Evidence of meeting #34 for Access to Information, Privacy and Ethics in the 41st Parliament, 1st Session. (The original version is on Parliament’s site, as are the minutes.) The winning word was audit.

A recording is available from Parliament.

On the agenda

MPs speaking

Also speaking

Jennifer Stoddart  Privacy Commissioner, Office of the Privacy Commissioner of Canada
Chantal Bernier  Assistant Privacy Commissioner, Office of the Privacy Commissioner of Canada

11:40 a.m.

Privacy Commissioner, Office of the Privacy Commissioner of Canada

Jennifer Stoddart

Yes, certainly we're looking at enforcement issues. There are some technical issues that have come up in previous work, but certainly enforcement is a major topic for consideration, because as you know now, there's an investigation, and if the alleged victim, the complainant, consents and the case is not resolved, we can go to the Federal Court.

In the Federal Court there are no statutory damages, and this differs from the privacy regimes now in comparable countries. People who have suffered some harm in the Ontario Court of Appeal spoke to this recently in a case. There should be some recognition of the harm they've suffered.

Strengthening the enforcement regime, I would think, would be something that should be considered at this point. There has to be some kind of sanction, on the one hand, for companies that don't pay attention to privacy, and on the other hand there has to be some recognition that if this is an important value, well, people should be compensated.

The Chair NDP Pierre-Luc Dusseault

Thank you. Your time is up.

Ms. Borg, the floor is yours for five minutes.

Charmaine Borg NDP Terrebonne—Blainville, QC

Thank you, Mr. Chair.

I want to thank Ms. Stoddart and Ms. Bernier for joining us today.

Ms. Stoddart, when you talked about CATSA, you highlighted a problem regarding protocol compliance by private companies with contracts for passenger screening. You mentioned certain gaps in their methods of data disposal and incident report safeguarding. In Bill C-30, the reliance on private companies to collect and safeguard personal information is apparent. Are you concerned by this increased reliance? Is that a current trend?

11:40 a.m.

Privacy Commissioner, Office of the Privacy Commissioner of Canada

Jennifer Stoddart

I will ask the assistant commissioner to answer your question.

11:40 a.m.

Assistant Privacy Commissioner, Office of the Privacy Commissioner of Canada

Chantal Bernier

Exactly. Public-private partnerships have an impact on privacy. Continuity must be established in the protection of privacy, and that continuity must be ensured through a strong and effective legislative framework.

In CATSA's case, that contract ensured that the agency's obligations with regard to privacy also applied to subcontractors. Therefore, this violation of privacy was non-compliant, and it violated the Privacy Act.

CATSA acknowledged the fact that it needed to improve its monitoring of contractors when it comes to privacy. Therefore, we expect improvements in the overseeing of contractors. Regarding your more general question, you are completely right. In our opinion, the public-private partnership phenomenon has very relevant repercussions on privacy protection, and we are monitoring the situation.

Charmaine Borg NDP Terrebonne—Blainville, QC

Thank you.

My second question is about sections 3.1 and 3.2 of your report.

You say that a complaint by a former soldier prompted you to undertake an investigation into the Department of Veterans Affairs. In 2012, personal information regarding Thomas Hope, another veteran, was made public without his consent. I think that you are currently looking into that issue. Could you tell us about how you are monitoring that situation?

11:45 a.m.

Assistant Privacy Commissioner, Office of the Privacy Commissioner of Canada

Chantal Bernier

There are a number of things that need mentioning. First, we have received several complaints. Therefore, we have several ongoing investigations. Second, following the first complaint, we noted some systemic deficiencies or an appearance, at first glance, of such deficiencies in the management of personal information at the Department of Veterans Affairs. That is why we decided to conduct an audit. So we also have an ongoing audit, which should lead to a report that will be submitted to you in the fall.

Charmaine Borg NDP Terrebonne—Blainville, QC

To follow up on this last question, I am worried by the fact that there have been so many violations of access to personal information involving veterans. Another one of my worries is that this may also be happening in other departments.

There is an increasing number of government services that are, in some cases, available only on line. Is that a reality we must get used to? Does that worry you?

11:45 a.m.

Privacy Commissioner, Office of the Privacy Commissioner of Canada

Jennifer Stoddart

Indeed, the idea of potential technological problems or programming errors is worrisome. One of our annual reports talks about such a case. On a Service Canada website, personal information on a number of individuals was suddenly exposed.

We are talking to the government about the security standards needed to establish new steps for providing Canadians with access to an online government. This is still an area we monitor carefully, and we hope that the government will continue to do so as well.

The Chair NDP Pierre-Luc Dusseault

Thank you, Ms. Borg.

Mr. Mayes now has the floor for five minutes.

11:45 a.m.

Conservative

Colin Mayes Conservative Okanagan—Shuswap, BC

Thank you, Mr. Chair.

I welcome our witnesses.

One of the aspects that you've touched on a little is that, really, communications and issues of privacy are not just domestic issues; they're international issues. Do you work with agencies internationally to see the best practices and legislation they have and model the best of the best...? Could you give me some examples of that, please?

11:45 a.m.

Privacy Commissioner, Office of the Privacy Commissioner of Canada

Jennifer Stoddart

Yes, absolutely, honourable member. It has been clear for many years now—and I've always said this to the committee—that the nature of privacy online now means that privacy is an international issue.

One of my own personal focuses, and the focus of Canada when we take part in international organizations like the OECD, is to encourage cooperation and the emergence of standards that can be shared among different groups when we're faced with the doings or the developments of international companies like some that we've met here. For example, there's the EU on the one hand, the U.S. on the other hand, and then Canada, New Zealand, and Australia, which are to the side. I believe that in our annual report we give some examples.

This continues to be a very important focus for my office, because often we have to coordinate—we're a member of something called the Asia Pacific Privacy Authorities—for example, on what Australia is doing, who's going to speak for us, and what the position of Hong Kong is when faced with the same phenomenon. But if you don't do that, then you're not providing effective privacy.

11:50 a.m.

Conservative

Colin Mayes Conservative Okanagan—Shuswap, BC

At one of the other committees I'm on, there was a representative from RIM, Research In Motion, and this question was asked: what does the future hold for RIM? He said that so much of your information will be on your BlackBerry, such as your driver's licence and maybe your passport.... There's a number of issues.

Do you have the resources to work with those who are developing those types of technologies, and to be able to work with them, so that you can see those safeguards they would apply as they develop these services within the products they produce?

11:50 a.m.

Privacy Commissioner, Office of the Privacy Commissioner of Canada

Jennifer Stoddart

I think that now, with our technology analysis branch and the laboratory that we have developed, we have a lot of high-level, senior information technology people who have the contacts and the know-how necessary to communicate with companies like RIM. Of course, we don't have the resources to embed somebody in Google or RIM, even if it were possible, but I think our people make those companies aware of what our requirements are.

On that front, could I just mention that we're developing a mobile privacy app? I'm not sure what this is going to look like. It sounds pretty innovative to me. That is one of the projects that we hope to release to deal with the issue of what we're now all carrying on our mobile devices.

11:50 a.m.

Conservative

Colin Mayes Conservative Okanagan—Shuswap, BC

One of the issues I have is not just information, but incorrect information. I have constituents who say that they've come across the border, CBSA has somebody with the same name who is red-tagged, and then they are detained for five hours. They're very upset about that whole issue, and they ask why CBSA can't get this right.

Do you do any investigations about making sure that the information they have is correct information? Is there an appeal process that you oversee or that you ensure is in place, not only to protect privacy but to make sure that the information that is taken is the correct information?

11:50 a.m.

Privacy Commissioner, Office of the Privacy Commissioner of Canada

Jennifer Stoddart

May I ask the assistant commissioner to tell us more about this?

11:50 a.m.

Assistant Privacy Commissioner, Office of the Privacy Commissioner of Canada

Chantal Bernier

Absolutely, and that's one of the reasons why we need to pay particular attention to the work being done on the border security perimeter.

As for what we do in relation to the possibility of inaccuracy, first of all, our audits are done on a risk basis. So we will look at either the number of incidents or the volume and sensitivity of the personal information held by an organization to decide whether we should go in and do an audit.

Certainly, a high level of inaccuracy, or the high impact of possible inaccuracy, would be exactly at the root of deciding to do an audit, hence our audit of CPIC and PROS. This fits exactly into your question.

Indeed, CBSA is another organization that we work very closely with, because, as you mentioned, the impact of inaccurate information at CBSA is quite significant. So yes, that is the kind of monitoring we do.

The Chair NDP Pierre-Luc Dusseault

Thank you. Unfortunately, your time is up.

We will have to adjourn the meeting for a few minutes and then move on to the study of the main estimates.

Additional time will be allocated for questions on the main estimates. That may also concern many of the topics we just talked about.

We will adjourn the meeting for two or three minutes and will resume shortly.

Thank you.

The Chair NDP Pierre-Luc Dusseault

We will now continue our work on the study planned for the second hour of our meeting. I call vote 45 under JUSTICE. We will have a 10-minute presentation.

I will repeat for everyone. I call vote 45 under JUSTICE.

If Ms. Stoddart is ready to begin, she has 10 minutes for her presentation.

Noon

Privacy Commissioner, Office of the Privacy Commissioner of Canada

Jennifer Stoddart

I am ready, Mr. Chair. Thank you very much.

Honourable members, Mr. Chairman, I'm very pleased to be able to have a second hour with you to talk about some of our key priorities now for the coming year. We go into the future, having done the annual reports, and once again will attempt to answer your questions.

For this particular phase, I'm joined not only by the assistant commissioner, whom you've already met, but also with Daniel Nadeau, our chief financial officer and director general of corporate affairs. We were very pleased to have him join us in August, following the retirement of a gentleman some of you may have previously met, Tom Pulcine. It's been a wonderful, seamless transition. I'm very happy that Daniel is with me today.

I would like to begin by explaining the evolving landscape of privacy issues and how public concern with them affects our office's work and choice of priorities. So for starters, as I think everyone around this table can appreciate, personal information protection is an issue of growing importance here in Canada and around the world. Canadian businesses need to be informed about how privacy law applies to their operations, and federal departments and agencies are constantly challenged to balance social benefits associated with initiatives that gather personal information on the one hand with the privacy rights of individuals on the other. As an agent of parliament, my office, of course, has the task of advising on such issues.

Individuals today face a reality of complex information technology. People enjoy the fact that these tools connect us like never before, and they bring valuable services to our fingertips. At the same time, Canadians fear the consequences of being tracked by data mining marketers and being surveyed by governments. As a result, Canadians turn to us to investigate their complaints and for information to protect and assert their rights.

I will now talk about the key areas of the OPC's mandate.

As you know, our office is mandated with overseeing compliance with both the Privacy Act, which applies to the government, and the Personal Information Protection and Electronic Documents Act, which applies to the public sector.

We also provide guidance to organizations on the application of privacy law, and to individuals on how they can protect themselves and assert their right to privacy. As in past years, we will be pursuing these objectives through actions under the following three key areas: compliance activities, research and policy development, and public outreach.

Before we get to your questions, I would like to highlight some of the key priorities we are pursuing over the coming year for each of those areas.

First of all, I'll start with compliance activities, where we are continuing our work to update and strengthen our complaint intake and investigation processes. In particular, we are in the midst of an effort to develop and adopt more innovative practices in the Privacy Act investigation process. Our goal is to continue resolving complaints thoroughly with a view to providing service to Canadians in a more efficient, effective, and timely manner.

We are also taking action to better deal with the fact that an increasing number of privacy issues are tied to information technology. For this reason, we are taking steps to ensure that we have the right expertise and tools to evaluate the privacy impact of various technologies. On top of improving ways to do our existing work, we are also focusing on the best approach to fulfilling new responsibilities.

As you know, it's expected that Canada's anti-spam law will come into force sometime next year. We are working alongside Industry Canada, the CRTC, and the Competition Bureau to develop the processes and systems to fulfill our respective roles under this legislation.

In addition, we're also gearing up to review the privacy impact assessments tied to the many initiatives being developed across government, to realize the vision outlined by the Canada-U.S. perimeter security and economic competitiveness action plan. Our office and our provincial and territorial counterparts have underlined the fact that many of the planned initiatives in this plan contain privacy risks.

Our office is ready to examine the assessments to come in order to make recommendations to departments on how to mitigate such risks. With respect to audits, as the assistant commissioner said, we will lay before you the audit of Veterans Affairs Canada this fall, and we have just commenced our second mandated audit of FINTRAC.

I will now discuss research and policy development.

As an agent of Parliament, we will continue to devote our expertise to analyzing legislation and sharing our observations with parliamentarians. We will also be paying special attention to the upcoming parliamentary review of the private sector act. That review is mandated every five years—and for good reason, as we have already mentioned.

Another way we help meet Canadians' privacy needs is by working with leading academic researchers in the field. One important way we do this is by supporting independent, non-profit research through our Contributions Program. Over the course of this year, we look forward to supporting further research, which can lead to new ideas and insights on privacy protection issues.

I'll talk now a bit about public education.

Public education is vital as privacy issues continually evolve. Very few of us can grasp the technological intricacies of what's happening on the other side of the screen. It's therefore more and more important I think to assist Canadians in protecting their personal information online. The generation growing up today is really the first to grow up online. This is why our outreach efforts to youth, to parents, and to educators remain among our top public education priorities.

We've already developed presentation materials for grades 7 through 12 to help adults engage youth about the privacy challenges of today's online world. This year we will be promoting education materials for grades 4 through 6. In addition to individuals, we know that businesses, especially small ones, have specific needs. In general, small businesses lack the resources to have dedicated in-house chief privacy officers and legal counsel. As a result, we're dedicated to providing guidance materials and making outreach efforts to help small businesses learn about and comply with their privacy obligations. Included as part of this we will be spreading the word about the importance of cyber-security and the steps small businesses need to take to protect customer and client data in the online age.

In relation to the public sector, significant changes in our public safety context, as well as in government interaction with citizens online, call for us to educate Canadians on the privacy implications of measures resulting from these changes.

In closing, Mr. Chair, let me underline that we will carry out our work in a way that will continue to see Canadians both well respected as taxpayers and well served as citizens. While not mandated to make reductions under the deficit reduction action plan, our office answered the call to adhere to the exercise's spirit and intent. As a result, we proposed to the government that we would find savings of 5%, or $1.1 million per year, within our operations by fiscal year 2014-15, while maintaining the best possible level of service for Canadians. This proposal was accepted and reflected in our budget for 2012.

To deliver on this, we have planned the following reductions: $676,000, or 2.8%, starting this year, will come from funding that had been allocated to my office in support of the implementation of the Federal Accountability Act. This funding was never accessed by the Office of the Privacy Commissioner. Then, an additional $430,000, or some 2.2%, starting in 2014-15, will be absorbed through general efficiencies from across the organization. Efforts to improve the use of technology and available tools, to take on a greater risk management approach, to better target public education activities, and to seek out partnering opportunities will help OPC generate these savings.

In addition, I also want to note a looming cost pressure that poses a challenge to our quest for a workable balance between quality services and lower costs. A forced move out of the OPC's present location to new offices in 2013 will result in additional costs of up to $5 million. Right now we cannot absorb this without significant impact on our core program. We're currently negotiating with the Treasury Board Secretariat to address this pressure, and I'm hopeful this issue will be settled adequately in the very near future.

With that, I look forward to your questions. Monsieur Nadeau will help me with any detailed questions on our finances.

Thank you very much, Mr. Chair.

The Chair NDP Pierre-Luc Dusseault

Thank you for your presentation.

I now give the floor to Mr. Boulerice for seven minutes.

Alexandre Boulerice NDP Rosemont—La Petite-Patrie, QC

Thank you very much for this presentation and the one you made during the first hour, Ms. Stoddart.

I am a bit worried after hearing the last part of your presentation regarding the financial pressures imposed by the budget cuts the Conservative government introduced. That will affect your ability to act and to carry out your growing number of tasks. Your tasks are multiplying, while your means are decreasing. I don't know how you will deal with that. It's a concern for all Canadians.

I want to come back to a specific issue. We are officially on the Department of Justice's vote 45, but I want to take a few moments to emphasize the fact that, if we rely on this document regarding expenditures, your budget is increasing. It is going from $20 million to $22.129 million. We also know that this document has nothing to do with the budget, which is calling for a reduction in spending.

You just said that you suggested a 5% budget cut and that, among other things, you will move, you will be more efficient and will better target public education activities. What do you mean by “better target”? Does that mean that you will provide fewer public education activities, even though more are needed?

12:10 p.m.

Privacy Commissioner, Office of the Privacy Commissioner of Canada

Jennifer Stoddart

No. In answer to the last part of your question, I would say that we will use virtual tools more extensively. As I already told another member of the committee, I believe that virtual tools are less expensive and are probably increasingly efficient. We will try to be more careful about choosing audiences we think will benefit the most from our efforts. For instance, we will prioritize young people.

Alexandre Boulerice NDP Rosemont—La Petite-Patrie, QC

Thank you.

In this current climate, a sword of Damocles is hanging over our heads. I am talking about Bill C-30, which the government wants to use to provide the Competition Bureau, the Canadian Security Intelligence Service and law enforcement agencies with direct access to personal data through Internet service providers. I have a feeling that will increase your workload considerably.

What kind of consequences do you think pieces of legislation such as Bill C-30—which enables Internet providers to directly search Canadians' computers—will have on your work, in terms of protecting personal, private and confidential citizen data? In addition, considering the cuts to your budget, how will you deal with that type of situation?

12:10 p.m.

Privacy Commissioner, Office of the Privacy Commissioner of Canada

Jennifer Stoddart

Bill C-30 does not give us any specific additional roles. If my memory serves me correctly, the bill mentions that we can conduct audits, but we can do that anyway. What we're worried about is the overall content of the bill. Since the bill is currently being discussed and the same issues have been raised for three years, our efforts are currently focused on the final version of the bill. For 10 years, various versions of this bill have been introduced, so we will have to wait and see. If the bill does not give us a specific role, the consequences of this new expenditure restraint program will clearly carry a lot of weight in terms of the risk elements that lead to audits, given our current resources.