<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Brian Bowman - On the Cutting Edge &#187; Privacy Breach</title>
	<atom:link href="http://brianbowman.ca/tag/privacy-breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://brianbowman.ca</link>
	<description>Your source for business information on privacy, access to information and other cutting edge legal issues</description>
	<lastBuildDate>Thu, 17 Nov 2011 17:25:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='brianbowman.ca' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/0b0eb147f180e4204870e399a7fe3035?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Brian Bowman - On the Cutting Edge &#187; Privacy Breach</title>
		<link>http://brianbowman.ca</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://brianbowman.ca/osd.xml" title="Brian Bowman - On the Cutting Edge" />
	<atom:link rel='hub' href='http://brianbowman.ca/?pushpress=hub'/>
		<item>
		<title>Fines needed to help stem growing data breaches, Privacy Commissioner says</title>
		<link>http://brianbowman.ca/2011/05/04/fines-needed-to-help-stem-growing-data-breaches-privacy-commissioner-says/</link>
		<comments>http://brianbowman.ca/2011/05/04/fines-needed-to-help-stem-growing-data-breaches-privacy-commissioner-says/#comments</comments>
		<pubDate>Wed, 04 May 2011 16:06:09 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Legislation Update]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Privacy Commissioner of Canada]]></category>
		<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[Privacy Commissioner]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=3504</guid>
		<description><![CDATA[The Privacy Commissioner of Canada has called for legislation empowering her to impose substantial fines against major corporations that fail to adequately protect Canadians’ personal information from preventable breaches. “I am deeply troubled by the large number of major breaches we are seeing, including serious incidents in recent weeks that have affected hundreds of thousands [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=3504&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://btdbowman.files.wordpress.com/2011/05/jail.jpg"><img class="alignleft size-thumbnail wp-image-3507" title="jail" src="http://btdbowman.files.wordpress.com/2011/05/jail.jpg?w=150&#038;h=100" alt="" width="150" height="100" /></a>The Privacy Commissioner of Canada has called for legislation empowering her to impose substantial fines against major corporations that fail to adequately protect Canadians’ personal information from preventable breaches.</p>
<p>“I am deeply troubled by the large number of major breaches we are seeing, including serious incidents in recent weeks that have affected hundreds of thousands of Canadians,’’ Jennifer Stoddart said in a <a href="http://priv.gc.ca/speech/2011/sp-d_20110504_e.cfm">speech</a> today at the <a href="http://www.canada30.com/">Canada 3.0 forum</a> in Stratford, Ont. “It seems to me that it’s time to begin imposing fines – significant, attention-getting fines – on companies when poor privacy and security practices lead to breaches.&#8221; To learn more, read the complete <a href="http://www.priv.gc.ca/media/nr-c/2011/nr-c_110504_e.cfm">news release</a>.</p>
<br />Filed under: <a href='http://brianbowman.ca/category/data-protection/'>Data Protection</a>, <a href='http://brianbowman.ca/category/legislation-update/'>Legislation Update</a>, <a href='http://brianbowman.ca/category/privacy/'>Privacy</a>, <a href='http://brianbowman.ca/category/privacy-breach/'>Privacy Breach</a>, <a href='http://brianbowman.ca/category/privacy-commissioner-of-canada/'>Privacy Commissioner of Canada</a> Tagged: <a href='http://brianbowman.ca/tag/pipeda/'>PIPEDA</a>, <a href='http://brianbowman.ca/tag/privacy/'>Privacy</a>, <a href='http://brianbowman.ca/tag/privacy-breach/'>Privacy Breach</a>, <a href='http://brianbowman.ca/tag/privacy-commissioner/'>Privacy Commissioner</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/3504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/3504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/3504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/3504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/3504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/3504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/3504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/3504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/3504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/3504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/3504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/3504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/3504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/3504/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=3504&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2011/05/04/fines-needed-to-help-stem-growing-data-breaches-privacy-commissioner-says/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2011/05/jail.jpg?w=150" medium="image">
			<media:title type="html">jail</media:title>
		</media:content>
	</item>
		<item>
		<title>How safe is your scan? Hard drives on copy machines pose risk</title>
		<link>http://brianbowman.ca/2010/10/20/how-safe-is-your-scan-hard-drives-on-copy-machines-pose-risk/</link>
		<comments>http://brianbowman.ca/2010/10/20/how-safe-is-your-scan-hard-drives-on-copy-machines-pose-risk/#comments</comments>
		<pubDate>Wed, 20 Oct 2010 15:11:08 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Safeguarding]]></category>
		<category><![CDATA[Safekeeping]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Corporate Information]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Privacy Compliance]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=3238</guid>
		<description><![CDATA[Does your office have a copy machine? If so, then this post is worth reading.  CBC news has just released the results of an investigation that exposes the security risks associated with modern copy machines, specifically, the ease at which information scanned into certain copiers can be tapped. Just think about the information that gets scanned into [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=3238&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://btdbowman.files.wordpress.com/2010/10/copy.jpg"><img class="alignleft size-thumbnail wp-image-3241" src="http://btdbowman.files.wordpress.com/2010/10/copy.jpg?w=107&#038;h=150" alt="" width="107" height="150" /></a>Does your office have a copy machine? If so, then this post is worth reading.  CBC news has just released the results of an investigation that exposes the security risks associated with modern copy machines, specifically, the ease at which information scanned into certain copiers can be tapped. Just think about the information that gets scanned into your office copier. Personal information. Confidential corporate information such as client data. Even intellectual property. It&#8217;s a scary thought if you haven&#8217;t done your due diligence, especially considering that privacy laws can apply to certain data undoubtedly scanned into your copy machine. Check out CBC&#8217;s <a href="http://www.cbc.ca/technology/story/2010/10/18/photocopier-security.html">online story here </a>or <a href="http://www.cbc.ca/video/player.html?category=News&amp;zone=technology&amp;site=cbc.technology.ca&amp;clipid=1619702612">TV segment here</a>. And if you&#8217;d like to learn more, you may also want to read my <a href="http://brianbowman.ca/2010/05/11/copy-machines-a-security-risk-you-bet/">post from earlier this year</a> which provided a link to a similar CBS news story.</p>
<br />Filed under: <a href='http://brianbowman.ca/category/data-encryption/'>Data Encryption</a>, <a href='http://brianbowman.ca/category/data-protection/'>Data Protection</a>, <a href='http://brianbowman.ca/category/identity-theft/'>Identity Theft</a>, <a href='http://brianbowman.ca/category/privacy/'>Privacy</a>, <a href='http://brianbowman.ca/category/privacy-breach/'>Privacy Breach</a>, <a href='http://brianbowman.ca/category/safeguarding/'>Safeguarding</a>, <a href='http://brianbowman.ca/category/safekeeping/'>Safekeeping</a>, <a href='http://brianbowman.ca/category/security/'>Security</a>, <a href='http://brianbowman.ca/category/technology/'>Technology</a> Tagged: <a href='http://brianbowman.ca/tag/corporate-information/'>Corporate Information</a>, <a href='http://brianbowman.ca/tag/identity-theft/'>Identity Theft</a>, <a href='http://brianbowman.ca/tag/information-technology/'>Information Technology</a>, <a href='http://brianbowman.ca/tag/privacy-breach/'>Privacy Breach</a>, <a href='http://brianbowman.ca/tag/privacy-compliance/'>Privacy Compliance</a>, <a href='http://brianbowman.ca/tag/safeguarding/'>Safeguarding</a>, <a href='http://brianbowman.ca/tag/security/'>Security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/3238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/3238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/3238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/3238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/3238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/3238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/3238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/3238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/3238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/3238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/3238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/3238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/3238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/3238/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=3238&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2010/10/20/how-safe-is-your-scan-hard-drives-on-copy-machines-pose-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2010/10/copy.jpg?w=107" medium="image" />
	</item>
		<item>
		<title>Privacy breach notification: to notify or not to notify?</title>
		<link>http://brianbowman.ca/2010/08/23/privacy-breach-notification-to-notify-or-not-to-notify/</link>
		<comments>http://brianbowman.ca/2010/08/23/privacy-breach-notification-to-notify-or-not-to-notify/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 18:56:39 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Online Shopping]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Safeguarding]]></category>
		<category><![CDATA[Safekeeping]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=3048</guid>
		<description><![CDATA[The CBC National News is reporting in this video news clip that the children&#8217;s retail store Please Mum has alerted its online customers about a privacy breach to its online customer database that occurred in early June. Despite the fact that the long-awaited amendments to PIPEDA (which will require organizations to notify affected customers when certain privacy [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=3048&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://btdbowman.files.wordpress.com/2010/08/yell.jpg"><img class="alignleft size-thumbnail wp-image-3055" src="http://btdbowman.files.wordpress.com/2010/08/yell.jpg?w=150&#038;h=99" alt="" width="150" height="99" /></a>The CBC National News is reporting in this <a href="http://www.cbc.ca/video/#/News/TV_Shows/The_National/ID=1572540239">video news clip </a>that the children&#8217;s retail store Please Mum has alerted its online customers about a privacy breach to its online customer database that occurred in early June. Despite the fact that the long-awaited amendments to PIPEDA (which will require organizations to notify affected customers when certain privacy breaches occur) have not yet become law, Please Mum has taken the initiative to alert its customers. </p>
<p>In the absence of specific legal requirements, the decision to notify customers when privacy breaches occur is not an easy task. Far from it. Factors that businesses should consider include assessing what personal information was compromised, the cause and extent of the privacy breach, the number of affected individuals and the anticipated harm that could result from the privacy breach.</p>
<br />Filed under: <a href='http://brianbowman.ca/category/online-shopping/'>Online Shopping</a>, <a href='http://brianbowman.ca/category/privacy/'>Privacy</a>, <a href='http://brianbowman.ca/category/safeguarding/'>Safeguarding</a>, <a href='http://brianbowman.ca/category/safekeeping/'>Safekeeping</a>, <a href='http://brianbowman.ca/category/security-breach/'>Security Breach</a> Tagged: <a href='http://brianbowman.ca/tag/privacy/'>Privacy</a>, <a href='http://brianbowman.ca/tag/privacy-breach/'>Privacy Breach</a>, <a href='http://brianbowman.ca/tag/security/'>Security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/3048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/3048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/3048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/3048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/3048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/3048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/3048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/3048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/3048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/3048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/3048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/3048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/3048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/3048/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=3048&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2010/08/23/privacy-breach-notification-to-notify-or-not-to-notify/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2010/08/yell.jpg?w=150" medium="image" />
	</item>
		<item>
		<title>Rite Aid Fined $1 Million (U.S.) for Improperly Disposing Personal Information</title>
		<link>http://brianbowman.ca/2010/08/09/rite-aid-fined-1-million-u-s-for-improperly-disposing-personal-information/</link>
		<comments>http://brianbowman.ca/2010/08/09/rite-aid-fined-1-million-u-s-for-improperly-disposing-personal-information/#comments</comments>
		<pubDate>Mon, 09 Aug 2010 17:35:28 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Privacy Compliance]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=3032</guid>
		<description><![CDATA[Hogan Lovells LLP is reporting that Ride Aid has agreed to pay $1 million dollars (U.S.) to settle violations of U.S. health information privacy requirements. Interestingly, the FTC has ordered Rite Aid to cease misrepresenting its information security practices to customers and establish other personal information management securities safeguards. As I have previously posted, we&#8217;ve seen [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=3032&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://btdbowman.files.wordpress.com/2010/08/money.jpg"><img class="alignleft size-thumbnail wp-image-3042" src="http://btdbowman.files.wordpress.com/2010/08/money.jpg?w=100&#038;h=150" alt="" width="100" height="150" /></a>Hogan Lovells LLP is <a href="http://www.hldataprotection.com/2010/08/articles/data-security-breaches-include/rite-aid-fined-1-million-for-improperly-disposing-personal-information/" target="_blank">reporting</a> that Ride Aid has agreed to pay $1 million dollars (U.S.) to settle violations of U.S. health information privacy requirements. Interestingly, the FTC has ordered Rite Aid to cease misrepresenting its information security practices to customers and establish other personal information management securities safeguards.</p>
<p>As I have previously <a href="http://brianbowman.ca/2009/02/13/right-to-privacy-worth-1-million/" target="_blank">posted</a>, we&#8217;ve seen million dollar privacy awards here in Canada but what&#8217;s interesting is the fact that the FTC took issue with an organization &#8220;misrepresenting&#8221; its privacy protection practices. It&#8217;s a good reminder that simply having a privacy policy doesn&#8217;t cut it. Businesses must ensure that internal policies and procedures exist and are enforced on an ongoing basis in order to live up to commitments made in privacy policies.</p>
<br />Filed under: <a href='http://brianbowman.ca/category/privacy/'>Privacy</a> Tagged: <a href='http://brianbowman.ca/tag/due-diligence/'>Due Diligence</a>, <a href='http://brianbowman.ca/tag/privacy-breach/'>Privacy Breach</a>, <a href='http://brianbowman.ca/tag/privacy-compliance/'>Privacy Compliance</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/3032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/3032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/3032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/3032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/3032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/3032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/3032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/3032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/3032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/3032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/3032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/3032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/3032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/3032/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=3032&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2010/08/09/rite-aid-fined-1-million-u-s-for-improperly-disposing-personal-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2010/08/money.jpg?w=100" medium="image" />
	</item>
		<item>
		<title>A Conversation with Jennifer Stoddart, Privacy Commissioner of Canada</title>
		<link>http://brianbowman.ca/2010/01/25/a-conversation-with-jennifer-stoddart-privacy-commissioner-of-canada/</link>
		<comments>http://brianbowman.ca/2010/01/25/a-conversation-with-jennifer-stoddart-privacy-commissioner-of-canada/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 16:36:54 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Airport Security]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Personal Information]]></category>
		<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Privacy Commissioner]]></category>
		<category><![CDATA[Privacy Commissioner of Canada]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Privacy Compliance]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=2448</guid>
		<description><![CDATA[I&#8217;m very pleased to be able to post the following conversation with Jennifer Stoddart.  Since becoming Canada&#8217;s Privacy Commissioner in 2003, Commissioner Stoddart has undoubtedly raised the value of privacy in a time when security, trade, technology and consumer expectations have created a volatile atmosphere for our personal information. I might add that she has accomplished this admirable feat with passion [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=2448&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong><em><a href="http://btdbowman.files.wordpress.com/2010/01/jennifer_stoddart.jpg"><img class="alignleft size-thumbnail wp-image-2450" title="Jennifer_Stoddart" src="http://btdbowman.files.wordpress.com/2010/01/jennifer_stoddart.jpg?w=125&#038;h=150" alt="" width="125" height="150" /></a></em></strong></p>
<p>I&#8217;m very pleased to be able to post the following conversation with <a href="http://www.priv.gc.ca/aboutUs/bio_e.cfm#contenttop">Jennifer Stoddart</a>. </p>
<p>Since becoming Canada&#8217;s Privacy Commissioner in 2003, Commissioner Stoddart has undoubtedly raised the value of privacy in a time when security, trade, technology and consumer expectations have created a volatile atmosphere for our personal information. I might add that she has accomplished this admirable feat with passion and professionalism.  As a result, Canadians have been exceptionally well-served.</p>
<p>Of course, I&#8217;d like to thank Commissioner Stoddart for agreeing to engage in this online Q &amp; A conversation.  If you&#8217;d like to learn more about Jennifer Stoddart, the Office of the Privacy Commissioner of Canada (the &#8220;OPC&#8221;) or the issues raised in this conversation, I&#8217;d encourage you to visit the OPC&#8217;s <a href="http://www.priv.gc.ca/index_e.cfm">website</a> and <a href="http://blog.privcom.gc.ca/">blog</a>.</p>
<p><strong><em>Q. How did you get involved in the world of privacy? </em></strong></p>
<p>A. Back in the spring of 2000, I happened to read an article in the <a href="http://www.nytimes.com/magazine/"><em>New York Times</em> <em>Magazine</em></a> by the noted American legal scholar <a href="http://en.wikipedia.org/wiki/Jeffrey_Rosen">Jeffrey Rosen</a>. Prof. Rosen was explaining how personal privacy was being subtly eroded in the digital age. I was fascinated.</p>
<p>I was working at the <a href="http://www.cdpdj.qc.ca/en/home.asp">Quebec Human Rights Commission</a> at the time. The next week, I was asked to head up <a href="http://www.cai.gouv.qc.ca/index-en.html">Quebec’s Access to Information and Privacy Commission</a>, and that’s the field I’ve been in ever since.</p>
<p><strong><em>Q. But it’s coming to an end.</em></strong></p>
<p>A. Sadly. My seven-year term as Privacy Commissioner will wind up this year. On the plus side, though, I can look back with considerable pride at the progress we’ve made. The encroachments on privacy in this digital era really are staggering, but that doesn’t mean we’re letting them bowl us over.</p>
<p>Last year’s <a href="http://www.priv.gc.ca/media/nr-c/2009/nr-c_090716_e.cfm">investigation</a><strong> </strong>into a complaint against Facebook was surely the most high-profile example of the kind of influence we have. And beyond that I would say that we’re making a meaningful difference, in countless other ways, every day of the year.</p>
<p><strong><em>Q. What are the most rewarding aspects of being the Privacy Commissioner of Canada? </em></strong></p>
<p>A. Certainly one of the most rewarding things for me is to know that our work matters, that it has a real and positive impact on the lives of Canadians.</p>
<p>As you know, it’s become fashionable in some circles to suggest that privacy is pretty much dead in this era of digital exhibitionism. But I think that’s totally wrong. And the best evidence for that was the worldwide response to our Facebook investigation.</p>
<p>Privacy may look different today than it did a generation – or even a decade – ago. But it remains an incredibly important and cherished value to Canadians. And to the extent that my Office can help protect that value, and advance privacy rights, I would say that is the most rewarding aspect of my job.</p>
<p><strong><em>Q. What do you consider to be the greatest challenges for the Office of the Privacy Commissioner of Canada? </em></strong></p>
<p>A. Our biggest challenges are the same that preoccupy data-protection authorities around the world: How to safeguard privacy rights in the face of so many rapidly changing technologies. You yourself have blogged about many of them – cloud computing, behavioural marketing, genetic technologies, to name just a few.</p>
<p>We’re seeing unimaginable quantities of data flash around the world, including to countries where data-protection laws are slim to non-existent. We’re also seeing technologies employed in the service of national security and law enforcement, but they’re guarded behind a wall of secrecy.</p>
<p>So the challenges are real, and they are huge.</p>
<p><strong><em>Q. So how does an Office like yours keep up? </em></strong></p>
<p>A. I guess the short answer is: By working smarter. We have zeroed in on four priority privacy challenges that are shaping and streamlining our work for the years ahead: information technology, genetic technology, national security and the protection of identity integrity.</p>
<p>We are re-engineering our internal processes to better handle the complaints and inquiries that come to our Office. We’re picking and choosing our privacy audits and our communications and public outreach efforts in order to maximize our impact. We’re ramping up our issuance of guidance, on the theory that an ounce of prevention outweighs a pound of cure. And we’re working with the global data-protection community, since so many of the challenges are international in scope.</p>
<p>But, most important of all, we’ve recently attracted an infusion of very bright, very knowledgeable – and in many cases young – new employees to key positions in our Office. They are really making a difference.</p>
<p><strong><em>Q. If you could make a few recommendations for Canadian business leaders, what would you say? </em></strong></p>
<p>A. First I’d thank them for having embraced PIPEDA, the <em><a href="http://laws.justice.gc.ca/en/P-8.6/">Personal Information Protection and Electronic Documents Act</a></em> as it came into force over the past nine years. When I look at the situation of our neighbours to the south, where there is no single law at the federal level to protect the personal information of consumers in a commercial setting, I am deeply gratified by the way things can work up here.</p>
<p>Beyond that, I would encourage business leaders to continue to consult the <a href="http://www.priv.gc.ca/leg_c/guidelines_e.cfm#contenttop">guidelines</a> we issue on specific topics for the purpose of clarifying the responsibilities of organizations under PIPEDA. And we invite them to work with us to fill any other information gaps they may have encountered.</p>
<p>I also want to take this opportunity to mention that data breach notification will become mandatory – and I suspect that will happen sooner rather than later. So I would encourage business leaders to start giving some thought now to how they can bring their processes into compliance. </p>
<p><strong><em>Q. Do you have any &#8220;privacy-related&#8221; predictions for 2010? </em></strong></p>
<p>A. I don’t think you need a crystal ball to conclude that national security will continue to dominate the privacy landscape in the year ahead. The controversy that erupted over Transport Canada’s deployment of millimetre-wave scanners at Canadian airports was just the first of the privacy-related issues that we can expect to be hearing about in 2010.</p>
<p>And stay tuned for more during and after the Vancouver Olympics. There, one of the big issues will revolve around the pervasive crowd surveillance measures, and what will happen with all the cameras and recordings after the flame is extinguished.</p>
<p>I’ll just mention two other issues of particular interest to our Office, because we will be consulting Canadians on them in the next few months. The first will focus on the tracking, profiling and targeting of consumers by marketers and other businesses, and we’ll be hosting consultation forums on that topic in Toronto in April and Montreal in May. Soon after, we’ll organize another forum to discuss the privacy implications of cloud computing.</p>
<br />Posted in Airport Security, Government, Personal Information, PIPEDA, Privacy, Privacy Breach, Privacy Commissioner, Privacy Commissioner of Canada, Security Tagged: Government, Personal Information, PIPEDA, Privacy, Privacy Breach, Privacy Commissioner of Canada, Privacy Compliance, Security <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/2448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/2448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/2448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/2448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/2448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/2448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/2448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/2448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/2448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/2448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/2448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/2448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/2448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/2448/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=2448&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2010/01/25/a-conversation-with-jennifer-stoddart-privacy-commissioner-of-canada/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2010/01/jennifer_stoddart.jpg?w=125" medium="image">
			<media:title type="html">Jennifer_Stoddart</media:title>
		</media:content>
	</item>
		<item>
		<title>Mandatory privacy breach notification requirement inevitable</title>
		<link>http://brianbowman.ca/2009/12/15/mandatory-privacy-breach-notification-requirement-inevitable/</link>
		<comments>http://brianbowman.ca/2009/12/15/mandatory-privacy-breach-notification-requirement-inevitable/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 16:40:30 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Personal Information]]></category>
		<category><![CDATA[PHIA]]></category>
		<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Breach]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=2249</guid>
		<description><![CDATA[For years now, Ontario&#8217;s Personal Health Information Protection Act has contained provisions requiring health custodians to notify individuals if their personal health information is stolen, lost or accessed by unauthorized persons.  Until now, such mandatory privacy breach notification provisions have been limited to the sphere of health care in Ontario. That&#8217;s about to change. The federal Personal Information Protection and Electronic [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=2249&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://btdbowman.files.wordpress.com/2009/12/lock-breach.jpg"></a><a href="http://btdbowman.files.wordpress.com/2009/12/oops.jpg"><img class="alignleft size-thumbnail wp-image-2310" src="http://btdbowman.files.wordpress.com/2009/12/oops.jpg?w=150&#038;h=100" alt="" width="150" height="100" /></a>For years now, Ontario&#8217;s <em><a href="http://www.e-laws.gov.on.ca/html/statutes/english/elaws_statutes_04p03_e.htm">Personal Health Information Protection Act</a></em> has contained provisions requiring health custodians to notify individuals if their personal health information is stolen, lost or accessed by unauthorized persons.  Until now, such mandatory privacy breach notification provisions have been limited to the sphere of health care in Ontario. That&#8217;s about to change.</p>
<p>The federal <em><a href="http://laws.justice.gc.ca/en/P-8.6/">Personal Information Protection and Electronic Documents Act </a></em>will likely contain mandatory privacy breach notification provisions in the near future. Since 2006, Special Committees at both the Federal and Provincial (Alberta and B.C.) levels have convened and generated a series of recommendations relating to breach notification.  For further information on these recommendations, see the final reports of the <a href="http://www2.parl.gc.ca/content/hoc/Committee/391/ETHI/Reports/RP2891060/ethirp04/ethirp04-e.pdf">Federal </a>, <a href="http://www.assembly.ab.ca/committees/reports/PIPA/finalpipawReport111407.pdf">Alberta</a> and <a href="http://www.leg.bc.ca/cmt/38thparl/session-4/pipa/">B.C.</a> committees.</p>
<p>The most important recommendation independently generated by each of the committees provides that organizations should be under a statutory breach notification duty.  On October 27, 2009, the initial step toward implementing this recommendation was taken in the Alberta Legislature with the first reading of <a href="http://www.assembly.ab.ca/ISYS/LADDAR_files/docs/bills/bill/legislature_27/session_2/20090210_bill-054.pdf">Bill 54: <em>Personal Information Protection Amendment Act,</em> 2009</a>.  The Alberta privacy breach notification provisions will soon come into force. British Columbia and the Feds are expected to follow suit and implement similar requirements in the near future. When that occurs, private sector organizations across Canada will be required by applicable law to notify affected individuals when privacy breaches occur.</p>
<p>The best advice is to make sure that privacy protection policies, procedures and training are implemented and enforced&#8230; now.</p>
<br />Posted in Personal Information, PHIA, PIPEDA, Privacy, Privacy Breach Tagged: Personal Information, PHIA, PIPEDA, Privacy, Privacy Breach <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/2249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/2249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/2249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/2249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/2249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/2249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/2249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/2249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/2249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/2249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/2249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/2249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/2249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/2249/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=2249&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/12/15/mandatory-privacy-breach-notification-requirement-inevitable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/12/oops.jpg?w=150" medium="image" />
	</item>
		<item>
		<title>Rogue employees pose risk to privacy compliance, corporate info</title>
		<link>http://brianbowman.ca/2009/11/18/rogue-employees-pose-risk-to-privacy-compliance-corporate-info/</link>
		<comments>http://brianbowman.ca/2009/11/18/rogue-employees-pose-risk-to-privacy-compliance-corporate-info/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 15:15:26 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Personal Information]]></category>
		<category><![CDATA[PIPA]]></category>
		<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Safeguarding]]></category>
		<category><![CDATA[Safekeeping]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Businesses]]></category>
		<category><![CDATA[Corporate Information]]></category>
		<category><![CDATA[Employees]]></category>
		<category><![CDATA[Privacy Compliance]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=2139</guid>
		<description><![CDATA[The U.K.&#8217;s Huffington Post is reporting that a rogue employee of a major mobile phone company has illegally sold millions of customer records to rival companies.  Apparently, customers&#8217; personal information (including contract expiry dates) was sold to several rivals, which then used the material to cold-call customers to offer them an alternative deal. As I&#8217;ve previously [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=2139&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://btdbowman.files.wordpress.com/2009/11/photoman060200049.jpg"><img class="alignleft size-thumbnail wp-image-2140" src="http://btdbowman.files.wordpress.com/2009/11/photoman060200049.jpg?w=150&#038;h=100" alt="" width="150" height="100" /></a>The U.K.&#8217;s Huffington Post is <a href="http://www.huffingtonpost.com/2009/11/17/millions-of-mobile-phone-_n_360860.html">reporting</a> that a rogue employee of a major mobile phone company has illegally sold millions of customer records to rival companies.  Apparently, customers&#8217; personal information (including contract expiry dates) was sold to several rivals, which then used the material to cold-call customers to offer them an alternative deal.</p>
<p>As I&#8217;ve <a href="http://www.pitblado.com/lawyer_images/WFPSEPT2006.PDF">previously written</a>, information really is the most valuable corporate asset. And for this reason, businesses of all sizes should take steps to protect corporate information regardless of whether it is stored online or off-line. Whether it’s customer or supplier lists, intellectual property or employees’ personal information, it’s information that needs safekeeping. </p>
<p>This case should serve as a reminder that corporate safekeeping practices must include protecting data from rogue employees.</p>
<br />Posted in Data Protection, Due Diligence, Personal Information, PIPA, PIPEDA, Privacy, Privacy Breach, Safeguarding, Safekeeping, Security Tagged: Businesses, Corporate Information, Due Diligence, Employees, Personal Information, PIPEDA, Privacy, Privacy Breach, Privacy Compliance, Safeguarding, Security <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/2139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/2139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/2139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/2139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/2139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/2139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/2139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/2139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/2139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/2139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/2139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/2139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/2139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/2139/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=2139&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/11/18/rogue-employees-pose-risk-to-privacy-compliance-corporate-info/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/11/photoman060200049.jpg?w=150" medium="image" />
	</item>
		<item>
		<title>Laptop Encryption: &#8220;I don’t know what we have to do to drive this message home” says Commissioner</title>
		<link>http://brianbowman.ca/2009/09/10/laptop-encryption-i-don%e2%80%99t-know-what-we-have-to-do-to-drive-this-message-home%e2%80%9d-says-commissioner/</link>
		<comments>http://brianbowman.ca/2009/09/10/laptop-encryption-i-don%e2%80%99t-know-what-we-have-to-do-to-drive-this-message-home%e2%80%9d-says-commissioner/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 18:49:59 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Access to Information]]></category>
		<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Laptops]]></category>
		<category><![CDATA[Mobile devices]]></category>
		<category><![CDATA[Personal Information]]></category>
		<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Privacy Commissioner]]></category>
		<category><![CDATA[PSDs]]></category>
		<category><![CDATA[Safeguarding]]></category>
		<category><![CDATA[Safekeeping]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Smartphones]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Laptop]]></category>
		<category><![CDATA[Privacy Compliance]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=1797</guid>
		<description><![CDATA[A summer incident involving sensitive personal information on stolen laptops has brought the issue of data protection once again into the crosshairs of Frank Work, the Alberta Information and Privacy Commissioner.  In a press release, the Commissioner expressed shock and disappointment with the fact that the stolen laptops, which contained the personal health information of more 300,000 individuals, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1797&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-thumbnail wp-image-1803" title="Laptop 11" src="http://btdbowman.files.wordpress.com/2009/09/laptop-11.jpg?w=150&#038;h=100" alt="Laptop 11" width="150" height="100" />A summer incident involving sensitive personal information on stolen laptops has brought the issue of data protection once again into the crosshairs of <a href="http://www.newswire.ca/en/extras/custom/bio/bio_fjw.html">Frank Work</a>, the <a href="http://www.oipc.ab.ca/pages/home/default.aspx">Alberta Information and Privacy Commissioner</a>. </p>
<p>In a <a href="http://alberta.ca/acn/200906/26322133049DB-DD41-B07F-25B636D2F942E829.html">press release</a>, the Commissioner expressed shock and disappointment with the fact that the stolen laptops, which contained the personal health information of more 300,000 individuals, were <em>not</em> encrypted. “This is shocking for me&#8230;I don’t know what we have to do to drive this message home” said the Commissioner. “The standard in Alberta for storing personal or health information on portable devices is encryption. I can’t accept anything less.&#8221; The Alberta incident is strikingly similar to an incident that occurred in Ontario back in 2007.  The Ontario incident also involved the theft of a non-encrypted laptop containing personal health information.  A review of the incident by <a href="http://www.ipc.on.ca/english/About-Us/About-the-Commissioner/">Ann Cavoukian</a>, <a href="http://www.ipc.on.ca/english/Home-Page/">Ontario&#8217;s Information and Privacy Commissioner</a>, produced an <a href="http://www.ipc.on.ca/images/Resources/up-ho_004.pdf">order</a> for information of this type to be encrypted. </p>
<p>These incidents demonstrate how easily sensitive data can be compromised when stored on laptops.  Encryption is a relatively easy way to improve the security of such information.  But, where do you start? There are numerous encryption options available.  Choices range from free open source encryption software like <a href="http://www.truecrypt.org/">TrueCrypt</a> to full information security consultations from companies that offer comprehensive data protection services like <a href="http://www.seccuris.com/">Seccuris</a>. Regardless of which course you choose, one fact remains the same, encrypting laptops significantly improves security and that&#8217;s just smart business.</p>
<br />Posted in Access to Information, Data Encryption, Data Protection, Laptops, Mobile devices, Personal Information, PIPEDA, Privacy, Privacy Breach, Privacy Commissioner, PSDs, Safeguarding, Safekeeping, Security, Security Breach, Smartphones, Technology Tagged: Data Encryption, Data Protection, Due Diligence, Information Technology, Laptop, Mobile devices, Personal Information, PIPEDA, Privacy, Privacy Breach, Privacy Commissioner, Privacy Compliance, Safeguarding, Security, Technology <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/1797/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/1797/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/1797/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/1797/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/1797/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/1797/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/1797/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/1797/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/1797/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/1797/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/1797/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/1797/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/1797/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/1797/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1797&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/09/10/laptop-encryption-i-don%e2%80%99t-know-what-we-have-to-do-to-drive-this-message-home%e2%80%9d-says-commissioner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/09/laptop-11.jpg?w=150" medium="image">
			<media:title type="html">Laptop 11</media:title>
		</media:content>
	</item>
		<item>
		<title>Changes to PIPEDA may be coming soon</title>
		<link>http://brianbowman.ca/2009/08/10/changes-to-pipeda-may-be-coming-soon/</link>
		<comments>http://brianbowman.ca/2009/08/10/changes-to-pipeda-may-be-coming-soon/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 15:37:47 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Privacy Commissioner]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Businesses]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Employees]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Personal Information]]></category>
		<category><![CDATA[Privacy Compliance]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=1726</guid>
		<description><![CDATA[Have you heard the saying &#8220;Just when you think you understand the situation, what you don&#8217;t understand is that the situation has changed&#8221;? If you think you understand The Personal Information Protection and Electronic Documents Act (&#8220;PIPEDA&#8221;), get ready&#8230; changes may be just around the corner.  PIPEDA was introduced back in 2001. It requires the Canadian Government to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1726&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-thumbnail wp-image-1733" title="coming-soon" src="http://btdbowman.files.wordpress.com/2009/08/coming-soon.gif?w=89&#038;h=101" alt="coming-soon" width="89" height="101" />Have you heard the saying &#8220;Just when you think you understand the situation, what you don&#8217;t understand is that the situation has changed&#8221;? If you think you understand <a href="http://laws.justice.gc.ca/en/P-8.6/index.html?noCookie"><em>The Personal Information Protection and Electronic Documents Act</em></a> (&#8220;PIPEDA&#8221;), get ready&#8230; changes may be just around the corner. </p>
<p>PIPEDA was introduced back in 2001. It requires the Canadian Government to review the law every five years.  To this end, the House of Commons Standing Committee on Access to Information, Privacy and Ethics (the “House of Commons Committee”) conducted its review and held public hearings from November 2006 to February 2007, where it heard from over 60 witnesses and considered over 30 submissions from a wide range of interested organizations and individuals. I had the pleasure of appearing before the House of Commons Committee to present the <a href="http://www.cba.org/CBA/Sections_privacy/main/">Canadian Bar Association&#8217;s National Privacy &amp; Access Law Section&#8217;s </a>submission, which you can read <a href="http://www.cba.org/CBA/submissions/pdf/06-58-eng.pdf">here</a>. The House of Commons Committee issued its <a href="http://www2.parl.gc.ca/HousePublications/Publication.aspx?DocId=2891060&amp;Language=E&amp;Mode=1&amp;Parl=39&amp;Ses=1">report</a> to Parliament in May 2007 (which outlined 25 recommended changes to the law), to which the Canadian Government subsequently issued its <a href="http://www.ic.gc.ca/eic/site/ic1.nsf/eng/h_02861.html">response</a> in October 2007. As part of the Canadian Government&#8217;s response, further public consultation on key issues was requested.  A link to the Office of the Privacy Commissioner&#8217;s reply to this request can be read <a href="http://www.priv.gc.ca/parl/2008/let_080115_e.cfm">here</a> and the Canadian Bar Association&#8217;s response can be read <a href="http://www.cba.org/CBA/submissions/pdf/08-06-eng.pdf">here</a>.</p>
<p>Changes to PIPEDA may include:</p>
<ul>
<li>a mandatory breach notification regime that would require organizations to promptly notify affected individuals and to report major data breaches to the Privacy Commissioner of Canada; </li>
<li>amendments to account for the unique circumstances regarding consent in employer/employee relationships; and</li>
<li>modifications to allow organizations to collect, use and disclose personal information as necessary for the conduct of business transactions, such as mergers and acquisitions.</li>
</ul>
<p>The <a href="http://www.ic.gc.ca/ic_wp-pa.htm">Industry Canada</a> website targets 2009/10 for the implementation of changes resulting from this first PIPEDA review.  Yet, there is no definitive time frame, so stay tuned. Changes may be just around the corner.</p>
<br />Posted in Government, PIPEDA, Privacy, Privacy Breach, Privacy Commissioner, Security Breach Tagged: Businesses, Data Protection, Due Diligence, Employees, Identity Theft, Personal Information, PIPEDA, Privacy, Privacy Breach, Privacy Commissioner, Privacy Compliance <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/1726/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/1726/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/1726/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/1726/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/1726/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/1726/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/1726/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/1726/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/1726/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/1726/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/1726/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/1726/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/1726/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/1726/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1726&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/08/10/changes-to-pipeda-may-be-coming-soon/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/08/coming-soon.gif?w=150" medium="image">
			<media:title type="html">coming-soon</media:title>
		</media:content>
	</item>
		<item>
		<title>Portable Storage Devices (PSDs): Lessons learned from Australia and New Zealand</title>
		<link>http://brianbowman.ca/2009/07/13/portable-storage-devices-psds-lessons-learned-from-australia-and-new-zealand/</link>
		<comments>http://brianbowman.ca/2009/07/13/portable-storage-devices-psds-lessons-learned-from-australia-and-new-zealand/#comments</comments>
		<pubDate>Mon, 13 Jul 2009 16:35:23 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Access to Information]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[PSDs]]></category>
		<category><![CDATA[Safekeeping]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Personal Information]]></category>
		<category><![CDATA[Privacy Breach]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=1668</guid>
		<description><![CDATA[The Australian and New Zealand Privacy Commissioners recently released studies examining the use of Portable Storage Devices (PSDs) by their governmental agencies. The aim was to examine the risks to personal information posed by the use of PSDs.  PSDs are small, convenient devices that are capable of storing large amounts of information including laptops, cell phones, USBs, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1668&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-thumbnail wp-image-1679" title="PDAs 8" src="http://btdbowman.files.wordpress.com/2009/07/pdas-8.jpg?w=113&#038;h=164" alt="PDAs 8" width="113" height="164" />The <a href="http://www.privacy.gov.au/paw/documents/psd_report.pdf">Australian</a> and <a href="http://www.privacy.org.nz/portable-storage-device-survey-report-200/">New Zealand</a> Privacy Commissioners recently released studies examining the use of Portable Storage Devices (PSDs) by their governmental agencies. The aim was to examine the risks to personal information posed by the use of PSDs.  PSDs are small, convenient devices that are capable of storing large amounts of information including laptops, cell phones, USBs, hard drives and iPods.</p>
<p>The studies found that government agencies often keep track of the PSDs they issue but seldom do audit checks on those devices. Policies regulating the proper usage are often developed, but rarely enforced. Hardware controls (i.e. sealing off ports and disabling cables) are used less frequently than software controls (i.e. blocking access to certain databases, monitoring access and information downloaded, etc.).</p>
<p>The majority of agencies (like most private sector businesses in Canada) also allow the use of private PSDs for work (i.e. a cell phone which is used for both personal and business purposes). The studies found that policies regarding the use of private PSDs were less common and much less enforceable than policies for agency-issued PSDs. Even though these studies only analyzed governmental use, the New Zealand Privacy Commissioner stated that she believed the findings were equally applicable to private sector businesses as well.</p>
<p>As I&#8217;ve commented in <a href="http://brianbowman.ca/2009/07/06/smartphones-in-the-workplace-whats-your-business-doing-to-manage-the-risk/">previous posts</a>, there are privacy risks associated with the use of PSDs. First of all, there have been numerous incidents of stolen laptops and other PSDs that contained personal information. Secondly, devices such as USBs are easy to lose. Thirdly, disgruntled employees can easily use PSDs to steal personal information and other confidential corporate information from employers.  For example, an employee can simply click a button and download a company&#8217;s entire database in a matter of minutes. This is called &#8220;<a href="http://en.wikipedia.org/wiki/Pod_slurping">pod-slurping</a>&#8221; and is especially a threat given the fact that many government agencies and private companies do not have the software capability to track when data has been downloaded to a PSD.</p>
<p>In order to avoid a privacy breach and resulting damage to your business, consider implementing some of the suggestions contained in a <a href="http://www.oipc.ab.ca/downloads/documentloader.ashx?id=2019">2006 investigation</a> by the <a href="http://www.oipc.ab.ca/pages/home/default.aspx">Alberta Privacy Commissioner</a> (which I would add should, of course, be implemented in accordance with your organization&#8217;s privacy policy and applicable law):</p>
<ol>
<li>Develop policies on proper usage of PSDs (whether company-issued or private) and train employees about these policies. Include detailed instructions about retention and deletion of personal information;</li>
<li>Limit the amount of personal information that is stored on PSDs;</li>
<li>Use encryption on all PSDs that store personal information. Password protection alone is not sufficient as there are <a href="http://en.wikipedia.org/wiki/Password_cracking">free software programs</a> available on the Internet which can crack passwords;</li>
<li>Monitor the use of PSDs through <a href="http://www.gfi.com/whitepapers/threat-posed-by-portable-storage-devices.pdf">software</a> (i.e. install software that tracks data downloaded from a database onto a PSD);</li>
<li>Instead of using PSDs, implement technologies that allow employees to access a database through a secure network;</li>
<li>With respect to laptop thefts, consider installing tracking software that can trace the location of a lost laptop. Also consider installing a &#8220;<a href="http://en.wikipedia.org/wiki/Kill_switch">kill switch</a>&#8221; so that the computer will self-destruct if an individual tries to gain unauthorized access; and</li>
<li>Stress to employees the need to use appropriate safeguards at all times, even when at home.</li>
</ol>
<a name="pd_a_1782618"></a><div class="PDS_Poll" id="PDI_container1782618" style="display:inline-block;"></div><div id="PD_superContainer"></div><noscript><a href="http://polldaddy.com/poll/1782618">Take Our Poll</a></noscript>
<br />Posted in Access to Information, Privacy, PSDs, Safekeeping, Security, Technology Tagged: Access to Information, Personal Information, Privacy, Privacy Breach, PSDs, Safekeeping, Security, Technology <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/1668/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/1668/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/1668/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/1668/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/1668/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/1668/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/1668/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/1668/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/1668/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/1668/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/1668/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/1668/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/1668/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/1668/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1668&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/07/13/portable-storage-devices-psds-lessons-learned-from-australia-and-new-zealand/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/07/pdas-8.jpg?w=100" medium="image">
			<media:title type="html">PDAs 8</media:title>
		</media:content>
	</item>
		<item>
		<title>Smartphones in the workplace: what&#8217;s your business doing to manage the risk?</title>
		<link>http://brianbowman.ca/2009/07/06/smartphones-in-the-workplace-whats-your-business-doing-to-manage-the-risk/</link>
		<comments>http://brianbowman.ca/2009/07/06/smartphones-in-the-workplace-whats-your-business-doing-to-manage-the-risk/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 13:10:35 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Employee Monitoring]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Smartphones]]></category>
		<category><![CDATA[BlackBerrys]]></category>
		<category><![CDATA[Businesses]]></category>
		<category><![CDATA[iPhones]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=1640</guid>
		<description><![CDATA[Recently, an interesting article in the Globe and Mail dealt with the issue of smartphone etiquette. Business professionals fidgeting with their BlackBerrys and iPhones in meetings, walking through airports with eyes glued to their small glowing screens and operating their devices in restrooms may seem unrealistic at first blush, but is it really? The reality [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1640&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-thumbnail wp-image-1660" title="Cell phones" src="http://btdbowman.files.wordpress.com/2009/06/cell-phones.jpg?w=150&#038;h=150" alt="Cell phones" width="150" height="150" />Recently, an interesting <a href="http://www.theglobeandmail.com/report-on-business/managing/mind-your-blackberry-manners-or-risk-your-career/article1194677/">article</a> in the <a href="http://www.theglobeandmail.com/">Globe and Mail</a> dealt with the issue of smartphone etiquette. Business professionals fidgeting with their <a href="http://en.wikipedia.org/wiki/BlackBerry">BlackBerrys</a> and <a href="http://en.wikipedia.org/wiki/IPhone">iPhones</a> in meetings, walking through airports with eyes glued to their small glowing screens and operating their devices in restrooms may seem unrealistic at first blush, but is it really? The reality is that smartphones have permeated the business world. They are everywhere, they are powerful and have the potential to be extremely damaging.</p>
<p>Breaches of confidential corporate data and personal information are nothing new to the business world, but smartphones have brought a new dimension to the problem. Smartphones are starting to make appearances in Canadian <a href="http://www.canlii.org/en/ab/abqb/doc/2009/2009abqb275/2009abqb275.html">court cases</a> in a supporting role, but it won&#8217;t be long before they are squarely in the spotlight. The latest <a href="http://www.apple.com/iphone/iphone-3gs/">iPhone model</a> has up to 32GB of memory while BlackBerrys can store vast amounts of data on memory cards. The equivalent of entire filing cabinets can now be carried around conveniently in your shirt pocket. This reality has increased the risk for massive privacy breaches in the blink of an eye.</p>
<p>The big question is how involved should employers be in regulating and monitoring their employees use of smartphones? All encompassing monitoring of employee smartphone use is a touchy area, but the permeation of smartphones in today&#8217;s corporate world and the corresponding risks to businesses necessitates (at the very least) that relevant guidelines concerning their use in the workplace should be implemented by employers. All it takes to damage a business is for one employee to misplace their smartphone without having first activated their security settings.</p>
<br />Posted in Employee Monitoring, Privacy, Privacy Breach, Security, Security Breach, Smartphones Tagged: BlackBerrys, Businesses, Employee Monitoring, iPhones, Privacy, Privacy Breach, Security, Security Breach, Smartphones <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/1640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/1640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/1640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/1640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/1640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/1640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/1640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/1640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/1640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/1640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/1640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/1640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/1640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/1640/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1640&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/07/06/smartphones-in-the-workplace-whats-your-business-doing-to-manage-the-risk/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/06/cell-phones.jpg?w=150" medium="image">
			<media:title type="html">Cell phones</media:title>
		</media:content>
	</item>
		<item>
		<title>IP Osgoode (at Osgoode Hall Law School) names On the Cutting Edge &#8220;Pick of the Week&#8221;</title>
		<link>http://brianbowman.ca/2009/06/10/ip-osgoode-at-osgoode-hall-law-school-names-on-the-cutting-edge-pick-of-the-week/</link>
		<comments>http://brianbowman.ca/2009/06/10/ip-osgoode-at-osgoode-hall-law-school-names-on-the-cutting-edge-pick-of-the-week/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 17:01:33 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Nymity]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=1551</guid>
		<description><![CDATA[I was delighted to learn that IP Osgoode has named this blog the &#8220;Pick of the Week&#8221;! IP Osgoode at Osgood Hall Law School in Toronto is a new, independent and authoritative voice which explores legal governance issues at the intersection of intellectual property (IP) and technology. If you haven&#8217;t yet visited the IP Osgoode website, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1551&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-thumbnail wp-image-1552" title="Choices" src="http://btdbowman.files.wordpress.com/2009/06/choices.jpg?w=150&#038;h=112" alt="Choices" width="150" height="112" />I was delighted to learn that <a href="http://www.iposgoode.ca/">IP Osgoode</a> has named this blog the &#8220;Pick of the Week&#8221;!</p>
<p>IP Osgoode at <a href="http://www.osgoode.yorku.ca/">Osgood Hall Law School </a>in Toronto is a new, independent and authoritative voice which explores legal governance issues at the intersection of intellectual property (IP) and technology. If you haven&#8217;t yet visited the IP Osgoode website, I would encourage you to do so as it contains some great content.</p>
<p>If you are also interested in finding additional resources, you may want to visit the <a href="http://www.nymity.com/">Nymity</a> website. Of particular interest, the Nymity website has a section dedicated to <a href="http://www.nymity.com/Free_Privacy_Resources/Privacy_Breach_Analysis.aspx">recent privacy breaches</a> and <a href="http://www.nymity.com/Free_Privacy_Resources/Latest_Privacy_Studies.aspx">recent privacy studies</a>. Finally, you may also want to visit the <a href="http://www.capapa.org/">Canadian Association of Professional Access and Privacy Administrators</a> website.</p>
<p>Hope these links help!</p>
<br />Posted in Blogs, Intellectual Property, Privacy, Privacy Breach, Technology Tagged: Intellectual Property, Nymity, Privacy, Privacy Breach, Technology <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/1551/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/1551/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/1551/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/1551/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/1551/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/1551/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/1551/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/1551/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/1551/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/1551/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/1551/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/1551/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/1551/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/1551/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1551&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/06/10/ip-osgoode-at-osgoode-hall-law-school-names-on-the-cutting-edge-pick-of-the-week/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/06/choices.jpg?w=150" medium="image">
			<media:title type="html">Choices</media:title>
		</media:content>
	</item>
		<item>
		<title>Information &amp; Ideas team speaks out on slaw.ca</title>
		<link>http://brianbowman.ca/2009/05/29/information-ideas-team-speaks-out-on-slaw-ca/</link>
		<comments>http://brianbowman.ca/2009/05/29/information-ideas-team-speaks-out-on-slaw-ca/#comments</comments>
		<pubDate>Fri, 29 May 2009 13:40:21 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[Copyright]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Social Networking Websites]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Training]]></category>
		<category><![CDATA[Businesses]]></category>
		<category><![CDATA[Corporate Information]]></category>
		<category><![CDATA[Employees]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Inventions]]></category>
		<category><![CDATA[Manitoba]]></category>
		<category><![CDATA[Mobile devices]]></category>
		<category><![CDATA[Personal Information]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Privacy Compliance]]></category>
		<category><![CDATA[Safeguarding]]></category>
		<category><![CDATA[Social Networking]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=1505</guid>
		<description><![CDATA[It&#8217;s been a thrilling week for my colleagues at Pitblado LLP as it was announced earlier this week that we were to be the 1st Canadian law firm to be a guest blogger on the must-read slaw.ca.  Yours truly, three of my colleagues from our firm&#8217;s Information &#38; Ideas Practice Group as well as our firm&#8217;s librarian each contributed one [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1505&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-thumbnail wp-image-1512" src="http://btdbowman.files.wordpress.com/2009/05/lightbulbs1.jpg?w=150&#038;h=112" alt="" width="150" height="112" /></p>
<p>It&#8217;s been a thrilling week for my colleagues at <a href="www.pitblado.com">Pitblado LLP </a>as it was announced earlier this week that we were to be the <a href="http://www.slaw.ca/2009/05/24/firm-guest-blogger-pitblado-llp/">1st Canadian law firm to be a guest blogger </a>on the must-read <a href="http://www.slaw.ca/">slaw.ca</a>.  Yours truly, three of my colleagues from our firm&#8217;s <a href="http://www.pitblado.com/area.asp?pid=8">Information &amp; Ideas Practice Group </a>as well as our firm&#8217;s librarian each contributed one post a day this week to slaw.ca on cutting edge legal topics.  Here&#8217;s what we covered&#8230;</p>
<p>On Monday, I posted <a href="http://www.slaw.ca/2009/05/25/what-would-happen/">&#8220;What Would Happen If One of your Employees Posted a Video of an Irate Customer on YouTube?&#8221;</a>, which I <a href="http://brianbowman.ca/2009/05/25/what-would-happen-if-one-of-your-employees-posted-a-video-of-an-irate-customer-on-youtube/">cross posted </a>on my blog earlier this week.  The post highlights a <a href="http://www.youtube.com/watch?v=xbVw7entkxg">YouTube video </a>of an irrate customer as a reminder to Canadian businesses of the powers of new technologies such as YouTube and the corresponding need to protect against the dissemination of this type of video through employee privacy training and the adoption and enforcement of privacy and procedures.</p>
<p>On Tuesday, <a href="http://www.pitblado.com/profile.asp?lid=13">Carol Lynn Schafer</a> posted <a href="http://www.slaw.ca/2009/05/26/do-tos-have-the-final-word/">&#8220;Do TOS Have the Final Word on our Fundamental Rights and Freedoms?&#8221;</a>, which discusses the controversial effects of Terms of Service on popular websites such as <a href="http://www.facebook.com/">Facebook</a> and <a href="http://twitter.com/">Twitter</a>.  As Carol Lynn notes, Terms of Service should be drafted with the bigger picture in mind and can no longer be seen as standard agreements that can be treated with a one size fits all approach.</p>
<p>On Wednesday, <a href="http://www.pitblado.com/profile.asp?lid=80">Jolin Spencer</a> posted <a href="http://www.slaw.ca/2009/05/27/whose-property-is-it-anyway/">&#8220;Whose Property Is It, Anyway?&#8221;</a>, which discusses the questions that come into play when employees leave their positions.  For example, what can an employee take, and what must they leave, when they vacate their position? As Jolin points out, no business wants its intellectual property assets walking out the door with a former employee.</p>
<p>On Thursday, our firm&#8217;s librarian, Karen Sawatsky, posted <a href="http://www.slaw.ca/2009/05/28/legal-research-bootcamp-winnipeg-style/">&#8220;Legal Research Bootcamp &#8211; Winnipeg Style&#8221;</a>, which discusses her experience collaborating with members of the <a href="http://www.cba.org/Manitoba/main/home/">Manitoba Bar Association </a>and the <a href="http://www.lawsociety.mb.ca/">Law Society of Manitoba </a>to create a CLE for articling students on legal research. The Legal Research Bootcamp is a first for Manitoba students, and aims to bridge the gap between when students start their articles and when <a href="http://www.lawsociety.mb.ca/articling.htm">CPLED</a> begins in the fall.</p>
<p>And last but not least, today <a href="http://www.pitblado.com/profile.asp?lid=5">Adam Herstein</a> posted <a href="http://www.slaw.ca/2009/05/29/manitoba-innovative-fighter-of-child-sexual-exploitation/">&#8220;Manitoba: Innovative Fighter of Child Sexual Exploitation&#8221;</a>, which focuses on Manitoba&#8217;s recent enactment of <a href="http://web2.gov.mb.ca/laws/statutes/ccsm/c080e.php">The Child and Family Services Amendment Act (Child Pornography Reporting) (Manitoba)</a> and how Manitoba is the first province in Canada to enact legislation that makes it mandatory for a person who encounters child pornography to report it to authorities.  Adam also notes that Canada has a national tipline called <a href="http://www.cybertip.ca/app/en/">Cybertip.ca </a>for reporting the sexual exploitation of children.</p>
<p>Thanks to slaw.ca for the opportunity to contribute!</p>
<br />Posted in Blogs, Copyright, Facebook, Government, Intellectual Property, PIPEDA, Privacy, Social Networking Websites, Technology, Training Tagged: Businesses, Copyright, Corporate Information, Employees, Facebook, Information Technology, Intellectual Property, Internet, Inventions, Manitoba, Mobile devices, Personal Information, PIPEDA, Privacy, Privacy Breach, Privacy Compliance, Safeguarding, Social Networking, Technology <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/1505/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/1505/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/1505/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/1505/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/1505/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/1505/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/1505/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/1505/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/1505/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/1505/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/1505/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/1505/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/1505/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/1505/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=1505&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/05/29/information-ideas-team-speaks-out-on-slaw-ca/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/05/lightbulbs1.jpg?w=150" medium="image" />
	</item>
		<item>
		<title>Businesses should conduct regular staff privacy training</title>
		<link>http://brianbowman.ca/2009/02/20/businesses-should-conduct-regular-staff-privacy-training/</link>
		<comments>http://brianbowman.ca/2009/02/20/businesses-should-conduct-regular-staff-privacy-training/#comments</comments>
		<pubDate>Fri, 20 Feb 2009 17:24:54 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Training]]></category>
		<category><![CDATA[Businesses]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Employees]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Privacy Commissioner]]></category>
		<category><![CDATA[Privacy Compliance]]></category>
		<category><![CDATA[Privacy Forum]]></category>

		<guid isPermaLink="false">http://brianbowman.ca/?p=537</guid>
		<description><![CDATA[Privacy professionals will know first hand the importance of conducting regular staff privacy training, which can mitigate customer privacy complaints and (as a result) the overall costs of privacy compliance.  I certainly know from my practice that the costs to businesses can be quite significant when having to deal with serious privacy complaints.  These costs [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=537&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-thumbnail wp-image-783" title="meeting-room" src="http://btdbowman.files.wordpress.com/2009/02/meeting-room.jpg?w=96&#038;h=96" alt="meeting-room" width="96" height="96" />Privacy professionals will know first hand the importance of conducting regular staff privacy training, which can mitigate customer privacy complaints and (as a result) the overall costs of privacy compliance.<span>  </span>I certainly know from my practice that the costs to businesses can be quite significant when having to deal with serious privacy complaints.<span>  </span>These costs can include settlements, legal fees and lost productivity.<span>  </span>Obviously, it&#8217;s better to be proactive and reduce the chances of having to deal with privacy complaints.<span>  </span>That&#8217;s where regular staff privacy training comes in! <span> </span>Businesses really should conduct staff privacy training on a regular basis &#8211; in my view, at least on an annual basis.</p>
<p>In a recent <a href="http://www.privcom.gc.ca/speech/2009/sp-d_090203_e.asp">speech</a> to the 10<sup>th</sup> Annual Privacy and Security Conference in Victoria, B.C., Privacy Commissioner Jennifer Stoddart commented, &#8220;Polling for my Office in 2007 found that only a third of all businesses reported having trained staff about their responsibilities under Canada’s privacy laws.  This is a huge concern!  We recently conducted an analysis of 86 breaches reported to my Office and found that employee awareness and training was the most important contributing factor.  It was an issue in more than half of the spills we examined! We found that very basic mistakes &#8211; human errors &#8211; often lead to breaches. Breaches are caused mostly by employee misconduct and human error, not technological weaknesses.&#8221;<span>  </span>The full speech is entitled, &#8220;<a href="http://www.privcom.gc.ca/speech/2009/sp-d_090203_e.asp">A Privacy Check Up For Canadians: Is the Glass Half Empty or Half Full?</a>&#8221; and is definitely worth reading.</p>
<br />Posted in PIPEDA, Privacy, Training Tagged: Businesses, Due Diligence, Employees, PIPEDA, Privacy, Privacy Breach, Privacy Commissioner, Privacy Compliance, Privacy Forum, Training <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/537/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/537/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/537/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=537&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/02/20/businesses-should-conduct-regular-staff-privacy-training/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/02/meeting-room.jpg?w=96" medium="image">
			<media:title type="html">meeting-room</media:title>
		</media:content>
	</item>
		<item>
		<title>Data &#8220;packrats&#8221; failing customers</title>
		<link>http://brianbowman.ca/2009/02/12/data-packrats-failing-customers/</link>
		<comments>http://brianbowman.ca/2009/02/12/data-packrats-failing-customers/#comments</comments>
		<pubDate>Thu, 12 Feb 2009 14:37:07 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Safekeeping]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Businesses]]></category>
		<category><![CDATA[Personal Information]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Retention]]></category>
		<category><![CDATA[Safeguarding]]></category>

		<guid isPermaLink="false">http://btdbowman.wordpress.com/?p=449</guid>
		<description><![CDATA[Data &#8220;packrats&#8221; failing customers: Companies need policies on retention My December 3, 2008 column in the Winnipeg Free Press details the problems businesses can get in to when they keep every single piece of information on their customers, even when they no longer need it. Posted in Due Diligence, PIPEDA, Privacy, Safekeeping, Security Tagged: Businesses, Due [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=449&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.pitblado.com/lawyer_images/Dec_3_2008_Data_'Packrats'_Failing_Customers.pdf"><img class="alignleft size-thumbnail wp-image-766" title="challenge" src="http://btdbowman.files.wordpress.com/2009/02/challenge.jpg?w=96&#038;h=96" alt="challenge" width="96" height="96" />Data &#8220;packrats&#8221; failing customers: Companies need policies on retention</a></p>
<p>My December 3, 2008 column in the <a href="http://www.winnipegfreepress.com">Winnipeg Free Press</a> details the problems businesses can get in to when they keep every single piece of information on their customers, even when they no longer need it.</p>
<br />Posted in Due Diligence, PIPEDA, Privacy, Safekeeping, Security Tagged: Businesses, Due Diligence, Personal Information, PIPEDA, Privacy Breach, Retention, Safeguarding, Security <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/449/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/449/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/449/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=449&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/02/12/data-packrats-failing-customers/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/02/challenge.jpg?w=96" medium="image">
			<media:title type="html">challenge</media:title>
		</media:content>
	</item>
		<item>
		<title>Businesses must take steps to prevent ID theft</title>
		<link>http://brianbowman.ca/2009/02/06/businesses-must-take-steps-to-prevent-id-theft/</link>
		<comments>http://brianbowman.ca/2009/02/06/businesses-must-take-steps-to-prevent-id-theft/#comments</comments>
		<pubDate>Fri, 06 Feb 2009 21:48:20 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Access to Information]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Breach Notification]]></category>
		<category><![CDATA[Businesses]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Privacy Compliance]]></category>

		<guid isPermaLink="false">http://btdbowman.wordpress.com/?p=262</guid>
		<description><![CDATA[Businesses must take steps to prevent I.D. theft My July 4, 2007 column in the Winnipeg Free Press points out the fine-tuning to PIPEDA and what businesses will have to do to remain compliant. Posted in Access to Information, Identity Theft, PIPEDA, Privacy, Security Tagged: Access to Information, Breach Notification, Businesses, Identity Theft, PIPEDA, Privacy, Privacy Breach, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=262&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.pitblado.com/lawyer_images/WFP%20-%20Article%20-%20JULY2007.pdf"><img class="alignleft size-thumbnail wp-image-921" title="buildings" src="http://btdbowman.files.wordpress.com/2009/02/buildings.jpg?w=128&#038;h=85" alt="buildings" width="128" height="85" />Businesses must take steps to prevent I.D. theft</a></p>
<p>My July 4, 2007 column in the <a href="http://www.winnipegfreepress.com">Winnipeg Free Press</a> points out the fine-tuning to PIPEDA and what businesses will have to do to remain compliant.</p>
<br />Posted in Access to Information, Identity Theft, PIPEDA, Privacy, Security Tagged: Access to Information, Breach Notification, Businesses, Identity Theft, PIPEDA, Privacy, Privacy Breach, Privacy Compliance <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/262/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=262&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/02/06/businesses-must-take-steps-to-prevent-id-theft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/02/buildings.jpg?w=128" medium="image">
			<media:title type="html">buildings</media:title>
		</media:content>
	</item>
		<item>
		<title>Identity theft growing rapidly</title>
		<link>http://brianbowman.ca/2009/02/06/identity-theft-growing-rapidly/</link>
		<comments>http://brianbowman.ca/2009/02/06/identity-theft-growing-rapidly/#comments</comments>
		<pubDate>Fri, 06 Feb 2009 21:40:29 +0000</pubDate>
		<dc:creator>Brian Bowman</dc:creator>
				<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Privacy Commissioner]]></category>

		<guid isPermaLink="false">http://btdbowman.wordpress.com/?p=227</guid>
		<description><![CDATA[Identity theft growing rapidly My February 7, 2007 column in the Winnipeg Free Press revisits identity theft with the publication of major data breaches by Winners and CIBC. Posted in Identity Theft, Privacy, Privacy Breach, Security, Technology Tagged: Data Breach, Identity Theft, Privacy, Privacy Breach, Privacy Commissioner, Security, Technology<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=227&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.pitblado.com/lawyer_images/WFPFEB2007.pdf"><img class="alignleft size-thumbnail wp-image-825" title="business-concepts1" src="http://btdbowman.files.wordpress.com/2009/02/business-concepts1.jpg?w=120&#038;h=96" alt="business-concepts1" width="120" height="96" />Identity theft growing rapidly</a></p>
<p>My February 7, 2007 column in the <a href="http://www.winnipegfreepress.com">Winnipeg Free Press</a> revisits identity theft with the publication of major data breaches by Winners and CIBC.</p>
<br />Posted in Identity Theft, Privacy, Privacy Breach, Security, Technology Tagged: Data Breach, Identity Theft, Privacy, Privacy Breach, Privacy Commissioner, Security, Technology <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/btdbowman.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/btdbowman.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/btdbowman.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/btdbowman.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/btdbowman.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/btdbowman.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/btdbowman.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/btdbowman.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/btdbowman.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/btdbowman.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/btdbowman.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/btdbowman.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/btdbowman.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/btdbowman.wordpress.com/227/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brianbowman.ca&amp;blog=4953393&amp;post=227&amp;subd=btdbowman&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://brianbowman.ca/2009/02/06/identity-theft-growing-rapidly/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8d51c3a56d4b622372aeac57ed6f7249?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">brianbowman</media:title>
		</media:content>

		<media:content url="http://btdbowman.files.wordpress.com/2009/02/business-concepts1.jpg?w=120" medium="image">
			<media:title type="html">business-concepts1</media:title>
		</media:content>
	</item>
	</channel>
</rss>
