PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Canadian town employee sends financial info to residents via Facebook account?

Posted on October 18, 2012 by pogowasright.org

A town employee in La Scie, Canada, used his personal Facebook email account to send private information to two individuals, who then filed a privacy complaint over, inter alia, the insecure method of sending financial information. The town attempted to justify their action by saying that they had no other way to contact the residents as they had no phone numbers and… wait for it… the account was password protected (insert *facepalm* here).

From the Office of the Information and Privacy Commissioner of Newfoundland and Labrador:

The Information and Privacy Commissioner, Ed Ring, has released his Report P-2012-001 under authority of theAccess to Information and Protection of Privacy Act. A summary of the Report is included below.

To view the Report in its entirety, please go to www.oipc.nl.ca/privacyreports.htm Opens in a new window.

Report: P-2012-001
Report Date: September 27, 2012
Public Body: Town of La Scie

Summary: On January 19, 2012 the Office of the Information and Privacy Commissioner received a Privacy Complaint under the Access to Information and Protection of Privacy Act (“ATIPPA”) filed collectively by two individuals regarding the Town of La Scie (the “Town”). The Complainants stated that their personal information had been sent to one of the Complainants by a Town employee via a private message on a social media website (“Facebook”). The message was sent using the employee’s personal Facebook account. The Complainants alleged that their personal information was not adequately protected pursuant to section 36; was improperly used pursuant to section 38; and was improperly disclosed pursuant to section 39.

The Commissioner found that the disclosure of the Complainants’ personal information was not contrary to the ATIPPA as the message was sent only to the Complainants. The Commissioner found that the Facebook message was a use of the Complainant’s personal information and that the method by which this use was carried out (i.e. Facebook) did not meet the limitations set out in section 38(2) or standard of necessity required by sections 38(1)(a) and 40(b) of the ATIPPA and, consequently, amounted to an improper use of personal information. Finally, the Commissioner found that the personal information had not been adequately protected. The Commissioner also provided commentary on the use of social media by public bodies and concluded that outside of community matters, announcements and notices, social media websites should not be used by public bodies to collect, use or disclose personal information regardless of the mechanism of delivery. The Commissioner recommended that the Town create and implement polices and practices regarding the use of social media and ensure that privacy training is provided to all Town employees.

h/t, Norwester

Category: Non-U.S.

Post navigation

← New “Surveillance-Proof” App To Secure Communications Has Governments Nervous
Commentary: Why you should oppose a data breach notification law (AU) →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants

RSS Recent Posts on DataBreaches.net

  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy