Thursday, October 11, 2012

Canadian internet surveillance bill dying in Parliament

John Ibbitson writes in the Globe & Mail that Bill C-30 isn't just dying, it's pretty well dead.

It hasn't gone to committee, it hasn't gone anywhere. It's just silently decaying on the order paper.

Let me be among the first to throw a shovel of dirt on its grave.

Here's Ibbiton's opinion piece:

John Ibbitson: The quiet death of the Internet surveillance bill - The Globe and Mail: What Parliament isn’t debating can be as interesting as what it is debating. This fall it emphatically isn’t debating Bill C-30.

That’s because, for all intents and purposes, the Conservatives’ Internet surveillance legislation is dead.

C-30, you will remember, would grant the federal government and law enforcement agencies the power to obtain information about individuals who are online without having to apply for a warrant.

You will also remember that Public Safety Minister Vic Toews endured a world of hurt back in February when he told critics of the bill that they could “either stand with us or with the child pornographers.”

Stung by the widespread opposition, including from the federal and provincial privacy commissioners and from within its own caucus, the Conservative government said it would refer the bill to a committee.

Last May, your correspondent was rebuked by Mr. Toews for writing that the bill was, in reality, “dead in the water.”

“Our government has been very clear, that matter will be referred to a parliamentary committee,” he insisted.

But the five hours of debate needed before the bill could be referred to the committee didn’t happen that May. It didn’t happen in June. It didn’t happen in September, when the House returned from summer recess. October? So far, nada.

When asked when and whether C-30 would come before the House this autumn, Mr. Toews’ spokeswoman, Julie Carmichael, said by email: “Our government is thoroughly reviewing this legislation.

“At all times we will strike an appropriate balance between protecting privacy and giving police the tools they need to do their job,” she wrote.

Which may be another way of saying the Internet surveillance bill is not just dead in the water – it’s at the bottom of the sea.

Nathan Cullen, House Leader for the NDP, says he has asked about the status of C-30 at virtually every one of his weekly meetings with Conservative House Leader Peter Van Loan.

“I always get the exact same answer back, which is a non-answer,” said Mr. Cullen in an interview.

“I don’t know whether it was because the Minister so screwed up the messaging, or whether they’ve had some other input saying they went too far or it just can’t be salvaged,” he speculates.

What isn’t speculation is that the Internet bill has disappeared from the radar – for good, it would appear.

Stephen Harper is likely to have Parliament prorogued this coming winter, in anticipation of a major cabinet shuffle and a throne speech to mark the halfway point in his majority government. With prorogation, C-30 will die on the order paper, unmourned.

A new Public Safety Minister may introduce new lawful access legislation that would require a judicial warrant before anyone could compel an Internet Service Provider to divulge information about a client.

But that’s down the road. What matters is this: If you’re with the child pornographers, or with the privacy commissioners, or with at least some of the Tory caucus, or with the millions of other Canadians who want to limit the power of the federal government to snoop online, you can forget about C-30.

The Tories appear content to leave this political shipwreck alone.

Friday, October 05, 2012

Canadian IT Law Association annual conference coming up ...

All Canadian privacy and nerd-law types take note:

The Sixteenth Annual Canadian Information Technology Law Association (“IT.CAN”) Conference will be held in Montreal, QC, October 29-30, 2012. For the full conference brochure including registration details, visit the association's website at www.it-can.ca. If you have any questions about the program please contact Lisa Ptack, IT.CAN Executive Director at lisa.ptack@rogers.com.

The speakers and content at the IT.Can conference are always top-notch (despite the fact that I'm speaking on privacy topics on the Monday).

Thursday, October 04, 2012

Libraries, privacy law and dealing with law enforcement requests for patron information

I was recently invited by a group of regional librarians in Nova Scotia to speak with them about libraries, privacy law and dealing with law enforcement requests for patron information.

While it's a pretty narrow niche, here's my presentation in case you're interested ...



