Proudly Presents. Navigating the Cloud Across the US & Canada Border



Similar documents
CLOUD COMPUTING & THE PATRIOT ACT: A RED HERRING?

Cloud Computing: Privacy and Other Risks

Index All entries in the index reference page numbers.

Insights and Commentary from Dentons

Cloud Computing: Trust But Verify

CANADIAN PRIVACY AND DATA RESIDENCY REQUIREMENTS. White Paper

INFORMATION SECURITY GUIDE. Cloud Computing Outsourcing. Information Security Unit. Information Technology Services (ITS) July 2013

The USA Patriot Act Government Briefing. Kirsten Tisdale, Chris Norman, Sharon Plater & Alexandra (Gina) Henley September 30, 2004

Privacy Law in Canada

CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:

The cloud thing: Privacy and cloud computing

Table of Contents. Background The Complaint...2 The Investigative Process...3. Issues Arising from the Investigation Discussion...

Protecting Saskatchewan data the USA Patriot Act

AN INTRO TO. Privacy Laws. An introductory guide to Canadian Privacy Laws and how to be in compliance. Laura Brown

COUNCIL OF THE EUROPEAN UNION. Brussels, 22 November /06 DATAPROTECT 45 EDPS 3

Data Management: Considerations for Integrating Compliance Requirements At Home and Abroad. Toronto, Ontario June 14, 2005

Privacy Law in Canada

MICROSOFT OFFICE 365 PRIVACY IMPACT ASSESSMENT. Western Student E-Communications Outsourcing

PIPEDA and Online Backup White Paper

Unofficial Consolidation January 1, 2015

Regulatory, Professional Liability and Payment for Telemedicine in Canada

Cloudy With a Chance Of Risk Management

Privacy and Security Framework, February 2010

SPECIAL ISSUES IN CANADIAN IT OUTSOURCING BY C. IAN KYER AND JOHN BEARDWOOD

Cloud Computing: Legal Risks and Best Practices

PRIVACY POLICY. Consent

Transferring Personal Information about Canadians Across Borders Implications of the USA PATRIOT Act

Bill C-27: First Nations Financial Transparency Act

Privacy Matters. The Federal Strategy to Address Concerns About the USA PATRIOT Act and Transborder Data Flows

Doing Business. A Practical Guide. casselsbrock.com. Canada. Dispute Resolution. Foreign Investment. Aboriginal. Securities and Corporate Finance

Big Data, Big Risk? Data Management and Privacy. Presented by: Timothy Banks, Heather Innes, and Colonel Vihar Joshi

Selected Annotated Bibliography Personal Health Information, Privacy and Access

Public Sector Chief Information Officer Council

Taking care of what s important to you

Cloud Computing: Privacy & Jurisdiction from a Canadian Perspective

Driving Excellence through Data Governance Personal Data Protection Seminar. Singapore, May 16, 2014

Public Accounting Rights for Certified General Accountants in Canada. Issue Brief

Strengthening Public Sector Transparency and Privacy

The Use of Cloud Computing for the Storing and Accessing of Client Information: Some Practical and Ethical Considerations

Cloud Computing Contracts. October 11, 2012

9/30/2013. What is Cloud Computing? Benefits of Cloud Computing

What s New in Access, Privacy and Health Care. Brian Beamish Commissioner. Ontario Connections May 21, 2015

An Introduction to Public Private Partnerships. Updated June 2003

SUBMISSION TO THE SPECIAL COMMITTEE TO REVIEW TRANSBORDER DATA FLOWS AND THEIR REGULATION THE FREEDOM OF INFORMATION AND PROTECTION OF PRIVACY ACT

Personal Information Protection Act. Information Sheet 12: 1. Service Providers Outside Canada: Notification, Policies and Practices

The HR Skinny: Effectively managing international employee data flows

RECORD AND INFORMATION MANAGEMENT FRAMEWORK FOR ONTARIO SCHOOL BOARDS/AUTHORITIES

A Year in Review: CIHI s Annual Privacy Report

Part 4 of the Corporate and Community Social Responsibility Research Series

Info Source. Sources of Federal Government and Employee Information Vancouver Fraser Port Authority. Table of Contents

Our Employees. CIBC s vision, mission and values are at the centre of our commitment to create an environment where all of our employees can excel.

