Privacy Law Update. Ontario Connections: Access, Privacy, Security & Records Management Conference, June 7, 2016

Similar documents
Privacy Law Update. David Goodis, Assistant Commissioner, Information & Privacy Commissioner of Ontario)

Involved with Consumer Products in Canada?

Canada: Electronic Commerce Law Overview

The New Mandatory Data Breach Requirements under Canada s Federal Privacy Act

Tis The Season For (Conditional) Giving? British Columbia Court Rules On Conditional Donation Agreements

OTTAWA 130 Albert Street, B1 Level, Suite 7, Ottawa, K1P 5G4

Appendix A to National Instrument General Prospectus Requirements. Schedule 1 Part A

1.1.3 Notice of Memorandum of Understanding with the China Securities Regulatory Commission MEMORANDUM

Why use this slogan anywhere else?

ONTARIO SUPERIOR COURT OF JUSTICE. ) ) ) ) ) ) ) Defendants ) ) ) ) ) REASONS FOR DECISION ON MOTION

Ontario Court of Appeal to Franchisors: Comply with your disclosure requirements, or else...

Form F3A Personal Information Form and Authorization of Indirect Collection, Use and Disclosure of Personal Information

new director election requirements for TSX companies

Let the Good Times Roll: Court Allows the Free Flow of Liquor Across Provincial Borders

The Supreme Court of Canada Renders a Long Awaited Ruling regarding the Power to Situate Radiocommunication Antenna Systems

Who's in Charge Here? Information Privacy in a Social Networking World

CASL Constitutional Challenge An Overview

Form F3A. Personal Information Form and Authorization of Indirect Collection, Use and Disclosure of Personal Information

MANITOBA FREEDOM OF INFORMATION AND PROTECTION OF PRIVACY RESOURCE MANUAL

LANGUAGE REQUIREMENTS IN QUÉBEC UNDER

MUTUAL FUND DEALERS ASSOCIATION OF CANADA PROPOSED AMENDMENTS TO MFDA RULE (CONTENT OF ACCOUNT STATEMENT)

Outline. David T.S. Fraser (

Government Introduces New Recruiting Requirements, Application Fee for LMOs

Court of Queen s Bench

Presentation Outline

Adapting Search and Seizure Jurisprudence to the Digital Age: Section 8 of the Canadian Charter of Rights and Freedoms

Class Action Intrusions: A Development In Privacy Rights or an Indeterminate Liability?

1. The Plaintiff, Richard N. Bell, took photograph of the Indianapolis Skyline in

Form F5 Change of Information in Form F4 General Instructions

Introductory Guide to Civil Litigation in Ontario

Broadcasting Notice of Consultation CRTC

PRIVACY DURING A HEARING: ACCESS TO TRIBUNAL DOCUMENTS

McNeil Disclosure Packages

CANADIAN INTERNET LAW UPDATE 2017

Privacy and the Workplace. David T.S. Fraser The Canadian Institute May 2007

Definitions The following terms have these meanings in this Policy: a. Act Personal Information Protection and Electronic Documents Act;

NEWFOUNDLAND AND LABRADOR OFFICE OF THE INFORMATION AND PRIVACY COMMISSIONER

Order F Ministry of Justice. Hamish Flanagan Adjudicator. March 18, 2015

PEl Government Introduces Long-Awaited Lobbying Law - Strong Enforcement, but Many Gaps. Includes rare exemption for lawyers who lobby

DISCIPLINE COMMITTEE OF THE COLLEGE OF NURSES OF ONTARIO. PANEL: CATHY EGERTON, Public Member Chairperson

Batty v City of Toronto: Municipalities at Forefront of Occupy Movement

2017 REVIEW OF THE FREEDOM OF INFORMATION AND PROTECTION OF PRIVACY ACT (FIPPA) COMMENTS FROM MANITOBA OMBUDSMAN

The New Canadian Tort of Invasion of Privacy DAVID DEBENHAM

Case 1:18-cv TWP-DML Document 1 Filed 01/06/18 Page 1 of 10 PageID #: 1

FERTILIZER CANADA BUSINESS PRINCIPLES AND CODE OF CONDUCT

D ISPUTE R ESOLUTION MAREVA INJUNCTIONS CAN STOP FRAUDSTERS COLD

Citizenship Policy Manual CP 1. Citizenship Lines of Business

Scotia Plaza 40 King St. West, Suite 5800 P.O. Box 1011 Toronto, ON Canada M5H 3S1 Tel Fax

