North America

In early April, the Office of the Privacy Commissioner of Canada (the “OPC”) issued a notice initiating a consultation on transborder data flows (the “Notice of Consultation” and the “Consultation”) in conjunction with PIPEDA Report of Findings #2019-001 (the “Report”). The OPC has also recently issued a supplementary discussion document with additional information on the Consultation.

In its Report and in its Notice of Consultation, the OPC made a surprising reversal of its long-standing position on the transfer of personal information (“PI”) under the Personal Information Protection and Electronic Documents Act (“PIPEDA”). In the past, the OPC viewed a transfer of PI for processing as a “use” of the PI by the transferor rather than a “disclosure” to the processor, such that an additional consent was not required, as long as the PI was being processed for the purpose for which it was originally collected.

The OPC now states that it views the transfer of PI for processing as a disclosure requiring consent. The new OPC position applies to any transfer of PI from one organisation to another, including transfers within Canada, cross-border transfers, and transfers to service providers and affiliates. In its Notice of Consultation, the OPC solicits submissions on its new position.

In this Bulletin we will discuss the previous OPC position, the new OPC position, the scope of the OPC’s Consultation, and whether consent to a disclosure for processing must be express consent. We will offer some suggestions on what organisations might wish to do at this stage in the process. We will also offer some additional general comments.

What was the previous position of the OPC?

PIPEDA provides that the consent of individuals is generally required for the collection, use and disclosure of PI. However, where PI is shared with a third party for processing, PIPEDA treats the sharing as a “transfer”, not a “disclosure”:

“An organisation is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organisation shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.”

(emphasis added)

In its 2009 Guidelines on Processing Personal Data Across Borders (PDF) (the “2009 Guidelines”) the OPC stated that a transfer of PI for processing, including a cross-border transfer, is a “use” of the PI and not a “disclosure”. The OPC view was that, as long as the PI was being processed for the purpose for which it was originally collected, additional consent for the transfer to the processor was not required. The OPC recommended that notice be given to the individual.

Although no OPC findings or guidance documents are binding on organisations, the 2009 Guidelines provided certainty to businesses about the OPC’s expectations, were consistent with OPC findings, and over time have come to form a key pillar in the foundation of many organizations’ current practices in relation to transfers of PI for processing, including cross-border transfers.

What is the new position of the OPC?

In the Report, the OPC expressed its new position that the transfers of PI by a Canadian entity to a related entity in the US for processing were “disclosures” of PI under PIPEDA and not mere “use” of PI by the Canadian entity, as described in the 2009 Guidelines. The OPC openly acknowledged its change of position as follows: “…, we acknowledge that in previous guidance our Office has characterised transfers for processing as a ‘use’ of personal information rather than a disclosure of personal information. Our guidance has also previously indicated that such transfers did not, in and of themselves, require consent.”.

With respect to question of consent for such disclosures for processing, the OPC stated that where the transferred information is sensitive PI or where individuals would not reasonably expect that their PI would be disclosed to a third party, organisations are required to obtain express consent (rather than implied consent) and to provide information about the options available to individuals who do not wish to have their information disclosed in this way.

In addition, in the Report, the OPC concluded that, even though the above transfer should be considered a “disclosure” under PIPEDA, the Canadian entity remained accountable and was required to have controls in place to ensure that the transferred PI received a comparable level of protection while it was being processed. The OPC stated that, given the volume and sensitivity of the PI, those controls were required to include: (1) a formal written arrangement, updated periodically and in the case of material changes, addressing at a minimum certain factors discussed in the Report; and (2) a structured program for monitoring compliance against the obligations laid out in the arrangement, addressing at a minimum certain continuing reporting and assessment factors discussed in the Report.

What is the scope of the Consultation?

In its Notice of the Consultation, the OPC announced that it is ‘revisiting’ its 2009 Guidance on cross-border data flows under PIPEDA. In its Notice of Consultation, the OPC states that its view is now that:

  • In the absence of an applicable exception, transfers for processing, including cross border transfers, require consent as they involve the disclosure of PI from one organisation to another (contrary to the OPC’s position in the 2009 Guidance).
  • For the consent to be valid, individuals must be provided with clear information about any disclosure to a third party, including instances when the third party is located in another country, and the associated risks.
  • When determining the form of consent (express or implied), organisations will need to consider the sensitivity of the information and individuals’ reasonable expectations. The OPC believes individuals would generally expect to know whether and where their PI may be transferred or otherwise disclosed to an organisation outside Canada.
  • Organisations are free to design their operations to include flows of PI across borders, but they must respect the individuals’ right to make that choice for themselves as part of the consent process.
  • Individuals must be informed of any options available to them if they do not wish to have their PI disclosed across borders.

