Wednesday, January 22, 2014

Microsoft to agree to local storage of foreign users' data

Crossposted from Canadian Cloud Law Blog: Microsoft to agree to local storage of foreign users' data:

According to the Financial Times, Microsoft is going to break from the pack of other cloud service providers by agreeing to store data locally. FT.com content is behind an annoying paywall, but here's the gist of it along with some commentary.

Microsoft to shield foreign users’ data - FT.com

By James Fontanella-Khan in Brussels and Richard Waters in San Francisco

Microsoft will allow foreign customers to have their personal data stored on servers outside the US, breaking ranks with other big technology groups that until now have shown a united front in response to the American surveillance scandal.

Brad Smith, general counsel of Microsoft, said that although many tech companies were opposed to the idea, it had become necessary following leaks that showed the US National Security Agency had been monitoring the data of foreign citizens from Brazil to across the EU.

“People should have the ability to know whether their data are being subjected to the laws and access of governments in some other country and should have the ability to make an informed choice of where their data resides,” he told the FT. ...


This decision seems to be based on (or appealing to) the fiction that the location of data is somehow determinative of whether law enforcement or national security folks can get access to data. As I said, it's mostly a fiction. Governments can assert control over things, or people, or entities on a number of bases. One of them is the presence of the thing (a server) in the physical jurisdiction, but most importantly is the presence of the person who can obtain and hand over the data.

... Some critics of the idea have questioned whether such a move would be effective in putting the personal data of non-Americans outside the reach of the NSA, since US tech companies have to hand over information about specific users when ordered to by a secret US court, regardless of where it is held.

However, keeping the information off US soil and under local data protection rules should make it harder for the NSA to tap into illicitly, Mr Chester said. “If the data are not being transported, then it does stop that kind of access.” ...


While this isn't really a solution to the principal problem that many people associate with the USA Patriot Act and the FISA Amendments Act, it may be an economically rational decision since many customers will only ask where the data is, rather than what it really means.

Mr Smith acknowledged that it would be expensive but added “does it mean that you ignore what customers want? That’s not a smart business strategy.” ...

I do agree, however, that the big question which is the driver behind all of this needs to be addressed at a government-to-government level.

Mr Smith also said that the US and EU should consider signing an international agreement that ensures they will not try to seek data in each other’s territory via technology companies.

“If you want to ensure that one government doesn’t seek . . . to reach data in another country, the best way to do it is . . . an international agreement between those two countries. Secure a promise by each government that it will act only pursuant to due process and along the way improve the due process.”

He argued that the existing “Mutual Legal Assistance Treaty” mechanism used by the US and EU to protect individuals’ rights from the two blocs is outdated: “It needs to be modernised or replaced.”

Citizen Lab calls for transparency by Canadian telcos

The smart folks a the Citizen Lab at the University of Toronto are calling for Canadian telecommunications companies to come clean about the extent to which they provide customer information and law enforcement agencies and under what circumstances.

We have seen a number of the large US internet-based companies, led by Google, provide detailed statistics about government requests for customer information. So far, no Canadian companies have followed this example so we continue to be in the dark. This is particularly important because PIPEDA has been consistently interpreted by Canadian telcos to have a massive backdoor to allow warrantless access to customer data.

Check out the details on this project from the Citizen Lab: Towards Transparency in Canadian Telecommunications - The Citizen Lab.

Tuesday, January 14, 2014

International Privacy Day Symposium on surveillance and privacy

On January 29, 2014 I'll be in Toronto with a great group of privacy advocates and privacy experts at the invitaion of Ontario's Information and Privacy Commissioner Ann Cavoukian for a symposium entitled Big Surveillance Demands Big Privacy - Enter Privacy-Protective Surveillance - Real Privacy. All the details are on the site, but before you get your hopes up you should know the event is now full. But you can register for the webcast.

Thursday, January 09, 2014

Global Networking Initiative assesses Google, Microsoft, and Yahoo on compliance with privacy and freedom of expression principles

This is very cool. As someone who believes very strongly in the rights to privacy and freedom of expression, I am very impressed that Microsoft, Google and Yahoo have not only founded an organization like the Global Network Initiative, but have all been subject to an assessment of their compliance with these important principles to see if they practice what they preach.

Yesterday, the GNI released the Public Report on the Independent Assessment Process for Google, Microsoft and Yahoo, all of which were found to be generally in compliance with the GNI's principles. Of concern was the exclusion of Skype China from Microsoft's assessment, but hopefully that will be remedied in future reports.

For more info, check out: GNI Report Finds Google, Microsoft, and Yahoo Compliant with Free Expression and Privacy Principles | Global Network Initiative.

Tuesday, January 07, 2014

CSEC spies on Canadians 'incidentally' to its mandate (but deliberately when helping other agencies)

The Communications Security Establishment of Canada (CSEC) has said, in a new informational website meant to be more transparent, that it sometimes "incidentally" intercepts the communications of Canada when fulfilling its mandate, though it often deliberately does so when assisting other agencies.

However, in the course of targeting foreign entities outside Canada in an interconnected and highly networked world, it is possible that we may incidentally intercept Canadian communications or information. The National Defence Act acknowledges that this may happen and provides for the Minister of National Defence to authorize this interception in specific circumstances. If a private communication is incidentally intercepted (e.g. a foreign individual we are targeting overseas is communicating with someone in Canada), CSE takes steps to protect the privacy of that information.
The website also has a reasonably clear page on the assistance they provide to federal law enforcement and security agencies.

The Ottawa Citizen is reporting on this (Spy agency admits it spies on Canadians ‘incidentally’) as well as the recent Federal Court decision that found CSIS and Department of Justice lawyers deliberately misled the Court in order to obtain warrants.

It's heartening to see that Michael Geist and Tamir Israel share my feelings about that case and are also calling for an independent review of the conduct of those involved.

Editorial tribute to Gary Dickson: He will be a tough act to follow

The Regina Leader Post has a very fitting tribute to Gary Dickson, who is retiring as Information and Privacy Commissioner of Saskatchewan:

Editorial: Dickson will be a tough act to follow

Gary Dickson has done fine job as privacy watchdog

THE LEADER-POST JANUARY 7, 2014

Gary Dickson announced last week that he would be resigning from his post as Saskatchewan’s Information and Privacy Commissioner.

Gary Dickson once described his role as "the umpire of the information age" and there's no doubt he's been a game changer as Saskatchewan's information and privacy commissioner.

Appointed in 2003 as the first full-time holder of the office, Dickson has significantly raised the profile of the public's right to privacy when it comes to the personal information held by government ministries and health agencies, and also a person's right to see their personal files and other information on how government works..

Sadly, he's chosen to leave at the end of this month following what he calls "a fascinating 10 years" in the job.

"Fascinating" might not be the word some in the corridors of power would use to describe Dickson's two terms of office. He's been a tenacious critic of politicians, bureaucrats and health officials in countless investigations that have exposed careless use of personal information, ignorance of privacy and access laws and a pitiful lack of consequences when things go wrong:

"Those arbitration decisions signal that if you have breached the privacy of a patient in Saskatchewan it's just no big deal. You can expect little more than the proverbial slap on the wrist." - Dickson's 2010 verdict on arbitration panels overturning dismissal of staff for privacy breaches.

"What we have here is a cascading series of bad decisions ... that ultimately culminated in the tossing of all of this patient information into the recycling bin." - From Dickson's damning 2011 report on how 2,682 patient files from a medical clinic wound up in a south Regina dumpster.

"You should never send anything by email - and I'm not talking about a closed email system within an organization, but a general email - that you wouldn't be prepared to see on an electronic billboard on Victoria Avenue." - Dickson's 2010 comment after the psychiatric assessment of an offender was emailed in error to a member of the public.

"When it comes to access and privacy, Saskatchewan is still a have-not province." - From Dickson's 2012-13 annual report criticizing successive governments for failing to update privacy and access laws.

