PIAC Comments on “Customer Name and Address Information Consultation”

October 18, 2007
PIAC today filed comments on the Government’s “Customer Name and Address Information Consultation” Document, otherwise known as “Lawful Access”, that is, the proposal to give police and government the power to intercept certain information from telecommunications providers such as Internet service providers and telephone companies. The initiative appears to consider allowing government to ask for certain information about, for example, personal e-mails and web surfing habits. Certain possible “safeguards” are proposed but none is subject to the level of public scrutiny that one would expect in Canada, according to PIAC, and it appears judges will have either no or only a limited role in deciding what the government and police may demand from telecommunications companies.
PIAC Comments are found here:
PIAC Comments on “Customer Name and Address Information Consultation” [pdf file: 0.04mb]
 

thumb_pdfPIAC Comments on “Customer Name and Address Information Consultation
Download File: piac_letter_lawful_access_2007.pdf [size: 0.04 mb]

 

PIAC REPORT: National Identity Cards, Biometrics and the Consumer: Displacing the Personal from the Person

As Canada continues to bolster national security post September 11th, and consumer commerce becomes increasingly jeopardized by identity theft, a National Identity Card scheme has been discussed as a potential solution. However, critics charge that National Identity Cards could turn into “de facto internal passports” which would be required to access almost all government or business services. Additionally, this new Card could lead to serious breaches to personal privacy. First, this report focuses on the security solutions offered by a National Identity Card, in terms of (a) National Security, (b) Identity Theft. Second, the privacy implications of a National Identity Card program will be identified, including a discussion of the effect of The Personal Information Protection and Electronic Documents Act (PIPEDA) in enabling infringement of personal privacy in the context of a National Identity Card scheme.
A National ID Card may likely be an inadequate solution to bolster national security because it fails to achieve the three broad goals set in Canada’s National Security Policy. National Identity Cards would link names with faces, and possibly even with biometric data, but would not, on its own, identify those persons harboring malicious intentions. Additionally, National Identity Cards would likely not help to curb identity theft, as identity theft has many causes. Even those for which a National ID Card might directly apply, there are weaknesses and dangers in its use. This report examines the reasons behind these shortcoming in terms of (1) Easy Credit, (2) Consumer Control of Credit Bureau Files and (3) Function Creep.
A National Identity Card program will also face technological and practical shortcomings. (1) They will be prone to fraud and counterfeit, just like other forms of identification. (2) Specifying who will be issued a Card, and who will not, includes the potential for social exclusion. And, (3) because of serious concerns about its accuracy and reliability, biometric indicators may in fact make National Identity Cards less secure. Given the pitfalls associated with a National Identity Card program, consumers are justified to be concerned about fraud, the implications of misidentification, as well as the cost of implementation.
A National Identity Card will also involve a vast accumulation of consumer information, which is cause for concern from a privacy standpoint. The major privacy implications stem from function creep, the threat posed by use of collected information for purposes other than that for which it was originally collected. Further, protecting the databases holding personal information is not only costly, but difficult to assure. Finally, exceptions under PIPEDA permit information to be exchanged between and within government, as well as between businesses and government for the protection of national security. This report concludes that the use of National Identity Cards, with or without biometrics, in interactions between individuals and the state or commercial entities, in a context of inadequate legal and technological safeguards, would introduce new ways of violating individual privacy and integrity. It would also be unacceptably costly given the expected, poor, results. However, should the Canadian federal government pursue the idea of a National Identity Card, recommendations have been supplied to reduce the risk of harm to consumers and citizens with respect to privacy and civil rights.
Read the full report:
 

thumb_pdfPIAC REPORT: National Identity Cards, Biometrics and the Consumer: Displacing the Personal from the Person
Download File: biometrics_national_id_piac_report.pdf [size: 0.14 mb]

 

PIAC REPORT: Spyware: Looking Out for Consumers

Spyware is essentially software that limits users’ control over their computers, and often is installed surreptitiously. Historically much of this type of software tracked users’ online behaviour and delivered pop-up advertising, leading to the label “spyware”. Its association with pop-up advertising and its difficult uninstall methods soon led to its reputation as an Internet scourge. “Spyware” as a broad category now includes many behaviours beyond spying, from the more ‘innocent’ displaying of advertisements right through to the delivery of viruses allowing for the remote control of the user’s computer.
Over the last few years, spyware infection rates rose dramatically until their peak in late 2004. While there was a reduction in spyware installation rates between late 2004 and late 2005, likely due to Windows security patches, consumer education and advancements in anti-spyware software, infection rates again are climbing to near-record levels in the first quarter of 2006.
This trend is a serious threat, since spyware lowers consumer confidence in e-commerce, costs consumers tremendous amounts of time and money, and threatens governments and corporations with the possibility of large-scale security vulnerabilities. Spyware is also responsible for an increasing amount of service calls and computer crashes each year.
Extreme spyware activities likely violate several Canadian laws, including consumer protection legislation, PIPEDA, Criminal Code provisions, the Competition Act and the common law tort of trespass to chattels. However, neither remedies currently available to individual users nor deterrents to spyware producers are sufficient to address the problem. While intentionally deceptive or misleading installations are likely caught by several statutes, it is often selectively omitted information, rather than outright deceptive statements, that characterize the spyware installation process. It is uncertain if these more common behaviours are actionable, despite the fact that a large majority of computer users report having no knowledge of the software in question, or how it was installed. Government actors in Canada are not actively pursuing any enforcement activities against spyware companies on their own initiative at the moment. This is likely due to a lack of resources or a view that spyware regulation does not fit the specific department’s mandate.
In this environment a legislative response may be necessary, but there is a major difficulty in regulating spyware: its lack of a cohesive definition. Any definition based on post-installation behaviours will ultimately leave significant discretion and potentially create unintended liability, because spyware behaviours can almost always have legitimate purposes in other contexts. Because of this limitation, the most appropriate legislative response should target the installation procedure, and require specific disclosures for potentially unwanted software behaviours that inhibit user control. This strategy will lead to a spyware definition built around the consent of the user, avoiding the need to outlaw specific software functionality and clarifying the emerging software installation regime.
Further regulation can rein in absurdly large affiliate networks, prevent the targeting of children to obtain installations, and perhaps pressure advertising companies to exercise more due diligence in controlling where their advertisements are displayed. Uninstall requirements could also be established, to eliminate misleading or ineffective uninstall procedures.
Critics of spyware regulation state that regulating bad actors on the Internet is impossible due to jurisdictional issues, or that additional notice will not affect user behaviour. Furthermore, legitimate software vendors likely fear overly broad legislation that could lead to unintended liability. While jurisdictional problems will always stand in the way of effective Internet regulation, this concern should not prevent spyware regulation since many large, established companies engage in spyware practices. These corporations can certainly be regulated with some success. The concern over additional notice similarly should not prevent regulation. While the relationship between notice and user behaviour may be questionable, uncertainty should not prevent legislators from establishing baseline standards to protect the public. Finally, legislation could be drafted in such a way as to minimize compliance efforts by legitimate software vendors, since most legitimate software will not engage in ‘potentially unwanted’ software activity. Generally any software that allows the user to control it will not be affected by legislation, and the vast majority of legitimate software allows the user to do so.
While US government actors have been criticized for their slow progress in tackling the threat posed by spyware, the Canadian government has done little concrete to date. Spyware nonetheless has been harming Canadian for several years and this inaction is becoming noticeable. Parliament should immediately determine which department is responsible for enforcing laws against spyware activity, and allocate the necessary resources to investigate and prosecute offenders. Spyware legislation, focused on the installation procedure, can then be introduced to aid in the fight, ensuring a strong reaction to the problem while minimally burdening legitimate software vendors.
While spyware has highlighted the need for clearer rules in software installation procedures, regulation of spyware should be viewed with a greater goal in mind: a stronger statement of users’ rights over their computers. Users should always be presumed to desire complete control over their computer, and any attempt to limit that control through the installation of software should be done in a transparent fashion that requires fair and obvious consent.
This report therefore makes recommendations for a multi-facted approach to controlling spyware that includes regulation of certain aspects of spyware. In particular, this report recommends the following:

  • Give a clear mandate and allocate resources towards the department best able to handle spyware complaints and enforce current laws against spyware activity.
  • Enforce current consumer protection and competition laws against companies who engage in the worst spyware activity.
  • Continue and strengthen consumer education initiatives regarding spyware, accentuating:
    • Only download from websites you trust;
    • Update your operating system software;
    • Install a trusted anti-spyware solution.
  • Build support in the software community for clearer rules of installation for potentially unwanted software.
  • Develop initiatives towards more accountability in the advertising industry, clarifying how advertising money gets to spyware distributors and what advertisers, advertising companies and brokers can do about it.
  • Introduce spyware-specific legislation that:
    • Creates liability for software producers for the actions of their affiliates;
    • Clarifies the rules of installing potentially unwanted software by creating clear disclosure requirements;
    • Creates a higher threshold of consent for software installations than simple contractual consent, namely “fair and obvious” consent;
    • Creates a private right of action, with statutory damages, for unwanted installations of spyware;
    • Specifically empowers an agency with spyware enforcement and permits that agency to cooperate with foreign counterparts
    • Regulates the practice of targeting software installations towards children;
    • Requires standard uninstall procedures for all software;
    • Contains exemptions for operating systems.

Although spyware appears to be on its way to becoming a fact consumers are resigned to, the truth is that the dangers of its unchecked growth are too large to ignore and the options for slowing its growth are both possible and not overly onerous. This report is a call to action on the part of consumers, governments and industry to work together to ensure consumers’ computers remain useful and unpolluted.
Download full report:
 

thumb_pdfPIAC Report: Spyware: Looking Out for Consumers
Download File: spyware_piac_report.pdf [size: 0.84 mb]

Radio Frequency Identification (RFID) and Privacy: Shopping into Surveillance

Download File: rfid.pdf [size: 0.21 mb]

Executive Summary

Radio Frequency Identification (RFID) is a technology that allows people and objects to be identified and tracked via a radio frequency signal. This report looks at privacy issues surrounding the likely use of RFID by major retailers, and suggests limits to these systems consistent with present privacy laws, as well as comments on whether the present privacy law regimes adequately protect consumers from retail surveillance. As this is a new technology, the report will seek to define the new technology, and to report on its applications and likely applications thus far as well as to report on consumer attitudes to the technology.
RFID is well-established in the supply chain of major retailers already. To a certain extent, RFID use in manufacturing and supply chain management has been encouraged by government safety concerns with products such as pharmaceuticals and automobile tires. However, government, when encouraging such ‘pre-retail’ uses, does not generally require privacy impact assessments, which might limit the extension of RFIDs from manufacturing into the retail environment.
Consumers soon will face RFIDs at the retail level. It is this ‘item-level’ use of RFID that raises consumer privacy and related concerns. Item level RFIDs produce individual data which, when linked to an individual shopper through a loyalty card or otherwise, constitutes a form of low-level, distributed consumer surveillance. This potential surveillance raises the specter of consumer profiles that track consumer behaviour in relation to objects. Such profiles may become available to not only the original retailer, but also affiliated companies, or even to the federal government under national security exceptions to Canada’s private sector privacy law. RFID tags, if left live ‘post-sales’ (whether consciously for warranty and related purposes or unconsciously – that is, not ‘killed’ at the point of sale) risk being read by third parties, if encryption or similar security measures are not applied by the original retailer.
RFID technology presents a novel challenge to Canadian privacy law. The “primitive” surveillance capabilities of RFID at present are unlikely to violate a reasonable expectation of privacy as interpreted by the Supreme Court of Canada. However, Canada’s private sector Personal Information Protection and Electronic Documents Act (PIPEDA) does appear to severely limit RFID use for consumer surveillance purposes. RFID technology has caught the eye of Canada’s Office of the Privacy Commissioner (OPCC), which has asked retailers for details of their planned RFID uses.
PIPEDA appears to require retailers who wish to track individual shoppers to obtain the informed consent of customers for the use or disclosure of the shopping patterns the RFID chips reveal about their customers. Such ‘informed consent’ will be difficult to achieve without extensive disclosure to the customer of the full implications of RFID surveillance and a positive indication of consent to the use and disclosure of RFID surveillance.
Retailers with more modest goals of controlling in-store inventory, rather than tracking customers will face less rigour in informing customers of RFID use. But, they will still be required as a matter of course to ‘kill’ RFID tags at the point-of-sale or undertake encryption or similar technological measures to safeguard the personal information of their shoppers from third party interception post-sales. Such retailers would appear to be prohibited from associating personal information from loyalty card or other customer information databases with RFID data obtained from interaction of individual customers with RFID chipped products.
Consumer polling appears to indicate great consumer discomfort in the surveillance aspect of RFID technology. While consumers may welcome certain safety and convenience benefits from RFID, their concern with privacy-invasive aspects of RFID outweighs it to the point where RFID use as surveillance appears unreasonable. In addition, some of the benefits of RFID promised by retailers may in fact interfere with established consumer rights and expectations – for example regarding hassle-free return policies.
As RFID implementation is moving forward quickly, it is recommended that immediate action be undertaken by the OPCC to provide RFID-specific guidelines which explain the constraints on the use of the technology for consumer surveillance and profiling, at least in the absence of very clear, and informed consumer consent. Ideally, the OPCC should ask that RFID- or surveillance-specific provisions be added to PIPEDA during the Parliamentary review of the legislation slated for 2006.

Revised Letter Findings – Bell ExpressVu Complaint

Public Interest Advocacy Centre Response To “Treatment of Efficiencies in the Competition Act”

Introduction

The Public Interest Advocacy Centre (PIAC) welcomes this opportunity to submit comments in response to the Competition Bureau’s Consultation Paper, “Treatment of Efficiencies in the Competition Act”. PIAC has been representing consumer interests before various regulatory and administrative tribunals for over twenty-five years, in particular as concerns questions of economic regulation. As a result, PIAC can bring a consumer perspective to bear on the questions raised by the Consultation Paper.
Consumers generally benefit greatly from competition. Lower prices, greater product and service innovation, and expanded variety and choice are all benefits of properly working competitive markets. PIAC strongly supports measures to block the prevention or substantial lessening of competition, through mergers and other structural reorganizations.
PIAC recognizes that in some circumstances competition may need to be subordinated to other factors. One such instance may be the potential of significant efficiency gains arising from a merger. However, such situations should be exceptional. Further, “efficiency gains” must be considered in the context of the other objectives stated in s. 1.1 of the Competition Act, and of the welfare of Canadian society in general.
Although the “efficiency defence” is available under provisions of the Act other than s. 96, it has never been invoked there, and, in PIAC’s view, it likely never will be. Accordingly, in what follows, PIAC addresses the “efficiency defence” as it applies to mergers under s. 96.
PDF [pdf file: 0.1mb]

Consumer Privacy and State Security: Losing Our Balance

Report: Consumer Privacy and State Security: Losing Our Balance

The Full Report is available in PDF. [pdf file: 0.48mb]

EXECUTIVE SUMMARY

Canadian citizens and consumers are facing an unprecedented challenge to their privacy rights. State security measures implemented in Canada since the terrorist attacks of September 11, 2001 have seriously reduced these privacy rights. There has been little public debate over the public policy and legal changes made in Canada to support the “war on terrorism”. However, these changes have made Canadians’ privacy rights possible “collateral damage” in this war. Canadians seem largely unaware of these measures and still supportive of government efforts to quell terrorist threats.
Nevertheless, Canadians are protective of many privacy rights that are necessarily or unnecessarily compromised in seeking to boost national security. These include the right and expectation that their movements and other clues they give about themselves as they purchase and live their way through life will not systematically be made available to government. They continue to have an expectation of privacy in their personal communications, whether these are conducted over the phone or over the Internet. They do not like surveillance of their daily activities. They do not appreciate business helping the government to collect profiles of their consumer habits. In short, they do not accept that their personal privacy necessarily must be compromised to increase national security. Above all, they are concerned that the Canadian government will allow the sharing of their personal information with other countries, especially the United States.
This report examines three challenges to Canadian privacy rights posed by the new security agenda of government and business. First, it looks at legal requirements that rely upon, or that risk, a systematic violation of usual privacy rights, including: the collection, use and disclosure of airline flight information; the outsourcing of personal information processing to entities subject to the USA PATRIOT Act; and the information requirements of the US VISIT traveler information program. Second, the report examines the increase in surveillance technologies of all kinds that has been hastened and expanded by national security concerns, including: interception of private communications; national identity cards/biometrics; and closed-circuit television and video surveillance of the public. Third, the report focuses on marketplace-driven and -assisted potential privacy violations, including: radio-frequency identification; datamining; and, finally, the virtual conscription of Canadian business into being “agents of the state” to collect and process “suspicious” data on Canadians.
The Report includes significant national polling results of Canadians’ attitudes towards, and knowledge of privacy and national security conflicts. The poll reveals Canadians wish to assist with national security efforts but are unclear on the trade-offs with personal privacy involved. The poll finds, significantly, that most Canadians expect a similar treatment of their privacy rights even in the new post 9/11 world.
The costs of reducing privacy rights to increase state security, both financial and in terms of lost confidence in business and government, has the potential to be large and appears to be growing. The report concludes with calls for increased accountability of government and business in this “balancing” of privacy rights and security measures.

SOMMAIRE

Les citoyens et les consommateurs canadiens doivent faire face à un défi sans précédent concernant les droits de la protection de leurs renseignements personnels. Les mesures de sécurité nationale mises en place au Canada depuis les attaques terroristes du 11 septembre 2001 ont sérieusement restreint ces droits. Les débats sur la politique publique et les changements juridiques effectués au Canada visant à appuyer « la guerre contre le terrorisme » sont rares. Néanmoins, ces changements aux fins de cette guerre peuvent causer d’éventuels « dommages collatéraux » aux droits de la protection des renseignements personnels des Canadiens. La plupart des Canadiens semblent ignorer ces mesures et approuvent encore les efforts du gouvernement visant à dissiper toute menace terroriste.
Cependant, les Canadiens protègent de nombreux droits de la protection des renseignements personnels qui sont nécessairement ou inutilement compromis aux fins d’une meilleure sécurité nationale. Ces droits comprennent le droit et la présomption que leurs mouvements et toute autre information qu’ils communiquent lors d’achats et dans leur vie quotidienne ne seront pas systématiquement mis à la disposition du gouvernement. Ils continuent de croire que leurs communications personnelles sont protégées, que ce soit par téléphone ou par Internet. Ils n’aiment pas la surveillance de leurs activités quotidiennes. Ils n’apprécient pas les entreprises qui aident le gouvernement à dresser le profil de leurs habitudes en matière de consommation. En bref, ils n’acceptent pas que la protection de leurs renseignements personnels soit nécessairement compromise dans le but d’améliorer la sécurité nationale. Ce qui les inquiète le plus est le fait que le gouvernement canadien puisse permettre le partage de leurs renseignements personnels avec d’autres pays, surtout les États-Unis.
Ce rapport examine trois questions relatives aux droits de la protection des renseignements personnels canadiens que pose le nouvel ordre du jour en matière de sécurité établi par le gouvernement et les entreprises. Tout d’abord, il étudie les prescriptions d’une loi fondées sur, ou posant le risque de, la violation systématique des droits au respect de la vie privée habituels, dont : la collecte, l’utilisation et la divulgation de l’information des vols des compagnies aériennes, la sous-traitance du traitement des renseignements personnels confiée aux entités assujetties au Patriot Act (Loi patriote) des États-Unis, et les renseignements qu’exige le US VISIT traveler information program (programme d’information du voyageur visitant les États-Unis). Le rapport aborde ensuite l’augmentation des technologies de surveillance de tout genre qui ont été dépêchées et dont le nombre s’est multiplié suite aux inquiétudes quant à la sécurité nationale, dont : l’interception des communications privées, la carte d’identité nationale/biométrie, la télévision en circuit fermé et la surveillance vidéo du public. Finalement, le rapport souligne les violations possibles du respect de la vie privée que le marché génère et multiplie, y compris : l’identification des fréquences radio, l’exploration des données, et pour conclure, la conscription virtuelle des entreprises canadiennes comme « agents d’état » recueillant et traitant les données « suspectes » des Canadiens.
Le rapport inclut les résultats de sondages nationaux significatifs sur les attitudes des Canadiens concernant la connaissance du respect de la vie privée et des conflits de sécurité nationaux. Le sondage révèle que les Canadiens souhaitent participer aux efforts visant une sécurité nationale plus efficace mais sont incertains des compromis affectant le respect de leur vie privée. Le sondage montre, de manière significative, que la plupart des Canadiens s’attendent à un traitement similaire des droits au respect de leur vie privée, même après les évènements du 11 septembre.
Les coûts affaiblissant les droits du respect à la vie privée aux fins d’une sécurité nationale plus efficace, que ce soit du point de vue financier et de celui de la perte de confiance dans les entreprises et le gouvernement, peuvent être importants et pourraient croître. En guise de conclusion, le rapport appelle à une plus grande responsabilité du gouvernement et des entreprises afin de préserver l’« équilibre » entre les droits de la protection des renseignements privés et les mesures de sécurité.

