S17_Banner_300x250-COPY
ONETrust_Webcon-3_23_17_Ad_300x250_OneTrust_v2
CS17_Banner_300x250-COPY
Globe24h PIPEDA ruling should be no surprise

Privacy law in Canada moves slowly. Even though there has been a sharp increase in class actions over the past few years, these cases tend to settle, resulting in little case law. A.T. v. Globe24h.com, published by the Federal Court just over a month ago, arguably moves the needle a little bit by becoming the first decision resulting in an order under the Personal Information Protection and Electronic Documents Act against a business with no physical presence in Canada. However, there is nothing really surprising or groundbreaking in this decision.

Globe24h.com was a Romanian-based website (as of today, it appears to no longer be online) that republished Canadian court and tribunal decisions found on other websites, then charged concerned individuals exorbitant prices to remove their personal information. Case law has been published online in Canada for several years by courts, tribunals and sites like the Canadian Legal Information Institute. These sites apply the robots exclusion standard to prevent indexing by search engines, so that the contents of court and tribunal decisions will not appear in search engine results. This provides litigants with a bit of practical obscurity for what can be extremely sensitive personal information, while at the same time recognizing the importance of the open courts principle.

Globe24h allowed its site to be indexed, exposing all personal information to search engines. This resulted in dozens of complaints to the Office of the Privacy Commissioner, which found that Globe24h’s activities violated PIPEDA. Globe24h initially responded to the commissioner’s investigation and removed some personal information from its site, but later refused to cooperate at all. Because the commissioner cannot make orders, one complainant applied to the Federal Court and obtained: a declaration that Globe24h had violated PIPEDA; an order requiring Globe24h to remove Canadian cases containing personal information from its site; and, an order for $5,000 in damages.

The Federal Court decision, which is aligned with the commissioner’s findings on virtually all points, is mostly common sense. Despite having no physical presence in Canada, the court nonetheless determined that Globe24h had a “real and substantial connection to Canada” because the site collected information about Canadians, collected it from Canadian sources, and directly affected the privacy of Canadians. PIPEDA was therefore found to apply, which should come as no surprise, as the Federal Court came to the same conclusion on similar facts ten years ago.

As expected, the court also agreed with the commissioner that Globe24h was engaged in commercial activity and did not publish court and tribunal decisions for exclusively “journalistic” purposes, which would have excluded its activities from PIPEDA. Although there remains little guidance on the scope of this exclusion, the journalistic purpose argument in this case was very weak. The court stated as follows: “the respondent adds no value to the publication by way of commentary, additional information or analysis. He exploits the content by demanding payment for its removal.”

To summarize, the court found that PIPEDA applied to Globe24h because it had a real and substantial connection to Canada, and it was collecting, using and disclosing personal information in the course of commercial activity. Further, there were no exceptions that would allow Globe24h to collect and use personal information without consent.

The court then took the logical next step of ordering Globe24h to change its practices to comply with PIPEDA. Specifically, the court ordered that Globe24h “shall remove all Canadian court and tribunal decisions containing personal information from Globe24h.com and take the necessary steps to remove these decisions from search engines caches.” Again, this is the first time an order has been made under PIPEDA against a foreign company with no physical presence in Canada.

There has been quite a bit of commentary on this case, much of which emphasizes the extraterritorial impacts, some going so far as to suggest that it has opened the door for a “right to be forgotten” in Canada. However, I think its significance may have been overstated.

First, while courts have historically exercised caution in making orders against foreign persons — particularly where it is unlikely that they can be enforced — it is hardly an extraordinary remedy in this case given: a) the clear violation of PIPEDA; and b) the explicit authority under PIPEDA to “order an organization to correct its practices.” In my view, it would seem odd if the court went so far as to find Globe24h non-compliant, then refused to make an order. This is nothing like, for example, ordering Google to block a website from appearing in it search results anywhere in the world to protect a Canadian company from intellectual property infringement, as the British Columbia Court of Appeal recently did (a controversial case that was recently heard by the Supreme Court on appeal).

Second, I do not think a case with such simple and straightforward facts offers any meaningful insight on the extremely complex question of whether there is (or should be) a right to be forgotten in Canada; e.g., a right to ask search engines to remove links to information that is inadequate, irrelevant, or no longer relevant. A.T. v. Globe24h.com should be taken for what it is: an acknowledgement that the Federal Court can make orders against non-Canadian companies that flagrantly violate PIPEDA by exploiting personal information about Canadians for financial gain. 

Written By

Shaun Brown

3 Comments

If you want to comment on this post, you need to login.

  • Christopher Berzins Mar 9, 2017

    Shaun,
    I fully agree with your analysis, especially with respect to the recognition of a right to be forgotten. There is nothing surprising with this outcome given the particular facts - this was simply an extortion racket that was clearly off-side PIPEDA. If anything, the OPC's earlier investigation report is potentially more illuminating in terms of a potential recognition of a right to be forgotten - it states very clearly that Canadians would not reasonably expect that court and tribunal decisions containing their personal information would be accessible through search engine queries. The real test will come when a complaint is made to the OPC against a search engine seeking to have such information removed from its search results or asking that a government body ensure that decisions containing personal information cannot be indexed by search engines. 
    Chris Berzins
  • Amalia Steiu Mar 10, 2017

    It is very impressive what the OPC was able to achieve her. But I heard this story many times with no detail around what did the Romanian regulators do? This is a a EU country subject to very powerful privacy legislation. What were the steps taken by the Romanian regulators to support Canada. This goes to a much bigger question and something I have been trying to get an answer...from the OPC. What about protection of Canadian personal information in the US? If this is to set a precedent, how will such precedent support our rights as Canadian citizens in the US? What is our right of appeal in the US, under a similar circumstance? EU seems to have secured a modality - that's Privacy Shield.
  • David Fraser Mar 10, 2017

    An additional reason to be cautious about relying on this case as a strong precedent for a finding of a "right to be forgotten" in Canada is that it was unopposed. There was nobody in court questioning any of the findings of the OPC, particularly in areas that might find a foothold in any future case such as freedom of expression, the appropriate remedy and the scope of the order.

Related

Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

Latin America Dashboard Digest

A roundup of the top privacy news from Latin America

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Get more News »

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find a KnowledgeNet Chapter Near You

Talk privacy and network with local members at IAPP KnowledgeNet Chapter meetings, taking place worldwide.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

The Privacy Core™ Library Has Evolved

Privacy Core™ e-learning essentials just expanded to include seven new units for marketers. Keep your data safe and your staff in the know!

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

Upcoming Web Conferences

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Team

Get your team up to speed on privacy by bringing IAPP training to your organization.

Let’s Get You DPO Ready

There’s no better time to train than right now! We have all the resources you need to meet the challenges of the GDPR.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

FIP Designation

Recognizing the advanced knowledge and issue-spotting skills a privacy pro must attain in today’s complex world of data privacy.

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

CIPP/E + CIPM = DPO

The IAPP’S CIPP/E and CIPM are the ANSI/ISO-accredited, industry-recognized combination for DPO readiness. Learn more today.

Learn more about IAPP certification »

IAPP-OneTrust Website Scanning & Cookie Compliance Tool

Scan your website for cookies, tags, forms and policies and create a custom, dynamically updated cookie policy based on the results of your scans.

Are You Ready for the GDPR?

Check out the IAPP's EU Data Protection Reform page for all the tools and resources you need.

Privacy Vendor List

Find a privacy vendor to meet your needs with our filterable list of global service providers.

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

More Resources »

Global Privacy Summit 2017

The world’s premier privacy conference returns with the sharpest minds and unparalleled programs—plus a whole new spin on Active Learning!

Canada Privacy Symposium 2017

The Symposium returns to Toronto! Take advantage of Early Bird rates before March 31 and join your fellow privacy pros for a stellar program.

The Privacy Bar Section Forum 2017

The Privacy Bar Section Forum is SOLD OUT and the wait list is closed. If you got on the wait list, we'll keep in touch about your status. Good luck!

Asia Privacy Forum 2017

Join us in Singapore for exclusive networking and intensive education on data protection trends and challenges in the Asia Pacific region.

Privacy. Security. Risk. 2017

We're bringing the best of the best in privacy and infosecurity to sunny San Diego. Early registration for P.S.R. opens in May.

Europe Data Protection Congress 2017

Your source for European policy debate, multi-level strategic thinking and thought-provoking discussion. Registration opens in early June.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»