Showing posts with label patriot act. Show all posts
Showing posts with label patriot act. Show all posts

Nomadic laptops can expect the rubber glove treatment

There's been a bit of a buzz lately about laptop inspections by the Department of Homeland Security (Crossing the border? Consider the possibility of laptop searches, Hands off my laptop, Your papers and laptops, please?, US Customs confiscating laptops). Today, the Washington Post is reporting on recently disclosed policies used by the DHS to take and inspect laptops:

Travelers' Laptops May Be Detained At Border (washingtonpost.com)

... The policies state that officers may "detain" laptops "for a reasonable period of time" to "review and analyze information." This may take place "absent individualized suspicion."

The policies cover "any device capable of storing information in digital or analog form," including hard drives, flash drives, cell phones, iPods, pagers, beepers, and video and audio tapes. They also cover "all papers and other written documentation," including books, pamphlets and "written materials commonly referred to as 'pocket trash' or 'pocket litter.' "

Reasonable measures must be taken to protect business information and attorney-client privileged material, the policies say, but there is no specific mention of the handling of personal data such as medical and financial records.

When a review is completed and no probable cause exists to keep the information, any copies of the data must be destroyed. Copies sent to non-federal entities must be returned to DHS. But the documents specify that there is no limitation on authorities keeping written notes or reports about the materials.

"They're saying they can rifle through all the information in a traveler's laptop without having a smidgen of evidence that the traveler is breaking the law," said Greg Nojeim, senior counsel at the Center for Democracy and Technology. Notably, he said, the policies "don't establish any criteria for whose computer can be searched." ...


If you want to take a look at the policy itself, it's here.

Thanks to Rob Hyndman for the tipoff.

Ask the privacy lawyer: Data in transit outside of Canada

I received the following question the other day:



In terms of personal data that was captured by a healthcare company while
a patient in Canada, and relayed to another city in Canada for analysis, further
use, etc., does that patient data have to remain in Canada ? or is it allowed to
traverse the US border at any time during its journey across the continent ?
My concern is that communication networks don't seem to be restricted to
intra-Canada operation or due to congestion or failure, most have to use large
data highways that may cross over into the United States.


Under PIPEDA, is patient or personal data limited to just traverse within Canada ?

In Canada, there are no restrictions on the export of personal information except for personal information that is subject to the Freedom of Information and Protection of Privacy Acts of Alberta, British Columbia and Nova Scotia, and the equivalent in Quebec. Each of those provinces have enacted laws in response to the USA Patriot Act. The Patriot Act gives American law enforcement with much easier access to information, including personal information. The laws in these provinces don't deal with information in transit, but talk about the storage and access to that information. For example, from Nova Scotia's PIIDPA:


5 (1) A public body shall ensure that personal information in its custody or under its control and a service provider or associate of a service provider shall ensure that personal information in its custody or under its control is stored only in Canada and accessed only in Canada, unless...
While there is no caselaw on this issue, I doubt that any of the privacy regulators of those provinces or the courts would find a contravention of this law if data packets containing personal information were routed through the United States on their way between two points in Canada. The information may be intercepted while in transit, but there users have little control over how this data travels. For example, a traceroute function from my home computer to ubc.ca shows that most of the data travels through the US:

Tracing route to ubc.ca [64.40.111.228] over a maximum of 30 hops:

1 2 ms 1 ms 1 ms [REDACTED]

2 20 ms 9 ms 9 ms [REDACTED]

3 17 ms 12 ms 10 ms [REDACTED]

4 11 ms 8 ms 8 ms hlfx-br1.eastlink.ca [24.222.79.205]

5 18 ms 28 ms 18 ms te-3-1.car2.Boston1.Level3.net [4.79.2.89]

6 22 ms 19 ms 18 ms ae-2-5.bar2.Boston1.Level3.net [4.69.132.250]

7 19 ms 19 ms 22 ms ae-0-11.bar1.Boston1.Level3.net [4.69.140.89]

8 46 ms 54 ms 49 ms ae-5-5.ebr1.Chicago1.Level3.net [4.69.140.94]

9 44 ms 52 ms 39 ms ae-68.ebr3.Chicago1.Level3.net [4.69.134.58]

10 73 ms 72 ms 70 ms ae-3.ebr2.Denver1.Level3.net [4.69.132.61]

11 99 ms 90 ms 90 ms ae-2.ebr2.Seattle1.Level3.net [4.69.132.53]

12 90 ms 89 ms 89 ms ae-22-52.car2.Seattle1.Level3.net [4.68.105.35]

13 90 ms 89 ms 88 ms unknown.Level3.net [64.154.178.134]

14 93 ms 91 ms 102 ms p2-1.pr0.yvrx.hgtn.net [66.113.197.5]

15 93 ms 93 ms 91 ms r1-hgtn.netnation.com [64.40.127.254]

16 102 ms 95 ms 93 ms itservices.ubc.ca [64.40.111.228]

Trace complete.



This leads to the question of whether your information is safe from interception during transit through the US. It's really not safe from interception at any point on the internet. At each point above, the signals can be intercepted. There was recent speculation that a collaboration between AT&T the National Security Agency allowed national security organs of the US to vacuum international internet and telco traffic from at least one AT&T facility. (See: EFF's class action against AT&T.) Do they have the tools to single out particular traffic? Probably.

So what to do? If sensitive information is being transferred between two points on the internet, it should be encrypted and sent through a secure "tunnel".

Update: Added reference to Quebec statute. Thanks, commenter.

Cross-border movement of personal health information

Earlier this week, I co-chaired Insight Information's conference on electronic health records here in Halifax. I was very pleased to see a lot of expertise in privacy developing in Atlantic Canada, which is necessary as Nova Scotia, New Brunswick and Newfoundland move towards developing and implementing health privacy laws and as electronic health record projects are driving forward.

I gave a presentation on the mess and uncertainty related to the cross-border movement of personal health information in Canada. The complicated overlap of laws that we see in provinces such as Nova Scotia is compounded when the information is disclosed out of the province.

If you're interested, the presentation is here and can be flipped through below:

US and Europe closer to information sharing pact

For over a year now, the United States and the European Union have been negotiating an arrangement so that US law enforcement and national security organizations can have easier access to data in Europe and about Europeans. The New York Times is reporting that that the two parties are closer to an arrangement that would permit trolling through personal information for suspicious activities, such as the review of SWIFT data that the American government undertook as the data was resident in the United States. One of the remaining issues is whether European citizens will have an ability to sue the Americans for misuse of their data.

The fact that Europe and the Bush administration are engaged in this process is a good thing. The alternatives are to shut off the tap entirely, which may not be a good idea, or to allow American authorities to freely troll through European data as easily as information about Americans, which would be worse. In Canada, Maher Arar learned the hard way about what can happen if an unstructured, unregulated information sharing "system" results in the transfer of unreliable information to the Bush administration.

Recently, the Canadian Bar Association presented its recommendations to Parliament, demanding that all information sharing arrangements be in writing with safeguards and oversight to make sure that information is accurate and does not unreasonably invade personal privacy.

The NYTimes article is here: U.S. and Europe Near Accord on Privacy - NYTimes.com.

Thanks to Rob Hyndman for the link.

Canadian Cloud Law Blog: Legal issues in cloud computing contracts

Just posted on my Canadian Cloud Law Blog:

Canadian Cloud Law Blog: Legal issues in cloud computing contracts


Yesterday, IT World Canada published a very lengthy article on the manifold legal issues that need to be considered when a company moves its data to the cloud, including a lengthy interview with me given a little while ago.


Here's the first part ...


Canadian cloud contracts: Liabilities and limitations - Page 1 - Leadership


More companies in Canada are turning to the cloud — or, at least, thinking about it — for flexibility, agility and cost savings. But there is often the perception that using cloud-computing services could compromise corporate and customer data, or may even be against the law.


But there’s no law that prevents most Canadian businesses from exporting personal information, said David Fraser, partner with McInnis Cooper, president of the Canadian IT Law Association and chair of the National Privacy and Access Law Section of the Canadian Bar Association.



