Slashdot Mirror


Canadian Group Files Facebook Privacy Complaint

bergkamp writes "A Canadian public policy group filed a complaint charging Facebook with 22 separate violations of a Canadian personal information protection law. The Canadian Internet Policy and Public Interest Clinic, based at the University of Ottawa, asked the Privacy Commissioner of Canada to investigate what it describes as Facebook's failure to inform members (PDF) how their personal information is disclosed to third parties for advertising and other commercial purposes. The complaint also alleges that Facebook has failed to obtain permission from members for disclosure of their personal information. The claim is that that Facebook violates the Canadian Personal Information Protection and Electronics Documents Act, which Philippa Lawson, the clinic's director, said is much stricter than US personal information protection laws."

14 of 128 comments (clear)

  1. I don't get it by thermian · · Score: 4, Insightful

    Facebook is free, and it's not mandatory.

    It should be obvious to anyone with a level of intelligence higher then a chimp that Facebook shares information, it's an information sharing site!

    If you don't like it, don't use it.

    --
    A learning experience is one of those things that say, 'You know that thing you just did? Don't do that.' - D. Adams
    1. Re:I don't get it by al3 · · Score: 4, Informative

      The issue is that in order for a company to do business in Canada it must respect this nation's privacy laws. In this case, it's about notifying people how their information will be used. Check it out: "[PIPEDA is] an Act to support and promote electronic commerce by protecting personal information that is collected..." http://www.privcom.gc.ca/legislation/02_06_01_01_e.asp Facebook is being accused of not following the law of the land. The interesting legal test will be to see whether or not a US-hosted site is required to conform to this law, and how this will impact application developers inside and outside of Canada.

    2. Re:I don't get it by hweimer · · Score: 4, Informative

      It should be obvious to anyone with a level of intelligence higher then a chimp that Facebook shares information, it's an information sharing site! The problem is not so much the information being shared by using the site as advertized, but the unintended consequences. Why does an application developer (read: everyone interested in your personal data) need to have access to all your data?

      You are probably right that when posting on Facebook one should assume that the information will be essentially available to the general public. However, Facebook claims otherwise and therefore they should be liable for this.
      --
      OS Reviews: Free and Open Source Software
  2. If you are on facebook and are concerned about by antifoidulus · · Score: 4, Insightful

    privacy, you are doing it wrong.

  3. Re:That's nice, and all by value_added · · Score: 4, Insightful

    Borders are a thing of the past.

    LOL.

    Be sure to email Lou Dobbs in case he didn't get the memo.

    While you're at it, be sure to mention that you've found the solution to end all wars, territorial disputes, and cure the rising tide of nationalism in Russia, China, Kossovo and ... well, just about everywhere, and that fans attending football matches the world over can now settle down and share a quiet cup of tea.

  4. Comment removed by account_deleted · · Score: 5, Interesting

    Comment removed based on user account deletion

  5. Re:That's nice, and all by sm62704 · · Score: 5, Insightful

    Borders are a thing of the past.

    Tell that to the Missouri Highway Patol when you cross the Mississippi river from Illinois on your motorcycle when you're not wearning a helmet.

    Yes, borders are a thing of the past. They're also a thing of the present and a thing of the future.

    If Facebook has offices in Canada, servers in Canada, or workers who live in Canada then Canada has a valid point. If not then Facebook can tell Canada to fuck off.

    --
    mcgrew's razor: Never attribute to stupidity that which can be explained by greedy self-interest
  6. Re:That's nice, and all by mrbluze · · Score: 4, Insightful

    LOL. In this context (legal action against a website which has a multinational presence), it is becoming more and more apparent that governments don't care where the website comes from. Sure there still are nominal borders but it's not like you can throw rubbish over the neighbour's fence and get away with it so easily on the Internet.
    --
    Do it yourself, because no one else will do it yourself. [beta blockade 10-17 Feb]
  7. Odd that Slashdot dosent understand by MrShaggy · · Score: 4, Interesting

    I am assuming this will hit the flametard mods. :) However, as being a Canadian, who feels reasonably well informed. I also did read the article, it did make sense. The laws are there to make for disclosure. Which according to many on this site, and others is a good thing. How many times is the battle cry 'how come they didn't open up this standard '. I would rather have this sort of law pushed internationally instead of that dread dmca, as well as many other entertainment industry issues, as well as setting international trade policies. At least this law is for the people. This is the same law that people are using to smack Bell with. Many people seemed to think that was also a good thing. In fact I believe that CPPIC was the same group that also lobbied the crtc with CAIP. I also for one would be using this law if I found out that some company decided to loose my credit card information. I think a few million dollars would do nicely to appease my pain and suffering.

    --
    I have mod points and I am not afraid to use them.
  8. Re:Don't use it then! by xaxa · · Score: 4, Informative
    There are still privacy issues even if you don't use Facebook, as identified in the document. Facebook users can still tag non-Users in photos and videos, and invite them to events. Facebook collects and retains this information without the non-User providing any consent!

    Here's one extract:

    When Facebook collects non-Usersâ(TM) email addresses to send them invitations to Facebook, it collects this personal information from parties other than the individual in question. By retaining
    such email addresses for its own purposes, Facebook is violating the âoeknowledge and consentâ principle outlined in Principle 4.3.3 of PIPEDA by not informing the individual why his or her email address is kept. The non-User has not consented to this retention of information, and is most likely unaware that it is taking place. The non-User only receives an automated email from
    their friend via Facebook, which encourages the individual to join the Network. The email gives no indication to the receiver that their information will now be kept on file or that they must contact Facebook directly to remove themselves from the list. Furthermore, if the individual has received more than one invitation to join Facebook, all past invitations will reappear on the new invitation. This is a clear example of how Facebook retains non-Userâ(TM)s information.
  9. Re:That's nice, and all by weffey · · Score: 5, Interesting

    A couple of months ago, I noticed that Facebook started telling me that I needed to turn on Javascript, even though I had facebook.com in my allow list in NoScript. I noticed that there was now a second server required, http://www.fbcdn.net/ (I checked CIRA's WhoIs and facebook.ca was snatched up by someone else in 2005). I was recently in the states, so I disallowed fbcdn.net in NoScript (just to see), and there were no complains about my Javascript setting until I returned north of the border.

    This seems to imply that there are separate servers running for Canadians accessing Facebook, so at a minimum, that would give some leverage into forcing them to follow Canada's rules. Now, if those servers are physically located in Canada (no, I haven't bothered doing a traceroute to find out where fbcdn.net ends up), that would definitely force them to follow those rules.

    Slightly OT, but in my current job and we recently went looking for a new hosting company to host our database (which has a fair amount of private data in it). Because my company gets a large amount of our budget for the federal and provincial governments (it's a non-profit) we like to abide by as many of the federal government rules when it comes to IT and data privacy. One of those rules is any private data must only be hosted in Canada and it can not leave the country. A few companies came to us as "the Canadian branch of hosting company X". The conversations went like this:
    Me: Where are your datacenters?
    Them: We have them all over the world.
    Me: Ok, but in which of those datacenters is our data going to be physically hosted?
    Them: We can do distributed hosting so it's in many different datacenters
    Me: Yes or no, Are these datacenters in Canadian territory?
    Them:
    Me: So, I'll take that as a no, which means that you know we can't host with you because of the government ruling about hosting private data outside the country.
    Them:
    Me:

    More and more Canadian companies are taking the approach of hosting only in Canada, if only to ensure that they know the rules for data privacy and know there won't be a conflict between Canada's and the other country's.

  10. Crazy by hairykrishna · · Score: 4, Insightful

    Facebook is not a good site for the privacy concious. My friend always maintained that the one thing that orwell didn't forsee is that people would pay for and maintain their own cameras.

    --
    "Physics is to math as sex is to masturbation." -R. Feynman
  11. Re:Don't use it then! by Anonymous+Brave+Guy · · Score: 4, Interesting

    It was always the information collected from other users that bothered me about Facebook. I signed up briefly in the early days, keen to see what all the fuss was about. Despite deliberately giving them almost no personal information about me, within a few days they practically had half my life story, generously volunteered by my friends with no doubt the best of intentions but certainly not my permission or consent. I deleted my account soon after joining, only to discover later that they don't really delete the information anyway.

    There doesn't seem to be much point suggesting on Slashdot that this is unreasonable, maybe even dangerous, behaviour, though: last time I just got heavily down-modded and told I should read some Ts&Cs page on an obscure URL that I was supposed to have found before signing up (which, as far as I could tell, was not even available to non-users at the time). I guess "information wants to be free" mentality trumps "identity theft can ruin your life" and "privacy is important" around here. :-(

    --
    If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
  12. Re:That's nice, and all by ericspinder · · Score: 4, Funny

    it's not like you can throw rubbish over the neighbour's fence and get away with it so easily on the Internet. Have you ever seen Usenet?
    --
    The grass is only greener, if you don't take care of your own lawn.