Teresa Scassa - Blog

Displaying items by tag: public sector privacy

This post is the second in a series on the consultation paper published by Treasury Board Secretariat on proposed reform of the federal Privacy Act. The first can be found here. This post focuses on the first of six themes in the document: Enabling integrated services.

If I had to sum up the new consultation paper on reform of the Privacy Act, I would describe it as a document about pragmatic privacy. It is about how government will protect privacy while enabling the uses that it needs and wants to make with data. It is not about the ideal of privacy, nor is it really about where the line should be drawn between government and citizen when it comes to the use of personal data. I am not suggesting that the document ignores the importance of privacy as a value; but I am proposing that the overall approach is pragmatic.

The pragmatism is evident in first of six themes chosen to lead the consultation paper on reform of the federal Privacy Act: “Enabling integrated services”. This set of reforms is aimed at facilitating horizontal information sharing across the federal government. Horizontal data sharing has, to date, been limited by the Privacy Act, since the vertical siloing of personal data within departments and agencies was initially seen as a way to protect privacy. Only those departments or agencies that had collected information directly from individuals had access to that data.

Horizontal sharing reflects two broad modernization goals. The first is to make it simpler for Canadians to access government services without having to provide or update the same information multiple times when dealing with programs housed in different departments. The second is less overt in the discussion paper, which describes :

[…] a new, purpose-based approach that allows government institutions to reuse and securely share personal data with each other and with their provincial, territorial, or municipal partners without asking for consent, if it clearly serves a public interest or directly benefits individuals, such as improving service delivery or program activities.

This is broad language that will surely include using data in analytics and AI systems to develop and deliver services.

The consultation paper makes it clear that horizontal data sharing will be subject to strict conditions which will include sharing only the information that is necessary for the stated purpose, sharing in the “least privacy-invasive way possible”, and having in place strong safeguards to protect privacy. (Note: Some of these issues are part of subsequent themes and proposals in the discussion document, and I will dig into them in later posts in this series). The document also promises that individuals will be informed of any reuse or sharing of their personal data, although it seems that this will be through plain language notices “published in a central registry before the data is shared or reused.” This transparency is important but note how the technological infrastructure to ensure transparency seems already determined. It will not be done through individual notice nor will it be through an Estonian-style citizen portal (called Data Tracker) which allows individuals to see who within government has accessed their personal data and when.

The general move towards horizontal data sharing is evident in the reforms of some provincial public sector data protection laws. For example, Alberta’s new Protection of Privacy Act contains, in Part 3, a framework governing “data matching”, which is defined in s. 1(f) as “linking personal information between 2 or more databases or other electronic sources of information”. Nova Scotia’s revised Freedom of Information and Protection of Privacy Act allows for personal information to be shared horizontally if it is “necessary for the delivery of a common or integrated program or activity” (s. 70, s. 71(g)). Data linking is also permitted for research or statistical purposes in s. 72. It is unsurprising, then, that a reform of the federal Privacy Act would seek to better enable horizontal data sharing. However, this objective is buried in the first theme in language about enabling better services and requiring individuals only to provide information once instead of multiple times. The broader goals of horizontal data sharing should be more explicit.

It is important to note that the data sharing envisaged is not just horizontal within the federal government, since the discussion paper refers to the potential to share information with provincial, territorial or even municipal governments. There is nothing inherently wrong with sharing information across governments. In Canada we sometimes create unnecessary barriers to getting things done, especially across layers of government. Yet there are also substantial risks with horizontal data sharing. These can include unwarranted surveillance, and problematic uses of data in AI systems that drive decision-making. Safeguards, transparency and accountability will be crucial.

As part of the infrastructure to support horizontal data sharing, the consultation paper puts forward a model which would designate “certain programs or institutions as the official sources for specific types of personal data”. TBS admits that there would be set-up time required for this infrastructure, but that it will ultimately “reduce the need for repeated data collection, lower storage costs, and simplify updates to personal data for individuals by allowing them to maintain their data in fewer trusted locations.”

The combination of discussion of privacy rules and infrastructure in the same document is part of the ‘pragmatic privacy’ approach. It highlights one of the differences between Privacy Act reform housed at TBS rather than in the Department of Justice. Past consultation papers from Justice have focused on privacy principles and reform of specific statutory provisions, with little discussion of the infrastructure required. On this model, principle precedes design. By contrast, the TBS consultation paper has one eye on privacy principles and another on how the new data infrastructures that will be required might be built. Another difference is that past discussion papers have been very specific about what provisions of the Privacy Act are targeted for change and how they might be changed. This consultation document discusses legislative changes in more general terms.

One thing is clear: in this first theme, the discussion of reform of the Privacy Act is closely tied to new data infrastructure. Public sector data protection laws have an odd relationship to infrastructure. What the law allows and does not allow can dictate how data infrastructure is designed and built. Conversely, how data infrastructure is built can establish a reality to which privacy laws must adapt. We seem to be at a transition point, where new data infrastructure is clearly contemplated (some of it is sketched out in this document). At the same time, Privacy Act reform is underway to enable the new ways of collecting and handling data that this infrastructure will enable. Privacy reform is therefore in part about how privacy will be protected within this new infrastructure – but the new infrastructure, which will enable new uses of personal data across the federal government, will also transform long-held expectations about privacy that stem in part from what was and was not previously possible. There is a fundamental paradigm shift. This is a Privacy Act being rewritten for a government that has access to more data than ever before and has tools to do more with that data than ever imagined in 1983. The nature and scale of data use has changed. It is a vision of a Privacy Act that is about enabling use and reuse of data.

The next post in this series will consider the second theme in the document: Enhancing Accountability and Transparency.

 

Published in Privacy

Treasury Board Secretariat has published a discussion paper and launched a consultation into the long-overdue reform of the federal Privacy Act. The consultation is open until July 10, 2026.

The Privacy Act, which came into force in 1983, has not had a significant overhaul since that time, although we have seen dramatic changes in how personal data are collected and used. The Privacy Act’s woeful state of disrepair is no secret. The statute has been the subject of multiple reports and recommendations for reform from the Standing Committee on Access to Information, Privacy and Ethics, the Office of the Privacy Commissioner of Canada, the Information Commissioner, and from several public consultations. One thing that is different this time around is that responsibility for Privacy Act reform has shifted from the Department of Justice to Treasury Board Secretariat (TBS). Since Justice has failed to move privacy law reform forward over decades, this move offers some hope. Among other things, TBS is responsible for establishing and maintaining internal federal government policies on information management, privacy, automated decision-making, and cybersecurity. Taking responsibility for the legal framework that shapes these policies makes sense.

Reform of the Privacy Act is sorely needed. Both the nature and volume of information collected by government has dramatically changed since the early 1980’s. So too have the uses to which such data are put. Another change is the desire of government (signaled in its strategy on the use of AI in the public service) to make greater use of data analytics and technology to derive value from data and to increase efficiency and improve service delivery. A 1980’s era privacy statute which relies on the strict vertical siloing of data to enhance privacy is not well adapted to an environment in which greater access to more complex data is seen as desirable. At the same time, the cybersecurity landscape has also dramatically changed, increasing the impact of privacy breaches and leaving Canadians more vulnerable where greater and greater volumes of data are collected. The Privacy Act must provide Canadians with modernized rules fit for our contemporary context. Although additional safeguards have been added over the years through directives and policies, these lack both the enforceability and independent oversight that privacy legislation can provide. Their scope of application across the public sector is also more limited. It is clear from the discussion document that TBS sees the reform process as a way to consolidate some of the approaches currently found in directives and policies and to extend them more broadly across the federal public sector.

In framing their approach to privacy reform, TBS has identified three overarching policy approaches:

o Enabling better services to Canadians

o Strengthening privacy protections for the digital age

o Updating foundations and oversight of the federal public sector privacy regime

By setting enabling better services to Canadians as a priority, TBS signals that its reforms will seek to remove some of the friction experienced by Canadians when accessing government services (notably the need to provide the same personal information to multiple different departments or agencies). In this sense, one of the goals of Privacy Act reform is to make personal data more reusable by government – with appropriate safeguards in place. The safeguards, and oversight of privacy measures are part of the second and third policy approaches.

The recommendations in the discussion paper are organized around 6 broad themes. These are: enabling integrated services; enhancing accountability and transparency; advancing safeguards across the spectrum of data sensitivity; modernizing the foundation for privacy and trust; Indigenous People’s access to, and protection of, their data; and updating the compliance framework. The themes and the discussion that accompanies them are not considered exhaustive or definitive, and feedback is invited.

There are a number of interesting features in this proposal for reform. Notably, it seeks to integrate Indigenous data sovereignty within a reformed Privacy Act. This builds upon considerable work done by First Nations, Métis and Inuit on data sovereignty issues over the years, as well as government efforts towards truth and reconciliation. The document also includes proposals to create new legal safeguards for public sector automated decision-making and to include (long overdue) privacy breach notification requirements. There is a proposal to formally recognize privacy as a fundamental right in the statute. New transparency measures are also proposed, both with respect to automated decision-making and the use of personal data by departments and agencies. There is also a recommendation to shift requests for access to one’s personal data to the Access to Information Act. Proposed changes would also add new compliance features, including order-making powers for the OPC, a new offence for deliberate re-identification of anonymized data; expanded judicial remedies; and a mandatory 5-year review of the Privacy Act.

Taken together there is much that is new and interesting in this document. There is also still room for criticism, comment and discussion. I will be diving into the TBS recommendations for reform over the next few weeks. My comments will be structured around each of the themes in the document. Stay tuned!

 

Published in Privacy

Canadian Trademark Law

Published in 2015 by Lexis Nexis

Canadian Trademark Law 2d Edition

Buy on LexisNexis

Electronic Commerce and Internet Law in Canada, 2nd Edition

Published in 2012 by CCH Canadian Ltd.

Electronic Commerce and Internet Law in Canada

Buy on CCH Canadian

Intellectual Property for the 21st Century

Intellectual Property Law for the 21st Century:

Interdisciplinary Approaches

Purchase from Irwin Law