Canada: Privacy Briefing - August 2004

Last Updated: September 2 2004

Edited by Michael Power

Contents

  • B.C. to Legislate Protection from Patriot Act
  • Big Companies Employing Snoopers for Staff Email
  • Canada: Police May Not Fish for Evidence
  • Italy: Civil Choice to Publish Mobile Numbers
  • South Africa: Sentech Confidentiality Breach
  • Under-The-Skin ID Chips Move Toward U.S. Hospitals
  • U.K.: Privacy Traded for Personalization
  • U.S.: Allegheny County Courts Reveal Personal Information
  • U.S.: No Constitutional Right to Sexual Privacy
  • U.S.: The Confidentiality of Alcohol and Drug Abuse Patient Records Regulation and the HIPAA Privacy Rule

B.C. To Legislate Protection From Patriot Act

British Columbia has announced plans to stop any far-reaching effects the U.S. Patriot Act may have on the privacy of people in B.C. The province will introduce rules this fall to forbid Canadian subsidiaries of American companies from handing over private information to American law enforcement agencies.

Under the Patriot Act, passed in response to the September 11, 2001 attacks, U.S. agencies are allowed access to the information in the name of U.S. homeland security. Civil liberty and privacy activists say there's an easier way around the Patriot Act—stop contracting out government data services to American-owned companies.

The province is currently negotiating seven different contracts where private information could be exposed under the Act, including financial and medical records. Geoff Plant, B.C.'s attorney general, says the Patriot Act presents "a small and largely theoretical risk to personal information" collected in B.C.

Full press report available at:

http://www.cbc.ca/story/canada/national/2004/07/24/bc_privacy040724.html

Full press release available at:

http://www2.news.gov.bc.ca/nrm_news_releases/2004MSER0012-000602.pdf

BC Submission to BC Privacy Commissioner outlining proposal available at:

http://www.gov.bc.ca/mser/down/submission.pdf

Big Companies Employing Snoopers For Staff Email

Large companies are now so concerned about the contents of the electronic communications leaving their offices that they're employing staff to read employees' outgoing emails. According to research from Forrester Consulting, 44 per cent of large corporations in the U.S. now pay someone to monitor and snoop on what's in the company's outgoing mail, with 48 per cent actually regularly auditing email content.

The Proofpoint-sponsored study found the motivation for the mail paranoia was mostly due to fears that employees were leaking confidential memos and other sensitive information, such as intellectual property or trade secrets, with 76 per cent of IT decision makers concerned about the former and 71 per cent concerned about the latter.

Full press report available at:

http://www.silicon.com/silicon/management/government/

Canada: Police May Not Fish For Evidence

Police with reasonable suspicions have the power to detain people temporarily but can't go on "fishing expeditions" for evidence, the Supreme Court of Canada ruled in a decision released July 23rd.

It was the first time the high court had examined an everyday police practice that many law officers and prosecutors take for granted. The decision upholds a ruling by a trial judge in Winnipeg, who acquitted Phillip Henry Mann of trafficking after police stopped him on the street in relation to a nearby break-and-enter and found almost an ounce of pot in his sweatshirt pouch.

"Individuals have a reasonable expectation of privacy in their pockets," Justice Frank Iacobucci wrote in a majority decision that divided the high court 5-2. "The search here went beyond what was required to mitigate concerns about officer safety and reflects a serious breach of (Mann's) protection against unreasonable search and seizure."

The court agreed, however, that police can briefly detain a person for investigative purposes, provided they have reasonable grounds to suspect the person is connected to a particular crime.

Full press report available at:

http://cnews.canoe.ca/CNEWS/Law/2004/07/23/pf-554418.html

Italy: Civil Choice To Publish Mobile Numbers

The Privacy Authority's decision to authorize the publication of mobile phone numbers in telephone directories is "a very civil choice that could be useful and timely for all users." This is the opinion of the Communications Minister, Maurizio Gasparri. "…I believe that for all us users it will be useful and timely to also have available alongside the yellow pages and the white pages a directory of these numbers. Naturally, if there is the authorization of the user." Gasparri said a decision on this matter was wanted for some time: "If you like we are even behind compared to other countries given the mobile phone boom in Italy."

Press Report available at:

http://www.agi.it/english/news.pl?doc=200407212034-1262-RT1-CRO-0-NF82

South Africa: Sentech Confidentiality Breach

Sentech, a South African wireless carrier, has e-mailed a database of MyWireless users to some of its clients, in what one user described as a "serious breach of confidentiality."

Astonished MyWireless clients forwarded copies of the database to ITWeb, saying it had been attached to an e-mail they received from Sentech the previous weekend. The e-mail purported to contain an attachment outlining Acceptable Use Policy. The Excel database includes names, addresses and contact numbers of around 1 500 users.

