+ All Categories
Home > Documents > Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Date post: 11-Jan-2016
Category:
Upload: prudence-walters
View: 214 times
Download: 1 times
Share this document with a friend
31
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick
Transcript
Page 1: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Privacy Law for Network Administrators

Steven Penney

Faculty of Law

University of New Brunswick

Page 2: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Overview

• Criminal Code

• Public sector privacy legislation

• Private sector privacy legislation

• Sector-specific legislation

Page 3: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Criminal Code

Page 4: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Interception and seizure of private communications

• Prohibitions– Wire-to-wire communications– Wireless (radio-based) communications– Systems manager exception (quality control, unauthorized use,

mischief)

• Interception (wiretap) warrants– Content– Routing (“envelope”) data

• Search and seizure warrants

• 3d party production orders

Page 5: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Public sector privacy legislation

• Privacy Act– “Personal information” under control of a

“government institution”

• Provincial legislation

Page 6: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Private sector privacy legislation

Page 7: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

PIPEDA

Personal Information Protection and Electronic Documents Act

Page 8: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

History

• EU Directive (1995)– “adequate level of protection”

• CSA Model Code (1996)

• Phased implementation– Full effect January 1, 2004

Page 9: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Jurisdiction

• Commercial activities (federal & provincial)

• Employee information (federal only)

• Exemptions– Privacy Act – Personal or domestic purposes– “substantially similar” provincial statutes

(intra-provincial information only)

Page 10: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Overview

• Personal information

• Privacy principles

• Oversight and enforcement

Page 11: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Personal Information

• Definition– “information about an identifiable

individual . . . [except] the name, title or business address or telephone number of an employee of an organization”

• Intimacy not required

• Collection v. generation irrelevant

• Anonymity and aggregation

Page 12: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Privacy Principles

Page 13: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Interpretive tools

• Schedule (“shall” v. “should”) (s. 5(2))

• Reasonableness (s. 5(3))– “An organization may collect, use or disclose

personal information only for purposes that a reasonable person would consider are appropriate in the circumstances.”

Page 14: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

The Schedule

Page 15: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Accountability

• Designated person

• 3d party transfers

– Mere processing (contractual protections)

– Disclosure (must comply with Act)

Page 16: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Notice of purposes

• New purposes

Page 17: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Informed consent• No conditions for non-essential information

– e.g. “no SIN, no connection”

• Form of consent– Sensitivity of information– Express v. implied– “Opt-in” v. “opt-out”

• Withdrawal of consent– Subject to legal and contractual restrictions

Page 18: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Exceptions to consent

• Collection– Interests of person and consent can’t be obtained– Investigation of breach of contract or law – Journalistic, artistic, or literary purpose– Publicly available and in regulations

• Use– Investigation of breach of law– Health or security emergency– Statistical or scholarly research (restrictions)– Publicly available and in regulations– Collected under ss. 7(1)(a) or (b)

Page 19: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Exceptions to consent con’t• Disclosure

– Organization’s lawyer– Debt collection– Court order– Law enforcement and national security (where legal

entitlement)– Investigation of breach of contract or law (to or by

investigative body)– Health or security emergency– Statistical or scholarly research (restrictions)– Archives– 100 years or 20 years after death– Publicly available and in regulations– Compliance with law

Page 20: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Limiting collection

• Only for identified purposes

Page 21: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Limiting use, disclosure and retention

• No additional purposes without consent

• Retain only for as long as necessary to fulfill purpose for which information collected

• Retain long enough to enable access to information used for decision

• Guidelines and procedures encouraged, including minimum and maximum retention periods

Page 22: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Accuracy

• Accurate, complete, and up-to-date

Page 23: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Safeguards

• Loss or theft, unauthorized access, etc.

• Measures vary with sensitivity of information

• Technological measures (e.g. encryption)

• Employee training

Page 24: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Openness

• Policies in readily accessible form

• Contact information

• Means for access to information

• General description of types of information held

Page 25: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Access

• Confirmation of existence

• Right of review

• Disclosure of information to third parties (list)

• Minimal or no cost

• Due diligence and time limits

• Amendment and corrections

Page 26: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Exceptions to Access

• 3d party information

• Solicitor-client privilege

• Confidential commercial information

• Health or security of 3d party

• Compromise legal investigation

• Information generated from formal dispute resolution process

• Notification of access request to government for law enforcement (government veto)

Page 27: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Challenging compliance

• Procedures and notification

• Duty to investigate

• Appropriate remedies

Page 28: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Oversight and Enforcement

Page 29: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Privacy Commissioner

• Complaints

• PC’s power to initiate

• Investigative powers and mediation

• Reports (confidentiality and shaming)

• Audits

• Education, research, and compliance assistance

Page 30: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Federal Court

• Complainant

• Privacy Commissioner

• Remedies

Page 31: Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.

Provincial Legislation

• Non-commercial

• Employees in provincial sector

• Commissioners’ order-making powers

• Jurisdictional issues


Recommended