alberta

Showing posts with label alberta. Show all posts
Showing posts with label alberta. Show all posts

Edmonton pawnshop owner takes a stand over electronic reporting of personal information of customers to police

As of January 1, 2006, pawnshop operators in the City of Edmonton will be required by a city bylaw to enter information about customers into a database that will be electronically transmitted to the police. He has always collected this sort of information, as required by law, but Kelly Buryuniuk is not at all happy with having to send it to the cops, particularly via a private contractor. He is concerned about the security of that data, he says. The pawnshop operator says he will defy the bylaw, even if it gets his license suspended. The Information and Privacy Comissioner of Alberta is reviewing the system. See: edmontonsun.com - Edmonton News - Standoff brewing.

Canadian Privacy Firsts: Misdirected faxes leads to joint investigation and report by Alberta and Federal Commissioners

Canada suffers under a tangle of privacy laws, some of which overlap and others that leave gaping holes. In some cases, a number of privacy laws may apply. Misdirected faxes with sensitive information in Alberta over the summer engaged both the Alberta Health Information Act and the Personal Information Protection and Electronic Documents Act, resulting in the first joint investigation and report from the federal and Alberta privacy commissioners. The report is also notable as the Federal Commissioner's report "names names".

The Federal Commissioner's finding is here:

Report: Misdirected faxes containing health information end up in apartment managers' hands - December 21, 2004

Incident

In July 2004, it was reported in the Edmonton Journal that a couple who managed an apartment building had received facsimile transmissions in error from various sources. These transmissions contained personal medical information.

The Office of the Privacy Commissioner of Canada and the Office of the Information and Privacy Commissioner of Alberta collaborated in investigating this incident. It was determined that the couple received 10 facsimile transmissions from seven different companies. Some of these transmissions came under the jurisdiction of the Personal Information Protection and Electronic Documents Act (PIPEDA). Two companies were responsible for these transmissions:

  • Dynacare
  • Viewpoint

The following is a summary of the investigation into the incidents.

Summary of Investigation — Dynacare

One facsimile was sent erroneously by Dynacare, which operates medical laboratories, on January 19, 2004. It contained such personal information as the name, age, height, smoking habits, and patient number of an individual who had undergone testing by the company. Also included was a diagnosis and specific medical test results for the individual.

Once the company had been alerted to the privacy breach, it investigated the incident but was unable to determine who was directly responsible for the transmission. It was able to narrow responsibility, however, down to one of five individuals. Our Office confirmed that the facsimile was sent via manual transmission, in other words, the person who sent the facsimile manually keyed in the number.

All five individuals had signed an oath of confidentiality at the time of hiring, and were aware of the confidential nature of the medical records and the need to ensure that they are not inappropriately disclosed. These oaths had not been reviewed since they were signed. The company has developed a new form and will ensure that employees review and sign it annually.

Dynacare also implemented an electronic auto fax function on its computers. Facsimile numbers are entered into the system and checked for accuracy. If an employee wishes to send a facsimile, he or she will use the automated system. Such a measure should minimize the risk of regularly used numbers being misdialed. For numbers that are used infrequently or on a one-time basis (they are not programmed into the system), Dynacare provided employees with a set of instructions that are intended to ensure that they confirm the accuracy of the fax numbers before transmission.

Dynacare is in the process of revising its policies and procedures to ensure full compliance with all applicable legislation, including Alberta's Health Information Act and the PIPEDA.

Although Dynacare had not notified the individual whose personal information was on the facsimile, it indicated that it would consider doing so.

Conclusion

The Assistant Privacy Commissioner concluded that Dynacare disclosed personal information without consent, contrary to the provisions of PIPEDA.

Summary of Investigation — Viewpoint

Viewpoint is a medical organization that provides diagnosis consultation services. The facsimile in question, sent on April 14, 2004, was a medical evaluation. It contained the patient's name, age, occupation, detailed medical history, and also included information about the patient's children. The evaluation was sent by a medical consultant to a Viewpoint physician, who reviewed and made comments on the report. It was then supposed to be sent back to the consultant via facsimile. Two of the numbers, however, were transposed, and the facsimile was sent to the incorrect place. Although the Viewpoint physician made notes to the report, he was not responsible for its transmission and Viewpoint has not been able to determine who in fact sent the facsimile to the wrong number.

When the recipients of the facsimile contacted Viewpoint regarding the transmission they were told to destroy the documentation. Viewpoint indicated to our Office that in future, should any facsimile transmissions containing personal information be sent to the wrong number, Viewpoint will dispatch a courier to retrieve any such records. The company has also taken steps to have all facsimile numbers verified before transmission and has implemented measures to have any incidents reported to management.

As for the patient in question, Viewpoint indicated that it would be more appropriate for the medical consultant to contact the patient regarding the disclosure as they have a doctor-patient relationship.

Conclusion

The Assistant Commissioner concluded that Viewpoint contravened PIPEDA when it disclosed personal information without consent.

Recommendations made to Dynacare and Viewpoint

The Assistant Commissioner made the following recommendations to both companies:

  • That the organizations implement and follow the OPC's recommendations with respect to the transmission of facsimiles as set out in the fact sheet Faxing Personal Information.
  • That the organizations implement measures to notify individuals whose personal information has been inadvertently disclosed via misdirected facsimiles.
  • That the organizations review and update employee confidentiality/privacy agreements on a yearly basis.


The press release from the Alberta Information and Privacy Commissioner is available in PDF at http://www.oipc.ab.ca/ims/client/upload/NR_H2004_IR_001_2.pdf and his report is here: http://www.oipc.ab.ca/ims/client/upload/H2004-IR-001.pdf

From the Edmonton Journal:

Clinics, doctors criticized for fax foul-ups: Privacy commissioner puts onus on offices to ensure information sent to correct number:

"EDMONTON - A new report from Alberta's privacy commissioner is a sharp reminder to health workers that careless faxes can put patient privacy in jeopardy.

Each day, hundreds of fax machines in medical clinics send patient information from one place to another. It's the standard way information is shared among doctors, therapists, laboratories and consultants.

On Tuesday, the commissioner's office released a 16-page report that found two local doctors and three clinics violated the Health Information Act by not handling faxes correctly.

The investigation was launched after The Journal reported in July that a local woman received more than 20 faxes with confidential medical information that were supposed to go to LifeMark Health Institute, a private medical consulting company. Nese Premakumran's fax number was one digit different from LifeMark's...."

Employees in Ontario (and perhaps other Canadian provinces) have no right to privacy

This is hot off the presses. With no statutory right to privacy in Ontario (unlike Alberta and British Columbia), an arbitrator has decided that the "reasonableness" test that has ordinarily applied to determine the admissibility of video surveillance evidence may not be warranted. It is worth asking if the admission of video surveillance is really any different from admitting the testimony of the private investigator who took the video. Should the fact that it is more persuasive make it more difficult to admit?

2004 CarswellOnt 5241

Hotel-Dieu Grace Hospital v. CAW-Canada, Local 2458

Ontario Arbitration Board

Snow Member

Heard: July 15, 2004
Heard: October 14, 2004
Judgment: November 2, 2004
Docket: MPA/Y401670

Snow Member:

...

1 The grievor was discharged on the basis of video surveillance evidence. This is an interim award regarding the admissibility of that video evidence.

IV. Union Position

....

8 The Union submitted that the Employer could only use this video evidence if:

1. It was reasonable for the Employer to request surveillance;

2. The surveillance was conducted in a reasonable manner; and,

3. There were no other alternatives open to the Employer to obtain this evidence.


9 The Union submitted that the arbitration cases indicated that video of an employee was an intrusion that should not be taken lightly, that an Employer needed to have reasonable grounds to decide to engage in surveillance of an employee and, if the Employer did not have reasonable grounds, the video evidence should be rejected. The Union reviewed several awards and adopted the arguments contained in them.

10 As for reasonable grounds, the Union said the cases made clear that mere suspicion was inadequate. The Union said there were no reasonable grounds to use surveillance in this case. To allow the Employer to use video evidence without first subjecting that evidence to the above reasonableness test would shift the balance of power in favour of the Employer. In summary, the Union said it made sound labour relations sense to use the test of reasonableness in assessing video surveillance evidence.

....

V. Employer Position

12 The Employer said there was no legal reason to require the Employer to have reasonable grounds to engage in surveillance and there was no proper basis to refuse to admit the video evidence from that surveillance.

13 The Employer referred to Section 48 (12) (f) of the Labour Relations Act, 1995 dealing with admissibility of evidence and said that an examination of that provision indicated that the video was admissible. The Employer submitted that the arbitration cases upon which it relied indicated that the cases cited by the Union have not been followed in recent years. The Employer reviewed both the Union's and its own cases in detail and urged me to follow the approach found in its cases.

...

15 In summary, the Employer said that, absent a collective agreement or statutory provision, an Employer can engage in surveillance of an employee and use the video from that surveillance in arbitration. There was no basis for subjecting the issue of admissibility of this video evidence to a special test.

Should there be an additional reasonableness test for surveillance video?

32 Notwithstanding that this evidence is relevant to a material issue, and would be admissible applying the statute, the Union said that there was a line of arbitration cases which took a different approach. The Union submitted that those cases held that video evidence should only be admitted in an arbitration if that evidence also passed the reasonableness test. Although there are conflicting decisions of Ontario arbitrators on this point, the Union is correct that in the decisions upon which it relied the arbitrators subjected the introduction of video surveillance to the reasonableness test. There are minor differences in those tests but the key points are:



1. The employer had to have acted reasonably in deciding to place the employee under surveillance; and,

2. The Employer had to have conducted the actual surveillance in a reasonable manner.

33 I note that the reasonableness test appears to have been used in Ontario only for video evidence. Before the days of video, and currently as well, this Employer could have hired a detective to conduct similar surreptitious surveillance away from the work place, make notes on what was observed and take still photographs, and then testify in an arbitration from his or her memory aided by the notes and still photographs. I am aware of no suggestion that such evidence has been subjected to the reasonableness test in an arbitration under the Labour Relations Act.

34 From the awards before me it is clear that this reasonableness test for the admissibility of video evidence was first used in British Columbia in Re Doman Forest Products Ltd. and I.W.A., Loc. 1-357 (1990), 13 L.A.C. (4th) 275 (Vickers), a case discussed in several of the awards relied upon by the parties. At that time British Columbia had a statute providing for a right of privacy and Arbitrator Vickers took the view that, among other things, surveillance conflicted with the employee's statutory right of privacy. In reconciling the employer's right to prove its case through relevant evidence with the employee's statutory privacy right to be free from surveillance, the arbitrator adopted the reasonableness test. If the surveillance was unreasonable under the privacy legislation, the resulting video evidence was not admitted.

