affected individuals.
70 Under the Alberta statute, the decision to notify individuals
affected by a breach rests with the Commissioner, and not with the organization.
71
PIPEDA’s data breach notification provisions also require organizations to keep a
record of every breach of security safeguards—regardless of the degree of risk to
individuals. Such records must be made available to the Commissioner on request.
72
Although the obligation is to make information available to the Commissioner,
rather than to the public, such records might be capable of being subpoenaed, for
example, in cases where there is litigation relating to a data security breach. The data
breach notification regulations limit the retention period for such information to two
years.
73
3 Data Protection in the Electronic Communications Sector
Because of the interprovincial and cross-border nature of electronic communications, PIPEDA is the applicable statute. The Privacy Commissioner of Canada has
taken the position that Internet Protocol addresses (IP addresses) are personal
information so long as they can be linked to an identifiable individual.
74 Electronic
communications providers are subject to the same rules as all other organizations
under PIPEDA, including the data breach notification requirement provisions.
4 Data Protection and Digital Forensics
PIPEDA and the equivalent provincial private sector data protection laws generally
permit the disclosure of personal information without consent when it comes to the
investigation, detection and prosecution of crimes. In fact, the legislation is worded
broadly enough to include not just crimes, but also “the purpose of enforcing any law
of Canada, a province or a foreign jurisdiction, carrying out an investigation relating
to the enforcement of any such law or gathering intelligence for the purpose of
enforcing any such law”.
75 There is also an exception to the requirement of consent
to disclosure of personal information where “disclosure is requested for the purpose
of administering any law of Canada or a province”.
76
70 PIPEDA, s. 10.1(3).
71 PIPA (Alberta), s.37.1(1).
72 PIPEDA, s. 10.3.
73 Breach of Security Safeguards Regulations, SOR/2018-64, s. 6.
74 Privacy Commissioner of Canada (2013a) Interpretation Bulletin.
75 PIPEDA, s. 7(3)(c.1)(ii).
76 PIPEDA, s. 7(3)(c.1)(iii).
66
T. Scassa
70 Under the Alberta statute, the decision to notify individuals
affected by a breach rests with the Commissioner, and not with the organization.
71
PIPEDA’s data breach notification provisions also require organizations to keep a
record of every breach of security safeguards—regardless of the degree of risk to
individuals. Such records must be made available to the Commissioner on request.
72
Although the obligation is to make information available to the Commissioner,
rather than to the public, such records might be capable of being subpoenaed, for
example, in cases where there is litigation relating to a data security breach. The data
breach notification regulations limit the retention period for such information to two
years.
73
3 Data Protection in the Electronic Communications Sector
Because of the interprovincial and cross-border nature of electronic communications, PIPEDA is the applicable statute. The Privacy Commissioner of Canada has
taken the position that Internet Protocol addresses (IP addresses) are personal
information so long as they can be linked to an identifiable individual.
74 Electronic
communications providers are subject to the same rules as all other organizations
under PIPEDA, including the data breach notification requirement provisions.
4 Data Protection and Digital Forensics
PIPEDA and the equivalent provincial private sector data protection laws generally
permit the disclosure of personal information without consent when it comes to the
investigation, detection and prosecution of crimes. In fact, the legislation is worded
broadly enough to include not just crimes, but also “the purpose of enforcing any law
of Canada, a province or a foreign jurisdiction, carrying out an investigation relating
to the enforcement of any such law or gathering intelligence for the purpose of
enforcing any such law”.
75 There is also an exception to the requirement of consent
to disclosure of personal information where “disclosure is requested for the purpose
of administering any law of Canada or a province”.
76
70 PIPEDA, s. 10.1(3).
71 PIPA (Alberta), s.37.1(1).
72 PIPEDA, s. 10.3.
73 Breach of Security Safeguards Regulations, SOR/2018-64, s. 6.
74 Privacy Commissioner of Canada (2013a) Interpretation Bulletin.
75 PIPEDA, s. 7(3)(c.1)(ii).
76 PIPEDA, s. 7(3)(c.1)(iii).
66
T. Scassa
