Thursday, February 10, 2005

Federal Court of Appeal issues a declaration in the Englander case

According to Mathew Englander's website, the Federal Court of Appeal today issued its decision with respect to his remedy. There was no order issued, but the Court did declare that Telus had contravened PIPEDA. Stay tuned for a link to the decision and some commentary on it.

Mathew Englander, privacy advocate:

"UPDATE: On February 10, 2005 the Court issued its decision on remedy. The Court declined to order Telus to comply with the Act in future, but issued a judicial declaration that Telus had contravened the Act in the past.

The Court held that Telus has infringed PIPEDA in not informing its first-time customers, at the time of enrolment, of all the purposes for which their personal information is collected and in not informing them at that time of non-published number service. On the other issue, the Court held that the fee Telus charges does not infringe the Act.

This is the first time a court has ruled that an organization breached PIPEDA."

Update: Mathew has put the decision on his site at http://www.mathew-englander.ca/fca-order-09feb2005/

Will back-to-school sales include tinfoil suits?

A rural school in the US is planning to make their students wear RFID-embeded tags to track their movements. As a client of mine just mentioned to me, "Is this to get them used to being surveilled while they're young?"

Yahoo! News - Parents Protest Student Computer ID Tags:

"SUTTER, Calif. - The only grade school in this rural town is requiring students to wear radio frequency identification badges that can track their every move. Some parents are outraged, fearing it will take away their children's privacy. ..."

Anti-terror laws spark concerns about abuse, trampling of freedoms

The Canadian federal government commissioned a study of Canadians' attitudes to the Anti-Terrorism Act, which is summarized in the following CP story:

Yahoo! News - Anti-terror laws spark concerns about abuse, trampling of freedoms:

"OTTAWA (CP) - Canadians worry federal anti-terrorism powers could be used to invade personal privacy, unfairly target minorities or turn neighbours into snitches, a government study has found. ...."

Wednesday, February 09, 2005

Alberta Commissioner finds three businesses failed to protect personal information from identity thieves

The Alberta Information and Privacy Commissioner has released three investigation reports, castigating three Alberta businesses for failing to protect personal information from identity thieves.
Investigations find Alberta businesses failed to protect personal information from identity thieves

Recent investigations by the Office of the Information and Privacy Commissioner (OIPC) found that three Alberta businesses failed to protect personal information in their custody.

On November 24, 2004, Edmonton Police Service (EPS) notified the OIPC that documents containing personal information from a number of Alberta businesses were found during a police investigation. Some of the records were found in a motel room; others were subsequently turned over to police by two individuals charged with credit card fraud. The records included return of goods slips, debtor account files from a collection agency, and cell phone contracts. Personal information in the records included Social Insurance Numbers, bank account information, credit card numbers, and customer signatures.

In response to the information from EPS, Information and Privacy Commissioner Frank Work initiated investigations of Linens ‘N Things, Nor-Don Collection Network Inc., and Digital Communications Group Inc., under the Personal Information Protection Act (PIPA).

PIPA applies to private sector organizations in Alberta, and requires them to protect personal information against such risks as unauthorized access, collection, use, disclosure, copying, modification, disposal or destruction.

The investigators found that these businesses failed to protect personal information in their custody.

Recommendations from the investigations required all three organizations to contact the individuals whose information was, or may have been, exposed to identity theft. In at least one case this meant contacting hundreds of customers. Additional recommendations required the organizations to:

  • ensure all records containing personal information are stored securely,
  • limit access to personal information to staff on a “need-to-know” basis,
  • develop procedures for storage, retention and destruction of personal information, and
  • provide privacy and security training/awareness for employees.

One organization was also required to obtain computer equipment to obscure credit card numbers printed on receipts and return slips. Along with the affected individuals, these three businesses were victimized in these incidents, but each is responsible under PIPA for securing personal information.

The OIPC is advising other businesses not to put themselves in the same situation.

To obtain a copy of an Investigation Report, click the following links:

Investigation #P2005-IR-001 http://www.oipc.ab.ca/ims/client/upload/P2005_IR_001.pdf (Linens ‘N Things)

Investigation #P2005-IR-002 http://www.oipc.ab.ca/ims/client/upload/P2005_IR_002.pdf (Nor-Don Collection Network Inc.)

Investigation #P2005-IR-003 http://www.oipc.ab.ca/ims/client/upload/P2005_IR_003.pdf (Digital Communications Group Inc.)

