Save Online law articles on social network:
Showing posts with label ontario. Show all posts
Showing posts with label ontario. Show all posts

READ THIS! Privacy chief to e-commerce firms: Don't blame PIPEDA

I highly recommend reading this article from ITBusiness.ca. It quotes from both Jennifer Stoddart (Federal Privacy Commissioner) and Anne Cavoukian (Ontario Commissioner) emphasising how important it is to gain and maintain customer trust. So, get your privacy act together.

Privacy chief to e-commerce firms: Don't blame PIPEDA

8/25/2004 5:00:00 PM - Jennifer Stoddart defends the federal legislation and warns software vendors about potential damage to their corporate reputations. Plus: Why can't security and privacy assessors get along?

...

Stoddart made an aggressive pitch, referring to a 2002 Leger Marketing survey that found issues with security and privacy continue to be the biggest barrier to Canadians making online purchases.

"These fears are fuelled by an identity theft problem galloping out of control, which is estimated to result in losses of $2 trillion worldwide by the end of 2005," she said.

Stoddart cautioned that while a company may see a business opportunity in data mining, "their next door neighbour might see it as an unacceptable invasion of privacy".

Yet, if a business conforms with PIPEDA’s "informed consent" and "document storage" provisions on the treatment of personal electronic information, that business stands to recoup the loyalty of would-be customers, she said.

"This will help you grow your business by improving trust."

Ann Cavoukian, information and privacy commissioner of Ontario and one of Stoddart’s co-presenters, pointed to a Harris/Westin poll conducted in 2001 and 2002 which supported her federal counterpart’s argument.

Over 90 per cent of the poll’s respondents said the volume and frequency of business they conduct with a company is directly related to the level of confidence they have in that company’s privacy practices. The same poll found that 83 per cent of respondents would stop doing business with a company if they felt that their personal information was misused. ...


Read more from this post in Online law articles »

Article: NWT privacy commissioner appalled by some cases

The CBC has an interesting story, reporting on the annual report of the privacy commissioner of the Northwest Territories. The incident highlighted in the article shows the challenges of not building a privacy culture within an organization:

NWT privacy commissioner appalled by some cases

...Keenan-Bengts says senior officials were more concerned about the impact the complaint could have on their reputation, than they were about the woman's privacy.

"I was just appalled, I was just absolutely appalled by the circumstances and I think it's important that these very bad situations be brought to the fore so that they don't happen again."



It is interesting to note that Privacy Commissioners in Ontario and NWT have recently gotten appalled and are not being shy about saying so.

As an aside, I'm trying to track down a copy of the Commissioner's report. I'll post any interesting or instructive nuggets.

Read more from this post in Online law articles »

Can't use PIPEDA to avoid relevant questions in litigation

I think any privacy lawyer would have predicted the result of this Ontario court decision about whether you can use PIPEDA as a shield against answering questions in the course of litigation, but it is good to have authority on the point. The full text of the decision is available on CanLII at http://www.canlii.org/on/cas/onsc/2004/2004onsc11636.html. Below is an excerpt of the relevant portions of the decision.


FILE NO.: 03-CV-251465-CM1



DATE: 20040706



SUPERIOR COURT OF JUSTICE - ONTARIO



RE:

Clustercraft Jewellery Manufacturing Co. Ltd.
- Appellant




- and -



Wygee Holdings, Ltd. Artam Diamonds International



Inc., and Enterprising Promotions Ltd.
-
Respondents



BEFORE:

T. Ducharme, J.



COUNSEL:

D.R. Rothwell




For the Appellant





R. Shour




For the Respondents



MOTION



HEARD:

July 2, 2004



E N D O R S E M E N T



[1] The
Plaintiff/Appellant ["Appellant"] appeals from an interlocutory order
made on April 20, 2004 by Case Management Master Carol Albert which:



(a) granted leave to amend the Statement of Defence
and Counterclaim;



(b) gave directions for further examinations for discovery;



(c) ordered answers to three questions which had been refused
during the discovery of Einhardt Wiedel; and



(d) awarded and fixed costs payable by the plaintiff of
$2,100.



The Appellant asks that this order be set aside and an order
be made instead in terms as set out in paragraph 2 of their factum.



[2] The Parties
are agreed that the appropriate standard of review is that set out in Bank of Nova Scotia v. Liberty Mutual Insurance Co., [2003], O.J. No. 4474 (Div. Ct.):



(a) if the matter is one of discretion, the court should
not interfere unless the Master was clearly wrong;



(b) if the matter is one of law that is not vital to the
disposition of the lawsuit, the court should not interfere unless the Master
was clearly wrong; and



(c) if the matter is one of law that is deemed vital to
the disposition of the lawsuit, the test should be one of correctness.



Moreover, where the Master is
dealing with interlocutory matters not vital to the disposition of the case,
the motion ought to be heard as an appeal and not de novo.



The Granting of Leave to Amend the
Statement of Defence and Counterclaim



[3] Master Albert
granted leave to amend the Statement of Defence and Counterclaim. The Appellant
concedes that many of these amendments were in the nature of housekeeping
amendments, but objects to the addition of the name of one Alan Grelowski to
paragraphs 53 and 58 of the Statement of Defence and to paragraph 137(i) of the
Counterclaim. The Appellant advances two arguments: (1) There was not a
sufficient factual basis in the motion record before the Master to permit this
amendment; and (2) The amendments caused prejudice to the Appellant insofar as
they result in a re-attendance for further examination for discovery.



[4] The granting
of the amendments to the pleadings is governed by Rule 26.01 which provides
that the court shall grant leave to amend a pleading unless prejudice
would result that could not be compensated for by costs or an adjournment. As Moldaver
J.A. noted in Andersen Consulting Ltd. v. Canada (Attorney
General)
, [2001] O.J. No. 3576 at paragraph
37 (Ont.
C.A.)
there is a:



well-established rule that amendments like those sought in
the present case should be presumptively approved unless they would occasion
prejudice that cannot be compensated by costs or an adjournment; they are shown
to be scandalous, frivolous, vexatious or an abuse of the court's process; or
they disclose no reasonable cause of action.



It is worth noting that Moldaver, J.A. made no mention of
some minimal factual support in the record as being a further prerequisite to
the granting of leave to amend the pleadings. Indeed, the balance of Andersen Consulting Ltd. suggests
precisely the opposite, as the motions judge was criticized at paragraph 35 for

"weighing evidence, interpreting controversial contractual provisions and
making findings of fact, all matters that should have been avoided at the
pleading stage." Counsel for the Appellant was unable to cite
any authority for the proposition that amendments to pleadings can only be
granted where there is a sufficient factual basis for them outlined in the motion
record. In my view, this argument must be rejected as it is clearly
inconsistent with the presumptive approval test mandated by Rule 26.
It should also be noted that the reasons for these amendments were
explained in the Case Management Motion Form filed before the Master. While the
Appellant may dispute the factual basis for these assertions that is a matter
for trial.



[5] The argument
that the amendments resulted in prejudice that cannot be compensated for
"by costs or an adjournment" can be dispensed with quickly. As Master
Albert noted there was no evidence that any prejudice would result from the six
month delay. Moreover, the prejudice identified on appeal that is, the need to
re-attend for further examinations for discovery, is precisely the type of
prejudice that can be dealt with by way of costs and/or an adjournment. Thus,
it cannot be maintained that the amendments should have been refused on this
basis.[1]
In oral argument, the Appellant conceded that this prejudice could be remedied
by costs and asked that this Court make an order in this regard. However, as
the Appellant sought no such relief in argument before the Master, it would not
be appropriate to order costs when the matter was not raised at the first
instance.



[6] As a result,
the order permitting the Respondent to amend the Statement of Defence and
Counterclaim is upheld.



The Order to Answer Questions Which Had
Been Refused



[7] Master Albert ordered
that questions 659, 698 and 956 which had been refused upon the examination of Einhard
Wiedel should be answered. Both parties agree that the numbers of the first two
questions was misidentified and that the questions to be answered were 879, 899
and 956. The Appellant does not rely on this error and the parties are agreed
that these questions related to the provision of names and addresses of
employees, the length of service of employees and the names addresses and
telephone numbers of former employees since 1999. Here again the Appellant
argues that there was an insufficient factual basis in the record before the
Master to support this order. The Appellant also argues that these refusals
should have been sustained as the questions were irrelevant and because the
disclosure of such information was prohibited by the
Personal Information
Protection and Electronic Documents Act
( 2000, ch. 5).



[8] The
pleadings in any civil action form the terms of reference for discovery and
relevance at discovery is broader than at trial. There is no requirement that
the proposed questions be factually supported by the motion record and, once
again, counsel for the Appellant was unable to cite any authority for that
proposition.
The applicable standard here is the
"semblance of relevance" test articulated by Steele, J. in Kay v. Posluns
(1989), 71 O.R. (2d) 238 (H.C.).
As Master Albert found, the information relating to
employees and former employees of the Appellant is relevant to paragraphs 99 to
106 of the Statement of Defence and paragraph 27 of the Reply and Defence to
Counterclaim. These employees may have information relating to the 308.73
carats of diamonds that the Appellant alleges were never delivered to them. As
such these questions are relevant and, with respect to questions 879 and 956,
expressly authorized by Rule 31.06(2). This order was a discretionary one and,
applying the proper standard of review, it cannot be said that Master Albert
was clearly wrong.



[9] As for
the Appellant's submission that the disclosure of this information would be
prohibited by the
Personal Information Protection and Electronic Documents Act( 2000, ch. 5) this ignores the express provision of
section 7(3)(c) of that Act which provides, in relevant part:



(3) . . . an organization may
disclose personal information without the knowledge or consent of the
individual only if the disclosure is



(c) required to comply with a subpoena or
warrant issued or an order made by
a court, person or body with
jurisdiction to compel the production of information, or to comply with rules
of court relating to the production of records.



At a minimum, the order of Master
Albert is an order made by a court with jurisdiction to compel the production
of information. Thus, this submission of the Appellant also fails.



[10] As a result, the Master's order is
upheld and the Respondent is ordered to answer questions
879, 899 and 956.



The Order to Re-attend for Further
Examinations for Discovery



[11]
At the outset, the parties are agreed that the
Master should not have ordered re-attendance as a result of the amendments to
the pleadings as the Respondent made no such request before her. They are
agreed that, if the order to re-attend is sustained, it should be in relation
only to undertakings and refusals subsequently answered. I agree.



[12]
Here again the Appellant argues that there was
an insufficient factual basis in the record before the Master to support this
order. In this regard, the Appellant relies on the decision of Master Beaudoin
in Central Guaranty Trust Co. v. Beebe Estate, [1997] O.J. No. 4882
where he states at paragraph 7:



Rule 31.06 certainly contemplates
only one oral examination for discovery. As to whether or not
there is a right to further discovery, once again I am presented with
conflicting authorities by counsel. The plaintiff relies on I.C.S.
Construction Ltd. v. GKN Birelco Ltd
., [1991] O.J. No. 597, (March 13,
1991), Doc. CLA 162/87 Forestell J. (Ont. Gen. Div.) whereas the defendants
rely on Christie Corporation v. Alvarez (1994) 34 C.P.C. (3d) 92, a decision of Mr. Justice McNeely which
distinguishes the J.C.S. Construction case. Upon reading
these decisions, I am satisfied that there is no automatic right by one party
to compel the re-attendance of another merely because the other party has
complied with an undertaking or provided an answer after a discovery.

I believe the decision of McNeely J. gives some guidance in this
regard in that he suggests the moving party must demonstrate why reattendance
would serve a useful purpose. In this instance, I believe it would
be helpful for the court to have, by way of affidavit, an indication of what
areas need to be explored through further oral examination on discovery.

It is not sufficient to accept, as submitted by plaintiffs
counsel, that the opposing party can object if counsel, on re-examination
strays into areas previously responded to or into areas upon which he may not
be entitled to re-examine.



[13]
I accept
that there is no automatic right by one party to
compel the re-attendance of another merely because the other party has complied
with an undertaking or provided an answer after a discovery. However, I reject
the suggestion that in
Central Guaranty Trust Co. v. Beebe Estate Master Beaudoin was
propounding a general requirement that affidavit evidence is required before an
order for re-attendance will be made. Indeed, Master Beaudoin expressly limited
the scope of his suggestion when he said affidavit evidence would be helpful
"In this instance". None of the other cases cited by the Appellant
support such a general rule and counsel for the Appellant was unable to cite
any cases where Central Guaranty Trust Co. v. Beebe Estate was
interpreted to this effect. Indeed, the proper approach to the ordering of
re-attendance was clearly identified by McNeely, J. in
Christie Corporation v.
Alvarez
where he said at paragraph 4, "no general rules are possible
and each case must be considered on its merits." In this case, after the
completion of discoveries, the Appellant provided answers to ninety nine
undertakings and twenty refusals. The decision to order re-attendance
was a discretionary one
and, applying the proper standard of review, it cannot be said that Master Albert
was clearly wrong.



[14]
As
a result, the Master's order is upheld and t
he Appellant is ordered to re-attend for discovery arising from the
answers to the undertakings and refusals.




Read more from this post in Online law articles »

Article: Patients are denied the last rites under data protection law

I've heard of this happening in Canada, but it has not been widely reported on. The Telegraph has a very good article on the issues related to not providing patient religious affiliation info to hospital chaplains because of privacy concerns.

Patients are denied the last rites under data protection law

By Elizabeth Day

(Filed: 25/07/2004)

Thousands of terminally ill patients are being denied access to spiritual guidance from hospital chaplains because the Data Protection Act is being applied over-zealously.

The Hospital Chaplaincies Council has criticised several NHS Trusts for their "hysterical" refusal to disclose the religious backgrounds of their patients. The trusts claim that such information is "too sensitive" to share with chaplains.

Now many of Britain's 3,425 hospital chaplains are unable to offer spiritual succour - or perform the last rites in the case of Roman Catholics - unless patients ask to see a chaplain on admission to hospital. Chaplains are concerned that many patients going for routine check-ups will not give their consent and then be unable to change their mind should their medical condition deteriorate.


Read the rest of the extensive article here ...

From what I've heard informally, it'll be a lot worse for chaplains in Ontario once Bill 31 is implemented in November.

Read more from this post in Online law articles »

Article: Ontario to tackle address sharing

It looks like there'll be a comprehensive examination of private sector access to government databases following the well-publicised Impark issues:

Ontario to tackle address sharing

Privacy commissioner sought action for years

Parking ticket harassment highlighted policy


JORDAN HEATH-RAWLINGS

STAFF REPORTER

The minister of transportation and Ontario's privacy commissioner will meet soon to examine the complex system that allows more than 3,000 companies and organizations access to the addresses and other personal information of the province's residents.

Privacy commissioner Ann Cavoukian wants the government to limit the scope of the organizations that can access personal information, specifically those who use such information to chase down bad debtors.

The authorized request system, which allows certain organizations access to public information in the transportation ministry databases, came under fire this week after stories in the Star revealed that Imperial Parking (Impark) was giving personal information to its collection agency, Canadian Bonded Collection, Inc., to chase people who owed small debts on unpaid parking tickets. The collection agency was calling people repeatedly, sometimes twice a day, according to several people who told the Star they had been receiving the calls for months.



For the rest of the story from the Toronto Star: Ontario to tackle address sharing.

Read more from this post in Online law articles »

Report from the CBA in Winnipeg

I just returned from a very good few days at the Canadian Bar Association’s annual get-together
in Winnipeg, Manitoba. There were quite a few privacy-related events during the
two-day substantive program.



The first event was more administrative than anything. It
was the meeting of the CBA Privacy Law subsection. The meeting was chaired by Brian Bowman, the section
secretary who is also a privacy lawyer at Pitblado
in Winnipeg. We reviewed the privacy-related resolutions passed by the CBA
general meeting and the extensive activity undertaken by the section during its
first year. (I’m told that it has an unprecedented level of activity for a
brand-new section.) The next year should be just as busy.



David
Young
, who chairs the Advocacy and Government Relations subsection led a
discussion of the contribution that can be made when the Personal Information Protection
and Electronic Documents Act
(Canada) comes up for full review in 2006.
I expect there will be no shortage of suggestions. Ann Goldsmith, legal counsel
to the Office of the Privacy Commissioner
mentioned they have many suggestions already, with deemed consent for due
diligence review in the course of sales of businesses near the top of their list.



Cross-border privacy issues



The second event was also on Monday: a panel discussion of
cross-border privacy issues. Moderated by David Young of Lang Michener, the panel was composed
of Simon
Chester
of McMillan Binch,
Evelyn Sullen of Volkswagen of America Inc.
and me. The presentation that I gave is available here and I’ll try to
get permission to post Simon and Evelyn’s powerpoints.



Simon Chester began with a presentation on European privacy
law, using three European women as illustrations of the law’s development and
enforcement: (a) Bodil Lindqvist,
(b) Naomi Campbell (see Campbell v. MGN Limited, [2004] UKHL 22) and (c)
Princess
Caroline of Monaco
. The first example demonstrates how some authorities in Europe
are being much more aggressive in enforcing the Data Protection Directive,
including against clearly non-commercial and “domestic” use of personal
information. The latter two examples show how the balance between privacy and
freedom of the press are moving clearly towards privacy in Europe. (We will not
likely see any of the Campbell/Caroline examples in Canada soon, as PIPEDA
specifically does not apply to information collected for “artistic, literary or
journalistic purposes. Any similar complaints against paparazzi will have to be
grounded in the independent tort of “invasion of privacy”, which is being
slowly developed in the Canadian provinces that do not have a statutory tort.) Interested readers should take a look at Simon's comprehensive paper, which is available here.



Evelyn’s presentation included an overview of the sectoral
laws in the United States (COPPA, HIPAA, GLB, etc.) and a look at Volkswagen USA’s
experience in addressing PIPEDA and the European privacy rules. It was
estimated that VW spent about $500K in complying with PIPEDA, including postage
for sending a “grandfathering/opt-out” letter to all customers in their
database.



One of the questions posed was whether to adopt a fragmented
privacy management system within an international company or should one try to
develop a policy that complies with all legal regimes in which the company
operates. Much of what was discussed in the international context is also
applicable within the Canadian federal system. We are dealing with a number of
privacy regimes in this country, including the present 100% overlap between
federal and provincial laws in Alberta and British Columbia. (I am told that
the Order-in-Council to declare AB and BC’s laws “substantially similar” to
PIPEDA is on the agenda for the next meeting of the federal cabinet.) We also
have an interesting overlap in the health privacy arena. Alberta, Saskatchewan
and Manitoba each have provincial health information laws and none of them are
expected to be declared substantially similar. This means that physicians in
private practice, who are engaged in “commercial activities”, must comply with
PIPEDA and with the local health information law. In most cases, the healthcare
professionals can design their programs to comply with the most demanding
individual rules and principles. In some cases, this is not always possible as
some contradictions may appear between the laws.



Update on Canada’s Privacy Laws



On Tuesday, Brian Bowman moderated a panel of
representatives from various privacy commissioners’ offices. On the panel was
Heather Black, Assistant Privacy Commissioner of Canada; Brian Loukidelis,
Information and Privacy Commissioner from British Columbia, Barry Tuckett, Manitoba’s
Ombudsman and Mary O'Donoghue, legal counsel to the Information and Privacy Commissioner of Ontario.
Each of the panelists gave an update on developments in their respective
jurisdictions, beginning with Heather Black’s overview of the roll-out of
PIPEDA. Heather made an interesting distinction between systemic and more
accidental violations of PIPEDA. Systemic violations are those which
demonstrate a systemic problem, such as a lack of awareness, policies or
procedures. Accidental ones are simply where a company’s established – and otherwise
compliant – procedures and policies are not followed, resulting in a breach.
Both are problems, but the balance of complaints is leaning further away from
systemic breaches. Heather also mentioned that the number of complaints that
are “well founded” has declined (to the end of 2003) to around 20% from 45% a
couple of years before.



Mary O'Donoghue, from the Ontario Information and Privacy
Commissioner’s Office, provided a very good and brief overview of the Personal Health
Information Protection Act
, 2004.



At the moment, I’m a little jetlagged. I’ll try to write
more about the conference when I’ve got a few more minutes and once I’ve heard
back from my co-panellists about posting their materials.


Read more from this post in Online law articles »

Article: TheStar.com - Parking firm's tactics "outrage" privacy head

The Ontario Information and Privacy Commissioner had a few choice words about the Ontario government's practice of selling registry of motor vehicle info to private parking lots:

TheStar.com - Parking firm%27s tactics %27outrage%27 privacy head:

"Improper use of government data, Cavoukian says

Readers recount similar tales of ticket harassment

It is "completely outrageous" that a parking lot operator used a government database to hound a citizen over a parking ticket" says Ontario's information and privacy commissioner. "It is unbelievable. You do not use information you obtain from the government to harass a member of the public" Ann Cavoukian said in an interview after reading of the plight of Peter Thompson in yesterday's Star."

Read more from this post in Online law articles »

IPC - Health Information Protection Act - Frequently Asked Questions

The Ontario Information and Privacy Commissioner has just released a very useful list of frequenly asked questions related to the Personal Health Information Protection Act (Bill 31 or PHIPA). A good starting point for anyone who wants to understand this complicated statute ...

IPC - Health Information Protection Act - Frequently Asked Questions:

"Note: This FAQ provides a general overview of the Health Information Protection Act, 2004, S.O. 2004, c.3.. This document does not include references to the Regulations, since currently there are no Regulations under the Act. As such, this document should be read in conjunction with the Act and any Regulations that will be made under the Act. The information contained on this web page is for general reference purposes only and should not be construed as legal advice. You should consult with your own solicitor for all purposes of interpretation."

Read more from this post in Online law articles »

Bill 31 Training - Personal Health Information Protection Act (Ontario)


An Unprecedented Training Opportunity



ClinCoach and National Privacy Services have developed a range of training courses to assist health and health research professionals in adapting to and complying with Ontario's new Bill 31, the Personal Health Information Protection Act (aka PHIPA). This law comes into force on November 1, 2004 and has significant requirements for "health information custodians", including all regulated health professionals (physicians, physiotherapists, etc.), hospitals, nursing homes, and more.

The administrative requirements are similar to those of PIPEDA (hopefully the federal cabinet will deem the entire statute to be "substantially similar" to PIPEDA), and there are limited resources available to get healthcare professionals in compliance by the November 1 deadline. No matter what, it is not business as usual. The consent requirements are more specific for healthcare, but they are not exactly user friendly.

The new law also contains specific requirements for clinical researcher and Paula's years of experience in clinical research and clinical research education will prove to be a tremendous asset to attendees of our course designed for clinical research professionals.

From August to October, we will be offering our PHIPA training courses in Ottawa and Toronto. We will likely be hitting other centres in the rest of Ontario through late October and into the fall.

Training for Bill 31 - Personal Health Information Protection Act (Ontario):

"On November 1, 2004, the Personal Health Information Protection Act comes into force for Ontario's healthcare community. The new regime means it is no longer "business as usual" for regulated health professionals, hospitals and clinics. The rules have also changed for clinical research.

National Privacy Services Inc. (NPSi) and ClinCoach each have proven track records in delivering practical and effective privacy training for the healthcare sector. Together, we have designed a range of Bill-31 training courses specifically tailored for the medical community's varied roles and environments. Unlike other workshops and conferences you may have seen elsewhere, NPSi and ClinCoach provide solid training: in-depth, concise guidance on how to implement Bill 31 in your practice, all of which will be sufficient for continuing education credits. "



For more information, check out our brochure (advance copy available here) and the websites of National Privacy Services and ClinCoach.

Read more from this post in Online law articles »

ClinCoach and NPSi Alliance for Clinical Research Privacy


National Privacy Services Inc. and ClinCoach Inc. are going to announce tomorrow the establishment of a unique alliance to provide privacy training services for those involved with clinical research. ClinCoach is a leading, international provider of training for clinical research best practices, including the provision of Clinical Research Standard Operating Procedures. With NPSi, ClinCoach is developing a Standard Operating Procedures for interjurisdictional privacy best practices, designed to assist clinical researchers in complying with PIPEDA, PHIPA and other privacy laws.



ClinCoach and NPSi Alliance for Clinical Research Privacy:

"Standard Operating Procedures for Clinical Research

ClinCoach and NPSi have developed standardized means of integrating privacy best practices and legal requirements into clinical research, offering the first-of-its-kind Privacy Standard Operating Procedures for clinical trials. The best practices contained in the Privacy SOPs are designed to be compliant with Canada's multiple health privacy regimes, including PIPEDA, PHIPA: the Personal Health Information Protection Act and various laws in all Canadian provinces. These SOPs offer a privacy solution to sponsors in multi-centre trials located at sites across Canada."



You can check out the announcement at the websites of National Privacy Services Inc. and ClinCoach Inc. starting tomorrow.


Also, stay tuned for an announcement about Bill 31 training of Ontario's health professionals and institutions.


Read more from this post in Online law articles »

Correction: Coming into force of Bill 31

In an earlier blog entry, I suggested that the bulk of Ontario's Personal Health Information Protection Act will come into force on January 1, 2005. That was incorrect. The version of the bill passed by the legislature had November 1, 2004 as the effective date:

PART IX

COMMENCEMENT AND SHORT TITLE

Commencement

99. (1) Subject to subsection (2), this Schedule comes into force on the day the Health Information Protection Act, 2004

receives Royal Assent.

Same

(2) Sections 1 to 72 and 75 to 98 come into force on November 1, 2004.

Short title

100. The short title of the Act set out in this Schedule is the Personal Health Information Protection Act, 2004.



Addition: For information about Bill 31 (PHIPA) training, see http://www.privlaw.com/pages/training_courses.htm

Read more from this post in Online law articles »

Proposed Bill 31 Regulations published

The Ontario Ministry of Health and Long-Term Care has published
a notice of proposed regulations under Bill 31. The public and
interested parties are invited to comment on the proposed regulations (deadline: September 3, 2004):

Notice of Proposed Regulations- Invitation to Provide Comments on Proposed Regulations:

"The Minister of Health and Long-Term Care on behalf of the Government of Ontario invites public comments on proposed regulations for the Personal Health Information Protection Act, 2004 and the Quality of Care Information Protection Act, 2004.

The public is invited to provide written comments on the draft regulations over a 60-day period, commencing on July 3, 2004 and ending on September 3, 2004.

Please be as specific as possible, and provide reasons for any suggested changes or additions. All comments and submissions received during the comment period will be considered during final preparation of the regulation.




The proposed regulations are available at this link.

Addition: For information about Bill 31 (PHIPA) training, see http://www.privlaw.com/pages/training_courses.htm

Read more from this post in Online law articles »

Ontario's Personal Health Information Protection Act receives royal assent

Ontario's Personal Health Information Protection Act (also known as Bill 31) received royal assent on May 30, 2004. The main parts of the statute come into force on January 1, 2005:

PART IX

COMMENCEMENT AND SHORT TITLE

Commencement

95. (1) This section and sections 71, 72 and 96 come into force on the day the Health Information Protection Act, 2004 receives Royal Assent.

Same

(2) Sections 1 to 70 and 73 to 94 come into force on January 1, 2005.

Short title

96. The short title of the Act set out in this Schedule is the Personal Health Information Protection Act, 2004.





Addition: For information about Bill 31 (PHIPA) training, see http://www.privlaw.com/pages/training_courses.htm

Read more from this post in Online law articles »

Article: Build privacy into products

Ann Cavoukian, Ontario's very active privacy commissioner, gave a speech recently highlighting the distinction between privacy and security. She also discussed who in an organization should assume the role of CPO. See the ITbusiness.ca article:

ITBusiness.ca: Build privacy into products:


"As North America witnesses the rise of chief privacy officers, one of the fastest growing designations, companies must decide who within an organization will be responsible for this job, Cavoukian said. Ideally, the function should rest with a 'customer-friendly' department like marketing or business development, she said.

Karbaliotis predicted chief privacy officers will grow in importance because these will be individuals 'willing to stand for the company and say 'We're doing this right.'

'Maybe it shouldn't be the security officer. Maybe it shouldn't be the chief technology officer.'

Instead the right candidate should understand technology, business processes, the legislative environment and be involved in business planning, he said.

The 9/11 crisis allowed an increasing degree of security to marginalize privacy, but now 'we need a new paradigm,' urged Cavoukian, and added security and privacy are necessary for freedom to prevail."

Read more from this post in Online law articles »

Privacy Officer Training: Toronto, Ottawa, London

National Privacy Services Inc. will be offering its unique privacy officer training course in London, Toronto and Ottawa, Ontario in the month of June.

Unlike most "privacy seminars" (which I have found to be rambling, too theoretical and disjointed), NPSi's offering is very practical, hands-on and leaves attendees with solid skills and tools to either begin the compliance process for their organizations or to increase their competence in critical skills.

For more information, check out NPSi's training schedule or the links to the individual sessions above.

Read more from this post in Online law articles »

PIPEDA and Video Surveillance: Guidance from the Ontario Courts


I recently blogged about PIPEDA and Video Surveillance, particularly in the insurance claims process. We are finally getting some guidance from the courts on how PIPEDA will be applied in litigation.


Since the Personal Information Protection and Electronic Documents Act (“PIPEDA”) came into full effect on January 1, 2004, insurers have been concerned about what impact this legislation might have on their claims handling processes and the ability of claims personnel to order video surveillance of claimants. There has been a fair amount of uncertainty and, while the issues are not entirely resolved, we are beginning to receive some guidance on how the courts will deal with the intersection between privacy rights and litigation.

The Ontario Superior Court of Justice recently issued a decision in the matter of Ferenczy v. MCI Medical Clinics. In this case, the insurer ordered video surveillance of the claimant, which was used at trial to impeach the claimant’s testimony. An objection was raised by the Plaintiff’s counsel on the basis that the video surveillance was conducted in violation of PIPEDA and should therefore be inadmissible in court. In the absence of the jury, Justice Dawson considered this issue and reached a number of notable conclusions.

PIPEDA applies with respect to personal information that is collected, used or disclosed in the course of “commercial activities.” When the law applies, it requires the knowledge and consent of the individual concerned for the collection, use or disclosure of his or her personal information. There are a number of exceptions to the consent principle contained in Section 7 of the statute.

Justice Dawson concluded that litigation of third-party claims is not “commercial activity” for the purposes of PIPEDA. (Please note that this is likely not the case for a first-party claim, such as under a disability policy or for Section B benefits.) Justice Dawson also concluded that, if PIPEDA applied, the Plaintiff implicitly consented to the collection of personal information via video surveillance by the act of putting forward the claim. Finally, Justice Dawson also concluded that the exception to the consent principle contained in Section 7(1)(b) was applicable.

Lawyers in our privacy and insurance law groups have been recently involved with a number of PIPEDA complaints against insurers initiated by plaintiff’s counsel. While the complaints are not yet resolved, insurers would be well advised to anticipate that such complaints may become commonplace until these matters are clearly resolved by the Privacy Commissioner or the Federal Court. It is possible that the Privacy Commissioner’s conclusions will differ from those of Justice Dawson, further complicating matters for insurers.


Read more from this post in Online law articles »

Article: Employment law myths

In today's National Post, Howard Levitt, counsel to Lang Michener, takes a pretty aggressive stand with respect to PIPEDA. His sentiments about the constitutionality are shared by others, but I was surprised to read that he suggests ignoring PIPEDA. Most privacy lawyers with whom I speak are of the view that PIPEDA should be followed until it is declared to be unconstitutional:


"4. Privacy legislation applies across Canada.

The federal privacy legislation constitutionality provided that, if similar legislation was not passed in each province by January 1, 2004, the federal legislation would apply provincially. Many provinces, including Ontario, have not yet passed Privacy Acts. However, virtually everyone is conducting themselves as if the federal privacy legislation applies. It does not. Despite the wording of that legislation, the federal government lacks the constitutional power to impose privacy legislation on the provinces and no attempt to do so would survive legal challenge. Therefore, contrary to seemingly everyone's belief, there is presently no effective, binding privacy legislation in most of Canada."


This is very aggressive and, at least to this point, many Courts have been applying PIPEDA without hesitation. It is true that the federal government has no constitutional way to regulate the provincially regulated workplace, but PIPEDA does not purport to operate there.

Read more from this post in Online law articles »

Privacy aspects of THE MATTER OF BMG Canada Inc. et al v. Jane Doe et al

The Canadian and US media have been abuzz with reports that "file sharing is legal in Canada!" (see Google News coverage). The actual decision doesn't, in my view, go that far (much of it seemed to turn on a deficient affidavit and the difficulty of connecting an IP address and a Kazaa screen name), but that's a bit ultra vires my blog. Here we deal with privacy. But fear not, there is some privacy-related analysis in the decision rendered by von Finckenstein J (2004 FCT 488).


Part of the argument advanced by the internet service providers was that they were prohibited from revealing personal information of their subscribers, absent a court order. The parties agreed in advance that the subscribers have an expectation of privacy regarding their identities, pursuant to their subscriber agreements and sections 3 and 5 of PIPEDA. They also agreed that this personal information can be released without the consent of individuals if the court so orders under section 7(3)(c) of PIPEDA.



[13] I read the Norwich and Glaxco Wellcome cases as establishing that the test for granting an equitable bill of discovery involves the following five criteria: ...

Criterion e: the public interests in favour of disclosure must outweigh the legitimate privacy concerns

[36] It is unquestionable but that the protection of privacy is of utmost importance to Canadian society. In the words of Lamer J. in R. v. Dyment, [1988] 2 S.C.R. 417 (S.C.C.): Grounded in man's physical and moral autonomy, privacy is essential for the well-being of the individual. For this reason alone, it is worthy of constitutional protection, but it also has profound significance for the public order.

[37] In respect of the internet specifically, Wilkins J. in Irwin Toy v. Doe (2000), 12 C.P.C. (5th) 103 (Ont. S.C.J.) stated at paras. 10-11: Implicit in the passage of information through the internet by utilization of an alias or pseudonym is the mutual understanding that, to some degree, the identity of the source will be concealed. Some internet service providers inform the users of their services that they will safeguard their privacy and/or conceal their identity and, apparently, they even go so far as to have their privacy policies reviewed and audited for compliance. Generally speaking, it is understood that a person's internet protocol address will not be disclosed. Apparently, some internet service providers require their customers to agree that they will not transmit messages that are defamatory or libellous in exchange for the internet service to take reasonable measures to protect the privacy of the originator of the information. In keeping with the protocol or etiquette developed in the usage of the internet, some degree of privacy or confidentiality with respect to the identity of the internet protocol address of the originator of a message has significant safety value and is in keeping with what should be perceived as being good public policy. As far as I am aware, there is no duty or obligation upon the internet service provider to voluntarily disclose the identity of an internet protocol address, or to provide that information upon request.

[38] Parliament has also recognized the need to protect privacy by enacting PIPEDA, which has as one of its primary purposes the protection of an individual’s right to control the collection, use and disclosure of personal information by private organizations (section 3).

[39] However while the law protects an individual’s right to privacy, privacy cannot be used to protect a person from the application of either civil or criminal liability. Accordingly, there is no limitation in PIPEDA restricting the ability of the Court to order production of documents related to their identity. Section 7(3)(c) allows disclosure without consent if such disclosure is: c) required to comply with a subpoena or warrant issued or an order made by a court, person or body with jurisdiction to compel the production of information, or to comply with rules of court relating to the production of records. (emphasis added).

[40] Thus, both PIPEDA as well as the test set out in Norwich/Glaxco, require the Court to balance privacy rights against the rights of other individuals and the public interest.

[41] This motion is not a novel proceeding. In the past, third parties have been compelled to disclose documents identifying the name and address of a defendant previously identified solely by an Internet Protocol address. In no case have privacy or other concerns weighing against disclosure outweighed the interest in obtaining documents and information necessary to identify the defendants. See: Irwin Toy v. Doe (2000), 12 C.P.C. (5th) 103 (Ont. S.C.J.); Ontario First Nations Limited Partnership v. John Doe (3 June 2002) (Ont.S.C.J.); Canadian Blood Services/Société Canadienne du Sang v. John Doe (June 17, 2002) (Ont. S.C.J.); Wa’el Chehab v. John Doe (October 3, 2003) (Ont. S.C.J.); Kibale v. Canada, [1991] F.C.J. No. 634 (QL) (FC); Loblaw Companies Ltd. v. Aliant Telecom Inc. and Yahoo [2003] N.B.J. No.208 (N.B.Q.B.), online: QL (NBJ).


One thing that surprises me is that there is no obligation on the part of the ISPs to inform the "owners" of the IP addresses that their information is the subject of an application for an equitable bill of discovery, affording them the opportunity to retain counsel and -- anonymously - resiting the application. To do otherwise seems to put too much discretion in the hands of the ISPs. Afterall, they choose whether to resit the discovery request.

Read more from this post in Online law articles »

Article: Great Taste, Less Privacy

The practice of swiping drivers' licenses is starting to get more and more attention. (See my blog entries: "Bar scheme could breach privacy rules"; "Ontario considering putting biometric data on drivers' licenses" and "Swiping drivers' licenses - instant marketing lists"). Privacy activitsts are paying very close attention to the practice.



Wired news, bless their hearts, has a story that illustrates how instrusive the practice may be.



Wired News: Great Taste, Less Privacy

By Kim Zetter - 02:00 AM Feb. 06, 2004 PT



A patron walks into a bar and orders a drink. The bartender asks to see some ID. Without asking permission, the barkeep swipes the driver's license through a card reader and the device flashes a green light approving the order.

The bartender is just verifying the card isn't a fake, right? Yes, and perhaps more.

Visitors to an art exhibit at the Pittsburgh Center for the Arts got more than their martinis when they ordered drinks at a bar inside the gallery's entrance. Instead of pretzels and peanuts, they were handed a receipt containing the personal data found on their license, plus all the information that could be gleaned from commercial data-mining services and voter registration databases like Aristotle. Some patrons also got receipts listing their phone number, income range, marital status, housing value and profession. For added effect, the receipt included a little map showing the location of their residence. "

Read more from this post in Online law articles »

Article: New law guards consumer privacy

Once again, the Toronto Star is to be applauded for its coverage of PIPEDA. The February 1, 2004 edition had a good article on the topic: New law guards consumer privacy:

"If you are headed to your dentist's office, pharmacy or travel agency, you may be asked to sign a form before you can get service, now that new federal privacy laws are in place.

And in some cases, you may not be able to book an appointment for a family member or have someone pick up a prescription for you without specific permission. The new privacy laws are altering the way many businesses � from pharmacies to dentists, travel agents and even the much-maligned 407 toll road � do business.

'The new law means you just can't go and collect information about people willy-nilly,' says Irwin Fefergrad, registrar with the Royal College of Dental Surgeons of Ontario.

Consumers must now be told what information is collected about them, how it is used and why it is collected. Every operation, large and small, from video stores and magazine publishers to charities and accounting firms, will need to get its information management practices in order if it wants to avoid possible court action and fines, in some cases of $10,000. Consent may be written, verbal or implied � meaning that, by using a service, a person consents. However, the person must be given a chance to opt out.

Fefergrad says that will definitely mean some changes in wording and protocols. 'You can't leave personal information on voice mail, for example.'
He says people may not be able to make some dental appointments for a family member without their written permission. But he notes dentists already have strong confidentiality rules."


(Once again, there's an otherwise accurate article that suggests that you can be fined for violating consumer privacy. Not a bad message to send people fleeing to privacy lawyers, but the info is still wrong.)

Read more from this post in Online law articles »
Info recommended by: Webpages of law and Law articles

© Online law articles: ontario