By Jiahui (Jennifer) Zhang and Paul Jones
Jones Law Professional Corporation
Recently, efforts have been made on different levels to overhaul the privacy protection laws in Canada. The Provinces of Québec and British Columbia enacted legislative amendments, while other Canadian jurisdictions are also actively considering reform.
In Québec, the Act respecting the protection of personal information in the private sector (“Bill 64”) received Royal Assent on September 22, 2021. The bill introduces sweeping changes to Québec’s existing privacy regime (the Québec Privacy Act), which was Canada’s first private sector privacy law, enacted in 1994. Bill 64 will come into force in part in September 2022, with the penalties and most of the key provisions coming into force in September 2023. It applies to anyone operating an “enterprise” within the meaning of the Civil Code of Québec.
The strengthened Québec French language law -Bill 96 amendments tabled in May 2021 even adds another layer of complexity to the privacy law issue to businesses who operate in Québec.
All franchise businesses now have privacy concerns. What comes with the changes to the laws in Quebec are stricter requirement for formal consent by customers and for transferring data out of Québec. And the relevant documentation and communication will need a French version.
Why should franchising business pay attention to privacy law?
Franchised businesses, like any other businesses, are obliged to comply with data privacy laws. Franchisors and/or franchisees are collecting customer data and use them in many ways over the ordinary course of business.
To suit the market in pandemic, many franchise systems accept payment by tapping a bank card or digital wallet. Information contained in the payment card will be shared with the franchisee and the financial institution that issued the card. Payment terminals can also be built to feed into a retailer’s “customer relationship management” database so that a retailer can track customer purchases and tie those to other information about customers, such as their email address, the payment card network operator receive information about where and when the customer shopped and how much one spent.
Franchise websites and mobile applications also collect and transmit other personal information related to the purchase, such as customer device’s IP address, information about previous purchases, location information, browsing history, or other information about customer device. Some websites allow customers to log in using the credentials from social network site. All the information could be potentially shared with loyalty card companies, data brokers, or marketers, or sold to organizations that want to profit from personal information.
Considering the high degree of interconnectivity that exists between the franchisee and the franchisor, both parties must implement best practices and diligently police the use, transmission, and protection of data.
The franchisor’s franchise agreement and its operations manual should clearly state which parties are responsible for acquiring the customer’s consent to collecting, using, and retaining their personal information. It should be specified which party is ultimately responsible for maintaining the safety and integrity of customer data and personal information.
Moreover, the franchisor’s operations manual should clearly specify its requirements for its franchisees with respect to information technology hardware and software standards, including operating hardware specifications and the type and version of anti-virus software that should be used. These requirements should be revisited by the franchisor regularly, to consider whether the requirements remain adequate and current.
The manual and the franchisor’s initial and ongoing training programs for franchisees should also provide sufficient training, guidance, and operating procedures on data collection, handling, storage, and protection, provide the franchisees with the knowledge and training they need to recognize potential threats and attempts by bad actors to access their systems, and procedures to follow should they be compromised or potentially compromised. This training should provide franchisees with tools to help them recognize “phishing” attempts, which are becoming increasingly sophisticated.
What are the new requirements for those who operate business in Québec?
Québec’s Bill 64 is considered similar to EU privacy rule – the General Data Protection Regulation (GDPR). And it is stricter than PIPEDA. Bill 64 contains extremely high penalties and fines for breaches of the law while PIPEDA has no such comparable regime, though the CPPA would have had very significant penalties and fines.
How should business get prepared for the new privacy law?
1. Appointing Privacy Officer
To meet the requirement of Bill 64, the entity collects and uses data (could be a franchisor or a franchisee) must designate an individual as its privacy officer; that individual will then be accountable for the entity’s compliance with Bill 64. This is the same as PIPEDA.
2. Establish and publish privacy policy
Enterprises will be required to establish and implement governance policies and practices
to ensure that personal information is protected in outsourcing transactions.
Therefore, the enterprise must also have a written privacy policy dealing with its management of personal information. The policy must be made available to individuals upon request. Often, such policies will be published on their websites, available in French, to ensure compliance in Québec.
3. Obtain consent and sign agreement with data-processing service provider
Bill 64 treats disclosures of personal information to processors (third party data management contractors) as a “communication” for which consent is required. Organizations must inform individuals when they collect personal information using a technology that allows the individual to be identified, located, or profiled.
Bill 64 recognizes that consent may be implied in certain circumstances, and it formally requires express consent for the processing of sensitive personal information. This is more onerous than PIPEDA and may require changes to franchise systems. It also sets out specific conditions to be met for the exception to apply including contractual terms between the controller and processer.
An arrangement with a service provider processing personal information for either a franchisor or a franchisee must place appropriate limitations on the use of the information by the service provider, and must ensure that the franchisor or franchisee retains adequate tools to control the use of the information by the service provider. The franchisor or franchisee should seek the contractual right to audit the service provider’s compliance with the agreement, and should exercise this right in practice.
4. Conduct PIA prior to inter-provincial and cross-border transfer
Bill 64 creates a requirement for conducting a Privacy Impact Assessment (“PIA”) before information can be disclosed outside of Québec, which presumably applies to both inter-provincial and to foreign disclosures. Bill 64’s PIA is a new requirement. No such express requirement exists under PIPEDA.
The entity must also communicate with the person whose personal information is transferred out of Québec by entering into a written agreement. The agreement should consider the outcome of the PIA and establishes adequate protections taking into account the sensitivity of the personal information, the purpose for which it is to be used, safeguards, and the receiving jurisdiction’s legal framework.
This means when the franchisee in Québec shares the data with a non-Québec franchisor, a PIA and such written agreement is required.
5. Get the English-French translation prepared
The Charter of the French Language (La Charte de la Langue Française in French) (the “Charter”) is a Québec law that makes French the usual language of business in Québec. Any person or company that sells products or services in Québec has to follow the language requirements of the Charter. This applies to all businesses no matter how big or small they are.
On May 13, 2021, the Government of Québec tabled An Act Respecting French, the Official and Common Language of Québec (the Act), which proposes the most significant changes to the Charter since its enactment in 1977. The Act introduces a new mandatory requirement for businesses to “inform and serve” clients in French, regardless of whether they are consumers.
For franchising business operated in Québec, this means that the privacy policy published on websites, the consent, and all other forms of communication to customers must be translated into French if they are originally drafted in English.
