Wednesday, April 14, 2004

Article: New privacy sprouts forest of complaints

Today's Toronto Star has a very interesting article that highlights something that I have been trying to emphasizes to my clients for some time: the most important thing that a business must do to comply with PIPEDA and to avoid complaints is to communicate with its customers. Principle 2, from the CSA Model Code, requires a business to take reasonable steps to bring to an individual's attention the purpose for which information is being collected. This communication forms the foundation for the "knowledge and consent" that are required under "Principle 3 - Consent". Many commentators emphasize that PIPEDA is about consent, but this consent has to be based on the identification of purposes. If you tell you customers what you propose to do, there won't be any uncertainty or confusion and, therefore, the business is much less likely to get a complaint.

TheStar.com - New privacy sprouts forest of complaints:
"Canada's privacy watchdog says a 'communications gap' forming between businesses and consumers may be partly to blame for an increase in complaints since new federal privacy legislation went into full force on Jan. 1.

The law requires businesses, large and small, to put systems in place that will make sure customer information is secure, accurate, gathered with consent and not used beyond a stated purpose.

Heather Black, assistant federal privacy commissioner, said Canadians are taking advantage of their newfound privacy rights but many businesses, when asked to explain how and why they collect and use customer information, aren't providing adequate answers.

'When people ask why they're being asked for this information, they're not getting very satisfactory responses,' said Black. 'So it really is a communications gap.'

The commission began noticing this trend in January, specifically in the retail sector. Black said a number of people have filed complaints against certain retail outlets that require customers to provide their names, phone numbers and addresses when goods are returned for refund or exchange."

Full article ...

Monday, April 12, 2004

Article: Employment law myths

In today's National Post, Howard Levitt, counsel to Lang Michener, takes a pretty aggressive stand with respect to PIPEDA. His sentiments about the constitutionality are shared by others, but I was surprised to read that he suggests ignoring PIPEDA. Most privacy lawyers with whom I speak are of the view that PIPEDA should be followed until it is declared to be unconstitutional:

"4. Privacy legislation applies across Canada.

The federal privacy legislation constitutionality provided that, if similar legislation was not passed in each province by January 1, 2004, the federal legislation would apply provincially. Many provinces, including Ontario, have not yet passed Privacy Acts. However, virtually everyone is conducting themselves as if the federal privacy legislation applies. It does not. Despite the wording of that legislation, the federal government lacks the constitutional power to impose privacy legislation on the provinces and no attempt to do so would survive legal challenge. Therefore, contrary to seemingly everyone's belief, there is presently no effective, binding privacy legislation in most of Canada."

This is very aggressive and, at least to this point, many Courts have been applying PIPEDA without hesitation. It is true that the federal government has no constitutional way to regulate the provincially regulated workplace, but PIPEDA does not purport to operate there.

Saturday, April 10, 2004

Correction re: Mathew Englander

Mathew Englander, to whom I referred a while back, has e-mailed me a correction about an entry in PIPEDA and Canadian Privacy Law. I had been told that his complaint had arrived by e-mail, having been sent at the stroke of midnight 2001. Mr. Englander writes:

I just came across the reference to me on your blog (http://pipeda.blogspot.com/2004_01_04_pipeda_archive.html#107338559447219057).

It's ironic that your "sources at the Office of the Privacy Commissioner" infringed on my privacy by telling you that my complaint "was sent by e-mail on January 1, 2001 at 12:01 am." The Privacy Commissioner should not unnecessarily divulge details about complaints and complainants.

In any event the information is wrong. I did not file my complaint by e-mail.

You can post this email on your web site if you like, but of course not my email address (which is a disposable address anyway).

Mathew Englander

As they say, it is always better to get your information first hand ...

Wednesday, April 07, 2004

Article: Privacy officer for hire

Since the launch of National Privacy Services, we've gotten some quite favourable coverage in the media. ConnectIT had the following article in today's edition:

[ ConnectIT e-News Daily ]:
"Privacy officer for hire
6 April, 2004
by Liam Lahey

Security solutions provider Thor Solutions Inc. and law firm McInnes Cooper have teamed up to form National Privacy Services Inc. (NPSI) � a partnership designed to help small to mid-sized businesses (SMBs) understand and comply with Canada�s federal privacy legislation.

According to David T.S. Fraser, chair of McInnes Cooper's privacy group in Halifax, NPSI helps SMBs avoid the expense of building a solution from scratch, spending a great deal of time trying to become privacy experts themselves, and/or ignoring the legislation and risking their businesses by being identified as non-compliant. "

Full article ...

Tuesday, April 06, 2004

Article: CMA - Why we changed e-marketing rules

The Canadian Marketing Association, which had been one of the strongest voices in favour of PIPEDA, has amended its Code of Ethics and Standards of Practice to deal with spam:

ITBusiness.ca: "Canada's largest marketing industry group has amended its Code of Ethics and Standards of Practice to deal with the growing volume of unsolicited commercial e-mail.

The Canadian Marketing Association said the amendments would apply immediately to all 800 of its corporate members, and would be specific to e-marketing programs.

Under the new rules, CMA members must obtain a consumer�s explicit or opt-in consent before disclosing their e-mail address to a third party; use the e-mail address only for the purposes that have been disclosed to the consumer; and clearly identify the CMA member and source of the e-mail. They must also provide the recipient with a simple and easy-to-use e-mail means to opt-out from receiving further e-mail marketing communications from the marketer.

CMA communications director Ed Cartwright recently spoke with Pipeline about the changes...."

Monday, April 05, 2004

Article: Security scare for business laptops

Security and privacy go hand in hand. While this article, Security Scare for Business Laptops, primarily deals with confidential business information, the principles also hold true for personal information that an organization is obliged to safeguard under PIPEDA's dictates. Insufficiently secured Wi-Fi can be a significant vulnerability for any computer user and computer network.

The Financial Times: Security Scare for Business Laptops

Business travellers are unwittingly making company secrets available to rivals by ignoring the risks of local wireless networks, known as wi-fi hotspots, security experts warn.

IT security experts who have carried out checks at hotels, railway stations and other public places equipped with wireless internet access technology have found the networks and users' computers are often insecure. "It's actually happening: there is competitive intelligence being gathered," said Richard Hollis, chief executive of Orthus, a security firm.

Hackers - who need little specialist knowledge - can access contents of a rival's laptop because other users' files are visible to anybody using an unsecured wireless network. Hackers are also using wi-fi hotspots to store their files on other computers.

Saturday, April 03, 2004

McInnes Cooper and Thor Solutions Team Up to Provide Affordable Privacy Solutions

NEWS RELEASE

Attention Business Editors:

McInnes Cooper and Thor Solutions Team Up to Provide Affordable Privacy Solution to Small and Med-sized Businesses

April, 2004, Halifax – Thor Solutions Inc. and McInnes Cooper have formed National Privacy Services Inc. (NPSi) to provide businesses with a cost-effective solution to the new privacy legislation.

            “Businesses have a long list of things to do to comply with the new legislation governing the handling of personal information,” says David T.S. Fraser, Chair of McInnes Cooper's Privacy Group. “We help them avoid the expense of building a solution from scratch, spending a great deal of time becoming privacy experts themselves, or ignoring the legislation and risking their businesses by being identified as non-compliant.”

            “Our solution is cost-effective and immediate,” says Dale Telford, Chief Privacy Officer of NPSi.  “It provides businesses with the tools to quickly become compliant through policies, procedures, consent strategies, a multi-media training program and their very own out-sourced privacy officer.  The Common Sense Privacy Solution is very affordable for smaller organizations. “It is focused at small- and medium-sized businesses that are at high risk, such as medical practices and insurance brokers,” says Telford. “We can act as the privacy officer, helping both the business and the customers. We save our clients time and money by dealing with queries, access requests and complaints. We can answer their questions and provide critical support”

            “This law applies to every business that handles personal information in the course of commercial activities. Without an effective privacy plan, businesses are at risk of having their reputation significantly damaged. NPSi is designed to give businesses the tools they need, at a price they can afford, to reduce the risk. The last thing a growing business needs is to be named as non-compliant by the Privacy Commissioner or end up in Federal Court,” says Fraser.  “Addressing the new privacy law is prudent risk-management. Given the risks of non-compliance and the cost of our program, this truly is a common sense solution.”

About National Privacy Services Inc.

National Privacy Services Inc. (NPSi) (www.privlaw.com) was founded in 2003 by Thor Solutions Inc. and McInnes Cooper in order to assist businesses, professionals and industry associations in following privacy best practices, based on the information privacy requirements of the federal privacy law and similar provincial statutes.

Thor Solutions Inc. (www.thorsolutions.com) is a recognized leader in the field of information security. McInnes Cooper (www.mcinnescooper.com) is Atlantic Canada's largest single law partnership with a nationally recognized privacy practice.

NPSi's focus is to provide guidance and support to organizations as they adopt mandatory privacy best practices. We work closely with industry groups to design privacy programs that can be easily and efficiently adopted without interfering with the operations of the organizations required. In addition, we provide full support to our clients, with toll-free, on-call expertise and our privacy professionals can act as the designated privacy officer for our clients.

- 30 -

Media contacts:
David Fraser, McInnes Cooper (902) 424-1347 cell: (902) 478-6654 david.fraser@mcinnescooper.com
Dale Telford, Thor Solutions (902) 469-8467 cell: (902) 830-1981 dale.telford@thorsolutions.com

Privacy aspects of THE MATTER OF BMG Canada Inc. et al v. Jane Doe et al

The Canadian and US media have been abuzz with reports that "file sharing is legal in Canada!" (see Google News coverage). The actual decision doesn't, in my view, go that far (much of it seemed to turn on a deficient affidavit and the difficulty of connecting an IP address and a Kazaa screen name), but that's a bit ultra vires my blog. Here we deal with privacy. But fear not, there is some privacy-related analysis in the decision rendered by von Finckenstein J (2004 FCT 488).

