Monday, March 07, 2022

Video: Individual access requests under PIPEDA

New on my YouTube Channel.

Intro

Today I am going to be speaking about individual personal information access requests. If you're from Europe, you probably have heard the term data subject access requests, which is essentially the same concept.

This is where an individual gets to ask a business what information they have about them, expects a copy of it and perhaps disputes its accuracy.

I remember when our federal privacy law was being debated and phased in, many businesses were concerned they would be overrun with individual access requests. They were particularly concerned with frivolous or vexatious ones. We really haven’t seen that in practice.

But the right exists and any organization that does business in Canada needs to know about it and should be able to manage it.

Today, I am only going to be talking about Canada's personal information protection and electronic documents act. This law includes a general rule that individuals have an access right. Like most rules, this is not absolute and there are some exceptions. I plan to cover many of these exceptions in this discussion.

While this discussion is limited to Canada's personal information protection and electronic documents act, you should probably know that every single Canadian privacy law includes an access right.

Most of our public sector laws are divided between freedom of information and protection of privacy. In the federal public sector, there is a separate Privacy Act and an Access to Information Act. Many provinces also have health privacy laws, all of which include an individual access right.

Though I am talking about the federal private sector law, you should know that some of the details can differ from law to law.

If you have followed any of these discussions, you will know that the Personal Information Protection and Electronic Documents Act is weird. This federal law is based on the general principles of the Canadian Standards Association Model Code for the Protection of Personal Information. In fact, this standard of Canada is appended as a schedule to the law.

If you read it, you will see that it is written as a general list of principles, not like most of our laws. The general rules are in the schedule but there are exceptions in the body of the statute. The body of the law and the Schedule have to be read together.

The General Principle of Access

So we will be looking at Principle 9 from the CSA Model Code and then sections 8 through 10 of the Act.

Of course, we have to start with the general rule of access. This is in Principle 9, entitled “individual access”. It says…

“Upon request, an individual shall be informed of the existence, use, and disclosure of his or her personal information and shall be given access to that information. An individual shall be able to challenge the accuracy and completeness of the information and have it amended as appropriate.”

This talks about access to the information itself. It also refers to access to information about how it has been used. And the individual also gets to challenge the accuracy and completeness of that information.

There are some sub-principles that elaborate on this. Sub principle 9.1 says…

“9.1 Upon request, an organization shall inform an individual whether or not the organization holds personal information about the individual. Organizations are encouraged to indicate the source of this information. The organization shall allow the individual access to this information. … In addition, the organization shall provide an account of the use that has been made or is being made of this information and an account of the third parties to which it has been disclosed.”

The business should answer the question about whether they even have information about the individual, and should be able to tell them where that information came from.

They also should be able to tell the individual how that information has been used and to whom it has been disclosed. Businesses are sometimes surprised to discover that they have to keep information about their information in order to satisfy this requirement.

Because a business cannot disclose personal information about somebody without their consent, and the information contained in an individual access request is pretty all-encompassing, it makes sense that the business can require the individual to prove that they are the person they purport to be. It also makes sense that the individual should cooperate in helping the business identify what information may be about them.

That includes “how do we know you are who you say you are?” And “where should we look to find information about you?”

Information provided in that particular context can only be used for that purpose.

To whom has the information been disclosed?

I mentioned that businesses have to keep information about their information. In sub-principle 9.3, individual access rights include a right to know to whom a person’s personal information may have been disclosed. The principle reads:

“9.3 In providing an account of third parties to which it has disclosed personal information about an individual, an organization should attempt to be as specific as possible. When it is not possible to provide a list of the organizations to which it has actually disclosed information about an individual, the organization shall provide a list of organizations to which it may have disclosed information about the individual.”

At the end of the day, organizations need to know where the data they control goes and need to be able to tell people when they ask.

Timelines to respond

The timelines to respond are a good example of the difference between the very general language of the principles and some of the specifics in the statute. The sub-principle 9. 3 says it has to be provided “within a reasonable time”. We’ll see when we flip to section 8 that that really means no later than 30 days in most cases.

The sub-principle also says it has to be at minimal or no cost to the individual.

