NEWS RELEASE: Ministerial Order an exception to the rule

MEDIA RELEASE
March 30, 2020

Ministry of Citizens’ Services relaxes restrictions on the use of third-party tools and applications to disclose personal information inside or outside of Canada

VANCOUVER, March 30, 2020 – In the time of a global emergency, the protection of privacy and access to information rights needs to be kept at the forefront of policy discussions rather than used as a trade-off for convenience.Ministerial Order (no. M085) from the Minister of Citizens’ Services has called for a relaxation of the Freedom of Information and Protection of Privacy Act (FIPPA)’s data residency provisions in the context of the COVID-19 pandemic.

In addition to allowing the various provincial health authorities to disclose personal information inside or outside of Canada in response to COVID-19, the Order has given public bodies approval to use third-party tools and applications to disclose personal information inside or outside of Canada so long as they are being used “to support and maintain the operation of programs or activities of public [bodies]” and “to support public health recommendations or requirements” such as social distancing, working from home, etc. The order has an end date of June 30th, 2020.

We are firmly committed to the requirements for local data storage contained within the Act, even in extraordinary times. BC FIPA acknowledges that we are facing unprecedented challenges arising from the need to respond swiftly and responsibly to the COVID-19 pandemic, but this cannot be done at the expense of data residency and broader privacy rights. The all-party special committee who reviewed the Act in 2016 recommended that the personal information of British Columbians be protected in accordance with Canadian law – storing or accessing said data outside of Canada could subject it to a lower standard of privacy protection.  

BC FIPA is continuing to monitor for instances where the privacy of BC citizens is being sacrificed during the COVID-19 pandemic. “We hoped the government had exercised due diligence and put appropriate and necessary overrides in place that were triggered with the declaration of an emergency. It appears they felt those measures were insufficient and they took further action” says Jason Woywada, BC FIPA’s executive director. “There needs to be consideration for the long-term impacts of personal information being disclosed to third parties that cross borders and the impact that creates. Privacy and data residency has been under attack for years by those who wish to profit from its erosion. Maintaining privacy and data residency requirements is a positive sum proposition and should always be considered.”

BC FIPA continues to call for a comprehensive overhaul of FIPPA that is informed by a deep and sincere commitment to updating and expanding the information and privacy rights of British Columbians.  

Contact: 
Jason Woywada, Executive Director 
BC Freedom of Information and Privacy Association 

– 30 –

Related Links: 

Order of the Minister of Citizens’ Services: Freedom of Information and Protection of Privacy Act: Ministerial Order No.M085 – March 17 
https://www2.gov.bc.ca/assets/gov/british-columbians-our-governments/services-policies-for-government/information-management-technology/information-privacy/resources/ministerial_order_085_respecting_disclosures_during_covid-19_emergency__march_2020_pdf.

Declaration of a state of emergency – March 18 
https://news.gov.bc.ca/releases/2020PSSG0017-000511

Decision of the OIPC Commissioner Michael McEvoy – March 18 
https://www.oipc.bc.ca/news-releases/2399

Report of the Special Committee to Review the Freedom of Information and Protection of Privacy Act 2016 
https://www.leg.bc.ca/content/CommitteeDocuments/40th-parliament/5th-session/foi/Report/SCFIPPA_Report_2016-05-11.pdf

Statement on Investigation Report into AggregateIQ

Privacy violations highlight the need for law reform

Earlier this week, the Office of the Privacy Commissioner of B.C. (OIPC BC) and the Office of the Privacy Commissioner of Canada (OPC) released a joint investigation report that found a B.C. company violated B.C.’s provincial and Canada’s federal privacy laws.

While conducting business on high-profile campaigns in the U.K., the U.S., and in Canada, the report states that AggregateIQ did not comply with the consent provisions in B.C.’s Personal Information Protection Act (PIPA) and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and did not employ reasonable security safeguards.

The report makes two recommendations in order for the offending company to become compliant with Canadian privacy laws:

  • That they take measures to ensure that the consent that they have received to collect, use, and disclose personal information is in compliance with PIPA and PIPEDA;
  • And that they employ reasonable security safeguards to protect the personal information in their control.

The OIPC BC and the OPC will collect evidence from the company in approximately six months to confirm that the recommendations have been implemented and that the company is now compliant.

Fines are the international standard for privacy enforcement

This response highlights the need for Canadian regulatory bodies to have the power to issue fines when they find organizations to be in violation of Canadian law.

When asked why no fines were issued despite the investigation finding the company to have violated Canadian privacy laws, the Information and Privacy Commissioner for B.C., Michael McEvoy said: “There are no fines because we do not have the authority to levy fines.”

Absent amongst the international media attention that this report received, is the observation that Canada’s privacy regulators are powerless to enforce privacy laws through fines.

International regulators are using their fining powers to compel compliance to great effect. Examples include the Federal Trade Commission’s $5 billion civil penalty against Facebook, and the Information Commissioner Office (ICO) in U.K.’s intention to fine British Airways more than £183 million.

In fact, the ICO in the U.K. has a standing enforcement notice against AggregateIQ, threatening fines of up to 20 million Euros should the company not comply with their notice within 30 days of the conclusion of the joint OIPC and OPC investigation.

This leads one to wonder if AggregateIQ is implementing the recommendations of the OIPC BC and OPC out of good faith, or because they face the threat of significant fines from an international regulatory body.

Canadian regulators need fining power to protect privacy

“At the end of the day, privacy, and the legislation that governs it, needs to be brought into the 21st century where the realities of cross-boundary data sharing leave much to be coveted in terms of protections for personal information,” says Joyce Yan, BC FIPA’s Interim Executive Director.

“We have been a longtime advocate for increasing the Commissioners’ powers, but with the case of AggregateIQ, it has become clear that order-making powers (a tool the federal Privacy Commissioner still doesn’t have in his toolkit) is simply not enough. The provincial and federal privacy laws are antiquated, and we are falling behind our foreign counterparts.”

We strongly urge our fellow privacy advocates to join us as we continue to push for law reform that gives Canadian regulators the power necessary to protect privacy and compel compliance.

Federal Election 2019 Results: What does a Liberal minority government mean for ATI and privacy?

Previously, we compared access to information and privacy commitments in the platforms of four of Canada’s major federal political parties. Now, we’ll take a look at what we can expect from a Liberal minority government.

With the election results in, we now have greater clarity about how Canada will proceed with access to information and privacy in the years to come.

According to our ranking system, the Liberal Party made a total of six commitments out of a possible eleven, none of which were related to access to information. The only party to make more commitments was the Green Party.

Should the Liberal Party keep its commitments, we can expect the changes outlined below to privacy and data protection in Canada. These changes are part of something that the Liberal Party is calling Canada’s Digital Charter and were proposed before the election, in early 2019.

In an attempt to ensure equality, not all of the items contained within Canada’s Digital Charter were included within our ranking system. As noted below, some of these abilities theoretically already exist within Canada’s legislative framework.

The changes are the following:

In the coming months, we’ll publish articles that explain what each of these promises mean for Canadians and their privacy.

It should also be noted that Canada’s Digital Charter is based on consultations that took place between June and October of 2018. After FIPA was not invited to participate in any of the sixteen consultations, we filed an access to information request to learn who was in attendance.  

We learned that civil society organizations were significantly underrepresented in all the roundtable discussions, while input from the technology industry was overrepresented. On average, less than ten per cent of attendants were from civil society. In one case, representation from civil society was entirely absent.

Check back in on the news section of our website as we release the articles exploring the new rights that were promised by the Liberal Party during their 2019 campaign. This page will also be updated to include links to the articles as they become available.

Which party will deliver most transparent government?

By Stanley Tromp

Stanley Tromp is a Vancouver independent journalist and author of the book Fallen Behind: Canada’s Access to Information Act in the World Context.

Canada’s Access to Information Act of 1982 is an essential law that allows citizens and the media to obtain government records on many vital topics, such as health and safety, crime, public finance and the environment. Yet today it could be equated to a rusted manual typewriter in the iPhone-Twitter age. In 2008, I wrote a book called Fallen Behind , which compared all the world’s freedom of information laws to reveal that our ATI Act had lagged far behind global FOI standards in their level of openness.

Over the past decade, more than 50 nations have passed FOI laws for a total of 128, and such access has come to be recognized by courts as a “human right.” In the authoritative Global Right to Information Rating system of the world’s laws, Afghanistan ranks number 1, while Canada – which ironically has so worked hard to transform that nation from a theocratic dictatorship into a modern democracy – ranks 58th. (The top ten list includes Serbia, Sri Lanka, Slovenia, Albania, India, Croatia, and Liberia.)

The problem has grown so much worse that, indeed, the second edition of this book – to be released later this year – could well be entitled Fallen Further Behind .

In the 2015 election campaign, Liberal leader Justin Trudeau made several FOI reform promises, and after he won, actually kept a few of them. In Ottawa this year, Bill C-58 was passed, which grants the Information Commissioner the power to order government to release records against its will.

Even this new power has received very mixed reviews, mostly negative. The Commissioner has objected that the Bill is in fact a “regression” of existing FOI rights, and the new power is not “a true order-making model” due to five serious failings with it, features that are mostly absent in the rest of the FOI world.

The Liberal party broke its pledge to have the prime minister’s and ministers’ offices covered under the ATIA, instead prescribing only some proactive release of some self-selected records, which is a form of faux transparency.

Overall, as Information Commissioner John Reid said in a 1999 speech: “It amuses me to see the profound change in attitude about access to information which occurs when highly placed insiders suddenly find themselves on the outside. And vice versa!”

To raise our ATI Act to world standards, the law needs a public interest override, a harms tests for all exemptions, some limit on the delays that authorities are allowed to claim, and new rules for officials to create and preserve records so as to defeat the growing menace of “oral government.” This last occurs when officials no longer commit their thoughts to paper, and convey them verbally instead, to avert the chance of the information emerging in response to FOI requests.

We also need FOI coverage of the wholly owned and controlled entities that perform public functions and spend billions of taxpayer’s dollars. Today more than 100 such quasi-governmental entities are still not covered by the ATIA . The exclusion of some of these such as the Canadian Blood Services, the nuclear Waste Management Organization and air traffic controllers could result in harm to public health and safety.

As well, the records of cabinet discussions are excluded completely from the scope of the FOI law only in Canada and South Africa, whereas other nations have a mandatory exemption for it. The ATIA ’s Section 21 exemption for policy advice is far broader than in most of the world, and it is being over applied to withhold countless records in the public interest. (Its 20 year secrecy limit is grossly overlong, compared to the five years set in Nova Scotia’s FOI law.) In the world, 78 nations grant citizens a right to access state-held information in their Constitutions or Bill of Rights, while Canada does not.

“As someone who travels around the world promoting the right to information, it is frankly a source of profound embarrassment to me how poorly Canada does on this human right,” writes Halifax lawyer and FOI expert Toby Mendel. “Given that everyone who uses this system regularly is aware that it is profoundly broken, it is inexplicable that it does not get fixed.”

By stubbornly holding Canada back in such an insular, stagnant backwater within the FOI world, Prime Minister Trudeau is placing our country’s reputation for democratic process at risk. When will the ATI Act be raised to accepted global standards? Will we have to wait another 36 years to finally bring it into the 21st century?

In this 2019 federal election campaign, Canadians should insist upon answers from all the candidates.