A lawyer, past president of the Alberta Civil Liberties Association and a former Alberta Liberal MLA, Dickson served for nine years on the Alberta committee overseeing that province's information and privacy commissioner. A non-partisan committee selected him for the Saskatchewan post from a field of 52 candidates in 2003.

Dickson leaves some very big shoes to fill. The Saskatchewan Party government could make his successor's job easier by a) bringing privacy and access legislation up to the standards of other provinces and b) adding the fourth investigator Dickson has been requesting for the past six years.

Friday, January 03, 2014

Saskatchewan Information and Privacy Commissioner, Gary Dickson, stepping down

The long-serving and very well-regarded Information and Privacy Commissioner for the province of Saskatchewan, Gary Dickson, has announced he will be stepping down effective as of the end of this month: Sask. information and privacy commissioner stepping down | CTV Regina News.

I have had the great pleasure of getting to know Gary over the years, particularly in connection with his very gracious relationship with practitioners in the Canadian Bar Association's National Privacy and Access Law Section. I hope he will continue his involvement with the privacy community while he enjoys more time with his family.

Thursday, January 02, 2014

Happy tenth birthday to the Canadian Privacy Law Blog

Ten years ago, on January 2, 2004, I hit "publish" on the first post for this blog: Canadian Privacy Law Blog: Welcome to the Canadian Privacy Law blog. That was immediately after the full coming-into-force of the Canadian federal privacy law, the Personal Information Protection and Electronic Documents Act.

Since then, there have been 3647 posts and over two million page views. But, more importantly, I've had the opportunity to connect with and in many cases meet many of my colleagues and others who share my interest in privacy law. As a lawyer based in the relative hinterlands of Atlantic Canada, it has enabled me to build a practice exclusively devoted to privacy and internet law, working with great clients around the world who have to grapple with questions related to Canadian privacy law. I am sure that this would not have been possible without my blog.

For those who have been following since day one and others who have found this blog more recently, thanks so much for your support and encouragement. I am grateful. And I hope I can keep it up for another ten.

And if you're similarly inclined to take a stroll down memory lane, here are the most popular posts over the past ten years, at least in terms of page views:

1 - From August 2012 - Photographing and filming police officers in Canada

2 - From June 2006 - Can you record telephone calls without consent?

3 - From December 2006 - Phoenix airport rolling out backscatter x-ray tech

4 - From April 2011 - Cloud Computing and Privacy FAQ

5 - From August 208 - First conviction under Canada's new voyeurism law

6 - From February 2004 - Canadian privacy law and video surveillance

7 - From April 2010 - Some thoughts on street photography

8 - From February 2012 - The hidden gag order in Bill C-30 (aka the lawful access bill)

9 - From August 2007 - Montreal mall fake toilet cam raising concerns

10 - From March 2008 - Toilet cameras are for research purposes only

Thanks again for stopping by and for your support.

Monday, December 30, 2013

Getting the facts straight as we rush to legislate cyberbullying

Over the past number of months, Halifax Chronicle Herald reporter Selena Ross has been researching the failure of the authorities to lay any charges in the Rehtaeh Parsons case (until political pressure resulted in the case being reopened). This past week, she published her findings into the police investigation and the crown's refusal to lay charges. The fact that it has taken months to get this level of information speaks volumes. They also make depressing reading.

The tragedies of Rehtaeh Parsons and Amanda Todd galvanized attention on the issue and lawmakers have swung into action by passing laws to address it. First, we saw the Cyber-safety Act in Nova Scotia and more recently the federal Conservative government introduced Bill C-13, Protecting Canadians from Online Crime Act. The Nova Scotia statute creates a CyberScan unit, headed by a former cop, to investigate cyberbullying, allows for anti-cyberbullying orders and allows victims (with their parents permission) to sue cyberbullies. The proposed federal legislation makes it a crime to distribute intimate images without consent.

When these laws were introduced, there was much self-congratulatory back slapping about how we are finally doing something, with the clear implication that these laws would have saved the lives of Rehtaeh Parsons and Amanda Todd, if only they’d been in effect earlier. That is simply not true.

