Thursday, March 29, 2007

Supreme Court to hear PIPEDA appeal

The Supreme Court of Canada has today granted leave to appeal a decision of the Federal Court of Appeal that held the Privacy Commissioner of Canada is not able to require an organization to disclose to the Commission information for which a claim of solicitor client privlege has been claimed.

For past coverage, see: Canadian Privacy Law Blog: Commissioner cannot compel privileged documents: FCA.

This will be an important case, both for PIPEDA and for the ability of non-court tribunals to evaluate claims of privilege.

TJX: At least 45.7M card numbers stolen

Sorry for the light blogging for the last little while. Busy times at work, two family weddings and March break for the kids intervened. But I'm back.

The Associated Press is reporting that TJX has disclosed that their recent breach compromised 45.7 million credit and debit card numbers (including mine). The breach went on for eighteen months and the card information the company had on file dated as far back as December 2002. See: TJX: At least 45.7M card numbers stolen - Yahoo! News.

Thursday, March 22, 2007

Alberta Commissioner upholds cameras in locker rooms at health club

This is likely to spur some interesting discussion:

OIPC

A complaint was made against the Organization which operates the “Talisman Centre for Sport and Wellness”. The Complainant stated that the Organization had placed overt security cameras in the Talisman Centre’s men’s locker rooms. The Complainant was concerned about a loss of privacy and that patrons of the Centre would be unable to change without being viewed by the cameras. The Organization stated that the security cameras were installed in 1997 in response to over 900 incidents of theft and property damage during the years 1994-97. The security cameras were installed after all other means to prevent criminal activity had failed. The cameras’ field of vision was restricted to the lockers and had no zoom, panoramic or audio capabilities. The cameras were not actively monitored and a protocol was in place which restricted the viewing of images to instances where there was an incident or reported criminal activity with a case number assigned by the Calgary Police Service. Viewing of the images occurs only in the presence of two senior staff members or by one such member and a police constable. If images are not reviewed they are automatically overwritten in approximately 21 days. After installation of the cameras there was a sharp reduction in criminal activity. As of the date of the Organization’s submission to the Commissioner only 19 images had ever been viewed. The Commissioner found that due to the history of theft, the attempt to use other measures prior to using security cameras as a last resort, and the fact that the images recorded were only accessed in the event of a criminal incident, that the Organization’s collection of personal information was for purposes that were reasonable, as required by section 11(1) of the Personal Information Protection Act (“PIPA”). However, the Organization’s signage was not in compliance with section 13(1) of PIPA. The Commissioner ordered the Organization to change the signage.

Click to view more information Order P2006-008

Wednesday, March 21, 2007

FBI confirms contracts with telcos for providing customer info

This is interesting.... From WIRED Blogs: 27B Stroke 6


FBI Confirms Contracts with AT&T, Verizon and MCI

The FBI's general counsel, Valerie Caproni, testified today on Capitol Hill that the FBI entered into contracts with AT&T, Verizon and MCI to harvest phone records on American citizens under a national security letter program that has come under fire from Congress and the Justice Department's Office of Inspector General for circumventing privacy laws.

Caproni confirmed during a House Judiciary hearing that AT&T and Verizon, which bought MCI in 2005, had and continue to have contracts with the FBI that compensate phone companies for turning over the toll records of customers connected to counterterroism investigations. The telecoms entered into the contracts in May 2003, according to the report issued last week by the DoJ Inspector General.

"The contract essentially pays for the man hours or the personnel cost for the people who have to do the work," said FBI Assistant Director John Miller in an interview with Wired News last night. "We want dedicated people who handle our requests or do nothing else."

Saturday, March 17, 2007

Equifax and Privacy Commissioner settle spat over audit

In August 2006, the Privacy Commissioner of Canada initiated an audit of Equifax under PIPEDA, which requires reasonable grounds to believe the audited company is in breach of the law. Equifax sought judicial review of that decision, arguing that the Commissioner did not have the grounds to initiate an audit. The parties have now settled the judicial review proceeding and it appears the audit is close to being concluded.

CNW Telbec

Privacy Commissioner works with Equifax to conclude audit

OTTAWA, March 16 /CNW Telbec/ - The Office of the Privacy Commissioner of Canada announced today that it has successfully negotiated a resolution with regard to litigation involving its audit of the credit reporting agency, Equifax.

The Commissioner's Office launched an audit of Equifax in August 2006 under the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's private sector privacy law. The intention was to audit the personal information management practices of Equifax and, more specifically, its online identification and authentication system. The Office has since published guidelines for businesses on identification and authentication, which are available on its web site.

Under section 18(1) of PIPEDA, the Commissioner may audit the personal information management practices of an organization if she has reasonable grounds to believe that the organization is contravening a provision of the Act.

Equifax had launched an application for judicial review, challenging whether the Privacy Commissioner's Office had reasonable grounds to conduct the audit in the first place. The two parties recently negotiated a resolution, the details of which are in the court documents. A notice of discontinuance and minutes of settlement were filed with the Federal Court on March 14, 2007.

"I am pleased that Equifax agreed to discontinue their court challenge because it is important for us to make use of all the tools at our disposal, including exercising our powers to audit personal information management practices in the private sector," said Jennifer Stoddart, Privacy Commissioner of Canada. "Ultimately, what we determine in our work can only be of benefit to the organizations involved and their customers."

Throughout the course of the litigation, the Office's audit of Equifax remained ongoing and a report will be provided to the credit reporting agency.


The Office of the Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of the privacy and protection of personal information rights of Canadians.

Friday, March 16, 2007

FTC investigating TJX, Winners parent company

This really shouldn't be a big surprise:

FTC Launches Investigation Of T.J. Maxx Parent Company - Yahoo! News

The U.S. Federal Trade Commission Tuesday confirmed that it has launched an investigation of TJX, the parent company of T.J. Maxx, Marshalls, HomeGoods, and other stores. While the FTC wouldn't reveal the nature of the investigation or when it began, it's likely the result of a large data breach that allowed cyberintruders to steal customer data.

Should TJX be worried? During the past few years, ChoicePoint showed everyone just how much power the FTC wields. That company wound up paying $10 million in civil penalties and $5 million in customer redress after it handed over consumers' names, addresses, Social Security numbers, and credit reports to fraudsters working out of Los Angeles County. But the monetary penalty is just the beginning, says Jo Anne Adlerstein, an attorney with Thelen Reid Brown Raysman & Steiner LLP. ChoicePoint also had to implement a new IT security system, and their security systems will be audited every two years for the next 20 years. If TJX is found to be in violation of privacy laws, "it will be the beginning of an ongoing relationship with the FTC," she says.

The FTC's investigation of TJX should put all companies that handle customer data on notice. "Companies must think in terms of, 'What if the FTC stops by to see me tomorrow? What will they find?'" Adlerstein says....

Thursday, March 15, 2007

Dion pledges breach notification if he's elected PM

Stephane Dion, the leader of the Liberal Party of Canada, pledged in a speech yesterday to require breach notification if he becomes Prime Minister. He also pledged to implement the recommendations of the federal Anti-Spam Task Force:

Liberal.ca :: Speeches:

Protecting Our Homes and Our Rights March 14, 2007

...

  • To protect Canadian seniors, we will act on the recommendations of the Privacy Commissioner to address the problem of identity theft. There were almost 8,000 reports of identity theft in the past year, resulting in more than $16 million being lost, much of it taken from vulnerable seniors. A lifetime of hard work and savings can vanish in an instant. We need tougher laws to prevent this kind of crime.
  • One of the main recommendations of the Privacy Commission is that we need to change private-sector privacy laws, so companies are forced to notify customers when their personal information gets leaked. If your social security number gets into the wrong hands, you deserve to find out about it, so you can avoid becoming a victim of identity theft. This kind of change would finally cause businesses to take the security of their customers more seriously.
  • Another recommendation is that we need laws implementing the recommendations of the federal Task Force on Spam – recommendations that have so far been ignored by the Conservatives. Spam is the weapon of choice for identity thieves, who use phony e-mails to trick people into revealing personal information. Canada is the only G-8 country without anti-spam legislation, and a Liberal government led by me will change that.

Thanks to Michael Geist for pointing me to Dion's speech.

PS: I'm not sure why the first point is solely for the protection of seniors.

Saved searches provide the smoking gun in muder case

Speaking of Google and privacy, here's an interesting story. The data came from the computer of the accused, but ...

Welcome to www.dailyrecord.com - Updates - Cop: Wife googled 'How to commit murder':

"At exactly 5:45:34 on April 18, 2004 a computer taken from the office of the attorney of Melanie McGuire, did a search on the words 'How To Commit Murder.'

That same day searches on Google and MSN search engines, were conducted on such topics as `instant poisons,` `undetectable poisons,' 'fatal digoxin doses,' and gun laws in New Jersey and Pennsylvania.

Ten days later, according to allegations by the state of New Jersey, McGuire murdered her husband, William T. McGuire, at their Woodbridge apartment, using a gun obtained in Pennsylvania, one day after obtaining a prescription for a sedative known as the 'date rape' drug...."

Librarians to talk about Patriot Act challenge in Vermont

Seven Days, the Vermont alternative web weekly is running a preview of a presentation to be given by Peter Chase and George Christian later this month. Both are librarians who were on the receiving end of national security letters under the USA Patriot Act and fought them with the assistance of the ACLU.

If I get my hands on the presentation materials, I'll post them here.
Seven Days: Librarians, No Longer Gagged, Detail Patriot Act Abuses

WINDSOR, CT — In September 2003, then-U.S. Attorney General John Ashcroft ridiculed the American Library Association for its “breathless reports and baseless hysteria” about a USA PATRIOT Act provision that allows FBI agents to search library records without a warrant. Until he left office in early 2005, Ashcroft repeatedly denied that the feds were snooping into Americans’ reading habits and computer activities.

In July 2005, Peter Chase and George Christian discovered firsthand that Ashcroft was lying. They couldn’t tell anyone, though — not friends, co-workers or family members — even as Congress debated the Patriot Act’s reauthorization.

