2011 Pipeda E.Pdf
Total Page:16
File Type:pdf, Size:1020Kb
Office of the Privacy Commissioner of Canada Report on the Annual Report to Parliament 2011 Personal Information Protection and Electronic Documents Act The drawings on this page and throughout the report are the works of the children of employees at the Office of the Privacy Commissioner of Canada. Office of the Privacy Commissioner of Canada 112 Kent Street Ottawa, Ontario K1A 1H3 (613) 947-1698, 1-800-282-1376 Fax (613) 947-6850 TDD (613) 992-9190 © Minister of Public Works and Government Services Canada 2012 Cat. No. IP51-1/2011 1910-0051 This publication is also available on our website at www.priv.gc.ca. Follow us on Twitter: @privacyprivee June 2012 The Honourable Noël A. Kinsella, Senator The Speaker The Senate of Canada Ottawa, Ontario K1A 0A4 Dear Mr. Speaker: I have the honour to submit to Parliament the Annual Report of the Office of the Privacy Commissioner of Canada on the Personal Information Protection and Electronic Documents Act for the period from January 1 to December 31, 2011. Yours sincerely, Original signed by Jennifer Stoddart Privacy Commissioner of Canada June 2012 The Honourable Andrew Scheer, M.P. The Speaker The House of Commons Ottawa, Ontario K1A 0A6 Dear Mr. Speaker: I have the honour to submit to Parliament the Annual Report of the Office of the Privacy Commissioner of Canada on the Personal Information Protection and Electronic Documents Act for the period from January 1 to December 31, 2011. Yours sincerely, Original signed by Jennifer Stoddart Privacy Commissioner of Canada Table of Contents Message from the Commissioner ...............................................................................1 Privacy by the Numbers in 2011 .................................................................................7 1. Overview of 2011 .....................................................................................................9 1.1 Serving Canadians ........................................................................................................ 9 1.2 Supporting Parliament ...............................................................................................10 1.3 Supporting Organizations .........................................................................................11 1.4 Advancing Knowledge ...............................................................................................12 1.5 Global Initiatives ..........................................................................................................13 1.6 Technology Lab ............................................................................................................15 2. Key Issue: Children and Youth Privacy ...............................................................17 2.1 Investigations Relating to Children and Youth ....................................................20 • Nexopia .......................................................................................................................20 • Webcam use in a daycare ......................................................................................25 2.2 Surveillance of Children .............................................................................................26 2.3 Youth Outreach Initiatives .......................................................................................27 2.4 Digital Literacy ............................................................................................................28 2.5 Contributions Program - Projects for Youth ........................................................30 3. The Privacy Landscape Overview of other major issues addressed by the OPC .......................................31 3.1 Financial Privacy ..........................................................................................................32 • Investigations ...........................................................................................................32 • Task Force for the Payments System Review ....................................................36 3.2 Biometrics .....................................................................................................................37 • Investigation .............................................................................................................37 • Biometrics Guidance Document .........................................................................41 3.3 Online Privacy .............................................................................................................42 • Investigations (Facebook, Google) ......................................................................42 • Canada’s Anti-Spam Legislation .........................................................................46 • Consumer Privacy Consultations .........................................................................47 • Online Behavioural Advertising Guidance .........................................................48 • Privacy Poll .................................................................................................................49 • Technology Lab .........................................................................................................50 3.4 Modernization of Privacy Laws ..............................................................................50 • Implementing Amendments to PIPEDA ...........................................................50 • Reducing the Risk of Data Breaches ..................................................................51 • PIPEDA review ...........................................................................................................52 Table of Contents 4. Meeting the Concerns of Canadians ..................................................................53 4.1 Information Requests ..............................................................................................53 4.2 Intake ...........................................................................................................................54 4.3 Complaints Received ...............................................................................................54 4.4 Complaints by Industry Sector .............................................................................55 4.5 Types of Complaints Received ..............................................................................56 4.6 Early Resolution ........................................................................................................56 4.7 Complaint Investigations ........................................................................................59 4.8 Snapshot of 2011 Investigations ..........................................................................60 4.9 Data Breaches ...........................................................................................................67 5. Reaching out to Canadians ...................................................................................71 5.1 Toronto Office ............................................................................................................72 5.2 Self-Assessment Tool for Organizations ............................................................73 5.3 Small Business Week – Cyber Security ..............................................................74 5.4 Business Poll ..............................................................................................................75 5.5 Lawyers’ Handbook ..................................................................................................75 5.6 Data Privacy Day 2011 ...........................................................................................76 5.7 Outreach Across Canada .......................................................................................76 5.8 Contributions Program ............................................................................................76 5.9 Speaking Engagements ...........................................................................................78 6. In the Courts ...........................................................................................................79 7. Substantially Similar Provincial and Territorial Legislation ..............................83 8. The Year Ahead ......................................................................................................85 Appendix 1 ...................................................................................................................91 Definitions ...........................................................................................................................91 Investigation Process .........................................................................................................94 Appendix 2 ...................................................................................................................96 PIPEDA Investigation Statistics for 2011 .....................................................................96 The Personal Information Protection and Electronic Documents Act, or PIPEDA, sets out ground rules for the management of personal information in the private sector. The legislation balances an individual’s right to the privacy of personal information with the need of organizations to collect, use or disclose personal information for legitimate business purposes. PIPEDA applies to organizations engaged in commercial activities across the country, except in provinces that have substantially similar