Saturday, December 04, 2004

Opposition calls for minister's resignation after privacy incident

After it was revealed that 27,000 benefits cheques were distributed along with social insurance numbers and addresses of other benefits recipients, the opposition Conservative Party is calling for the resignation of Ontario's finance minister, Greg Sorbara. I don't expect it will happen, but this is further evidence how a glitch that was likely caused by a lower-level employee can have huge repurcussions for an organization:

The Globe and Mail: Tories call for finance minister to step down pending privacy investigation:

"Toronto - The province's finance minister should step aside over an embarrassing security lapse, Conservative Leader John Tory said Saturday.

Mr. Tory called on the premier to ask Greg Sorbara to step down while the privacy commissioner investigates how the social insurance numbers of 27,000 people were accidentally released last week...."

Province apologizes in privacy snafu (Globe and Mail)

The Globe and Mail, in today's edition, has more information on the most recent breach of privacy to hit the presses:

The Globe and Mail: Province apologizes in privacy snafu:

"The Ontario government appears to have made a major privacy gaffe, mailing out thousands of cheques this week that included wrong names and social insurance numbers.

Government officials said yesterday that as many as 27,000 cheques were sent out with incorrect confidential information.

Ontario Management Board chairman Gerry Phillips blames human error and a new computer system for the security lapse.

'I take this matter extremely seriously and apologize on behalf of the government for this unacceptable release of personal information,' Mr. Phillips said. 'I want to assure the public that government officials have identified the cause of the problem and have taken steps to ensure this does not happen again.'

The cheques were issued with the correct names of the recipients, but the cheque stub contained the name of someone else as well as a social insurance number and home address.

The cheques were part of the Ontario government's child-care supplement for working families.

The issuing bank for the cheques was the Canadian Imperial Bank of Commerce, which was implicated in a separate privacy breach last week that involved the transmission of confidential bank customer data to a business in West Virginia.

'CIBC is not in any way involved in this error made by the Ontario Ministry of Finance,' bank spokeswoman Susan McDougall said in a statement. Ministry officials were also quick to stress that the CIBC played no part in the error."

Friday, December 03, 2004

Another privacy breach to round out the week

CTV News is reporting another Canadian privacy breach apparently caused by a computer glitch. Apparently, twenty seven thousand welfare cheques were distributed this week with the social insurance numbers of others written on them. Once again, apologies are the the order of the day:

CTV.ca | Personal info released on Ont. benefit cheques:

"The Ontario government is apologizing for an embarrassing security lapse that accidentally disclosed the social insurance numbers of 27,000 people in the province.

The error occurred when the latest run of Ontario child-care supplement cheques went out with stubs attached that included the wrong name, address and SIN, said Management Board Chairman Gerry Phillips.

'I want to begin by apologizing to those 27,000 people,'' Philips said late Friday. 'This is unacceptable.''...."

Privacy law and insolvent companies

There has been no shortage of criticism of the Personal Information Protection and Electronic Documents Act (PIPEDA). Some say it is simply weird by incorporating an external standard (in this case the Canadian Standards Association Model Code for the Protection of Personal Information). Some say it is hard to follow because it is full of principles rather than rules. Others think it is unmanageable. Others say it is toothless.

One thing that most agree on is that there is an important aspect provision that was simply forgotten: there is nothing in the law that would allow the disclosure of a customer list either as a prelude to or in the course of a business acquisition. Theoretically, you can't disclose a customer list as part of due diligence, nor can you provide details of key employees (if the company in question is a federal work, undertaking or business) unless you have the consent of the individuals concerned.

One exception to the consent rule is that you can disclose personal information without consent if the disclosure is:

"7(3)(c) required to comply with a subpoena or warrant issued or an order made by a court, person or body with jurisdiction to compel the production of information, or to comply with rules of court relating to the production of records;"

Some clever insolvency practitioners have taken advantage of paragraph 7(3)(c) in PIPEDA and the huge discretion given to judges under the Companies' Creditors Arrangement Act (CCCA) to deal with this problem when the anticipated acquisition is related to the court supervised sale of a business under the CCAA. A recent order of the Quebec Superior Court in Re Strategy First Inc. includes a reference to PIPEDA and gives the court's blessing to due diligence disclosure and post-closing disclosure of personal information:

