SlideShare a Scribd company logo
Privacy, Privilege, Confidentiality and Ethics Canadian Bar Association Annual Meeting, Halifax, August, 2011 Mark Hayes, Hayes eLaw LLP, Toronto
Privacy, Privilege and Confidentiality 3 distinct and overlapping concepts Often confused with each other Important for lawyers to understand different types of obligations
General Concepts Privilege Legal right that applies in specific circumstances (e.g. solicitor/client & litigation privilege) Confidentiality Legal duty to hold in strict confidence and not disclose any kind of information that are subject to such duty, not just personal information Privacy Body of statute law governing collection, use and disclosure of personal information
Control Confidentiality Controlled by client; can be waived (intentionally or otherwise) Privilege Controlled by client; can be waived (intentionally or otherwise) Privacy Controlled by individual in question; consent or exception to consent requirement General reasonableness requirement
Confidentiality Source: primarily common law and professional regulations (e.g. Rules of Professional Conduct) Broad in scope – Ont. RPC s. 2.03 – “all information concerning the business and affairs of the client acquired in the course of the professional relationship” Waiver of duty of confidentiality & solicitor/client privilege: Harish  v. Stamp, R. v. Hobbs, Osiris Inc. V. 1444707 Ontario Ltd. Waiver of confidentiality does not necessarily waive privilege (if one applies)
Privilege Source: primarily common law Salosky(SCC): "fundamental civil and legal right” Emerges from the duty of confidentiality inherent in solicitor/client relationship Sometimes permanent (e.g. solicitor/client privilege) or limited by existence of specific circumstances (e.g. litigation privilege only pending litigation) Statutory limitations must be clearly and expressly provided by (Blood Tribe Dept of Health v. Canada) Waiver of privilege may not affect confidentiality
Privacy Primarily statutory Must obtain informed consent for collection, use or disclosure of personal information by an organization in the course of its commercial activities In addition to consent requirement, collection, use or disclosure of PI must be reasonable Only collect as much information as is required Publicly available personal information is not exempt from consent requirement
Privacy Application: any organization engaged in commercial activity Includes lawyers, unless acting as agent for individual in personal capacity (Ferenczy) This conclusion not accepted by Privacy Commissioner  Various administrative requirements Provide access to or correct PI in possession on request Keep PI secure Retain PI only for long as is required
Consent Exemptions For lawyers, exemptions from consent requirement are critical Some important ones: Required by law Investigations of breach of statute or contract Private purposes (if acting for individual) Provincial privacy laws in BC and Alberta have additional exemptions
Cases on Lawyers and Privacy Can’t disclose PI pursuant to summons issued by an individual without jurisdiction to compel production (i.e. other lawyer) - PIPEDA Case Summary #2009-005 Consent not required to disclose personal information in response to writ of seizure issued by court - PIPEDA Case summary #2003-174 Law firms cannot collect credit reports without consent: PIPEDA Case Summary #2006-340 Solicitor’s lien insufficient grounds to deny access to personal information - Settled case summary #30 (2007) Not reasonable to use individual’s SIN for general identification purposes – limited to payroll and income tax purposes - PIPEDA Case summary #2002-69
Overlaps Personal information subject to privilege Client information subject to privilege Personal information that is confidential
Obligations Different But Consistent For the most part, all of privacy, privilege and confidentiality consistent in requiring: Access to information be limited Appropriate security steps be taken Major difference Privilege and confidentiality controlled by client (who can waive rights) Privacy controlled by legislation and consent of individual concerned - client cannot validly instruct lawyer to breach privacy
Privacy and Privilege Privacy statutes: individual must be given access to PI Many examples of litigants requesting access from lawyers What if PI is privileged? PIPEDA s. 9(3) excludes access obligation if “information is protected by solicitor-client privilege” But what about other privileges? PIPEDA Case Summary #2008-397: also applies to litigation privilege; liberal interpretation PIPEDA Case Summary #2010-001: court procedures more appropriate to deal with allegation that documents improperly withheld as privileged
Privacy and Confidentiality Confidentiality obligation subject to certain exemptions E.g. Ont. RPC s. 2.03: may disclose confidential information “where a lawyer believes upon reasonable grounds that there is an imminent risk to an identifiable person or group of death or serious bodily harm, including serious psychological harm that substantially interferes with health or well-being…” Privacy laws don’t contain exact same exemption PIPEDA s. 7(3)(e): “made to a person who needs the information because of an emergency that threatens the life, health or security of an individual” Must inform individual in writing without delay
Builders Energy Services Ltd. Alberta IPC Investigation Report P2005-IR-005 Lawyer acting for acquirer of company posted employee personal information on SEDAR, where it was publicly available While case concentrated on whether disclosure of PI was reasonably necessary, clear that lawyer had not considered whether this PI was subject to privacy regime Similar considerations often arise in litigation
Technology and Privacy Risks Service providers Storage devices (servers, hard drives, sticks) Laptops Blackberries and smartphones “Cloud computing”
Managing Technology Risks Mitigate highest and most immediate risks Inventory personal data maintained by the firm Employee training and management Conduct risk assessment: Information systems design and information processing, storage, transmission and disposal Responding to and preventing attacks, intrusions and systems failures Fix vulnerabilities identified through risk assessment Continually evaluate and adjust information security program
Data Retention Policies Privacy laws require lawyer to retain PI for only as long as required for disclosed purposes Ethical obligations require retention of client files until client releases you and all regulatory and liability issues have passed Finding correct balance between hanging on too long and destroying too quickly is tricky, especially since appropriate retention periods may be different depending on nature of data
Summary Privacy issues have significant impacts in many practice areas: Family Civil and criminal litigation Real estate Estates Employment law Even in practices where PI of third parties is not critical, have to worry about employee privacy
Summary Think about PI issues whenever you handle PI about individuals who are not your clients Know your obligations Know the relevant exceptions you can use to your advantage and in your clients’ interest Privacy obligations are constantly changing Keep informed; PCC and provincial sites, blogs Talk to the experts
Thank You! For a copy of these slides, email me at mark@hayeselaw.com

More Related Content

What's hot

Healthcare confidentiality training.2013bev
Healthcare confidentiality training.2013bevHealthcare confidentiality training.2013bev
Healthcare confidentiality training.2013bevblk70130
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentiality
jaredbrady
 
Confidentiality New Employee Training (First-Week)
Confidentiality New Employee Training (First-Week)Confidentiality New Employee Training (First-Week)
Confidentiality New Employee Training (First-Week)
ChildrensHomeIllinois
 
Legal Reasoning & Problem Solving
Legal Reasoning & Problem SolvingLegal Reasoning & Problem Solving
Legal Reasoning & Problem SolvingAlex Olteanu
 
Functions of a Notary and the Notaries Ordinance
Functions of a Notary and the Notaries OrdinanceFunctions of a Notary and the Notaries Ordinance
Functions of a Notary and the Notaries Ordinance
Ajithaa Edirimane
 
Professional ethics for legal person
Professional ethics for legal personProfessional ethics for legal person
Professional ethics for legal personRavi Lakhani
 
Protecting patients confidentiality slide presentation
Protecting patients confidentiality slide presentationProtecting patients confidentiality slide presentation
Protecting patients confidentiality slide presentation
plunkk
 
Steps in Criminal Prosecution in india
Steps in Criminal Prosecution in indiaSteps in Criminal Prosecution in india
Steps in Criminal Prosecution in india
Adv Rajasekharan
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
WilmerHale
 
Courts of equity, powers and functions
Courts of equity, powers and functionsCourts of equity, powers and functions
Courts of equity, powers and functions
A K DAS's | Law
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection ActSaimaRafiq
 
Right to privacy on internet and Data Protection
Right to privacy on internet and Data ProtectionRight to privacy on internet and Data Protection
Right to privacy on internet and Data Protection
atuljaybhaye
 
Short version ethical decision making process
Short version ethical decision making processShort version ethical decision making process
Short version ethical decision making processPablo Galiana
 
Lecture 4 confidentiality, disclosure and the law.1
Lecture 4  confidentiality, disclosure and the law.1Lecture 4  confidentiality, disclosure and the law.1
Lecture 4 confidentiality, disclosure and the law.1
Newham College University Centre Stratford Newham
 
HIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to knowHIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to know
Compliancy Group
 
Ethical principles of psychologists and the code of
Ethical principles of psychologists and the code ofEthical principles of psychologists and the code of
Ethical principles of psychologists and the code ofUniversity of Miami
 
Confidentiality
Confidentiality Confidentiality
Confidentiality
pcsamuels10
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
kajal pradhan
 

What's hot (20)

Healthcare confidentiality training.2013bev
Healthcare confidentiality training.2013bevHealthcare confidentiality training.2013bev
Healthcare confidentiality training.2013bev
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentiality
 
Drafting of deeds
Drafting of deedsDrafting of deeds
Drafting of deeds
 
Confidentiality New Employee Training (First-Week)
Confidentiality New Employee Training (First-Week)Confidentiality New Employee Training (First-Week)
Confidentiality New Employee Training (First-Week)
 
Legal Reasoning & Problem Solving
Legal Reasoning & Problem SolvingLegal Reasoning & Problem Solving
Legal Reasoning & Problem Solving
 
Functions of a Notary and the Notaries Ordinance
Functions of a Notary and the Notaries OrdinanceFunctions of a Notary and the Notaries Ordinance
Functions of a Notary and the Notaries Ordinance
 
Professional ethics for legal person
Professional ethics for legal personProfessional ethics for legal person
Professional ethics for legal person
 
Protecting patients confidentiality slide presentation
Protecting patients confidentiality slide presentationProtecting patients confidentiality slide presentation
Protecting patients confidentiality slide presentation
 
Steps in Criminal Prosecution in india
Steps in Criminal Prosecution in indiaSteps in Criminal Prosecution in india
Steps in Criminal Prosecution in india
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
Courts of equity, powers and functions
Courts of equity, powers and functionsCourts of equity, powers and functions
Courts of equity, powers and functions
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
 
Right to privacy on internet and Data Protection
Right to privacy on internet and Data ProtectionRight to privacy on internet and Data Protection
Right to privacy on internet and Data Protection
 
Short version ethical decision making process
Short version ethical decision making processShort version ethical decision making process
Short version ethical decision making process
 
Hearsay
HearsayHearsay
Hearsay
 
Lecture 4 confidentiality, disclosure and the law.1
Lecture 4  confidentiality, disclosure and the law.1Lecture 4  confidentiality, disclosure and the law.1
Lecture 4 confidentiality, disclosure and the law.1
 
HIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to knowHIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to know
 
Ethical principles of psychologists and the code of
Ethical principles of psychologists and the code ofEthical principles of psychologists and the code of
Ethical principles of psychologists and the code of
 
Confidentiality
Confidentiality Confidentiality
Confidentiality
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 

Viewers also liked

Staff_confidentiality_training_TeresaStewart
Staff_confidentiality_training_TeresaStewartStaff_confidentiality_training_TeresaStewart
Staff_confidentiality_training_TeresaStewart
teresastewart99
 
Employee confidentiality training
Employee confidentiality trainingEmployee confidentiality training
Employee confidentiality trainingJessi Morris
 
Confidentially in the workplace
Confidentially in the workplaceConfidentially in the workplace
Confidentially in the workplace
Knighten
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
DeniseMHA
 
Privacy and patient confidentiality
Privacy and patient confidentialityPrivacy and patient confidentiality
Privacy and patient confidentiality
jmw1019
 
Protecting patient privacy and confidentiality
Protecting patient privacy and confidentialityProtecting patient privacy and confidentiality
Protecting patient privacy and confidentialityTiffany Cochran
 
Workplace strategies for protecting confidential and proprietary property
Workplace strategies for protecting confidential and proprietary propertyWorkplace strategies for protecting confidential and proprietary property
Workplace strategies for protecting confidential and proprietary property
Now Dentons
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentiality
johnzinn
 
Email Etiquette at work
Email Etiquette at workEmail Etiquette at work
Email Etiquette at work
Metamorph Training Pvt Ltd
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
LLSS64
 
The importance of confidentiality
The importance of confidentialityThe importance of confidentiality
The importance of confidentialityswilson0050
 

Viewers also liked (13)

Staff_confidentiality_training_TeresaStewart
Staff_confidentiality_training_TeresaStewartStaff_confidentiality_training_TeresaStewart
Staff_confidentiality_training_TeresaStewart
 
Employee confidentiality training
Employee confidentiality trainingEmployee confidentiality training
Employee confidentiality training
 
Confidentially in the workplace
Confidentially in the workplaceConfidentially in the workplace
Confidentially in the workplace
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Privacy and patient confidentiality
Privacy and patient confidentialityPrivacy and patient confidentiality
Privacy and patient confidentiality
 
Protecting patient privacy and confidentiality
Protecting patient privacy and confidentialityProtecting patient privacy and confidentiality
Protecting patient privacy and confidentiality
 
Confidentiality: A Responsibility of Legal Staff
Confidentiality: A Responsibility of Legal StaffConfidentiality: A Responsibility of Legal Staff
Confidentiality: A Responsibility of Legal Staff
 
Workplace strategies for protecting confidential and proprietary property
Workplace strategies for protecting confidential and proprietary propertyWorkplace strategies for protecting confidential and proprietary property
Workplace strategies for protecting confidential and proprietary property
 
Privacy and confidentiality
Privacy and confidentialityPrivacy and confidentiality
Privacy and confidentiality
 
Confidentiality Training by Electra ISD
Confidentiality Training by Electra ISDConfidentiality Training by Electra ISD
Confidentiality Training by Electra ISD
 
Email Etiquette at work
Email Etiquette at workEmail Etiquette at work
Email Etiquette at work
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
The importance of confidentiality
The importance of confidentialityThe importance of confidentiality
The importance of confidentiality
 

Similar to Privacy, Privilege And Confidentiality For Lawyers

Confidentiality in the Workplace.pptx
Confidentiality in the Workplace.pptxConfidentiality in the Workplace.pptx
Confidentiality in the Workplace.pptx
Felger Tilos
 
Privacy and Litigation
Privacy and LitigationPrivacy and Litigation
Privacy and Litigation
Dan Michaluk
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
Robert MacLean
 
Internal Investigations and Employee Privacy
Internal Investigations and Employee PrivacyInternal Investigations and Employee Privacy
Internal Investigations and Employee Privacy
Dan Michaluk
 
Data protection act new 13 12-11
Data protection act new 13 12-11Data protection act new 13 12-11
Data protection act new 13 12-11mrmwood
 
Best Practices In Corporate Privacy & Information Security
Best Practices In Corporate Privacy & Information SecurityBest Practices In Corporate Privacy & Information Security
Best Practices In Corporate Privacy & Information Securitysatyakam_biswas
 
Privacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the RiskPrivacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the Risk
duffeeandeitzen
 
Privacy Compliance for Law Firms: Moving Beyond Confidentiality
Privacy Compliance for Law Firms: Moving Beyond ConfidentialityPrivacy Compliance for Law Firms: Moving Beyond Confidentiality
Privacy Compliance for Law Firms: Moving Beyond Confidentiality
Clio - Cloud-Based Legal Technology
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Diana Maier
 
Lasa European NFP Technology Conference 2010 - Data protection and the cloud
Lasa European NFP Technology Conference 2010 - Data protection and the cloudLasa European NFP Technology Conference 2010 - Data protection and the cloud
Lasa European NFP Technology Conference 2010 - Data protection and the cloud
ukriders
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
zayadeen2003
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
Harrison Clark Rickerbys
 
data-privacy-egypt-what-you-need-know-en.pdf
data-privacy-egypt-what-you-need-know-en.pdfdata-privacy-egypt-what-you-need-know-en.pdf
data-privacy-egypt-what-you-need-know-en.pdf
kiruthigajawahar6
 
data privacy handbook: A starter guide to data privacy compliance
data privacy handbook: A starter guide to data privacy compliancedata privacy handbook: A starter guide to data privacy compliance
data privacy handbook: A starter guide to data privacy compliance
DesmondMontgomery2
 
What You Need To Know About Privacy Now!
What You Need To Know About Privacy   Now!What You Need To Know About Privacy   Now!
What You Need To Know About Privacy Now!catherinecoulter
 
What You Need To Know About Privacy Now!
What You Need To Know About Privacy   Now!What You Need To Know About Privacy   Now!
What You Need To Know About Privacy Now!catherinecoulter
 
Texas Privacy Laws - Tough New Changes
Texas Privacy Laws - Tough New ChangesTexas Privacy Laws - Tough New Changes
Texas Privacy Laws - Tough New Changes
Jim Brashear
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
mrmwood
 

Similar to Privacy, Privilege And Confidentiality For Lawyers (20)

Confidentiality in the Workplace.pptx
Confidentiality in the Workplace.pptxConfidentiality in the Workplace.pptx
Confidentiality in the Workplace.pptx
 
Privacy and Litigation
Privacy and LitigationPrivacy and Litigation
Privacy and Litigation
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
 
Internal Investigations and Employee Privacy
Internal Investigations and Employee PrivacyInternal Investigations and Employee Privacy
Internal Investigations and Employee Privacy
 
Data protection act new 13 12-11
Data protection act new 13 12-11Data protection act new 13 12-11
Data protection act new 13 12-11
 
Best Practices In Corporate Privacy & Information Security
Best Practices In Corporate Privacy & Information SecurityBest Practices In Corporate Privacy & Information Security
Best Practices In Corporate Privacy & Information Security
 
Privacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the RiskPrivacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the Risk
 
Privacy Compliance for Law Firms: Moving Beyond Confidentiality
Privacy Compliance for Law Firms: Moving Beyond ConfidentialityPrivacy Compliance for Law Firms: Moving Beyond Confidentiality
Privacy Compliance for Law Firms: Moving Beyond Confidentiality
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
 
Lasa European NFP Technology Conference 2010 - Data protection and the cloud
Lasa European NFP Technology Conference 2010 - Data protection and the cloudLasa European NFP Technology Conference 2010 - Data protection and the cloud
Lasa European NFP Technology Conference 2010 - Data protection and the cloud
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Ss
SsSs
Ss
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
data-privacy-egypt-what-you-need-know-en.pdf
data-privacy-egypt-what-you-need-know-en.pdfdata-privacy-egypt-what-you-need-know-en.pdf
data-privacy-egypt-what-you-need-know-en.pdf
 
data privacy handbook: A starter guide to data privacy compliance
data privacy handbook: A starter guide to data privacy compliancedata privacy handbook: A starter guide to data privacy compliance
data privacy handbook: A starter guide to data privacy compliance
 
What You Need To Know About Privacy Now!
What You Need To Know About Privacy   Now!What You Need To Know About Privacy   Now!
What You Need To Know About Privacy Now!
 
What You Need To Know About Privacy Now!
What You Need To Know About Privacy   Now!What You Need To Know About Privacy   Now!
What You Need To Know About Privacy Now!
 
Texas Privacy Laws - Tough New Changes
Texas Privacy Laws - Tough New ChangesTexas Privacy Laws - Tough New Changes
Texas Privacy Laws - Tough New Changes
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 

More from canadianlawyer

Hayes Privacy And Social Media PowerPoint, October 29, 2010
Hayes   Privacy And Social Media PowerPoint, October 29, 2010Hayes   Privacy And Social Media PowerPoint, October 29, 2010
Hayes Privacy And Social Media PowerPoint, October 29, 2010
canadianlawyer
 
Hayes Privacy And Social Media Paper, October 29, 2010
Hayes   Privacy And Social Media Paper, October 29, 2010Hayes   Privacy And Social Media Paper, October 29, 2010
Hayes Privacy And Social Media Paper, October 29, 2010
canadianlawyer
 
Social Media And Privacy October 9 2009
Social Media And Privacy October 9 2009Social Media And Privacy October 9 2009
Social Media And Privacy October 9 2009canadianlawyer
 
Privacy Breaches - The Private Sector Perspective
Privacy Breaches  - The Private Sector PerspectivePrivacy Breaches  - The Private Sector Perspective
Privacy Breaches - The Private Sector Perspective
canadianlawyer
 
"Some 2009 Copyright Issues" June 4 2009
"Some 2009 Copyright Issues" June 4 2009"Some 2009 Copyright Issues" June 4 2009
"Some 2009 Copyright Issues" June 4 2009
canadianlawyer
 
Privacy Breaches In Canada It.Can May 1 2009
Privacy Breaches In Canada   It.Can May 1 2009Privacy Breaches In Canada   It.Can May 1 2009
Privacy Breaches In Canada It.Can May 1 2009canadianlawyer
 
Privacy Breaches In Canada Lsuc It.Can May 1 2009 (Plain Background)
Privacy Breaches In Canada Lsuc It.Can May 1 2009 (Plain Background)Privacy Breaches In Canada Lsuc It.Can May 1 2009 (Plain Background)
Privacy Breaches In Canada Lsuc It.Can May 1 2009 (Plain Background)
canadianlawyer
 
Internet Copyright Law
Internet Copyright  LawInternet Copyright  Law
Internet Copyright Law
canadianlawyer
 
User Generated Content And Copyright
User Generated Content And CopyrightUser Generated Content And Copyright
User Generated Content And Copyright
canadianlawyer
 
Privacy Breaches - The Private Sector Perspective
Privacy Breaches - The Private Sector PerspectivePrivacy Breaches - The Private Sector Perspective
Privacy Breaches - The Private Sector Perspective
canadianlawyer
 
Leveraging Jurisdictional Differences in Copyright Litigation
Leveraging Jurisdictional Differences in Copyright LitigationLeveraging Jurisdictional Differences in Copyright Litigation
Leveraging Jurisdictional Differences in Copyright Litigation
canadianlawyer
 

More from canadianlawyer (11)

Hayes Privacy And Social Media PowerPoint, October 29, 2010
Hayes   Privacy And Social Media PowerPoint, October 29, 2010Hayes   Privacy And Social Media PowerPoint, October 29, 2010
Hayes Privacy And Social Media PowerPoint, October 29, 2010
 
Hayes Privacy And Social Media Paper, October 29, 2010
Hayes   Privacy And Social Media Paper, October 29, 2010Hayes   Privacy And Social Media Paper, October 29, 2010
Hayes Privacy And Social Media Paper, October 29, 2010
 
Social Media And Privacy October 9 2009
Social Media And Privacy October 9 2009Social Media And Privacy October 9 2009
Social Media And Privacy October 9 2009
 
Privacy Breaches - The Private Sector Perspective
Privacy Breaches  - The Private Sector PerspectivePrivacy Breaches  - The Private Sector Perspective
Privacy Breaches - The Private Sector Perspective
 
"Some 2009 Copyright Issues" June 4 2009
"Some 2009 Copyright Issues" June 4 2009"Some 2009 Copyright Issues" June 4 2009
"Some 2009 Copyright Issues" June 4 2009
 
Privacy Breaches In Canada It.Can May 1 2009
Privacy Breaches In Canada   It.Can May 1 2009Privacy Breaches In Canada   It.Can May 1 2009
Privacy Breaches In Canada It.Can May 1 2009
 
Privacy Breaches In Canada Lsuc It.Can May 1 2009 (Plain Background)
Privacy Breaches In Canada Lsuc It.Can May 1 2009 (Plain Background)Privacy Breaches In Canada Lsuc It.Can May 1 2009 (Plain Background)
Privacy Breaches In Canada Lsuc It.Can May 1 2009 (Plain Background)
 
Internet Copyright Law
Internet Copyright  LawInternet Copyright  Law
Internet Copyright Law
 
User Generated Content And Copyright
User Generated Content And CopyrightUser Generated Content And Copyright
User Generated Content And Copyright
 
Privacy Breaches - The Private Sector Perspective
Privacy Breaches - The Private Sector PerspectivePrivacy Breaches - The Private Sector Perspective
Privacy Breaches - The Private Sector Perspective
 
Leveraging Jurisdictional Differences in Copyright Litigation
Leveraging Jurisdictional Differences in Copyright LitigationLeveraging Jurisdictional Differences in Copyright Litigation
Leveraging Jurisdictional Differences in Copyright Litigation
 

Privacy, Privilege And Confidentiality For Lawyers

  • 1. Privacy, Privilege, Confidentiality and Ethics Canadian Bar Association Annual Meeting, Halifax, August, 2011 Mark Hayes, Hayes eLaw LLP, Toronto
  • 2. Privacy, Privilege and Confidentiality 3 distinct and overlapping concepts Often confused with each other Important for lawyers to understand different types of obligations
  • 3. General Concepts Privilege Legal right that applies in specific circumstances (e.g. solicitor/client & litigation privilege) Confidentiality Legal duty to hold in strict confidence and not disclose any kind of information that are subject to such duty, not just personal information Privacy Body of statute law governing collection, use and disclosure of personal information
  • 4. Control Confidentiality Controlled by client; can be waived (intentionally or otherwise) Privilege Controlled by client; can be waived (intentionally or otherwise) Privacy Controlled by individual in question; consent or exception to consent requirement General reasonableness requirement
  • 5. Confidentiality Source: primarily common law and professional regulations (e.g. Rules of Professional Conduct) Broad in scope – Ont. RPC s. 2.03 – “all information concerning the business and affairs of the client acquired in the course of the professional relationship” Waiver of duty of confidentiality & solicitor/client privilege: Harish v. Stamp, R. v. Hobbs, Osiris Inc. V. 1444707 Ontario Ltd. Waiver of confidentiality does not necessarily waive privilege (if one applies)
  • 6. Privilege Source: primarily common law Salosky(SCC): "fundamental civil and legal right” Emerges from the duty of confidentiality inherent in solicitor/client relationship Sometimes permanent (e.g. solicitor/client privilege) or limited by existence of specific circumstances (e.g. litigation privilege only pending litigation) Statutory limitations must be clearly and expressly provided by (Blood Tribe Dept of Health v. Canada) Waiver of privilege may not affect confidentiality
  • 7. Privacy Primarily statutory Must obtain informed consent for collection, use or disclosure of personal information by an organization in the course of its commercial activities In addition to consent requirement, collection, use or disclosure of PI must be reasonable Only collect as much information as is required Publicly available personal information is not exempt from consent requirement
  • 8. Privacy Application: any organization engaged in commercial activity Includes lawyers, unless acting as agent for individual in personal capacity (Ferenczy) This conclusion not accepted by Privacy Commissioner Various administrative requirements Provide access to or correct PI in possession on request Keep PI secure Retain PI only for long as is required
  • 9. Consent Exemptions For lawyers, exemptions from consent requirement are critical Some important ones: Required by law Investigations of breach of statute or contract Private purposes (if acting for individual) Provincial privacy laws in BC and Alberta have additional exemptions
  • 10. Cases on Lawyers and Privacy Can’t disclose PI pursuant to summons issued by an individual without jurisdiction to compel production (i.e. other lawyer) - PIPEDA Case Summary #2009-005 Consent not required to disclose personal information in response to writ of seizure issued by court - PIPEDA Case summary #2003-174 Law firms cannot collect credit reports without consent: PIPEDA Case Summary #2006-340 Solicitor’s lien insufficient grounds to deny access to personal information - Settled case summary #30 (2007) Not reasonable to use individual’s SIN for general identification purposes – limited to payroll and income tax purposes - PIPEDA Case summary #2002-69
  • 11. Overlaps Personal information subject to privilege Client information subject to privilege Personal information that is confidential
  • 12. Obligations Different But Consistent For the most part, all of privacy, privilege and confidentiality consistent in requiring: Access to information be limited Appropriate security steps be taken Major difference Privilege and confidentiality controlled by client (who can waive rights) Privacy controlled by legislation and consent of individual concerned - client cannot validly instruct lawyer to breach privacy
  • 13. Privacy and Privilege Privacy statutes: individual must be given access to PI Many examples of litigants requesting access from lawyers What if PI is privileged? PIPEDA s. 9(3) excludes access obligation if “information is protected by solicitor-client privilege” But what about other privileges? PIPEDA Case Summary #2008-397: also applies to litigation privilege; liberal interpretation PIPEDA Case Summary #2010-001: court procedures more appropriate to deal with allegation that documents improperly withheld as privileged
  • 14. Privacy and Confidentiality Confidentiality obligation subject to certain exemptions E.g. Ont. RPC s. 2.03: may disclose confidential information “where a lawyer believes upon reasonable grounds that there is an imminent risk to an identifiable person or group of death or serious bodily harm, including serious psychological harm that substantially interferes with health or well-being…” Privacy laws don’t contain exact same exemption PIPEDA s. 7(3)(e): “made to a person who needs the information because of an emergency that threatens the life, health or security of an individual” Must inform individual in writing without delay
  • 15. Builders Energy Services Ltd. Alberta IPC Investigation Report P2005-IR-005 Lawyer acting for acquirer of company posted employee personal information on SEDAR, where it was publicly available While case concentrated on whether disclosure of PI was reasonably necessary, clear that lawyer had not considered whether this PI was subject to privacy regime Similar considerations often arise in litigation
  • 16. Technology and Privacy Risks Service providers Storage devices (servers, hard drives, sticks) Laptops Blackberries and smartphones “Cloud computing”
  • 17. Managing Technology Risks Mitigate highest and most immediate risks Inventory personal data maintained by the firm Employee training and management Conduct risk assessment: Information systems design and information processing, storage, transmission and disposal Responding to and preventing attacks, intrusions and systems failures Fix vulnerabilities identified through risk assessment Continually evaluate and adjust information security program
  • 18. Data Retention Policies Privacy laws require lawyer to retain PI for only as long as required for disclosed purposes Ethical obligations require retention of client files until client releases you and all regulatory and liability issues have passed Finding correct balance between hanging on too long and destroying too quickly is tricky, especially since appropriate retention periods may be different depending on nature of data
  • 19. Summary Privacy issues have significant impacts in many practice areas: Family Civil and criminal litigation Real estate Estates Employment law Even in practices where PI of third parties is not critical, have to worry about employee privacy
  • 20. Summary Think about PI issues whenever you handle PI about individuals who are not your clients Know your obligations Know the relevant exceptions you can use to your advantage and in your clients’ interest Privacy obligations are constantly changing Keep informed; PCC and provincial sites, blogs Talk to the experts
  • 21. Thank You! For a copy of these slides, email me at mark@hayeselaw.com