Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada April 21, 2008, Montreal, QC Online privacy and identity.

Slides:



Advertisements
Similar presentations
Chapter 3 The American Judicial System, Jurisdiction, and Venue
Advertisements

Office of the Information and Privacy Commissioner, Ontario, Canada
TECHNO-TONOMY Privacy & Autonomy in a Networked World Learning Module 2: Legislating Privacy: Your Rights.
NIXON PEABODY LLP 1 Understanding the Marketing Restrictions of HIPAA Leigh-Ann M. Patterson Nixon Peabody LLP 101 Federal Street Boston, MA (617)
Advanced Issues in HIPAA Research Compliance The Sixth National HIPAA Summit March 27, 2003 Kim P. Gunter Senior Consultant.
Assurance Services Independent professional services that “improve the quality of information, or its context, for decision makers” Assurance service encompass.
12-1 Chapter 12 Advanced EHR Functionality © 2012 The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill.
1 Copyright © 2010, Elsevier Inc. All rights Reserved Fig 2.1 Chapter 2.
Refugee Protection Division Navigating the Sea of Change – Refugee Lawyers Group CLE 2013.
Using Family Connection On-line Resource for Planning & Advising Overview for Parents Brien McMahon High School Guidance Department
1 SOURCES AND SCOPE OF COMMUNITY LAW Michele Colucci Web site: PARMA 8-9 November.
WHO Good Distribution Practices for Pharmaceutical Products
1 Targeted Case Management (TCM) Changes Iowa Medicaid Enterprise October 14, 2008.
0 - 0.
Addition Facts
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
Red-Flag Identity Theft Requirements February 19th 2009 Cathy Casagrande, Privacy Officer.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
Human Capital Investment Programme Disability Activation Project (DACT) WELCOME Support Workshop Thursday 7 th February
Reinsurance Regulation in Australia an overview
Does Debt Policy Matter?
Mobile Payments and the FTC Manas Mohapatra Director of Mobile Policy Mobile Technology Unit Federal Trade Commission The views expressed are not necessarily.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
McGraw-Hill/Irwin Copyright © 2007 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter Eleven Cost Behavior, Operating Leverage, and CVP Analysis.
Red Flags Rule BAS Forum August 18, What is the Red Flags Rule? Requires implementation of a written Identity Theft Prevention Program designed.
1.7.6.G1 © Family Economics & Financial Education –March 2008 – Financial Institutions – Online Banking – Slide 1 Funded by a grant from Take Charge America,
HITECH ACT Privacy & Security Requirements Cathleen Casagrande Privacy Officer July 23, 2009.
M&A International™ – the world's leading M&A alliance Common Errors in Business Valuation and How to Avoid Them April 8, 2013 Howard E. Johnson, MBA, FCPA,
1 The Data Protection Officer at work Experience, good practices and lessons learnt Pierre Vernhes – former DPO at the Council of the EU Workshop on Data.
Addition 1’s to 20.
Test B, 100 Subtraction Facts
© 2014, The McGraw-Hill Companies, Inc. All Rights Reserved. capitolo 4 Ascoltiamo! La famiglia italiana oggi p. 107 Cultura © 2014, The McGraw-Hill Companies,
Week 1.
1 Revenue Update Jody M. Wagner Secretary of Finance Commonwealth of Virginia
The Problem Solvers TM Privacy Rights: Minors and Parents Michael J. Hewitt Marcel Daigle Singleton Urquhart LLP.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
Ethical Issues in Data Security Breach Cases Presented by Robert J. Scott Scott & Scott, LLP
The role of the Office of the Privacy Commissioner in telecommunications Andrew Solomon Director, Policy.
1 Office of theCommissariat Privacy Commissionerà la protection de of Canadala vie privée du Canada Personal Information Protection and Electronic Documents.
Information Privacy Policy in Canada Presented By: Sue Wu.
Investigating & Preserving Evidence in Data Security Incidents Robert J. Scott Scott & Scott, LLP
P A R T P A R T Regulation of Business Administrative Agencies The Federal Trade Commission Act and Consumer Protection Laws Antitrust: The Sherman Act.
APPLICATION FOR ACCESS (PAIA) Mandatory protection (which must be refused in terms of Chap 4 subject to S46) DENIAL OF ACCESS (PAIA) Internal Appeal to.
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
Web Awareness: Knowing the Issues Web Awareness: Knowing the Issues © Media Awareness Network 2000.
Internal Investigations: A primer Bob Cooper May 30, 2007.
Part 6 – Special Legal Rights and Relationships Chapter 35 – Privacy Law Prepared by Michael Bozzo, Mohawk College © 2015 McGraw-Hill Ryerson Limited 34-1.
The DoubleClick controversy and other related issues pertaining to privacy on the Internet.
BEHAVIORAL TARGETING IN ADVERTISING By Rita Aliperti.
AICP New England 13 th Annual Education Day PRIVACY Jenny Erickson Vice President, Legislative and Regulatory Affairs The Life Insurance Association of.
Copyright © 2005 Pearson Education Inc. Marketing in the Digital Age Chapter 3 PowerPoint slides Express version Instructor name Course name School name.
1 Canadian Privacy Policy: Customizing E.U. Standards Remarks by Jennifer Stoddart Privacy Commissioner of Canada Privacy Symposium: Summer 2007 August.
28/01/20161 The Future of Online Privacy: Online advertising and behavioral targeting Kristina Irion Third Internet Governance Forum Thursday, 5/12/2008.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
External Threats Internal Threats Nation States Cyber Terrorists Hacktivists Organised criminal networks Independent insider Insider planted by external.
Practical Analysis of Obstacles Encountered by Legal Services as Part of Access to Information Requests Presentation to the Canadian Institute at the Conference.
Data Breach ALICAP, the District Insurance Provider, is Now Offering Data Breach Coverage as Part of Our Blanket Coverage Package 1.
JOHN M. HUFF NAIC PRESIDENT DIRECTOR, MISSOURI DEPARTMENT OF INSURANCE JUNE 16, 2016 NAIC CYBERSECURITY INITIATIVES.
Canada’s Breach Reporting Law What you need to know Timothy M. Banks, CIPP/C Dentons Canada LLP July 21, 2015.
Combating Identity Fraud In A Virtual World
Privacy principles Individual written policies
Privacy principles Individual written policies
GENERAL DATA PROTECTION REGULATION (GDPR)
The activity of Art. 29. Working Party György Halmos
Upcoming PIPEDA Changes
The Freedom of Information and Data Protection Legislation An Overview
Presentation transcript:

Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada April 21, 2008, Montreal, QC Online privacy and identity A regulatory bodys perspective

2 Internet Use and the Norm o$50 million in sales to Canadians o10 million Canadians use social networking sites o1 million Canadians visit Second Life each week oOver $1 billion in revenue from online advertising Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

3 Issues for the OPC oEnforcing the law in a virtual environment oEnforcing Canadian standards in a global context Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

4 Personal Information Online oConsumption oFinancial institutions oCarelessness of Internet users o25% use privacy settings o3% adjust their cookies Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

5 Educating the Public oBlogs oProtecting yourself when using social networking sites Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

6 Ads Targeted at Consumers oMarketing value oOnline profiling is becoming more accurate oGoogles acquisition of DoubleClick Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

7 Federal Trade Commission oProposed Online Behavioral Advertising Privacy Principles December 2007 oDifferent from Canada Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

8 Jurisdiction in the Virtual World oLawson v. Accusearch Inc. (F.C.), 2007 FC 125 oReal and substantial connection because much of the data came from Canada/was about a Canadian oThe issue of being able to effectively carry out an investigation is separate from the issue of having jurisdiction to investigate Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

9 Outcome oSites that are accessible from Canada may fall under the OPCs jurisdiction for investigations oThese sites must comply with PIPEDA Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

10 PIPEDA Standards oThe Streetview caseGoogle oThe Ticketmaster case oThe private life of avatars Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

11 International Cooperation is Essential oFTC oCooperation oPossibility of intervening in Accusearch Inc.s appeal to the U.S. Tenth Circuit Court of Appeals oOECD oGuidelines on the Protection of Privacy and Transborder Flows of Personal Data Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

12 The Influence of Canadian Standards- TJX oAlberta-Federal investigation oPublic findings oLoss of $60.8 million to date oA reserve fund of $178.1 million set up by TJXthis represents an estimate of total losses Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

13 Security of Personal Information oIdentity theft/false pretence oBill C-27 (An Act to Amend the Criminal Code) oRecklessness as to subsequent use of identity information o…being reckless Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

14 Review PIPEDA oProvision on data breach notification oA clear definition of triggers and thresholds for notification is essential oTwo-step approach: (i) notify those affected by a loss of personal information where there is a high risk of significant harm; and (ii) have a requirement that the OPC be advised of any major loss or theft oOPCneed for objective information on the extent and cause of losses Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

15 Identity in Context oGordon v. Canada (Health)(2008 FC 258) oInformation will be about an identifiable individual where there is a serious possibility that an individual could be identified through the use of that information, alone or in combination with other available information. Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

16 Conclusion oCanada oEuropean standards oIndividuals: right/choice regarding protection of their personal information oMultinational companies must ensure they comply with PIPEDA online Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada

17 Conclusion oPrivacy, continually redefined oWyndowe v. Rousseau (2008 FCA 39) oAn individual has a right of access to the information he or she provides in the context of an independent medical exam performed by a third-party doctor and to the final opinion of the doctor oPrivacy Commissioner v. Blood Tribe Department of Health (SCC decision pending) oReview of solicitor-client privileged documents Office of the Privacy Commissioner of Canada Commissariat à la protection de la vie privée du Canada