air travel

Showing posts with label air travel. Show all posts
Showing posts with label air travel. Show all posts

Eye scans at airport for U.S.-bound travellers

I was contacted by the Canadian Broadcasting Corporation yesterday to comment on a new inititiave to speed cross-border travel between the US and Canada for "low risk" travellers. New technologies allow pre-screened passengers to skip through customs and immigrations after confirming their identity with an iris scan:

Eye scans at airport for U.S.-bound travellers:

"...The iris scans are voluntary, and no one is compelled to go through a process that critics say is invasive.

But Halifax privacy lawyer David Fraser says increasingly, people are deciding it's worth it.

'Survey after survey says that people are concerned about their privacy, but they really don't put their money where their mouth is,' he says.

'It's easy to tell a pollster that, but when it comes to trading privacy for convenience, people often chose convenience.' ..."

Leading privacy groups release annual global report

Privacy International and the Electronic Privacy Information Center have recently released their seventh annual Privacy and Human Rights Survey, which details global threats to privacy and related civil rights. It particularly highlights the increasing surveillance of citizens and intrusive uses of technology in the battle against terrorism.

From the joint EPIC/PI press release:


Privacy International & EPIC Release Annual Global Privacy Study

17/11/2004

GLOBAL HUMAN RIGHTS STUDY WARNS OF ENDEMIC PRIVACY THREATS

Major report sets out government surveillance strategies

17th November 2004

A major international privacy report published today has concluded that governments across the world have substantially increased surveillance in the past year. The report warns that threats to personal privacy have reached a level that is dangerous to fundamental human rights.

The 7th annual Privacy and Human Rights survey, published by Privacy International & the US based Electronic Privacy Information Center (EPIC) reviews the state of privacy in sixty countries and warns that invasions of privacy across the world has increased significantly in the past twelve months. The 800 page report is available free of charge at http://www.privacyinternational.org/survey/phr2004

The report paints a bleak picture of the erosion of the right to privacy, particularly since the September 11th attacks in the United States. It observed: that crime and public order laws passed in recent years have placed substantial limitations on numerous rights, including freedom of assembly, privacy, freedom of movement, the right of silence, and freedom of speech. Governments have continued to use terrorism as the pretext for an increase of surveillance, even when surveillance is unwarranted.

The report identifies a trend across the world toward mass surveillance of the general population, and cited a catalogue of illegal spying and surveillance activities by government agencies.

In response to calls for increased security many countries have pursued policy and legislative efforts that aim at implementing identification schemes, expanding the surveillance of communications for law enforcement and national security agencies, weakening data protection regimes, and intensifying data sharing and collection practices - all made possible by a growing cooperation between government entities and the private sector.

The report singles out a number of trends:


  • New identification measures and new traveller pre-screening and profiling systems
  • New anti-terrorism laws and governmental measures provide for increased search capabilities and sharing of information among law enforcement authorities
  • Increased video surveillance
  • DNA and health information databases
  • Censorship measures
  • Radio frequency identification technologies
  • New electronic voting technologies
  • Mismanagement of personal data and major data leaks


Privacy International's Director, Simon Davies, said the report highlighted a 'disturbing' trend toward greater state power. 'Governments are systematically removing the right to privacy. Surveillance of every type is being instituted throughout society without any thought about the need for safeguards.'

'The spectre of terrorism has at last become the device that any government can deploy to entrench the powers they always sought. The situation has become a dangerous farce,' he added.

'Governments are joining together their data systems. They are sharing information to a greater extent each year with the private sector. And they are cooperating unquestioningly with other governments to exchange vast reserves of personal information. This situation cannot continue without imperilling the right to privacy', said Mr Davies.

On a more upbeat note, the report did identify positive counter-trends:

'Invasions of privacy were met in various countries with forceful reactions from human rights groups. In Germany, outcry against a retail chain's use of RFID tags unbeknownst to its customers led to the halt to the company's projects. In Greece, the data protection authority struck down the use of biometric identity verification in airports because the collection of personal information through RFID tags exceeded its purpose. In Malaysia, the Bar Council criticized the security and privacy risks of Mykad, the multi-purpose smart card, which forced the government to work on a legislation to answer such concerns. In Poland, the Constitutional Tribunal held unconstitutional a law that allowed police officers to observe and record events in public places. Public interest groups had opposed the law alleging that it violated the right to privacy enshrined in the Polish Constitution. In Sweden, the privacy commissioner forbade a school's fingerprint recognition program. In Ukraine, a new law that restricts access to information was strongly opposed by several NGOs and international organizations because of its violation of the Constitution and global freedom of information standards. In reaction, amendments were introduced that improve the final version of the law.'

Privacy Battle Could Halt European Flights to U.S.

Further to my posting of Tuesday, The Canadian Privacy Law Blog: EU Advocate General says European-US passenger data sharing agreement violates European law, there is speculation that a ban on cross-Atlantic data sharing may result in European airlines being prevented from flying to the US: RedOrbit - Technology - Privacy Battle Could Halt European Flights to U.S.. I doubt it'll come to that, but ...

Tracking impact of computer thefts and break-ins on privacy

OnlyPunjab.com is carrying what appears to be an advertorial for PC Guardian that reports that computer thefts and break-ins in North America for 2003/04 resulted in the compromise of information for 2.5 million North Americans. (No word on how many Punjabi identities were compromised.) Regardless of the source, it is an interesting read:

North America's "October Surprise" - 2.5 Million Personal Electronic Records Stolen in 2004 Due to Computer Thefts:

"For instance, in the last 12 months PC Guardian has identified the following thefts:

  1. Officials for the Ohio Democratic Party announced the theft of three computers, including a server that contained the local party's financial information, names and personal phone numbers of hundreds of party members, candidates and volunteers.
  2. The Republican Party campaign headquarters in Washington state announced the theft of three laptops with confidential Bush-Cheney campaign information.
  3. Reynolds Cancer Support Center officials warned clients that a server containing personal health information was stolen from its Fort Smith, Ark., office.
  4. A Lake Forest, Calif., direct mail marketing company reported the theft of a server containing personal financial records of more than 100,000 credit union customers in the western United States.
  5. First Option Financial reported the theft of thousands of personal financial records when computers were stolen from its office in Houston, Texas.
  6. Wells Fargo & Company lost more than 200,000 customer financial records when two laptops were stolen, one in California, the other in Texas.
  7. Airlines Reporting Corporation (ARC), in Arlington, Virginia, reported the theft of computers containing financial data on thousands of customers from United Air Lines, Northwest Airlines, Delta Airlines and American Airlines.
  8. Kern County Mental Health Office lost 110,000 personal Medicare records when a laptop was stolen from its Bakersfield, Calif. office."

ChoicePoint appoints first privacy officer

ChoicePoint has appointed a big name former TSA official to be its new privacy officer, according to Forbes:

Forbes.com: Smith: ChoicePoint Names TSA Big As Chief Privacy Officer:

Faces In The News Smith: ChoicePoint Names TSA Big As Chief Privacy Officer Greg Levine, 03.08.05, 5:13 PM ET NEW YORK - Doers and doings in business, entertainment and technology: It's a start. Data dealer ChoicePoint (nyse: CPS - news - people ) on Tuesday announced it hired a U.S. Transportation Security Administration big to batten its info hatches. Helmed by Chief Executive Derek Smith, the firm has recently suffered an incursion by identity thieves. (Related note: On Feb. 25, Bank of America (nyse: BAC - news - people ) too suffered a security compromise.) ChoicePoint said its new employee, TSA Deputy Administrator Carol A. DiBattiste, has been named chief credentialing, compliance and privacy officer. She will lead an independent office to oversee improvements to ChoicePoint's screening process, and its enacting of procedures to streamline how incidents are reported. The TSA oversees airport screening in the U.S. Any such moves to regain the public's trust are vital at this juncture: After the CEO stated that the recent incident was the only such major security compromise of which he was aware, Assistant U.S. Attorney Mark Krause in Los Angeles claimed he'd dug up evidence of to the contrary, viz.: A sizable identity theft in 2002. Then, on March 4, the firm said the U.S. Securities and Exchange Commission is investigating stock sales by Smith and by Chief Operating Officer Douglas Curling. So it couldn't hurt ChoicePoint's image--not to mention its operations--to bring in "untouchables" like DiBattiste. More...


It is somewhat surprising that a company that deals in personal information never had an officer responsible for privacy. Perhaps that's why the original breaches never came to the attention of the executives.

Organizations in Alberta and British Columbia Receive Exemption from Federal Personal Information Protection Legislation

As announced on this page last week, the private sector privacy laws of Alberta and British Columbia have been declared by the Federal Cabinet to be substantially similar to PIPEDA. The official announcement was made by Industry Canada today:

Organizations in Alberta and British Columbia Receive Exemption from Federal Personal Information Protection Legislation:

OTTAWA, November 3, 2004 — The Government of Canada today announced that organizations in Alberta and British Columbia that are subject to either province's private sector privacy laws are exempt from the Personal Information Protection and Electronic Documents Act (PIPEDA). This exemption applies to the collection, use and disclosure of personal information within either province.

PIPEDA will continue to apply to the collection, use and disclosure of personal information related to the operations of a federal work, undertaking or business (e.g. banks, airlines, telecommunications companies) in both provinces, as well as to the cross-border collection, use and release of personal information.

Both Alberta and British Columbia have privacy legislation that is considered substantially similar to PIPEDA. This helps ensure the existence of an effective national standard for privacy protection, which also meets accepted international norms. Clear, consistent rules for the protection of personal information increase consumer and business confidence in online commerce.

PIPEDA came into full effect January 1, 2004. It applies to all personal information collected, used or disclosed by private sector organizations in the course of commercial activity. Its privacy provisions are based on the Canadian Standards Association's Model Code for the Protection of Personal Information (CAN/CSA-Q830-96). The Act's key provisions state:

  • organizations are required to seek the consent of individuals prior to collecting, using or disclosing their personal information;
  • organizations must protect personal information with security safeguards appropriate to the sensitivity of the information; and
  • individuals may access personal information about themselves held by an organization and have it corrected, if necessary.

For more information on PIPEDA, please visit http://www.strategis.ic.gc.ca/privacy.

For more information on compliance, organizations should refer to the Office of the Privacy Commissioner's online guide at http://privcom.gc.ca/information/guide_e.asp.

For more information, please contact:

Media Relations

Industry Canada

(613) 943-2502


For those in the loop, RFID is a privacy concern

Government Technology is reporting a recent survey that has determined that, among those who are aware of RFID, 63% of those polled are concerned about the privacy issues related to the emerging technology. The surveyed consumers said that government, followed by "crooks and bad guys," banks, insurance companies and credit card companies are the most likely to abuse their privacy without their knowledge and consent.

Study Detailing RFID Privacy Concerns Released:

"....Consumers express being more concerned with privacy issues today than ever before. And with many forms becoming electronic, they are cautious about divulging personal information and are taking active steps to protect themselves such as checking to make sure websites are secure before submitting information and shredding paper and mail received unsolicited at home. Many believe their personal information is easily obtained by companies through magazine subscriptions and frequent-buyer programs implemented by grocery stores and airlines.

Although consumers recognize the "perks" of being rewarded for loyal shopping behavior, they are also concerned that their information is not protected and will be shared without their permission. "Almost everyone knows somebody lately who has had a bad experience with privacy invasion, credit card abuse or identify theft," said Linda Stegeman, president of Artafact. "In online focus groups, they recount stories of friends or families who have been affected by institutions or crooks and bad guys getting access to their personal information."

Only 35% of consumers concerned about protecting their personal information believe that RFID (Radio Frequency Identification) is a "good idea." However, they also recognize the business benefits of easily tracking merchandise and preventing theft. Many consumers think they will not reap any benefit from RFID technology and are concerned with the potential for misuse, given the "lack of safeguards."


Canadians in American government databases

The Toronto Star, which has the best privacy coverage of any Canadian daily newspaper, is running an article by Thomas Walkom that highlights the amount of data about Canadians that may be in the hands of American authorities. It begins with a discussion of Canadian tax records that found their way into the possession of an American prisoner, via the Department of Homeland Security. The article also discussed the Arar case and the use of No-Fly Lists by Canadian airlines.


TheStar.com - Uncle Sam's steely glare:

"... It's safe to say she never expected to find her name, Canadian income tax summaries and social insurance number in the files of the U.S. Homeland Security Department. Indeed, if it weren't for a fluke, she probably never would have...."

Facial scans, digital fingerprints to be compiled for Canadian border security project

Canadian immigration authorities are making their first foray into using biometrics to keep track of refugees, immigrants and visitors to Canada. A pilot project is being implemented at border crossings in British Columbia and the Vancouver International Airport. The test will involve digital photos and fingerprints. At the moment it is only a pilot project, but is likely a sign of things to come. From the Canadian Press: Facial scans, digital fingerprints to be compiled for border security project - Yahoo! News.

Commentary on new international passenger info transfer rule

As of this week, the US Government requires all airlines, cruise ship companies and others to provide the Department of Homeland Security with detailed passenger information in standard, electronic format. The Practical Nomad notes this new development and offers a strong opinion on the new regulations. While the government may have an interest in obtaining this information, the author is more than a little upset that passengers are required to hand it over to the carriers (which are often unregulated in what they do with the info), who then pass it to the government:

The Practical Nomad blog: USA requires passenger details from international airlines:

"... But that's not what the rule requires: the rule gives travellers no option to provide the required information directly to the CBP. Instead, the rule requires airlines to provide passengers' personal information to the CBP, effecting requiring travellers -- if the airlines are to be able to comply, without which airlines' passengers won't be allowed to travel -- to turn over their information to the airlines as well as the government.

Both the final rule and the PIA entirely ignore the implications of requiring passengers to provide detailed personal information to, at a minimum, airlines (and, in most cases, other companies such as Computerized Reservation Systems (CRS's) and travel agencies), under government order, without imposing any restrictions whatsoever on the ability or authority of the recipient airlines and other companies to use, rent, or sell the information that passengers will be forced to give them, without any requirement for notice or consent. This government-compelled transfer of rights in personal data to unregulated private entities is the real violation of privacy rights in the new rule...."

Canada and EU sign data-sharing accord for passenger information

Canada and the European Union have signed an agreement for the transatlantic transfer of passenger data. I haven't seen the actual accord yet, but both sides are naturally talking about how wonderful it is and how it incorporates robust data protection standards.

Air Transport World Daily News:

"European Union and Canada signed an agreement allowing the transfer of selected API/PNR data by airlines flying from the EU to Canada. 'The agreement strikes a good balance between security requirements and the data protection standards required under EU and Canadian law, thus making an important contribution to the fight against terrorism,' the European Commission said in a statement, noting that the negotiations took 'over two years of painstaking work.' The EC said the agreement with Canada gives further enhanced data protection compared to the deal concluded with the US last year, and a smaller number of data elements are involved. In addition, carriers will initiate the transfer of data using the so-called 'push' system. The European Parliament is trying to get the agreement with the US blocked and has lodged an appeal against it with the European Court of Justice. The court's ruling is expected in the coming months. The accord with Canada will enter into force once notes have been exchanged confirming that the Canadian side has completed the internal regulatory changes necessary for full implementation."

Article: Product ID tags raise privacy concerns

Delaware Online has an article referring to a recent conference on RFID technology an includes a brief discussion of the privacy issues raised by the use of the chips:

www.delawareonline.com : Product ID tags raise privacy concerns:

"The potential for tracking more than just products has prompted the formation of groups such as Consumers Against Supermarket Privacy Invasion and Numbering.

RFID devices can be read from 20 to 30 feet away and the antennas, first made from copper, can now be printed with conductive ink, making it difficult for consumer to know if products they buy contain RFID transmitters, the group argues. The group has proposed legislation that would require the complete disclosure of products containing RFID devices.

While some have concerns about the tags being used to track more than just products, Ed Coyle, head of the Department of Defense's Logistics Automatic Information Technology office, said at the confer- ence that the key to security, or privacy concerns, is limiting the amount of information on the tags, which also makes the system speedier. "



I am not sure I agree with this last sentiment. The privacy impact of the technology has very little to do with the amount of information embedded in the chip. What matters is the database that the unique identifier is connected with. Afterall, your social insurance number is only nine digits long but has the potential to be a universal tracking code. The VIN on your car is longer, but is connected with your driver's license, which is connected to you.

The following scenario demonstrates the potential of these simple codes: If you buy a pair of shoes with RFID embedded in them at your local mega store, ostensibly for inventory tracking purposes, it will have a unique serial number. At the point of purchase, that unique number can be attached to your visa card number or your debit card in the back office database. The database can connect that to your address, etc. If the RFID in the shoes is linked to your personal unique identifier, anybody who scans the code from the shoes can connect it with you. And it can be scanned from twenty feet away. If your local mega storage puts scanners at the entrances, it will know, for example, if you visited the store again wearing those shoes. It can follow you around the store and know more about your behaviour in the store than you'd probably like. This micro tracking has the potential to be taken to the macro level if scanners, linked to databases, become pervasive.

More information on the privacy impact of RFID is available from Consumers Against Supermarket Privacy Invasion and Numbering at http://www.spychips.com/ (bonus points if you can figure out what side of the issue they espouse).

