Retention as a Achilles’ heel – why regulations prevent storage of vaccine certificates

An interview with CBC on the approach taken in Ontario on data retention of proof of vaccination. For those interested, the regulations are under the Reopening Ontario Act, O. Reg 364/20: Rules for Areas at Step 3 and at the Roadmap Exit Step (“O. Reg. 364/20”).  The relevant sections are:

2.1 (1) The person responsible for a business or an organization described in subsection (2) that is open shall require each patron who enters an area of the premises of the business or organization that is described in that subsection to provide, at the point of entry, proof of identification and of being fully vaccinated against COVID-19.

And

(9) A business or an organization shall not retain any information provided pursuant to this section.

Also relevant is this Q&A Sheet from the Ministry of Health.

https://www.cbc.ca/news/canada/ottawa/ontario-vaccine-passport-records-1.6216533

COVID Passport and data retention in Ontario

Recorded September 22, 2021 on the John Oakley Show:

Some businesses opt for one-time check of vaccine passports - but is it legal?

Some businesses opt for one-time check of vaccine passports – but is it legal?

https://tunein.com/podcasts/News–Politics-Podcasts/The-John-Oakley-Show-p413607/?topicId=165993578

Proof of identity or the vaccine certificate; you are likely okay to record the ‘pass.’

https://platform.twitter.com/widgets.js

from Twitter https://twitter.com/constantk

Reinvention and learning; an anniversary note

I want to note that this month marks my 35th year anniversary of my Call to the Bar of the Province of Ontario. This also marks one year since I joined nNovation LLP, and I went to thank Kris Klein, Tim Banks, Shawn Brown, Dustin Moores, Abigail Dubiniecki and Kim Alexander-Cook, for welcoming me to a great and supportive group. Their expertise in privacy is huge, and the anxiety of launching into practice in the midst of a pandemic and a recession, has certainly been made less stressful with their support. This started off as just a note to acknowledge these two milestones, but as I wrote, I realized that I want to offer up my history as a bit of guidance to those who are starting their journey in privacy. Perhaps it will also be encouraging to those further down the road, too, given how many times I have had to reinvent myself over the course of my career.

I want to thank my clients, whom I appreciate for how engaging they are to work for and with. I have had a chance to learn their businesses, their challenges, and to support them in various steps on their privacy journey. Whether it in negotiating data transfer agreements, helping to establish or enrich a privacy program, or (shudder) dealing with the incidents that befall all organizations, it has all been fascinating work – and what I love to do.

I want to thank the many people that have helped me along the way – the friends and business colleagues, the clients, who have been a part of my journey.

I was called to the Bar in 1986. My first real job was for a software company called Legalware, which had developed tools to help lawyers automate documents and files. I began developing expert system templates for them, which involved analyzing legal processes and figuring out how to automate them through questions and answers. I was so lucky to get got involved with and learn technology far earlier than many others then in law. Sadly they folded – too far ahead of their time- and I went through a couple of law firms before starting practice on my own. I heavily used technology in practice – I had a bulletin board for my clients to connect to me, for those of you who remember the whine of modems… while also still consulting and lecturing about the use of technology in law (some of you may remember “CSALT”?)

In 1998 I was approached by CGI and initially I thought they wanted me for their legal department. They actually wanted me to join as a consultant because I was well known, not for law, but for legal technology. At that point, I had had my fill of trying to compete as a sole practitioner in a crowded market where I was relatively unknown, and despite what I knew about technology, the tech firms of the world were not beating on the door of a sole practitioner. I welcomed being able to combine what I knew about law and technology, joined CGI and worked with some really great people in their legal technology practice, and then their document & knowledge management group.

One of my most proud accomplishments at CGI was when I was project manager for the Video Remand and Bail Project. I was the only consultant on the team; I led for three years an outstanding group of people in a project to build and run a video conferencing network between the courts and the jails in Ontario. Our project won a Diamond Award for Organizational Transformation at Showcase for the Justice Cluster, and it is still in operation as a key component in the delivery of justice (remember that anytime you hear “the accused appeared by video”). What I definitely found influenced my later career in privacy was about change management: technology was easy, but getting people to change the way they do things – much harder – but with the right approach, you can get “organizational transformation.”

My part in the project come to an end as it became a program, but I was soon on another. A project manager at CGI found me and said “You! You can read a law! You are now the privacy manager on a government project we’ve won.” At first I was not so keen; but as I got into it, I found to my surprise, that privacy also combined whet I loved most about law, with what I loved to do in technology.

That project was a mixed blessing. I got a chance to develop a PIA that had four ministries (!) sign off on a very complex project, another chance to practice what I had learned about building consensus; but the project was ultimately cancelled, with the PIA I had led being the sole document accepted by our client out of the whole project. However, it was what started me on the privacy road.

It was about this time I was introduced to the International Association of Privacy Professionals. I wrote at the first CIPP exam in New Orleans in 2004, when the IAPP was I believe about 400 members. At first I thought I joined a cult – there was Richard Purcell proctoring the exam in a nun’s outfit, I think because of a popular musical at the time… Anyone who knows me knows I drank the Kool-Aid, because I went on to get more certifications and as well to teach them, and to speak and participate as often as they’ll let me. Later on when they got really big, when the IAPP first introduced the “Little Big Stage” they had an empty slot and offered it to me. Note: I am currently the only person I am aware of that has done a stand-up routine at the Global Summit; perhaps the IAPP learned from the experience…

I was put in charge of the Security and Privacy team at CGI, which gave me an exposure and grounding in the cybersecurity world; and then ultimately moved from there to Symantec. I initially support compliance sales, but then moved to an internal position to build and manage Symantec’s global privacy program. In 2010 I became a privacy officer to Mercer, a human resources and benefits company, again getting to work with great and dedicated people. In both organizations, supported by great people, I developed an international experience and mandate, working on issues both internal, client-facing, and customer-­facing, around the world. I realized while helping to negotiate yet another data transfer agreement with a EU company, that I had realized my goal in going to law school was to practice international law – in the realm of privacy, and that I was getting an experience few lawyers in Canada were able to get.

From Mercer I went to Nymity. I had been a customer for over ten years and routinely had dragged people to their booth to talk to them at conferences, so it was in many ways natural that I would go there. I had very different role leading a sales team, but it gave me a chance to learn more, and apply what I had leaned as a privacy officer in a whole new way, to build and run a successful team of privacy advisors who could understand and speak to clients’ issues. And in a strange way, it was what I had started in technology doing – I was just helping to automate a different kind of practice.

And from Nymity I went to PwC, where I re-entered the consulting world to address the question I kept hearing from customers while at Nymity: “This is great software, but could you just do it for us?” At PwC l had some really great clients, and found, with some surprise, that my long road and experiences were truly valued – I could actually help clients not only by building a program and helping them with it, but by help them learn to do it.

Which brings us up to date: I joined nNovation in April last year. It has not been an easy year for any of us, and it’s been particularly trying and worrisome to build a practice in the midst of a pandemic. What is different now is that I have spent nearly two decades in privacy, and have now established a reputation. It is the result of the accumulated effort over many years of experience but also speaking and writing. I have to thank the marketing people who put me into positions where I could speak at many events, both in the real world and online, and for teaching me to promote. Anyone who knows me knows that I am frequently writing, speaking and otherwise participating through the IAPP (as was with other organizations and technology partner events).

And while promotion is important, I feel strongly you can only be successful at it if you share knowledge and experience with our community, in a productive way, to help advance our understandings of privacy as a discipline and as a transformative exercise.

It also helps me, I think to reach out and try to be a help to others – whether one-on-one for young professionals now trying to develop their careers in privacy, in offering my time to charities to talk about good privacy hygiene in an epidemic (pun intended), or through teaching (I am getting my teaching fix right now through Continuing Studies at the University of Toronto).

Since I have mentioned puns… One of the things, my friends and colleagues have always known about me – or soon learned – was my sense of humour. I tell jokes; I relate privacy principles to stories, to help clients and students, using humour to make the privacy learnings I have to share, well, interesting – memorable, and approachable. The best compliment I have received was when a client’s employees said in after a full day workshop was “I never thought privacy would be so interesting.”

In addition to making a successful practice – one where I can be the ‘guru on the hill,’ counselling organizations and their general counsel, my goals now include continuing my teaching, and also getting onto a board of directors, as there are few at that level with the experiences needed in today’s world of cybersecurity and privacy challenges.

We will constantly re-invent ourselves, and that is okay; I have had at last count six career changes. I was once in the middle of an interview for a privacy officer role, which I was ultimately unsuccessful in getting. The interviewer asked me why they would hire me, since I had been in a software company, entered practice, left practice, gone to consulting and now wanted to become their privacy officer.

I was unprepared for that question, so my response came to me (and the interviewer) as an epiphany:

I analyze and solve problems; I build programs; I advocate and persuade; I find ways to understand and utilize the connections between technology and the way we work; I write; I amuse and engage; and I motivate and teach. The job title is irrelevant; what I do, stays the same.

The interviewer wanted to hire me on the spot, but as I said, I was not selected. That is okay; we all will face situations where we know we are the right person but at the wrong place, or the wrong time. My learning from this moment in my past was that I understood what made me tick. I hope you will take the time to reflect on what makes you tick; this will ultimately be what gives you contentment in your career path, whatever twists and turns it takes.

Serious Privacy Podcast

Thanks to TrustArc‘s Paul Breitbarth and K Royal for hosting the Serious Privacy Podcast; especially honoured to share the podium with Jennifer Stoddart as we discussed implications for Canadian adequacy under the newly proposed Consumer Privacy Protection Act. #PIPEDA #CPPA #privacy #privacylaw

How to opt out of Yahoo mail scanning

www.theverge.com/2018/8/28/17793964/how-to-opt-out-yahoo-mail-email-data-scanning-advertising

How to really turn off location tracking in Google

www.wired.com/story/google-location-tracking-turn-off

RT @wemdevries: How well prepared are you for GDPR? Did you read and test any of the creations by @constantk ? It was part of my training @universityofMaastricht to become certified DPO and it is useful to test the compliancy of your company with GDPR. #… https://t.co/vNbDl0GBZd

https://platform.twitter.com/widgets.js

from Twitter https://twitter.com/constantk

Adequacy is not adequate: why Canadian companies should care about the GDPR

(Originally posted on LinkedIn, May 15 2017)

I am looking forward to the next IAPP Canada Symposium, as I always do, and this time I am wondering if now Canadian companies are finally going to start doing something about the #GDPR. I spoke two years ago about the state of our laws; I spoke last year about what Canadian companies need to do with regard to complying with the GDPR.

The reason for the title is simple; we have been very comfortable with our ‘adequacy’ finding, but the transfer of data under our adequacy finding is not by itself adequate to deal with the requirements of GDPR. In contrast, there is work being frantically done in the US and the EU to address GDPR compliance. Until this point, the understanding that GDPR means something consequential for Canada, has not seemed to instigate more than conversations about possibly getting someone on board to take charge. But time is running out; as of May 15, 2017 there are only 263 working days, not including vacations, between now and May 25, 2018 when GDPR comes into effect.

If a Canadian company is doing business in Europe, then yes it can (with certain qualifications) bring personal data without need of model clause agreements or other mechanisms. However, that does not meet all the requirements of the GDPR. Canadian companies must if collecting information from EU residents act in all respects as a European company would – notably:

  • The right to be forgotten – Canadian companies have to be able to act on a request by a European customer
  • Record keeping requirements – you will need to have your Article 30 records of processing, just as any EU company would
  • Data protection impact assessments – you will need processes to meet Article 35’s requirements when you trigger its requirements, and document your DPIAs
  • Appointment of DPO where warranted – you may need to have someone appointed as a DPO, perhaps in individual countries, where your business is primarily processing personal data, and the expectations for this may rise depending on national derogations
  • Onward transfers – Article 28 of the GDPR requires adequate protection for onward transfers from Canada elsewhere, as well as restrictions without the controller’s approval
  • Representative office in Europe – if you don’t have a physical presence there, you will need to appoint a representative office
  • Data breach reporting – new for a lot of Canadian organizations, you will need to report within 72 hours a data breach to your lead regulator (and of course, you know who that is, right?)
  • Enforcement – fines of up to 4% of global revenue or EU20 million, whichever is greater

If you are a data processor – a service provider to an EU company – then you are not off the hook. The obligations will be passed on by contract to you in any event through data transfer agreements as your customer are obliged to do so – and you are also subject to the requirements of the GDPR directly, for pretty much the same things I have set out above. The fines will be 2% of global revenue or EU10 million, but note this doesn’t let your client (the processor) off the hook – you can both be found liable independently.

What can Canadian companies do? There are no silver bullets; this is going to require work. You need to update your #privacy program to address the requirements of the GDPR. Some Canadian companies, because they have been doing what they should under PIPEDA or provincial laws, will be in a good position with some additional activities and capabilities. For the rest, it is quickly going to become a question of what they can do in the time that remains, and it means prioritizing based upon risk.

In any event, if you don’t have a plan, now is the time to get moving on it.

Postcards from Hell: After the Nightmare Subject-Access Request

(Originally posted on LinkedIn, May 15, 2017)

Following on my (apparently) popular nightmare subject-access request and letter from a DPA…

The GDPR provides for a number of remedies for individuals in regards to their personal data, that will put companies through their paces:

  • rectification;
  • the right to be forgotten and erasure;
  • data portability; and
  • objection to and restrictions on processing.

The natural next step when someone has written you an annoying letter to find out what a company knows about a data subject, and how it is handling their personal data, is for the author to start exercising those rights.

This gets harder to do in the natural flow of a letter, because of course, the exercise of these rights can arise in so many scenarios. I wanted to highlight individual elements of what data subjects can ask under the GDPR. They may not all come at once, but through the death of a thousand paper cuts, in a series of postcards from hell:

1.   Let’s get rectified.

Based on the information that you have provided to me in my subject-access request, it appears you have collected a profile on me based on my purchases. The fact that I am buying a lot of toilet paper is no one’s concern but my own; and it is not due to anything other than I have a lot of guests, not as is implied in the profile, that I am having some kind of organic issues. Please rectify this as soon as possible, as I now understand why I am receiving invitations to purchase medication.

2.   Transfer this.

I note that you have been transferring my personal data, namely my meal choices on flights, to the United States, and you have indicated that the basis on which you are making that transfer is based upon the EU-US PNR Agreement. The inferences being drawn from my being a vegetarian are that I am in a suspect group and am being profiled on that basis, which is why I am routinely pulled aside for “random” searches whenever I visit the United States. I request that you delete all information concerning my meal choices that you have collected on me.

3.   Your vendor is infectious.

I request you delete my contact information from your customer service vendor in India. I had one interaction to get support for my software a year ago – and now I routinely get calls from India insisting my Windows computer is infected (I own a Macintosh), so your outsourced vendor is not keeping my information confidential. Please confirm that you have followed up with any organization with whom my contact details have been shared with by your vendor. And in future, please restrict processing of my data to my software subscription maintenance.

4.   Let my data go.

I have been using your free budget management program on the Internet and now that I understand you are storing my financial and purchase data in countries which have a high rate of identity theft, I no longer wish you to have my data. Prior to deleting it, I would like to ask you to provide all my data in a CSV format that I can use to export to a system which stores its data in the European Union. Please use the attached schema which will support the import into the new system I wish to use.

5.   Taking a gamble you have it right.

I have been receiving direct mail from you both by the post and in my e-mail. I am in risk management and I attend conferences on privacy and risk management. I assume that is how you got my contact information, but I do not understand how this got linked to gambling. I don’t find gambling interesting and I don’t know why you would assume that I would want your magazine on gambling, or your e-mails to let me know about gambling events, and the connection with gambling is embarrassing and potentially damaging to my career. Stop sending me anything more and remove my name and address from your lists in relation to gambling.

(Yes, the last one happened to me).

Design a site like this with WordPress.com
Get started