Friday, December 08, 2006

PIPEDA hearing, day six

More from the PIPEDA hearings, thanks to Michael Geist:

Michael Geist - PIPEDA Hearings - Day 06 (CIPPIC, PIAC, MRIA): Friday December 08, 2006 The PIPEDA hearings continued on Wednesday with CIPPIC, PIAC, and the Marketing Research and Intelligence Association providing their views. While I was unable to find a student to blog the event, CIPPIC has posted its meeting notes and speaking notes.

Update (20070118): For links to the full hearing transcripts, go to: Canadian Privacy Law Blog: PIPEDA Review Transcripts.

Thursday, December 07, 2006

Right to Know Coalition of Nova Scotia

The new access to information advocacy organization for Nova Scotia, the Right to Know Coalition of Nova Scotia, has a new blog: Right to Know Coalition of Nova Scotia.

Wednesday, December 06, 2006

Calgary Health Region found in Contravention of Health Information Act over stolen laptop

The Office of the Information and Privacy Commissioner of Alberta has found that the Calgary Health Region violated the Health Information Act in connection with a stolen laptop:

Calgary Health Region found in Contravention of Health Information Act over stolen laptop:

The Office of the Information and Privacy Commissioner has found that the Calgary Health Region contravened the Health Information Act (HIA), following an investigation into the theft of a laptop computer. The laptop contained a database of more than 1,000 children in a mental health care program, including patient history and treatment details.

Key findings included:

  • The Health Region had policies in place that would have protected the stolen laptop and the information it contained, but those policies were not fully implemented by the Collaborative Mental Health Program.
  • A copy of the entire database was stored on the stolen computer, increasing the number of people affected. Program workers should only have copied the files they needed, rather than the entire database.
  • While the laptop was protected by passwords, this was not adequate given the nature of the information it contained
  • A knowledgeable and motivated individual could access the data with tools that are readily available on the internet.
  • While the risk of identity theft from the information is low, it cannot be ruled out.
  • Encryption technology would have protected the lost data, but it was not implemented.

The CHR informed the Commissioner's Office of the incident on its own initiative, took immediate action to notify affected individuals and has since implemented measures to secure mobile computers. The Health Region also agreed to follow our Investigator's recommendations.

Investigator Brian Hamilton says, "For the most part the Calgary Health Region does a good job protecting information, and has been taking steps to improve security. Unfortunately, they failed to recognize and address the risks of mobile computing in this program area."

Others can learn from this investigation. The Office of the Information and Privacy Commissioner urges all HIA custodians, public bodies and private sector organizations to follow these recommendations for mobile computing:

  • Perform a Privacy Impact Assessment (or a security risk assessment) before implementing mobile computing.
  • Do not store personal or health information on mobile computing devices unless you need to - consider technologies that allow secure, remote access to your network and data instead.
  • If you must store personal or health information on a mobile device, use encryption to protect the data - password protection alone is not sufficient.
  • Keep the amount of personal or health information stored on mobile computing devices to a minimum, based on your business needs.
  • Periodically check your policies against practice to ensure they reflect reality and remain effective.
  • Provide specific training on mobile computing to staff to ensure they understand the risks and understand how to protect their equipment.

-30-

For more information or to view a copy of Investigation Report H2006-IR-002, visit our website, http://www.oipc.ab.ca/.

Tuesday, December 05, 2006

Blogging the PIPEDA hearings - Day 5

Michael Geist has again posted notes from the PIPEDA review hearings on is blog:

Michael Geist - PIPEDA Hearings - Day 05 (CMA, FETCO):

"Today marked the fifth day of PIPEDA hearings with the Canadian Marketing Association and FETCO (Federally Regulated Employers Transportation and Communication) taking centre stage. The gist of today's discussion from the witnesses - no order making power, cautious approach on security breach disclosure, and cut back on employee privacy rights. The MPs have begun to settle into specific issues with the Conservative members focused on the compliance costs, while the opposition members more receptive to enhanced privacy rights within PIPEDA. Shiran Sabari provides a complete look at the discussion: ..."

Update (20070118): For links to the full hearing transcripts, go to: Canadian Privacy Law Blog: PIPEDA Review Transcripts.

Sunday, December 03, 2006

PIPEDA Case Summary #351: Use of personal information collected by Global Positioning System considered

On Thursday, the Office of the Privacy Commissioner of Canada posted a very interesting and detailed finding on the use of GPS tracking of company vehicles. The finding is lengthy and worth a read: Commissioner's Findings - PIPEDA Case Summary #351: Use of personal information collected by Global Positioning System considered (November 9, 2006).

A summary of the summary is in the following media release:

News Release: Privacy Commissioner urges caution before installing GPS in company vehicles (November 30, 2006):

News Release

Privacy Commissioner urges caution before installing GPS in company vehicles

Ottawa, November 30, 2006 – Employers need to carefully consider the privacy rights of their workers before installing Global Positioning Systems (GPS) into their vehicle fleets, according to the Privacy Commissioner of Canada, Jennifer Stoddart.

The Office of the Privacy Commissioner of Canada (OPC) today released a summary of its findings into a case involving the workplace use of GPS, which can track the location of a vehicle in real time. The Commissioner discussed her Office’s findings at a workplace privacy seminar hosted by Ryerson University.

“This is an important issue for employers and employees across Canada. We’re seeing more and more organizations installing GPS in their cars and trucks and it’s unclear whether they are adequately addressing privacy issues,” Ms. Stoddart said.

In the case investigated by the OPC, several workers complained that their employer, a telecommunications company, is using GPS to improperly collect their personal information – specifically their daily movements while on the job.

The company is using GPS in its installation and repair, and construction vehicles to locate, dispatch and route employees to job sites. Some workers worried, however, that GPS is also being used to monitor work performance and that information gleaned from this technology will be used to justify disciplinary action.

The OPC investigation accepted most of the company’s arguments for using GPS. It agreed, for example, that using GPS to dispatch vehicles is likely to lead to better service for the company’s customers and also could help locate missing vehicles.

However, the OPC expressed concern about using GPS as an employee surveillance tool. While using GPS to track a vehicle is not overly privacy invasive, routinely evaluating worker performance based on assumptions drawn from GPS information impinges on individual privacy.

The use of GPS as an employee surveillance tool may be acceptable in certain situations, which are defined and communicated to employees beforehand, according to the OPC findings. However, a company should not routinely use GPS to monitor its workforce.

In this case, the OPC asked the company to clearly explain to its employees how GPS would be used to check up on them, and also to develop a policy outlining an appropriate process of warnings and progressive monitoring. The policy subsequently prepared by the company spelled out situations in which the company will use GPS data to monitor employees. These include an investigation into a complaint – about speeding, for example – from a member of the public; an investigation into concerns raised within the company; or to address productivity problems. The company also made a commitment to train its managers about the appropriate use of the technology.

“Systematically using GPS to check up on workers and try to determine how well they are doing their jobs would be going too far,” said Ms. Stoddart. “Employers do not have carte blanche to use GPS to constantly monitor their workforce.”

The OPC finding also cautions employers about “function creep” – collecting information for one purpose, and then using it for some other unrelated purpose in violation of basic fair information practices.

“Managing workplace privacy is a balancing act. On the one hand, employers have the right to know what workers are up to on company time. On the other, employees have a right to privacy,” the Commissioner said.

“Workers do not check their privacy rights at the factory or office door. Workplace privacy is an important part of the basic autonomy rights of individuals in our society,” she said. “Employers must find ways to weed out the bad employees without shattering the dignity and privacy rights of the good employees – who make up the vast majority of the workforce.”

The OPC is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy rights in Canada.

The summary of the findings in the GPS investigation is available on the OPC Web site:

PIPEDA Case summary #351: Use of personal information collected by Global Positioning System considered

Once again, I am left at a bit of a loss when it comes to using PIPEDA in the workplace. Unlike PIPA in Alberta and BC, PIPEDA has no deemed consent for reasonable collection, use and disclosure in the workplace. To "make do", the practice seems to have been to use s. 5(3) of the Act to say that as long as it's reasonable, you have implied consent (particularly if there is notice). But logically you can't have consent by implication if it is clearly negated by an employee complaint. Hopefully this will become moot if the Parliamentary Committee recommends fixing up that portion of PIPEDA and something is done about it.

When fired for using police documents to check out girlfriends, call centre worker says everyone does it

From New Zealand, an interesting story ...

Police files used to check out girlfriends - New Zealand, world, sport, business & entertainment news on Stuff.co.nz:

Police files used to check out girlfriends

04 December 2006

By EMILY WATT

A 111 call-centre worker, sacked after being accused of stealing information from the police computer, says he will fight the dismissal because the practice is rife.

Les Neilson – who admits he used the police computer to check on potential girlfriends – says many police regularly look up acquaintances and friends on the database.

He claims he has been made a scapegoat.

"I've basically been screwed for doing something that's a common practice. I've used the information the same as everyone else has," he said.

"If I'm socialising with people and I'm meeting new partners then I need to know the background of those partners because I don't want to put myself or the department in a compromising position.

"There's nothing that says 'I can't do that' – I've been doing it for the last 20 years."

Mr Neilson, who has been involved with the police for 20 years, was accused of "inappropriate accessing and disclosure of police information" in April and summarily dismissed.

However, he is fighting the sacking by taking an unfair dismissal case to the Employment Relations Authority. Mr Neilson is now working as a private investigator in Wellington.

A law expert says police could be sued over the revelations for breach of privacy and says police must investigate how many staff do this and what the confidential information is used for.

The police database contains a range of personal information, including current addresses, vehicle details, next of kin, details of who individuals live and associate with, criminal histories and any links with gangs.

The information is highly valued by private investigators and debt collectors. Sources say a current name and address alone can sell for between $100 and $200.

Police Commissioner Howard Broad said staff knew it was wrong to access the database for personal use. "If they do, it's wrong and they would know that it's wrong. It's quite a clear breach."

Mr Neilson, a former policeman who was later employed as a non-sworn staff member in the Wellington communications centre, said he regularly looked up associates and girlfriends "to protect myself and the organisation".

He denies police allegations that he gave computer information to other people, that he misrepresented himself, and that he was using the database for personal gain.

"I have not disclosed the information to anyone. I've given an explanation. If they investigate it they'll find out it's a very legitimate explanation."

Mr Neilson thought the public would not care that police accessed the database as he did.

"How many of the general public would be upset that the local policeman or someone working for the police checks up on them, or who's in the street, or checks up on potential tenants for flats or aunts' and uncles' criminal histories?"

A police headquarters spokeswoman said the office was constrained about what could be said because the case was before the Employment Relations Authority.

"The police organisation is intolerant of any abuses of information that is held. As this case illustrates, action will be taken against any staff member who seeks to use police information for purposes unrelated to their duties," the spokeswoman said.

Police Association president Greg O'Connor said the union had reminded members to be aware of how they used police information and facilities.

Operation Insider, which investigated the distribution of pornographic e-mails among police, had highlighted the importance of using such facilities appropriately, he said.

Auckland University associate law professor Scott Optican said the revelation was a significant breach of privacy and police could face lawsuits as well as formal complaints.

"Certainly, there's no question that something like this is going to have to cause the police to rethink how they safeguard the information against the people who have access to it."

Professor Optican said police had a duty to investigate how many people had accessed the database for personal use, and what they did with that information. "If it looks like there were consequences (for the person who was looked up), they need to contact that person and find out what happened.

"Quite frankly, I think the police should explain to members of the public exactly what happened here and what they'll do to make sure it doesn't happen again."

Saturday, December 02, 2006

More on warrants for ISP records

Back in October, I blogged about the CIPPIC and Online Rights privacy pledge (Canadian Privacy Law Blog: The ISP Privacy Pledge). In that post, I referred to a posting by Mark Goldberg called "Online rights is wrong."

More recently, Mark has posted 7 reasons why warrants aren't needed. This one has resulted in a bit of a debate between David Butt and Mark Goldberg, on one side, and Rob Hyndman on the other side.

The seven reasons are listed, as is additional information offered by David in the course of the debate with Rob Hyndman:

Internet child abuse investigators routinely need bare bones subscriber information (name and address) from ISPs to conduct their investigations. A question commonly asked by ISPs and privacy advocates is, why shouldn’t the police use a search warrant to get that bare bones subscriber information? There are seven really good answers to this question.
  1. Bare bones subscriber information is not the kind of private information that requires a search warrant. The highest court in Canada, the Supreme Court, has clearly said so. [R. v. Plant, [1993] 3 SCR 281]
  2. Every other business in Canada must supply this kind of bare bones customer information to the police upon request. There is no principled reason why ISPs should be exempted from the rules that apply to every other business. [This engages the moral calculus of social, not legal obligation. Simply put, fighting child abuse is more important than "protecting" the confidentiality of basic subscriber information that is widely recognized as not engaging core privacy values. In other words, I [David] challenge any business to state publicly that they would rather hamper child abuse investigations than voluntarily surrender upon request non-intimate basic customer information for which a search warrant is not necessary.]
  3. PIPEDA has a specific section in it whose purpose is to authorize the granting of this bare bones subscriber information to police. ISPs therefore have specific statutory authority to rely upon. [PIPEDA s.7(3)(c.1)(ii) Based on the comfort provided by this section, the letter of authority endorsed by CAIP is a commendable step taken by the industry to address internet based child abuse.]
  4. Police services are always understaffed and over worked. The demand for policing services always exceeds the available supply. Therefore, adding unnecessary burdens on police by requiring them to go to the trouble of getting legally unnecessary warrants prevents police officers from devoting their limited time to more important work. The result is that the whole community suffers unnecessarily.
  5. Search warrant requirements under Canadian law are onerous. A typical search warrant, even for bare bones subscriber information, may often run to more than 40 pages in length. This will require several hours of work by an officer, sometimes many officers. It will involve at least two visits to a judge. Given the limited availability of judges, the entire process may take days. All of this effort is legally unnecessary and therefore a complete waste of public funds.
  6. Bare bones subscriber information is necessary to identify the location of the suspect so that the case can be conducted by the local police service. If a search warrant were necessary for every such bare bones request, the police service in the city where the ISP head office is located would be obliged to do a great deal of onerous search warrant work simply to pass the file on to another jurisdiction when the bare bones subscriber information comes back. This places not only an unnecessary but a disproportionate burden on police services in those cities that host ISP head offices.
  7. Other democratic countries, that fully respect privacy rights, require businesses to supply this type of bare bones subscriber information to the police upon request. Internationally, the practice is routine.

With respect, I don't think it is legally correct to say that subscriber information can be provided by an ISP in response to a "letter of authority". And I am not going to get into the political debate that starts with the premise that if you follow the Charter, you are supporting child exploitation.

The first point relies entirely on R. v. Plant, a 1993 and pre-PIPEDA decision from the Supreme Court of Canada. It did not deal with subscriber information from an ISP or other telco, but electricity consumption records from a publicly owned power generation company. At the time, this information was provided to cops on a routine basis. In fact, the police had a direct computer connection to the hydro company's system. In addition, at the time, the electricity consumption records of every customer was available to anyone who asked. The majority of the Court concluded that there was no reasonable expectation of privacy in this information and a warrant was not required. It is also notable that the current Chief Justice wrote a very strong dissent arguing that there was a reasonable expectation of privacy in this information.

In my personal opinion, R. v. Plant is readily distinguishable. Plant deals with electricity consumption at a particular address, not specifically identifying information that is now being discussed from ISPs. Since PIPEDA and the PIPAs, it would be very difficult to say that there is no expectation of privacy in your name and address in ISP billing records. Just look at BMG Canada Inc. v. John Doe (F.C.), [2004] 3 F.C. 241, 2004 FC 488 (CanLII) where the Court noted:

[37]In respect of the internet specifically, Wilkins J. in Irwin Toy Ltd. v. Doe (2000), 12 C.P.C. (5th) 103 (Ont. Sup. Ct.) stated, at paragraphs 10-11:
Implicit in the passage of information through the internet by utilization of an alias or pseudonym is the mutual understanding that, to some degree, the identity of the source will be concealed. Some internet service providers inform the users of their services that they will safeguard their privacy and/or conceal their identity and, apparently, they even go so far as to have their privacy policies reviewed and audited for compliance. Generally speaking, it is understood that a person's internet protocol address will not be disclosed. Apparently, some internet service providers require their customers to agree that they will not transmit messages that are defamatory or libellous in exchange for the internet service to take reasonable measures to protect the privacy of the originator of the information.

In keeping with the protocol or etiquette developed in the usage of the internet, some degree of privacy or confidentiality with respect to the identity of the internet protocol address of the originator of a message has significant safety value and is in keeping with what should be perceived as being good public policy. As far as I am aware, there is no duty or obligation upon the internet service provider to voluntarily disclose the identity of an internet protocol address, or to provide that information upon request.

[38]Parliament has also recognized the need to protect privacy by enacting PIPEDA, which has as one of its primary purposes the protection of an individual's right to control the collection, use and disclosure of personal information by private organizations (section 3).

The context of this case is a civil lawsuit, but the sentiments would apply in the criminal context as well. The Ontario courts have more recently dealt the exact issue we are discussing here (including the use of a so-called "letter of authority") in Re S.C., 2006 ONCJ 343 (CanLII). In this case, Justice of the Peace Conacher was being asked to issue a search warrant on the basis of information provided by an ISP to the police pursuant to a letter of authority. The Court considered both the expectation of privacy and section 7(3)(c.1)(iii) of PIPEDA, referred to by David Butt. This section reads:

Disclosure without knowledge or consent

(3) For the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may disclose personal information without the knowledge or consent of the individual only if the disclosure is ...

(c.1) made to a government institution or part of a government institution that has made a request for the information, identified its lawful authority to obtain the information and indicated that
(i) it suspects that the information relates to national security, the defence of Canada or the conduct of international affairs,

(ii) the disclosure is requested for the purpose of enforcing any law of Canada, a province or a foreign jurisdiction, carrying out an investigation relating to the enforcement of any such law or gathering intelligence for the purpose of enforcing any such law, or

(iii) the disclosure is requested for the purpose of administering any law of Canada or a province; [emphasis added]

In the result, the Court in Re S.C. concluded that an ongoing criminal investigation is not "lawful authority" under PIPEDA that would permit the ISP to disclose the name and address of a subscriber without consent or a warrant:

[9] However, s. 7(3) stipulates that the information can be provided without consent only if the body seeking the information has "identified its lawful authority to obtain the information" and has indicated that the disclosure is requested (in this case) for law enforcement purposes. The Act does not set out that the existence of a criminal investigation is, in and of itself, “lawful authority” within the meaning of the Act nor, therefore, does a “Letter of Request for Account Information Pursuant to a Child Sexual Exploitation Investigation” establish such authority. Accordingly, there must still be some “legal authority” to obtain the information; in the view of this Court s. 7(3)(c.1)(ii) by itself does not establish what that “lawful authority” is. The section provides authority for disclosing information. It does not establish the authority for obtaining and possessing the information.

[10] The Information to Obtain does not otherwise reflect that the Informant established to Bell Canada the lawful authority, within the meaning of the Act, by which the investigators were seeking to obtain the requested information. Accordingly, Bell Canada did not have a basis upon which to disclose the information.

