Saturday, January 31, 2004

Release - Federal, British Columbia and Alberta Commissioners Working Together to Ensure Seamless Privacy Protection in the Private Sector

News Release - January 26, 2004 - Office of the Privacy Commissioner of Canada: Federal, British Columbia and Alberta commissioners working together to ensure seamless privacy protection in the private sector

"Ottawa, January 26, 2004 - The Privacy Commissioner of Canada, Jennifer Stoddart, the Information and Privacy Commissioner of British Columbia, David Loukidelis, and the Information and Privacy Commissioner of Alberta, Frank Work, today announced that they will be working cooperatively to develop a harmonized approach to dealing with privacy complaints in the private sector.

All three jurisdictions face new responsibilities with the coming into force on January 1, 2004 of their respective private sector privacy laws. Last week, Ms. Stoddart, Mr. Loukidelis and Mr. Work met in Ottawa to begin working out an understanding for administering their respective laws and to begin developing fair, consistent and clear rules of enforcement, which will help to eliminate any confusion regarding jurisdiction. "

Article: Companies and Consumers Clash on Privacy Issues

Here is some coverage of the Accenture survey (reported on in a previous post) from destinationCRM.com: Companies and Consumers Clash on Privacy Issues:

"Although the majority of businesses were found to underestimate the importance of their privacy policies and think they are unlikely to influence consumer perception, 51 percent of consumers surveyed said they avoid dealing with companies whose privacy policies make them uncomfortable. Simultaneously, consumers overestimated the amount of personal information that companies are legally allowed to collect about them, although businesses did admit to collecting some data to which they believe they are not entitled. "

Friday, January 30, 2004

Study: Wide Chasm Exists Between U.S. Businesses and Consumers Regarding Privacy and Trust Related to Personal Data

Thanks to beSpacific for the link to the following study from Accenture:

"Accenture Study Reveals Wide Chasm Exists Between U.S. Businesses and Consumers Regarding Privacy and Trust Related to Personal Data
Findings Point to Opportunity for Businesses to Build Trusted Relationships with Customers

NEW YORK; Jan. 27, 2004 - Fear of inadequate protection of personal data has compelled half of consumers to reject or cancel doing business with a company. This is just one of several findings of a survey of U.S. consumers and businesses on privacy, trust and access to personal data released today by Accenture. "

Interesting study, but the usual disclaimers apply.

Incident: Hackers may have accessed personal info for 20,000 Georgia students

Mercury News | 01/29/2004 | Hackers may have accessed personal info for 20,000 Georgia students: "Hackers may have accessed personal info for 20,000 Georgia students"

CNN.com - Hackers breach university server - Jan. 30, 2004: "ATHENS, Georgia (AP) -- Federal and state authorities are investigating whether hackers gained access to Social Security and credit card numbers of 31,000 University of Georgia students and applicants, officials said Thursday. "

Thursday, January 29, 2004

Sorry, but implementing privacy laws may upset some customers.

New laws, such as Alberta's new privacy law, often cause disruptions. There's a letter in the Edmonton Journal from an Epcor customer who is irate that she was not able to get information about her bill without her husband's OK. It appears that the account is in his name and EPCOR now has a policy that they won't give out information without the OK of the person whose name is on the account. I guess that seventeen years ago, when the account was opened, it didn't make any sense to put both names on it. More current practice that I've seen for new accounts is to ask the customer if they want an other person to have access to the account information. At least that was the case when I last set up an account with Aliant, my local phone company.

I have some sympathy for the writer of the angry letter:

"When I gave her my name she told me that due to the new provincial legislation regarding privacy and the disclosure of information to third parties, she could not talk to me. My husband was not at home at the time. I asked to speak to a supervisor and was given the same information.

I am livid. This account was established 17 years ago when we moved into our home and in fact our account is on Epcor's authorized payment withdrawal plan (we have a joint bank account).

The supervisor informed me that while we may have a joint account she still cannot talk to me. My husband would have to call Epcor and authorize them to add my name as a contact for our account! When he did call, they asked him for his date of birth for verification purposes. Turns out they have my date of birth on file.

I do not believe Epcor's practice is in the spirit of the new legislation. In fact, I called Shaw earlier this week where the account is also in my husband's name and had no problem talking with customer service about my account. "

While I may have some sympathy for her, the company in question is between a rock and a hard place, and it is better to err on the side of caution. They can't really rely on implied consent in this case, but one call from her husband should fix it.

I'm sure customers would be equally livid if they went through the experience of the guy in Missisauga Ontario whose ex-spouse received his cell-phone details without his consent, which were subsequently used against him and his mistress. (I can't find any other info on the story since the National Post took the September 27, 2003 story offline.) Philandering spouses usually don't get much sympathy, but the phone company was clearly in the wrong. It wouldn't take much imagination to imagine what sort of damage such a disclosure might have caused if it the records at issue were the calls made by an abused wife and the phone company had released records to an abusive spouse. Anybody thinking about what to do about releasing personal information really needs to weigh the inconvenience factor against the worst-case risk of harm. In light of the unfortunately reality out there, businesses really need to avoid accidentally giving the wrong people the tools to stalk, steal identities and commit violence. Unfortunately, nobody becomes aware of the disasters avoided.

Wednesday, January 28, 2004

"PIPEDA compliant" software

I am often perplexed by press releases and marketing speak that suggest that a piece of software can make your business "PIPEDA compliant" or "privacy compliant". I just came across the following (names are changed so that I'm not singling anyone out):

"XXXX upgrades e-mail marketing product

E-mail marketing service provider XXXX has released version XXXX of its e-mail marketing product, XXXX. The new release includes an improved spam-checker feature, certified compliance in support of Canada's new privacy law (PIPEDA) and significantly enhanced reporting capabilities."

What the heck does "certified compliance" mean? I looked at the company website and there was no certificate from anyone other than a web-seal of their privacy policy. No suggestion that their product has been certified as PIPEDA A-OK. I'm curious if my shoe can be "certified privacy compliant" since it doesn't collect, use or disclose personal information without written opt-in consent. The part that is particularly confusing in this release is the fact that their e-mail product includes what appear to be intrusive "enhanced reporting capabilities":

"Features of the improved reporting system include visual link tracking report (with colour-coding, marketers can now see where e-mail recipients have clicked in a visual representation of the actual e-mail that was sent) and drill-down reporting (all reports in the XXXX system now link e-mail addresses to a profile of that individual)."

Not only is privacy not a technology problem with a technology solution, it appears that an intrusive product that collects personal information without the individual's knowledge is being dressed up a privacy-friendly. Buyer beware!

Article: Ontario Privacy chief criticizes limits to health records

London Free Press: News Section - Privacy chief criticizes limits to health records:

"Privacy chief criticizes limits to health records
Ontario's information and privacy office called proposed legislation insulting and flawed.

TORONTO -- Forcing Ontario's information and privacy office to obtain warrants to ontain patient's medical records is a serious and insulting flaw in proposed legislation to protect the personal health information of individuals, says commissioner Ann Cavoukian. 'I am truly baffled. It makes no sense,' Cavoukian told reporters yesterday after appearing before a legislative committee studying the proposed bill. "

Tuesday, January 27, 2004

Conference: Securing Privacy in the Internet Age

Stanford's upcoming conference: Securing Privacy in the Internet Age:

A Stanford Law School Symposium: Securing Privacy in the Internet Age

What legal regimes or market initiatives would best prevent the unauthorized disclosure of private information while also promoting business innovation?

March 13-14 2004
Stanford Law School

As individuals do more – shopping, talking, working – on-line, they leave private information behind in databases stored on Internet-connected servers. Companies store proprietary data on networked servers connected to the Internet. Computer security experts struggle to develop technology and best practices to protect this information from unauthorized intruders or inadvertent leaks. Are private initiatives sufficient to protect private and confidential information, or should the law allocate the responsibility of keeping the server secure, and if so, on whom? And will the imposition of this legal and economic burden impede further exponential advances like those the computer industry has made in the past decade?

The Law, Science and Technology Program (LST) and the Center for Internet and Society (CIS) at Stanford Law School invite you to join us at a symposium where the speakers will present papers that address the ways in which application of various legal doctrines could induce software vendors, hardware companies and system administrators to adopt security-enhancing practices, report unauthorized disclosures of private information, properly value and remedy harm flowing from privacy breaches, while promoting vigorous competition and innovation.

Article: Microsoft, IBM, Philips to back RFID tracking technology

IDG.com.sg - Microsoft, IBM, Philips to back RFID tracking technology:

"'2004 is going to be a real crazy year for RFID,' said Evelien Vredeveld, IBM's worldwide RFID leader. 'Last year there was a lot of concern about privacy issues with RFID but this year, I think consumers will begin to learn the many benefits of the technology.' For example, if a product with the RFID tag breaks and needs to be returned to the store, the consumer won't need a receipt as all of that information will be part of the tag's data. "

Monday, January 26, 2004

Article: New call for cab cams

New call for cab cams:

VANCOUVER - The manager of a Vancouver taxi company is renewing his call for cameras in cabs, to protect drivers.

John Palis says there have been three vicious assaults on drivers in the past month, with the most recent attack just last Thursday.

A driver with Yellow Cabs was so badly beaten, he ended up in the intensive care ward at Vancouver General Hospital.

'I think that taxi drivers are vulnerable, because for one thing, for criminal or desperate criminals they're a quick source of cash,' he says.

Palis says cameras in cabs in Toronto and Winnipeg prevent assaults.

B.C.'s Information and Privacy Commissioner has expressed concern over the cameras, and has suggested that plastic shields might be a better solution. "