Facebook breaches Canadian privacy law: commissioner
Last Updated: Thursday, July 16, 2009 | 3:20 PM ET
CBC News
Related
Internal Links
- VIDEO: Are you comfortable with Facebook's privacy policies?
- IN DEPTH: Facebook users warned about dangers of being app happy
- IN DEPTH: Facebook generation
- YOUR VIEW: What are your privacy concerns about Facebook?
- University of Ottawa law students file privacy complaint against Facebook
- Facebook's response to new privacy concerns: trust us
- Prof says young people have unique sense of Facebook privacy
Video
- David McGuffin reports: Facebook breaches Canadian privacy law: commissioner (Runs: 2:34)
- Play: QuickTime »
- Play: Real Media »
External Links
- Privacy Commissioner: Report on findings about Facebook
- Personal Information Protection and Electronic Documents Act
- Canadian Internet Policy and Public Interest Clinic
(Note: CBC does not endorse and is not responsible for the content of external sites - links will open in new window)
'Although Facebook provides information about privacy issues, it is often confusing or incomplete,' said Elizabeth Denham, assistant privacy commissioner. (Emily Chung/CBC)Facebook shares its users' personal information with developers who create games and quizzes in a way that breaches Canadian privacy law, the Office of the Privacy Commissioner of Canada has found.
The popular social networking site, which is used by 12 million Canadians and 200 million people worldwide, also keeps personal information indefinitely after users deactivate their accounts, contrary to the Personal Information Protection and Electronic Documents Act, says the report released Thursday by assistant privacy commissioner Elizabeth Denham.
The office's main concern was that users could not always give "meaningful consent" to the use of their personal information due to a lack of transparency on the site.
"We found that, although Facebook provides information about privacy issues, it is often confusing or incomplete," Denham said at a news conference.
Users should be able to opt out of actions that could lead them to lose control over their personal information, she added. In some cases, that information could then be used for marketing purposes or even identity theft.
'For a hangman application ... there is no use for the developer to know where the person lives or have their personal email address.'— Jordan Plener, CIPPIC
Facebook declined interview requests Thursday, but issued a statement saying it is about to introduce new privacy features that it believes "will keep the site at the forefront of user privacy and address any remaining concerns the commission may have." It added that in the meantime, it will continue to work with the commissioner's office and to raise awareness about its privacy controls.
4 areas of concern
The Office of the Privacy Commissioner's report found that Facebook continues to breach PIPEDA in four ways and it made recommendations to correct the problem. It found:
- Facebook doesn't have enough safeguards to prevent 950,000 third-party developers around the world from getting unauthorized access to users' personal information, nor does it ensure users have given "meaningful consent" to allow their personal information to be disclosed to the developers. Recommendation: Developers should only get the information needed to run the application. Users would have to specifically consent to the release of that information after being told why it is needed. Information about anyone other than the user would not be disclosed.
- Facebook keeps information from accounts deactivated by users indefinitely. Recommendation: Facebook should have a policy to delete the information after a reasonable length of time, and users should be informed of the policy.
- Facebook keeps the profiles of deceased users for "memorial purposes" but does not make this clear. Recommendation: Information about use for memorial purposes should be in Facebook's privacy policy.
- Facebook allows users to provide personal information about non-users without their consent. For example, it allows them to tag photos and videos of non-users with their names, and provide Facebook with their email addresses to invite them to join the site. It keeps the addresses indefinitely. Recommendation: Facebook should only keep non-users’ email addresses for a reasonable, specific length of time and should make its users aware that they need to seek consent of non-users before posting information about them.
Users' responsibilities
Denham and privacy commissioner Jennifer Stoddart emphasized, however, that they aren't telling people to stay away from social networking sites.
"We all understand that social networking sites can be a wonderful way to connect," Stoddart said at the news conference. She added that not everyone sees privacy in the same way, and some people may be more willing to share personal information more widely than others.
Denham added that users also need to take responsibility by reading privacy policies and using the information to make their own choices.
The investigation was launched by the privacy commissioner's office in response to a complaint from the Canadian Internet Policy and Public Interest Clinic, which is based at the University of Ottawa.
Jordan Plener, a law student who initiated the complaint on behalf of CIPPIC, said he had a number of concerns about areas such as Facebook's default privacy settings and the personal information available to developers.
"For a hangman application, for example, there is no use for the developer to know where the person lives or have their personal email address."
The complaint cited allegations on 12 topics. Denham deemed allegations about four topics unfounded. Facebook accepted Denham's recommendations and resolved problems in four other areas.
Plener said that was a good start. But he noted that so far, Facebook has refused to accept Denham's other recommendations.
With respect to the four remaining topics, the assistant privacy commissioner has asked Facebook to reconsider its recommendations to resolve the problems and said she will follow up in 30 days. If Facebook does not comply at that point, the privacy commissioner's office can have its recommendations enforced by the Federal Court.
Denham noted that the company has been co-operative throughout the investigation, and she is hopeful that it will comply.
Share Tools
Top News Headlines
- Oda's travel expenses cause dissent in Tory caucus
- Conservative MP John Williamson, who was once head of the Canadian Taxpayers Federation, has raised the issue of International Co-operation Minister Bev Oda's spending habits behind closed doors with the Conservative caucus. more »
- Canada accused of 'complicity' in torture in UN report
- The United Nations Committee Against Torture has condemned what it calls Canadian "complicity" in torture and human rights violations of Muslim men caught up in the post-9/11 security net. Terry Milewski has exclusive details. more »
- Diamond Jubilee: Your photos of royal encounters
- The CBC Community team asked you to submit your best photos of the Queen's visits to Canada, or visits by any member of the Royal Family. The result was tremendous! more »
- Helicopter crash kills 3 near Terrace, B.C.
- All three people aboard a helicopter that went down west of Terrace, B.C., died in the crash, the aircraft's owners say. more »
Latest Technology & Science News Headlines
- Newly mapped tomato genome could yield tastier, hardier fruit
- You might think you know all you need to know about the humble tomato, but now, you can truly get a look at what this fleshy fruit is made of thanks to the work of about 300 scientists who have identified almost all of the genes that make up one common variety. more »
- Last chance to see Venus transit across sun
- If you happen to glance at the sun in the early evening next Tuesday and notice a black dot moving across it, fear not, that's not dust in your eye or an early sign of glaucoma — it's Venus. more »
- Call of Duty creators, Activision settle legal fight
- Activision has reached a settlement with the creators of the hit video game series Call of Duty following a bitter legal battle. more »
- Google flags censored search words to Chinese users
- Google has fired a new salvo in its censorship battle with Beijing by adding a feature that warns users in China each time they enter keywords into its search engine that might produce blocked results and suggests they try other terms. more »
- Social mapping software turns neighbourhoods into 'Livehoods'
- You might have no doubt about what neighbourhood you live in, but can you pinpoint your livehood? If you're in Montreal, you can now, thanks to a new mapping software that redraws traditional city boundaries using data gleaned from social media applications such as Twitter and Foursquare. more »
Bob McDonald's Blog
SpaceX got it right when things went wrong Jun. 1, 2012 2:55 PM It was back slaps and hugs all around this week as the Dragon space capsule, the first privately-built spacecraft to visit the International Space Station, returned safely to Earth. What's most impressive is how problems that arose during the mission were solved along the way.
Quirks & Quarks
- June 2: The Day the World Discovered the Sun Jun. 1, 2012 4:32 PM We'll look back at the Transit of Venus in 1769, which sparked a worldwide competition among aspiring global superpowers, each sending its own scientific expedition to far-flung destinations to track the transit, in order to measure the distance to the Sun.
Latest Features
- Body-parts victim a Chinese student in Montreal
- Edmonton teacher suspended for giving 0s
- Flooding closes Toronto subway hub Union station
- Owner defends 'gore' site connected to Luka Magnotta
- New duty-free limits will challenge Canadian retailers
- Copyright board to charge for music at weddings, parades
- Helicopter crash kills 3 near Terrace, B.C.
- Alberta teen hospitalized after fight involving dozens of students
- 2,000 jobs cut as GM to close Oshawa plant

