Cloud Computing and the USA Patriot Act: Canadian Implications

by Dentons
Contact

[author: Timothy Banks]

A perennial issue in Canadian privacy law is what to do about the USA Patriot Act. Just when we think we have things reasonably sorted out, issues pop up again in a new context. This time, it is cloud computing.

What is the USA Patriot Act?

The Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act 1 (usually referred to as the USA Patriot Act or just the Patriot Act) is United States legislation that was passed following the September 11, 2001, attacks on the World Trade Centre in New York City. Among other things, the Patriot Act made it easier for U.S. law enforcement officials to intercept electronic communications and business records. One of the controversial measures was that officials were granted the power to issue a National Security Letter to electronic communication service providers requiring them to hand over information without informing the affected parties (in some cases without any judicial oversight).

For the purposes of this discussion of cloud computing, one of the most important provisions of the Patriot Act is s. 215, which deals with access to business records. Section 215 repealed and re-enacted provisions of the U.S. Foreign Intelligence Surveillance Act.2 Pursuant to s. 215 of the Patriot Act, the Federal Bureau of Investigation may apply to a federal judge for an order requiring the production of any tangible things (including books, records, papers, documents, and other items) for an investigation to protect against international terrorism or clandestine intelligence activities. U.S. commentators agree that this definition covers electronic business records.

What is cloud computing?

In its most complete form, cloud computing involves outsourcing applications (e.g., e-mail, customer relationship management, and accounting software), platforms (e.g., database architecture) and infrastructure (e.g., servers). All of these IT functions are offered as a service to organizations either independently or as a package. An organization's data (e.g., its e-mails) may be stored in segregated servers or intermingled with the data of other organizations and segregated through the functionality of the service provider's information technology. The organization accesses its data through Internet portals.

Where is the Cloud?

The cloud isn't in the sky. Data sent over the Internet in a cloud computing arrangement may be (and often will be) stored outside of Canada and may be intermingled with data from other organizations. In many cases, the cloud computing service provider may subcontract the storage of data to one or more organizations operating data centres. If these data centres are in the U.S., well, therein lies the rub. The data is going to be subject to the laws of the United States, including the Patriot Act. Actually, if the data is even accessible from the U.S. or by an organization subject to the jurisdiction of the U.S., the data is likely to be subject to the laws of the United States.

Is there a Canadian privacy problem?

All transfers of information create legal issues, particularly where the transfer is to a third party across borders. Organizations have a privacy "problem" every time they transfer data. This is because under Canadian federal and provincial private sector privacy laws, the organization that collected and is entitled to use the personal information remains responsible for its security throughout its lifecycle. Indeed, in many cases, organizations will have created a contractual obligation with individuals by incorporating the organization's privacy policy (and privacy commitments) into terms of service or use or other customer e-commerce contracts. An organization will need to assess carefully with legal advisors how commencing cloud service transfers of personal information will affect existing legal commitments. It may be necessary, for example, to give special notice to individuals and to provide them with opt-out or termination opportunities.

However, organizations are not prohibited from using U.S.-based cloud services (assuming they are only operating in the private sector). Federal and provincial private sector privacy legislation does not prohibit the transfer of personal information to an organization in another jurisdiction for processing and storing, provided that

- The transfer does not entitle the organization receiving the personal information to use that information for purposes other than those for which individuals expressly or impliedly consented.

- The transferring organization remains accountable for the protection of the personal information that has been transferred.

- The organization receiving the personal information provides a comparable level of data security, as would be required under Canadian law, and the terms on which the collecting organization collected the information.

- Disclosure is made to individuals. As a general rule, this disclosure to individuals should include notice that (1) their personal information will be transferred outside of Canada for processing and storage; (2) their personal information will be subject to the laws of the foreign jurisdiction; and (3) the laws of the foreign jurisdiction may be different (and less protective) than those of Canada.

The transferring organization will wish to consider obtaining meaningful contractual commitments to administrative, technological and physical security protections from the organization to which the personal information is being transferred. The transferring organization will also wish to consider audit or other rights that would permit ongoing diligence of these security protections, as well as the use being made of the personal information.

The Patriot Act does not mean that personal information will necessarily be subject to lesser security in the U.S. than in Canada. An interesting survey and comparison of surveillance laws in Canada, the U.S., the United Kingdom, and France was conducted by the Office of the Privacy Commissioner of Canada in 2009, which remains an important reference.3 Since 1990, Canada and the U.S. have had a Treaty on Mutual Legal Assistance in Criminal Matters 4 in which, each country has agreed to assist the other with the investigation, including seizure of records, of criminal activity. The Canadian Security and Intelligence Service Act 5 provides for secret warrants for the interception and seizure of, among other things, electronic data. The National Defence Act 6 permits the Minister of Defence (without judicial supervision) to authorize the Canadian Communications Security Establishment to intercept communications relating to foreign entities under certain circumstances. In addition, the Criminal Code 7 permits seizures of electronic data. The combination of this legislation has led the Office of the Privacy Commissioner of Canada to conclude in three decisions8 not only that Canadians are at risk of personal information being seized by Canadian governmental authorities (including without the knowledge of the target), but also that there is already a risk of that information being shared with U.S. authorities.

This is not to say that reasonable people cannot still differ as to whether they wish to have their personal information stored outside of Canada. As such, organizations should factor into their business model the possibility that companies or individuals who do business with them may have legitimate concerns about the theoretical increased risk that their personal information could be shared with U.S. authorities without any gate-keeping function of a Canadian policing, governmental or judicial authority.

Final Caution

There are additional complications when entering into cloud computing arrangements in which government data regarding citizens may be involved. Although it is beyond the scope of this article to enter into a complete discussion, it should be noted that there are restrictions in British Columbia and Nova Scotia (and probably Alberta) to storing data outside of Canada. In British Columbia, public bodies that are subject to the Freedom of Information and Protection of Privacy Act are required to ensure that personal information under their custody or control is only stored in and accessible from Canada, subject to certain exceptions.9 Similarly, the Nova Scotia Personal Information International Disclosure Protection Act requires that public bodies and their service providers ensure that personal information under their custody or control is stored and accessed only in Canada, subject to certain exceptions.10 In Alberta, organizations are prohibited from wilfully disclosing personal information in response to a subpoena, warrant or order issued or made by a court, person or body having no jurisdiction in Alberta to compel the production of information or pursuant to a rule of court that is not binding in Alberta.11

Tim Banks is a partner in FMC's Toronto Office. He is also the head of the Toronto Research Group, which provides reasoned opinions on litigious or potentially litigious issues.

___________________
1 115 Stat. 272 (2001).
2 50 U.S.C. ch. 36.
3 Privacy Commissioner of Canada, Surveillance, Search or Seizure Powers Extended by Recent Legislation in Canada, Britain, France and the United States by Jennifer Stoddart (Ottawa: Office of the Privacy Commissioner of Canada, May 9, 2009) <http://www.priv.gc.ca/parl/2009/parl_bg_090507_e.pdf>. In addition, the submissions of Professor Michael Geist and Milani Homsi to the B.C. Information and Privacy Commissioner entitled “The Long Arm of the USA Patriot Act: A Threat to Canadian Privacy” remain foundational research in this area. See <www.michaelgeist.ca/resc/FINAL_UNB.doc>.
4 Can. T.S. 1990 No. 19 (Canada Gazette, Part I, 1990, p. 953).
5 R.S.C. 1985, c. C-23, ss. 21-24.
6 R.S.C. 1985, c. N-5, ss. 273.65-273.69.
7 R.S.C. 1985, c. C-46 (e.g., the provisions in Part VI).
8 PIPEDA Case Summary #313, [2005] C.P.C.S.F. No. 27; PIPEDA Case Summary #333, [2006] C.P.C.S.F. No. 10; and PIPEDA Case Summary #394, [2008] C.P.C.S.F. No. 7.
9 RSBC 1996, CHAPTER 165, s. 30.1.
10 S.N.S. 2006, c. 3, s. 5.
11 Freedom of Information and Protection of Privacy Act, RSA 2000, c. F-25, s. 92(3).

 

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Dentons | Attorney Advertising

Written by:

Dentons
Contact
more
less

Dentons on:

Readers' Choice 2017
Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
Sign up using*

Already signed up? Log in here

*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Privacy Policy (Updated: October 8, 2015):
hide

JD Supra provides users with access to its legal industry publishing services (the "Service") through its website (the "Website") as well as through other sources. Our policies with regard to data collection and use of personal information of users of the Service, regardless of the manner in which users access the Service, and visitors to the Website are set forth in this statement ("Policy"). By using the Service, you signify your acceptance of this Policy.

Information Collection and Use by JD Supra

JD Supra collects users' names, companies, titles, e-mail address and industry. JD Supra also tracks the pages that users visit, logs IP addresses and aggregates non-personally identifiable user data and browser type. This data is gathered using cookies and other technologies.

The information and data collected is used to authenticate users and to send notifications relating to the Service, including email alerts to which users have subscribed; to manage the Service and Website, to improve the Service and to customize the user's experience. This information is also provided to the authors of the content to give them insight into their readership and help them to improve their content, so that it is most useful for our users.

JD Supra does not sell, rent or otherwise provide your details to third parties, other than to the authors of the content on JD Supra.

If you prefer not to enable cookies, you may change your browser settings to disable cookies; however, please note that rejecting cookies while visiting the Website may result in certain parts of the Website not operating correctly or as efficiently as if cookies were allowed.

Email Choice/Opt-out

Users who opt in to receive emails may choose to no longer receive e-mail updates and newsletters by selecting the "opt-out of future email" option in the email they receive from JD Supra or in their JD Supra account management screen.

Security

JD Supra takes reasonable precautions to insure that user information is kept private. We restrict access to user information to those individuals who reasonably need access to perform their job functions, such as our third party email service, customer service personnel and technical staff. However, please note that no method of transmitting or storing data is completely secure and we cannot guarantee the security of user information. Unauthorized entry or use, hardware or software failure, and other factors may compromise the security of user information at any time.

If you have reason to believe that your interaction with us is no longer secure, you must immediately notify us of the problem by contacting us at info@jdsupra.com. In the unlikely event that we believe that the security of your user information in our possession or control may have been compromised, we may seek to notify you of that development and, if so, will endeavor to do so as promptly as practicable under the circumstances.

Sharing and Disclosure of Information JD Supra Collects

Except as otherwise described in this privacy statement, JD Supra will not disclose personal information to any third party unless we believe that disclosure is necessary to: (1) comply with applicable laws; (2) respond to governmental inquiries or requests; (3) comply with valid legal process; (4) protect the rights, privacy, safety or property of JD Supra, users of the Service, Website visitors or the public; (5) permit us to pursue available remedies or limit the damages that we may sustain; and (6) enforce our Terms & Conditions of Use.

In the event there is a change in the corporate structure of JD Supra such as, but not limited to, merger, consolidation, sale, liquidation or transfer of substantial assets, JD Supra may, in its sole discretion, transfer, sell or assign information collected on and through the Service to one or more affiliated or unaffiliated third parties.

Links to Other Websites

This Website and the Service may contain links to other websites. The operator of such other websites may collect information about you, including through cookies or other technologies. If you are using the Service through the Website and link to another site, you will leave the Website and this Policy will not apply to your use of and activity on those other sites. We encourage you to read the legal notices posted on those sites, including their privacy policies. We shall have no responsibility or liability for your visitation to, and the data collection and use practices of, such other sites. This Policy applies solely to the information collected in connection with your use of this Website and does not apply to any practices conducted offline or in connection with any other websites.

Changes in Our Privacy Policy

We reserve the right to change this Policy at any time. Please refer to the date at the top of this page to determine when this Policy was last revised. Any changes to our privacy policy will become effective upon posting of the revised policy on the Website. By continuing to use the Service or Website following such changes, you will be deemed to have agreed to such changes. If you do not agree with the terms of this Policy, as it may be amended from time to time, in whole or part, please do not continue using the Service or the Website.

Contacting JD Supra

If you have any questions about this privacy statement, the practices of this site, your dealings with this Web site, or if you would like to change any of the information you have provided to us, please contact us at: info@jdsupra.com.

- hide
*With LinkedIn, you don't need to create a separate login to manage your free JD Supra account, and we can make suggestions based on your needs and interests. We will not post anything on LinkedIn in your name. Or, sign up using your email address.