Christian is executive director of the Library Connection, a nonprofit consortium in Windsor, Connecticut. Chase is president of the group’s executive committee and director of one of its 27 member libraries. An eight-month gag order prevented them from disclosing that they’d received a “national security letter” from the FBI seeking confidential library computer records.

“We were shocked,” Chase recalls. “None of us had ever heard of a national security letter before.”

....

Chase and Christian, along with fellow committee members Barbara Bailey and Janet Nocek, decided to fight the warrantless search. Though the librarians were never told why the FBI wanted their files, a federal prosecutor later disclosed that it was a matter of “domestic surveillance.”

The Connecticut librarians have since been released from their gag order. On March 20, they’ll speak at the University of Vermont about how they fought the Patriot Act — and won. Civil libertarians say their case is a chilling example of the threats to privacy rights in the post-9/11 era.

“My initial twinge in opposing [the FBI] was that I was aiding and abetting a catastrophe,” recalls Christian. “But right away, I could glean that they weren’t worried that someone was going to cause a catastrophic event tomorrow.” The letter, he notes, was dated two months earlier, and the records the FBI wanted were six months old. In Connecticut, as in 47 other states, library records are protected by law.

Vermont’s own protections for library records aren’t as strong as those in other states, notes Trina Magi, who chairs Vermont’s Intellectual Freedom Committee. Though library records are exempt from the open-records law, she says, nothing explicitly prevents librarians from disclosing them. Moreover, last year’s Patriot Act reauthorization did nothing to alleviate librarians’ concerns.

“What people read at libraries is confidential,” Chase argues. “People should feel free to come to the library and look up whatever information they need, without thinking that Big Brother is looking over their shoulder.”

In August 2005, the Connecticut librarians sued the federal government, with help from the ACLU. Initially, they were collectively known as “John Doe.” However, because of sloppy redacting of court records by government attorneys, Christian’s and Chase’s identities were made public, and reporters soon came calling.

...

Even after the librarians’ names were known, the gag order still barred them from discussing their case. Those restrictions reached absurd proportions. When the government asserted that the librarians’ presence in federal court in Bridgeport raised a “national security issue,” they had to watch the proceedings on closed-circuit TV from a locked courtroom in Hartford. When an appeal was heard in federal court in Manhattan, the librarians were allowed to attend but were prohibited from entering the courtroom together, sitting together, speaking to each other, or making eye contact with their attorneys.

Tellingly, the librarians were released from the document request and gag order shortly after the Patriot Act was reauthorized in March 2006. Once the government dropped its appeal, the librarians lost their legal standing to challenge the statute’s constitutionality.

Today, Christian is troubled by how many Americans have apparently complied with NSL requests. “I’m trying to figure out in my mind how 30,000 NSLs can be issued each year,” he says, “and in five years only two people have said, ‘I don’t think so.’”

Peter Chase and George Christian give a lecture titled "Gagged by the Government: Two Librarians Tell How They Resisted the USA PATRIOT Act." Tuesday, March 20, 3:30-5 p.m. Bailey Howe Library, University of Vermont. Free. Info, 656-5723.

Wednesday, March 14, 2007

Google to anonymize older data

This is an interesting development, though some think it is too late and doesn't go far enough:

Official Google Blog: Taking steps to further improve our privacy practices

3/14/2007 03:00:00 PM

Posted by Peter Fleischer, Privacy Counsel-Europe, and Nicole Wong, Deputy General Counsel

When you search on Google, we collect information about your search, such as the query itself, IP addresses and cookie details. Previously, we kept this data for as long as it was useful. Today we're pleased to report a change in our privacy policy: Unless we're legally required to retain log data for longer, we will anonymize our server logs after a limited period of time. When we implement this policy change in the coming months, we will continue to keep server log data (so that we can improve Google's services and protect them from security and other abuses)—but will make this data much more anonymous, so that it can no longer be identified with individual users, after 18-24 months.

Just as we continuously work to improve our products, we also work toward having the best privacy practices for our users. This includes designing privacy protections into our products (like Google Talk's “off the record” feature or Google Desktop’s “pause” and “lock search” controls). This also means providing clear, easy to understand privacy policies that help you make informed decisions about using our services.

After talking with leading privacy stakeholders in Europe and the U.S., we're pleased to be taking this important step toward protecting your privacy. By anonymizing our server logs after 18-24 months, we think we’re striking the right balance between two goals: continuing to improve Google’s services for you, while providing more transparency and certainty about our retention practices. In the future, it's possible that data retention laws will obligate us to retain logs for longer periods. Of course, you can always choose to have us retain this data for more personalized services like Search History. But that's up to you.

Our engineers are already busy working out the technical details, and we hope to implement this new data policy over the coming months (and within a year's time). We’ll communicate more as we work out these details, but for now, we wanted you to know that we’re working on this additional step to strengthen your privacy.

If you want to know more, read the log retention FAQ (PDF).

There's more here: WIRED Blogs: 27B Stroke 6: Google To Anonymize Data -- Updated. And here: Google adopts tougher privacy measures.

Thanks to Boing Boing for the tipoff.