Monday, October 30, 2006

Differing perspectives on the role of the Privacy Commissioner

The most recent Law Times includes an article on different perspectives likely to be presented as PIPEDA is up for its five year review. Included is a brief summary of the suggestions put forward by the Canadian Bar Association:

Law Times: Privacy commissioner needs teeth:

The Canadian Bar Association noted that PIPEDA should follow the tribunal model adopted by the Canadian Human Rights Commission in its recommendations to the Privacy Commissioner last month, elaborating on its formal submission from 2005.

'An impartial, rotating panel should be established with order-making powers and ability to award damages, with a cap on general damages. The Office of the Privacy Commissioner should retain investigative powers and advocacy role. If the commissioner determines that a complaint is 'well founded,' the commissioner should be required to issue a finding within six months and this finding should be referred to the tribunal.

Both complainants and respondents would be able to seek judicial review of a decision of the tribunal,' says the CBA's submission.

Brian Bowman of Pitblado LLP in Winnipeg, chair of the national privacy and access law section of the CBA, told Law Times, 'Currently the privacy commissioner's findings can only be advanced to Federal Court by the complainant or the commissioner with the complainant's consent and there isn't the ability for the organization which, in some cases, has been labelled a privacy infringer by the commissioner . . . to appeal that to the Federal Court.

'The danger is that organizations will be accused of invading privacy by the commissioner but won't be able to take steps to get judicial review to possibly defend themselves.'

Bowman said there has been a lot of debate about the role and powers of the privacy commissioner. "Some would argue that the commissioner has all the power that they need and they simply should use them more fully. We simply took the position that the structure should be changed and a new tribunal should be adopted and that tribunal, however, would have order-making power," he said.

Geist on Ottawa's new strategy for lawful access

Michael Geist's most recent Law Bytes column in the Toronto Star discusses documents obtained under the Access to Information Act which provide a behind the scenes view of the government and consulted stakeholders on "lawful access". There's no link to the documents themselves, but the column makes interesting reading. See: Michael Geist - Ottawa's Divide and Conquer Strategy for Net Surveillance.

What I find particularly interesting is this:

With the government working to diminish the effectiveness of the privacy community, it is particularly disheartening to learn that officials also recognize that Canadian privacy legislation suffers from serious shortcomings. A Department of Justice memorandum candidly notes that "current privacy laws may not be sufficient to protect Canadians' personal information," acknowledging that "federal privacy legislation is not responsive to new technologies, including the Internet, biometrics, data matching and data mining, video and infrared surveillance, the decoding of the human genome, the need for protection of genetic information and the ability to store and manipulate large personal data banks."

Officials are open to reform, stating that "as the privacy and personal information of citizens and businesses is increasingly vulnerable in the online environment, substantive measures to protect personal information need to be considered." Potential solutions apparently considered by the Department of Justice include the establishment of a new Task Force on online privacy.

This suggests a strong interest in reopening PIPEDA as part of the five year review that's just beginning. Or it suggests that real changes will be put off until after the online privacy task force has completed its work.

Wha?

I'm guessing this is just a poorly-written headline from The Insurance Journal: J.D. Power: Homeowners Want Carriers to Offer Identity Theft. I'm thinking I'll pass.

Sunday, October 29, 2006

ACLU drops USA Patriot Act challenge

The ACLU has dropped its court challenge to section 215 of the USA Patriot Act. The Washington Post reports that the reason for the withdrawal is the recent amendment that clarifies the right to seek legal counsel and challenge a demand for personal records under that section. See: ACLU Withdraws Lawsuit Challenging Patriot Act - washingtonpost.com.

Don't flash your breasts in public and expect to sue for invasion of privacy

The United States District Court for Maryland has recently (October 18, 2006) granted summary judgment against a woman who sued Easyrider magazine for invasion of privacy after a photo of her flashing her breasts at a BBQ attended by one hundred bikers appeared in the magazine. The claim in Barnhart v. Paisano Publications was based on three traditional bases of "invasion of privacy":

  • Intrusion upon seclusion - Not much seclusion or expectation of privacy when you pull up your shirt at a BYOB biker BBQ.
  • False light invasion of privacy - The depiction was accurate and did not falsely suggest that the plaintiff was the type of person who would consent to having topless pictures published in Easyrider.
  • Appropriation of personality - The plaintiff is not famous, is not a professional model and there is nothing particularly of value associated with her likeness. Also, it was done in public. (Maybe I'm being a bit too Canadian, but I think I'd rather not tell anyone their breasts have no commercial value.)

