
CBSA’s use of commercial genetic genealogy in a deportation case contravenes the Privacy Act
A former refugee complained that the Canadian Border Services Agency (CBSA) contravened his privacy rights by using commercial genetic genealogy (FamilyTreeDNA) to determine his nationality for deportation. He alleged lack of legal authority, unnecessary collection, invalid consent, deceptive practices, inadequate disclosure limitation, and insufficient Personal Information Bank (PIB) description. The Office of the Privacy Commissioner (OPC) found that while the collection was directly related to CBSA's program, the agency contravened section 5 of the Privacy Act by failing to obtain valid, informed authorization for indirect collection from FTDNA. CBSA also contravened section 8 by making incidental disclosures of the complainant's personal information to other FTDNA users, failing to monitor account settings, and not using a pseudonym. Furthermore, the CBSA's PIB descriptions were non-compliant with section 11, as they did not adequately describe the collection of genetic profiles of other FTDNA users. The OPC made several recommendations, which CBSA committed to implement for most parts, but two accounts remained open at the time of the report, leading to an ongoing, unresolved contravention. Consequently, the complaint was found well-founded in part and conditionally resolved in part.
- 1Whether CBSA's collection of genetic genealogy information was directly related to an operating program or activity under s.4 of the Privacy Act
- 2Whether CBSA collected unnecessary information under s.4 of the Privacy Act
- 3Whether CBSA obtained valid authorization from the complainant for the indirect collection of his personal information from FTDNA under s.5(1) of the Privacy Act
- 4Whether the complainant's consent for indirect collection was voluntary and not given under duress
- 5Whether the complainant was adequately informed about FTDNA's terms and his rights as a DNA donor for valid authorization
- 6Whether CBSA acted deceptively in its collection via FTDNA
- 7Whether the incidental indirect collection of genetic profile information of hundreds of other individuals contravened s.5(1) of the Privacy Act
- 8Whether CBSA's incidental disclosures of the complainant's personal information contravened s.8 of the Privacy Act
- 9Whether allowing potential disclosure of the complainant's personal information to other law enforcement bodies (via "law enforcement matching" opt-in) contravened s.8 of the Privacy Act
- 10Whether the disclosure of ancillary personal information (ethnicity) to genetic matches contravened s.8 of the Privacy Act
- 11Whether the disclosure of the complainant's identity to genetic matches (failure to use a pseudonym) contravened s.8 of the Privacy Act
- 12Whether CBSA's Personal Information Bank (PIB) descriptions complied with the transparency obligations under s.11 of the Privacy Act
- 13Whether the PIB adequately described the collection of biometric information for individuals subject to removal orders
- 14Whether the PIB adequately described the collection of genetic profiles of other FTDNA users (relatives of individuals subject to removal orders)
- Legal authority for collection: Collection directly related to program
- Validity of consent: Invalid consent for indirect collection
- Disclosure limitation: Incidental disclosures contravened s.8
- PIB description adequacy: PIB non-compliant with s.11
- Resolution of contravention: Contravention ongoing due to open accounts
Complaint well-founded in part and conditionally resolved in part
The OPC found that CBSA contravened sections 5, 8, and 11 of the Privacy Act due to invalid authorization for collection, unauthorized incidental disclosures, and inadequate transparency in its Personal Information Bank descriptions. While CBSA committed to implementing most recommendations, two accounts remained open at the time of the report, constituting an ongoing, unresolved contravention.
The OPC recommended that CBSA ensure future indirect collections provide access to all relevant third-party documentation, actively monitor third-party terms and conditions, carefully consider secondary disclosures with appropriate controls, update PIB content to describe all collected personal information, immediately close any active genetic genealogy accounts or inform individuals to take control, and institute robust structures for assessing and controlling novel biometric information collection.
- s.4 Privacy Act
- s.5 Privacy Act
- s.5(1) Privacy Act
- s.5(2) Privacy Act
- s.5(3) Privacy Act
- s.8 Privacy Act
- s.8(1) Privacy Act
- s.8(2) Privacy Act
- s.8(2)(a) Privacy Act
- s.11 Privacy Act
- s.11(1) Privacy Act
- s.11(1)(a)(i) Privacy Act
- s.11(1)(b)(i) Privacy Act
This summary is informational only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro