Showing posts with label public sector. Show all posts
Showing posts with label public sector. Show all posts

Who do our privacy laws protect?

I was intereviewed by a New Brunswick journalist last week who was writing an article on how privacy laws can be used in a knee-jerk way to limit access to government information. The article, I expect, is a reaction to a number of stories out of NB where reporters were given the excuse of privacy laws to limit their access to information about potential high-risk offenders, the investigation of a motor vehicle accident that claimed a number of lives and public sector salaries.

Here is the bit that I contributed:

nbbusinessjournal.com - Who do our privacy laws protect?

Governments must protect citizens' public information [note: I'm sure I said "private information"] while still being accountable and transparent to the public, said David Fraser, a privacy lawyer with the Atlantic Canadian law firm McInnes-Cooper.

For example, the expenses for a cabinet minister's trip to Europe would likely be made public. However, a doctor's billing records, which would essentially reveal their salary, are only made available in some provinces, he said.

And although some form of privacy legislation has existed federally for quite some time, that doesn't mean the laws regulate every activity on the internet.

"It regulates commercial activities. So it says what information your bank can ask about you and what it can do with it, or your local video store," said Fraser. "But if an individual takes a picture of another person on their camera phone in embarrassing circumstances and then they post it on the Internet that's a personal use, not a commercial use, so that's not caught by that law." There are some circumstances where personal information can be released. For example, if an individual gives consent.

As well, personal information can be disclosed if it's deemed to be for the greater good of the public.

"I think people, just as a knee-jerk reaction, they say no - it's personal information," said Fraser.

Privacy Act report released by parliamentary committee

The Parliamentary Standing Committee on Access to Information, Privacy and Ethics has released its long-awaited report on proposed reforms to the Privacy Act. I appeared before the committee on behalf of the Canadian Bar Association and was pleased to see that many of our recommendations to the Committee are also recommendations made by the Committee to the government.

The report is available here.

Privacy in the cloud for Canadian universities

This past week, I was invited to speak at the annual get-together of The Canadian University Council of CIOs (CUCCIO) in Toronto on the topic of cloud computing. Many universities in Canada are struggling with the legal and privacy issues of adopting cloud computing, particularly when Google and Microsoft are both offering very attractive (and free!) offerings that would relieve universities of the costs and burdens of administering student and alumni e-mail.

Universities in Alberta, British Columbia and Nova Scotia are particularly hampered by legislation that was designed to thwart the boogeyman represented by the USA Patriot Act.

BC and Nova Scotia have each adopted legislation that either categorically prohibits the "export" of personal information by public bodies, or put in place administrative hurdles. Alberta joins this pack by making it an offense under their public sector privacy law to disclose personal information in response to a "foreign demand for disclosure".

Part of the problem is that the legal framework is not particularly nuanced, as each decision about whether to outsource a service should be guided by a detailed risk assessment and privacy impact assessment instead of ham-fisted categorical rules that don't take particular circumstances into account.

Here is my presentation, which was well received.


If the embedded slideshow isn't showing you the love, click here: https://docs.google.com/present/view?id=ddpx56cg_320fx7rkbhh&interval=30

Commissioner tables annual Privacy Act Report for 2008-2009

The Privacy Commissioner of Canada has tabled her annual report on the public sector privacy law, the Privacy Act: Annual Report to Parliament 2008-2009 - Report on the Privacy Act.

At the same time, she has also tabled additional privacy audits, related to FINTRAC and the Canadian no-fly list:


Here's the media release that accompanied the tabling of the reports:

Audits of major national security programs raise concerns for privacy
Excessive reporting of personal information to FINTRAC and potential information technology risks with Canada’s “no-fly list” are among concerns identified in audits highlighted in the Privacy Commissioner’s annual report on public sector issues.

OTTAWA, November 17, 2009 — The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) has more personal information in its database than it needs, uses or has the legislative authority to receive.

This was one of the key findings of the Privacy Commissioner of Canada’s in-depth audit of the independent agency mandated to analyze financial transactions and identify suspected money laundering and terrorist financing in Canada.

A separate audit, also published today, examined the Passenger Protect Program – better-known to Canadians as the no-fly list. It identified several concerns, such as the fact that the Deputy Minister ultimately in charge of who is on the list was not provided with complete information to allow for informed decision-making.

“Since the terrorist attacks of 9/11, we’ve seen a proliferation of new national security programs. We fully appreciate the underlying aim of many security programs – protecting Canadians. However, it is critical – a point reinforced by our new audits – for government officials to integrate privacy protections into all of these programs at the outset,” says Privacy Commissioner Jennifer Stoddart.

The findings of the two audits are highlighted in the Commissioner’s 2008-2009 report to Parliament on Canada’s federal public-sector privacy legislation, the Privacy Act.

FINTRAC Audit

Legislative changes passed in 2006 expanded the types of transactions that must be reported to FINTRAC, as well as the number of professionals and organizations that are required to collect information about clients and to report it to FINTRAC. Examples of entities required to report to FINTRAC include financial institutions, life insurance companies, accountants and casinos.

