Cloud Computing: Privacy & Jurisdiction from a Canadian Perspective
|
|
|
- Asher Lewis
- 10 years ago
- Views:
Transcription
1 Cloud Computing: Privacy & Jurisdiction from a Canadian Perspective Professor Michael Geist Canada Research Chair in Internet and E-commerce Law University of Ottawa, Faculty of Law
2 Cloud Computing - Canada Competitive advantage? Climate: reduced energy costs Infrastructure: networks running north Geography: proximity to U.S. Legislative: national privacy legislation
3 Canadian Privacy 101 National privacy legislation takes effect in 2004; sub similar provincial rules in BC, Alta, Quebec Privacy Commissioner - ombuds power but has proven effective (Facebook) Consent requirements for collection, use, disclosure Security and safeguard requirements Accountability principle - collector responsible regardless of location, future uses Access requirements
4 Privacy Meets Jurisdiction B.C. Outsourcing Case Not strictly a cloud computing issue, but puts outsourcing, jurisdictional concerns on the map BC Gov t plan to outsource health management data - U.S. companies likely RFP winners Concerns focus on USA Patriot Act (non-disclosed disclosure) Quickly expands - NSA letters, grand jury, etc. Provincial privacy consultation
5 Privacy Meets Jurisdiction B.C. Outsourcing Case New legislation enacted targeted public sector outsourcing of personal information effectively prohibits export of citizen s data, with some exceptions (e.g., system upgrades or repair, with ministerial consent) All BC public bodies must ensure personal information stays in Canada and is accessed only in Canada Cannot disclose in response to foreign requests or demands This extends to service providers to public bodies Exceptions: other Canadian legislative authority; Canadian court order; installation, repair, upgrade, etc. of electronic systems or equipmentdisclosure also allowed by law enforcement agencies to foreign counterparts under an arrangement, written agreement or treaty
6 Other Patriot Act Cases LSAC Privacy complaint against LSAC for requiring fingerprint for test takers Object to mandatory collection of biometric data, transfer to the U.S. Commissioner rules in favor of complainants LSAC adjusts requirements in Canadian testing centers SWIFT Complaint re: transfer of banking information Not well-founded Law does not block outsourcing of data Banks ultimately responsible under accountability principle
7 Subsequent Cases - Web based Canada.com ( ) Major media organization switches management to U.S. Privacy Commissioner receives multiple complaints Rejects complaint The risk of a U.S.-based service provider being ordered to disclose personal information to U.S. authorities is not a risk unique to U.S. organizations. emphasizes the importance of organizations assessing the risks that could jeopardize the security and confidentiality of customer personal information when it is transferred to foreign-based third-party service providers. It is essential that organizations using third-party service providers outside Canada use contractual or other means to provide a comparable level of protection while the information is being processed by the third party.
8 Subsequent Cases - Web based Lakehead University v. CAUT University wishes to switch management to Gmail Faculty association objects - raises Patriot Act privacy concerns Case proceeds to arbitration University wins Privacy concerns arise regardless of whether data transferred to U.S. or remains in Canada
9 Subsequent Cases - Jurisdiction Abika Complaint against U.S. provider advertising access to personal info Privacy Commissioner refuses to investigate, claims no jurisdiction Judicial appeal of decision - orders Commissioner to investigate Well-founded finding - works with FTC in taking action Opens door to future cases - ie. Facebook
10 The Cloud Computing Consultation Privacy commissioner launches cloud computing consultation in Comments due by April 15, 2010 Roundtable scheduled for Calgary in June 2010 Includes panel on jurisdiction
11
Privacy Law in Canada
Privacy Law in Canada Federal and provincial privacy legislation has a profound impact on the way virtually all organizations carry on business across the country. Canada s privacy laws, while likely the
Privacy Law in Canada
by PATRICIA WILSON & MICHAEL FEKETE Protection of personal information remains at the forefront of public policy debate in. Federal and provincial privacy legislation has a profound impact on the way virtually
Cloud Computing: Privacy and Other Risks
December 2013 Cloud Computing: Privacy and Other Risks by George Waggott, Michael Reid and Mitch Koczerginski, McMillan LLP Introduction While the benefits of outsourcing organizational data storage to
Index All entries in the index reference page numbers.
Index All entries in the index reference page numbers. A Audit of organizations, 37-38, Access to personal information 162-163 by individual, 22, 31, 151-154 B assistance by organization, Biometrics, 123-125
The cloud thing: Privacy and cloud computing
The cloud thing: Privacy and cloud computing David T.S. Fraser ([email protected] / @privacylawyer) University of New Brunswick July 2011 Disclaimer What follows are the views of the author
CLOUD COMPUTING & THE PATRIOT ACT: A RED HERRING?
CLOUD COMPUTING & THE PATRIOT ACT: A RED HERRING? Lindsey Finch Senior Global Privacy Counsel Salesforce.com [email protected] David T.S. Fraser Partner McInnes Cooper [email protected]
INFORMATION SECURITY GUIDE. Cloud Computing Outsourcing. Information Security Unit. Information Technology Services (ITS) July 2013
INFORMATION SECURITY GUIDE Cloud Computing Outsourcing Information Security Unit Information Technology Services (ITS) July 2013 CONTENTS 1. Background...2 2. Legislative and Policy Requirements...3 3.
Data Management: Considerations for Integrating Compliance Requirements At Home and Abroad. Toronto, Ontario June 14, 2005
Data Management: Considerations for Integrating Compliance Requirements At Home and Abroad Toronto, Ontario June 14, 2005 Outsourcing Update: New Contractual Options and Risks Lisa K. Abe June 14, 2005
CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:
CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES: Privacy Responsibilities and Considerations Cloud computing is the delivery of computing services over the Internet, and it offers many potential
Protecting Saskatchewan data the USA Patriot Act
Protecting Saskatchewan data the USA Patriot Act Main points... 404 Introduction... 405 Standing Committee on Public Accounts motion... 405 Our response to the motion... 405 ITO, its service provider,
Cloud Computing: Trust But Verify
Cloud Computing: Trust But Verify 14th Annual Privacy and Security Conference February 8, 2013, Victoria Martin P.J. Kratz, QC Bennett Jones LLP Cloud Computing Provision of services available on the Internet
MICROSOFT OFFICE 365 PRIVACY IMPACT ASSESSMENT. Western Student E-Communications Outsourcing
MICROSOFT OFFICE 365 PRIVACY IMPACT ASSESSMENT Western Student E-Communications Outsourcing Paul Eluchok - University Privacy Officer David Ghantous - Associate Director of Technical Services Dated: August
Doing Business. A Practical Guide. casselsbrock.com. Canada. Dispute Resolution. Foreign Investment. Aboriginal. Securities and Corporate Finance
About Canada Dispute Resolution Forms of Business Organization Aboriginal Law Competition Law Real Estate Securities and Corporate Finance Foreign Investment Public- Private Partnerships Restructuring
Distributel Communications Limited. c/o Privacy Officer 177 Nepean St. Suite 300, Ottawa, ON, K2P 0B4. January 20, 2014
Distributel Communications Limited. c/o Privacy Officer 177 Nepean St. Suite 300, Ottawa, ON, K2P 0B4 January 20, 2014 Dear Distributel Privacy Officer: We are academic researchers and civil rights organizations
Taking care of what s important to you
A v i v a C a n a d a I n c. P r i v a c y P o l i c y Taking care of what s important to you Table of Contents Introduction Privacy in Canada Definition of Personal Information Privacy Policy: the ten
Accountable Privacy Management in BC s Public Sector
Accountable Privacy Management in BC s Public Sector Contents Accountable Privacy Management In BC s Public Sector 2 INTRODUCTION 3 What is accountability? 4 Steps to setting up the program 4 A. PRIVACY
The Manitoba Child Care Association PRIVACY POLICY
The Manitoba Child Care Association PRIVACY POLICY BACKGROUND The Manitoba Child Care Association is committed to comply with the legal obligations imposed by the federal government's Personal Information
The Use of Cloud Computing for the Storing and Accessing of Client Information: Some Practical and Ethical Considerations
The Use of Cloud Computing for the Storing and Accessing of Client Information: Some Practical and Ethical Considerations Jeffrey D. Scott Jeffrey D. Scott, Legal Professional Corporation Practice Advisors
Personal Information Protection Act ( PIPA ) Privacy-Proofing Your Retail Business Tips for Protecting Customers Personal Information 1
Personal Information Protection Act ( PIPA ) Tips for Protecting Customers Personal Information 1 More than ever before, retailers have to be prepared to deal with customers who ask questions about the
GENERAL INSURANCE STATISTICAL AGENCY
GENERAL INSURANCE STATISTICAL AGENCY Policy on Access to Information and Protection of Privacy APPROVED DEC 17, 2007 The General Insurance Statistical Agency (GISA) is committed to being a transparent,
Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries
Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries Sopra HR Software as a Data Processor Sopra HR Software, 2014 / Ref. : 20141120-101114-m 1/32 1.
COUNCIL OF THE EUROPEAN UNION. Brussels, 22 November 2006 15644/06 DATAPROTECT 45 EDPS 3
COUNCIL OF THE EUROPEAN UNION Brussels, 22 November 2006 15644/06 DATAPROTECT 45 EDPS 3 COVER NOTE from: Secretary-General of the European Commission, signed by Mr Jordi AYET PUIGARNAU, Director date of
Cloud Computing: Legal Risks and Best Practices
Cloud Computing: Legal Risks and Best Practices A Bennett Jones Presentation Toronto, Ontario Lisa Abe-Oldenburg, Partner Bennett Jones LLP November 7, 2012 Introduction Security and Data Privacy Recent
Insurance Journal. Defending Until the End When Does the Duty to. Volume 1, Issue 3 Editor Keoni Norgren. May 1, 2013
Insurance Journal May 1, 2013 In this Issue Volume 1, Issue 3 Editor Keoni Norgren Defending Until the End When Does the Duty to Defend End? Cyber Liability Laws in Canada Dolden Wallace Folick Welcomes
CANADIAN PRIVACY AND DATA RESIDENCY REQUIREMENTS. White Paper
CANADIAN PRIVACY AND DATA RESIDENCY REQUIREMENTS White Paper Table of Contents Addressing compliance with privacy laws for cloud-based services through persistent encryption and key ownership... Section
The USA Patriot Act Government Briefing. Kirsten Tisdale, Chris Norman, Sharon Plater & Alexandra (Gina) Henley September 30, 2004
The USA Patriot Act Government Briefing Kirsten Tisdale, Chris Norman, Sharon Plater & Alexandra (Gina) Henley September 30, 2004 Agenda Background Overview of Government Responses and Approach Mitigation
At TELUS we respect our customers privacy
At TELUS we respect our customers privacy We know you may have some questions about your privacy at TELUS. To help with those we developed this FAQ page. Please take a moment to familiarize yourself with
Protecting your privacy
Protecting your privacy Table of Contents Answering your questions about privacy Your privacy... 1 Your consent... 1 Answering your questions about privacy... 2 About cookies... 9 Behavioural Advertising/Online
We will not collect, use or disclose your personal information without your consent, except where required or permitted by law.
HSBC Privacy Notice HSBC's Privacy Principles HSBC Bank Canada is a subsidiary of HSBC Holdings plc which, together with its subsidiaries and affiliates, is one of the world s largest banking and financial
Common Student Information System for Schools and School Boards. Project Summary
for Schools and School Boards May 2007 Table of Contents 1. Executive Summary...... 3 2. Project Background, Rationale, Benefits and Scope... 4 3. Procurement Process... 8 4. The Final Agreement. 10 5.
3. Consent for the Collection, Use or Disclosure of Personal Information
PRIVACY POLICY FOR RENNIE MARKETING SYSTEMS Our privacy policy includes provisions of the Personal Information Protection Act (BC) and the Personal Information Protection and Electronic Documents Act (Canada),
Act CLXV of 2013. on Complaints and Public Interest Disclosures. 1. Complaint and public interest disclosure
Act CLXV of 2013 on Complaints and Public Interest Disclosures The National Assembly, committed to increasing public confidence in the functioning of public bodies, recognising the importance of complaints
POLICE RECORD CHECKS IN EMPLOYMENT AND VOLUNTEERING
POLICE RECORD CHECKS IN EMPLOYMENT AND VOLUNTEERING Know your rights A wide range of organizations are requiring employees and volunteers to provide police record checks. Privacy, human rights and employment
Using AWS in the context of Australian Privacy Considerations October 2015
Using AWS in the context of Australian Privacy Considerations October 2015 (Please consult https://aws.amazon.com/compliance/aws-whitepapers/for the latest version of this paper) Page 1 of 13 Overview
Privacy Risk Assessments
Privacy Risk Assessments Michael Hulet Principal November 8, 2012 Agenda Privacy Review Definition Trends Privacy Program Considerations Privacy Risk Assessment Risk Assessment Tools Generally Accepted
Cloud Computing Contracts. October 11, 2012
Cloud Computing Contracts October 11, 2012 Lorene Novakowski Karam Bayrakal Covering Cloud Computing Cloud Computing Defined Models Manage Cloud Computing Risk Mitigation Strategy Privacy Contracts Best
British Columbia Personal Information Protection Act. Frequently Asked Questions:
British Columbia Personal Information Protection Act Frequently Asked Questions: (Further queries may be sent to Bob Stewart at the B.C. Conference Archives.) (1) What is the Personal Information Protection
A Guide to Ontario Legislation Covering the Release of Students
A Guide to Ontario Legislation Covering the Release of Students Personal Information Revised: June 2011 Ann Cavoukian, Ph.D. Information and Privacy Commissioner, Ontario, Canada Commissioner, Ontario,
PRIVACY NOTICE. Last Updated: March 24, 2015
PRIVACY NOTICE Your access to and use of this website is governed by the TERMS OF WEBSITE USE and the following PRIVACY NOTICE. Please read them carefully as they constitute a legally binding agreement
How To Ensure Health Information Is Protected
pic pic CIHI Submission: 2011 Prescribed Entity Review October 2011 Who We Are Established in 1994, CIHI is an independent, not-for-profit corporation that provides essential information on Canada s health
Align Technology. Data Protection Binding Corporate Rules Processor Policy. 2014 Align Technology, Inc. All rights reserved.
Align Technology Data Protection Binding Corporate Rules Processor Policy Confidential Contents INTRODUCTION TO THIS POLICY 3 PART I: BACKGROUND AND ACTIONS 4 PART II: PROCESSOR OBLIGATIONS 6 PART III:
Best Practices for Protecting Individual Privacy in Conducting Survey Research
Best Practices for Protecting Individual Privacy in Conducting Survey Research CONTENTS Foreword... 1 Introduction... 2 Privacy Considerations at Each Stage of a Survey Research Project... 5 Stage 1: Issue
Insights into Cloud Computing
This article was originally published in the November 2010 issue of the Intellectual Property & Technology Law Journal. ARTICLE Insights into Cloud Computing The basic point of cloud computing is to avoid
THE GENERAL INSURANCE OMBUDSERVICE
THE GENERAL INSURANCE OMBUDSERVICE Terms of Reference for Dispute Resolution The General Insurance OmbudService (GIO) is an independent not-for-profit corporation, created in 2002, with the sole purpose
PIPEDA and Online Backup White Paper
PIPEDA and Online Backup White Paper The cloud computing era has seen a phenomenal growth of the data backup service industry. Backup service providers, by nature of their business, are compelled to collect
A Privacy Handbook for Lawyers PIPEDA AND YOUR PRACTICE
A Privacy Handbook for Lawyers PIPEDA AND YOUR PRACTICE Table of Contents Introduction...1 Privacy Issues in Managing a Law Practice...6 Privacy issues in Civil Litigation...16 Conclusion...26 Endnotes...28
The United States Federal Trade Commission ("FTC") and the Office of the Data Protection Commissioner of Ireland (collectively, "the Participants"),
MEMORANDUM OF UNDERSTANDING BETWEEN THE UNITED STATES FEDERAL TRADE COMMISSION AND THE OFFICE OF THE DATA PROTECTION COMMISSIONER OF IRELAND ON MUTUAL ASSISTANCE IN THE ENFORCEMENT OF LAWS PROTECTING PERSONAL
DATA THEFT OR LOSS: TEN THINGS YOUR LAWYER MUST TELL YOU ABOUT HANDLING INFORMATION by Craig Bavis and Michael Parent
FEATURE ARTICLE July/August 2007 DATA THEFT OR LOSS: TEN THINGS YOUR LAWYER MUST TELL YOU ABOUT HANDLING INFORMATION by Craig Bavis and Michael Parent Craig Bavis is a labour and employment lawyer with
235.1. Federal Act on Data Protection (FADP) Aim, Scope and Definitions
English is not an official language of the Swiss Confederation. This translation is provided for information purposes only and has no legal force. Federal Act on Data Protection (FADP) 235.1 of 19 June
Overview of. Health Professions Act Nurses (Registered) and Nurse Practitioners Regulation CRNBC Bylaws
Overview of Health Professions Act Nurses (Registered) and Nurse Practitioners Regulation CRNBC Bylaws College of Registered Nurses of British Columbia 2855 Arbutus Street Vancouver, BC Canada V6J 3Y8
AIG INSURANCE COMPANY OF CANADA Privacy Principles
AIG and Individual Privacy We at AIG Insurance Company of Canada (referred to as AIG, we, our, or us ) abide by these and want you, our applicants, policyholders, insureds, claimants, and any other individuals
Data Privacy in the Cloud: A Dozen Myths & Facts
Data Privacy in the Cloud: A Dozen Myths & Facts March 7-9 Washington DC Presented by: Barbara Cosgrove, Chief Security Officer, Workday, Inc. Lothar Determann, Partner, Baker & McKenzie LLP We re taking
Cloud Computing. Introduction
Cloud Computing Introduction This information leaflet aims to advise organisations which are considering engaging cloud computing on the factors they should consider. It explains the relationship between
INDEX PRIVACY POLICY...2
INDEX PRIVACY POLICY...2 WHAT PERSONAL INFORMATION DOES RENTINGCARZ GATHER FROM ME AND HOW IS THIS INFORMATION USED?...2 MAKING A PURCHASE...2 NEWSLETTERS...2 ONLINE SURVEYS...2 PROMOTIONS & SWEEPSTAKES...3
Law Firm Compliance: Key Privacy Considerations for Lawyers and Law Firms in Ontario
PRIVACY COMPLIANCE ISSUES FOR LAW FIRMS IN ONTARIO By Sara A. Levine 1 Presented at Law Firm Compliance: Key Privacy Considerations for Lawyers and Law Firms in Ontario Ontario Bar Association, May 6,
It s stated goal is to give people the power to share and make the world more open and connected.
BALANCING INDIVIDUAL RIGHTS WITH THE SOCIAL AND ECONOMIC BENEFITS OF A DIGITAL ECONOMY INTRODUCTION The World Wide Web and advances in broadband technology have presented enormous opportunities for economic
Privacy Policy. 30 January 2015
Privacy Policy 30 January 2015 Table of Contents 1 Overview 3 Purpose 3 Scope 3 2 Collection 3 What information do we collect? 3 What if you do not give us the information we request? 4 3 Use of information
Privacy and Security Framework, February 2010
Privacy and Security Framework, February 2010 Updated April 2014 Our Vision Better data. Better decisions. Healthier Canadians. Our Mandate To lead the development and maintenance of comprehensive and
Policy Brief: Protecting Privacy in Cloud-Based Genomic Research
Policy Brief: Protecting Privacy in Cloud-Based Genomic Research Version 1.0 July 21 st, 2015 Suggested Citation: Adrian Thorogood, Howard Simkevitz, Mark Phillips, Edward S Dove & Yann Joly, Policy Brief:
Information Sheet: Cloud Computing
info sheet 03.11 Information Sheet: Cloud Computing Info Sheet 03.11 May 2011 This Information Sheet gives a brief overview of how the Information Privacy Act 2000 (Vic) applies to cloud computing technologies.
INTRODUCTION...3 THE FREEDOM OF INFORMATION AND PROTECTION OF PRIVACY ACT...3 THE INFORMATION AND PRIVACY COMMISSIONER...5
Page 2 TABLE OF CONTENTS INTRODUCTION...3 THE FREEDOM OF INFORMATION AND PROTECTION OF PRIVACY ACT...3 THE INFORMATION AND PRIVACY COMMISSIONER...5 RECORDS AND REQUESTING ACCESS...6 REQUESTING A REVIEW
Bankruptcy and Restructuring
doing business in Canada 102 p Bankruptcy and Restructuring 1. Legislation and Court System The Canadian bankruptcy and insolvency regime is divided between the federal and provincial levels of government
THE CANADIAN LIFE AND HEALTH INSURANCE OMBUDSERVICE
THE CANADIAN LIFE AND HEALTH INSURANCE OMBUDSERVICE Terms of Reference The Canadian Life and Health OmbudService ( CLHIO ) is an independent organization that deals with Consumer Complaints about life
The HR Skinny: Effectively managing international employee data flows
The HR Skinny: Effectively managing international employee data flows Topics we will cover today Laws affecting HR data flows HR international data protection challenges and strategic solutions Case study
PRIVACY POLICY NEXT BUSINESS ENERGY PTY LIMITED ABN 91 167 937 555
PRIVACY POLICY NEXT BUSINESS ENERGY PTY LIMITED ABN 91 167 937 555 TABLE OF CONTENTS 1. INTRODUCTION 3 2. HOW WE COLLECT YOUR PERSONAL INFORMATION 3 3. TYPES OF INFORMATION WE COLLECT 4 4. HOW WE USE THE
Understanding Criminal Records
Understanding Criminal Records John Howard Society of Alberta 2000 With Financial Support From: The Alberta Law Foundation TABLE OF CONTENTS INTRODUCTION...1 POLICE CRIMINAL RECORD SYSTEMS...2 Creating
Resolution on Consumer Protection in Cloud Computing
DOC NO: INFOSOC 46-11 DATE ISSUED: JUNE 2011 Resolution on Consumer Protection in Cloud Computing Consumers, businesses and governments are increasingly using cloud computing services to store and share
THE PERSONAL INFORMATION PROTECTION AND ELECTRONIC DOCUMENTS ACT (PIPEDA) PERSONAL INFORMATION POLICY & PROCEDURE HANDBOOK
THE PERSONAL INFORMATION PROTECTION AND ELECTRONIC DOCUMENTS ACT (PIPEDA) PERSONAL INFORMATION POLICY & PROCEDURE HANDBOOK REVISED August 2004 PERSONAL INFORMATION POLICY & PROCEDURE HANDBOOK Introduction
Consultation on Canada's International Education Strategy
Consultation on Canada's International Education Strategy In Budget 2011, the Government of Canada announced funding for the development and implementation of an international education strategy that will
Information Security Policy
Information Security Policy Policy Title Responsible Executive Responsible Office Information Security Policy Vice President for Information Technology and CIO, Jay Dominick Office of Information Technology,
