{"id":38202,"date":"2023-05-11T11:58:44","date_gmt":"2023-05-11T15:58:44","guid":{"rendered":"https:\/\/www.itworldcanada.com?p=538733"},"modified":"2023-05-16T13:08:09","modified_gmt":"2023-05-16T17:08:09","slug":"proposed-overhaul-of-canadas-private-sector-privacy-law-a-step-in-the-right-direction-commissioner","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/proposed-overhaul-of-canadas-private-sector-privacy-law-a-step-in-the-right-direction-commissioner\/","title":{"rendered":"Proposed overhaul of Canada\u2019s private sector privacy law \u2018a step in the right direction\u2019: Commissioner"},"content":{"rendered":"<p>Canada&#8217;s privacy commissioner says the government\u2019s proposals to modernize Canada\u2019s federal private sector privacy law are \u201ca step in the right direction,\u201d but must go further to protect fundamental privacy rights.<\/p>\n<p>The statement from Privacy Commissioner Phillipe Dufesne came<a href=\"https:\/\/priv.gc.ca\/en\/opc-actions-and-decisions\/submissions-to-consultations\/sub_indu_c27_2304\/\"  rel=\"noopener\"> in a written submission on Bill C-27,<\/a> the Consumer Privacy Protection Act (CPPA), the government\u2019s proposed new private sector privacy law, to the House of Commons standing committee on Industry and Technology.<\/p>\n<p>As part of his submission, Dufresne repeated his office&#8217;s call for the legislation to recognize privacy as a fundamental right, and that the law limit organizations\u2019 collection, use and disclosure of personal information to specific and explicit purposes that take into account the relevant context.<\/p>\n<p><a href=\"https:\/\/www.itworldcanada.com\/article\/breaking-news-government-files-latest-attempt-at-privacy-legislation-reform\/488771\"  rel=\"noopener\">C-27 was introduced in Parliament last June.<\/a> It was recently forwarded to the Industry committee for witness testimony and detailed analysis. No date has yet been set for hearings to begin.<\/p>\n<p>Federal private sector privacy law applies to federally-regulated industries and firms in provinces and territories that don&#8217;t have their own law. That includes every jurisdiction except British Columbia, Alberta and Quebec.<\/p>\n<p>While C-27 includes the proposed Artificial Intelligence Data Act (AIDA) for regulating AI, Dufresne&#8217;s comments only deal with the CPPA. Some experts hope the government will hive off AIDA from C-27, arguing it needs a separate analysis<a href=\"https:\/\/www.itworldcanada.com\/article\/canadian-experts-urge-parliament-to-pass-ai-law-fast\/536830\"  rel=\"noopener\">. Others argue a flawed AI bill is better than none.<\/a><\/p>\n<p>Dufresne said the CPPA is an improvement over both the existing law, the Personal Information Protection and Electronic Documents Act\u00a0(<abbr>PIPEDA<\/abbr>), as well as an earlier version of the reform bill (known at the time as C-11) which died when the last election was called.<\/p>\n<p>\u201cI welcome and am encouraged by the committee\u2019s upcoming study of Bill C-27,\u201d Dufresne said. \u201cThis bill is a step in the right direction, but it can and must go further to protect the fundamental privacy rights of Canadians while supporting the public interest and innovation.\u201d<\/p>\n<p>In his written submission to the committee, Dufresne listed 15 key recommendations to improve and strengthen the proposed law.<\/p>\n<p>They\u00a0are:<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li>recognize privacy as a fundamental right;<\/li>\n<li>protect children\u2019s privacy and the best interests of the child;<\/li>\n<li>limit organizations\u2019 collection, use and disclosure of personal information to specific and explicit purposes that take into account the relevant context;<\/li>\n<li>expand the list of violations qualifying for financial penalties to include, at a minimum, appropriate purposes violations;<\/li>\n<li>provide a right to disposal of personal information even when a retention policy is in place;<\/li>\n<li>create a culture of privacy by requiring organizations to build privacy into the design of products and services and to conduct privacy impact assessments for high-risk initiatives;<\/li>\n<li>strengthen the framework for de-identified and anonymized information;<\/li>\n<li>require organizations to explain, on request, all predictions, recommendations, decisions and profiling made using automated decision systems;<\/li>\n<li>limit the government\u2019s ability to make exceptions to the law by way of regulations;<\/li>\n<li>provide that the exception for disclosure of personal information without consent for research purposes only applies to scholarly research;<\/li>\n<li>allow individuals to use authorized representatives to help advance their privacy rights;<\/li>\n<li>provide greater flexibility in the use of voluntary compliance agreements to help resolve matters without the need for more adversarial processes;<\/li>\n<li>make the complaints process more expeditious and economical by streamlining the review of the Commissioner\u2019s decisions;<\/li>\n<li>amend timelines to ensure that the privacy protection regime is accessible and effective;<\/li>\n<li>expand the Commissioner\u2019s ability to collaborate with domestic organizations in order to ensure greater coordination and efficiencies in dealing with matters raising privacy issues.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p>Among the improvements C-27 has over C-11, Dufresne said, is the addition of a preamble to offer guidance on the law\u2019s broader objectives; new provisions to help protect the privacy of minors; an expansion of personal information that individuals can request be disposed of; amendments to require that information provided to obtain valid consent be presented in understandable language; and amendments that grant increased discretion to the Office of the Privacy Commissioner, for example, in relation to complaints and investigations.<\/p>\n<p>Other differences between C-27 and the previous version that Dufresne likes include an expanded requirement to ensure that the manner in which personal information is collected, used, and disclosed is appropriate; an amendment to accountability measures requiring organizations to maintain privacy management programs; and a new requirement to authenticate identity as part of security safeguarding requirements.<\/p>\n<p>Businesses may focus their attention on the Commissioner&#8217;s insistence that CPPA limit organizations\u2019 collection, use and disclosure of personal information to specific and explicit purposes that take into account the relevant context.<\/p>\n<p>The CPPA, like PIPEDA, sets boundaries for how a firm can collect, use, or disclose personal information, the submission says. However, it adds, under <abbr title=\"Personal Information Protection and Electronic Documents Act\">PIPEDA<\/abbr>, organizations\u2019 purposes for handling personal information need to be &#8216;explicitly specified.&#8217; This important requirement, that purposes be both explicit and specific, is missing from the <abbr title=\"Consumer Privacy Protection Act\">CPPA<\/abbr>. &#8220;Without it,&#8221; says Dufresne&#8217;s submission, &#8220;the door is open to organizations identifying overly broad and ambiguous purposes, such as &#8216;improving customer experience.&#8217;&#8221;<\/p>\n<p>Dufrense also said provisions should be added to the\u00a0<abbr title=\"Consumer Privacy Protection Act\">CPPA<\/abbr> to require organizations to practice privacy by design and to conduct privacy impact assessments for high-risk activities.<\/p>\n<p>His recommendations for changing the CPPA also deal with automated decision-making\u00a0 software systems, like machine learning and AI. The\u00a0<abbr title=\"Consumer Privacy Protection Act\">CPPA<\/abbr> imposes two new obligations on organizations using automated decision-making systems. However, Dufresne says their scope is too limited in areas where there should be increased transparency.<\/p>\n<p>For example, Dufresne&#8217;s submission says, unlike the <abbr title=\"European Union\">EU<\/abbr>\u2019s General Data Protection Regulation (<abbr>GDPR<\/abbr>) and other modern privacy laws in California and Qu\u00e9bec, the obligations do not explicitly apply to profiling. As drafted, the obligations would only apply to automated decision systems that make decisions, recommendations, or predictions. Profiling should be added to that list, the submission says.<\/p>\n<p>The <abbr title=\"Consumer Privacy Protection Act\">CPPA<\/abbr> also requires organizations to provide a general account of the use of any automated decision system that makes predictions, recommendations or decisions that could have a \u201csignificant impact\u201d on individuals. That qualifier should be removed, the submission says.<\/p>\n<p>The post <a href=\"https:\/\/www.itworldcanada.com\/article\/proposed-overhaul-of-canadas-private-sector-privacy-law-a-step-in-the-right-direction-commissioner\/538733\">Proposed overhaul of Canada\u2019s private sector privacy law \u2018a step in the right direction\u2019: Commissioner<\/a> first appeared on <a href=\"https:\/\/www.itworldcanada.com\/\">IT World Canada<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dufresne says proposed bill must still limit the collection, use and disclosure of personal information of customers and<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[58,361,16],"tags":[466,527,512,703,275],"class_list":["post-38202","post","type-post","status-publish","format-standard","hentry","category-government-public-sector","category-privacy","category-security","tag-canadian-government","tag-legislation","tag-privacy-commissioner-of-canada","tag-privacy-legislation","tag-top-story"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/38202","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=38202"}],"version-history":[{"count":2,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/38202\/revisions"}],"predecessor-version":[{"id":38317,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/38202\/revisions\/38317"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=38202"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=38202"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=38202"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}