TO WHAT EXTENT IS PRIVACY LEGISLATION REFLECTED IN THE UNIVERSITY LIBRARIES’ PRIVACY POLICIES IN NEW ZEALAND? by LE THI TUONG VY Submitted to the School of Information Management, Victoria University of Wellington in partial fulfillment of the requirements for the degree of Master of Library and Information Studies February, 2008 Acknowledgements I wish to express my sincere thanks to my supervisor, Lynley Stone for her reading, commenting on early drafts of the study, her insightful advice and suggestions that have guided my subsequent revisions as well as her encouragement throughout this project. Many thanks to the managers at the eight university libraries in New Zealand for providing the privacy information and documentation. Their collaboration has considerably helped me to finish the study in a restricted time. Page 2 /78 Abstract University libraries are built on the concept of freedom for users to use the library and to access information and are also places where users’ activities are strictly kept confidential and private as a legislative requirement.
The main objectives of the study are to find out the legal framework of privacy which governs the New Zealand university libraries’ operations; to explore the state of the New Zealand university libraries’ policies in terms of the protection of their users’ privacy, to seek and identify primary concerns of the privacy policies of New Zealand university libraries Content analysis was used as a research technique to analyse the wording of privacy policies of the eight university libraries of New Zealand which are available on their websites. The twelve IPPs of the Privacy Act 1993 can be used as primary cores of a privacy policy and privacy protection procedures of a university library. At present, the eight university libraries of New Zealand do not have their own privacy policies/ procedures. They are following overall privacy policies/ statements of their universities.
The university privacy policies to some extent follow with the main principles of the Privacy Act 1993, however, they have not reflected clearly and sufficiently the privacy principles of the Privacy Act 1993. The existing university privacy policies are not consistently comprehensive across the libraries’ services and therefore have not been sufficient to prevent the potential privacy risks of the libraries. The privacy policy of university libraries should adhere strictly with the twelve IPPs of the Privacy Act 1993 and professional ethical principles, including: display privacy statement prominently, set up procedures to protect library users’ privacy, adopt the relevant legislation and professional library organization Code of Ethics, appoint a privacy compliance officer, develop training privacy program for the library staff and users and conduct privacy audit. Keywords: Privacy, privacy legislation, privacy policy, university library.
Page 3 /78 TABLE OF CONTENTS Abstract 3 Table of contents 4 I.2 Privacy as a concept 9 2.3 Privacy legislation of New Zealand 10 2.2 Overview of privacy principles of New Zealand 11 2.4 Attitudes of libraries towards privacy 12 2.1 Privacy as a core mission 12 2.5 Privacy policies of university libraries 15 2.6 Conclusion of the literature review 17 2.7 Theoretical framework 17 III.4 Definitions of terms 20 VI.2 Research methodology 22 Page 4 /78 4.4 Data collection & analysis 26 4.3 Data analysis strategies 27 V. TIMETABLE TO PERFORM THE STUDY 30 VII. FINDINGS AND DISCUSSION 31 7.1 Research question 1: What are the privacy principles of the New Zealand legislation? How are they applied to the university libraries? 31 7.2 Research question 2: How are the principles of New Zealand privacy legislation demonstrated in the university libraries’ policies? 38 7.1 How are the principles of New Zealand privacy legislation 38 demonstrated in the libraries’ policies? 7.2 What critical factors should be considered when developing the 49 university libraries’ policies? VIII.1 Summary of key findings 53 8.2 The future of privacy protection in New Zealand university libraries. 54 Page 5 /78 BIBLIOGRAPHY 57 APPENDICES 63 Appendix 1: Gantt Chart of timetable to perform the study 64 Appendix 2: Letter to the university libraries 65 Appendix 3: Letter to the universities’ Information Officers/ Privacy Officers 68 Appendix 4: Privacy policies of the eight universities in New Zealand 71 Appendix 5: Overview about privacy policies of the universities 73 Appendix 6: Comparison on the privacy compliance of the universities’ privacy policies 76 Page 6 /78 I.
INTRODUCTION Kemp and Moore (2007) indicate that privacy has a very long established history since the ancient time of Socrates, Plato and Aristotle. Although these philosophers considered privacy protection unnecessary, they could not deny the existence of privacy. Gradually, privacy has been recognized widely. In Middle Eastern and some Asian countries, privacy right is not viewed as a basic human right due to the unlimited Governmental control over the people and therefore is not well developed like Western countries (Klosek, 2007).
During the mid and late 1990s, privacy became an increasing concern in Western countries due to: (1) their perception of privacy as a human right, (2) the adverse impacts of high technologies, (3) their fear of cross-border data transfer, and (4) the response to the terrorist attack on 9/11 (Klosek, 2007). Many countries, in particular developed countries including United States and European countries, have legislative commitments to privacy (Longworth & McBride, 1994; Moghe, 2003; Pedley, 2006). The Universal Declaration of Human Rights (1948, Article 12) states that “No one should be subject to arbitrary interference with his privacy, family, home or correspondence, nor to attacks on his honour or reputation”. Protecting the privacy of clients is also one of the most fundamental obligations of professionals, in particular with those who deal frequently with personal information of customers, such as doctors, lawyers, educators, priests, journalists, traders and information/library practitioners (Adams, Bocher, Gordon, & Kessler, 2005).
In New Zealand, university libraries have to deal with a significant amount of personal information of users. University libraries are also considered as places where users’ activities are strictly kept confidential and private (Bowers, 2006). How New Zealand university libraries comply with privacy legislation in addition to making information accessible for all their users, who are students, academic and administrative staff is still little known. This study aims to explore how New Zealand university libraries comply with the privacy legislation to protect their Page 7 /78 users’ privacy right via the formulating privacy policies/ regulations.
This is a critical issue internationally and nationally in order to protect a fundamental human right, to adhere to the national legislation and to monitor the technology impacts in the university libraries.1 Purposes The review discusses the concept of privacy and the impacts of privacy in libraries; privacy legislation with its historical background and the most important privacy principles of New Zealand, librarians’ attitudes towards privacy as well as the development of privacy protection policies of university libraries. Accordingly, the review attempts to explore the trends and issues surrounding the privacy policies of the university libraries in New Zealand. 2 Privacy as a concept Privacy is difficult to define (Adams et al., 2005) and literature shows that the meaning of privacy varies from country to country, even in the same country with different contexts of legislation interpretation. In New Zealand, the Privacy Act 1993 defines information privacy principles as applying to all personal information.
Personal information therefore is considered widely as “information about an identifiable individual”. In the United States, privacy has been considered as “a right to be let alone” (Klosek, 2007; Longworth & McBride, 1994). According to a number of authors (Adams et al., 2005; McMenemy, Poulter, & Burton, 2007), the widely acceptable notion is that privacy is the right to prevent the disclosure of personal information to others and may involve both confidentiality and security. Nevertheless, privacy has played an important role in the formation of liberal democracies (Kemp & Moore, 2007).
University libraries are a part of the borderless society where information transactions and privacy rights often come Page 9 /78 together. University libraries may have the pressure to satisfy the increasing academic demands via applying high technology (e. RFID, websites, virtual reference, cameras etc.) while having insufficient knowledge about the technological mechanisms (Fifarek, 2002). The more information transactions the university libraries conduct via applying high technology, the more personal information they obtain, therefore the development of library policies as a tool to comply strictly with privacy protection principles would be essential.
Several authors (Adams et al., 2005; McMenemy et al., 2007; Pedley, 2006) point out that the Library & Information Association of New Zealand Aotearoa (LIANZA, 1978), the American Library Association (ALA, 1995), the Canadian Library Association (CLA, 1976) and the Chartered Institute of Library and Information Professionals (CILIP, 2007) all have principles or statements to respect for privacy in dealing with personal information. 3 Privacy legislation of New Zealand 2.1 Historical background The New Zealand Government was one of the first in the world to propose the establishment of a Privacy Commissioner in 1975 by law (Stewart, 1999). The recognition of privacy right in New Zealand was adopted for many years from 1974 to 1994, including the most remarkable trends such as the New Zealand Bill of Rights 1990, privacy reports in 1984-1989, the Privacy Bill and Privacy of Information Bill in 1990 and Privacy Commissioner Act 1991. There are two international documents that establish general privacy principles and have had significant influence on privacy legislation in New Zealand, namely the OECD Guidelines of 1980 and United Nations Guidelines of 1990.
The OECD guidelines have been adopted in New Zealand via the Privacy Act 1993 ( Privacy Commissioner, 2006). In addition, the European Data Protection Directive 1995 requests all EU member countries to implement its requirements about the Page 10 /78 establishment of statutory privacy control. It also applies a strict approach to notice, consent, accuracy and access of information. Although the EU Directive is not obligatory to New Zealand, its provisions influence significantly the privacy compliance in this country because of its privacy ideals to specific industry conditions (Alderdice, 2000).
The information privacy principles in the Act are associated closely with the concepts identified in the OECD guidelines. In addition, the principles of the Privacy Act 1993 are also similar to regulations stipulated in relevant European privacy laws (Stewart, 1999). This implies that there is a high level of consistency in these laws across countries. In New Zealand, like some other countries, the Privacy Act 1993 has an interrelationship with other relevant laws on the handling of personal information.
These include the Archives Act (1957), Public Record Act (2005) and Official Information Act 1982 (Privacy Commissioner, 1998). This shows that privacy protection is a nationally legislative requirement in New Zealand and therefore university libraries must adhere to it strictly.2 Overview of privacy principles of New Zealand The Privacy Act 1993 consists of twelve privacy principles on personal information held by “agencies”. Subsequently, “agencies” are defined widely in the public and private sectors. They include all individuals as well as companies, banks, insurance organizations, medical centers, local councils and governmental departments (Longworth & McBride, 1994).
In summary, the core principles of the Privacy Act 1993 stipulates “the rules on the collection, storage, security, accuracy, use and disclosure of personal information as well as an individual’s rights to access, and correct personal information” (Longworth & McBride, 1994, p. Everyone and all entities in New Zealand are subject to the same privacy principles through the Privacy Act 1993. The Privacy Act 1993 provides the legal framework Page 11 /78 in respect of privacy protection in New Zealand. Various industrial sectors such as health, banking and marketing specify privacy principles to be appropriate their functional and operational organizations (Longworth & McBride, 1994).
University libraries also have distinctions on their functions and operations and therefore how properly they control the privacy issues and reflect the privacy legislation in their policies is a useful and necessary issue to explore. This is for an in-depth understanding of the privacy compliance issues and to construct a privacy policy as a good tool for both legislative compliance and operational control purposes in university libraries. Attitudes of libraries towards privacy 2.