Bank ensures openness and comparable protection for personal information transferred to third party
PIPEDA Report of Findings #2020-001
August 4, 2020
A former employee of TD Canada Trust (TD) complained that TD had outsourced aspects of its fraud claims processing services to a third party service provider in India without getting customers’ consent or offering the choice to opt out. We found that TD is not required to obtain additional consent for this activity and that it was appropriately open to current and potential customers about its oursourcing. We also found that TD remained accountable for the personal information of its clients through a strong contract and monitoring approach.
- Organizations transferring personal information to third-party processors should communicate clearly about this transfer to both current and potential customers
- Organizations should address privacy risks related to trans-border data flows through contractual and other measures, including compliance monitoring
Complaint under the Personal Information Protection and Electronic Documents Act (the Act)
The Complainant, a former employee of the TD Fraud Claims Department, became aware through her employment that TD had outsourced aspects of its fraud claims processing activities to a third-party service provider in India. She submitted a complaint to our Office alleging that TD did not obtain consent for, or allow customers to opt-out of, the transfer of personal information to a service provider in a foreign jurisdiction. The Complainant further alleged that TD had not been sufficiently open with respect to this practice. Finally, our Office also investigated whether TD was being accountable, by ensuring that its third-party processor provided a level of protection of personal information comparable to that required under PIPEDA.
First, we found that the third-party service provider was using TD customers’ information to manage fraud claims for TD, a purpose for which TD had originally collected the information. Noting that TD’s consent for the use of customers’ information for fraud claims management was not at issue in this complaint, in our view, TD was not required to obtain separate consent for, or to provide customers the choice to opt out of, the transfer of customers’ personal information to the third-party service provider for that same purpose.
Secondly, in our view, TD was sufficiently open about this transfer for processing. TD provides customers with information pertaining to its transfers of personal information, including to service providers in other jurisdictions, in account opening agreements. It also makes this information available through its various privacy resources, in bank branches and on its website.
Finally, we found that TD had been accountable with respect to the information it transferred to the third party in question, ensuring a comparable level of protection for that information via a robust contract as well as other methods, including regular audits to ensure compliance with contractual requirements.
We therefore found each of the matters we investigated to be not well-founded.
- The Complainant alleged that TD Canada Trust (“TD”) was outsourcing and transferring personal information to a third party service provider located in India for the processing of fraud claims without the customer’s knowledge and consent. More specifically, the Complainant alleged that TD:
- did not allow customers to opt-out of this activity; and
- was not being open about its outsourcing practices in relation to fraud claims processing.
- Given that the allegations relate to the transfer of personal information across borders, our Office also investigated whether TD was being accountable with respect to outsourcing certain services, by ensuring that its third-party processor provided a level of protection that was comparable to that required under the Personal Information Protection and Electronic Documents Act (“PIPEDA”, or the “Act”).
- The Complainant is a former employee of the TD Fraud Claims Department.
- In 2013, TD entered into a contractual relationship with a service provider (“service provider” or “provider”) to assist its fraud claims investigation team. The service provider is a large multinational IT service and consultancy firm that offers numerous products and services. In the circumstances of this case, the service provider has employees located in India.
- The service provider performs specific functions to support TD’s Canadian fraud investigation team. These functions relate to the processing of transaction disputes relating to debit fraud, Visa debit non-fraud (merchant disputes), and credit card fraud claims. The functions that the service provider performs include, but are not limited to, preparing customer dispute forms and other supporting documents for TD to send to cardholders, issuing temporary/provisional credit on transactions approved as fraud claims and investigated for recovery, and adjudicating customer disputes.
- While the service provider performs other services for TD, the scope of our investigation was limited to only those services relating to fraud claims processing for Canadian clients.
- At the outset, we note that this complaint focused on TD’s general practices around the use of a third party service provider in a foreign jurisdiction to process personal information. The Office of the Privacy Commissioner of Canada (“OPC”) has no evidence of any breaches of security safeguards relating to TD’s outsourcing of fraud claims processing activities, nor has the Complainant alleged that the service provider is failing to meet the privacy and security obligations set out under its contract with TD.
- Our analysis of this matter was informed by our Office’s Guidelines for processing personal data across bordersFootnote 1 (the “Guidelines”).
- These Guidelines note that PIPEDA does not prohibit organizations from transferring personal information to an organization in another jurisdiction for processing.
- That said, organizations remain accountable for the protection of personal information under any outsourcing arrangement. Principle 4.1.3 of PIPEDA states the following:
An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.
- As a preliminary matter, TD has asserted that it does not “transfer” customer personal information to the service provider in India. Rather, TD says that the service provider has only limited remote access to personal information stored in Canada via a secure TD-managed portal.