Full press report available at:

http://allafrica.com/stories/200407261247.html

Under-The-Skin Id Chips Move Toward U.S. Hospitals

VeriChip, the company that makes radio frequency identification—RFID—tags for humans, has moved one step closer to getting its technology into hospitals. The Federal Drug Administration issued a ruling on July 27 that essentially begins a final review process that will determine whether hospitals can use RFID systems from the Palm Beach, Florida-based company to identify patients and/or permit relevant hospital staff to access medical records, said Angela Fulcher, vice president of marketing and sales at VeriChip.

VeriChip sells 11-millimeter RFID tags that get implanted in the fatty tissue below the right tricep. When near one of Verichip's scanners, the chip wakes up and radios an ID number to the scanner. If the number matches an ID number in a database, a person with the chip under his or her skin can enter a secured room or complete a financial transaction.

The approval process does not center on health risks or implications. The company's basic technology has also been used in animals for years. Instead, the FDA may mostly examine privacy issues.

Full press report available at:

http://zdnet.com.com/2100-1103_2-5285815.html

U.K.: PRIVACY TRADED FOR PERSONALIZATION

British consumers are happy to give away private information if they get better, more personalised online content in exchange. A survey found 64 per cent would exchange preference information for personalised content and product information. Just over half, 56 per cent would give away information about their age and gender.

The survey also found differences in attitude according to age—younger surfers are more trusting (gullible?) than their older and more suspicious counterparts. Among 18-to-34 year olds, 63 per cent would happily give away demographic information; this falls to 49 per cent of over-35s. Overall, 40 per cent of respondents would agree to let a Web site monitor their clicks and purchases.

Full press report available at:

http://www.theregister.co.uk/2004/07/27/privacy_personalised/print.html

U.S.: ALLEGHENY COUNTY COURTS REVEAL PERSONAL INFORMATION

For nearly a year, the Allegheny County prothonotary's(chief clerk's) office has been electronically scanning court documents in civil cases, including divorces and child custody cases, and posting them online for public access. The problem is that many of the files contain potentially sensitive personal data, including birth dates, Social Security numbers, even bank account numbers—the information ID thieves crave in order to steal people's identities.

The prothonotary's office believes it's the only court in the state, and one of the few nationwide, that allows unfettered electronic access to court filings, throwing it into the forefront of a debate pitting greater public access against concerns about privacy.

Advocates of electronic access, including the local prothonotary's office and the news media, defend the practice by pointing out that the court filings being displayed are already public record and can be viewed in hard copy at courthouses.

Critics, chiefly consumer privacy groups, argue that since paper filings are relatively difficult and time-consuming to obtain (it requires visiting the courthouse and asking a clerk to retrieve them by case number or name), sensitive personal data is protected by "practical obscurity." Simply put, electronic access makes viewing court records a whole lot easier, for both the public and ID thieves.

Full press report available at:

www.post-gazette.com/pg/04211/353372.stm

U.S.: NO CONSTITUTIONAL RIGHT TO SEXUAL PRIVACY

On July 28th a federal appeals court upheld a 1998 Alabama law banning the sale of sex toys in the state, ruling the Constitution doesn't include a right to sexual privacy.

In a 2-1 decision overturning a lower court, a three-judge panel of the 11th U.S. Circuit Court of Appeals said the state has a right to police the sale of devices that can be sexually stimulating.

The American Civil Liberties Union, which represented merchants and users who sued to overturn the law, asked the appeals court to rule that the Constitution included a right to sexual privacy that the ban on sex toy sales would violate. The court declined, indicating such a decision could lead down other paths.

The state law bans only the sale of sex toys, not their possession, the court said, and it doesn't regulate other items including condoms or virility drugs. "The Alabama statute proscribes a relatively narrow bandwidth of activity," U.S. Circuit Judge Stanley F. Birch Jr. wrote.

Circuit Judge Rosemary Barkett disagreed, saying the decision was based on the "erroneous foundation" that adults don't have a right to consensual sexual intimacy and that private acts can be made a crime in the name of promoting "public morality."

Full press reports available at:

http://seattlepi.nwsource.com/national/apus_story.asp?category=1110

http://courttv.com/news/2004/0729/sextoys_ap.html

http://abcnews.go.com/wire/US/ap20040729_210.html

U.S.: The Confidentiality Of Alcohol And Drug Abuse Patient Records Regulation And The HIPAAacy Rule

The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule establishes a foundation of Federal privacy protections and individual rights with respect to individually identifiable health information held by covered entities and their business associates. Other laws, such as state and other federal laws, may provide additional privacy rights and protections.

The document "The Confidentiality of Alcohol and Drug Abuse Patient Records Regulation and the HIPAA Privacy Rule: Implications For Alcohol and Substance Abuse Programs," addresses the interaction of the Confidentiality of Alcohol and Drug Abuse Patient Records regulation (42 CFR Part 2) and the HIPAA Privacy Rule. It offers guidance on how these entities may integrate the Privacy Rule into business and clinical processes. Among other things, the document contains a summary that highlights significant areas in which the two federal regulations interact.

The document, produced by the Substance Abuse and Mental Health Services Administration, may be found at:

http://www.hipaa.samhsa.gov/Part2ComparisonCleared.htm

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

To print this article, all you need is to be registered on Mondaq.com.

Click to Login as an existing user or Register so you can print this article.

 
In association with
Related Topics
 
Related Articles
 
Related Video
Up-coming Events Search
Tools
Print
Font Size:
Translation
Channels
Mondaq on Twitter
 
Register for Access and our Free Biweekly Alert for
This service is completely free. Access 250,000 archived articles from 100+ countries and get a personalised email twice a week covering developments (and yes, our lawyers like to think you’ve read our Disclaimer).
 
Email Address
Company Name
Password
Confirm Password
Position
Mondaq Topics -- Select your Interests
 Accounting
 Anti-trust
 Commercial
 Compliance
 Consumer
 Criminal
 Employment
 Energy
 Environment
 Family
 Finance
 Government
 Healthcare
 Immigration
 Insolvency
 Insurance
 International
 IP
 Law Performance
 Law Practice
 Litigation
 Media & IT
 Privacy
 Real Estate
 Strategy
 Tax
 Technology
 Transport
 Wealth Mgt
Regions
Africa
Asia
Asia Pacific
Australasia
Canada
Caribbean
Europe
European Union
Latin America
Middle East
U.K.
United States
Worldwide Updates
Registration (you must scroll down to set your data preferences)

Mondaq Ltd requires you to register and provide information that personally identifies you, including your content preferences, for three primary purposes (full details of Mondaq’s use of your personal data can be found in our Privacy and Cookies Notice):

  • To allow you to personalize the Mondaq websites you are visiting to show content ("Content") relevant to your interests.
  • To enable features such as password reminder, news alerts, email a colleague, and linking from Mondaq (and its affiliate sites) to your website.
  • To produce demographic feedback for our content providers ("Contributors") who contribute Content for free for your use.

Mondaq hopes that our registered users will support us in maintaining our free to view business model by consenting to our use of your personal data as described below.

Mondaq has a "free to view" business model. Our services are paid for by Contributors in exchange for Mondaq providing them with access to information about who accesses their content. Once personal data is transferred to our Contributors they become a data controller of this personal data. They use it to measure the response that their articles are receiving, as a form of market research. They may also use it to provide Mondaq users with information about their products and services.

Details of each Contributor to which your personal data will be transferred is clearly stated within the Content that you access. For full details of how this Contributor will use your personal data, you should review the Contributor’s own Privacy Notice.

Please indicate your preference below:

Yes, I am happy to support Mondaq in maintaining its free to view business model by agreeing to allow Mondaq to share my personal data with Contributors whose Content I access
No, I do not want Mondaq to share my personal data with Contributors

Also please let us know whether you are happy to receive communications promoting products and services offered by Mondaq:

Yes, I am happy to received promotional communications from Mondaq
No, please do not send me promotional communications from Mondaq
Terms & Conditions

Mondaq.com (the Website) is owned and managed by Mondaq Ltd (Mondaq). Mondaq grants you a non-exclusive, revocable licence to access the Website and associated services, such as the Mondaq News Alerts (Services), subject to and in consideration of your compliance with the following terms and conditions of use (Terms). Your use of the Website and/or Services constitutes your agreement to the Terms. Mondaq may terminate your use of the Website and Services if you are in breach of these Terms or if Mondaq decides to terminate the licence granted hereunder for any reason whatsoever.

Use of www.mondaq.com

To Use Mondaq.com you must be: eighteen (18) years old or over; legally capable of entering into binding contracts; and not in any way prohibited by the applicable law to enter into these Terms in the jurisdiction which you are currently located.

You may use the Website as an unregistered user, however, you are required to register as a user if you wish to read the full text of the Content or to receive the Services.

You may not modify, publish, transmit, transfer or sell, reproduce, create derivative works from, distribute, perform, link, display, or in any way exploit any of the Content, in whole or in part, except as expressly permitted in these Terms or with the prior written consent of Mondaq. You may not use electronic or other means to extract details or information from the Content. Nor shall you extract information about users or Contributors in order to offer them any services or products.

In your use of the Website and/or Services you shall: comply with all applicable laws, regulations, directives and legislations which apply to your Use of the Website and/or Services in whatever country you are physically located including without limitation any and all consumer law, export control laws and regulations; provide to us true, correct and accurate information and promptly inform us in the event that any information that you have provided to us changes or becomes inaccurate; notify Mondaq immediately of any circumstances where you have reason to believe that any Intellectual Property Rights or any other rights of any third party may have been infringed; co-operate with reasonable security or other checks or requests for information made by Mondaq from time to time; and at all times be fully liable for the breach of any of these Terms by a third party using your login details to access the Website and/or Services

however, you shall not: do anything likely to impair, interfere with or damage or cause harm or distress to any persons, or the network; do anything that will infringe any Intellectual Property Rights or other rights of Mondaq or any third party; or use the Website, Services and/or Content otherwise than in accordance with these Terms; use any trade marks or service marks of Mondaq or the Contributors, or do anything which may be seen to take unfair advantage of the reputation and goodwill of Mondaq or the Contributors, or the Website, Services and/or Content.

Mondaq reserves the right, in its sole discretion, to take any action that it deems necessary and appropriate in the event it considers that there is a breach or threatened breach of the Terms.

Mondaq’s Rights and Obligations

Unless otherwise expressly set out to the contrary, nothing in these Terms shall serve to transfer from Mondaq to you, any Intellectual Property Rights owned by and/or licensed to Mondaq and all rights, title and interest in and to such Intellectual Property Rights will remain exclusively with Mondaq and/or its licensors.

Mondaq shall use its reasonable endeavours to make the Website and Services available to you at all times, but we cannot guarantee an uninterrupted and fault free service.

Mondaq reserves the right to make changes to the services and/or the Website or part thereof, from time to time, and we may add, remove, modify and/or vary any elements of features and functionalities of the Website or the services.

Mondaq also reserves the right from time to time to monitor your Use of the Website and/or services.

Disclaimer

The Content is general information only. It is not intended to constitute legal advice or seek to be the complete and comprehensive statement of the law, nor is it intended to address your specific requirements or provide advice on which reliance should be placed. Mondaq and/or its Contributors and other suppliers make no representations about the suitability of the information contained in the Content for any purpose. All Content provided "as is" without warranty of any kind. Mondaq and/or its Contributors and other suppliers hereby exclude and disclaim all representations, warranties or guarantees with regard to the Content, including all implied warranties and conditions of merchantability, fitness for a particular purpose, title and non-infringement. To the maximum extent permitted by law, Mondaq expressly excludes all representations, warranties, obligations, and liabilities arising out of or in connection with all Content. In no event shall Mondaq and/or its respective suppliers be liable for any special, indirect or consequential damages or any damages whatsoever resulting from loss of use, data or profits, whether in an action of contract, negligence or other tortious action, arising out of or in connection with the use of the Content or performance of Mondaq’s Services.

General

Mondaq may alter or amend these Terms by amending them on the Website. By continuing to Use the Services and/or the Website after such amendment, you will be deemed to have accepted any amendment to these Terms.

These Terms shall be governed by and construed in accordance with the laws of England and Wales and you irrevocably submit to the exclusive jurisdiction of the courts of England and Wales to settle any dispute which may arise out of or in connection with these Terms. If you live outside the United Kingdom, English law shall apply only to the extent that English law shall not deprive you of any legal protection accorded in accordance with the law of the place where you are habitually resident ("Local Law"). In the event English law deprives you of any legal protection which is accorded to you under Local Law, then these terms shall be governed by Local Law and any dispute or claim arising out of or in connection with these Terms shall be subject to the non-exclusive jurisdiction of the courts where you are habitually resident.

You may print and keep a copy of these Terms, which form the entire agreement between you and Mondaq and supersede any other communications or advertising in respect of the Service and/or the Website.

No delay in exercising or non-exercise by you and/or Mondaq of any of its rights under or in connection with these Terms shall operate as a waiver or release of each of your or Mondaq’s right. Rather, any such waiver or release must be specifically granted in writing signed by the party granting it.

If any part of these Terms is held unenforceable, that part shall be enforced to the maximum extent permissible so as to give effect to the intent of the parties, and the Terms shall continue in full force and effect.

Mondaq shall not incur any liability to you on account of any loss or damage resulting from any delay or failure to perform all or any part of these Terms if such delay or failure is caused, in whole or in part, by events, occurrences, or causes beyond the control of Mondaq. Such events, occurrences or causes will include, without limitation, acts of God, strikes, lockouts, server and network failure, riots, acts of war, earthquakes, fire and explosions.

By clicking Register you state you have read and agree to our Terms and Conditions