{"id":29187,"date":"2022-09-30T15:24:36","date_gmt":"2022-09-30T19:24:36","guid":{"rendered":"https:\/\/www.itworldcanada.com?p=505696"},"modified":"2022-10-03T09:18:44","modified_gmt":"2022-10-03T13:18:44","slug":"federal-privacy-commissioner-silent-on-proposed-new-privacy-act-for-businesses","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/federal-privacy-commissioner-silent-on-proposed-new-privacy-act-for-businesses\/","title":{"rendered":"Federal privacy commissioner silent on proposed new privacy act for businesses"},"content":{"rendered":"<p data-ar-index=\"0\">Canada\u2019s recently-appointed privacy commissioner is still not saying what he thinks of the government\u2019s latest attempt to update the federal privacy law covering the business sector.<\/p>\n<p data-ar-index=\"1\">In the <a href=\"https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/ar_index\/202122\/ar_202122\/\" rel=\"noopener\">annual report to Parliament<\/a> filed Thursday by the Office of the Privacy Commissioner (OPC), Philippe Dufresne said he welcomes the introduction of <a href=\"https:\/\/www.itworldcanada.com\/article\/breaking-news-government-files-latest-attempt-at-privacy-legislation-reform\/488771\" rel=\"noopener\">Bill C-27, formally called The Digital Charter Implementation Act, 2022<\/a>, which includes the Consumer Privacy Protection Act (CPPA) and the Artificial Intelligence and Data Act.<\/p>\n<p data-ar-index=\"2\">But Dufresne \u2014 who was appointed in June \u2014 said he won\u2019t reveal his position until Parliament debates the bill. So far, the House of Commons committee on ethics, privacy and access to information hasn\u2019t set dates for hearings.<\/p>\n<p data-ar-index=\"3\">The CPPA is aimed at updating the Personal Information Protection and Electronic Documents Act (PIPEDA), which sets the data protection rules for federally-regulated industries and for provinces that don\u2019t have their own private-sector privacy laws. It would create a new tribunal to hear requests from the privacy commissioner to levy heavy fines for firms that violate the CPPA.<\/p>\n<p data-ar-index=\"4\">The Artificial Intelligence and Data Act is new legislation forcing businesses deploying \u201chigh impact\u201d AI technologies to use them responsibly. An AI data commissioner will enforce regulations.<\/p>\n<p data-ar-index=\"5\">Reform of federal privacy laws is long overdue, Dufresne said. He repeated the OPC\u2019s long-time call for any new legislation to recognize privacy as a human right.<\/p>\n<p data-ar-index=\"6\">However, with a minority, it isn\u2019t clear if Prime Minister Justin Trudeau and his government have the will to pass a privacy overhaul. In the previous Parliament, the government failed to get behind or amend the first version of its proposed Consumer Privacy Protection Act. That version was<a href=\"https:\/\/www.itworldcanada.com\/article\/is-canadas-reform-of-privacy-legislation-dead\/456028\" rel=\"noopener\"> heavily criticized by the privacy commissioner at the time, Daniel Therrien.<\/a> The new proposed law contains some changes.<\/p>\n<p data-ar-index=\"7\">The annual report covers the commission\u2019s work enforcing PIPEDA and the federal Privacy Act, which covers federal institutions, for the 12-month period ending March 31st. Although outside that reporting period, the report notes that in <a href=\"https:\/\/www.itworldcanada.com\/article\/canada-should-limit-police-use-of-facial-recognition-technology-say-privacy-commissioners\/482311\" rel=\"noopener\">May, the OPC, and federal and provincial privacy commissioners called on legislators<\/a> to develop a legal framework that clearly and explicitly establishes the circumstances in which police use of facial recognition may be acceptable.<\/p>\n<p data-ar-index=\"8\">The report notes that during the past year<\/p>\n<p data-ar-index=\"9\">\u2014 the OPC and three provincial privacy commissioners <a href=\"https:\/\/www.itworldcanada.com\/article\/privacy-commissioners-find-tim-hortons-violated-privacy-laws\/486785\" rel=\"noopener\">found Tim Horton\u2019s violated federal and provincial privacy laws<\/a> with the location tracking capability of its mobile app;<\/p>\n<p data-ar-index=\"10\">\u2013the OPC pushed Rogers Communications to change its voiceprint biometric authentication program, Voice ID, used when customers call the support centre and access to their accounts is needed.\u00a0 Unknown to customers, Rogers collected voiceprints in the background on calls before seeking customers\u2019 consent. Rogers promised to obtain express consent from individuals for voiceprints; to more clearly inform customers of their ability to opt out; and to delete voiceprints upon opt-out;<\/p>\n<p data-ar-index=\"11\">\u2013the OPC upheld the complaint of a truck driver that his employer, Trimac Transportation Services Inc., had installed a dash camera in his vehicle that continuously recorded audio and video without his consent. The OPC found that continuous recording, particularly when drivers were off duty and not driving, was not necessary to meet Trimac\u2019s goals of safety and protecting equipment. Trimac agreed the audio recording function will be active only when a driver is on-duty or driving. Viewing of video clips will be limited to those who need to know;<\/p>\n<p data-ar-index=\"12\">The OPC handled 463 reports of breaches of federal department security controls, most of which concerned the loss (278) or unauthorized disclosure (132) of personal information.<\/p>\n<p data-ar-index=\"13\">The majority of the breach reports (93 per cent) were due to human error, which includes email and mailing errors, mishandling of data\/records using an inappropriate shortcut or workaround, and losing or misplacing information, \u201csuggesting that the institution may have had policies or security procedures in place that were not being followed or enforced,\u201d the report said.<\/p>\n<p data-ar-index=\"14\">\u201cThese types of breaches underscore that it is not enough to have policies and protocols in place to protect information, but that they also need to be implemented and followed faithfully to be effective,\u201d the report said. \u201cIt is key that personal information is properly managed throughout its lifecycle, from collection, to use, to disposal. To this end, employee awareness and engagement is crucial.\u201d<\/p>\n<p data-ar-index=\"15\">The OPC continues to suspect there is under-reporting of cyber-attacks, including malware and phishing attacks, by public sector institutions. It noted the commission received only five reports in 2021-2022 of cyber attacks, down from nine the previous year. And of those five, three involved private-sector service providers to federal institutions. One involved the hack of a U.S.-based third-party contractor used by both the Canada Border Security Agency (CBSA) and U.S. Customs and Border Protection which saw approximately 9,000 photos (of the 1.4 million stolen) of licence plates of travelers driving into Canada released on the dark web.<\/p>\n<p data-ar-index=\"16\">The OPC investigation found inconsistencies in the way the CBSA managed licence plate information, and a lack of security measures, including adequate contractual clauses to ensure the\u00a0CBSA\u2019s private sector partner was properly protecting the information in its care.<\/p>\n<p data-ar-index=\"17\">Meanwhile, mandatory private sector reporting of data breaches dropped during the 12-month period to 645 incidents. These affected at least 1.9 million Canadian accounts. The OPC suspects there is still under-reporting of private sector breaches.<\/p>\n<p data-ar-index=\"18\">The leading cause of breaches involved unauthorized access, usually by external threat actors.<\/p>\n<p data-ar-index=\"19\">The post <a href=\"https:\/\/www.itworldcanada.com\/article\/federal-privacy-commissioner-silent-on-proposed-new-privacy-act-for-businesses\/505696\">Federal privacy commissioner silent on proposed new privacy act for businesses<\/a> first appeared on <a href=\"https:\/\/www.itworldcanada.com\/\">IT World Canada<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Annual report of the federal privacy commissioner notes the office only got reports of five cyber attacks during a 12 mo<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[58,361,16],"tags":[391,402,396,512,275],"class_list":["post-29187","post","type-post","status-publish","format-standard","hentry","category-government-public-sector","category-privacy","category-security","tag-di","tag-dotgov","tag-postmedia","tag-privacy-commissioner-of-canada","tag-top-story"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/29187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=29187"}],"version-history":[{"count":3,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/29187\/revisions"}],"predecessor-version":[{"id":29258,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/29187\/revisions\/29258"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=29187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=29187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=29187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}