Privacy protection is an important area of regulatory compliance. It is not new knowledge that government agencies are responsible for privacy protection in their own operations; Canada’s Privacy Act came into effect in 1983, and the United States has had a privacy law on the books since 1974 (the Privacy Act of 1974).
However, many countries lag Canada in terms of privacy governance as applicable to the private sector. In Canada, phased implementation of the Personal Information Protection and Electronic Documents Act (PIPEDA) occurred as early as 2000. In comparison, the General Data Protection Regulation (GDPR) was only implemented in the European Union and the European Economic Area in 2018. In the United States, the California Consumer Privacy Act (CCPA) came into effect in 2020, but there is no federal legislation for the private sector. Despite efforts by advocate groups and politicians in the wake of several serious data breaches that had an impact on many millions of consumers, a private sector privacy bill has yet to pass in the U.S. Congress.
The Canadian landscape
The Office of the Privacy Commissioner of Canada (OPC) is the federal agency that supervises all privacy-related matters. It enforces the Privacy Act for federal institutions, and PIPEDA for the private sector. At the provincial level, three provinces—British Columbia, Alberta, and Quebec—have provincial regulations that are substantially similar to PIPEDA. The private sector in all other provinces and territories is under the jurisdiction of PIPEDA.
Not-for-profit and charity groups, as well as political parties and associations, are not usually within PIPEDA’s scope unless they engage in commercial activities that are not central to their mandate and involve personal information.
Lastly, it is important to remember that PIPEDA deals with the privacy of natural persons. An entity that is not a natural person, such as a company, may very well have confidential information that needs to be protected, but protecting that information is not within PIPEDA’s scope.
What is personal information?
Personally identifiable information (PII) includes a person’s name, address, social insurance number, and date of birth: in short, PII is any information that is linkable to a natural person. The above fields are often sufficient for a credit reporting agency to locate a person in its credit data warehouse and pull that person’s credit report.
It is important to know that personal information is a superset of PII; some information that is not linkable to a natural person is still considered personal information, such as a person’s blood type, ethnic origin, and medical history. While one cannot identify a person simply based on an A negative blood type, or that they immigrated from a particular country, this type of data would still fall under the category of personal information and therefore would be protected by PIPEDA.
The scope of personal information protected by PIPEDA includes not only factual but also subjective information about a person, along the lines of opinions, evaluations, comments, and social status.
Business card information is usually not considered protectable personal information. Quite intuitively, this means information you would find on a typical business card, such as an employee’s name, title, business address, telephone number or email addresses. These data fields are collected and used for work-related communications.
The 10 Fair Information Principles
Businesses must follow the 10 principles laid out in PIPEDA, which provide detailed and clear compliance requirements for how to deal with privacy protection in day-to-day operations.
Application of these principles in the investment industry
The OPC publishes actions and decisions when it completes the review of a complaint or an incident. On its website Investigations into businesses), one can go view a database that houses detailed incident and complaint reports about private businesses.
These cases range by type of business, severity of alleged non-compliance, year and date of incident, and the principle that the defendant has allegedly violated. The reports on most incidents do not identify the businesses, but reports on some severe incidents do not omit that information. Cases #2019-001 and #2008-395, for example, name the businesses that were in serious non-compliance with PIPEDA.
The cases discussed next are two different examples of PIPEDA non-compliance, which illustrate other instances that investment professionals and management can encounter.
OPC Case #2015-016
Consider OPC Case #2015-016 in which the non-compliant parties are named. Shortly after giving birth, a woman received a phone call from someone trying to sell her a Registered Education Savings Plan (RESP) for her newborn. The call was made by a company selling investment products. The woman was told by the sales representative that they had received her information from the hospital where she had given birth. Stories in the media after the incident reported that two former hospital employees had been involved in the sale of thousands of patients’ information; this news prompted the woman to file a complaint with the OPC.
Without digging much deeper, we can see that the hospital was not in compliance with the principles of safeguards, at least, and did not protect patient data from being breached. The investment firm, by purchasing and using the patients’ data to conduct cold calls to solicit new business, violated the principles of consent, limiting collection, and limiting use and disclosure.
OPC Case #2001-17
Not all cases are so clear-cut, and not all cases involve data leaks for a malicious purpose. Some incidents and complaints received by the OPC have a high level of subtlety and nuance. Case #2001-17 is an example of such a case.
An employee of a large corporation complained that his employer was improperly disclosing employee personal information, including information related to cash bonuses, to the investment firm involved in an RRSP and savings plan sponsored by the corporation. Employees did not have prior knowledge of this, and therefore did not give consent to such disclosure.
During the investigation, the corporation in question admitted to disclosing certain personal information without explicit consent to the investment firm. Data fields that were transmitted to the investment firm contained PII (including social insurance number) and more (including gender).
The OPC website does not provide more detail about the incident, but one can reasonably assume the employer shared the information with good intentions—in this case, to set up employees for proper RRSP contributions. However, the existence of good intentions does not release the employer from the responsibility of collecting consent. And, as investment professionals, we might ask how someone’s gender has anything to do with RRSP setup or asset allocation in any way. Therefore, the employer’s practice is questionable with respect to several of the fair information principles, particularly “identifying purposes,” “consent,” and “limiting use and disclosure.”
Some final comments
Most businesses want to do the right thing for their clients and employees. However, some careless slips in terms of purposes, consent, uses, and safeguards could result in a complaint and an OPC investigation. When you want to call your clients to ask them to donate to a charity, stop and ask whether clients gave you their phone numbers for this purpose. When you intend to buy a marketing list for business development, stop and ask whether the seller has been given the consent to sell personal information to your organization: a third-party, in this case. When you are transmitting client or employee personal data for a permissible purpose after you have received their consent, stop and ask whether you are using reasonably secure encryption and file transfer methods. Simply sending a spreadsheet by email, without any password protection, may result in a data leak, causing your organization to fall into non-compliance with the principle of safeguards.
When it comes to privacy matters, it pays to slow down and ask the right questions, starting with the PIPEDA fair information principles.