Monday, May 05, 2014

My opening statement to the House of Commons Justice and Human Rights Committee on Bill C-13

Apparently my testimony tomorrow at the House of Commons Justice and Human Rights committee on Bill C-13, the Protecting Canadians from Online Crime Act will not be webcast. Nor will it be on C-PAC or available on Pay Per View at your local arena. So, in case you are interested in what I plan to say, here you go ... (subject to tweaking as I finalize the text)

Introduction

Thank you very much for providing me with the opportunity to speak with you today.

For the purposes of introduction, my name is David Fraser. I’m a partner with the Atlantic Canadian law firm McInnes Cooper, but I do need to emphasise that I am here speaking as a private individual and my comments should not be attributed to my firm, its clients or any other organization with which I am affiliated.

I have been practicing internet and privacy law for over a dozen years. I have represented a range of clients over the years, including victims of cyberbullying, victims whose intimate images have been posted online, and I have represented and advised service providers.

Most notably, I was part of a team at my firm that took the case of a 15 year old victim of cyberbullying to the Supreme Court of Canada, pro bono. This was the first time that the Court had the opportunity to consider the phenomenon of cyberbullying and the unanimous Court came out very strongly to protect the interests of the victim of sexualized cyberbullying.

I have also advised people who have been accused of cyberbullying. I hope that this experience from a number of different perspectives will provide this Committee with some assistance in its important task of considering Bill C-13.

Bill C-13 as a whole

I am disappointed that Bill C-13 combines two very different but related matters: the dissemination of intimate images, on one hand, and law enforcement powers more generally, on the other hand. Both aspects raise very important issues that merit close scrutiny but we are seeing that debate about police powers is overshadowing the discussion of cyberbullying.

That said, we have one bill in front of us and I’m pleased to provide you my thoughts.

Intimate Images

It has been suggested that Bill C-13, if it had been in force, could have saved Amanda Todd and Rehtaeh Parsons. That makes a good soundbite, but the world is much more complicated than that. Creation, possession and dissemination of child pornography is already a crime. So is the creation, possession and dissemination of voyeurism images. So is extortion. So is criminal harassment.

That said, there is a gap that we should fill: the malicious dissemination of intimate images without the consent of the person depicted in them.

We need to be very careful about how we craft this offence. The current reality is that young people and adults, whether we like it or not, take photos of themselves and voluntarily share them with intimate partners. Those digital images can easily be spread around without the consent of the of the person depicted.

We want to criminalize the boyfriend who posts pictures of his ex-girlfriend online without her consent -- so-called “revenge porn”. We want to criminalize the actions of the person who forwards around images of current or former intimate partners. In each of those cases, the individual would know -- or ought to have known -- whether they had the consent of the person depicted in the image.

But we shouldn’t inadvertently criminalize behaviour that is not blameworthy: someone finds a picture online of someone naked and forwards it to a friend. That person knows nothing about the circumstances in which the photo was taken. It could be a professional model. The photo may have been posted by the person in the photo herself. There’s no way to tell whether consent was obtained, whether there was any expectation of privacy at the time the photo was taken and the individual has no way of determining this.

The real challenge arises when addressing third parties who do not know the person depicted in the image, nor do they know the circumstances under which the image was taken. The provisions in the bill use a “recklessness” standard, which in my view is too low. Recklessness applies where a person should have looked into it but decided to be “willfully blind”. However, given the huge amount of naked images online, it is not possible to “look into it.”

This is especially important for online service providers who have no way of knowing and no way of finding out the circumstances under which an image was taken or uploaded.

We need to be especially attentive to crafting the law so that it will survive a challenge in the Courts and “recklessness” poses the risk of having the law struck down or making criminals out of people who are not truly blameworthy.

Police powers

Transmission data

Bill C-13 creates a “Production Order for Transmission Data” (section 487.016) and a “Warrant for Transmission Data Recorders” (section 492.2). It has been said that the purpose of the transmission data provisions of the Bill is to extend the current police powers -- that are coupled with judicial oversight -- related to telephony information to the internet age, without significantly extending the status quo.

While this may be a reasonable objective, this must be done very carefully because “transmission data” is significantly different from traditional telephony signalling data.