My general advice is to not charge people for this. But there are cases where individuals will repeatedly make requests and there is no mechanism to say “no” to frivolous or vexatious requests. Attaching a cost may make sense. For example, in any twelve month period the first request is free.

I think Google had the right idea when it started providing users with the ability to download their account information. A self-serve individual access right. Since then, many large data driven companies have followed suit allowing individuals to easily access their own data for free.

This sub-principle also says “The requested information shall be provided or made available in a form that is generally understandable. For example, if the organization uses abbreviations or codes to record information, an explanation shall be provided.”

This makes sense. If a person can’t parse a JSON file or decipher technical abbreviations, the person really isn’t able to access the information. I know of some healthcare providers who will provide a nurse or a records clerk to walk through the records with a patient who asks for it.

Finally, you’ll note that this doesn’t go so far as to give a “data portability” right. We expect this to be added when PIPEDA is updated in the coming year or so.

Disputes about accuracy

PIPEDA contains an accuracy principle, which requires that “Personal information shall be as accurate, complete, and up-to-date as is necessary for the purposes for which it is to be used.”

The individual has the right to dispute the accuracy of any personal information a company may have, and sub-principles 9.5 and 9.6 address how this is to be dealt with. It is pretty straightforward:

“9.5 When an individual successfully demonstrates the inaccuracy or incompleteness of personal information, the organization shall amend the information as required. Depending upon the nature of the information challenged, amendment involves the correction, deletion, or addition of information. Where appropriate, the amended information shall be transmitted to third parties having access to the information in question.”

But what happens if the company doesn’t agree that the information is inaccurate? Sub-principle 9.6 addresses this:

9.6 When a challenge is not resolved to the satisfaction of the individual, the substance of the unresolved challenge shall be recorded by the organization. When appropriate, the existence of the unresolved challenge shall be transmitted to third parties having access to the information in question.

How to make a request

So those are the relevant provisions in the Schedule from the CSA Model Code. Let’s now turn to some of the specifics in the body of the statute itself.

Subsection (1) of Section 8 of PIPEDA says that these requests have to be in writing. This can, of course, be electronic. Note that the wording says “must”. This implies that a request that is not in writing doesn’t trigger the formalities of the Act, but can still be responded to.

Duty to assist

Subsection (2) of Section 8 places an obligation on the organization to assist the individual to make a request if they say they need help.

This makes sense.

Timing

I mentioned earlier that the general language about timing in the principles is firmed up in the body of the statute. Specifically, it says “An organization shall respond to a request with due diligence and in any case not later than thirty days after receipt of the request.”

Extension of time limit

This isn’t absolute, however. In some cases, the organization can extend the time but has to let the individual know about the extension, the reason for it and of their right to complain to the Privacy Commissioner.

The first circumstance is if “meeting the time limit would unreasonably interfere with the activities of the organization”.

This would be if the request is complex or would require a lot of resources, who would be taken away from their usual tasks and it would “unreasonably interfere with the activities of the organization.” What “unreasonably interfere” means is unclear. In this case, the timeline can be extended for a second thirty days.

The second circumstance is if the organization needs more time to carry out consultations necessary to respond to the request. For example, some of the information may have been generated in litigation or in contemplation of litigation, and the organization needs to determine if the privilege exception applies and to decide whether to waive it. In this case as well, the timeline can be extended for a second thirty days.

The third scenario is more open ended and allows time to convert the personal information into an alternative format. This may be to accommodate a disability.

Deemed refusal

Subsection (5) of Section 8 says that if the organization fails to respond to an access request within the timelines imposed by the Act, that is a deemed refusal and the individual thus has the right to complain to the Privacy Commissioner.

Costs for responding

You’ll recall that the principles say that access requests have to be “at minimal or no cost to the individual.”

Subsection (6) of Section 8 says that you can only charge the individual if they are advised of the approximate cost and the individual then tells the organization that the request is not being withdrawn.

Notably, there is no other guidance on costs or whether the cost has to be reasonable. That’s likely implied.

Reasons for refusals

If the organization refuses an individual’s request – and I’ll get into the exceptions that can justify a refusal shortly – this refusal has to be in writing. It has to tell them the reasons for the refusal and to tell them they have the right to complain to the Privacy Commissioner.

