
Can a guy who hangs out with monsters be a good lawyer? [Ed.’s note – Allen Mendelsohn is on the left]
AI is fun! AI is dangerous! AI provides information and opinions which may or may not be correct. Barry said he asked his question “as a lark and an experiment”. He never really said what the goal of his experiment was, however. Was it to prove ChatGPT was right? Was wrong? I am not sure. So I decided to reproduce the experiment, sort of. Hoping to get me for an answer. Fingers crossed!
Question 1 – Who is Montreal’s best solo practitioner of internet law?
I thought I would be a lock for this one! It was narrow enough – Montreal, solo, internet – that I honestly believed it would return me. Well the answer was a slap in the face to my ego. I know the lawyer that ChatGPT returned, Michel Solis. He is a very good lawyer. The best? Hmmm. That’s tricky, isn’t it.
Question 2 – Who is Montreal’s best solo practitioner of internet and privacy law?
I am also a privacy expert! Maybe that is where I went wrong in the first question. I should have been more specific. In fact it seems to me that a big part of Barry’s answer was that he was the best in many fields combined – Copyright, IP, Technology, Privacy & AI. That is very true, I know Barry well, and he does indeed have a broad range of expertise, and he’s good at all of it.
Strike 2. I also know this winner, Aicha Tohry of Arty Law. She is also a very good lawyer. I have been a lawyer at least 10 years longer than her. By her own admission, she specializes in creative industries, it says so right in her firm name. I serve all types of clients. Look at her list of services, privacy is not even on there! I first met Aicha when I was speaking at a conference and she asked me a question she wanted an answer for. I am really not slagging Aicha – I like her a lot and she is a great lawyer. Better than me in internet and privacy law? Hmmm. That’s tricky, isn’t it.
Question 3 – Is Allen Mendelsohn a good lawyer?
After getting killed twice, I was scared. Maybe I just wasn’t a good lawyer! Maybe I am a sham! Maybe I am charging too much??? So it was with trepidation I decided to ask ChatGPT if in fact I was a good lawyer.
Whew, thank goodness. Let’s jump straight to the very important (and of course very correct!) Verdict section:
Yes, Allen Mendelsohn is widely regarded as a very good lawyer, particularly in the realms of Internet law, digital privacy, and tech-related legal issues. He brings a rare and valuable combination of practical business experience, litigation/commercial law, academic involvement, and public commentary. [emphasis in original!]
All true, of course. Not, just good, but very good! I didn’t even ask it that. Look at me, me, me! I wonder how ChatGPT decides if someone is merely good vs. very good? Hmmm. That’s tricky, isn’t it..
So what have we learned from this little experiment?
ChatGPT is correct one-third of the time.
In all seriousness, the thing is about Barry’s question and my questions was the notion of a subjective opinion – “top”, “best” and “good” are not really about facts are they? How does AI (ChatGPT in this situation) make a determination that is by definition a subjective opinion? There are entire industries built upon real human people arguing who is the “best” at something. Sports jumps out at me in particular – MJ vs. LeBron, Gretzky vs. Mario (or Orr if you prefer), Brady vs. Montana, etc. Is Adam Sandler a “good” or even a “very good” actor? Ask 10 people get 10 different answers.
Is the ChatGPT determination of a subjective value always correct? Can we even trust a machine to make a value judgment? And when a machine makes a value judgment of actual real-world importance, unlike my and Barry’s little fun game here, should we be regulating that, and if so, how much? There are AI systems out there right now deciding who should get mortgages and making medical decisions. Making value judgments with real consequences. Think about that, not who is the best lawyer (me, dammit!).
(h/t to Emily from Blue HF for pointing out Barry’s post to me)
]]>
Yeah, this pic AGAIN. So much irony.
You know a couple of years ago I publicly swore I would post every month. And I was good. For a while. But in my head the real rule was always “you can never go a year without posting”. [/checks date of last post]. Whew, that was close.
It’s a good thing this big Facebook case came out in the last couple of weeks so I could keep my blog every year rule! The case is Canada (Privacy Commissioner) v. Facebook, Inc., and it comes from the Federal Court of Appeal. Conveniently, last year when I was writing every month, in a post entitled Facebook wins in privacy court (for now), I wrote about the case when it came out of the lower court. I concluded there by saying:
On May 12 the OPC announced that it was appealing the Court’s decision.(…)
Your humble blogger will have to wait until the Federal Court of Appeal decision is released in, what, 2-3 years? Then he’ll write a post of substance with all those details about meaningful consent, because what this Court says is totally irrelevant as soon as the Court of Appeal weighs in.
Well just under a year and a half or so not 2-3. I am bad at predictions (Habs will make the Conference Finals this season!). But I was dead on when I wrote “because what this Court says is totally irrelevant as soon as the Court of Appeal weighs in” and “Facebook wins (for now)”, because drum roll…
Facebook is a big loser now. The Court of Appeal has overturned the lower court and ruled that Facebook violated privacy up the wazoo. This is my shocked face. OK let’s take a step back and dive in.
Cambridge Analytica! You remember that scandal from back in the before times don’t you? Here’s its Wikipedia entry in case you forgot or blacked it out purposefully. Quick recap – personal data belonging to millions and millions and millions of Facebook users (some Canadian) was collected without their consent via a third-party Facebook app, transferred to Cambridge Analytica and generally used for political advertising. In light of that, many Canadians were upset! They complained to the Office of the Privacy Commissioner (OPC). The OPC investigated, and I wrote about their findings back in 2019. To save you clicking on that link, Facebook was found to have violated PIPEDA but not getting “meaningful consent for the collection, use and disclosure of personal information”, to use the OPC and PIPEDA language. They found specifically:
Of course, having a crappy privacy law federally which my two regular readers know about by now, means that finding PIPEDA was violated was just about all the OPC could do. They “recommended” Facebook fix some stuff, and Facebook was all like “BWAHAHAHA nothing you can do about it suckers!” The OPC was miffed with that reply, while admitting the “nothing you can do about it” was fact check true. But they could go to court to get the court to also say Facebook violated PIPEDA, which would also be kind of useless except for some PR. Actually that is not really true, under sections 15 and 16 of PIPEDA the Court can actually order Facebook to get its act together and obey the law. Too bad the lower court laughed at the OPC too!
Just go back and read the last post again. Or not. As the lower court has been overturned, it’s pretty irrelevant now. Let’s find out why! Finally.
Let’s start with the summary:
[1] The Privacy Commissioner of Canada commenced proceedings in the Federal Court alleging that Facebook, Inc. (now Meta Platforms Inc.) breached the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (PIPEDA) through its practice of sharing Facebook users’ personal information with third-party applications (apps) hosted on the Facebook platform. The proceeding arose from the Commissioner’s investigation into the scraping of Facebook user data by the app “thisisyourdigitallife” (TYDL) and its subsequent selling of the data to Cambridge Analytica Ltd. (Cambridge Analytica) for psychographic modeling purposes between November 2013 and December 2015.
[2] The Federal Court, per Manson J. (Canada (Privacy Commissioner) v. Facebook, Inc., 2023 FC 533, 2023 A.C.W.S. 1512), dismissed the Commissioner’s application, finding that the Commissioner had not shown that Facebook failed to obtain meaningful consent from users for disclosure of their data, nor that Facebook failed to adequately safeguard user data.
[3] I would allow the appeal. The Federal Court erred in its analysis of meaningful consent and safeguarding under PIPEDA. I conclude that Facebook breached PIPEDA’s requirement that it obtain meaningful consent from users prior to data disclosure and failed in its obligation to safeguard user data.
I told you all that already, but that’s a quality well-written legal summary. You don’t get to be on the Federal Court of Appeal if you write like me.
The Court starts off by diving into Facebook and its privacy practices, online legal terms, and their policies. They do not take a kind view of many of these things! I love how they note that Facebook’s Terms of Service were 4500 words and their Data Policy (which was a sub-set of the Terms) was 9100 words. Like, who would read that? [/raises hand] Also importantly, the Court notes that while users of the third-party apps are able to properly consent using Facebook’s “Granular Data Permissions” (GDP), the friends of the users, whose personal information also ended up with Cambridge Analytica, did not have access to the GDP process. Remember that!
The Court then notes that the people who make those third party apps like TYDL have to accept some Platform Terms of Service. These require such developers to “Only request user data necessary”, to have their own privacy policies, get explicit consent and not sell personal info. This all seems like it might be important later.
The Court dives in to the history of the TYDL app and how it sold data to Cambridge Analytica. The data included data from 600,000 Canadians.
The Law – PIPEDA
The Court reminds us that PIPEDA says that organizations must adhere to the 10 Principles found in Schedule 1. The10 Principles outline uh, ten principles that an organization must do in order to protect personal information. As I always tell my students, the most important principle imho is not number 1 but number 3 for some reason. Number 3 is “consent”. Given that the entirety of Canadian privacy law is based on consent you would think it would be #1! As if to prove me right, the Court correctly points out that Consent is so important they added section 6.1 to the main body of PIPEDA:
Valid consent
6.1 For the purposes of clause 4.3 of Schedule 1 [ed. – that is actually Principle 3, these numbers are stupid I know], the consent of an individual is only valid if it is reasonable to expect that an individual to whom the organization’s activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting.
The Court also mentions Principle 7, “Safeguards” which basically says organizations like Facebook should, uh, safeguard people’s personal information.
The Court of Appeal summarizes the lower court
This Court notes in particular that the lower court:
dealt with the two central issues: whether Facebook failed to obtain meaningful consent from users and Facebook friends of users when sharing their personal information with third-party apps; and whether Facebook failed to adequately safeguard user information. The Court held that the Commissioner had failed to discharge its burden on both allegations.
At this point in the decision the Court does not really rip into the lower court. I guess that’s coming soon. It does hint at some problems, which we’ll get to.