Part of the argument advanced by the internet service providers was that they were prohibited from revealing personal information of their subscribers, absent a court order. The parties agreed in advance that the subscribers have an expectation of privacy regarding their identities, pursuant to their subscriber agreements and sections 3 and 5 of PIPEDA. They also agreed that this personal information can be released without the consent of individuals if the court so orders under section 7(3)(c) of PIPEDA.

[13] I read the Norwich and Glaxco Wellcome cases as establishing that the test for granting an equitable bill of discovery involves the following five criteria: ...

Criterion e: the public interests in favour of disclosure must outweigh the legitimate privacy concerns

[36] It is unquestionable but that the protection of privacy is of utmost importance to Canadian society. In the words of Lamer J. in R. v. Dyment, [1988] 2 S.C.R. 417 (S.C.C.): Grounded in man's physical and moral autonomy, privacy is essential for the well-being of the individual. For this reason alone, it is worthy of constitutional protection, but it also has profound significance for the public order.

[37] In respect of the internet specifically, Wilkins J. in Irwin Toy v. Doe (2000), 12 C.P.C. (5th) 103 (Ont. S.C.J.) stated at paras. 10-11: Implicit in the passage of information through the internet by utilization of an alias or pseudonym is the mutual understanding that, to some degree, the identity of the source will be concealed. Some internet service providers inform the users of their services that they will safeguard their privacy and/or conceal their identity and, apparently, they even go so far as to have their privacy policies reviewed and audited for compliance. Generally speaking, it is understood that a person's internet protocol address will not be disclosed. Apparently, some internet service providers require their customers to agree that they will not transmit messages that are defamatory or libellous in exchange for the internet service to take reasonable measures to protect the privacy of the originator of the information. In keeping with the protocol or etiquette developed in the usage of the internet, some degree of privacy or confidentiality with respect to the identity of the internet protocol address of the originator of a message has significant safety value and is in keeping with what should be perceived as being good public policy. As far as I am aware, there is no duty or obligation upon the internet service provider to voluntarily disclose the identity of an internet protocol address, or to provide that information upon request.

[38] Parliament has also recognized the need to protect privacy by enacting PIPEDA, which has as one of its primary purposes the protection of an individual’s right to control the collection, use and disclosure of personal information by private organizations (section 3).

[39] However while the law protects an individual’s right to privacy, privacy cannot be used to protect a person from the application of either civil or criminal liability. Accordingly, there is no limitation in PIPEDA restricting the ability of the Court to order production of documents related to their identity. Section 7(3)(c) allows disclosure without consent if such disclosure is: c) required to comply with a subpoena or warrant issued or an order made by a court, person or body with jurisdiction to compel the production of information, or to comply with rules of court relating to the production of records. (emphasis added).

[40] Thus, both PIPEDA as well as the test set out in Norwich/Glaxco, require the Court to balance privacy rights against the rights of other individuals and the public interest.

[41] This motion is not a novel proceeding. In the past, third parties have been compelled to disclose documents identifying the name and address of a defendant previously identified solely by an Internet Protocol address. In no case have privacy or other concerns weighing against disclosure outweighed the interest in obtaining documents and information necessary to identify the defendants. See: Irwin Toy v. Doe (2000), 12 C.P.C. (5th) 103 (Ont. S.C.J.); Ontario First Nations Limited Partnership v. John Doe (3 June 2002) (Ont.S.C.J.); Canadian Blood Services/Société Canadienne du Sang v. John Doe (June 17, 2002) (Ont. S.C.J.); Wa’el Chehab v. John Doe (October 3, 2003) (Ont. S.C.J.); Kibale v. Canada, [1991] F.C.J. No. 634 (QL) (FC); Loblaw Companies Ltd. v. Aliant Telecom Inc. and Yahoo [2003] N.B.J. No.208 (N.B.Q.B.), online: QL (NBJ).

One thing that surprises me is that there is no obligation on the part of the ISPs to inform the "owners" of the IP addresses that their information is the subject of an application for an equitable bill of discovery, affording them the opportunity to retain counsel and -- anonymously - resiting the application. To do otherwise seems to put too much discretion in the hands of the ISPs. Afterall, they choose whether to resit the discovery request.

Thursday, April 01, 2004

Article: Turning online privacy into a joke

Donal Daly of the Customer Respect Group has a very interesting commentary on CNet today about the importance of privacy policies in communicating respect to customers. They conducted a survey that underscores the importance of a true, meaningful and customer-friendly privacy policy:

Turning online privacy into a joke | Perspectives | CNET News.com:
"In a survey of the adult online population, conducted by The Customer Respect Group in February 2004, the importance of respectful treatment of consumers' privacy concerns was underlined by some dramatic findings. When survey participants were asked how much they care about a company's privacy policy when invited to enter personal information to a Web site, 22.4 percent responded that in the absence of a privacy policy, they would not offer the information. A further 26.6 percent echoed this sentiment by indicating that if they were unhappy with a company's privacy policy they would leave the site. "