Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Thursday, January 13, 2011





Canada Enacts Anti-Spam, Phishing, Spyware Legislation

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

New Canadian anti-spam law legislation was approved by Parliament and received Royal Assent on December 15, 2010. The “Fighting Internet and Wireless Spam Act” (Statutes of Canada 2010, c. 23; Bill C-28) prohibits the sending of commercial electronic messages without the prior consent of the recipient. The legislation also addresses threats from other types of unsolicited electronic contact, including identity theft, phishing, spyware, viruses, and botnets.

The law grants a right of civil action to businesses and consumers targeted by the perpetrators of such activities. It will come into force on a day or days to be fixed by order of the Governor in Council.

Spam

Along with the prior consent requirement, the legislation provides that commercial e-mail messages must:

(1) Identify the person who sent the message and the person on whose behalf it is sent,

(2) Provide accurate contact information for these parties, and

(3) Set out an unsubscribe mechanism as outlined in the legislation.
The prohibition on spam does not apply to messages that facilitate, complete, or confirm a commercial transaction that has already been agreed to by the recipient, or that provides warranty, product recall, safety, or security information about a product, good, or service that the recipient has used or purchased.

Phishing

The same consent requirement for spam also applies to phishing messages. Phishing is described as e-mail that is sent from what appears to be an organization the recipient knows, such as a bank, requiring the recipient to send back personal information or confirm the information via a link.

Alterations of Transmissions

The legislation prohibits certain activities regarding electronic communications between two parties that have been intercepted. Such transmissions may not be altered so that the message is sent or copied anywhere other than where the sender thinks it is going.

All alterations to the transmission data require the express consent of the sender, with the ability to withdraw that consent at will. Service providers are exempt from this requirement, because they sometimes need to alter transmission data for technical reasons.

Unauthorized Software

The statute provides that no one may, in the course of a commercial activity, install or cause to be installed a computer program on any other person’s computer system, nor may anyone use any installed program to cause an electronic message to be sent from another person’s computer, without the owner’s express consent. This provision is aimed particularly at the surreptitious installation of spyware and malware.

Enforcement and Penalties

The law designates the Canadian Radio-television and Telecommunications Commission as the main regulatory agency responsible for pursuing administrative penalties against violators. The CRTC is given investigative powers by the statute, including the power to require production of documents.

The maximum penalty for an individual is $1 million and the maximum penalty for a corporation or other organization is $10 million. These penalties are to be imposed per violation.

The law also amends the Personal Information Protection and Electronic Documents Act (CCH Privacy Law in Marketing ¶42,200) to expand the Privacy Commissioner’s discretion and permit the Office of the Privacy Commissioner to take measures against the unauthorized collection of personal information through hacking or illicit trading of lists of electronic addresses.

In addition, the law amends the Competition Act, giving the Competition Bureau and the Commissioner of Competition a role in investigating and enforcing the new anti-spam provisions. Under the anti-spam legislation, the Competition Act’s existing regime on misleading and deceptive practices has been expanded to include online activity.

Private Right of Action

Persons affected by violations are able to bring a private action for actual damages. Courts may also award statutory damages of $200 for each violation, up to a maximum of $1 million per day.

Text of the legislation will appear in CCH Privacy Law in Marketing. More information on the law is available here at the Canadian Parliament’s website.

Thursday, June 10, 2010





Data Breach Notice, Anti-Spam Laws Proposed in Canada

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Proposed privacy legislation introduced on May 25, 2010 in the Canadian Parliament would create an obligation for Canadian businesses to notify the government and, in some cases, individuals of data security breaches and would place new restrictions on Internet and wireless spam.

Bill C-29 would add provisions to Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) (CCH Privacy Law in Marketing ¶42,200) to require organizations to report material breaches of data security safeguards to the Privacy Commissioner. Organizations would have to notify individuals of data security breaches only when such breaches create a risk of significant harm.

Disclosure of Personal Information

In addition, the measure would amend PIPEDA to permit the disclosure of personal information without the knowledge or consent of the individual for the purposes of:

(1) Identifying an injured, ill, or deceased individuals and communicating with their next of kin;

(2) Performing police services;

(3) Preventing, detecting, or suppressing fraud; and

(4) Protecting victims of financial abuse.

Spam, Spyware

Another bill (Bill C-28) proposes the enactment of a new statute, the “Fighting Internet and Wireless Spam Act.” That legislation would prohibit the sending of commercial electronic messages without the prior consent of the recipient and would provide rules governing the sending of such messages, including a mechanism for the withdrawal of consent.