"[44] ORDERS that, pursuant to subparagraph 7(3)(c) of the Personal Information Protection and Electronic Documents Act, S.C. 2000, c.5, the Petitioner is permitted in the course of these proceedings to disclose personal information of identifiable individuals in its possession or control to stakeholders or prospective investors, financiers, buyers or strategic partners and to their advisers (individually, a 'Third Party'), to the extent desirable or required to negotiate and complete the Restructuring or the preparation and implementation of the Plan or a transaction in furtherance thereof, provided that the Persons to whom such personal information is disclosed enter into confidentiality agreements with the Petitioner binding them to maintain and protect the privacy of such information and to limit the use of such information to the extent necessary to complete the transaction or Restructuring then under negotiation. Upon the completion of the use of personal information for the limited purpose set out herein, the personal information shall be returned to the Petitioner or destroyed. In the event that a Third Party acquires personal information as part of the Restructuring or the preparation and implementation of the Plan or a transaction in furtherance thereof, such Third Party shall be entitled to continue to use the personal information in a manner which is in all material respects identical to the prior use of such personal information by the Petitioner;"

One additional aspect of interest is that the Order requires acquirors to use the personal information in the manner in which it was used by the original custodian.

Ok, one more interesting thing: The order was made by the Quebec court. Presumably, it was dealing with a Quebec company that is not a federal work, undertaking or business. But ... PIPEDA doesn't apply in Quebec to such companies, but I guess it doesn't hurt to throw it in.

Release: Task Force on Spam Achieves Consensus for Best Practices to Reduce Spam

The Industry Canada Task Force on Spam has released a consensus document that includes nine "best practices" for ISPs and network players for the reduction of spam. From the IC press-release:

Task Force on Spam Achieves Consensus for Best Practices to Reduce Spam:

"OTTAWA, December 3, 2004 - The Honourable David L. Emerson, Minister of Industry, today congratulated members of the Government of Canada's Task Force on Spam for agreeing to a series of best practices that should help reduce spam before it reaches the end-user.

The Task Force met with key stakeholders today to review the progress of An Anti-Spam Action Plan for Canada. Announced last May, the action plan is a joint government and private sector effort to reduce and control spam. Increased public awareness, international collaboration, industry best practices and regulatory measures are all being addressed.

"The Task Force is six months into its mandate and the fact that such a disparate group of private sector players, ranging from small Internet service providers to large corporations, has agreed to a common standard is worthy of praise," said Minister Emerson. "It shows our mutual commitment to reducing spam."

Among the best practices the industry leaders have agreed to follow are that Internet service providers (ISPs) and other network operators should block e-mail file attachments with specific extensions known to carry infections, or filter e-mail file attachments based on content properties.

Industry-wide practices of this kind are a world first, representing a product of consensus among Canada's largest and smallest ISPs, network operators, large enterprise users, software developers, anti-spam advocates and Industry Canada.

The Task Force also unveiled an Internet-based communications campaign, including a common logo and Web site, to raise public awareness on steps that users can take to limit and control the volume of spam they receive.

"Public education and awareness are critical tools in our fight against spam," said Suzanne Morin, Co-chair of the Public Education and Awareness Working Group. "We point out a number of straightforward measures that consumers can take to help protect themselves and fight spam."

Unsolicited commercial e-mail, generally known as spam, has become a major problem globally, accounting for approximately two thirds of e-mails circulating on the Internet. The majority of spam originates outside Canada and therefore outside of Canadian jurisdiction. Spam results in increased network management costs and is often used to spread viruses. This is a serious issue that affects consumer and business confidence in e-mail and the Internet.

Launched on May 11, 2004, the Task Force on Spam oversees the implementation of a six-point action plan. The plan calls for specific initiatives by government and the private sector, including: the use of existing laws and regulatory measures; the review of regulatory or legislative gaps; the improvement of current industry practices; the use of technology to validate legitimate commercial communications; the enhancement of consumer education and awareness; and the promotion of an international framework to fight spam.

The Task Force on Spam will submit a final report to Minister Emerson in spring 2005.

For more information, including the nine recommended best practices, please visit http://www.e-com.ic.gc.ca."

The Task Force Home Page is at http://e-com.ic.gc.ca/epic/internet/inecic-ceac.nsf/en/h_gv00248e.html

You're faxing my what, where?

After the anger and fingerpointing about the recent CIBC faxing incident(s), columnists are moving to a practical approach on the issue: why are you faxing confidential informaiton and is there a better way to communicate? Jim Middlemiss of the Financial Post has a good column on these questions:

You're faxing my what, where?:

"There are better ways to send sensitive information

Jim Middlemiss
Financial Post
December 2, 2004

Businesses can avoid potential public relations and legal nightmares by developing privacy policies, authentication processes and using cutting-edge technology. The Canadian Imperial Bank of Commerce learned this the hard way last week when U.S. scrapyard operator Wade Peer went public with his story about how one of Canada's largest banks was flooding his fax machine with highly confidential information about its clients for the past three years."

