1 Canadian Privacy Policy: Customizing E.U. Standards Remarks by Jennifer Stoddart Privacy Commissioner of Canada Privacy Symposium: Summer 2007 August.

Slides:



Advertisements
Similar presentations
1 Enforcement Powers of National Data Protection Authorities and Experience gained of the Data Protection Directive Safe Harbour Conference Washington.
Advertisements

Innovation and the Privacy Advantage Jennifer Stoddart, Privacy Commissioner of Canada August 25, 2010 Institute of Public Administration of Canada 62.
2.01C - Explain company selling policies.
ICP 25 CONSUMER PROTECTION Y. Priya Bharat. ICP 25: CONSUMER PROTECTION. Principle: Minimum requirements for Insurers and Intermediaries in dealing with.
Silicon Valley Apps for Kids Meetup Laura D. Berger October 22, 2012 The views expressed herein are those of the speaker, and do not represent the views.
Cross-border Data Flows and Privacy Reform Patrick Sefton | Principal, Brightline Lawyers.
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
Quebec City February 2005 PUBLIC SECTOR CIO COUNCIL BC - USA Patriot Act Update.
London, England 7-8 July 2011 International Congress on Professional and Occupational Regulation Fairness in Canadian Public Policy and its Effect on Registration.
CSE2500 Systems Security and Privacy Week 11 Privacy Law in Australia (after 2000)
Mark S. Hayes – Blake, Cassels & Graydon LLP Privacy and Security – Some Observations Mark S. Hayes, Blake, Cassels & Graydon LLP 7th CACR Privacy and.
Insights on the Legal Landscape for Data Privacy in Higher Education Rodney Petersen, J.D. Government Relations Officer and Security Task Force Coordinator.
© 2003 IBM Corporation Privacy 12 th CACR Workshop Yim Y. Chan Chief Privacy Officer & CIO IBM Canada Ltd. w3.ibm.com/Privacy.
Managing Personal Information - Australian Companies Outsourcing to India and the Philippines Professor Margaret Jackson and Marita Shelly.
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
Privacy in Ontario Brian Beamish Office of the Information and Privacy Commissioner/Ontario Presentation to Security Canada Central 2002 International.
The role of the Office of the Privacy Commissioner in telecommunications Andrew Solomon Director, Policy.
Internet and Information Technology Law September 18 th – Privacy Law Allyson Whyte Nowak UVIC.
Lecture to Carleton University, Center for European Studies, December 1, 2010.
1 Office of theCommissariat Privacy Commissionerà la protection de of Canadala vie privée du Canada Personal Information Protection and Electronic Documents.
What if my organization conducts business across borders ? Your footnote Privacy and “Personal Information” have different meanings in different countries;
PRIVATE SECTOR PRIVACY LEGISLATION The New Private Sector Privacy Regime Presented by Christopher Lee.
A NEW GOVERNANCE PARADIGM: Canadian Privacy Law Developments March 11, 2004 Haliburton, Ontario Canada Volunteerism Initiative Arts Council for Haliburton.
Taking Steps to Protect Privacy A presentation to Hamilton-area Physiotherapy Managers by Bob Spence Communications Co-ordinator Office of the Ontario.
Understanding Privacy Breach Risk: Ontario Universities Risk Management Symposium Presented by Brian Rosenbaum LL.B. Director, Legal and Research Practice.
CASA & CCEL Webinar Series 9. PRIVACY & OLDER ADULTS Aging and The Law: What Every Professional Needs To Know.
Using Technology in Nursing Practice: Part 1: Complying with Policy 1.
One Size Fits All Data Protection in New Zealand: Processes and Outcomes Gehan Gunasekara & Erin Dillon.
1 9. PRIVACY & OLDER ADULTS Faculty : Laura Watts, LL.B., National Director, CCEL Aging and The Law : Professional Issues Level 1 Webinar #9 Canadian Academy.
LegalTech Asia DATA PRIVACY LAWS UPDATE Edward Chatterton 4 March 2013.
Name of presenter(s) or subtitle Privacy laws and their impact on research David W. Stark MRIA B.C. Chapter November 2, 2005.
Forgetting, Non-Forgetting and Quasi-Forgetting: Public Policy and Corporate Practice Colin J. Bennett, Adam Molnar and Christopher Parsons Department.
David W. Stark Name of presenter(s) or subtitle MRIA Alberta Chapter
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
Privacy: It’s just good business
CLOUD AND SECURITY: A LEGISLATOR'S PERSPECTIVE 6/7/2013.
Building User Trust Online Sarah Andrews International Conference on the Legal Aspects of an E-Commerce Transaction The Hague October 2004.
Florida Information Protection Act of 2014 (FIPA).
Privacy & Personal Information Prepared by the CBC Law Department CONFIDENTIAL – FALL 2011.
The European influence on privacy law and practice Nigel Waters, Pacific Privacy Consulting International Dimension of E-commerce and Cyberspace Regulation.
Part 6 – Special Legal Rights and Relationships Chapter 35 – Privacy Law Prepared by Michael Bozzo, Mohawk College © 2015 McGraw-Hill Ryerson Limited 34-1.
Financial Services Privacy - the interaction of the privacy and financial services regulatory systems Chris Connolly Financial Services Consumer Policy.
A Perspective: Data Flow Governance in Asia Pacific & APEC Framework Martin Abrams October 21, 2008.
Initial reflections of the privacy commissioner on Ontario’s draft privacy bill Ann Cavoukian, Ph.D. Information and Privacy Commissioner/Ontario Toronto.
Privacy Professional Practice for Computer Science Guest Lecture, 05 March 2007 Philippa Lawson Director, Canadian Internet Policy & Public Interest Clinic.
CORPORATE STRUCTURING AND BASIC TAX CONSIDERATIONS.
Governing the Corporation Conference Queen’s University, Belfast 21 September 2004.
Robert Guerra Director, CryptoRights Foundation Implementing Privacy Implementing Privacy: Rules of the Game for Developers Mac-Crypto Conference on Macintosh.
PIPEDA and Receivables Management Robin Gould-Soil Receivables Management Association of Canada November 16, 2011.
BC Public Libraries November, 2008 Privacy Principles.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
Privacy Advisory Services … … A Best Practices, Integrated Approach Insert Firm Name Here.
By Dr. Viljar Peep by Dr. Viljar Peep Director General Estonian Data Protection Inspectorate Transparency and Privacy in Public Sector EUROPEAN.
1 Copyright © International Security, Trust & Privacy Alliance -All Rights Reserved Making Privacy Operational International Security, Trust.
Fred Carter Senior Policy & Technology Advisor Information and Privacy Commissioner Ontario, Canada MISA Ontario Cloud Computing Transformation Workshop.
Privacy Information for Advisors. Agenda PIPEDA Advisor Required Privacy Program Our MGA Privacy Program Recommendations for Advisors.
Privacy Issues - Watch Out! John D.R. Craig ORIMS Professional Development Day March 19, 2013.
CYBERSECURITY: RISK AND LIABILITY March 2, 2016 Joshua A. Mooney Co-chair-Cyber Law and Data Protection White and Williams LLP (215)
TASFAA 2016 Legacy of Leadership. TASFAA 2016 Legacy of Leadership Family Educational Rights and Privacy Act (FERPA) An Overview Molly Thompson Associate.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Data protection—training materials [Name and details of speaker]
Key Points for a Privacy Programme for Multinationals Steve Coope.
The Health Information Protection Act. What is the Health Information Protection Act (HIPA)? HIPA is legislation that speaks to access to, and protection.
Pioneers in secure data storage devices. Users have become more accustomed to using multiple devices, are increasingly mobile, and are now used to storing.
PRIVACY TRAINING For CAILBA members
Closing Remarks and Next Steps
Employee Privacy and Privacy of Employee Information
Analysis of Privacy and Data Protection Laws and Directives
Mandatory Breach Reporting (isn’t *that* bad)
On the Cutting Edge – Update on Privacy Legislation
Presentation transcript:

