
PIPEDA Report of Findings #2018-003: Facebook agrees to stop using non-users’ personal information in users’ address books
The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Facebook Inc. following a 2013 privacy breach where contact information, including that of non-users, was inadvertently disclosed via the 'Download Your Information' (DYI) tool. The investigation focused on Facebook's safeguards, consent practices for its 'matching across address books' process for both users and non-users, and the ability for individuals to access and correct their personal information. The OPC found Facebook's safeguards inadequate prior to the breach, but deemed the issue resolved after Facebook implemented a new Privacy Framework. While Facebook's use of user contact information for matching was found not to contravene consent principles, the OPC determined Facebook was not sufficiently open about these practices, an issue conditionally resolved by Facebook's commitment to revise its notices. The OPC also found Facebook used non-users' personal information for matching without meaningful consent, an issue resolved by Facebook's agreement to stop maintaining such data. Finally, Facebook was found not to be providing adequate access to and correction of matched data, which was resolved through an interim solution.
- 1Whether FB had appropriate safeguards in place prior to the breach to protect contact information of users and non-users.
- 2Whether FB implemented appropriate safeguards after the breach.
- 3Whether FB was using the personal information of users and non-users during the process of matching across address books.
- 4Whether FB was obtaining meaningful consent from users for the use of personal information during the matching process.
- 5Whether FB was meeting its obligation to be open about its policies and practices regarding the matching process for users.
- 6Whether FB was obtaining meaningful consent from non-users for the use of personal information during the matching process.
- 7Whether FB was providing users and non-users the ability to obtain access to their personal information/data.
- 8Whether FB was providing users and non-users the ability to correct their personal information/data.
- 9Whether the breach resulted in unauthorized disclosure of personal information.
- 10Whether the testing conducted by FB for the DYI tool was adequate.
- 11Whether the notice provided to non-users in email invitations was consistent with PIPEDA s.6.1 and Principles 4.3 and 4.8.
- 12Whether providing access to matched data would likely reveal personal information about a third party under PIPEDA s.9(1).
- 13Whether providing access to matched data would raise safety and security concerns.
- Safeguards: Inadequate safeguards found, issue resolved by new Privacy Framework
- Consent for user data matching: No contravention of consent principles for user data matching
- Openness of practices: Insufficient openness found, issue conditionally resolved by commitment to revise notices
- Consent for non-user data matching: Non-user data used without meaningful consent, issue resolved by agreement to stop maintaining data
- Access and correction of data: Inadequate access and correction found, issue resolved by interim solution
Multiple findings: well-founded and resolved (safeguards, non-user consent, access/correction), not well-founded (user consent), well-founded and conditionally resolved (user openness).
The OPC found several contraventions related to safeguards, openness, consent for non-users, and access/correction. Facebook took corrective actions or committed to them, leading to most issues being resolved or conditionally resolved, with one issue found not well-founded.
Facebook implemented a new Privacy Framework, revised its notices regarding the contact importer and matching process, deprecated the data store for non-users' matched data, and provided an interim solution for users to access and correct their matched data.
- Principle 4.7 of Schedule 1 of PIPEDA
- Principle 4.7.1 of Schedule 1 of PIPEDA
- Principle 4.5 of Schedule 1 of PIPEDA
- Principle 4.3 of Schedule 1 of PIPEDA
- Principle 4.3.1 of Schedule 1 of PIPEDA
- Principle 4.3.2 of Schedule 1 of PIPEDA
- Section 6.1 of PIPEDA
- Principle 4.8 of Schedule 1 of PIPEDA
- Principle 4.6 of Schedule 1 of PIPEDA
- Principle 4.9 of Schedule 1 of PIPEDA
- Principle 4.9.1 of Schedule 1 of PIPEDA
- Principle 4.9.5 of Schedule 1 of PIPEDA
- Subsection 9(1) of PIPEDA
- Subsection 5(3) of PIPEDA
This summary is informational only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro