Monday, July 31, 2006

Canadian Commissioner issues fact sheet on metadata

The Privacy Commissioner of Canada has recently posted a "fact sheeet" on the risks of metadata and the information it can reveal: Fact Sheet: The Risks of Metadata (July 2006). Thanks to Michel Adrien's Library Boy for the link.

Friday, July 28, 2006

Alberta commissioner launches investigation into stolen laptop

From the Office of the Information and Privacy Commissioner of Alberta:

OIPC:

News Release: Commissioner launches investigation into stolen laptop

Alberta’s Information and Privacy Commissioner has initiated an investigation into a stolen laptop computer which contains financial and other personal information about possibly 8,000 clients of MD Management, a subsidiary of the Canadian Medical Association.

Click to view more information News Release: Commissioner launches investigation into stolen laptop.

CIPPIC complains about SWIFT disclosure

The Canadian Internet Policy and Public Interest Clinic has filed a complaint with the Privacy Commissioner against the Big Six Canadian banks over the disclosure of information by the international, inter-bank clearinghouse SWIFT. (Via Michael Geist.)

According to previous reports, the Commissioner is already on the case (Canadian Privacy Law Blog: Canadian Commissioner investigates whether Canadian banking records were reviewed by the CIA).

Thursday, July 27, 2006

Alberta Commissioner releases summaries of cases with educational value

The Information and Privacy Commisisoner of Alberta has published a sample of cases on its website that are considered to have educational or instructive value. They can be found here. All orders are still on the website here, but summaries provide a good snapshot of some of the Commissioner's "greatest hits".

Tuesday, July 25, 2006

US judge dismisses phone records lawsuit

According to Yahoo! News, the lawsuit against AT&T related to the disclosure of phone records to federal authorities has been thrown out for national security reasons.

Judge dismisses phone records lawsuit - Yahoo! News

CHICAGO - Citing national security, a federal judge Tuesday threw out a lawsuit aimed at blocking AT&T Inc. from giving telephone records to the government for use in the war on terror.

"The court is persuaded that requiring AT&T to confirm or deny whether it has disclosed large quantities of telephone records to the federal government could give adversaries of this country valuable insight into the government's intelligence activities," U.S. District Judge Matthew F. Kennelly said....

Might also give citizens insight into the government's activities....

Monday, July 24, 2006

Canadian passport office to match pics against photo watchlists

I reported a little while ago that the Canadian Passport Office was about to roll out biometrics in passports (Canadian Privacy Law Blog: Canada prepares to roll out biometric passports). Now, the Globe & Mail is reporting that phase II is on the horizon: facial recognition. The Canadian government will compare all passport photos to known terrorists (and criminals, deadbeat dads or just shifty looking people). See: globeandmail.com : Passport database to use facial imaging.

Australian Privacy Foundation calls for inquiry into US SWIFT monitoring

According to Open and Shut, the Australian Privacy Foundation is pressing that country's Privacy Commissioner to investigate US review of SWIFT interbank transfer information, as the Canadian Commissioner is currently doing. See: Open and Shut: Australian Privacy Foundation calls for inquiry into US SWIFT monitoring.

Sunday, July 23, 2006

RFID privacy in Canada

Saturday's Globe & Mail had an interesting article on RFID, which is now online in the Globe's technology section: globeandmail.com : Who's watching the watchers? I find these articles to be interesting, but often overstate the threat that RFID poses in Canada. Most of the concern is that item-level tagging of purchased items will lead to the ability to track individuals once they have left the store. While this might theoretically be possible, the advent of a new technology does not mean that Canadian laws go out the window.

Every retail operation in Canada is governed by privacy laws, either PIPEDA or a substantially similar equivalent. Among other things, these laws require that the collection of personal information be reasonable and that personal information only be collected with the knowledge and the consent of the individual. I have no doubt that the unique identifier in a purchased item's RFID tag, when attached to any other information about an individual, is personal information for the purposes of these statutes. Therefore, in Canada:

  1. Any retail operation using RFID in Canada has to inform customers;
  2. Any retail operation that matches an RFID serial number to any personal information has to get the consent of the consumer; and
  3. You cannot require a consumer to consent to a collection, use or disclosure of personal information that is unreasonable or is for a purpose not identified to the individual.

Essentially, this means that retailers cannot covertly use RFID to track consumers in this country. The situation is entirely different in the US where no general privacy law covers the retail sector.

If you want any more information on RFID and Canadian privacy law, check out this great report by Teresa Scassa, Michael Deturbide, Theodore Chiasson and Anne Uteck of Dahousie's Law and Technology Institute: An Analysis of Legal and Technological Privacy Implications of Radio Frequency Identification Technologies. This report was funded by the Privacy Commissioner's contributions programme.

Update:

In a letter to the editor in today's Globe & Mail (July 25, 2006), Anne Cavoukian responds to the article from Saturday's paper:

globeandmail.com : RFIDs track products:

"RFIDs track products

ANN CAVOUKIAN Information and Privacy Commissioner of Ontario

Toronto -- The article Who's Watching The Watchers? (July 22) suggests that Katherine Albrecht was invited 'back' to brief my office on Radio Frequency Identifiers (RFIDs). I would like to make this perfectly clear -- she was never there, nor was she ever invited. Meanwhile, the article's characterization of RFIDs as spy chips is misleading.

Let's have a reality check. Currently in Canada, RFID tags are used in the supply-chain process for inventory control (tracking products, not people), which involves no privacy issues. But in future, if and when RFIDs are embedded into consumer products and linked to personal identifiers, we must remain vigilant to ensure that they are deployed in a manner that does not threaten privacy.

I have been studying RFIDs since 2003 and recently issued RFID privacy guidelines to address the future prospect of item-level, potentially privacy-invasive, RFIDs. I am a fierce protector of privacy but also believe in describing issues fairly and evenly. What we need is public education about this technology rather than fear mongering.

Misrepresenting RFIDs only serves to keep the public in the dark."

Thursday, July 20, 2006

Emily of the State

Cynically Tested has posted a brief video on YouTube featuring Emily of the State, an interesting bit of "lawful access" spyware for your computer: YouTube - Emily of the State - Internet Spying Short

Via Connie Crosby and Michael Geist.

Wednesday, July 19, 2006

Commissioner releases batch of new findings

The flow of findings posted on the website of the Office of the Privacy Commissioner has slowed to a trickle this year, but the floodgates opened long enough to release seven new findings today. I'll comment on them in greater detail before too long, but here are their titles and links:

Commissioner's Findings - Privacy Commissioner of Canada

In a conversation with the Assistant Commissioner, I've been told that there is no shortage of complaints but only a shortage of complaints that raise novel issues. Astute observers will note that most of these findings deal with novel issues, particularly situations of marital breakdown.