Global fintech and funding innovation ecosystem

Office of the Privacy Commissioner Announces Digital ID Ecosystem Resolution to Ensure Transparency and Privacy

Office of the Privacy Commissioner of Canada | Oct 24, 2022

privacy guardians across canada - Office of the Privacy Commissioner Announces Digital ID Ecosystem Resolution to Ensure Transparency and PrivacyBenefits of digital ID ecosystem will be realized only with adequate privacy protections, say data protection authorities

  • In a resolution issued today, federal, provincial and territorial privacy regulators note that the digital identity ecosystem emerging in Canada and around the world will allow individuals, businesses and governments to confirm identities and carry out transactions online with a high degree of efficiency and confidence.
  • However, while a secure digital identity offers many benefits, it must be designed and implemented in a manner that upholds privacy, security, transparency and accountability to be trusted enough to be widely adopted.

Ecosystem properties

  • A privacy impact assessment should be conducted and provided to the oversight body in the early design, development and update stages of a digital identity system as the project and solution evolve;
  • The privacy implications of identity ecosystem design, functions and information flows should be transparent to all users of the system;

See:  Modernizing Privacy Law in Canada – Striking the Right Balance

  • Digital identification should not be used for information or services that could be offered to individuals on an anonymous basis and systems should support anonymous and pseudonymous transactions wherever appropriate;
  • Systems should not create central databases;
  • The principle of minimizing personal information must be applied at all stages of the digital identity process: only necessary information should be collected, used, disclosed or retained.Footnote 2 The collection or use of particularly intimate, sensitive and permanent information such as biometric data should be considered only if it is demonstrated that other less intrusive means would not achieve the intended purpose;
  • Personal information in an identity ecosystem should not be used for purposes other than assessing and verifying identity or other authorized purpose(s) necessary to provide the service. Ecosystems must not allow tracking or tracing of credential use for other purposes;
  • The security of personal information should be proportional with its sensitivity, the context and the degree to which it could be desired by malicious actors;
  • Digital identity information must be secure from tampering, unauthorized duplication and use;
  • Systems should be capable of being assessed and audited, and of being subject to independent oversight;
  • Digital identity systems should provide options and alternatives in order to ensure fair and equitable access to government services for all.

Individual Rights and Remedies

  • Individual participation in a digital identity ecosystem should be voluntary and optional;
  • Individuals should be able to choose alternative forms of identification and these forms should be reasonably convenient and accessible;
  • Clear and informed consent of the individual should be the basis for exchanging personal information between services;
  • Individuals should be in control of their personal information;

See:  Canada to Launch ‘Digital Ambition 2022’ Public Consultation For Digital ID Framework of Federal Public Services

  • Redress to an independent body with adequate resources and powers should be provided for individuals in the event of rights violations.

Governance and oversight

  • Governments should be open and transparent about the defined purposes of the digital identity systems, what personal information will be used, how and by whom;
  • Governments should provide for express lawful authority, prohibitions, penalties and redress;
  • Where necessary, existing privacy laws should be strengthened to support digital governance and uphold the principle of do no harm;
  • Governments should establish clear accountability mechanisms to meet transparency and privacy obligations, including providing authority and resources for regulators to exercise adequate oversight and impose appropriate penalties for non-compliance.

Continue to the full article --> here

View the resolution --> here


NCFA Jan 2018 resize - Office of the Privacy Commissioner Announces Digital ID Ecosystem Resolution to Ensure Transparency and PrivacyThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

Latest news - Office of the Privacy Commissioner Announces Digital ID Ecosystem Resolution to Ensure Transparency and PrivacyFF Logo 400 v3 - Office of the Privacy Commissioner Announces Digital ID Ecosystem Resolution to Ensure Transparency and Privacycommunity social impact - Office of the Privacy Commissioner Announces Digital ID Ecosystem Resolution to Ensure Transparency and Privacy

Support NCFA by Following us on Twitter!







NCFA Sign up for our newsletter - Office of the Privacy Commissioner Announces Digital ID Ecosystem Resolution to Ensure Transparency and Privacy




 

Leave a Reply

Your email address will not be published. Required fields are marked *

two × four =