Sunday, May 14, 2006

Finding: Complainant objects to providing two pieces of ID to get own credit report

In this just-released finding, an individual complained that a credit bureau required that the individual provide two pieces of identification before providing him a copy of his credit report. The Commissioner consulted with another credit bureau and found that their policy was the same.

In this case, the Commissioner relied on principle 4.9.2, in which an organization can require additional information in order to fulfil an access request. The complaint was not well founded as the credit bureau has to authenticate an individual's identity before handing over this sensitive information. (As an aside: I expect they'd be risking a complaint about inadequate security if they did not do so.)

Read the finding here: Commissioner's Findings - PIPEDA Case Summary #324: Consumer complains about requirement to provide identification in order to obtain credit report (January 9, 2006)

Finding: Personal information practices considered in sale of dental practice

One of the most commonly identified "defects" with PIPEDA is that it does not contemplate and efficiently handle the disclosure of personal information in connection with the sale of a business, including pre-sale due diligence. This complaint dealt with the sale of a dentist's practice before the Ontario health information privacy law came into effect and was declared to be "substantially similar" to PIPEDA.

In this particular case, the complainant was given a "consent form" that contemplated that patient records may be disclosed in connection with the sale of the dental practice. It is not clear what the form actually said and whether it purported to obtain patients' consent. (Again, we have a situation where the lack of full detail in the summarized finding makes it very difficult to pull out best practices for the future.)

The Commissioner determined that the disclosure of certain patient records in connection with pre-purchase due diligence in this case was not contrary to PIPEDA. She reasoned:

  • Although the Personal Information Protection and Electronic Documents Act (PIPEDA) does not specifically contemplate any such collection, use or disclosure of personal information as described in the consent form, she noted that it was likely that a reasonable person would consider it appropriate for a dental office to disclose patient personal information to prospective buyers in order for the buyer to evaluate the practice, as per subsection 5(3).
  • The Commissioner also noted that dentists are subject to numerous regulations concerning privacy. Indeed, several regulations, policies, procedures, and laws apply to the disclosure of information: for example, Health Disciplines and Dentistry Acts, confidentiality agreements, and policies concerning personal information.
  • She stated that the Act also requires that personal information be safeguarded, and confidentiality agreements would meet such a requirement.
  • Given the above, the Commissioner was satisfied that the purpose, as described in the consent form, was an appropriate one.

Does this mean that a company that is not "subject to numerous regulations concerning privacy" can't disclose customer information as part of the sale process? I don't know.

Read the full finding here: Commissioner's Findings - PIPEDA Case Summary #325: Personal information practices considered in sale of dental practice (January 18, 2006)

Finding: Credit bureau required to set retention limit for positive information

In a finding by the Office of the Privacy Commissioner released on Friday, two individuals complained that a credit bureau was keeping positive credit information on file for too long. Retention of negative information is limited by provincial law, but there was no self-imposed retention period for favourable information. During the course of the investigation, the bureau decided on twenty years and also decided to give individuals the right to have it removed before then. The Commissioner therefore considered the complaint to be resolved.

See: Commissioner's Findings - PIPEDA Case Summary #326: Credit bureau sets retention period for positive information (January 18, 2006).

Saturday, May 13, 2006

TorStar consumer columnist focuses on three privacy complaints

The consumer columnist in the Toronto Star, Ellen Roseman, is focusing on three privacy-related complaints. See: TheStar.com - Playing fast and loose with privacy. Thanks to Pogo Was Right for the link.

War Amps reaches compromise agreement for key tag program in Alberta

Most Canadians are familiar with the War Amps key tag program. This amazing organization, whose chief purpose is to assist amputees in Canada, creates numbered key tags in a sheltered workshop and sends them to Canadians. If you put the tag on your keychain and your keys are lost, they'll find their way back to you if the finder drops them in a mailbox or calls the toll free number printed on the tag. One way that the organization has obtained names and addresses is through agreements with the provinces. Recently, they've encountered problems with the province of Alberta, where the Freedom of Information and Protection of Privacy Act limits the province's ability to disclose personal information to third parties. The Calgary Sun is reporting that the War Amps and the province have reached a deal that is a real compromise: all Albertans will be asked if they consent to the disclosure of their personal information when they renew their drivers' licenses. The War Amps is concerned that not all will consent and that it'll increase their costs. See: The Calgary Sun - Privacy form key to deal.

Friday, May 12, 2006

Nova Scotia's Personal Information International Disclosure Protection Act to die on the order paper

Nova Scotia's proposed Personal Information International Disclosure Protection Act is set to die on the order paper as the new Premier is expected to ask the Lieutenant Governor of Nova Scotia to disband the legislature and call an election for June 13.

For coverage of the imminent election call, see: The ChronicleHerald.ca: Premier poised for June vote: Election announcement "matter of hours now,’ Tory source says

For more on Bill 16, see The Canadian Privacy Law Blog: Bill 16: The Personal Information International Disclosure Protection Act (Nova Scotia) and The Canadian Privacy Law Blog: Nova Scotia introduces amendments to thwart USA Patriot Act.

More on LSAT fingerprinting

Phillipa Lawson of the Canadian Internet Policy and Public Interest Clinic has a thing or two to say about the practice of taking thumbprints from LSAT test-takers:

blog*on*nymity - blogging On the Identity Trail: Mandatory thumbprinting for the LSAT: an appropriate use of biometrics?:

...In any case, LSAC must still explain why other, less intrusive identification methods (such as the presentation of photo ID) are inadequate for the purpose of deterring fraud. Perhaps it is necessary to collect and store individual identifiers for some time after the test is administered, in order to be able to authenticate identities after the fact, in response to allegations of fraud. If so, are non-digitized thumbprints the least intrusive method? ...

For some additional background, see: The Canadian Privacy Law Blog: Complaint about LSAT fingerprinting

FTC settles with mortgage company for dumping customer applications

The US Federal Trade Commission has just settled a case with Nations Title Agency and its parent company, Nations Holding Company, for dumping customers' loan applications in dumpsters instead of properly disposing of them. There does not appear to be a fine involved. See:

Feds Ding Data 'Dumpster'

The Kansas City-based NHC settled with the FTC Wednesday, agreeing to not misrepresent the extent of its data protection safeguards. The company also agreed to establish and maintain a comprehensive information security program subject to third-party audits for the next 20 years.

Thursday, May 11, 2006

Cape Cod school runs criminal records checks on prom dates

Sorry folks, I don't make this stuff up ...

A school board on Cape Cod in Massachusetts has caused a minor kerfuffle by requiring students to fill out a form on their intended prom dates so that the school board can run a criminal records check on them. Tonya Dockray is a little peeved that her boyfriend's old pot bust means she'll be flying solo at the prom. Check it out: School Bans Some Dates From Senior Prom - Yahoo! News.

Update (20060513): Apparently the school authorities have backed off: BostonHerald.com - Local / Regional News: Prom-ising ending: School backs off ban on dates amid probe.

NSA collection of info on ordinary Americans wider than originally suspected

USA Today is reporting that the US National Security Agency, which has already been linked to warrantless wiretaps, has been collecting data on virtually all phone calls made in the United States of America since the end of 2001. The data for this mammoth collection effort was provided by AT&T, Verizon and BellSouth. While the contents of the calls are not reported to have been collected, the effort was focused at analyzing calling patters to ferret out terrorists.

From USA Today:

NSA has massive database of Americans' phone calls - Yahoo! News

The National Security Agency has been secretly collecting the phone call records of tens of millions of Americans, using data provided by AT&T, Verizon and BellSouth, people with direct knowledge of the arrangement told USA TODAY.

The NSA program reaches into homes and businesses across the nation by amassing information about the calls of ordinary Americans - most of whom aren't suspected of any crime. This program does not involve the NSA listening to or recording conversations. But the spy agency is using the data to analyze calling patterns in an effort to detect terrorist activity, sources said in separate interviews.

"It's the largest database ever assembled in the world," said one person, who, like the others who agreed to talk about the NSA's activities, declined to be identified by name or affiliation. The agency's goal is "to create a database of every call ever made" within the nation's borders, this person added.

For the customers of these companies, it means that the government has detailed records of calls they made - across town or across the country - to family members, co-workers, business contacts and others.

The three telecommunications companies are working under contract with the NSA, which launched the program in 2001 shortly after the Sept. 11 terrorist attacks, the sources said. The program is aimed at identifying and tracking suspected terrorists, they said.

The sources would talk only under a guarantee of anonymity because the NSA program is secret. ...