- We accept TD’s submissions that the personal information in question is not being stored on servers in India. However, TD acknowledges in its submissions that personal information is accessed and processed by the employees of a service provider located in India to carry out specific tasks on behalf of TD. In our view, therefore, TD does “transfer” personal information to a third party for processing within the meaning of Principle 4.1.3 of PIPEDA such that it remains accountable for that customer information.
- In this case, we specifically considered:
- Consent: if TD was required to obtain consent for, or allow customers to opt-out of, the transfer of personal information for the processing in question;
- Openness: if TD was sufficiently open with respect to its transfer of personal information to a third party service provider in a foreign jurisdiction for processing; and
- Accountability: if TD ensured a comparable level of protection while personal information was being processed by the service provider.
ISSUE 1: Consent
- In our view, and for the reasons that follow, TD does not require additional consent for its transfer of customers’ personal information to the service provider for purposes of fraud claims management. Nor is TD required to provide its customers with the choice to opt out of this transfer.
- Principle 4.3 of Schedule 1 of the Act states that the knowledge and consent of the individual are required for the collection, use, or disclosure of personal information, except where inappropriate.
- As described in our Office’s Guidelines, when an organization transfers personal information to a third party for processing, the third party can only use the personal information for the purposes for which the information was originally collected. If the information is being used for a purpose for which it was originally collected, additional consent for the transfer is not required.Footnote 2
- The Complainant did not question whether TD itself could collect and use personal information for the purpose of investigating and resolving fraud claims. The Complainant instead takes issue with TD’s practice of transferring personal information to a third-party service provider in a foreign jurisdiction for processing, rather than TD processing the personal information in question in Canada.
- While the Complaint did not question TD’s initial collection of personal information, we nevertheless examined the purposes that TD identifies when it obtains consent at the outset of the customer relationship in order to determine whether the service provider was using information for the same purpose, such that additional consent for the transfer of personal information would not be required.
- TD submitted to our Office that it obtains consent to use customer information for the processing of fraud claims via its account opening agreements, which include the TD Privacy Terms (the TD Privacy AgreementFootnote 3 and TD Privacy CodeFootnote 4). These documents identify a number of purposes for which customers’ information is collected.
- TD submitted that all of its account opening agreements contain substantially similar descriptions of the purposes for which customers’ personal information is collected, used, and disclosed. For example:
- Within the TD Privacy Agreement, the ‘Collecting and Using Your Information’ section identifies that:
We will limit the collection and use of Information to what we require in order to serve you as our customer and to administer our business, including to: […] help protect you and us against fraud and error…Footnote 5 [Emphasis added.]
- TD’s Cardholder and Electronic Financial Services Terms and Conditions identifies in section 30, ‘Consent to the Collection, Use and/or Disclosure of Your Information,’ that:
You agree that, at the time you request to begin a relationship with us and during the course of our relationship, we may share your Information with our world-wide affiliates, and collect, use and disclose your Information as described in the Privacy Agreement on td.com, including for, but not limited to, the purposes of […] protecting us both from fraud and error…Footnote 6 [Emphasis added.]
- Within the TD Privacy Agreement, the ‘Collecting and Using Your Information’ section identifies that:
- TD submitted to our Office that the personal information it transfers to the service provider is used only to fulfill specific tasks relating to processing fraud-related claims – in other words, for the same purpose for which TD collects the information. The supporting documentation provided by TD, including its contract and Statement of Work with the service provider, is consistent with this assertion. We further note that the Complainant did not allege that the service provider was using personal information for any purposes other than supporting TD’s fraud-related activities.
- Considering that the service provider uses personal information provided by TD for the same purpose as that identified for the purpose identified to customers when TD obtains consent for its collection and use of customers’ information, we are of the view TD is not required to obtain separate consent for the transfer of customer information to the service provider.
- The Complainant also complained that customers could not opt out of the transfer of their information to India for fraud claims purposes.
- We note that our Guidelines explain that “once an informed individual has chosen to do business with a particular company, they do not have an additional right to refuse to have their information transferred.”
- It is our view that TD is not obligated under PIPEDA to allow its customers to opt-out of the transfer at issue in this investigation.
- Accordingly, we find this aspect of the complaint, with respect to Principle 4.3 of Schedule 1 of the Act, to be not well-founded.
ISSUE 2: Openness
- In our view, TD is sufficiently open about its transfers of personal information for processing.
- Principle 4.8 of the Act requires that organizations make readily available specific information regarding how they manage personal information.