35 A similar test was used in Manitoba, where there was also a statutory right to privacy, in Re New Flyer Industries Ltd. (supra). Arbitrator Chapman cited with approval an earlier decision of Arbitrator Peltz between the same parties (the Mogg case) and, at page 63 of his award, Arbitrator Chapman quoted from Arbitrator Peltz' earlier award where the existence of a statutory right to privacy is relied upon. Although Arbitrator Chapman does not specify the source of the statutory right, at page 146 of his award in Re Canadian Timken Ltd. (supra), Arbitrator Welling indicates that the right to privacy in Manitoba was found in the Privacy Act, R.S.M. 1987, c. P125.

36 A similar test was used in Ross v. Rosedale Transport Ltd. (supra), a dispute under federal jurisdiction, to balance an employee's privacy rights found in the federal Personal Information Protection and Electronic Documents Act with the employer's right to prove its case through relevant evidence.

37 In each of those jurisdictions there is a statutory right of privacy and I have no issue with the reasonableness test being applied to balance an employee's right of privacy with an employer's right to prove its case through relevant evidence.

38 But I do have difficulty with the use of a reasonableness test where there is no right of privacy. A reasonableness test has been used in Ontario - see, for example, two cases cited by the Union, Re Toronto Transit Commission (Saltman) (supra) and Re Labatt Ontario Breweries (supra) - where there is no statutory right to privacy. In subjecting videotape evidence to a reasonableness test Arbitrators Saltman and Brandt applied a different approach from that normally used in assessing the admissibility of evidence.

39 In examining the reasonableness test of Arbitrators Saltman and Brandt in the above cases, a test also applied by some other Ontario arbitrators, it is important to note that the use of the reasonableness test for the admission of videotape evidence has been criticized and firmly rejected in a number of later cases - see, for example, Re Kimberly-Clark Inc. (Bendel) (supra); Re Toronto Transit Commission (Solomatenko) (supra); and Re Canadian Timken Ltd. (Welling) (supra) cited by the Employer. (I note that while Arbitrator Bendel's award was released in 1996, prior to Arbitrator Saltman's 1997 award, it was not published in Labour Arbitration Cases until 1998 and was not mentioned in Arbitrator Saltman's award.)

40 The initial and primary basis for the use of the reasonableness test for the admissibility of video evidence has been a concern about privacy. The use of the reasonableness test as a means of balancing privacy expectations or concerns (there being no right to privacy) with the right to lead relevant evidence has been fully and ably reviewed in the three awards by Arbitrators Bendel, Solomatenko and Welling (supra) and I do not intend to repeat that analysis. Although the analysis in those three cases varies in some details, each rejects the reliance on privacy as a basis for using the reasonableness test for the admissibility of video evidence.

41 As there is no right of privacy in Ontario, this reasonableness test, originally designed to balance rights, has to be carefully examined. Since it is not needed to balance competing rights, and has been persuasively rejected by other arbitrators, why might I adopt it?

42 Some of the cases (including cases not relied upon by the Union but referred to in the various awards) suggest alternative rationales for using the reasonableness test and subjecting video evidence, particularly video evidence resulting from surveillance, to heightened scrutiny. But those alternative bases (reliance on values in the Canadian Charter of Rights and Freedoms, analogy with cases on searching employees, and safeguarding the integrity and credibility of the arbitration process) are also examined by Arbitrators Bendel, Solomatenko and Welling in Re Kimberly-Clark Inc. (supra); Re Toronto Transit Commission (supra); and Re Canadian Timken Ltd. (supra), respectively, and persuasively rejected.

43 I can find no basis in the arbitration awards relied upon by the parties to persuade me to adopt a reasonableness test for the admissibility of this video evidence. In particular, I reject the primary ground advanced for this test - privacy - as a basis for using the reasonableness test. I also reject the other reasons which have been advanced - reliance on values in the Canadian Charter of Rights and Freedoms, analogy with cases on searching employees, and safeguarding the integrity and credibility of the arbitration process. Nothing in those awards persuades me that a special test is needed to determine the admissibility of video evidence.

44 The Union offered further policy reasons for adopting the reasonableness test. The Union submitted that to allow the Employer to use video evidence without subjecting that evidence to the reasonableness test would shift the balance in favour of the Employer. The Union also submitted that it made sound labour relations sense to use the test of reasonableness in assessing surveillance evidence. The Union did not provide specifics, but I understood that the submissions flowed from:

1. The idea that employees have an expectation of privacy, even if not a right; and,

2. The distaste which some people have regarding an employer conducting surreptitious surveillance.

45 The Union urged me to shift the balance, and to uphold sound labour relations values, by subjecting the video evidence to the reasonableness test.

46 I do not think that my subjective perception about a need to shift the balance of power between the parties, or the balance between the Employer and the grievor, is a sound basis for a decision to reject relevant evidence, or to subject this evidence to the additional reasonableness test.

