In today’s technological context, it is not unusual for information to be collected by an organization and kept by it in cryptographic form, so that only numbers or symbols appear. This common practice is generally encouraged and considered more secure, since its purpose is to protect personal and confidential information. Organizations may also outsource certain encrypted data for storage in the cloud.
Does such information, then, retain its personal character once encrypted? The question is crucial, because an organization has to know whether the rules protecting personal information apply, in order to determine how to handle its information flows. To answer it, we will set out the various legal definitions of personal information and offer an interpretation of what may constitute “identifiable” information in Québec, drawing on Canadian and European legal texts.
Personal information: a few definitions
In Québec, the Act respecting the protection of personal information in the private sector (“Private Sector Act”) provides that “any information which relates to a natural person and allows that person to be identified”[1] is personal information. In the same vein, information is personal where it is “information concerning a natural person which allows the person to be identified”[2] under the Act respecting Access to documents held by public bodies and the Protection of personal information (“Access Act”), which applies to Québec’s public sector. Federally, the Personal Information Protection and Electronic Documents Act (“PIPEDA”) defines personal information as “information about an identifiable individual, but does not include the name, title or business address or telephone number of an employee of an organization”[3]. Information must therefore allow a person to be identified in order to qualify as personal information within the meaning of the applicable statutes, and so possess an “identifiable” character.
As some jurists point out, it is not entirely clear whether the new forms of data that new technologies generate can be linked to an individual or not, and so qualify as personal information[4]. We must therefore assess how encrypted personal information retains its identifiable character and, with it, its personal character.
The “identifiable” character and its interpretation
The decision in Gordon v. Canada (Health) [5] provided an interpretation of the notion of an “identifiable individual”, concluding that there must be a serious possibility that an individual could be identified through the information, whether that information is taken on its own or in combination with other available data [6]. On that decision, information “about” an individual is information that “permits” or “makes possible” their identification, whether that information is used alone or combined with information from other sources. This includes sources to which the public has access, whatever their form and medium [7]. In line with Gordon [8], the Office of the Privacy Commissioner of Canada (“OPC”) takes the view that information may identify an individual “even where it exists in an unrecorded form, such as oral conversations, biological samples or real-time video surveillance” [9]. Moreover, “information is about an identifiable individual where there is a strong possibility that a person could identify the available information” [10].
The factors to consider
Conversely, “the mere hypothetical possibility of singling out a person” by means of some piece of information would therefore not be enough to consider that person identifiable [12]. Those are indeed the conclusions of the Article 29 Working Party, in Europe, which states that in determining whether a person is identifiable, “account should be taken of all the means likely reasonably to be deployed, either by the controller or by any other person, to identify the said person” [13]. The costs identification would entail, the purpose pursued, the way the processing is structured, the advantage expected by the controller, the interests at stake for the individuals, the risks of organizational dysfunctions (breaches of the duty of confidentiality, for example) and technical failures are among the factors taken into account in assessing all the means likely reasonably to be deployed [14].
It must therefore be difficult, if not impossible, for an organization to identify the individual by means of the encrypted information concerning them if that information is to lose its personal character[11]. In other words, a business holding the encryption key, or any other software allowing it to decrypt the personal information, will have a means of identifying a person.
As a practical example, Alberta’s Information and Privacy Commissioner has already concluded that a digital identifier stored in place of an original biometric datum remained personal information [15]. The business did, admittedly, have the technology allowing it to decrypt the data. The data was also combined with other personal information, which made the individual identifiable. In another matter, a Québec arbitrator likewise concluded that the binary result obtained after the algorithmic conversion of an employee’s hand measurements could be considered personal information [16]. It should be noted here that, since the purpose of processing the biometric data was precisely to identify individuals, the employer no doubt had a means of identifying them. On the other hand, “in a situation where this type of information (the binary result obtained after the algorithmic conversion of hand measurements) finds its way into the hands of a third party who has no other information allowing a correlation to be made between that information and an identifiable individual, it would then be harder to argue that it is in fact personal information within the meaning of the applicable privacy statutes”[17].
Conclusion
In the end, as long as there is a reasonable or serious possibility of linking encrypted personal information back to an individual, the information should be treated by the organization as personal information under the applicable statutes. We therefore believe that (1) encrypted information will be considered personal information if there is a reasonable possibility of decrypting it, whether within the organization or by a third party, and that (2) encrypted information kept together with other personal information about the same individual is likely to be held to be personal information, on what follows from the case law.
It is difficult, however, to argue that information encrypted and kept in isolation, with no other personal information associated with it, is identifiable and therefore personal. A host with no means of decrypting the data it keeps would not normally be obliged to treat the information as personal information. That information will nonetheless remain personal as regards the organization that holds control over it and over the encryption key.
The whole question will therefore turn on the context and on the interpretation of a serious possibility of identifying an individual by means of encrypted personal information, taking account of the means likely reasonably to be deployed. Each factual situation will have to be assessed in the light of the specific circumstances and of the privacy statutes applicable to the organization’s area of jurisdiction.
Other important points
-
The keys encrypting personal information will have to be protected by security measures that are effective, up to date and reliable throughout their life cycle. Otherwise, the higher risk of a security breach could open the door to a reasonable possibility that the encrypted information be identified.
-
A contract must govern the outsourcing of personal information between an organization and a subcontractor (or host).
[1] S. 2, Act respecting the protection of personal information in the private sector, R.S.Q., chapter P-39.1
[2] S. 54, Act respecting Access to documents held by public bodies and the Protection of personal information, R.S.Q., chapter A-2.1
[3] S. 2, Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5.
[4] Éloïse GRATTON, “Understanding Personal Information”, Lexis Nexis, 2013, p.32 and 114.
[5] Gordon v. Canada (Health), 2008 FC 258 (CanLII)
[8] Gordon v. Canada (Health), cited above, note 5.
[9] OFFICE OF THE PRIVACY COMMISSIONER OF CANADA, “Legal information related to PIPEDA”, concerning the definition of personal information. See also: Morgan v. Alta Flights Inc., (2006) FCA 121
[11] Éloïse GRATTON, cited above, note 4, p. 112: « On the other hand, if an organization has information about an individual, but it is impossible (or very difficult) for the organization to find out who the individual is, then the information is not personal information, and therefore not governed by DPLs ».
[12] ARTICLE 29 DATA PROTECTION WORKING PARTY, “Opinion 4/2007 on the concept of personal data”, adopted on 20 June, 01248/07/EN, WP 136, p.16.
[15] OFFICE OF THE INFORMATION AND PRIVACY COMMISSIONER, « Report of an Investigation into the Collection and Use of Personal Information, Empire Ballroom (1208558 Alberta Ltd.) », Investigation Report P2008-IR-005, Alberta, August 27th 2008.
[16] Syndicat des travailleurs de Mométal (C.S.N.) v. Mométal Inc., [2001] R.J.D.T. 1967 (T.A.)
[17] Éloïse GRATTON, « Chronique – Qu’est-ce qu’un renseignement personnel ? Le défi de qualifier les nouveaux types de renseignements », EYB2013REP128.
