Analytics Unleashed: Why Canadian data pros need to watch proposed privacy bills, court decisions

Share post:

Most data analytics staff worry about number crunching and outputs. But a lawyer has warned IT pros that proposed legislation before Parliament should also be on their minds.

“Understand them and understand what your company needs to do,” Jennifer Davidson told IT World Canada‘s Analytics Unleashed conference this month. “Don’t leave it to the last minute.”

Davidson, a partner and technology lawyer at Deeth, Williams, Wall LLP, was referring to Bill C-27, which introduces the Consumer Privacy Protection Act (CPPA) and the Artificial Intelligence and Data Act (AIDA), and Bill-C-26, the Critical Cyber Systems Protection Act.

If passed, the CPPA will replace the Personal Information Protection and Electronic Documents Act (PIPEDA) with new rules on the collection, use, and disclosure of personal data. Proposed fines for violating the act and its reporting obligations jump to a maximum $25 million, or five per cent of an organization’s gross global revenue, Davidson pointed out.

The new AIDA covers high-impact systems using artificial intelligence, and requires affected firms to, among other things, keep records describing how the system works and the decisions/recommendations/predictions it is intended to make. Whoever is responsible for the system has to notify the government if it results in, or is likely to result in, harming people.

Both acts have tough rules for notifying privacy regulators, victims, and possibly others in a firm’s supply chain, she added.

“When you look at this act, it’s time to pay attention,” she warned.

C-26 and C-27 are federal laws that apply to all federally-regulated industries, and to the private sectors in Ontario, the Maritime provinces, Saskatchewan, Manitoba, and the Territories, she added. Alberta, British Columbia, and Quebec have their own private-sector privacy laws that have some differences, so data pros in those provinces have to be up on the laws.

Court decisions involving data breaches should also be on the mind of a data controller or data analyst, she added.

She pointed to a recent decision faulting the Insurance Bureau of British Columbia, which insures B.C. drivers and vehicles, in the 2012 theft of a list of insured people by an employee, who then sold it to crooks. They used the names in targeted arson and shooting attacks. While the bureau had written policies forbidding unapproved uses of its databases, there was no evidence the bureau had any system or method that would have detected or prevented data theft.

The lesson from this case is “we need to actively protect data or we (companies) are going to pay the consequences,” Davidson said.

She also urged data pros and security pros to make sure their organization has policies and procedures to safeguard data it holds, and that the firm’s partners are also protecting their IT networks and data.

Analytics Unleashed was sponsored by SAS, Informatica and Shinydocs.

The post Analytics Unleashed: Why Canadian data pros need to watch proposed privacy bills, court decisions first appeared on IT World Canada.

Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, April 24, 2024 – Good news/bad news in Mandiant report, UnitedHealth admits paying a ransomware gang, and more

This episode reports on the danger of using expired open-source packages, a tool used by a Russian hacking group and passw

Google Play introduces new biometric verification with a user warning

Google has recently announced updates to the biometric verification process for Google Play purchases, aiming to bolster security...

Cyber Security Today, Week in Review for week ending Friday April 19, 2024

On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT d

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways