BreachOfPrivacy
Decisions/Federal (Canada)

Federal (Canada) Privacy Decisions

Browse privacy decisions from Federal (Canada) — with AI-generated plain-language summaries for every ruling.

1,620 decisions in archive
Federal (Canada)Privacy ActWell-founded & conditionally resolved
May 7, 2026Special report to Parliament· Indexed May 8, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

Canada Revenue Agency

This special report details an investigation into unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency (CRA). The Office of the Privacy Commissioner (OPC) found that the CRA contravened the Privacy Act regarding accuracy and disclosure of personal information. While the CRA has made efforts to improve its security, shortcomings remain in prevention, monitoring, detection, remediation, and governance, particularly concerning the handling of "Unauthorized Use of Taxpayer Information by a Third Party" (UUTP) incidents. The investigation concluded that the CRA contravened subsections 6(2) and 8(2) of the Act.

Quick View

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

May 7, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

This special report details an investigation into unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency (CRA). The Office of the Privacy Commissioner (OPC) found that the CRA contravened the Privacy Act regarding accuracy and disclosure of personal information. While the CRA has made efforts to improve its security, shortcomings remain in prevention, monitoring, detection, remediation, and governance, particularly concerning the handling of "Unauthorized Use of Taxpayer Information by a Third Party" (UUTP) incidents. The investigation concluded that the CRA contravened subsections 6(2) and 8(2) of the Act.

Key Issues
  • Adequacy of safeguards to protect taxpayer personal information from unauthorized disclosure and modification.
  • Timeliness and strength of multi-factor authentication implementation.
  • Effectiveness of monitoring and detection mechanisms for UUTPs.
  • Coordination and proactivity of the CRA's governance for addressing UUTPs.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & unresolved
May 6, 2026PIPEDA Findings #2026-002· Indexed May 6, 2026

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

OpenAI OpCo, LLC

This joint investigation by privacy authorities across Canada found that OpenAI contravened privacy laws in its collection, use, and disclosure of personal information through its ChatGPT models GPT-3.5 and GPT-4. Specifically, the investigation found that OpenAI's collection of personal information from publicly accessible websites for training purposes was overbroad and inappropriate. The company also failed to obtain valid consent and be sufficiently transparent about its data practices. While OpenAI has since implemented new mitigation measures and committed to further improvements, some provincial authorities found the new measures insufficient to meet their specific legislative requirements.

Quick View

Personal Information Protection and Electronic Documents ActWell-founded & unresolved

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

May 6, 2026PIPEDA Findings #2026-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

This joint investigation by privacy authorities across Canada found that OpenAI contravened privacy laws in its collection, use, and disclosure of personal information through its ChatGPT models GPT-3.5 and GPT-4. Specifically, the investigation found that OpenAI's collection of personal information from publicly accessible websites for training purposes was overbroad and inappropriate. The company also failed to obtain valid consent and be sufficiently transparent about its data practices. While OpenAI has since implemented new mitigation measures and committed to further improvements, some provincial authorities found the new measures insufficient to meet their specific legislative requirements.

Key Issues
  • Appropriateness of purpose for data collection and use
  • Validity of consent and transparency obligations
  • Accuracy of generated information
  • Individual rights to access, correction, and deletion
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Mar 31, 20265825-04112· Indexed Jun 1, 2026

Transport Canada, 5825-04112

The OIC ordered Transport Canada to provide a complete response to the access request no later than 36 business days following the date of the final report..

Quick View

Access to Information ActOIC Order (ATIA s.36.1, binding)

Transport Canada, 5825-04112

Mar 31, 20265825-04112

The OIC ordered Transport Canada to provide a complete response to the access request no later than 36 business days following the date of the final report..

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Mar 31, 20265825-03242· Indexed Jun 1, 2026

Privy Council Office, 5825-03242

The OIC ordered Privy Council Office to provide a complete response to the access request no later than 36 business days following the date of the final report..

Quick View

Access to Information ActOIC Order (ATIA s.36.1, binding)

Privy Council Office, 5825-03242

Mar 31, 20265825-03242

The OIC ordered Privy Council Office to provide a complete response to the access request no later than 36 business days following the date of the final report..

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Mar 30, 20265825-04608· Indexed Jun 1, 2026

National Defence, 5825-04608

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Quick View

Access to Information ActOIC Order (ATIA s.36.1, binding)

National Defence, 5825-04608

Mar 30, 20265825-04608

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Mar 30, 20265825-04449· Indexed Jun 1, 2026

National Defence, 5825-04449

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Quick View

Access to Information ActOIC Order (ATIA s.36.1, binding)

National Defence, 5825-04449

Mar 30, 20265825-04449

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Mar 30, 20265825-04230· Indexed Jun 1, 2026

National Defence, 5825-04230

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Quick View

Access to Information ActOIC Order (ATIA s.36.1, binding)

National Defence, 5825-04230

Mar 30, 20265825-04230

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Mar 30, 20265825-03732· Indexed Jun 1, 2026

Privy Council Office, 5825-03732

The OIC ordered Privy Council Office to provide a complete response to the access request no later than 36 business days following the date of the final report..

Quick View

Access to Information ActOIC Order (ATIA s.36.1, binding)

Privy Council Office, 5825-03732

Mar 30, 20265825-03732

The OIC ordered Privy Council Office to provide a complete response to the access request no later than 36 business days following the date of the final report..

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Mar 27, 20265825-04451· Indexed Jun 1, 2026

National Defence, 5825-04451

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Quick View

Access to Information ActOIC Order (ATIA s.36.1, binding)

National Defence, 5825-04451

Mar 27, 20265825-04451

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Mar 27, 20265825-04229· Indexed Jun 1, 2026

National Defence, 5825-04229

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Quick View

Access to Information ActOIC Order (ATIA s.36.1, binding)

National Defence, 5825-04229

Mar 27, 20265825-04229

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Mar 27, 20265825-03824· Indexed Jun 1, 2026

National Defence, 5825-03824

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Quick View

Access to Information ActOIC Order (ATIA s.36.1, binding)

National Defence, 5825-03824

Mar 27, 20265825-03824

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Mar 27, 20265825-02381· Indexed Jun 1, 2026

Privy Council Office, 5825-02381

The OIC ordered Privy Council Office to provide a complete response to the access request no later than 36 days following the date of the final report..

Quick View

Access to Information ActOIC Order (ATIA s.36.1, binding)

Privy Council Office, 5825-02381

Mar 27, 20265825-02381

The OIC ordered Privy Council Office to provide a complete response to the access request no later than 36 days following the date of the final report..

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Mar 27, 20265825-02181· Indexed Jun 1, 2026

Canada Revenue Agency, 5825-02181

The OIC ordered Canada Revenue Agency to provide a complete response to the access request no later than 36 business days following the date of the final report..

Quick View

Access to Information ActOIC Order (ATIA s.36.1, binding)

Canada Revenue Agency, 5825-02181

Mar 27, 20265825-02181

The OIC ordered Canada Revenue Agency to provide a complete response to the access request no later than 36 business days following the date of the final report..

Federal (Canada)Access to Information ActWell-founded
Mar 27, 20265823-04320· Indexed May 22, 2026

Health Canada (Re), 2026 OIC 36

Health Canada

The complainant alleged that Health Canada improperly withheld records related to a COVID-19 vaccine safety update report, citing exemptions for confidential government information, personal information, and third-party commercial information. The Information Commissioner found that while some information was properly withheld under exemptions for confidential government information (section 13(1)) and personal information (section 19(1)), Health Canada failed to properly exercise its discretion regarding publicly available information under section 13(1). The Commissioner also found that exemptions for third-party commercial or financial information (section 20(1)(b) and (c)) were not met. The Commissioner ordered Health Canada to disclose the information withheld under third-party exemptions and reconsider the disclosure of publicly available information under section 13(1).

Quick View

Access to Information ActWell-founded

Health Canada (Re), 2026 OIC 36

Mar 27, 20265823-04320
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Health Canada improperly withheld records related to a COVID-19 vaccine safety update report, citing exemptions for confidential government information, personal information, and third-party commercial information. The Information Commissioner found that while some information was properly withheld under exemptions for confidential government information (section 13(1)) and personal information (section 19(1)), Health Canada failed to properly exercise its discretion regarding publicly available information under section 13(1). The Commissioner also found that exemptions for third-party commercial or financial information (section 20(1)(b) and (c)) were not met. The Commissioner ordered Health Canada to disclose the information withheld under third-party exemptions and reconsider the disclosure of publicly available information under section 13(1).

Key Issues
  • Proper application of section 13(1) (confidential information from government bodies)
  • Proper application of section 19(1) (personal information)
  • Proper application of section 20(1)(b) (confidential third-party financial, commercial, scientific or technical information)
  • Proper application of section 20(1)(c) (financial impact on a third party)
Federal (Canada)Privacy ActWell-founded
Mar 25, 2026· Indexed Jun 5, 2026

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Immigration, Refugees and Citizenship Canada

The OPC investigated a complaint alleging that Immigration, Refugees and Citizenship Canada (IRCC) improperly withheld access to personal information. The complainant requested the "History Section" of their case file, but IRCC only provided a subset of information from other sections, referred to as the "Short Form" report. The OPC found that IRCC's practice of systematically retrieving and processing only the Short Form report contravenes section 12 of the Privacy Act, as it fails to provide individuals with access to all personal information under the government's control. Although the specific file was eventually provided, IRCC refused to update its procedures to address the systemic issue.

Quick View

Privacy ActWell-founded

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated a complaint alleging that Immigration, Refugees and Citizenship Canada (IRCC) improperly withheld access to personal information. The complainant requested the "History Section" of their case file, but IRCC only provided a subset of information from other sections, referred to as the "Short Form" report. The OPC found that IRCC's practice of systematically retrieving and processing only the Short Form report contravenes section 12 of the Privacy Act, as it fails to provide individuals with access to all personal information under the government's control. Although the specific file was eventually provided, IRCC refused to update its procedures to address the systemic issue.

Key Issues
  • Whether IRCC's practice of only retrieving and processing a "Short Form" subset of records in response to access requests complies with the Privacy Act's access obligations.
  • Whether the "History Section" of the Global Case Management System (GCMS) file contains personal information.
  • Whether IRCC's assertion that information outside the "Short Form" would always be withheld under exemptions is valid.
  • Whether IRCC's failure to commit to updating its procedures constitutes a continuing contravention of the Privacy Act.