BODY ARMOUR CONTROL ACT

February 23, Dear Ms. Ursulescu, Re: Legislative Model for Lobbying in Saskatchewan

DISCIPLINE COMMITTEE OF THE COLLEGE OF PHYSICIANS AND SURGEONS OF ONTARIO COLLEGE OF PHYSICIANS AND SURGEONS OF ONTARIO. - and - MARTIN JUGENBURG

Order F16-25 BC SECURITIES COMMISSION. Elizabeth Barker Senior Adjudicator. May 17, 2016

Case 1:18-cv JMS-MJD Document 1 Filed 06/11/18 Page 1 of 8 PageID #: 1

Regulation of Controlled Defence Goods and Technology in Canada and Conflicts with U.S. ITAR John W. Boscariol

Law Enforcement Request for Personal Information Procedures - What to do When a Police Officer Asks for Information

Proxy Access and Proposed Legislative Amendments - Supplemental Submission

ACCESS, OPENNESS, ACCOUNTABILITY: A Guide to the Newfoundland and Labrador Registry of Lobbyists

FEDERAL COURT PRACTICE AND ARREST OF SHIPS

Privacy, Policy and Public Opinion in Canada

OBSERVATION. TD Economics A DEMOGRAPHIC OVERVIEW OF ABORIGINAL PEOPLES IN CANADA

Restitution Repairing Financial Harm to Victims of Crime

ONTARIO SUPERIOR COURT OF JUSTICE DIVISIONAL COURT FERRIER, SWINTON & LEDERER JJ. ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) Applicant.

Rugby Ontario Policy Manual

DEPARTMENT OF JUSTICE CANADA MINISTÈRE DE LA JUSTICE CANADA

Memorandum of Understanding between SAMPLE. Toronto Police Service (hereinafter called the "Service") and. (hereinafter called the "Agency")

Keith Pridgen and Steven Pridgen (applicants) v. The University of Calgary (respondent) ( ; 2010 ABQB 644)

Order F12-12 MINISTRY OF JUSTICE. Catherine Boies Parker, Adjudicator. August 23, 2012

T-Mobile Transparency Report for 2013 and 2014

Pension Arbitration Trumped by Class Proceeding Legislation

Education Law Newsletter

Form F5 Start-up Crowdfunding Funding Portal Individual Information Form

Re Rao. The Dealer Member Rules of the Investment Industry Regulatory Organization of Canada (IIROC)

Application for a Public Accountant Licence

Lex Mundi Data Privacy Guide: Focus on the Asia/Pacific Region

Information Sharing Protocol

Nestlé Canada Inc. Privacy Policies and Practices April 13, 2012

This booklet may not be commercially reproduced, but copying for other purposes, with credit, is encouraged.

Health Care Consent Act

Privacy, personal information, law enforcement and lawful access

RISK MANAGEMENT CODE OF CONDUCT

IN THE SUPREME COURT OF BRITISH COLUMBIA

5.1.6 Form F5 Personal Information Form and Authorization to Collect, Use and Disclose Personal Information

Be it enacted by the General Assembly of the Commonwealth of Kentucky: Section 1. KRS is amended to read as follows:

Type of law: CRIMINAL LAW. A 2015 Alberta Guide to the Law TRAFFIC OFFENCES. Student Legal Services of Edmonton

IN THE PROVINCIAL COURT OF BRITISH COLUMBIA

Balancing Privacy Interests of an Incapable Person with the Responsibilities of Attorneys, Guardians and Section 3 Counsel. By Justin W.

WORKERS COMPENSATION APPEALS TRIBUNAL PRACTICE MANUAL

Five questions about blowing the whistle

IN THE QUEEN'S BENCH JUDICIAL CENTRE OF REGINA. -and-

E-HEALTH (PERSONAL HEALTH INFORMATION ACCESS AND PROTECTION OF PRIVACY) ACT

Security Video Surveillance Policy

THE FEDERAL LOBBYISTS REGISTRATION SYSTEM

Beyond Disability Accommodating Family Status and Religion

Claims for Misfeasance in Public Office: A Brief Summary

Securities Transfer Association of Canada

IN THE SUPREME COURT OF BRITISH COLUMBIA

Proposed Amendments to Section 35 (No actions against the Corporation) of MFDA By-Law No. 1 MUTUAL FUND DEALERS ASSOCIATION OF CANADA

CANADIAN ANTI-SPAM LAW [FEDERAL]

w21carcv& BYLAW NO TOWN OF VEGREVILLE TOWN OF

Consistency with the New Zealand Bill of Rights Act 1990: Children, Young Persons, and Their Families (Oranga Tamariki) Legislation Bill

Transcription:

Privacy Law Update Ontario Connections: Access, Privacy, Security & Records Management Conference, June 7, 2016 David Goodis, Information and Privacy Commissioner of Ontario Lyndsay Wasser, McMillan LLP McMillan LLP Vancouver Calgary Toronto Ottawa Montréal Hong Kong mcmillan.ca

Disclosure to Children s Aid Society de Pelham v Peel Regional Police 2015 ONSC 6558 CAS advise police of presence of potential caregiver in home where vulnerable foster child placed police tell CAS he had pending criminal charges [drug, gun] he claims disclosure violated MFIPPA IPC says permitted under: Child and Family Services Act [s. 72 duty to disclose for harm prevention] MFIPPA [s. 32(e) disclosure under another statute] Divisional Court upholds IPC (on both substantive and Legislative privilege grounds) mcmillan.ca l 2

Privacy Torts John Stevens v Glennis Walsh, 2016 ONSC 2418 Pilot accessed work schedule of colleague who was in divorce proceedings and provided information to the ex-wife Intrusion upon seclusion Damages - 1,500 T.K.L. v. T.M.P., 2016 BCSC 789 Step-father surreptitiously recording step daughter in bedroom and bathroom Statutory tort under Privacy Act, R.S.B.C., 1996, c.373 Damages - $85,000 (general and aggravated) mcmillan.ca l 3

Privacy Torts Jane Doe 464533 v. N.D Former boyfriend posted intimate video online New Privacy Tort Public Disclosure of Private Facts/Publicity Given to Private Life Giving publicity to a matter concerning the private life of another person If the matter publicized or the act of publication would be highly offensive to a reasonable person and is not of legitimate concern to the public Damages - $100,000 plus costs mcmillan.ca l 4

Video Surveillance Halton Catholic District School Board [MC13-46] privacy complaint about school s use of video surveillance IPC finds board failed to demonstrate volume, scope of PI collected was necessary [MFIPPA s. 28(2)] IPC recommends board conduct assessment of system in a manner consistent with MFIPPA, the board s internal policy and the report Toronto Catholic District School Board [MC13-60] similar complaint to above but, based on the evidence, collection of images within school property permitted under MFIPPA although capturing of images outside school property not lawful IPC recommends board adjust cameras to blur off-site images, revise notice of collection and its policies mcmillan.ca l 5

Charter Cases Telus & Rogers Tower Dump case Police request for 40,000 call detail records from cell phone tower Names, numbers, addresses, banking details Far beyond what was reasonably necessary to gather evidence concerning the commission of the crimes under investigation Contrary to Section 8 of the Canadian Charter of Rights and Freedoms i.e., The right to be secure against unreasonable search or seizure Guidelines for police and courts to follow in future mcmillan.ca l 6

Privacy and text messages R v Pelucco 2015 BCCA 370 police seize phone of potential drug buyer (Guray), use it to solicit drugs from dealer (Pelucco) when P arrives by car, police seize phone, with the text messages, and cocaine/other drugs on appeal, Crown argues P had no reasonable expectation of privacy in sent text messages, since G could have chosen to share them with anyone BCCA (majority): sender normally will have a reasonable expectation that text will remain private in hands of recipient [Charter s. 8] P was entitled to expect police would not search messages on G s phone without authorization police violated P s reasonable expectation of privacy mcmillan.ca l 7

Class Actions Ashley Madison Data breach affecting 30 to 40 million users of website Class action lawsuit claiming $750 million in damages Breach of contract Breach of Ontario Consumer Protection Act Negligence Intrusion upon seclusion Publicity given to private life Breach of Privacy To what extent will Canadian courts impose liability on organizations that have been victims of criminal activity, such as cyberattacks? mcmillan.ca l 8

Class Actions The Bank of Nova Scotia case Employee of bank provided personal information to girlfriend for fraudulent purposes 165 suffered identity theft Big question: Would bank be held vicariously liable? If it settles, we will not know Proposal to offer $1.55 million divided among some of the claimants Currently waiting to see if the settlement will be approved mcmillan.ca l 9

Background checks for public servants union representing federal workers challenges new security screening process for employees new process includes fingerprinting, credit and criminal checks, searches of public information (including social media) check required to obtain basic reliability status needed to be federal employee replaces a 1994 standard which collected less information for entry-level clearance mcmillan.ca l 10

Background checks for public servants union files Federal Court application, claims new check violates Charter s. 7, federal Privacy Act union also sought an interim injunction FC finds serious issue but union fails irreparable harm test for injunction government would face irreparable harm if checks halted, delay would not be in the public interest in ensuring Canada s national security, international interests, public trust in the public service but main FC application yet to be decided mcmillan.ca l 11

Statutory Changes The Digital Privacy Act - Amendments to PIPEDA 1. Definition of Personal Information 2. Changes to Consent 3. Collection, use and disclosure of employee personal information 4. Business transactions 5. Compliance agreements 6. Mandatory breach reporting (still not in force) mcmillan.ca l 12

Snooping into health records to date, IPC has referred six individuals to AG for PHIPA offence prosecution [s. 72] 2011: nurse at North Bay Health Centre 2015: two radiation therapists at Toronto s UHN 2015: social worker at a family health team 2016: registration clerk at a regional hospital 2016: regulated professional at a Toronto hospital mcmillan.ca l 13

Snooping into health records successful offence prosecutions two radiation therapists pled guilty to willfully collecting, using or disclosing personal health information in contravention of PHIPA [s. 72(1)(a)] each fined $2,000, $500 victim surcharge registration clerk pled guilty to same offence clerk agreed to $10,000 fine, $2,500 victim surcharge professional discipline nurses in North Bay and Peterborough suspended by College of Nurses of Ontario for four months each mcmillan.ca l 14

Online Behavioural Advertising Bell Case - Relevant Advertising Program (RAP) Considered reasonable expectations of customers Paid service Sensitive information Explicit opt-in consent required RAP also resulted in class action lawsuit Plaintiff s claiming $750 million mcmillan.ca l 15

Online Behavioural Advertising Guidelines on Privacy and Online Behavioural Advertising; Policy Position on Online Behavioural Advertising Conditions for relying upon opt-out consent Clear and understandable notice - Cannot be buried in a privacy policy Notice must outline purposes and parties involved Must be able to opt-out easily. Opt-out must take effect immediately and be persistent Can only collect and use non-sensitive information (not sensitive information e.g., medical or health information) Information must be destroyed or de-identified as soon as possible mcmillan.ca l 16

McMillan offices Vancouver Royal Centre, 1055 West Georgia Street Suite 1500, PO Box 11117 Vancouver, British Columbia Canada V6E 4N7 t: 604.689.9111 Ottawa World Exchange Plaza 45 O'Connor Street, Suite 2000 Ottawa, Ontario Canada K1P 1A4 t: 613.232.7171 Calgary TD Canada Trust Tower, Suite 1700 421 7 th Avenue S.W. Calgary, Alberta Canada T2P 4K9 t: 403.531.4700 Montréal 1000 Sherbrooke Street West Suite 2700 Montréal, QC Canada H3A 3G4 t: 514.987.5000 Toronto Brookfield Place, Suite 4400 181 Bay Street Toronto, Ontario Canada M5J 2T3 t: 416.865.7000 Hong Kong 3502 Tower 2 Lippo Centre 89 Queensway Hong Kong, China t: 852.3101.0213 McMillan LLP Vancouver Calgary Toronto Ottawa Montréal Hong Kong mcmillan.ca