Saturday, May 06, 2006

Nova Scotia introduces amendments to thwart USA Patriot Act

Yesterday, in the second day of the spring sitting of the provincial legislature, Nova Scotia's Justice Minister, Murray Scott, tabled Bill No. 16 - Entitled an Act to Protect the Personal Information of Nova Scotians from Disclosure Outside Canada. (Hon. Murray Scott), (the full text is not yet available online). It will amend the Freedom of Information and Protection of Privacy Act to address the perceived threat to privacy posed by the USA Patriot Act if the processing or storage of personal information is outsourced by Nova Scotia public bodies to companies operating in the US (or US companies operating in Canada).

The appearance of the bill was foreshadowed by consultations among public bodies and IT service providers (see: The Canadian Privacy Law Blog: Nova Scotia consultations on Patriot Act amendments to FOIPOP).

Here's the press release from the Nova Scotia government:

News Release: Department of Justice:

"New Legislation to Protect Privacy

Department of Justice

May 5, 2006 11:15

New provincial legislation will better ensure that Nova Scotians' personal information is not disclosed under the U.S. Patriot Act.

The new Personal Information International Disclosure Protection Act outlines a series of requirements and penalties that protect personal information from inappropriate disclosure.

"We know that American security legislation has led to concerns about the ability to access personal information of Nova Scotians held outside Canada," said Murray Scott, Minister of Justice. "This legislation clearly outlines the responsibilities of public bodies, municipalities and technology service providers, and the consequences if they are not fulfilled."

The act provides protection regarding storage, disclosure and access to personal information outside of Canada in the custody or under the control of a public body or municipality.

Under the act, the minister of Justice must be notified if there is a foreign demand for disclosure of any personal information of Nova Scotians. It also requires that service providers storing information only collect and use personal information necessary for their work for a public body or municipality.

The act also address "whistleblower" protection for employees of external service providers to ensure they are protected if they report an offense under the act. Whistleblower protection for Nova Scotia government staff already exists under the Civil Service Act.

"In order for these measures to be successful, staff must be sure they will be protected if they come forward to report wrongdoing under this act," said Mr. Scott.

Penalties under the act include up to $2,000 per government employee for malicious disclosure by employees of public bodies and municipalities. The act also creates offences for service providers, with penalties of up to $2,000 for employees and $500,000 for companies.

Offences relate to the improper storage, collection, use, or disclosure, failure to notify the minister of Justice of foreign disclosure demands, and improper discipline or termination of employees.

"We are putting in place serious and significant penalties to protect the privacy of Nova Scotians," said Mr. Scott.

The minister also announced that the Wills Act is being amended. Updates will bring it more in line with other Canadian jurisdictions. The amendments respond to recommendations of the Law Reform Commission and will make it easier for people to ensure their final wishes are fulfilled by clarifying the effect divorces have on wills and the distribution of property in Nova Scotia under wills made outside the province. It will also permit handwritten wills.

The province is also introducing a number of housekeeping amendments under the Justice Administration Act.


FOR BROADCAST USE:

Justice Minister Murray Scott has introduced new provincial legislation that will help ensure Nova Scotians' personal information is not at risk from activities under the U.S. Patriot Act.

The new Personal Information International Disclosure Protection Act outlines a series of requirements and penalties that protect personal information from inappropriate disclosure.

The act provides protection regarding storage, disclosure and access to personal information in the custody or under the control of a public body or municipality.

-30-

I'll definitely have more to say about this once I've had a chance to review Bill 16 in some detail.

Noncommercial spam and PIPEDA

Alec Saunders, at saunderslog.com is a little upset about receiving some unsolicited e-mail from the liberal party and Bill Graham (How to Stop the Liberal Party of Canada From Spamming You -- Alec Saunders .LOG):

Hypocrites that they are, by spamming me with Liberal propaganda, they’ve violated their own privacy policy. Their hypocrisy is further amplified by the fact that what they’ve done contradicts the Personal Information Protection and Electronic Documents Act, section 4.2.4 which states:
When personal information that has been collected is to be used for a purpose not previously identified, the new purpose shall be identified prior to use. Unless the new purpose is required by law, the consent of the individual is required before information can be used for that purpose.

And here, of course, is the irony. It was a Liberal Government which introduced the Personal Information Protection and Electronic Documents Act.

Whether this is a violation of PIPEDA depends upon whether that law applies at all. PIPEDA only regulates the collection, use and disclosure of personal information in the course of commercial activities (and information about employees of federal works, undetakings and businesses). This generally excludes non-profits, like political parties. Some activities are deemed to be commercial, like the sale or trade of personal information by a non-profit organization.

It's arguable that PIPEDA wouldn't apply in the case of political spam, unless one organization has traded the e-mail address with another. But if it bugs you enough, complain to the Privacy Commissioner and see if she agrees...

RFID Hacking

Wired is running an article on RFID hackers, highlighting that it is rather easy for RFID chips to be hacked/cloned/altered/abused using a little knowledge and some off the shelf equipment: Wired 14.05: The RFID Hacking Underground.

Friday, May 05, 2006

Nova Scotia man charged with voyeurism

According to the Halifax Chronicle-Herald, a Nova Scotia man is the first in the province (and perhaps the country) to be charged under Canada's recent voyeurism amendments to the Criminal Code. Gist:

The ChronicleHerald.ca

Man, 33, first to face voyeurism charge

By TOM McCOAG Amherst Bureau

AMHERST — A Cumberland County man has become the first Nova Scotian to be charged under the new voyeurism section of the Criminal Code.

Winston Charles Patriquin, 33, of Port Howe is alleged to have used a video camera to secretly tape a girl having a shower. He is also charged with one count of knowingly accessing child pornography through a computer for his own use, making child pornography and possession of child pornography.

"This is definitely the first case of (voyeurism) to be tried in the province, and we think it may be the first case in Canada," Chris Hansen, spokeswoman for the Nova Scotia Public Prosecution Service said Thursday. ""We’re not exactly sure of the latter, but if it isn’t the first, it certainly is among the first charges under this newly created section to be laid in the country."

The bill that added voyeurism to the code passed last fall and increases the sentences for people convicted for possessing, making and distributing child pornography or committing an act of child molestation by "ensuring that those convicted of those crimes will serve jail time." ...

Wednesday, May 03, 2006

Q. What could a boarding pass tell an identity fraudster about you?

The Guardian Online has a very interesting special report on identity theft, using a discarded boarding pass to track down huges troves of information on the poor guy who discarded it. It's a tale of how much information is collected and how easy it is for bad guys to get ahold of it. Read on:

Guardian Unlimited | Special reports | Q. What could this boarding pass tell an identity fraudster about you? A. Way too much:

"... We logged on to the BA website, bought a ticket in Broer's name and then, using the frequent flyer number on his boarding pass stub, without typing in a password, were given full access to all his personal details - including his passport number, the date it expired, his nationality (he is Dutch, living in the UK) and his date of birth. The system even allowed us to change the information.

Using this information and surfing publicly available databases, we were able - within 15 minutes - to find out where Broer lived, who lived there with him, where he worked, which universities he had attended and even how much his house was worth when he bought it two years ago. (This was particularly easy given his unusual name, but it would have been possible even if his name had been John Smith. We now had his date of birth and passport number, so we would have known exactly which John Smith.) ..."

US wiretap scandal leads to closer look at Canada's CSE

Recent scandal in the United States over warrantless wiretapping by the NSA under the USA Patriot Act has led to increased scrutiny of Canada's Communications Security Establishment and its actions under the Anti-terrorism Act. Gist:

CTV.ca | U.S. wiretapping scandal sparks Canadian inquiry:

OTTAWA -- Allegations of illegal eavesdropping by U.S. spies prompted pointed questions from the federal watchdog who oversees their Canadian counterparts, newly released records reveal.