Canadian government proposes regulations to require disclosure of employee data without consent for policing employment insurance program

Human Resources and Skills Development Canada has proposed amendments to the Employment Insurance Regulations to ensure that HRSDC has access to employee payroll information to detect fraud and abuse of the Employment Insurance Program. The National Post has a large front page story on this, saying that the fraud detection program has been on hold for nine months because of fears of transgressing federal and provincial privacy laws. I would have suggested that this information collection without consent was already allowed under PIPEDA, the Alberta Personal Information Protection Act and BC's Personal Information Protection Act. Better to be safe than sorry ...


Canada Gazette:

"REGULATORY IMPACT ANALYSIS STATEMENT

Description

The purpose of the proposed amendment to the Employment Insurance Regulations is to ensure that earnings verification programs conducted by Human Resources and Skills Development Canada (HRSDC), formerly Human Resources Development Canada, in cooperation with employers, satisfy the requirements of federal and provincial legislation pertaining to the disclosure of personal information.

As of January 1, 2004, subsection 7(3) of the federal Personal Information Protection and Electronic Documents Act (PIPEDA), applies to employers who fall under federal jurisdiction (i.e. airlines, banks, interprovincial transportation, radio and television broadcasting or telecommunications industries). Under the Act, these employers may not disclose personal information about an employee to HRSDC without the employee's consent unless HRSDC can demonstrate that it has the lawful authority to obtain this information. In addition, Quebec, British Columbia and Alberta have enacted privacy protection legislation requiring HRSDC to have lawful authority before it can obtain employee information from private sector employers in those provinces without employee consent. Similar legislation is being developed in other provinces.

With the implementation of the above-mentioned privacy legislation, regulatory clarification is required to ensure the ongoing functions of two verification programs administered by the Employment Insurance (EI) program: the Automated Earnings Reporting System (AERS) and the Report on Hirings (ROH) Program. These voluntary programs involve the comparison of EI claim files with current employee information provided to HRSDC by employers. HRSDC's lawful authority to obtain this information needs to be made explicit as a result of PIPEDA implementation. The AERS and ROH programs are currently under suspension (since January 1, 2004) and will be reinstated once the Regulations comes into effect.

Both the AERS and the ROH programs were developed in the late 1970s following recommendations made by stakeholders representing employers and employees. The level of participation has been considerable among employers because these programs are cost-effective and they help to alleviate the significant paper burden of requests for payroll information employers would otherwise receive.

Employees working for participants of AERS and the ROH benefit because the overpayment of EI benefits is minimized keeping financial hardship for the claimant to a minimum if repayments are required. This also means that subsequent administrative penalties or prosecutions are less likely because HRSDC is aware of the problem at the outset. As well, deterrence is achieved by encouraging participating employers to advise their employees that they participate in the AERS or ROH program. HRSDC provides employers with posters and inserts for use in informing employees that they share payroll and hiring information with HRSDC.

The proposed Regulations safeguards the privacy of Canadian workers and at the same time, it reduces the potential for making EI payments to claimants who are not lawfully entitled to receive them. The only information available to HRSDC that is collected from the verification programs, is information matching employees subject to an overpayment.

AERS and ROH are early intervention measures and serve as major deterrents to fraud and abuse of the EI program. HRSDC considers the use of regular and ongoing verification programs as crucial control mechanisms that assist HRSDC in meeting its obligations with respect to sound management practices and its fiduciary responsibility under the Employment Insurance Act.

To support the continuation of these voluntary verification programs, it is proposed that section 55.1 of the Employment Insurance Regulations be added to make explicit that HRSDC has the lawful authority to obtain employee information on a continuing basis. The information to be collected will include information in respect of the date of commencement of employment, duration of employment, amounts earned and reasons for separation from employment. It will apply to employers who (a) hired or recalled ten or more employees in a twelve-month period or expect to do so in the upcoming twelve months or (b) were required to issue ten or more records of employment in a twelve-month period or expect to do so in the upcoming twelve months.

...

Consultation

This proposed regulatory amendment was prepared by Human Resources and Skills Development Canada's Employment Program Policy and Design in consultation with Insurance Program Services, Investigation and Control, Legal Services and Privacy and Access to Information. External consultations have taken place with Industry Canada which is responsible for PIPEDA and the Department of Justice which agreed to the intent of the Regulations and drafted the wording. The Office of the Privacy Commissioner was also consulted during the developmental stages. The Employment Insurance Commission (including the Commissioners for Workers and the Employers) approved the Regulations in principle on November 14, 2003.