[11] In the absence of express authority within the legislation, the Charter right not to have one’s reasonable expectation of privacy interfered with, except through prior judicial authorization with all the protections that affords, must govern. Accordingly, it is the view of this Court that the Informant is not lawfully in possession of the information that was provided by Bell Canada. Therefore, that information must be set aside in the overall consideration of this application to obtain a search warrant.

With respect to the other points raised, the current Criminal Code allows for searches and obtaining personal information if there are exigent circumstances that require the information immediately. Whether the bar should be further reduced (or can be further reduced in light of the Charter), I leave to others to debate.

Friday, December 01, 2006

Phoenix airport rolling out backscatter x-ray tech

Interesting development:

Phoenix airport to test X-ray screening - Yahoo! News:

"PHOENIX - Sky Harbor International Airport here will test a new federal screening system that takes X-rays of passenger's bodies to detect concealed explosives and other weapons.

The technology, called backscatter, has been around for several years but has not been widely used in the U.S. as an anti-terrorism tool because of privacy concerns.

The Transportation Security Administration said it has found a way to refine the machine's images so that the normally graphic pictures can be blurred in certain areas while still being effective in detecting bombs and other threats.

The agency is expected to provide more information about the technology later this month but said one machine will be up and running at Sky Harbor's Terminal 4 by Christmas...."

CIPPIC calls for major changes to PIPEDA

Again on the topic of the PIPEDA review, the Canadian Internet Policy and Public Interest Clinic (CIPPIC) has released its written submission to the Parliamentary Committee on Ethics, Access to Information and Privacy. Not surprisingly, they are calling for some major changes:

We therefore propose a number of amendments designed to clarify rights and obligations, to close gaps, and to give the regime the "teeth" it is clearly lacking. Such amendments include:
  • giving the Commissioner (or an associated Tribunal) order-making powers;
  • reducing barriers to the enforcement of PIPEDA rights via Federal Court;
  • permitting class actions under PIPEDA;
  • providing for punitive as well as compensatory damages in court;
  • mandatory naming of respondents in published Commissioner findings;
  • mandatory Commissioner reporting on complaints;
  • expanding the list of offences under PIPEDA;
  • removing the "reasonable grounds" requirement for audits; and
  • giving the Commissioner powers to share information with her counterparts.

While PIPEDA's redress and enforcement regime is most need of reform, some important substantive provisions of the Act suffer from lack of clarity, and others leave strange gaps. We have therefore proposed amendments to clarify and add provisions dealing with:

  • the criteria for valid consent;
  • data breach notification;
  • reasonable limits on collection, use and disclosure;
  • children's privacy;
  • openness and individual access;
  • attempted collection, use and disclosure;
  • state surveillance; and
  • the definition of "organization".

Update (20070118): For links to the full hearing transcripts, go to: Canadian Privacy Law Blog: PIPEDA Review Transcripts.

Day four of the PIPEDA hearings

Michael Giest has a summary of the fourth day of testimony before the Parliamentary Committee conducting the PIPEDA review hearings:

Michael Geist - PIPEDA Hearings - Day 04 (B.C. Privacy Commissioner Loukidelis and Professor Val Steeves):

"Wednesday's PIPEDA hearing featured B.C. Privacy Commissioner David Loukidelis and University of Ottawa professor Val Steeves. Commissioner Loukidelis went even further than the federal privacy commissioner in downplaying significant change. Loukidelis downplayed his order making power (a last resort), security breach notification (more evidence on impact needed), and even the concerns associated with cross-border transfers to the U.S. (can always pick a different private sector company). Professor Steeves highlighted the privacy challenges posed by new technologies and offered some specific reform recommendations. Natalie Senst was in attendance on Wednesday afternoon and she filed the following report:..."

Update (20070118): For links to the full hearing transcripts, go to: Canadian Privacy Law Blog: PIPEDA Review Transcripts.