LifeLabs goes to court to block privacy watchdogs from probing 2019 data breach
cbc.ca
cbc.ca
Government will just leak more important info.
I think a shift toward identity as a service is underway for the market to solve this. Auth0 and the like are offering a solution.
How does auth0 solve this? This isn't about your email or passwords getting leaked. This is about your lab test results (eg. HIV, herpes, etc.) getting leaked.
This is entirely separate from strict liability, though. The main issue is damages. Even if a company is strictly liable, they are only liable for the dollar value of damages caused by the data breach. And your data privacy has a dollar value of zero dollars until a law like CCPA says otherwise.
Under current legal theory, if your data is stolen, you can sue a company for the cost of identity theft that is provably caused by that data breach. But if you are not the victim of identity theft (or if you are, but can't connect that to the data breach in a court of law), then you don't have damages. A company has nothing to fear from strict liability if they are liable for zero damages.
tl;dr CCPA addresses severe problem in the existing system.
> “a result of the business’s violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information.”
[1] https://www.natlawreview.com/article/data-breaches-and-damag...
I would only apply it to business models that directly monetize consumer data though, because there are no technological means to guarantee complete security. A fact more people calling themselves computer scientists should make more clear in my opinion. But if you want to monetize data, you have the responsibility to keep it safe.
Would have severe consequences for funding of some sites, but I think it would seriously be worth it.
Also liability is interesting: According to [1] banks are not liable for contents of lockers. According to [2] banks might be liable for ATM robberies though, if there is not a resonable amount of security (camera, lighting, ...). It's quite an interesting topic.
There are also quite a few followup questions: Does a company that had a databreach have recourse against the software vendors? Are open source developers liable when there was a bug leading to a databreach? (I assume "no liability" licencese might be void in this case?) Is an social engineered or phished employee personally liable?
It might have far reaching consequences, and it's interesting to think about them.
[1] https://www.financialexpress.com/money/bank-locker-theft-rbi...
[2] https://www.hg.org/legal-articles/can-banks-be-held-liable-f...
Not sure how there is no government oversight for handling of sensitive data in the first place. I get that we have a "Privacy Commissioner of Canada". But this sort of thing should almost never happen.
Also, how the heck can a privately owned company that deliberately mishandled data (let's be honest here - instead of paying legal fees to fight in court, you could be, I don't know, tightning up your NetSec?) overrule a federally mandated officer?
Holy crap this stinks.
I'm considering registering myself as a lobbyist so that I can have more of a face to face contact with councillors in my city, and actually push for more change.
Because right now, if people in tech aren't advocating for better security practices...we're going to doom ourselves by standing by and not doing anything at all.
What does that even mean?
You don't think it's of any consequence to citzens? You think they are causing an unnecessary ruckus?
What part of Canada are you from? Is that you Justin?
I'm in Ontario btw and don't see the need for a personal attack in your comment.
The risk to them is, IMO, the standard of security and privacy governance within the public sector is much higher than pretty much any other institution I've seen, so in comparison, showing that a private company did not meet that standard would be trivial. However, the question of what kind of diligence was done on the original contract (or not) could blow up, since every mandatory risk assessment (if completed) done on it would have raised this breach possibility and recommended controls to mitigate it.
I was livid when I read about the breach as it's precisely the kind of incident every single security and privacy analyst who has ever advised the public service has used as a baseline scenario. It fell out of the news cycle I think because it was so bad it crossed the line into discrediting institutions, which isn't done in mainstream Canada.
The party in power whose minister approved this contract has been out of power for 3+ years, so politically for them it's just wastewater under the bridge, but as a legacy, this breach was in the realm of worst case scenario. For the sake of popular trust in the health system in general, the root cause analysis should be seen through.
LifeLabs needs to be held accountable and the courts should make an example out of them, and send a clear message to other companies that hoard personal data.
Corporations need to consider personal data as a liability, not an asset.