SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

Elections Ontario lashed for missing data fiasco

Elections Ontario lashed for missing data fiasco

By:  Howard Solomon  On: 31 Jul 2012 For: Computing Canada Creator
 

After losing two unencrypted data sticks, staff were given two more to continue their work. ‘I hit the roof,” Ann Cavoukian told reporters

Not only that, she said, the initial report by a forensics firm into the loss wrongly said the data on the keys could only be accessed by Elections Ontario software or “specialized” commercial software.

In fact, Cavoukian said, the information was in a “standard database coding language” that could be accessed by a variety of commercially available and free software programs.

It was initially believed that the missing sticks held data on 25 voting districts out of 107. However, because the temporary staff were working on a total of 49 districts, Cavoukian can’t be sure data on which districts were lost.

So she’s recommending that 4 million voters in the 49 polls watch their bank and credit card records for the next 12 months for suspicious activity.

The data included persons names, addresses and dates of birth. Birth dates are important pieces of information for people who commit identity fraud, Cavoukian said. But the voters list also has exact names --- say, John Irving Smith, as opposed to John Smith – which could help fraudsters as well.
 
Elections Ontario is an agency that reports to the Speaker of the Legislature.

Two people who had responsibilities for the drives for locking up the drives at the temporary facility are no longer with agency.

The Ontario Provincial police has opened a criminal investigation.

Cavoukian said she couldn’t fault completely Elections Ontario’s technical staff completely, for they repeatedly advised management against using USB keys. Instead a decision was made to give the project leaders memory sticks with encryption software, but not the training in how to use it. Nor could she fault the temporary staff.

“While there appeared to be a general recognition of the importance of privacy and security,” Cavoukain said, “for the most part concerns about how personal information was to be managed tended to be directed to Elections Ontario’s external stakeholders [including political parties and returning officers] who are the recipients of the information, as opposed to their internal processes.”

“Ultimately, at the root of the problems uncovered during my investigation was the complete failure to build privacy into the routine day to day information management practices of this organization,” she told reporters.

“What is particularly discouraging was the discovery that the privacy and security of personal information, which is their sole responsibility in terms of the electorate, was not part of the training programs that were offered to staff.

The need to protect personal information must be part of Election Ontario’s culture, she said, to restore the trust of taxpayers.

To do it, she recommends

--The agency hire an independent group to audit its privacy policies and procedures, and develop a requirement that any personal information stored on mobile devices must be encrypted.


Sign up for our Newsletters

 












Print |  Views: 3503   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Howard Solomon Howard Solomon I'm assistant editor of ComputerWorld Canada covering network infrastructure, communications and government IT issues. An IT journalist  since 1997, I've written ... more

Recent Canadian IT Jobs




blog comments powered by Disqus