← Back to catalogue/Federal (Canada)PIPEDA Findings #2021-004
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Organization: Fido Solutions Inc. (a subsidiary of Rogers Communications Inc.)Complainant: Anonymous applicant
Plain-language brief

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Key issues
  1. 1Whether Fido adequately safeguarded the Complainant’s personal information under Principle 4.7
  2. 2Whether Fido responded to the Complainant’s access request in a generally understandable format under Principle 4.9 and 4.9.4
Outcome breakdownFavours: Applicant / complainant
  • Safeguards: Systemic issue found, recommendations made
  • Access to information format: Initial format not understandable
  • Access to information: Transcripts subsequently provided
Outcome

Complaint well-founded and conditionally resolved (safeguards) and well-founded and resolved (access)

Reasoning

Fido's employees repeatedly failed to follow authentication protocols, leading to unauthorized access, and the initial provision of call recordings for an access request was not in a generally understandable format. Fido committed to corrective actions for safeguards and resolved the access issue by providing transcripts.

AI-generated summary for reference only. Always verify against the official decision ↗
Decision notes
Recommended action / remedy

For safeguards, the OPC recommended Fido consolidate authentication protocols, provide regular refresher training to staff and managers, and implement proactive feedback for non-compliance. For the access request, Fido provided transcripts of the calls.

Statutes considered
  • Principle 4.7 PIPEDA
  • Principle 4.7.1 PIPEDA
  • Principle 4.9 PIPEDA
  • Principle 4.9.4 PIPEDA

This summary is informational only and not legal advice.

Pro · AI

Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.

Pro
Coverage — 13 of 14 jurisdictions searchable

Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.

Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).

Coming soon: Nunavut — being re-processed for AI search.

Find decisions like this one — by meaning, not keywords.

Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.

Upgrade to Pro