- Our Office’s Guidelines say that individuals should expect transparency on the part of organizations when it comes to transfers to foreign jurisdictions, including acknowledging that no contract can override the criminal, national security or other laws of a country to which information has been transferred. The Guidelines provide that:
Organizations need to make it plain to individuals that their information may be processed in a foreign country and that it may be accessible to law enforcement and national security authorities of that jurisdiction. They must do this in clear and understandable language. Ideally they should do it at the time the information is collected. [Emphasis in original.]
- TD submits that it provides information to customers up-front, in its account opening agreements and the TD Privacy Code, that it may transfer personal information to third parties for processing in other jurisdictions, and that that personal information may be subject to disclosures pursuant to the laws of foreign jurisdictions.
- For example, the TD Privacy Code includes the following statements:
- the ‘When we release your information’ section identifies that:
…we may release your information to parties outside TD in certain circumstances, which include -
We give a limited amount of information, only as necessary, to our suppliers and agents […] who provide goods and services to you, through us. These suppliers and agents may be located in Canada or other jurisdictions or countries and may disclose information in response to valid demands or requests from governments, regulators, courts and law enforcement authorities in those jurisdictions or countries.Footnote 7
- the ‘Why we share your information’ section also identifies that:
Your information may be shared, stored or accessed in Canada or other jurisdictions or countries. Your information may be disclosed in response to valid demands or requests from governments, regulators, courts and law enforcement authorities in those jurisdictions or countries.Footnote 8
- the ‘When we release your information’ section identifies that:
- Within the TD Privacy Agreement, the ‘Disclosing your information’ section also identifies that:
We may disclose Information […] to suppliers, agents and other organizations that perform services for you or for us or on our behalf.Footnote 9
- The ‘Privacy Highlights’ webpage includes the following statements under ‘Uses’:
We may release your information to parties outside TDBG [TD Banking Group], such as regulators, and our suppliers and agents who assist us in serving you and who may be located in Canada or other jurisdictions or countries and may disclose information in response to valid demands or requests.Footnote 10
- Individuals receive information regarding TD’s privacy practices as part of their account opening agreement. In cases where customers cannot review the full Privacy Terms at the time that they apply for a TD product, such as where an individual applies by telephone, TD submitted that it provides an oral summary and later sends the full privacy agreement to the customer with other account documentation. We also note that individuals can access TD privacy documentation in person at a TD branch, or through the TD website at any time.
- For example, an individual that wishes to access the TD Privacy CodeFootnote 11, TD Privacy HighlightsFootnote 12, or other resources that are available on the ‘Our privacy commitments’ webpageFootnote 13 can navigate to these pages in the following manner:
- from the TD ‘Personal Banking’ main pageFootnote 14 or other TD webpage such as ‘Investor Relations’Footnote 15 or ‘Careers’Footnote 16, navigate to the bottom of the page and select the ‘Privacy and Security’ link in the bottom banner;
- from the ‘Privacy and Security’ pageFootnote 17, navigate to the ‘Privacy Practices’ heading and select the ‘View our privacy commitments’ link at the end of the section; and,
- from the ‘Our privacy commitments’ pageFootnote 18, select the ‘TD Privacy Highlights’, ‘TD Privacy Code’, or other TD privacy resources available on the webpage.
- In her submissions, the Complainant pointed to the example of the TD First Class Travel Visa Infinite Cardholder Agreement and Benefit Coverages Guide.Footnote 19 We have reviewed this agreement and note that it contains substantially similar languageFootnote 20 to that relied on by TD, as described above.
- In our view, TD makes readily available, and quite prominent, clear and understandable information regarding its transfers of personal information to third-party service providers, including in foreign jurisdictions, for processing.
- Further, these notices acknowledge that customers’ information may be disclosed in response to lawful demands by authorities within the jurisdictions where information is being processed.Footnote 21
- We therefore find this aspect of the matter, with respect to Principle 4.8 of Schedule 1 of the Act, to be not well-founded.
ISSUE 3: Accountability
- In our view, TD has, via contractual and various other means, provided a level of protection comparable to that required under the Act, for customers’ personal information being processed by the third-party service provider for fraud claims management purposes.
- As noted above, PIPEDA does not prohibit organizations from transferring personal information to an organization in another jurisdiction for processing. However, PIPEDA does establish rules governing transfers for processing.
- Under Principle 4.1.3, an organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.
- Importantly, the wording of Principle 4.1.3 makes it clear that TD remains accountable for personal information, even if it chooses to use a third-party service provider for processing.