Rehtaeh Parsons and Amanda Todd died because the police and the prosecutors did not use the laws that existed to seriously investigate the crimes that they were already the victims of. Making up new crimes may be a useful endeavour, but saying that it was the absence of laws like these that was responsible for these horrendous tragedies is an outright lie.

Amanda Todd was the victim of extortion, harassment, and child pornography at the hands of an adult online and her peers. All of these were crimes the day she was born and continued to be crimes the day that she died. The Royal Canadian Mounted Police failed to investigate, failed to prosecute and failed to give her hope for justice. The British Columbia agencies charged with protecting children in the province failed her as well.

Rehtaeh Parsons was the victim of sexual assault, harassment, child pornography and voyeurism offences at the hands of her peers. All of these (other than the voyeurism offence) were crimes the day she was born and and all were crimes the day that she died. The Royal Canadian Mounted Police and the Halifax Regional Police Service failed to adequately investigate, failed to prosecute and failed to give her hope for justice.

Instead of stepping up and taking responsibility for the horrendous failure of those who are charged with protecting children, investigating and prosecuting crimes, police agencies and the politicians to whom they report have shrewdly deflected the attention of the media and the public towards new initiatives under the clear implication that it was the absence of these laws that failed these two young women.

While both laws (with their flaws) fill an important legal void as far as cyberbullying is concerned, the principal benefit to be derived from these laws is likely that it gives authorities fewer excuses to do nothing when children are the victims of such crimes.

Monday, December 23, 2013

Special prosecutor required to investigate spies and their lawyers lying to the Federal Court

On Saturday, I blogged about the stunning decision of Justice Mosley of the Federal Court in IN THE MATTER OF an application by [xxxxx xxxxxx ] for a warrant pursuant to Sections 12 and 21 of the Canadian Security Intelligence Service Act, R.S.C. 1985, c. C-23, 2013 FC 1275 [PDF](See Canadian Privacy Law Blog: Canadian intelligence agencies lied to obtain warrants, Federal Court judge says).

The Court specifically found that agents of the Canadian Security Intelligence Service -- on the advice of and with the concurrence of their Department of Justice lawyers -- misled the Federal Court of Canada in order to obtain a warrant or warrants under the CSIS Act. The Court specifically found -- as a fact -- that this had occurred:

[117] In my view, as soon as it was determined that the Service would rely on the general power to investigate set out in s 12 of the Act to request second party assistance with the interception of the communications of Canadian subjects abroad, that determination constituted facts known to the affiant which could lead the Court to find that there was no investigative necessity to issue a 30-08 warrant. The failure to disclose that information was the result of a deliberate decision to keep the Court in the dark about the scope and extent of the foreign collection efforts that would flow from the Court’s issuance of a warrant.

[118] This was a breach of the duty of candour owed by the Service and their legal advisors to the Court. It has led to misstatements in the public record about the scope of the authority granted the Service by the issuance of the 30-08 warrants.

Courts are generally hesitant to go so far as to say that an affiant or a legal advisor lied to the court. That the Court did so in this case highlights how significant and egregious it was. This sort of conduct brings the administration of justice into disrepute and casts a pall over every warrant ever issued by the Court.

The decision names five Department of Justice lawyers who made "appearances" at the hearing of this matter but does not specify on whose specific advice CSIS was acting.

The warrant system only works if CSIS and their lawyers are truthful to the Court. This duty of candour is greatly elevated when they are the only ones appearing before the Court, as there is nothing adversarial to ensure that the truth comes out.

This cannot go unnoticed. This is not a "no harm, no foul" situation. The Government needs to appoint a special prosecutor to investigate how this came to be and the law societies governing those five lawyers should investigate what really appears to be egregious professional misconduct. Only a special prosecutor can do the job, as all five of the lawyers were arguing their case on behalf of the Deputy Attorney General of Canada, the country's top lawyer and prosecutor. Anything less would be sweeping this under the rug.