Saturday, November 10, 2007

Privacy laws and general cluelessness

Karen Selick, a lawyer from Belleville, has an opinion piece in a recent National Post going on a tirade against privacy laws. I can certainly see her point. But the problem is not the privacy laws themselves, but the general cluelessness of the people who cite them to avoid doing something they can and likely should do.

The examples raised by Ms. Selick are general bureaucratic nonsense, but I do agree that privacy laws are increasingly and incorrectly cited by people who should know better:

The CRA vs. Canadian men

Wednesday, November 07, 2007

It appears that the Canada Revenue Agency (CRA) has recently established a policy of ripping off divorced or separated men on the flimsiest of pretexts. Within the past month, two of my legal clients have had their spousal support deductions disallowed, despite having filed copies of the documents (court order or separation agreement) proving that they have to pay.

They've both received letters from CRA bureaucrats saying they must provide signed receipts from their estranged wives. Fat chance. The wives have no obligation to provide receipts. Many women in these circumstances would withhold receipts either as a bargaining tactic to exact some other concession, or from sheer malice.

...

I phoned the CRA and spoke to a "pre-assessment review officer." She told me that it was within an officer's discretion to accept other evidence of support having been paid, without insisting that a man approach a hostile wife for receipts, and that she herself would have accepted the copy of the wife's tax return. I suspected that her apparent reasonableness may have arisen because she was talking to an irate lawyer, so I pressed on, asking why the CRA would not, on its own initiative, simply compare the two tax returns and allow the husband's deduction so long as the wife had reported the same amount of income.

Oh no, she said, that would violate the privacy laws. If they allowed the man's deduction so easily, that would be tantamount to spilling some confidential information that the wife had provided on her return.

My mind boggled. The CRA would choose to overtax a man by thousands of dollars rather than have him infer, from the fact that his deduction was allowed, that his wife had complied with the Income Tax Act and reported the money he already knew he had given her.

Could anyone really believe that this is what the Privacy Act requires? What nonsense. Men wouldn't necessarily assume that the CRA had cross-checked their wives' returns. They'd just assume the deduction was allowed because they're legally entitled to it.

The Privacy Act and its private sector counterpart, the Personal Information Protection and Electronic Documents Act (PIPEDA), now loom up unexpectedly and absurdly in many situations, I've observed. Few people know what they really require, so they've become a bogeyman, lurking ominously in the background, waiting to trip up some insufficiently vigilant flunky. It's like being a kid again, worrying that Santa's always watching and will know if you'd been bad or good. When in doubt, don't stick your neck out by saying anything about anything, no matter how absurd and inconvenient the consequences may be to anyone else.

Here's another example: Last year, I spent nine hours at a hospital emergency ward with a relative, who ultimately died there following a stroke. Days later, I wrote a letter praising the three doctors and one nurse who had attended her for their diligence and compassion. I didn't know their names but asked the hospital to pass my letter on to them. Astonishingly, the hospital replied that doing so would violate the privacy laws, unless the deceased's executor consented. Huh? I was there. I watched them doing their jobs. They discussed things with me. I observed their competence and kindness. I wanted them to know that. How on Earth could it violate anybody's "privacy" for the hospital to pass along my letter?

Aah, PIPEDA -- I've pondered this farce before. Every divorce lawyer in the country collects and uses personal information about their clients' spouses. We couldn't do our jobs otherwise. Theoretically, PIPEDA says we're supposed to seek the opposing party's consent to collecting and using information about their incomes, their adultery, their alcoholism, their bankruptcies, etc. Never yet has another lawyer contacted a client of mine seeking consent, so I assume my colleagues are as mystified as I am over how we're supposed to comply. Legislation like this, applied in the ridiculous way in which it is so often applied, undermines respect for the law. And the law could sure stand a little respect these days.

The only thing that I'd add is the last paragraph is likely incorrect. The case between the spouses is not a "commercial activity" so PIPEDA would not apply to that, even if it is facilitated by a lawyer. No PIPEDA, no consent required.

Saturday, November 03, 2007

AOL to permit opting out of targeted ads

Apparently, AOL is going to permit users to opt out of online targeted advertising. See: AOL's 'Do Not Track' Effect - eMarketer.

Tuesday, October 30, 2007

Privacy and pre-employment screening

Yesterday, I spoke at the McInnes Cooper labour and employment group's annual conference. It's been going on for years, but it was my first time to attend. I was greatly impressed with the turnout of more than two hundred attendees.

I gave a presentation on privacy and pre-employment screening, which is here: Pre-employment screening.

Monday, October 29, 2007

Hitachi develops world's smallest RFID chip

Hitachi has just unveiled a new generation of tiny RFID chips that are .15 mm X .15 mm. They're so small, they're nicknamed "dust".

See: Hitachi Develops World's Smallest RFID Chip - TFOT.

Sunday, October 28, 2007

E-mail screw-up blows the whistle on whistleblowers

If this is true, it's pretty staggering.

The House Judiciary Commitee of the US Congress set up a form on its website to collect tips on misdeeds in the US Department of Justice from whistleblowers. A staffer recently sent an e-mail to all the would-be whistleblowers and put all the addresses in the "TO:" field on the outgoing e-mail. Oh, and s/he copied vice_president@whitehouse.gov. Not good at all.

