The Canadian Privacy Law Blog: Developments in privacy law and writings of a Canadian privacy lawyer, containing information related to the Personal Information Protection and Electronic Documents Act (aka PIPEDA) and other Canadian and international laws.
The author of this blog, David T.S. Fraser, is a Canadian privacy lawyer who practices with the firm of McInnes Cooper. He is the author of the Physicians' Privacy Manual. He has a national and international practice advising corporations and individuals on matters related to Canadian privacy laws.
For full contact information and a brief bio, please see David's profile.
The views expressed herein are solely the author's and should not be attributed to his employer or clients. Any postings on legal issues are provided as a public service, and do not constitute solicitation or provision of legal advice. The author makes no claims, promises or guarantees about the accuracy, completeness, or adequacy of the information contained herein or linked to. Nothing herein should be used as a substitute for the advice of competent counsel.
This web site is presented for informational purposes only. These materials do not constitute legal advice and do not create a solicitor-client relationship between you and David T.S. Fraser. If you are seeking specific advice related to Canadian privacy law or PIPEDA, contact the author, David T.S. Fraser.
Saturday, January 08, 2005
David Canton, of eLegal Canton fame, is a regular contributor to the London Free Press. In today's business section, David recommends that all businesses need to adopt a "culture of privacy" to prevent the sorts of privacy fiascos that we have seen in the last few months:
London Free Press: Business Section - Privacy culture necessary:
"Just when you thought your bank and government have your privacy interests protected -- think again. Recent privacy gaffs show privacy breaches can happen despite the best intentions of business or government.
Protection of privacy rights is not an automatic concern for many. However, people are becoming more aware of the repercussions of not having privacy top of mind....
And perhaps most importantly, create a culture of privacy within your organization. All organizations will have a chief privacy officer, but that person alone cannot do the job. All employees should understand the importance of keeping certain information confidential."
I couldn't agree more. So many of the high-profile screwups and a huge portion of the negative findings of the Office of the Privacy Commissioner stem from employees not having privacy at the top of their minds. In my experience, the lack of privacy culture leads directly to non-compliance or to not dealing with the incident properly when it comes to the company's attention.
The best example of this is an incident that happened in Ontario in 2003. If memory serves (the media reports about it are no longer online), a woman was suspecting that her spouse was having an affair. So she calls his cellphone company [the phone was not in her name] and says, essentially, "Hi, this is Mrs. Smith. I'm doing the bills and I don't know what all these charges are. Can you fax me the calling details for the last few months so I can figure these out?" The customer service person, thinking that s/he was providing the best customer service possible, says "sure thing!" and faxes them right over. So the list of numbers leads to the mistress, causing all sorts of problems for both the mistress and the ex-husband. The ex-husband gets upset and goes to the media with the story of how his phone company violated his privacy.
So, what went wrong? The customer service representative didn't think about privacy. S/he may have known about the company's policy of not disclosing this sort of information to anyone who is not listed on the account, but s/he was not thinking about privacy in a meaningful way. She sould have told the inquiring spouse that "at XYZ cellular, we respect our customers' privacy. You're not listed on the account, so I can't send you that information. Please have Mr. Smith give is a call to add you to the account, so you can get this information now and in the future, of ask Mr. Smith to request the information directly." But she didn't. As a result, her company's name was dragged through the mud.
Customer privacy needs to be the first thing your employees think about.
Labels: information breaches
The Canadian Privacy Law Blog is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 2.5 Canada License.