Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

What's new in the anti-spam bill?

Since my redline of the PIPEDA amendments seemed to be of interest to readers of the blog, I thought readers may also be interested to see what has changed between the anti-Spam bill that fell off the order paper last parliamentary session (the Electronic Commerce Protection Act or ECPA) and the new Bill C-28, also known as the Fighting Internet and Wireless Spam Act or FISA.

Here is a redline comparing the old ECPA to the new FISA, via Google docs.

Privacy Commissioner tables annual PIPEDA report

The Privacy Commissioner of Canada has tabled her annual report for 2009 addressing PIPEDA. Here's the executive summary:

Introduction

The dominant theme of our work in 2009 was the protection of privacy in an increasingly online, borderless world.

A case in point was the investigation that resulted in more public attention than any other in our Office’s history: Facebook.

The investigation was a huge undertaking for us because it was wide-ranging and the issues were incredibly complex and, in some aspects, highly technical. We were also dealing with a multinational organization based in the United States.

We expect that, as people continue to spend more time online, we will see a growing number of complaints about online organizations. And, with the digital world erasing the borders between countries, more complaints will be about organizations outside Canada.

Data without Borders

We live in a world in which global data flows have become multipoint and multidirectional.

These streams of personal information circling the globe are only going to increase as more individuals take advantage of information and communication technologies.

There are currently some 1.5 billion Internet users. A billion more people are expected to join the online world in the next 10 years, with many of the new users coming from countries such as China, India and Brazil.

The need for a global privacy standard is clear, given global data flows and ubiquitous communication and information technologies. In our interconnected world, we need to take a co-operative approach to protecting personal information.

In 2009, our Office worked with several organizations and initiatives to develop a global privacy solution, including the Organisation for Economic Cooperation and Development, Asia-Pacific Economic Cooperation, International Conference of Data Protection Commissioners and the International Organization for Standardization.

Responding to Canadians

One of the most important ways we serve Canadians is through our inquiries service and investigations branch.

In 2009, we handled 5,095 new inquiries about issues that fall under PIPEDA. These calls and letters dealt with everything from how to ask an organization for access to personal information to whether a particular company has the right to collect a digital fingerprint.

We find that more people are turning to our website when they are seeking information about privacy issues. In 2009, we developed many materials and tools for our website, including complaint and data breach reporting forms and numerous fact sheets and guidance documents for business.

Our Office received 231 new PIPEDA-related complaints for investigation in 2009 – a drop from the 422 we received the previous year.

Part of this decrease is explained by the fact that we are encouraging people to try to resolve issues directly with organizations before they make an official complaint. We’re finding that many problems can be dealt with quickly – and in a way that is satisfactory to would-be complainants.

Our investigations dealt with a wide range of issues, including the online collection and use of personal information; covert surveillance by private investigation firms; workplace surveillance, such as the use of video cameras and location-tracking devices, and the collection of driver’s licence information by retailers.

We closed 587 complaints in 2009, a significant increase compared with 412 the previous year. Our concerted effort to eliminate a backlog of complaints was successful, and this will allow us to complete future investigations far more quickly.

We were pleased that many private-sector organizations voluntarily reported data breaches to our Office. We received 58 breach reports in 2009. That was fewer than the previous year, when a large number of mortgage brokers reported breaches to us.

Protecting Privacy in a Changing Environment

We continued to stress the need to ensure that laws keep up with changing threats to privacy.

We welcomed the adoption of legislation to combat identity theft through amendments to the Criminal Code.

Important legislation aimed at fighting electronic spam, the Electronic Commerce Protection Act, was also introduced and we hope it will be passed into law in the near future. Canada is currently the only G-8 country without anti-spam legislation.

That bill also included legislative amendments that would increase our Office’s ability to share information about spam and other privacy issues with provincial and foreign counterparts who enforce laws similar to PIPEDA. It would also provide the Commissioner with greater discretion to accept complaints or discontinue investigations.

New technologies sometimes put privacy laws to the test – and this was the case in 2009 as well. Social networking sites and online street-level imaging applications, for example, highlighted new ways of collecting and using personal information.

We found that PIPEDA – a technology-neutral and principles-based law – appears to be flexible enough to guide commercial uses of new technology.

While we addressed privacy concerns in social networking as part of our investigative work, we dealt proactively with our concerns about street-level imaging during a series of discussions with Google Street View and Canpages. These discussions resulted in improved privacy protection on both websites.

We also did extensive work on the issue of deep packet inspection – both as part of an in-depth investigation and submissions to the Canadian Radio-television and Telecommunications Commission (CRTC). As well, we created a website showcasing a series of essays on deep packet inspection by leading academics and professionals working in telecommunications, law, privacy, civil liberties and computer science. The project grew out of our desire to better understand a technology that can be a tool for network traffic management, behavioural advertising, and law enforcement. We hope it will promote discussion about the privacy implications of deep packet inspection.

New anti-spam bill introduced

My head has been spinning with the proposed new amendments to PIPEDA introduced this week so that I haven't really had a chance to focus on Bill C-28 (Fighting Internet and Wireless Spam Act). David Canton has a good summary and introduction over at Slaw: FISA – new anti-spam bill introduced — Slaw.

Markup of Bill C-28 and Bill C-29 Amendments to PIPEDA

Due to popular demand, here's a markup of PIPEDA showing the proposed amendments made by both Bill C-28 (Fighting Internet and Wireless Spam Act) and Bill C-29 (An Act to amend the Personal Information Protection and Electronic Documents Act), via Google Docs.

Breach notification amendments to PIPEDA introduced in Parliament

Industry Minister Tony Clement has tabled legislation to amend PIPEDA, requiring data breach notification. (I haven't seen the text of the bill yet, but will provide a link as soon as I get my hands on it).



From the preliminary coverage (Firms not required to inform victims of privacy breach under new rules), it appears the new rules will be the same as Alberta's only requiring notice to affected individuals if the company determines there exists a "real risk of significant harm". Critics suggest that this threshold is too low or leaves too much discretion in the hands of companies.



Here's the press release, which outlines other amendments being made to PIPEDA:


Government of Canada Moves to Enhance Safety and Security in the Online Marketplace





OTTAWA, ONTARIO--(Marketwire - May 25, 2010) - The Honourable Tony Clement, Minister of Industry, and the Honourable Denis Lebel, Minister of State (Economic Development Agency of Canada for the Regions of Quebec), today announced two steps that the Government of Canada is taking to enhance the safety and security of the online marketplace. Together, the tabling of amendments to the legislation protecting the personal information of Canadians (Personal Information Protection and Electronic Documents Act, or PIPEDA) and the reintroduction of anti-spam legislation in the House of Commons (the proposed Fighting Internet and Wireless Spam Act, or FISA) are important steps towards positioning Canada as a leader in the digital economy.



"Canadian shoppers should feel just as confident in the electronic marketplace as they do at the corner store," said Minister Clement. "With today's two pieces of legislation, we are working toward a safer and more secure online environment for both consumers and businesses — essential in positioning Canada as a leader in the digital economy."



"Our government believes that personal information should be no less secure when shared online than anywhere else. That is why we are taking steps to ensure it is better protected," said Minister of State Lebel. "These measures will empower and better protect consumers while ensuring that Canadian businesses can continue to compete in the global marketplace."



To address public concerns about the increasing number of data breaches involving personal information, PIPEDA proposes a new requirement for organizations to report material data breaches to the Privacy Commissioner of Canada and to notify individuals where there is a risk of harm. This requirement will complement the government's recently enacted identity theft legislation and encourage better information security practices on the part of organizations.



PIPEDA also proposes amendments related to protecting the privacy of minors and other vulnerable individuals online. Other amendments are designed to clarify and streamline rules for business and support effective investigations by law enforcement and security agencies.



The proposed FISA is intended to deter the most damaging and deceptive forms of spam, such as identity theft, phishing and spyware, from occurring in Canada and to help drive spammers out of Canada.