Letter to Privacy Commissioner of Canada

Letter to Privacy Commissioner of Canada urging Commissioner to name names of respondents in Commissioner Findings PDF [pdf file: 0.12mb]
December 18, 2003
Ms. Jennifer Stoddart
Privacy Commissioner of Canada
Office of the Privacy Commissioner of Canada
112 Kent Street
Ottawa, Ontario K1A 1H3
BY FAX & MAIL
Dear Ms. Stoddart:
Naming Names of Respondents in Commissioner Findings
I am writing to you on behalf of the Public Interest Advocacy Centre. Firstly let us congratulate you on your appointment as Privacy Commissioner of Canada. We look forward to your able stewardship of this most important public office.

Naming of Respondents in Findings

PIAC is calling on you to consider naming the respondents in the findings of the Privacy Commissioner of Canada, effective January 1, 2004. The Office of the Privacy Commissioner of Canada has become an invaluable resource for Canadians seeking to vindicate their privacy rights. In particular, the Commissioner’s findings have convinced many federally-regulated businesses to mend their ways and respect Canadians’ privacy rights as guaranteed in the Personal Information Protection and Electronic Documents Act (PIPEDA).
However, these findings are significantly weakened as an enforcement tool by the anonymization of the organization whose practices have been challenged. Identification of parties is a matter of course in the courts and in administrative tribunals, including those dealing with such sensitive matters as human rights. The reason for this is obvious ­ it keeps the parties honest, and it informs the public. “Justice should not only be done, but manifestly and undoubtedly be seen to be done.” ­ Lord Hewart.

History of the Anonymous Findings Policy

The previous Privacy Commissioner, Mr. Radwanski, continued the practice of the first Commissioner, Mr. Phillips, of anonymizing the parties and offering the public the findings only in summary form. Apparently, there was some concern expressed by the industries likely to be most affected by PIPEDA during its early years (banks, telcos, transport companies), that publication of their names would be unfair and counterproductive to their efforts to comply. PIAC and others have in the past expressed the opposing view to Mr. Radwanski. However, we now feel the forbearance and restraint shown by the previous Commissioners has outlived the rationale of protecting the “early adopters”.

Recent Developments

We note that in a recent speech the B.C. Information and Privacy Commissioner, Mr. Loukidelis, has come out strongly in favour of publishing the names of the participants in any public hearing he holds in B.C. under the new B.C. privacy legislation (which is likely to apply in B.C. in place of PIPEDA). 1
This will also likely occur in Alberta and is also the case when matters come to a hearing in Quebec, as you know. In the interests of consistency of privacy law in Canada, publication of names should not depend where one’s corporation is headquartered.
We understand that the Office of the Privacy Commissioner of Canada, like the B.C. Information and Privacy Commissioner, is intending to adopt a dispute resolution model for the vast majority of complaints. This is to be applauded and will likely greatly aid citizens in providing fast, informal and better resolutions of complaints. It will also help the privacy commissioner in reducing misunderstandings and narrowing the issues for those complaints that do proceed to a formal hearing or investigation. However, we feel the naming of names will complement this approach, not harm it.

Policy and the Finding Process

When the issue truly is a difficult one, with corporate interests lined up against an individual complaint of a privacy violation, a formal investigation process is needed. A final finding will be invaluable to companies seeking to comply with privacy legislation and to citizens wishing to protect their privacy rights. But presently citizens cannot modify their behaviour by shunning a non-compliant organization or, as is more likely, demanding change from the organization ­ they simply don’t know who it is. And the organization has no real incentive to change its practice ­ a recipe for recidivism.
For example, the Interim Commissioner, Mr. Marleau, recently had to chastise “the bank” again for not implementing a previous finding and Commissioner advice on how to handle alternatives to taping telephone conversations with customers. Which bank? Only your office, “the bank” and one “lucky” customer know.
As Mr. Loukidelis notes, “the publication of the name of a non-compliant organization is a necessary and legitimate sanction for non-compliance and an incentive for compliance.” Of course, those organizations that are found to have been compliant with PIPEDA will be able to trumpet this fact. However, we do not see this as a drawback. Instead it will be a market-driver: organizations may sell themselves on their privacy stance ­ and competitors will be able to state they can equal or better it. This is a true “privacy pay-off”.

The Law

There is some statutory reference to the issue in s. 20 of PIPEDA. Unfortunately it is general in nature. However, since the wording is key to your jurisdiction, we hope you will permit us to quote it, and to tolerate our following attempt at statutory interpretation.
Confidentiality

20. (1) Subject to subsections (2) to (5), 13(3) and 19(1), the Commissioner or any person acting on behalf or under the direction of the Commissioner shall not disclose any information that comes to their knowledge as a result of the performance or exercise of any of the Commissioner’s duties or powers under this Part.

Public interest

(2) The Commissioner may make public any information relating to the personal information management practices of an organization if the Commissioner considers that it is in the public interest to do so. [. . .]

At first glance, subs. 20(1) seems to prohibit the Commissioner from publishing anything at all about complaints. However, it must be read in conjunction with the Commissioner’s duty to report the findings under subs. 13(1). Nonetheless, the Commissioner’s past stance regarding non-publication of names could appear to be justified by subs. 20(1) and subs. 13(1).
Note however, that subs. 20(1) is subject to subsection 2, that is, subject to the public interest. Under subs. 20(2) the “Commissioner may make public any information relating to the personal information practices of an organization” if it is in the public interest. It is futile to detail the poor information practices of an organization without naming it. The public, in whose interest this power has been enacted, cannot act unless the personal information practices in question can be linked to the perpetrator. Otherwise subs. 20(2) is a dead letter. Parliament should not be assumed to have created a little black privacy box which spews only good advice of a general “feel good” nature. This is not in the public interest.
We are aware of the reasons of the Supreme Court of Canada in Lavigne v. Canada (Office of the Commissioner of Official Languages), [2002] 2 S.C.R. 773, which considers s. 72 of the Official Languages Act, that has nearly identical wording to subs. 20(1) of PIPEDA. However, a close reading of Lavigne reveals a concern with anonymity for the complainant, not the respondent, in such “ombudsman”-like proceedings. We are, in fact, highly supportive of an asymmetrical naming policy by the Commissioner. For all the reasons given in Lavigne, we feel it is not appropriate to name complainants, who may therefore be victimized a second time by publicity.
Organizations, however, the vast majority of which are major corporations, cannot expect such privacy. These businesses increasingly collect, use and disclose (often for secondary marketing) personal information of real, live human beings. This means these businesses cannot have a reasonable expectation of privacy for their dealings with other people’s personal information. If they will trade in it, they will be accountable for it.
Rather than being a barrier to making the names of respondent public, section 20, on a common-sense reading, appears to be aimed squarely at protecting valuable commercial or other information of respondents. This is indeed the interpretation given in The Canadian Privacy Law Handbook by Murray Long and Suzanne Morin.2
Should you be willing to consider naming respondents, we hasten to point out the Commissioner and staff cannot be held criminally or civilly liable for any statements made in the course of their duties: s. 22 PIPEDA.
We therefore recommend that the Commissioner name respondents in findings as a matter of course.

Other Problems with the Finding Process

There are related problems with the process of issuing Commissioner findings that are exacerbated by the anonymization of organizations. Firstly, the practice of issuing separate findings to the complainant and respondent is quite irregular and leaves an impression that it is possible there could be a double-standard. It also seems contrary to the wording of s. 13, which speaks of “a report” and “the report” not the “reports”. Secondly, the practice of only making public the short summaries of findings means omitting very important details that would greatly benefit those seeking to comply with the Act. It also places the findings at one further remove from reality.
We therefore recommend that the Commissioner issue a single report on each investigation, as contemplated by the legislation. This report should be available to all interested parties, not just the parties to the complaint.
Thirdly, businesses routinely cite “errors” in the Commissioner’s factual findings ­ and then justify the anonymization of parties as a protection against negligent factual investigation. Surely this problem is better resolved by requiring the complainant and respondent to agree to a statement of facts. In this way, factual “errors” can be avoided in the first place.
We therefore recommend that the Commissioner obtain an agreed statement of facts from the parties before making findings on any complaint.
In conclusion, PIAC feels there is an enforcement problem with PIPEDA: due to the ombudsman model adopted for the Privacy Commissioner and the policy of not naming respondents, little incentive exists for organizations to fully respect the Act. Other aspects of the Commissioner’s findings exacerbate this problem. With the increase in jurisdiction of the Privacy Commissioner in January 2004, the time seems right to institute a policy of naming names of respondents as a matter of course and generally increasing the transparency of the findings. In the name of Canadian consumers and citizens, we call upon you to seriously consider such a choice, and we are available to speak to you or meet with you to discuss this matter.
Sincerely,
John Lawford
Research Counsel
1. See “Thoughts on Private Sector Privacy Regulation” (November 24, 2003) at: http://www.oipcbc.org/publications/speeches_presentations/FIPAPIPAspeech112403.pdf.
2. See their comment to subs. 20(1):

“While the scope of what can be released is conceivably quite broad, this subsection [subs. 20(1)] should be read as requiring the Commissioner to maintain the confidentiality of any proprietary business information, business plans, trade secrets, or any other information that is not generally of a public nature and is properly outside the scope of an investigation or audit.” [emphasis added.]

 

Privacy Commissioner Response to PIAC Proposal

Mr. John Lawford
Research Counsel
Public interest Advocacy Centre
1 Nicholas Street, Suite 1204
Ottawa, Ontario
K1N7B7
Dear Mr. Lawford:
I am writing in response to your letter received by fax on December 19, 2003. Thank you for your congratulations on my recent appointment and for raising such an important issue with regard to naming names of respondents.
As I have stated publicly, this office will give serious consideration to the question of in what situation the identities should be made public. It must be part of a structured approach with rational, defendable reasons to support it. As you know, the law states that we “may” make public any information but it does not state that we have to. However, there may be compelling reasons to do so.
You have my assurance that I will, in conjunction with the Assistant Commissioners, study this issue in further detail.
Sincerely,
Jennifer Stoddart
Privacy Commissioner of Canada
 

Revised Letter Findings – Bell Mobility Complaint

Office of the Commissariat
Privacy Commissioner a la protection de
of Canada la vie privee du Canada
112 Kent Street
Ottawa, Ontario
K1A1H3
Tel.:(613) 995-8210
Fax:(613)947-6850
1-800-282-1376
www.privcom.gc.ca
As you may be aware, the Public Interest Advocacy Centre (PIAC) received a letter of finding from this Office, dated October 16, 2002, with regard to the complaint that Phillipa Lawson filed against Bell Mobility (Mobility), under the Personal Information Protection and Electronic Documents Act (the Act). She was complaining, on behalf of the Public Interest Advocacy Centre, about the information practices of Bell Mobility. She alleged that Mobility failed to bring to the attention of its customers its policy of sharing customer data with affiliates for secondary marketing purposes, and the opportunity for customers to opt-out of such disclosure practices. Subsequent to the October 16th letter, our Office received additional information and made further detailed inquiries regarding Mobility’s collection, use and disclosure practices. We have determined that it is appropriate in this instance to issue this revised letter of finding.
Complete Letter Available in PDF [pdf file: 0.63mb]