Showing posts with label Canadian Privacy Commissioner. Show all posts
Showing posts with label Canadian Privacy Commissioner. Show all posts

Friday, March 02, 2012

Google’s New Privacy Policy Questioned by U.S., Canadian, European Authorities

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Google’s new comprehensive privacy policy may not adequately protect consumers’ legal rights and interests, government officials and privacy regulators in the United States, Canada, and Europe have told the company in three separate letters.

According to Google, the policy—which took effect yesterday—is intended to streamline and simplify the privacy policies for its various services by consolidating them into a single policy.

The National Association of Attorneys General (NAAG) sent a letter to Google CEO Larry Page on February 22, signed by 36 attorneys general, declaring that Google’s new policy was “troubling” and “appears to invade consumer privacy.”

Canada’s Privacy Commissioner, Jennifer Stoddart, wrote to Google’s Global Public Policy Manager in Ottawa, seeking additional information about the policy, particularly with regard to the collection of information via Android mobile devices.

On February 27, the French data protection authority, CNIL, also wrote to Page, informing him that the European Union’s Article 29 Data Protection Working Party had invited CNIL to investigate on behalf of the EU member states’ data protection authorities.

State Attorneys General Express Concerns

NAAG expressed concern that the new policy allows for greater information sharing between Google’s products and services without providing consumers an “opt-in” option or meaningful “opt-out” options.

“Google’s new privacy policy is troubling for a number of reasons,” the letter said. “On a fundamental level, the policy appears to invade consumer privacy by automatically sharing personal information consumers input into one Google product with all Google products.”

According to NAAG, users of Google’s many products use them in different ways and expect that information they provide for one product, such as YouTube, would not be synthesized with information they provide for another product, such as Gmail or Google Maps. The new policy “forces” consumers to allow information across all of Google’s products to be shared without giving them the proper ability to opt out, the letter said.

The attorneys general requested to meet with Google “as soon as possible to work toward a solution that will best protect the privacy needs of those who use Google’s products.”

Full text of the letter is available here on NAAG’s website.

Canadian Privacy Commissioner Requests Information

According to Commissioner Stoddart, Google’s new consolidated policy lacked specific provisions relating to data retention and disposal, such as specific deadlines for the deletion of personal information following a user’s request.

“We strongly encourage Google to more clearly explain its data retention and disposal policies and practices, particularly those dealing with data deletion in response to a user request, and would request that you let us know how you intend to address this issue,” Stoddart said.

In addition, the new policy’s apparent removal of the separation between its various products—causing linkage of all of a user’s data together when the user logs into his or her account and uses various services—may make some users uncomfortable, according to Stoddart.

“We would strongly encourage you to make it clearer to users that if they are uncomfortable with these new uses of information, they can create separate accounts,” Stoddart said.

With respect to Android users, Stoddart pointed out that users appeared to have very little choice with regard to the ways Google would collect information from Android devices and link that information to other Google services they use.

“We would appreciate receiving comments from Google with respect to such linking of vast quantities of personal information as a condition of service to use the Android phone,” Stoddart said.

Further information on Stoddart’s letter is available here on the Canadian Privacy Commissioner’s website.

French Data Protection Authority Launches Investigation

CNIL stated that its preliminary analysis of the new policy showed that the policy did not meet the requirements of the European Data Protection Directive, particularly with regard to the information provided to data subjects.

“The new privacy policy provides only general information about all the services and types of personal data Google processes,” CNIL said. “As a consequence, it is impossible for averages users who read the new policy to distinguish which purposes, collected data, recipients or access rights are currently relevant to their use of a particular Google service.”

CNIL stated that it would send Google a full questionnaire on the matter before mid-March 2012. CNIL requested that Google “pause” its implementation of the policy until it had completed its analysis.

The text of CNIL’s letter is available here on the European Commission’s website.

Thursday, June 09, 2011





Google’s Privacy Improvements Satisfy Canadian Enforcer

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Google Inc. has implemented remedial measures to reduce the risk of future privacy violations, such as those that occurred during Google’s collection of WiFi data for its “Street View” service in 2010, according to Canadian Privacy Commissioner Jennifer Stoddart.

Collection of Personal Information

Stoddart initiated an investigation under Canada’s federal private-sector privacy law after Google admitted that it had collected data transmitted over unprotected wireless networks installed in homes and businesses around the globe.

Personal information collected included complete e-mails, usernames and passwords, and home telephone numbers. Stoddart’s investigation concluded that the incident was largely a result of Google’s lack of proper privacy policies and procedures.

New Training, Procedures

The Office of the Privacy Commissioner issued findings and recommendations in October 2010 and asked for a response by February 2011. Stoddart announced on June 6 that the Office is satisfied with the measures that Google has agreed to implement, including the augmentation of privacy and security training provided to all employees; the implementation of a system for tracking projects that collect, use, or store personal information; and the establishment of a process for conducting periodic audits and reviews of privacy practices. Google also told the Office that it had begun to delete the data it collected in Canada.

“Google appears to be well on the way to resolving serious shortcomings in the way in which it addresses privacy issues,” Stoddart said. “However, given the significance of the problems we found during our investigation, we will continue to monitor how Google implements our recommendations.”

More information on the Canadian Privacy Commissioner’s findings can be found here.

Thursday, September 10, 2009





Facebook Agrees to Privacy Safeguards After Canadian Investigation

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Online social networking site operator Facebook has agreed to add significant new privacy safeguards and make other changes in response to the Privacy Commissioner of Canada’s recent investigation into Facebook’s privacy policies and practices, the Privacy Commissioner announced on August 27.

On July 16, Privacy Commissioner Jennifer Stoddart issued a report on an in-depth investigation triggered by a complaint from the Canadian Internet Policy and Public Interest Clinic (CCH Privacy Law in Marketing ¶60,350).

Stoddart was particularly concerned about the risks posed by the over-sharing of personal information with third-party developers of Facebook applications, such as games and quizzes.

Facebook was given 30 days to respond to the Commissioner’s report and explain how it would address the outstanding concerns. Following a review of Facebook’s formal response and discussions with company officials, Stoddart said she is now satisfied that Facebook is on the right path to addressing the privacy gaps on its site.

Changes to Privacy Practices

Facebook has agreed to make changes to help users better understand how their personal information will be used and, ultimately, make more informed decisions about how widely to share that information. The Commissioner’s office will follow up with Facebook as the changes are implemented.

With regard to third-party application developers, Facebook has agreed to retrofit its application platform to prevent any application from accessing information until express consent is obtained for each category of a user’s personal information the developer wishes to access.

According to Facebook, implementing the necessary significant technological changes to its application platform will take one year.

Facebook also agreed to make it clear to users that they have the option of deleting their accounts, rather than merely deactivating them. In addition, Facebook agreed to change the wording of in its privacy policy to explain what will happen in the event of a user’s death.

Further information on the agreement is available here on the Privacy Commissioner’s website.

Friday, August 14, 2009





Facebook Not Complying with Canadian Privacy Law: Report

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

In order to comply with Canadian privacy law, popular social networking website operator Facebook must take greater responsibility for the personal information in its care, according to Canadian Privacy Commissioner Jennifer Stoddart.

On July 16, Stoddard released a report detailing the results of an investigation into Facebook’s privacy policies and practices.

The investigation was prompted by a complaint from the Canadian Internet Policy and Public Interest Clinic, a public-interest legal clinic based at the University of Ottawa. Stoddart said that the investigation identified several areas where Facebook needs to better address privacy issues and bring its practices in line with Canadian privacy law.

Privacy Information Confusing or Incomplete

An overarching concern was that information provided by Facebook about its privacy practices was often confusion or incomplete. For example, the “account settings” page described how to deactivate accounts, but not how to delete them, which actually removes personal data from Facebook’s servers.

The Privacy Commissioner’s report recommends more transparency to ensure that the social networking site’s nearly 12 million Canadian users have the information they need to make meaningful decisions about how widely they share personal information.

Access by Third Parties

The investigation also found that Facebook lacks adequate safeguards to effectively restrict third-party application developers from accessing users’ profile information, the investigation found.

The report recommended technological measures to ensure that developers can access only the user information actually required to run a specific application and to prevent the disclosure of personal information of any of the user’s friends who are not themselves sighing up for an application.

Deactivated Accounts

The Privacy Commission also recommended that Facebook change its policy of indefinitely keeping the personal information of people who have deactivated their accounts. According to the report, the practice violates Canada’s federal Personal Information Protection and Electronic Documents Act (PIPEDA). To comply with PIPEDA, Facebook should delete personal information in deactivated accounts after a reasonable length of time.

The Office of the Privacy Commissioner will review after 30 days the actions Facebook takes to comply with the recommendations. The Commissioner is empowered to go to Canadian federal court to seek to have her recommendations enforced.

Text of the Privacy Commissioner’s report appears at CCH Privacy Law in Marketing ¶60,350.