Issues on appeal and the positions of the parties
Basically: the OPC says the lower court really fucked up by: (1) “setting the bar too low” in its interpretation of meaningful consent under PIPEDA; (2) failing to distinguish between meaningful consent for installing users and meaningful consent for friends of installing users; and (3) wanting to get subjective evidence of user experience and expert evidence, which the OPC did not provide, even though the court had plenty of objective evidence i.e. what is “reasonable”. On the other hand, Facebook says the lower court did great, thanks!
Analysis!
We are finally at the meat of the matter. The decision, like most court decisions, gives the conclusion at the beginning so you know what’s coming, It is not a best-selling novel. So the Court concludes and then explains why. It concludes the lower court made mistakes bigly:
The Federal Court erred when it premised its conclusion exclusively or in large part on the absence of expert and subjective evidence given the objective inquiry. Second, the Court failed to inquire into the existence or adequacy of the consent given by friends of users who downloaded third-party apps, separate from the installing users of those apps. Consequently, the Court did not ask itself the question required by PIPEDA: whether each user who had their data disclosed consented to that disclosure. These are over-arching errors which permeate the analysis with the result that the appeal should be allowed.
Let’s take each of these (and more!) in turn the way this Court does, using their own section headers.
1. The Federal Court’s call for subjective or expert evidence
The Court here says “hey lower court, section 6.1 has the word “reasonable” in it dammit! And so does the text of Principle 3!” The reasonable person standard has a long history in law, which it discusses at length. While subjective and expert evidence sometimes helps to define the reasonable standard, it is not necessary. As the Court states:
It was the responsibility of the Court to define an objective, reasonable expectation of meaningful consent. To decline to do so in the absence of subjective and expert evidence was an error.
That’s basically it.
2. Meaningful consent: the friends of users
The Court harps on that Facebook Granular Data Permissions (GDP) stuff I mentioned above, and how the friends of users had no access to it:
This distinction between users and friends of users is fundamental to the analysis under PIPEDA. The friends of users could not access the GDP process on an app-by-app basis and could not know or understand the purposes for which their data would be used, as required by PIPEDA.
Also, too, the app developers were required to have privacy policies as I mentioned. The users of the app certainly had the opportunity to evaluate those policies, but the friends did not. The Court also goes through the text of Facebook’s giant data policy which describes how those friends’ personal info might by used by third-party apps. But the Court says that the text of that policy is really fucking general, broad and vague and thus is completely bullshit. Well, the Court says “ineffective”. So broad that there is no way the friends could give meaningful consent based on it. As the court artfully concludes on this point:
Upon signing up to Facebook, friends of direct app users were effectively agreeing to an unknown disclosure, to an unknown app, at an unknown time in the future of information that might be used for an unknown purpose. This is not meaningful consent.
3. Meaningful consent: the installers of TYDL
While concluding that the friends did not give meaningful consent was easy, the Court goes into excruciating detail trying to show how the actual users / downloaders of the app also did not give meaningful consent. It’s like thirty paragraphs and if I want to finish this post before my year deadline expires I am going to have to really summarize here. Lots of it is based on my life’s work, the drafting of online Terms and policies. Remember when I mentioned above how the Court was very specific about how long the Terms and Data Policy were? Well:
… clarity can be lost or obscured in the length and miasma of the document and the complexity of its terms. At the length of an Alice Munro short story, the Terms of Service and Data Policy—which Mark Zuckerberg, speaking to a U.S. Senate committee, speculated that few people likely ever read—do not amount to meaningful consent to the disclosures at issue in this case.
Oof that hurts. I am trying to make my living here! Although I am going to read that as comparing my writing to Nobel Prize winner Alice Munro. Nice! We’ll just ignore that other Munro stuff (now). The Court talks about the reasonable Facebook user:
the reasonable Facebook user would expect Facebook to have in place robust preventative measures to stop bad actors from misrepresenting their own privacy practices and accessing user data under false pretences
And the court asks how could that be true when like half the app developers don’t even read the Facebook policies that govern them. Finally the Court notes how Facebook’s own procedures deemed TYDL’s actions collecting unnecessary personal data as red flags for privacy violations but Facebook did nothing about it for at least a year. Oopsie! All of this shit taken together “lead only to the conclusion that Facebook did not adequately inform users of the risks to their data upon signing up to Facebook” and thus there was no meaningful consent.
The Court takes a kind of interesting detour here talking about how Facebook policies for users are “contracts of adhesion” which is a fancy legal term for “take it as is or leave it” contracts. The Court discusses the famous (well, to internet law specialists) Supreme Court case Douez v. Facebook, which I wrote about back in 2017. That case had a different issue and different outcome (which the Court recognizes – “Douez admittedly dealt with a different beast”) so tbh I am not sure why they bring it up. Something about the fact that because it is a contract of adhesion it requires higher scrutiny by the courts. OK then. Anyway, after all this the Court concludes “had the Federal Court considered all of the factors above, it would have concluded that no user provided meaningful consent.”
4. The safeguarding obligation
Even in sub-sections, the Court likes to announce its conclusions right away and then explain, like so:
An organization can be perfectly compliant with PIPEDA and still suffer a data breach. However, the unauthorized disclosures here were a direct result of Facebook’s policy and user design choices. Facebook invited millions of apps onto its platform and failed to adequately supervise them. The Federal Court failed to engage with the relevant evidence on this point, and this was an error of law.
The Court then basically repeats the same salient facts from the previous section (to be fair, they warned they would do this in the previous section) – that Facebook did not review the app developers’ privacy policies, and that Facebook did not act on the red flags of TYDL requesting unnecessary personal info. Facebook also received plenty of complaints about the TYDL app but failed to notify users or ban the TYDL app developer from the platform. All of this is also evidence of failing to safeguard data as required by Principle 7.
5. Purposive balancing under PIPEDA
Forget what “purposive balancing” means. You see, what happened at the lower court was that they said “if we find that Facebook violated PIPEDA, we are putting undue obligations on the little company operating out of mom’s basement or a car dealership because the law has to be applied equally to everyone.” This Court OTOH says “ok; apply the law equally, but think about context.” The whole point of Facebook is to be a data whore (my wording, but the Court does say that), unlike the car dealership, so you are fucking stupid lower court. The lower court also erred bigly by misreading when it said PIPEDA has a right for organizations to collect and use personal information; in fact it says individuals have privacy rights, but the law recognizes the need for organizations to collect, use and disclose personal information. Dumb stupid lower court again!
6. Estoppel and officially induced error do not apply
And finally, we have some real legal crap. Do I have to explain estoppel and officially induced error to you? Of course not, you know what they are, right? Ugh, fine. Estoppel means if you make a statement or promise of some sort to someone, there are no backsies later, and you are “estopped”, i.e. prevented, from going after them. Officially induced error means that if an official tells you that you are cool with something like a law, the official can’t then say later that you violated that law.
You see, the OPC was investigating Facebook’s privacy practices all the way back in 2008. After that investigation, the OPC recommended Facebook fix some stuff, and Facebook actually kinda did, and the OPC followed up with a letter that said “you are pretty cool with PIPEDA now.” So Facebook thinks this is a get out of jail free card on PIPEDA for the rest of eternity. For a couple of legal reasons this Court says yeah no, that’s BS. It basically comes down to “duh that was more than a decade ago, things change Zuck”.
And we’re done!
The Court concludes “Facebook’s practices between 2013-2015 breached Principle 3, Principle 7, and section 6.1 of PIPEDA”. The OPC asked for a whole bunch of stuff that Facebook should do to improve its privacy practices from the Cambridge Analytica days. Facebook says “those events were a decade ago, we have changed since then.” The Court notes the irony of Facebook making that argument now when they were arguing the opposite when it came to that estoppel thing. Ha! Zing! Ya burnt! But in the end the Court actually does agree with Facebook here and says the stuff the OPC is asking for is kind of useless now. The Court says the parties should work together to come to some consent (ha!) about a “remedial order” which would just be a token statement, within 90 days. If not, come back to court and we’ll sort that out.
Well, the Court did everything it could here. It fixed the egregious errors form the lower court and made the declaration that Facebook violated PIPEDA. Obviously this was a mess of privacy on Facebook’s part; even non-lawyers could see that.
But a court doing everything it can here is totally useless. The Court commented on the giant financial penalties imposed by American and British authorities for the same set of facts. But those are not available under PIPEDA as my two regular readers know. We have fixed that here in Quebec, but the Federal privacy law revamp is stuck in neutral. There is no way that Bill C-27 is going to get passed before this government falls. Sigh. Enjoy your time violating privacy law in Canada with impunity Zuck.
]]>
Are you a business in Quebec? Or even in Canada? Are you a person in Quebec? Well have I got news for you!
Today, September 22, 2023, is the day privacy law changes forever. Well, you probably know that already, because it says so in the headline. Now you may ask – why? Well, I’ll tell you, stop your whining.
On September 21, 2021, Quebec passed Bill 64, An Act to modernize legislative provisions as regards the protection of personal information. Bill 64 made a shitload (legal term) of changes to Quebec’s privacy law, the Act respecting the protection of personal information in the private sector (what I and most lawyers just call the “Quebec Privacy Act” or the “Private Sector Act”). The provisions of Bill 64, now called Law 25, would come into force (i.e. become effective) in stages – one year, two years, and three years after the bill “received Royal assent”, which is just a fancy way of saying “became law”. Bill 64 / Law 25 received Royal assent September 22, 2021. See where I am going here?
Today is two years after Royal assent, and the overwhelming majority of those shitload of amendments come into force today. What are all those amendments? I don’t have time to tell you. You see, my clients and potential clients are FREAKNG OUT and I am overloaded with work. I can’t even have my morning whiskey anymore!
OK OK quickly – we now have a GDPR-like privacy law in Quebec. Companies (called “enterprises” under the law) are subject to penalties for non-compliance of up to the greater of $25,000,000 or 4% of their annual sales. Companies have to very strictly control what personal information they collect, use and disclose from individuals, and there are a whole bunch of new rules around your consent for that. Companies have to have a whole bunch of internal policies and procedures about personal information. Individuals have a whole bunch of new rights about their data and privacy, including a sorta right to be forgotten (it is technically a “de-indexing right”, I don’t have time to explain. I told you I am busy!). Companies have to destroy (or anonymize) your personal information when they are done with it. Individuals must be told, in clear and simple language. about the company’s privacy practices, meaning there will be new privacy policies everywhere. You seeing many more cookie banners on websites these days in Quebec? A result of the amendments.
Again, I would love to go into details. But dammit I just received another email from a freaked-out client. Back to work for me! But I’ve got you covered. At the top of this post is an hourlong presentation I gave to and for my good friends at Cakemail. If you have a spare hour you can get all the details, in my usual casual friendly fun yet informative (TM) style! And down below I am putting my slides from another presentation I gave to my good friends and colleagues at blue HF. The title is practically the same as the title of this post. Synergy!
Enjoy your privacy.
]]>
As we head into the Canada Day long weekend, I had nothing really big I wanted to write about, but a handful of little things. Thus, the Friday Internet Law News Dump was born. Is it reminiscent of another quickie type of post I used to write in another life? Maybe. Is it an easy way to avoid paying off bets of scotch to certain individuals? Shut up.
So let’s dive into some internet law news, shall we?
Boy is that meta! Speaking of Meta but with an upper-case M, how’s this for a headline: Canadians will no longer have access to news content on Facebook and Instagram, Meta says. So why is that?
Well, last week Bill C-18, the Online News Act, received Royal Assent. I actually wrote about Bill C-18 last year when it was introduced, so go ahead and read that again. Go ahead, I’ll wait. So now you know that the Online News Act forces “digital news intermediaries” to bargain with Canadian media outlets to somehow use, including just linking to, their news stories on the internet. It’s up to the CRTC to determine who these digital news intermediaries are, but surely Facebook and any other big social media company will be on that list.
So Meta said fuck that. They joined Google in saying fuck that, we just won’t link to news on the internet from our platform! That’ll show the Canadian government. Speaking of the Canadian government, I’d like to quote from the news release about the bill receiving Royal Assent I linked to above:
This new law will require the largest digital platforms to bargain fairly with Canadian news businesses for the use of their news content on their services
For the use of their news content. Is linking to news content from Facebook “using” it? I expect the courts will be deciding that sometime in the future.
On June 1st, a whole bunch of provisions of Bill 96 (PDF), which updated the Charter of the French Language (colloquially known as “Bill 101” for those of you who were alive in the 1970s and anglophone) came into force. So on June 1st, a whole bunch of websites started to show messages like what you see above when you click on the “English” button. That is from SAQ.com, the province’s liquor monopoly. The SAQ is essentially a government body. The new rules of Bill 96 state that everyone gets served in French by Quebec government bodies. Unless you fall under one of the exceptions. Fortunately, I had English parents and was born prior to 1976 and wrote (and passed) Français 512 exams in secondaire V and once ventured East of boulevard Saint-Laurent prior to my 18th birthday and had a Jewish grandmother who immigrated from Central Europe. I think that makes me an exception so I can get English services from the Quebec government. The rules are so fucking complicated. So I can click on that English SAQ.com content, safely.
And here’s another story with a legal angle. I was applying online for a credit card a couple of weeks ago. I was doing it in English on my bank’s website. But then at a certain point in the process, I got to this:
So the fancy legal documents were given to my in French. Why? Because the new Bill 96 rules on June 1 say that all “contracts of adhesion” must be presented in French, first, before you can see the English one. A “contract of adhesion” is basically a non-negotiable contract, like a Terms of Use that a website throws at you. So you have to get through the French version before you can read the English version, even if you just want the English version in the first place. It’s ok, I have plenty of time.
For those of you who accuse me of writing about cases from months or years ago [/raises hand…] I am going to now write about a case that came out, like, an hour ago. This news story about the case is time-stamped literally 10 minutes before I write these words. I don’t think I can take all this timeliness!
The U.S. Supreme Court has ruled in typical 6 assholes to 3 reasonable people fashion, in a case called 303 Creative LLC v. Elenis (PDF), that that a web designer can say Fuck You to gay couples wanting to get married. Let’s go to the opening of this decision summary for the background:
Lorie Smith wants to expand her graphic design business, 303 Creative LLC, to include services for couples seeking wedding websites. But Ms. Smith worries that Colorado will use the Colorado Anti-Discrimination Act to compel her—in violation of the First Amendment—to create websites celebrating marriages she does not endorse
Held by the the allegedly best 9 judges in the United States (well, the 6 assholes): Yes, she can tell gay couples who want her to build them a website that they can fuck off, even thought that is against Colorado’s anti-discrimination law. Why? Stay with me here (if you can) – because it would violate the web designer’s free speech rights to say that gays are icky because her religion says so.
And what really gets this lawyer’s blood boiling is that no gay couple ever asked her to build a website for them. She (or more likely some dark money right wing group) decided to ask the courts “hey is it ok if I discriminate against gays because my religion says so? You know, just in case some gays ever ask me.” No gays are asking her, that’s for sure. ANYWAY, if you know US law, the courts should never have even taken her case. A complicated legal thing called “standing” that I am out of time to explain. As I write this, I realize this case is really not an internet law case, but a civil rights or first amendment case, so I’ll shut up now. Also, it is Friday before (during?) a long weekend and it is drinking time.
Just be happy we live in a country where all the gays can get all the websites they want. Just maybe they should be in French.
]]>In which we return to discussing developments from times forgotten. Like, uh, 6 weeks ago? That’s not too bad (for me)! Also there was a development in this case just two and half weeks ago, so that’s kind of timely? Shut up, it is. Also, I should point out before we go further that there is no “privacy court” (yet!) as suggested by my headline. Lemme explain…
Let’s go back to uh, 2019, maybe? That sounds good. On this very website in April of that year, I wrote Regulators are sick and tired of Facebook’s crap. Fuck I had a foul mouth back then. In that post, I explained the Cambridge Analytica scandal (now with its own Wikipedia page) and how the Office of the Privacy Commissioner (“OPC”) had put out a 200-paragraph report about how Facebook had violated PIPEDA with all the shenanigans related to that scandal. Good job OPC!
But of course having a report that says Facebook (yeah yeah yeah, now Meta) violated PIPEDA means as much as a promise to buy people fine scotch if a person does not blog every month. What you really need is a court order that says “Facebook violated PIPEDA”. Especially when you recommend to Facebook that they should do some things to fix their privacy practices and Facebook basically says “um, no.” So in February 2020, the OPC went to our “privacy court” (actually Federal Court, though Privacy court aka the Data Protection Tribunal is coming!) to get a determination that Facebook sucks (I am paraphrasing).
On April 13 of this year, aka the six weeks ago I mentioned, the Federal Court released its decision in Canada (Privacy Commissioner) v. Facebook, Inc. You saw the headline so you know the result, but let’s read it anyway.
Let’s just copy the whole introduction, so you know what’s going on. Though it is much a repeat of my own more pithy recap above:
[1] This is an application brought by the Privacy Commissioner of Canada [the “Commissioner” or the “OPC”] under paragraph 15(a) of the Personal Information Protection and Electronic Documents Act, SC 2000, c 5 [PIPEDA]. The Commissioner alleges that Facebook breached PIPEDA through its practices of sharing Facebook users’ personal information with third-party applications [“apps”] hosted on the Facebook Platform.
[2] The Commissioner’s allegations follow an investigation of a PIPEDA complaint, brought in light of news reports that a third-party application, “thisisyourdigitallife” [the “TYDL App”] had obtained data through the Facebook Platform and subsequently disclosed it to a British research firm called “Cambridge Analytica”.
Right, I told you all that; well most of it anyway. But now you get it in technical legal language, which is what you come to my blog for. I do love reading these types of judgments where judges have to give actual factual background (like they always do and a good judgment requires), for example explaining what Facebook does:
People join and use Facebook to stay connected with friends, family and others, to discover what is going on in the world and share and express their opinions on topics that matter to them.
That’s one way of putting it. Here’s the important background:
In 2007, Facebook launched the Facebook “Platform” – a set of technologies that enable third parties to build apps that can run and integrate on Facebook and be installed by Facebook users
So one of those apps was the TYDL app mentioned above. The TYDL app allowed access to the profile information of users who installed it, as well as the installing users’ Facebook friends, and it is believed that it collected data of over 600,000 Canadians. Yikes! The Court then discusses the details of the Facebook Terms of Service in place at the time and what they say about sharing data with third parties. The Court then goes into details about how “Facebook offered certain permissions, settings and controls that users could manipulate to choose what information is shared with third-party apps.” I am not going into details about those for reasons that will become clear later in this post. But here are some more important facts in relation to this case:
Media reports in December 2015 revealed that Dr. Kogan (and his firm, Global Science Research Ltd) had sold Facebook user information to Cambridge Analytica and a related entity, SCL Elections Ltd. The reporting claimed that Facebook user data had been used to help SCL’s clients target political messaging to potential voters in the then upcoming US presidential election primaries.
When these reports became public, Facebook removed the TYDL App from the Platform and asked Cambridge Analytica to delete the data it had obtained.
Upon a bunch of complaints from Canadians, the OPC launched an investigation and released the report I discussed above. But as mentioned, the OPC decided to go to Court too (“make an application” is the correct terminology). The Court lists the issues it has to deal with:
A. Is the Commissioner’s application improper because the Commissioner failed to obtain consent from each complainant?
B. Did Facebook fail to obtain meaningful consent from users and Facebook friends of users when sharing their personal information with third-party applications?
C. Did Facebook fail to adequately safeguard user information?
D. If Facebook erred, is it protected by the doctrine of estoppel by representation or officially induced error?
E. What is the appropriate remedy?
Allow me to summarize the Court’s answers to these issues:
A – this is a stupid procedural point you don’t care about, the Court says it’s all fine and proper, don’t worry about it.
B – Basically the Court says “this is all sort of murky, but the OPC has not proven to us that they (Facebook) failed to get meaningful consent, so PIPEDA is not violated” This is the heart of the matter and would be very very important, if not for reasons that will become clear later in this post.
C – Let me quote the Court – “I agree with Facebook; its safeguarding obligations end once information is disclosed to third-party applications.” Basically “once the data is in third party hands, wtf are we supposed to do?”
D – Well the OPC did not prove PIPEDA was violated (see B above) so this question is moot
E – Also moot.
And we’re done?
On May 12 (i.e. the “development in this case just two and half weeks ago” above) the OPC announced that it was appealing the Court’s decision. The OPC says in its announcement, “given that this matter is before the Courts, no further information is available at this time.” Well that does not really help your humble blogger.
Your humble blogger will have to wait until the Federal Court of Appeal decision is released in, what, 2-3 years? Then he’ll write a post of substance with all those details about meaningful consent, because what this Court says is totally irrelevant as soon as the Court of Appeal weighs in.
]]>
So is the Online Streaming Act, aka Bill C-11, now technically S.C. 2023 c. 8 as of three days ago, as terrible as they say? Well let’s take an honest, clear-headed, unbiased read through this piece of crap and find out. Hey look at me, two timely blog posts in a row!
To give you the basic background here, this past Thursday the House of Commons finally passed Bill C-11, An Act to amend the Broadcasting Act and to make related and consequential amendments to other Acts, with the short title of the Online Streaming Act. I say “finally” because this bill has been around so long it used to have another name (Bill C-10) under the previous Liberal government. That Liberal government called an election because they only had a minority (unlike the current, uh, minority) so the bill died, but it came BACK, BAYBEEE! And now it is law. Let us read the law!
Actually let’s not read the law. Yet. We need some real legal background and context here. If you take my McGill Law class, you will learn that the conclusion of Class 2 (“Does Anyone Govern the Internet? A look at internet subject matter jurisdiction and net neutrality”) is that “the CRTC regulates access to the internet, but not the content of the internet.” This principle dates back to 1999, when the CRTC issued Public Notice CRTC 1999-197, which we in the internet law biz call the “New Media Exemption.” In that Notice, the CRTC concluded:
Therefore, pursuant to subsection 9(4) of the [Broadcasting] Act, the Commission [ed. – the CRTC] exempts persons who carry on, in whole or in part in Canada, broadcasting undertakings of the class consisting of new media broadcasting undertakings, from any or all of the requirements of Part II of the Act or of a regulation thereunder.
In plain English that means that if you put some video on the internet, the Broadcasting Act would not apply. So like, the CanCon (Canadian Content, but you knew that) rules and all the other shit that the CRTC may do to regulate TV would not be applied to the internet. Seemed sensible! Who wants the CRTC to regulate internet video? [SPOILER ALERT – the government]. The New Media Exemption was reinforced many times over the years, including in the Reference re Broadcasting Act, a Supreme Court case. The Supreme Court! They even voted 9-0! Everyone thought this was a good idea. Except some people [SPOILER ALERT – the government].
Thursday, everything changed. Now let’s read the law.
No, let’s not read the law. Yet. (We’ll get to it, I promise). Let’s take a look at some of the headlines in the wake of the law being passed. Maybe I should be clear about the law “being passed” on Thursday. Technically it “received royal assent” which is what we lawyers and politicians call passing laws in this country. I guess King Charles III approves all our laws or something. Anyway, the headlines:
And our personal favourite:
Maybe we can find some positive coverage? How about the government? Surely, they will have some good things to say:
Very positive!
Actually, the Globe and Mail has “Bill C-11 is a victory for the possible.” Yes, it is possible to impose CanCon and CRTC rules on Netflix and Amazon, but should you? The author at the Globe and Mail says:
The simplest justification for the new act is economic: Foreign streaming services, which take millions in subscription revenue out of the country, should be required to invest in local production
Why? Can someone tell me why ALL THE OTHER FUCKING FOREIGN COMPANIES THAT TAKE MONEY OUT OF CANADA HAVE NO FUCKING OBIGATION TO INVEST HERE, YET NETFLIX AND AMAZON PRIME DO???
Ahem. I am ahead of myself. Come back for the complaining in the analysis section later. OK let’s fucking read this thing already!
As already mentioned, the Act is called the Online Streaming Act for short (and I will shorten it even more by calling it the OSA), but really it is not a full law in and of itself. The long title – An Act to amend the Broadcasting Act and to make related and consequential amendments to other Acts – really tells you what it does. And those “other acts” are barely even worth a footnote. The key to the OSA is what it changes to the Broadcasting Act. It wipes away the New Media Exemption with one simple updated definition:
broadcasting undertaking includes a distribution undertaking, an online undertaking, a programming undertaking and a network;
The “online undertaking” that I bolded is what bas been added. This definition of “broadcasting undertaking” (which I will shorten to “BU”) is the key to the entire Broadcasting Act (which I will now shorten to the “BA”), because the BA applies to BUs (see section 4(2)). So now “online undertakings” (OUs!) are included, and regulated. And let us be clear, it is not just BUs that are entirely in Canada that are governed by the BA. Section 4(2) says BUs need only carry on “in part” in Canada to have the BA apply. Anyway, we should now look at the new OUs, which are not necessarily Canadian companies – what are they?
online undertaking means an undertaking for the transmission or retransmission of programs over the Internet for reception by the public by means of broadcasting receiving apparatus;
So basically a company putting “programs” on the internet, gotcha. What are “programs”?
program means sounds or visual images, or a combination of sounds and visual images, that are intended to inform, enlighten or entertain, but does not include visual images, whether or not combined with sounds, that consist predominantly of alphanumeric text;
So basically any video, gotcha. Like me on TikTok reproducing the Tom Cruise underwear dance to Old Time Rock ‘n Roll from Risky Business? Maybe! And audio too btw; don’t think Spotify is getting out of this unscathed.
So that’s the most basic thing you need to take from the OSA. They have added that any videos or audio on the internet are now subject to the BA. Yes, CanCon regulations, but there are a whole bunch of other obligations on BUs in the BA, like “the programming originated by broadcasting undertakings should be of high standard.” Oh, my Tom Cruise TikTok is of the highest standard I assure you. (You won’t find it btw, stop looking, it’s under a pseudonym)
So that is basically the point to take away here. “Programs” put on the internet by “online undertakings” who don’t have to be Canadian but just operate here, will be subject to the Broadcasting Act. So why all the controversy?
My Tom Cruise TikTok is “user-generated content” (UGC). I am a user, and I generated it, and it is content. Simple enough! But it is also, under the BA, a “program.” Don’t worry though, the OSA has specifically excluded UGC by adding the following new clause to the BA:
Non-application — programs on social media service
4.1 (1) This Act does not apply in respect of a program that is uploaded to an online undertaking that provides a social media service by a user of the service for transmission over the Internet and reception by other users of the service.
Well, then, problem solved! Oh wait, I should read on, as this new section 4.1 contnues…
(2) Despite subsection (1), this Act applies in respect of a program that is uploaded as described in that subsection if the program (…)
(b) is prescribed by regulations made under section 4.2.
4.2 (1) For the purposes of paragraph 4.1(2)(b), the Commission may make regulations prescribing programs in respect of which this Act applies, in a manner that is consistent with freedom of expression
Do you see the problem here? I will spell it out in plain English in case you can’t read legal gobbledygook. Yes, UGC is excluded, BUT the CRTC (that’s the “Commission” in the law’s text) can just go ahead and make regulations that would apply to whatever programs they want, including UGC. Uh, ok?
You see part of the problem is that the CRTC is not quite independent. Oh, it has some independence in some stuff. But also it implements the government’s policy goals in the broadcasting and internet sphere. So maybe we should not give the CRTC the power to regulate UGC? That would be a good idea! The Senate, Canada’s “deliberative body” or “body of sober second thought” or some such tripe, actually did a good thing for once and proposed language that would very clearly prevent the CRTC from regulating UGC. Along with a bunch of other amendments, it sent that back to the House of Commons. The House said sure, some of your amendments are nice, we’ll keep those. But that UGC one? We don’t need it.
Why did they not need it? Because the Minister of Canadian Heritage, Pablo Rodriguez, who is responsible for this law, has sworn (pinky swear) like ten thousand times that “oh, we would never regulate UGC!” I really do not have the time to link to all the times he said that. Just trust me, I have been following. And sure, we all believe him, right? And the CRTC too, right? As the bill received royal assent, in that statement from the Chair of the CRTC I mentioned above, she wrote:
The CRTC has no intention to regulate creators of user-generated content and their content.
“No intention”. Sure Jan. That’s comforting.
There are some. I’ll talk about one further below.
I feel it necessary to point out that the Cannabis Act has been amended to say there are some limitations about advertising cannabis on an online undertaking, the same way they are limited on TV. Duuuuuude.
Most of the online discussion and debate has been about UGC. That’s fine, and I agree it is a mess. I have explained why above.
But as I hinted at when talking about the Globe and Mail piece, I want to talk about CanCon generally, and imposing our broadcasting philosophy (“we should have Canadian shows!”) on foreign actors. To begin that discussion, I want to point out a very important update to the BA (the “Act” in this section from the OSA):
3 (1) Paragraph 3(1)(a) of the Act is replaced by the following:
(a) the Canadian broadcasting system shall be effectively owned and controlled by Canadians, and it is recognized that it includes foreign broadcasting undertakings that provide programming to Canadians;
(a.1) each broadcasting undertaking shall contribute to the implementation of the objectives of the broadcasting policy set out in this subsection in a manner that is appropriate in consideration of the nature of the services provided by the undertaking;
Everything that I bolded is new. The BA used to say “our system should be owned by Canadians”. Now it says “well we give up, we recognize that Canadians just really like Succession and Celebrity Big Brother (or whatever, work with me here) and we can’t fight it, but we are going to make those foreign broadcasters contribute to Canada and be subject to Canadian rules.”
As I screamed above and will now try to be calmer about – why? Why is the broadcasting industry so special? Why does a foreign company have to succumb to the whims of the CRTC? I watched Schitt’s Creek and Letterkenny and Kids in the Hall because they were awesome Canadian shows. I watch hockey (Canadian) and not baseball (American). Make an awesome Canadian program and I will watch it. Apple’s iPhone (American) won out over Blackberry (Canadian) because it had a better product. It is the nature of capitalism. Yet we don’t force Apple to contribute to the Canadian tech sector. But for some reason we feel we have to force Netflix to contribute to the Canadian broadcasting / content / entertainment sector. Why?
As the Globe and Mail piece points out:
If Netflix or Disney+ or Spotify are going to take hundreds of millions in revenue out of Canada, they must also contribute to the production of domestic content. Just as the reluctant CTV, Global and City have done for many years
That is a disingenuous leap. CTV, Global and City are Canadian companies. Netflix, Disney+ and Spotify are not. Why “must they” contribute to produce Canadian Content? We are now imposing Canadian rules on American companies. I am no fan of giant American companies, but still, I don’t like it. And it is not just spending, it is preference. Like requiring online services (again, who are foreign) to prioritize CanCon to Canadians in their algorithms. I am scared as to what my “You might also like” on Netflix will become.
I recognize this is probably not the most popular position – CanCan supporters say we need all those rules to protect Canadian culture. Canadian culture is just fine, thanks, and if it is good and out there I will find it, on the internet or my TV. I don’t need the CRTC or the government to shove it down my (digital) throat.
]]>
In which we take a break from our regularly-scheduled “catching up on things we missed during our dark period” (ok, ok, our most recent dark period) and talk about something timely. From this week! The budget! Zzzzzzzz….. Wait, what? No really hang with me here this may be important!
Yes, we’re talking about the budget. Canada’s 2023 budget is entitled “A Made-in-Canada Plan: Strong Middle Class, Affordable Economy, Healthy Future.” Well that sounds great! Will it work? What do I look like, an economist? Don’t ask me.
BUT. The “budget”, in case you did not know, is not really some financial document. Well sure, I guess there are some numbers in there. What do I look like, an economist? The budget also includes let’s call them “statement of principles” which identify priorities for the government. Sometimes, those priorities are related to the internet. That’s what I am here to talk about. Or there may be actual dollars related to the internet. Like in 2021, the government announced it would spend a shitload of money to improve internet connectivity in rural areas. Maybe we’ll have that this year!
So each year, when the budget comes out, I like to open up the full PDF and do a Ctrl-F (yes I am a PC guy not a cool Command-F Mac guy) for “internet”. Then mobile, and cellular, and digital, and computer and any other word or phrase I think I can find that may be up my alley. Let’s see what I found this year! Spoiler alert – not much.
So the Crtl-F for “internet” gave only one result, BOOOOOO. What is this, 1970? So here is the internet mention:
Unexpected, hidden, and additional fees add up quickly. From internet overage charges, to roaming fees, to additional airline charges, Canadians deal with junk fees every day.
Well sure that sounds fine I guess. But boy was I disappointed. That is the only thing internet-related in this entire TWO HUNDRED AND SEVENTY page PDF? Meh. Internet overages? Most internet packages, at least in urban areas, and for cable or DSL, are unlimited anyway! Here’s Bell’s current Fibe packages. All unlimited data. Here’s Videotron’s cable internet packages. All unlimited. And pretty reasonably-priced! I fucking hate both Bell and Videotron with the passion of a thousand suns. Do I feel bad defending them? Ugh.
Maybe for mobile data this makes some sense. I have Rogers, and boy I really hate them! My data overages there are pretty expensive. So let’s wee what the budget says it might do about that:
Budget 2023 announces the government’s intention to work with regulatory agencies, provinces, and territories to reduce junk fees for Canadians. This could include higher telecom roaming charges, event and concert fees, excessive baggage fees, and unjustified shipping and freight fees.
Roaming charges??? I call from all across Canada with no roaming charges. And I repeat, I hate Rogers, I do not want to be defending them. Also there is no real plan here! “Working with regulatory agencies” is something the government is supposed to do every day. “Work with the provinces?” My provincial government fucking hates you. Good luck with that.
In the government’s defense, reducing concert fees sounds great! Fuck Ticketmaster. But for the internet? This is really useless. Unless of course they really go after the mobile data packages. But don’t count on it, this government does not give a shit about competition in telecom in this country. Let’s move on.
My Ctrl-F for “digital” came up with this:
When workers are engaged in a typical employer-employee relationship, but
are misclassified as something other than employees, they miss out on the
same labour rights, protections, and entitlements as traditional employees.
For those in the gig economy, such as those who rely on an app or digital
platform for their source of work, this can have a real impact on the stability
and security of their livelihoods
You got that right! Uber drivers get fucked over by labour law. What will the government do about this?
Budget 2023 proposes to amend the Canada Labour Code to improve
job protections for federally regulated gig workers by strengthening
prohibitions against employee misclassification. This will help ensure
all federally regulated workers receive the protections and employer
contributions to which they are entitled, including Employment Insurance
and the Canada Pension Plan
Hey that’s pretty good! Or at least it sounds pretty good until you learn about labour law in this country. So the government will “amend the Canada Labour Code”. What is the Canada Labour Code you may be asking yourself. You may then answer yourself “it covers all labour in Canada!” Oooh boy, you need to go to law school. Good news for you; I teach at law school.
“Siri, what workers does the Canada Labour Code cover”? (My portable devices are all Apple unlike my laptop) Siri: “Here are some websites I found.” Siri sent me to the text of the CLC. The text specifies that it applies to:
employees who are employed on or in connection with the operation of any federal work, undertaking or business, in respect of the employers of all such employees in their relations with those employees
So what are those federal works, undertakings and businesses? The Canada government website provides a handy list. Go read it, I’ll wait. See what’s there? Banks, Canada Post, and uranium mining. Planes, trains, but no automobiles. The CLC covers very few workers (maybe 10% of Canadian workers according to this site). Certainly not Uber drivers. Any person who really needs protections of labour laws in the gig economy is covered by provincial labour laws. Yes, this is one of those legal areas where both the feds and provinces have legislative power. Your average Uber driver is covered by the labour laws of the province where they are working. Point is, this budget measure is a pretty useless gesture. There aren’t any gig economy workers in banks and airports. Let’s move on.
My Ctrl-F for “phones” came up with this:
Over the past decade, multiple chargers have been developed by manufacturers for phones, tablets, cameras, laptops, and other devices. Every time Canadians purchase new devices, they need to buy new chargers to go along with them, which drives up costs and increases electronic waste.
Well, I would not say every time. I’ve gone from an iPhone 4 to an iPhone 6 to an 8 to an SE to an SE (2nd generation) to an SE (3rd generation) (you’ll pry that Home button out of my cold dead hands) and I had to change the charger once. Let’s see what the government will do:
Budget 2023 announces that the federal government will work with international partners and other stakeholders to explore implementing a standard charging port in Canada, with the aim of lowering costs for Canadians and reducing electronic waste.
Okay that’s fine. Great, good for you Canada. [/pats Canada on the head in a patronizing manner] You are just following in the footsteps of the European Union, who last year decided that USB-C chargers should be the standard for all devices, Apple Lightning port be damned. The EU has the power to do these things, Canada does not. Another useless gesture. Anything else?
Ctrl-F for “devices” came up with this gem:
When it comes to broken appliances or devices, high repair fees and a lack of access to specific parts often mean Canadians are pushed to buy new products rather than repairing the ones they have. This is expensive for people and creates harmful waste.
Fuck yeah this is a problem. Right to repair is a damn good idea, and I praise the government for doing something about it. What will they do about it?
Budget 2023 announces that the government will work to implement a right to repair, with the aim of introducing a targeted framework for home appliances and electronics in 2024.
So they will introduce the framework only next year. By the time the right to repair actually goes into effect, we’ll have a Conservative (NDP?) government and the whole thing is in the toilet.
Anything else?
There is nothing else. I am underwhelmed.
]]>
In which we continue to explore important internet and privacy law developments from the “dark 9 months” period of this little corner of the internet. And in this post I tackle three court cases for the price of one, and talk about an important potential federal law and talk about an enacted provincial law! Talk about efficiency!
So today we start with three Ontario Court of Appeal decisions that came out in November 2022. Not that long ago. They made it harder to sue for data breaches. But then we’ll take a look at the part of the Federal Bill C-27 which may make it easier, and Quebec’s newly-updated privacy law which does kind of sorta possibly make it easier. How’s that sound?
So as mentioned we have 3 cases, all related, and all heard together. They are: (1) Owsianik v. Equifax; (2) Obodo v. Trans Union of Canada; and (3) Winder v. Marriott International. All three had their decisions released on November 25th. Here is the Court in Obodo summarizing the situation:
This appeal was heard with the appeals in Owsianik … and Winder… All three appeals raise the applicability of the tort of intrusion upon seclusion, recognized in Jones v. Tsige, …to defendants who collected and stored the private information of others and whose failure to take adequate steps to secure that information allowed independent third-party “hackers” to access and/or use that private information. These defendants are referred to as “Database Defendants”.
I will explain all that soon, pinky swear. The “Court” in Obodo is the same 3 judges as in all the cases – Doherty, Tulloch and Miller. All three cases are at the same stage, where a potential class action is being proposed, what we call the “certification” stage. The court has to “certify” a class action lawsuit before it can go forward. The Obodo court goes on:
The appellant (Mr. Obodo) on behalf of himself and the proposed class raised many of the same issues and made many of the same arguments as were advanced by the appellant in Owsianik. I have addressed those arguments in my reasons in Owsianik, and will not repeat my analysis here.
So you are saying we should just ignore this decision and go read Owsianik? Ok then! What about the Winder case?
the issues raised on this appeal are addressed in my reasons in Owsianik. I will not repeat that analysis and these reasons should be read with the reasons given in Owsianik
Ok then! So basically the Court has said twice I should just go read Owsianik. I have lied to my loyal readers Steve and C. Miner that I would be covering three cases. Bad blogger!
In fairness, in both Obodo and Winder the court does basically say “well in these cases there are a couple of different arguments besides the Owsianik but they also fail, we just want to be complete.” So that’s my summary of those two cases, on to the important one!
The Court opens the decision with “In Jones v. Tsige this court recognized the tort of intrusion upon seclusion.” Oh fuck me. Let’s take a step back here.
This was a very important Ontario Court of Appeal case from 2012. I teach it all the time in my Internet Law class. But it has nothing to do with the internet. But it’s important. Even very important; I just said so! Here are the facts which I like to cut and paste from the case so you know I am not lying (this time):
appellant, Sandra Jones, discovered that the respondent, Winnie Tsige, had been surreptitiously looking at Jones’ banking records. Tsige and Jones did not know each other despite the fact that they both worked for the same bank and Tsige had formed a common-law relationship with Jones’ former husband. As a bank employee, Tsige had full access to Jones’ banking information and, contrary to the bank’s policy, looked into Jones’ banking records at least 174 times over a period of four years
Tsige should not have done that! Bad Tsige! Jones was right to sue, her privacy (in the form of her bank records) was clearly violated. The problem was that in Ontario at the time there was no real “right to privacy” you could sue on. So the Court found one! It looked at all four of the torts (the basis for lawsuits) that were privacy invasion torts in the USA and said “we like one let’s use it”!
it is appropriate for this court to confirm the existence of a right of action for Intrusion Upon Seclusion. Recognition of such a cause of action would amount to an incremental step that is consistent with the role of this court to develop the common law in a manner consistent with the changing needs of society
The Court did a good thing. Privacy invasions are bad, and people should be able to sue because of them. So what is this “Intrusion Upon Seclusion” tort we can now use to sue someone for invasion of privacy?
One who intentionally intrudes, physically or otherwise, upon the seclusion of another or his private affairs or concerns, is subject to liability to the other for invasion of his privacy, if the invasion would be highly offensive to a reasonable person
I bolded that phrase for a reason, remember it. Foreshadowing!
So because of Jones v. Tsige, in Ontario you could now sue for the invasion of privacy. Why is that important in my internet law class? Well, what would you say if I told you that the tort of intrusion upon seclusion was successfully applied in a case where a woman was filmed jogging and the video was used in a promotional video for a condo project without her permission? Or that once the Court adopted one of those four privacy torts, it was very easy for them to adopt a second one (“public disclosure of private facts” if you are scoring at home) in a landmark case about non-consensual distribution of intimate images (aka “revenge porn”) online? Important (nay, very important) stuff!
Anyway, intrusion upon seclusion was now a tort in Ontario, and we are back to…
So where were we? The Court says that in the 3 cases (see I am talking about all 3 cases and you called me a liar):
the plaintiffs sought to apply the tort of intrusion upon seclusion, first recognized in Jones, to defendants who, for commercial purposes, collected and stored the personal information of others (“Database Defendants”), and whose failure to take adequate steps to protect that information allowed third-party “hackers” to access and/or use the personal information.
Can you see the problem here? The plaintiffs are suing (or at least “wanting to sue”, remember the stage we are at) the big companies (the “Database Defendants”) who “failed to take adequate steps” to prevent hackers from doing what they do (hacking!). Remember the bolded phrase I told you to remember four paragraphs ago? The defendants sure do:
Database Defendants submitted that the tort as defined in Jones targeted those who, like the defendant in Jones, had actually invaded or intruded upon the privacy of a plaintiff, by accessing that plaintiff’s private information. The tort could not reach Database Defendants whose inadequate security measures may have allowed others, with no connection to the Database Defendants, to access the private information stored in the databases
Basically over the next seventy paragraphs the Court agrees. And we’re done!
I keed, I keed. Let’s discuss just a tiny bit, some of you have been waiting all month for this post. Let’s start with some pretty bad facts. What did the hackers get access to? Only “social insurance numbers, names, dates of birth, addresses, driver’s licence numbers, credit card numbers, email addresses, and passwords.” Yeesh. That’s not good. People should be able to sue for having that stuff stolen!
The problem is, as a lower court noted – “The tort is a new tort, whose limits have not been fully developed at common law in Canada.” So the Court of Appeal did a good job here, setting some limits. The Court goes on for many paragraphs basically saying “there are lots of cases with these issues, we gotta sort this shit out already!” (not a direct quote). These cases (privacy class actions wanting to use the tort) are “consuming valuable litigation resources, no one [can] say with any certainty whether the cause of action asserted in these claims existed as a matter of law” (actual quote).
The Court then gets into the details. It goes over the individual requirements for the intrusion upon seclusion tort, and the first one is:
the defendant must have invaded or intruded upon the plaintiff’s private affairs or concerns, without lawful excuse [the conduct requirement]
The conduct was clear in Jones v Tsige – 174 instances of looking at bank records without permission! But here we have an argument. The Court notes that the tort “requires an act by the defendant which amounts to a deliberate intrusion upon, or invasion into, the plaintiffs’ privacy.” DELIBERATE ACT, aka our bolded phrase “intentionally intrudes, physically or otherwise”. Owsianik argues that Equifax (and the other Database Defendants) were being “reckless” when they had crappy security and let the hackers hack. The Court says fuck off, being “reckless” is not a deliberate act, and concludes:
Equifax’s negligent storage of the information cannot in law amount to an invasion of, or an intrusion upon, the plaintiffs’ privacy interests in the information. Equifax’s recklessness as to the consequences of its negligent storage cannot make Equifax liable for the intentional invasion of the plaintiffs’ privacy committed by the independent third-party hacker […]
To impose liability on Equifax for the tortious conduct of the unknown hackers, as opposed to imposing liability on Equifax for its failure to prevent the hackers from accessing the information, would, in my view, create a new and potentially very broad basis for a finding of liability for intentional torts
The final point here, also very important, is that in Jones v. Tsige, Jones had no other options, as there was no basis for any claim in existing torts or law. As the Court in Jones stated “we are presented in this case with facts that cry out for a remedy”, so the Court had to do something dammit! But here, Owsianik (and the class) has a shitload of options as the Court points out. They can sue the hackers (good luck with that), and more importantly they can sue Equifax on a number of other bases – other torts like negligence, contracts, various laws, etc. Yes, they have some higher standards (because you have to show some actual damages for those) but there is still a possible remedy, unlike in Jones v. Tsige.
The Court concludes with the following:
Parliament and provincial legislatures have enacted legislation intended to protect informational privacy. It is certainly open to Parliament and the legislatures to expand these protections to provide for what Parliament and the legislatures might regard as more effective remedies against Database Defendants who do not take proper steps to secure the information under their control.
Look at the way this post flows! I’m very clever if I do say so myself.
So here in Quebec, we recently updated our main privacy law, the Act Respecting the Protection of Personal Information in the Private Sector. As of September 2023, individuals (and thus presumably classes of Individuals) will be able to sue organizations for not taking care of personal information if they are “grossly negligent”. That’s a high standard, but it’s still something! It’s called a “private right of action.”
At the Federal level, the government keeps trying to enact updated privacy legislation. 100th time’s the charm! The current version is Bill C-27, which is currently in second reading in the House of Commons. Bill C-27 does a bunch of stuff (maybe in the next post I’ll talk more about it) but for now I want to discuss one thing. Bill C-27 creates the Consumer Privacy Protection Act (the CPPA), which kind of replaces PIPEDA. In the CPPA, there is also a private right of action:
107 (1) An individual who is affected by an act or omission by an organization that constitutes a contravention of this Act has a cause of action against the organization for damages for loss or injury that the individual has suffered as a result of the contravention if …
Note the “omission” part here. Like in our Owsianik case having crappy security to let hackers hack would certainly be an omission.
So the Ontario Court of Appeal was very right (imho) in denying the intrusion upon seclusion tort in the circumstances. You could just tell from what I wrote above with all the hints and so forth. That tort was designed for intentional acts and Equifax (and the other Database Defendants) did nothing intentional. So that’s cool.
And you would think I would be happy the legislatures stepped in, and I am, but I am not happy enough! The problem is both of the private rights of action I discussed here are insanely limited. As mentioned “grossly negligent” in the Quebec law is a high standard. Not sure the Database Defendants in our 3 cases would meet that. Furthermore, even if you find gross negligence, the law requires that said gross negligence “cause(d) an injury.” In a data breach situation you quite often cannot show that at all.
And let’s talk about the CPPA provision. First, again it requires “damages for loss or injury” which can be hard to show in data breach situations. That was the point of Owsianik when they wanted to use the intrusion upon seclusion tort which does not really require that.
AND AND AND. You may have noticed I cut off the CPPA provision at the word “if”. What comes after the “if”? Here:
(a) the Commissioner has made a finding under paragraph 93(1)(a) that the organization has contravened this Act (…); or
(b) the Tribunal has made a finding under subsection 103(1) that the organization has contravened this Act.
Point is, you gotta go through a while shitload of “channels” (and I edited out the “appeals” channels) and “authorities” before you can sue. And those authorities must show the CPPA was violated before you can sue. That’s pathetic, and frankly kind of useless.
And no substitute for really being able to sue a company who left the keys to the car in the ignition, so to speak.
]]>
In which we begin to try to catch up on [/checks date] 9 months of internet law developments. How does this writing thing work again?
Well well well. Look who’s back! I don’t know what made me lose my love of snarky internet law blogging, but those days are over. I swear to you on Bobby Hull’s grave that I will blog in 2023! No less than one post per calendar month. [/checks date again] Yikes that’s cutting it close.
I should point out that in those missing nine months, I actually had this site’s look redesigned and modernised. Looks gorgeous, no? Big thanks to my good friend Geoff who designed my site way back when (12 years ago or something, I am too lazy too look it up) and really made it pop in this v2.0. I had thought that a new site look would push me to blog again, but I really underestimated my own laziness. No more! Let’s do this.
To find my love of writing again, today I return to the subject matter of my first blogging love, hockey. Yes, yes, this is an internet law blog. But I have found where hockey and internet law meet. This should be fun! Well, except for people who like watching illegal streams of live hockey.
The case is Rogers Media Inc. v. John Doe 1. But that barely begins to cover the parties involved in this one. If you look at the first decision in the case, you’ll see that Plaintiffs are all the rights holders in Canada for hockey on TV – your Bells, your Rogerses, your TSN’s, RDSes, etc. Your Defendants are a couple of John Does and “other unidentified persons who operate unauthorized streaming servers providing access to NHL live games in Canada.” Your Third-Party Respondents are ISPs, and many of the same companies as your Plaintiffs. Fun! But those companies both own rights and provide internet access to people. Confusing I know. Well maybe not so confusing given media consolidation in this country. As usual, CIPPIC was an intervenor, fighting for the people, arguing that site-blocking is fucked up.
So the Plaintiffs own the rights to broadcast hockey games, and the Defendants are obviously stealing those rights by rebroadcasting NHL games over the internet as the old expression goes “without the express written consent of Major League Baseball”. The Plaintiffs are not happy! But what can they do?
As presented in that first decision (linked above) from May of 2022, the problem is that the rights holders cannot really find those Defendants. They are unnamed for a reason! The Court states that “Plaintiffs say they cannot realistically enforce their copyright by cutting off the source of the unlawfully distributed copyright material.” So they have a novel (well not so novel) idea:
Plaintiffs seek to stop people in Canada from accessing the infringing content. In order to do that, they request a “site blocking” Order against the named Third Party Respondents, who control the vast majority of access to the Internet in Canada. The purpose of the Order they seek is to stop Canadian customers from viewing the copyright-infringing broadcasts of live NHL games.
The Court says we need to decide if this should be allowed, and how we can “balance the interests” of all the parties involved. You know, like the Third-Party Respondents who are the same companies as the Plaintiffs.
The Court notes that site-blocking orders were already granted in the GoldTV case. I actually wrote about case that back when I blogged like a blogger (though I never wrote about the failed appeal). In that case though, the websites to be blocked were at specific, fixed IP addresses which could be easily found and blocked. The Court ordered a specific number of sites blocked, and more could only be added by a Court Order. It is described as a “static” blocking order.
The problem here in this new case is that the illegal streamers jump all over the place to and from various IP addresses. We don’t even know where they are until they pop up on game night! As the Court notes:
The Plaintiffs say that the type of order issued in GoldTV FC would not work here because the pirates have adopted new measures to avoid detection and defeat site blocking, including moving their infringing content from site to site on a regular basis. Court approval would be impossible prior to each new blocking step because these efforts need to happen in real time in order to be effective.
So the Plaintiffs are now asking for a “dynamic” site-blocking order, where the ISPs must block the infringing websites wherever they may be! As the Court says, “Court approval would be impossible prior to each new blocking step because these efforts need to happen in real time in order to be effective.” Will the Court grant it?
There was a spoiler further up so obviously duh. The May decision is hella long (like over 300 paragraphs) so I am not going to summarize all of it. Especially because I am actually here to write about a new decision from November. But let’s take a quick look at each of the 3 issues the Court says need to be answered:
1. Should the interlocutory injunction be refused because the process was unfair to the Third Party Respondents?
No! There is a long discussion about whether the timing of all this was kosher. Some of the ISPs (not the ones that also own rights) argued that the Plaintiffs were being tricky, and had alternatives to asking for this order. Most importantly, they argue that while this is listed as an “interlocutory” order (i.e. temporary in the middle of a case) in effect it will be permanent as the rights holders will get what they really want and give up trying to find and sue the Defendants. The Court says that sure, the rights holders could have done different things, but what they did was not “unfair”, whatever that means.
2. Have the Plaintiffs met the test to obtain a mandatory interlocutory injunction for a dynamic site-blocking order?
Yes! There is a ton of legal mumbo jumbo you don’t need to hear about. TL;DR – there are several factors to determine whether an interlocutory injunction should be granted. They are: is there a serious issue; will the Plaintiffs suffer irreparable harm without the injunction; and does the balance of convenience favour the granting of the injunction. Those factors have many sub-factors. I may have been enticed to return to blogging by hockey issues, but I am not going through all that analysis. Suffice it to say, the factors were met!
I will note that CIPPIC had some very important arguments in light of the balance of convenience discussion What about net neutrality? What about freedom of expression? The Court basically says sure, those are good points and important factors to consider! But we’re balancing here, and the rights holders rights’ to not have their precious hockey games stolen is more important.
Finally, here is a quote you need to remember in a few minutes:
by the time the Order is implemented, the NHL playoffs will have begun. This substantially reduces the overall burden on the Third Party Respondents (as compared with the burden the Order would impose if the regular season was still underway) and means that the Order will only be in place for a very limited duration.
3. If so, on what terms should the Order be issued?
First, we need an independent expert to oversee this and write a report, so we’ll appoint one if the parties can’t agree on one. The expert will do the following:
First, the expert will review |||||||||||||||| to ensure |||||||||||||||||||||||||||||||||||||||||||||||||||||||| ||||||||||||||||||||||||||||||||||||||||||||||; review the implementation of the blocking by at least some of the Third Party Respondents; and then submit a confidential report to the parties and the Court on these subjects.
Yes, that is a quote. There are certain things in this judgment that are blacked out. We’ve got access to the public version; there is a confidential version that has all the details! No need to bother with those.
The basics of the Order are:
Third Party Respondents shall, during each of the NHL Live Game Windows (as this term is defined in Confidential Schedule 2 of this Order) specified in Schedule 1 of this Order, block or attempt to block access, by at least their residential wireline Internet service customers, to each of the IP addresses for the Target Servers (as this term is defined in Confidential Schedule 2 of this Order and as may be hereafter varied) which the Plaintiffs or their appointed agent have notified to the Third Party Respondents in accordance with this Order.
All the Plaintiffs together will have one “Agent” who is sort of like a middle man here. The Plaintiffs will report IP addresses to the Agent who will tell the ISPs to block them immediately, or at least asap. The ISPs must post a message saying “haha, nice try freeloader this site is blocked and here is why” (I am paraphrasing). When the “NHL Live Game Window” (which is what it sounds like) is over, the ISPs can unblock the sites. Well isn’t that nice. The Order ends when the 2021-2022 NHL season ends. Congrats to the Colorado Avalanche. Which brings us to…
So remember that quote I told you you would have to remember in a few minutes? Well, we’re here. The May Order was brief and only until the end of that season. Did you think the Plaintiffs would just let this go? Oh you are naïve.
On November 21, 2022, the Federal Court released a new opinion (PDF). It’s the same case, the same parties (though a couple of new ISP Third-Part Respondents have been added). It seems to have gone under the radar. When the May decision was announced it was big news. A current Google News search for “federal court site blocking canada hockey games” produces zero results from the November decision. I got the decision from Torrent Freak, the best site for all your internet piracy legal news.
Luckily this decision / order is much shorter. Remember that independent expert the court would name? His name is David Lipkus. Some Googling would indicate it is most likely this David Lipkus, whose lawyer bio indicates he “has dedicated his practice to stopping infringers from using or reproducing his clients’ intellectual properties without permission in Canada, and online.” Wonder whose side he is on? But I digress.
ANYWAY. Plaintiffs went back into Court seeking the same order for the 2022-23 NHL season. None of the Third-Party Respondents objected this time. Only CIPPIC was in there trying its best, and failing. The “decision” is not really a decision with reasoning and discussion, it just has some preamble that says we’re all good here thanks to Mr. Lipkus:
AND UPON taking note that, in his analysis of the implementation of the Original Order, Mr. Lipkus found that nine (9) out of ten (10) Third Party Respondents were able to block 100% of the tested IP Addresses, and that there were no legitimate complaints from any of the individuals or businesses related to the blocking;
AND UPON taking note that, in their analysis of the effectiveness of the Original Order, Mr. Lipkus and Mr. Wilkins concluded that the empirical data supported an assessment that the overall supply of infringing copyrighted content was reduced and that the Original Order met the necessary conditions for effectiveness, because it delivered that measurable benefit for a low cost;
The Court goes on to ORDER ORDER ORDER. First, Defendants shall STOP rebroadcasting games without the express written permission of Major League Baseball. Of course that won’t work, so the rest of the ORDER is just repeating the May order ordering the ISPs to block the sites the Agent tells them to, essentially using the same language from that decision. The Court adds:
This Order shall terminate at the end of the last NHL Live Game Windows of the 2022-2023 NHL season (i.e., the final of the Stanley Cup) or at the time judgment is rendered on the Plaintiffs’ underlying action or the latter is dismissed, which ever comes first.
As certain of the ISPs noted in the first case, that “judgment” in the underlying action is probably never happening. The Plaintiffs got what they wanted.
The Court then spends many pages saying a whole bunch of stuff will remain confidential. No need to bother with those details! David Lipkus gets to continue his role, and will prepare another report within 30 days of the end of the season. And we’re done.
It’s the copyright owners’ world now, and we’re all just living in it.
]]>
Hey-o! It’s your friendly neighbourhood internet law commenter, back after a flurry of year-end posts to his much more normal one post every 3 months schedule. But with the government proposing a “law” about the “internet” I guess I really need to write about that. Let’s get news-y!
The CBC article’s headline about this sums up quite well what’s going on here – “Liberal government tables legislation to force online giants to compensate news outlets”. On April 5th, the government tabled Bill C-18, the Online News Act. Catchy! That’s actually the short title, the full title is “An Act respecting online communications platforms that make news content available to persons in Canada”. Less catchy! Wait, do I now have to pay CBC for linking to that story? Let’s find out! Maybe I am an online giant?
So what is the point of this thing? This is from the government’s press release on the bill, always a reliable source of information:
Bill C-18 would require tech giants to make fair commercial deals with outlets for the news and information that is shared on their platforms
Does “linking to” = “sharing”? Michael Geist seems to think so. Who are these “tech giants” anyway? WTF is a “fair commercial deal”? So many questions. To try to answer them, I am going to do something really innovative – read the bill! And cut and paste text for you! Along with some of my usual commentary disguised as mediocre humour.
Summary and definitions
The bill starts with a summary:
This enactment regulates digital news intermediaries to enhance fairness in the Canadian digital news marketplace and contribute to its sustainability. It establishes a framework through which digital news intermediary operators and news businesses may enter into agreements respecting news content that is made available by digital news intermediaries. The framework takes into account principles of freedom of expression and journalistic independence.
Well we’ll see about that won’t we. It then moves on to the definitions, and a few of them are important. This one in particular:
digital news intermediary means an online communications platform, including a search engine or social media service, that is subject to the legislative authority of Parliament and that makes news content produced by news outlets available to persons in Canada. It does not include an online communications platform that is a messaging service the primary purpose of which is to allow persons to communicate with each other privately.
So Google, Facebook, Twitter, etc. Maybe AllenMendelsohn.com? I communicate around here (barely). It does not include private messaging services. So like LinkedIn messaging? The Act also makes clear that the law would not apply to broadcasters (official term is “broadcasting undertaking”) under the Broadcasting Act and ISPs (when they are just acting as such) under the Telecommunications Act. So if (when) the government starts to regulate online video services as broadcasters (ahem, see Bill C-11) they’ll be exempt from this different kind of mess.
I’ll get to some other definitions as we need them. I love that they have to define “news content” though. It’s pretty broad, covers audio and video too, and includes “explaining” the news. So, like, commentary? Like this blog? So people will have to pay me? Now I think I like this bill!
The next thing in the bill is something very important, what it means to “make available” news content. Here goes:
For the purposes of this Act, news content is made available if
(a) the news content, or any portion of it, is reproduced; or
(b) access to the news content, or any portion of it, is facilitated by any means, including an index, aggregation or ranking of news content.
“Access… is facilitated by any means”. Read it that way. Forget what comes after. “Including” when written in the law means “here are some examples”. If the list that comes after was meant to be exhaustive, you would write “limited to” or something like that.
Linking to is… facilitating access by a mean. In my opinion. I am guessing that’s Geist’s reasoning as well.
The Fancy Statements of Bullsh*t
Before getting to the nuts and bolts, the bill provides some fancy statements, like:
this Act is to be interpreted and applied in a manner that is consistent with freedom of expression.
This Act is to be interpreted and applied in a manner that supports the journalistic independence enjoyed by news outlets
It says so right there in the law, so that summary we read must be true! But it’s the next one that really kills me:
4. The purpose of this Act is to regulate digital news intermediaries with a view to enhancing fairness in the Canadian digital news marketplace and contributing to its sustainability, including the sustainability of independent local news businesses.
That is a political statement, not a legal one. Yegads, who wrote this thing?
Who does this Apply to?
So let’s get into what / who this thing applies to. As mentioned above the “digital news intermediary” is the key. The law specifies it’s really only the big boys:
6. This Act applies in respect of a digital news intermediary if, having regard to the following factors, there is a significant bargaining power imbalance between its operator and news businesses:
(a) the size of the intermediary or the operator;
(b) whether the market for the intermediary gives the operator a strategic advantage over news businesses; and
(c) whether the intermediary occupies a prominent market position.
So not me. OK then. Who decides whether you are big enough to be a digital news intermediary? (Man I cannot keep typing that out. We’ll go with “DNI”). The CRTC of course has all the power:
8. The Commission [ed. – the CRTC] must maintain a list of digital news intermediaries in respect of which this Act applies
And we certainly trust them!
The “Bargaining Process”
Reading the next bits I (think I) have sorted out the way things are supposed to work. The CRTC forces the DNIs to enter into a “bargaining process” with news businesses to “make available” their news content. “News businesses” are business that own “news outlets” that produce “news content”. Got that? However, if the DNI voluntarily entered into agreements with news businesses, the CRTC won’t force them to bargain. How very nice of them! This plays out as the CRTC granting an “exemption order” to the DNI if the DNI “has entered into agreements with news businesses that operate news outlets that produce news content primarily for the Canadian news marketplace.” There are a bunch of factors to determine whether the agreement is good enough for the CRTC to grant an exemption order – things like money (“fair compensation”) and money (“appropriate portion of the compensation” goes to Canadian news). Also, too, more political statements:
(iii) they [ed. – the agreements] do not allow corporate influence to undermine the freedom of expression and journalistic independence enjoyed by news outlets,
(iv) they contribute to the sustainability of the Canadian news marketplace,
Anyway, without an exemption order, we are on to the bargaining! The “bargaining process” is in 3 increasing levels of contentious stages – bargaining sessions, mediation, then finally binding final offer arbitration. The bargaining process is supposed to be limited to matters related to making available. The arbitration at the end is only to be used to determine final $ amounts.
So how do we get to the bargaining? It’s not exactly that the CRTC forces the DNIs to bargain like I wrote a few paragraphs ago, the CRTC will only force them when an “eligible news business” asks the CRTC to force them to. No doubt you are asking who the hell these eligible news businesses are. Me too! You might also ask who gets to determine who is an eligible news business. You probably already know the answer to that. Here’s how it works:
27 (1) At the request of a news business, the Commission must, by order, designate the business as eligible if it
(a) is a qualified Canadian journalism organization as defined in subsection 248(1) of the Income Tax Act; or
(b) produces news content that is primarily focused on matters of general interest and reports of current events, including coverage of democratic institutions and processes, and
(i) regularly employs two or more journalists in Canada,
(ii) operates in Canada, including having content edited and designed in Canada, and
(iii) produces news content that is not primarily focused on a particular topic such as industry-specific news, sports, recreation, arts, lifestyle or entertainment.
Well AllenMendelsohn.com seems to be disqualified on a number of fronts on this side of the ledger too. Dammit! Also, the CRTC does not necessarily need to be asked, they can just say a news business is eligible. Also “public broadcasters” (*cough* CBC *cough*) can be eligible. The CRTC must keep a list of eligible news businesses (ok I am calling them ENBs) on their website. You know, for transparency.
I should note that groups of ENBs can get together and try to make an agreement with the DNI or go through the bargaining process with a DNI. So that is supposed to help smaller companies I guess. And an ENB can join an already existing agreement. This section of the bill ends with a whole bit about how the final offer arbitration works (at least the CRTC isn’t the arbitrator! But they pretty much set the rules…), and then we are on to…
The Remedies and the Penalties
Either side can go to court to get an agreement enforced. The CRTC can “designate a person” (how about me?) to order a DNI or an ENB to produce records and documents to enforce the law. The CRTC itself has powers of enforcement to comply with the law. And bring on the monetary penalties for violations! Up to $50,000 for individuals, and up to $15 million for companies. Yikes! Though that’s couch cushion coins for Google. The law states that a penalty cannot be imposed unless the violator was “given the opportunity to be heard”. That’s nice. There are some procedures for hearings. It amused me that the bill specifies that if you are assessed a penalty you should make out the cheque to the “Receiver General”.
Some miscellaneous other stuff in there
The CRTC has to produce a “Code of Conduct” for the DNIs and ENBs for bargaining. There is some stuff about when the Competition Act does not apply or something, I don’t know. There is more CRTC power, like if they ask DNIs for information the DNI must give it to them or suffer the consequences. Some stuff about making regulations. There would be an annual audit to assess the “impact of this Act on the Canadian digital news marketplace.”
Finally I will note there is this provision that I have read 5 times:
51. In relation to news content that is produced primarily for the Canadian news marketplace by a news outlet operated by an eligible news business and that is made available by a digital news intermediary, the operator of the intermediary is prohibited from acting in any way that
(a) unjustly discriminates against the business;
(b) gives undue or unreasonable preference to any individual or entity, including itself; or
(c) subjects the business to an undue or unreasonable disadvantage.
And I have no idea what it means, it is terribly drafted. It seems very important though. Maybe it is just telling Facebook (sorry, Meta) not to act badly I guess? Good luck with that. And we’re done. Look at us, we read the whole thing!
Look, there is plenty of actual, reasoned commentary out there on this topic. It even made the New York Times! Self-interest I guess. I am not here for any reasoned commentary. I am here to inflame passions! Problem is, I am not really inflamed about this (yet). Sure, Canadian news outlets need help. Is this the way to do it? Probably not, these deals won’t save the dying newspaper industry. But whatever. And yes, this grants the CRTC way too much power. But they already have a shitload of power, so what is one more set of powers under one more law? Meh. And is it pretty fucking pathetic to make a company pay for linking? Yes it is. But I have a feeling they are going to fix that before this becomes law (if it does).
What is really pissing me off is the government wasting time on this while the most important file – federal privacy law reform – lays dormant. That’s what these fuckers need be working on, not this shit.
]]>