The OPC intends to provide guidance on disclosures for processing and related consent and accountability requirements, and seeks input from interested parties. Responses must be submitted to the OPC by June 4, 2019.

When is express consent required for a disclosure for processing?

In its Guidelines on obtaining meaningful consent (the “Consent Guidelines”), which came into effect on January 1, 2019, the OPC states that organisations must generally obtain express consent, rather than implied consent, when: (1) the information being collected, used or disclosed is sensitive; (2) the collection, use or disclosure is outside of the reasonable expectations of the individual; or (3) the collection, use or disclosure creates a meaningful residual risk of significant harm.

In the Report and in the Notice of Consultation, the OPC uses and applies these concepts. As a consequence, an express consent to a disclosure for the purpose of processing, whether or not cross-border, would be required under the OPC approach when: (1) the information being collected, used or disclosed is sensitive; (2) the collection, use or disclosure is outside of the reasonable expectations of the individual; or (3) the collection, use or disclosure creates a meaningful residual risk of significant harm.

With respect to individuals’ reasonable expectations, the OPC states the following in the Notice of Consultation:

“Under PIPEDA, the form of consent required depends on the sensitivity of the information at issue and the individual’s reasonable expectations in the circumstances. Underlying the contextual analysis of both sensitivity and reasonable expectations is the risk of harm to the individual. Where there is a meaningful risk that a residual risk of harm will materialise and will be significant, consent should be express, not implied.

It is the OPC’s view that individuals would reasonably expect to be notified if their information was to be disclosed outside of Canada and be subject to the legal regime of another country. Whether this affects their decision to enter into a business relationship with an organisation or to forego a product or service should be left to the discretion of the individual.”

(emphasis added)

The first paragraph is a restatement of the principles from the Consent Guidelines. The second paragraph strongly implies, but does not explicitly state, that the OPC’s view is that an express consent is required for all cross-border transfers of PI. Why did the OPC not explicitly state that an express consent is required for all cross-border disclosures? Perhaps the OPC is leaving some room for the possibility that there might be some circumstances where an implied consent is sufficient, if the individual has sufficient notice that the PI would be disclosed cross-border for processing. Organisations will want to review future OPC guidance for any clarification of the OPC’s views on whether express consent is required for all cross-border disclosures of PI for processing.

What should organisations do now?

The OPC’s new position on transfers of PI will have dramatic implications for many organisations. Domestic and international transfers of personal information to service providers and affiliates are commonplace in Canada and in many cases will not have been implemented in a manner that would be compliant with the OPC’s new view.

Bearing in mind that OPC findings and guidance documents do not have the force of law, organisations should conduct an assessment of their compliance with the new OPC position, consider the impact on their information practices, privacy notice and consent documents, and plan their next steps.

Organisations may also wish to submit a response to the Consultation, to monitor the OPC Consultation process, and to review future changes to the OPC guidance documents on cross-border transfers and consent.

Comments on the OPC’s new position

There has been widespread criticism of the OPC’s new position, including in respect of the following themes:

  • Recognising the close integration of the Canadian and US economies, and recognising that the US was not adopting general personal information protection legislation, Parliament chose to adopt privacy legislation that was more adapted to Canadian commercial reality than the EU Data Protection Directive — a middle path — and Parliament chose not to expressly address cross- border transfers in PIPEDA.
  • Critics argue that fundamental change in privacy regulation should be effected through legislative change by the elected members of Parliament, and not by the OPC adopting aggressive reinterpretations of PIPEDA (notwithstanding that the OPC’s interpretations are not binding in law).
  • To the extent that the OPC approach might be motivated by the EU General Data Protection Regulation (“GDPR”), it fails to take into consideration key differences in approach and concepts between PIPEDA and the GDPR, including in relation to the concepts of “controller” and “processor” and the fact that, unlike PIPEDA, the GDPR includes a number of mechanisms which are widely utilised to support cross-border transfers without consent. If the GDPR is to be considered as a model that should influence the approach to cross-border transfers under PIPEDA, the full range of relevant factors should be considered.
  • This is not the first time that the OPC has aggressively reinterpreted PIPEDA. The OPC’s reinterpretation of PIPEDA to allow for increased regulation of cross-border transfers is reminiscent of the OPC’s recent reinterpretation of PIPEDA to purport to recognise an otherwise non-existent GDPR-like right to be forgotten in PIPEDA.
  • In the absence of legislative change, the OPC appears to have wanted to find some other way to regulate cross-border transfers. To accomplish this end, the OPC unfortunately chose to reinterpret PIPEDA to impose new requirements on all transfers for processing by a third party, including transfers within Canada and transfers to affiliates.
  • If the Consultation confirms the OPC’s new position without material change, then organisations may face many practical difficulties and increased costs of compliance. Meaningful consent will be difficult to obtain. Detailed disclosure of information about processing arrangements will be expensive to provide and to maintain. Disclosure of information about subprocessors may be required. Will an individual be permitted to opt-out of an existing contract if a processor or subprocessor changes?
  • There will also be significant transitional issues. New consents will be difficult to obtain from existing customers. Will existing consents be grandfathered? Existing contracts with processors may not comply with the new OPC expectations, and processors may not agree to amend them.

We will continue to monitor developments related to the OPC’s Consultation and next steps.

Authors

Antoine Guilmain, LLD
Associate
Montreal, QC
Julie Uzan-Naulin
Associate
Montreal, QC
Bruce Tattrie
Partner
Vancouver, BC

© 2017 Fasken Martineau DuMoulin LLP The content of this website may contain attorney advertising under the laws of various states.

Related Articles by Firm
New transparency registry for all private BC companies in the offing
If the bill comes into force it will have far reaching compliance consequences for all private BC companies.
Changes are coming!
Five factors to consider when reviewing your Canadian trademark strategy in 2019.
The Canadian gig economy: Embracing the future of work
Instead of quashing models that have the potential to empower the workforce, better protections for gig workers are needed.
A closer look at Canada’s budget
Fasken’s team examines important budget 2019 measures — some which made headlines, and others that should not escape notice.
Selected tax measures in Canada's 2019 federal budget
The budget contains significant proposals to amend income and excise taxes, while also providing updates on previously announced tax measures and policies.
OSFI issues advisory on technology and cyber security incident reporting
The Advisory reflects the fact that OSFI is very focused on this increasingly significant area of risk.
Health Canada pushes for safer medical devices
The announcements foreshadow significant near-term changes to Canada's medical device regulatory regime.
USMCA impact on communications industries
How the US-Mexico-Canada Agreement affects telecommunications, broadcasting and digital trade.
Surprise changes seek to modernise Canadian trademarks law and practice
This bulletin looks at key proposed changes to trademark law in Canada.
Time limits for retaining information about employees
Retention of personal information carries various obligations, particularly in terms of access to the information and confidentiality.
Further hurdles for regulatory approval of notifiable mergers in South Africa
On July 12, the Competition Amendment Bill was introduced in Parliament, substantially revising the earlier version of the Bill.
Hitting the sweet spot: Regulation of sweetened alcoholic beverages
Health Canada issued a notice of intent to restrict the amount of alcohol in highly sweetened alcoholic beverages.
Significant changes proposed to Canada’s AML/ATF regime
The Proposed Regulations are wide ranging and include a number of substantive changes as well as technical amendments.
Canada: Privacy commissioner issues key guidelines for consent and inappropriate data practices
Important guidance documents issued in respect of activities regulated pursuant to the Personal Information Protection and Electronic Documents Act ...
Cybersecurity risks for directors and officers
The cybersecurity field is ripe for affected stakeholders to test claims that directors and officers have failed to discharge their duties.
Cybersecurity Risks for Directors and Officers
Directors and officers in Canada face increased risk of personal liability and threats to job security in relation to cybersecurity...
Proposed changes to Canada's anti-money laundering and anti-terrorist financing regime
A consultation paper released in February could potentially have broad implications for Canada's AML/ATF regime.
Bill 148 Update: Scheduling and the three-hour rule
The Fair Workplaces, Better Jobs Act, 2017 makes significant changes to the Employment Standards Act, 2000.
Does your non-competition clause really protect you?
Or does it merely offer the illusion of protection? What you need to know about the validity and enforceability of a non-competition clause.
Canada: Selected Tax Measures in the Federal Budget 2018
Canada's 2018 Federal Budget contains significant proposals to amend the Income Tax Act and the Excise Tax Act while also providing updates on previously announced tax measures and policies ...
Expect the Intersection of Privacy and AI in 2018
We must consider how to regulate, or at least control, the use of artificial intelligence at different levels ...
Energy Licences and Approvals in Canada
Update on Directive 067: Eligibility Requirements for Acquiring and Holding Energy Licences and Approvals ...
Canada to Revise Tax Voluntary Disclosures Program
Effective March 1, 2018: New Regime will Result in Limited Relief for Certain Taxpayers Disclosing Errors and Omissions ...
Canada: New CASL Ruling
CRTC Provides Guidance on B2B Messaging and the Due Diligence Defence ...
Corporate Parent Liability: Litigation Risks for Resource Companies
Traditionally, parent companies have been considered legally distinct entities and thus immune from the actions of their subsidiaries, a concept described as the “corporate veil”. This position is now being challenged ...
Canada: No Duty to Consult Triggered by Omnibus Changes to Environmental Laws
In Canada (Governor General In Council) v. Courtoreille, 2016 FCA 311, the Federal Court of Appeal found that the federal government did not owe a duty to consult when it developed and implemented changes to environmental legislation through two omnibus bills ...
The Global Reach of Canadian Privacy Law
Federal Court Issues Landmark Ruling in Globe24h ...
Temporary Foreign Workers in Canada: Employer Compliance Rules
The regulations that govern applications for work permits provide a very strict framework for employers who hire temporary foreign workers in Canada ...
Canada is Open for Business
Trump and the Changing Political Landscape in the US ...
Primer on Procurement Rules in the New Canadian FTA
Fasken Martineau Releases Primer on Procurement Rules in the New Canadian Free Trade Agreement ...
Canada: Donald Trump, Paris and the Climate Policy Two­-Step
Will the U.S. withdrawal from the Paris Agreement fundamentally alter Canada's course?
China’s Priorities for a Free Trade Agreement with Canada
Analysis of Chinese language commentary, news media and academic studies, reveal some of China's top priorities for a free trade agreement with Canada ...
Canada: New Authorities under Vanessa's Law
On June 18, 2016, the Federal Department of Health published a Notice of Intent to amend the Food and Drug Regulations and the Medical Devices Regulations to implement key authorities under Vanessa's Law...
Canada: Consultation on New Health Regs for Self-Care Products
Health Canada is seeking consultation on new standards for self-care products, over-the-counter drugs, natural health products and cosmetics ...
Private right of action under Canada’s Anti-Spam Law
As of July 1, 2017, individuals and organizations will be entitled to institute a "private right of action" before the courts against those that contravene certain provisions of Canada's Anti-Spam Law ...
New Federal Consumer Protection Regime for Bank Customers
Canada: The government has introduced a bill which proposes to create a comprehensive federal consumer code and strengthen federal jurisdiction over provincial jurisdiction with respect to products and services of banks.
Canada: Alberta's Renewable Electricity Program
Alberta released details of the Renewable Electricity Program to accelerate the development of renewable power generation through a competitive bid process.
Certainly Uncertain: Construction Trusts after Iona in Canada
A recent decision clarifies the law regarding provincial statutory trusts in the insolvency context, particularly in the construction sector.
The Fight against Climate Change and the Overhaul of Canada's Environment Quality Act
A bill allows government to require a "climate test" from a project proponent.
Health Canada Is Cracking The Whip On Advertising Violations
On January 21, 2016, various hospitals, natural health product manufacturers, physicians and pharmaceutical companies found themselves specifically named by Health Canada in a published list of health product advertising complaints ...
Canada: New Strategic Plan for the Patented Medicines Prices Review Board
The Strategic Plan comprises a fresh vision, a revised mission statement and four new strategic objectives ...
Transport Canada Promises New Drone Regulations
Increase in popularity has had a direct effect on risks involved for the safe use of regular aircraft ...
N. America: Northern Gateway Pipeline
Province must consult and decide but may impose conditions
Canada: Tinkering with Title - Don’t Get Caught by Surprise
The Mining Amendment Act 2015 proposes a new electronic mining lands administration system in Ontario.
New Lobbyists’ Code Will Restrict Dealings with Canada’s Federal Government and Agencies
Canada's new Lobbyists' Code of Conduct will significantly restrict the activities of lobbyists and others seeking to influence federal decision making.
Righting a Wrong: Canadian Regulators Improve the Rights Offering Regime
Canadian regulatory authorities recently overhauled how prospectus exempt rights offerings are to be conducted going forward.
A change of role for a legal representative under the new Clinical Trials Regulation 536/2014?
The roles and responsibilities of the legal representative set out under Clinical Trials Directive 2001/20/EC are likely to change under the new Clinical Trials Regulation 536/2014.
Historic Court of Appeal Decision in Dunkin' Brands: Three Lessons for Franchisors in Canada
The Quebec Court of Appeal has specified the intensity of the franchisor's implied obligations in what is the most significant franchise case in Québec since 1998.
New Compliance Form and Fee for Employers of Foreign Work Permit Applicants in Canada
Employers whose foreign employees must apply for a work permit or extension should be aware of a new Compliance Form and Compliance Fee that they must submit before the person applies for the work permit in Canada.
Use of Trademarks As Metadata & #Hashtags in Canada
A recent decision of the Federal Court of Canada provides guidance on the proper use of IP in this digital world that brand owners need to know now.
Claims that Involve a Fixed Dosage and Schedule Can Constitute Patentable Subject Matter
The Canadian Intellectual Property Office has issued a revised guidance which provides clear instructions on how to approach medical use claims and determine whether such claims are eligible for patent protection.
The Application of the Bhasin Principle of Good Faith in Canada: An Early Example
A recent decision from the Supreme Court of British Columbia provides an early example of how courts will apply the general principle of good faith in Canada.
The TPP Agreement: A Canadian Business Perspective
The TPP will impact goods access and other aspects of Canadian businesses.
Foreign Corruption and the Integrity Framework in Canada: A Difficult Corporate Board Dilemna
Canada's Integrity Framework raises difficult choices for corporate board directors and management regarding voluntary disclosure of prior foreign corrupt activity of an acquired company.
Canada-EU Comprehensive Economic and Trade Agreement Negotiation Completed: Additional Protection for Innovative Pharmaceutical Products
If ratified, key intellectual property provisions in the Canada-EU trade pact will provide additional protection for innovative pharmaceutical products.
An Update on the Proposed EU Revisions to the Regulation of Medical Devices
The proposed European regulatory regime will merge the directives on Medical Devices and Active Implantable Medical Devices into a single regulation and wholly replace the current regulation on In Vitro Diagnostic Medical Devices.
UK FCA consults on requirements for reports on payments to government
While Canada does not currently have a reporting regime for payments to governments, a process is underway to ensure that a regime is implemented in the near future.
Trademark Use: an Important Shift in Canada
Bill C-31, which was given royal assent on June 19, 2014, will eliminate the requirement that a trademark be used in order to be registered in Canada.
Intellectual Property Protection - Industrial Designs
Many companies will consider the availability of and merits of seeking patent and/or trade-mark registration. However, one form of IP protection that is often overlooked is an industrial design registration.
Protocol to Amend the Canada-UK Tax Treaty
The Canada-United Kingdom Tax Convention was amended with the signing of a protocol on July 21, 2014. This article will describe some highlights of the Protocol and comment on the impact of these provisions on cross-border tax issues between Canada and the ...
The end of the Canadian "iPod Tax" saga
The "Certain Televisions Remission Order" confirms that, in fact, there is not now, and never actually was, "tax" on "iPod" imports to Canada.
Updating Canadian Trademark Filing & Registration Strategies
Here are some key trademark filing strategies for avoiding or minimizing the potential impact of recent amendments to the Canadian trademark landscape.
The Canadian insurance M&A environment
There have been a significant number of insurance company M&A transactions in the Canadian market in recent years, a trend expected to continue. Fasken Martineau DuMoulin have surveyed the acquisition agreements from these transactions and analysed ...
Merger control and foreign investment review in Canada
Fasken Martineau DuMoulin’s Huy Do and Jack Yu1 write that acquisitions of, or investments in, Canadian businesses can give rise to merger control and foreign investment reviews. ...
Related Articles
Related Articles by Jurisdiction
The Application of the Bhasin Principle of Good Faith in Canada: An Early Example
A recent decision from the Supreme Court of British Columbia provides an early example of how courts will apply the general principle of good faith in Canada.
Corporate Parent Liability: Litigation Risks for Resource Companies
Traditionally, parent companies have been considered legally distinct entities and thus immune from the actions of their subsidiaries, a concept described as the “corporate veil”. This position is now being challenged ...
Proposed changes to Canada's anti-money laundering and anti-terrorist financing regime
A consultation paper released in February could potentially have broad implications for Canada's AML/ATF regime.
Latest Articles