
PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings
An employee complained that her pension and benefit provider disclosed her unique identifier to a third party, failed to keep her address accurate, and failed to safeguard her personal information. The investigation found that another plan member with the same name called the provider, and was mistakenly given the complainant's ID number. This led to the complainant's address being changed to the other member's address, resulting in five misdirected mailings containing sensitive information. Although the mailings were returned unopened, the complainant's insurance coverage was cancelled due to unreturned forms. The provider admitted to disclosing the ID number without consent and failing to follow authentication procedures. The provider agreed to reinstate the insurance, revamp authentication and address-change procedures, develop a privacy plan, improve incident response, and undergo a third-party privacy audit. The OPC found the matter well-founded and conditionally resolved.
- 1Whether the provider disclosed the complainant's unique identifier to a third party without consent (Principle 4.3 PIPEDA)
- 2Whether the provider failed to keep the complainant's address information accurate (Principle 4.6 PIPEDA)
- 3Whether the provider failed to implement appropriate safeguards to protect personal information from unauthorized disclosure and modification (Principle 4.7 PIPEDA)
- 4Whether proper authentication of the caller took place before the complainant's ID number was given out (Principle 4.7.1 PIPEDA)
- 5Whether the provider's failure to detect and correct the erroneous address sooner constituted a contravention of Principle 4.6.1 PIPEDA
- Disclosure of unique identifier: Disclosure without consent found
- Accuracy of personal information: Inaccurate address found
- Safeguards for personal information: Failure to safeguard found
- Authentication procedures: Failure to follow procedures found
- Remedial actions: Provider agreed to multiple remedial actions
- Complaint outcome: Matter found well-founded and conditionally resolved
Complaint well-founded and conditionally resolved
The OPC found that the provider contravened PIPEDA Principles 4.3, 4.6, 4.6.1, 4.7, and 4.7.1 by disclosing the complainant's ID, misdirecting mail, and failing to properly authenticate. The matter was conditionally resolved based on the provider's commitment to implement significant corrective measures and undergo an audit.
The provider agreed to reinstate the complainant’s cancelled insurance retroactively, make changes to its customer identification and authentication policies and practices, develop a privacy plan, review its address change process, improve forms and training, improve privacy incident response procedures, and submit to a third-party privacy audit.
- Principle 4.3 PIPEDA
- Principle 4.6 PIPEDA
- Principle 4.6.1 PIPEDA
- Principle 4.7 PIPEDA
- Principle 4.7.1 PIPEDA
This summary is informational only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro