Information Overload

Privacy protection is an important area of regulatory compliance. It is not new knowledge that government agencies are responsible for privacy protection in their own operations; Canada’s Privacy Act came into effect in 1983, and the United States has had a privacy law on the books since 1974 (the Privacy Act of 1974).

However, many countries lag Canada in terms of privacy governance as applicable to the private sector. In Canada, phased implementation of the Personal Information Protection and Electronic Documents Act (PIPEDA) occurred as early as 2000. In comparison, the General Data Protection Regulation (GDPR) was only implemented in the European Union and the European Economic Area in 2018. In the United States, the California Consumer Privacy Act (CCPA) came into effect in 2020, but there is no federal legislation for the private sector. Despite efforts by advocate groups and politicians in the wake of several serious data breaches that had an impact on many millions of consumers, a private sector privacy bill has yet to pass in the U.S. Congress.

The Canadian landscape

The Office of the Privacy Commissioner of Canada (OPC) is the federal agency that supervises all privacy-related matters. It enforces the Privacy Act for federal institutions, and PIPEDA for the private sector. At the provincial level, three provinces—British Columbia, Alberta, and Quebec—have provincial regulations that are substantially similar to PIPEDA. The private sector in all other provinces and territories is under the jurisdiction of PIPEDA.

Not-for-profit and charity groups, as well as political parties and associations, are not usually within PIPEDA’s scope unless they engage in commercial activities that are not central to their mandate and involve personal information.

Lastly, it is important to remember that PIPEDA deals with the privacy of natural persons. An entity that is not a natural person, such as a company, may very well have confidential information that needs to be protected, but protecting that information is not within PIPEDA’s scope.

What is personal information?

Personally identifiable information (PII) includes a person’s name, address, social insurance number, and date of birth: in short, PII is any information that is linkable to a natural person. The above fields are often sufficient for a credit reporting agency to locate a person in its credit data warehouse and pull that person’s credit report.

It is important to know that personal information is a superset of PII; some information that is not linkable to a natural person is still considered personal information, such as a person’s blood type, ethnic origin, and medical history. While one cannot identify a person simply based on an A negative blood type, or that they immigrated from a particular country, this type of data would still fall under the category of personal information and therefore would be protected by PIPEDA. 

The scope of personal information protected by PIPEDA includes not only factual but also subjective information about a person, along the lines of opinions, evaluations, comments, and social status.

Business card information is usually not considered protectable personal information. Quite intuitively, this means information you would find on a typical business card, such as an employee’s name, title, business address, telephone number or email addresses. These data fields are collected and used for work-related communications.

 

The 10 Fair Information Principles

Businesses must follow the 10 principles laid out in PIPEDA, which provide detailed and clear compliance requirements for how to deal with privacy protection in day-to-day operations.

  1. Accountability: Organizations are accountable for personal information under its control, and are required to appoint a staff member to ensure compliance with PIPEDA. Depending on size and budget, many businesses have either created a dedicated privacy officer role or have added the responsibility to an existing officer.
  2. Identifying purposes: Why are you collecting the personal information? This must be spelled out before or at time of collection.
  3. Consent: Your consumers need to acknowledge that you have told them the purpose for collecting the information, and to give you the go-ahead for collection.
  4. Limiting collection: If you have received consent to collect information for Purpose A, then you cannot use the information later for Purpose B. You need to obtain specific consent for Purpose B.
  5. Limiting use, disclosure, and retention: The “limiting use and disclosure” requirement repeats the fourth principle somewhat. If businesses have gathered information for Purpose A, they cannot simply use the information for Purpose B unless a new consent is received specifically for Purpose B (this point will be illustrated with examples in the next section “Application of these principles in the investment industry”). The “retention” requirement means personal information may only be kept as long as necessary to serve those purposes.
  6. Accuracy: Businesses have an obligation to ensure the personal information on file is as accurate, complete, and up-to-date as reasonably possible.
  7. Safeguards: Organizations are required to protect personal information with appropriate security measures. Recent high-profile data breaches in the financial services industry highlight the importance of safeguarding clients’ personal information.
  8. Openness: Organizations are required to make detailed information about privacy protection policies and practices publicly and readily available. As an example of best practices, many businesses display the link to their privacy policies at a prominent position on the home page of their websites. Some businesses include a printed copy of the privacy policies on a regular basis (usually once a year) when they mail statements to clients.
  9. Individual access: Consumers can request and be informed of a business’s use and disclosure of their personal information, and can also request a copy of that information. Note that businesses are expected to respond to the request with the information package within 30 calendar days. Under some circumstances, businesses can ask for an extension of another 30 days. Consumers can challenge the accuracy and completeness of the information and have it corrected as appropriate.
  10. Challenging compliance: Consumers are able to challenge an organization’s compliance with these fair information principles. Challenges are typically addressed to the organization’s own privacy officer.

Application of these principles in the investment industry

The OPC publishes actions and decisions when it completes the review of a complaint or an incident. On its website Investigations into businesses), one can go view a database that houses detailed incident and complaint reports about private businesses.

These cases range by type of business, severity of alleged non-compliance, year and date of incident, and the principle that the defendant has allegedly violated. The reports on most incidents do not identify the businesses, but reports on some severe incidents do not omit that information. Cases #2019-001 and #2008-395, for example, name the businesses that were in serious non-compliance with PIPEDA.

The cases discussed next are two different examples of PIPEDA non-compliance, which illustrate other instances that investment professionals and management can encounter. 

OPC Case #2015-016

Consider OPC Case #2015-016 in which the non-compliant parties are named. Shortly after giving birth, a woman received a phone call from someone trying to sell her a Registered Education Savings Plan (RESP) for her newborn. The call was made by a company selling investment products. The woman was told by the sales representative that they had received her information from the hospital where she had given birth. Stories in the media after the incident reported that two former hospital employees had been involved in the sale of thousands of patients’ information; this news prompted the woman to file a complaint with the OPC.

Without digging much deeper, we can see that the hospital was not in compliance with the principles of safeguards, at least, and did not protect patient data from being breached. The investment firm, by purchasing and using the patients’ data to conduct cold calls to solicit new business, violated the principles of consent, limiting collection, and limiting use and disclosure.

OPC Case #2001-17

Not all cases are so clear-cut, and not all cases involve data leaks for a malicious purpose. Some incidents and complaints received by the OPC have a high level of subtlety and nuance. Case #2001-17 is an example of such a case.

An employee of a large corporation complained that his employer was improperly disclosing employee personal information, including information related to cash bonuses, to the investment firm involved in an RRSP and savings plan sponsored by the corporation. Employees did not have prior knowledge of this, and therefore did not give consent to such disclosure.

During the investigation, the corporation in question admitted to disclosing certain personal information without explicit consent to the investment firm. Data fields that were transmitted to the investment firm contained PII (including social insurance number) and more (including gender).

The OPC website does not provide more detail about the incident, but one can reasonably assume the employer shared the information with good intentions—in this case, to set up employees for proper RRSP contributions. However, the existence of good intentions does not release the employer from the responsibility of collecting consent. And, as investment professionals, we might ask how someone’s gender has anything to do with RRSP setup or asset allocation in any way. Therefore, the employer’s practice is questionable with respect to several of the fair information principles, particularly “identifying purposes,” “consent,” and “limiting use and disclosure.”

Some final comments

Most businesses want to do the right thing for their clients and employees. However, some careless slips in terms of purposes, consent, uses, and safeguards could result in a complaint and an OPC investigation. When you want to call your clients to ask them to donate to a charity, stop and ask whether clients gave you their phone numbers for this purpose. When you intend to buy a marketing list for business development, stop and ask whether the seller has been given the consent to sell personal information to your organization: a third-party, in this case. When you are transmitting client or employee personal data for a permissible purpose after you have received their consent, stop and ask whether you are using reasonably secure encryption and file transfer methods. Simply sending a spreadsheet by email, without any password protection, may result in a data leak, causing your organization to fall into non-compliance with the principle of safeguards.

When it comes to privacy matters, it pays to slow down and ask the right questions, starting with the PIPEDA fair information principles.