention, I added Michael Fitzgibbon's fantastic blog Management Updates: Thoughts from a Management Lawyer to my blogroll. He consistently has very high quality analysis and insights on important issues that affect all employers. (He's also a charter member of the Canadian legal blogging community.)

Needless to say that I wholeheartedly agree with his post that privacy is consistenly one of the hot topics of 2004. I just hope it will continue to be so in 2005! Check it out: Privacy - The 'Hot' Topic of 2004?