The statute would also prohibit the alteration of data transmissions and the unauthorized installation of spyware programs on computers. Violations would be subject to administrative monetary penalties by the Canadian Radio-television and Telecommunications Commission. Persons affected by violations would be able to bring a private action for actual and statutory damages.

Bill C-28 also would amend PIPEDA to prohibit the collection of personal information by means of unauthorized access to computer systems, as well as the unauthorized compilation of lists of electronic addresses.

“Canadian shoppers should feel just as confident in the electronic marketplace as they do at the corner store,” said Minister of Industry Tony Clement.

“With today’s two pieces of legislation, we are working toward a safer and more secure online environment for both consumers and businesses—essential in positioning Canada as a leader in the digital economy,” he added.

Thursday, December 10, 2009





EU Adopts New Rules on Data Breaches, Cookies, Spyware

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Telecommunications service providers in European Union member states will be required to notify customers of security breaches that compromise their personal data, under new amendments to the EU’s Directive on Privacy and Electronic Communications ("ePrivacy Directive,” CCH Privacy Law in Marketing ¶40,110).

The amendments to the ePrivacy Directive were part of a sweeping telecommunications reform package approved by the European Parliament on November 24, 2009.

The breach notification rules are the first of their kind in Europe, although unlike breach notification laws in the United States, the ePrivacy Directive’s notice requirements will be limited to telecommunications providers.

The legislation also reinforces protection against the interception of users’ communication through the use of spyware and cookies stored on a user’s computer or other device. The amended ePrivacy Directive requires websites to provider users with better information and easier ways to control whether they want cookies stored on their computers.

The amendments also (1) give Internet service providers the right to protect their business and their customers through legal action against spammers and (2) substantially strengthen the enforcement powers of national data protection authorities.

“The new provisions will bring vital improvements in the protection of the privacy and personal data of all Europeans active in the online environment,” according to European Data Protection Supervisor Peter Hustinx.

“The improvements relate to security breaches, spyware, cookies, spam, and enforcement of rules,” he said. “But it is now crucially important to broaden the scope of the security breach provisions to all sectors and further define the procedures for notification.”

The revised ePrivacy Directive, as amended by the European Parliament and adopted by the European Council, must be implemented by the member states within 18 months.

The amendments to the ePrivacy Directive will be reflected in CCH Privacy Law in Marketing. They appear on pages 71 to 83 of the telecom legislation found here on the European Union website.

Thursday, May 07, 2009





Privacy Laws Proposed in Congress, Canadian Parliament

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Federal laws addressing privacy concerns have been introduced recently in both Congress and Canada’s Parliament.

Data Security, Breach Notification

The Congressional proposal would regulate information security standards and breach notification procedures. The proposed “Data Accountability and Trust Act” (H.R. 2221) would require persons engaged in interstate commerce that own or possess data in electronic form containing personal information—or that contract to have a third-party maintain such data—to establish and implement reasonable security policies and procedures to protect that data. The measure would also provide for nationwide notice in the event of a security breach.

The proposed law would be enforced by the Federal Trade Commission and state attorneys general. A private right of action would not be available, and the federal statute would preempt state data security and breach notification laws and regulations.

The bill, introduced April 30, was sponsored by Rep. Bobby Rush (D-Ill.) and co-sponsored by Reps. Cliff Stearns (R-Fla.), Joe Barton (R-Tex.), Jan Schakowsky (D-Ill.), and George Radanovich (R-Calif.). Further information—and text of the bill—appears at the Thomas site of the Library of Congress.

Spam, Phishing

The Canadian legislation is aimed at deterring “the most dangerous forms of spam” and threats posed to privacy and personal security by Internet fraud.

The proposed “Electronic Commerce Protection Act” (ECPA) would prohibit the sending of commercial electronic messages without the prior consent of the recipient and would provide rules regulating the sending of such messages, including a mechanism for withdrawal of consent. It would also prohibit the alternation of e-commerce data transmissions and the unauthorized installation of computer addresses.

Persons injured by violations would have a private right of action for actual and statutory damages. The Canadian Radio-television and Telecommunications Commission and the Competition Bureau would also be authorized to impose administrative monetary penalties of up to $1 million Canadian for individuals and $10 million Canadian for all other offenders.

The proposal (Bill C-27) was introduced in the House of Commons of Canada on April 24. Text of the bill is available here.