Monday, August 18, 2008

CBA urges Government to reform Privacy Act

I am currently in Quebec City attending the Canadian Bar Association's annual Canadian Legal Conference. On behalf of the CBA's National Privacy and Access Law Section, I had the honour of presenting a resolution to the National Council calling for reforms to the Privacy Act. The resolution passed with one contrary vote (I wanted to speak with the fellow who voted against it, but didn't get the chance and then lost him in the crowd). This is the third time the CBA has formally called upon the government to look at the antiquated 1982 Act. The Privacy Commissioner, Jennifer Stoddart, is here and spoke to the Council on the following day. Her office has issued the following press release about the resolution:
News Release: Commissioner welcomes legal community’s call for privacy law reform (August 18, 2008) - Privacy Commissioner of Canada

Commissioner welcomes legal community’s call for privacy law reform

Quebec City, August 18, 2008 — A Canadian Bar Association (CBA) resolution once again highlights the urgent need for reform of Canada’s federal public sector privacy legislation, says the Privacy Commissioner of Canada, Jennifer Stoddart.

“With this resolution, lawyers from across the country are urging the government to strengthen privacy protection for Canadians. Canada’s federal sector privacy legislation, the Privacy Act, is unbelievably inadequate,” says Commissioner Stoddart. “I hope the federal government will heed the CBA’s call for modernization of the Act. This is the latest in a string of appeals from privacy experts about the need to update legislation which has been far outpaced by technological and societal changes.”

The CBA, which is holding its 2008 Legal Conference in Quebec City, passed the resolution calling for comprehensive revision of the Privacy Act on the weekend.

In particular, it proposes changes to the legislation to ensure that:

  • Federal government departments only collect personal information when demonstrably necessary for clear and articulated state goals;
  • Once collected, personal information is rigorously protected with stringent safeguards and accountability requirements, including a breach notification requirement; and
  • Personal information is not shared within or beyond Canada’s borders unless those safeguards and requirements can be guaranteed.

The Office of the Privacy Commissioner of Canada (OPC) has long been advocating for reform of the Privacy Act, which is a quarter-century old and has never been substantially updated.

Last spring, the House of Commons Standing Committee on Access to Information, Privacy and Ethics began a study of the Privacy Act and possible amendments. The OPC reform proposals to the committee are posted at http://www.privcom.gc.ca/keyIssues/ki-qc/mc-ki-pa_e.asp. The OPC looks forward to the Committee’s recommendations.The CBA resolution is available at www.cba.org/cba/resolutions/pdf/08-06-a-pdf.pdf. The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy and the protection of personal information rights of Canadians.

Sunday, August 17, 2008

Commissioner launches her "Legal Corner"

The Federal Privacy Commissioner has launched on her website a "Legal Corner" which contains a wide range of resources that will be of interest to practitioners in the area of privacy law. See: http://www.privcom.gc.ca/leg_c/index_e.asp.

Thursday, August 07, 2008

Supposedly secure ePassports easily cloned

Cynics, who may say that "chipped" passports are more about control than security, may point to articles like this one to support their position:

‘Fakeproof’ e-passport is cloned in minutes - Times Online

New microchipped passports designed to be foolproof against identity theft can be cloned and manipulated in minutes and accepted as genuine by the computer software recommended for use at international airports.

Tests for The Times exposed security flaws in the microchips introduced to protect against terrorism and organised crime. The flaws also undermine claims that 3,000 blank passports stolen last week were worthless because they could not be forged.

In the tests, a computer researcher cloned the chips on two British passports and implanted digital images of Osama bin Laden and a suicide bomber. The altered chips were then passed as genuine by passport reader software used by the UN agency that sets standards for e-passports.

The Home Office has always argued that faked chips would be spotted at border checkpoints because they would not match key codes when checked against an international data-base. But only ten of the forty-five countries with e-passports have signed up to the Public Key Directory (PKD) code system, and only five are using it. Britain is a member but will not use the directory before next year. Even then, the system will be fully secure only if every e-passport country has joined....

Wednesday, August 06, 2008

New pain at the pump: Card skimming

Gas stations and convenience stores are probably among the most reported locales for card skimming, in which debit and credit cards are double-swiped and PINs are observed to commit fraud. Since my own debit card was skimmed a few weeks ago (Canadian Privacy Law Blog: Cloned!), I've stopped paying for gas inside and opting to pay at the pump where I am sure that my card does not leave my hands. Well, things are getting more complicated. Apparently pumps are becoming a common place for thieves to place covert card skimmers, at least in the US. See: Thieves skim credit card data at fuel pumps - Yahoo! News.

Student complains about Kiwi can cam

Sorry about the headline. I thought I could do beter than the one written by Stuff.co.nz.

I have reported on toilet cams on this site in the past, but all of those I've heard about installed by businesses have ended up to be fakes. That is until this report from New Zealand where a drunk student was roughed up by bouncers who were covertly watching him rip down a poster above the urinal.

See: Student shocked to star on club's loo-cam - New Zealand news on Stuff.co.nz.

Who do our privacy laws protect?

I was intereviewed by a New Brunswick journalist last week who was writing an article on how privacy laws can be used in a knee-jerk way to limit access to government information. The article, I expect, is a reaction to a number of stories out of NB where reporters were given the excuse of privacy laws to limit their access to information about potential high-risk offenders, the investigation of a motor vehicle accident that claimed a number of lives and public sector salaries.

Here is the bit that I contributed:

nbbusinessjournal.com - Who do our privacy laws protect?

Governments must protect citizens' public information [note: I'm sure I said "private information"] while still being accountable and transparent to the public, said David Fraser, a privacy lawyer with the Atlantic Canadian law firm McInnes-Cooper.

For example, the expenses for a cabinet minister's trip to Europe would likely be made public. However, a doctor's billing records, which would essentially reveal their salary, are only made available in some provinces, he said.

And although some form of privacy legislation has existed federally for quite some time, that doesn't mean the laws regulate every activity on the internet.

"It regulates commercial activities. So it says what information your bank can ask about you and what it can do with it, or your local video store," said Fraser. "But if an individual takes a picture of another person on their camera phone in embarrassing circumstances and then they post it on the Internet that's a personal use, not a commercial use, so that's not caught by that law." There are some circumstances where personal information can be released. For example, if an individual gives consent.

As well, personal information can be disclosed if it's deemed to be for the greater good of the public.

"I think people, just as a knee-jerk reaction, they say no - it's personal information," said Fraser.

Tuesday, August 05, 2008

Charges following TJX breach investigation

The New York Times is reporting that 11 people have been charged in connection with the massive data breach that dominated the headlines for months after January 2007:

11 Charged in Theft of 40 Million Card Numbers - NYTimes.com

...The charges focus on three people from the United States, three from the Ukraine, two from China, one from Estonia and one from Belarus.

The authorities said that the scheme was spearheaded by a Miami man named Albert Gonzalez, who hacked into the computer systems of retailers including TJX, BJ’s Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW Inc. The numbers were then stored on computer servers in the United States and Eastern Europe.

They then sold the information to people in the United States and Europe, who used it to withdraw tens of thousands of dollars at a time from automated teller machines, the authorities said....

For the sordid history, see these related posts.

Sunday, August 03, 2008

OT: Now appearing on slaw.ca

I've been invited to be a regular contributor on Slaw.ca (the Canadian cooperative weblog on things legal), which is a great opportunity to write about things other than privacy. I'll be posting there on Fridays. My initial contribution is the first of a series on contentment in the practice of law. Check it out, if interested: Slaw: Lawyers and the unnamed force.

SCC to hear case about privacy in garbage

Dan Michaluk reports in All About Information that the SCS is getting ready to hear a case from Alberta about reasonable expectation of privacy in garbage. See: One to Watch - Garbage case ready for hearing at SCC « All About Information.

Friday, August 01, 2008

Nomadic laptops can expect the rubber glove treatment

There's been a bit of a buzz lately about laptop inspections by the Department of Homeland Security (Crossing the border? Consider the possibility of laptop searches, Hands off my laptop, Your papers and laptops, please?, US Customs confiscating laptops). Today, the Washington Post is reporting on recently disclosed policies used by the DHS to take and inspect laptops:

Travelers' Laptops May Be Detained At Border (washingtonpost.com)

... The policies state that officers may "detain" laptops "for a reasonable period of time" to "review and analyze information." This may take place "absent individualized suspicion."

The policies cover "any device capable of storing information in digital or analog form," including hard drives, flash drives, cell phones, iPods, pagers, beepers, and video and audio tapes. They also cover "all papers and other written documentation," including books, pamphlets and "written materials commonly referred to as 'pocket trash' or 'pocket litter.' "

Reasonable measures must be taken to protect business information and attorney-client privileged material, the policies say, but there is no specific mention of the handling of personal data such as medical and financial records.

When a review is completed and no probable cause exists to keep the information, any copies of the data must be destroyed. Copies sent to non-federal entities must be returned to DHS. But the documents specify that there is no limitation on authorities keeping written notes or reports about the materials.

"They're saying they can rifle through all the information in a traveler's laptop without having a smidgen of evidence that the traveler is breaking the law," said Greg Nojeim, senior counsel at the Center for Democracy and Technology. Notably, he said, the policies "don't establish any criteria for whose computer can be searched." ...

If you want to take a look at the policy itself, it's here.

Thanks to Rob Hyndman for the tipoff.