top of page

Our Recent Posts

Tags

Privacy and Travel

  • Aug 4
  • 7 min read

 

I am taking this opportunity to talk about travel and privacy.  A rather odd combination some may think, but as a privacy advocate, I believe that privacy is an important consideration both at home and abroad.

 

We recognize that in the present day, when we travel, we will suffer a loss of privacy. Whether it is from the collection of our personal data in order to travel, or when we arrive in a country, there is always a requirement to surrender personal information.

 

Let’s just take a look at a few of these:

 

-       Providing personal information in order to fly or check in for a cruise;

-       Submitting to a personal and baggage search at security screening;

-       Showing identification with a boarding pass at an airport terminal gate;

-       Showing a sea pass or cruise ID card in order to board a ship/boat;

-       Collection of biometric information when entering certain countries;

-       Collection of personal information in support of obtaining a visa; and

-       Collection and retention of identification when checking into hotels in certain countries.

 

I could continue to provide examples, but this is simply a sampling of times when information is collected and retained in support of travel.

 

Let’s take a quick look at the Entry/Exit System (EES), now in place in the following countries in Europe:

 

Austria                    Belgium                      Bulgaria                  Croatia

Czechia                  Denmark                     Estonia                   Finland

France                    Germany                     Greece                   Hungary

Iceland                    Italy                             Latvia                     Liechtenstein

Lithuania                 Luxembourg                Malta                      Netherlands

Norway                    Poland                        Portugal                  Romania

Slovakia                  Slovenia                      Spain                      Sweden

Switzerland

 

The EES applies to you if you are a non-EU national who are over the age of 12 and either:

 

  • need a short-stay visa to travel to the European countries using the EES

or

  • does not need a visa to travel for a short stay in the European countries using the EES


So what information is collected under the EES? A range of personal information such as the fingerprints of four (4) of your fingers along with your facial image. Your passport information from your picture and personal information page, and your entry and exit points (i.e.: airport, cruise port, rail, vehicle etc.).  Clearly this range of data fits squarely into the definition of personal information. Can you refuse on the grounds of privacy to provide the information? Yes, but then there will be a denial of service. You simply won’t be able to get into a country using the EES. The reason that such collection is allowed, is in relation to bona fide security concerns and immigration controls.


There is a need to ensure that such information, which is clearly personal information, is safeguarded. That is a key component to any data protection legislation. Since I used the EU as an example, I will return to the EU which has data protection, rules and rights surrounding the collection, use, disclosure and safeguarding such information. By way of a little privacy trivia history, the EU developed the core ten (10) privacy principles on which Canadian and other countries base their privacy legislation.

 

Most industrialized countries, have data protection legislation and mechanisms in place to safeguard information they have collected. But as we know from our examples of data collected during travel, it is not always countries that collect information, it is also companies.

 

Companies that collect and retain personal information, must be able to safeguard it and this is not always done.

 

Why would a company not safeguard personal information? Sometimes it is because they are not aware of the need to do so, have not dedicated the resources or they have insufficient safeguards in place. Large airlines and cruising companies all have privacy policies and a dedicated Privacy Officer. But what about smaller businesses?

 

When giving a talk on this subject, I often use the example of a small hotel I stayed at which was in a quaint and charming village. The check-in procedure was done manually and the owner told me his family used the same check-in process for the last 100 years with the only change being the type of information required to ensure adherence with local registration requirements. My ID and passport information was collected and handwritten in a guest logbook. Very retro.

 

Once completed, the hotel owner turned the registration book towards me to sign and there in the recent entry portion of the ledger, was everyone who was currently staying in one of the hotel’s six rooms, name, passport details, home addresses and phone numbers neatly printed on each line. He turned to get an old-fashioned room key from the cubby hole board behind him and then went to the nearby kitchen to get us a welcome drink. I could easily have taken a quick picture of the guest registration page if I had been so inclined. What was also in evidence, were the previous check-in logbooks, neatly stacked in easy reach on bookshelves. Although they added to the rustic charm, there was a treasure trove of information.

 

Now you may be asking yourself whether checking into a hotel is a private activity that needs to be safeguarded? Anyone entering the hotel could see that I was checking in, so that was obvious. People seeing me take my luggage to a room and open a door with a key, would clearly know I was staying there. But they would not have known my name or passport number. They may not have known my nationality and certainly not my birthdate, phone number etc.

 

Why is privacy important? I get asked that a lot along with people telling me, “If you have nothing to hide, what is the problem with a loss of a little privacy?”  I usually respond with a question. “When you go to the toilet when travelling, do you shut the toilet stall door and if so, why? You are not doing anything wrong so why shut the door. The answer is simple, you want privacy.”

 

Protecting your privacy is not synonymous with hiding an illegal activity, or even evidence that you are up to no good. It is an expectation. Some people don’t mind having sex in a public place but the majority, want privacy.

 

As a writer, my corporation has a privacy policy, and I adhere to the applicable Canadian privacy legislation.

 

One thing we are hearing more and more about are privacy violations that are tied to information technology breaches. Specifically, the failure of IT to keep the information collected and safeguarded. Here is a very recent example of an IT malfunction that led to a breach.

 

Following a cruise, I was going to Iguazu Falls on a two-day tour. Rather than go through the work of arranging an onsite guide, booking our flights out of Buenos Aires, hotel in Iguazu Falls etc. I opted to go through a 3rd party tour provider (who contracted the tour with a local company in Argentina). To facilitate the booking of the flights from Buenos Aires, the local company sent me a link to their customer information form. I was to complete and submit the document.

 

When I clicked on the link, I found it had already been filled out with the personal information of other travellers. Names, addresses, telephone numbers, email addresses, passport numbers and passport expiry dates etc. I took screen shots of the information of the first three customers and notified the company that they had a data breach. I also indicated that I would not use their form due to personal information security concerns. In that notification, I copied the first people (whose personal information was on display as soon as anyone clicked on the link). The reason for the CC was to ensure that those customers were aware that their personal information was being disclosed by way of this form. They responded with a thank you for letting them know about the data breach. Once I had sent the company and the individuals' proof of the data breach, I did not retain any of their information.

 

I heard nothing from the local tour company for approximately five days until I contacted them again and the 3rd party tour provider. The company at first indicated the breach was an IT glitch and that the information on the form was from tours conducted three years ago. However, that was factually incorrect as the information on offer on the forms also showed the date of the flights the customers were arriving on which was certainly not three years ago. In other words, the visible information did not support the narrative put forward by the company. The company did state that they were addressing the data breach.

 

Just as a note of import, I want to make it clear, that the data breach, whether it involved data collected three years ago or three hours ago, was still a breach. The passport information and expiry dates were all current etc. So, I was surprised at the company’s response re the age of the information because it was a moot point.

 

I did a little research and found that Brazil has federal privacy legislation called the General Personal Data Protection Law (LGPD - Lei Geral de Proteção de Dados), and Argentina has the Personal Data Protection Act (Law 25,326), also known as the PDPA or Ley de Protección de los Datos Personales. The tour operator would operate under the jurisdiction of both countries and as such, I suspect it must have some type of privacy policy (although I don’t know the jurisdictional limitations imposed by the federal legislation of those two countries).

 

I decided to cancel the booking. Although it was a non-refundable tour, given the data breach and my concerns relating to the security of the booking form, the company agreed to a 100% refund.

 

This story provides an example that if you plan on booking a tour with any tour provider, please ensure that the data links you are sent are secure, that the company uses an encryption program and that IF there is a data breach, there is a complaint mechanism that will act upon your complaint. Know your rights and follow up on any data breaches.

 

When travelling, know when you must provide personal information, and when you are not required to give out personal data. Feel free to ask why copies are being made of your documents and what happens to any copies made. Know your rights and enjoy safe travels.

 

As always, feel free to contact me if you have any questions or comments.

 

Comments


Sunrise over the Pacific.jpg

This could be your next view. Book a cruise now!
 

©2018 by Gail Gauvreau. All Rights Reserved.

bottom of page