A Note on Business Tax Competitiveness in British Columbia

How To Ensure Health Information Is Protected

National Association of Pharmacy Regulatory Authority s Privacy Policy for Pharmacists' Gateway Canada

HEALTH INFORMATION ACT (HIA) BILL QUESTIONS AND ANSWERS

IT Security and Employee Privacy: Tips and Guidance

Response to COPE 378 Information Request No. 1

Protecting your privacy

E-COMMERCE GOES MOBILE: SEEKING COMPETITIVENESS THROUGH PRIVACY

SCOTIA DEALER ADVANTAGE RETAIL FINANCING PROGRAM DEALER AGREEMENT

Privacy and EHR Information Flows in Canada. EHIL Webinar Series. Presented by: Joan Roch, Chief Privacy Strategist, Canada Health Infoway

Review of Section 38 (Benefits), Workers Compensation Act

2008 BCSECCOM 143. Applicable British Columbia Provisions National Instrument Mutual Fund Sales Practices, s. 5.4(1), 9.1

Managing Contracts under the FOIP Act. A Guide for Government of Alberta Contract Managers and FOIP Coordinators

Cybersecurity in the States 2012: Priorities, Issues and Trends

PROVINCIAL CANADIAN GEOGRAPHIC RESTRICTIONS ON PERSONAL DATA IN THE PUBLIC SECTOR

Canadian Provincial and Territorial Early Hearing Detection and Intervention. (EHDI) Programs: PROGRESS REPORT

Cloud Computing and Privacy Toolkit. Protecting Privacy Online. May 2016 CLOUD COMPUTING AND PRIVACY TOOLKIT 1

Conquering Internal Company Challenges in Handling Canadian Taxes and Other VAT

Accountable Privacy Management in BC s Public Sector

Electronic Health Records

Residential Tenancy Office Compliance and Consumer Services Branch Ministry of Public Safety and Solicitor General Residential Tenancy Office (RTO)

National Retail Report Canada FALL 2015 EDITION. Accelerating success.

The Community Maps of Canada Program

Common Student Information System for Schools and School Boards. Project Summary

Cloud Service Contracts: An Issue of Trust

CYBER LIABILITY CLAIMS

Insurance Journal. Defending Until the End When Does the Duty to. Volume 1, Issue 3 Editor Keoni Norgren. May 1, 2013

KEY ISSUES IN PRIVACY AND INFORMATION MANAGEMENT

Opening Your Retail Account

How To Manage Revenue Management In The Province Of Britain Colony

OPPORTUNITY PROFILE. Associate Dean Executive Education

Open Government and Information Management. Roy Wiseman Executive Director, MISA/ASIM Canada CIO (Retired), Region of Peel

Issues in Canadian Universities and Impact on Business Schools

insurance bulletin unlicensed insurance in Canada

Pan-Canadian Quality Assurance Framework for the Assessment of International Academic Credentials

PERSONAL INFORMATION PROTECTION ACT

The CIPM certification is comprised of two domains: Privacy Program Governance (I) and Privacy Program Operational Life Cycle (II).

July 25, Dear Sirs/Mesdames:

The Value of a CHRP: More Promotions and Better Pay

We will not collect, use or disclose your personal information without your consent, except where required or permitted by law.

PositionStatement TELEHEALTH: THE ROLE OF THE NURSE CNA POSITION

Additional Tables, Youth Smoking Survey

Consultation Document Automobile Insurance Reform

Personal Information Protection Act ( PIPA ) Privacy-Proofing Your Retail Business Tips for Protecting Customers Personal Information 1

An Oracle White Paper May Transparency in the Public Sector: Its Importance and How Oracle Supports Governments Efforts

If you have experience and academic. The Applied Science and Engineering Technology Professions in Canada ELECTRICAL TECHNOLOGY

CHARITY LAW BULLETIN NO. 302

Our Vision Better data. Better decisions. Healthier Canadians.

