Google Main Search by MoneyBlogNewz (CC BY 2.0) https://flic.kr/p/92t8FA

Google Main Search by MoneyBlogNewz (CC BY 2.0) https://flic.kr/p/92t8FA

Columns

Why the Canadian Privacy Commissioner’s Proposed Right to be Forgotten Creates More Problems Than it Solves

The right to be forgotten, which opens the door to public requests for the removal of search results that are “inadequate, irrelevant or no longer relevant”, has been among the world’s most controversial privacy issues since it was first established in Europe in 2014. My Globe and Mail op-ed notes that the new right responds to concerns with potential reputational harms from inaccurate or misleading information online, but faces the challenge of balancing privacy protections with the benefits of the Internet for access to information and freedom of expression.

The Privacy Commissioner of Canada waded into the debate on Friday with a new draft report concluding that Canadian privacy law can be interpreted to include a right to de-index search results with respect to a person’s name that are inaccurate, incomplete, or outdated. The report, which arises from a 2016 consultation on online reputation, sets the stage for potential de-indexing requests in Canada and complaints to the Privacy Commissioner should search engines refuse to comply.

The Commissioner envisions a system that would allow Canadians to file de-indexing requests with leading search engines, who would be required to evaluate the merits of the claim and, where appropriate, remove the link from the search index or lower its rank to obscure the search result. Moreover, the commissioner would require search engines to actively block Canadians from accessing the offending links by using geo-identifying technologies to limit access in Canada to the results.

There is a need to address the risks associated with online reputation, but the Privacy Commissioner’s proposal raises a plethora of concerns. First, the claim that existing law includes a right to de-index search results stands on shaky ground. In addition to the broader questions regarding its consistency with freedom of expression protections under the Charter of Rights and Freedoms, there is reason to doubt whether PIPEDA, the private sector privacy law, applies to search results.

Federal privacy law is limited to commercial activity, yet search results are typically provided at no cost to the user nor the sites being indexed. Indeed, all the activity behind search – indexing content, developing algorithms to identify relevant results, and the display of those results – fall outside a conventional commercial transaction. There may be paid results or other advertising displayed with some search results, but those are arguably secondary to the indexing, ranking, and display of the relevant links.

Second, the report’s conclusions stand at odds with the majority of responses generated by the Privacy Commissioner’s consultation. The feedback from leading Internet services, media companies, academics, and civil society groups cautioned against creating a right to be forgotten in Canada. Without a foundation for its approach arising from the consultation, participants can be forgiven for wondering whether the report’s recommendations were a foregone conclusion.

Even if the report can be justified as consistent with existing privacy law, the proposed approach features a remarkable level of micro-managing of search engine activity. The de-indexing right is limited solely to search results for a specific name, meaning that alternate searches will not be affected. For example, an embarrassing court decision might be blocked for a person’s name, but parallel searches for facts arising from the case would not.

The report also suggests that rather than de-indexing a link, search engines might instead be asked to lower the rank of a search result or flag the result as inaccurate or incomplete. This would vest editorial power in search engines they have generally been reluctant to assume. While algorithmic decision making is far from neutral and deserves greater scrutiny, using privacy law to justify intentionally obscuring results by lowering ranks transforms information intermediaries into knowledgeable publishers.

Once the revised search results are developed, the report has further recommendations on who can access them, calling on search engines to use geo-identifying technologies to block access in Canada to offending links. Mandated use of blocking technologies as well as a parallel recommendation for a notice-and-takedown system for content that is not found under current Canadian law represents a dramatic departure from the existing Internet rules of the road. These forms of regulation cannot simply be read into PIPEDA by the Privacy Commissioner, but rather should require careful review and legislative reforms by Parliament.

Perhaps most troubling is that the report empowers search engines to play the role of judge and jury over the relevance and harm associated with links to content. Companies such as Google have attracted increasing concern over their ubiquitous role in how we access information. If implemented, the Privacy Commissioner’s report would troublingly expand that role by granting Internet giants the power to determine upon request whether a search result is incomplete or outdated as well as whether it should be de-indexed, lowered in ranking, or flagged as incomplete. In the search for a solution to online reputational harm, the proposal creates more problems than it solves.

10 Comments

  1. Pingback: Why the Canadian Privacy Commissioner’s Proposed Right to be Forgotten Creates More Problems Than it Solves « Data Protection News

  2. free speech getting a bad name vs letting the same group censor. wikipedia type thing, right? elitism. (que will love this.)

    flight from unreliable sources results, loss of new insights,
    retrogressive.
    reduco ad adsb’ium elements? : only their power is useable.

  3. Kelly Manning says:

    There is nothing new about the Right to be Forgotten. In the USA it goes back at least to 1931

    https://casetext.com/case/melvin-v-reid

  4. People do not need to worry or be concerned about being forgotten on the Internet. Within a few years all their pictures and articles will disappear due to the high number of new posts every day. In most cases it take about three years before the indexing drops old links. The billion photos uploaded every day gradually disappear due to their poor quality. It becomes space dust lost in the 1’s and 0’s.

    • Kelly Manning says:

      We have already seen Civil Cases in the USA try and demand retrieval from some of the archives disclosed by the Snowden document dump. Optical fibre lines in the USA have beam splitters that allow the NSA and other alphabetised government entities to make a complete copy of vast swaths of network traffic.

      The complexes they operate go far underground, so it is difficult to get a grip on the scale of the operation. If only that was a conspiracy theory.

      https://www.wired.com/2012/03/ff_nsadatacenter/

  5. Pingback: Canadian Privacy Commissioner Report Says Existing Law Already Gives Canadians A Right To Be Forgotten – Miller Trades

  6. Pingback: Canadian Privacy Commissioner Report Says Existing Law Already Gives Canadians A Right To Be Forgotten – Objective News

  7. Pingback: A Right to be Forgotten Online: A Response to the Office of the Privacy Commissioner Draft Position |

  8. Pingback: Privacy News Update, 2-18-18

  9. Pingback: 01-21 February 2018 | Privacy News Highlights