telemarketing

Showing posts with label telemarketing. Show all posts
Showing posts with label telemarketing. Show all posts

EPIC Top Ten Privacy Resolutions for 2005

The Electronic Privacy Information Center has released their top ten privacy resolutions for 2005:

EPIC Top Ten Privacy Resolutions for 2005

Top Ten Consumer Privacy Resolutions

Protect Your Privacy in The New Year!



1. Engage in "privacy self defense." Don't share any personal information with businesses unless it is absolutely necessary (for delivery of an item, etc.). Don't give your phone number, address, or name to retail stores. If you do, they can sell that information or use it for telemarketing and junk mail. If they ask for your information, say "it's none of your business," or give "John Doe, 555-1212, 123 Main St." Don't return product warranty cards. Don't complete consumer surveys even if they appear to be anonymous. Profilers can build in barely-perceptible codes that link you to the survey, and this data goes straight to direct marketers.

2. Pay with cash where possible. Electronic transactions leave a detailed dossier of your activities that can be accessed by the government or sold to telemarketers. Paying with cash is one of the best ways to protect privacy and stay out of debt.

3. Install anti-spyware, anti-virus, and firewall software on your computer. If your computer is connected to the Internet, it is a target of malicious viruses and spyware. There are free spyware-scanning utilities available online, and anti-virus software is probably a necessary investment if you own a Windows-based PC. Firewalls keep unwanted people out of your computer and detect when malicious software on your own machine tries to communicate with others.

4. Use a temporary rather than a permanent change of address. If you move in 2005, be sure to forward your mail by using a temporary change of address order rather than a permanent one. The junk mailers have access to the permanent change of address database; they use it to update their lists. By using the temporary change of address, you'll avoid unwanted junk mail.

5. Opt out of prescreened offers of credit. By calling 1-888-567-8688, you can stop receiving those annoying letters for credit and insurance offers. This is an important step for protecting your privacy, because those offers can be intercepted by identity thieves.

6. Choose Supermarkets that Don't Use Loyalty Cards. Be loyal to supermarkets that offer discounts without requiring enrollment in a loyalty club. If you have to use a supermarket shopping card, be sure to exchange it with your friends or with strangers.

7. Opt out of financial, insurance, and brokerage information sharing. Be sure to call all of your banks, insurance companies, and brokerage companies and ask to opt out of having your financial information shared. This will cut down on the telemarketing and junk mail that you receive.

8. Request a free copy of your credit report by visiting http://www.annualcreditreport.com. All Americans are now entitled to a free credit report from each of the three nationwide credit reporting agencies, Experian, Equifax, and Trans Union. You can engage in a free form of credit monitoring by requesting one of your three reports every four months. By staggering your request, you can check for errors regularly and identify potential problems in your credit report before you lose out on a loan or home purchase. Currently, these reports are available to residents of most western states. By September 2005, all Americans will have free access to their credit report.

9. Enroll all of your phone numbers in the Federal Trade Commission's Do-Not-Call Registry. The Do-Not-Call Registry (http://www.donotcall.gov or 1-888-382-1222) offers a quick and effective shield against unwanted telemarketing. Be sure to enroll the numbers for your wireless phones, too.

10. File a complaint. If you believe a company has violated your privacy, contact the Federal Trade Commission, your state Attorney General, and the Better Business Bureau. Successful investigations improve privacy protections for all consumers.

For more information about privacy, visit the Electronic Privacy Information Center at http://www.epic.org/


Slashdot has a discussion of the resolutions at Slashdot | Privacy Resolutions for the New Year.

Privacy and the negative option

Apparently the Privacy Commissioner's office is currently investigating a complaint related to the "opt out" policy of one of Canada's largest telecommunications companies. While this is not entirely a new issue, this article - in and of itself - demonstrates that complainants can easily seek publicity for their complaints as the media is very interested in covering privacy issues these days.

Yahoo! News - Privacy commissioner investigating new Rogers 'negative option' complaint:

"TORONTO (CP) - The federal privacy commissioner's office has opened an investigation into a Toronto man's complaint that the Rogers Wireless service contract includes a 'negative option' privacy policy that is illegal.

Communications consultant Michael Krauss complained in September about a fine-print section of the company's service agreement that requires cellphone customers to fill out an online form or contact a customer service representative to prevent Rogers from disseminating information to other Rogers companies for telemarketing.
'I have commenced an investigation under the Personal Information Protection and Electronic Documents Act (PIPEDA) that Rogers Wireless is allegedly using negative consent when obtaining customers' permission to collect, use and disclose their personal information,' senior privacy investigator Kasia Krzymien told Krauss in a letter dated last Friday.... "

Jurisdictional limitations on Canadian privacy law

Canada's privacy law is already hobbled by the constitutional division of power. For example, as a federal law, it cannot apply to the provincially regulated workplace. But, theoretically, it can apply outside of Canada's border. This has been the theoretical position of officials from the Office of the Privacy Commissioner. However, when dealing with an actual complaint, the Commissioner did not extend the federal privacy law to an organization entirely outside of Canada.

Michael Geist, in his weekly Toronto Star Column, reports on an as-of-yet unpublished finding of the Commisioner that concludes that the law cannot regulate the use of Canadian personal information that is in the hands of an organization that has no presence in this country:

TheStar.com - CIBC breach spotlights hole in privacy law:

"...According to a recent unpublished letter from the privacy commissioner, the answer is unfortunately no. The Commissioner has adopted the position that Canada's privacy legislation stops at the border and that her office does not have the power to investigate companies that do not have a physical presence in Canada.

The letter was issued in response to a complaint launched by the Canadian Internet Policy and Public Interest Clinic (CIPPIC) against Abika.com, a U.S. company that harvests databases and public reports. The company uses the information to produce reports that allegedly include, in some cases, psychosexual profiles. CIPPIC filed its complaint in June, claiming that Abika collects, uses, and discloses the personal information of Canadians without their consent in violation of Canada's national privacy law.

The privacy commissioner's office responded privately to Canadian Internet Policy and Public Interest Clinic two weeks ago. It noted that the company does not have a physical presence in Canada and therefore concluded that 'while the organization may well be collecting information on Canadians, our legislation does not extend to investigating organizations located only in the United States. We are, therefore, unable to investigate this matter under PIPEDA' (the Personal Information Protection and Electronic Documents Act, Canada's national privacy law that governs how businesses collect and use personal information)...."



I tend to agree with Michael ... the Privacy Commissioner could have asserted jurisdiction and then dealt with the challenges of enforcement. This would at least have left the complainant with the ability to take the finding to the Federal Court of Canada to see if a real remedy could be fashioned.

Under traditional principles of international law, there are six bases on which a country such as Canada can assume jurisdiction to proscribe the actions of individuals and companies. (In most cases, these principles have arisen in the criminal law context but there is no reason to believe the Canadian courts would not apply them.) Four of the bases for jurisdiction are relevant to this discussion:

  • Territorial Principle – A state has the jurisdiction to regulate individuals and subjects within its territory, including internal waters and airspace. This is the primary and most universal base for jurisdiction.
  • Nationality Principle – Civil law countries have traditionally asserted jurisdiction over their nationals, regardless of where they may be located.
  • Passive Personality Principle – States have assumed jurisdiction over crimes committed abroad against its nationals.
  • By Agreement – A country may, by agreement, grant another country jurisdiction over certain persons or subjects within its borders.


Traditionally, the territorial principle has been the most persuasive and widely applied. This is based on the fundamental principle of international sovereignty that a state has absolute jurisdiction over "all persons, citizens and aliens alike, and things within its territory."

The Supreme Court of Canada’s decision in Libman v. The Queen is the leading Canadian authority on the issue of how and when a Canadian court may assert jurisdiction. Libman dealt with a "telemarketing scam" where the calls originated from Canada but were made to residents of the United States. Justice LaForest, who delivered the judgment of the unanimous court, recited the relevant facts:

3 During the period covered by the informations, Mr. Libman operated a telephone sales solicitation room (or "boiler room") at 43 Menin Road in Toronto, where a number of individuals were employed as telephone sales personnel. Pursuant to Mr. Libman's directions the sales personnel telephoned United States residents and attempted to induce them to purchase shares in two companies, Hebilla Mining Corporation and Claravella Corporation, which purported to be engaged in gold mining in Costa Rica. In addition to the telephone representations, the United States residents also received promotional material which was mailed from Panama City, Panama and San José, Costa Rica by associates of Mr. Libman.

4 The telephone sales personnel, on the direction of Mr. Libman, made material misrepresentations with respect to their identity, where they were telephoning from, and the quality and value of the shares they were selling. As a result of these misrepresentations, a large number of United States residents were induced to purchase shares in the two mining companies. There was some evidence tendered at the preliminary inquiry from which it could be inferred that these shares were virtually worthless.

5 The United States residents who agreed to purchase shares were told by the telephone sales personnel to send their money to offices operated by Mr. Libman's associates in either San José, Costa Rica or Panama City, Panama. There was evidence tendered that Mr. Libman went to a location outside Canada, usually Costa Rica or Panama, to meet with his associates and receive his share of the proceeds of the sale of the shares. Mr. Libman then brought this money back to Toronto and distributed a portion of it to his sales personnel. There was also evidence tendered at the preliminary inquiry with respect to the wire transfer of monies from Panama City to Mr. Libman in Toronto.



The appellant, Mr. Libman, was charged in Canada with fraud under the Criminal Code. In his defence, the appellant argued that Canada did not have the jurisdiction to prosecute him for the offence as the deprivation of the victim is the essential element of the offence and, if it did occur at all, it did not occur in Canada.

Justice LaForest began with the essential principle of territorial jurisdiction:

11 The primary basis of criminal jurisdiction is territorial. The reasons for this are obvious. States ordinarily have little interest in prohibiting activities that occur abroad and they are, as well, hesitant to incur the displeasure of other states by indiscriminate attempts to control activities that take place wholly within the boundaries of those other countries; see R. v. Martin, [1956] 2 All E.R. 86, at p. 92. … As well, along with other types of protective measures, states increasingly exercise jurisdiction over criminal behaviour in other states that has harmful consequences within their own territory or jurisdiction; see The Lotus (1927), P.C.I.J., Ser. A., No. 10. It follows from this that the same criminal act may occasionally be subject to prosecution in more than one country, a matter to which I shall refer from time to time.



The analysis is relatively straightforward where all the elements and effects of an alleged offence are within the bounds of the prosecuting state: Territorial and subject matter jurisdiction unambiguously provide that state with sufficient grounds to assert jurisdiction. In fact, it would be difficult for another state to attempt to exert jurisdiction. Matters become much more complicated when transnational activities are in question:

16 The cases reveal several possibilities, of which I mention a few. One is to assume that jurisdiction lies in the country where the act is planned or initiated. Other possibilities include the place where the impact of an offence is felt, where it is initiated, where it is completed, or again where the gravamen, or essential element of the offence took place. It is also possible to maintain that any country where a substantial or any part of the chain of events constituting an offence takes place may take jurisdiction.

17 Though counsel for Mr. Libman argued that exclusive jurisdiction belongs to the country where the gravamen of the offence took place or where it was completed, a review of the English authorities does not really support that position. What it shows is that the courts have taken different stances at different times and the general result, as several writers have stated, is one of doctrinal confusion, a confusion compounded by the fact that the discussion often focuses on the specific offence charged, a discussion made more complicated by the further fact that some offences are aimed at the act committed and others at the result of that act.



After surveying the threads of English and Canadian jurisprudence, LaForest J. concluded that a Canadian court may assert jurisdiction in circumstances where there is a "real and substantial link" between the offence and Canada:

74 I might summarize my approach to the limits of territoriality in this way. As I see it, all that is necessary to make an offence subject to the jurisdiction of our courts is that a significant portion of the activities constituting that offence took place in Canada. As it is put by modern academics, it is sufficient that there be a “real and substantial link” between an offence and this country, a test well-known in public and private international law; see Williams and Castel, supra; Hall, supra. As Professor Hall notes (p. 277), this does not require legislation. It was the courts after all that defined the manner in which the doctrine of territoriality applied, and the test proposed simply amounts to a revival of the earlier way of formulating the principle. It is in fact the test that best reconciles all the cases. The only ones that do not fall within it are those like Harden and Rush which, in my view, should no longer be followed.

75 That this approach is attuned to modern times is evident from the fact that some variant of it has been recommended by numerous law reform bodies or adopted in legislation…

76 Just what may constitute a real and substantial link in a particular case, I need not explore. There were ample links here. The outer limits of the test may, however, well be coterminous with the requirements of international comity.

77 As I have already noted, in some of the early cases the English courts tended to express a narrow view of the territorial application of English law so as to ensure that they did not unduly infringe on the jurisdiction of other states. However, even as early as the late 19th century, following the invention and development of modern means of communication, they began to exercise criminal jurisdiction over transnational transactions as long as a significant part of the chain of action occurred in England. Since then means of communications have proliferated at an accelerating pace and the common interests of states have grown proportionately. Under these circumstances, the notion of comity, which means no more nor less than “kindly and considerate behaviour towards others”, has also evolved. How considerate is it of the interests of the United States in this case to permit criminals based in this country to prey on its citizens? How does it conform to its interests or to ours for us to permit such activities when law enforcement agencies in both countries have developed cooperative schemes to prevent and prosecute those engaged in such activities? To ask these questions is to answer them. No issue of comity is involved here. In this regard, I make mine the words of Lord Diplock in Treacy v. Director of Public Prosecutions cited earlier. I also agree with the sentiments expressed by Lord Salmon in Director of Public Prosecutions v. Doot, supra, that we should not be indifferent to the protection of the public in other countries. In a shrinking world, we are all our brother's keepers. In the criminal arena this is underlined by the international cooperative schemes that have been developed among national law enforcement bodies.

78 For these reasons, I have no difficulty in holding on the facts agreed upon for the purpose of this appeal, that the counts of fraud with which the appellant is charged may properly be prosecuted in Canada, and I see nothing in the requirements of international comity that would dictate that this country refrain from exercising its jurisdiction. Since these fraudulent activities took place in Canada, it follows for the reasons set forth in the Chapman case that the conspiracy count may also be proceeded with in Canada.



It goes without saying that the evolving adoption of privacy and data protection laws are not identical to criminal law, either domestically or internationally. However, analogies are easily made and there is an evolving international cooperative scheme, beginning with the OECD Guidelines.

As the basis for Canada to claim jurisdiction requires a "real and substantial link" between the activity and Canada, one must consider whether the collection of personal information about Canadians by foreign companies would be considered to provide a "real and substantial link" to Canada or the collection of information about non-Canadians by a Canadian company. The facts in Libman are sufficiently analogous to provide authority for the proposition that a court on review would likely find a “real and substantial link” between such activities and Canadian jurisdiction, notwithstanding any argument that the connection is de minimis.

The Personal Information Protection and Electronic Documents Act sets out, at Section 4, the basis of its application:

Application

4. (1) This Part applies to every organization in respect of personal information that

(a) the organization collects, uses or discloses in the course of commercial activities; or

(b) is about an employee of the organization and that the organization collects, uses or discloses in connection with the operation of a federal work, undertaking or business.



Limit

(2) This Part does not apply to

(a) any government institution to which the Privacy Act applies;

(b) any individual in respect of personal information that the individual collects, uses or discloses for personal or domestic purposes and does not collect, use or disclose for any other purpose; or

(c) any organization in respect of personal information that the organization collects, uses or discloses for journalistic, artistic or literary purposes and does not collect, use or disclose for any other purpose.



Other Acts

*(3) Every provision of this Part applies despite any provision, enacted after this subsection comes into force, of any other Act of Parliament, unless the other Act expressly declares that that provision operates despite the provision of this Part.



The application section is entirely silent with respect to its intended territorial application. The only reference to specific jurisdictions are contained in the transitional provisions and the definition of "federal work, undertaking or business". The transition provisions begin with Section 30:

DIVISION 5

TRANSITIONAL PROVISIONS

Application

30. (1) This Part does not apply to any organization in respect of personal information that it collects, uses or discloses within a province whose legislature has the power to regulate the collection, use or disclosure of the information, unless the organization does it in connection with the operation of a federal work, undertaking or business or the organization discloses the information outside the province for consideration.

Application

(1.1) This Part does not apply to any organization in respect of personal health information that it collects, uses or discloses.

Expiry date

*(2) Subsection (1) ceases to have effect three years after the day on which this section comes into force.

*[Note: Section 30 in force January 1, 2001, see SI/2000-29.]

Expiry date

*(2.1) Subsection (1.1) ceases to have effect one year after the day on which this section comes into force.

*[Note: Section 30 in force January 1, 2001, see SI/2000-29.]



These provisions are temporary (and expired on January 1, 2004), as they assist with the gradual implementation of the legislation, providing individual provinces with the ability to put in place substantially similar legislation during the period in which the law only applies to the federally regulated private sector and cross-border sales of information. It may be notable that the cross-border reference says "outside the province" and not "to another province".

In the absence of clear guidance from the statute, one can interpret it to apply in all circumstances where there exists a "real and substantial link" to Canada, following the Supreme Court's guidance in Libman. In any event, there is nothing in the statute that would prevent Canada from assuming jurisdiction in the circumstances set out above.

In the past, Officials with the Office of the Privacy Commissioner have advised that the Commissioner likely would assume jurisdiction where the collection of personal information is about Canadians or Canadian residents or where the collection originates in Canada. This appears to no longer be the case. Not only would the collection take place "in Canada", the Commissioner’s office used to be of the view that PIPEDA is part of an international scheme of privacy protection that could reach over borders.

The Privacy Commissioner has an arguable basis to make this second assertion and assume jurisdiction. As mentioned above, Canada implemented PIPEDA following the OECD Guidelines and in light of threatened restrictions on cross-border data flows caused by the EU Directive. Recital 20 of the EU Directive reads:

(20) Whereas the fact that the processing of data is carried out by a person established in a third country must not stand in the way of the protection of individuals provided for in this Directive; whereas in these cases, the processing should be governed by the law of the Member State in which the means used are located, and there should be guarantees to ensure that the rights and obligations provided for in this Directive are respected in practice;


The EU Directive is implemented, for example, in the United Kingdom's Data Protection Act 1998, which provides that the statute would apply, for example, if a call centre contacting Canadians were located in the United Kingdom:

Application of Act.

5. - (1) Except as otherwise provided by or under section 54, this Act applies to a data controller in respect of any data only if-

(a) the data controller is established in the United Kingdom and the data are processed in the context of that establishment, or

(b) the data controller is established neither in the United Kingdom nor in any other EEA State but uses equipment in the United Kingdom for processing the data otherwise than for the purposes of transit through the United Kingdom.



(2) A data controller falling within subsection (1)(b) must nominate for the purposes of this Act a representative established in the United Kingdom.

(3) For the purposes of subsections (1) and (2), each of the following is to be treated as established in the United Kingdom-

(a) an individual who is ordinarily resident in the United Kingdom,

(b) a body incorporated under the law of, or of any part of, the United Kingdom,

(c) a partnership or other unincorporated association formed under the law of any part of the United Kingdom, and

(d) any person who does not fall within paragraph (a), (b) or (c) but maintains in the United Kingdom-

(i) an office, branch or agency through which he carries on any activity, or

(ii) a regular practice;



and the reference to establishment in any other EEA State has a corresponding meaning.



While Canada is obviously not bound by the EU Directive, it appears to be the spirit of PIPEDA that the Canadian law fit within this general scheme of international data protection.

This may be academic, as this no longer appears to be the position of the Office of the Privacy Commissioner.

Do not call legislation on the way

Both the Toronto Star and CTV are carrying stories predicting that long-awaited "no not call" legislation is on the way, sooner rather than later.

CTV.ca | Canadian do-not-call legislation coming: report:

"By the end of next week, Canadian lawmakers could be considering a bill aimed at ending the scourge of unwanted phone calls from telemarketers.

According to a report in The Toronto Star, legislation to create a national do-not-call registry similar to one already launched in the United States is expected to be tabled before the end of next week.

The bill is expected to bar telemarketers from calling anyone on the list, unless they have established a pre-existing relationship. That means someone who's requested information about a specific service can be contacted.

Previous legislation that would have allowed Canadians to register with such a list died with the last federal election call.

Under current Canadian Radio-television and Telecommunications Commission regulations, telemarketing agencies must maintain their own registry of people not wishing to be called. Numbers appearing on those lists can't be faxed or phoned for three years....."


And from the Toronto Star:

TheStar.com - National 'do-not-call' registry likely:

"The Liberal government is widely expected to introduce legislation next week that would create a national do-not-call registry, giving Canadian households the option of shielding themselves from unwanted telemarketing calls.

A similar registry was introduced with great fanfare last year in the United States and has already attracted more than 66 million households. Government and industry sources said a bill is likely to be tabled before the House of Commons breaks next week for the holidays, but could be delayed until it sits again in late January.

'I am convinced now that they have every intent of doing it, and doing it very soon,' said John Gustavson, president of the Canadian Marketing Association, which has supported a national registry since 2001. 'We think it's the right way to go, and we think it will be valuable information for marketers and valuable relief for consumers.'...."



As a complete aside, I find it interesting that Canadian marketing organizations, unlike their US counterparts, favour DNC laws and privacy laws.

FCA hands privacy victory to the "little guy"

Sorry for the light (read: non-existent) blogging over the last few days. I've finally gotten to an internet connection ....

Mathew Englander e-mailed me the other day to say that the Federal Court has rendered their decision in his fight against Telus. I haven't read the full reasons, which should be available here soon, but all reports suggest that Telus did not persuade the Federal Court of Appeal to uphold the finding of the Privacy Commissioner and the Federal Court, Trial Division. I haven't found any free coverage online, but here is an extract of an article from the Calgary Herald.

Little guy wins privacy fight against giant Telus.


Canwest News Service

Saturday, November 20, 2004

Byline: Sarah Staples

In a victory for the little guy, a federal appeals tribunal has ruled
unanimously that Telus Communications Inc. must go to greater lengths to
get its customers' approval before reselling their personal information
to telemarketers and others.

``There is no evidence that Telus made any `effort,' let alone a
`reasonable' one . . . to ensure that its first-time customers are
advised of the secondary purposes (of their personal information) at the
time of collection,'' wrote Justice Decary on behalf of his colleagues
in the decision released this week.

The case is the result of a protracted battle by Mathew Englander, a
lawyer and Vancouver resident, with the phone company since 2001.

Englander argued Telus breaks new federal privacy rules by not informing
customers when they sign up for service that it repackages telephone
directory listings into CD-ROMs and machine-readable lists and sells
them to telemarketers, charities and political parties.

Minutes after the Personal Information Protection and Electronic
Documents Act (PIPEDA) was enacted on Jan. 1, 2001, Englander became the
first Canadian to lodge a formal complaint to the federal privacy
commissioner under the new law.

His arguments were rejected, first by the commissioner and later by a
Federal Court judge in a ruling last June. But the Federal Court of
Appeals reversed those earlier decisions this week, saying Telus didn't
go far enough to make Englander understand his privacy rights.

Telus has been ordered to reimburse Englander the nearly $12,000 he paid
in costs after losing the earlier Federal Court decision.

Experts following Englander v. Telus said the ruling sets positive early
precedents, defining the legal obligations of business at a time when
consumers' expectation of privacy is under siege.

PIPEDA theoretically gives Canadians the right to scrutinize innumerable
bits of data collected about them by customer service reps, squirreled
into computerized cash registers, and revealed to creditors, doctors and
employers. It also warns companies to seek permission before using those
details. But the law frames the issues broadly, leaving it to the courts
to resolve what crucial notions, such as ``informed consent,'' will mean
in practice.

``There are huge costs to industry in attempting to inform the public.
Nevertheless, we've moved so far into an age of technology that people
don't understand what they're agreeing to,'' said Stephanie Perrin, a
consultant and former federal civil servant who was one of the authors
of PIPEDA.

``This gives us a first interpretation of what a person can reasonably
be expected to understand.''

Englander called the ruling ``an interpretation such that people can
make their own decisions about how their information will be used.

``That's what privacy is about,'' he said in a telephone interview.
``It's not only keeping things secret, it's giving individuals the right
to decide what stays confidential and what does not.''

Englander's win is a partial victory: the appeals court denied his
attempt to stop Telus from charging customers $2 a month for unlisted
service a fee that adds $5.96 million annually to the company's coffers,
from roughly 250,000 unlisted telephone numbers in Alberta and B.C.,
according to affidavits.

The telco now has 60 days to offer suggestions for revamping its
policies to bring them into compliance with the privacy law. Any changes
negotiated with the federal appeals tribunal will be incorporated into
their final written judgment, to be issued at an unspecified later date.

Drew McArthur, VP of corporate affairs and privacy officer for Telus,
hinted his firm will argue any court-ordered changes should apply only
to new customers, and only involve ``the scripting for new customers
when they call in for service,'' as opposed to more elaborate and
expensive retraining for employees.

The spokesman said phone companies across Canada may be affected, and
added Telus is considering its options, including appealing all or some
parts of the decision to the Supreme Court of Canada.

One potential hot potato for the highest court is a question of
jurisdiction: the appeals tribunal apparently granted federal judges
``overlapping jurisdiction'' to rule on PIPEDA cases, whereas Telus
argued any decision on fees should be made exclusively by its regulator,
the CRTC.

Also, ironically, the tribunal denied Canada's privacy commissioner
deference in cases that come before the courts in future, arguing that
to do so would have given privacy advocates an unfair advantage over
business interests.

``I think it's now further education of how the court views the balance
of the privacy rights of individual versus the needs of businesses,''
said McArthur.

...


Go ahead and complain to the privacy commissioner ...

CFCN of Calgary, Alberta is running a story about an individual who was called by a telemarketer on behalf of a life insurer, who got the individual's personal information from one of Canada's large retailers.
The individual was upset that they had his birthdate, which was also obtained from the same source. The individual had not opted out from the information sharing.

The story is interesting also because it suggests that readers complain to the Information and Privacy Commissioner of Alberta: See the article here: CFCN.ca - Calgary news from CFCN, CTV

Court: Federal Law Bans Text-Message Spam

An Arizona appeals court has held that unsolicited text messages to a cell phone violate a federal anti-telemarketing law originally aimed at voice calls. See Court: Federal Law Bans Text-Message Spam - Mobile News - Designtechnica.

Article: CRTC puts new rules on hold

The Toronto Star has an article in today's edition about the CRTC suspension of the changes to the Canadian telemarketing regulations:

TheStar.com - CRTC puts new rules on hold:

"Strict rules imposed on telemarketers in May have been put on hold pending the outcome of a regulatory review.

The Canadian Radio-television and Telecommunications Commission has decided to reconsider its new rules in response to a complaint filed in August by the Canadian Marketing Association.

The association, with 800 members that include major financial institutions, telephone operators and media companies, argued that the high cost of complying with the regulations will put many smaller phone marketers out of business and result in job loss across an industry that employs 270,000...."