The proposed FISA legislation provides a comprehensive regulatory regime that uses economic disincentives to protect electronic commerce and is modelled on international best practices. To enforce the legislation, the bill would use the expertise, and expand the mandates, of the three enforcement agencies: the Canadian Radio-television and Telecommunications Commission, Competition Bureau Canada and the Office of the Privacy Commissioner of Canada.



Industry Canada will act as a national coordinating body to increase consumer and business awareness and education, to further coordinate work with the private sector and to conduct research and intelligence gathering.



Backgrounder



Government of Canada Introduces Amendments to the Personal Information Protection and Electronic Documents Act (PIPEDA)



The Government of Canada has introduced enhancements to private sector privacy legislation in a bill seeking to amend the Personal Information Protection and Electronic Documents Act (PIPEDA). In doing so, the Government is implementing the Government Response to the first statutory review of PIPEDA and is delivering on a commitment made by the Minister of Industry at the June 22, 2009, forum entitled Canada's Digital Economy: Moving Forward.



In a modern, information-based economy, or "digital economy", a solid, efficient regime for the protection of personal information is vitally important for both consumers and businesses.



To ensure that PIPEDA continues to keep pace with rapid marketplace and technological changes, and their societal impacts, the proposed amendments in this Bill are designed to:



protect and empower consumers;



clarify and streamline rules for business;



enable effective investigations by law enforcement and security agencies; and,



make linguistic and other technical drafting corrections.



EMPOWERING CONSUMERS



The proposed amendments will make a significant contribution to the government's efforts to ensure a safe and secure Internet for Canadians. A key proposed amendment would require organizations to report material data breaches of personal information to the Privacy Commissioner of Canada, and to notify affected individuals when the organization deems the breach to pose a real risk of significant harm, such as identity theft or fraud, or damage to reputation. This amendment will not only provide consumers with the information they need to mitigate harm resulting from a breach of their personal information, it will also encourage better information security practices in organizations. This proposed amendment will complement the government's new identity theft law, An Act to amend the Criminal Code (identity theft and related misconduct).



Acknowledging the increasing Internet usage rates of children, Canada is working with a number of international organizations to develop strategies to better protect children online. The Bill proposes an amendment to PIPEDA's consent regime that will provide further protection for children online by requiring organizations to consider the ability of their target audience to comprehend the consequences of sharing their personal information.



The Bill also proposes additional exceptions to allow for the release of personal information to help protect victims of financial abuse, to help locate missing persons and to identify injured, ill or deceased individuals.



STREAMLINING RULES FOR BUSINESS



In its October 2007 Response to the Report of the Standing Committee on Access to Information, Privacy and Ethics, the Government committed to supporting business by providing greater clarity and certainty with respect to key provisions of PIPEDA. The Bill proposes exceptions to consent for the collection, use and disclosure of information needed for, among others, managing the employment relationship, information produced for work purposes ("work product"), and information used for due diligence in business transactions. Organizations will also be able to share and use business contact information that is required to conduct day-to-day business.



In addition, a new provision allowing the disclosure of personal information without consent for private sector investigations and fraud prevention will replace a regulatory process that has been burdensome for small and medium-size organizations.



SUPPORTING EFFECTIVE LAW ENFORCEMENT



Another key thrust of the Bill is supporting effective law enforcement. The Government considers the safety and security of Canadian citizens to be of utmost importance. Proposed amendments will reaffirm the view that the information needs of law enforcement and security agencies can be met while respecting the privacy rights of Canadians. Proposed amendments would make it clear that organizations may collaborate with government institutions, such as law enforcement and security agencies that have requested personal information, in the absence of a warrant, subpoena, or order. To avoid jeopardizing investigations, new provisions would prohibit organizations from notifying an individual about the disclosure of their personal information to law enforcement and security agencies where the government institution to whom the information was disclosed objects.



COMPLETING A PARLIAMENTARY PROCESS



Part 1 of the Personal Information Protection and Electronic Documents Act (PIPEDA) governs the collection, use and disclosure of personal information in the course of commercial activity. It has been in force since January 1, 2001, and is mandated to be reviewed by Parliament every five years.



This Bill acts on the Government's October 2007 Response to the Report of the Standing Committee on Access to Information, Privacy and Ethics arising from the first Parliamentary review of the Act. The Government Response addressed each of the 25 recommendations contained in the Committee's report and committed to amending the Act in agreement with many of the Committee's recommendations.



In its report, the Committee recognized that the Act is working well and does not require major changes at this time. The Committee recommended the "fine-tuning" of some of the Act's provisions and encouraged increased harmonization with provincial privacy laws.



Industry Canada, which administers the Act, conducted formal consultations with stakeholders in order to further develop and define options for implementing the Government Response to the Committee report. The Government received 76 written submissions, and officials held more than 25 meetings involving a wide range of stakeholders including business, consumer and privacy advocates, the Privacy Commissioner of Canada, provincial governments and law enforcement authorities.



Where possible, the proposed amendments take into consideration approaches taken in provincial privacy laws.

Update: Here is the First Reading text of Bill C-29.

Anti-Spam and data breach notification bills expected next week

According to Michael Geist, the conservative government has given notice that it will table two bills next week. The first is the reintroduction of the Anti-Spam Act, also known as the Electronic Commerce Protection Act. The second, an Act to amend PIPEDA, is expected to add data breach notification.

Prime Minister prorogues parliament, privacy legislation in limbo

It's official, the Prime Minister is proroguing parliament until the beginning of March: CBC News - Politics - PM seeks Parliament shutdown until March. (Never mind that they've been on vacation since November.)

This means that a number of privacy-affecting bills are being forced into a coma. The list includes:

  • Bill C-27 - Electronic Commerce Protection Act (Second Reading in the Senate and Referred to Committee on December 15, 2009) (aka Anti-spam Act);
  • Bill C-46 - Investigative Powers for the 21st Century Act (Referred to Committee on October 27, 2009);
  • Bill C-47 - Technical Assistance for Law Enforcement in the 21st Century Act (Referred to Committee on October 29, 2009);

The media is also reporting that, in the meantime, Harper plans to fill five vacant senate seats, which will give the Conservatives the majority they need to ensure safe passage of their legislation.

Canadian anti-spam bill introduced

The Industry Minister tabled the Electronic Commerce Protection Act (ECPA) in Parliament at the end of last week.

Here's the government's press release and backgrounder:

Industry Canada Site - Government of Canada Protects Canadians with the Electronic Commerce Protection Act

Government of Canada Protects Canadians with the Electronic Commerce Protection Act
OTTAWA, April 24, 2009 — The Honourable Tony Clement, Minister of Industry, today announced that the Government of Canada is delivering on its commitment to protect consumers and businesses from the most dangerous and damaging forms of spam. The government has introduced legislation in Parliament that aims to boost confidence in online commerce by protecting the privacy and personal security concerns that are associated with spam, counterfeit websites and spyware.

The proposed Electronic Commerce Protection Act (ECPA) will deter the most dangerous forms of spam, such as identity theft, phishing and spyware, from occurring in Canada and will help drive spammers out of Canada.

“Our government knows how damaging spam can be to Canadians and Canadian businesses and that is why we are cracking down on Internet fraud and other forms of malicious activities,” said Minister Clement. “With this landmark legislation, our government will help protect consumers from Internet spam and related threats and boost confidence in the electronic marketplace.”

Spam and related online threats are a real concern to all Internet users as they can lead to the theft of personal data, such as credit card information (identity theft), online fraud involving counterfeit websites (phishing), the collection of personal information through illicit access to computer systems (spyware), and false or misleading representations in the online marketplace. The proposed legislation would also treat unsolicited text messages, or “cellphone spam,” as “unsolicited commercial electronic messages.”

This bill would allow businesses and consumers to take civil action against anyone who violates the ECPA. The Canadian Radio-television and Telecommunications Commission (CRTC), the Competition Bureau and the Office of the Privacy Commissioner will be given the power to share information and evidence with their counterparts in other countries who enforce similar laws internationally, so that violators beyond our borders cannot use Canada as a spam safe haven. The proposed ECPA would allow the CRTC and the Competition Bureau to charge offenders with administrative monetary penalties of up to $1 million for individuals, and $10 million for all other offenders.