Transcription:

Proudly Presents Navigating the Cloud Across the US & Canada Border

Presenters Rob Groves, B.A., M.B.A., Director, Finance and Business Services, Calgary Catholic School District Rob Groves is the Director, Finance and Business Services for Calgary Catholic School District which is the largest Catholic School District in Alberta with over 45,000 students, 4500 staff, 110 district facilities and a budget of just under $0.5 billion. With a primary role in budget preparation, Mr. Groves is also responsible for risk management which is his passion. He is also chair of the Technical Team for the Urban Schools Insurance Consortium (USIC) a partnership of fourteen of the largest school districts in Alberta which operates under an insurance reciprocal arrangement. USIC is implementing the ivos web-based event reporting to assist in risk management. Calgary Catholic already has significant risk management and occupational health & safety programs which are all linked through the ivos event reporting program. This allows for relevant risk management information to be collected enabling members to be proactive in loss prevention and risk management. David Black, Chief Information Security Officer Aon esolutions David Black is the CISO for Aon esolutions, the leading global provider of web-enabled integrated risk management tools and resources. Mr. Black is responsible for Aon esolutions strategy and approach to IT risks as well execution of initiatives for protection of all our products and services as well as our corporate environment. Previously Mr. Black was the Director of Information Security for EarthLink, Inc, Manager within KPMG s Information Risk Management Practice, and held various information security and technology positions during his time at The Coca-Cola Company. During his 14-year information security career, Mr. Black has performed security roles from technical design and implementation to development and execution of comprehensive strategic security and IT risk management programs. His experience spans across industries with consulting and corporate tenures directing global security initiatives and teams. david.black@aon.com t: +1.678.784.4664

Session Overview Cloud computing enables companies to free up resources, lower operating costs, and focus on core business functions. While safe, secure and cost-effective to implement, utilizing them across the U.S. and Canada border can be tricky, with concerns around the Patriot Act. Learn the benefits of working in the cloud and the differences between private and public clouds. Acquire information that will assist U.S. and Canadian companies understand the laws and risks of cloud computing and help maximize value, while minimizing risk. Hear the experiences of a Canadian organization working with a U.S. based firm, while complying with data laws.

Session Agenda Cloud Evolution & Terms Cloud Implications/Risks U.S. PATRIOT Act Cloud Governance Canada Federal Provincial Laws Real-world Solution Example

What is Cloud Computing Cloud computing is Internet-based computing, whereby shared resources, software and information are provided to computers and other devices on-demand, like electricity Computing in which services and storage are provided over the Internet (or "cloud") Refers to accessing computing resources that are typically owned and operated by a third-party provider on a consolidated basis in one, or more, data center locations

Cloud Evolution Self Hosted & Managed Private* Cloud Computing Public* Cloud Computing Traditional Data Center Company employees or 3 rd party manages applications & infrastructure components & data Hosted/SaaS Provider Partner manages applications & infrastructure components & data Hosted/SaaS Provider Partner manages partners that manage applications & infrastructure components & data

Cloud Evolution (cont d) Corporate Private Clouds Internal uses of cloud technologies to provide services to corporate clients with self-managed & owned infrastructure Community Clouds External cloud infrastructures dedicated to specific industries, sectors or purposes. Also known as vertical clouds Commodity Clouds External cloud infrastructures open to host any application types for virtually any purpose and can be brokered by a cloud integrator Healthcare RIMS Financial Government Communications Distribution Retail Business Services Media Technology Energy

Cloud Solution Provider User Traffic Company Traffic Internet Partner Traffic Private Cloud Partner IT Infrastructure File Transfer Solution Data Loading/Conversion Application Platform Data Development/QA Implications Direct & Complete Partner Relationship Direct Contractual Protections/SLAs Central & Direct IT/Application Management Central Security, Controls and Certifications Minimal Data Duplication/Exposure

Cloud Solution Broker User Traffic Company Traffic Internet Partner Traffic Broker Application Development/ QA Data Commodity Cloud Provider(s) Implications Direct & Indirect Partner Relationships Indirect Contractual Protections/SLAs Indirect IT/Application Management Disperse Security, Controls and Certifications Increased Data Duplication/Exposure File Transfer Solution Data Loading/ Conversion Data IT Infrastructure Platform Application Data rackspace.com force.com

Cloud Solution Risks Normal outsourcing risks Cost Reduction Expectations Process Discipline Loss of Business Knowledge Vendor Failure to Deliver Scope Creep Culture Turnover of Key Personnel Knowledge Transfer Data Breach Government Oversight/Regulation

Data Breach Risk Duplication/Replication of Data (multi-vendor solutions) Complexities in scope of security and control needs Different types of cloud solutions require differing levels of security and audit requirements. Potential for use of outsourced and/or offshore resources

Government Oversight/Regulation Local and Federal governance requirements for: The organization The cloud provider/broker Any additional providers serving the broker

The USA PATRIOT Act Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001 Intended to facilitate the fight against terrorism Introduced 4 key changes from previous information and evidence gathering laws Search and surveillance authority more widely available Threshold lowered Subject-matter scope broadened National Security Letter regime expanded

PATRIOT Act U.S. government could compel the disclosure of Canadian citizen information that is stored within U.S. controlled areas Such disclosure could be viewed as a violation of privacy There are examples of the U.S. taking advantage of the PATRIOT Act to collect information Side note: Canada has very similar act/permissions: Canada s Anti-terrorism Act of 2001 PIPEDA subsection 7(3)(c.1)

Canadian Federal Privacy Private sector transfer of personal information from Canada to the U.S. is not a violation of Canadian Federal law. Government sector transfer of personal information from Canada to the U.S. is not a violation of Canadian Federal law. The transfer of personal information from Canada to the U.S. by financial sector companies is not a violation of Canadian Federal law. With a few exceptions, provincial laws permit the transfer of personal information from Canada to the U.S.

Use vs. Disclosure A transfer for processing is a use of the information; it is not a disclosure. Assuming the information is being used for the purpose it was originally collected, additional consent for the transfer for processing is not required.

Provincial Law Federal law for public organizations (PIPEDA) does not apply to provincially regulated organizations within provinces where privacy laws have received substantially similar status from the Governor in Council.

Provincial Specifics British Columbia: Bill 73 the Freedom of Information and Protection of Privacy Amendment Act, 2004. The law requires public bodies to ensure that personal information in its custody or under its control is stored only in Canada and accessed only in Canada. Quebec: Aligns with British Columbia Nova Scotia: Personal Information International Disclosure Protection Act, 2006. Follows British Columbia s Bill 73. Alberta: Freedom of Information and Protection of Privacy Act permits the disclosure of personal information controlled by a public body in response to a subpoena, warrant or order only if issued by a court with jurisdiction in Alberta.

Cloud Challenges Canadian organizations spread across multiple provinces Dynamic and Complex laws/regulations U.S. PATRIOT Act Misconceptions and confusion created by differing laws/regulations Organization Policies Brand/reputation impact

Key Cloud Considerations Where is your data actually located? Who has the ability to access your data? How are service levels measured/maintained? How do you escalate issues? How do contractual protections apply? Does cloud computing support your compliance requirements? Does the provider offer ASP-Hosted or self-hosted solutions? Which recommendations/checklists should we leverage based on industry/sector/data types?

Due-diligence Steps 1. Determine which Canadian (Federal & Provincial) data privacy regulations apply to your organization 2. Demonstrate focus on privacy during all phases of solution selection 3. Identify Personal information is defined in section 3 of the Privacy Act 4. Perform an invasion-of-privacy test - http://www.tbs-sct.gc.ca/atip-aiprp/tpa-pcp/tpa-pcp07-eng.asp 5. Perform a Privacy Impact Assessment (PIA) or a Preliminary PIA (PPIA) - http://www.priv.gc.ca/fs-fi/02_05_d_33_e.cfm 6. Complete Privacy Protection Checklist for each prospective solution - http://www.tbs-sct.gc.ca/atip-aiprp/tpa-pcp/tpa-pcp08-eng.asp 7. Build security and privacy into contract

Case Study: USIC USIC is the Urban Schools Insurance Consortium in Alberta (14 Boards with different requirements and issues). Purchased ivos event reporting and customized for needs. Where information was to be stored created added complexity to purchase and implementation required Canadian host location. With a separate hosting arrangement (TELUS initially), other arrangements needed for dba and system admin. Additional costs and delays in implementation. Too many fingers in the pot ended up with a dba in Ontario, TELUS contacts in both Ontario and Alberta, ivos implementation team in Florida and California, users in Alberta. Perseverance, a clear vision of the goal, and ample assistance from both Aon (broker) and Aon esolutions resulted in happy ending.

Thank you for attending the Ottawa Capital Connexions Conference