Compliance and enforcement

Existing compliance mechanisms contained in HRSDC's adjudication and control procedures will ensure that these changes are properly implemented. ..."

Rumours about spy chips in cash

The following link was sent by a regular correspondent ...

Bearing in mind that rumours are rumours, this one is rather interesting and perhaps chilling:

New rumours about spy chips in Euro notes | EDRI:

"

There is a renewed rumour that the European Central Bank is going to add spy chips (RFIDs) to Euro banknotes. 'Czerwensky intern', a German newsletter providing bank and insurance background reports, says the ECB might have already signed contracts with Hitachi, and is ready to introduce the spy-notes this year. Allegedly, the contract requires such a high volume of RFIDs that Hitachi can't deliver all chips itself, but has to rely on subcontractors.

Earlier rumours (dating back to 2001) about plans to track and trace all Euro notes with the help of RFIDs were strongly denied by the ECB. On 4 June 2003 EDRI-gram reported about a press release from Hitachi announcing negotiations about the contract to Japanese investors. The RFIDs in euro banknotes could help against counterfeiting and make it possible to detect money hidden in suitcases at airports. But the technology would also enable a mugger to check if a victim has given all of his money. If RFIDs are embedded in banknotes, governments and law enforcement agencies can literally 'follow the money' in every transaction. The anonymity that cash affords in consumer transactions would be eliminated.

According to the biannual report from the ECB on the counterfeiting of the euro, released on 13 January 2005, the amount of counterfeited euro banknotes is still very low. It has risen 8% compared to 2003, "but the recent trend has been downwards."..."

Biometrics coming soon to an airport near you

From Washington Technology:

Canada-DHS pilot program to use iris scanning:

"The Canada Border Service Agency, which is working on a Registered Traveler-style pilot program with the U.S. Homeland Security Department, is implementing iris-scanning technology at Canadian airports to verify the identity of travelers.

The program, called Nexus Air, will begin in November at Vancouver International Airport, Vancouver, British Columbia, before rollout at other Canadian airports for a yearlong trial. ...

Nexus Air builds on Canada’s Canpass Air program, which has 4,000 members and also uses iris scanning. As in the U.S. Transportation Security Administration’s Registered Travel pilot program, frequent fliers enroll in Canpass Air -- and soon Nexus Air -- by volunteering personal information and submitting to an iris scan. In return, they can then enjoy expedited check-in and customs screening. "

Update on weird questions at airport checkin

There has been a lot of buzz about Cory Doctorow's experience checking in for a transatlantic flight with American Airlines. (See PIPEDA and Canadian Privacy Law: Weird personal questions reported on checkin with airline.) The author of Secondary Screeining contacted the airline and actually received a prompt reply, which is posted in his site:

Secondary Screening: Cory Doctorow and Secondary 'Secondary Screening' Classes:

"After reviewing our documentation on Mr. Doctorow's experience in London, it is evident that both our contracted security screener and Mr. Doctorow contributed to what is not a representative example of our security screening process.

Mr. Doctorow exhibited specific behaviors and cues before and during our initial security screening that caused our screener to initiate a secondary screening process. We will not publicize those behaviors because to do so might hamper the effectiveness of the screening process in the future.

That said, our contracted screener veered from standard procedure when she asked for Mr. Doctorow to write the addresses of his destinations in the United States. She did clearly state that once the interview was completed, the address list would be destroyed in front of Mr. Doctorow or that he could have the list to keep. American Airlines absolutely does not register or record that type of personal data.

Although the agent concerned is very promising, this incident clearly showed a lack of experience in the questioning process. The agent will go through additional training and supervision. Through daily briefings, the remainder of the station will benefit from the experience gained from this incident.

American Airlines is entirely serious about the security procedures we undertake to help ensure the safety of our passengers and crews. We expect that our passengers apply the same serious consideration when they encounter our procedures. The vast majority of airline travelers appreciate the increased security and have adapted to a new reality in air travel. That is not, however, an excuse for security measures to be applied unevenly, and to reiterate, we do not keep personal information gathered during screening processes.

We appreciate that Mr. Doctorow called our attention to the mistakes that were made because it helps us rectify the situation going forward. He will also receive a personal response to the letter he sent to our Customer Relations department.

Tim Wagner

American Airlines Spokesman"

Weird personal questions reported on checkin with airline

Cory Doctorow, author of the popular website BoingBoing, has a post on his site about a weird experience he had checking in for a flight from the UK to the USA. The airline required him to provide a list of all the folks he'd be staying with in the US. Not content to comply, he refused, questioned their authority to ask this information and, finally, has written an open letter to the airline, which is available here. This is the first I've heard of such questioning.

Boing Boing: Why is American Airlines gathering written dossiers on fliers' friends?

"Last week on a trip from London to the US, American Airlines demanded that I write out a list of the names and addresses of all the friends I would be staying with in the USA. They claimed that this was due to a TSA regulation, but refused to state which regulation required them to gather this information, nor what they would do with it once they'd gathered it. I raised a stink, and was eventually told that I wouldn't have to give them the requested dossier because I was a Platinum AAdvantage Card holder (e.g., because I fly frequently with AA). I have written an open letter to AA asking for details on this -- see the link below for the whole text...."

Handling customer complaints under PIPEDA

Anybody reading the Canadian media before Christmas couldn't help but notice the huge amount of coverage given to a stream of faxes sent by a number of branches of a particular bank that kept on finding their way to a junkyard in West Virginia. The story took off and other complainants came out of the woodwork. Other banks were also the subject of stories, all related to mishandling of sensitive personal information (PIPEDA and Canadian Privacy Law: Bank faxes saga continues; involves other banks, too). Further examples of misdirected personal information are appearing in the media (see TheStar.com - Customer privacy concerns continue at CIBC).

The most obvious thing to learn from these incidents is that people need to be very careful when faxing customer information. Or mailing it. But what is not as obvious is that none of these stories should have ever made it as far as they did. Not only was customer information mishandled, but more importantly (from the bank's point of view), the customers were mishandled.

I've touched on this before (PIPEDA and Canadian Privacy Law: Two magic words, big effects ...), but it bears repeating. Where the banks (and most organizations that end up at the unpleasant end of a privacy complaint) went wrong is the way they acted when their misstep was brought to their attention: (i) they did little to assure their customers, (ii) they did not appreciate the gravity of the situation, and (iii) they did not escalate the issue to the proper level.

From what I understand of the faxing fiasco, the faxes went from a wide range of branches to one unintended recipient. Calls to the branches may have elicited a response, but they were not reported to a higher authority who would get a sense of the big picture and realize that there was a problem and it was chronic. Each branch did not know that dozens of other branches were making the same mistake and nobody was tracking the issue. When it comes to privacy breaches, one person in senior management must be apprised of the situation. Only that person will know if it was an one-off incident or whether the screw-up is pervasive.

Secondly, employees of organizations need to be resensitised to the importance of the personal information they handle. It may not be important to the company, but that is irrelevant. It is important to the customer, so it must be treated appropriately. I happened upon an example of this at Ottawa airport night before last. Sitting in the restaurant, the woman at the table next to me got up to go. She must have been an airline employee because she left behind a copy of a manifest for a flight from Halifax to Ottawa. Being a nosy sort, I picked it up. I recognized a few names on the list, including a particular superior court judge who would not have been impressed. It told me that the person in seat 23A was 73 years old and needed help to get on and off the plane (why the put her in a window seat at the back of the plane should be the subject of a different sort of complaint). It also listed who ordered kosher meals.

To some, this is sensitive personal information and should not have been left lying around. But I think that people who deal with sensitive personal information all the time become numb to the fact that it really is sensitive and needs to be properly protected. I am sure that all lawyers know of colleagues who can be pretty casual when talking about clients. I've certainly heard some doozies about testimony about intimate matters that was probably humiliating to the person to reveal, but really had no effect on the lawyers since they've seen it all. When the information is routine, you start treating it routinely. I have heard from dozens of managers and business owners who say that they don't have to worry about privacy law because the information they handle isn't "sensitive." Well, in many cases it is, but the company has forgotten that it is sensitive or may be sensitive to their clients. All businesses need to think about information through the eyes of their clients. Even more, they need to think about it through the eyes of their most sensitive, paranoid clients. Personal information is important and must be treated accordingly.

Finally, each customer concern must be treated seriously. Most people don't complain routinely. Some may be chronic complainers, but most are not. If a client takes the time to complain about how their information was handled, they only have done so because it matters to them. If you treat the complaint casually, it can easily get out of control. If they don't get satisfaction from the organization, with the respect and priority they think it deserves, they will take their complaint to the privacy commissioner or, worse yet, to the media. I've read all the published findings on the Commissioner's website. Initially, would sometimes think that some people complain about truly trivial things. I scratched my head at more than a few. Then I began to wonder more and more often how the organization ever let the complaint get to the Office of the Privacy Commissioner in the first place. When a complaint gets that far, particularly about something "trivial", it is most likely because the organization didn't fix the "trivial problem" and let it get out of control. If you fix it as soon as it happens, that's it. No complaint. No problem.

I've dealt with customer concerns on behalf of clients. In almost every case, they are resolved favourably if you take the concern seriously, give it due priority, treat the customer with respect, and ultimately fix their problem.

To give an example, I was involved with a concern/complaint about a consent form that had been prepared for a client. This particular client was in a large industry but was the only location in their city that was visibly tackling the privacy issue. The customer called with some questions and was immediately referred to the privacy officer. Initially, the customer sounded a little indignant. He had read the form and had a problem with one of its provisions. We were satisfied with the correctness of the document, but the customer didn't seem to be amenable to our explanation. Since we were right, we could have told him that and walked away. But that wouldn't have ended the matter, since he knew enough about PIPEDA to make it likely that he'd buy a stamp and complain to the Commissioner. So we figured that if he was asking questions, there were probably a dozen or so customers who had the same question but didn't contact the client. Rather than fight it, we redrafted the form to make it more clear. We even asked the customer for his opinion of the new form and he approved. In the end, rather than have a potential complaint on our hands, the customer actually sang the client's praises around town leading to more business. Not only was a complaint avoided, but we managed to improve the customer's relationship with the client.

Privacy is not just a legal compliance issue. As an increasing portion of customers are concerned with the protection of their personal information and whether they can trust the companies they deal with, privacy is a critical customer relations issue. If you don't appreciate that fact and begin to look at your business through your customers' eyes, you are at much greater risk of having a complaint go to the Privacy Commissioner. That involves expense, a risk of bad publicity and a lost customer.

One further thought: I'm often asked by my clients about who should assume the role of privacy officer for their company. If they are a large company, they often think it should be their in-house counsel. At first blush, this seems sensible since a lawyer has the tools to understand and apply the law. I always say that it depends upon the individual lawyer. Many lawyers reflexively get defensive and switch into denial mode. (Or at least begin denying until they have a chance to investigate.) Because this is a customer service issue as well as a legal issue, the privacy officer needs to be customer-friendly. Not all lawyers have this trait. Automatic denials and switching to "damage control" tend to escalate matters, while empathy, understanding and focusing on a solution for the customer will calm the situation. A lawyer with privacy expertise should always be consulted, because this is a legal, risk-management issue. Few employees have the knowledge of PIPEDA to fully understand the company's obligations and the risk it faces in a particular situation.

FBI Keeping Records on Pre-9/11 Travelers

In the aftermath of the terrorist attacks on September 11, 2001, US federal investigators obtained massive amounts of information on individuals who were airline passengers in the months leading up to the attack. The FBI is keeping those records, according to the Associated Press, with no intention of giving them up. Privacy activists are up in arms over it:

FBI Keeping Records on Pre-9/11 Travelers: "

WASHINGTON (AP) - If you're among the millions of Americans who took airline flights in the months before the Sept. 11, 2001, terrorist attacks, the FBI probably knows about it - and possibly where you stayed, whom you traveled with, what credit card you used and even whether you ordered a kosher meal.

The bureau is keeping 257.5 million records on people who flew on commercial airlines from June through September 2001 in its permanent investigative database, according to information obtained by a privacy group and made available to The Associated Press.

Privacy advocates say they're troubled by the possibility that the FBI could be analyzing personal information about people without their knowledge or permission.

'The FBI collected a vast amount of information about millions of people with no indication that they had done anything unlawful,' said Marcia Hofmann, attorney with the Electronic Privacy Information Center, which learned about the data through a Freedom of Information Act request.
'The fact that they're hanging on to the information is inexcusable,' Hofmann said on Friday...."

Two US airlines install surveillance cameras for pilots to view aircraft cabins

According to the Washington Times (via Privacy.org), JetBlue and Sun Country airlines in the United States have used post-9/11 FAA grants to install surveillance cameras in the cabins of all of its aircraft. The purpose, according to the airlines, is to give pilots a view of the aircraft cabin so a decision about emergency landing can be made in the event of a hijack. The author of the Washington Times article was not able to get a comment from the airlines directly, so is it unclear what policies and procedures are in place to deal with the privacy issues raised by the cameras. See: JetBlue, Sun Country install cameras for pilots - Nation/Politics - The Washington Times, America's Newspaper.