CANADIAN E-COMMERCE AND PRIVACY STUDY 2000:
A FAILURE TO COMMUNICATE
Professor Michael
Geist & Gabe Van Loon
University of Ottawa, Faculty of Law, Common Law
Section
STUDY INTRODUCTION
1. Goals of the Study
This study's primary objective was to evaluate pre-determined
features on selected Web sites of interest to Canadians in order to
develop an e-commerce "status report." Corporate privacy statements
and practices were the primary focus, though other factors relating
to security, domain names, and general e-commerce practices were also
examined. The chief reasons for performing this type of evaluation
included:
- Assessment of potential corporate compliance issues with
respect to Canadian privacy legislation.
- Addressing public concerns in the area of Internet privacy by
providing an objective report on the actual status of corporate
practices.
- Comparison of Canadian and international corporate approaches
to online privacy, and correlate with external factors such as
government regulation and pressure from consumer advocates.
2. Basic Methodology
Sites were selected based on consideration of a number of factors,
including:
- On-line user traffic surveys (Media Matrix)
- Search engines including Meta-Crawler and Google
- Lists compiled by sites such as AltaVista
- The off-line yellow pages (under different business
categories)
- The 2000 Globe and Mail Report on Business listing of top
Canadian companies
- The e25 ranking of the top 25 e-businesses in Canada from Bain
& Company and the Globe and Mail
- Linking from major Canadian portals
The evaluators completed a two-page evaluation form for each site.
Most evaluations were quantifiable to facilitate comparisons between
sites and categories of sites. Sites were assessed on a
pre-determined absolute scale. In 40 separate categories, sites were
given rankings dependant on the presence or absence of certain
factors or groupings of factors. The data from the individual forms
was collated and compiled in a spreadsheet.
3. Study Timing and Size
The survey was conducted from May to September 2000. Analysis was
performed from September to November 2000. All sites were visited on
repeated occasions to ensure validity and currency.
A total of 259 sites were studied. The majority of the sites
(194) analyzed were of Canadian origin, as defined by corporate
ownership and/or target audience. However, a number of sites of
"dual-origin" are also included in the evaluation (42). These sites
may be based outside Canada but appear to target a Canadian audience
by including significant Canadian content. A small number of major
"foreign" sites (23) that surveys suggest are of interest to
Canadians but do not have customised Canadian content were also
included.
A complete list of all sites surveyed is contained at Appendix A.
For comparison purposes, the sites are divided into 34 categories,
and the categories are grouped into 5 sectors. The sectors and
categories are as follows:
1. E-commerce Group
ISPs, Music, Auction, Groceries, Hardware, General E-Commerce,
Traditional Retail, Software, Auto, Auto Rentals, Travel Agents
2. Sensitive Info Group
Banks, Brokers, Insurance, Financial, Career, Online Recruiting,
Health
3. Services Group
Telecommunications, Legal, Real Estate, Travel Agents, Airlines,
Trains, Buses
4. Culture and Government group
Museum, Events, Sports, Hobbies, Government, Education
5. Canadian Media group
Magazines, newspapers, TV & radio
STUDY HIGHLIGHTS
1. PRIVACY AT RISK &endash; THE TIE BETWEEN DATA COLLECTION AND
ABSENT PRIVACY POLICIES
- 27% of sites do not have privacy policies but collect
significant personal data
- Canada/Dual Origin split - 32% vs. 10%
- Particularly bad for Canadian services (46%), culture (49%)
2. THE MISSING POLICIES
- 41% of all sites (Canadian, dual, and foreign) did not have a
privacy policy
- 50% of Canadian sites did not have a privacy policy
- only 15% of sites have policies specifically targeted toward
children
- 58% of sites do not provide privacy warning before collecting
personal information
- only 21% of sites make their privacy policies easily
accessible
3. THE INADEQUATE POLICIES/C-6 COMPLIANCE
- 26% of sites use cookies but do not reveal that to users
- 46% of privacy policies do not contain a statement of purpose
relating to information collection
- 94% of sites do not provide information on data retention
policies
- 62% of privacy policies do not provide access to previously
submitted information
- 57% of privacy policies do not provide contact
information
- 90% of privacy policies do not provide information on updating
personal information
- 40% of sites do not indicate whether they share information
with third parties
4. THE DISAPPOINTING POLICIES
- only 10% of sites use opt-in for first party information
- only 3% of sites use opt-in for third party information
- 24% of sites request more than just name and email address
without opt-out in conjunction with online services
5. THE DIFFERENCE BETWEEN CANADIAN SITES & DUAL
ORIGIN
significant variation between Canadian only and Dual Origin sites
on the following issues:
- statement of purpose (55/46)
- cookies (29/19)
- no access to previously submitted information (68/44)
- no contact information provided (63/33)
- no ability to update previously submitted information
(94/76)
- no statement regarding accessibility (51/17)
- no statement regarding sharing information with third parties
(49/14)
- no child specific privacy provisions (91/71)
- presence of privacy policy in addition to substantial
collection of information (46/65)
- no privacy policy in addition to substantial collection of
information (32/10)
- statement indicating no sharing with third parties
(29/40)
6. REGULATION MAKES A DIFFERENCE &endash; SENSITIVE INFORMATION
SECTORS DO BETTER
sector fares better than others for:
- retention
- access
- contact information
- information updating
- use of ADR
- security
7. IS PRIVACY NOT PART OF CANADIAN CULTURE &endash; THE POOR
SHOWING OF CULTURE AND MEDIA SECTORS
consistently poor showing for the culture, government & media
sectors:
links
- statement of purpose
- access to information
- updating information
- contact information
- disclosure of policies
8. DISAPPOINTING USAGE OF ADR & SEAL PROGRAMS
- low use of seals
- noise with seal programs &endash; no dominant program
- no use of ADR except where regulatory compliance
9. WHOSE LAW APPLIES?
- only 20% of sites employ jurisdiction clause
- of the dual origin sites, Canadian jurisdiction only half of
the time
10. WHAT'S IN A NAME &endash; LACK OF CONFIDENCE IN
DOT-CA
- 41% of Canadian sites use dot-com
- 35% of Canadian sites use both dot-com and dot-ca
- only 16% of e-commerce sites use dot-ca
STUDY METHODOLOGY
The pre-configured two-page evaluation form that was used for this
study took into account the following factors and contained the
following elements:
- A brief description of the nature of business, the URL of the
site, the "home base" of the site
- Top level domain name choices
- A listing of the type of personal information collected on
the site. Separate listings were made regarding off-line and
on-line information collection. Off-line information collection
relates to activities such as retail purchases, travel bookings,
and financial services that potentially require the provision of a
mailing address. On the other hand, on-line service information
collection relates to services that can be conducted completely
on-line such as comment forms, email subscriptions, and chat room
sign-ups.
- Accessibility of the statement:
- Is access to the privacy statement clearly evident to the
user?
- Is it available directly on the site, or does it have to be
downloaded?
- Is a direct link to the privacy statement available on
every page on the site, most pages, active e-commerce pages, or
just the home page?
- Is the statement easy to understand, or written using legal
or technical terms?
- Comprehensiveness of statement:
- Are the purposes for which personal information is
collected clearly stated?
- What issues are dealt with?
- Is there any reference to dispute resolution
mechanisms?
- Are retention times of personal information indicated? (The
degree of comprehensiveness will be dependent on the nature of
the business)
- Can consumers access their own personal information to
update / modify it?
- Is there any reference to security procedures that are in
place to prevent information theft or misuse? What type of
security measure is utilised?
- Substantive nature of policy:
- With reference to the comprehensiveness of the policy, it
may detail very clearly what a company does with personal
information, but this could still involve anything up to and
including complete disclosure to third parties.
- Fair warnings to consumers:
- If information is about to be collected, are consumers
given details at that specific time, in an easily accessible
manner?
- Presence of external audits/ quality assurance
- CA WebTrust, BBBOnline, TRUSTe
- Contact information:
- Is a contact name or address provided relating to the
privacy statement?
- Specific accommodation made for children
- Summary and Comments
- For assessors to fill in more "subjective" commentary - not
captured in other categories of analysis
Where possible, the survey form was designed to have enhanced
quantifiability. For example, a sliding scale was used in the
"statement of purposes for information collection" category. The
clearest privacy statements ranked "0" whereas statements that did
not include a statement of purposes for information collection would
rank "4". Such scales were based on readily identifiable
characteristics of Web sites.
Note that most of the analysis performed for the purpose of this
research was passive in nature. It is possible that a corporate
entity on the Internet may make certain representations regarding
their privacy policy, but have no intention to actually apply the
procedures that they have indicated they will follow.
