Wednesday, April 28, 2004

Article: Workplace privacy gets day in court

Today's Globe and Mail Careers section has an interesting article on workplace privacy. The article begins with an introduction to the first case (PIPEDA Case Summary #114) on this topic to make it to the Federal Court of Canada.

The Globe and Mail: Workplace privacy gets day in court:

"Every time Erwin Eastmond goes to work, he is being watched.

Cameras set up around Canadian Pacific Railway Ltd.'s maintenance shop in Scarborough, Ont., make it impossible for the 200 workers in the facility to avoid having their movements tracked by an array of security cameras. And that, Mr. Eastmond says, 'makes us very uneasy.'

So uneasy that Mr. Eastmond, a diesel engine electrician, lodged a complaint last year with the Privacy Commissioner of Canada. It has led to a landmark federal court case over surveillance in the workplace that was argued before a justice last week.

The case has become the biggest test to date of Canada's legal protections for the privacy of Canadian workers from a proliferation of sophisticated and inexpensive monitoring technology."

Full article ...

Wednesday, April 21, 2004

Article: Privacy issues develop over work done overseas

The issue of the privacy of personal information shipped overseas in connection with outsourcing is not a new issue, but an important one ...

Duluth News Tribune | 04/18/2004 | Privacy issues develop over work done overseas:

"The growing business of shipping sensitive personal data overseas threatens the privacy rights of U.S. citizens, according to Sens. Hillary Rodham Clinton, D-N.Y., Bill Nelson, D-Fla., and other foes of outsourcing.

Clinton is pushing legislation that would make U.S. businesses legally liable if a foreign subcontractor abuses American privacy laws.

The bill also would require U.S. businesses -- such as accounting firms, physicians, hospitals and banks -- to gain consent from consumers before shipping their private data to an overseas contractor if the Federal Trade Commission has determined that the country where the contractor is based doesn't have adequate privacy laws.

The privacy issue gained the attention of lawmakers after a Pakistani woman, Lubna Baloch, who transcribed confidential medical records of patients at UC San Francisco Medical Center, threatened to post them on the Internet last October unless the hospital helped her collect an overdue bill from a man who hired her as a medical transcription subcontractor.

Baloch withdrew her threat after she was paid.

Sue Blevins, president of the Institute for Health Freedom, a nonprofit concerned with medical privacy, said if personal information like mental illness, alcoholism treatment, marriage counseling, illegal drug use or a sexually transmitted disease gets out to the public, 'it could be devastating and cause emotional pain and affect people's career, families or even the ability to get a mortgage.'"

As I've said before, nearshore outsourcing to places like Nova Scotia does not have the same risk as outsourcing to Asia. Check out Nova Scotia Business Inc.

Article: Privacy issues develop over work done overseas

The issue of the privacy of personal information shipped overseas in connection with outsourcing is not a new issue, but an important one ...

Duluth News Tribune | 04/18/2004 | Privacy issues develop over work done overseas:

"The growing business of shipping sensitive personal data overseas threatens the privacy rights of U.S. citizens, according to Sens. Hillary Rodham Clinton, D-N.Y., Bill Nelson, D-Fla., and other foes of outsourcing.

Clinton is pushing legislation that would make U.S. businesses legally liable if a foreign subcontractor abuses American privacy laws.

The bill also would require U.S. businesses -- such as accounting firms, physicians, hospitals and banks -- to gain consent from consumers before shipping their private data to an overseas contractor if the Federal Trade Commission has determined that the country where the contractor is based doesn't have adequate privacy laws.

The privacy issue gained the attention of lawmakers after a Pakistani woman, Lubna Baloch, who transcribed confidential medical records of patients at UC San Francisco Medical Center, threatened to post them on the Internet last October unless the hospital helped her collect an overdue bill from a man who hired her as a medical transcription subcontractor.

Baloch withdrew her threat after she was paid.

Sue Blevins, president of the Institute for Health Freedom, a nonprofit concerned with medical privacy, said if personal information like mental illness, alcoholism treatment, marriage counseling, illegal drug use or a sexually transmitted disease gets out to the public, 'it could be devastating and cause emotional pain and affect people's career, families or even the ability to get a mortgage.'"

As I've said before, nearshore outsourcing to places like Nova Scotia does not have the same risk as outsourcing to Asia. Check out Nova Scotia Business Inc.

Tuesday, April 20, 2004

Article: CRIA to appeal file sharing ruling

Following it's widely publicized loss in the Federal Court of Canada (see previous blog entry), CRIA has filed an appeal of Justice Finckenstein's ruling. Google news links to loads of coverage, such as this from the Globe and Mail:

Globetechnology: "The Canadian Recording Industry Association has filed an appeal of the recent court decision denying CRIA's request for Internet Service Providers to reveal the identities of alleged uploaders of digital music. ...

"Today we filed an appeal of last month's court decision," CRIA General Counsel Richard Pfohl said in a statement. "We will argue that the decision was in error on a number of legal bases.

"In our view, Canadian copyright law does not allow people to make copies of hundreds or thousands of musical recordings for global copying, transmission and distribution to millions of strangers on the Internet," he said.

"Any owner of intellectual property that can be digitally transmitted has a stake in this appeal process," CRIA president Brian Robertson said.

The appeal comes at a time when news of the recording industry's profits or losses have been highly contradictory."

Monday, April 19, 2004

Article: Weak enforcement undermines privacy laws

Michael Geist, one of Canada's most respected technology lawyers, has a very interesting comment in Today's Toronto Star. He argues that the federal Privacy Commissioner needs to take some affirmative steps before privacy protection in Canada becomes more bark than bite. In many ways, the Commissioner's office is hamstrung by a lack of resources following the scandals involving the former Commissioner, George Radwanski.

TheStar.com - Weak enforcement undermines privacy laws:

"If the commissioner's office is to take the lead on cutting edge issues and increase its enforcement activity, the federal government must step up to the plate to provide it with much-needed resources.

In the wake of last year's scandal involving former privacy commissioner George Radwanski, the office has faced significant budget pressures that have constrained new hiring and sadly transformed the current privacy legislation into a complaints-only-driven process.

While there is no doubt the will at the commissioner's office to ensure that PIPEDA meets expectations, the federal government must help pave the way.

It is evident that privacy laws without effective enforcement and genuine transparency may provide Canadians with little more than placebo privacy protection.

Ensuring that this does not happen is, in the words of the privacy commissioner, a question of responsibility."

Full article ...

Saturday, April 17, 2004

Privacy Officer Training

National Privacy Services Inc. is going to be offering its Privacy Officer Training program in Ottawa (May 19-20) and Toronto (May 17-18) next month. The two-day course is designed to provide the necessary training and tools for businesses to begin to implement privacy law compliance in their organizations. The course was originally designed by McInnes Cooper's privacy law practice group when clients regularly asked how and where privacy officers can get the training necessary to undertake the role in an informed and professional manner. The brochure [PDF] is available from the National Privacy Services Inc. website.

The two-day privacy officer training program provides an in-depth review of PIPEDA and its myriad exceptions. Key decisions of the Office of the Privacy Commissioner are reviewed, as are security and privacy issues. It also includes specific assistance for dealing with inquiries and complaints.

Wednesday, April 14, 2004

Article: New privacy sprouts forest of complaints

Today's Toronto Star has a very interesting article that highlights something that I have been trying to emphasizes to my clients for some time: the most important thing that a business must do to comply with PIPEDA and to avoid complaints is to communicate with its customers. Principle 2, from the CSA Model Code, requires a business to take reasonable steps to bring to an individual's attention the purpose for which information is being collected. This communication forms the foundation for the "knowledge and consent" that are required under "Principle 3 - Consent". Many commentators emphasize that PIPEDA is about consent, but this consent has to be based on the identification of purposes. If you tell you customers what you propose to do, there won't be any uncertainty or confusion and, therefore, the business is much less likely to get a complaint.

TheStar.com - New privacy sprouts forest of complaints:
"Canada's privacy watchdog says a 'communications gap' forming between businesses and consumers may be partly to blame for an increase in complaints since new federal privacy legislation went into full force on Jan. 1.

The law requires businesses, large and small, to put systems in place that will make sure customer information is secure, accurate, gathered with consent and not used beyond a stated purpose.

Heather Black, assistant federal privacy commissioner, said Canadians are taking advantage of their newfound privacy rights but many businesses, when asked to explain how and why they collect and use customer information, aren't providing adequate answers.

'When people ask why they're being asked for this information, they're not getting very satisfactory responses,' said Black. 'So it really is a communications gap.'

The commission began noticing this trend in January, specifically in the retail sector. Black said a number of people have filed complaints against certain retail outlets that require customers to provide their names, phone numbers and addresses when goods are returned for refund or exchange."

Full article ...

Monday, April 12, 2004

Article: Employment law myths

In today's National Post, Howard Levitt, counsel to Lang Michener, takes a pretty aggressive stand with respect to PIPEDA. His sentiments about the constitutionality are shared by others, but I was surprised to read that he suggests ignoring PIPEDA. Most privacy lawyers with whom I speak are of the view that PIPEDA should be followed until it is declared to be unconstitutional:

"4. Privacy legislation applies across Canada.

The federal privacy legislation constitutionality provided that, if similar legislation was not passed in each province by January 1, 2004, the federal legislation would apply provincially. Many provinces, including Ontario, have not yet passed Privacy Acts. However, virtually everyone is conducting themselves as if the federal privacy legislation applies. It does not. Despite the wording of that legislation, the federal government lacks the constitutional power to impose privacy legislation on the provinces and no attempt to do so would survive legal challenge. Therefore, contrary to seemingly everyone's belief, there is presently no effective, binding privacy legislation in most of Canada."

This is very aggressive and, at least to this point, many Courts have been applying PIPEDA without hesitation. It is true that the federal government has no constitutional way to regulate the provincially regulated workplace, but PIPEDA does not purport to operate there.

Saturday, April 10, 2004

Correction re: Mathew Englander

Mathew Englander, to whom I referred a while back, has e-mailed me a correction about an entry in PIPEDA and Canadian Privacy Law. I had been told that his complaint had arrived by e-mail, having been sent at the stroke of midnight 2001. Mr. Englander writes:

I just came across the reference to me on your blog (http://pipeda.blogspot.com/2004_01_04_pipeda_archive.html#107338559447219057).

It's ironic that your "sources at the Office of the Privacy Commissioner" infringed on my privacy by telling you that my complaint "was sent by e-mail on January 1, 2001 at 12:01 am." The Privacy Commissioner should not unnecessarily divulge details about complaints and complainants.

In any event the information is wrong. I did not file my complaint by e-mail.

You can post this email on your web site if you like, but of course not my email address (which is a disposable address anyway).

Mathew Englander

As they say, it is always better to get your information first hand ...

Wednesday, April 07, 2004

Article: Privacy officer for hire

Since the launch of National Privacy Services, we've gotten some quite favourable coverage in the media. ConnectIT had the following article in today's edition:

[ ConnectIT e-News Daily ]:
"Privacy officer for hire
6 April, 2004
by Liam Lahey

Security solutions provider Thor Solutions Inc. and law firm McInnes Cooper have teamed up to form National Privacy Services Inc. (NPSI) � a partnership designed to help small to mid-sized businesses (SMBs) understand and comply with Canada�s federal privacy legislation.

According to David T.S. Fraser, chair of McInnes Cooper's privacy group in Halifax, NPSI helps SMBs avoid the expense of building a solution from scratch, spending a great deal of time trying to become privacy experts themselves, and/or ignoring the legislation and risking their businesses by being identified as non-compliant. "

Full article ...