Canadian privacy law
Part of a series on |
Canadian law |
---|
Canadian privacy law is derived from the common law, statutes of the Parliament of Canada and the various provincial legislatures, and the Canadian Charter of Rights and Freedoms. Perhaps ironically, Canada's legal conceptualization of privacy, along with most modern legal Western conceptions of privacy, can be traced back to Warren and Brandeis’s "The Right to Privacy" published in the Harvard Law Review in 1890,[1] Holvast states "Almost all authors on privacy start the discussion with the famous article 'The Right to Privacy' of Samuel Warren and Louis Brandeis".[1]
Evolution of Canadian privacy statutes
Canadian privacy law has evolved over time into what it is today. The first instance of a formal law came when, in 1977, the Canadian government introduced data protection provisions into the Canadian Human Rights Act.[2] In 1982, the Canadian Charter of Rights and Freedoms outlined that everyone has "the right to life, liberty and security of the person" and "the right to be free from unreasonable search or seizure",[3] but did not directly mention the concept of privacy. In 1983, the federal Privacy Act regulated how federal government collects, uses and discloses personal information. Canadians' constitutional right to privacy was further confirmed in the 1984 Supreme Court case, Hunter v. Southam.[4] In this case, Section 8 of the Canadian Charter of Rights and Freedoms (1982) was found "to protect individuals from unjustified state intrusions upon their privacy" and the court stated such Charter rights should be interpreted broadly.[5] Later, in a 1988 Supreme Court case, the right to privacy was established as "an essential component of individual freedom".[4] The court report from R. v. Dyment states, "From the earliest stage of Charter interpretation, this Court has made it clear that the rights it guarantees [including privacy rights] must be interpreted generously, and not in a narrow or legalistic fashion".[5] Throughout the late 1990s and 2000s, privacy legislation placed restrictions on the collection, use and disclosure of information by provincial and territorial governments and by companies and institutions in the private sector.
Governing relations with public sector institutions
Privacy Act
The Privacy Act, passed in 1983[6] by the Parliament of Canada, regulates how federal government institutions collect, use and disclose personal information. It also provides individuals with a right of access to information held about them by the federal government, and a right to request correction of any erroneous information.[2]
The Act established the office of the Privacy Commissioner of Canada, who is an Officer of Parliament. The responsibilities of the Privacy Commissioner includes supervising the application of the Act itself.
Under the Act, the Privacy Commissioner has powers to audit federal government institutions to ensure their compliance with the act, and is obliged to investigate complaints by individuals about breaches of the act. The Act and its equivalent legislation in most provinces are the expression of internationally accepted principles known as "fair information practices." As a last resort, the Privacy Commissioner of Canada does have the "power of embarrassment", which can be used in the hopes that the party being embarrassed will rectify the problem under public scrutiny[2]
Although the office of the commissioner has no mandate to conduct extensive research and education under the current Privacy Act, the Commissioner believed that he had become a leading educator in Canada on the issue of privacy.[2]
Access to Information Act
The next major change to the Canadian privacy laws came in 1985 in the form of the Access to Information Act. The main purposes of the Act were to provide citizens with the right of access to information under the control of governmental institutions. The Act limits access to personal information under specific circumstances.[7]
Freedom of Information Act
The Freedom of Information Act was enacted in 1996, and expanded upon the principles of the Privacy Act and Access to Information Act. It was designed to make governmental institutions more accountable to the public, and to protect individual privacy by giving the public right of access to records, as well as giving individuals right of access to and a right to request correction of personal information about themselves. It also specifies limits to the rights of access given to individuals, prevents the unauthorized collection, use or disclosure of personal information by public bodies, and redefines the role of the Privacy Commissioner of Canada.[8]
Extension to private sector organizations
Federal
The Personal Information Protection and Electronic Documents Act ("PIPEDA") governs the topic of data privacy, and how private-sector companies can collect, use and disclose personal information. The Act also contains various provisions to facilitate the use of electronic documents. PIPEDA was passed in the late 1990s to promote consumer trust in electronic commerce, as well as was intended to assure other governments that Canadian privacy laws were strong enough to protect the personal information of citizens of other nationalities.
PIPEDA includes and creates provisions of the Canadian Standards Association's Model Code for the Protection of Personal Information, developed in 1995. Like any privacy protection act, the individual must be informed of information that may be disclosed, whereby consent is given. This may be done through accepting terms, signing a document or verbal communication.
In PIPEDA, "Personal Information" is specified as information about an identifiable individual, that does not include the name, title or business address or telephone number of an employee of an organization.[9]
Provinces
PIPEDA allows for similar provincial laws to continue to be in effect. Quebec, British Columbia and Alberta have subsequently been determined to have similar legislation, and laws governing personal health information only, in Ontario and New Brunswick, have received similar recognition. They all govern:
- What personal information can be collected from individuals (including customers, clients and employees);
- When consent is required to collect personal information and how consent is obtained;
- What notice must be provided before personal information is collected, and
- How personal information may be used or disclosed;
- The purposes for which personal information may be collected, used or disclosed by the organization;
- How an individual may get access to and request correction of his or her personal information held by the organization.
The provincial Acts that have been so recognized, and agencies responsible, are as follows:
Development of personal privacy rights
Provincial statutes
The Civil Code of Quebec contains provisions governing privacy rights that can be enforced in the courts.[10] In addition, the following provinces have passed similar statutes:
All four Acts establish a limited right of action, whereby liability will only be found if the defendant acts wilfully (not a requirement in Manitoba) and without a claim of right. Moreover, the nature and degree of the plaintiff‟s privacy entitlement is circumscribed by what is "reasonable in the circumstances".
Evolution of the common law
In January 2012, the Ontario Court of Appeal declared that the common law in Canada recognizes a right to personal privacy, more specifically identified as a "tort of intrusion upon seclusion",[15] as well as considering that appropriation of personality is already recognized as a tort in Ontario law.[16] The ramifications of this decision are just beginning to be discussed.[17][18]
See also
- Information privacy law
- Law in Canada
- Privacy laws of the United States
- Privacy law
- R v Cole—privacy for personal use of workplace computers (where permitted or reasonably expected)
References
- ^ a b "History of Privacy". rdcu.be. Retrieved 2018-11-15.
- ^ a b c d "The Evolution of Canada's Privacy Laws - Privacy Commissioner of Canada". Archived from the original on 2006-08-15. Retrieved 2008-07-30.
- ^ "Canadian charter of rights and freedoms". Archived from the original on 2006-10-20. Retrieved 2008-07-30.
- ^ a b Communications, Government of Canada, Department of Justice, Electronic (24 November 2005). "Department of Justice - THE OFFICES OF THE INFORMATION AND PRIVACY COMMISSIONERS: THE MERGER AND RELATED ISSUES". www.justice.gc.ca. Retrieved 2018-03-09.
{{cite web}}
: CS1 maint: multiple names: authors list (link) - ^ a b "R. v. Dyment - SCC Cases (Lexum)". scc-csc.lexum.com. January 2001. Retrieved 2018-03-09.
- ^ https://laws-lois.justice.gc.ca/eng/acts/p-21/FullText.html Privacy Act
- ^ "Access to Information Act". laws.justice.gc.ca. Archived from the original on 2001-04-08.
- ^ "Freedom of Information and Protection of Privacy Act". gov.bc.ca. Retrieved 18 January 2017.
- ^ "Personal Information Protection and Electronic Documents Act - an Unofficial Version of the Act - Privacy Commissioner of Canada". Archived from the original on 2009-02-28. Retrieved 2008-07-30.
- ^ CCQ, ss. 3 and 35-37, as well as s. 5 of the Charter of Human Rights and Freedoms, R.S.Q. c. C-12
- ^ Privacy Act, R.S.B.C. 1996 c. 373
- ^ Privacy Act, R.S.S. 1978, c. P-24
- ^ Privacy Act, R.S.M. 1987 c.P125
- ^ Privacy Act, R.S.N. 1990, c.P-22
- ^ Jones v. Tsige, 2012 ONCA 32, 2012-01-18
- ^ Cathy Beagan Flood; Iris Fischer; Nicole Henderson; Pei Li. "Ontario Court of Appeal Recognizes New Privacy Tort". Blake, Cassels & Graydon. Archived from the original on 2012-11-03. Retrieved 2012-02-03.
- ^ Rob Barrass; Lyndsay A. Wasser (January 2012). "seclusion intrusion: a common law tort for invasion of privacy". McMillan LLP. Retrieved 2012-01-19.
- ^ Kirk Makin (2012-01-19). "Ontario court paves way for victims of privacy intrusion to sue snoopers". The Globe and Mail. Retrieved 2012-01-20.