Real and substantial connections : Enforcing Canadian privacy laws against American social networking companies
Colin J. Bennett, Christopher A. Parsons, Ádám Molnár
Abstract
Colin J. Bennett, Christopher A. Parsons, Ádám Molnár
Abstract
Any organisation that captures personal data in Canada for processing is deemed to have a ‘real and substantial connection’ to Canada and thus fall within the jurisdiction of the Personal Information Protection and Electronic Documents Act (PIPEDA) and of the Office of the Privacy Commissioner of Canada (OPC). What has been the experience of enforcing Canadian privacy protection law on US-based social networking services? We analyse some of the high-profile enforcement actions by the Privacy Commissioner. We also test compliance through an analysis of the privacy policies of the top 23 SNSs operating in Canada and through the use of access to personal information requests. Our analysis suggests that non-compliance is widespread, and is explained by the countervailing conceptions of jurisdiction inherent in corporate policy and technical system design.
OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Any organisation that captures personal data in Canada for processing is deemed to have a ‘real and substantial connection’ to Canada and thus fall within the jurisdiction of the Personal Information Protection and Electronic Documents Act (PIPEDA) and of the Office of the Privacy Commissioner of Canada (OPC). What has been the experience of enforcing Canadian privacy protection law on US-based social networking services? We analyse some of the high-profile enforcement actions by the Privacy Commissioner. We also test compliance through an analysis of the privacy policies of the top 23 SNSs operating in Canada and through the use of access to personal information requests. Our analysis suggests that non-compliance is widespread, and is explained by the countervailing conceptions of jurisdiction inherent in corporate policy and technical system design.
Key concepts: Jurisdiction, Privacy law, Privacy policy, Personally identifiable information, Privacy by Design, Information privacy, Enforcement, Information privacy law