With conventional telephony, “transmission data” refers to the number called from, the number called, whether the call was completed and the duration of the call. In the internet context, the amount of information and what it reveals is dramatically different. It would include the IP address of the originating computer, information about the computer, the browser or other program being used, the internet communications protocol being used (web surfing, file transfer, peer-to-peer, voice over IP, video conferencing, etc.), the IP address or domain name of the server or computer being communicated with, URL of the page visited and whether the transmission was completed. An interception of “transmission data” would tell law enforcement agencies whether the target of the surveillance was visiting a search engine (and possibly what is searched for), an encyclopaedia (and again, what is being viewed), a poker site or a medical site. Furthermore, the data will also provide greater insight into the likely physical location of the surveillance target. This is a dramatic expansion of the information provided compared to traditional telephone communications.

Individuals use computer assisted communications in a very different manner than the telephone system. A telephone call is usually a singular event that creates one small packet of transmission data. A browsing session will create a new packet for each page or site visited, which amounts to many, many packets during a session. And information about what sites are visited and in what sequence also communicate -- by inference -- information about the content of that communications. Finally, individuals use web browsers for many purposes that go well beyond the traditional uses of telephones.

Even with the express exclusion of “content” from the definition, transmission data may provide insight into the content of the communications. And in any event, internet transmission data will provide law enforcement agencies with information that goes to the biographical core of the target of the surveillance, which triggers a need for heightened legal protections under s. 8 of the Charter.

The increased privacy intrusion represented by these new law enforcement powers can be mitigated in either of the following two ways:

(a) the extension of the current lawful access to telephony transmission data to other forms of transmission data should be accompanied by a higher threshold: from “reasonable grounds to suspect” to “reasonable grounds to believe”; or

(b) the definition of “transmission data” should be refined to strictly limit the scope of what is included so that it much more closely tracks telephony transmission data.

Notice to the affected individuals

On important element is missing from all of this … the individual whose information is being sought. I am of the view that the police or government agency seeking information about an individual should inform him or her as soon as doing so would not prejudice the lawful investigation. This should be no later than six months after the information is sought, unless a judge orders otherwise.

Immunity

The immunity provisions in the new s. 487.0195 are gravely problematic. This is a very cleverly drafted provision. We are told that this is simply “for greater certainty”, but everything we know suggests otherwise. It says you will not be liable for handing over any data that you are not prohibited by law from handing over, and if you do so you are civilly immune.

Only the criminal law creates real legal prohibitions. Handing over data might not be a criminal offense, but it may create civil liability. This civil liability is there for a reason. I may not be legally prohibited from accidentally - emphasis on “accidentally” -- hitting your car with mine, but I certainly should be liable to pay for the harm that I cause. This is an incentive for me to pay attention when I am driving. Likewise, service providers should have to think about all the interests involved before handing over data, willy-nilly. This provision should be removed. It cannot be fixed and will only encourage over-reaching by law enforcement.

This is not simply providing needed clarity, but taking rights away from citizens.

While we don’t have Bill S-4, the Digital Privacy Act, in front of us, I am concerned that we are weakening Canadians’ privacy under the guise of protecting it. While this immunity provision tells service providers, “it’s OK, hand it over”, the new provisions in S-4 underscore that and seem to allow any business to hand over customer information to police, government and other businesses without any due process and without any notice to the affected individual. This is a very regressive step

Thursday, May 01, 2014

We seriously need transparency about law enforcement demands

Earlier this week, Interim Privacy Commissioner Chantal Bernier dropped a bombshell: Law enforcement agencies asked nine Canadian telcos for personal information 1.2 MILLION times and received data in more than three quarters of those cases. On its face, that number is staggering. It appears even more staggering when you figure that this is only a sub-set of Canadian telcos. But these numbers say virtually nothing about what kind of information we're talking about, what kinds of requests are made, under what circumstances, how many of them are with a warrant and how many are without, how many are based on intrusive and judicially unaccountable orders such as those under the Income Tax Act and the Customs Act? How many relate to the administration of laws, how many relate to law enforcement and how many are for national security purposes?

We know that hundreds of times a year, Canadian telcos provide private customer information to the police without a warrant under a protocol that I believe to be unlawful. (We'll see what the Supreme Court of Canada ultimately has to say about this practice in R v Spencer heard in December of last year.) We also know that not all telcos have adopted this protocol.

