Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

Organization: CIBC
Plain-language brief

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Key issues
  1. 1Whether CIBC's privacy practices adequately protected personal information from misdirected faxes
  2. 2Whether CIBC effectively responded to notifications of misdirected faxes
  3. 3Whether CIBC appropriately recovered misdirected personal information
  4. 4Whether CIBC adequately notified affected customers of privacy breaches
  5. 5Whether CIBC employees recognized misdirected faxes as privacy issues
  6. 6Whether CIBC's internal privacy management structure was sufficient to address breaches
Outcome breakdownFavours: Both, in part
  • Misdirected faxes: CIBC failed to adequately address misdirected faxes
  • Breach recognition: CIBC employees failed to recognize misdirection as breaches
  • Customer notification: CIBC failed to notify affected customers
  • Privacy practices: CIBC's privacy practices were inadequate
  • Remedial measures: CIBC implemented remedial measures
  • Recommendations: OPC made recommendations for future actions
  • Compliance verification: OPC planned to verify CIBC's actions
Outcome

Privacy practices failed; corrective measures implemented and recommended

Reasoning

The OPC found that CIBC's privacy practices failed, leading to misdirected faxes of personal information. However, CIBC took a number of remedial measures during and after the investigation, and the OPC made recommendations for further action.

AI-generated summary for reference only. Always verify against the official decision ↗
Decision notes
Recommended action / remedy

The OPC recommended that CIBC fully implement its planned changes and safeguards, establish a mechanism to immediately notify affected persons of inappropriate disclosures, and report back to the Assistant Privacy Commissioner.

Statutes considered
  • Principle 4.1 PIPEDA
  • Principle 4.7 PIPEDA

This summary is informational only and not legal advice.

Pro · AI

Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.

Pro
Coverage — 13 of 14 jurisdictions searchable

Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.

Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).

Coming soon: Nunavut — being re-processed for AI search.

Find decisions like this one — by meaning, not keywords.

Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.

Upgrade to Pro