BreachOfPrivacy
Decisions/Federal (Canada)/Privacy Act/Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service
Office of the Privacy Commissioner of CanadaPrivacy ActNot well-founded
Flag of Canada

Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service

Organization: Various Federal Separate Employers
Decision: May 30, 2023Published: May 30, 2023

This investigation examined whether COVID-19 vaccination attestation requirements implemented by several federal separate employers for their employees complied with the Privacy Act. The OPC found that the collection and use of vaccination status information, including for accommodation requests, was authorized under the Act and directly related to the employers' operating programs, specifically workplace health and safety during the pandemic. While not a strict legal requirement of the Act, the OPC also assessed the necessity and proportionality of these measures and found them to be reasonable given the exceptional circumstances of the pandemic.

  • Whether the collection of COVID-19 vaccination status information was directly related to an operating program or activity of the institutions.
  • Whether the use and disclosure of vaccination status information, including for accommodation requests, was authorized under the Privacy Act.
  • The necessity and proportionality of the vaccination attestation measures in the context of the COVID-19 pandemic.

Complaints not well-founded; recommendations made regarding structured analysis of necessity and proportionality and limiting access to sensitive information.

The OPC determined that the collection, use, and disclosure of vaccination status information by the respondent institutions were authorized under the Privacy Act, as they were directly related to occupational health and safety programs during the COVID-19 pandemic. The measures were also deemed necessary and proportional given the emergency circumstances.

AI-generated summary for reference only. Always verify against the official decision ↗

Recommended action / remedy

The OPC recommended that institutions explicitly consider necessity and proportionality in a structured way when introducing or modifying privacy-invasive programs, and that Canada Post consider what types of information constitute a 'need to know' for support employees with access to sensitive personal information.

Statutory provisions cited
  • s. 4 Privacy Act
  • s. 7 Privacy Act
  • s. 8(2)(a) Privacy Act

This summary is informational only and does not constitute legal advice.