In this post-Snowden age and without credible information, we simply assume the worst and -- too often -- these assumptions are borne out.

In response, some telcos are providing some very general information (In my neck of the woods, Atlantic Canada's largest telcos, Bell Aliant and Eastlink both say they don't provide private information without a warrant or other legal compulsion.) But they are generally tight-lipped about what information they can provide, citing that it is law enforcement sensitive.

When the industrious researchers at the Citizen Lab tried to get this information from telcos directly, they were largely told to ask the government. MP Charmaine Borg, when trying to get clear information from federal law enforcement agencies, only received a paltry amount of data.

I don't buy it. And I can't accept it. We saw a huge furore over warrantless access to subscriber information when the federal government proposed Bill C-30. We're seeing a big fuss over this revelation related to the 1.2 million requests. We're about to start debating the new cyberbullying act that revives much of C-30's "lawful access" and we're ramping up to debate S-4, the Digital Privacy Act which extends voluntary disclosures of sensitive personal information beyond law enforcement. We cannot have an informed and educated debate about these incredibly important topics without real information.

So why aren't telcos and law enforcement agencies coming clean? We saw Google take the lead with its Transparency Report, which has been followed by other technology companies including as Twitter and Facebook. The list of companies actually includes telecommunications companies such as AT&T and Time Warner Cable in the US and Telstra in Australia [PDF]. But, to my knowledge, no Canadian company provides any data akin to a transparency report. Do government and law enforcement agencies want us to be in the dark? The cynic in my is starting to think so.

We need more transparency and accountability. We need one Canadian telco to take the courageous first step of producing a comprehensive transparency report, with full details of its methodology and terminology so that other telcos can step out of the shadows and provide comparable useful data. It's probably in their interests, since the speculation that is swirling around is likely worse than the reality. I don't know how or when a Canadian telco will step up, but Canadians should be calling on their providers to come clean with this information.

Tuesday, April 29, 2014

Government demands telco customer data more than a MILLION times per year

Paul McLeod of the Halifax Chronicle Herald and Alex Boutilier of the Toronto Star have both reported on a dramatic revelation made by Interim Privacy Commissioner Chantal Bernier after testifying before a Senate committee about Bell Canada's new privacy policy.

Following previous revelations, I would have expected a relatively high number but this is an order of magnitude more than I expected.

Bernier disclosed that law enforcement (and presumably national security agencies) ask Canadian telecommunications providers for customer information more than A MILLION times a year. That statistic comes from a report provided to Bernier's predecessor, Jennifer Stoddart, by the CWTA, which combined the answers of nine telcos to questions put by Stoddart to 12 telcos which refused to answer individually. The purpose for combining their answers was clearly to prevent any particular telco being singled out. The report was received by Jennifer Stoddart on December 15, 2011 but has not seen the light of day since then.

The report includes the following:

  • Government agencies requested customer information an average of 1,193,630 times annually.
  • Approximately 784,756 users and accounts were subject to disclosure, based on responses from three of the nine providers. One provider responded that the ratio worked out to 1.74 requests per customer.
  • Telecom companies keep detailed records of access requests by government authorities, but do not report them publicly.
  • Telecom companies responded they are not willing to make this information public.
  • Telecom companies do not report access requests to their customers, when the law allows it. Customers therefore have no way to challenge the access in court.

These numbers are staggering and raises many questions:

  • This staggering number comes from only nine of Canada's 30 telcos. What's the actual number and will we ever know (since government and telcos are refusing to be transparent about this)?
  • How many of these requests were with a warrant and how many were without?
  • Why do telcos keep a database of these requests and under what lawful authority?
  • Why did Jennifer Stoddart not disclose the information sooner, particularly while the horrible "lawful access" Bill C-30 was being hotly debated.

I expect we'll hear much more about this in the coming days.

Monday, April 28, 2014

Presentation on Canada's new Anti-Spam law

For the lawyers who read this blog, this topic may be getting tired but I'm regularly confronted by business folks who have heard very little about Canada's new Anti-SPAM law (CASL). I was asked to give a presentation on the topic on behalf of Digital Nova Scotia as part of its Business 101 seminar series.