CRTC suspends application of new Canadian telemarketing rules

The CRTC has temporarily suspended the application of their recent changes to the Canadian telemarketing rules. The full text of the decision is here and the "blurb" is below:

Telecom Decision CRTC 2004-63

Telemarketing


Telecom Decision:


2004-63 The
Commission approves, with one exception, the Canadian Marketing Association's
(CMA's) application to stay Review of telemarketing rules, Telecom
Decision CRTC 2004-35, 21 May 2004, pending the disposition of the CMA's
application to review and vary that Decision. The stay applies to all
requirements set out in Decision 2004-35 except the requirement that
telecommunications service providers track and report complaint statistics; this
requirement becomes effective 1 January 2005. Reference: 8662-C131-200408543. [.pdf]



Readers interested in Canadian telemarketing law and the regulation of it by the CRTC in particular are encouraged to check out Mathew Englander's site devoted to the topic at http://www.mathew-englander.ca/canada-telemarketing-law.htm

New rules for reverse phone directory lookup

The Canadian Radio-television and Telecommunications Commission (CRTC) has just produced guidelines regulating how incumbent local carriers can offer reverse directory assistance. (Instead of asking for a name and locality to get the number, this service provides name and location when given the phone number.) The issue has a couple of privacy issues, both pro and con. On one hand, it provides personal information that the individual may not want handed out, based solely on their phone number. On the other hand, the service may give people more information about who is calling them, giving them greater control over intrusions into their seclusion. Hard call. According to this article in ITBusiness.Ca, they've hit the balance by only providing name and general locality, not home address. And, presumably, unlisted numbers will not be included in the directory.

CRTC's reverse directory search policy addresses privacy advocates' concerns

The Canadian Radio-television and Telecommunications Commission (CRTC) recently established a framework for the provision of Reverse Search Directory Assistance (RSDA) offered by incumbent local exchange carriers (ILECs). RSDA is an expanded directory assistance service that provides the listed name and address associated with a specific telephone number.

The Commission has decided to allow ILECs to perform information searches when presented with telephone numbers under certain conditions.

As part of the public process leading to the current CRTC decision, the ILECs stated that none of objectives of the Telecommunications Act would be adversely affected if they provided RSDA. On the other hand, groups such as the Anti-Poverty Organization and the Information and Privacy Commissioner of Ontario, argued that this service contravenes the privacy protection provided by the Act.

...

Because of the significant safety concerns over providing street addresses, the Commission decided the only information that can be provided by RSDA searches are name and general locality, such as city, town or postal code.

There were some concerns expressed that RSDA service could be a valuable asset to commercial entities involved with telemarketing. They could use the service to determine the names and addresses of those calling for information about products and services without their knowledge or consent.

To address this issue, the new regulations prohibit the use of RSDA for compiling and updating telemarketing lists. ..."


Article: A privacy win and a privacy loss

From the Direct Marketing News comes an article by Robert Gellman reviewing two ipmortant American privacy-related cases:

It’s time to catch up with two court cases that were the subject of past columns and that produced new opinions. Privacy did well in one case and poorly in the other.

The first case is the litigation over the do-not-call registry decided in February by the 10th Circuit. Everybody knows that the court rejected the telemarketing industry’s arguments that the registry is unconstitutional. It was a sweeping victory for the registry, as the court dismissed every argument put forward in opposition. ...


February also brought a decision by the Supreme Court in a case arising under the Privacy Act of 1974, a law that applies only to federal agencies. The case, Doe v. Chao, involved the improper disclosure of a Social Security number by the Department of Labor. The issue was what a plaintiff had to prove to receive the $1,000 in minimum damages that the statute provides.

...

The case is a setback for privacy. Privacy advocates hoped that the court would have more sympathy for the consequences of privacy violations and for the difficulty of proving damages in privacy cases, but they did not prevail.

...

If you didn’t like the result in these cases, just wait. There will be more decisions in more privacy cases soon.