
Early resolved case summary #2015-05: Anti-virus service provider steps up safeguards after customer personal information fraudulently used by someone posing as an employee
A couple received fraudulent calls from someone posing as an anti-virus service provider technician, who gained remote access to their computer and processed a fraudulent credit card payment. The fraudster used the couple's private account number, which they believed was obtained from the legitimate service provider. The couple struggled to get the service provider to investigate the matter, leading them to file a complaint with the OPC. The OPC requested the service provider conduct an investigation, which revealed an employee had improperly accessed the complainant's account. The employee was dismissed, and the service provider reimbursed the couple and implemented new safeguards, including an auditing system for employee access and a streamlined procedure for escalating privacy concerns. The complainants were satisfied with these outcomes.
- 1Whether the anti-virus service provider adequately protected personal information against unauthorized access by employees (Principle 4.7 PIPEDA)
- 2Whether the anti-virus service provider had adequate procedures to receive and respond to complaints about personal information handling (Principle 4.10 PIPEDA)
- 3Whether the anti-virus service provider adequately investigated the complaint (Principle 4.10.4 PIPEDA)
- Improper access to personal information: Employee found to have improperly accessed account
- Employee dismissal: Employee dismissed
- Reimbursement: Couple reimbursed for fraudulent payment
- New safeguards: New safeguards implemented by institution
- Complaint resolution: Complainants satisfied with outcomes
Complaint early resolved — corrective measures implemented
The complaint was resolved early in the OPC's investigation after the service provider conducted an internal investigation, dismissed the responsible employee, reimbursed the complainants, and implemented new safeguards and complaint handling procedures to the satisfaction of the complainants.
The service provider dismissed the employee responsible for unauthorized access, reimbursed the complainants, implemented an auditing system for employee access to customer files, and streamlined its procedure for escalating privacy concerns to management.
- Principle 4.10.4 PIPEDA
This summary is informational only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro