SUBSCRIBE

Federal privacy commissioner to initiate investigations, not just wait for complaints

Sensing that Canadians lack confidence in the private sector and government on safeguarding and using their personal data, the federal privacy commissioner says heโ€™s temporarily no longer going to wait until people file complaints about alleged privacy issues before acting.

Instead, Daniel Therrien will be more proactive, including launching investigations into questionable privacy practices or โ€œchronic problemsโ€ on his own when necessary.

Daniel Therrien

And, he warned, โ€œwhen we will launch Commissioner-initiated complaints, we will also, when appropriate, ask organizations to demonstrate accountabilityโ€ of their privacy management practices.

In a complaints-driven investigation privacy accountability is one of the matters the commission office is entitled to look into under the law. That will apply in a commission-ordered investigation.

โ€œDonโ€™t wait until we come to your doorโ€ acting on a complaint, Therrien said in an interview. โ€œAccountability should include the concept that if we do come to the door, even though you have not violated the law necessarily, you should be able to demonstrate that you have programs to protect privacy.โ€

Itโ€™s what Therrien called the commissionโ€™s new policy of โ€œproactive compliance.โ€

โ€œSomething has to change or we run the risk Canadians will lose trust in the digital community, thus hindering its growth,โ€ he said Wednesday at the opening of the annual International Association of Privacy Professionalsโ€™ Canadian conference in Toronto.

That lack of trust, he added, may impact the spread of innovation.

โ€œMore fundamentally โ€ฆ it is quite unhealthy in a democracy when most citizens fear one of their most basic rights is routinely not respected.โ€

His office will draw on complaints and trends to determine if there are issues or sectors that would benefit from a special investigation. In an interview he said investigations would be on โ€œissues of broad concern.โ€

This โ€œproactive enforcementโ€ will will last at least until September, when Therrien files his annual report to Parliament, where he may call for changes to federal legislation to update his officeโ€™s mandate.

โ€œI donโ€™t want to worry organizations in this group [at the conference],โ€ he added. โ€œTo the contrary I believe this approach will shift the focus to addressing those privacy threats posing the greatest risk to Canadians. It will also assist compliance-minded organizations to avoid restrict misststeps that are costly to their businesses and their consumers.โ€

As part of being proactive, to help the private sector Therrien is considering offering to audit companies โ€“ perhaps for a fee โ€“ to see if they comply with the Personal Information Protection and Electronic Documents Act (PIPEDA).

A survey done by his office shows 92 per cent of Canadian respondents are concerned about protection of privacy, he said, and nearly half said they felt theyโ€™ve lost control over how organizations collect and use their personal data.

โ€œSo what I propose is a slight course correction, a tilting of the scales โ€“ itโ€™s not a revolution.โ€

โ€œWhile we will continue to investigate complaints we will look for ways to be more proactive. We will take key privacy principles to the next level and champion demonstrable accountability and our work will be more citizen focused.โ€

In addition โ€œwe will pay close attention to whatโ€™s happening on the international frontโ€ to make sure the privacy rights of Canadians are their data is respected when they travel.

โ€œMy hope is this will all lead to improved outcomes for privacy protection of Canadians.โ€

Therrien oversees enforcement (PIPEDA), which covers private sector companies that come under federal jurisdictional, and the Privacy Act, which covers the federal government.

In an interview Therrien said there wasnโ€™t a particular incident that led to his decision. Instead, it was the realization that โ€œweโ€™re looking at extremely small portion of the pieโ€ of privacy issues by dealing with complaints. In addition, he added, he likes the ability of privacy commissioners in the U.K. and Ireland to offer to do voluntary privacy audits for businesses.

โ€œWe need to look at a broader set of facts and business models if privacy is to be protected.โ€

In their investigation of complaints, annual reports to Parliament and speeches federal privacy commissioners have been outspoken.

In addition the office launches research. For example, new research was announced this week into privacy issues surrounding connected cars, smart toys and the countryโ€™s data brokerage industry. There is also a report in the works are on how whether individuals properly consent to the use of personal data (due in September). Heโ€™s also called for legislative change that would require written information-sharing agreements between federal institutions or with other levels of government, foreign states and organizations to protect personal data. And he also wants an explicit requirement that federal institutions only collect information necessary for the operation of a government program or activity.

Therrien has also told Parliament his office needs in addition to his powers as ombudsman the ability to make recommendations, make orders and issue fines โ€œto make sure so-called bad actors are brought into line.โ€

Donโ€™t expect a flurry of privacy commission investigation. Therrien said he does have resource limitations and investigating of complaints usually has priority.

Tech Jobs

Categories