Pressure builds to name privacy-law offenders

Up to now, one of the loudest advocates of having the Privacy Commissioner "name names" has been Michael Geist (see Geist: Revise privacy law to expose offenders, block snoops, Article: Weak enforcement undermines privacy laws). Two additional voices have been added to the chorus, according to this article in the The Toronto Star:

TheStar.com - Pressure builds to name privacy-law offenders:

"Canadians had high expectations of a new privacy act that came into force on Jan. 1, 2004, designed to safeguard personal information in the private sector.

But the high hopes have not been fulfilled, according to two recent critical reports.

The Personal Information Protection and Electronic Documents Act (PIPEDA) "has not been kind to consumers," says the Public Interest Advocacy Centre.

...

People who bring a complaint to the privacy commissioner are free to make the full findings public.

But few do.

...

Similar arguments are made by Chris Berzins, a lawyer with the Ontario labour ministry, in an article published in the Canadian Journal of Law and Technology.

"The all but categorical refusal to reveal the names of complaint respondents," he says, "has a number of unfortunate results."

  • It greatly undercuts the instructive value that complaint investigations might have.
  • It deprives companies of the recognition they deserve when they comply with the law.
  • It unjustly rewards companies that flout the law.
  • It penalizes consumers who are unable to make informed privacy decisions.
  • It prevents the market from rewarding or penalizing companies based on the public's awareness of privacy practices.
  • It makes it difficult to assess the effectiveness of the commissioner's office in promoting compliance.

..."

I am of two minds on this issue. I have acted for a number of companies that have been complained about. In most cases, the matters complained about are relatively minor and the situation that gave rise to the complaints were inadvertent mistakes. In at least one case, they resolved the matter long before complaint ever went to the Commissioner, leaving us scratching our heads as to why they decided to proceed in that manner. It would be unfair to penalize companies acting in good faith that make an honest mistake, fix it and move on. But in cases where the consequences of the violation is significant or was a result of not being concerned about customer privacy, naming names may provide a wake-up call.

Tuesday, February 08, 2005

EFF helps online service providers to minimise data collection

The Electronic Frontier Foundation has just released an interesting software product to assist online service providers in limiting the information that they collect from users. I'd describe it, but I might as well let EFF speak for itself:

EFF: Best Practices for Online Service Providers:

"Online service providers (OSPs) are vital links between their users and the Internet, offering bandwidth, email, web, and other Internet services. Because of their centrality, however, OSPs face legal pressures from all sides: from users, industry, and government. Here we offer information for people who run and use OSPs in order to help them make sound, ethical decisions about how to safeguard private data and preserve freedom of expression online.

Legal and Technical Policy Suggestions for Data Logging

As an intermediary, the OSP finds itself in a position to collect and store detailed information about its users and their online activities that may be of great interest to third parties. The USA PATRIOT Act also provides the government with expanded powers to request this information. As a result, OSP owners must deal with requests from law enforcement and lawyers to hand over private user information and logs. Yet, compliance with these demands takes away from an OSP's goal of providing users with reliable, secure network services. In this paper, EFF offers some suggestions, both legal and technical, for best practices that balance the needs of OSPs and their users' privacy and civil liberties. "

Monday, February 07, 2005

Italian personal data protection code

Alessandro Monteleone has sent me a link to his site http://www.dataprotection.it. The front page is mostly in Italian, but his site includes an English version of the Italian personal data protection code, along with some commentary. Worth bookmarking.

Sunday, February 06, 2005

Your Statements Went Where?

The Washington Post (via Yahoo! News) is carrying a lengthy story about errant bank statements and tax documents. A fellow in Minnesota has been receiving piles of mail from a bank that was meant for various others of its customers. Despite repeatedly sending it back marked "Return to sender. Don't send me other people's banking information," the problem persisted.

While accidents do happen, the bigger problem is the inattention to the problem on the part of the bank and the amount of effort that it finally took to get it to stop.

Yahoo! News - Your Statements Went Where?

...Because of a few wayward keystrokes by a clerk at a bank processing center, Pirozzi has for nine months received the financial statements of scores of strangers, many of whom are Washington area residents and all of whom had had Wachovia Corp. escrow accounts.

Pirozzi tried desperately to get the problem fixed once the first batch arrived last spring, but he says that no one at the bank or at a local title company that helped establish the accounts took action on his repeated calls. It was only in the past few weeks, after Pirozzi began receiving strangers' tax forms and after inquiries from a Washington Post reporter, that both companies began to investigate.

"I potentially have access to their Social Security (news - web sites) numbers and their names. I also have their bank account numbers. That's very private information," Pirozzi said. "I don't know what I could do with all of that -- I don't have a criminal mind. But there are definitely opportunities."

Privacy experts agree.

"This is a raft of sensitive financial information that would be an identity thief's dream," said Travis Plunkett, legislative director of the Consumer Federation of America.

Experiences like Pirozzi's are rare in an industry that depends on sophisticated computers and software to shuffle billions of transactions a day. But it nevertheless points to the vulnerabilities in systems that have become so highly automated that small errors in the management of databases can quickly become amplified into major security breaches, consumer advocates say. They say, too, that the lack of a prompt response from the companies involved reflects a broader problem with financial institutions not doing all they can to safeguard their clients' private information.

Saturday, February 05, 2005

Yet another university security foul-up

If you put it online -- anywhere -- odds are that Google will find it. Students of Johns Hopkins have found out the hard way. Student information was put online, but in an obscure place, but it wasn't obscure to Google. The school is renumbering more than two thousand students as a result of the leak. According to one student:

The Johns Hopkins News-Letter - J-CARD numbers leaked on Internet:

'For some reason, I don't have much confidence in the security measures at this school,' said Matt Bassett, a junior. 'This is just another example of a security failure; they can't even keep our personal information safe on the Internet.'

Industry Canada proposes PIPEDA exemption for Ontario "health information custodians"

Industry Canada has gazetted its proposed cabinet order exempting Ontario's "health information custodians" from the application of Part I of PIPEDA. It is no surprise that the federal goverment considers that the Personal Health Information Protection Act to be "substantially similar" to PIPEDA.

The notice in the Canada Gazette is soliciting comments within the next fifteen days.

Canada Gazette:

"Vol. 139, No. 6 — February 5, 2005

Health Information Custodians in the Province of Ontario Exemption Order

Statutory authority

Personal Information Protection and Electronic Documents Act

Sponsoring department

Department of Industry

REGULATORY IMPACT ANALYSIS STATEMENT

(This statement is not part of the Order.)

Description

Part 1 of the Personal Information Protection and Electronic Documents Act (PIPEDA) establishes rules to govern the collection, use and disclosure of personal information by organizations in the course of commercial activity. Part 1 of the Act was implemented in two stages. On January 1, 2001, the Act applied to the collection, use and disclosure of personal information in connection with the operation of federal works, undertakings or businesses and to the disclosure of personal information for consideration outside a province. On January 1, 2004, the Act's reach was extended to all collections, uses and disclosures of personal information in the course of commercial activity, either within, or outside a province. Pursuant to paragraph 26(2)(b) of the Act, the Governor in Council may, by order, if satisfied that legislation of a province that is substantially similar to PIPEDA applies to an organization, a class of organizations, an activity or a class of activities, exempt the organization, activity or class from the application of PIPEDA in respect of the collection, use and disclosure of personal information within the province.

Under the trade and commerce power conferred on Parliament by subsection 91(2) of the Constitution Act, 1867, PIPEDA establishes a set of economy-wide principles and rules for the protection of personal information. The Act helps to build trust and confidence in the Canadian marketplace, while encouraging provinces and territories to develop their own privacy laws in a manner that addresses their particular needs and circumstances. To this end, the Government of Canada included provisions in PIPEDA to exempt from the federal Act organizations or activities subject to provincial or territorial laws that are deemed to be substantially similar.

On August 3, 2002, Industry Canada published the policy and criteria used to determine whether provincial or territorial legislation would be considered as substantially similar. PIPEDA provides a standard around which provinces can legislate. Under the policy, laws that are substantially similar provide privacy protection that is consistent with and equivalent to that in the federal Act; incorporate the ten principles in the CSA Model Code for the Protection of Personal Information, CAN/CSA-Q830-96, found in Schedule 1 of PIPEDA; provide for an independent and effective oversight and redress mechanism with powers to investigate; and restrict the collection, use and disclosure of personal information to purposes that are appropriate or legitimate. In recognizing such laws as substantially similar, PIPEDA provides a common standard for privacy protection across both federal and provincial domains.

The Ontario Personal Health Information Protection Act, 2004 (PHIPA) which came into force on November 1, 2004, sets rules that health information custodians must abide by when collecting, using and disclosing personal health information within the Ontario health care system. PHIPA is substantially similar to PIPEDA. The purpose of this Order is thus to exempt from PIPEDA those health information custodians, as defined in PHIPA, in respect of the collection, use and disclosure of personal health information that occurs within the province of Ontario, in the course of commercial activity. PIPEDA will continue to apply to the collection, use and disclosure of personal health information outside the province, in the course of commercial activity.

Alternatives

The legislative framework in Part 1 of PIPEDA requires that exemptions for organizations, classes of organizations or an activity or class of activities subject to provincial or territorial laws that are substantially similar to the federal Act be done through Order in Council. There are no alternatives to exempt from PIPEDA health information custodians subject to the Ontario PHIPA.