“Once you move into a real cloud computing model, all of a sudden you don’t know where your data is — where in Canada or where in the world — and we’ve seen a big privacy-related backlash against cloud computing,” he said. So a large part of his job is telling people they’re wrong, since there’s a huge amount of misinformation out there.


Private-sector privacy laws require that you ensure a comparable level of security for personal information, regardless of whether you permit it to be managed by a Canadian company or a non-Canadian company. And some highly regulated industries, such as banking, have special rules that may include additional regulation for outsourced services.


“The Patriot Act is the big thing that people freak out about,” he said, “but we have a Canadian version of the Patriot Act, which is just as offensive.”


Here’s the deal: In 2001, the U.S. Congress passed the USA Patriot Act, which expanded the powers of law enforcement and national security agencies to carry out investigations and obtain intelligence in connection with anti-terrorism investigations.


But the provisions that have attracted the most criticism, said Fraser, have equivalents under Canadian law. Regardless of where information resides, it will always be subject to lawful disclosure to law enforcement or national security bodies. In Canada, he said, this includes search warrants under the Criminal Code of Canada and the Canadian Security Intelligence Service Act. Many European countries also permit broader law enforcement and national security access to information than in both the U.S. and Canada.


Of course, where the data sits can have an impact on that data. If it’s in North Korea or China, it’s at high risk, said Fraser. In the U.S., it may in some cases be significant, but in most cases it won’t be. “How interested would the FBI be in getting their hands on that data and would they be able to justify getting a subpoena? In most cases no,” he said. “And if it’s a person of interest they can get it in Canada.”


Many people are surprised to learn there’s a secret court in the U.S. where judges hear applications made by Department of Justice lawyers for search warrants (and other such things) and there’s nobody on the other side to oppose those applications.


“We have a secret court in Canada,” said Fraser. “We have a bunker in Ottawa where judges hear lawyers from the Department of Justice and CSIS for warrants to do things as potentially offensive as break into your house and install wiretapping equipment. These orders can specifically provide for authorities to go back in and change the batteries. So people don’t often think that Canada is engaged in these types of cloak and dagger things, and we are. Our definition of anti-terrorism is as broad and offensive as the U.S.”


Canadian authorities have virtually identical powers under the Canadian Security Intelligence Service Act, he said, which permits secret court orders that authorize CSIS to intercept communications or to obtain anything named in the warrant.


On top of that, Canada has a mutual legal assistance treaty with the U.S. (as well as informal agreements), so if the FBI wants data and it’s in the hands of a Canadian company, the FBI calls the RCMP or CSIS. “So when you dig into it, that cross-border issue, at least in most cases, really is not the large issue that many people are led to believe it is,” he said, adding that the Patriot Act has become shorthand for just saying no.


Only British Columbia and Nova Scotia have laws strictly regulating the export of personal information from Canada by public bodies, said Fraser. For all other jurisdictions, including the federal jurisdiction, export is permitted, but the public body must ensure a comparable level of security for personal information, regardless of whether it’s managed by a Canadian or non-Canadian company.


What businesses need to do is benchmark their existing privacy infrastructure and compare it to the privacy infrastructure of the proposed cloud provider. What are the real risks to the data, and to privacy and security? A lot of businesses have significant existing vulnerabilities — from insecure desktops, to playing catch-up with security patches, to mobile employees running around with laptops. Or thumb drives. “Nothing is more stupid or dangerous,” said Fraser. “In a cloud model if the computer is lost you lose nothing.”


Very often, this benchmark leans heavily in favour of the cloud provider that has squadrons of security people. Small businesses, in particular, are vulnerable to power outages and basic continuity issues. A reputable large-scale cloud provider will have multiple data centres, so things will stay up and running.


Read more ...

Patriot Act reality check and Canadian authorities' similar powers

I had the honour of being invited to speak to the Canadian Bar Association's Alberta branch earlier this week about cross-border privacy issues.


We have had to deal with them rather acutely in Nova Scotia since the passage of the Personal Information International Disclosure Protection Act (PIIDPA), which prompted me to take a closer look at the different regimes for access to personal information by law enforcement and national security types on both sides of the border.