- Though the Complainant did not raise explicitly the issue of accountability in her complaint, we deemed it appropriate to examine this issue during the course of our investigation given its close relationship to the issue at hand and its importance in protecting individuals’ privacy in outsourcing arrangements. This was particularly so considering that the information TD transfers to the third party includes personal information that can be sensitive, such as financial transaction history and associated details.
- The Guidelines note that the primary means by which organizations protect personal information in the hands of third-party processors is through contract. Robust contracts are especially important when the third-party processor is located in a foreign jurisdiction and may not itself be subject to PIPEDA.
- TD has asserted that, through its contract with the service provider, and other safeguarding measures, it has established a comprehensive set of privacy and security-related practices that provide a comparable level of protection for customers’ personal information while the service provider in India is processing it.
- Pursuant to that contract, the service provider is obligated to comply with Canadian privacy laws. This clause would not, on its own be sufficient to ensure a comparable level of protection. Thus, we closely reviewed TD’s contract with the service provider, as well as the supporting documentation that TD provided our Office to demonstrate how it confirms that the service provider is meeting contractual requirements on an ongoing basis.
- According to the OPC Guidelines, a “comparable level of protection” within the meaning of Principle 4.1.3 means that the third-party processor must provide protection that can be compared to the level of protection the personal information would receive if it had not been transferred. While that does not mean that the protections must be the same across the board, it does mean that they should be generally equivalent.
- Organizations should be able to demonstrate that they have addressed the PIPEDA principles that are applicable within the context of their processing arrangements with third-party service providers, which will depend on, among other things, the nature of the services provided.
- In this case, the service provider has only remote access to a limited amount of customer personal information via a TD-managed portal. Employees of the service provider do not interact directly with TD customers, nor do they use information other than what is made accessible by TD.
- Given the limited nature of the service provider’s access to, and use of, personal information in these circumstances, our Office focused its analysis of “comparable level of protection” for the purposes of Principle 4.1.3 on whether TD’s contract limited collection (Principle 4.4); limited use, disclosure, and retention (Principle 4.5); and appropriately safeguarded its customers’ personal information (Principle 4.7).
- Our Office’s assessment of privacy protections surrounding transfers to third-party service providers will depend on the facts of each case and the nature of the services being provided. In a different situation, greater emphasis may be placed on different principles under Schedule 1 of PIPEDA.
- Principle 4.7.1 provides in part that safeguards shall protect personal information against unauthorized use and disclosure. In considering TD’s level of protection while information is being processed by the third party service provider, we note that its safeguards are also the primary mechanism by which it ensures that customers’ personal information is protected in a manner consistent with Principles 4.4 and 4.5.
- More specifically, we note that the contract provides that the service provider receives access to only the personal information it requires to fulfill specific tasks on behalf of TD, which is stored and maintained in Canada (i.e., it does not otherwise collect any personal information for this purpose). The contract prohibits, and associated safeguards prevent, the service provider from using or disclosing the personal information it accesses for any purposes other than those set out under the contract, and from retaining any personal information in India.
- In assessing the adequacy of TD’s safeguards, we note that the level of protection of personal information should be commensurate with its sensitivity, per Principle 4.7.2. TD represented to our Office that service provider employees have access to financial information and details of customers’ fraud claims, which we note can be sensitive, meaning that a higher level of safeguards would be required to ensure protection of the personal information accessed by the service provider.
- Principle 4.7.3 provides further that the methods of protection should include physical, organizational, and technological safeguards. Below, we provide a summary and a non-exhaustive list of examples of the various methods by which TD provides comparable protection for customer information transferred to the service provider in question. The contractual and other measures implemented by TD can be broadly characterized as:
- Risk assessment prior to entering into the contract,
- Employee background assessment and monitoring,
- Employee policies and training,
- Work environment controls,
- Access and other cybersecurity controls, and
- Proactive monitoring and enforcement of contractual obligations.
Risk assessment prior to entering into the contract
- TD engaged in a number of risk assessment activities to identify and mitigate the potential privacy risks associated with engaging the service provider prior to signing a contract. These activities included:
- following a proprietary risk management process that included a review of the Office of the Superintendent of Financial Institutions (“OSFI”) Guideline, Outsourcing of Business Activities, Functions and Processes,Footnote 22 as well as the OPC’s Guidelines for Processing Data Across Borders;
- completing an internal privacy impact assessment;
- obtaining legal advice on the privacy and information security obligations imposed under Indian law, including India’s Information Technology Act 2000Footnote 23; and,
- incorporating the findings of these risk assessment activities in the contract with the service provider.
- We reviewed portions of these risk assessment activities as part of our analysis of TD’s representations, including the internal privacy impact assessment. We did not review the legal advice that TD received prior to signing a contract with the service provider as TD claimed solicitor-client privilege over this advice.
Employee background assessment and monitoring
- TD included a number of requirements relating to employee background verification and monitoring within the contract. The service provider is required to:
- conduct criminal and other background verification for all current and prospective employees including annual re-verification; and,
- remove access to TD systems and information for any service provider employees that fail any aspect of background verification.
Employee policies and training
- The contract requires the service provider to:
- develop and maintain policies and procedures for employees to prohibit copying of TD customer personal information, to ensure that no TD information is stored outside of Canada;
- develop and maintain policies and procedures for physical security management;
- Provide specified training according to TD accreditation requirements to all employees, including regular refresher training; and,
- comply with TD’s Information Security practices.
Work environment controls
- The service provider is required within the contract to control the work environment to prevent employees from storing, copying, downloading, recording, printing, distributing, caching, or maintaining TD information through physical and organizational methods that include:
- prohibiting employees from bringing electronic devices, such as mobile devices, removable storage devices, and printers, or writing instruments into the physical workspace (also known as having a ‘clean room’ environment);
- requiring the ‘clean room’ to have a physical ceiling and no windows through which the contents, including information, contained in the room may be viewed or identified;
- engaging in physical monitoring of the service provider work environment, including through the use of security guards, visual inspections of employees entering the production environment for restricted material, and CCTV cameras; and,
- implementing paperless processes.
Access and other cybersecurity-related controls
- TD represented that it supplies all hardware and software to the service provider, and that it has implemented numerous measures to protect against unauthorized access to information, including:
- providing access to the TD environment and information through a remote web-based gateway platform, with all TD information stored and maintained within Canada;
- structuring databases that hold TD information to contain only information required for a specific task or business process, and incorporating a role-based access permissions model that limits employee access to only the databases that they require to perform specific tasks;
- ensuring that only computers that are physically located within the service provider’s ‘clean room’ environment, as described in paragraph 61, are able to access the TD environment;
- implementing two-factor authentication to access the TD environment;
- ensuring that service provider employees’ access is limited to visual access on their computer screens and to only the information required to perform their assigned tasks;
- partially masking certain sensitive personal information such as a SIN or date of birth, such that employees can only see a portion of those numbers on their computer screen;
- limiting activities that service provider employees can conduct – such as restricting access to unauthorized URLs and portions of the external web, allowing emails within the TD environment to be sent only to other email addresses in the TD domain, and disabling any print, cut, copy, screenshot, or similar capabilities;
- requiring the service provider to engage in electronic monitoring of employee activities, including through the use of computer access monitoring and audit logs;
- requiring the service provider to maintain a formal program to ensure malicious software protection is in place; and
- requiring the service provider to perform industry standard security and intrusion testing, including attack and penetration testing, at least annually.
- In addition, the contract requires the service provider to comply with TD security requirements, which include compliance with industry standards. Specifically, TD provided evidence that the service provider was ISO-27001:2013 certified, and TD verified the service provider’s compliance with those standards via certification by an independent third party. The service provider was initially certified against this standard in 2006 and most recently provided proof to TD of valid certification for the period of June 2019 to March 2021.
Proactive monitoring and enforcement of contractual obligations
- The contract allows TD to proactively monitor and audit the service provider to ensure contractual compliance.
- TD engages in monitoring activities including:
- regular audits by an independent auditor of the service provider’s practices including, but not limited to, security and access monitoring;
- requiring any issues identified during the course of any audit to be monitored by an independent auditor;
- requiring the service provider to obtain sign-off by the independent auditor to confirm that all remedial actions have been effective; and
- requiring the service provider to attest annually that it meets all contractual obligations.
- TD provided our Office with several examples of previous audits to illustrate this proactive monitoring process, including cases where deficiencies were identified and corrective measures applied to resolve these deficiencies.
- We note that the contract contains provisions to address non-compliance with contractual obligations, up to and including a termination clause.
- We are satisfied that these measures provide TD with the ability to effectively identify and resolve instances of non-compliance with contractual obligations.
- In our view, TD’s technological controls, coupled with the terms of its contract with the service provider and associated monitoring and enforcement of those contractual provisions do provide a level of protection comparable to that which would be required under PIPEDA if the information was processed by TD, in particular, under Principles 4.4, 4.5 and 4.7, which are most relevant in the context of this case. As a result, we are satisfied that TD has met the requirements of PIPEDA’s accountability principle.
- We therefore find this aspect of the complaint, with respect to Principle 4.1.3. of the Act, to be not well-founded.
- Accordingly, we conclude that the matter is not well-founded.
Report a problem or mistake on this page
- Date modified: