Connect with us
[bsa_pro_ad_space id=12]

Alberta

Tim Hortons app violated privacy laws in collection of ‘vast amounts’ of sensitive location data

Published

7 minute read

People who downloaded the Tim Hortons app had their movements tracked and recorded every few minutes of every day, even when their app was not open, in violation of Canadian privacy laws, a joint investigation by federal and provincial privacy authorities has found.

The investigation concluded that Tim Hortons’ continual and vast collection of location information was not proportional to the benefits Tim Hortons may have hoped to gain from better targeted promotion of its coffee and other products.

The Office of the Privacy Commissioner of Canada, Commission d’accès à l’information du Québec, Office of the Information and Privacy Commissioner for British Columbia, and Office of the Information and Privacy Commissioner of Alberta issued their Report of Findings today.

The Tim Hortons app asked for permission to access the mobile device’s geolocation functions, but misled many users to believe information would only be accessed when the app was in use. In reality, the app tracked users as long as the device was on, continually collecting their location data.

The app also used location data to infer where users lived, where they worked, and whether they were travelling. It generated an “event” every time users entered or left a Tim Hortons competitor, a major sports venue, or their home or workplace.

The investigation uncovered that Tim Hortons continued to collect vast amounts of location data for a year after shelving plans to use it for targeted advertising, even though it had no legitimate need to do so.

The company says it only used aggregated location data in a limited way, to analyze user trends – for example, whether users switched to other coffee chains, and how users’ movements changed as the pandemic took hold.

While Tim Hortons stopped continually tracking users’ location in 2020, after the investigation was launched, that decision did not eliminate the risk of surveillance. The investigation found that Tim Hortons’ contract with an American third-party location services supplier contained language so vague and permissive that it would have allowed the company to sell “de-identified” location data for its own purposes.

There is a real risk that de-identified geolocation data could be re-identified. A research report by the Office of the Privacy Commissioner of Canada underscored how easily people can be identified by their movements.

Location data is highly sensitive because it can be used to infer where people live and work, reveal trips to medical clinics. It can be used to make deductions about religious beliefs, sexual preferences, social political affiliations and more.

Organizations must implement robust contractual safeguards to limit service providers’ use and disclosure of their app users’ information, including in de-identified form. Failure to do so could put those users at risk of having their data used by data aggregators in ways they never envisioned, including for detailed profiling.

The investigation also revealed that Tim Hortons lacked a robust privacy management program for the app, which would have allowed the company to identify and address many of the privacy contraventions the investigation found.

The four privacy authorities recommended that Tim Hortons:

  • Delete any remaining location data and direct third-party service providers to do the same;
  • Establish and maintain a privacy management program that: includes privacy impact assessments for the app and any other apps it launches; creates a process to ensure information collection is necessary and proportional to the privacy impacts identified;  ensures that privacy communications are consistent with, and adequately explain app-related practices; and
  • Report back with the details of measures it has taken to comply with the recommendations.

Tim Hortons agreed to implement the recommendations.

QUOTES

“Tim Hortons clearly crossed the line by amassing a huge amount of highly sensitive information about its customers. Following people’s movements every few minutes of every day was clearly an inappropriate form of surveillance. This case once again highlights the harms that can result from poorly designed technologies as well as the need for strong privacy laws to protect the rights of Canadians.”

Daniel Therrien, Privacy Commissioner of Canada

“This report eloquently illustrates the risks inherent in the use of geolocation and the importance of transparent and accountable privacy practices. Without a suitable prior assessment, Tim Hortons collected sensitive information about its customers through its app, without their adequate knowledge or consent. It is to put an end to this kind of practice that Quebec has reviewed its legislation protecting personal information giving more powers to the Commission and making companies more accountable. ”

Me Diane Poitras, president, Commission d’accès à l’information du Québec

“This investigation sends a strong message to organizations that you can’t spy on your customers just because it fits in your marketing strategy. Not only is this kind of collection of information a violation of the law, it is a complete breach of customers’ trust. The good news in this case is that Tim Hortons has agreed to follow the recommendations we set out, and I hope other organizations can learn from the results of this investigation.”

Michael McEvoy, Information and Privacy Commissioner for British Columbia

“This investigation is yet another example where an organization has not effectively notified customers about its practices. Tim Hortons’ customers did not have adequate information to consent to the location tracking that was actually occurring. When people download and use these types of apps, it’s important that they know in advance what will happen to their personal information and that organizations follow through with their commitments.”

Information and Privacy Commissioner of Alberta Jill Clayton

This is a news release from the Government of Alberta.

Follow Author

Alberta

Former senior financial advisor charged with embezzling millions from Red Deer area residents

Published on

News release from Alberta RCMP

Former senior financial advisor charged for misappropriating nearly $5 million from clients

On April 4, 2024, the RCMP’s Provincial Financial Crime Team charged a Calgary resident for fraud-related offences after embezzling millions of dollars from his clients while serving as a senior financial advisor.

Following a thorough investigation, the accused is alleged to have fraudulently withdrawn funds from client accounts and deposited them into bank accounts he personally controlled. A total of sixteen victims were identified in the Red Deer area and suffered a combined loss of nearly $5 million.

Marc St. Pierre, 52, a resident of Calgary, was arrested and charged with:

  • Fraud over $5,000 contrary to section 380(1)(a) of the Criminal Code; and,
  • Theft over $5,000 contrary to section 344(a) of the Criminal Code.

St. Pierre is scheduled to appear in Red Deer Provincial Court on May 14, 2024.

“The ability for financial advisors to leverage their position to conduct frauds and investment scams represents a significant risk to the integrity of Alberta’s financial institutions. The investigation serves as an important reminder for all banking clients to regularly check their accounts for any suspicious activity and to report it to their bank’s fraud prevention team.”

  • Sgt. John Lamming, Provincial Financial Crime Team

The Provincial Financial Crime Team is a specialized unit that conducts investigations relating to multi-jurisdictional serious fraud, investments scams and corruption.

Continue Reading

Alberta

Political parties will be part of municipal elections in Edmonton and Calgary pilot projects

Published on

Alberta’s government is introducing legislation to ensure Albertans can rely on transparent, free and fair elections, and municipally-elected officials have clearer accountability measures.

In a democratic society, Albertans expect their local elections to be free and fair, and their elected officials to be held to account by clear rules that govern their local councils. The Municipal Affairs Statutes Amendment Act proposes amendments to the Local Authorities Election Act (LAEA) and the Municipal Government Act (MGA) to add greater transparency to local election processes and ensure local councils and elected officials continue to remain accountable to the citizens who elected them.

“Our government is committed to strengthening Albertans’ trust in their local governments and the democratic process that elects local leaders. The changes we are making increase transparency for Alberta voters and provide surety their votes will be counted accurately. We know how important local democracy is to Albertans, and we will work with local authorities to protect and enhance the integrity of local elections.”

Ric McIver, Minister of Municipal Affairs

Local Authorities Election Act

Albertans expect free and fair elections and that’s why it’s important we strengthen the rules that govern local elections. To strengthen public trust in local elections, Alberta’s government will eliminate the use of electronic tabulators and other automated voting machines. All Albertans should be able to trust the methods and results of local elections; requiring all ballots to be counted by hand, clarifying rules and streamlining processes for scrutineers will provide voters greater assurance in the integrity of the results.

All eligible Albertans should be able to vote in local elections without impediment. Alberta’s government will limit the barriers for eligible voters to cast a ballot by expanding the use of special ballots. Currently, special ballots can only be requested for very specific reasons, including physical disability, absence from the municipality, or for municipal election workers. By expanding the use of special ballots, the government is encouraging more voter participation.

Amendments in the Municipal Affairs Statutes Amendment Act would increase transparency in local elections by enabling political parties at the local level. Political parties would be enabled in a pilot project for Edmonton and Calgary. The act will not require candidates to join a political party in order to run for a local or municipal office, but will create the opportunity to do so.

In addition, proposed changes to the Local Authorities Election Act would allow municipalities the option to require criminal record checks for local candidates, thus increasing transparency and trust in candidates who may go on to become elected officials.

Municipal Government Act

The role of an elected official is one with tremendous responsibility and expectations. Changes proposed to the Municipal Government Act (MGA) will strengthen the accountability of locally elected officials and councils. These include requiring mandatory orientation training for councillors, allowing elected officials to recuse themselves for real or perceived conflicts of interest without third-party review and requiring a councillor’s seat to become vacant upon disqualification.

If passed, the Municipal Affairs Statutes Amendment Act will also unlock new tools to build affordable and attainable housing across Alberta. Proposed amendments under the MGA would also create more options for municipalities to accelerate housing developments in their communities. Options include:

  • Exempting non-profit, subsidized affordable housing from both municipal and education property taxes;
  • Requiring municipalities to offer digital participation for public hearings about planning and development, and restricting municipalities from holding extra public hearings that are not already required by legislation; and
  • Enabling municipalities to offer multi-year residential property tax exemptions.

Municipal Affairs will engage municipalities and other partners over the coming months to hear perspectives and gather feedback to help develop regulations.

Quick facts

  • The LAEA establishes the framework for the conduct of elections in Alberta municipalities, school divisions, irrigation districts and Metis Settlements.
  • The MGA establishes the rules governing the conduct of local elected officials once on council, as well as the overall administration and operation of municipal authorities in Alberta, including any policy those authorities may wish to implement.

Related information

Continue Reading

Trending

X