♬ An' now I'm flyin' through the air.
On a cloud, on a cloud.
On a cloud, lookin' down…♬

Lyrics and Music by Cody Canada, recorded by Cross Canadian Ragweed.

Privacy Commission of Canada Web Logo

Privacy Commission of Canada Web Logo

Further to Simon Fodden's post on August 16, 2011 entitled: "Privacy Commissioner Releases PIPEDA Guide for Lawyers", I thought that a relevant passage in that report dealing with safeguarding personal information and in particular, with reference to mobile devices and cloud computing, would deserve its own post. The section in question on Safeguarding Personal Information is as follows (relevant paragraphs bolded for emphasis):

Safeguarding personal information

Lawyers are familiar with the need to safeguard their clients’ information. However, like all organizations, work options available to lawyers have evolved considerably. In the course of their practices, lawyers and support staff often work using computers, laptops, smart phones and other mobile devices. The use of such devices presents a number of challenges in safeguarding personal information.

Lawyers can face a number of potential vulnerabilities in the course of their practice, including the following:

  • poor security measures for paper documents, computer systems, computer applications, mobile devices, computer networks, wireless networks or email transmission;
  • misplacing paper or electronic documents;
  • traces left by electronic documents (i.e. metadata)
  • insecure courier/postal communication; and
  • third-party suppliers and partners may mishandle information (including third-parties offering cloud computing services).

PIPEDA requires personal information to be safeguarded at all times. Personal information should be safeguarded through the use of:

  • physical measures, for example, locked filing cabinets and restricted access to offices;
  • organizational measures, for example, security clearances and limiting access on a “need-to-know” basis; and
  • technological measures, for example, the use of passwords and encryption.

The more sensitive the information is, the stronger the safeguards must be.

One measure to ensure that personal information is secured is to avoid physically removing the information from the office at all, or to limit doing so to the greatest extent possible. There are many technological solutions that allow lawyers to securely access office systems remotely. Such solutions, provided they are implemented in a secure manner and employ appropriate encryption standards and firewalls, can offer the best protection for personal information.

Any laptops and other mobile devices and media must be secured, including through the use of encryption. Highest care must also be taken when working in public spaces or on devices to which more than one person may have access. As well, lawyers or law firms considering cloud computing solutions must carefully consider the privacy and security implications of any service they may create or subscribe to.

Lawyers must use contractual or other means to provide a comparable level of protection while the information is being processed by a third party. Where any third-party service provider may have access to or otherwise handle personal information on behalf of a lawyer, including cloud computing service providers, it is strongly recommended that a written agreement be put in place between the third-party and the lawyer. Such a contract should include provisions governing the jurisdiction where information will be processed or stored, ownership and use of information, the level of privacy controls used by the service provider, access and correction procedures, audits, and deletion procedures. Lawyers must remember that they remain accountable for information transferred to third-parties for processing. PIPEDA also requires organizations to be transparent about their personal information handling practices. Accordingly, organizations should notify clients when using a service provider located outside Canada and advise them that their personal information may be subject to the laws of a foreign jurisdiction.

The Office of the Privacy Commissioner has developed a self-assessment tool to assist organizations measure how well they are safeguarding personal information.

Hat tip to my colleague Doug Munroe for pointing out this particular section – good advice when you are flying on a cloud.

David J. Bilinsky is a lawyer and Practice Management Consultant. His area of expertise is enhancing a law firm¹s profitability, developing strategic business planning and applying technology to the practice of law. Dave's mission in life is to empower lawyers to anticipate the changes, realize the opportunities, face the challenges and embrace the expanding possibilities of the application of practice management concepts to the practice of law in innovative ways that provide service excellence. He is the founder and current Chair of the Pacific Legal Technology Conference. You can visit his blog at: www.thoughtfullaw.com.
[click on the author's name for more information]

up

2 Comments on “PIPEDA and Cloud Computing”

  1. Sean says:

    My concern with cloud computing has to do with the US Patriot act which gives *any* US government agency the right to request information from any database housed on US soil. Since all cloud services, to date, originate in the USA, I fail to see how PIPEDA can protect client confidentiality, or how a paper agreement with a third party provider of cloud services can protect your (or your client's) privacy. The Patriot Act was supposed to expire in 2004, and has since been renewed every year by two successive administrations.

  2. Wally Kowal says:

    There are cloud providers in Canada that address this specific issue. The Patriot Act has always been a issue for non-US companies using the public cloud, but most have chosen to ignore it. As companies start to use cloud services for their core operations, this issue is coming to the forefront. Cloud can meet stringent privacy demands, but you have to be careful. Just because something is hard doesn't mean you should not do it

Make a comment:

Note that some comments may be moderated. If you have not had an approved comment here before, your comment will be held for approval. We are glad to publish comments that address issues raised in the post or other comments on it and that contribute to a fruitful discussion. We do not publish comments that seek to promote commercial products, that make personal attacks, or that seek personal legal advice.

Although we do not require it, we ask that in making a comment you use your full name. You must supply a valid email address, which will not appear with your comment.

 

SlawTips      

SlawTips Good Communications = Satisfied Clients
Thursday, February 23

As Richard Ferguson, a lawyer friend of ours says on his email message: “People may forget what you said…. People may forget what you did…. but people will never forget … »»

Practice

SlawTips Current Awareness
Wednesday, February 22

There are two possible approaches to personal current awareness: Develop excellent searching skills so that you can find what you need when you need it Pick a fairly narrow specialty … »»

Research

SlawTips Top 10 Financial Errors: #10 Rely on the Lottery for Your Partnership Retirement Plan
Thursday, February 16

“It is better to have a permanent income than to be fascinating” was said once by Oscar Wilde. The final tip in this series is the capstone issue in our … »»

Practice

noted on Slaw    

MLB Selected Case Summaries    

These summaries of selected recent cases are provided each week to Slaw by Maritime Law Book.
More information.

  • Limitation of Actions - Actions in contract - Actions for debt - General

    Moody died on December 3, 2005, leaving four adult children. Pursuant to Moody’s will two of her children, James and Tyrell, were appointed executors of the estate. It was alleged that, during her ...

  • Barristers and Solicitors - Discipline - Suspension - For professional misconduct

    McLean pled guilty five counts of conduct unbecoming a lawyer. The Discipline Committee suspended him from practice for four months and placed him on indefinite supervision. McLean appealed the length of the penalty.

    The Saskatchewan ...

  • Mines and Minerals - Operation of mines, quarries and wells - Licences and permits - Appeals or judicial review - Standing - Costs

    Grizzly Resources Ltd. (Grizzly). made an applications to the Energy Resources Conservation Board to drill two sour gas wells on the same site. ...

  • Narcotic Control - Offences - Trafficking - Elements of

    The accused was charged with trafficking in cocaine. The trial judge granted the accused’s motion to discharge the charge. The Crown appealed.

    The Saskatchewan Court of Appeal allowed the appeal and ordered a new trial.

    Link ...


TalkLaw/ParLoi    

This is a listing of a few upcoming events in Canada of interest to lawyers, law students, legal librarians, and others involved in the practice of law.

Clicking on any event in the list below will give you access to more information and to links allowing you to see the full entry and to add the event to your own calendar.

Click this link for a fuller version of the TalkLaw/ParLoi calendar of events and for instructions as to how to add events and calendars to your own calendar.

Switch to our mobile site