Canadian privacy law raises ante
Complying may place burden on U.S. firms
Computerworld - Next month, Canada will enact a law that offers sweeping privacy protections for its citizens. But the law may also create legal obligations and data management problems for potentially thousands of businesses that exchange data with firms and subsidiaries in Canada, the U.S.'s largest trading partner.
On Jan. 1, Canada's Personal Information Protection and Electronic Documents Act becomes law, requiring businesses to offer Canadian citizens certain guarantees regarding the collection and use of personal data. For example, they must get a customer's consent before sharing data with affiliates or commercial partners and must provide access to that data for review.
Initially, the law will apply only to certain federally regulated businesses in Canada: airlines, banks, telecommunications firms and broadcasting organizations. But by 2004, virtually every Canadian business will be affected - and consequently, so will a broader range of U.S. businesses.
"In some cases, [the law] is going to create some interesting nightmares" for companies, said Murray Long, a privacy consultant in Ottawa. Long cited the case of a Canadian affiliate that stores its data in U.S.-based servers.
"How do you ensure that the [privacy compliance] safeguards on the U.S. corporate network are up to par?" he said.
Contractual Requirements
The Canadian law will likely force many U.S. companies that exchange personally identifiable information with Canadian firms and subsidiaries to have a contract that commits them to following Canada's law, say legal experts.
"A multinational company operating in Canada will have to have dozens and dozens of contracts with everybody who supplies them with any personal information, including their own subsidiaries," said David Aaron, a former official at the U.S. Department of Commerce who negotiated the European "safe harbor" agreement and is now an attorney at Dorsey & Whitney LLP in Washington.
And even though it may take three years before the law affects all U.S. firms doing business in Canada, the lack of a grandfather clause - which would have exempted data collected prior to the law's enactment - may force companies to begin seeking an individual's consent well before any deadline, legal experts noted.
If a company doesn't have the consent of the individual on the day the law takes effect, it won't be able to use that person's information, even if his data was collected years ago, said Brian C. Keith, an attorney at Borden Ladner Gervais LLP in Toronto.
Some companies, such as American Express Co. in New York, prepared long ago to adapt to the law. Amex already follows the Canadian Standards Association's model code



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Retail White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Retail Webcasts