Wednesday, July 06, 2005

Tuesday, July 05, 2005

Alberta OIPC report on missing backup tape containing health information

The Alberta Information and Privacy Commissioner has released his report on the case of the missing backup tape (for earlier reports, see The Canadian Privacy Law Blog: Incident: Encrypted tapes containing health information on hundreds of thousands of Albertans missing or tampered with). The report is available from the Commissioner's site:

Investigation Report H2005-IR-001:

"Commissioner releases report into missing computer tape containing health information. Commissioner Frank Work initiated an investigation on his own motion under the Health Information Act (HIA) into the loss of a missing data tape containing information related to the administration of the Alberta Health Care Insurance Plan (AHCIP), specifically group premium statement information.

Click to view more information Investigation Report H2005-IR-001."

After a privacy breach, how should you break the news?

Larry Ponemon, of the Ponemon Institute, writes in ComputerWorld about how to break the news of a privacy breach to your customers. All makes sense:

After a privacy breach, how should you break the news? - Computerworld:
  • Timeliness is important.
  • Document the issue.
  • Don't sugarcoat the message.
  • Provide support.
  • Show me the money.
  • Personalization creates trust.
  • Adjust the message to fit the severity of the breach.

Charges dropped in hidden camera case

A little while ago, I blogged about a news article from the Morning Call Online. The article was about an arrest that had been made by police in Northampton County in PA, allegedly for invasion of privacy after an teddy bear had been discovered harboring a covert video camera. Tonight, I got a comment on that post that suggested I remove my blog entry:

The Canadian Privacy Law Blog: Beware the bear:

"FYI - never happened. he did not do it. so says pennsylvania law. and that's that. remove the article or i will contact him and have him contact his lawyer, who will then MAKE you remove it.

thanks!"

The comment didn't provide a lot of info, but I did manage to find a later article in the Morning Call saying that the charges had been dropped: mcall.com - Charges dropped in Peeping Tom case.

Michael Geist calls for privacy breach reporting law in Canada

Michael Geist has been a vocal proponent of reform to Canada's privacy laws. In the past, he has criticised the ombudsman model adopted under PIPEDA is inadequate and that the privacy commissioner should "name names". His latest Law Bytes column suggests that there should be an obligation to report privacy breaches, following the lead of California.

Michael Geist - Canada Needs A National Privacy Breach Reporting Law:

"My latest Law Bytes column ... makes the case for a national Canadian privacy and security breach reporting law. Over the past twelve months, there has been a staggering number of reported privacy and security breaches -- with some experts estimating that more than 50 million people have been put at risk since the start of this year alone. While the number of breaches may not have changed (few doubt that privacy breaches have been occurring for years), news of yet another privacy or security breach, whether it is the 40 million credit card holders whose personal information was recently placed at risk or it is the several dozen CIBC banking customers whose data was inadvertently faxed to a West Virginia junkyard, this type of violation has become a staple of the daily news cycle.

The change in practice is due in large measure to the State of California's SB1386, a two-year old law which mandates that companies and agencies that do business in the state or possess personal information of state residents must report breaches in the security of personal information in their possession.

Unfortunately, no similar law exists in Canada at the present time. In fact, until Ontario Privacy Commissioner Ann Cavoukian publicly called for the adoption of such a law late last month, no Canadian privacy commissioner at either the federal or the provincial level had used their position to pressure for such reforms...."

Interestingly, most of the Canadian privacy lawyers with whom I have discussed the issue are advising their clients to voluntarily fess up to affected customers if personal information is compromised. We do not yet have any judicial consideration of the common law duty to warn, but it appears likely that a Canadian court will find a duty to warn a customer if the custodian's actions (or inactions) has placed that customer at risk of identity theft or other threat and the custodian did not assist the customer to mitigate the harm that the breach may have caused.

At a recent meeting of privacy lawyers, at which we were discussing reform of PIPEDA, it was interesting to see that they were virtually unanimous in supporting such a reform to PIPEDA.

Your car's identity can be stolen

Yahoo news is carrying a story on "VIN theft", which is essentially identity theft of your car:

Is your car a clone?:

"... In recent months, the term 'auto theft' has sprouted a new variation, known as 'VIN theft,' 'VIN cloning' or 'auto identity theft.' Whichever you prefer, it's a costly and complicated problem for some car dealers and car buyers.

Of the 1.5 million vehicles stolen last year, 225,000 were used in VIN-theft activity, says Dan Kahn, road test editor for Edmunds.com and Insideline.com.

In this new genre of the crime, your automobile stays with you but the VIN is duplicated on another vehicle -- usually one that is stolen or used in a different state...."

New Brunswick City of Fredericton opts for downtown cameras

The City of Fredericton is planning to install a network of video cameras in the bar district to catch hooligans who make noise and cause problems when the bars close. I haven't heard too much of a fuss about it from this end of the country. It may be that law-abiding patrons want to be surveilled:

CBC New Brunswick - Fredericton opts for downtown cameras:

"... Coun. Bruce Grandy, the chair of the city's Public Safety Committee, says law-abiding bar patrons may come to appreciate the fact that they're being watched...."

Photographers' Guide to Privacy

The Reporters' Committee for Freedom of the Press has produced a fact sheet on privacy for photographers. I don't know when it was first produced, but it is an interesting and handy guide to the principal privacy torts in the United States:

Photographers' Guide to Privacy:

"Celebrities, politicians and other sought-after sources of news would appear, by their routine claims that members of the media have violated their privacy, to understand precisely what is private and what is public, or newsworthy, information.

Journalists, however, often possess different notions of privacy and newsworthiness, and know that the question is more complicated. Reporting news stories in a way that serves and informs the public will often entail publicizing facts or displaying images that will embarrass or anger someone...."

Monday, July 04, 2005

Online resumes turn risky - Job seekers post data that can be used by identity thieves

I've posted about this before (see The Canadian Privacy Law Blog: Privacy watchdog warns online job seekers to beware), but it bears repeating. The San Francisco Chronicle is warning jobseekers to beware what they put online since thieves, criminals and other miscreants are out there, looking for fertile sources of personal information: Online resumes turn risky / Job seekers post data that can be used by identity thieves.

Sunday, July 03, 2005

Privacy and workplace e-mail in the US

WomensBiz.US has asked a range of American lawyers about privacy of workplace e-mail. Thanks to Gerry Riskin for pointing me to The Common Scold's posting about this article:

The Fizz June05 - WomensBiz.US:

"With the recent ruling awarding 30 million dollars to saleswoman Laura Zubulake, who won her sex discrimination case against UBS with the help of subpoenaed e-mail messages, a Pandora's box of issues is emerging regarding work-product privileges in this new age of electronic communications. Many states now have laws requiring employers to preserve all electronic documents, including those generated by their employees on personal business. So we asked you to tell us if you think it's fair to eavesdrop on employee conversations via phone or e-mail? Are our Blackberries and home computers no longer private? And how far do you think this will go? This is what you said!"