See: TPMmuckraker Talking Points Memo D'Oh: House Panel Screw-Up Reveals Whistleblower Email Addresses.

Friday, October 26, 2007

Privacy and Personal Health Information

I spoke with the Health Law class at Dalhousie Law School about personal health information today. It focuses mainly on the situation in Nova Scotia, where we don't yet have personal health information legislation. Private practice physicians, physiotherapists, dentists, etc. are still subject to PIPEDA.

My presentation is here, if you're interested.

Facebook seeks identity of Canadian hackers

The National Post is reporting that Facebook is suing unnamed Canadian hackers for stealing pesonal information from the social networking site. In order to unmask the identity of the hackers, the company has taken Rogers and Look to court. Quite rightly (in my view), both ISPs are requiring a court order to hand over the info. See: Court urged to force Rogers, Look to release customer data. Via: Michael Geist - Facebook Seeks Court Order For Canadian ISP Customer Info.

Thursday, October 25, 2007

NB releases personal health information task force

Yesterday, the Government of New Brunswick's Task Force on Personal Health Information released its report, calling for the province to adopt legislation modeled on Ontario's Pesonal Health Information Protection Act. Newfoundland is advanced in this process and Nova Scotia is just about to embark on a similar project. For the report and all the background documents, see: Health - Personal Health Information Task Force.

Privacy and Law Enforcement

I was invited to be the keynote speaker at a half-day session put on today by the Canadian Bar Association - New Brunswick. I spoke about the current law related to the law enforcement access to personal information and an update on what's happing with "lawful access". Here's the presentation: click here (google Docs) or here (pdf).

I tried embedding it but it only worked if you are logged into a google account, which wasn't my intention.

Wednesday, October 24, 2007

Apparently, it's as simple as one word

The National Post has been running a series of articles on child abuse and child pornography. The last instalment delves into (just sticks its toe into, really) some of the debate that has been swirling around on "lawful access". The article is entitled "Words get in way of saving children" and the word being discussed is "may" in Section 7(2) of PIPEDA. If we could just change "may" to "shall" -- requiring ISPs to identify their customers -- the world would be a safer place for children. If only life were that simple. There really needs to be a much more nuanced debate about this.

Words get in way of saving children

Adrian Humphreys

National Post, with files from Allison Hanes, National Post

Wednesday, October 24, 2007

With a proliferation of horrific allegations in the headlines, Canadians can be forgiven for thinking that child molesters are everywhere. But what is the actual prevalence of the problem, and how should we be dealing with it? In this, the final instalment of a four-part series, the National Post looks at what the law-and-order approach prescribes and how the current system could be fixed.

---

Changing a single word in a seven year-old piece of legislation -- that was designed to support and promote electronic commerce in Canada -- could help save children from horrific sexual abuse, police officers and child protection advocates say.

It suggests that not all solutions to the problem of child sexual exploitation need to be buoyed by millions in capital infusion, backed by sweeping new laws, clouded by medical debate on effectiveness or spark public controversy over whether being soft or hard on pedophiles best helps curb their urges.

Experts who investigate pedophiles and work to help their child victims say that much more can be done in the realm of law and order to reduce the impact of the sexual predators among us. One of their targets is changing a three-letter word: "may."

Simply swapping the word "may" to "shall" in Section 7, Subsection 2 of the Personal Information Protection and Electronic Documents Act (PIPEDA) would be an easy step towards helping police intercept child molesters and pornographers, child advocates say.

The distinction may seem irrelevant to non-lawyers, but in the backrooms of some of Canada's Internet service providers and in the squad rooms of police forces across Canada there is a world of difference.

"The problem is, these cases move at the speed of light. Files are sent around the world, copied, downloaded and erased in seconds --by the time you get a search warrant it can be too late," said Paul Gillespie, who recently retired as the pioneering head of the Toronto police's Child Exploitation Section.

The existing guidelines on electronic documents state: "an organization may disclose personal information without the knowledge or consent of the individual," under certain circumstances, one of which is to police "carrying out an investigation relating to the enforcement of any such law or gathering intelligence for the purpose of enforcing any such law."

Police have found that when they have evidence of someone trading in child pornography over the Internet and they want to know where the activity is coming from, not all Internet service providers are forthcoming.

When some providers read the regulations, they see the disclosure of the customer's name and address as an option, not an obligation, and tell officers to come back when they have a court-authorized warrant.

Changing the rules from allowing ISPs to give a customer's name and address to police to requiring them to provide it would help, say police.

Staff Sergeant Rick Greenwood, manager of the RCMP's National Child Exploitation Coordination Centre, understands there are privacy concerns.

"All we care about is the starting point. We're after the customer's name and address," he said. The ISPs are not being asked to turn over billing records or credit card information; they are not giving police access to email in-boxes or Internet histories.

He likens it to a licence plate on a car.

"If you jump in your car and race off along a highway and hit a child, there is something we can do to investigate it. Someone can get a licence plate number or a description of the car," said Staff-Sgt. Greenwood.

"The same should be true for the Internet. If you jump onto the information freeway, you need to be accountable. "

Police would still need to get court authorization for any invasive investigation, such as reading email or tracking Internet activity, officers say.

However, red tape, a lack of resources, and poor enforcement of existing laws all help child abusers escape detection, or at least successful prosecution, activists say.

...