47 Moreover, the fact that some people find this practice of surreptitious video surveillance offensive does not, in my view, carry any weight in determining the admissibility of the video evidence. Improvements in technology have enhanced the ability of a "sleuth" to record what an employee has done away from the work place but, as I noted earlier, it has long been possible to engage in surveillance and testify about what was observed. I do not see that the recent use of video has created a shift in the balance of power which should be corrected, even assuming that correcting a shift in the balance of power was a sound basis for determining admissibility. In my view, because the evidence is clearer, more detailed, and thus perhaps more persuasive, the possibility of video evidence has, at most, simply prompted employers to more frequently exercise a power which employers have long possessed.

48 While I have concluded that shifting the balance of power is not a proper basis for determining the admissibility of this video evidence, I would note that if the Union wishes to shift the balance of power it is able to do so in the bargaining process. The parties' collective agreement is their current agreement in terms of the allocation of power between the two of them. It is clearly possible for a collective agreement to address this issue and to indicate an approach to the admissibility of video evidence which an arbitrator would be required to apply. But there was no suggestion of anything in the parties' existing collective agreement which would assist in resolving the issue before me on the admissibility of this video evidence. ....

Privacy, hospitals and law enforcement

A FOX station in the pacific northwest is carrying the following story:

FOX 12 OREGON Conflict with law enforcement:

"WENATCHEE, Wash. Last spring a Douglas County man shot himself in the hand while cleaning his gun.

He was treated at a hospital that did not report the incident to law enforcement because of privacy law.

Douglas County Sheriff Dan LaRoche heard about it weeks later and said it should have been investigated, although he believes it was an accident.

The incident is an example of how the privacy law (Health Insurance Portability and Accountability Act -- known as HIPAA) can hamper law enforcement.

A spokeswoman for the Washington State Hospital Association, Cassie Sauer, says the year-old law has strained the working relationship between health care workers and police in some areas of the state.
(Wenatchee World)"


In Alberta, the Health Information Act allows healthcare providers to tell the cops, but only if the person has not told the hopspital not to: "Doc, don't tell the cops about my seven gunshot wounds."

Meth addicts' other habit: Online theft

USA Today is running a lengthy article on the intersection between methamphetamine addiction and identity theft. The article, Meth addicts' other habit: Online theft, chonicles investigations that began in Edomonton and Calgary, Alberta and forcefully brought this connection to the attention of Canadian law enforcement.

Intersection of crimes

... What's happening in Edmonton is happening to one degree or another in communities across the USA and Canada — anywhere meth addicts are engaging in identity theft and can get on the Internet, say police, federal law enforcement officials and Internet security experts.

Internet Relay Chat channels, private areas on the Internet where real-time text messaging takes place, are rife with communications between organized cybercrime groups and meth users and traffickers discussing how they can assist each other. "It's big time," says San Diego-based security consultant Lance James, who monitors IRC channels.

Such collaboration seems almost preordained. "This hits at the intersection of two of the more complex law enforcement investigations: computer crimes and drug crimes," says Howard Schmidt, CEO of R&H Security Consulting and former White House cyber-security adviser.

Identity theft has fast become the crime of preference among meth users for three reasons: It is non-violent, criminal penalties for first-time offenders are light — usually a few days or weeks in jail — and the use of computers and the Internet offers crooks anonymity and speed with which to work. Meth is a cheap, highly addictive street derivative of amphetamine pills; it turns users into automatons willing to take on risky, street-level crime.

Meanwhile, global cybercrime groups control e-mail phishing attacks, keystroke-stealing Trojan horse programs and insider database thefts that swell the pool of stolen personal and financial information. They also have ready access to hijacked online-banking accounts. But converting assets in compromised accounts into cash is never easy. That's where the meth users come in.

Sophisticated meth theft rings, like the one in Edmonton, control local bank accounts — and underlings who are willing to extract ill-gotten funds from such accounts. The two men at the seedy motel were helping outside crime groups link up with local accounts under their control when a tipster guided police to them in December 2004....


The article is worth the read.

Alberta bureaucrat calls in the federal commissioner to investigate privacy breach

In another interesting turn of events, an Alberta public servant has requested that the Federal Privacy Commissioner investigate the breach of privacy connected to the discovery of hundreds of files of bureaucrats' personal information in Alberta. This is in addition to an investigation conducted by the Alberta Commissioner, the report for which was released this week (see PIPEDA and Canadian Privacy Law: Alberta Commissioner releases report on incident involving sensitive info of senior public servants).


Feds called in:

"A top Alberta bureaucrat burned in the recent leak of private credit data from the provincial government's staff-screening process has sicced Ottawa's privacy watchdog on the case. The bureaucrat, who has asked not to be named, said he's filed a request for an investigation by the federal Office of the Privacy Commissioner.

The commission office couldn't confirm the request yesterday. 'We get about 19,000 requests a year, [!]' said a spokesman.

Although provincial Information and Privacy Commissioner Frank Work released his own report on the Trans Union affair this week, the federal office may also have jurisdiction - since the screening process involved the Canadian Security Intelligence Service.

The screening process was launched by the Klein government last year to guard against fraud or security breaches by top bureaucrats. It included criminal background and credit checks, along with a CSIS 'vulnerability risk screening.' ...."



For background, see:

Alberta Commissioner to conduct his own "PATRIOT ACT" outsourcing inquiry

The Alberta Information and Privacy Commissioner, Frank Work, announced that his office will be working jointly with the Government of Alberta to examine the implications of public sector outsourcing for the personal information of Albertans. The news release can be found here.

Alberta Commissioner releases report on incident involving sensitive info of senior public servants

The Alberta Information and Privacy Commissioner has released his report related to the huge incident involving the breach of credit information related to hundreds of senior civil servants. See the report and press release here.

Alberta Government 'dropped ball' on security breach

Following the incident in which sensitive personal information of senior public servants was found in the course of a drug bust (see Article: Dumpster-diving meth-heads collect info for ID thieves and Incident: Massive leak of personal information in Edmonton, Alberta), the Alberta Information and Privacy Commissioner has released his report. The breach originated with the private contractor, the investigation found, but the government didn't do enough to obtain privacy assurances:

Government 'dropped ball' on security breach:

"The Klein government is not living up to its own rules regarding the security of personal information it collects, charge Opposition Liberals. Edmonton Manning Grit MLA Dan Backs said a report prepared by the privacy commissioner's office into the discovery of personal documents pertaining to senior government officials in a city hotel room last month shows the government is 'failing miserably' in its duties.

'The government really dropped the ball on this one,' Backs said yesterday. 'The government ministers responsible (for the Solicitor General department and Personnel Administration Office) are failing miserably in their responsibility to protect the privacy of Albertans.'
However, the report states the leak did not occur at the government level, but rather with TransUnion Credit Information Services Inc., a credit-reporting agency...."

Churches and the federal privacy law

Focus on the Family is running the following article in their "Today's Family News":

Churches fear breaching privacy laws

December 14, 2005

Recent privacy legislation is causing some churches to fear they could be breaking the law simply by circulating the addresses of members, praying aloud for people by name, and – at least in Ontario – making hospital visits, the Ottawa Citizen reported.

At the heart of their concern, which some think is exaggerated, is the Personal Information Protection and Electronic Documents Act, which Parliament passed in January 2004. It primarily affects businesses and would only apply to churches that sold their parish or membership lists or charged for their services.

Even so, it has prompted some pastors to question whether even making public the names and addresses of the people in their congregations might be deemed illegal under the Act.

One church in Halifax, for example, removed a “prayer board” in its foyer listing the names of people in hospital. Others have adopted privacy policies and some have even appointed privacy officers to oversee the correct handling of information.

For clergy in Ontario, the province’s year-old Personal Health Information Protection Act has made it more difficult from them to visit hospital patients, even if they belong to the same denomination.

Patients when being admitted have the option of indicating their faith background, which James Christie, dean of the faculty of theology at the University of Winnipeg, says clergy have assumed indicated they would welcome “some sort of pastoral presence.” But now, as he told the Citizen, “that graciousness is gone.”

But London, Ontario, lawyer Janet Allinson, a specialist in privacy law, believes many churches “are misunderstanding the legislation altogether. I get quite a few calls from people very concerned, they are so afraid of the Privacy Act.”

"I think it's important that they don't lose the spirit and treat it like a business" added Allinson.



The impact of the federal private sector privacy law has been very misunderstood by churches and other non-profits.

The Personal Information Protection and Electronic Documents Act, or PIPEDA as it is commonly known, applies to the collection, use and disclosure of personal information in the course of commercial activities, except in those provinces that have enacted substantially similar legislation. Ontario has not enacted legislation that is substantially similar to PIPEDA (other than the Personal Health Information Protection Act which may hinder the abilities of health information custodians to share information with visiting clergy, but does not regulate churches directly). In short, PIPEDA applies to personal information that is handled in connection with commercial activities, other than in Alberta, BC and Quebec.

The reason for the commercial activity connection is that the Federal Government is relying upon its constitutional jurisdiction over general trade and commerce in Canada to implement PIPEDA. It can use this power to regulate commerce generally, but is not able to regulate the non-profit sector using this power except to the extent that the non-profit organization actually is engaged in commercial activity. There are some activities that a non-profit can engage in that are deemed commercial activities and some activities can be sufficiently commercial to invoke PIPEDA. The deemed activities are generally limited to certain kinds of dealing with membership and donor lists. If a church exchanges, sells, trades or leases its membership list, that is a deemed commercial activity and PIPEDA applies (including requiring consent for the transfer). The key is an exchange of value. If a list is freely given with no expectation of any value in return, there is no commercial activity and PIPEDA is not triggered. Also, if a church veers away from its core not-for-profit objectives, it can be seen to be engaged in commercial activity. Charging admission to a benefit concert for the church is not commercial activity. Operating a business within the church may be commercial. Church fund-raising is not a commercial activity, nor is praying out loud or listing members in a directory.

This does not mean that a church or a non-profit shoudn't follow fair information practices. This is not because it is required by PIPEDA or any other law, but rather because it is just the right thing to do. Churches are entrusted with sensitive personal information. Having a privacy policy that is reasonable and consistently followed sends a positive message to the members of the congregation who are more privacy aware.

Authorities give US prisoner detailed personal information on Albertans

Here's a head-scratcher. A prisoner is a US jail, facing deportation to Canada, was given highly sensitive information about a number of Albertans so he could apparently prepare to fight the extradition order. The prisoner may be accused of a savage beating, but at least he knows that he probably should have the info:

Privacy shocker:

"Skinhead Daniel Sims has in his U.S. jail cell the SIN numbers of staff of the Edmonton law firm that sued him after he beat former broadcaster Keith Rutherford so badly he lost an eye. The SIN numbers - including that of high-profile Edmonton lawyer Tom Engel - are included in a 1,000-page immigration file Sims obtained this week from American authorities as he battles deportation back to Canada.

