Saturday, November 26, 2011

Ontario Commissioner Issues Significant Order on Custody or Control of University Records

If any part of your practice involves advising universities on access to information issues, run -- don't walk -- over to Dan Michaluk's summary of the recently released decision in University of Ottawa – Order PO-3009-F (November 7, 2011).

One of the big issues these days is whether records held by a university professor is in the custody or control of the university, so that they may be subject to access to information legislation. The Information and Privacy Commissioner of Ontario has just held that it is up to the IPC and not any other process (such as arbitration or reference to arbitral jurisprudence) to determine whether this is the case. The decision also provides the following very helpful guidance:

Accordingly, I conclude that the arbitral awards are not determinative with respect to the custody or control of records that may be responsive in this case. Rather, the determination is to be made based in the principles enunciated in this order. The significant conclusions I have reached in this regard are:

1. records or portions of records in the possession of an APUO member that relate to personal matters or activities that are wholly unrelated to the university’s mandate, are not in the university’s custody or control;

2. records relating to teaching or research are likely to be impacted by academic freedom, and would only be in the university’s custody and/or control if they would be accessible to it by custom or practice, taking academic freedom into account;

3. administrative records are prima facie in the university’s custody and control, but would not be if they are unavailable to the university by custom or practice, taking academic freedom into account.

Run to Dan's summary: Ontario Commissioner Issues Significant Order on Custody or Control of University Records « All About Information.

Thursday, November 24, 2011

SCC declines to hear Alberta Privacy Commissioner's appeal

The Supreme Court of Canada announced today that they will not hear the appeal of the Information and Privacy Commissioner of Alberta in the case of Leon's Furniture Limited v. Alberta (Information and Privacy Commissioner), 2011 ABCA 94.

For some history, see:

Bill C-12 and “lawful authority” under PIPEDA

Phillipa Lawson has a very well thought out post over at Slaw on "lawful authority" under PIPEDA and the ability of businesses to share personal information with law enforcement. Check it out: Bill C-12 and “lawful authority” under PIPEDA — Slaw.

Tuesday, November 22, 2011

Current issues in privacy: Social media and cloud computing

Today, I was honoured to be asked to present to the Nova Scotia Association of Educational Administrators on current privacy issues. A very interesting group of people with some great questions. Here's the presentation, in case you're interested:

What information is law enforcement looking for under "lawful access"?

Christopher Parsons has a great and detailed blog post on the sort of information that would be open for inspection by law enforcement under "lawful access". And it's isn't "phone book" information. Check it out: The Anatomy of Lawful Access Phone Records | Technology, Thoughts, and Trinkets.

Paper on Canadian ISP cooperation with law enforcement

An interesting read:

Updated: Business disclosure of personal information to law enforcement agencies: PIPEDA and the CNA letter of request protocol (PDF):

By Suzanne Morin with the assistance of Amy Awad and Dee Pham

Canadian Internet Service Providers (“ISPs”) are continuing their strategy to deal with a subset of requests for customer information from law enforcement agencies requests that is of particular concern to them – those pertaining to online child exploitation investigations.

The initiative, where participating ISPs voluntarily disclose customer name and address linked to an IP address at a particular date and time to law enforcement at the pre-warrant stage of child exploitation investigations, remains interesting at a number of levels.

It touches on privacy issues pertaining to the proper interpretation of PIPEDA and the reasonable privacy expectations of ISPs’ customers. It also provides an ongoing example of a relatively successful voluntary collaboration between private business, law enforcement and privacy regulators aimed at tackling legal uncertainties where they may most negatively affect the public good.

Friday, November 18, 2011

Nova Scotia Privacy Review officer reviews workers' comp board

Until recently, the "Review Officer" appointed under Nova Scotia's Freedom of Information and Protection of Privacy Act only had the power to deal with access to information issues and not privacy complaints. That's now changed and the Protection of Privacy Review Officer, Dulcie McCallum has come out swinging following a review of the province's Workers' Compensation Board. Below is the press release, summarizing Review P-11-01 (PDF):

REVIEW OFFICER ISSUES PUBLIC REPORT: RECOMMENDS CHANGES TO WCB PRIVACY PRACTICES

November 18, 2011

Dulcie McCallum, Nova Scotia’s Privacy Review Officer, today released her report investigating the privacy practices of the Nova Scotia Workers’ Compensation Board: Privacy Matters: Creating a Zero Tolerance Privacy Environment. Ms. McCallum made 21 recommendations that she believes will improve the privacy culture at the WCB, and the WCB has agreed to implement all of the recommendations.

“Because privacy is such an important part of how we define ourselves, I have recommended that the WCB work towards creating an institutional goal where privacy is given priority, where one privacy breach is one too many,” said Ms. McCallum. “I believe this approach to privacy lines up closely to WCB’s primary emphasis on safety in the workplace, where one accident is one too many.”

The Review marks the first time the Privacy Review Officer has completed a systemic privacy review of a public body. Ms. McCallum launched the investigation early this year when it was publicly reported that at least two separate individuals had received another WCB claimant’s claim file when requesting their own. Most claimant's files include considerable personal information and in particular personal health information.

Before this report was made public, the Review Officer shared a draft version with the WCB in order to ensure that the Review Office had fully captured the work of the WCB and its privacy practices. In its response, the WCB emphasized the similarities between efforts to prevent workplace injuries and efforts to prevent privacy breaches and agreed to implement all 21 recommendations.

“I am happy to report that the WCB has fully accepted preventing privacy breaches as a priority and has indicated that our expert advice as to how to go about achieving that is welcome,” said Ms. McCallum. “I want to thank the WCB for the full cooperation it provided throughout this investigation.”

The WCB has committed to implementing seven of the recommendations immediately, while the remaining 14 will require a reasonable period of time to fully adopt. The Review Office intends to revisit the progress being made by the WCB on implementation within the next year.

The Privacy Review was expedited to ensure any privacy breaches that may have occurred were not ongoing and had been sufficiently contained by the WCB. The Privacy Review Officer found that they had been contained, though the overall privacy practices of the WCB needed improvement in order to give privacy protection the attention it deserved.

Thursday, November 17, 2011

Privacy Commissioner of Canada releases annual report on public sector privacy law

Jennifer Stoddart has just tabled her annual report to Parliament on the Privacy Act, Canada's federal public sector privacy law: Annual Report to Parliament 2010-2011 - Report on the Privacy Act.

From her media release on the topic:

Audit of airport security measures flags concerns about over-collection and safeguarding of travellers’ personal information

2010-2011 Annual Report to Parliament on the Privacy Act examines the stewardship of personal information by Canada’s airport security authority, the RCMP and other federal departments and agencies

OTTAWA, November 17, 2011 – The Government of Canada is collecting too much information about some air travellers and is not always safeguarding it properly, Privacy Commissioner Jennifer Stoddart found in an audit published with her annual report today.

The audit of the privacy policies and practices of the Canadian Air Transport Security Authority (CATSA) concluded that the agency was reaching beyond its mandate by completing security reports on incidents which were not related to aviation security.

This was the case even with incidents involving an activity that was legal. For example, CATSA collected information about air passengers who were found to be carrying large sums of cash on domestic flights. CATSA also contacted police in such cases. Since it should not be collecting personal information about legal activities not related to aviation security, the Office of the Privacy Commissioner of Canada recommended that CATSA immediately cease that practice. CATSA agreed.

Moreover, the audit found that such incident reports, and other types of personal information collected by the agency, were not always properly secured.

“Documents containing sensitive personal information were left on open shelves and in plain view in a room where passengers may be taken for security checks,” Commissioner Stoddart reported.

The audit also identified other concerns about procedures not being followed during the screening process. When auditors visited the rooms where CATSA officials screen full-body scans, they discovered a cell phone and a closed-circuit TV camera even though these types of devices are strictly prohibited according to CATSA’s operating procedures.

“Fortunately, these irregularities were uncommon and we were pleased that CATSA moved quickly to correct them by issuing a reminder to staff and conducting inspections to ensure proper procedures were followed,” said Commissioner Stoddart.

Even so, she added, “the Government of Canada is entrusted with highly sensitive personal information, and is obliged to handle it with an uncompromising level of care—not some of the time, or even most of the time, but all of the time.”

The audit was summarized in the 2010-2011 annual report on the Privacy Act, which was tabled in Parliament today.

The annual report also contains a summary of another audit conducted by the Office of the Privacy Commissioner of Canada (OPC). It examined the Royal Canadian Mounted Police’s (RCMP) management of operational databases that are widely shared with other police forces, government institutions and other organizations.

The audit determined that, while the RCMP has policies and procedures to safeguard the sensitive information contained in the databases, there were also some disturbing gaps.

For instance, the Privacy Act, which governs the information-handling practices of federal government departments and agencies, requires that organizations retain personal information no longer than absolutely necessary. And yet, information about offences for which a pardon had been granted, or that resulted in a wrongful conviction, continues to be accessible in a database called the Police Reporting and Occurrence System.

“People who were convicted of an offence they did not commit, or who have been granted a pardon, have a right to go about their lives without information—and especially misinformation—about their past coming to light,” Commissioner Stoddart noted. “Such information must be more tightly controlled.”

The annual report highlights the work of the OPC in 2010-2011 in strengthening the privacy rights of Canadians. It summarizes key investigations into privacy complaints and data breaches that the Office conducted under the Privacy Act. The report also describes several Privacy Impact Assessments that federal institutions submitted to the Office for review during the past fiscal year.

Aimed at assessing the government’s stewardship of personal information, the report has separate chapters devoted to the collection, use and disclosure of data. Given the sensitive nature of the personal information that the state needs to govern, the report warns of grave consequences for its over-collection, misuse or inappropriate disclosure.

Aside from the two audit summaries, here are other highlights of today’s reports:

  • Biometric identifiers: Citizenship and Immigration Canada submitted Privacy Impact Assessments for two initiatives involving the use of fingerprints and other biometric identifiers for immigration control. The OPC recommended ways to strengthen privacy safeguards for vulnerable populations such as refugee claimants.
  • Passenger behaviour observation: A Privacy Impact Assessment for a new pilot project to observe airport travellers for suspicious activity raised several concerns, including the potential for inappropriate risk profiling based on characteristics such as race, age or gender.
  • Personal data breaches: The OPC received a record number of reports of breaches of personal information in 2010-2011. One involved a malfunction of the new My Service Canada Account website, a day after its launch, which allowed an estimated 75 users to see financial and other personal data of previous visitors to the site.
  • Follow-up to past audits: During follow-ups on three audits originally conducted in 2008 and 2009, the entities that we audited indicated that 32 of 34 of the OPC’s recommendations had been fully or substantially implemented. For example, the RCMP reported that it had removed tens of thousands of surplus files from its exempt databanks, in compliance with the Privacy Commissioner’s recommendations.

The full annual report and audit reports on CATSA’s aviation security measures and the RCMP operational databanks are available at www.priv.gc.ca.

The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman and guardian of privacy in Canada.

Monday, November 14, 2011

Ontario Court: Information about landlords not Personal Information

Dan Michaluk has a summary of a very recent Ontario Superior Court of Justice Case which held that information about landlords in the capacity as landlords is not really personal information, but is instead business information. Check it out: Information About Landlords not Personal Information « All About Information.

Thursday, November 10, 2011

Cloud computing session at Privacy and Information Security Congress 2011

I'm going to be on a panel discussion at the Reboot conference "Privacy and Information Security Congress 2011" on November 28/29 in Ottawa.

The session is entitled Borderless Cloud Computing – "Hey You, Get Off My Cloud!"

Moderator: Winn Schwartau, President, Interpact, Inc. Author of Information Warfare, Cyber Shock, Time Based Security and Internet & Computer Ethics for Kids

Speakers:

  • David Fraser, Partner, McInnes Cooper
  • Omkhar Arasaratnam, Lead Security Architect, SmartCloud Enterprise+, IBM
  • Ibrahim Gedeon*, Chief Technology Officer, TELUS

For more info, check out the agenda here: http://www.rebootconference.com/ottawaPS2011/agenda.php