Wednesday, June 07, 2006

Privacy Commissioner tables report calling for urgent reform of Canada's Privacy Act

The Federal Privacy Commissioner appeared before the House Standing Committee on Access to Information, Privacy and Ethics to call for reform of the federal Privacy Act, which governs the collection, use and disclosure of personal information by federal government institutions.

News Release: Privacy Commissioner tables report calling for urgent reform of Canada's Privacy Act (June 5, 2006):

Ottawa, June 5, 2006 –The Privacy Act is an outdated law that leaves the Office of the Privacy Commissioner of Canada virtually powerless to protect the privacy rights of Canadians relating to information collected, used and disclosed by the federal government, said Privacy Commissioner Jennifer Stoddart in a document tabled today with the House of Commons Standing Committee on Access to Information, Privacy and Ethics.

The Privacy Act, which came into force in 1983, has never been amended or updated despite repeated calls for review by successive Privacy Commissioners.

“The world has profoundly changed since the Privacy Act was drafted,” said Ms. Stoddart. “Globalization has increased, national security concerns have become heightened, and Canadians have higher expectations that the federal government will respect fundamental privacy rights. The Privacy Act is outdated and it must be amended.”

Two separate federal laws protect Canadians’ privacy rights: the Personal Information Protection and Electronic Documents Act, or PIPEDA, and the Privacy Act. PIPEDA limits the private-sector’s collection, use or disclosure of an individual’s personal information. The Privacy Act governs how the public sector must handle personal information.

In her report, the Commissioner calls for the scope of the Privacy Act—which the Supreme Court has said has quasi-constitutional status—to be expanded in a number of specific ways:

  • Since 1982, the government has created many entities that are not subject to either the Privacy Act or PIPEDA. All public-sector bodies or offices should be subject to the Privacy Act unless Parliament specifically excludes them.
  • The Federal Court should be able to review not only claims of denial of access to personal information held by government, but also improper collection, use and disclosure of personal information. The Court should also be empowered to assess damages against offending institutions.
  • The definition of personal information should be expanded to include both recorded and unrecorded information, such as DNA samples, about identifiable individuals.
  • All individuals about whom the government holds personal information—and not just those present in Canada—should have the right to access, correct and be informed of that information. For example, airline passengers, immigration applicants and foreign student applicants have no right to access their information in Canadian government files.

The Commissioner has noted that the Privacy Act could be substantially remedied by adopting many of the provisions of PIPEDA, which came into force in stages starting in 2001. Ms. Stoddart identified specific fair information principles contained in PIPEDA that should be applied to the Privacy Act, such as:

  • Government institutions should only collect personal information that is reasonable and necessary for a particular purpose. They should specify the authority under which information is being collected, the uses to which it will be put, whether and with whom it may be shared, the consequences of not providing the information, and the right to make a complaint.
  • Where possible, when information is disclosed without consent, there should be a corresponding duty on the government to inform the individual about the disclosure.

The Office of the Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy rights in Canada.

To view the report: Government Accountability for Personal Information: Reforming the Privacy Act

An ounce of prevention ...

This should be obvious to most, but needs to be repeated: It is much less expensive to properly protect data than it is to deal with the aftermath of a data breach. See: Cleaning Up Data Breach Costs 15x More Than Encryption.

Monday, June 05, 2006

Quebec to amend law to protect transfer of personal information to U.S.

According to an article that crossed the wired about twenty minutes ago, the Province of Quebec is planning to amend its privacy law to require any export of personal information from the province is as secure as it would be in the provice. I haven't seen the proposed amendments to provide any more details, but check out the article in the meantime:

Macleans.ca : Quebec to amend law to protect transfer of personal information to U.S.:

MONTREAL (CP) - Quebec plans to follow the lead of several other provinces in attempting to protect its residents from the prying eyes of the American government.

Quebec's 12-year-old law governing the release of personal information by private businesses will be enhanced, partly in reaction to the USA Patriot Act enacted to give broader FBI access to records held by U.S. firms. The proposals, which are expected to be passed later this month, would require public bodies and private companies to ensure the information they send outside the province is as secure as it is in Quebec, said Richard Parent, a government official.

'You will have to ask the question with each contract: 'Will there be a violation of privacy and should there be a transmission of that information?' ' he said in an interview.

Companies would face increased fines - although the amount hasn't yet been made public - and would have to disclose publicly if a breach has occurred.

Individuals could also ask Quebec's information commissioner to investigate suspected breaches of the law.

Quebec's legal change comes in the wake of reports that the U.S. National Security Agency co-opted telecommunications companies to track millions of phone calls and store them in what may be the largest database in the world.

The NSA Is Listening

Daryl Cagle's Professional Cartoonists Index at MSNBC is a great one-stop-shopping source for all your editorial cartoon needs. Not only does it include all the top editorial cartoonists from around the world and is up to date, they are also well organized by theme. Anyone with any interest in the latest scandal over NSA wiretapping should check out the theme "The NSA Is Listening".

Privacy should be guarded

David Canton's regular column in the London Free Press this week is a brief overview of the Annual Report of the Federal Privacy Commissioner on PIPEDA:
London Free Press - David Canton - Privacy should be guarded:

One noteworthy element is a more aggressive stance taken by the commissioner, Jennifer Stoddart, against organizations that are the subject of privacy complaints her staff determines to be well founded. Transgressors must now state the corrective measures they will take and when they will be completed.

Sunday, June 04, 2006

Incident: Hotels.com customer info on laptop stolen from auditor in February

OK. Now I'm a little mad. Another laptop reportedly stolen from an auditor. These have gotten too routine.

But this time, there's a good chance my personal information may have been on the stolen laptop. The data is from Hotels.com, a subsidiary of Expedia.com. This company also handles hotels booked through the Air Canada website using their Destina service. This is a service I've used in the past.

I haven't gotten a letter, but with information on 243,000 customers, I expect this is a subset of customers from 2002, 2003, 2004.

It is particularly rich that Hotels.com and Ernst & Young is suggesting that customers "take appropriate action to protect their personal information". Hello? You're suggesting that I take appropriate action to protect my personal information? How about you and your auditors taking appropriate action to protect my personal information. You can start by not letting it leave the building on a laptop. But if you don't follow that basic step, you could think about encrypting the information.

Here's the story from the Associated Press:

Hotels.com customer info may be at risk - Yahoo! News:

SEATTLE - Thousands of Hotels.com customers may be at risk for credit card fraud after a laptop computer containing their personal information was stolen from an auditor, a company spokesman said Saturday.

The password-protected laptop belonging to an Ernst & Young auditor was taken in late February from a locked car, said Paul Kranhold, spokesman for Hotels.com, a subsidiary of Expedia.com based in Bellevue, Wash.

"As a result of our ongoing communication with law enforcement, we don't have any indication that any credit card numbers have been used for fraudulent activity," Kranhold said. "It appears the laptop was not the target of the break-in."

Both Hotels.com and Ernst & Young mailed letters to Hotels.com customers this past week encouraging them to take appropriate action to protect their personal information.

The transactions recorded on the laptop were mostly from 2004, although some were from 2003 or 2002, the companies said. The computer contained personal information including names, addresses and credit card information of about 243,000 Hotels.com customers. It did not include their Social Security numbers.

Ernst & Young, which has been the outside auditor for Hotels.com for several years, notified the company of the security breach on May 3.

"We deeply regret this incident has occurred and want to apologize to you and Hotels.com for any inconvenience or concern this may cause," said the unsigned memo from Ernst & Young dated May 2006.

Ernst & Young invites those affected by the incident to enroll in a free credit monitoring service arranged by the auditor.

"We sincerely regret that this incident occurred and we are taking it very seriously," said the letter signed by Hotels.com general manager Sean Kell.

The letter from Hotels.com said "Ernst & Young was taking additional steps to protect the confidentiality of its data, including encrypting the sensitive information we provide to them as part of the audit process."

Saturday, June 03, 2006

Stolen DVA laptop had info on active duty personnel

The Department of Veterans Affairs fiasco gets bigger with each few days.

It is now reported that the stolen laptop likely contained personal information on fifty thousand active duty military personnel:

IDs of active personnel on stolen laptop - Yahoo! News:

WASHINGTON - Personal data on up to 50,000 active Navy and National Guard personnel were among those stolen from a Veterans Affairs employee last month, the government said Saturday in a disclosure that goes beyond what VA initially reported.

VA Secretary Jim Nicholson said in a statement that his agency discovered after an internal investigation that the names, Social Security numbers and dates of birth of up to 20,000 National Guard and Reserve personnel who were on at least their second active-duty call-up were 'potentially included.'

Law enforcement want ISPs to create and retain records of user activities

The US Attorney General and the Director of the FBI met with executives from some of the largest ISPs in the US to suggest that they create and retain records to benefit law enforcement if/when they eventually come knocking. There is much speculation that this voluntary suggestion will soon become mandatory:

U.S. Wants Companies to Keep Web Usage Records - New York Times:

The Justice Department is not asking the Internet companies to give it data about users, but rather to retain information that could be subpoenaed through existing laws and procedures, Mr. Roehrkasse said.

While initial proposals were vague, executives from companies that attended the meeting said they gathered that the department was interested in records that would allow them to identify which individuals visited certain Web sites and possibly conducted searches using certain terms.

It also wants the Internet companies to retain records about whom their users exchange e-mail with, but not the contents of e-mail messages, the executives said. The executives spoke on the condition that they not be identified because they did not want to offend the Justice Department.

Thursday, June 01, 2006

Response to: "If you've done nothing wrong, you have nothing to worry about"

In case you haven't heard about it, Ask MetaFilter is an interesting online community where users post a wide range of questions and usually get high quality responses. A user just asked for a snappy response to "If you've done nothing wrong, you have nothing to worry about". Some of the best ones can't be reprinted on this family-friendly website, but I suggest checking it out: Response to: "If you've done nothing wrong, you have nothing to worry about" | Ask MetaFilter.

Contractor loses personal data of 1.3M student loan customers

The Associated Press is reporting that a contractor has lost a piece of unspecified equipment containing personal information related to 1.3 Million customers of Texas Guaranteed Student Loan Corp. The info had been decrypted by the contractor but is said to be protected by passwords "a number of times over". (I'm not sure what that means.) Check out the story here: Co. loses personal data of 1.3M customers - Yahoo! News, and the company's information page here: TG: TG announces contractor's loss of borrower files.