I usually advise clients to be very careful faxing. The preferred way to do it is to e-mail a PDF of the documents (and turn off e-mail address auto-complete features). If you routinely send confidential information via fax, you should only use pre-programmed speed-dial numbers. And make sure you verify each one right after they are programmed. And you need to do what you can to avoid hitting the wrong button: the medical records department button must not be adjacent to the button for the local newspaper. Don't laugh. It has actually happened. Do you think that they will heed your cover-page warning to immediately destroy the fax? Perhaps not.

Thursday, December 02, 2004

Privacy watchdog probes firms

The Information and Privacy Commissioner has his work cut out for him, at least for the short term. More purloined personal information has been found through an investigation that began with the discovery of sensitive data in the course of a drug bust. It appears the information was collected by dumpster diving drug addicts, who sell the info to ID thieves to fuel their addictions. From the Edmonton Sun:

Edmonton Sun: Privacy watchdog probes firms:

"The province's privacy commissioner yesterday launched an investigation into three Edmonton-area businesses whose customers' personal information ended up in a hotel room. The privacy office is already investigating how civil servants' personal data - including credit reports - got to the hotel and was then found by cops working on a credit card probe. Drug paraphernalia and a shotgun were also found.

'This has got to stop,' Privacy Commissioner Frank Work said. 'The paper that the (police) showed me was mind-blowing. There's bags of it. I thought, 'Holy smokes.' '

Linens 'n' Things, Nor-Don Collection Network Inc. and Digital Communications Group Ltd. are under investigation.

But the holiday season is prime-time for dumpster divers and identity thieves, Work warned.

'There's going to be a zillion purchases and then a zillion returns. All that paper generated will make for a field day for thieves when they go rifling through dumpsters,' he said.

...."

Also, from today's Globe and Mail:

The Globe and Mail: Alberta probes leak of credit records:

CALGARY -- Alberta's Privacy Commissioner launched an investigation yesterday after the credit information of thousands of consumers landed in the hands of suspects in an identity-theft scheme.

Edmonton police recovered bank records, cellphone contracts, credit information held by a collection agency and credit-card receipts in connection with a search warrant executed Nov. 9 in a city hotel room in a credit-card investigation.

A man and a woman face criminal charges, including two counts each of possession of credit-card data, and it appears the documents were seized before the personal information of hundreds, even thousands of individuals, was used illicitly...."

More of PIPEDA and litigation: Goldberg v. St. John

PIPEDA made a brief appearance in an Ontario court in an interlocutory decision of Case Management Master Thomas Hawkins rendered at the end of September 2004. In Goldberg v. St. John, the defendant sought the plaintiff's client records to test a lost income claim. The plaintiff had been an employee of CIBC World Markets and he resisted the discovery request on the basis that the information should be subject to privilege and that its disclosure was barred by PIPEDA. He lost on the PIPEDA claim:

Goldberg v. St. John:

"[3] In order to challenge and test the plaintiff's evidence as to lost income, the defendants seek the following information: production of client records on all the plaintiff's customers for the period from 1997 to the present including client names and addresses. The defendants wish to track all the plaintiff's commission revenue and to understand why the plaintiff's commission revenue increased or decreased. Some 150 clients are involved. The theory of the defence is that some or all of the income which the plaintiff has lost and will lose in the future was and will be the result of factors unrelated to the accident.

[4] The plaintiff and CIBC World Markets Inc. resist this request on the ground that the information which the defendants seek is information which they are required to keep confidential. This confidentiality obligation is found in several places. First there is the Investment Dealers Association National Instrument 33-102. Secondly, there are the confidentiality of client information provisions found standard 'B' in the Conduct and Practices Handbook for Securities Industry Professionals prepared by The Canadian Securities Institute.

[5] The plaintiff and CIBC World Markets Inc. also rely upon the privacy provisions of the Personal Information Protection and Electronic Documents Act, S. C. 2000 ch. 5. I do not base my decision on this statute. I am not persuaded that this federal statute applies to a provincially regulated business and its employees such as CIBC World Markets Inc. and the plaintiff. CIBC World Markets Inc. is a stockbroker, not a bank."

Once again, it has been held that PIPEDA does not shield a party to litigation from disclosing relevant records. But this also reminds one that the info may be shielded by other legal and procedural rules.

Wednesday, December 01, 2004

Round two of labour-sponsored privacy campaign against BC government to begin

Labour groups are once again attacking the government of British Columbia for outsourcing public services that involve personal information. This second campaign comes after its high-profile attempt to derail the outsourcing of the province's medicare administration (See BCGEU's privacy campaign). While that campaign did not dissuade the Campbell government from its plans (BC announces medical privatization plan), it did lead to a significant inquiry by the province's Information and Privacy Commissioner. Now under attack is the province's plan to outsource bill collection:

B.C. opens private bank and credit data to U.S. scrutiny: "B.C. opens private bank and credit data to U.S. scrutiny

New privatization deal means U.S. authorities will have access to bank account and credit card numbers, property records, income and driver's licence information on B.C. residents

Vancouver - The B.C. Government and Services Employees' Union (BCGEU/NUPGE) plans to launch a new campaign this week warning residents that the Liberal government of B.C. Premier Gordon Campbell is making highly personal data vulnerable to American scrutiny through outsourcing and privatization.

The latest information to be placed in the hands of private American companies involves a wide range of information on most B.C. residents, including bank account and credit card numbers, property records, income and driver's licence information.

The province announced a $572-million ($483-million US) deal Friday with Electronic Data Systems (EDS) of Plano, Texas, to take over much of its bill collection activity. The 10-year deal comes with barely six months remaining in the Liberals' current mandate.

The province argues that privacy provisions contained in the contract will safeguard personal information but the union says the government is misleading citizens because it is already known that the contract will not withstand the overriding and intrusive powers available to American authorities under the U.S. Patriot Act.

The Patriot Act was passed by Congress and signed into law by President George Bush following the Sept. 11, 2001 terrorist attacks on New York and Washington.

The deal is even worse than a recent 10-year, $324-million contract signed with U.S.-based Maximus Inc. to privatize the processing of the medical claims of B.C. residents.

Privacy commissioner ignored

Once again, the province has ignored concerns raised by its own information and privacy commissioner, putting private sector ideological interests ahead of those of its own people, the BCGEU says.

Essentially, the latest contract means that intensely personal information on most British Columbians will be exposed to potential scrutiny by the FBI and other U.S. government agencies, the union warns.

"It’s another example of the Liberals bullying ahead without heeding the warnings of privacy commissioner David Loukidelis issues raised by the privatizing of records management, says BCGEU president George Heyman.

Loukidelis said the U.S. Patriot Act creates a real risk that personal information, once placed in the hands of private companies with U.S. links, will be open to scrutiny by the FBI and other American agencies. He recommended a series of measures to protect the privacy of British Columbians.

Heyman says Premier Campbell has failed to take the necessary range of measures recommended by the commissioner.

Patriot Act applies

"The fact is that the Patriot Act applies. EDS is an American company, and all the records in its possession are exposed," Heyman says.

"The Campbell government is clearly misleading the public and betraying the promise they made to British Columbians that real protections would be in place before any contracts were signed."

A long list of personal data at risk, Heyman warns..

"It includes everything from credit card and bank account numbers, personal property and asset details, individual and family income, and drivers license, vehicle and insurance information. It’s pretty serious stuff that British Columbians wouldn’t want to share with the Bush government," he says.

Meanwhile, the BCGEU leader said full details on his union's latest campaign to warn residents will be announced this week. The union is also continuing efforts to mount a legal challenge to the government.

The union says privacy guarantees written into the contract by EDS and the province will be overridden by the all-intrusive federal powers of the U.S. Privacy Act.

NUPGE

Misdirected fax saga continues

The Globe and Mail has been full of futher reports related to the CIBC misdirected faxes saga. Today, a Toronto Star columnist, and CIBC customer, replies to the bank's efforts:

TheStar.com - Trust misdirected at CIBC:

"CIBC, wake up. You can do a better job on privacy.

As one of your many customers, I appreciate getting a personal apology from your chief executive officer, John Hunkin - at least, in an open letter on the CIBC website.

This followed an earlier letter from chief privacy officer Ron Lalonde, who talked about what was done to safeguard customers' information after the Canadian Imperial Bank of Commerce learned that some faxes had been misdirected to a U.S. company in the spring of 2002.

'We notified our branches that information was being faxed to an incorrect number,' Lalonde said. 'We also contacted the owner of the company who had been receiving the faxes and elicited from him a commitment to shred all the faxes he had received and to notify us should he receive any additional ones.'

What about all the CIBC customers whose privacy had been breached? Didn't they deserve to know a U.S. business was privy to confidential details on their banking transactions?

And what about the Privacy Commissioner of Canada's office? Didn't it deserve to know about a potential violation of the act it administers, the Personal Information Privacy [sic] and Electronic Documents Act?

Apparently, you decided there was no need to notify customers or the privacy commissioner...."

For more coverage see:

Update: April 18, 2005 - PIPEDA and Canadian Privacy Law: Privacy Commisioner of Canada releases her report on the CIBC faxing incidents