For anyone who may benefit, here is my presentation:

Data location doesn't matter: US Federal Judge

Just posted to the Canadian Cloud Law Blog:

Canadian Cloud Law Blog: Data location doesn't matter: US Federal Judge:

In a decision that should not come as a big surprise, a US Federal Court judge has determined that the location of data under Microsoft's custody is not relevant. If Microsoft can produce it, it is required to do so.

As reported in Computerworld, the decision relates to a search warrant that directed Microsoft to produce the contents of one of its customer’s e-mails, where that information is stored on a server located in Dublin, Ireland. Microsoft contended that courts in the US cannot issue warrants for extraterritorial search and seizure, but the judge denied Microsoft's motion to quash the warrant. It argued, in part, that a US court can't issue a search warrant for premises outside of the United States so they should not be able to do so virtually.

However, the Court found that these orders may look like search warrants but they are more like subpoenas. They order an American company to do something entirely in the Unites States:

But the concerns that animate the presumption against extraterritoriality are simply not present here: an SCA Warrant does not criminalize conduct taking place in a foreign country; it does not involve the deployment of American law enforcement personnel abroad; it does not require even the physical presence of service provider employees at the location where data are stored. At least in this instance, it places obligations only on the service provider to act within the United States....

This case, for some Canadian readers will be reminiscent of the Canadian Federal Court decision in eBay Canada Ltd. v. M.N.R., 2008 FCA 348, where the Court ordered eBay in Canada to turn over information about Canadian "powersellers" regardless of the fact that the data was not within the territorial jurisdiction of the Court.

Microsoft is appealing this decision, but for now it stands for the proposition that the location of data is largely irrelevant in determining whether a government can order it to be turned over. The location or nationality of the custodian is much more relevant.

Friday, April 25, 2014

Documents related to the loss of the hard drive from the Office of the Privacy Commissioner of Canada

Readers of this blog may be interested to see the following documents related to the recent loss of a hard drive which occurred while the staff of the Office of the Privacy Commissioner of Canada moved offices from Ottawa to Gatineau:

Thursday, April 24, 2014

Supreme Court upholds Ontario's Information and Privacy Commissioner's order to disclose anonymised sex offender information

The Supreme Court has just issued its decision in the case of Ontario (Community Safety and Correctional Services) v. Ontario (Information and Privacy Commissioner), 2014 SCC 31. The case relates to a request for access to statistical information about the geographic distribution of information about individuals listed on Ontario's sex offender registry.

The requester sought information about the number of people on the list according to the first three digits of postal codes. The province had refused to provide the requester with access, citing the exemptions of the Freedom of Information and Protection of Privacy Act related to privacy and law enforcement information. The IPC found that the information was not subject to such exemptions and should be disclosed. On the ultimate appeal, the Supreme Court of Canada agreed with the Commissioner.

From the headnote:

Access to Information — Exemptions — Confidentiality provisions — Requester seeking disclosure of number of offenders registered under sex offender registry residing in areas designated by first three digits of Ontario’s postal codes — Government institution denying request on grounds of exemptions contained in Freedom of Information and Protection of Privacy Act — Information and Privacy Commission ordering disclosure — Standard of review of Commission’s decision — Whether Commission made reviewable error in interpreting applicable legislation — Whether Commission applied appropriate evidentiary standard with regards to harms‑based exemptions — Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. F‑31, ss. 14, 67 — Christopher’s Law (Sex Offender Registry), 2000, S.O. 2000, c. 1, ss. 10, 13.

A requester sought disclosure from the Ministry of Community Safety and Correctional Services of the number of offenders registered under its sex offender registry residing within the areas designated by the first three digits of Ontario’s postal codes. The registry is established and maintained under Christopher’s Law (Sex Offender Registry), 2000. The information contained in the Registry is kept confidential by the Ministry and police. The Ministry refused to disclose, citing law enforcement and personal privacy exemptions in the Freedom of Information and Protection of Privacy Act. The Information and Privacy Commissioner held that the exemptions do not apply and ordered disclosure. The Commissioner’s decision was upheld on judicial review and on appeal.

Held: The appeal should be dismissed.

The Commissioner made no reviewable error in ordering disclosure. The applicable standard of review is reasonableness. The Commissioner was required to interpret Christopher’s Law for the narrow purpose of determining whether it contained a confidentiality provision that prevails over the Freedom of Information and Protection of Privacy Act. This task was intimately connected to her core functions. The Commissioner reasonably concluded that the Ministry did not provide sufficient evidence that disclosure could lead to the identification of offenders or of the risks of the harms that the exemptions seek to prevent.

