♬ An' now I'm flyin' through the air.
On a cloud, on a cloud.
On a cloud, lookin' down…♬

Lyrics and Music by Cody Canada, recorded by Cross Canadian Ragweed.

Privacy Commission of Canada Web Logo

Privacy Commission of Canada Web Logo

Further to Simon Fodden's post on August 16, 2011 entitled: "Privacy Commissioner Releases PIPEDA Guide for Lawyers", I thought that a relevant passage in that report dealing with safeguarding personal information and in particular, with reference to mobile devices and cloud computing, would deserve its own post. The section in question on Safeguarding Personal Information is as follows (relevant paragraphs bolded for emphasis):

Safeguarding personal information

Lawyers are familiar with the need to safeguard their clients’ information. However, like all organizations, work options available to lawyers have evolved considerably. In the course of their practices, lawyers and support staff often work using computers, laptops, smart phones and other mobile devices. The use of such devices presents a number of challenges in safeguarding personal information.

Lawyers can face a number of potential vulnerabilities in the course of their practice, including the following:

  • poor security measures for paper documents, computer systems, computer applications, mobile devices, computer networks, wireless networks or email transmission;
  • misplacing paper or electronic documents;
  • traces left by electronic documents (i.e. metadata)
  • insecure courier/postal communication; and
  • third-party suppliers and partners may mishandle information (including third-parties offering cloud computing services).

PIPEDA requires personal information to be safeguarded at all times. Personal information should be safeguarded through the use of:

  • physical measures, for example, locked filing cabinets and restricted access to offices;
  • organizational measures, for example, security clearances and limiting access on a “need-to-know” basis; and
  • technological measures, for example, the use of passwords and encryption.

The more sensitive the information is, the stronger the safeguards must be.

One measure to ensure that personal information is secured is to avoid physically removing the information from the office at all, or to limit doing so to the greatest extent possible. There are many technological solutions that allow lawyers to securely access office systems remotely. Such solutions, provided they are implemented in a secure manner and employ appropriate encryption standards and firewalls, can offer the best protection for personal information.

Any laptops and other mobile devices and media must be secured, including through the use of encryption. Highest care must also be taken when working in public spaces or on devices to which more than one person may have access. As well, lawyers or law firms considering cloud computing solutions must carefully consider the privacy and security implications of any service they may create or subscribe to.

Lawyers must use contractual or other means to provide a comparable level of protection while the information is being processed by a third party. Where any third-party service provider may have access to or otherwise handle personal information on behalf of a lawyer, including cloud computing service providers, it is strongly recommended that a written agreement be put in place between the third-party and the lawyer. Such a contract should include provisions governing the jurisdiction where information will be processed or stored, ownership and use of information, the level of privacy controls used by the service provider, access and correction procedures, audits, and deletion procedures. Lawyers must remember that they remain accountable for information transferred to third-parties for processing. PIPEDA also requires organizations to be transparent about their personal information handling practices. Accordingly, organizations should notify clients when using a service provider located outside Canada and advise them that their personal information may be subject to the laws of a foreign jurisdiction.

The Office of the Privacy Commissioner has developed a self-assessment tool to assist organizations measure how well they are safeguarding personal information.

Hat tip to my colleague Doug Munroe for pointing out this particular section – good advice when you are flying on a cloud.

David J. Bilinsky is a lawyer and Practice Management Consultant. His area of expertise is enhancing a law firm¹s profitability, developing strategic business planning and applying technology to the practice of law. Dave's mission in life is to empower lawyers to anticipate the changes, realize the opportunities, face the challenges and embrace the expanding possibilities of the application of practice management concepts to the practice of law in innovative ways that provide service excellence. He is the founder and current Chair of the Pacific Legal Technology Conference. You can visit his blog at: www.thoughtfullaw.com.
[click on the author's name for more information]

up

2 Comments on “PIPEDA and Cloud Computing”

  1. Sean says:

    My concern with cloud computing has to do with the US Patriot act which gives *any* US government agency the right to request information from any database housed on US soil. Since all cloud services, to date, originate in the USA, I fail to see how PIPEDA can protect client confidentiality, or how a paper agreement with a third party provider of cloud services can protect your (or your client's) privacy. The Patriot Act was supposed to expire in 2004, and has since been renewed every year by two successive administrations.

  2. Wally Kowal says:

    There are cloud providers in Canada that address this specific issue. The Patriot Act has always been a issue for non-US companies using the public cloud, but most have chosen to ignore it. As companies start to use cloud services for their core operations, this issue is coming to the forefront. Cloud can meet stringent privacy demands, but you have to be careful. Just because something is hard doesn't mean you should not do it

Make a comment:

Note that some comments may be moderated. If you have not had an approved comment here before, your comment will be held for approval. We are glad to publish comments that address issues raised in the post or other comments on it and that contribute to a fruitful discussion. We do not publish comments that seek to promote commercial products, that make personal attacks, or that seek personal legal advice.

Although we do not require it, we ask that in making a comment you use your full name. You must supply a valid email address, which will not appear with your comment.

 

SlawTips      

SlawTips Cash Flow Reports – Part 2
Thursday, May 24

This is the second in a series of ten tips dealing with cash flow reports and cash flow management. Gregory Nunn once said: “Never underestimate the value of cold cash.”… »»

Practice

SlawTips United Nations Documents
Wednesday, May 23

Today’s Tip: Monitor UN documents with RSS Since I last looked, the United Nations Documents site has a new look and feel. For what the site is trying to deliver, … »»

Research

SlawTips Updated Version of Great Social Media Guide for Lawyers Released
Wednesday, May 23

Last spring, Meritas’ Leadership Institute released a Social Media Guide for Lawyers. This helpful resource provided lawyers with an overview of the three main social media tools — LinkedIn, Faceb. […] »»

Technology

noted on Slaw    

MLB Selected Case Summaries    

These summaries of selected recent cases are provided each week to Slaw by Maritime Law Book.
More information.

  • Aliens - Exclusion and expulsion - Power to detain and deport - Minister’s certificate - Review - Evidence

    In 2002, Harkat was detained pursuant to a ministerial security certificate issued under the Immigration and Refugee Protection Act (IRPA) as a person inadmissible to Canada on grounds ...

  • Contracts - Formation of contract - Signing - Electronic signature

    The plaintiff expressed an interest in purchasing the defendant’s (vendor’s) condo. The parties agreed to carry on their discussions through e-mail. Following an exchange of e-mails, the plaintiff claimed that the defendant was contractually bound to ...

  • Barristers and Solicitors - Relationship with client - Confidential communications - General

    The petitioner was a Receiver appointed in March 2009 by a California court over the assets of GJB Enterprises Inc. (a “Ponzi scheme”) and its principals, the Berkes (the GJB parties). The court ordered ...

  • Practice - Costs - Funding before judgment - When interim or advance costs available

    The plaintiffs were “direct to home” satellite based subscription program providers. Rex and other defendants offered “grey market” services to Canadian residents to facilitate the unauthorized reception in Canada of the plaintiffs’ ...

TalkLaw/ParLoi    

This is a listing of a few upcoming events in Canada of interest to lawyers, law students, legal librarians, and others involved in the practice of law.

Clicking on any event in the list below will give you access to more information and to links allowing you to see the full entry and to add the event to your own calendar.

Click this link for a fuller version of the TalkLaw/ParLoi calendar of events and for instructions as to how to add events and calendars to your own calendar.