Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #3: Misdirected faxes - December 4, 2006

Organization: Two Canadian banks
Plain-language brief

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Key issues
  1. 1Whether organizations adequately safeguard personal information to prevent inappropriate disclosure (Principle 4.7 PIPEDA)
  2. 2Whether organizations implement effective policies and procedures to give effect to fair information practices (Principle 4.1 PIPEDA)
  3. 3Whether employees are attuned to privacy issues and can respond to problems when they arise
  4. 4Whether organizations notify affected customers of privacy breaches
  5. 5Whether organizations have processes for confirming correct fax transmission
  6. 6Whether organizations have measures to recover erroneously transmitted customer information
Outcome breakdownFavours: Both, in part
  • Safeguards: Banks failed to adequately safeguard personal information
  • Policy implementation: Banks failed to ensure privacy policies were effectively implemented
  • Corrective measures: Banks took corrective measures during investigation
  • Recommendations: OPC made further recommendations
  • Recommendations implementation: Banks fully implemented recommendations
Outcome

Well-founded and resolved — corrective measures implemented

Reasoning

The OPC found that both banks failed to adequately safeguard personal information and ensure effective implementation of privacy policies, leading to misdirected faxes. However, both banks fully implemented the OPC's recommendations to address these issues.

AI-generated summary for reference only. Always verify against the official decision ↗
Decision notes
Recommended action / remedy

The OPC recommended that each bank fully implement planned measures to improve internal communication of privacy breaches, commit to notifying all affected customers of breaches, examine processes for confirming correct fax transmission, and implement measures to ensure recovery of erroneously transmitted customer information. Both banks fully implemented these recommendations.

Statutes considered
  • Principle 4.1 PIPEDA
  • Principle 4.7 PIPEDA

This summary is informational only and not legal advice.

Pro · AI

Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.

Pro
Coverage — 13 of 14 jurisdictions searchable

Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.

Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).

Coming soon: Nunavut — being re-processed for AI search.

Find decisions like this one — by meaning, not keywords.

Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.

Upgrade to Pro