Showing posts with label piidpa. Show all posts
Showing posts with label piidpa. Show all posts

Ask the privacy lawyer: Data in transit outside of Canada

I received the following question the other day:



In terms of personal data that was captured by a healthcare company while
a patient in Canada, and relayed to another city in Canada for analysis, further
use, etc., does that patient data have to remain in Canada ? or is it allowed to
traverse the US border at any time during its journey across the continent ?
My concern is that communication networks don't seem to be restricted to
intra-Canada operation or due to congestion or failure, most have to use large
data highways that may cross over into the United States.


Under PIPEDA, is patient or personal data limited to just traverse within Canada ?

In Canada, there are no restrictions on the export of personal information except for personal information that is subject to the Freedom of Information and Protection of Privacy Acts of Alberta, British Columbia and Nova Scotia, and the equivalent in Quebec. Each of those provinces have enacted laws in response to the USA Patriot Act. The Patriot Act gives American law enforcement with much easier access to information, including personal information. The laws in these provinces don't deal with information in transit, but talk about the storage and access to that information. For example, from Nova Scotia's PIIDPA:


5 (1) A public body shall ensure that personal information in its custody or under its control and a service provider or associate of a service provider shall ensure that personal information in its custody or under its control is stored only in Canada and accessed only in Canada, unless...
While there is no caselaw on this issue, I doubt that any of the privacy regulators of those provinces or the courts would find a contravention of this law if data packets containing personal information were routed through the United States on their way between two points in Canada. The information may be intercepted while in transit, but there users have little control over how this data travels. For example, a traceroute function from my home computer to ubc.ca shows that most of the data travels through the US:

Tracing route to ubc.ca [64.40.111.228] over a maximum of 30 hops:

1 2 ms 1 ms 1 ms [REDACTED]

2 20 ms 9 ms 9 ms [REDACTED]

3 17 ms 12 ms 10 ms [REDACTED]

4 11 ms 8 ms 8 ms hlfx-br1.eastlink.ca [24.222.79.205]

5 18 ms 28 ms 18 ms te-3-1.car2.Boston1.Level3.net [4.79.2.89]

6 22 ms 19 ms 18 ms ae-2-5.bar2.Boston1.Level3.net [4.69.132.250]

7 19 ms 19 ms 22 ms ae-0-11.bar1.Boston1.Level3.net [4.69.140.89]

8 46 ms 54 ms 49 ms ae-5-5.ebr1.Chicago1.Level3.net [4.69.140.94]

9 44 ms 52 ms 39 ms ae-68.ebr3.Chicago1.Level3.net [4.69.134.58]

10 73 ms 72 ms 70 ms ae-3.ebr2.Denver1.Level3.net [4.69.132.61]

11 99 ms 90 ms 90 ms ae-2.ebr2.Seattle1.Level3.net [4.69.132.53]

12 90 ms 89 ms 89 ms ae-22-52.car2.Seattle1.Level3.net [4.68.105.35]

13 90 ms 89 ms 88 ms unknown.Level3.net [64.154.178.134]

14 93 ms 91 ms 102 ms p2-1.pr0.yvrx.hgtn.net [66.113.197.5]

15 93 ms 93 ms 91 ms r1-hgtn.netnation.com [64.40.127.254]

16 102 ms 95 ms 93 ms itservices.ubc.ca [64.40.111.228]

Trace complete.



This leads to the question of whether your information is safe from interception during transit through the US. It's really not safe from interception at any point on the internet. At each point above, the signals can be intercepted. There was recent speculation that a collaboration between AT&T the National Security Agency allowed national security organs of the US to vacuum international internet and telco traffic from at least one AT&T facility. (See: EFF's class action against AT&T.) Do they have the tools to single out particular traffic? Probably.

So what to do? If sensitive information is being transferred between two points on the internet, it should be encrypted and sent through a secure "tunnel".

Update: Added reference to Quebec statute. Thanks, commenter.

Cross-border movement of personal health information

Earlier this week, I co-chaired Insight Information's conference on electronic health records here in Halifax. I was very pleased to see a lot of expertise in privacy developing in Atlantic Canada, which is necessary as Nova Scotia, New Brunswick and Newfoundland move towards developing and implementing health privacy laws and as electronic health record projects are driving forward.

I gave a presentation on the mess and uncertainty related to the cross-border movement of personal health information in Canada. The complicated overlap of laws that we see in provinces such as Nova Scotia is compounded when the information is disclosed out of the province.

If you're interested, the presentation is here and can be flipped through below:

Patriot Act reality check and Canadian authorities' similar powers

I had the honour of being invited to speak to the Canadian Bar Association's Alberta branch earlier this week about cross-border privacy issues.


We have had to deal with them rather acutely in Nova Scotia since the passage of the Personal Information International Disclosure Protection Act (PIIDPA), which prompted me to take a closer look at the different regimes for access to personal information by law enforcement and national security types on both sides of the border.


Most people are surprised to learn that some of the most "problematic" provisions of the USA Patriot Act are replicated in Canadian law in the Anti-Terrorism Act. We just don't hear about it as much. People are also surprised to learn of huge amount of information sharing that takes place between agencies in Canada and their counterparts in the US.


For example, we have our equivalent of the FISA secret court in the form of designated judges of the Federal Court of Canada acting under the CSIS Act, who issue secret orders. Our National Defence Act allows for warrantless interception, for the purpose foreign intelligence, of private communications directed at foreign entities located outside of Canada. This is very similar to authorizations by the Attorney General of the United States under the Foreign Intelligence Surveillance Act.


Here's the presentation I gave:



Join the discussion about Dalhousie University and Cloud Computing

Dalhousie University, like many other Canadian post-secondary institutions, is engaging in a deep conversation with students, faculty and staff about the possibility of moving e-mail and other IT services to the cloud. As part of that conversation, the university is hosting a special forum on privacy and the cloud. Here's the details:

“A Forum on Privacy Laws, Cloud Computing and Impact to IT Strategy”

Presentation Date: Monday, April 18th, 2011 2:00-5:00 (Rowe Potter Auditorium)

Information Technology Services at Dalhousie University is exploring a number of opportunities with emerging “Software-as-a-Service” or “Cloud Computing” initiatives. Cloud computing introduces a number of potential concerns around security, privacy, data ownership and data stewardship.

In an effort to address concerns and increase awareness around the legal, policy and academic implications, Dalhousie has invited professionals in a number of areas to speak and take part in a panel discussion on these topics.

David Fraser, Partner, McInnes Cooper

Mr. Fraser will speak to Canadian and American laws in relation to cross border data transfer, privacy and access to information.

Dwight Fischer, CIO, Dalhousie University

Mr. Fischer will speak to the technology challenges and changes taking place and the impact on Dalhousie.

Paul Jones, Policy & Education Officer, Canadian Association of University Teachers

Mr. Jones will speak to the concerns around privacy and academic freedom, specifically how it relates to faculty.

Come and take part in the discussion on April 18th from 2:00 to 5:00 p.m!

Join in the online conversations now at blogs.dal.ca/connectedU

4th Annual Payment Card Compliance In Canada

I had the pleasure of speaking this morning at the Canadian Institutes 4th Annual Payment Card Compliance In Canada. I was on a panel with Art Dunfee, Director General of Investigations and Inquiries at the Office of the Privacy Commissioner of Canada and Sandy Stephens, Senior Manager, Legal CounselCapital One Canada. Sandy covered the new Do Not Call List and Art covered PIPEDA compliance and the new breach notification guidelines. I then presented on a few additional topics: (i) the effect of US breach notification laws on Canadian companies and (ii) the effect of provincial anti-USA PATRIOT Act laws on Canadian banks.

Here's my presetation if you're interested:



And if Google Documents isn't showing you the love, here it is as a PDF: Payment%20Card%20Compliance.pdf

Popular entries

 

Web world of law online piidpa © 2012