The following steps were taken to locate privacy policies on the
Web sites surveyed:
- Accessing direct link to "privacy policy" from the home
page
- Visual survey for keywords such as "privacy", "security",
"legal notices", "privacy policy" on other pages
- Use of restricted site-specific search engine
- Use of external search engine
Appendix A: Listing of Site Sectors and
Categories
E-commerce Group
Portals, ISPs, Search Engines (13)
- www.sympatico.ca
- www.hotmail.msn.com
- www.canoe.ca
- http://ca.yahoo.com/
- www.canada.com/
- www.aol.ca/
- http://ca.msn.com/
- http://home.netscape.com/
- www.altavista.ca/
- http://www.peionline.com/
- www.canada411.ca/
- www.tucows.com/
- www.webhel.com/
Music (9)
- www.HMV.com
- www.samscd.com/
- www.mymusic.ca/
- www.sonymusic.ca/
- www.cdplus.com/
- www.archambault.ca
- www.absound.ca/
- www.bmgmusicservice.com
- www.columbiahousecanada.com
Auctions (4)
- www.bid.com/service/
- www.bidaway.com
- www.clickabid.com/help/privacy.shtml
- www.canadaauction.com/
Grocery (2)
- www.peachtreenetwork.com/
- www.44thstreet.com/
Software Companies (4)
- www.hummingbird.com
- www.corel.com/
- www.microsoft.com/
- www.cognos.com/
Hardware Companies (5)
- www.dell.ca/
- www.apple.com/
- www.eurocom.ca
- www.angelcomputers.com
- www.ipc.ca/
General E-Commerce (13)
- www.norstarmall.ca/
- www.chapters.ca/
- www.indigo.ca/
- www.buy.ca/
- www.canada.buy.com
- www.etoys.com/
- www.airmiles.ca
- http://secure.gardencrazy.com
- www.savingyoumoney.com/
- www.point2.com
- www.onvia.com
- www.brandera.com
- www.patchgear.com
Traditional Retail On-Line (14)
- http://www.sears.ca/
- www.CanadianTire.ca/
- www.FutureShop.ca
- www.pharmasave.com
- www.HBC.com/
- www.grandandtoy.com
- www.marks.com
- www.RONA.ca/
- www.Reitmans.ca
- www.JeanCoutu.com
- www.leChateau.ca
- www.radioshack.ca
- www.Danierleather.com
- www.Blacksphoto.com
Automobiles (11)
- http://english.honda.ca/
- http://www.autobytel.ca/
- http://www.ford.ca/
- www.carcanada.com/
- www.autonet.ca/
- www.autoweb.com/
- www.carsbynet.com/
- www.driveonline.ca
- www.chariots.com
- www.canadacar.com
- www.carcostcanada.ca
Automobile Rentals (7)
- www.thrifty.com
- www.budget.ca
- https://wfserver01.discountcar.com/
- http://www.dollar.com/
- www.hertz.com/
- www.rentawreck.ca
- www.nationalcar.com
Travel Agents (14)
- www.thomascook.ca/
- www.carlsonwagonlit.ca
- www.travelocity.ca/
- www.uniglobe.ca/
- www.travelworld.bc.ca/
- www.gtstravel.com/
- www.sears.ca/
- www.downhillriders.com/
- www.bayridgetravel.com/
- www.atcotravel.com/
- www.airlineticketcentre.com/
- www.carletontravel.com
- www.tripeze.com/
- www.expedia.ca/
Sensitive Info Group
Banks (12)
- http://www.bmo.com/
- http://www.cibc.com/
- http://www.tdbank.ca/
- http://www.royalbank.com/
- http://www.scotiabank.com/
- http://www.ingdirect.ca/
- http://www.bankone.com/
- http://www.nbc.ca/
- https://www.citizensbank.ca/
- http://www.bankofamerica.com/
- www.lbcdirect.laurentianbank.ca/
- www.hkbc.com/
Brokers (4)
- www.canada.etrade.com/
- www.tdwaterhouse.ca
- www.bmonesbittburns.com/
- www.hsbc.ca
Insurance (5)
- www.manulife.com/
- www.cooperators.ca
- www.gwl.ca
- www.sunlife.ca
- www.canadalife.com/
Financial Services (4)
- www.quicken.ca/
- www.stockhouse.ca/
- www.canadamortgage.com/
- www.baystreetdirect.com
Career (5)
- www.workopolis.ca/
- www.jobsonline.ca/
- http://english.monster.ca/
- www.careerclick.com
- www.jobshark.ca
On-line Recruiting (2)
- www.nortelnetworks.com/
- www.pmcsierra.com
Health (7)
- www.sutton-javelin.com/medicalert2/
- www.healthnet.ca
- www.specialk.ca
- www.medbroadcast.com/
- www2.healthmart.ca/
- www.wellnet.ca
- www.globalmedic.com
Services Group
Telecommunications and Cable (10)
- www.rogers.ca/
- https://secure.shaw.ca/
- www.bell.ca
- www.attcanada.com/
- www.primus.ca
- www.Cantel.com/
- www.magma.ca
- www.Psi.ca
- www.Clearnet.com/
- www.videotron.ca
Legal Services (4)
- www.blakes.ca
- www.mccarthy.ca
- www.blgcanada.com
- www.heenanblaikie.com
Real Estate (5)
- http://realtors.mls.ca/
- www.coldwellbanker.ca/
- www.remax.com/
- www.century21canada.com/
- www.realestate.ca/
Airlines (5)
- www.AirCanada.com
- www.Canada3000.com
- http://www.westjet.com/
- http://www.british-airways.com/
- www.royal.ca
Travel Agents (14)
- www.thomascook.ca/
- www.carlsonwagonlit.ca
- www.travelocity.ca/
- www.uniglobe.ca/
- www.travelworld.bc.ca/
- www.gtstravel.com/
- www.sears.ca/
- www.downhillriders.com/
- www.bayridgetravel.com/
- www.atcotravel.com/
- www.airlineticketcentre.com/
- www.carletontravel.com
- www.tripeze.com/
- www.expedia.ca/
Hotels (12)
- www.clubintrawest.com
- www.bestwestern.com
- www.daysinn.com/
- www.mintohotel.com
- www.cphotels.com/
- www.hojo.com/
- http://go.marriott.com/canada
- www.hilton.com/
- www.ramada.ca
- www.travelodge.com/
- www.deltahotels.com
- www.fourseasons.com/
Trains and Buses (3)
- www.Viarail.ca
- www.greyhound.ca
- www.can-arcoach.com/
Culture and Government group
Museums and Galleries (5)
- http://www.cirquestore.com/
- http://national.gallery.ca/
- www.osc.on.ca
- www.rom.on.ca/
- www.ago.net
Events (5)
- www.montrealjazzfest.com/
- www.Calgary-Stampede.com
- www.tulipfestival.ca
- www.admission.com/
- www.ticketmaster.ca/
Sports (7)
- www.tsn.ca/
- www.nhl.com/
- www.headlinesports.com (same as www.thescore.ca)
- www.montrealexpos.com
- www.book4golf.com
- www.sportsrocket.com
- www.gearunlimited.com
Hobbies and Interest (4)
- www.Golfcanada.com/
- www.anglingbc.com
- www.icangarden.com/
- www.bingo.com
Government (17)
- http://www.hc-sc.gc.ca/ (Health Canada)
- http://pm.gc.ca/ (Prime Minister's Page)
- http://www.oag-bvg.gc.ca/ (Auditor General of Canada)
- www.elections.ca/
- www.dfait-maeci.gc.ca/ (Department of Foreign Affairs)
- www.canadapost.ca/
- www.epost.ca
- www.rcmint.ca/
- www.gov.on.ca
- www.city.toronto.on.ca
- www.ontarioparks.com/
- www.ontarioplace.com
- www.gov.mb.ca
- www.gov.sk.ca/
- www.gov.ab.ca/
- www.gov.bc.ca/
- www.gouv.qc.ca/
- www.hrdc-drhc.gc.ca (Department of Human Resources and
Development)
Education (7)
- http://www.uwo.ca/
- www.umanitoba.ca
- www.usask.ca
- www.sheridancollege.on.ca
- www.ualberta.ca/
- www.ubc.ca/
- www.athabascau.ca
Canadian Media Group
Magazines (14)
- www.flare.com/
- www.macleans.ca/
- www.chatelaine.ca/
- www.saturdaynight.ca
- www.canadiangeographic.ca/
- www.equinox.ca
- www.lactualite.com
- www.canadian-living.com/
- www.frankmag.net/
- www.tor-lifeline.com/
- www.xtra.ca
- www.readersdigest.ca/
- www.albertareport.com/
- www.mbnet.mb.ca/ (Canadian Dimensions Magazine)
Newspapers (12)
- www.sharenews.com ("Canada's largest ethnic newspaper")
- www.globeandmail.com/
- www.nationalpost.com
- www.torstar.com
- www.montrealgazette.com/
- www.vancouverprovince.com
- www.ledevoir.com
- www.herald.ns.ca/
- www.bowesnet.com/
- www.lapresse.com
- www.lesoleil.com/
- www.montrealmirror.com/
Television and Radio (10)
- http://cbc.ca/
- www.CTV.ca
- www.globaltv.ca
- www.Citytv.com/
- www.Theweathernetwork.com/
- www.infinit.com/ (TVA network)
- www.Discovery.ca/PrivacyPolicy/
- www.YTV.ca
- www.Chum.ca
- www.muchmusic.com/
Other
Children/Youth Content (3)
- www.studyweb.com
- www.kids-korner.com
- www.2learn.ca