Title: Privacy, Security, ECommerce and the Internet:
1Privacy, Security, E-Commerce and the Internet
Brian Foran Director of Privacy Impact
Assessment, Office of the Privacy Commissioner or
Canada
March 25, 2002
2Privacy and EthicsPrivacy and the LawPrivacy
and Technology
3Privacy and Ethics
4The claim to privacy finds moral justification in
the recognition that people need to have control
over matters that intimately relate to them
- Online Ethics Centre for Engineering and Science
5If privacy is diminished, we will not be able to
function fully as human beings
6Privacy is at the heart of liberty in the modern
state
- former Canadian Supreme Court Justice La Forest
7Privacy, security and confidentiality
8Privacy is the right to be let alone
- Justice Louis Brandeis Olmstead Vs. US 1928
9Privacy is the claim of individuals to determine
for themselves when, how, and to what extent
information about them is communicated to others.
- Alan Westin Privacy and Freedom 1967
10Privacy is the right to control access to ones
person and to information about oneself
- George Radwanski Privacy Commissioner of
Canada
11Types of privacy
- territorial privacy
- bodily privacy
- communications privacy
- informational privacy
12Informational privacy
- Concerning the collection and handling of
personal data such as credit information and
medical records
13In an information society, our individual
autonomy and our control are on the line
14Privacy ? Security Privacy ? Confidentiality
15Privacy
- An individual right
- individual control over ones own personal
information
16Confidentiality
- An obligation of a custodian to protect the
personal information in which it has been
entrusted
17Security
- The process or manner of assessing the threats
and risks and - taking appropriate steps to protect the
information
18Privacy and the law
191. Privacy Act (public sector) 2. PIPED Act
(private sector)
20The Privacy Act An information handlers code of
ethics for the federal government
21- Its purpose
- to protect the privacy of an individuals
personal information held by federal government
institutions
22- Privacy Act
- limits the governments collection of personal
information to what is necessary and relevant
23- Privacy Act
- requires the government to advise the individual
directly of the purpose for this information
prior to the collection
24- Privacy Act
- recognizes the inherent right of information
ownership by the individual from whom it is
collected
25- Privacy Act
- outlaws unrelated uses and disclosures of this
personal information
26Privacy Act authorizes an independent ombudsman
- the Privacy Commissioner of Canada - to
27- Investigate complaints
- resolve problems
- conduct privacy audits
- oversee the governments compliance with the Act
28ThePersonal Information and Electronic Documents
Act (PIPED Act)
29Accords privacy protection to Canadians in their
dealings with the private sector
30Private-sector organizations covered under the
new law cannot
31- Collect
- use or disclose
- personal information about someone without his or
her consent
32It applies to the federally regulated - banks -
telecommunications - broadcasting - transportation
33It also applies to the sale of personal
information across provincial or national borders
34It also applies to the three territories, where
the whole private sector is a federal work under
the Constitution.
35Privacy and Technology
36- Engineering and Privacy
- building privacy into systems and technology
37Digital AngelMobiltrakBiometrics
38Canadian Information Processing Society
(CIPS)www.cips.ca
39COACHwww.coachorg.com
40Computer Professionals for Social
Responsibilitywww.cpsr.org
41Computers, Freedom and Privacywww.cfp.org
42Privacy should be built in at the outset
43Privacy Impact Assessment
- analysis of the likely impacts on privacy of a
project, practice or system
44Privacy Impact Assessment
- A feasibility study from a privacy perspective
45Office of the Privacy Commissioner of
Canada www.privcom.gc.ca