Sims said the documents include financial information such as total income, taxes paid and Canada Pension Plan contributions made by Engel and his wife in 2001 - two years after Rutherford's lawsuit was concluded.

'I got this from the U.S. Attorney's office but because the file is so big they didn't notice,' said Sims, 33, from his Kern County jail cell in Bakersfield, California.

'As far as me and Tom Engel, there's no way I should have this. I don't really want it.' ...."



The Information and Privacy Commissioner of Alberta says he'll investigate if he receives a complaint.

Bank faxes saga continues; involves other banks, too

Perhaps spurred by the coverage of the CIBC faxing incidents, more people are contacting the media to report having received misdirected bank faxes. And it is not just CIBC that is affected as CTV.ca reports: CTV.ca | More people report receiving bank faxes. Also, check out the video of their television reports on the right-hand column of the page.

Everyone would be well advised to read the Alberta Information and Privacy Commissioner's fact sheet on faxing sensitive medical information: "Guidelines on Facsimile Transmission"".

Update: April 18, 2005 - PIPEDA and Canadian Privacy Law: Privacy Commisioner of Canada releases her report on the CIBC faxing incidents

Alberta Commissioner authorizes an organization under PIPA to disregard an access request.

The Information and Privacy Commissioner of Alberta, Frank Work, has authorized a company to ignore access requests as being vexatious. PIPA allows the Commissioner to authorize a company to ignore such requests. In this case, the individual had been involved in fifteen years of litigation with Manulife (the applicant). The company said it had no other information on the individual that had not already been handed over as part of the discovery process. The report of the Commissioner is availble here: http://www.gov.ab.ca/acn/200512/19181.pdf.

Don't be liable for identity theft

[A slightly edited version of the article below was just published in the December 2005 edition of Business Voice.]

Don't be liable for identity theft


Identity theft, we are told, is one of the fastest growing crimes in North America, claiming thousands of new victims every year. This crime most often involves using the personal information of unsuspecting victims to obtain goods and services, including credit, in the names of those victims. How the fraudsters obtain personal information varies and, unfortunately, their ingenuity apparently knows no bounds. Identity theft is obviously a problem for its victims but it also presents significant legal risk to businesses.

Every business in Atlantic Canada that handles customer information is subject to the Personal Information Protection and Electronic Document Act (“PIPEDA”). Among its many requirements, PIPEDA requires every business to implement safeguards to protect personal information against inappropriate use and disclosure. The form of safeguards depends upon the sensitivity of the information. If the misuse of the information could lead to fraud or identity theft, the safeguards must be appropriately robust.

Unfortunately businesses are often the weak link in the data protection chain, jeopardizing their customers and their own business reputations. In the first half of this year, the media reported on a series of incidents that resulted in the disclosure or theft of personal information of almost two million Americans. We are not immune here in Canada: Some may recall the attention given to the accidental faxing of the personal information of thousands of bank customers to a junkyard in the United States. More shocking was the discovery made by police in Alberta this past winter: piles of extremely sensitive information, including credit reports, on senior provincial public servants were found in a methamphetamine lab. Further investigations showed that drug addicts are being hired by identity thieves to steal personal information by a number of means, including “dumpster diving” in the trash receptacles and recycling bins of businesses. It would be foolish to assume that this does not occur in Atlantic Canada.

Businesses that do not adequately lock up personal information can find themselves legally and financially liable to the victims of identity theft and other forms of fraud. In April of this year, a number of identity theft victims in Michigan successfully sued a trade union because information of its members to be misused. The high profile misdirected faxes incidents spawned a class-action lawsuit in Ontario, alleging that the bank involved should have to pay compensation for the increased risk of identity theft, plus the actual cost of more vigilant credit monitoring. These lawsuits relate to inappropriate safeguards, but it will not be long before individuals whose identities are stolen will seek recourse against credit grantors and others who offered facilities to the impostors, arguing they did not do enough to verify the identity of the person seeking credit. These plaintiffs will be seeking damages related to the costs of repairing their credit and, perhaps, opportunities they have lost due to an unfavourable credit rating. PIPEDA, to which all Atlantic Canadian businesses are subject, allows individuals to seek damages in the Federal Court for any harm they might have suffered, including any embarrassment that might have been caused by a leak of personal information.

So what does all this mean to businesses? Anybody in possession of personal information that would be useful to commit identity theft or the disclosure of which might be embarrassing to the individual has an obligation to protect that information against all risks. This obligation is already set out in PIPEDA and the common law will likely also impose a duty of care where the risk of identity theft is foreseeable. (In the current climate, it would be difficult to argue that identity theft is not foreseeable.)

Business owners also need to be very careful to supervise employees. Significant portions of fraud committed can be traced to dishonest employees who misuse the information they have access to or even participate in activities such as “card skimming”, where information is taken from credit cards and debit cards. All employers need to be aware that the courts will generally hold them legally and financially responsible for the misdeeds of their employees.

Credit grantors in particular have to be even more vigilant in establishing the identities of those to whom they extend credit. This will not only protect against credit losses, but will reduce the likelihood that your company will be the subject of privacy complaints and litigation. In this effort, privacy laws unfortunately pull businesses in two different directions. On one hand, credit grantors should clearly establish the identity of an applicant. On the other hand, the law says that they can only collect information that is reasonably necessary in the circumstances. To satisfy both, businesses need to establish reasonable policies and practices on how identity will be confirmed and how that information will be subsequently used. Doing so simply makes business sense in this legal climate.

While legal liability may appear remote to many businesses, a single incident can destroy your business reputation that you have worked years to develop. Surveys have shown that customers are increasingly concerned about their personal information and are making buying decisions based upon what businesses they trust. If word gets out that your business is not doing what is necessary to protect customer information, it can be shunned by consumers with dramatic effect on your bottom line.

Tips for Protecting Information


  • Only collect the minimum amount of information that is necessary for carrying on your business. The more information you have, the greater the likelihood of loss and the consequences such as fraud.

  • Information that is no longer required must be securely disposed of. This involves shredding all paper that contains personal information and making sure that all hard-drives of surplus computers are completely wiped clean of data.

  • Carefully screen all employees who will have access to personal information.

  • Carefully restrict employee access to personal information, on a need-to-know basis.

  • Carefully vet all service providers, such as cleaning companies and data processors, and require them to sign non-disclosure agreements and indemnities in case they misuse personal information or allow its disclosure.

Alberta judge: Conditional sentence not sufficient for card skimmer

In a recent judgement, R. v. Naqvi, 2005 ABPC 339, the Associate Chief Judge of the Alberta Provincial Court has sentenced a convicted card-skimmer to eighteen months in prison. The accused worked in two gas stations and skimmed cards using equipment provided by a high-school acquaintance. He was paid $100 per card he skimmed, for a total of $17,000.

In rejecting the call for a conditional sentence, the judge said:


To describe him as a minor participant is akin to describing a bank robber as a low level
participant, and the driver of the getaway vehicle as the primary offender. Without the gathering
of information by the accused, and its distribution to his criminal acquaintance, the criminal
enterprise that resulted from his participation would not have been possible.

Hopefully this will send a message ...

Privacy watchdog probes firms

The Information and Privacy Commissioner has his work cut out for him, at least for the short term. More purloined personal information has been found through an investigation that began with the discovery of sensitive data in the course of a drug bust. It appears the information was collected by dumpster diving drug addicts, who sell the info to ID thieves to fuel their addictions. From the Edmonton Sun:

Edmonton Sun: Privacy watchdog probes firms:

"The province's privacy commissioner yesterday launched an investigation into three Edmonton-area businesses whose customers' personal information ended up in a hotel room. The privacy office is already investigating how civil servants' personal data - including credit reports - got to the hotel and was then found by cops working on a credit card probe. Drug paraphernalia and a shotgun were also found.

'This has got to stop,' Privacy Commissioner Frank Work said. 'The paper that the (police) showed me was mind-blowing. There's bags of it. I thought, 'Holy smokes.' '

Linens 'n' Things, Nor-Don Collection Network Inc. and Digital Communications Group Ltd. are under investigation.

But the holiday season is prime-time for dumpster divers and identity thieves, Work warned.

'There's going to be a zillion purchases and then a zillion returns. All that paper generated will make for a field day for thieves when they go rifling through dumpsters,' he said.

...."



Also, from today's Globe and Mail:

The Globe and Mail: Alberta probes leak of credit records:

CALGARY -- Alberta's Privacy Commissioner launched an investigation yesterday after the credit information of thousands of consumers landed in the hands of suspects in an identity-theft scheme.

Edmonton police recovered bank records, cellphone contracts, credit information held by a collection agency and credit-card receipts in connection with a search warrant executed Nov. 9 in a city hotel room in a credit-card investigation.

A man and a woman face criminal charges, including two counts each of possession of credit-card data, and it appears the documents were seized before the personal information of hundreds, even thousands of individuals, was used illicitly...."

Article: Dumpster-diving meth-heads collect info for ID thieves

The Edmonton Sun is reporting on how sensitive personal information related to senior Alberta bureaucrats found their way into a drug-bust crime scene. (See PIPEDA and Canadian Privacy Law: Incident: Massive leak of personal information in Edmonton, Alberta.) Apparently, dumpster-diving meth-heads are selling found personal information to ID thieves:

Documents dug out of dumpsters:

"...Personal data including credit reports for provincial bureaucrats recently recovered by cops appears to have fallen into the wrong hands due to 'dumpster diving,' say police. 'My feeling is yes, most of that stuff came from dumpster diving,' city police Det. Bob Gauthier said yesterday, after cops showed the hundreds of documents recovered.

'Dumpster divers' or 'binners,' as police call them, are people who in some cases are addicted to methamphetamine and hunt garbage bins for personal information. They then sometimes exchange the data for drugs. "

Alberta bar to continue scanning IDs despite Commissioner's advice not to

The saga related to the scanning of IDs in Alberta bars continues. The Gauntlet, a University of Calgary student publication, reports that the bar in question is planning to ignore the Information and Privacy Commissioner's recommendation by continuing to use the Secureclub system. The investigation by the IPC will likely continue and may culminate with an order under the Personal Information Protection Act of Alberta in the new year. In the meantime, the univeristy pub is going ahead with using the technology. See
Gauntlet News - Private info or no beer.

For some background on this complaint and the issue generally:

What your photocopier knows about you ...

The Alberta Information and Privacy Commissioner's office is raising the alert about security and privacy issues related to newer photocopiers and fax machines. Their hard-drives may store information without the user's knowledge:

Yahoo! News - Alta privacy office says hi-tech fax machines an overlooked security risk:

"CALGARY (CP) - In the realm of high-tech dangers, few would consider the lowly fax machine or photocopier a security risk.

That would be naive, says Tim Chander, research manager of Alberta's Office of Information and Privacy.

'It's not your grandfather's printer anymore - these things are computers with hard drives that can be connected to the Internet,' said Chander.

'Anything you're photocopying (is) copied and stored on the hard drives unless they are overwritten.'

Chander said most businesses, government offices and health authorities lease their office equipment without considering the security ramifications.

'We haven't had a complaint come to our office. We just want organizations to be aware that anyone photocopying personal, business or health information to realize that when your lease is up, your information is going out the door,' he said...."

FCA hands privacy victory to the "little guy"

Sorry for the light (read: non-existent) blogging over the last few days. I've finally gotten to an internet connection ....

Mathew Englander e-mailed me the other day to say that the Federal Court has rendered their decision in his fight against Telus. I haven't read the full reasons, which should be available here soon, but all reports suggest that Telus did not persuade the Federal Court of Appeal to uphold the finding of the Privacy Commissioner and the Federal Court, Trial Division. I haven't found any free coverage online, but here is an extract of an article from the Calgary Herald.

Little guy wins privacy fight against giant Telus.


Canwest News Service

Saturday, November 20, 2004

Byline: Sarah Staples

In a victory for the little guy, a federal appeals tribunal has ruled
unanimously that Telus Communications Inc. must go to greater lengths to
get its customers' approval before reselling their personal information
to telemarketers and others.

``There is no evidence that Telus made any `effort,' let alone a
`reasonable' one . . . to ensure that its first-time customers are
advised of the secondary purposes (of their personal information) at the
time of collection,'' wrote Justice Decary on behalf of his colleagues
in the decision released this week.

The case is the result of a protracted battle by Mathew Englander, a
lawyer and Vancouver resident, with the phone company since 2001.

Englander argued Telus breaks new federal privacy rules by not informing
customers when they sign up for service that it repackages telephone
directory listings into CD-ROMs and machine-readable lists and sells
them to telemarketers, charities and political parties.

Minutes after the Personal Information Protection and Electronic
Documents Act (PIPEDA) was enacted on Jan. 1, 2001, Englander became the
first Canadian to lodge a formal complaint to the federal privacy
commissioner under the new law.

His arguments were rejected, first by the commissioner and later by a
Federal Court judge in a ruling last June. But the Federal Court of
Appeals reversed those earlier decisions this week, saying Telus didn't
go far enough to make Englander understand his privacy rights.

Telus has been ordered to reimburse Englander the nearly $12,000 he paid
in costs after losing the earlier Federal Court decision.

Experts following Englander v. Telus said the ruling sets positive early
precedents, defining the legal obligations of business at a time when
consumers' expectation of privacy is under siege.

PIPEDA theoretically gives Canadians the right to scrutinize innumerable
bits of data collected about them by customer service reps, squirreled
into computerized cash registers, and revealed to creditors, doctors and
employers. It also warns companies to seek permission before using those
details. But the law frames the issues broadly, leaving it to the courts
to resolve what crucial notions, such as ``informed consent,'' will mean
in practice.

``There are huge costs to industry in attempting to inform the public.
Nevertheless, we've moved so far into an age of technology that people
don't understand what they're agreeing to,'' said Stephanie Perrin, a
consultant and former federal civil servant who was one of the authors
of PIPEDA.

``This gives us a first interpretation of what a person can reasonably
be expected to understand.''

Englander called the ruling ``an interpretation such that people can
make their own decisions about how their information will be used.

``That's what privacy is about,'' he said in a telephone interview.
``It's not only keeping things secret, it's giving individuals the right
to decide what stays confidential and what does not.''

Englander's win is a partial victory: the appeals court denied his
attempt to stop Telus from charging customers $2 a month for unlisted
service a fee that adds $5.96 million annually to the company's coffers,
from roughly 250,000 unlisted telephone numbers in Alberta and B.C.,
according to affidavits.

The telco now has 60 days to offer suggestions for revamping its
policies to bring them into compliance with the privacy law. Any changes
negotiated with the federal appeals tribunal will be incorporated into
their final written judgment, to be issued at an unspecified later date.

Drew McArthur, VP of corporate affairs and privacy officer for Telus,
hinted his firm will argue any court-ordered changes should apply only
to new customers, and only involve ``the scripting for new customers
when they call in for service,'' as opposed to more elaborate and
expensive retraining for employees.

The spokesman said phone companies across Canada may be affected, and
added Telus is considering its options, including appealing all or some
parts of the decision to the Supreme Court of Canada.

One potential hot potato for the highest court is a question of
jurisdiction: the appeals tribunal apparently granted federal judges
``overlapping jurisdiction'' to rule on PIPEDA cases, whereas Telus
argued any decision on fees should be made exclusively by its regulator,
the CRTC.

Also, ironically, the tribunal denied Canada's privacy commissioner
deference in cases that come before the courts in future, arguing that
to do so would have given privacy advocates an unfair advantage over
business interests.

``I think it's now further education of how the court views the balance
of the privacy rights of individual versus the needs of businesses,''
said McArthur.

...