Save Online law articles on social network:
Showing posts with label retention. Show all posts
Showing posts with label retention. Show all posts

Article: Think before you text

Years later, cell phone text messages can come back to haunt you. According to CNN.com, ancient text messages may be ordered to be produced as evidence in the Kobe Bryant trial (see below). These messages "tend to be saved on servers."

Canada's federal privacy law, PIPEDA, has applied to telecom companies since 2001. One of the principles of the law is that information can only be retained for as long as is reasonable for the purposes for which the information was collected:

4.5 Principle 5 -- Limiting Use, Disclosure, and Retention

Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required by law. Personal information shall be retained only as long as necessary for the fulfilment of those purposes.

4.5.2

Organizations should develop guidelines and implement procedures with respect to the retention of personal information. These guidelines should include minimum and maximum retention periods. Personal information that has been used to make a decision about an individual shall be retained long enough to allow the individual access to the information after the decision has been made. An organization may be subject to legislative requirements with respect to retention periods.

4.5.3

Personal information that is no longer required to fulfil the identified purposes should be destroyed, erased, or made anonymous. Organizations shall develop guidelines and implement procedures to govern the destruction of personal information.



It would seem that Canadian telcos should not be retaining these messages indefinitely. Of course, "should" and "do" are two entirely different matters... Beware what you text, it may come back in civil or criminal proceedings.

The CNN story on the Bryan trial is here:

CNN.com - Think before you text - Jun 7, 2004:

"DENVER, Colorado (AP) -- A few hours after NBA star Kobe Bryant had sex with a Vail-area hotel worker last summer, the woman exchanged cell phone text messages with a former boyfriend and someone else.

What's in those messages could help determine whether the sex was consensual or whether Bryant is guilty of rape as charged. The judge himself said the content may be 'highly relevant' to the case.

That the judge could order the woman's cell phone company to produce the messages so long after they were sent shouldn't surprise anyone, analysts say.

Texters beware. Like e-mail and Internet instant messages, text messages tend to be saved on servers.

'One of the false assumptions that people make is that when they hit the delete button, messages are gone forever, but nothing can be further from the truth,' said Jeff Kagan, an independent telecommunications analyst in Atlanta."


See also Slashdot discussion of the issue ...

Read more from this post in Online law articles »

Release: Privacy Law Spurs Jump in Shredding Business

This should come as no surprise:



Privacy Law Spurs Jump in Shredding Business:
"Proshred Sees Accelerated Expansion of Its Door-to-Door Shredding Services As Personal Information Protection and Electronic Documents Act Takes Full Effect


TORONTO, March 23 /CNW/ - With the Personal Information Protection and Electronics Act now in full effect in Canada after a three-year phased-in program, Canadian businesses are increasingly turning to shredding services for assistance in complying with the law's prohibition against disclosing personal information collected during the normal course of commercial activities.

Proshred Security International Inc., Canada's largest mobile shredding service with offices in 350 cities across the country, has seen surging interest in the use of its door-to-door document destruction services by companies and organizations wishing to avoid potential liability under the privacy law.

The company's client roster has expanded by 15 percent in the last six months, with a majority of new customers citing the law as a key reason for coming on board. Inquiries have continued to flow in since January 1 as businesses that had delayed changing their document retention and destruction procedures are scrambling to protect themselves.

'We had a number of proposals with large companies that didn't go anywhere for months or even years because there appeared to be no pressing need for a shredding service,' said Ron Campbell, Proshred President and CEO. 'Now we're seeing those proposals being funded because of this privacy legislation.'

Privacy without tears: In addition to helping uphold the law's ban on unauthorized personal information disclosure by ensuring that information is destroyed before it can be used for illicit purposes, shredding can minimize the burden created by the provision of the law that requires companies to supply all information they have on a specific individual upon request."

Read more from this post in Online law articles »

Article: Privacy rules turn shredders on: Document destruction firms see business booming in age of Enron, identity theft

Today's Globe and Mail has an article on the increased used of document destruction in response to identity theft and privacy laws:



Privacy rules turn shredders on: Document destruction firms see business booming in age of Enron, identity theft

By KEITH DAMSELL

TECHNOLOGY REPORTER



For Terry Farrell, contact with his paper shredder has escalated from a casual fling to a torrid relationship.

Every day, the Toronto financial planner's GBC Shred Master hums to life, slicing and dicing sensitive statements and client correspondence.

"I don't keep every statement that I have. Sometimes with transactions I have too many copies and so I shred what I need to. For me, its strictly security and compliance," said the burly 58-year old. His list of about 400 clients ranges from wealthy retirees to frugal school teachers.

That's a big change from five years ago when the machine sat idle most days in his home office.

"When I first got it, I barely used it," he said. "Now, I am absolutely inundated with paperwork. It is never-ending."

Mr. Farrell is on to something. New privacy legislation -- and a liberal dose of corporate paranoia -- has made the paper shredding trade very big business. In the age of Enron and identity theft, conscientious paper management is hot. ...

New Canadian legislation called the Personal Information Protection and Electronic Documents Act, effective Jan. 1, 2004, is driving the desire to mince and chop, industry sources say. The federal act sets ground rules for how the private sector collects, uses and discloses personal information. For shredders, the kicker is in the act's notes on retention: Businesses must "destroy, erase or render anonymous" personal data that are no longer required.



Last summer I wrote on article on PIPEDA and document destruction, which is available from the McInnes Cooper website at http://www.mcinnescooper.com/publications/destruction.pdf.

Information destruction is the one place that businesses fall flat on their faces in the most public of ways. Most privacy incidents are related to not controlling the waste stream. Some time ago, I used to work in a building that also housed an investment firm. Each week, the loading dock was filled with blue bins for recycling. Available for anyone to see (if they were curious) were print-outs of all their accounts, including names of account holders, addresses, balances, recent trades and overall performance. Neeless to say, I'd take my investment business somewhere else.

The best rule of thumb is to shred all paper waste and destroy all magnetic media. Better safe than sorry.


Read more from this post in Online law articles »

File-swapping litigation raises important privacy issues

Up until recently, Canadians have been free of the sort of litigation that the American recording industry has inflicted on "file sharers" in the U.S. As many know, the first movements toward similar litigation has recently been noticed in Canada (See the Globe & Mail's article, Canadian Recording Industry hopes to inspire fear over file swapping). Some of the more recent media attention has focussed on the attempt by CRIA to discover the identities of individuals whom they have targetted:



London Free Press: Business Section - Copyright suit raises concerns

David Canton, Freelance writer 2004-03-06 03:22:53



A legal action that could potentially affect anyone who has downloaded music on the Internet was recently initiated in Canada. The plaintiffs in this civil suit are some of the biggest music record labels, represented by the Canadian Recording Industry Association (CRIA).

...

CRIA intends to go after "egregious" or high-volume file-sharers that make massive quantities of music available for free.

The defendants in these proceedings are unknown for the moment. CRIA is requesting a court order that could change that. If granted, it would require Internet service providers (ISP) to produce names and addresses of the alleged perpetrators.

Electronic Frontier Canada and the Canadian Internet Policy and Public Interest Clinic have both been allowed by the court to intervene in this matter to argue the legal issues surrounding privacy, due process, and copyright law.

CRIA has tracked computers trading in copyrighted songs using their Internet protocol (IP) addresses through the use of surveillance technology. CRIA needs to match those IP addresses with subscriber information to identify the defendants.

Five ISPs have been targeted by CRIA for the disclosure of personal information that would lead to the identification of subscribers using the Web to upload music. The court ordered an adjournment until March 12 so the parties can cross-examine each other's affidavit documents to determine the technical and legal issues in dispute.

Downloading involves taking information from another computer. Uploading is transferring data from one's own computer to another. It is generally accepted that the Copyright Act allows music downloading so long as it is for personal use. Uploading is not so clear. These issues have not yet been decided in courts.

...

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), an ISP is not permitted to disclose a subscriber's personal information without the person's knowledge and consent. One exception is a court order.

There are many issues to be considered, such as whether civil actions should be held to a higher threshold before privacy is violated than in criminal cases, and whether uploading music as done by the peer-to-peer networks is actually copyright infringement.

There is also concern about the accuracy of the information being sought. Dynamic IP addresses can be reassigned to different customers on a continual basis, making it difficult to determine which individuals upload music files.

The worry is that ISPs could be compelled to provide private information that wrongly identifies someone. One of the ISPs maintains it can not accurately match the IP addresses with alleged file-sharers.

Copyright © The London Free Press 2001,2002,2003



One concern that I have, right off the bat, is that the ISPs probably collect way too much information in the first place and probably should put in place a rigorous retention policy that would delete their logs pretty darn quick. If they don't have the information desired by CRIA, they don't have to worry about it. It is not the job of the ISPs to collect and stockpile evidence for the recording industry (or any other organization). In fact, under PIPEDA they should probably not retain it:

Principle 5 -- Limiting Use, Disclosure, and Retention



Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required by law. Personal information shall be retained only as long as necessary for the fulfilment of those purposes.




The information being requested by CRIA is probably from routine logging of network activity and connections. I know of some providers who (despite advice to the contrary) keep these logs indefinitely for security and audit purposes. In most cases, this is not made known to the customers. I know that my ISP does not mention this sort of information collection in its Privacy Policy, even though the Openness Principle requires making this sort of collection known. My cellphone company doesn't say anything about signalling information, which I am sure is logged and can be traced to me.


According to what I've heard, the US PATRIOT Act allows the Department of Homeland Security to request information about borrowers from public libraries. The logical response from many librarians is to make sure they don't collect information that would be useful to the FBI. From the San Francisco Public Library:


The Library does not maintain a history of what a borrower has previously checked out once books and materials are returned on time.


In short, if you don't want to fight over disclosing it to anyone, don't collect it and, if you do, don't retain it!




Read more from this post in Online law articles »

Privacy Site of the Day: Privacy Impact Assessment Guidelines

The Treasury Board Secretariat, the principal policy making body for the Canadian federal government, has made available a tremendous resource for the conduct of privacy impact assessments (PIAs). The federal government's PIA policy and guidelines are on the Treasury Board's site, and they provide an excellent and systematic way of scrutinizing new or expanded projects to ensure that privacy principles and privacy legislation are considered at every step. This is much more efficient than discovering at the conclusion of the project that it has to be redisigned to mitigate privacy risks.

An additional benefit of the PIA guidelines is that they can be implemented, by and large, by the project team with review and oversight by a privacy lawyer or the organization's privacy officer.

Also on the subject of PIAs, I'd recommend reading a speech by Stuart Bloomfield, of the Office of the Privacy Commissioner. Stuart spoke about PIAs to the 2nd annual forum on managing government information in March 2004.

By asking the right questions — i.e., whether the information requested is truly necessary, whether the use is consistent with the stated purpose, whether retention is rationally connected to its use, etc, the PIA serves to give effect to the fair information practice principles.

In sum, PIAs perform the following roles:


  1. They act as an early warning and planning tool;
  2. They forecast and/or confirm the impacts of a government proposal on the privacy of individuals and groups;
  3. They provide a mechanism to assess a proposal's compliance with privacy protection legislation and principles; and
  4. They provide a framework for the development and implementation of actions and strategies required to avoid or overcome the negative impacts of the proposal on privacy.

In conducting a PIA and acting upon the advice advanced therein, government departments can:


  1. Avoid adverse publicity, the loss of credibility and public confidence and the legal costs, remedies and sanctions that could result from negative impacts; and
  2. Increase Canadians' privacy awareness and confidence with the government's handling of their personal information by informing them of the details of the proposal.

The potential costs to departments by not conducting a PIA where one is required should not be underestimated. One need only recall the highly publicized debacle over HRDC's Longitudinal Labour Force File (LLF) whose subsequent dismantlement following public complaints against the database cost the department millions of dollars. Arguably had a PIA been done on the LLF prior to implementation, HRDC could have avoided the adverse publicity and financial losses that it suffered as a result of this incident.



Read more from this post in Online law articles »
Info recommended by: Webpages of law and Law articles

© Online law articles: retention