The audit found that FINTRAC needs to do more to ensure that the amount of personal information it acquires is kept to an absolute minimum. A random sample of files examined in the audit turned up several reports that did not clearly demonstrate reasonable grounds to suspect money laundering or terrorist financing. For example:

A reporting entity filed several reports stating it was “taking a conservative approach in reporting this … because there are no grounds for suspecting that this transaction is related to the commission of a money laundering offence, but there is a lack of evidence to prove that the transaction is legitimate.”

An individual deposited a government cheque for an amount less than $300 and then withdrew the entire amount. The financial institution filed a suspicious-transaction report, but did not indicate why the transaction was deemed suspicious.

A financial institution filed a report about an individual who had deposited a cheque from a law firm. The institution was satisfied that the individual had provided legitimate reasons for the source of funds, but decided to notify FINTRAC anyway because of the individual’s ethnic origin and the fact that this person had visited a particular country.

“It is clear that such reports, containing not a shred of evidence of money laundering and terrorist financing, should not be making their way into the FINTRAC database,” says Commissioner Stoddart.

“It is a bedrock privacy principle that you collect only the personal information you need for a specific purpose,” she says. “The federal government needs to have a justifiable need to collect someone’s personal information. Clearly, FINTRAC needs to do more work with organizations to ensure it does not acquire personal information that it has no legislative authority to receive – and that it does not need or use.”

The audit recommended enhanced front-end screening of reports; stronger ongoing monitoring and review to ensure that information holdings are relevant and not excessive, and the permanent deletion of information that FINTRAC did not have the statutory authority to receive.

Under amendments passed in 2006, the Proceeds of Crime (Money Laundering) and Terrorist Financing Act requires the Privacy Commissioner to review FINTRAC every two years and report the results to Parliament.

Passenger Protect Program Audit

The “no-fly list” is a passenger screening tool introduced in 2007 to prevent people named on a “specified persons list” from boarding domestic and international flights from or to Canadian airports.

The program has sparked privacy concerns, in part because it is secretive in that it uses personal information without the knowledge of the individuals concerned. Moreover, the repercussions for a person named on the list being denied boarding on an aircraft can be profound in terms of privacy and other human rights, such as freedom of association and expression and the right to mobility.

The focus of the audit, however, was to determine whether the program has adequate controls and safeguards in place to protect personal information.

“We were concerned to learn that officials did not always provide the Deputy Minister – who is ultimately responsible for adding to or removing people’s names from the ‘specified persons’ list – all the information needed to make these sorts of decisions,” says Assistant Privacy Commissioner Chantal Bernier.

Other concerns identified during the audit included:

Transport Canada has not verified that airlines are complying with federal regulations related to the handling and safeguarding of the “specified persons list.” The risk of this information being inappropriately disclosed is particularly high for the small number of air carriers that rely on paper copies of the list.

There were no requirements that air carriers report to Transport Canada security breaches involving personal information related to the no-fly list.

Transport Canada did not demonstrate that the application used to transmit information to air carriers met government security standards.

The Passenger Protect Program and the FINTRAC audits, as well as the latest Privacy Act annual report, are available at http://www.priv.gc.ca/.

The annual report also includes details of privacy-related complaints against federal departments and agencies investigated during the 2008-2009 fiscal year. The Office received 748 formal complaints in 2008-2009, down slightly from the previous year. The most common complaints related to access to personal information and to the length of time government departments and agencies were taking to respond to access requests.

The Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy and the protection of personal information rights of Canadians.

To view the reports:


Nova Scotia introduces and then drops intrusive licence renewal form

Earlier today, the Nova Scotia government came under fire for introducing a new form for driver's licence renewals that asked applicants to say whether they had any kind of mental illness. (Critics: Don’t tie driver’s licence renewal to psychiatric history) Too much information, I say. So says the FOIPOP Review Officer, Dulcie McCallum.

Apparently anyone who checks off affirmatively will be required to provide a medical report detailing their mental illnesses, which may be referred to a medical panel to determine fitness to drive.

The question is so broad that it would capture loads of irrelevant information, including a bout of post-partum depression twenty years previously. Of course, many people will lie to keep their licences.

The form was introduced to replace a form that many called confusing.

What's most interesting is that the government promptly pulled the form and went back to the old one.

Backlash forces N.S. to drop new driver's licence form


“They should not be collecting personal information on this basis,” Dulcie McCallum, the province’s Freedom of Information and Protection of Privacy review officer, said.

“It’s completely unnecessary.”

That kind of information has historically been used against people, she said.

“It goes kind of to the heart of things that are most intimate and that people want most protected,” Ms. McCallum said. “You can’t make any assumptions about people. You can’t have a policy that automatically creates a different standard for people.

“There’s no evidence to support that somehow psychiatric challenges make you more or less of a bad driver.”

It would be more appropriate to ask if people were taking any prescription medication that could affect their driving, she said.

“That doesn’t connect it to any particular illness or disability or historically disadvantaged group and it may be a bona fide question,” she said.

David Fraser, a Halifax lawyer who specializes in privacy law, said the province deserves credit for acting quickly to fix its error but questioned whether reverting to the old form would solve the problem.

“It sounds to me like an interesting response,” he said. “I’m not sure if it’s to everybody’s benefit if they’re going back to a form that had previously been confusing.

Popular entries

 

Web world of law online public sector © 2012