Save Online law articles on social network:
Showing posts with label information breaches. Show all posts
Showing posts with label information breaches. Show all posts

Collection practices to avoid

A blogger from India has posted an e-mail of complaint that he sent to his cellular phone company, complaining about its collection practices. It appears that they make liberal use your calling records to track you down and to tell your friends and colleagues that you should pay your bill. Not a good practice and it certainly wouldn't fly under PIPEDA. We have the benefit of a similar situation that was considered by George Radwanski last year. In PIPEDA Finding #225, the Commissioner admonished a collection agency for leaving a phone message with a debtor's aunt that disclosed the existence of the debt. They had implied consent to leave a message to have the debtor call them, but disclosing the debt went over the line. Similarly, Radwanski found that a telephone company had improperly used personal information in Finding #61 by using called numbers to track down a delinquent customer. Just don't do it.

Below is an extract of the original blog post, which came to my attention via Engadget and TechDirt:

Manish Jethani - Unethical practices by Hutch collection agents: "[snip]

Last month, one of your collection agents, [agent's name and phone number], called up a friend and prospective client of mine, [my friend's name and phone number], seeking information on my whereabouts and requesting payment of the bill.

The aforementioned unwarranted and unethical act of [agent's name], on behalf of your department, has caused damage to my reputation with my client, potentially costing me business of several thousand rupees. It is absolutely unacceptable for a collection agent to get in touch with a customer's relatives, friends, clients, and any other contacts, regarding the customer's bill payments. Since I am told that this is standard practice at Hutch India, I am out to fight against it.

Here is what I am looking for:

  • Written apology from Hutch India.
  • Assurance from Hutch India that any such unethical practices currently employed by the collection agents will be discontinued with immediate effect.
  • Compensation for damages.

[snip]"

Read more from this post in Online law articles »

Australia begins review of private sector privacy legislation

The Australian Attorney General, Philip Ruddock, has initiated a review of private sector privacy legislation in that country.

Computerworld | Ruddock sets up privacy law review:

"Enterprises handling the personal information of customers are being given a second chance to influence the operation of the federal Privacy Act (1998). Federal Attorney General Philip Ruddock has announced a review of private sector provisions of the law.

According to a statement from Ruddock's office, Federal Privacy Commissioner Karen Curtis has been asked to 'examine the impact of the legislation on the community and the private sector', with the review assessing whether regulation of the private sector has been a success since the introduction of national legislation three years ago.

Specifically, the review will consider whether the laws have achieved a 'comprehensive national scheme for the private sector that regulates how organizations collect, use, store, disclose and transfer individuals' personal information'. "


Interested readers should note that Canada's PIPEDA is subject to mandatory review, which will take place next year.

Read more from this post in Online law articles »

Article: Plan to match Canadian passport photos with terrorist watch lists in works

The Canadian Department of Public Security has been involved in a trial of facial recognition software that, they hope, will be used to match passport photos against the mugshots of known and suspected terrorists. I'll be curious to see the results of the privacy impact assessment, if it is released:

Plan to match Canadian passport photos with terrorist watch lists in works:

"OTTAWA (CP) - Federal officials plan to screen the photos of Canadian passport applicants against images of suspects on terrorist watch lists.

The Passport Office recently tested a computer program that compares a picture of a face with thousands of other mugshot-style photos and zeroes in on possible matches.

The office is seeking approval from the federal privacy commissioner to use the facial-recognition technology in processing passport applications.

The proposal has raised questions about the accuracy and potential intrusiveness of the system among those who study the effect of security measures on privacy and civil liberties. "



I did some looking around the Public Safety and Emergency Preparedness Canada website and didn't find the report referred to in the article. If any readers know where to find it, please drop me a line.

Read more from this post in Online law articles »

Re: F-bomb-dropping attorney gets worldwide notoriety

I was thinking a bit more recently about the story that was the basis for my previous post ("F-bomb-dropping attorney gets worldwide notoriety"). There is a second privacy aspect ... Thanks to the internet, the Chicago lawyer who left the message in question is probably going to be living with the incident for a very long time. It is now routine to google job applicants, contacts and just people you know. If he finds himself looking for a job or going on a blind date, googling his name will bring back this story as if it only happened today. I've heard it said that you should never write anything in an e-mail that you wouldn't wanted reported on the front page of the New York Times. This is a reminder that you shouldn't write an e-mail or leave a voice-mail that you wouldn't want on the front pages, either. The internet takes it to the next level, since it is all a quick click away.

Read more from this post in Online law articles »

F-bomb-dropping attorney gets worldwide notoriety

Most of this article and the buzz surrounding this incident (see below) is about lawyer civility and its supposed decline since the "good old days". It also serves as a reminder that many voicemail systems make messages very portable. Some systems send messages as e-mails with a .wav attachment. A breeze to forward far and wide. Not only should you be careful about what you leave on someone's message machine (see the Federal Privacy Commissioner's finding against a bank on this subject: PIPED Act Case Summary #270: Bank agrees to modify automated message), but you should remember that they can be easily saved and fowarded to goodness only knows where.

F-bomb-dropping attorney gets worldwide notoriety

August 25, 2004

BY ERIC HERMAN - Business Reporter

So much for professional courtesy.

A Chicago lawyer's expletive-filled phone message circulating on the Internet is providing fresh evidence to those who say lawyers' standards of behavior are eroding. ..."



The voice mail message (along with some commentary) is posted on on KinsellaLaw, for the curious.

Thanks to Bag and Baggage for leading me to this...

Read more from this post in Online law articles »

Article: Credit-card processors gear up for new privacy law

I find it amazing that when I closely examine the detritus of daily life (by emptying my pockets at the end of the day), I discover that so many merchants still print all the digits of the card number on credit and debit card receipts. Why? Why? Why? There is simply no need to have that info there and by it threatens the privacy of the cardholders.

The problem is usually compounded by a pretty cavalier attitude toward these flimsy pieces of paper. How many times have I picked up someone's reciept from the check-out at the grocery store, only to find a full credit card number, complete with expiry date? Or a full debit card number? When I mention it to the clerk, they just chuck it in the garbage. If you want to commit fraud, I can tell you the dumpsters to dive in.

PIPEDA, thanks to its broad statement that you must secure personal information against accidental disclosure, etc., probably requires obscuring at least part of the number. But not enough retailers have read it. At least the US is taking this seriously. The Fair and Accurate Credit Transactions Act requires card "truncation" by January 1 and some state laws have mandated it for some time:

Credit-card processors gear up for new privacy law:

"By Marion Davis, Staff Writer



A federal law requires merchants to truncate personal information on credit card receipts by Jan. 1. Does your business take credit cards? If so, when the slip prints out, how much of the customer's card number is included? If it's more than the last five digits, and/or if the expiration date shows, you need to upgrade your terminal by Jan. 1.

A federal law passed last December, the Fair and Accurate Credit Transactions Act, requires credit-card "truncation" by that date, and a new state law makes merchants liable, starting in 2007, for any resulting fraud, plus legal fees, if they don't comply.

Some states, starting with California, have been gradually implementing truncation mandates for new terminals since 2001, but it was only last January that the first laws affecting existing machines kicked in. Some are tougher than Rhode Islandos: In Maine, anyone who didn't switch by last Jan. 1 is already subject to a $1,000 penalty; in Arizona, as of June 1, merchants who don't truncate can be fined $10,000. "



I gather that Visa/Mastercard have made this mandatory for their Canadian retailers by 2005.

Read more from this post in Online law articles »

Article: Blawgs may be worth a try

I just discovered an article about Canadian lawyers' blogs from Canada Law Book. It mentions this blog, but I didn't know about it when it came out in June. And I'm not too offended that the author didn't get my name right.

Blawgs may be worth a try

...

"The marketing advantage of blawgs are that they put your name out there," says Girard. "If a blawg is reasonably well read, it will move up pretty quickly in the Google rankings."

Aficionados estimate that there are currently about 500 law-related blogs online in the United States, which indicates the trend is still in its infancy. Interested readers can search them out by going to www.blawg.org

In Canada, an initial Law Times search turned up only Girard's site (www.e-Lawg.com). Later searches found a few more: one for a lawyer in Nova Scotia on elder law (www.nselderlaw.ca), one on privacy law from David T.S. Cooper FRASER at McInnes Cooper in Atlantic Canada (pipeda.blogspot.com), Martin G. Ertl in B.C. has two, www.opinionated.ca and another called Boiler-plate (contract.matinertl.ca), which is "dedicated to elegant drafting in contracts."

Michael Crawford, a marketing and communications consultant with marketingdept.biz in Toronto, thinks he knows why there are so few in Canada.



Read the full article here.

Read more from this post in Online law articles »

Article: Watch those attachments!

Another helpful reminder from a (hopefully remorseful and sheepish) organizer of the Rupublican convention that you need to double-check your attachments before clicking send.

E-mail to volunteers gets a bit personal

BY DEBORAH S. MORRIS

STAFF WRITER

August 26, 2004

Oops! A welcome e-mail that was sent to hundreds of volunteers for the Republican National Convention inadvertently included the name, address, Social Security number, race and other personal information of those volunteers.

The e-mail, with a subject header of "Transportation Volunteer Information - Final Email Before Your Arrival to NYC," was sent out yesterday across the country and apparently was to serve as a checklist for transportation volunteers' arrival on Saturday.

At the end of the e-mail, two attachments, which when opened, display private information such as volunteers' home, work and mobile phone numbers as well as their birthdates, rooming information and other personal information. The information, if it landed in the wrong hands, would be a security concern.

"The attachment was inadvertent," Leonardo Alcivar, spokesman for the Republican National Convention, said yesterday. "As a precaution, security [personnel] has been alerted and will take any additional steps necessary to protect the integrity of anyone listed."

...



Thanks to PrivacySpot for the pointer.

Read more from this post in Online law articles »

READ THIS! Privacy chief to e-commerce firms: Don't blame PIPEDA

I highly recommend reading this article from ITBusiness.ca. It quotes from both Jennifer Stoddart (Federal Privacy Commissioner) and Anne Cavoukian (Ontario Commissioner) emphasising how important it is to gain and maintain customer trust. So, get your privacy act together.

Privacy chief to e-commerce firms: Don't blame PIPEDA

8/25/2004 5:00:00 PM - Jennifer Stoddart defends the federal legislation and warns software vendors about potential damage to their corporate reputations. Plus: Why can't security and privacy assessors get along?

...

Stoddart made an aggressive pitch, referring to a 2002 Leger Marketing survey that found issues with security and privacy continue to be the biggest barrier to Canadians making online purchases.

"These fears are fuelled by an identity theft problem galloping out of control, which is estimated to result in losses of $2 trillion worldwide by the end of 2005," she said.

Stoddart cautioned that while a company may see a business opportunity in data mining, "their next door neighbour might see it as an unacceptable invasion of privacy".

Yet, if a business conforms with PIPEDA’s "informed consent" and "document storage" provisions on the treatment of personal electronic information, that business stands to recoup the loyalty of would-be customers, she said.

"This will help you grow your business by improving trust."

Ann Cavoukian, information and privacy commissioner of Ontario and one of Stoddart’s co-presenters, pointed to a Harris/Westin poll conducted in 2001 and 2002 which supported her federal counterpart’s argument.

Over 90 per cent of the poll’s respondents said the volume and frequency of business they conduct with a company is directly related to the level of confidence they have in that company’s privacy practices. The same poll found that 83 per cent of respondents would stop doing business with a company if they felt that their personal information was misused. ...


Read more from this post in Online law articles »

Article: California Legislature OKs offshore privacy bill

California's legislature has passed a bill regulating privacy aspects of the offshoring of personal information processing. It has landed on the Governator's desk for signature or veto. We'll keep you posted ...

Legislature OKs offshore privacy bill

MEASURE PROTECTS CONFIDENTIAL CONSUMER DATA SENT OVERSEAS

By Karl Schoenberger

Mercury News

A bill that would protect the privacy of personal medical and financial information when it is processed overseas in an offshoring contract was approved by the Legislature and has been sent to the governor's desk, the author of the legislation announced Tuesday.

State Sen. Liz Figueroa, D-Fremont, said her bill -- SB 1451 -- provides that a stringent existing California law protecting consumer privacy in the state would apply to anyone who has access to such confidential information no matter where they are located. ...



Read more from this post in Online law articles »

Document meta-data FAQ and risk information

That Word (or other document) you send may give away your confidential information and even leak personal information outside of your company. Many are aware that "metadata" is commonly embedded in certain document formats. (I recently received a document from a client that was riddled with metadata, including tracked changes that showed changes made by the other side's lawyer and "notes to draft" about certain clauses. It came from one of the leading firms in Canada, acting for a VERY large company that, ironically, is a major player in the data security area. But I digress ...) In any event, this has become a significant security risk. Workshare (maker of DeltaView and, coincidentally, a metadata remover called Workshare Protect) has established a "public benefit" site to provide information about content security risks. It's called MetadataRisk and is at http://www.metadatarisk.org. To give Workshare credit, there is no marketing material on the site and it has some good content. Thanks to PrivacySpot for leading me there ...
Read more from this post in Online law articles »

Article: NWT privacy commissioner appalled by some cases

The CBC has an interesting story, reporting on the annual report of the privacy commissioner of the Northwest Territories. The incident highlighted in the article shows the challenges of not building a privacy culture within an organization:

NWT privacy commissioner appalled by some cases

...Keenan-Bengts says senior officials were more concerned about the impact the complaint could have on their reputation, than they were about the woman's privacy.

"I was just appalled, I was just absolutely appalled by the circumstances and I think it's important that these very bad situations be brought to the fore so that they don't happen again."



It is interesting to note that Privacy Commissioners in Ontario and NWT have recently gotten appalled and are not being shy about saying so.

As an aside, I'm trying to track down a copy of the Commissioner's report. I'll post any interesting or instructive nuggets.

Read more from this post in Online law articles »

Canadian Bankers push for ID theft law

A number of privacy stories are coming out of the meeting of Chiefs of Police this week. Among them is a presentation by the Canadian Bankers Association, calling for stronger criminal laws specifically dealing with ID theft. See the following article from the Globe & Mail, a portion of which is quoted below:


Stronger ID Theft Laws Needed, CBA Says

VANCOUVER — The Canadian Bankers Association will advocate for new identity theft legislation at this week's national police chiefs' convention in Vancouver.

On Wednesday, the banking association's security director will address the Canadian Association of Chiefs of Police about the need to reform the Criminal Code to curtail identity theft.

"It's part of our ongoing effort with law enforcement," said Caroline Hubberstey, banking association spokeswoman.

Among other changes, the banking association wants to see identity theft clearly defined in the Criminal Code. They also want to make it an offence to possess multiple pieces of other people's identification, Ms. Hubberstey said.

At present, about 30 Criminal Code offences and one under the National Defence Act address identity theft, she said.



Read more from this post in Online law articles »

Can't use PIPEDA to avoid relevant questions in litigation

I think any privacy lawyer would have predicted the result of this Ontario court decision about whether you can use PIPEDA as a shield against answering questions in the course of litigation, but it is good to have authority on the point. The full text of the decision is available on CanLII at http://www.canlii.org/on/cas/onsc/2004/2004onsc11636.html. Below is an excerpt of the relevant portions of the decision.


FILE NO.: 03-CV-251465-CM1



DATE: 20040706



SUPERIOR COURT OF JUSTICE - ONTARIO



RE:

Clustercraft Jewellery Manufacturing Co. Ltd.
- Appellant




- and -



Wygee Holdings, Ltd. Artam Diamonds International



Inc., and Enterprising Promotions Ltd.
-
Respondents



BEFORE:

T. Ducharme, J.



COUNSEL:

D.R. Rothwell




For the Appellant





R. Shour




For the Respondents



MOTION



HEARD:

July 2, 2004



E N D O R S E M E N T



[1] The
Plaintiff/Appellant ["Appellant"] appeals from an interlocutory order
made on April 20, 2004 by Case Management Master Carol Albert which:



(a) granted leave to amend the Statement of Defence
and Counterclaim;



(b) gave directions for further examinations for discovery;



(c) ordered answers to three questions which had been refused
during the discovery of Einhardt Wiedel; and



(d) awarded and fixed costs payable by the plaintiff of
$2,100.



The Appellant asks that this order be set aside and an order
be made instead in terms as set out in paragraph 2 of their factum.



[2] The Parties
are agreed that the appropriate standard of review is that set out in Bank of Nova Scotia v. Liberty Mutual Insurance Co., [2003], O.J. No. 4474 (Div. Ct.):



(a) if the matter is one of discretion, the court should
not interfere unless the Master was clearly wrong;



(b) if the matter is one of law that is not vital to the
disposition of the lawsuit, the court should not interfere unless the Master
was clearly wrong; and



(c) if the matter is one of law that is deemed vital to
the disposition of the lawsuit, the test should be one of correctness.