Most people are surprised to learn that some of the most "problematic" provisions of the USA Patriot Act are replicated in Canadian law in the Anti-Terrorism Act. We just don't hear about it as much. People are also surprised to learn of huge amount of information sharing that takes place between agencies in Canada and their counterparts in the US.


For example, we have our equivalent of the FISA secret court in the form of designated judges of the Federal Court of Canada acting under the CSIS Act, who issue secret orders. Our National Defence Act allows for warrantless interception, for the purpose foreign intelligence, of private communications directed at foreign entities located outside of Canada. This is very similar to authorizations by the Attorney General of the United States under the Foreign Intelligence Surveillance Act.


Here's the presentation I gave:



Join the discussion about Dalhousie University and Cloud Computing

Dalhousie University, like many other Canadian post-secondary institutions, is engaging in a deep conversation with students, faculty and staff about the possibility of moving e-mail and other IT services to the cloud. As part of that conversation, the university is hosting a special forum on privacy and the cloud. Here's the details:

“A Forum on Privacy Laws, Cloud Computing and Impact to IT Strategy”

Presentation Date: Monday, April 18th, 2011 2:00-5:00 (Rowe Potter Auditorium)

Information Technology Services at Dalhousie University is exploring a number of opportunities with emerging “Software-as-a-Service” or “Cloud Computing” initiatives. Cloud computing introduces a number of potential concerns around security, privacy, data ownership and data stewardship.

In an effort to address concerns and increase awareness around the legal, policy and academic implications, Dalhousie has invited professionals in a number of areas to speak and take part in a panel discussion on these topics.

David Fraser, Partner, McInnes Cooper

Mr. Fraser will speak to Canadian and American laws in relation to cross border data transfer, privacy and access to information.

Dwight Fischer, CIO, Dalhousie University

Mr. Fischer will speak to the technology challenges and changes taking place and the impact on Dalhousie.

Paul Jones, Policy & Education Officer, Canadian Association of University Teachers

Mr. Jones will speak to the concerns around privacy and academic freedom, specifically how it relates to faculty.

Come and take part in the discussion on April 18th from 2:00 to 5:00 p.m!

Join in the online conversations now at blogs.dal.ca/connectedU

EU Clears SWIFT Data Transfers to United States Treasury Department

The New York Times is reporting on an agreement reached between European ministers and the United States for restored access to information about bank transfers processed by the Society for Worldwide Interbank Financial Telecommunications (SWIFT). See: EU Clears Bank Data Transfers to United States - NYTimes.com.

There has been some coverage of this already on blogs, particularly the Brussels Blogger (SWIFT - EU to grant USA nearly unlimited access to all EU banking data). Much of the tone has suggested that wholesale transfers of information will take place with massive datamining operations to be set up, but take a look at the actual agreement between the US and Europeans. It's available at wikileaks: EU draft council decision on sharing of banking data with the US and restructuring of SWIFT, 10 Nov 2009 - Wikileaks.

The agreement doesn't contemplate wholesale, massive data downloads of the kind one would expect if the database were in the United States. Instead, targeted requests must be made and these are directed through European authorities rather than to SWIFT directly. There are covenants on the US side that it will not be used for data mining purposes and other privacy-protective promises. And, to top it off, the term of the agreement is one year so that it can be renegotiated if it's not working out.

While all of this needs to be examined with a critical eye and it's not perfect, the cynic in me was pleasantly surprised by the details of the agreement.

Privacy in the cloud for Canadian universities

This past week, I was invited to speak at the annual get-together of The Canadian University Council of CIOs (CUCCIO) in Toronto on the topic of cloud computing. Many universities in Canada are struggling with the legal and privacy issues of adopting cloud computing, particularly when Google and Microsoft are both offering very attractive (and free!) offerings that would relieve universities of the costs and burdens of administering student and alumni e-mail.

Universities in Alberta, British Columbia and Nova Scotia are particularly hampered by legislation that was designed to thwart the boogeyman represented by the USA Patriot Act.

BC and Nova Scotia have each adopted legislation that either categorically prohibits the "export" of personal information by public bodies, or put in place administrative hurdles. Alberta joins this pack by making it an offense under their public sector privacy law to disclose personal information in response to a "foreign demand for disclosure".

