The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

1,631 decisions in the archive
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 14, 2026Indexed Jul 15, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

WestJet

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

Jul 14, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Key Issues
  • Adequacy of security safeguards under PIPEDA
  • Adequacy of notifications to affected individuals under PIPEDA
  • Whether WestJet's post-breach remediation actions and future commitments provide a fair and reasonable response to the incident
Federal (Canada)Access to Information ActDiscontinued
Federal (Canada) flag
Jun 20, 20262026 OIC 45Indexed Jun 30, 2026

Decision under section 30, 2026 OIC 45

A federal institution

The Information Commissioner received a complaint alleging that the titles of certain briefing notes published on the Open Canada website were improperly withheld. The complaint did not arise from an access request made under Part 1 of the Access to Information Act (ATIA). The Commissioner reviewed the complaint under section 30 of the ATIA, which outlines the types of complaints that can be investigated. It was determined that the complaint did not fall under paragraphs 30(1)(a) to (d.1) as it did not relate to an access request. Furthermore, it did not fall under paragraph 30(1)(e) or 30(1)(f) as it did not concern a matter relating to requesting or obtaining access to records under Part 1 of the ATIA. The Commissioner noted that subsection 91(1) of the ATIA specifically precludes her from exercising powers related to the proactive publication of information under Part 2 of the Act. Consequently, the complaint was found inadmissible, and the Commissioner declined to investigate due to a lack of authority.

Quick view

Access to Information ActDiscontinued

Decision under section 30, 2026 OIC 45

Jun 20, 20262026 OIC 45
Adjudicator: Caroline Maynard
Plain-Language Summary

The Information Commissioner received a complaint alleging that the titles of certain briefing notes published on the Open Canada website were improperly withheld. The complaint did not arise from an access request made under Part 1 of the Access to Information Act (ATIA). The Commissioner reviewed the complaint under section 30 of the ATIA, which outlines the types of complaints that can be investigated. It was determined that the complaint did not fall under paragraphs 30(1)(a) to (d.1) as it did not relate to an access request. Furthermore, it did not fall under paragraph 30(1)(e) or 30(1)(f) as it did not concern a matter relating to requesting or obtaining access to records under Part 1 of the ATIA. The Commissioner noted that subsection 91(1) of the ATIA specifically precludes her from exercising powers related to the proactive publication of information under Part 2 of the Act. Consequently, the complaint was found inadmissible, and the Commissioner declined to investigate due to a lack of authority.

Key Issues
  • Whether the complaint fell within the scope of section 30(1)(a) to (d.1) of the ATIA (complaints related to access requests)
  • Whether the complaint fell within the scope of section 30(1)(e) or (f) of the ATIA (other matters relating to requesting or obtaining access under Part 1)
  • Whether the Commissioner has authority to investigate complaints related to proactive publication under Part 2 of the ATIA (s.91(1))
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Jun 16, 20262026 OIC 46Indexed Jun 30, 2026

Canada Border Services Agency (Re), 2026 OIC 46

Canada Border Services Agency

The Information Commissioner initiated a systemic investigation into the Canada Border Services Agency's (CBSA) handling of access to information requests related to the ArriveCAN application. The investigation focused on the completeness and timeliness of responses. While allegations of permanent destruction of emails were not substantiated, the investigation revealed that the ArriveCAN project team used the communication platform Slack, which was permanently deleted in May 2023 without consultation with the ATIP unit or content review. This led to a finding that the CBSA failed to conduct reasonable searches for six ArriveCAN-related access requests, as Slack was not searched despite likely containing responsive records. The investigation also identified broader weaknesses in information management, including the use of non-government email accounts and insufficient governance over third-party tools. Although the CBSA failed to meet legislated timelines for some ArriveCAN requests, no unique timeliness concerns specific to the initiative were identified. The complaint was found to be well-founded, and the CBSA accepted the Commissioner's recommendations for corrective measures.

Quick view

Access to Information ActWell-founded

Canada Border Services Agency (Re), 2026 OIC 46

Jun 16, 20262026 OIC 46
Adjudicator: Caroline Maynard
Plain-Language Summary

The Information Commissioner initiated a systemic investigation into the Canada Border Services Agency's (CBSA) handling of access to information requests related to the ArriveCAN application. The investigation focused on the completeness and timeliness of responses. While allegations of permanent destruction of emails were not substantiated, the investigation revealed that the ArriveCAN project team used the communication platform Slack, which was permanently deleted in May 2023 without consultation with the ATIP unit or content review. This led to a finding that the CBSA failed to conduct reasonable searches for six ArriveCAN-related access requests, as Slack was not searched despite likely containing responsive records. The investigation also identified broader weaknesses in information management, including the use of non-government email accounts and insufficient governance over third-party tools. Although the CBSA failed to meet legislated timelines for some ArriveCAN requests, no unique timeliness concerns specific to the initiative were identified. The complaint was found to be well-founded, and the CBSA accepted the Commissioner's recommendations for corrective measures.

Key Issues
  • Whether the Canada Border Services Agency conducted reasonable searches for records related to ArriveCAN access requests
  • Whether the deletion of the ArriveCAN Slack workspace impacted the completeness of responses to access requests
  • Whether the Canada Border Services Agency's information management practices were adequate for access to information purposes
  • Whether the Canada Border Services Agency responded to ArriveCAN-related access requests within legislated timelines
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 11, 2026PIPEDA Findings #2026-004Indexed Jun 30, 2026

PIPEDA Findings #2026-004: Commissioner-initiated complaints concerning X Corp.’s and X.AI LLC’s compliance with PIPEDA

X Corp. and X.AI LLC

The Office of the Privacy Commissioner of Canada (OPC) initiated complaints against X Corp. and X.AI LLC following reports that their AI chatbot, Grok, generated millions of sexualized deepfakes of identifiable individuals. The investigation focused on whether valid consent was obtained for the collection, use, and disclosure of personal information for this purpose, and if such practices were appropriate under PIPEDA. The OPC found that neither company obtained valid consent, noting the sensitive nature of the information, the unreasonableness of individuals' expectations, and the significant risk of harm. Furthermore, the OPC concluded that the generation of sexualized deepfakes was inappropriate, as the loss of privacy and harm far outweighed any benefits, and less privacy-invasive means were available. While the companies implemented some safeguards, the OPC deemed their initial response insufficient and their current measures unproven. Consequently, the matter was found well-founded, with the OPC making several recommendations for improved safeguards, proactive monitoring, and annual third-party audits, while committing to ongoing monitoring.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2026-004: Commissioner-initiated complaints concerning X Corp.’s and X.AI LLC’s compliance with PIPEDA

Jun 11, 2026PIPEDA Findings #2026-004
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated complaints against X Corp. and X.AI LLC following reports that their AI chatbot, Grok, generated millions of sexualized deepfakes of identifiable individuals. The investigation focused on whether valid consent was obtained for the collection, use, and disclosure of personal information for this purpose, and if such practices were appropriate under PIPEDA. The OPC found that neither company obtained valid consent, noting the sensitive nature of the information, the unreasonableness of individuals' expectations, and the significant risk of harm. Furthermore, the OPC concluded that the generation of sexualized deepfakes was inappropriate, as the loss of privacy and harm far outweighed any benefits, and less privacy-invasive means were available. While the companies implemented some safeguards, the OPC deemed their initial response insufficient and their current measures unproven. Consequently, the matter was found well-founded, with the OPC making several recommendations for improved safeguards, proactive monitoring, and annual third-party audits, while committing to ongoing monitoring.

Key Issues
  • Whether PIPEDA applies to X Corp. and X.AI LLC, specifically regarding the existence of a "real and substantial connection" to Canada.
  • Whether deepfakes of identifiable individuals, including sexualized deepfakes, constitute "personal information" under PIPEDA.
  • Whether X Corp. and X.AI LLC obtained valid consent for the collection, use, and disclosure of personal information to generate sexualized deepfakes, as required by Principle 4.3 of PIPEDA.
  • Whether express consent was required for the generation of sexualized deepfakes, considering the sensitivity of the information, individuals' reasonable expectations, and the risk of significant harm (Principle 4.3.4, 4.3.5, and s.6.1 of PIPEDA).
  • Whether X Corp. and X.AI LLC are accountable for ensuring valid consent for content generated by their tools in the course of commercial activity.
  • Whether a reasonable person would consider the collection, use, and disclosure of personal information for the purpose of an image generation service capable of producing sexualized deepfakes to be appropriate in the circumstances, as per subsection 5(3) of PIPEDA.
  • Whether the organizations had a legitimate need or bona fide business interest that extended to providing an image generation tool capable of producing non-consensual sexualized deepfakes.
  • Whether less privacy-invasive means were available to achieve the organizations' purposes at comparable cost and benefits.
  • Whether the loss of privacy and risk of harm associated with sexualized deepfakes were proportionate to the benefits of the practice.
  • Whether X Corp. and X.AI LLC's initial response and implemented safeguards were sufficient and effective in preventing the generation of sexualized deepfakes.
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
May 13, 20265825-03354Indexed Jul 23, 2026

Library and Archives Canada (Re), 2026 OIC 47

Library and Archives Canada

The complainant alleged that Library and Archives Canada (LAC) improperly withheld information under section 23 (solicitor-client privilege) of the Access to Information Act. The request sought documents related to the appointment of an administrator for a Lieutenant Governor. While the Commissioner found that the information met the requirements for solicitor-client privilege, LAC's initial exercise of discretion not to release the 93-year-old record was deemed unreasonable. LAC had a policy to release such records if over 100 years old, but failed to consider other relevant factors like the content, context, and the fact that involved individuals were long deceased. During the investigation, LAC re-exercised its discretion, considering these factors, and subsequently released all the information. The complaint was found to be well-founded due to the initial unreasonable exercise of discretion, but no order was necessary as the information was ultimately disclosed.

Quick view

Access to Information ActWell-founded

Library and Archives Canada (Re), 2026 OIC 47

May 13, 20265825-03354
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Library and Archives Canada (LAC) improperly withheld information under section 23 (solicitor-client privilege) of the Access to Information Act. The request sought documents related to the appointment of an administrator for a Lieutenant Governor. While the Commissioner found that the information met the requirements for solicitor-client privilege, LAC's initial exercise of discretion not to release the 93-year-old record was deemed unreasonable. LAC had a policy to release such records if over 100 years old, but failed to consider other relevant factors like the content, context, and the fact that involved individuals were long deceased. During the investigation, LAC re-exercised its discretion, considering these factors, and subsequently released all the information. The complaint was found to be well-founded due to the initial unreasonable exercise of discretion, but no order was necessary as the information was ultimately disclosed.

Key Issues
  • Whether the information met the requirements of s.23 ATIA (solicitor-client privilege)
  • Whether the institution reasonably exercised its discretion not to disclose information subject to s.23 ATIA
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
May 11, 20265825-02105Indexed Jul 8, 2026

Canadian Heritage (Re), 2026 OIC 44

Canadian Heritage

The complainant alleged that Canadian Heritage failed to conduct a reasonable search for records and improperly withheld personal information under subsection 19(1) of the Access to Information Act. The request sought records related to weightlifting in 2023 and 2024, specifically confirmation letters, athlete rationale forms, and appeals. During the investigation, the complainant withdrew the allegation regarding subsection 19(1). The investigation found that Canadian Heritage's search was too narrow, as it only used one athlete's name despite the request not being limited to a specific individual. While the institution provided explanations for the non-existence of some specific records, the Commissioner concluded that the overall search was not reasonable and additional records might exist. The Information Commissioner ordered Canadian Heritage to conduct a new, broader search and provide a new response to the complainant.

Quick view

Access to Information ActWell-founded

Canadian Heritage (Re), 2026 OIC 44

May 11, 20265825-02105
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Canadian Heritage failed to conduct a reasonable search for records and improperly withheld personal information under subsection 19(1) of the Access to Information Act. The request sought records related to weightlifting in 2023 and 2024, specifically confirmation letters, athlete rationale forms, and appeals. During the investigation, the complainant withdrew the allegation regarding subsection 19(1). The investigation found that Canadian Heritage's search was too narrow, as it only used one athlete's name despite the request not being limited to a specific individual. While the institution provided explanations for the non-existence of some specific records, the Commissioner concluded that the overall search was not reasonable and additional records might exist. The Information Commissioner ordered Canadian Heritage to conduct a new, broader search and provide a new response to the complainant.

Key Issues
  • Whether Canadian Heritage conducted a reasonable search for records
  • Whether the scope of the search was broad enough to capture all responsive records
  • Whether s.19(1) personal information exemption was properly applied
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
May 7, 20265825-04014Indexed Jul 2, 2026

Canadian Food Inspection Agency (Re), 2026 OIC 42

Canadian Food Inspection Agency

The complainant alleged that the Canadian Food Inspection Agency (CFIA) failed to respond to an access request within the 30-day statutory period. The request sought records related to the cull of ostriches at Universal Ostrich Farms. The CFIA was deemed to have refused access due to the delay, which it attributed to ongoing RCMP investigations, safety and security concerns, and the volume of records. The Information Commissioner found the CFIA's delay in searching and gathering records to be irresponsible and a blatant disregard for the Act. The Commissioner noted that the Act does not permit an institution to 'pause' a request due to sensitivity or a strategic plan for multiple requests. The Commissioner ordered the CFIA to provide a complete response within 36 business days of the final report. The CFIA confirmed it would implement the order and had already begun retrieving and reviewing records.

Quick view

Access to Information ActWell-founded

Canadian Food Inspection Agency (Re), 2026 OIC 42

May 7, 20265825-04014
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Canadian Food Inspection Agency (CFIA) failed to respond to an access request within the 30-day statutory period. The request sought records related to the cull of ostriches at Universal Ostrich Farms. The CFIA was deemed to have refused access due to the delay, which it attributed to ongoing RCMP investigations, safety and security concerns, and the volume of records. The Information Commissioner found the CFIA's delay in searching and gathering records to be irresponsible and a blatant disregard for the Act. The Commissioner noted that the Act does not permit an institution to 'pause' a request due to sensitivity or a strategic plan for multiple requests. The Commissioner ordered the CFIA to provide a complete response within 36 business days of the final report. The CFIA confirmed it would implement the order and had already begun retrieving and reviewing records.

Key Issues
  • Whether the institution responded to the access request within the 30-day period set out in section 7 of the Access to Information Act
  • Whether the institution's reasons for delay (ongoing RCMP investigations, safety/security concerns, volume of records) justified the failure to respond within statutory timelines
  • Whether the Access to Information Act authorizes an institution to 'pause' a response to an access request
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 7, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

Canada Revenue Agency

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

May 7, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Key Issues
  • Whether the CRA adequately protected personal information against unauthorized disclosure and modification
  • Whether the CRA contravened subsection 6(2) of the Privacy Act regarding accuracy of personal information
  • Whether the CRA contravened subsection 8(2) of the Privacy Act regarding disclosure of personal information
  • Whether the CRA's prevention measures were adequate
  • Whether the CRA implemented mandatory multi-factor authentication (MFA) in a timely manner and with sufficient strength
  • Whether the CRA's authentication processes by phone were strong enough
  • Whether the CRA considered and integrated a zero-trust approach into its security measures
  • Whether the CRA had sufficient visibility over its attack surface and managed it effectively
  • Whether the CRA's vetting, training, and awareness tools were effective for employees and third parties
  • Whether the CRA's monitoring and detection approach was tailored to the threats and risks leading to Unauthorized Use of Taxpayer Information by a Third Party (UUTP)
  • Whether the CRA's remediation efforts for individual UUTPs were adequate, including root cause analysis
  • Whether the CRA's governance processes for addressing UUTPs were coordinated, comprehensive, and efficient
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & unresolved
Federal (Canada) flag
May 6, 2026PIPEDA Findings #2026-002Indexed Jun 30, 2026

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

OpenAI OpCo, LLC

This joint investigation by the OPC, CAI, OIPC-BC, and OIPC-AB examined OpenAI OpCo, LLC's compliance with federal and provincial privacy laws regarding its ChatGPT service. The Offices investigated OpenAI's collection, use, and disclosure of personal information for model training, consent practices, openness, accuracy, individual rights (access, correction, deletion), data retention, and accountability. While OpenAI challenged jurisdiction and argued for implied consent, the Offices largely found contraventions in its initial practices, particularly concerning the overbroad collection of personal information from public sources and user interactions without valid consent or sufficient transparency. However, in response to the preliminary report, OpenAI committed to implementing significant privacy-enhancing measures, including a new filtering tool for training data, improved transparency, and enhanced individual rights processes. Consequently, the OPC found the matter well-founded and conditionally resolved under PIPEDA, expecting continued implementation and improvement of these measures. The OIPC-AB and OIPC-BC, due to stricter provincial consent requirements, found the consent issues well-founded and unresolved, while the CAI had mixed outcomes, also finding some issues unresolved. The Offices will monitor OpenAI's implementation of the agreed-upon recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & unresolved

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

May 6, 2026PIPEDA Findings #2026-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

This joint investigation by the OPC, CAI, OIPC-BC, and OIPC-AB examined OpenAI OpCo, LLC's compliance with federal and provincial privacy laws regarding its ChatGPT service. The Offices investigated OpenAI's collection, use, and disclosure of personal information for model training, consent practices, openness, accuracy, individual rights (access, correction, deletion), data retention, and accountability. While OpenAI challenged jurisdiction and argued for implied consent, the Offices largely found contraventions in its initial practices, particularly concerning the overbroad collection of personal information from public sources and user interactions without valid consent or sufficient transparency. However, in response to the preliminary report, OpenAI committed to implementing significant privacy-enhancing measures, including a new filtering tool for training data, improved transparency, and enhanced individual rights processes. Consequently, the OPC found the matter well-founded and conditionally resolved under PIPEDA, expecting continued implementation and improvement of these measures. The OIPC-AB and OIPC-BC, due to stricter provincial consent requirements, found the consent issues well-founded and unresolved, while the CAI had mixed outcomes, also finding some issues unresolved. The Offices will monitor OpenAI's implementation of the agreed-upon recommendations.

Key Issues
  • Whether the Offices had jurisdiction over OpenAI's activities under federal and provincial privacy laws.
  • Whether OpenAI collected, used, and disclosed personal information for purposes that a reasonable person would consider appropriate in the circumstances.
  • Whether OpenAI obtained valid consent for the collection and use of personal information from publicly accessible websites and licensed third-party sources for model training.
  • Whether OpenAI obtained valid consent and met its obligation to inform individuals with respect to the collection and use of personal information included in their interactions with ChatGPT.
  • Whether OpenAI obtained valid consent and met its obligation to inform individuals with respect to the disclosure of personal information collected from various sources via ChatGPT.
  • Whether OpenAI was sufficiently open and transparent about its models and information handling practices.
  • Whether OpenAI took reasonable steps to ensure that the information it generates about individuals is as accurate, complete, and up-to-date as is necessary for the purposes for which it is to be used.
  • Whether OpenAI provided individuals with the ability to obtain access to their personal information.
  • Whether OpenAI provided individuals with the ability to correct their personal information.
  • Whether OpenAI provided individuals with the ability to remove/delete their personal information from its models.
  • Whether OpenAI established appropriate retention and disposal procedures for the personal information that it collects, uses, and discloses.
  • Whether OpenAI met its accountability requirements in respect of the personal information under its control.
  • Whether the personal or domestic purposes exemption applied to OpenAI's commercial activities.
  • Whether the publicly available information exception applied to OpenAI's collection of personal information from the Internet.
  • Whether the journalistic, historical, or genealogical material exception under Quebec's Private Sector Act applied to OpenAI's model training data.
  • Whether section 9.1 of Quebec's Private Sector Act (privacy by default) applied to ChatGPT's privacy settings.
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
May 1, 20265825-02107Indexed Jul 1, 2026

Canadian Heritage (Re), 2026 OIC 40

Canadian Heritage

The complainant alleged that Canadian Heritage failed to conduct a reasonable search for records and improperly claimed that some records did not exist in response to an access request for communications between Canadian Olympic Committee staff and Sport Canada staff related to weightlifting. The investigation found that the institution's search scope was too narrow, as it only used one athlete's name for keywords and did not adequately explain why certain repositories like Outlook were not searched. Furthermore, the OIC identified specific responsive records that were not provided by Canadian Heritage. The Commissioner concluded that Canadian Heritage did not conduct a reasonable search and that additional records likely exist. The complaint was found to be well founded, and Canadian Heritage was ordered to conduct a new search and provide a new response.

Quick view

Access to Information ActWell-founded

Canadian Heritage (Re), 2026 OIC 40

May 1, 20265825-02107
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Canadian Heritage failed to conduct a reasonable search for records and improperly claimed that some records did not exist in response to an access request for communications between Canadian Olympic Committee staff and Sport Canada staff related to weightlifting. The investigation found that the institution's search scope was too narrow, as it only used one athlete's name for keywords and did not adequately explain why certain repositories like Outlook were not searched. Furthermore, the OIC identified specific responsive records that were not provided by Canadian Heritage. The Commissioner concluded that Canadian Heritage did not conduct a reasonable search and that additional records likely exist. The complaint was found to be well founded, and Canadian Heritage was ordered to conduct a new search and provide a new response.

Key Issues
  • Whether Canadian Heritage conducted a reasonable search for records
  • Whether Canadian Heritage improperly responded that some or all requested records do not exist
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 9, 20265823-01285Indexed Jun 30, 2026

Department of Justice Canada (Re), 2026 OIC 39

Department of Justice Canada

The complainant alleged that the Department of Justice Canada improperly withheld a "Final report: Mandatory Minimum Penalties. Recommendations to the Minister of Justice and Attorney General of Canada. Expert Panel on Sentencing Reform" under sections 14 and 21(1)(a) of the Access to Information Act. The Department argued that disclosure would harm federal-provincial affairs and that the report constituted advice or recommendations from internal-like advisors. The Commissioner found no reasonable expectation of harm to federal-provincial affairs, noting the report was six years old, drafted by volunteers, and did not detail active negotiations or provincial positions. Furthermore, the Commissioner determined that the report was prepared by external consultants, not employees or ministerial staff, thus falling under an exception to the advice and recommendations exemption. Consequently, the Commissioner ordered the Department to disclose the records in their entirety, and the Department agreed to comply.

Quick view

Access to Information ActWell-founded

Department of Justice Canada (Re), 2026 OIC 39

Apr 9, 20265823-01285
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Department of Justice Canada improperly withheld a "Final report: Mandatory Minimum Penalties. Recommendations to the Minister of Justice and Attorney General of Canada. Expert Panel on Sentencing Reform" under sections 14 and 21(1)(a) of the Access to Information Act. The Department argued that disclosure would harm federal-provincial affairs and that the report constituted advice or recommendations from internal-like advisors. The Commissioner found no reasonable expectation of harm to federal-provincial affairs, noting the report was six years old, drafted by volunteers, and did not detail active negotiations or provincial positions. Furthermore, the Commissioner determined that the report was prepared by external consultants, not employees or ministerial staff, thus falling under an exception to the advice and recommendations exemption. Consequently, the Commissioner ordered the Department to disclose the records in their entirety, and the Department agreed to comply.

Key Issues
  • Whether s.14 ATIA (federal-provincial affairs) was properly applied to the records
  • Whether disclosure of the report could reasonably be expected to harm the conduct of federal-provincial affairs
  • Whether s.21(1)(a) ATIA (advice or recommendations) was properly applied to the records
  • Whether the report was prepared by consultants or advisers who were not directors, officers, or employees of an institution or members of a minister's staff, as per s.21(2)(b) ATIA
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 9, 20265825-01407Indexed Jun 30, 2026

Business Development Bank of Canada (Re), 2026 OIC 38

Business Development Bank of Canada

The complainant alleged that the Business Development Bank of Canada (BDC) improperly refused to process an access request for records related to three companies. BDC argued that the requester had not confirmed their right of access and that any responsive records would ultimately be withheld due to statutory confidentiality obligations. The Information Commissioner found that the request met the requirements of section 6 of the Access to Information Act, as it was in writing, made to the correct institution, and provided sufficient detail. The Commissioner also determined that the complainant, a corporation located in Canada, had met the right of access under section 4 of the Act. BDC's demand for proof of identification and board resolutions was deemed an improper prerequisite to processing the request. The Commissioner concluded that BDC was obligated to process the request and issue a proper response under sections 7 and 10 of the Act. The complaint was found to be well founded, and BDC was ordered to accept and process the request.

