{"id":583,"date":"2023-10-14T18:47:00","date_gmt":"2023-10-14T18:47:00","guid":{"rendered":"https:\/\/privacyand.com\/?p=583"},"modified":"2024-01-15T22:53:17","modified_gmt":"2024-01-15T22:53:17","slug":"patterns-of-privacy-enforcement","status":"publish","type":"post","link":"https:\/\/privacyand.com\/?p=583","title":{"rendered":"Patterns of Privacy Enforcement"},"content":{"rendered":"\n<p>The less transparent organizations are about their privacy practices, the more difficult it is for a data subject to make a decision about who to trust with their personal information. By being transparent about informational privacy practices in legislation, the data subject can make more informed decisions about who and when to release their own information.<\/p>\n\n\n\n<p>Organizations that collect personal information benefit as well; in Ontario, for example, where legislative enforcement is generally complaint based, having a happy customer means a customer who does not register complaints with enforcement bodies (either the IPC or the OPC).\u00a0\u00a0Increasing complaints and inquiries can generally be considered to reflect misunderstandings between the data subject and the organization.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Complaints under the Privacy Act<\/h2>\n\n\n\n<p>In 2009 under the\u00a0<em>Privacy Act<\/em>\u00a0(Canada\u2019s oldest privacy legislation), which governs federal Government privacy practices (including the management of employee personal information), there were 2,572 inquiries and 665 complaints received.\u00a0\u00a0The next year, inquiries dropped to 1,944 and complaints rose to 708.\u00a0\u00a0For 2011, inquiries dropped again to 1,310, while complaints rose again to 986.\u00a0\u00a0Over the 2012-2013 reporting period, there were 2,599 inquiries (almost double) while complaints increased to 1,458.\u00a0\u00a0Historical data is provided below:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"824\" height=\"452\" src=\"https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-1.png\" alt=\"\" class=\"wp-image-584\" srcset=\"https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-1.png 824w, https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-1-300x165.png 300w\" sizes=\"auto, (max-width: 824px) 100vw, 824px\" \/><\/figure>\n\n\n\n<p>Inquiries and Compliants under Canada\u2019s Public Sector Privacy Legislation\u00a0(Office of the Privacy Commissioner of Canada, 1984, 1985, 1994, 1995, 1996, 1997, 1998, 1999, 2000, 2001, 2003a, 1986, 2004, 2005b, 2006b, 2007b, 2008b, 2009b, 2010b, 2011b, 2012b, 2013b, 1987, 1988, 1989, 1990, 1991, 1992, 1993).<\/p>\n\n\n\n<p><em>The notable spike in complaints in 2003-2004 was notably the result of over 500 complaints filed from First Nations groups with Health Canada over a consent form.\u00a0\u00a0The form was subsequently changed.<\/em>\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Complaints under FIPPA<\/h3>\n\n\n\n<p>Specific data on complaints filed under FIPPA in first five years of reporting is not published.\u00a0\u00a0The significant decrease from the 1995 through 1998 period was due to a process change; much of what was previously handled as a formal privacy compliant was resolved informally at the intake stage beginning in 1997.\u00a0\u00a0By the time the 25 year report was issued, 2,139 complaints had been processed. An overview:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"782\" height=\"388\" src=\"https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-2.png\" alt=\"\" class=\"wp-image-585\" srcset=\"https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-2.png 782w, https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-2-300x149.png 300w\" sizes=\"auto, (max-width: 782px) 100vw, 782px\" \/><\/figure>\n\n\n\n<p>Compliants under Ontario\u2019s Provincial Public Sector Privacy Legislation\u00a0(Information and Privacy Commissioner \/ Ontario, 1996, 1997, 2006, 2007, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 1998, 1999, 2000, 2001, 2002, 2003, 2004, 2005)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Complaints under MFIPPA<\/h3>\n\n\n\n<p>Complaints under municipal legislation were not recorded until 1991, and specific data was not made public until 1994.\u00a0\u00a0By the time the 25 year report was issued (2012), 1,766 complaints had been processed.\u00a0\u00a0An overview is provided below:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"784\" height=\"376\" src=\"https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-3.png\" alt=\"\" class=\"wp-image-586\" srcset=\"https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-3.png 784w, https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-3-300x144.png 300w\" sizes=\"auto, (max-width: 784px) 100vw, 784px\" \/><\/figure>\n\n\n\n<p>Complaints under Ontario\u2019s Municipal Public Sector Privacy Legislation\u00a0(Information and Privacy Commissioner \/ Ontario, 1996, 1997, 2006, 2007, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 1998, 1999, 2000, 2001, 2002, 2003, 2004, 2005)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Complaints under PIPEDA<\/h3>\n\n\n\n<p>Under PIPEDA, the number of complaints has remained relative steady over time in recent years.\u00a0\u00a0In 2009, there were a total of 231 new complaints opened and 5,095 inquiries from the public received. In 2010, the numbers decreased slightly to 207 complaints and 4,793 inquiries.\u00a0\u00a0In 2011, they rose to 5,236 information requests and 281 new complaints accepted.\u00a0\u00a0A decrease was evident again in 2012 in new complaints filed (total of 220), 4474 information requests were received and 33 breach notifications filed (made publicly available for the first year). Historical data is provided:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"442\" src=\"https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-4.png\" alt=\"\" class=\"wp-image-587\" srcset=\"https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-4.png 700w, https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-4-300x189.png 300w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure>\n\n\n\n<p>Inquiries and Compliants under Canada\u2019s Private Sector Privacy Legislation\u00a0(Office of the Privacy Commissioner of Canada, 2001, 2003a, 2003b, 2004, 2005a, 2006a, 2007a, 2008a, 2009a, 2010a, 2011a, 2012a, 2013a)<\/p>\n\n\n\n<p>The office also publishes findings and relevant sections of the Act.&nbsp;&nbsp;A brief review of available data, the majority of complaints are based on the consent principle of the legislation; in other words, data subjects are expressing unhappiness with how organizations are managing their data as stated in consent forms.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Complaints under PHIPA<\/h3>\n\n\n\n<p>During the first full year under PHIPA, 177 new complaints were opened and 108 were closed.\u00a0\u00a059% of those new complaints involved access or correction to existing records of personal health information (PHI).\u00a0\u00a023% were breaches (19% self-reported, 4% initiated by the regulatory office) and 26% regarded the collection, use and \/ or disclosure of PHI.\u00a0\u00a0Over the past 9 years, the overall numbers have steadily increased.\u00a0\u00a0By 2013, 126 access and correction complaints were opened (7% down from the previous year).\u00a0\u00a0Self-reported breaches by organizations were down 3% to 184, while officially initiated breach investigations were up 21%.\u00a0\u00a0New individual complaints rose 7% over 2012.\u00a0\u00a0Historical data:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"814\" height=\"364\" src=\"https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-5.png\" alt=\"\" class=\"wp-image-588\" srcset=\"https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-5.png 814w, https:\/\/privacyand.com\/wp-content\/uploads\/2024\/01\/image-5-300x134.png 300w\" sizes=\"auto, (max-width: 814px) 100vw, 814px\" \/><\/figure>\n\n\n\n<p>Compliants under Ontario\u2019s Health Privacy Legislation\u00a0(Information and Privacy Commissioner \/ Ontario, 2005, 2006, 2007, 2008, 2009, 2010, 2011, 2012, 2013, 2014)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The less transparent organizations are about their privacy practices, the more difficult it is for a data subject to make a decision about who to trust with their personal information. By being transparent about informational privacy practices in legislation, the data subject can make more informed decisions about who and when to release their own &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/privacyand.com\/?p=583\" class=\"more-link\">Read more<span class=\"screen-reader-text\"> &#8220;Patterns of Privacy Enforcement&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1],"tags":[],"class_list":["post-583","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p7IDr7-9p","_links":{"self":[{"href":"https:\/\/privacyand.com\/index.php?rest_route=\/wp\/v2\/posts\/583","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/privacyand.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/privacyand.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/privacyand.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/privacyand.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=583"}],"version-history":[{"count":1,"href":"https:\/\/privacyand.com\/index.php?rest_route=\/wp\/v2\/posts\/583\/revisions"}],"predecessor-version":[{"id":589,"href":"https:\/\/privacyand.com\/index.php?rest_route=\/wp\/v2\/posts\/583\/revisions\/589"}],"wp:attachment":[{"href":"https:\/\/privacyand.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=583"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/privacyand.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=583"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/privacyand.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=583"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}