Benefits and costs

Benefits

The alignment of federal and provincial/territorial legislative regimes for the protection of privacy makes privacy laws easier for individuals to understand and simpler for organizations to implement. Harmonization of privacy rules within the Ontario health care system creates a consistent and seamless set of rules with regard to the protection of personal health information, covering all custodians operating in the province, thereby increasing the efficiency with which they collect, use and disclose personal health information as part of their care and treatment activities.

Costs

The Order will have no adverse cost impact on the activities of health information custodians in Ontario. To the extent that they collect, use and disclose personal health information within the Ontario health care system, health information custodians are expected to comply with the privacy rules established by PHIPA. These privacy requirements are based on the national standard set in the CSA Model Code for the Protection of Personal Information, CAN/CSA-Q830-96 that is embedded in PIPEDA and in the Ontario PHIPA. Both laws establish a set of ten fair information principles, and both have set up an independent oversight and redress mechanism.

Consultation

Provincial and territorial governments, along with the general public, the health care sector and the business community have already been made aware of the federal government's commitment to exempt from PIPEDA organizations subject to provincial/territorial laws that are substantially similar to PIPEDA. During parliamentary consideration of the legislation, which included extensive hearings before the Standing Committee on Industry and the Senate Standing Committee on Social Affairs, Science and Technology, taking place between October 1998 and April 2000, and through speeches, press releases and other communications to the public, the Government of Canada has clearly indicated its intention to encourage provinces and territories to develop substantially similar privacy legislation. It further confirmed that PIPEDA would not apply to organizations subject to these laws in respect of the collection, use and disclosure of personal information, including personal health information, taking place within a province or territory.

Information was also provided on the Act's substantially similar provision when Industry Canada published its policy and criteria for determining substantially similar provincial and territorial legislation in Part I of the Canada Gazette in August 2002.

The government of Ontario, as well as the Information and Privacy Commissioner of Ontario made the request to the Government of Canada that the substantially similar nature of PHIPA be recognized and that an Order in Council be passed exempting health information custodians from PIPEDA. The Privacy Commissioner of Canada, Jennifer Stoddart, also communicated with the Government of Canada on the issue, indicating that in her opinion PHIPA meets the criteria for recognizing its substantially similar nature. She also expressed her support for an exemption order exempting health information custodians in Ontario from the federal Act.

Compliance and enforcement

This Order will confirm that Ontario health information custodians will not be subject to PIPEDA in respect of the collection, use and disclosure of personal health information. Compliance with privacy rules and enforcement of the Ontario PHIPA is delivered through the Information and Privacy Commissioner of Ontario. Following the issuance of this Order, complaints and investigations about the practices of health information custodians in respect of the collection, use and disclosure of personal health information taking place within the province in the course of commercial activity will be handled exclusively by the Ontario Information and Privacy Commissioner. The Privacy Commissioner of Canada will continue to be responsible for providing oversight in relation to the collection, use and disclosure of personal health information that crosses provincial boundaries in the course of commercial activity.

Contact

Mr. Richard Simpson, Director General, Electronic Commerce Branch, Industry Canada, 300 Slater Street, Room D2090, Ottawa, Ontario K1A 0C8, (613) 990-4292 (telephone), (613) 941-0178 (facsimile), simpson.richard@ic.gc.ca (electronic mail).

PROPOSED REGULATORY TEXT

Notice is hereby given that the Governor in Council, pursuant to paragraph 26(2)(b) of the Personal Information Protection and Electronic Documents Act (see footnote a), proposes to make the annexed Health Information Custodians in the Province of Ontario Exemption Order.

Interested persons may make representations with respect to the proposed Order within 15 days after the date of publication of this notice. All such representations must cite the Canada Gazette, Part I, and the date of publication of this notice, and be addressed to Mr. Richard Simpson, Director General, Electronic Commerce Branch, Industry Canada, 300 Slater Street, Room D2090, Ottawa, Ontario K1A 0C8.

Ottawa, January 31, 2005

EILEEN BOYD
Assistant Clerk of the Privy Council

HEALTH INFORMATION CUSTODIANS IN THE PROVINCE OF ONTARIO EXEMPTION ORDER

EXEMPTION

1. Any health information custodian to which the Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Schedule A, applies is exempt from the application of Part 1 of the Personal Information Protection and Electronic Documents Act in respect of the collection, use and disclosure of personal information that occurs within the Province of Ontario.

COMING INTO FORCE

2. This Order comes into force on the day on which it is registered.