Quick view

Access to Information ActWell-founded

Business Development Bank of Canada (Re), 2026 OIC 38

Apr 9, 20265825-01407
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Business Development Bank of Canada (BDC) improperly refused to process an access request for records related to three companies. BDC argued that the requester had not confirmed their right of access and that any responsive records would ultimately be withheld due to statutory confidentiality obligations. The Information Commissioner found that the request met the requirements of section 6 of the Access to Information Act, as it was in writing, made to the correct institution, and provided sufficient detail. The Commissioner also determined that the complainant, a corporation located in Canada, had met the right of access under section 4 of the Act. BDC's demand for proof of identification and board resolutions was deemed an improper prerequisite to processing the request. The Commissioner concluded that BDC was obligated to process the request and issue a proper response under sections 7 and 10 of the Act. The complaint was found to be well founded, and BDC was ordered to accept and process the request.

Key Issues
  • Whether the access request met the requirements of section 6 of the ATIA
  • Whether the complainant, a corporation, met the right of access under section 4 of the ATIA
  • Whether BDC's demand for proof of identification and board resolutions was a valid prerequisite to processing the request
  • Whether BDC's refusal to process the request based on anticipated exemptions was appropriate
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Mar 31, 20265824-01584Indexed Aug 6, 2026

Canada Revenue Agency (Re), 2026 OIC 48

Canada Revenue Agency

The complainant alleged that the Canada Revenue Agency (CRA) improperly withheld employee telephone numbers under paragraph 16(2)(c) of the Access to Information Act, claiming disclosure could facilitate the commission of an offence. The request was for a telephone list for the CRA Headquarters International and Large Business Directorate. The complainant also initially alleged an unreasonable search, but later withdrew this aspect of the complaint. The CRA argued that disclosing cell phone numbers, now widely used by employees, could lead to hacking, interception of communications, identity theft, fraud, and harassment, citing vulnerabilities like SS7 attacks. However, the OIC found that the CRA failed to provide clear and convincing evidence of a reasonable expectation of harm, noting that government devices are encrypted and employees are trained on security risks. The OIC also pointed out that some of the numbers were already publicly available, undermining the CRA's claim of harm. The Information Commissioner concluded that the CRA did not meet the requirements for applying paragraph 16(2)(c). The complaint was deemed well founded, and the CRA subsequently released the withheld phone numbers.

Quick view

Access to Information ActWell-founded

Canada Revenue Agency (Re), 2026 OIC 48

Mar 31, 20265824-01584
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Canada Revenue Agency (CRA) improperly withheld employee telephone numbers under paragraph 16(2)(c) of the Access to Information Act, claiming disclosure could facilitate the commission of an offence. The request was for a telephone list for the CRA Headquarters International and Large Business Directorate. The complainant also initially alleged an unreasonable search, but later withdrew this aspect of the complaint. The CRA argued that disclosing cell phone numbers, now widely used by employees, could lead to hacking, interception of communications, identity theft, fraud, and harassment, citing vulnerabilities like SS7 attacks. However, the OIC found that the CRA failed to provide clear and convincing evidence of a reasonable expectation of harm, noting that government devices are encrypted and employees are trained on security risks. The OIC also pointed out that some of the numbers were already publicly available, undermining the CRA's claim of harm. The Information Commissioner concluded that the CRA did not meet the requirements for applying paragraph 16(2)(c). The complaint was deemed well founded, and the CRA subsequently released the withheld phone numbers.

Key Issues
  • Whether s.16(2)(c) ATIA (facilitating the commission of an offence) was properly applied to withhold employee telephone numbers
  • Whether there was a reasonable expectation of harm from disclosing employee telephone numbers
  • Whether the institution's security measures for government devices mitigated the risk of harm
  • Whether the public availability of some employee telephone numbers undermined the claim of harm
  • Whether the institution conducted a reasonable search for records
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
Mar 31, 20265825-04112Indexed Jun 1, 2026

Transport Canada, 5825-04112

The OIC ordered Transport Canada to provide a complete response to the access request no later than 36 business days following the date of the final report..

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Transport Canada, 5825-04112

Mar 31, 20265825-04112

The OIC ordered Transport Canada to provide a complete response to the access request no later than 36 business days following the date of the final report..

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
Mar 31, 20265825-03242Indexed Jun 1, 2026

Privy Council Office, 5825-03242

The OIC ordered Privy Council Office to provide a complete response to the access request no later than 36 business days following the date of the final report..

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Privy Council Office, 5825-03242

Mar 31, 20265825-03242

The OIC ordered Privy Council Office to provide a complete response to the access request no later than 36 business days following the date of the final report..