1 Canadian Privacy Policy: Customizing E.U. Standards Remarks by Jennifer Stoddart Privacy Commissioner of Canada Privacy Symposium: Summer 2007 August 23, 2007

2 Personal Information Regulation in Canada Fair information/OECD principles became law: Personal Information Protection and Electronic Documents Act (PIPEDA) Civil and common law

3 Characteristics Adequate for E.U Applies to all handling of personal information by federally regulated commercial entities in Canada affecting Canadians Applies outside of Canada if personal information outsourced for processing, other uses (Abika case)

4 Characteristics Unlike E.U in: –No registration of databases –No prior approval for export of personal information –No restrictions on whistle blowing legislation

5 Characteristics Enforcement through multi-functional approach Federally –Ombudsman (Agent of Parliament) –Investigate complaints –Mediation –Audits –Education –Outreach –Federal court litigation (damages) Substantially similar provinces –Tribunals (no damages)

6 Substantially Similar Principle Quebec (1994) Alberta (2004) B.C. (2004) Ontario (Health, 2004)

7 Substantially Similar Provinces PIPEDA applies when: –Organization handling personal information is federally regulated, e.g., banks, airlines –Sending personal information from Canada elsewhere or across provincial borders –Federally regulated employee information

8 Criteria Appropriate consent for collection/use/disclosure Opt-in (express) – sensitive Opt-out (implied) – reasonable test

9 When You Export Personal Information… Exporting personal information outside Canada PATRIOT Act Concerns Finding #313 (CIBC VISA) Finding #365 (SWIFT)

10 When You Use Personal Information… Direct marketing practices –Finding #308 (Inserts) –Finding #297 ( s) –Finding #271 (Solicitations)

11 When Your Entity Markets in Canada… Can be situated outside Canada Abika case TJX case and federal/provincial enforcement

12 Security PIPEDA includes security principle in section 7 Data Breach Guidelines Recommend mandatory notification in law

13 International Co-operation in Enforcement OPC with FTC and others OECD Recommendation on Cross-border Co-operation in the Enforcement of Laws Protecting Privacy, 2007

14 PIPEDA Enforcement: % of complaints settled 26 letters of recommendation (e.g. financial institutions, insurance companies, law firms, real estate firms) 2 audits, e.g., Equifax No OPC initiated actions in Federal Court

15 Conclusion Flexible compliance approach Same standards as E.U. Extra-territorial reach International enforcement framework

16 29 th International Data Protection and Privacy Commissioners Conference

17 THANK YOU! Questions?