Via The Southern California Law Blog.

Also from delawareonline ¦ The News Journal ¦ Maryland judge: Topless photo didn't violate privacy

"Barnhart’s display of her breasts “cannot reasonably be said to have constituted a private act,” Motz wrote. “She exposed herself at an outdoor fundraising event open to any members of the public who purchased a ticket.”

Her claim that the image presented her in a false light also failed because she never claimed that the picture distorted “her true appearance,” but only that it created the impression she was the sort of person who would consent to posing topless for a magazine, Motz ruled.

Finally, Motz held that Barnhart’s claim for appropriation of her likeness failed because her image has no commercial value. Maryland courts have held that someone whose picture is taken in a public place at a newsworthy event does not have an appropriation claim, the judge noted."

Saturday, October 28, 2006

Canadian no-fly list coming soon to an airport near you

Both the Toronto Star (TheStar.com - No-fly list cleared for takeoff) and the Globe & Mail (globeandmail.com: No-fly list will add layer of security to air travel) are reporting that the Canadian government is about to release regulations to allow for a "made in Canada" do not fly list.

From the Globe:

globeandmail.com: No-fly list will add layer of security to air travel:

The government says people will be added to the new no-fly list only under specific circumstances: past involvement in a terrorist group and reasonable suspicion of being a threat to air safety; or having at least one conviction for a life-threatening crime against aviation security or another target that would indicate a possible threat to air safety.

The government also said it will set up an efficient, non-judicial appeal process for those who believe their names don't belong on the list and want to be removed quickly. Individuals can also appeal to the Commission for Public Complaints against the RCMP, or take the case to Federal Court.

We'll have to wait and see how exactly this is implemented, but I have one suggestion: the screening should happen when the booking is made, not just when the person shows up at the airport. At least that will provide some opportunity to challenge a decision without having to necessarily miss a flight.

Tuesday, October 24, 2006

Your papers and laptops, please?

The blogosphere has recently been buzzing about what appears to be a growing practice of laptop searches when entering the United States. The NYT had a piece on this yesterday (At U.S. Borders, Laptops Have No Right to Privacy - New York Times) and Boing Boing is linking to it.

It's a long established soverign right to strictly regulate what comes into a country. Increasingly, information has value and is even regulated from both the export perspective and the import perspective. This appears to be a simple extension of customs officers having the right to go through your dirty clothes on your way back from vacation, but certainly has privacy effects.

More and more people keep intimate information on their laptops and crossing a border with one is akin to crossing the border with your personal archives. If they were in paper form, there's no doubt the customs folks would have the right to take a peek. But laptops also often contain information that is a cut above the routine. A lawyer's laptop is full of privileged material and a physician's laptop is full of confidential information. It doesn't sound like there are any protections built into the system to acknolwedge this and that's particularly troubling.

Monday, October 23, 2006

Researchers See Privacy Pitfalls in No-Swipe Credit Cards

Today's New York Times is running a very interesting article on the next battle over RFID: the mass rollout out proximity-based consumer credit cards. The latest fuss particularly relates to alleged defects in the implementation of RFID that allow researchers (and perhaps malevolent folks) to read cards en clair from a distance. See: Researchers See Privacy Pitfalls in No-Swipe Credit Cards - New York Times.

Sunday, October 22, 2006

Search Engine Privacy Standard Proposed

Virante, an internet marketing company, has made an interesting proposal to protect the privacy of search engine users. It suggests that users should be able to opt out of having their search tracked by IP address or cookie by appending "#privacy" to the search query. Here's the release from Virante:

Press Release - Search Engine Privacy Standard Proposed To Protect Users:

New website proposes a new search standard, #privacy, to protect user privacy when performing search engine queries.

/24-7PressRelease/ - DURHAM, NC, October 22, 2006 - With recent data leaks at AOL, governments seeking information from Google on its users, and no simple user privacy solutions available, a standard for empowering user search privacy has finally been proposed. PoundPrivacy.org is spearheading a search privacy revolution with its proposed #privacy standard. Our proposal is that the #privacy flag could be added to the end of searches by users to tell the search engine 'don't track this query.' In response, the search engine should not track the user by IP address or cookie, and the query should not be made public in keyword tools. The website carefully addresses the one exception to this capability - queries in which a crime is likely being committed (like the solicitation of child pornography) should be excluded from the #privacy flag.

PoundPrivacy.org contains an open letter addressed to the major four search engines - Google, Yahoo, Microsoft, and Ask - requesting that they adopt the #privacy standard. Additionally, the site offers ideas on ways individuals who agree with the standard can support the campaign, including blogging about it, linking to poundprivacy.org, and sending out emails to friends.

About Virante, Inc.

Virante, Inc., is a leading internet marketing solution provider. For more information please visit Virante Web Marketing Solutions or contact us at Email Virante, (919) 459-1088, 1-800-650-0820.

Also check out www.poundprivacy.org.

UPDATE: Adam over at Emergent Chaos thinks this is a silly idea and I must say I agree with just about everything he says, other than the bit about the goat. I'm sure they're not that expensive.

Emergent Chaos: A Very Silly Idea: #privacy, and poundprivacy.org:

"This is silly on a number of levels:

  1. It propagates the simplistic 'opt-in/opt-out' thinking that the US marketing industry has been promulgating for decades. Look where that thinking has taken us.
  2. It defaults all queries to opt-in, implied by absence of an opt-out. Privacy should be a default, and the 'right' way to implement this would be with #trackthis.
  3. It will be prone to user error (typos) and forgetting. It offers no way to say, set a privacy cookie. Even Doubleclick does that.
  4. Implementation is left as an exercise for the search engines, who are supposed to both magically not track your queries, and magically track them if you might be violating a law. (I say magically because I have some understanding of how web logs actually work.)
  5. For some remarkable reason, no search engine has actually bothered to comment on the proposal. Certainly, no one has accepted it yet. So why am I blogging about it?
  6. Really, this idea is one level above an idea I had at the pub last night. Unfortunately, as it turns out, goats are expensive, and probably won't walk on treadmills. It's a good thing I sobered up before setting up a web site."

Thursday, October 19, 2006

Commissioner cannot compel privileged documents: FCA

The Federal Court of Appeal yesterday released its decision in Blood Tribe Department of Health v. Canada (Privacy Commissioner). This is the important decision in which the Federal Court had held that the Privacy Commissioner had jurisdiction to review documents that are claimed to be privileged to determine if the privilege was properly claimed in a request for access (FCT case).

The Court of Appeal held (and forgive the bad OCR of a faxed copy of the decision -- a cleaned up version will appear shortly):

(e) How to Deal with a Claim of Solicitor-Client Privilege under PIPEDA

[31] Section 15 of PIPEDA permits the Commissioner to apply to the Federal Court in relation to any matter referred to in section 14 which in turn encompasses solicitor-client privilege pursuant to subsection 9(3) of that Act (supra, at paragraph 4).

[32] The Intervener, the Law Society of Alberta, directed the panel to the Supreme Court of Canada of R v, McClure, 2001 SCC 14 [McClure]. That case outlined useful principles to be applied regarding a review of solicitor-client privilege by civil and criminal courts. McClure faced sexual charges from twelve former students, including one 'J.C.' who had also commenced a civil action. In the criminal action, McClure sought production of JC's civil litigation file in order to determine the nature of his allegations and to test his motivation in fabricating or exaggerating incidents of abuse. Major J. outlhed a three stage procedural test to protect the solicitor-client privilege. In the first two stages, the party seeking privileged material must establish that there i s no other compellable source for the privileged information as well as an evidentiary basis upon which to conclude that the information would be legally useful. In the third stage, the judge must then examine the documents and will not release them unless satisfied that they would likely give rise to an issue of relevance pertinent to the ,ultimate disposition of the case.

[33] In my analysis, the Commissioner's ability to conduct her investigation is not fettered by a rule that protects privileged communication. In circumstances where a broad claim of solicitor client privilege is used as a shield to thwart on investigation, judges of the Federal Court are equal to the task of developing procedures that adequately minimize the potential invasion of the privilege (see also Goodis v. Ontario (Ministry of Correctional Services}, 2006 SCC 3 1 at paragraph 2 1).

V. Conclusion

[34] In summay, the Judge erred in adopting a purposive and liberal interpretation of paragraphs 12(l)(a) and (c) of PIPEDA and in adopting AIA principles in a PIPEDA review. The appeal should be allowed, the order of the Judge dated March 8, 2005 should be set aside and the Commissioner's order for production of rccords dated October 22, 2003 should be vacated. Costs to the appellant in this appeal. No costs were sought by the intervener, the Law Society of Alberta.