Update (2012-10-05): In Nova Scotia, public libraries are "public bodies" governed either by the Freedom of Information and Protection of Privacy Act or Part XX of the Municipal Government Act. Both statutes permit public bodies to disclose personal information to law enforcement for law enforcement purposes without the consent of the individual. However, just because a library can make such disclosures doesn't automatically lead to the conclusion that a library should.

The Canadian Library Association has taken some strong positions on patron privacy, such as the Position Statement on Citizenship Access to Information Data Banks - Right to Privacy made in 1987 which includes:

Therefore, to protect the personal rights and privacy of users to consult and borrow library materials without prejudice, the Canadian Library Association endorses the following policy: That names of library users not be released to any person, institution, association or agency for any reasons save as may be legally required by Federal or Provincial laws.

The CLA's earlier (1976) Statement on a Code of Ethics includes general support for patron privacy:

Members of the Canadian Library Association have the individual and collective responsibility to:
  1. support and implement the principles and practices embodied in the current Canadian Library Association Statement on Intellectual Freedom;
  2. make every effort to promote and maintain the highest possible range and standards of library service to all segments of Canadian society;
    facilitate access to any or all sources of information which may be of assistance to library users;
  3. protect the privacy and dignity of library users and staff.

Both of these policy statements support the proposition that patron information should only be disclosed where required by law, not just as permitted by law.

In my view, libraries should develop a written policy on interactions with law enforcement that are consistent with a librarian's ethical obligations to protect patrons, which would govern the exercise of discretion. One might come to the conclusion that information about a patron's use of library resources (such as books, computers, etc) would only be provided pursuant to a warrant or a production order while less sensitive information (was a person at the library at a particular time) may be provided without lawful compulsion. The policy should also say who is able to exercise discretion and make decisions on behalf of the library, with a general prohibition against all disclosures by anyone other than the sanctioned decision-makers.

In order to minimise confusion and clarify processes, such policies should be clearly communicated to local law enforcement.

Finally, I should note that the above is meant to be educational, to assist librarians in seeking proper legal advice on this sensitive topic. Above all, this should not be construed as legal advice.

Privacy Commissioner tables annual public sector privacy report

The Privacy Commissioner of Canada tabled her annual report to Parliament on the Privacy Act, highlighting many challenges with the protection, use and disclosure of personal information in the federal public sector. Here's the media release with links to the report:

News Release: Privacy Commissioner highlights need for better protection of personal information by federal departments and agencies - October 4, 2012:

Privacy Commissioner highlights need for better protection of personal information by federal departments and agencies

Veterans Affairs Canada audit outlines effort to regain confidence

OTTAWA, October 4, 2012 – There is a continued rise in the level of privacy complaints about government by the public, along with greater delays in responding to requests by people seeking access to their personal information, according to Jennifer Stoddart, Privacy Commissioner of Canada, in her 2011-12Privacy Act annual report which was tabled today in the Parliament. The Commissioner’s report provides details on investigation findings and privacy trends across federal departments and agencies, and also includes the conclusion of an audit into the privacy practices of Veterans Affairs Canada (VAC).

Veterans Affairs Canada audit concludes

The audit of VAC conducted by the Office of the Privacy Commissioner of Canada (OPC) followed a 2010 investigation which uncovered some serious systemic privacy issues involving the handling of veterans’ personal information. Specifically, it was found that a veteran’s sensitive medical information was shared among officials who lacked a legitimate need to see it. Some health information even ended up in ministerial briefing notes detailing the veteran’s advocacy work.

The audit found that VAC has made significant improvements to its privacy practices. For example, following the OPC investigation, VAC reviewed access rights to veterans’ electronic records and subsequently removed privileges outright for some 500 employees while reducing them for 95 percent of others. Investments have also been made in monitoring access to files, educating employees, and developing new policies, procedures and guidelines to respect privacy.

“The Department has agreed to implement all of our 13 audit recommendations and we are pleased with progress made to date,” said Commissioner Jennifer Stoddart, noting that the Office will follow-up with VAC within two years.  “I’m satisfied that our findings paint an encouraging picture of a department now working to better ensure that its practices comply with the Privacy Act. It is clear that senior management has implemented structures and control mechanisms to move the department from one that merely reacts to privacy issues to one capable of addressing them systematically and proactively.  All organizations would best serve Canadians by striving to reach this destination without having to endure a similar journey.”

Record high in access time delays causes concern and action

The Commissioner’s annual report also documents privacy trends within the federal government. This year saw a concerning increase in delayed responses from organizations to individuals seeking personal information held about them, as is a right under the Privacy Act. While this has been a concern for years, the 2011-12 increase reached an all-time high. 

As a result, upon receipt of future time delay complaints, the OPC now provides departments with a maximum four months to commit to a release. Failing that, a “deemed denial” finding will be issued, clearing the way for court action to resolve the matter.

“We note that as awareness and concerns over privacy increase, resources dedicated to facilitating access to personal information for individuals has remained stagnant or even decreased,” said the Commissioner. “Even during a time of greater fiscal restraint, the government shouldn’t cut back on its commitment to meeting the privacy rights of Canadians.” 

Increased numbers of complaints, breach reports

The report also notes that the OPC accepted 986 complaints in 2011-12, marking a 39 percent increase over the previous fiscal year.  The period also saw reported data breaches within federal organizations reach an all-time high of 80.  It must be noted however that because data breach notification within the federal government is voluntary, it’s unclear whether this statistic represents an actual increase in privacy breaches or more diligent reporting by departments.

“Overall, as we take stock upon 30 years of the Privacy Act, the need for a stronger emphasis on respecting privacy within the federal government remains,” added the Commissioner. “We will continue to use the tools and leverage we have to encourage the government to take action.”

The report also details findings from numerous investigations into privacy complaints against other federal organizations, including Correctional Services Canada and the Canada Revenue Agency (CRA). Additionally, following numerous reports of privacy breaches involving employees inappropriately accessing taxpayer information in recent years, the report notes that the OPC has selected the CRA for an audit under Section 37 of the Privacy Act. Work on this has begun and will continue over the coming months.

The full annual report and audit of VAC are available at www.priv.gc.ca. The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman and guardian of privacy in Canada.

Related Documents


Tuesday, October 02, 2012

Ontario Court of Appeal rules no expectation of privacy in connecting IP address to customer name

The Ontario Court of Appeal has today released its decision in R. v. Ward, 2012 ONCA 660, in which it held that -- in the circumstances of the case -- a customer has no expectation of privacy in his or her customer name and address when the police come armed with an IP address. I haven't had a chance to digest the full decision, but it gets added to the list of cases that permit the police, in certain circumstances, to obtain customer details when they have the IP address of a suspect.

I expect that this will further embolden those who support the resurrection of lawful access legislation before parliament.

Similar to other cases that have found no expectation of privacy in customer name and address information, the Ontario Court of Appeal held that Bell Sympatico had expressly "circumscribed" its customer's expectation of privacy:

[100] Setting aside the contractual terms for the moment, I think the “reasonable and informed person” identified by Binnie J. in Patrick, at para. 14, would view a customer’s reasonable expectation of privacy in his or her subscriber information to be circumscribed by the service provider’s discretion to disclose that information to the police where it was both reasonable to do so and a PIPEDA compliant request for disclosure had been made by the police.

Monday, October 01, 2012

Political parties should be included in privacy laws; it'll never happen

The editorial in today's Halifax Chronicle Herald calls upon the government to include political parties within the protections of privacy laws. While it's a good idea, I can't see this happening ... it would require the politicians to agree that their hands should be tied.

PROTECTING PRIVACY: Challenges growing | The Chronicle HeraldPROTECTING Canadians’ privacy in a digital universe is a growing challenge.

Just how big that challenge has become was reflected in recent stories that underline the different ways Canadians’ personal information is not as secure as it should be.

The outcry after Immigration Minister Jason Kenney’s MP office emailed thousands of Canadians on Sept. 14, to boast about government efforts to protect gay refugees, focused on a simple question: How did the politician get those addresses?

Turns out Mr. Kenney’s office captured email addresses from letters that had been automatically sent to him whenever someone had signed a 2011 online petition protesting the deportation of a gay artist from Nicaragua.

Despite the widespread concern over what had happened, however, federal privacy commissioner Jennifer Stoddart’s office last week said that, based on what was known, they lacked jurisdiction.

Which points to an ongoing, glaring weakness in Canada’s laws protecting personal information. Though they collect vast amounts of personal data about voters, political parties in Canada are not, for the most part, bound by federal privacy legislation.

A study commissioned by Ms. Stoddart’s office and released last March found that Canada was one of just a few democratic countries lacking such protection. A poll done for the privacy commissioner’s office two years ago showed 92 per cent of Canadians wanted privacy laws to also cover political parties.

Earlier this month, Elections Canada’s chief electoral officer, Marc Mayrand, said the agency, in the wake of the robocalls scandal last spring, was examining possible regulations to control the huge databanks on voters held by political parties. It’s unclear, however, how comprehensive such regulations could be.

Meanwhile, Ms. Stoddart last week also issued a warning to 11 large commercial websites in Canada that were sharing consumers’ personal data without permission.

It’s time the federal government put enough “teeth” in Canada’s privacy laws to make offenders respect their “bite” — and it’s past time the privacy commissioner was given the power to bring political parties to heel, too.

Saturday, September 29, 2012

Nova Scotia trade union resurrects the USA Patriot Act boogeyman to prevent outsourcing

For those who have been following this topic in Canada, you'll remember that the first time that the USA Patriot Act appeared on the country's radar in earnest was when the British Columbia government proposed to outsource IT processing to the Canadian subsidiary of a US company. The union, most likely concerned about job losses latched onto the USA Patriot Act as the hook that would get some traction in the media and in the public mind.

That led to the inquiry by BC's Information and Privacy Commissioner, then amendments to that province's Freedom of Information and Protection of Privacy Act and then Nova Scotia's Personal Information International Disclosure Protection Act.

Now, somewhat predictably, the principal Nova Scotia trade union for public employees is resurrecting the boogeyman to try to stop outsourcing of IT services by the provincial government. We'll see how this plays out ...

Data at risk in private-sector deal | The Chronicle Herald

Union worried Nova Scotian’s records vulnerable

The province’s largest public-sector union is worried about the security of Nova Scotians’ information if the government contracts out information technology work in a deal workers say could total $100 million over 10 years.

Joan Jessome, president of the Nova Scotia Government and General Employees Union, said Thursday that there’s a vast amount and array of data in the SAP computer system. She said it includes everything from payroll numbers to procurement information and data from the Registry of Motor Vehicles.

“There probably isn’t a single Nova Scotian ... that has not been impacted by SAP,” Jessome said.

“(Our members) are telling us that we have reason, no matter what the agreement is, that once that (information) goes to an international company, we should always be concerned about how far that goes and what acts does it cover in different countries across the world.”

She said employees mentioned the Patriot Act in the United States, passed after the 9-11 attacks. It requires U.S. companies to provide records to the American government upon demand.

A 2005 provincial auditor general’s report raised a concern that U.S. companies with Canadian subsidiaries could also be compelled to turn over information. In 2006, the minority Tory government of the day passed the Personal Information International Disclosure Protection Act, meant to prevent U.S. authorities from inappropriately accessing Nova Scotians’ information under the Patriot Act.

Finance Department spokeswoman Michelle Lucas had said Wednesday that ensuring information is secure would be a top priority. She had no further comment on the potential outsourcing Thursday.

On Monday, government officials met with employees who run the system to tell them about the possibility their jobs will be contracted out. There are about 73 unionized workers, and another 35 who aren’t unionized. The non-union workers run the system for district health authorities and the IWK Health Centre.

Jessome said workers told her that the government is considering a 10-year contract for the work, worth $10 million a year.

Lucas had said Wednesday that a multinational firm approached the province last year about setting up a “global delivery centre” in the province. Its main office would be in Halifax, with a smaller one in Sydney.

Sources have said the firm is IBM Canada. Jessome said the government has told her which company, but she agreed to keep it confidential.

IBM Canada spokeswoman Carrie Bendsza said the company, which has employees in Halifax now, doesn’t comment on rumour or speculation. She also said it doesn’t reveal how many employees it has in individual cities or countries.

Jessome said there are currently eight union SAP information technology workers in Sydney, three in Truro, and the rest in Halifax.

Lucas has said that if the province does make a deal with the company, all affected provincial employees would be offered a job. Jessome said many have already indicated they wouldn’t take it.

She said they’d lose the security of being in the union, the work week would likely go up to 40 hours from 35, their pension plan would change to defined contribution from defined benefit, and they could face months-long placements at the company’s other locations, such as China and India.

“They’re certainly concerned about their jobs, no question, but the other thing that they were scared of is the security of information,” Jessome said.

Lucas also said the potential contracting out isn’t being considered as a cost-cutting measure, but as an economic development opportunity in the hope of creating more jobs.

The province has spent many millions on the SAP system since first adopting it in 1996, with some projects going over budget, and the system not always working properly.

Thursday, September 27, 2012

Supreme Court upholds children's privacy, allows cyberbullying victim to proceed anonymously

The Supreme Court of Canada's decision in AB v. Bragg Communications, 2012 SCC 46 has just been released and the Court has allowed the appeal in part. The decision supports the right of a child victim of cyber-bullying to proceed in the civil courts anonymously.

In the interests of full disclosure, I need to state that my firm represented the victim and my partners Michelle Awad and Jane O'Neill argued the case at the Supreme Court of Canada.

Here is the headnote:

Courts — Open court principle — Publication bans — Children — 15‑year old victim of sexualized cyberbullying applying for order requiring Internet provider to disclose identity of person(s) using IP address to publish fake and allegedly defamatory Facebook profile — Victim requesting to proceed anonymously in application and seeking publication ban on contents of fake profile — Whether victim required to demonstrate specific harm or whether court may find objectively discernable harm.

A 15‑year old girl found out that someone had posted a fake Facebook profile using her picture, a slightly modified version of her name, and other particulars identifying her. The picture was accompanied by unflattering commentary about the girl’s appearance along with sexually explicit references. Through her father as guardian, the girl brought an application for an order requiring the Internet provider to disclose the identity of the person(s) who used the IP address to publish the profile so that she could identify potential defendants for an action in defamation. As part of her application, she asked for permission to anonymously seek the identity of the creator of the profile and for a publication ban on the content of the profile. Two media groups opposed the request for anonymity and the ban. The Supreme Court of Nova Scotia granted the request that the Internet provider disclose the information about the publisher of the profile, but denied the request for anonymity and the publication ban because there was insufficient evidence of specific harm to the girl. The judge stayed that part of his order requiring the Internet provider to disclose the publisher’s identity until either a successful appeal allowed the girl to proceed anonymously or until she filed a draft order which used her own and her father’s real names. The Court of Appeal upheld the decision primarily on the ground that the girl had not discharged the onus of showing that there was evidence of harm to her which justified restricting access to the media.

Held: The appeal should be allowed in part.

The critical importance of the open court principle and a free press has been tenaciously embedded in the jurisprudence. In this case, however, there are interests that are sufficiently compelling to justify restricting such access: privacy and the protection of children from cyberbullying.

Recognition of the inherent vulnerability of children has consistent and deep roots in Canadian law and results in the protection of young people’s privacy rights based on age, not the sensitivity of the particular child. In an application involving cyberbullying, there is no need for a child to demonstrate that he or she personally conforms to this legal paradigm. The law attributes the heightened vulnerability based on chronology, not temperament.

While evidence of a direct, harmful consequence to an individual applicant is relevant, courts may also conclude that there is objectively discernable harm. It is logical to infer that children can suffer harm through cyberbullying, given the psychological toxicity of the phenomenon. Since children are entitled to protect themselves from bullying, cyber or otherwise, there is inevitable harm to them — and to the administration of justice — if they decline to take steps to protect themselves because of the risk of further harm from public disclosure. Since common sense and the evidence show that young victims of sexualized bullying are particularly vulnerable to the harms of revictimization upon publication, and since the right to protection will disappear for most children without the further protection of anonymity, the girl’s anonymous legal pursuit of the identity of her cyberbully should be allowed.

In Canadian Newspapers Co. v. Canada (Attorney General), [1988] 2 S.C.R. 122, prohibiting identity disclosure was found to represent only minimal harm to press freedom. The serious harm in failing to protect young victims of bullying through anonymity, as a result, outweighs this minimal harm. But once the girl’s identity is protected through her right to proceed anonymously, there is little justification for a publication ban on the non‑identifying content of the profile. If the non‑identifying information is made public, there is no harmful impact on the girl since the information cannot be connected to her. The public’s right to open courts –and press freedom – therefore prevail with respect to the non‑identifying Facebook content.

Wednesday, September 26, 2012

Landmark cyberbullying and children's privacy decision expected from Supreme Court of Canada

The Supreme Court of Canada will tomorrow release its decision in the appeal of A.B. v. Bragg Communications Inc., 2011 NSCA 26. At issue is whether a young person can initiate a legal proceeding under a pseudonym in circumstances where the young person is seeking information to identify a cyberbully. In addition, the Court will consider the imposition of a publication ban on the details of the underlying defamation.


Here are the details from the SCC:

Supreme Court of Canada - Decisions - Judgments to be Rendered in Appeals

34240 A.B. by her Litigation Guardian, C.D. v. Bragg Communications Incorporated, a body corporate and Halifax Herald Limited, a body corporate

(Publication Ban in Case) (Sealing Order)

Civil procedure ‑ Confidentiality orders ‑ Defamation ‑ Appellant applying for order requiring disclosure of identity of persons who used particular IP address to create fake profile on Facebook ‑ Appellant also applying for permission to proceed by way of initials and for order prohibiting publication of allegedly defamatory statements in profile ‑ Whether a minor seeking a civil remedy for online sexualized bullying should be entitled to bring a motion to determine the identity of the intended defendant using a pseudonym and under a publication ban concerning the substance of the statement ‑ Whether a court should take notice of the inherent vulnerability of young people subject to online sexualized bullying and the serious risk of harm to them if they are required to republish the comments and reveal their identity to seek a remedy, in considering if a confidentiality order and publication ban should be granted ‑ Whether a court can invoke its parens patriae jurisdiction to protect a child, in considering whether a confidentiality order and publication ban should be granted for a child subject to online sexualized bullying ‑ Whether media that choose to intervene in a motion for a publication ban should be entitled to costs if the motion is not successful, particularly when the motion involves interests broader than those of the applicant.

The appellant became aware of a fake profile on the social networking website Facebook, which included a photograph of the appellant, a slightly modified version of her name, and other particulars which identified her. The fake profile also discussed the appellant’s physical appearance, her weight, and allegedly included scandalous sexual commentary of a private and intimate nature. The appellant, by her litigation guardian, applied in chambers for an order requiring the respondent Bragg Communications to disclose the identity of the persons who used a particular IP address to perpetrate the alleged defamation. As additional relief, the appellant sought an order which would allow her to proceed by pseudonym (initials), and as well, a partial publication ban to prevent the public from knowing the words contained in the fake Facebook profile. LeBlanc J. granted the disclosure order but refused the additional relief sought. The Court of Appeal upheld that decision.

Origin of the case: Nova Scotia

File No.: 34240

Judgment of the Court of Appeal: March 4, 2011

Counsel: Michelle Awad, Q.C. for the appellant
Daniel W. Burnett as Amicus Curiae

Who polices political parties' privacy practices? Nobody.

The recent minor scandal resulting from the Immigration Minister's mass e-mailing to members of the LGBT community has again focused attention on the fact that Canadian political parties are beyond the jurisdiction of Canada's public sector and private sector privacy laws.

See: Political parties operate outside Canada's privacy laws - Politics - CBC News.

This is not the first time that this gap has been noticed. Check out a few of the past examples from this blog by clicking the "political parties" tag.