Moreover, where the Master is
dealing with interlocutory matters not vital to the disposition of the case,
the motion ought to be heard as an appeal and not de novo.



The Granting of Leave to Amend the
Statement of Defence and Counterclaim



[3] Master Albert
granted leave to amend the Statement of Defence and Counterclaim. The Appellant
concedes that many of these amendments were in the nature of housekeeping
amendments, but objects to the addition of the name of one Alan Grelowski to
paragraphs 53 and 58 of the Statement of Defence and to paragraph 137(i) of the
Counterclaim. The Appellant advances two arguments: (1) There was not a
sufficient factual basis in the motion record before the Master to permit this
amendment; and (2) The amendments caused prejudice to the Appellant insofar as
they result in a re-attendance for further examination for discovery.



[4] The granting
of the amendments to the pleadings is governed by Rule 26.01 which provides
that the court shall grant leave to amend a pleading unless prejudice
would result that could not be compensated for by costs or an adjournment. As Moldaver
J.A. noted in Andersen Consulting Ltd. v. Canada (Attorney
General)
, [2001] O.J. No. 3576 at paragraph
37 (Ont.
C.A.)
there is a:



well-established rule that amendments like those sought in
the present case should be presumptively approved unless they would occasion
prejudice that cannot be compensated by costs or an adjournment; they are shown
to be scandalous, frivolous, vexatious or an abuse of the court's process; or
they disclose no reasonable cause of action.



It is worth noting that Moldaver, J.A. made no mention of
some minimal factual support in the record as being a further prerequisite to
the granting of leave to amend the pleadings. Indeed, the balance of Andersen Consulting Ltd. suggests
precisely the opposite, as the motions judge was criticized at paragraph 35 for

"weighing evidence, interpreting controversial contractual provisions and
making findings of fact, all matters that should have been avoided at the
pleading stage." Counsel for the Appellant was unable to cite
any authority for the proposition that amendments to pleadings can only be
granted where there is a sufficient factual basis for them outlined in the motion
record. In my view, this argument must be rejected as it is clearly
inconsistent with the presumptive approval test mandated by Rule 26.
It should also be noted that the reasons for these amendments were
explained in the Case Management Motion Form filed before the Master. While the
Appellant may dispute the factual basis for these assertions that is a matter
for trial.



[5] The argument
that the amendments resulted in prejudice that cannot be compensated for
"by costs or an adjournment" can be dispensed with quickly. As Master
Albert noted there was no evidence that any prejudice would result from the six
month delay. Moreover, the prejudice identified on appeal that is, the need to
re-attend for further examinations for discovery, is precisely the type of
prejudice that can be dealt with by way of costs and/or an adjournment. Thus,
it cannot be maintained that the amendments should have been refused on this
basis.[1]
In oral argument, the Appellant conceded that this prejudice could be remedied
by costs and asked that this Court make an order in this regard. However, as
the Appellant sought no such relief in argument before the Master, it would not
be appropriate to order costs when the matter was not raised at the first
instance.



[6] As a result,
the order permitting the Respondent to amend the Statement of Defence and
Counterclaim is upheld.



The Order to Answer Questions Which Had
Been Refused



[7] Master Albert ordered
that questions 659, 698 and 956 which had been refused upon the examination of Einhard
Wiedel should be answered. Both parties agree that the numbers of the first two
questions was misidentified and that the questions to be answered were 879, 899
and 956. The Appellant does not rely on this error and the parties are agreed
that these questions related to the provision of names and addresses of
employees, the length of service of employees and the names addresses and
telephone numbers of former employees since 1999. Here again the Appellant
argues that there was an insufficient factual basis in the record before the
Master to support this order. The Appellant also argues that these refusals
should have been sustained as the questions were irrelevant and because the
disclosure of such information was prohibited by the
Personal Information
Protection and Electronic Documents Act
( 2000, ch. 5).



[8] The
pleadings in any civil action form the terms of reference for discovery and
relevance at discovery is broader than at trial. There is no requirement that
the proposed questions be factually supported by the motion record and, once
again, counsel for the Appellant was unable to cite any authority for that
proposition.
The applicable standard here is the
"semblance of relevance" test articulated by Steele, J. in Kay v. Posluns
(1989), 71 O.R. (2d) 238 (H.C.).
As Master Albert found, the information relating to
employees and former employees of the Appellant is relevant to paragraphs 99 to
106 of the Statement of Defence and paragraph 27 of the Reply and Defence to
Counterclaim. These employees may have information relating to the 308.73
carats of diamonds that the Appellant alleges were never delivered to them. As
such these questions are relevant and, with respect to questions 879 and 956,
expressly authorized by Rule 31.06(2). This order was a discretionary one and,
applying the proper standard of review, it cannot be said that Master Albert
was clearly wrong.



[9] As for
the Appellant's submission that the disclosure of this information would be
prohibited by the
Personal Information Protection and Electronic Documents Act( 2000, ch. 5) this ignores the express provision of
section 7(3)(c) of that Act which provides, in relevant part:



(3) . . . an organization may
disclose personal information without the knowledge or consent of the
individual only if the disclosure is



(c) required to comply with a subpoena or
warrant issued or an order made by
a court, person or body with
jurisdiction to compel the production of information, or to comply with rules
of court relating to the production of records.



At a minimum, the order of Master
Albert is an order made by a court with jurisdiction to compel the production
of information. Thus, this submission of the Appellant also fails.



[10] As a result, the Master's order is
upheld and the Respondent is ordered to answer questions
879, 899 and 956.



The Order to Re-attend for Further
Examinations for Discovery



[11]
At the outset, the parties are agreed that the
Master should not have ordered re-attendance as a result of the amendments to
the pleadings as the Respondent made no such request before her. They are
agreed that, if the order to re-attend is sustained, it should be in relation
only to undertakings and refusals subsequently answered. I agree.



[12]
Here again the Appellant argues that there was
an insufficient factual basis in the record before the Master to support this
order. In this regard, the Appellant relies on the decision of Master Beaudoin
in Central Guaranty Trust Co. v. Beebe Estate, [1997] O.J. No. 4882
where he states at paragraph 7:



Rule 31.06 certainly contemplates
only one oral examination for discovery. As to whether or not
there is a right to further discovery, once again I am presented with
conflicting authorities by counsel. The plaintiff relies on I.C.S.
Construction Ltd. v. GKN Birelco Ltd
., [1991] O.J. No. 597, (March 13,
1991), Doc. CLA 162/87 Forestell J. (Ont. Gen. Div.) whereas the defendants
rely on Christie Corporation v. Alvarez (1994) 34 C.P.C. (3d) 92, a decision of Mr. Justice McNeely which
distinguishes the J.C.S. Construction case. Upon reading
these decisions, I am satisfied that there is no automatic right by one party
to compel the re-attendance of another merely because the other party has
complied with an undertaking or provided an answer after a discovery.

I believe the decision of McNeely J. gives some guidance in this
regard in that he suggests the moving party must demonstrate why reattendance
would serve a useful purpose. In this instance, I believe it would
be helpful for the court to have, by way of affidavit, an indication of what
areas need to be explored through further oral examination on discovery.

It is not sufficient to accept, as submitted by plaintiffs
counsel, that the opposing party can object if counsel, on re-examination
strays into areas previously responded to or into areas upon which he may not
be entitled to re-examine.



[13]
I accept
that there is no automatic right by one party to
compel the re-attendance of another merely because the other party has complied
with an undertaking or provided an answer after a discovery. However, I reject
the suggestion that in
Central Guaranty Trust Co. v. Beebe Estate Master Beaudoin was
propounding a general requirement that affidavit evidence is required before an
order for re-attendance will be made. Indeed, Master Beaudoin expressly limited
the scope of his suggestion when he said affidavit evidence would be helpful
"In this instance". None of the other cases cited by the Appellant
support such a general rule and counsel for the Appellant was unable to cite
any cases where Central Guaranty Trust Co. v. Beebe Estate was
interpreted to this effect. Indeed, the proper approach to the ordering of
re-attendance was clearly identified by McNeely, J. in
Christie Corporation v.
Alvarez
where he said at paragraph 4, "no general rules are possible
and each case must be considered on its merits." In this case, after the
completion of discoveries, the Appellant provided answers to ninety nine
undertakings and twenty refusals. The decision to order re-attendance
was a discretionary one
and, applying the proper standard of review, it cannot be said that Master Albert
was clearly wrong.



[14]
As
a result, the Master's order is upheld and t
he Appellant is ordered to re-attend for discovery arising from the
answers to the undertakings and refusals.




Read more from this post in Online law articles »

Article: Patients are denied the last rites under data protection law

I've heard of this happening in Canada, but it has not been widely reported on. The Telegraph has a very good article on the issues related to not providing patient religious affiliation info to hospital chaplains because of privacy concerns.

Patients are denied the last rites under data protection law

By Elizabeth Day

(Filed: 25/07/2004)

Thousands of terminally ill patients are being denied access to spiritual guidance from hospital chaplains because the Data Protection Act is being applied over-zealously.

The Hospital Chaplaincies Council has criticised several NHS Trusts for their "hysterical" refusal to disclose the religious backgrounds of their patients. The trusts claim that such information is "too sensitive" to share with chaplains.

Now many of Britain's 3,425 hospital chaplains are unable to offer spiritual succour - or perform the last rites in the case of Roman Catholics - unless patients ask to see a chaplain on admission to hospital. Chaplains are concerned that many patients going for routine check-ups will not give their consent and then be unable to change their mind should their medical condition deteriorate.


Read the rest of the extensive article here ...

From what I've heard informally, it'll be a lot worse for chaplains in Ontario once Bill 31 is implemented in November.

Read more from this post in Online law articles »

Article: Customer's data protection fears hinder Lloyds TSB's offshoring plans

It is not only in British Columbia where unions are using privacy legislation to prevent offshoring of data processing jobs:

Lloyds TSB in data protection battle over offshore outsourcing

18 August 2004 - UK bank Lloyds TSB has been threatened with legal action by its staff union over the transfer of call centre jobs to outsourced processing centres in India on grounds that the move breaches the Data Protection Act.

An unnamed customer is mounting the legal challenge, backed by The Lloyds TSB Union (LTU).

The union claims the bank is breaching the Data Protection Act by transferring customer financial data to overseas centres without their consent. LTU says according to European law, personal data can only be transferred outside the European Economic Area with the written consent of customers.

The government-appointed Information Commissioner is expected to decide on the union's case in the next few weeks.

Lloyds TSB announced in October last year that it was closing its customer contact centre in Newcastle, leading to the loss of 986 UK jobs, and would transfer the work to its operations in India. Additionally, in April this year, the bank's Scottish Widows division opened a new office in Bangalore India to pilot the offshoring of back office functions.

The union has been actively campaigning against the offshoring of jobs and says if the challenge is successful, it would have wider implications for the whole of the financial services industry.

Earlier this year British members of the European Parliament called for new data protection laws to prevent unauthorised access to customer data by offshore workers. The MEPs, backed by British trade union Amicus tabled plans for European regulations to prevent unauthorised access of personal details being processed abroad.



See also this article from Personneltoday.com:

Customer's data protection fears hinder Lloyds TSB's offshoring plans

Lloyds TSB's plans to transfer work to India are being challenged by one of the bank's customers on the grounds that they infringe legal requirements concerning data protection.

The case against Lloyds TSB is that India does not have the same stringent standards of data protection that are legally required by the Data Protection Act 1998.

European legislation requires that sensitive personal data can only be transferred outside of the European Economic Area with the express consent of customers.

India is not included on the European Union's list of countries that offer adequate levels of protection for personal data.

The government-appointed Information Commissioner is being asked to rule on whether Lloyds TSB is acting legally when transferring sensitive personal data abroad.

Steve Tatlow, assistant general secretary at Lloyds TSB Group Union, said: "This is an important case. If successful, it could force Lloyds TSB to drop its offshoring policy for fear of losing many customers.

"Concerns over data protection are yet another reason why Lloyds TSB should now listen to its customers and commit itself to the UK."



Read more from this post in Online law articles »

Incident: Highly Personal Information Found In Trash

These kinds of stories appear in the media all the time, but this one is particularly bad. The information chucked in the trash was from a collection/credit agency.

Highly Personal Information Found In Trash

10 Investigates has recovered personal information found behind a Columbus collection agency. It's confidential information on people from Ohio and across the country. Could it be personal information about you?

Read more from this post in Online law articles »

Top of a privacy lawyer's wish list

One of the things that you can get almost all privacy lawyers to agree on is that the current system of summarized findings does not provide the detail that lawyers are comfortable with basing their opinions on. At present, the Privacy Commissioner releases very brief summaries of findings that have been made in response to complaints under PIPEDA. (See the Commissioner's findings here.) They do not name the complainant and they do not name the organization complained about. But, more importantly, they are cleansed of any details that would tend to identify any of the parties, so that the resulting summary is relatively vague on details and also vague on analysis.

Some time ago, the Public Interest Advocacy Centre in Ottawa complained to the Commissioner about a number of large corporations. PIAC published all the complaints and related correspondence on their website (see PIAC's Privacy Page here). The "findings" of the Commissioner, nicely scanned are published and provide a great wealth of information about how the Commissioner approaches these complaints and also shows the significant degree of "back and forth" among the parties during the investigation process.

For individuals and corporations who are trying to figure out the details of compliance and their rights, the present findings do not provide a strong foundation for understanding. For lawyers advising clients on matters related to PIPEDA, the lack of detail may often result in vague advice or educated guesses by counsel. Even though the Commissioner is not bound by previous decisions, readers do rely upon the findings to determine how the Commissioner is likely to respond to a particular set of facts in the future.

PIPEDA is coming up for review in 2006 and it is expected that the deficiencies of the findings will be the subject of some debate. Most privacy lawyers are hoping that this will be considered in greater detail.

I also note that a number of prominent members of the Canadian privacy community have called for the Commissioner to "name names" in her findings. (See Michael Geist's "Name names, or privacy law toothless" and PIAC's letter to Commissioner Jennifer Stoddart.) This approach is favoured by some so that fully-informed consumers can vote with their feet and companies are appropriately shamed into compliance. I'm not 100% sure if I agree with this, but publicly naming companies would likely help in getting recalcitrant companies to take privacy more seriously.

Read more from this post in Online law articles »

Article: Credit companies cool toward 'freeze'

The ability to freeze one's credit report is touted in a number of articles as the solution to ID theft. Is short, a consumer can lock his or her credit report so that it can only be released by a PIN given directly by the consumer. If credit grantor can't successfully get a credit report at the behest of an ID thief, no credit can be granted and no ID theft.

I have no idea if this is available in Canada, but you may be able to argue that PIPEDA would provide for this if you told all the consumer credit agencies that they do not have your permission to disclose your personal information except with your explicit consent, confirmed via a PIN or other tool. Most consumers have, via credit card agreements and others, given carte blanche to access credit reports, so you may not be able to revoke this.

Credit companies cool towards 'freeze'

By BRIAN BERGSTEIN

Associated Press

NEW YORK — Little by little, a weapon against identity theft is gaining currency — but few people know about it. It's called the security freeze, and it lets individuals block access to their credit reports until they personally unlock the files by contacting the credit bureaus and providing a PIN code.



Credit agencies were required to allow freezes, at least in California, thanks to a new state law. For more info, you can also check out http://www.fightidentitytheft.com/legislation_california_sb168.html

Read more from this post in Online law articles »

Privacy Presentations from the CBA Annual CLE Extravaganza

As promised a short while ago, I've posted the presentations from the CBA Annual CLE session on cross-border privacy issues. Many thanks to Simon Chester for compiling our three powerpoints into one coherent (and hefty) acrobat file.

Cross-Border Issues for Privacy Law Compliance in Canada, the US & the EU

Presented by the National Privacy Law Section and the National Business Law Section
This panel will focus on issues facing multi-national organizations that seek
to align their privacy law compliance procedures across jurisdictions. The
panel will examine the approaches taken by multi-nationals in complying
with the new Canadian laws, as well as requirements for Canadian
companies doing business in the US and the EU.

Moderator: David M.W.Young, Partner, Lang Michener LLP (Toronto)

Speakers: Simon Chester, Partner, McMillan Binch LLP (Toronto)

Evelyn L. Sullen, Staff Counsel, Volkswagen of America Inc. (Auburn Hills, MI)

David T.S. Fraser, Associate, McInnes Cooper (Halifax)

Read more from this post in Online law articles »
Info recommended by: Webpages of law and Law articles

© Online law articles: information breaches