Under the new legislation, Industry Canada will act as a “national coordinating body” in order to increase consumer and business awareness and education, to further coordinate work with the private sector in support of voluntary guidelines, and to conduct research and intelligence gathering.

As part of the proposed ECPA, new legislative measures would complement the federal government's previous efforts to address spam and related online threats.

In introducing this legislative proposal, the Government of Canada wishes to thank Senators Donald Oliver and Yoine Goldstein for their efforts to help address this issue. The bill also addresses the legislative recommendations of the Task Force on Spam. The Government of Canada, Canadian business and Canadian consumers owe a debt of thanks to Senators Oliver and Goldstein and to the Task Force for their contributions to the protection of electronic commerce and the online economy.

--------------------------------------------------------------------------------

April 24, 2009

Backgrounder

Government of Canada Introduces the Electronic Commerce Protection Act
On April 24, 2009, the Government of Canada introduced anti-spam legislation, entitled the Electronic Commerce Protection Act (ECPA). In doing so, the government is delivering on a key commitment made by Prime Minister Harper to Canadians and Canadian businesses in September 2008.

This bill addresses the legislative recommendations of the Task Force on Spam, which brought together industry, consumers and academic experts to design a comprehensive package of measures to combat threats to the online economy.

The intention of the proposed legislation is to deter the most dangerous and damaging forms of spam from occurring in Canada and to help to drive spammers out of Canada.

The government studied successful legislative models in other countries and, based on their experiences, has developed a focused plan to address spam and related threats. By tabling legislation now, the government is able to address the latest technology and online threats.

This bill proposes a private right of action, modelled on U.S. legislation, which would allow businesses and consumers to take civil action against anyone who violates the ECPA. The proposed ECPA's technology-neutral approach allows all forms of commercial electronic messages to be treated the same way. This means that the proposed bill would also address unsolicited text messages, or “cellphone spam,” as a form of “unsolicited commercial electronic message.”

The bill would establish a clear regulatory enforcement regime consistent with international best practices and a multi-faceted approach to enforcement that protects consumers and empowers the private sector to take action against spammers.

An important component of the proposed ECPA is the enforcement regime whereby the Canadian Radio-television and Telecommunications Commission (CRTC), the Competition Bureau and the Office of the Privacy Commissioner would be given the authority to share information and evidence with their counterparts who enforce similar laws internationally, in order to pursue violators beyond our borders.

The proposed ECPA would enable the CRTC to impose administrative monetary penalties (AMPS) of up to $1 million for individuals and $10 million in all other cases. The Competition Bureau would use a similar AMPS regime already provided for in the Competition Act,and the Office of the Privacy Commissioner would use its existing tools and enforcement framework to enforce the provisions of this legislation. The bill also proposes that the Privacy Commissioner's powers to cooperate and exchange information with her counterparts be expanded, in respect of the Personal Information Protection and Electronic Documents Act.

Consultations show support from consumers, Internet service providers, marketers, businesses, educators, the financial sector, legal and consumer groups, and enforcement agencies.

Under the proposed ECPA, Industry Canada would act as a “national coordinating body” in order to expand awareness and education of consumers, network operators and small businesses, coordinate work with the private sector, and conduct research and intelligence gathering.

The government also intends to create a Spam Reporting Centre that would receive reports of spam and related threats allowing it to collect evidence and gather intelligence to assist the three enforcement agencies (the CRTC, the Competition Bureau and the Office of the Privacy Commissioner).

Businesses will benefit from improved protection against harm to the network and from consumers' strengthened confidence in the online marketplace.

The Internet has become the primary platform for online commerce and general communications. The online marketplace represents a major segment of Canada's economy, with $62.7 billion in sales in 2007. Worldwide, electronic commerce is projected to exceed $8.75 trillion in 2009.

At the same time, there has been an enormous increase in the vulnerabilities and threats to the Internet and online commerce. Spam now makes up over 80 percent of global email traffic, imposing huge costs on businesses and consumers.

Canada's anti-spam act passes and receives royal assent

Bill C-28, Fighting Internet and Wireless Spam Act, also known as the anti-spam act, has passed through the sentate and received royal assent on December 15, 2010. It comes into force on the day or days set by the Governor in Council.

Check it out: LEGISINFO - The Library of Parliament's research tool for finding information on legislation.

Facebook wins $873M judgment against spammer

Facebook has just won a multi-multi-million dollar judgment against a Montreal residet under the American CAN-SPAM Act after the individual was accused of sending millions of unsolicited commercial e-mails to Facebook users. The company will never see most of the cash, but Facebook has said they'll go after all they can.

Hopefully, this will be a strong, visible deterrent.

See: The Associated Press: Facebook wins $873M judgment against spammer.

Canada's Anti-Spam Act back on the order paper

Bill C-28, called the Fighting Internet and Wireless Spam Act (or, more formally: An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities, and to amend the Canadian Radio-television and Telecommunications Commission Act, the Competition Act, the Personal Information Protection and Electronic Documents Act and the Telecommunications Act) is back on the order paper in Parliament today. Here's the bill's status and a link to the full-text: LEGISINFO - The Library of Parliament's research tool for finding information on legislation.

Via @kaplanmyrth.


Google reduces log retention times

Google has just announced that they are cutting their log retention period in half: from 18 monts to 9 months.

From the Official Google Blog:

Official Google Blog: Another step to protect user privacy

Today, we're announcing a new logs retention policy: we'll anonymize IP addresses on our server logs after 9 months. We're significantly shortening our previous 18-month retention policy to address regulatory concerns and to take another step to improve privacy for our users.

Back in March 2007, Google became the first leading search engine to announce a policy to anonymize our search server logs in the interests of privacy. And many others in the industry quickly followed our lead. Although that was good for privacy, it was a difficult decision because the routine server log data we collect has always been a critical ingredient of innovation. We have published a series of blog posts explaining how we use logs data for the benefit of our users: to make improvements to search quality, improve security, fight fraud and reduce spam.

Over the last two years, policymakers and regulators -- especially in Europe and the U.S. -- have continued to ask us (and others in the industry) to explain and justify this shortened logs retention policy. We responded by open letter to explain how we were trying to strike the right balance between sometimes conflicting factors like privacy, security, and innovation. Some in the community of EU data protection regulators continued to be skeptical of the legitimacy of logs retention and demanded detailed justifications for this retention. Many of these privacy leaders also highlighted the risks of litigants using court-ordered discovery to gain access to logs, as in the recent Viacom suit.

Today, we are filing this response (PDF file) to the EU privacy regulators. Since we announced our original logs anonymization policy, we have had literally hundreds of discussions with data protection officials, government leaders and privacy advocates around the world to explain our privacy practices and to work together to develop ways to improve privacy. When we began anonymizing after 18 months, we knew it meant sacrifices in future innovations in all of these areas. We believed further reducing the period before anonymizing would degrade the utility of the data too much and outweigh the incremental privacy benefit for users.

We didn't stop working on this computer science problem, though. The problem is difficult to solve because the characteristics of the data that make it useful to prevent fraud, for example, are the very characteristics that also introduce some privacy risk. After months of work our engineers developed methods for preserving more of the data's utility while also anonymizing IP addresses sooner. We haven't sorted out all of the implementation details, and we may not be able to use precisely the same methods for anonymizing as we do after 18 months, but we are committed to making it work.

While we're glad that this will bring some additional improvement in privacy, we're also concerned about the potential loss of security, quality, and innovation that may result from having less data. As the period prior to anonymization gets shorter, the added privacy benefits are less significant and the utility lost from the data grows. So, it's difficult to find the perfect equilibrium between privacy on the one hand, and other factors, such as innovation and security, on the other. Technology will certainly evolve, and we will always be working on ways to improve privacy for our users, seeking new innovations, and also finding the right balance between the benefits of data and advancement of privacy.

Popular entries