Thursday, June 10, 2004

Privacy and Employee References

The Globe and Mail newspaper has a column in which readers can send in their questions. This week's edition includes a question about checking references:

The Globe and Mail:

"Dear Susan,

Can a recruiter or potential employer contact a reference without your permission?

--MYOB

Dear MYOB,

Employers can and do, but they shouldn't. "I heard it through the grapevine" is still the anthem of talent scouts in certain sectors, recent privacy legislation notwithstanding. But asking for the straight dope without consent is risky. Not only does the practice breach ethical and legal boundaries about personal privacy, the information gleaned this way is hardly reliable. An opinion about an employee says more about the referee than the worker, according to reams of studies, and thus off-the-record telephone exchanges are becoming less common in reputable human resources circles. Without the employee's nod even something as basic as checking where a candidate is currently employed can jeopardize her career if her boss doesn't know she's looking around. So seeking the low-down behind an employee's back is bad form, possibly illegal and not exactly how you welcome a new recruit into the fold. The whole practice smells.

So what if it already happened? I'm no lawyer, but a cursory look at the federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), and the three provinces that have their own privacy legislation (Quebec, Alberta and British Columbia) shows that most explicitly discourage employers from disclosing information without the employee's okay. Alberta is one exception, allowing employers to collect personal information about public employees "from any party without specific consent," according to a human resources guide published on the provincial government's Freedom of Information and Privacy website and confirmed by one of the government's information officers.

But all it takes is one test case to make Canadian employers clam up forever, says Vic Catano, a psychology professor and recruitment expert at St. Mary's University. That's what happened in the United States, when a referee not authorized by a candidate gave a negative point of view that off-sided an applicant for a vacant position. The employee sued and was awarded damages, an event that cast a pall on the reference-giving world. Even if a candidate has given permission, information not germane to the job is off-limits. It's irrelevant if you curl with the candidate's father. Just the facts, ma'am. Except for checking biographical facts with the candidate's permission, when it comes to references the rule is don't ask, don't tell. "

Getting consent is always a good idea. PIPEDA only applies to employees in the federally regulated private sector (banks, airlines, etc.), but employees (potential and otherwise) are beginning to expect that employers will respect their privacy. I advise my clients to have the prospective employee sign a consent at the interview, giving permission to contact anyone who may have information that is relevant, not just their listed references. Of course, their sunday school teacher will say good things about them. The key is to get relevant information. The consent form also has to say that the individual gives consent for the disclosure of personal information from the person who is asked. Referees are well advised to insist on seeing such a consent.

Study: Patient privacy at risk in hospitals' hallways, lobbies, cafeterias

File this under "not very surprising" ...

A recent study, published in the journal Health Communication (and abstracted on the Purdue university website) discusses how patient privacy can be casually violated by conversations among health professionals in public spaces:

Patient privacy at risk in hospitals' hallways, lobbies, cafeterias:

"Patient privacy at risk in hospitals' hallways, lobbies, cafeterias

WEST LAFAYETTE, Ind. -- New health communication research shows that casual conversations in hospital hallways and waiting rooms poses a threat to the confidentiality of patients' medical information.

Research conducted at Purdue University by Maria Brann, assistant professor of communication studies at West Virginia University, and Marifran Mattson, associate professor of communication at Purdue, shows patient privacy is breached when hospital employees talk about patient cases in public areas, such as the cafeteria, or with people outside of work. The researchers' paper appears in the spring issue of the journal Health Communication."

Thanks to the Science Blog for this link.

Wednesday, June 09, 2004

Article: For Sale by Public Auction -- Juicy Laptop Secrets

Yet another story about personal and commercial information left on hard-drives sold at auction:

Yahoo! News - For Sale by Public Auction -- Juicy Laptop Secrets:

"... In all, the firm's technicians were able to pull sensitive details from 70 of the 100 machines it bought.

In one case, it obtained a particularly vulnerable hard drive from online auction site eBay that apparently once belonged to one of Europe's largest insurance companies.

On the hard drive were current details of customers' pension plans, payroll records, personnel details, login codes and administration passwords for the company's Intranet site. Home addresses, telephone numbers and dates of birth of customers were also listed in 77 Microsoft Excel files, the company said. ..."

Tuesday, June 08, 2004

Article: Think before you text

Years later, cell phone text messages can come back to haunt you. According to CNN.com, ancient text messages may be ordered to be produced as evidence in the Kobe Bryant trial (see below). These messages "tend to be saved on servers."

Canada's federal privacy law, PIPEDA, has applied to telecom companies since 2001. One of the principles of the law is that information can only be retained for as long as is reasonable for the purposes for which the information was collected:

4.5 Principle 5 -- Limiting Use, Disclosure, and Retention

Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required by law. Personal information shall be retained only as long as necessary for the fulfilment of those purposes.

4.5.2

Organizations should develop guidelines and implement procedures with respect to the retention of personal information. These guidelines should include minimum and maximum retention periods. Personal information that has been used to make a decision about an individual shall be retained long enough to allow the individual access to the information after the decision has been made. An organization may be subject to legislative requirements with respect to retention periods.

4.5.3

Personal information that is no longer required to fulfil the identified purposes should be destroyed, erased, or made anonymous. Organizations shall develop guidelines and implement procedures to govern the destruction of personal information.

It would seem that Canadian telcos should not be retaining these messages indefinitely. Of course, "should" and "do" are two entirely different matters... Beware what you text, it may come back in civil or criminal proceedings.

The CNN story on the Bryan trial is here:

CNN.com - Think before you text - Jun 7, 2004:

"DENVER, Colorado (AP) -- A few hours after NBA star Kobe Bryant had sex with a Vail-area hotel worker last summer, the woman exchanged cell phone text messages with a former boyfriend and someone else.

What's in those messages could help determine whether the sex was consensual or whether Bryant is guilty of rape as charged. The judge himself said the content may be 'highly relevant' to the case.

That the judge could order the woman's cell phone company to produce the messages so long after they were sent shouldn't surprise anyone, analysts say.

Texters beware. Like e-mail and Internet instant messages, text messages tend to be saved on servers.

'One of the false assumptions that people make is that when they hit the delete button, messages are gone forever, but nothing can be further from the truth,' said Jeff Kagan, an independent telecommunications analyst in Atlanta."

See also Slashdot discussion of the issue ...

The Daily Telegraph | This is an Act of total bastardry

The Australian Daily Telegraph has an interesting bit about one person's experience of Australian privacy legislation. Highly recommended (and entertaining) read:

The Daily Telegraph | This is an Act of total bastardry:

By DAVID PENBERTHY

June 9, 2004

JUST over a year ago while driving home along Parramatta Rd I had one of those car accidents that restores your faith in human nature. Or so it seemed.

While changing lanes I failed to check my blindspot and side-swiped another car in the inside lane, smashing its front bumper and headlight and doing a fair bit of damage to my right-hand side.

Given that I was the one who was changing lanes, the accident was my fault. The other bloke couldn't have been nicer, especially, as he explained, he'd just had a new front bumper fitted.

We exchanged names and numbers. I was insured, he wasn't, but given that I was in the wrong it was a simple matter of paying the excess and lumping it.

I processed the forms, but forgot to pay the excess. A couple of weeks later I received a call from my apparent friend which not only spurred me into lightning action, but made me reassess my initial appraisal of the once-genial knockabout with whom I had the pleasure of colliding.

The bloke rang me out of the blue, told me he knew where I lived, that I didn't know what sort of person he was, and that if I didn't pay up by the end of the week he'd get the money off me by other means.

I know when I'm being threatened and did the only manly thing. I panicked like a girl. I rang the insurance company, gave them my credit card details, had it all paid within 60 seconds, and asked if they could provide me with my frightening friend's mobile number so I could reassure him that everything was cool.

"Sorry sir, under the Privacy Act we can't give you that number," the woman said.

"But I gave you his number," I said reasonably. "He doesn't have insurance. The only reason you have his number is because I took it at the scene and gave it to you on the form. I want to call him now to sort this out but I don't have it on me."

"Yes, sir, but under the Privacy Act I can't give it to you."

"So how did you get his number?"

"That's not the point, sir."

Etcetera. After some journalistic theatrics – where I explained to the woman (with the mildest exaggeration) that I feared for my safety – the woman relented, albeit in a drawn-out New Price is Right-type charade where I guessed the first two numbers were 04, and then played higher and lower for the remaining eight digits.

I didn't win the car, or even the vacuum cleaner, but I came away with the feeling that the Privacy Act may be one of the daftest pieces of legislation going around.

..."

Full text here ...

Criminal Code Amended to allow for e-mail interception by sysadmin

By amendments to the Criminal Code of Canada, the authority of a sysadmin to review employee e-mail in the course of system management has been clarified. From the London Free Press:

London Free Press: Business Section - Law amended for e-mail:

"The Criminal Code of Canada makes it an indictable offence to "willfully" intercept a private communication. On April 22, Bill C-14 came into effect, which among other things amends the Criminal Code to protect computer system managers from the threat of criminal conviction. The bill amends the Criminal Code to add a section that allows computer system managers to intercept a private communication. Interception under this new provision is lawful only if it is "reasonably necessary" for managing the "quality of service" of the computer system.

Preventing and dealing with intrusion detection and malicious attempts to compromise systems is a crucial issue for any business.

The concern was that without such a change, the viewing or scanning of e-mails by a computer systems employee for such things as virus detection or spam-blocking might be considered an illegal interception of a private communication. Other legitimate purposes include the prevention of data theft or the use of systems by unauthorized individuals. One could argue that, depending to some extent on employer policies, e-mails to and from the workplace are not private communications. But this amendment clarifies the issue.

...

Under the changes, intrusion-detection activities must be limited to authorized individuals who perform duties relating to the security management and protection of computer systems.

Intrusion-detection activities must be limited to what is reasonably necessary for legitimate management purposes to ensure service quality and protect systems against computer-related offences.

The then-Privacy Commissioner took issue with one aspect of the bill.

The commissioner opposed permitting a private communication that had been intercepted lawfully to be disclosed in the course of a civil or criminal proceeding, or for the purposes of any criminal investigation.

That would have meant that a manager operating a computer intrusion-detection system who discovered an e-mail attachment containing child pornography, or evidence of a murder plot, could not notify the police or use the material to discipline the employee.

The commissioner's proposal was defeated. ..."

Ontario's Personal Health Information Protection Act receives royal assent

Ontario's Personal Health Information Protection Act (also known as Bill 31) received royal assent on May 30, 2004. The main parts of the statute come into force on January 1, 2005:

PART IX COMMENCEMENT AND SHORT TITLE

Commencement

95. (1) This section and sections 71, 72 and 96 come into force on the day the Health Information Protection Act, 2004 receives Royal Assent.

Same

(2) Sections 1 to 70 and 73 to 94 come into force on January 1, 2005.

Short title

96. The short title of the Act set out in this Schedule is the Personal Health Information Protection Act, 2004.

Addition: For information about Bill 31 (PHIPA) training, see http://www.privlaw.com/pages/training_courses.htm

Saturday, June 05, 2004

Article: Build privacy into products

Ann Cavoukian, Ontario's very active privacy commissioner, gave a speech recently highlighting the distinction between privacy and security. She also discussed who in an organization should assume the role of CPO. See the ITbusiness.ca article:

ITBusiness.ca: Build privacy into products:

"As North America witnesses the rise of chief privacy officers, one of the fastest growing designations, companies must decide who within an organization will be responsible for this job, Cavoukian said. Ideally, the function should rest with a 'customer-friendly' department like marketing or business development, she said.

Karbaliotis predicted chief privacy officers will grow in importance because these will be individuals 'willing to stand for the company and say 'We're doing this right.'

'Maybe it shouldn't be the security officer. Maybe it shouldn't be the chief technology officer.'

Instead the right candidate should understand technology, business processes, the legislative environment and be involved in business planning, he said.

The 9/11 crisis allowed an increasing degree of security to marginalize privacy, but now 'we need a new paradigm,' urged Cavoukian, and added security and privacy are necessary for freedom to prevail."

Wednesday, June 02, 2004

Article: The Impact of PIPEDA

Today's Globe Technology has a comment by Adam N. Atlas, a member of the bars of Quebec and New York. He discusses the cross-border aspects of PIPEDA and the article merits a read.

Globetechnology:

"The best kept secret in privacy law is what to do about cross-border information transfers. There has been a lot written about the new Canadian privacy law, entitled Personal Information Protection and Electronic Documents Act (PIPEDA), but few lawyers or other experts are willing to offer an opinion on the legality of international cross-border information transfers under PIPEDA.

To date there is little to be found within the published rulings of the Privacy Commissioner that can definitively answer the numerous questions that this issue poses. This is surprising given that nearly every business in Canada faces the privacy question almost on a daily basis. The following is a practical overview for any business that sends or receives any personal information from or to Canada across international borders. ..."

The one area that he doesn't really touch on is probably the most prevalent example of the impact of PIPEDA on cross-border data flows. That is American retailers doing business with Canadian customers. For example, Land's End and LL Bean both collect personal information in association with any sale to a Canadian. PIPEDA itself is silent about its impact on cross-border transactions, but the Commissioner's office has taken the view that PIPEDA applies. Usual Canadian principles of conflicts of laws would suggest that Canadian federal law can apply where there is a "real and substantial connection" with this jurisdiction. Since the law is designed to protect Canadian residents and the collection would be deemed to take place "in Canada", applying it to American retailers is consistent with that purpose. The company may be able to tell the Commissioner to buzz off when she calls the corporate offices in Ohio, but the Federal Court's order or award of damages may be enforceable outside of the country. If the company has assets in Canada, it has a much stronger interest in complying.

Tuesday, June 01, 2004

Federal Privacy Commissioner announces funding program for Privacy in Canada

Jennifer Stoddart has today (1 June 2004) announced a new initiative from the Office of the Privacy Commissioner to support the promotion of research and promotion of personal information protection. More details are available on the Commissioner's website:

Contributions Program Introduction:

"The Office of the Privacy Commissioner of Canada (OPC) has officially launched a $200,000 Contributions Program which will support research into, as well as the promotion of, the protection of personal information.

With this Program, we hope to encourage the development of a national privacy research capacity that will contribute to advances in knowledge and policy development in the areas of privacy and data protection. We also hope to support the development of expertise in selected areas of privacy and data protection, and to foster an understanding of the social value of privacy to address emerging issues and opportunities...."