<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Barry Sookman &#187; ECPA</title>
	<atom:link href="http://www.barrysookman.com/tag/ecpa/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.barrysookman.com</link>
	<description>Copyright, Intellectual Property, Computer, Internet, e-Commerce Law.</description>
	<lastBuildDate>Sat, 04 Feb 2012 13:30:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Draft FISA (Anti-SPAM) regulations published by CRTC and Industry Canada (updated)</title>
		<link>http://www.barrysookman.com/2011/07/18/draft-fisa-regulations-published-by-crtc/</link>
		<comments>http://www.barrysookman.com/2011/07/18/draft-fisa-regulations-published-by-crtc/#comments</comments>
		<pubDate>Mon, 18 Jul 2011 15:30:21 +0000</pubDate>
		<dc:creator>Barry Sookman</dc:creator>
				<category><![CDATA[E-commerce]]></category>
		<category><![CDATA[FISA]]></category>
		<category><![CDATA[CASL]]></category>
		<category><![CDATA[crtc reglations]]></category>
		<category><![CDATA[ECPA]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam regulations]]></category>

		<guid isPermaLink="false">http://www.barrysookman.com/?p=3282</guid>
		<description><![CDATA[The Canadian Anti-SPAM law (CASL or FISA) contemplated that regulations would need to be promulgated before the Act is proclaimed into force. CASL contemplated two sets of regulations: one from Industry Canada and the other from the CRTC.  The CRTC published draft regulations for comment purposes on June 30, 2011. The Commission will accept comments [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://laws-lois.justice.gc.ca/eng/acts/E-1.6/page-1.html">Canadian Anti-SPAM law </a>(CASL or FISA) contemplated that regulations would need to be promulgated before the Act is proclaimed into force. CASL contemplated two sets of regulations: one from Industry Canada and the other from the CRTC.  The CRTC published <a href="http://crtc.gc.ca/eng/archive/2011/2011-400.htm" target="_blank">draft regulations</a> for comment purposes on June 30, 2011. The Commission will accept comments from interested persons that it receives on or before September 7, 2011, a date <a href="http://www.crtc.gc.ca/eng/archive/2011/2011-400-1.htm">extended by the CRTC</a> from the original date of 29 August 2011.</p>
<p>The CRTC draft regulations are as follows:</p>
<blockquote><p><strong>1. </strong> In these Regulations, “Act” means <em>An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities, and to amend the Canadian Radio-television and Telecommunications Commission Act, the Competition Act, the Personal Information Protection and Electronic Documents Act and the Telecommunications Act</em>.</p>
<p>INFORMATION TO BE INCLUDED IN COMMERCIAL ELECTRONIC MESSAGES</p>
<p><strong>2. </strong> (1)   For the purposes of subsection 6(2) of the Act, the following information must be set out in any commercial electronic message:</p>
<p>(<em>a</em>)   the name of the person sending the message and the person, if different, on whose behalf it is sent;</p>
<p>(<em>b</em>)   if the message is sent on behalf of another person, a statement indicating which person is sending the message and which person on whose behalf the message is sent;</p>
<p>(<em>c</em>)   if the person who sends the message and the person, if different, on behalf of whom it is sent carry on business by different names, the name by which those persons carry on business; and</p>
<p>(<em>d</em>)   the physical and mailing address, a telephone number providing access to an agent or a voice messaging system, an email address and a web address of the person sending the message and, if different, the person on whose behalf the message is sent and any other electronic address used by those persons.</p>
<p>(2)   If it is not practicable to include the information referred to in subsection (1) and the unsubscribe mechanism referred to in paragraph 6(2)(<em>c</em>) of the Act in a commercial electronic message, that information may be provided by a link to a web page on the World Wide Web that is clearly and prominently set out and that can be accessed by a single click or another method of equivalent efficiency at no cost to the person to whom the message is sent.</p>
<p>FORM OF COMMERCIAL ELECTRONIC MESSAGES</p>
<p><strong>3.</strong> (1)   The information referred to in section 2 and the unsubscribe mechanism referred to in paragraph 6(2)(<em>c</em>) of the Act must be set out clearly and prominently.</p>
<p>(2)   The unsubscribe mechanism referred to in paragraph 6(2)(<em>c</em>) of the Act must be able to be performed in no more than two clicks or another method of equivalent efficiency.</p>
<p>INFORMATION TO BE INCLUDED IN A REQUEST FOR CONSENT</p>
<p><strong>4. </strong> For the purposes of subsections 10(1) and (3) of the Act, a request for consent must be in writing and must be sought separately for each act described in sections 6 to 8 of the Act and must include</p>
<p>(<em>a</em>)   the name of the person seeking consent and the person, if different, on whose behalf consent is sought;</p>
<p>(<em>b</em>)   if the consent is sought on behalf of another person, a statement indicating which person is seeking consent and which person on whose behalf consent is sought;</p>
<p>(<em>c</em>)   if the person seeking consent and the person, if different, on whose behalf consent is sought carry on business by different names, the name by which those persons carry on business;</p>
<p>(<em>d</em>)   the physical and mailing address, a telephone number providing access to an agent or a voice messaging system, an email address and a web address of the person seeking consent and, if different, the person on whose behalf consent is sought and any other electronic address used by those persons; and</p>
<p>(<em>e</em>)   a statement indicating that the person whose consent is sought can withdraw their consent by using any contact information referred to in paragraph (<em>d</em>).</p>
<p>SPECIFIED FUNCTIONS OF COMPUTER PROGRAMS</p>
<p><strong>5. </strong> A computer program’s material elements that perform one or more of the functions listed in subsection 10(5) of the Act must be brought to the attention of the person from whom consent is being sought separately from any other information provided in a request for consent and the person seeking consent must obtain an acknowledgement in writing from the person from whom consent is being sought that they understand and agree that the program performs the specified functions.</p></blockquote>
<p>Industry Canada published additional <a href="http://canadagazette.gc.ca/rp-pr/p1/2011/2011-07-09/html/reg1-eng.html">draft regulations</a> on July 8, 2011. There is also a 60 day period for commenting on these regulations. These draft regulatons read as follows:</p>
<blockquote><p>PERSONAL RELATIONSHIP AND FAMILY RELATIONSHIP</p>
<p><strong>2.</strong> For the purposes of paragraph 6(5)(<em>a</em>) of the Act</p>
<ol>
<li>(<em>a</em>) “family relationship” means the relationship between individuals who are connected by
<ol>
<li>(i) a blood relationship, if one individual is the child or other descendant of the other individual, the parent or grandparent of the other individual, the brother or sister of the other individual or of collateral descent from the other individual’s grandparent,</li>
<li>(ii) marriage, if one individual is married to the other individual or to an individual connected by a blood relationship to that other individual,</li>
<li>(iii) a common-law partnership, if one individual is in a common-law partnership with the other individual or with an individual who is connected by a blood relationship to that other individual; and</li>
<li>(iv) adoption, if one individual has been adopted, either legally or in fact, as the child of the other individual or as the child of an individual who is connected by a blood relationship to that other individual; and</li>
</ol>
</li>
<li>(<em>b</em>) “personal relationship” means the relationship, other than in relation to a commercial activity, between an individual who sends the message and the individual to whom the message is sent, if they have had an in-person meeting and, within the previous two years, a two-way communication.</li>
</ol>
<p>CONDITIONS FOR USE OF CONSENT</p>
<p><strong>3.</strong> (1) For the purposes of paragraph 10(2)(<em>b</em>) of the Act, a person who obtained express consent on behalf of a person whose identity was unknown may authorize any person to use the consent on the condition that the person who obtained consent ensures that, in any commercial electronic message sent to the person from whom consent was obtained,</p>
<ol>
<li>(<em>a</em>) the person who obtained consent is identified; and</li>
</ol>
<ol>
<li>(<em>b</em>) the authorized person provides an unsubscribe mechanism that, in addition to meeting the requirements set out in section 11 of the Act, allows the person from whom consent was obtained to withdraw their consent from the person who obtained consent or any other person who is authorized to use the consent.</li>
</ol>
<p>(2) The person who obtained consent must ensure that, on receipt of an indication of withdrawal of consent by the authorized person who sent the commercial electronic message, that authorized person notifies the person who obtained consent that consent has been withdrawn from, as the case may be,</p>
<ol>
<li>(<em>a</em>) the person who obtained consent;</li>
<li>(<em>b</em>) the authorized person who sent the commercial electronic message; or</li>
<li>(<em>c</em>) any other person who is authorized to use the consent.</li>
</ol>
<p>(3) The person who obtained consent must inform, without delay, a person referred to in paragraph 2(<em>c</em>) of the withdrawal of consent on receipt of notification of withdrawal of consent from that person.</p>
<p>(4) The person who obtained consent must give effect to a withdrawal of consent and, if applicable, ensure that a person referred to in paragraph 2(<em>c</em>) gives effect to the withdrawal of consent, in accordance with subsection 11(3) of the Act.</p>
<p>MEMBERSHIP, CLUB, ASSOCIATION AND VOLUNTARY ORGANIZATION</p>
<p><strong>4.</strong> (1) For the purposes of paragraph 10(13)(<em>c</em>) of the Act, membership is the status of having been accepted as a member of a club, association or voluntary organization in accordance with the membership requirements of the club, association or organization.</p>
<p>(2) For the purposes of paragraph 10(13)(<em>c</em>) of the Act, a club, association or voluntary organization is a non-profit organization that is organized and operated exclusively for social welfare, civic improvement, pleasure or recreation or for any purpose other than profit, if no part of its income is payable to, or otherwise available for the personal benefit of any proprietor, member or shareholder of that organization unless the proprietor, member or shareholder is an organization the primary purpose of which is the promotion of amateur athletics in Canada.</p></blockquote>
<p>*Updated after the Industry Canada draft regulations were published.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barrysookman.com/2011/07/18/draft-fisa-regulations-published-by-crtc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rethinking  FISA</title>
		<link>http://www.barrysookman.com/2011/05/25/rethinking-fisa/</link>
		<comments>http://www.barrysookman.com/2011/05/25/rethinking-fisa/#comments</comments>
		<pubDate>Wed, 25 May 2011 12:45:05 +0000</pubDate>
		<dc:creator>Lorne Salzman and Barry Sookman</dc:creator>
				<category><![CDATA[Bill C-28]]></category>
		<category><![CDATA[CASL]]></category>
		<category><![CDATA[ECPA]]></category>
		<category><![CDATA[Electronic Commerce Protection Act (ECPA)]]></category>
		<category><![CDATA[FISA]]></category>
		<category><![CDATA[FIWSA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[wppt]]></category>
		<category><![CDATA[maleware]]></category>
		<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[SPAM law]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.barrysookman.com/?p=3134</guid>
		<description><![CDATA[SPAM is awful.&#160; It wastes our time. It clogs the Internet. It is full of scams, malware and fraudulent, false and misleading messages. Who wouldn’t cheer when Canada finally decided late in 2010 to outlaw SPAM and related afflictions of malware, spyware, address harvesting and sending false and misleading commercial electronic messages?
Indeed, there was much [...]]]></description>
			<content:encoded><![CDATA[<p>SPAM is awful.&nbsp; It wastes our time. It clogs the Internet. It is full of scams, malware and fraudulent, false and misleading messages. Who wouldn’t cheer when Canada finally decided late in 2010 to outlaw SPAM and related afflictions of malware, spyware, address harvesting and sending false and misleading commercial electronic messages?</p>
<p>Indeed, there was much satisfaction when Canada’s anti-SPAM law, also known as FISA<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn2" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn2">[2]</a>, was given royal assent on December 15, 2011.&nbsp; After a lengthy and thorough review process, including consultations and Parliamentary reviews, Canadians could look forward to the toughest anti-SPAM law in the world just as soon as the regulations were finalized, which is expected this summer.</p>
<p>With FISA passed into law, and expected to come into force by the end of 2011, Canadian businesses started preparing for a new SPAM-reduced world. They began to scrutinize their use of emails, SMS and social network communication with existing and prospective customers. They looked at the language for obtaining consent from these customers, and for allowing them to unsubscribe. They reviewed the conditions for those customers that may have given implied consent. All of this scrutiny was expected.</p>
<p>Businesses also began to look closely at regulatory aspects of FISA. They began to appreciate the severe penalties for violating FISA, and thus the risks of failing to fully comply with the new requirements. Their interest in compliance increased further. And this too was expected.</p>
<p>But a funny thing happened on the way to the SPAM-free utopia.&nbsp; It began to dawn on some that FISA imposes very significant costs, not just on individual Canadian businesses, but also on the Canadian economy as a whole. These are costs that Canadians will uniquely bear because FISA is the toughest anti-SPAM law in the world.&nbsp; And while everyone understood that implementing FISA would not be cost-free, questions began to be asked about the balance of costs and benefits from complying with FISA.</p>
<p>During the past months, as we have helped numerous Canadian businesses understand FISA and its impact on their operations.&nbsp; In doing so, we have come to recognize that stakeholders did not fully appreciate just how costly this law would become for Canada or the dangers it poses to the Canadian economy.&nbsp; We acknowledge that FISA was thoroughly reviewed before it was passed into law.&nbsp; However, we have also come to recognize that rather than promoting the “efficiency and adaptability of the Canadian economy”, as formally stated in FISA’s official title, it may well achieve the opposite result.</p>
<p>In this commentary we will describe some of the challenges presented by FISA.&nbsp; We will focus on the anti-SPAM provisions, and leave for another day the anti-spyware and other provisions of FISA.</p>
<p>In summary, we have identified the following problems that need to be addressed before FISA’s regulations are finalized and the law is proclaimed into force:</p>
<blockquote><p>1)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FISA will impede start-up businesses from launching in Canada.</p>
<p>2)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FISA will impede Canadian businesses from developing new marketing models over the Internet.</p>
<p>3)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FISA will deter suppliers of service providers, including outsourcing and cloud service providers, from operating with or maintaining facilities in Canada.</p>
<p>4)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FISA will deter foreign businesses from offering their products to Canadians via the Internet, mobile and other communications networks.</p>
<p>5)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FISA will impose costs and restrictions on Canadian businesses that their competitors outside Canada will not have to bear.</p>
<p>6)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FISA contains very strong incentives for Canadian businesses to confess wrong-doing, even in cases of questionable or trivial conduct, thereby tarnishing the reputation of legitimate businesses in circumstances where the offending conduct is not significant.</p>
<p>7)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FISA will chill legitimate commercial speech and thereby undermine fundamental values protected by the <span mce_name="em" mce_style="font-style: italic;" style="font-style: italic;" class="Apple-style-span">Charter of Rights and Freedoms</span>.</p>
</blockquote>
<p>Our analysis starts with a brief background introduction to FISA.&nbsp; We then move on to discuss the problems we have observed.</p>
<p><span mce_name="strong" mce_style="font-weight: bold;" style="font-weight: bold;" class="Apple-style-span">Overview of FISA’s anti-SPAM provisions</span></p>
<p>The anti-SPAM and related provisions of FISA have their genesis in a 2005 federal government Task Force report: <span mce_name="em" mce_style="font-style: italic;" style="font-style: italic;" class="Apple-style-span">Stopping Spam: Creating a Stronger, Safer Internet</span>.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn3" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn3">[3]</a> The report included a range of recommendations to fight SPAM including more rigorous law enforcement, public education, policy development and legislation. Importantly, the Task Force made recommendations that formed the structure that eventually became FISA including:</p>
<ul>
<li>Commercial email sent without prior consent — or that is deceptive, fraudulent or malicious — is SPAM and should be prohibited.</li>
<li>Failure to abide by an opt-in regime for sending unsolicited commercial email should be made an offence in a stand-alone, technology-neutral SPAM statute.</li>
<li>The use of false or misleading headers or subject lines designed to disguise the origins, purpose or contents of an email should be made an offence. This should be the case whether the objective is to mislead recipients or to evade technological filters.</li>
<li>The new offences created should be civil and strict-liability offences, with criminal liability open for more egregious or repeated offences. There should be meaningful statutory penalties for all offences outlined above.</li>
<li>There should be an appropriate private right of action available to persons, both individuals and corporations. There should be meaningful statutory damages available to persons who successfully bring civil action.</li>
</ul>
<p>The Task Force recommendations, which by and large were carried over into FISA, were not just ambitious. They cast a wider net than legislation anywhere else in the world. For example, the U.S. CAN-SPAM Act of 2003<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn4" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn4">[4]</a> prohibits e-mails that are sent in violation of an individual’s opt-out request, or that are fraudulent, false or misleading. The EU Directive 2002/58/EC on privacy and electronic communications targets sending e-mail for the purposes of direct marketing to individuals. The Australia Spam Act 2003<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn5" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn5">[5]</a> and the New Zealand Unsolicited Electronic Messages Act 2007<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn6" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn6">[6]</a>, after which FISA’s provisions are most closely modelled (but with significant changes which make FISA more encompassing and more difficult to comply with), prohibit sending certain commercial electronic messages without the express or inferred consent of the recipient.</p>
<p>In contrast to the narrower approach of these other countries, FISA prohibits sending (or causing or permitting to be sent) any commercial electronic message to any electronic address unless express consent is given by the recipient, or certain specific exclusions apply.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn7" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn7">[7]</a></p>
<p>The exclusions are limited, and encompass the following: (1) some categories of electronic message are excluded completely; (2) some categories are excluded from the consent requirements, but they must still comply with certain formalities (for example, contain an unsubscribe mechanism); and (3) very similar to (2), some categories are deemed to have implied consent, although they must also comply with the formalities.</p>
<p>The totally excluded categories are: commercial electronic messages to an individual with whom the person stands in a personal or family relationship as defined in regulations; an inquiry or application to a person engaged in commercial activity; or messages of a class defined in regulations.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn8" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn8">[8]</a> There is a further exception for telecommunications service providers (TSPs) in their role as carriers.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn9" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn9">[9]</a> Messages related to law enforcement, public safety, the protection of Canada, the conduct of international affairs or the defence of Canada are excluded because they are deemed not to be part of a commercial activity.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn10" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn10">[10]</a></p>
<p>Then, there are categories of commercial electronic messages which do not require consent, but for which the prescribed formalities still apply, namely commercial electronic messages that solely involve the following: (a) provide a quote in response to a request; (b) are in furtherance of previously agreed to transactions; (c) provide warranty, safety, security, product recall information; (d) provide factual information about a purchase; (e) provide information about an employment or benefits plan; (f) deliver a product, service or upgrade; or (g) other exceptions specified in a regulation.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn11" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn11">[11]</a></p>
<p>The categories of commercial electronic messages for which there is deemed to be implied consent (and to which the prescribed formalities still apply) are limited to the following exclusive circumstances:</p>
<ul>
<li>There is “an existing business relationship” as this term is defined. In summary, this is a relationship arising from a purchase or barter within 2 years; acceptance of a business, investment or gaming opportunity with last 2 years; or is related to a contract until 2 years after expiry; or any inquiry or application within 6 months.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn12" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn12">[12]</a></li>
<li>There is an “existing non-business relationship” as this term is defined. In summary, this is a relationship arising from a donation or gift; volunteer work performed for a registered charity; or membership, within a 2 year window.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn13" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn13">[13]</a></li>
<li>The person to whom the message is sent has “conspicuously published”, or has caused to have published, an electronic address without a statement that the person does not wish to receive unsolicited commercial electronic messages at the electronic address and the message is relevant to the person’s business, role, functions or duties in a business or official capacity.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn14" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn14">[14]</a></li>
<li>The person to whom the message is sent has disclosed, to the person who sends the message, an electronic address without indicating a wish not to receive unsolicited commercial electronic messages, and the message is relevant to the person’s business, role, functions or duties in a business or official capacity.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn15" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn15">[15]</a></li>
<li>The message is sent in the circumstances set out in the regulations.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn16" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn16">[16]</a></li>
</ul>
<p>Commercial electronic messages that do not fall into one or more of the above exclusions cannot be sent except with the express consent of the recipient. Obtaining consent has its own requirements. When requesting consent, the sender must set out clearly and simply: (a) the purpose or purposes for which the consent is being sought; (b) information prescribed in regulations that identifies the person seeking consent and, if the person is seeking consent on behalf of another person, information prescribed in regulations that identifies that other person; and (c) any other prescribed information.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn17" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn17">[17]</a> Sending a message to obtain consent is deemed to be a commercial electronic message.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn18" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn18">[18]</a> As such, contacting a recipient to ask if the sender can send a commercial electronic message is itself SPAM (unless some exclusion applies).</p>
<p>Moreover, each commercial electronic message that is transmitted by a sender must abide by certain formalities which require the sender to: (a) set out prescribed information that identifies the person who sent the message and, if different, on whose behalf it is sent; (b) set out information enabling the person to whom the message is sent to readily contact the sender (the contact information must be valid for 60 days); and (c) set out the prescribed unsubscribe mechanism.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn19" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn19">[19]</a></p>
<p>The unsubscribe mechanism must (a) enable the recipient to indicate, at no cost to them, the wish to no longer receive any messages, or any specified class of such messages, from the sender, using (i) the same electronic means by which the message was sent, or (ii) if using those means is not practicable, any other electronic means that will enable the person to indicate the wish; and (b) specify an electronic address, or link to a page on the World Wide Web that can be accessed through a web browser, to which the indication may be sent.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn20" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn20">[20]</a></p>
<p>Having described the key elements of FISA, we will now describe some of the problems that we have encountered as Canadian businesses grapple with its implementation.</p>
<p><span mce_name="strong" mce_style="font-weight: bold;" style="font-weight: bold;" class="Apple-style-span">FISA Impedes Start-up Companies</span></p>
<p>Unlike established companies, start-up companies do not have a ready list of electronic contacts they can approach to market their products. Rather, they will develop emailing lists from a variety of sources and use them to launch their products. For example, a newly graduated financial advisor may look up the lawyers and doctors in his/her neighbourhood using a published professional or business directory or other publication such as a magazine, book, or newspaper and invite them to an educational event. A newly established orthodontist may send an announcement to dentists in her town, with the electronic addresses derived from a conference attendance list. A university student wanting to earn some money as a contract programmer may contact professors and lecturers using their electronic addresses found in the university catalogue or telephone directory. A new real estate agent in search of listings may want to contact owners of properties using information recorded in publically available registries.</p>
<p>Although few would find these activities offensive, they will all likely be illegal under FISA.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn21" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn21">[21]</a> Rather than using electronic communications, business start-ups will therefore be forced to send their messages using the post or other more expensive and less convenient and efficient mechanisms, or limit the persons to whom they can send messages to the limited exception that permits use of conspicuously published e-mail addresses.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn22" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn22">[22]</a> The new start-ups could also not rely on the alternative route of using software that is design to assist them in searching for relevant business or other connections because it will also be illegal to use such software or electronic addresses gathered using such software under the amendments to PIPEDA included in FISA.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn23" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn23">[23]</a></p>
<p>Although it is easy to say that the FISA impositions on small businesses are not that important, most countries, Canada included, actively promote small business formation and expansion. Policy-makers understand that small business is a vital part of the economy in its own right and, as well, that all big businesses were small start-ups at one point.&nbsp; As such, Canada should not want to impede start-up businesses from making effective use of digital communications to launch and sustain their businesses.</p>
<p><span mce_name="strong" mce_style="font-weight: bold;" style="font-weight: bold;" class="Apple-style-span">FISA Impedes Use of New Forms of Communications and Business Models</span></p>
<p>FISA is supposed to be technologically neutral, applying broadly to practically all electronic means of sending electronic messages. However, the FISA regulatory regime (which prescribes specific formalities for each message) is modelled on regulating electronic messages that are sent as emails. This focus on emails means that other forms of electronic messaging, such as those through social networks, do not easily fit within the FISA framework. As a result, Canadian businesses that wish to exploit new and developing alternative electronic messaging systems will be impeded by FISA.</p>
<p>As an example, consider an enterprise that wishes to send its commercial electronic messages, with express consent, by SMS.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn24" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn24">[24]</a> Because SMS only allows for 140 characters, it will be very difficult if not impossible in the allotted number of characters to include all of the formalities required for commercial electronic messages. The SMS message would have to include (a) prescribed information that (1) identifies the sender and (2) any person on whose behalf the message is sent, (b) information that enables the recipient to (1) contact the sender or (2) the person on whose behalf the message was sent, and (c) an unsubscribe mechanism that (1) enables the recipient to indicate, at no cost to him/her a wish to no longer receive messages (which could be at a separate web location), and (2) specifies an electronic address or link to the web which can be used to unsubscribe from receiving further messages.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn25" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn25">[25]</a> Consider the following difficulties when trying to utilize SMS for a commercial electronic message:</p>
<ul>
<li>Can conditions (a)(2), (b)(2), and (c)(2) be met in a message that is only 140 characters?&nbsp; Some URLs could be as long as the message itself.&nbsp; The same problem will arise in other messaging services where short messages are the rule, such as <span mce_name="em" mce_style="font-style: italic;" style="font-style: italic;" class="Apple-style-span">Instant Messaging</span> (IM) services.</li>
<li>Where the recipient uses a regular cell phone, not a smart phone, an unsubscribe URL is likely not accessible by the phone to effect an unsubscribe instruction.&nbsp; Is it still a compliant message?&nbsp; If not, how can the sender ever know if its messages are compliant given that the sender will not know what sort of device the recipient is using?</li>
<li>Where the sender wants to permit recipients to unsubscribe using a text message at no cost to the recipient<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn26" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn26">[26]</a>, this will require negotiations with all mobile operators to ensure that the recipient is not charged for the unsubscribe message – a very cumbersome approach.</li>
<li>Further, it may be challenging for a person using any of these messaging services to seek express consents from recipients using 140 characters given the request for the consent must “clearly and simply” provide information setting out the purpose or purposes for which consent is being requested, information that identifies the requester and another person on whose behalf the request is made, and other prescribed information.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn27" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn27">[27]</a></li>
</ul>
<p>The result is that unless accommodation is made by means of the regulations or amendment to the legislation, FISA could make using new and innovative short messaging platforms effectively impractical to use in Canada for whole categories of commercial speech.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn28" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn28">[28]</a></p>
<p>As another example, consider the situation of a social network that allows a recruiter to search the profiles of members looking for suitable employee prospects, who the recruiter then contacts using the social network built-in communications tools. Many members would welcome such communications, and therefore they would likely consent to such recruitment messages, presumably at sign-up time. However, FISA’s design does not easily accommodate such a situation. The recruiter cannot directly request consent to send a message to a member of the social network because that message would be deemed to be a commercial electronic message.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn29" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn29">[29]</a> The social network could try and obtain the member’s consent for the recruiter to send such messages. However, FISA contemplates that the consent request must include identification information about the person on whose behalf the consent is being obtained, in this case the recruiter’s identity.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn30" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn30">[30]</a> But is this workable when the identity of the recruiter(s) will only be known much after the consent is granted? Faced with this complexity and uncertainty, recruiters and their social network partners may well ponder if they should avoid offering these services in Canada.</p>
<p>Consider another business model where a virtual gaming site allows members to offer to buy and sell virtual objects amongst themselves. Does each member have to obtain consent from the other members before the messages are sent? Can the social network site request consent in advance for all such messages among members? Bear in mind that the members only disclose game-playing aliases and not their real identities. How then can the identification requirements of FISA be satisfied? How practical is it for each game-player to include an unsubscribe mechanism in every buy-sell offer? If members fail to comply with these identification or unsubscribe mechanisms, will be social network operator have to enforce these requirements in order to avoid liability for aiding in a contravention of FISA? Will the operators of such sites be concerned that they could face accessorial liability for not designing mechanisms to enable&nbsp; their players to comply with FISA? Will they make necessary changes to their games or simply exclude Canadians from being able to join their networks?</p>
<p>Consider next a business model where a social network operator offers business coupons to members and encourages the members to pass the coupons on to friends and social media contacts.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn31" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn31">[31]</a> As an incentive, the operator grants a modest incentive to the member for every person that uses such a passed-on coupon. The passing on of the coupon with an express or implied suggestion as its use is likely the sending of a commercial electronic message. While some recipients in these models may fit into the personal or family relationship exemption in FISA,<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn32" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn32">[32]</a> others won’t necessarily fall within these so far undefined categories. And how many members are likely to include unsubscribe mechanisms when sending such messages to their contacts? Although one might be tempted to say that no-one will pursue the members for such trivial transgressions of FISA, the operator that knowingly permits such conduct might well worry if it will be at risk of being accused of aiding, inducing, procuring or causing to be procured the doing of any act contrary to the anti-SPAM provisions of FISA.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn33" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn33">[33]</a></p>
<p>Faced with the risks of offending FISA, Canadian businesses will be wary of developing (or continuing to offer) these innovative business models or implementing similar models that are legal in other countries such as the United States. Or if they do wish to develop them, they will feel a strong incentive to develop and launch them outside of Canada. The logical port of call for any such developers will be the United States, with its familiarity to Canadians, vast market, openness to innovation, and ample sources of funding. Canada, which already faces a tough time in fostering innovation inside our borders, will now be adding one more reason for Canadians to take their digital economy initiatives south of the border.</p>
<p><span mce_name="strong" mce_style="font-weight: bold;" style="font-weight: bold;" class="Apple-style-span">FISA Will Deter Service Providers from Locating in Canada </span></p>
<p>In the foregoing, we have explained impediments that will be faced by start-ups and developers of new e-commerce models as a result of FISA. But the potential harm to the Canadian economy goes further. FISA will deter many suppliers from providing innovative services globally using Canadian facilities.</p>
<p>Consider the case of a data centre operator that is deciding where to locate a new server farm.&nbsp; If the operator decides to locate it in Canada, the customers that send electronic commercial messages from those servers will be subject to FISA for all of those communications – even those where the company is non-Canadian and the recipients are all non-Canadian. This consequence arises because FISA applies if a computer system in Canada is used to <u style="">send or receive</u> the electronic message.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn34" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn34">[34]</a> The data centre operator will realize that its customer base will be immediately narrowed if the server farm is located in Canada and knowledgeable customers will ask the operator that servers in Canada not be used for their commercial electronic communication purposes.</p>
<p>For the same reasons, FISA will also deter businesses from operating or using cloud services that have facilities in Canada. In an era of ever-increasing reliance on “cloud computing”, where operators organize servers in the most efficient manner, operators and their customers would avoid locating cloud services with facilities in Canada to avoid burdening their foreign customers with onerous obligations they would not have, and their foreign competitors will not have, if their facilities were located outside of Canada.</p>
<p>Likewise, operators of messaging systems such as e-mail services, social networks, and e-commerce platforms that serve North American or global enterprises will have a strong reason to avoid locating their facilities in Canada to ensure that their global users are not regulated by FISA. They would likely relocate existing Canadian facilities outside of Canada to avoid requiring their non-Canadian customers having to bear costs and expenses of complying with laws that their competitors do not face.</p>
<p>Even established Canadian businesses, especially global ones, might decide that it is in their interest to locate their servers, whether in-house or outsourced, outside the country. Many of them will send commercial electronic communications to non-Canadians. They will not want to take on the FISA-derived extra costs and restrictions associated with communicating with those non-Canadians from a Canadian server. Faced with the choice of two servers, one in Canada for FISA-complaint Canadian messages, and one outside Canada for everything else, many Canadian companies will decide that the most efficient approach is to ensure that all their&nbsp; servers are located outside Canada.</p>
<p>By discouraging service suppliers from locating or maintaining facilities in Canada, not only does Canada lose the jobs, taxes and spin-off activities from such businesses, but Canada’s participation in a core building block of the digital economy is reduced. This in turn lessens the attractiveness of Canada as a location for other participants in the digital economy.</p>
<p><span mce_name="strong" mce_style="font-weight: bold;" style="font-weight: bold;" class="Apple-style-span">FISA Will Deprive Canadians of Products and Services From Foreign Businesses </span></p>
<p>In the foregoing discussion, we have concentrated on the impact of FISA on Canadian businesses and suppliers to those businesses. But there is another constituency that will be impacted by FISA, namely consumers.</p>
<p>FISA will of course benefit consumers by hopefully reducing the flow of SPAM. That is the key purpose behind FISA. But consumers will be negatively impacted by FISA if they cannot benefit from worthwhile commercial electronic messages simply because foreign companies are unwilling to comply with FISA and thus decide simply to exclude Canadians from their electronic communication databases. We have been told by some businesses that the costs of developing specific marketing campaigns for Canadians could influence whether foreign businesses make the same offers to Canadians that they make to their customers in other countries.</p>
<p>The point to realize is that not all commercial electronic messaging is bad and unwanted (although some is undoubtedly both). Some is benign, and some may be quite useful. Indeed, in the example above of a recruiter using social media platforms to contact prospective employees, some may be very welcome.</p>
<p>FISA however risks walling off Canada from the good as well as the bad. And foreign companies, especially international companies that market and promote products and services on a global basis from outside Canada, may well decide that Canada is simply not worth the effort and hazards that come with FISA.</p>
<p><span mce_name="strong" mce_style="font-weight: bold;" style="font-weight: bold;" class="Apple-style-span">FISA Imposes Costs on Canadian Businesses that Foreign Competitors will not Bear </span></p>
<p>Canadian businesses are coming to grips with the costs of FISA compliance, and it is not a happy realization. Businesses that have large contact lists must assess which contacts fit into particular categories: exempt, express consent, implied consent, no consent. The exempt category will be small for most businesses. Where express consent has been given, businesses have to figure out if the consent is sufficient for FISA purposes, now and in the future. Absent express consent, businesses will have to determine if one of the listed categories of an implied consent can apply.&nbsp; This will be difficult to assess in many cases.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn35" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn35">[35]</a> For example, where an individual was entered onto a contact list 5 years ago, how will a business determine if that person voluntarily disclosed his/her email address, or whether it was “conspicuously published” or if there exists an existing business relationship that is less than 2 years old? If the existing business relationship heading is relied on, what sort of routines are in place to determine customer-by-customer when the 2-year window expires? The answer to each of these question can be determined, but at a cost – a cost that can be significant for a company with thousands or even millions of contacts.</p>
<p>It may be simple to suggest that businesses should just communicate with everyone on their contact lists and ask for express consent. But the response rate from such campaigns is often not large, and Canadian businesses risk a large contraction of their contact lists, with a consequential impact on their business models. In some cases, such as the social network recruiter described earlier, it is questionable if a consent approach is even workable. And, of course, once FISA comes into force, communicating with a contact to ask for consent will itself be prohibited unless some exemption or implied consent applies.</p>
<p>Further, as noted above, Canadian businesses with substantial numbers of non-Canadian contacts will face costs of moving their servers outside of Canada in order to service these non-Canadians, and likely Canadians as well. In the same vein, those Canadian businesses will have to give up any use of cloud computing that involves Canada-based servers if there is a chance that some commercial electronic messaging could originate on servers in Canada.</p>
<p>Canadian businesses will also face extra costs as ongoing customers unsubscribe from commercial electronic messages.&nbsp; The FISA-mandated&nbsp; unsubscribe mechanism must permit the recipient to not receive <u style="">any</u> commercial electronic messages, or any specified class of messages.&nbsp; If even a handful of customers choose the broad unsubscribe option, companies will have to either change their systems to ensure that innocuous commercial electronic messages are not included in ordinary correspondence such as billing statements (consider, for example, a mention that mortgage rates are being reduced which appears in a bank account statement with an offer to extend the mortgage term), or ensure that such correspondence is sent to those customers by the post or other non-electronic means. All of this can be done, but clearly at a cost.&nbsp; The problem would be compounded for businesses that contract with their customers only to communicate electronically.&nbsp; Customers including B2B business partners could arguably use FISA’s unsubscribe right to require communications in a different format and to thereby trump contractually agreed to terms.&nbsp; This could undermine purely electronic means of doing business (including data interchange arrangements) and force companies to cease doing business with any person insisting on an unsubscribe right or to incur substantial costs to do business in less modern and inefficient way.</p>
<p>In addition to costs of these proactive activities, Canadian businesses will face potentially large costs of after-the fact compliance by way of substantial fines and class action damages, and associated legal costs, as further discussed below.</p>
<p>In contrast, most non-Canadian competitors do not face equivalent costs. Although some may elect to comply with FISA for their Canadian contacts, others may simply abandon services to Canadians. Others will likely just ignore FISA, expecting that the Canadian regulators will have neither the inclination nor resources nor the jurisdiction to pursue these offenders.</p>
<p><span mce_name="strong" mce_style="font-weight: bold;" style="font-weight: bold;" class="Apple-style-span">FISA’s Enforcement Model is Biased Towards Excessive Fault-Finding, which will Tarnish Legitimate Businesses</span></p>
<p>The penalties for violating FISA are severe. Companies can be subject to fines<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn36" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn36">[36]</a> of up to $10 million per violation. The regulations may specify that violations are a day-by-day determination.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn37" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn37">[37]</a> Officers and directors can be liable, whether or not the corporation is prosecuted.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn38" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn38">[38]</a> If the CRTC does not initiate proceedings, companies can be liable to private action by SPAM recipients, including (most worryingly) class action claims, for actual damages (which will likely be insignificant), but also an additional private fine of up to $1 million per day (which is not so insignificant).<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn39" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn39">[39]</a></p>
<p>The fear of class action claims, which can be very expensive to defend against, will act as a strong incentive for companies to self-report potential contraventions to the CRTC and submit to voluntary undertakings and fines. Entering into such an undertaking with the CRTC will exempt the contravention from private action liability.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn40" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn40">[40]</a> Although this incentive will help ensure FISA compliance, its undoubted goal, it will also encourage companies to confess wrong-doing in situations where the impugned conduct may be questionable or trivial. This will lead to a parade of Canadian businesses being punished under FISA, with the regulators extolling their enforcement proficiency against these wrong-doers.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn41" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn41">[41]</a> As such, the public image of many Canadian businesses will be unfairly tarnished in circumstances where the offending conduct may not be significant.</p>
<p><span mce_name="strong" mce_style="font-weight: bold;" style="font-weight: bold;" class="Apple-style-span">Is It Right To Extensively Chill Commercial Electronic Communications?</span></p>
<p>In the proceeding pages, we have explained the negative impact that FISA will have on Canadian businesses and consumers. But there is a larger question that should also be asked. Is it right to so extensively curtail Canadian businesses from engaging in commercial electronic communication, which is, after all, a form of commercial free speech? This is a big question, with clear constitutional overtones. But it is a question that should be asked.</p>
<p>FISA’s regulatory approach to SPAM is to broadly ban all commercial electronic messages unless the messages are sent with prior express consent or fall into an excluded category. The regulatory regime does not focus, as do most laws that restrict the free speech of Canadians, on prohibiting actions that are necessarily unwanted, false, fraudulent, misleading or otherwise harmful. It is therefore inevitable that sending some legitimate, wanted, and economically and socially useful commercial speech will be rendered illegal.</p>
<p>FISA’s curtailment of commercial speech is apparent in a number of ways.</p>
<ul>
<li>The prohibitions on commercial speech are not narrowly tailored to a limited class of electronic communications that are more likely than not to be unwanted or harmful such as direct marketing, pornography, messages sent to consumers that misuse personal information, or messages that are false, fraudulent, or misleading.</li>
<li>Because FISA extends to “any particular transaction, act or conduct or any regular course of conduct that is of a commercial character, whether or not the person who carries it out does so in the expectation of profit”, it will extend to activities of not-for-profit entities, educational institutions, charities, private clubs, and political fundraising activities, subject the specific exceptions that only partially exclude some of their commercial electronic messages.</li>
<li>A message that is, on balance, benign or useful, will nonetheless be caught by FISA if only one of the message’s many purposes would encourage participation in a commercial activity.</li>
<li>FISA’s anti-SPAM provisions provide for extensive accessorial and vicarious liability Under FISA, liability extends to any person who aids, induces or procures a prohibited act.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn42" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn42">[42]</a> Businesses are liable for acts of their employees within the scope of their authority.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn43" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn43">[43]</a> The liability also extends to officers, directors, agents, and mandataries if they “directed, authorized, assented to, acquiesced, or participated in the prohibited act”.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn44" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn44">[44]</a></li>
<li>A direct result of the “ban-all” approach taken in FISA will be to shift the onus onto individuals and businesses to find an exception that would permit their sending electronic messages. However as described above, FISA also has extremely tough sanctions that can be levied against individuals or businesses that violate its prohibitions. These sanctions will undoubtedly deter individuals and businesses from sending messages in circumstances where it is unclear they are entitled to do so.</li>
</ul>
<p>The Canadian <span mce_name="em" mce_style="font-style: italic;" style="font-style: italic;" class="Apple-style-span">Charter of Rights and Freedoms</span> protects free speech as one of our highest legal and societal imperatives.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn45" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn45">[45]</a> The courts have recognized that Canadian businesses benefit from this protection and that commercial speech benefits Canadian consumers.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn46" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn46">[46]</a> While limits on free speech are clearly permitted, these limits should be reasonable and justified, with minimal impairment of the free speech right and with the limit on free speech being in proportion to the harm that is being targeted.&nbsp; As we have come to better understand how companies will be required to operate under FISA, questions indeed arise as to whether this important principle has been given appropriate regard.</p>
<p><span mce_name="strong" mce_style="font-weight: bold;" style="font-weight: bold;" class="Apple-style-span">Where Should We Go From Here?</span></p>
<p>Recognizing that it may be too late to revise the FISA legislation, developing sensible regulations will be of paramount importance as many of the deficiencies that we have discussed can be remedied in the regulations. For example, FISA provides significant flexibility to for the regulations to exclude classes of commercial electronic messages from its scope.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn47" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn47">[47]</a> FISA also enables the government to create, by regulation, new broad categories of implied consent.<a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn48" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn48">[48]</a> Employing the regulation process in this remedial manner should not be seen as undermining the basic thrust of FISA, which is to reduce the volume of SPAM, but rather as properly aligning FISA’s benefits with its costs.</p>
<p>To conclude, we believe that it is time to re-examine FISA – and to do so before the regulations are finalized and FISA is proclaimed into law. Failing to undertake such a review, and to make appropriate changes through regulation or otherwise, risks imposing significant burdens on Canadian businesses and depriving Canadians of beneficial services, thereby undermining the promotion of “the efficiency and adaptability of the Canadian economy” that FISA calls for. Other countries have managed to discover a different and more proportionate balance between thwarting SPAM and not impeding legitimate electronic messaging. Canada should seek to do likewise.</p>
<hr size="1">
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref1" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref1">[1]</a> Lorne Salzman and Barry Sookman are lawyers with McCarthy Tétrault LLP.</p>
<p></p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref2" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref2">[2]</a> FISA is the acronym for “Fighting Internet and Wireless Spam Act”, a title bestowed in an early version of the legislation that was eventually passed by the Canadian Parliament. Unfortunately (and unusually), the final version did not include any such short-form title. Accordingly, some commentators refer to FISA, while others refer to “CASL”, which is the acronym for Canadian Anti-Spam Legislation, while others employ yet other titles and abbreviations. For ease of understanding, we will use the term “FISA” in this commentary.</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref3" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref3">[3]</a> Available at www.ic.gc.ca/eic/site/ecic-ceac.nsf/eng/h_gv00317.html</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref4" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref4">[4]</a> www.ftc.gov/bcp/edu/microsites/spam/rules.htm</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref5" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref5">[5]</a> www.austlii.edu.au/au/legis/cth/consol_act/sa200366/</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref6" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref6">[6]</a> www.legislation.govt.nz/act/public/2007/0007/latest/DLM405134.html</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref7" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref7">[7]</a> The breadth of FISA’s prohibitions can be seen from looking at the definitions:</p>
<p>• An “electronic message” is an open ended list of message types: a “message sent by any means of telecommunication, including a text, sound, voice or image message”.</p>
<p>• An “electronic address” is an open ended list of types of addresses to which messages may be sent; it is “an address used in connection with the transmission of an electronic message to (a) an electronic mail account; (b) an instant messaging account; (c) a telephone account; or (d) any similar account”.</p>
<p>• A “commercial electronic message” is an open ended list of electronic messages “that, having regard to the content of the message, the hyperlinks in the message to content on a website or other database, or the contact information contained in the message, it would be reasonable to conclude has as its purpose, or one of its purposes, to encourage participation in a commercial activity, including an electronic message that (a) offers to purchase, sell, barter or lease a product, goods, a service, land or an interest or right in land; (b) offers to provide a business, investment or gaming opportunity; (c) advertises or promotes anything referred to in paragraph (a) or (b); or (d) promotes a person, including the public image of a person, as being a person who does anything referred to in any of paragraphs (a) to (c), or who intends to do so.” An electronic message that contains a request to send a prohibited message is also deemed to be a prohibited commercial electronic message.</p>
<p>• A “commercial activity” is also broadly defined to mean “any particular transaction, act or conduct or any regular course of conduct that is of a commercial character, whether or not the person who carries it out does so in the expectation of profit”. It excludes “any transaction, act or conduct that is carried out for the purposes of law enforcement, public safety, the protection of Canada, the conduct of international affairs or the defence of Canada”.</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref8" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref8">[8]</a> s. 6(5)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref9" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref9">[9]</a> s. 6(7)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref10" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref10">[10]</a> s. 1(1)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref11" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref11">[11]</a> s. 6(6)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref12" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref12">[12]</a> ss. 10(9) and 10(10)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref13" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref13">[13]</a> ss. 10(9) and 10(13)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref14" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref14">[14]</a> s. 10(9)(b)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref15" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref15">[15]</a> s. 10(9)(c)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref16" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref16">[16]</a> s. 10(9)(d)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref17" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref17">[17]</a> s. 10(1)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref18" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref18">[18]</a> s. 1(3)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref19" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref19">[19]</a> ss. 6(2) and 6(3)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref20" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref20">[20]</a> ss. 11(1) and 11(2)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref21" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref21">[21]</a> Despite problems under FISA, collecting personal information from some of the sources described above would likely be permissible under PIPEDA (Canada’s federal privacy law) pursuant to regulations which permit the collection, use and disclosure of personal information that is publically available. See, Regulations Specifying Publicly Available Information, P.C. 2000-1777 13 December, 2000, <a href="http://www.gazette.gc.ca/archives/p2/2001/2001-01-03/html/sor-dors7-eng.html" mce_href="http://www.gazette.gc.ca/archives/p2/2001/2001-01-03/html/sor-dors7-eng.html">http://www.gazette.gc.ca/archives/p2/2001/2001-01-03/html/sor-dors7-eng.html</a></p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref22" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref22">[22]</a> s. 10(9)(b). This section has some overlap with the PIPEDA publically available exception. However, the FISA exception is limited to where the recipient “has conspicuously published, or caused to be conspicuously published”, the electronic address. It would seem to clearly apply where an individual publishes his/her email address on a web site. It is much less clear that it applies where an individual gives his/her email address to an organization and the organization publishes the email address in a directory or other publication. To fall within the exception one would have to conclude that by giving an organization an email address, the person who provides the email address “causes” the organization to publish it – which may be somewhat of a stretch.</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref23" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref23">[23]</a> s. 82 (adding new s. 7.1(2) to PIPEDA)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref24" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref24">[24]</a> Short Message Service (SMS) is a text-based data communications service typically used in connection with cell phones and smart phones.</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref25" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref25">[25]</a> ss. 6(2) and 11(1)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref26" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref26">[26]</a> s. 11(1).</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref27" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref27">[27]</a> s. 10(1).</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref28" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref28">[28]</a> For a real life example of an entrepreneur who recently used Twitter service as a pivotal aid in launching a new business, see: www.thestar.com/business/smallbusiness/article/985678&#8211;twitter-marketing-word-of-mouth-on-steroids</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref29" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref29">[29]</a> s. 1(3). It does not appear that this approach would fall within any of the existing exceptions including the exception for inquiries (s. 6(5)(b)). The message would be an inquiry, but would not necessarily be an inquiry related to the commercial activity of the recipient. It would not fall into the employment benefits exception either. (s. 6(6)(e)).</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref30" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref30">[30]</a> s. 10(1). The upcoming regulations are expected to address the identification information that will be required.</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref31" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref31">[31]</a> Other innovative businesses also use variations on the “refer a friend” business model.</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref32" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref32">[32]</a> s. 6(5)(a)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref33" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref33">[33]</a> s. 9</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref34" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref34">[34]</a> s. 12(1)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref35" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref35">[35]</a> Consents obtained under PIPEDA cannot be relied upon given PIPEDA recognizes opt-out consents in many circumstances.</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref36" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref36">[36]</a> Technically, the fines are referred to as “administrative monetary penalties”. Quaintly, FISA states that these penalties are “to promote compliance” but not “to punish”. See s. 20.</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref37" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref37">[37]</a> s. 20(5)(a)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref38" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref38">[38]</a> s. 52. Note that there is a “due diligence” defence that may be available in some cases to companies and their staff. See s.54(1)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref39" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref39">[39]</a> s. 51(1)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref40" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref40">[40]</a> s. 48(1)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref41" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref41">[41]</a> As an example of the CRTC’s press releases when it punishes offenders of the do-not-call regime, see www.crtc.gc.ca/eng/com100/2010/r101217.htm</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref42" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref42">[42]</a> s. 9</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref43" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref43">[43]</a> ss. 32 and 53</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref44" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref44">[44]</a> ss. 31 and 52</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref45" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref45">[45]</a> See s. 2(b) of the Charter.</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref46" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref46">[46]</a> See <span mce_name="em" mce_style="font-style: italic;" style="font-style: italic;" class="Apple-style-span">RJR-MacDonald Inc. v. Canada (Attorney General)</span>, [1995] 3 S.C.R. 199; <span mce_name="em" mce_style="font-style: italic;" style="font-style: italic;" class="Apple-style-span">Rocket v. Royal College of Dental Surgeons of Ontario</span>, [1990] 2 S.C.R. 23.</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref47" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref47">[47]</a> s. 6(5)(c)</p>
<p><a href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref48" mce_href="http://www.barrysookman.com/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftnref48">[48]</a> s. 10(9)(d)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barrysookman.com/2011/05/25/rethinking-fisa/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Name Canada’s Anti-Spam/Anti-Spyware Law</title>
		<link>http://www.barrysookman.com/2011/02/06/name-canada%e2%80%99s-anti-spamanti-spyware-law/</link>
		<comments>http://www.barrysookman.com/2011/02/06/name-canada%e2%80%99s-anti-spamanti-spyware-law/#comments</comments>
		<pubDate>Mon, 07 Feb 2011 01:35:01 +0000</pubDate>
		<dc:creator>Barry Sookman</dc:creator>
				<category><![CDATA[Bill C-28]]></category>
		<category><![CDATA[Bill C-58]]></category>
		<category><![CDATA[E-commerce]]></category>
		<category><![CDATA[Electronic Commerce Protection Act (ECPA)]]></category>
		<category><![CDATA[FISA]]></category>
		<category><![CDATA[FIWSA]]></category>
		<category><![CDATA[misleading advertising]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[ECPA]]></category>
		<category><![CDATA[Electronic Commerce Protection Act]]></category>
		<category><![CDATA[spam bill]]></category>

		<guid isPermaLink="false">http://www.barrysookman.com/?p=2644</guid>
		<description><![CDATA[Canada has a new anti-SPAM and anti-spyware law, Bill –C-28. It is a law with an inordinately long name: “An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities, and to amend the Canadian Radio-television and Telecommunications Commission [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 13.3333px;">Canada has a new anti-SPAM and anti-spyware law, <a href="http://www2.parl.gc.ca/HousePublications/Publication.aspx?Language=E&amp;Parl=40&amp;Ses=3&amp;Mode=1&amp;Pub=Bill&amp;Doc=C-28_4">Bill –C-28</a>. It is a law with an inordinately long name: “An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities, and to amend the Canadian Radio-television and Telecommunications Commission Act, the Competition Act, the Personal Information Protection and Electronic Documents Act and the Telecommunications Act”.</span></p>
<p>The Bill has no short title. As a result different terms and acronyms are being used to refer to it including the ECPA, FISA, FIWSA, the SPAM Bill, the Anti-SPAM Legislation, and the Anti-SPAM and Anti-Spyware Bill.</p>
<p>The Bill needs a short title we can all agree on. I am asking you to help decide what we call it.</p>
<p><strong>Some Background</strong></p>
<p>On April 24, 2009, the Government introduced <a href="http://www2.parl.gc.ca/HousePublications/Publication.aspx?DocId=3832885&amp;Language=e&amp;Mode=1">Bill C-27</a>. It had a short title called <em>the Electronic Commerce Protection Act</em>. Its acronym was the ECPA. It received second reading in the House of Commons. The ECPA died on the Order Paper, however, when it reached the stage of second reading in the Senate, due to the prorogation of Parliament on December 30, 2009.</p>
<p>On 25 May 2010, the Government introduced Bill C-28. This bill was based substantially on Bill C-27. At <a href="http://www2.parl.gc.ca/HousePublications/Publication.aspx?Language=E&amp;Parl=40&amp;Ses=3&amp;Mode=1&amp;Pub=Bill&amp;Doc=C-28_1&amp;File=32%22%20%5Cl%20%221">first reading</a> in the House of Commons, the short title of the Bill was <em>Fighting Internet and Wireless Spam Act</em>. It was also known by the acronyms <a href="http://www.canadiantechnologyiplaw.com/2010/06/articles/privacy/canadian-government-reintroduces-antispam-legislation/">FIWSA</a> or <a href="http://www2.parl.gc.ca/Sites/LOP/LegislativeSummaries/Bills_ls.asp?lang=E&amp;ls=c28&amp;source=library_prb&amp;Parl=40&amp;Ses=3">FISA</a>.<span style="font-size: 13.3333px;"> </span></p>
<p>Bill C-28 was reviewed by the <a href="http://www2.parl.gc.ca/HousePublications/Publication.aspx?DocId=4754401&amp;Language=E&amp;Mode=1&amp;Parl=40&amp;Ses=3">Standing Committee on Industry, Science and Technology</a>. On Tuesday, November 2, 2010, the Committee voted to amend the Bill to remove the short title. The amendment was initiated by NDP MP Brian Masse during the following exchange in the Committee hearings over the short title:</p>
<blockquote><p><span style="text-decoration: underline;">Mr. Brian Masse</span>:</p>
<p>I have just one last quick question. I noticed that the short title of the bill has been amended. We&#8217;ve had some things around that. Who suggested that the short title be changed?</p>
<p><span style="text-decoration: underline;">Mrs. Janet DiFrancesco: </span></p>
<p><span style="font-size: 13.3333px;">The short title of the bill was provided to us.</span></p>
<p>I also can&#8217;t tell you why they dropped a letter out of it. I don&#8217;t what happened to the “W” to go with the initials FISA, but that was the acronym they also gave us when it was tabled.<span style="font-size: 13.3333px;"> </span></p>
<p><span style="text-decoration: underline;">Mr. Brian Masse:</span></p>
<p>I suspected as much.</p>
<p>Thank you very much for your answers. I appreciate them.</p>
<p>Thank you, Mr. Chair. I&#8217;m all done.</p>
<p><span style="text-decoration: underline;">The Chair:</span></p>
<p>There are 92 clauses, so we&#8217;ll postpone the short title, as is the practice per Standing Order 75(1).</p>
<p>(Clauses 2 to 92 inclusive agreed to)</p>
<p>(On clause 1—Short title)…</p>
<p><span style="text-decoration: underline;">The Chair:</span></p>
<p>Shall the short title carry?</p>
<p><span style="text-decoration: underline;">Mr. Brian Masse:</span></p>
<p>No, I&#8217;m not going to agree to the short title. First of all, it wasn&#8217;t from the department. We got into these silly games of naming bills with these little titles here and there. I&#8217;m not going to give them this; it&#8217;s just ridiculous to do this type of stuff. I haven&#8217;t seen this in the years I&#8217;ve been here, so I&#8217;m not supporting this nonsense.</p>
<p><span style="text-decoration: underline;">The Chair:</span></p>
<p>Okay.</p>
<p><span style="text-decoration: underline;">Mr. Anthony Rota:</span></p>
<p>Mr. Chair, just for clarification, if we vote in favour of the title, then it has a title. If we vote against the short title, then it has no title. Am I correct?</p>
<p><span style="text-decoration: underline;">The Chair:</span></p>
<p><span style="font-size: 13.1944px;">That&#8217;s right. We&#8217;ll report it back that way. We&#8217;ll still have the long title.</span></p>
<p><span style="text-decoration: underline;">Mr. Anthony Rota:</span></p>
<p>I just wanted to clarify that. Thank you.</p>
<p><span style="text-decoration: underline;">The Chair:</span></p>
<p>Shall the short title carry? Can I see a show of hands?</p>
<p>(Clause 1 negatived)</p>
<p><span style="text-decoration: underline;">The Chair</span>: It&#8217;s defeated.</p>
<p>Shall the title carry?</p>
<p>Some hon. members: Agreed.</p>
<p><span style="text-decoration: underline;">The Chair:</span> Shall the bill as amended carry?</p>
<p>Some hon. members: Agreed.</p>
<p><span style="text-decoration: underline;">The Chair:</span> Shall I report the bill, as amended to the House?</p>
<p>Some hon. members: Agreed.</p>
<p><span style="text-decoration: underline;">The Chair</span>: Shall the committee order a reprint of the bill?</p>
<p>Some hon. members: Agreed.</p>
<p>The Chair: Gentlemen, that&#8217;s very good work. We have no meeting on Thursday.</p>
<p>The meeting&#8217;s adjourned.</p></blockquote>
<p>The Bill eventually passed the House of Commons and the Senate before being given <a href="http://www2.parl.gc.ca/sites/lop/legisinfo/index.asp?Language=E&amp;Chamber=N&amp;StartList=A&amp;EndList=Z&amp;Session=23&amp;Type=0&amp;Scope=I&amp;query=7019&amp;List=stat">Royal Assent</a> on December 15, 2010. It awaits publication of the regulations and then proclamation, which is expected to occur in the fall of this year.<span style="font-size: 13.1944px;"> </span></p>
<p><strong>You Name the Bill</strong></p>
<p>Bill C-28 is going to be with us for a long time. It is legislation that is very complex and will undoubtedly result in considerable study, litigation (including class action proceedings) and enforcement proceedings before the CRTC. (The Bill is summarized <a href="http://www.ic.gc.ca/eic/site/ecic-ceac.nsf/eng/gv00568.html">here</a>, <a href="http://www.barrysookman.com/2011/01/26/impacts-of-bill-c-28-the-new-anti-spam-and-anti-spyware-legislation/">here</a>, <a href="http://www.barrysookman.com/2011/01/06/canada-passes-anti-spam-and-anti-spyware-law/">here</a>, and <a href="http://www.lexology.com/library/detail.aspx?g=f5266525-0a55-47c5-803a-abdf4bad5a22">here</a>.)</p>
<p>We need a common way of referring to it. We need a short title. What do you think it should be?</p>
<p>I encourage you to email me (bsookman@mccarthy.ca) or post comments on my blog with your recommended short name (and/or acronym) and the reasons for choosing it. I will list the top few suggested names along with some of the main reasons for suggesting it and ask people to let me know their preferences.*</p>
<p>What do you recommend we call the Bill and why?</p>
<p>One of the people to recommend the winning name will be given a McCarthy Tétrault branded gift as a reward for his/her skill.</p>
<p>* By participating, you confirm you are okay with me attributing (or not attributing) suggestions to you, unless you let me know otherwise.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barrysookman.com/2011/02/06/name-canada%e2%80%99s-anti-spamanti-spyware-law/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Impacts of Bill C-28 (the new anti-SPAM and anti-spyware legislation)</title>
		<link>http://www.barrysookman.com/2011/01/26/impacts-of-bill-c-28-the-new-anti-spam-and-anti-spyware-legislation/</link>
		<comments>http://www.barrysookman.com/2011/01/26/impacts-of-bill-c-28-the-new-anti-spam-and-anti-spyware-legislation/#comments</comments>
		<pubDate>Wed, 26 Jan 2011 20:11:31 +0000</pubDate>
		<dc:creator>Barry Sookman</dc:creator>
				<category><![CDATA[Bill C-28]]></category>
		<category><![CDATA[E-commerce]]></category>
		<category><![CDATA[Electronic Commerce Protection Act (ECPA)]]></category>
		<category><![CDATA[Presentations]]></category>
		<category><![CDATA[address harvesting]]></category>
		<category><![CDATA[ECPA]]></category>
		<category><![CDATA[FIWSA]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.barrysookman.com/?p=2588</guid>
		<description><![CDATA[The new anti-SPAM and anti-spyware legislation (Bill C-28) will have significant implications for entities carrying on business in Canada and for entities doing business with Canadians. Its scope is very broad. Its approach to tacking the challenges posed by SPAM, malware, spyware, false and misleading representations associated with electronic messages, and harvesting of electronic address and personal information, is comprehensive.
The legislation creates [...]]]></description>
			<content:encoded><![CDATA[<p>The new anti-SPAM and anti-spyware legislation (Bill C-28) will have significant implications for entities carrying on business in Canada and for entities doing business with Canadians. Its scope is very broad. Its approach to tacking the challenges posed by SPAM, malware, spyware, false and misleading representations associated with electronic messages, and harvesting of electronic address and personal information, is comprehensive.</p>
<p>The legislation creates significant vicarious and accessorial liability for companies and for their officers and directors with the potential for administrative penalties of up to $10 million and damages awards which can reach $1 million per day or per breach.</p>
<p>Accordingly, you will want to learn about this new legislation and how to comply with its many provisions. To help you do so, I am posting slides prepared by Lorne Salzman and I for the  IT Can Roundtable presentation we gave earlier today on the impacts of Bill C-28.</p>
<p><a style="margin: 12px auto 6px auto; font-family: Helvetica,Arial,Sans-serif; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none; display: block; text-decoration: underline;" title="View Sookman Salzman ITCAN Spam Slides on Scribd" href="http://www.scribd.com/doc/47617311/Sookman-Salzman-ITCAN-Spam-Slides">Sookman Salzman ITCAN Spam Slides</a> <object id="doc_83134370867928" style="outline: none;" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="100%" height="600" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="name" value="doc_83134370867928" /><param name="data" value="http://d1.scribdassets.com/ScribdViewer.swf" /><param name="wmode" value="opaque" /><param name="bgcolor" value="#ffffff" /><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="FlashVars" value="document_id=47617311&amp;access_key=key-t03tuyz2zjj2ky3gqlk&amp;page=1&amp;viewMode=list" /><param name="src" value="http://d1.scribdassets.com/ScribdViewer.swf" /><param name="allowfullscreen" value="true" /><param name="flashvars" value="document_id=47617311&amp;access_key=key-t03tuyz2zjj2ky3gqlk&amp;page=1&amp;viewMode=list" /><embed id="doc_83134370867928" style="outline: none;" type="application/x-shockwave-flash" width="100%" height="600" src="http://d1.scribdassets.com/ScribdViewer.swf" flashvars="document_id=47617311&amp;access_key=key-t03tuyz2zjj2ky3gqlk&amp;page=1&amp;viewMode=list" allowscriptaccess="always" allowfullscreen="true" wmode="opaque" bgcolor="#ffffff" name="doc_83134370867928" data="http://d1.scribdassets.com/ScribdViewer.swf"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.barrysookman.com/2011/01/26/impacts-of-bill-c-28-the-new-anti-spam-and-anti-spyware-legislation/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Canada Passes Anti-Spam and Anti-Spyware Law</title>
		<link>http://www.barrysookman.com/2011/01/06/canada-passes-anti-spam-and-anti-spyware-law/</link>
		<comments>http://www.barrysookman.com/2011/01/06/canada-passes-anti-spam-and-anti-spyware-law/#comments</comments>
		<pubDate>Thu, 06 Jan 2011 17:16:46 +0000</pubDate>
		<dc:creator>James Gannon Charles S. Morgan Lorne P. Salzman</dc:creator>
				<category><![CDATA[E-commerce]]></category>
		<category><![CDATA[Electronic Commerce Protection Act (ECPA)]]></category>
		<category><![CDATA[anti-spam]]></category>
		<category><![CDATA[ECPA]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam bill]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.barrysookman.com/?p=2484</guid>
		<description><![CDATA[Organizations that conduct business online should start preparing for Canada’s new anti-spam and anti-spyware legislation, which was passed in mid-December and is expected to come into force later this year.1 As the Act is complex and the penalties for violating the new law can be severe, organizations should review and modify their online practices, where [...]]]></description>
			<content:encoded><![CDATA[<p>Organizations that conduct business online should start preparing for Canada’s new anti-spam and anti-spyware legislation, which was passed in mid-December and is expected to come into force later this year.<sup>1</sup> As the Act is complex and the penalties for violating the new law can be severe, organizations should review and modify their online practices, where necessary, at an early opportunity.</p>
<div><strong>Anti-Spam Provisions</strong></div>
<p>The Act prohibits organizations from sending commercial electronic messages unless the recipient has given express or implied consent. A &#8220;commercial&#8221; electronic message is an electronic message where one of its purposes is to encourage participation in commercial activity. An &#8220;electronic message&#8221; is defined broadly to include any &#8220;message sent by any means of telecommunication, including a text, sound, voice or image message.&#8221; This covers e-mails, text messages, instant messages, &#8220;tweets&#8221; or Facebook® postings, but excludes two-way voice communication, faxing to a telephone account or accessing a voice mailbox.</p>
<p>When requesting express consent to send a commercial electronic message, an organization must &#8220;clearly and simply&#8221; set out the purpose(s) for which consent is being sought and identify the organization seeking the consent. However, consent is not required to send a commercial electronic message where the purpose is to:</p>
<ul>
<li>provide a quote or estimate in response to a request;</li>
<li>facilitate, complete or confirm a pre-agreed commercial transaction;</li>
<li>provide warranty, product recall or safety information to a purchaser of goods;</li>
<li>provide information related to an ongoing subscription, membership, account or loan;</li>
<li>provide information related to an employment relationship; or</li>
<li>deliver a pre-authorized product, goods or service, including product updates and upgrades<strong>.</strong></li>
</ul>
<p>Consent to receive messages can also be implied, most notably where:</p>
<ul>
<li>the sender and the recipient have an existing business relationship or non-business relationship (<em>e.g.</em>, membership in a club), where the relationship arose within the past two years or is pursuant to a contract in effect in the past two years;</li>
<li>the recipient has &#8220;conspicuously published&#8221; its electronic address and has not indicated a desire to not receive unsolicited commercial electronic messages, <em>and</em> the message is relevant to the recipient’s business role; or</li>
<li>the recipient has provided its electronic address to the sender without indicating a wish not to receive unsolicited commercial electronic messages, <em>and</em> the message is relevant to the recipient’s business role.</li>
</ul>
<p>The Act also requires that all commercial electronic messages must identify the sender, include the sender’s contact information, and provide an &#8220;unsubscribe&#8221; mechanism so that recipient can opt out of receiving future communications.</p>
<div><strong>Anti-Spyware Provisions</strong></div>
<div><strong> </strong></div>
<div>To combat spyware, malware and other malicious software, the Act prohibits the installation of computer programs without the consent of the computer’s user or owner. When consent to install the program is requested, it must &#8220;describe clearly and simply the function and purpose of every computer program that is to be installed.&#8221;</div>
<p>In addition, if a program performs certain potentially undesirable functions, it must bring its &#8220;foreseeable impacts&#8221; to the attention of the user. The prescribed list of undesirable functions includes:</p>
<ul>
<li>collecting personal information stored on the computer system;</li>
<li>interfering with the user’s control of the computer system;</li>
<li>changing or interfering with settings or preferences on the computer system without the user’s knowledge;</li>
<li>interfering with access to or use of that data on the computer system;</li>
<li>causing the computer system to communicate with another computer system without the authorization of the user; or</li>
<li>installing a computer program that may be activated by a third party without the knowledge of the user.</li>
</ul>
<p>These requirements apply not only to personal computers and computer servers, but also to any electronic device that allows for the installation of third-party programs — such as smartphones and tablets. Programs are exempted from these requirements only if it is reasonable to conclude from the recipient’s conduct that the recipient consented to the installation of the programs (<em>e.g</em>., HTML code, Web cookies, javascript code, operating systems, patches and add-ons). Program upgrades and updates are also exempt if the recipient consented to the initial installation and is entitled to receive upgrades or updates<strong>.</strong></p>
<p><strong>Amendments to the <em>Competition Act </em>and <em>PIPEDA</em><sup>2</sup></strong></p>
<p>The Act amends the <em>Competition Act</em> to prohibit false or misleading representations in the sender description, subject matter field or message field of an electronic message, or in the URL or other locater on a webpage. Senders will have to be particularly wary of making overly boastful statements in subject matter lines in an attempt to catch readers’ attention.</p>
<p>The Act also amends <em>PIPEDA, </em>to prohibit the collection of personal information by means of unauthorized access to computer systems, and the unauthorized compiling of lists of electronic addresses (sometimes called &#8220;address harvesting&#8221;).</p>
<div><strong>Enforcement and Penalties</strong></div>
<div>Violators of the anti-spam and anti-spyware provisions of the Act could face fines of up to $1 million for individuals and $10 million for organizations per violation. Officers and directors can also be penalized if they directed, authorized, acquiesced in or participated in the offending conduct. The Act is enforced by the Canadian Radio-television and Telecommunications Commission.</div>
<p>The Act also creates a private right of action that allows any business or consumer to take civil action directly against anyone who violates the Act, or the new false or misleading representations provisions of the <em>Competition Act</em>. The Act contemplates that a litigant will be able to recover its actual damages <em>and </em>additional amounts that could amount to as much as $1 million per day. These latter provisions will undoubtedly excite the plaintiff class action bar.</p>
<div><strong>McCarthy Tétrault Notes</strong></div>
<div>While aimed at preventing spam and spyware, the Act imposes strict requirements on all businesses that use electronic communication. Any company conducting business online (including through e-mails) should be aware of these new requirements and may need to adapt their business practices. In order to prepare for the Act coming into force, which is expected in the next six to nine months, organizations should consider taking the following steps:</div>
<ul>
<li>review and update website privacy policies and terms and conditions to ensure proper consents for the collection of personal information and/or the installation of computer programs on dynamic websites;</li>
<li>review and update their forms for obtaining express consent to send commercial electronic messages (including e-mail or newsletters), or install software programs to ensure that the forms satisfy the prescribed requirements;</li>
<li>re-examine their procedures for documenting the receipt of consent, as the onus will rest on senders and software developers to prove they obtained consent;</li>
<li>ensure that any commercial electronic message contains the prescribed information and an unsubscribe mechanism that is operational for the specified period;</li>
<li>deal with unsubscribe requests within the requisite time frame;</li>
<li>ensure that any process that involves online collection of e-mail addresses or other personal information complies with the amendments to the <em>PIPEDA</em>;</li>
<li>generally review and revise marketing, advertising and external communication practices to comply with the requirements of the Act and the new provision of the <em>Competition Act</em>; and</li>
<li>in the case of software developers:
<ul>
<li>examine their program-installation procedures to ensure that information about the function and purpose of the program is provided prior to installation;</li>
<li>if the program performs one of the prescribed undesirable functions, the disclosure mechanism will also need to describe the foreseeable impacts of these functions; and</li>
<li>revise end-user licence agreements (EULAs) to ensure that consent to install patches and upgrades is expressly obtained before installation of computer programs.</li>
</ul>
</li>
</ul>
<div><strong></strong></div>
<p><strong><br />
<hr /></strong> <sup><strong>1</strong></sup> The full name of the Act is long, and quite unmemorable: &#8220;An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities, and to amend the <em>Canadian Radio-television and Telecommunications Commission Act</em>, the <em>Competition Act</em>, the <em>Personal Information Protection and Electronic Documents Act</em> and the<em> Telecommunications Act.</em>&#8221; The Act will come into force upon proclamation.</p>
<p><sup>2</sup><em> Personal Information Protection and Electronic Documents Act</em>, which is the primary federal statute that addresses privacy matters.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barrysookman.com/2011/01/06/canada-passes-anti-spam-and-anti-spyware-law/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Industry Committee Amends Anti-Spam Bill (ECPA)</title>
		<link>http://www.barrysookman.com/2009/10/27/industry-committee-amends-anti-spam-bill-ecpa/</link>
		<comments>http://www.barrysookman.com/2009/10/27/industry-committee-amends-anti-spam-bill-ecpa/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 03:03:37 +0000</pubDate>
		<dc:creator>Barry Sookman</dc:creator>
				<category><![CDATA[Electronic Commerce Protection Act (ECPA)]]></category>
		<category><![CDATA[address harvesting]]></category>
		<category><![CDATA[ECPA]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.barrysookman.com/?p=135</guid>
		<description><![CDATA[By Barry Sookman and James Gannon
In May of this year, we sent an e-Alert that reviewed the concerns many Canadian businesses had expressed with the first draft of Bill C-27 – the Electronic Commerce Protection Act (ECPA). The Bill was criticized for containing overly broad anti-spam and anti-spyware provisions that would have rendered illegal many [...]]]></description>
			<content:encoded><![CDATA[<p>By Barry Sookman and James Gannon</p>
<p>In May of this year, we sent an e-Alert that reviewed the concerns many Canadian businesses had expressed with the first draft of Bill C-27 – the Electronic Commerce Protection Act (ECPA). The Bill was criticized for containing overly broad anti-spam and anti-spyware provisions that would have rendered illegal many common legitimate commercial practices. It would have potentially exposed businesses to millions of dollars in fines and liabilities for activities that were unrelated to sending spam emails or installing spyware programs.</p>
<p>Since then, officials at Industry Canada and MPs on the Standing Committee on Industry, Science and Technology (INDU) have made substantial amendments to the Bill to address the concerns raised by Canadian businesses.  However, some problems remain.</p>
<p>Amendments to the ECPA</p>
<p>The INDU Committee completed its clause-by-clause review of the ECPA on Monday, October 26. Among the amendments recommended by the committee:<br />
• The spam provisions will not extend to electronic messages that (a) provide a quote or estimate; (b) facilitate, complete or confirm an existing commercial transaction; (c) provide warranty information; (d) provide information related to an ongoing subscription, membership, account or loan; (e) provide information related to an employment relationship; or (f) deliver a product, goods or a service, including product updates and upgrades.<br />
• The spam provisions will also not extend to messages sent to a published e-mail address, where the message is relevant to the person’s type of business so is not considered spam.<br />
• The anti-spam laws will now only apply to messages that are sent or accessed from within Canada. Messages that are merely routed through a Canadian server will not be subject to the Bill.<br />
• The disclosure requirements for the installation of computer programs were changed from describing the “function, purpose and impact” of the program to simply the “function and purpose.” However, if a program performs certain undesirable functions, it must bring their foreseeable impacts to the attention of the user. The prescribed list of undesirable functions is similar to those found in international anti-spyware law precedents.<br />
•The anti-spyware law was also amended to create exceptions for software updates, upgrades and patches.<br />
• Certain programs were excluded from the consent requirements of the anti-spyware law, including web cookies, HTML code, Javascript and operating systems.<br />
• The maximum damage award for a contravention of the anti-spyware provision was changed from $200 per contravention to $1 million for each day on which a contravention occurred.<br />
• Transitional provisions were included so that businesses have up to three years to obtain consent to send messages from existing business contacts. Similarly, if a computer program was already installed before the ECPA comes into force, the user’s consent to updates and upgrades can be implied for up to three years.</p>
<p>While these amendments would alleviate a number of concerns that were expressed with respect to the ECPA, a key amendment to Section 78 that had sought to preserve the ability  to collect personal information to investigate breaches of law was not adopted by the Committee.</p>
<p>PIPEDA Provisions</p>
<p>Under the original draft of the Bill, PIPEDA would have been amended to make it illegal to collect “personal information, through any means of telecommunication, if the collection is made by accessing a computer system or causing a computer system to be accessed without authorization.”  There were no exceptions to this prohibition.<br />
Business groups such as the Canadian Chamber of Commerce, ITAC and others were concerned that the new prohibition was not subject to the usual PIPEDA exceptions, including the exception that permits the collection of personal information for the purposes of investigating breaches of an agreement or the contravention of a federal or provincial law.</p>
<p>The business community was worried that s.78 could have been construed to prevent the collection of personal information over the Internet to investigate contraventions of law including: fraud such as bank, insurance, and credit card fraud; money laundering, securities violations, theft, misappropriation, or unauthorized use of confidential information/personal information; violations of business practices legislation; defamation; workplace-related sexual harassment; computer hacking, including committing the criminal offences associated with theft of telecommunications services, making unauthorized use of a computer, or mischief in relation to data; identity theft or impersonation; and violations of copyright by peer-to-peer networks and other infringers.</p>
<p>The government had tabled amendments to fix this potentially serious flaw in the Bill, however, during the final day of Committee hearings, the government withdrew its proposed amendment and the flawed bill is being sent to Parliament for Third Reading. If the proposed amendments are not made before the Bill becomes law, there could be serious implications for private and public law enforcement in Canada.</p>
<p>Conclusion</p>
<p>Bill c-27 will now go to the Senate before becoming law. It will have major implications on software licensing practices as well as on how businesses collect and use personal information in their electronic communications. Since the Bill will become law soon, it is essential that businesses review their practices concerning sending electronic messages, their privacy policies, and software licence and maintenance agreements to ensure compliance with the ECPA.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barrysookman.com/2009/10/27/industry-committee-amends-anti-spam-bill-ecpa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anti-Spam Bill Raises Concerns</title>
		<link>http://www.barrysookman.com/2009/05/12/anti-spam-bill-raises-concerns-2/</link>
		<comments>http://www.barrysookman.com/2009/05/12/anti-spam-bill-raises-concerns-2/#comments</comments>
		<pubDate>Tue, 12 May 2009 21:44:48 +0000</pubDate>
		<dc:creator>Barry Sookman</dc:creator>
				<category><![CDATA[E-commerce]]></category>
		<category><![CDATA[Electronic Commerce Protection Act (ECPA)]]></category>
		<category><![CDATA[bill c-27]]></category>
		<category><![CDATA[ECPA]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.barrysookman.com/?p=68</guid>
		<description><![CDATA[ On May 8, 2009, the Electronic Commerce Protection Act (ECPA) received a second reading in the House of Commons. The Government of Canada had introduced the bill on April 24th. The intention of the ECPA is &#8220;to deter the most dangerous forms of spam, such as identity theft, phishing and spyware, from occurring in [...]]]></description>
			<content:encoded><![CDATA[<p><span lang="EN-CA"> On May 8, 2009, the <em>Electronic Commerce Protection Act</em> (<em>ECPA</em>) received a second reading in the House of Commons. The Government of Canada had introduced the bill on April 24<sup>th</sup>. <span lang="EN-CA">The intention of the <em>ECPA</em> is &#8220;to </span><span>deter the most dangerous forms of spam, such as identity theft, phishing and spyware, from occurring in Canada&#8221; and to &#8220;help drive spammers out of Canada.&#8221; The bill also contains provisions intended to combat spyware by prohibiting the installation of computer programs without the consent of the computer’s owner. While the objective of the legislation is laudable, the bill&#8217;s overly broad language could circumscribe legitimate business-to-business marketing and impact software companies&#8217; ability to deliver upgrades and patches to customers.</span><strong><em> </em>Section 6(1) of the <em>ECPA</em> states that &#8220;No person shall send or cause or permit to be sent to an electronic address a commercial electronic message unless (a) the person to whom the message is sent has consented to receiving it, whether the consent is express or implied; and (b) the message complies [with specified formalities].&#8221;<strong><em> </em></strong> </strong> </span><span lang="EN-CA">Unlike other international anti-spam legislation, the prohibition against unsolicited commercial messages in the <em>ECPA</em> is not limited to messages sent with some element of fraud or misleading information, sent with an &#8220;intent to deceive or mislead,&#8221; sent to addresses that were gathered using &#8220;automated means,&#8221; or sent in bulk.</span></p>
<p>Technologies affected by this provision include commercial electronic messages sent by e-mail, instant messaging and mobile phones <span style="font-family: Times New Roman;">―</span> and probably also messages sent using social networks, chat groups, Internet forums, business networks, and websites where users have accounts. The <em>ECPA</em> would prohibit sending &#8220;an electronic message that, having regard to the content of the message, the hyperlinks in the message to content on a website or other database, or the contact information contained in the message, it would be reasonable to conclude has as its purpose, or one of its purposes, to encourage participation in a commercial activity.&#8221; The types of communication technologies that are subject to the prohibition are open-ended, and the messages that are sent must include prescribed content and be in a prescribed form.</p>
<p>The requirements for obtaining express consent are stringent and the circumstances in which an implied consent can be relied upon are limited. It is not possible to seek consent electronically, because such a request itself would be a prohibited electronic message. Consent is implied only where the sender has an existing relationship with the recipient.</p>
<p><strong><em>Restrictions on Software Installation</em>Although the government’s stated intent in introducing this bill is to stop the spread of unlawful programs engaged in &#8220;the collection of personal information through illicit access to computer systems,&#8221; the <em>ECPA</em> would actually prohibit a business from installing any computer program on any person’s computer without obtaining express consent. As currently drafted, this provision would outlaw any program, patch, upgrade or add-on installed without express consent.</strong></p>
<p>The <em>ECPA</em> would also require, before any software is installed on a computer, that the person requesting consent &#8220;describe clearly and simply the function, purpose and impact of every computer program that is to be installed.&#8221; The provisions in the <em>ECPA </em>would apply not only to personal computers but to a whole host of devices, from iPhones and BlackBerry® devices to mainframe computers, even though many do not have the capability of displaying consent forms and relaying consent.</p>
<p><strong><em>Administrative Penalties</em>The <em>ECPA</em> would make the violation of the above provisions subject to &#8220;administrative monetary&#8221; penalties of up to $1 million in the case of an individual, or $10 million in the case of a non-individual. These high penalties can be exacted without any right to a trial, and a conviction can be entered on proof of only a &#8220;balance of probabilities.&#8221; This liability would also extend to employers, officers, directors or agents of a company. It also appears to include a statutory damages regime that could result in an order to pay &#8220;a maximum of $200 for each contravention of the provision, not exceeding $1,000,000 for each day on which one or more of those contraventions occurred.&#8221; This liability would also extend to employers, officers and directors of a company.</strong></p>
<p>The bill also contains a new private right of action for any person who alleges that they are affected by an act or omission that constitutes a contravention of Section 5 of the <em>Personal Information Protection and Electronic Documents Act</em>, which relates to a collection or use of information described in subsection 7.1(2) or (3) of that act. This would appear to now expose Canadian business to extensive new liabilities for the use or disclosure of personal information without the knowledge or consent of individuals. Officers, directors, and employers would also be potentially liable for their employees’ actions.</p>
<p>Over the last decade, the Internet has become an essential tool for conducting commercial activity. If passed, this bill would prohibit the formation of new business relationships over the Internet or through e-mail. It would stultify the use of the Internet for the distribution of software and software upgrades. It also contains very high penalties for breach, penalties that are particularly disconcerting given the wide and ambiguous nature of the bill.</p>
<p>If your business will be impacted by the <em>ECPA</em>, we recommend that you make submissions to the House of Commons Standing Committee on Industry, Science and Technology, setting out your concerns.</p>
<p>Restrictions on Commercial Electronic Messages</p>
]]></content:encoded>
			<wfw:commentRss>http://www.barrysookman.com/2009/05/12/anti-spam-bill-raises-concerns-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