Part of the problem is that the legal framework is not particularly nuanced, as each decision about whether to outsource a service should be guided by a detailed risk assessment and privacy impact assessment instead of ham-fisted categorical rules that don't take particular circumstances into account.

Here is my presentation, which was well received.


If the embedded slideshow isn't showing you the love, click here: https://docs.google.com/present/view?id=ddpx56cg_320fx7rkbhh&interval=30

Amendments to PIPA tabled, including breach notification and regulation of export of personal information

Yesterday (October 27, 2009), the Alberta Government introduced Bill 54, the Personal Information Protection Amendment Act, 2009. The Bill includes notification requirements for export of personal information to a service provider outside of Canada and breach notification.

The principal export provision is:

Notification respecting service provider outside Canada

13.1(1) Subject to the regulations, an organization that uses a
service provider outside Canada to collect personal information
about an individual for or on behalf of the organization with the
consent of the individual must notify the individual in
accordance with subsection (3).

(2) Subject to the regulations, an organization that, directly or
indirectly, transfers to a service provider outside Canada
personal information about an individual that was collected
with the individual’s consent must notify the individual in
accordance with subsection (3).

(3) An organization referred to in subsection (1) or (2) must,
before or at the time of collecting or transferring the
information, notify the individual in writing or orally of

(a) the way in which the individual may obtain access to
written
information about the organization’s policies and
practices with respect to
service providers outside
Canada, and

(b) the name or position name or title of a person who is
able to answer
on behalf of the organization the
individual’s questions about the
collection, use,
disclosure or storage of personal information by service
providers outside Canada for or on behalf of the
organization.

(4) The notice required under this section is in addition to any
notice required under section 13.

Permitted "as required by law" disclosures are now limited to required by Canadian or Alberta law.

The breach notification provisions require notice to the Commissioner and the Commissioner may order that individuals be notified.

I'm sure we'll be hearing more about this. Here's an extract from yesterday's Hansard:



ISYSweb 8 Search Results for Bill 54

Bill 54

Personal Information Protection Amendment Act, 2009

Mr. Denis: Thank you very much, Mr. Speaker. I rise to introduce
Bill 54, the Personal Information Protection Amendment Act, 2009.
Mr. Speaker, this bill is a direct result of the hard work of the
SelectSpecialPersonalInformation Protection ActReviewCommittee,
an all-party special committee of the Legislature that in 2006
undertook a complete review of the act and tabled a report to the
Legislature in November 2007 outlining recommendations for
amendments. This bill incorporates a number of their proposed
amendments.The main proposals for change include emerging issues such as
notifying the commissioner or individuals about security breaches
that place personal information at risk and informing individuals
when services involving personal information are occurring outside
of Canada. Mr. Speaker, as required for any new legislation in a
rapidly evolving area, this bill also does some updating and finetuning
of the existing provisions of this act.

Thank you very much, Mr. Speaker.

[Motion carried; Bill 54 read a first time]

The Speaker: The hon. Government House Leader.

Mr. Hancock: Thank you, Mr. Speaker. I move that Bill 54 be
moved onto the Order Paper under Government Bills and Orders.

[Motion carried]

4th Annual Payment Card Compliance In Canada

I had the pleasure of speaking this morning at the Canadian Institutes 4th Annual Payment Card Compliance In Canada. I was on a panel with Art Dunfee, Director General of Investigations and Inquiries at the Office of the Privacy Commissioner of Canada and Sandy Stephens, Senior Manager, Legal CounselCapital One Canada. Sandy covered the new Do Not Call List and Art covered PIPEDA compliance and the new breach notification guidelines. I then presented on a few additional topics: (i) the effect of US breach notification laws on Canadian companies and (ii) the effect of provincial anti-USA PATRIOT Act laws on Canadian banks.

Here's my presetation if you're interested:



And if Google Documents isn't showing you the love, here it is as a PDF: Payment%20Card%20Compliance.pdf

Canadian airlines look to goverment to solve privacy dilemma

The timing on this couldn't be worse, in the aftermath of the Christmas day "underwear bomber" and unprecedented scrutiny of airline passengers.

The National Airlines Council of Canada is looking to the federal government to develop a "permanent solution" to the dilemma they are facing. Airlines that overfly the United States are required to send passenger information to the US TSA, but the airlines contend this violates Canadian privacy laws.

There are a number of circumstances under Canadian privacy laws where organizations require the collection of personal information that's not strictly necessary for the provision of goods or services. PIPEDA permits collection, use and disclosure where it is "required by law", but this is not a Canadian legal requirement.

From the Canadian Press:

The Canadian Press: Canadian airlines plead with government to solve U.S. security dilemma

Canadian airlines plead with government to solve U.S. security dilemma

By Jim Bronskill (CP) – 13 hours ago

OTTAWA — Canada's major airlines say they will be forced either to break privacy laws or to ignore new American air security rules unless the federal government comes up with a response to U.S. demands for passenger information.

The National Airlines Council of Canada, which represents the four largest Canadian carriers, is pleading with the government to find "a permanent solution" to the dilemma posed by the U.S. Secure Flight program.

The program would collect the name, gender and birth date of the approximately five million Canadians who fly through American airspace each year en route to destinations such as the Caribbean, Mexico and South America, even if their planes don't touch the ground in the States.

The U.S. Transportation Security Administration (TSA) would then vet the names against security watch lists.

Passengers whose names appear on the list could face anything from extra security screening to being barred from a flight. There are also concerns the personal data could be used for purposes unrelated to aviation security.

Washington is still reeling from an apparent attempt by a Nigerian man to blow up a jetliner over Michigan by igniting explosives sewn into his clothes.

The near-disaster has put renewed pressure on the TSA to ensure the skies are safe.

Canadian airlines have already begun passing along the personal information for flights that land in the United States.

But the requirement to hand over information for international flights over U.S. airspace was put on hold last February pending discussions with the governments of Canada, Mexico and some Caribbean countries.

In a November letter to Bill Baker, deputy minister of Public Safety, the National Airlines Council says Canadian carriers "are not aware of any progress" on the discussions and are concerned the TSA might suddenly enact the overflight provisions.

The council says this would force Canadian airlines to breach either Secure Flight or the Personal Information Protection and Electronic Documents Act, a federal privacy law that applies to Canadian companies.

An internal Public Safety document prepared last January agrees that sharing such information is "currently prohibited" under the privacy law.

Nicole Baer, a spokeswoman for the federal privacy commissioner, said it was too early to determine whether giving overflight data to the Americans would break Canadian privacy law.

The Public Safety document, obtained under the Access to Information Act, raises other concerns about Secure Flight.

"It is possible that Canadians overflying the United States could be denied boarding based on U.S. no-fly lists that were developed based on lower U.S. risk tolerance," says the January 2009 assessment.

"There are also no guarantees how the U.S. will use the information it obtains from carriers overflying its territory."

The United States has indicated it will waive the Secure Flight requirement to provide information for overflights if Canada creates an equivalent security screening system.

Last March, the airlines council told Public Safety Minister Peter Van Loan in a letter that application of U.S. Secure Flight rules in Canada "is a direct result of the failure to ensure" that Canada's no-fly list, known as Passenger Protect, is "an accepted part of a continental aviation security system."

The airlines council favours a homegrown system as long as carriers don't bear any new costs.

Canada has been working for years on a more comprehensive passenger screening system. The Public Safety Department had no immediate update on those plans.

Critics say extending the Secure Flight program to Canadian flights that merely pass over the U.S. would indeed be a threat to Canadian sovereignty.

The Ottawa-based International Civil Liberties Monitoring Group has argued that sprawling American watch lists could ensnare many Canadians - or activists, immigrants and refugees who want to fly to Canada from Latin America but must travel through American airspace to do so.

Washington says Secure Flight, which transfers the task of watch-list screening to the TSA from individual airlines, will reduce the number of false matches - a longstanding problem with common names - and clear up mistakes more quickly.

Copyright © 2010 The Canadian Press. All rights reserved

Popular entries

 

Web world of law online patriot act © 2012