Correspondence obtained by The Canadian Press shows the public controversy about U.S. National Security Agency spying on American citizens led to a series of highly classified exchanges in Ottawa.

John Adams, chief of the ultra-secret Communications Security Establishment, was forced to respond to detailed inquiries spanning two months from the office of Antonio Lamer, the former Supreme Court chief justice who, as CSE commissioner, serves as watchdog over the spy outfit.

...

But it is clear from the records, obtained under the Access to Information Act, that Lamer's office wanted to ensure the CSE, a wing of the Defence Department, wasn't contravening Canadian law by conducting excessive snooping in the fight against terrorism.

...

The CSE works closely with the signals intelligence services of allied countries, including the massive Maryland-based National Security Agency, which boasts more than 30,000 employees.

...

New Brunswick premier in privacy hot water

The Premier of the Province of New Brunswick is in hot water and one of this senior official has had to resign after a letter from an opposition politician concerning a constituent with an 18-month licence suspension for drunk driving was released to the media by the Premier's Press Secretary. The Secretary has since resigned and the Ombudsman of the province is investigating under the province's privacy legislation. (See: canadaeast.com - CP Atlantic Regional News. Hat tip to Pogo Was Right for the link.)

This sort of thing is not particularly new in New Brunswick, but you would think they'd learn. See: The Canadian Privacy Law Blog: Politics and privacy: New Brunswick MLA resigns from cabinet over alleged violation of NB's privacy laws, The Canadian Privacy Law Blog: Second New Brunswick Minister resigns over new privacy breach.

Tuesday, May 02, 2006

New RFID privacy standard and privacy-protecting RFID device, both brought to you in part by IBM

Network World is running two interesting articles on RFIDs and privacy, both of which include reference to IBM's growing role in this field:

IBM demos RFID tag with privacy-protecting features - Network World:

"The latest to tackle the issue is IBM, which this week is expected to demonstrate its design for an RFID tag with a disabling feature that limits - but doesn't kill - a wireless chip's ability to broadcast item information.

The Clipped Tag gives consumers the option to disable RFID tags on items they purchase without eliminating the possibility that the tags could be used later to expedite product returns or recalls, says Paul Moskowitz, a research staff member at IBM's Watson Research Center in Hawthorne, N.Y. The design calls for a product label with perforations 'like a sheet of postage stamps,' he says.

After purchasing a tagged item, a consumer can tear the Clipped Tag label along the perforations to remove a portion of the tag's antenna, reducing its transmission capability. 'When you do that, you do not kill the tag completely. The chip is still there, and it has some of the antenna left. But you've just taken a tag that may have had a 30-foot range and reduced the range to just a few inches.' "

IT vendors, privacy groups release RFID standards - Network World:

"Companies using RFID tags on products should notify customers in all cases, should tell customers whether they can deactivate the tags and should build security into the technology as a primary design requirement, the group said. "

Monday, May 01, 2006

Ontario arbitrator determines that administration of employment is not "commercial activity" for the purposes of PIPEDA

The Personal Information Protection and Electronic Documents Act is a messy, difficult to understand statute. It is not clearly drafted and lay people have a heck of a time trying to figure out what it means. It should not be a surprise that many lawyers have a hard time getting their heads around its requirements. For those who deal with the statute on a daily basis, there is a consensus on how it works and how it is to be interpreted. These interpretations are generally confirmed by the Commissioners who enforce the laws and the courts, when privacy issues come before them.

It remains surprising to see parties to litigation (and their counsel) making arguments that go completely against the consensus view. It should not be suprising when the Courts make decisions that, with all due respect, are completely wrong. (See, for example, The Canadian Privacy Law Blog: Courts and PIPEDA: Why the federal law does not apply in British Columbia. )

In a recent arbitral decision from Ontario, an arbitrator was faced with the argument that (i) PIPEDA applies to employee information in the provincially regulated private sector in Ontario and (ii) because of PIPEDA, an employer is prohibited from providing certain information to the union as required under the province's occupational health and safety legislation. The union (oddly) did not seriously dispute argument (i). The panel of the Ontario Labour Relations Board didn't agree with the employer and went farther than the union desired: it concluded that the collection of employee information in connection with the administration of the employment relationship is not "commercial activity" for the purposes of PIPEDA. This is critical since section 4(1) of PIPEDA dictates the circumstances under which the law applies:

Application

4. (1) This Part applies to every organization in respect of personal information that

(a) the organization collects, uses or discloses in the course of commercial activities; or

(b) is about an employee of the organization and that the organization collects, uses or discloses in connection with the operation of a federal work, undertaking or business.

Except for employee information of federal works, undertakings and businesses, PIPEDA can only apply if ther personal information in question is collected, used or disclosed in connection withe commercial activities. The arbitration panel concluded:

Although the definition of commercial activity is quite broad and, as a result, subsection 4(1)(a) of PIPEDA would include the collection, use or disclosure by the company of the personal information of its employees’ for commercial purposes, where the employees’ personal information is being collected, used or disclosed for employment-related purposes, subsection 4(1)(a) does not apply. First, the collection, use or disclosure by an organization of the personal information of its employees solely for employment-related purposes cannot reasonably constitute a “commercial activity” under any logical interpretation of that phrase. The mere fact that an organization carries on a commercial activity cannot, on its own, render the collection, use or disclosure of employee personal information for employment-related purposes into a commercial activity. Furthermore, if subsection 4(1)(a) of PIPEDA is intended to include the employment-related collection, use or disclosure by an organization of the personal information of its employees, subsection 4(1)(b) of PIPEDA (under which Part 1 of PIPEDA applies to the personal information of the employees of federal works, undertakings or businesses) would be unnecessary. (See: Re: McKesson Canada and Teamsters Chemical, Energy and Allied Workers Union, Local 424, 136 L.A.C. (4th) 102, G.F. Luborsky).

This conclusion is in accord with the position embraced by most privacy law practitioners and may help to settle some still broadly-held misconceptions.

The case is International Association of Bridge, Structural, Ornamental and Reinforcing Iron Workers and its Local 736 v. E.S. Fox Limited, [2006] O.L.R.D. No. 107 (QL) and the full text is available online here: http://www.lancasterhouse.com/decisions/2006/jan/OLRB-IABSORIWU,736-v-ESFox.pdf

Thanks to the CUPE Local 1356 blog for the pointer to the case.

Survey on Canadian privacy law compliance released by CIPPIC

The Canadian Internet Policy and Public Interest clinic has today released a pair of reports that paint an unflattering portrait of the state of compliance with privacy laws in Canada. The first is a survey of Canadian retailers to determine whether the companies reviewed are complying with PIPEDA and its equivalents. The second is a survey of the data brokering indstry in Canada. Here's the blurb and links from the CIPPIC website:

CIPPIC News = CIPPIC:

CIPPIC study shows widespread violation of privacy laws

May 1, 2006

In a report released today, the CIPPIC provides the results of the first Canadian survey assessing the compliance of retailers with Canadian data protection laws. The results show widespread non-compliance with federal laws requiring openness, accountability, consent, and individual access to personal data. In a companion report also released today, CIPPIC exposes the many ways that detailed personal information about consumers is gathered and traded in the marketplace.

  • News Release (French version)
  • Report on Retailer Compliance with PIPEDA
  • Compliance Report - Executive Summary (French version)
  • Compliance Report - Appendices
  • Report on Databrokerage Industry
  • Databroker Report - Executive Summary (French version)
  • Update (20060512): The Ottawa Citizen is reporting on this in today's edition: Online sellers flout privacy rules.