It also says that the organization essentially must preserve and retain the information at issue for as long as is necessary to allow the individual to exhaust any recourse that they may have.

That makes sense. If it was an unjustified refusal, and the end result is a recommendation from the Commissioner or an order from the court to hand it over, that would be thwarted if the information were deleted in the meantime.

Mandatory refusals

The Act contains a number of circumstances where access either can be refused or where it must be refused.

In subsection (1) of section 9, it says that you have to refuse to provide access if doing so would disclose personal information of a third party. If that personal information can be severed from the disclosure, then you must do the severing and provide the balance of the information. If the third party consents, then access can be granted.

Interestingly, subsection (2) allows giving access even if it would disclose third party personal information if the “individual needs the information because an individual’s life, health or security is threatened.”

Notably, it is not just if the applicant’s life health or security is threatened

That is a real outlier of a scenario and if you encounter that, get immediate advice from an experienced privacy lawyer.

A second scenario where access must be refused is if the personal information that is the subject of the access request has previously been requested by law enforcement, national security or other government agencies. If this is the case: get immediate advice from an experienced privacy lawyer.

The Act sets out a whole routine of consulting with the government agency, seeking their input or direction. If they say don’t disclose it, you can’t disclose it. And you probably can’t tell the individual why and you also have to give notice to the Privacy Commissioner.

The legislators have created a real minefield for organizations if this comes up, so proceed with caution and with good advice.

Discretionary refusals

Subsection (3) of Section 9 sets out a number of circumstances where an organization can choose to refuse access. It doesn’t have to provide it, but it can.

The first is if the information is protected by legal advice or litigation privilege. This comes up a lot because individuals often use the access right under PIPEDA as a pre-litigation discovery tool. If there’s any doubt about whether information fits in this category, seek advice. And of course be aware that this would amount to a waiver of privilege.

The second is if providing access would reveal confidential commercial information, but if that information can be severed, it has to be and the balance of the information must be provided.

The third is if disclosing the information could reasonably be expected to threaten the life or security of another individual. As with confidential commercial information, if that information can be severed, it has to be and the balance of the information must be provided.

The fourth is if the information was collected under paragraph 7(1)(b), which is if it was collected without the knowledge or consent of the individual in connection with an investigation related to a breach of an agreement or a contravention of the laws of Canada or a province. If you refuse on this basis, you have to notify the Privacy Commissioner and include in the notice to the individual whatever information that the Commissioner may specify.

The fifth is if the information was generated in the course of a formal dispute resolution process. This would be in addition to litigation privilege, referred to in paragraph (a).

The sixth scenario where access can be refused is if the information relates to an investigation under the Public Servants Disclosure Protection Act. This rarely arises.

Conclusion

At the end of the day, Canadians are generally not frequent users of the individual access right that they have in the Personal Information Protection and Electronic Documents Act.

But businesses need to understand that this right exists and should have processes and procedures to manage it. Hopefully this has provided information on the general rules that apply to this, and the exceptions to the general right of access.

Thank you very much for tuning in. If you have any comments on this video or any suggestions for topics you’d like to see covered in the future, please leave them in the comments below.

If you find this sort of content to be interesting or informative, please subscribe. If you also click the bell, you’ll be notified of new videos as they are posted.

Monday, February 28, 2022

Video: What are privacy policies for in Canada?

New on my YouTube Channel.

Today I am going to be talking about what privacy policies are really for under Canadian privacy laws.

They are everywhere – on every website – seldom read. But their purpose in Canada is a little misunderstood.

I am going to limit this discussion to Canada’s current federal private sector privacy law, called the Personal Information Protection and Electronic Documents Act or PIPEDA. But most of my comments would be applicable for the “substantially similar” laws in British Columbia and Alberta.

I think most people who follow this sort of stuff know that Canadian private sector privacy law is based on consent – knowledgeable informed consent. There’s often an assumption that the “knowledgeable” and “informed” parts come from people reading privacy policies.

That’s not the way it usually works, however. I think we all know that people seldom read privacy policies. At least based on my own informal polling of my students, fewer people are actually reading privacy policies than ever before.

Let’s look at what the Act actually says about consent. To be informed consent, you have to look at principles 2 and 3 (which are taken from the Canadian Standards Association Model Code for the Protection of Personal Information).

Getting Consent

Principle 2 says

“The purposes for which personal information is collected shall be identified by the organization at or before the time the information is collected.”

It then goes on and says

“The identified purposes should be specified at or before the time of collection … to the individual from whom the personal information is collected. Depending upon the way in which the information is collected, this can be done orally or in writing. An application form, for example, may give notice of the purposes.”

It does not say that it should be simply set out in a privacy policy.

Principle 3 – Consent

Principle 3 is about consent. It says simply

“The knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate.”

We can ignore the “except where inappropriate” part because all the exceptions are enumerated in section 7 of the Act.

Principle 3 then goes on and says

“The principle requires “knowledge and consent”.

Organizations shall make a reasonable effort to ensure that the individual is advised of the purposes for which the information will be used.

To make the consent meaningful, the purposes must be stated in such a manner that the individual can reasonably understand how the information will be used or disclosed.”

Again, it does not say just throw it in the privacy policy.

So you’re really only confident that you have adequate consent if you are confident the individual has actually been apprised of the purposes for the collection, use or disclosure of their personal information.

In most cases, you can’t be confident that any particular visitor to your website has scrolled to the bottom and has even seen the link to a privacy policy, let alone clicked on one.

In some cases, however, you could use the privacy policy to “identify purposes”. That would be if you require a new visitor to or someone who is just creating a new account to read and acknowledge the privacy policy. In that case, you have made the effort to bring all the purposes to the user’s attention.

In other cases, you might give users clear notice that your privacy policy has been updated.

And either making them review it or at least telling them to do so.

So if a privacy policy in Canada isn’t for getting consent, what is it for?

Principle 8 – Openness

To find out, we have to flip forward to the 8th principle, entitled “Openness”.

Spoiler alert – privacy policies in Canada are about being open and transparent. They should also be where you go for answers to any privacy-related questions.

Let’s read Principle 8, starting with the main principle:

“An organization shall make readily available to individuals specific information about its policies and practices relating to the management of personal information.”

It doesn’t come right out and say “thou shalt have a privacy policy”, but it essentially means that.

Subprinciple 8.1 says:

“Organizations shall be open about their policies and practices with respect to the management of personal information. Individuals shall be able to acquire information about an organization’s policies and practices without unreasonable effort. This information shall be made available in a form that is generally understandable.”

Be open about what you do with personal information. Make it really easy to find and make it easy to understand.

There’s then a list of all the additional things that an organization must have in a privacy policy:

The information made available shall include

(a) the name or title, and the address, of the person who is accountable for the organization’s policies and practices and to whom complaints or inquiries can be forwarded;

This essentially means the contact information for the organization’s privacy officer. It doesn’t have to name them, but there has to be a way to reach that person if there are any complaints or any questions.

(b) the means of gaining access to personal information held by the organization;

In Canada, individuals have a right of access to their personal information, subject to some limitations. This means you have to let individuals know about this right and how to exercise it.

I’ll likely do a full video soon on data subject access rights in Canada.

(c) a description of the type of personal information held by the organization, including a general account of its use;

You have to say what information you collect and how you use it.

(d) a copy of any brochures or other information that explain the organization’s policies, standards, or codes; and

This essentially says you have to have a privacy policy to communicate all this information.

(e) what personal information is made available to related organizations (e.g., subsidiaries).

If you share information between related companies, you should call this out here.

Also, the Privacy Commissioner of Canada says that the privacy policy should include information on whether personal information is stored outside of Canada.

Who reads privacy policies?

In my experience, there are only three categories of readers.

Regulators, who want to make sure you have a mature privacy program.

People with questions about the handling of their personal information.

People with concerns or complaints about the handling of their personal information.

Privacy policies should be written with these audiences in mind.

So at the end of the day, what are privacy policies for?

At the very least, they are so you can say you’ve complied with Principle 8.

But what else? It should serve as a reference for anyone who has any questions or concerns about how an organization handles personal information.

Someone reading it should be able to get a handle on what information the organization collects, understand how it is used and know who to contact with any questions or concerns.

Tuesday, February 22, 2022

Video: Cross-border data flows for Canada

New on my YouTube Channel.

In today's video, I am going to talk about the mosaic of privacy laws that we have in Canada and what they have to say about cross border data transfers.

First, I will talk about public sector privacy laws with two particular examples coming from British Columbia and Nova Scotia.

Then I would be talking about Canada’s private sector privacy laws, in particular PIPEDA and the substantially similar laws in Alberta and British Columbia. I will also briefly discuss the new Quebec privacy statute.

Finally, I will touch on various provincial health privacy laws that also have provisions that relate to cross border data flows

What Canadian privacy laws

Canada is a federal country and jurisdiction as it relates to privacy is divided between the provinces and the federal government.

We also have three general varieties of privacy laws:

Those that regulate the collection, use and disclosure of personal information by the public sector – which includes governments, government agencies and other organizations like universities and school boards.

We have a separate category of privacy laws that regulate the private, non-government sector.

Because healthcare in Canada is a mix of public and private, a number of provinces have developed health privacy laws to ensure uniform treatment of personal health information regardless of whether it’s at a doctor’s office or in a hospital.

Public sector privacy laws

One area in Canada that does not have any gaps in privacy regulation is the public sector. Each federal, provincial and territorial jurisdiction has a public sector privacy law that regulates the collection, use and disclosure of personal information by government and government agencies.

One thing that they all have in common is an obligation to protect and safeguard all personal information against a range of risks, including unauthorized disclosure. Very few of them directly address cross border data flows.

Privacy Act

In the federal jurisdiction, we have the privacy act which regulates federal government institutions.

The privacy act does not address cross border transfers or disclosures of personal information.

Instead, the federal treasury board has created guidelines regarding outsourcing that effects personal information.

These guidelines do not prohibit this storage of personal information outside of Canada, but instead impose an assessment to determine whether in the circumstances it is appropriate to use a particular service that may result in personal information being stored outside of Canada or accessed from outside of Canada.

FIPPA (British Columbia)

In 2004, the British Columbia Freedom of Information and Protection of Privacy Act was amended to essentially prohibit the province’s government from allowing personal information to be stored outside of Canada or accessed from outside of Canada.

This was because of a large-scale union campaign that latched onto privacy and fear of the USA PATRIOT Act to oppose government outsourcing of IT services.

These prohibitions were finally removed in 2021, likely driven by the need of governments, universities and school boards to use more modern cloud technologies to support work from home during the pandemic.

The replacement provisions anticipate the government to pass regulations about cross-border data transfers, but we have not seen those yet.

PIIDPA (Nova Scotia)

In 2006, Nova Scotia followed British Columbia in strictly limiting cross-border data flows when it passed the Personal Information International Disclosure Protection Act, also known as “PIIDPA”.

What PIIDPA contains is a general prohibition against storage or access outside of Canada for public bodies in Nova Scotia. This includes public bodies in the health sector.

PIIDPA is not as draconian as the British Columbia law because it does permit the “head of the public body” to authorize the storage or access outside of Canada if it is for the public body’s necessary operations.

The public body also has to make a report of the decision to the minister of justice, which is then made public.

PIIDPA also imposes specific obligations on all service providers of public bodies.

Foreign demands for disclosure

The most significant – but maybe less known – obligation imposed on service providers relates to “foreign demands for disclosure”. These are warrants, subpoenas and court orders by a foreign authority for records, as long as there is a penalty for non-compliance.

It is unlawful for a service provider to provide the data, and the public body or its service provider must give written notice of the demand to the Nova Scotia Minister of Justice.

Then what? I don’t know. Presumably there would be some government-to-government communications.

Foreign demands under other laws

Every privacy law in Canada permits disclosures without consent where the disclosure is required by law. Some include examples like warrants, subpoenas, litigation document discovery and the like.

None of them specify “where required by CANADIAN law”, but that is a reasonable presumption.

These laws, other than PIIDPA, don’t make it an offense but it would still not be permitted.

But at the same time, the Office of the Privacy Commissioner of Canada has been clear that if information is stored outside of Canada, it becomes subject to the laws of the place where it is stored. That’s a risk that needs to be taken into account in any contracting decision.

Private sector privacy laws

For most of the private sector in Canada, there are no rules that prohibit cross-border data transfers but there are rules that come into play.

Each private sector privacy law requires that the original “controller” makes sure that there are adequate safeguards to protect personal information.

The original controller has to use contractual terms to make sure that any contractors implement those safeguards.

Jurisdiction may affect whether safeguards can be adequately assured.

Disclosures by the organization or its contractors in response to a “foreign demand for disclosure” may be unlawful. Any organization dealing with something like this should immediately seek experienced legal advice.

Alberta’s Personal Information Protection Act

Alberta’s Personal Information Protection Act specifically addresses giving people notice about cross-border data transfers.

Specifically, the law requires policies and procedures that include the countries in which the collection, use, disclosure or storage is occurring or may occur, and the purposes for which the service provider has been authorized to collect, use or disclose personal information for or on behalf of the organization.

Because this information has to be made available upon request, it should be included in an organization’s public-facing privacy policy.

The Privacy Commissioner of Canada recommends this as well for PIPEDA

Quebec’s Bill 64

In the past year, Quebec has significantly updated its private sector privacy law, including provisions that specifically address cross-border data transfers.

These new provisions come into effect on September 22, 2023.

When the Quebec provisions come into effect, they will require a process similar to a data transfer impact assessment under the European GDPR.

Before storing personal information outside of Quebec, the organization will need to carry out a privacy impact assessment, sometimes referred to as a PIA.

Then the organization will need to carry out an analysis of whether there will be “adequate” protection of the personal information when transferred outside of the province.

Finally, there needs to be a written agreement with the service provider that mitigates any risk identified in the PIA and ensures that personal information will be adequately protected.

Health privacy laws

Health privacy laws are a specific kind of privacy law in Canada, which cross over the private sector (doctors’ offices, pharmacies and physiotherapists) and the public sector (health authorities and public hospitals).

Most health privacy laws in Canada prohibit disclosures of personal health information outside of Canada unless there is consent from the individual. Some similarly prohibit disclosures outside of the province.

But most people who practice in this space, and some regulators I’ve spoken to, say that a transfer for processing is not a disclosure for the purposes of this prohibition.

What’s the reality on the ground?

Many people still believe that cross-border transfers are prohibited in Canada, which is likely the result of the publicity around the prohibitions added to the British Columbia public sector law years ago.

The only province that significantly limits cross-border transfers is Nova Scotia, for the public sector in that province.

We still see requests for proposals from both the public and the private sectors that require data residency in Canada.

When this happens in the public sector, this is likely in violation of international trade agreements.

Tuesday, January 04, 2022

Video: Recording the police in public

I've written before about the law around recording the police in public (see posts tagged "Photographing Police"), but thought it might be useful to have a video discussion about the topic. Here it is ...

If you have any comments on thoughts on future topics, please leave them in the comments for the video on YouTube.

Friday, December 31, 2021

Video: The Privacy Landscape in Canada

This blog has been a little quiet, as most of my public-facing energy has been spent on Twitter. I've decided to channel some of it into video content on YouTube. Here's my first attempt at providing information and education on Canadian privacy law via multimedia content.

Let me know in the comments for the video if there are any other topics you'd like covered.

Thursday, December 09, 2021

Presentation: Social Media Background Checks

I was invited to present to the IAPP Halifax Knowledgenet today on social media background checks, focusing on both the privacy and human rights dimensions. Here it is in case it's of interest:

Thursday, November 19, 2020

10 Ways Canada’s Consumer Privacy Protection Act Will Impact Privacy Practices

We just posted this on the McInnes Cooper client information site:
10 Ways Canada’s Consumer Privacy Protection Act Will Impact Privacy Practices

November 19, 2020

By Sarah Anderson Dykema, CIPP/C, Lawyer at McInnes Cooper,

David Fraser, Privacy Lawyer | Partner at McInnes Cooper

On November 17, 2020, the federal government proposed dramatic changes to how Canada will enforce privacy law, ushering in a new legal regime to protect individuals’ personal information – and to regulate organizations’ privacy practices. Bill C-11: the Digital Charter Implementation Act creates the Consumer Privacy Protection Act (CPPA) to replace the federal Personal Information and Electronics Documents Act (PIPEDA), and codify in law organizations’ obligations respecting the collection, use and disclosure of personal information rather than merely rely on the Canadian Standard Association (CSA) Model Code. The federal government says it estimates 18 months for the CPPA to go through the legislative process and become law, though this is always difficult to gauge. It might be derailed by, for example, a federal election or the ongoing COVID-19 Pandemic – but it might not.

It’s still early days, but if the CPPA (or some form of it) passes, it will take organizations time to put the necessary compliance processes in place. Here are 10 ways the Consumer Privacy Protection Act will impact organizations’ Canadian privacy practices.

1. Big Penalties. There will be significant penalties for non-compliance with the CPPA. It authorizes administrative monetary penalties and fines of up to 5% of global revenue or $25 million, whichever is higher, for the most serious offences. Currently, PIPEDA only authorizes penalties for breach of the Digital Privacy Act, and those are markedly lower than those under the CPPA: the maximum fine for breaching the Digital Privacy Act is $100,000 per violation (though if there were multiple violations, which would not be uncommon, the fines could add up).

2. Privacy Commissioner Powers. In a move away form the traditional ombudsman model, the CPPA gives the federal Privacy Commissioner broad power to make orders against organizations and to recommend penalties to a new “Personal Information and Data Protection Tribunal”. Under PIPEDA, the Privacy Commissioner only has the power to make recommendations to a breaching organization.

3. New Tribunal. A new “Personal Information and Data Protection Tribunal” will determine and levy any penalties – which will have the effect of a court order – and hear appeals from orders of the Privacy Commissioner.

4. Global Application. The new law takes an expansive approach to applicability, expressly applying to all personal information an organization collects, uses or discloses, including interprovincially or internationally. This reflects the increased digitization and globalization of the global economy, which knows no border, and which the COVID-19 Pandemic has accelerated.

5. New Right of Action. It creates a new privacy breach legal claim. Where the Privacy Commissioner decides an organization violated an individual’s privacy under the CPPA, and the Personal Information and Data Protection Tribunal upholds that finding, that individual can sue the organization (within 2 years) for compensation for the violation.

6. Data Portability & Deletion. It provides for new individual rights of data portability and deletion. Consumers can require an organization to transfer their data to another organization (subject to regulations that aren’t yet available), likely to be a boon to open banking. Individuals can also require that an organization delete the personal information it’s collected about them, subject to some limitations, in what appears to be a limited form of the “right to erasure”.

7. Algorithmic Transparency. It requires algorithmic transparency. Consumers would now have the right to require an organization to explain how an automated decision-making system made a prediction, recommendation or decision.

8. Consent Exceptions. It “simplifies” consent requirements for organizations by making some (potentially broad) exceptions to when an organization must obtain an individual’s consent to the collection, use or disclosure of the individual’s personal information, such as where the use of personal information is core to the delivery of a product or service. This could impact, for example, the information an organization must communicate in a privacy policy.

9. Data De-Identification. It makes new rules around the de-identification of data – including allowing for organizations to use an individual’s personal information without their consent in order to de-identify their data, but appears to limit other uses of de-identified data. Under certain circumstances, organizations can also disclose de-identified data to public entities for socially beneficial purposes.

10. Codes of Practice. It introduces the concept of “Codes of Practice”. The CPPA allows private organizations to establish a “code” and internal certification programs for complying with the law that the Privacy Commissioner will approve. Once approved, the “code” will effectively establish the organization’s legal compliance obligations.

Wednesday, November 18, 2020

Presentation: Privacy and Cybersecurity - latest trends and legal obligations

I was invited to speak at the 2nd Annual Atlantic Technology Summit on the topic of cybersecurity, privacy and the law. Not surprisingly, the entire conferene this year was online but it was all well attended.

In case it is of interest to others, here's the presentation I gave which started with a few case studies and then an overview of the current environment affecting legal risk. Of course, the slides were prepared before C-11 dropped though I was able to comment during the presenation that the stakes will get even higher with any breach of security safeguards.

Wednesday, October 07, 2020

Presentation: Little Brother - Surveillance Technology and Privacy Law

I had the pleasure of speaking at the University of New Brunswick Law School's weekly speaker hour, on the topic of non-police use of surveillance technology and how that intersects/collides with Canadian privacy laws. Here are the slides in case it's of wider interest ...