The Commissioner did not grant a right of access that is inconsistent with either Act. Section 67(2) of the Freedom of Information and Protection of Privacy Act does not specifically provide that a confidentiality provision in Christopher’s Law prevails and, although s. 10 of Christopher’s Law is a confidentiality provision, neither it nor any other part of Christopher’s Law prevails over the Freedom of Information and Protection of Privacy Act. Explicit references to Freedom of Information and Protection of Privacy Act in Christopher’s Law indicate that the Legislature considered the manner in which both statutes operate together. Had the Legislature intended the confidentiality provision in Christopher’s Law to prevail, it would have included specific language to that effect. Neither s. 13 of Christopher’s Law nor Christopher’s Law working together with the Police Services Act, R.S.O. 1990, c. P.15, ousts the application of the Freedom of Information and Protection of Privacy Act. The Commissioner did not take too narrow a view of the law enforcement exemptions under s. 14(1)(e) and (l) of the Freedom of Information and Protection of Privacy Act. Based on the evidence and arguments before her, she properly focused on the reasonableness of any expectation that the requested disclosure would lead to the identification of sex offenders or their home addresses. Because the law enforcement exemptions do not apply, the discretion not to disclose a record under s. 14 of the Freedom of Information and Protection of Privacy does not apply.

The Commissioner made no reviewable error with respect to the standard of proof applicable to the law enforcement exemptions. There is no difference in substance between “a reasonable expectation of probable harm” and a “reasonable basis for believing” that harm will occur. The “reasonable expectation of probable harm” formulation simply captures the need to demonstrate that disclosure will result in a risk of harm that is well beyond the merely possible or speculative, but also that it need not be proved on the balance of probabilities that disclosure will in fact result in such harm. The “reasonable expectation of probable harm” formulation should be used wherever the phrase “could reasonably be expected to” is used. The Commissioner reasonably concluded that the Ministry did not prove that the Record could be used to identify sex offenders or that it will ignite among sex offenders a subjective fear of being identified that will lead to lower compliance rates with Christopher’s Law.

Privacy Commissioner loses hard-drive with unencrypted personal information about 800 employees

Mark Goldberg over at Telecom Trends is blogging about an article in the print edition of the Toronto Star (Did Privacy Commissioner lose private information? that reports the Privacy Commissioner of Canada's office lost a hard-drive with the unencrypted personal information on 800 current and former employees.

The loss occurred when the OPC moved offices from downtown Ottawa to Gatineau and apparently went undetected for quite some time. I expect more details will emerge before long.

Of course, this is supreme irony and likely delicious irony to those agencies who the OPC has chided for inadequate security.

It also highlights that the greatest risk to personal information is mobile and portable devices, whether they are computers or phones, or portable storage devices. These things are small, easy to steal and very easy to lose. They are lost and compromised ALL THE TIME. If Canada and the OPC had a comprehensive cloud strategy that kept all the sensitive personal information in secure data centres, behind firewalls and properly secured, this sort of thing would never happen.

Stay tuned for more ...

Wednesday, April 23, 2014

Cyberbullying legislation and freedom of expression

I was invited to lead a discussion at the Canadian Centre for Ethics and Public Affairs on Nova Scotia's cyberbullying legislation and its impact on freedom of expression. It was part of their "everyday ethics" series. Though it was much more of a discussion than a presentation with powerpoint, did did prepare the below presentation which may be of interest to readers of this blog. Feel free to share it.


Monday, April 14, 2014

Sensitive mental health info goes into police databases, shared with US government

The Information and Privacy Commissioner has released her investigation report to allegations that Ontario police are routinely inputting sensitive mental health information into national police databases, which are not only accessible to all Canadian police departments, but also the US Federal Bureau of Investigation and Department of Homeland Security.

You can get the full report here: IPC - Office of the Information and Privacy Commissioner/Ontario | Commissioner Cavoukian calls for Ontario Police Services to stop the indiscriminate disclosure of attempted suicide information.

This indiscriminate disclosure of information is not in compliance with Ontario's privacy laws, she concluded.